Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   msi cr70 erkennt kamera nicht weder interne noch externe, win7,downspeedtest (https://www.trojaner-board.de/183924-msi-cr70-erkennt-kamera-weder-interne-noch-externe-win7-downspeedtest.html)

milkit54 12.01.2017 23:53

msi cr70 erkennt kamera nicht weder interne noch externe, win7,downspeedtest
 
Hallo zusammen hier bittet ein ziemlich verwirrter und MS kranker unwissender Anwender um evtl mögliche Hilfe. Fehler meinerseits bitte ich schon jetzt zu entschuldigen Danke
ich starte mal den Versuch
Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 11-01-2017
durchgeführt von Micha (Administrator) auf MICHA-MSI (12-01-2017 10:46:44)
Gestartet von C:\Users\Micha\Downloads
Geladene Profile: Micha (Verfügbare Profile: Micha & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\AvrcpService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Microsoft Corporation) C:\Windows\System32\CISVC.EXE
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareService.exe
(Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.2.9.5\LavasoftTcpService.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(MSI) C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe
(Visicom Media Inc.) C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe
(PLUMBYTES) C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\AmwService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\ws.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\creator-ws.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\RtkBleServ.exe
() C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\SkypePlugin.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(MSI) C:\Program Files (x86)\SCM\Radio Manager.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareTray.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Lavasoft) C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(© 2015 Microsoft Corporation) C:\Users\Micha\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
() C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\SymcPCCULaunchSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\scalc.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.bin
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\Micha\Downloads\FRST64(1).exe

==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13538376 2013-05-21] (Realtek Semiconductor)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [253440 2013-04-23] (Realtek Semiconductor Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2875728 2013-03-04] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2013-07-05] (MSI)
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [399528 2013-07-05] (MSI)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [Windows Mobile-based device management] => C:\windows\WindowsMobile\wmdcBase.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [AdAwareTray] => C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareTray.exe [9533688 2016-12-15] ()
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-10-13] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [230696 2011-10-13] (CyberLink Corp.)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [490480 2013-02-01] (MSI)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2014-03-18] (shbox.de)
HKLM-x32\...\Run: [QHSafeTray] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe [1153448 2016-08-10] ()
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-10-05] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1367360 2014-12-16] (Lavasoft)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series (Kopie 1)] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series (Kopie 2)] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-10-05] (Apple Inc.)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [BingSvc] => C:\Users\Micha\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27230168 2016-11-15] (Skype Technologies S.A.)
HKU\S-1-5-18\...\Run: [EPSON SX100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-18\...\RunOnce: [panda] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f
HKU\S-1-5-18\...\RunOnce: [panda_XP] => reg.exe delete "HKCU\Software\panda" /f
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Keine Datei
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop(777).ini [2009-07-14] ()
Startup: C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.6.lnk [2013-07-31]
ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.6.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
GroupPolicyScripts-x32: Beschränkung <======= ACHTUNG

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Winsock: Catalog9-x64 01 C:\windows\system32\LavasoftTcpService64.dll [358736 2014-12-16] (Lavasoft Limited)
Winsock: Catalog9-x64 02 C:\windows\system32\LavasoftTcpService64.dll [358736 2014-12-16] (Lavasoft Limited)
Winsock: Catalog9-x64 03 C:\windows\system32\LavasoftTcpService64.dll [358736 2014-12-16] (Lavasoft Limited)
Winsock: Catalog9-x64 04 C:\windows\system32\LavasoftTcpService64.dll [358736 2014-12-16] (Lavasoft Limited)
Winsock: Catalog9-x64 16 C:\windows\system32\LavasoftTcpService64.dll [358736 2014-12-16] (Lavasoft Limited)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2
Tcpip\..\Interfaces\{19590355-955C-4F75-9574-A5178867FB8F}: [DhcpNameServer] 192.168.0.1 192.168.0.2
Tcpip\..\Interfaces\{7AFF0EF0-F8B5-4E22-BED7-5BAC51243C58}: [NameServer] 193.189.244.206 193.189.244.225

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.n-tv.de/
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {2BA0719B-B10C-4176-8BB1-AF2B6E7453E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAM3&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {2BA0719B-B10C-4176-8BB1-AF2B6E7453E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAM3&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={18DC9A1B-75F8-4C91-A21F-328A8F8FCFB0}&mid=2f112f36b90e47cd86aa856e587a95e0-b67d740e056757739f071bdf1b00435729c4d0a4&lang=de&ds=AVG&coid=avgtbavg&cmpid=1016tb&pr=fr&d=2015-01-05 13:55:51&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> {2BA0719B-B10C-4176-8BB1-AF2B6E7453E0} URL =
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://pandasecurity.mystart.com/results.php?pr=vmn&gen=ms&id=pandasecuritytb&v=4_2&idate=2015-05-27&ent=ch_668&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> {85A60A59-D3D8-468F-B598-FB4393789EF4} URL = hxxps://www.google.de/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={18DC9A1B-75F8-4C91-A21F-328A8F8FCFB0}&mid=2f112f36b90e47cd86aa856e587a95e0-b67d740e056757739f071bdf1b00435729c4d0a4&lang=de&ds=AVG&coid=avgtbavg&cmpid=1016tb&pr=fr&d=2015-01-05 13:55:51&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> {BDF61FAE-9D19-40F0-8F34-688DEB334CA9} URL = hxxp://securedsearch.lavasoft.com/results.php?pr=vmn&id=webcompa&ent=ch_WCYID10088_test01_150105&q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll [2016-08-10] (Qihu 360 Software Co., Ltd.)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO-x32: PDF Architect Helper -> {691B33B0-B86E-47F3-81C7-56E4FE3B929C} -> C:\Program Files (x86)\PDF Architect 2\creator-ie-helper.dll [2014-10-10] (pdfforge GmbH)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon.dll [2016-08-10] (Qihu 360 Software Co., Ltd.)
Toolbar: HKLM-x32 - Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - C:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH)

FireFox:
========
FF ProfilePath: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 [2017-01-12]
FF NewTab: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> hxxp://hp.myway.com/downspeedtest/ttab02/index.html?coId=db9de8384d8040ac93524301c1b30367&subId=undefined&ln=de&n=783924d7&ptb=4E16B681-6380-4409-98AE-5BA6F85B170D&st=tab&p2=%5EBXM%5Exdm001%5ETTAB02%5Ede&si=undefined
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> Google
FF Homepage: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> hxxp://www.n-tv.de/
FF Extension: (Test Pilot) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\@testpilot-addon.xpi [2017-01-11]
FF Extension: (GMX MailCheck) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\browser-mailcheck@gmx.net [2016-11-23]
FF Extension: (Awesome Screenshot - Capture, Annotate & More) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2017-01-10]
FF Extension: (Page Shot) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\jid1-NeEaf3sAHdKHPA@jetpack.xpi [2017-01-11]
FF Extension: (DownSpeedTest) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\_dqMembers_@www.downspeedtest.com [2017-01-09]
FF SearchPlugin: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\searchplugins\avg-secure-search.xml [2016-12-09]
FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: (PDF Architect 2 Creator) - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2015-01-20] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [WebProtection@360safe.com] - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox
FF Extension: (360-Internetschutz) - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox [2016-05-26]
FF HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\jsjjbqd4.default\extensions\cliqz@cliqz.com => nicht gefunden
FF HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: (McAfee Security Scan Plus) - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] [ist nicht signiert]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\pandasecuritytb.xml [2015-05-27]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2016-10-18]
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-10] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-10] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-02-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-02-16] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll [2014-10-10] (pdfforge GmbH)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=de-de
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSearchURL: Default -> hxxp://pandasecurity.mystart.com/results.php?searchsource=omnibar&pr=vmn&id=pandasecuritytb&v=2_3&ent=ds_671&q={searchTerms}
CHR DefaultSearchKeyword: Default -> yahoo
CHR Profile: C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default [2017-01-04]
CHR Extension: (Google Präsentationen) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-13]
CHR Extension: (Google Docs) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-13]
CHR Extension: (Google Drive) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-10]
CHR Extension: (YouTube) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-10]
CHR Extension: (Google-Suche) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-10]
CHR Extension: (Yahoo!) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdhbkaahephniejapepaiggngjnedpci [2015-07-22]
CHR Extension: (Google Tabellen) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-13]
CHR Extension: (MSN Homepage) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkcgfbgohboipdhliafmacjnhjbhmim [2016-12-18]
CHR Extension: (Google Docs Offline) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-08-22]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-08-22]
CHR Extension: (Google Mail) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-13]
CHR Extension: (Chrome Media Router) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-18]
CHR HKU\S-1-5-21-2198626584-3468660724-23365673-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fkkcgfbgohboipdhliafmacjnhjbhmim] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fdhbkaahephniejapepaiggngjnedpci] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AvrcpService; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe [35328 2013-04-02] (Realtek Semiconductor Corporation) [Datei ist nicht signiert]
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [47104 2013-04-26] () [Datei ist nicht signiert]
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [Datei ist nicht signiert]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [Datei ist nicht signiert]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-02-16] (Intel Corporation)
R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareService.exe [630976 2016-12-15] ()
R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.2.9.5\LavasoftTcpService.exe [1351512 2014-12-16] (Lavasoft Limited)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2013-07-05] (Micro-Star International Co., Ltd.) [Datei ist nicht signiert]
R2 MSI Foundation Service; C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe [12800 2010-07-17] (MSI) [Datei ist nicht signiert]
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [143856 2013-02-01] (MSI)
R2 NAT; C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe [143928 2012-08-19] (Symantec Corporation)
S3 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4230016 2013-01-28] (Symantec Corporation)
R2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\SymcPCCULaunchSvc.exe [123320 2012-08-13] (Symantec Corporation)
R2 panda_url_filtering; C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe [287752 2015-10-02] (Visicom Media Inc.)
R2 pbamw_service; C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\AmwService.exe [125712 2016-11-08] (PLUMBYTES)
R2 PCCUJobMgr; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe [126392 2012-08-13] (Symantec Corporation)
R2 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1771560 2014-10-10] (pdfforge GmbH)
R2 PDF Architect 2 Creator; C:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
R2 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-10-10] (pdfforge GmbH)
R2 QHActiveDefense; C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe [914344 2016-08-10] (QIHU 360 SOFTWARE CO. LIMITED)
R2 RtkBleServ; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\RtkBleServ.exe [42496 2013-04-26] (Realtek Semiconductor Corporation) [Datei ist nicht signiert]
R2 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [15208 2014-12-16] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R1 360AntiHacker; C:\windows\System32\Drivers\360AntiHacker64.sys [151784 2016-08-10] (360.cn)
R3 360AvFlt; C:\windows\System32\DRIVERS\360AvFlt.sys [86248 2016-08-10] (360.cn)
R3 360AvFlt; C:\Windows\SysWOW64\DRIVERS\360AvFlt.sys [86248 2016-08-10] (360.cn)
R1 360Box64; C:\windows\System32\DRIVERS\360Box64.sys [330472 2016-08-10] (360.cn)
R1 360Camera; C:\windows\System32\Drivers\360Camera64.sys [40520 2015-07-09] (360.cn)
R1 360fsflt; C:\windows\System32\DRIVERS\360FsFlt.sys [391392 2016-08-10] (360.cn)
R1 BAPIDRV; C:\windows\System32\DRIVERS\BAPIDRV64.sys [190696 2016-08-10] (360.cn)
R3 ccSet_NARA; C:\windows\system32\drivers\NARAx64\0403000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
S3 ccSet_NAT; C:\windows\system32\drivers\NATx64\0106000.011\ccSetx64.sys [168096 2012-08-07] (Symantec Corporation)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [77416 2016-12-14] ()
S3 ewusbnet; C:\windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
R3 gzflt; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Antimalware Engine\3.0.129.0\gzflt.sys [161592 2016-04-28] (BitDefender LLC)
S3 hwusbdev; C:\windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
R0 iaStorF; C:\windows\System32\drivers\iaStorF.sys [28656 2013-03-22] (Intel Corporation)
R3 L1C; C:\windows\System32\DRIVERS\L1C62x64.sys [118504 2013-05-07] (Qualcomm Atheros Co., Ltd.)
R2 MBAMChameleon; C:\windows\system32\drivers\MBAMChameleon.sys [176064 2017-01-10] (Malwarebytes)
R3 MBAMFarflt; C:\windows\system32\drivers\farflt.sys [102856 2017-01-11] (Malwarebytes)
R3 MBAMProtection; C:\windows\system32\drivers\mbam.sys [43968 2017-01-11] (Malwarebytes)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [250816 2017-01-11] (Malwarebytes)
R3 MBAMWebProtection; C:\windows\system32\drivers\mwac.sys [81696 2017-01-12] (Malwarebytes)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-26] (MSI)
R3 panda_url_filteringd; C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys [51288 2014-03-19] (Visicom Media Inc.)
S3 RtkAvrcp; C:\windows\system32\drivers\RtkAvrcp.sys [61152 2012-12-27] (Realtek Semiconductor Corporation)
S3 RtkAvrcpCtrlr; C:\windows\system32\drivers\RtkAvrcpCtrlr.sys [66376 2013-04-08] (Realtek Semiconductor Corporation)
R3 RtkBtFilter; C:\windows\System32\DRIVERS\RtkBtfilter.sys [535624 2013-03-28] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\windows\System32\DRIVERS\rtwlane.sys [1514568 2013-05-02] (Realtek Semiconductor Corporation                          )
S3 SWDUMon; C:\windows\System32\DRIVERS\SWDUMon.sys [13920 2017-01-04] ()
S3 Trufos; C:\windows\System32\DRIVERS\Trufos.sys [485512 2016-04-28] (BitDefender S.R.L.)
S3 MGHwCtrl; \??\C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-01-12 10:45 - 2017-01-12 10:45 - 02419200 _____ (Farbar) C:\Users\Micha\Downloads\FRST64(1).exe
2017-01-11 12:41 - 2017-01-11 12:41 - 00000111 ____H C:\Users\Micha\Documents\.~lock.Insolvenz-1.ods#
2017-01-10 20:59 - 2017-01-05 19:55 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2017-01-10 20:59 - 2017-01-05 19:55 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2017-01-10 20:59 - 2017-01-05 19:52 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2017-01-10 20:59 - 2017-01-05 18:42 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2017-01-10 20:59 - 2017-01-05 18:32 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2017-01-10 20:59 - 2017-01-05 18:25 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2017-01-10 20:59 - 2017-01-05 18:23 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2017-01-10 20:59 - 2017-01-05 18:19 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2017-01-10 20:56 - 2017-01-10 20:56 - 00083124 _____ C:\Users\Micha\Downloads\FRST01102017.txt
2017-01-10 20:55 - 2017-01-10 20:55 - 00041706 _____ C:\Users\Micha\Downloads\Addition01102017.txt
2017-01-10 16:22 - 2017-01-10 16:22 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Vorlagen
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Startmenü
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Netzwerkumgebung
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Lokale Einstellungen
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Eigene Dateien
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Druckumgebung
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Videos
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Musik
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Bilder
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Verlauf
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Anwendungsdaten
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Anwendungsdaten
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 ____D C:\Users\DefaultAppPool
2017-01-10 16:22 - 2016-11-30 06:27 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\AVG
2017-01-10 16:22 - 2013-07-31 22:25 - 00002110 _____ C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
2017-01-10 16:22 - 2013-07-31 19:31 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\Media Center Programs
2017-01-10 15:44 - 2017-01-10 15:44 - 00002485 _____ C:\Users\Public\Desktop\DriverUpdate.lnk
2017-01-10 15:44 - 2017-01-10 15:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdate
2017-01-10 15:44 - 2017-01-10 15:44 - 00000000 ____D C:\Program Files (x86)\DriverUpdate
2017-01-10 09:57 - 2017-01-10 09:57 - 00000000 ____D C:\Users\Micha\AppData\Local\{12A8CCFE-3C33-4995-BAD8-074E4C5B22FD}
2017-01-10 09:38 - 2017-01-10 09:38 - 00176064 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMChameleon.sys
2017-01-10 09:37 - 2017-01-12 09:50 - 00081696 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2017-01-10 09:37 - 2017-01-11 01:27 - 00102856 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2017-01-10 09:37 - 2017-01-11 01:27 - 00043968 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2017-01-10 09:37 - 2017-01-11 01:26 - 00250816 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-10 09:37 - 2017-01-10 09:37 - 00001837 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-01-10 09:37 - 2017-01-10 09:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-01-10 09:37 - 2017-01-10 09:37 - 00000000 ____D C:\Program Files\Malwarebytes
2017-01-10 09:37 - 2016-12-14 12:55 - 00077416 _____ C:\windows\system32\Drivers\mbae64.sys
2017-01-10 09:35 - 2017-01-10 09:36 - 54199488 _____ (Malwarebytes ) C:\Users\Micha\Downloads\mb3-setup-consumer-3.0.5.1299(1).exe
2017-01-10 08:39 - 2017-01-10 08:39 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plumbytes Anti-Malware
2017-01-10 08:39 - 2017-01-10 08:39 - 00000000 ____D C:\Program Files\Plumbytes Software
2017-01-10 08:38 - 2017-01-10 08:38 - 00881904 _____ C:\Users\Micha\Downloads\antimalwaresetup.exe
2017-01-09 19:19 - 2017-01-09 19:19 - 00041077 _____ C:\Users\Micha\Desktop\Addition.txt
2017-01-09 15:57 - 2017-01-10 20:53 - 00041703 _____ C:\Users\Micha\Downloads\Addition.txt
2017-01-09 15:55 - 2017-01-12 10:47 - 00031700 _____ C:\Users\Micha\Downloads\FRST.txt
2017-01-09 15:55 - 2017-01-12 10:46 - 00000000 ____D C:\FRST
2017-01-09 15:54 - 2017-01-09 15:54 - 02419200 _____ (Farbar) C:\Users\Micha\Downloads\FRST64.exe
2017-01-05 20:02 - 2017-01-05 20:02 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk
2017-01-05 20:02 - 2017-01-05 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-01-05 00:41 - 2015-07-16 20:12 - 06131200 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2017-01-05 00:41 - 2015-07-16 20:12 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2017-01-05 00:41 - 2015-07-16 20:12 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 07077376 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 01057792 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2017-01-05 00:41 - 2015-07-11 14:15 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2017-01-04 19:30 - 2015-12-20 19:50 - 03180544 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2017-01-04 19:30 - 2015-12-20 19:50 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2017-01-04 19:30 - 2015-12-20 15:08 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2017-01-04 19:29 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2017-01-04 15:35 - 2017-01-04 15:35 - 00021286 _____ C:\Users\Micha\Desktop\scan malebyte 04012017.txt
2017-01-04 15:08 - 2017-01-04 15:08 - 54199488 _____ (Malwarebytes ) C:\Users\Micha\Downloads\mb3-setup-consumer-3.0.5.1299.exe
2017-01-04 13:53 - 2017-01-04 13:53 - 13425152 _____ (ReviverSoft) C:\Users\Micha\Downloads\DriverReviverSetup_ppc(2).exe
2017-01-04 10:30 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2017-01-04 10:30 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2017-01-04 10:30 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2017-01-04 10:30 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2017-01-04 10:30 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2017-01-04 10:30 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2017-01-04 10:30 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2017-01-04 10:30 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2017-01-04 10:30 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2017-01-04 10:30 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2017-01-04 10:28 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2017-01-04 10:28 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbGD.sys
2017-01-04 10:28 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2017-01-04 10:28 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2017-01-04 10:25 - 2015-08-05 18:56 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\icaapi.dll
2017-01-04 10:25 - 2015-08-05 18:06 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2017-01-04 09:59 - 2017-01-04 09:59 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ICCWDT_01009.Wdf
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\kbdgeoqw.dll
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZEL.DLL
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZE.DLL
2017-01-04 09:25 - 2015-12-16 19:48 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZE.DLL
2017-01-04 09:25 - 2015-12-16 19:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\kbdgeoqw.dll
2017-01-04 09:25 - 2015-12-16 19:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZEL.DLL
2017-01-04 02:04 - 2017-01-04 02:04 - 03279864 _____ (SPAMfighter ApS) C:\Users\Micha\Downloads\DRIVERfighter_Web(1).exe
2017-01-04 01:18 - 2017-01-04 10:38 - 00013920 _____ C:\windows\system32\Drivers\SWDUMon.sys
2017-01-04 01:18 - 2017-01-04 01:18 - 00000000 ____D C:\Users\Micha\AppData\Local\Downloaded Installers
2017-01-04 01:18 - 2017-01-04 01:18 - 00000000 ____D C:\ProgramData\SlimWare Utilities Inc
2017-01-04 01:03 - 2017-01-04 01:04 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Fighters
2017-01-04 01:02 - 2017-01-04 02:18 - 00000000 ____D C:\ProgramData\Fighters
2017-01-04 01:00 - 2017-01-04 01:01 - 03279864 _____ (SPAMfighter ApS) C:\Users\Micha\Downloads\DRIVERfighter_Web.exe
2017-01-04 00:56 - 2017-01-04 14:12 - 00000000 ____D C:\Program Files\ReviverSoft
2017-01-04 00:54 - 2017-01-04 00:55 - 13425152 _____ (ReviverSoft) C:\Users\Micha\Downloads\DriverReviverSetup_ppc(1).exe
2016-12-30 10:41 - 2016-12-30 10:41 - 00178564 _____ C:\Users\Micha\Downloads\HERMES_label_2016-12-30_10_40_52.pdf
2016-12-30 10:35 - 2016-12-30 10:35 - 00178968 _____ C:\Users\Micha\Downloads\HERMES_label_2016-12-30_10_33_49.pdf
2016-12-24 23:14 - 2016-12-24 23:14 - 00025199 _____ C:\Users\Micha\Documents\freelancer200855.vcf
2016-12-24 10:33 - 2012-06-01 06:39 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\wamregps.dll
2016-12-24 10:33 - 2012-06-01 06:36 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\iisRtl.dll
2016-12-24 10:33 - 2012-06-01 06:36 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\iisrstap.dll
2016-12-24 10:33 - 2012-06-01 06:35 - 00060928 _____ (Microsoft Corporation) C:\windows\system32\ahadmin.dll
2016-12-24 10:33 - 2012-06-01 06:34 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\admwprox.dll
2016-12-24 10:33 - 2012-06-01 06:33 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\iisreset.exe
2016-12-24 10:33 - 2012-06-01 05:40 - 00010752 _____ (Microsoft Corporation) C:\windows\SysWOW64\wamregps.dll
2016-12-24 10:33 - 2012-06-01 05:37 - 00154624 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisRtl.dll
2016-12-24 10:33 - 2012-06-01 05:37 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisrstap.dll
2016-12-24 10:33 - 2012-06-01 05:35 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\admwprox.dll
2016-12-24 10:33 - 2012-06-01 05:35 - 00026624 _____ (Microsoft Corporation) C:\windows\SysWOW64\ahadmin.dll
2016-12-24 10:33 - 2012-06-01 05:34 - 00015360 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisreset.exe
2016-12-24 02:30 - 2017-01-11 01:20 - 02210866 ____H C:\Users\Micha\AppData\Local\IconCache.db
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\windows\SysWOW64\BestPractices
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\windows\system32\BestPractices
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\inetpub
2016-12-23 17:25 - 2016-12-23 17:25 - 43886552 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\SkypeSetupFull(2).exe
2016-12-23 17:25 - 2016-12-23 17:25 - 00003142 _____ C:\windows\System32\Tasks\{42239007-962A-405B-897B-E4E0207270AF}
2016-12-23 17:23 - 2016-12-23 17:24 - 01463424 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\skypesetup.exe
2016-12-23 16:13 - 2017-01-03 14:27 - 00524288 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TMContainer00000000000000000001.regtrans-ms
2016-12-23 16:13 - 2017-01-03 14:27 - 00065536 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TM.blf
2016-12-23 16:13 - 2016-12-23 16:17 - 00524288 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 15:52 - 2016-12-23 15:52 - 00000000 __SHD C:\found.000
2016-12-18 14:28 - 2016-12-18 14:28 - 00000000 ____D C:\Users\Micha\Tracing
2016-12-18 14:25 - 2016-12-18 14:25 - 43872728 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\SkypeSetupFull(1).exe
2016-12-18 14:20 - 2016-12-18 14:20 - 43878872 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\SkypeSetupFull.exe
2016-12-18 14:12 - 2017-01-12 10:48 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Skype
2016-12-18 14:12 - 2016-12-18 14:28 - 00000000 ____D C:\Users\Micha\AppData\Local\Skype
2016-12-18 11:45 - 2016-12-18 11:45 - 00003202 _____ C:\windows\System32\Tasks\{7C15C6ED-AB8F-4479-AB67-B366BCA58406}
2016-12-18 11:00 - 2017-01-04 15:36 - 00000000 ____D C:\Users\Micha\AppData\Local\SlimWare Utilities Inc
2016-12-18 11:00 - 2016-12-18 11:00 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2016-12-16 09:55 - 2016-12-16 09:57 - 00000000 ____D C:\Users\Micha\Documents\Fax
2016-12-16 09:55 - 2016-12-16 09:55 - 00000000 ___RD C:\Users\Micha\Documents\Scanned Documents
2016-12-16 01:19 - 2016-12-16 01:19 - 00307001 _____ C:\Users\Micha\Downloads\urkunden(2).jpeg
2016-12-15 19:15 - 2016-12-15 19:15 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2016-12-15 19:13 - 2016-12-15 19:13 - 02586928 _____ C:\Users\Micha\Downloads\Adaware_Installer(7).exe
2016-12-14 03:58 - 2016-11-21 19:12 - 00109568 _____ (Microsoft Corporation) C:\windows\system32\hlink.dll
2016-12-14 03:58 - 2016-11-20 17:19 - 00084992 _____ (Microsoft Corporation) C:\windows\SysWOW64\hlink.dll
2016-12-14 03:58 - 2016-11-20 15:07 - 00467392 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2016-12-14 03:58 - 2016-11-17 17:41 - 00370920 _____ (Microsoft Corporation) C:\windows\system32\clfs.sys
2016-12-14 03:58 - 2016-11-15 00:27 - 00394448 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2016-12-14 03:58 - 2016-11-14 23:39 - 00346320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2016-12-14 03:58 - 2016-11-12 20:48 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2016-12-14 03:58 - 2016-11-12 20:48 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2016-12-14 03:58 - 2016-11-12 20:28 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2016-12-14 03:58 - 2016-11-12 20:26 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2016-12-14 03:58 - 2016-11-12 20:26 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2016-12-14 03:58 - 2016-11-12 20:25 - 00576000 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2016-12-14 03:58 - 2016-11-12 20:25 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2016-12-14 03:58 - 2016-11-12 20:21 - 02896384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-12-14 03:58 - 2016-11-12 20:15 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2016-12-14 03:58 - 2016-11-12 20:14 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2016-12-14 03:58 - 2016-11-12 20:09 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2016-12-14 03:58 - 2016-11-12 20:08 - 25759744 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-12-14 03:58 - 2016-11-12 20:08 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2016-12-14 03:58 - 2016-11-12 20:08 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2016-12-14 03:58 - 2016-11-12 20:07 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2016-12-14 03:58 - 2016-11-12 20:07 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2016-12-14 03:58 - 2016-11-12 19:56 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2016-12-14 03:58 - 2016-11-12 19:53 - 06049280 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-12-14 03:58 - 2016-11-12 19:52 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2016-12-14 03:58 - 2016-11-12 19:47 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2016-12-14 03:58 - 2016-11-12 19:41 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2016-12-14 03:58 - 2016-11-12 19:40 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2016-12-14 03:58 - 2016-11-12 19:35 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2016-12-14 03:58 - 2016-11-12 19:34 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2016-12-14 03:58 - 2016-11-12 19:31 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2016-12-14 03:58 - 2016-11-12 19:30 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2016-12-14 03:58 - 2016-11-12 19:29 - 00498688 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2016-12-14 03:58 - 2016-11-12 19:29 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2016-12-14 03:58 - 2016-11-12 19:29 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2016-12-14 03:58 - 2016-11-12 19:28 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2016-12-14 03:58 - 2016-11-12 19:27 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2016-12-14 03:58 - 2016-11-12 19:20 - 02287616 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-12-14 03:58 - 2016-11-12 19:20 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2016-12-14 03:58 - 2016-11-12 19:19 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2016-12-14 03:58 - 2016-11-12 19:17 - 20302848 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-12-14 03:58 - 2016-11-12 19:15 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2016-12-14 03:58 - 2016-11-12 19:14 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2016-12-14 03:58 - 2016-11-12 19:14 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2016-12-14 03:58 - 2016-11-12 19:14 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2016-12-14 03:58 - 2016-11-12 19:14 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2016-12-14 03:58 - 2016-11-12 19:11 - 00725504 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2016-12-14 03:58 - 2016-11-12 19:10 - 00806912 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2016-12-14 03:58 - 2016-11-12 19:08 - 02131456 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2016-12-14 03:58 - 2016-11-12 19:08 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2016-12-14 03:58 - 2016-11-12 19:03 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2016-12-14 03:58 - 2016-11-12 18:57 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-12-14 03:58 - 2016-11-12 18:56 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2016-12-14 03:58 - 2016-11-12 18:52 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2016-12-14 03:58 - 2016-11-12 18:51 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2016-12-14 03:58 - 2016-11-12 18:49 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2016-12-14 03:58 - 2016-11-12 18:47 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2016-12-14 03:58 - 2016-11-12 18:41 - 15257088 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-12-14 03:58 - 2016-11-12 18:40 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2016-12-14 03:58 - 2016-11-12 18:38 - 00693248 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2016-12-14 03:58 - 2016-11-12 18:37 - 04608000 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-12-14 03:58 - 2016-11-12 18:36 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2016-12-14 03:58 - 2016-11-12 18:36 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2016-12-14 03:58 - 2016-11-12 18:35 - 02920960 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-12-14 03:58 - 2016-11-12 18:21 - 13653504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-12-14 03:58 - 2016-11-12 18:20 - 01543680 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-12-14 03:58 - 2016-11-12 18:11 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2016-12-14 03:58 - 2016-11-12 18:05 - 02444800 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-12-14 03:58 - 2016-11-12 18:02 - 01312256 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-12-14 03:58 - 2016-11-12 18:02 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2016-12-14 03:58 - 2016-11-10 17:32 - 01009152 _____ (Microsoft Corporation) C:\windows\system32\user32.dll
2016-12-14 03:58 - 2016-11-10 17:19 - 00833024 _____ (Microsoft Corporation) C:\windows\SysWOW64\user32.dll
2016-12-14 03:58 - 2016-11-09 17:41 - 00114408 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2016-12-14 03:58 - 2016-11-09 17:33 - 03244032 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2016-12-14 03:58 - 2016-11-09 17:33 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2016-12-14 03:58 - 2016-11-09 17:33 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2016-12-14 03:58 - 2016-11-09 17:33 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2016-12-14 03:58 - 2016-11-09 17:33 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\msimsg.dll
2016-12-14 03:58 - 2016-11-09 17:33 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2016-12-14 03:58 - 2016-11-09 17:17 - 02365440 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2016-12-14 03:58 - 2016-11-09 17:17 - 01806848 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2016-12-14 03:58 - 2016-11-09 17:17 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
2016-12-14 03:58 - 2016-11-09 17:17 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimsg.dll
2016-12-14 03:58 - 2016-11-09 17:17 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2016-12-14 03:58 - 2016-11-09 17:02 - 00128512 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
2016-12-14 03:58 - 2016-11-09 16:55 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
2016-12-14 03:58 - 2016-11-06 17:33 - 00404992 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2016-12-14 03:58 - 2016-11-06 17:16 - 00312832 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2016-12-14 03:58 - 2016-11-06 17:01 - 03219456 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2016-12-14 03:58 - 2016-10-27 16:33 - 00802304 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2016-12-14 03:58 - 2016-10-27 16:20 - 00627712 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2016-12-14 03:58 - 2016-10-11 16:40 - 00631176 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2016-12-14 03:58 - 2016-10-11 16:37 - 05547752 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2016-12-14 03:58 - 2016-10-11 16:37 - 00706792 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2016-12-14 03:58 - 2016-10-11 16:34 - 01732864 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2016-12-14 03:58 - 2016-10-11 16:32 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2016-12-14 03:58 - 2016-10-11 16:32 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2016-12-14 03:58 - 2016-10-11 16:32 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2016-12-14 03:58 - 2016-10-11 16:32 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2016-12-14 03:58 - 2016-10-11 16:32 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\nlsbres.dll
2016-12-14 03:58 - 2016-10-11 16:32 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2016-12-14 03:58 - 2016-10-11 16:32 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2016-12-14 03:58 - 2016-10-11 16:32 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2016-12-14 03:58 - 2016-10-11 16:32 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:24 - 04000488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2016-12-14 03:58 - 2016-10-11 16:24 - 03944680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2016-12-14 03:58 - 2016-10-11 16:21 - 01314112 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlsbres.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 16:03 - 00148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2016-12-14 03:58 - 2016-10-11 16:03 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2016-12-14 03:58 - 2016-10-11 16:03 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2016-12-14 03:58 - 2016-10-11 15:59 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2016-12-14 03:58 - 2016-10-11 15:59 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2016-12-14 03:58 - 2016-10-11 15:55 - 00346112 _____ (Microsoft Corporation) C:\windows\system32\bcdedit.exe
2016-12-14 03:58 - 2016-10-11 15:55 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2016-12-14 03:58 - 2016-10-11 15:51 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2016-12-14 03:58 - 2016-10-11 15:51 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2016-12-14 03:58 - 2016-10-11 15:51 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2016-12-14 03:58 - 2016-10-11 15:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2016-12-14 03:58 - 2016-10-11 15:50 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 15:50 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 15:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 15:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-12-14 03:58 - 2016-10-11 14:18 - 00419648 _____ C:\windows\SysWOW64\locale.nls
2016-12-14 03:58 - 2016-10-11 14:17 - 00419648 _____ C:\windows\system32\locale.nls
2016-12-14 03:58 - 2016-10-08 14:06 - 00633296 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2016-12-14 03:58 - 2016-10-04 16:31 - 01483264 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2016-12-14 03:58 - 2016-10-04 16:31 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2016-12-14 03:58 - 2016-10-04 16:31 - 00190976 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2016-12-14 03:58 - 2016-10-04 16:31 - 00141824 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2016-12-14 03:58 - 2016-10-04 16:13 - 01176064 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2016-12-14 03:58 - 2016-10-04 16:13 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2016-12-14 03:58 - 2016-10-04 16:13 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2016-12-14 03:58 - 2016-10-04 16:13 - 00106496 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2016-12-13 11:53 - 2016-12-13 11:53 - 00180102 _____ C:\Users\Micha\Downloads\HERMES_label_2016-12-13_11_37_40(1).pdf
2016-12-13 11:38 - 2016-12-13 11:38 - 00180102 _____ C:\Users\Micha\Downloads\HERMES_label_2016-12-13_11_37_40.pdf

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-01-12 10:17 - 2014-12-14 15:17 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2017-01-12 09:08 - 2016-11-22 11:54 - 00000000 ____D C:\Users\Micha\AppData\LocalLow\Mozilla
2017-01-12 08:01 - 2009-07-14 05:45 - 00024432 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-12 08:01 - 2009-07-14 05:45 - 00024432 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-11 21:01 - 2014-12-19 21:37 - 00010240 _____ C:\Users\Micha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-01-11 12:42 - 2015-07-15 11:33 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-11 12:40 - 2015-01-21 09:55 - 00004476 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2017-01-11 12:38 - 2015-05-27 15:08 - 00000000 ____D C:\ProgramData\panda_url_filtering
2017-01-11 01:40 - 2015-07-26 08:18 - 00000000 ____D C:\Users\Micha\AppData\LocalLow\360WD
2017-01-11 01:29 - 2015-02-27 20:57 - 00000000 ____D C:\Users\Micha\AppData\Local\FreePDF_XP
2017-01-11 01:27 - 2013-07-31 21:55 - 00000000 ____D C:\ProgramData\Realtek
2017-01-11 01:26 - 2016-12-05 21:00 - 00002312 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2017-01-11 01:25 - 2009-07-14 06:08 - 00032640 _____ C:\windows\Tasks\SCHEDLGU.TXT
2017-01-11 01:25 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-01-11 00:03 - 2014-12-14 16:17 - 00000000 ____D C:\windows\system32\MRT
2017-01-11 00:02 - 2014-12-20 03:20 - 135657872 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2017-01-10 16:17 - 2014-12-14 15:17 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2017-01-10 16:17 - 2014-12-14 15:17 - 00000000 ____D C:\windows\system32\Macromed
2017-01-10 16:17 - 2013-07-31 22:22 - 00802904 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2017-01-10 16:17 - 2013-07-31 22:22 - 00144472 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-01-10 16:17 - 2013-07-31 22:22 - 00000000 ____D C:\windows\SysWOW64\Macromed
2017-01-10 09:37 - 2016-11-06 01:54 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-01-09 15:53 - 2015-09-21 09:06 - 00000000 __SHD C:\$360Section
2017-01-09 15:53 - 2015-09-02 15:13 - 00000000 ____D C:\ProgramData\360Quarant
2017-01-05 20:02 - 2013-07-31 22:29 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-01-05 20:02 - 2013-07-31 22:28 - 00000000 ____D C:\ProgramData\Skype
2017-01-04 13:31 - 2014-12-14 15:54 - 00000000 ____D C:\Program Files (x86)\chip
2017-01-04 10:35 - 2009-07-14 05:45 - 00313104 _____ C:\windows\system32\FNTCACHE.DAT
2017-01-04 10:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\PolicyDefinitions
2017-01-04 10:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\inf
2017-01-04 10:31 - 2013-07-31 21:39 - 01687534 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2017-01-04 10:31 - 2013-07-31 19:42 - 00738178 _____ C:\windows\system32\perfh007.dat
2017-01-04 10:31 - 2013-07-31 19:42 - 00160894 _____ C:\windows\system32\perfc007.dat
2017-01-04 10:31 - 2009-07-14 06:13 - 01687534 _____ C:\windows\system32\PerfStringBackup.INI
2017-01-04 10:31 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\inetsrv
2017-01-04 09:47 - 2016-06-30 15:21 - 00000000 ____D C:\Users\Micha\AppData\Local\ElevatedDiagnostics
2017-01-04 09:01 - 2015-07-24 19:27 - 00000000 ____D C:\ProgramData\360safe
2017-01-04 02:21 - 2014-12-14 00:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2017-01-04 02:05 - 2009-07-14 03:34 - 00000568 _____ C:\windows\win.ini
2017-01-03 17:08 - 2015-09-24 19:26 - 00000356 _____ C:\Users\Micha\Desktop\Zitate.txt
2016-12-28 22:36 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\migration
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\inetsrv
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\migration
2016-12-24 23:11 - 2014-12-19 22:43 - 00000000 ____D C:\Users\Micha\Documents\Youcam
2016-12-24 20:13 - 2009-07-14 04:18 - 00000000 __SHD C:\$Recycle.Bin
2016-12-24 00:58 - 2014-12-31 14:21 - 00000000 ____D C:\ProgramData\Freemake
2016-12-24 00:58 - 2014-12-31 14:21 - 00000000 ____D C:\Program Files (x86)\Freemake
2016-12-24 00:48 - 2015-07-30 22:30 - 00000000 _RSHD C:\360SANDBOX
2016-12-24 00:00 - 2009-07-14 04:20 - 00000000 __RSD C:\windows\assembly
2016-12-24 00:00 - 2009-07-14 04:20 - 00000000 ____D C:\windows\Microsoft.NET
2016-12-23 23:52 - 2014-12-14 00:06 - 00000000 ___RD C:\Users\Micha\Videos
2016-12-23 23:20 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2016-12-23 23:18 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-12-23 23:18 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Microsoft Games
2016-12-23 23:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\Drivers\etc
2016-12-23 23:18 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-12-23 21:47 - 2016-01-21 10:17 - 00000000 ____D C:\Program Files (x86)\pandasecuritytb
2016-12-23 19:30 - 2009-07-14 04:20 - 00000000 ____D C:\windows\AppPatch
2016-12-23 15:29 - 2016-11-02 17:00 - 00524288 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 15:29 - 2016-11-02 17:00 - 00065536 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TM.blf
2016-12-23 15:02 - 2016-11-02 17:00 - 00524288 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TMContainer00000000000000000001.regtrans-ms
2016-12-18 14:28 - 2014-12-14 00:06 - 00000000 ____D C:\Users\Micha\AppData\Local\Microsoft
2016-12-18 14:28 - 2014-12-14 00:06 - 00000000 ____D C:\Users\Micha
2016-12-18 12:19 - 2014-12-14 00:07 - 00072008 _____ C:\Users\Micha\AppData\Local\GDIPFONTCACHEV1.DAT
2016-12-18 12:13 - 2015-05-27 15:05 - 00000000 ____D C:\Program Files (x86)\Panda Security
2016-12-18 12:07 - 2015-05-27 15:03 - 00000000 ____D C:\ProgramData\Panda Security
2016-12-18 12:06 - 2015-05-27 15:06 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Panda Security
2016-12-18 11:00 - 2009-07-14 04:20 - 00000000 ___RD C:\Users\Public\Documents
2016-12-18 01:40 - 2014-12-14 00:06 - 00000000 ___RD C:\Users\Micha\Pictures
2016-12-17 01:20 - 2014-12-21 14:52 - 00003542 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-12-17 01:20 - 2014-12-21 14:52 - 00003414 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-12-15 22:58 - 2016-12-07 07:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-12-15 22:58 - 2014-12-14 14:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-12-15 22:00 - 2014-12-27 00:03 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Apple Computer
2016-12-15 19:17 - 2015-01-05 13:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2016-12-15 19:15 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files
2016-12-15 11:19 - 2014-12-21 14:53 - 00002197 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-12-15 11:19 - 2014-12-21 14:53 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-12-15 03:29 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\it-IT
2016-12-15 03:29 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\fr-FR
2016-12-15 03:29 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\es-ES
2016-12-15 03:29 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\en-US
2016-12-15 03:29 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\it-IT
2016-12-15 03:29 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\fr-FR
2016-12-15 03:29 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\es-ES
2016-12-15 03:29 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\en-US
2016-12-15 03:29 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\Boot
2016-12-15 03:29 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Internet Explorer
2016-12-15 03:29 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files (x86)\Internet Explorer

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2014-09-01 09:18 - 2014-09-01 09:18 - 0001248 _____ () C:\Users\Micha\AppData\Roaming\FODX
2014-12-14 00:06 - 2017-01-12 08:48 - 0077464 _____ () C:\Users\Micha\AppData\Local\BTServer.log
2014-12-19 21:37 - 2017-01-11 21:01 - 0010240 _____ () C:\Users\Micha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Einige Dateien in TEMP:
====================
C:\Users\Micha\AppData\Local\Temp\DllMonoCtrl.dll


==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert

LastRegBack: 2017-01-03 14:36

==================== Ende von FRST.txt ============================

hoffe hier ist noch etwas zu retten, danke MS-Michael

milkit54 13.01.2017 00:06

Teil 2 Addition zu MSI CR70 erkennt Kameras nicht
 
hier kommt Teil 2
Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 11-01-2017
durchgeführt von Micha (12-01-2017 10:48:56)
Gestartet von C:\Users\Micha\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2014-12-13 23:06:40)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2198626584-3468660724-23365673-500 - Administrator - Disabled)
Gast (S-1-5-21-2198626584-3468660724-23365673-501 - Limited - Disabled)
Micha (S-1-5-21-2198626584-3468660724-23365673-1000 - Administrator - Enabled) => C:\Users\Micha

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Ad-Aware Antivirus (Enabled - Up to date) {B0CC18C6-E527-6EE6-874C-9D19920E5619}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: 360 Total Security (Enabled - Up to date) {2B66EE1E-E5C8-C2F7-648F-4E55AC68D37D}
AS: 360 Total Security (Enabled - Up to date) {90070FFA-C3F2-CD79-5E3F-7527D7EF99C0}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Ad-Aware Antivirus (Enabled - Up to date) {0BADF922-C31D-6168-BDFC-A66BE9891CA4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

360 Total Security (HKLM-x32\...\360TotalSecurity) (Version: 8.8.0.1020 - 360 Security Center)
Ad-Aware Antivirus (HKLM\...\{AD9CEBD6-442D-4979-9D1D-E1050F2E272D}_AdAwareUpdater) (Version: 11.15.1046.10613 - Lavasoft)
Ad-Aware Web Companion (x32 Version: 1.1.844.1586 - Lavasoft) Hidden
AdAwareInstaller (Version: 11.15.1046.10613 - Lavasoft) Hidden
AdAwareUpdater (Version: 11.15.1046.10613 - Lavasoft) Hidden
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.023.20053 - Adobe Systems Incorporated)
Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.194 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated)
AntimalwareEngine (Version: 3.0.129.0 - Lavasoft) Hidden
Apple Application Support (32-Bit) (HKLM-x32\...\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BurnRecovery (HKLM-x32\...\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 3.0.1103.1801 - Micro-Star International Co., Ltd.)
Camera RAW Plug-In for EPSON Creativity Suite (HKLM-x32\...\{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}) (Version: 2.1.0.0 - )
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.31 - Cliqz.com)
concept/design onlineTV 11 (HKLM-x32\...\{8A4C3184-DA2F-4553-BF61-83F5690C3048}_is1) (Version: 11.0.0.0 - concept/design GmbH)
CX4300_5500_DX4400 Handbuch (HKLM-x32\...\CX4300_5500_DX4400 Handbuch) (Version:  - )
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.4612 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Desktopicon amazon.de (HKLM\...\DesktopIconAmazon) (Version: 1.0.1 - )
DriverUpdate (HKLM-x32\...\DriverUpdate) (Version: 2.7.3 - Slimware Utilities Holdings, Inc.)
DriverUpdate (x32 Version: 2.7.3 - Slimware Utilities Holdings, Inc.) Hidden
EPSON Attach To Email (HKLM-x32\...\InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON)
EPSON Attach To Email (x32 Version: 1.01.0000 - SEIKO EPSON) Hidden
EPSON Copy Utility 3 (HKLM-x32\...\{67EDD823-135A-4D59-87BD-950616D6E857}) (Version: 3.2.0.0 - )
EPSON File Manager (HKLM-x32\...\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}) (Version: 1.3.0.0 - )
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
EPSON Scan Assistant (HKLM-x32\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - )
EPSON SX100 Series Printer Uninstall (HKLM\...\EPSON SX100 Series) (Version:  - SEIKO EPSON Corporation)
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version:  - SEIKO EPSON Corporation)
ETDWare PS/2-X64 11.13.2.4_WHQL (HKLM\...\Elantech) (Version: 11.13.2.4 - ELAN Microelectronic Corp.)
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}) (Version: 2.1.27.0 - MAGIX AG)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
FreePDF (Remove only) (HKLM-x32\...\FreePDF_XP) (Version:  - )
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
GPL Ghostscript (HKLM\...\GPL Ghostscript 9.07) (Version: 9.07 - Artifex Software Inc.)
GPL Ghostscript (HKLM-x32\...\GPL Ghostscript 9.15) (Version: 9.15 - Artifex Software Inc.)
iCloud (HKLM\...\{29AAC3D3-23FC-496D-8266-0E3833686758}) (Version: 6.0.2.10 - Apple Inc.)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1310 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3186 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.5.0.1066 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.6 (HKLM\...\{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.6.2.0 - Intel)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
LavasoftTcpService (x32 Version: 2.2.9.5 - Lavasoft) Hidden
MAGIX Music Maker 16 Download-Version (HKLM-x32\...\MAGIX Music Maker 16 Download-Version D) (Version: 16.0.3.0 - MAGIX AG)
MAGIX Online Druck Service (HKLM-x32\...\MAGIX Online Druck Service D) (Version: 3.4.3.0 - MAGIX AG)
MAGIX Screenshare (HKLM-x32\...\MAGIX Screenshare D) (Version: 4.3.6.1987 - MAGIX AG)
MAGIX Speed burnR (HKLM-x32\...\MAGIX Speed burnR D) (Version: 7.0.2.6 - MAGIX AG)
Malwarebytes Version 3.0.5.1299 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mobile Partner (HKLM-x32\...\Mobile Partner) (Version: 16.002.03.01.40 - Huawei Technologies Co.,Ltd)
Movavi Video Suite 14 (HKLM-x32\...\Movavi Video Suite 14) (Version: 14.0.1 - Movavi)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 50.1.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 de)) (Version: 50.1.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla)
MSI Battery Calibration (HKLM-x32\...\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.0.1 - Micro-Star International Co., Ltd.)
MSI HOUSE (HKLM-x32\...\{DA5597C9-9216-44FF-9670-D1E48817B998}) (Version: 10.07.1601 - MSI)
MSI Software Install (HKLM-x32\...\{332EBFE0-C39E-42D1-99B5-ABBBECAD71B6}) (Version: 4.0.1105.1701 - Micro-Star International Co., Ltd.)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Norton Anti-Theft (HKLM-x32\...\NAT) (Version: 1.6.0.17 - Symantec Corporation)
Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.7.0.24 - Symantec Corporation)
Norton Online Backup ARA (x32 Version: 4.3.0.14 - Symantec Corporation) Hidden
Norton PC Checkup (HKLM-x32\...\NortonPCCheckup) (Version: 2.0.18.16 - Symantec Corporation)
OpenOffice 4.1.2 (HKLM-x32\...\{F5CAB1AF-7B1A-4CEC-B829-A3F699473AE1}) (Version: 4.12.9782 - Apache Software Foundation)
Panda Security Toolbar (HKLM-x32\...\pandasecuritytb) (Version: 4.3.1.9 - Panda Security and Visicom Media Inc.)
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.51.17865 - pdfforge GmbH)
PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Edit Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 View Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.1 - pdfforge)
Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.13 - Qualcomm Atheros Communications Inc.)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.728.728.042813 - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6914 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0212 - )
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: 1.90 - Ghostgum Software Pty Ltd)
SCM (HKLM\...\{CA85D7A7-6B45-4011-9BCC-C01F31EDE157}) (Version: 14.013.07054 -  )
Shotcut (HKLM-x32\...\Shotcut) (Version:  - )
Skype™ 7.30 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.30.105 - Skype Technologies S.A.)
SoftMaker FreeOffice (HKLM-x32\...\{8EBB8452-274B-465D-8324-00B0832FBB02}) (Version: 1.0.3475 - SoftMaker Software GmbH)
Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.017 - MSI)
Sweepi 5.4.00 (HKLM-x32\...\Sweepi_is1) (Version: 5.4.00 - YooApplications)
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
Web Companion (HKLM-x32\...\{D5116390-5C95-4FEA-A719-78C3C8B5DFB5}_WebCompanion) (Version: 1.1.844.1586 - Lavasoft)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinZip 19.0 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E4}) (Version: 19.0.11293 - WinZip Computing, S.L. )

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {17608ADD-35B5-4F2A-A369-E67C96C0B20E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {2B68F8A1-F7BA-4699-885D-EAF51F2DBD90} - System32\Tasks\{551F8A14-3EE5-4B8B-83D3-D11EB5BC5F15} => pcalua.exe -a "C:\Program Files (x86)\FreePDF_XP\setup.exe" -d "C:\Program Files (x86)\Mozilla Firefox" -c C:\Users\Micha\AppData\Local\Temp\Paketschein-14.pdf <==== ACHTUNG
Task: {3CDF7212-D471-42F4-A121-ED4D70251682} - System32\Tasks\{7C15C6ED-AB8F-4479-AB67-B366BCA58406} => pcalua.exe -a "C:\Program Files (x86)\DriverUpdate\UninstallStub.exe" -c --log {a9888f42-bffe-4aca-ac10-51983972c2df}
Task: {3DA3586E-C068-4460-B103-15DDD7C51B40} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-10] (Adobe Systems Incorporated)
Task: {3E09C0A2-D6E6-407F-A239-AAAECEF79B78} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {3F283151-7529-496F-9366-FCAEC83C2694} - System32\Tasks\1215tbUpdateInfo => C:\ProgramData\Avg_Update_1215tb\1215tb_{4D479988-B227-4153-A15F-3D6D13E85735}.exe
Task: {58A9DC7B-AC64-4449-B51A-1CA3922D1961} - System32\Tasks\Norton Online Backup ARA => C:\Program Files (x86)\Norton Online Backup ARA\Engine\4.3.0.14\\Ara.exe [2013-08-27] (Symantec Corporation)
Task: {63050248-0821-4CF1-A0FA-3D7C370A627F} - System32\Tasks\{42239007-962A-405B-897B-E4E0207270AF} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.24.0.104&amp;LastError=404
Task: {96FEB751-76F6-4B79-B85A-B188D39EBB02} - System32\Tasks\{DDE7AD7B-E373-4700-9749-EFD63E11B429} => C:\Windows\twain_32\escndv\escndv.exe [2008-04-06] (SEIKO EPSON CORP.)
Task: {B2A759E8-D7A6-40F4-8583-1B21178BF297} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: {CB02601F-EC46-425D-981C-29E9B6680ED3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {DF814115-C649-4F46-9705-DDBEC44F373C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {E499296A-F20A-4ACE-9CD0-242A1F09B9A3} - System32\Tasks\{129E23B6-40C3-4E2D-BA39-481FE58B2A62} => C:\Program Files\PDFCreator\PDFCreator.exe [2014-12-16] (pdfforge)
Task: {FB0D8A3E-E462-456A-A960-0E05DB4FE8BC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-01-09 01:19 - 2012-06-21 07:25 - 00113152 _____ () C:\windows\System32\redmon64.dll
2013-07-31 21:55 - 2013-04-26 00:32 - 00047104 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
2016-12-15 13:02 - 2016-12-15 13:02 - 00630976 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareService.exe
2016-12-15 13:06 - 2016-12-15 13:06 - 00122104 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\boost_thread-vc140-mt-1_61.dll
2016-12-15 13:06 - 2016-12-15 13:06 - 00030968 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\boost_system-vc140-mt-1_61.dll
2016-12-15 13:06 - 2016-12-15 13:06 - 00039672 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\boost_chrono-vc140-mt-1_61.dll
2016-12-15 13:06 - 2016-12-15 13:06 - 00067832 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\boost_date_time-vc140-mt-1_61.dll
2016-12-15 13:06 - 2016-12-15 13:06 - 00145144 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\boost_filesystem-vc140-mt-1_61.dll
2016-12-15 13:06 - 2016-12-15 13:06 - 00733432 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\boost_log-vc140-mt-1_61.dll
2016-12-15 13:06 - 2016-12-15 13:06 - 00525048 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\boost_locale-vc140-mt-1_61.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 11504888 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareServiceKernel.dll
2016-12-15 13:06 - 2016-12-15 13:06 - 03713272 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\RCF.dll
2016-12-15 13:06 - 2016-12-15 13:06 - 01001208 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\boost_regex-vc140-mt-1_61.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01061624 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareActivation.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 00634616 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareApplicationUpdater.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 00843000 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareGamingMode.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 00120568 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareReset.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 00142584 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareTime.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01025272 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareDefinitionsUpdater.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 00904440 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareDefinitionsUpdaterScheduler.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01468664 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareIgnoreList.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 00252664 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareQuarantine.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01644280 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareAntiMalwareEngine.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 00223992 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareAntiRootkitEngine.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01192184 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareScannerHistory.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01370360 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareScanner.dll
2016-12-15 13:06 - 2016-12-15 13:06 - 00039672 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\boost_timer-vc140-mt-1_61.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01030904 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareScannerScheduler.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01212152 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareRealTimeProtection.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 02879736 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareIncompatibles.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01524472 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareAntiSpam.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01456376 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareAntiPhishing.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 03462904 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareParentalControl.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01599224 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareWebProtection.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01339640 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareEmailProtection.dll
2016-12-15 13:06 - 2016-12-15 13:06 - 00073464 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\boost_iostreams-vc140-mt-1_61.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01645816 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareNetworkProtection.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01042680 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwarePromo.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 00475384 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareFeedback.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 03165944 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareThreatWorkAlliance.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01325304 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwarePinCode.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01044216 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareNotice.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01597688 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareAvcEngine.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01496312 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareRealTimeProtectionHistory.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 01380088 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareStatistics.dll
2014-12-16 12:08 - 2014-12-16 12:08 - 00015208 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
2014-12-16 12:08 - 2014-12-16 12:08 - 00012144 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Service.Logger.dll
2014-12-16 12:08 - 2014-12-16 12:08 - 00032616 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WcfService.dll
2017-01-10 09:37 - 2016-12-14 12:55 - 02259232 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-01-10 09:37 - 2016-12-14 12:55 - 02813904 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll
2017-01-10 09:37 - 2016-12-14 12:55 - 02247632 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2013-07-31 21:55 - 2013-04-09 22:42 - 00265728 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\SkypePlugin.exe
2016-12-15 13:05 - 2016-12-15 13:05 - 09533688 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareTray.exe
2016-12-15 13:05 - 2016-12-15 13:05 - 02479864 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\HtmlFramework.dll
2016-12-15 13:05 - 2016-12-15 13:05 - 00871672 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareTrayDefaultSkin.dll
2012-05-30 21:15 - 2012-05-30 21:15 - 00404008 _____ () C:\Program Files\Intel\TurboBoost\de\SignalIslandUi.resources.dll
2015-07-24 19:26 - 2016-08-10 11:54 - 01153448 _____ () C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
2015-07-24 19:27 - 2016-08-10 11:54 - 00099240 _____ () C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll
2014-12-16 12:08 - 2014-12-16 12:08 - 00070464 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Utils.dll
2014-12-16 12:08 - 2014-12-16 12:08 - 00171368 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Business.dll
2014-12-16 12:08 - 2014-12-16 12:08 - 00089928 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.adblocker.dll
2014-12-16 12:08 - 2014-12-16 12:08 - 00033136 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Repositories.dll
2014-12-16 12:08 - 2014-12-16 12:08 - 00015696 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Utils.SqlLite.dll
2014-12-16 12:10 - 2014-12-16 12:10 - 00041304 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.PUP.Management.dll
2014-12-16 12:08 - 2014-12-16 12:08 - 00039256 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.CSharp.Utilities.dll
2016-10-05 18:18 - 2016-10-05 18:18 - 01041720 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2016-10-05 18:18 - 2016-10-05 18:18 - 00080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2016-10-05 18:18 - 2016-10-05 18:18 - 00189752 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2015-07-24 19:27 - 2016-08-10 11:54 - 00582056 _____ () C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll
2013-07-31 21:37 - 2013-02-16 00:15 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2015-10-21 15:50 - 2015-10-21 15:50 - 00988160 _____ () C:\Program Files (x86)\OpenOffice 4\program\libxml2.dll
2015-10-21 15:49 - 2015-10-21 15:49 - 00170496 _____ () C:\Program Files (x86)\OpenOffice 4\program\libxslt.dll
2015-10-21 15:49 - 2015-10-21 15:49 - 00136192 _____ () C:\Program Files (x86)\OpenOffice 4\program\libxmlsec-mscrypto.dll
2015-10-21 15:49 - 2015-10-21 15:49 - 00303616 _____ () C:\Program Files (x86)\OpenOffice 4\program\libxmlsec.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LavasoftAdAwareService11 => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LavasoftAdAwareService11 => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1 - 192.168.0.2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [TCP Query User{F5428C65-02FD-4258-9D3B-DBA9131CD043}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{58EAA851-0F4D-4025-A9FA-82AAC4EEC077}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{FC62AAD4-D5DF-4232-B263-4FC654D0457F}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{9D370156-D01D-4231-A5C5-E72B2D7C382D}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{EB01AC34-1000-4725-AB7E-266EF7070BAE}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6AED153C-CE2F-4F79-A73D-5DA437D8EDD9}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{27B32960-48B2-478E-B66F-31E31A65D5F6}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{57A32D00-9BC9-4428-A8F3-767162CDE081}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{4AE2CA5C-F80C-436A-B9FF-2E8E125414F6}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{4B1F3D68-AEF2-4EE3-A176-82754C956CCF}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{535793E5-DA7A-48C6-9675-333B3C13480E}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1A36325C-7D02-4CAE-968A-A8054B57A386}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{EEBD56D9-AD50-4F27-871C-9FFB87C817E6}] => C:\Program Files (x86)\pandasecuritytb\cleanupie.exe
FirewallRules: [{DD826058-D556-4DB6-B195-3CFDAD7FE9C3}] => C:\Program Files (x86)\pandasecuritytb\cleanupie.exe
FirewallRules: [{1B35008A-2B15-4C6A-A7D9-6EF5E4509617}] => C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{933C0AF3-CFB0-49D7-8613-7113DE462D2F}] => C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{4E8E84F9-07C1-415A-A528-90BE6E2BCCBC}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{36E73BFD-7CEF-4516-8259-755DA03A06E5}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{CED2D614-329E-4C55-BAF4-F84F23D9BBB5}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4CAD39BB-8FD9-48ED-9A96-B3DABD7B4683}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{60005B18-84B8-4665-9D35-482C3A16A343}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{2FA7CE91-EAFF-49F9-B2DF-C5687CA4B179}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{72F59172-3120-434F-8648-B19F920FA80F}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{76C646E5-E59E-4079-91C6-6DB2955E5955}] => C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{4DC1F09C-7F6A-457F-B2C1-BF9062AD8B33}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{739F15EC-D12D-44B2-97C9-92DABE022A21}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe

==================== Wiederherstellungspunkte =========================

10-11-2016 06:10:16 Windows Update
26-11-2016 13:55:57 Geplanter Prüfpunkt
27-11-2016 17:27:32 Installed Windows Mobile-Gerätecenter
05-12-2016 20:53:37 AA11
09-12-2016 20:06:44 Removed Visual Studio 2012 x86 Redistributables
09-12-2016 20:08:07 Removed Visual Studio 2012 x64 Redistributables
15-12-2016 03:00:20 Windows Update
15-12-2016 19:14:17 AA11
16-12-2016 01:31:33 Windows Update
18-12-2016 11:42:27 Removed DriverUpdate
18-12-2016 11:45:52 Removed DriverUpdate
23-12-2016 16:08:55 Wiederherstellungsvorgang
23-12-2016 23:16:31 Windows Modules Installer
25-12-2016 00:00:28 Windows Update
03-01-2017 23:19:17 Wiederherstellungsvorgang
04-01-2017 01:02:43 Installed DRIVERfighter.
04-01-2017 02:23:30 Removed DriverUpdate
04-01-2017 09:36:49 Windows Update
04-01-2017 09:58:19 Windows Update
04-01-2017 10:00:56 Windows Update
04-01-2017 10:02:20 Windows Update
04-01-2017 10:26:13 Windows Update
04-01-2017 13:27:41 Removed DriverUpdate
04-01-2017 13:30:28 Removed CHIP Best Deal
04-01-2017 13:44:48 Konfiguriert Camera RAW Plug-In for EPSON Creativity Suite
04-01-2017 14:01:35 Driver Reviver (04/01/2017 14:01)
04-01-2017 17:31:04 Removed Skype™ 7.30
04-01-2017 18:18:15 Windows Update
05-01-2017 00:00:55 Windows Update
05-01-2017 00:41:14 Windows Update
05-01-2017 00:48:52 Windows Update
05-01-2017 00:54:51 Windows Update
10-01-2017 15:42:24 Installed DriverUpdate
10-01-2017 19:40:37 Windows Update
10-01-2017 19:45:26 Windows Update
10-01-2017 19:56:24 Windows Update
10-01-2017 19:58:33 Windows Update
10-01-2017 20:27:38 Windows Update
11-01-2017 00:00:21 Windows Update
11-01-2017 01:01:28 Wiederherstellungsvorgang

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Unknown Device
Description: Unknown Device
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Standard-USB-Hostcontroller)
Service:
Problem: : This device is disabled because the firmware of the device did not give it the required resources. (Code 29)
Resolution: Enable the device in the BIOS of the device.

Name: Microsoft-Teredo-Tunneling-Adapter
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (01/12/2017 08:42:48 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 351876

Error: (01/12/2017 08:42:48 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 351876

Error: (01/12/2017 08:42:48 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/12/2017 08:42:44 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 348600

Error: (01/12/2017 08:42:44 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 348600

Error: (01/12/2017 08:42:44 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/12/2017 08:42:35 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 339349

Error: (01/12/2017 08:42:35 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 339349

Error: (01/12/2017 08:42:35 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/12/2017 08:42:28 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 331971


Systemfehler:
=============
Error: (01/12/2017 08:47:23 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht.

Error: (01/12/2017 07:50:33 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst lmhosts erreicht.

Error: (01/12/2017 01:30:59 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst lmhosts erreicht.

Error: (01/11/2017 11:52:46 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst RapiMgr erreicht.

Error: (01/11/2017 11:52:49 AM) (Source: DCOM) (EventID: 10001) (User: )
Description: Ein DCOM-Server konnte nicht gestartet werden: {C39EE728-D419-4BD4-A3EF-EDA059DBD935} als /. Fehler:
"5"
Aufgetreten beim Start dieses Befehls:
C:\windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (01/11/2017 01:21:28 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst MBAMService erreicht.

Error: (01/11/2017 01:05:08 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst QHActiveDefense erreicht.

Error: (01/11/2017 01:04:28 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst MBAMService erreicht.

Error: (01/11/2017 12:28:23 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows-Audio" wurde nicht richtig gestartet.

Error: (01/11/2017 12:24:59 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: Der Server "{49BD2028-1523-11D1-AD79-00C04FD8FDFF}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.


==================== Speicherinformationen ===========================

Prozessor: Intel(R) Pentium(R) CPU 3560M @ 2.40GHz
Prozentuale Nutzung des RAM: 63%
Installierter physikalischer RAM: 4016.81 MB
Verfügbarer physikalischer RAM: 1449.62 MB
Summe virtueller Speicher: 8031.8 MB
Verfügbarer virtueller Speicher: 4073.84 MB

==================== Laufwerke ================================

Drive c: (OS_Install) (Fixed) (Total:272.65 GB) (Free:119.02 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive d: (Data) (Fixed) (Total:181.77 GB) (Free:181.63 GB) NTFS
Drive w: (BIOS_RVY) (Fixed) (Total:11.24 GB) (Free:0.28 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C54CB572)
Partition 1: (Not Active) - (Size=11.2 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=27)
Partition 3: (Not Active) - (Size=272.7 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=181.8 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================


cosinus 13.01.2017 09:26

Hi,

- das hat was mit Schädlingen zu tun?
- gab es Virenfunde deines AVs, wenn ja, Log dazu??

cosinus 13.01.2017 09:26

edit: Themen wurden zusammengeführt

milkit54 13.01.2017 10:52

Zitat:

Zitat von cosinus (Beitrag 1633844)
Hi,

- das hat was mit Schädlingen zu tun?
- gab es Virenfunde deines AVs, wenn ja, Log dazu??

Hi Cosinus,
sorry für meine Unzulänglichkeit. ich habe mich bemüht alles zu senden was ich

nach der Anleitung hatte, ich stellte fest, daß meine Startseite ständig und "automatisch" von "down speed test" geändert wurde. Microsoft zeigt mir Treiberprobleme mit toredo tunneling adapter an und die automatische Erkennung über usb funktioniert nicht mehr bzw wewrden als Unkown Device angezeigt (roblembehandlung nicht möglich)
funde von 360 Total Security habe ich nicht mitbekommen.
Wäre nett wenn du mir sagst wie ich an den log rankomme, bitte für "Unwissende Anwender"
PS meine Ms macht heute mehr Probleme als sonst. Gruß MS-Michael

cosinus 13.01.2017 11:01

Wir haben keine bebilderten Anleitungen für jeden Virenscanner den es auf der Welt gibt. Du solltest da schonmal selbst im Menü der Software nach den Logs schauen.

Die Logs von Malwarebytes findet du im Verlauf.

milkit54 13.01.2017 11:43

die logs Malwarebytes hatte ich eigentlich schon geschick sende ihn aber gerne mit den vom avs suche ich sofort

Code:

Malwarebytes
www.malwarebytes.com

-Protokolldetails-
Scan-Datum: 04.01.17
Scan-Zeit: 15:21
Protokolldatei: scan malebyte 04012017.txt
Administrator: Ja

-Softwaredaten-
Version: 3.0.5.1299
Komponentenversion: 1.0.43
Version des Aktualisierungspakets: 1.0.925
Lizenz: Testversion

-Systemdaten-
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Micha-MSI\Micha

-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 367832
Abgelaufene Zeit: 10 Min., 43 Sek.

-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

-Scan-Details-
Prozess: 1
PUP.Optional.DriverUpdate, C:\PROGRAM FILES\SLIMSERVICE\SLIMSERVICEFACTORY.EXE, Keine Aktion durch Benutzer, [1207], [335824],1.0.925

Modul: 1
PUP.Optional.DriverUpdate, C:\PROGRAM FILES\SLIMSERVICE\SLIMSERVICEFACTORY.EXE, Keine Aktion durch Benutzer, [1207], [335824],1.0.925

Registrierungsschlüssel: 37
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{149622B2-F1C5-492D-BFDF-8E5ED85854A0}, Keine Aktion durch Benutzer, [1207], [335820],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{149622B2-F1C5-492D-BFDF-8E5ED85854A0}, Keine Aktion durch Benutzer, [1207], [335820],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\APPID\{149622B2-F1C5-492D-BFDF-8E5ED85854A0}, Keine Aktion durch Benutzer, [1207], [335820],1.0.925
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, Keine Aktion durch Benutzer, [1317], [332494],1.0.925
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, Keine Aktion durch Benutzer, [1317], [332494],1.0.925
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, Keine Aktion durch Benutzer, [1317], [332494],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A5FF3EB5-BF62-4D59-84DF-DC518E46FCB3}, Keine Aktion durch Benutzer, [1207], [335824],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{A5FF3EB5-BF62-4D59-84DF-DC518E46FCB3}, Keine Aktion durch Benutzer, [1207], [335824],1.0.925
PUP.Optional.DriverUpdate, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SlimService, Keine Aktion durch Benutzer, [1207], [335824],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\TYPELIB\{A5FF3EB5-BF62-4D59-84DF-DC518E46FCB3}, Keine Aktion durch Benutzer, [1207], [335824],1.0.925
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}, Keine Aktion durch Benutzer, [1317], [327205],1.0.925
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\REI_AxControl.ReiEngine, Keine Aktion durch Benutzer, [1317], [327205],1.0.925
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\REI_AxControl.ReiEngine.1, Keine Aktion durch Benutzer, [1317], [327205],1.0.925
PUP.Optional.Reimage, HKU\S-1-5-21-2198626584-3468660724-23365673-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{10ECCE17-29B5-4880-A8F5-EAD298611484}, Keine Aktion durch Benutzer, [1317], [327205],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{6DC6EE87-F3BB-40EB-BCEE-12F7D6E3EEDF}, Keine Aktion durch Benutzer, [1207], [335836],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\APPID\{1BD47D21-01F4-4538-9290-39FD569A0F24}, Keine Aktion durch Benutzer, [1207], [335822],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{1BD47D21-01F4-4538-9290-39FD569A0F24}, Keine Aktion durch Benutzer, [1207], [335822],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{1BD47D21-01F4-4538-9290-39FD569A0F24}, Keine Aktion durch Benutzer, [1207], [335822],1.0.925
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}, Keine Aktion durch Benutzer, [1317], [327206],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Keine Aktion durch Benutzer, [1207], [335828],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Keine Aktion durch Benutzer, [1207], [335828],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Keine Aktion durch Benutzer, [1207], [335828],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{959D527D-6C27-4879-A644-065526D6969C}, Keine Aktion durch Benutzer, [1207], [335833],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{BAF87BD0-A924-4108-AFA5-A5FA720A2E86}, Keine Aktion durch Benutzer, [1207], [335831],1.0.925
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SlimCleaner Plus, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\APPID\REI_AxControl.DLL, Keine Aktion durch Benutzer, [1317], [327193],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\SLIMWARE UTILITIES INC\DriverUpdate, Keine Aktion durch Benutzer, [1207], [338931],1.0.925
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\WOW6432NODE\SLIMWARE UTILITIES INC\SlimCleaner Plus, Keine Aktion durch Benutzer, [1657], [338932],1.0.925
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\REI_AxControl.DLL, Keine Aktion durch Benutzer, [1317], [327193],1.0.925
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{ABA29C63-B22D-45F8-BA20-7C8EF17B5E62}, Keine Aktion durch Benutzer, [1657], [335437],1.0.925
PUP.Optional.Reimage, HKLM\SOFTWARE\REIMAGE\Reimage Repair, Keine Aktion durch Benutzer, [1317], [336077],1.0.925
PUP.Optional.Reimage, HKU\S-1-5-21-2198626584-3468660724-23365673-1000\SOFTWARE\Reimage, Keine Aktion durch Benutzer, [1317], [357494],1.0.925
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\REI_AxControl.DLL, Keine Aktion durch Benutzer, [1317], [327193],1.0.925
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\SLIMWARE UTILITIES? INC.\DriverApp, Keine Aktion durch Benutzer, [1207], [341522],1.0.925
PUP.Optional.Reimage, HKU\S-1-5-21-2198626584-3468660724-23365673-1000\SOFTWARE\LOCAL APPWIZARD-GENERATED APPLICATIONS\Reimage - Windows Problem Relief., Keine Aktion durch Benutzer, [1317], [327203],1.0.925
PUP.Optional.DriverUpdate, HKU\S-1-5-21-2198626584-3468660724-23365673-1000\SOFTWARE\SLIMWARE UTILITIES INC\DriverUpdate, Keine Aktion durch Benutzer, [1207], [341521],1.0.925
PUP.Optional.Reimage, HKU\S-1-5-21-2198626584-3468660724-23365673-1000\SOFTWARE\REIMAGE\PC REPAIR, Keine Aktion durch Benutzer, [1317], [327204],1.0.925

Registrierungswert: 2
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{ABA29C63-B22D-45F8-BA20-7C8EF17B5E62}|DISPLAYNAME, Keine Aktion durch Benutzer, [1657], [335437],1.0.925
PUP.Optional.Reimage, HKU\S-1-5-21-2198626584-3468660724-23365673-1000\SOFTWARE\REIMAGE\PC REPAIR|QUITMESSAGE, Keine Aktion durch Benutzer, [1317], [327204],1.0.925

Daten-Stream: 0
(keine bösartigen Elemente erkannt)

Ordner: 7
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SlimCleaner Plus, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Images, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\USERS\MICHA\APPDATA\LOCAL\SlimWare Utilities Inc\DriverUpdate, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.SlimCleanerPlus, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\SLIMCLEANER PLUS, Keine Aktion durch Benutzer, [1657], [331461],1.0.925
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SLIMSERVICE, Keine Aktion durch Benutzer, [1657], [331454],1.0.925

Datei: 93
PUP.Optional.DriverUpdate, C:\PROGRAM FILES\SLIMSERVICE\SLIMSERVICEFACTORY.EXE, Keine Aktion durch Benutzer, [1207], [335824],1.0.925
PUP.Optional.DriverUpdate, C:\PROGRAM FILES\SLIMSERVICE\SLIMSERVICE.EXE, Keine Aktion durch Benutzer, [1207], [335828],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\hi.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\am.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\ar.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\bg.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\bn.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\ca.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\cs.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\da.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\de.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\el.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\en-GB.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\en-US.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\es-419.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\es.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\et.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\fa.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\fi.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\fil.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\fr.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\gu.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\he.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\hr.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\hu.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\id.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\it.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\ja.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\kn.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\ko.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\lt.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\lv.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\ml.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\mr.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\ms.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\nb.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\nl.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\pl.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\pt-BR.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\pt-PT.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\ro.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\ru.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\sk.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\sl.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\sr.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\sv.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\sw.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\ta.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\te.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\th.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\tr.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\uk.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\vi.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\zh-CN.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\locales\zh-TW.pak, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\default.ui, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\main.ui, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\mdp.exe, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\Open-Source Licenses.txt, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimCleaner Plus\UninstallStub.exe, Keine Aktion durch Benutzer, [1657], [331458],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Images\acer.png, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs\2017-01-04  01-18-02 0.log, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs\2017-01-04  01-18-17 0.log, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs\2017-01-04  01-22-23 0.log, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs\2017-01-04  01-22-29 0.log, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs\2017-01-04  09-11-34 0.log, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs\2017-01-04  09-42-29 0.log, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs\2017-01-04  10-08-08 0.log, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs\2017-01-04  10-38-07 0.log, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\ignores.dat, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\rupdates.db, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\settings.db, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\supdates.db, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\SWDUMon.cat, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\SWDUMon.inf, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\SWDUMon.sys, Keine Aktion durch Benutzer, [1207], [341510],1.0.925
PUP.Optional.SlimCleanerPlus, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimCleaner Plus\SlimCleaner Plus.lnk, Keine Aktion durch Benutzer, [1657], [331461],1.0.925
PUP.Optional.SlimCleanerPlus, C:\USERS\PUBLIC\DESKTOP\SLIMCLEANER PLUS.LNK, Keine Aktion durch Benutzer, [1657], [331453],1.0.925
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SLIMSERVICE\CLEANER.DB, Keine Aktion durch Benutzer, [1657], [331454],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\Analyze.MyD, Keine Aktion durch Benutzer, [1657], [331454],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\Full.MyD, Keine Aktion durch Benutzer, [1657], [331454],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\icudt46l.dat, Keine Aktion durch Benutzer, [1657], [331454],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\MyDefragDll.dll, Keine Aktion durch Benutzer, [1657], [331454],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\Quick.MyD, Keine Aktion durch Benutzer, [1657], [331454],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\Ssd.MyD, Keine Aktion durch Benutzer, [1657], [331454],1.0.925
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\UnifiedLogger.dll, Keine Aktion durch Benutzer, [1657], [331454],1.0.925
PUP.Optional.Slimware, C:\USERS\MICHA\APPDATA\LOCAL\TEMP\SCP34E7.TMP.EXE, Keine Aktion durch Benutzer, [1931], [338168],1.0.925
PUP.Optional.Reimage, C:\USERS\MICHA\APPDATA\LOCAL\TEMP\REIMAGE.LOG, Keine Aktion durch Benutzer, [1317], [334717],1.0.925
PUP.Optional.Reimage, C:\WINDOWS\TEMP\REIMAGE.LOG, Keine Aktion durch Benutzer, [1317], [334717],1.0.925
PUP.Optional.DriverUpdate, C:\USERS\MICHA\DOWNLOADS\DRIVERUPDATE-SETUP.EXE, Keine Aktion durch Benutzer, [1207], [331447],1.0.925
PUP.Optional.Reimage, C:\USERS\MICHA\DOWNLOADS\REIMAGEREPAIR.EXE, Keine Aktion durch Benutzer, [1317], [331559],1.0.925
PUP.Optional.SpeedItUp, C:\WINDOWS\REIMAGE.INI, Keine Aktion durch Benutzer, [1421], [329423],1.0.925

Physischer Sektor: 0
(keine bösartigen Elemente erkannt)


(end)

soll ich noch mal malwarebytes laufen lassen?

cosinus 13.01.2017 11:48

Nein, aber tu dir einen Gefallen und deinstalliere Ad-Aware (unnötig bis unbrauchbar) sowie das schlechte China-AV 360 Total Security, dann gehts weiter.

milkit54 13.01.2017 13:06

Zitat:

Zitat von cosinus (Beitrag 1633845)
edit: Themen wurden zusammengeführt

Hi Cosinus die beiden Programme sind deinstalliert
jedoch erfolgte dann ein Neustart und jetzt ist der mailverlauf im trojanerboard nicht mehr drin ?

Zitat:

Zitat von cosinus (Beitrag 1633870)
Nein, aber tu dir einen Gefallen und deinstalliere Ad-Aware (unnötig bis unbrauchbar) sowie das schlechte China-AV 360 Total Security, dann gehts weiter.

die beiden sind deinstalliert, jedoch ist am ende ein neustart gelaufen, das nur zur info
Gruß MS-Micha

cosinus 13.01.2017 14:20

1. Schritt: Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers




2. Schritt: Kaspersky TDSS-Killer

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.




Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

milkit54 13.01.2017 18:27

Code:

Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org

Database version:
  main:    v2017.01.13.09
  rootkit: v2016.11.20.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.18537
Micha :: MICHA-MSI [administrator]

13.01.2017 15:23:14
mbar-log-2017-01-13 (15-23-14).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 353297
Time elapsed: 27 minute(s), 20 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DesktopIconAmazon (Trojan.Downloader) -> Delete on reboot. [2a4377046741b482b837dacf758b52ae]

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\Micha\AppData\Roaming\DesktopIconAmazon\desktopicon-Amazon.exe (Trojan.Downloader) -> Delete on reboot. [2a4377046741b482b837dacf758b52ae]

Physical Sectors Detected: 0
(No malicious items detected)

(end)

Code:

17:09:40.0009 0x19d8  TDSS rootkit removing tool 3.1.0.12 Nov  7 2016 07:10:01
17:09:55.0989 0x19d8  ============================================================
17:09:55.0989 0x19d8  Current date / time: 2017/01/13 17:09:55.0989
17:09:55.0989 0x19d8  SystemInfo:
17:09:55.0989 0x19d8 
17:09:55.0989 0x19d8  OS Version: 6.1.7601 ServicePack: 1.0
17:09:55.0989 0x19d8  Product type: Workstation
17:09:55.0990 0x19d8  ComputerName: MICHA-MSI
17:09:55.0990 0x19d8  UserName: Micha
17:09:55.0990 0x19d8  Windows directory: C:\windows
17:09:55.0990 0x19d8  System windows directory: C:\windows
17:09:55.0990 0x19d8  Running under WOW64
17:09:55.0990 0x19d8  Processor architecture: Intel x64
17:09:55.0990 0x19d8  Number of processors: 2
17:09:55.0990 0x19d8  Page size: 0x1000
17:09:55.0990 0x19d8  Boot type: Normal boot
17:09:55.0991 0x19d8  CodeIntegrityOptions = 0x00000001
17:09:55.0991 0x19d8  ============================================================
17:09:58.0355 0x19d8  KLMD registered as C:\windows\system32\drivers\82067764.sys
17:09:58.0355 0x19d8  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 7601.23572, osProperties = 0x1
17:09:58.0749 0x19d8  System UUID: {200DC177-E40D-48B4-4F9D-F09300A0C18B}
17:09:59.0472 0x19d8  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
17:09:59.0485 0x19d8  ============================================================
17:09:59.0485 0x19d8  \Device\Harddisk0\DR0:
17:09:59.0486 0x19d8  MBR partitions:
17:09:59.0486 0x19d8  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x16AC800, BlocksNum 0x2214F000
17:09:59.0486 0x19d8  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x237FB800, BlocksNum 0x16B8A800
17:09:59.0486 0x19d8  ============================================================
17:09:59.0534 0x19d8  C: <-> \Device\Harddisk0\DR0\Partition1
17:09:59.0606 0x19d8  D: <-> \Device\Harddisk0\DR0\Partition2
17:09:59.0663 0x19d8  ============================================================
17:09:59.0663 0x19d8  Initialize success
17:09:59.0663 0x19d8  ============================================================
17:11:00.0233 0x1ab4  ============================================================
17:11:00.0233 0x1ab4  Scan started
17:11:00.0233 0x1ab4  Mode: Manual;
17:11:00.0233 0x1ab4  ============================================================
17:11:00.0233 0x1ab4  KSN ping started
17:11:12.0452 0x1ab4  KSN ping finished: true
17:11:13.0510 0x1ab4  ================ Scan system memory ========================
17:11:13.0510 0x1ab4  System memory - ok
17:11:13.0510 0x1ab4  ================ Scan services =============================
17:11:13.0720 0x1ab4  [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci        C:\windows\system32\drivers\1394ohci.sys
17:11:13.0730 0x1ab4  1394ohci - ok
17:11:13.0790 0x1ab4  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI            C:\windows\system32\drivers\ACPI.sys
17:11:13.0800 0x1ab4  ACPI - ok
17:11:13.0810 0x1ab4  [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi        C:\windows\system32\drivers\acpipmi.sys
17:11:13.0810 0x1ab4  AcpiPmi - ok
17:11:13.0910 0x1ab4  [ B932E0EE190778D840F1442DFC0F9612, 8780963F14D57279FDD585BE945ED40F24590D32676C7A9EF94002D38B8BA643 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
17:11:13.0910 0x1ab4  AdobeARMservice - ok
17:11:14.0000 0x1ab4  [ CA363F172E1978FD155764F2840B0BE8, CB14E2C94ABB8C8809F4E96472F6D1A9A3A0860217631F592E0F62F043165575 ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
17:11:14.0010 0x1ab4  AdobeFlashPlayerUpdateSvc - ok
17:11:14.0049 0x1ab4  [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx        C:\windows\system32\drivers\adp94xx.sys
17:11:14.0059 0x1ab4  adp94xx - ok
17:11:14.0078 0x1ab4  [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci        C:\windows\system32\drivers\adpahci.sys
17:11:14.0085 0x1ab4  adpahci - ok
17:11:14.0102 0x1ab4  [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320        C:\windows\system32\drivers\adpu320.sys
17:11:14.0106 0x1ab4  adpu320 - ok
17:11:14.0153 0x1ab4  [ 262D7C87D0AC20B96EF9877D3CA478A0, 54F7E5A5F8991C5525500C1ECCF3D3135D13F48866C366E52DF1D052DB2EE15B ] AeLookupSvc    C:\windows\System32\aelupsvc.dll
17:11:14.0157 0x1ab4  AeLookupSvc - ok
17:11:14.0229 0x1ab4  [ 9A4A1EEE802BF2F878EE8EAB407B21B7, 177EB7DF4B35FE4C0E45E775A0FD5D48D39B410052E3EE18BDEEC809E152D9D8 ] AFD            C:\windows\system32\drivers\afd.sys
17:11:14.0256 0x1ab4  AFD - ok
17:11:14.0272 0x1ab4  [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440          C:\windows\system32\drivers\agp440.sys
17:11:14.0275 0x1ab4  agp440 - ok
17:11:14.0294 0x1ab4  [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG            C:\windows\System32\alg.exe
17:11:14.0297 0x1ab4  ALG - ok
17:11:14.0323 0x1ab4  [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide          C:\windows\system32\drivers\aliide.sys
17:11:14.0324 0x1ab4  aliide - ok
17:11:14.0334 0x1ab4  [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide          C:\windows\system32\drivers\amdide.sys
17:11:14.0344 0x1ab4  amdide - ok
17:11:14.0354 0x1ab4  [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8          C:\windows\system32\drivers\amdk8.sys
17:11:14.0354 0x1ab4  AmdK8 - ok
17:11:14.0364 0x1ab4  [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM          C:\windows\system32\drivers\amdppm.sys
17:11:14.0364 0x1ab4  AmdPPM - ok
17:11:14.0384 0x1ab4  [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata        C:\windows\system32\drivers\amdsata.sys
17:11:14.0394 0x1ab4  amdsata - ok
17:11:14.0414 0x1ab4  [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs          C:\windows\system32\drivers\amdsbs.sys
17:11:14.0414 0x1ab4  amdsbs - ok
17:11:14.0434 0x1ab4  [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata        C:\windows\system32\drivers\amdxata.sys
17:11:14.0434 0x1ab4  amdxata - ok
17:11:14.0514 0x1ab4  [ 59D01FA91962C9C1E9B4022B2D3B46DB, 3A111588538B77F010B5C900FB8425DDE55A08DBAC308CA7FB7BD9FCCCDEC69F ] AppHostSvc      C:\windows\system32\inetsrv\apphostsvc.dll
17:11:14.0514 0x1ab4  AppHostSvc - ok
17:11:14.0554 0x1ab4  [ FCE5C79717A487BDC71F3DEC78A684CA, F5520F112A4EBDD10444AA5E9FDB9125219FCF768FEB95AB608BC84D60136816 ] AppID          C:\windows\system32\drivers\appid.sys
17:11:14.0554 0x1ab4  AppID - ok
17:11:14.0584 0x1ab4  [ 8921E1D8AE5171691F186A7C5B98B630, 4A37313BB94D4B49D0294C9439AD0793DE328F9F4DA1C47E34E6ACEA46AF6E14 ] AppIDSvc        C:\windows\System32\appidsvc.dll
17:11:14.0594 0x1ab4  AppIDSvc - ok
17:11:14.0614 0x1ab4  [ DE23E052E557580674785CDF45B613F3, A955ADC6CC7D816BA7CE1065F911E7A3295A1908C22BE0A3C506C38CFEE8DE0D ] Appinfo        C:\windows\System32\appinfo.dll
17:11:14.0614 0x1ab4  Appinfo - ok
17:11:14.0654 0x1ab4  [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc            C:\windows\system32\drivers\arc.sys
17:11:14.0664 0x1ab4  arc - ok
17:11:14.0674 0x1ab4  [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas          C:\windows\system32\drivers\arcsas.sys
17:11:14.0674 0x1ab4  arcsas - ok
17:11:14.0766 0x1ab4  [ EE424A5CE56E3923D59BB7DE2E15036D, 8B8196870EFE74D43EDA72674021A46846D370E97A6A058134D84A721AECD091 ] aspnet_state    C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
17:11:14.0776 0x1ab4  aspnet_state - ok
17:11:14.0816 0x1ab4  [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac        C:\windows\system32\DRIVERS\asyncmac.sys
17:11:14.0816 0x1ab4  AsyncMac - ok
17:11:14.0856 0x1ab4  [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi          C:\windows\system32\drivers\atapi.sys
17:11:14.0856 0x1ab4  atapi - ok
17:11:14.0936 0x1ab4  [ E857EEE6B92AAA473EBB3465ADD8F7E7, 1C7E4737E649A025B3C4974A4F7D1353EAB85561FC8ED54E5C22A777E1A189B3 ] athr            C:\windows\system32\DRIVERS\athrx.sys
17:11:14.0977 0x1ab4  athr - ok
17:11:15.0018 0x1ab4  [ 67C717EC24FCAAE7B518D9E06AD036AB, F08550E4FCEC2899FACEF2A18CEE3D068D5911FFD2FF5534E4921E56FB0AEF59 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
17:11:15.0046 0x1ab4  AudioEndpointBuilder - ok
17:11:15.0062 0x1ab4  [ 67C717EC24FCAAE7B518D9E06AD036AB, F08550E4FCEC2899FACEF2A18CEE3D068D5911FFD2FF5534E4921E56FB0AEF59 ] AudioSrv        C:\windows\System32\Audiosrv.dll
17:11:15.0074 0x1ab4  AudioSrv - ok
17:11:15.0135 0x1ab4  [ C4EEE661379D86429ACEAB31F3FD0391, D67F5D6863B066D974567521A00A48C50F0D9B6F6B16565FF8958E2020C651FD ] AvrcpService    C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe
17:11:15.0136 0x1ab4  AvrcpService - ok
17:11:15.0156 0x1ab4  [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV        C:\windows\System32\AxInstSV.dll
17:11:15.0159 0x1ab4  AxInstSV - ok
17:11:15.0196 0x1ab4  [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv        C:\windows\system32\drivers\bxvbda.sys
17:11:15.0206 0x1ab4  b06bdrv - ok
17:11:15.0229 0x1ab4  [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a        C:\windows\system32\DRIVERS\b57nd60a.sys
17:11:15.0235 0x1ab4  b57nd60a - ok
17:11:15.0251 0x1ab4  [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC          C:\windows\System32\bdesvc.dll
17:11:15.0254 0x1ab4  BDESVC - ok
17:11:15.0285 0x1ab4  [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep            C:\windows\system32\drivers\Beep.sys
17:11:15.0286 0x1ab4  Beep - ok
17:11:15.0350 0x1ab4  [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE            C:\windows\System32\bfe.dll
17:11:15.0380 0x1ab4  BFE - ok
17:11:15.0470 0x1ab4  [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS            C:\windows\System32\qmgr.dll
17:11:15.0510 0x1ab4  BITS - ok
17:11:15.0550 0x1ab4  [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive        C:\windows\system32\drivers\blbdrive.sys
17:11:15.0560 0x1ab4  blbdrive - ok
17:11:15.0670 0x1ab4  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD, 17BFFC5DF609CE3B2F0CAB4BD6C118608C66A3AD86116A47E90B2BB7D8954122 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
17:11:15.0690 0x1ab4  Bonjour Service - ok
17:11:15.0730 0x1ab4  [ ABA3984C822E4D3F889699912D85D6C5, 2251FA135CC290DA13DAE4743F393C7CC9E6A737C054707CB8D72C369D1FFACB ] bowser          C:\windows\system32\DRIVERS\bowser.sys
17:11:15.0730 0x1ab4  bowser - ok
17:11:15.0740 0x1ab4  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\windows\system32\drivers\BrFiltLo.sys
17:11:15.0740 0x1ab4  BrFiltLo - ok
17:11:15.0760 0x1ab4  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\windows\system32\drivers\BrFiltUp.sys
17:11:15.0760 0x1ab4  BrFiltUp - ok
17:11:15.0770 0x1ab4  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser        C:\windows\System32\browser.dll
17:11:15.0770 0x1ab4  Browser - ok
17:11:15.0800 0x1ab4  [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid        C:\windows\System32\Drivers\Brserid.sys
17:11:15.0810 0x1ab4  Brserid - ok
17:11:15.0810 0x1ab4  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\windows\System32\Drivers\BrSerWdm.sys
17:11:15.0810 0x1ab4  BrSerWdm - ok
17:11:15.0820 0x1ab4  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\windows\System32\Drivers\BrUsbMdm.sys
17:11:15.0820 0x1ab4  BrUsbMdm - ok
17:11:15.0820 0x1ab4  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\windows\System32\Drivers\BrUsbSer.sys
17:11:15.0820 0x1ab4  BrUsbSer - ok
17:11:15.0850 0x1ab4  [ FB38F90DE58996A4906A04F1152C3C3B, DA4A226FAE045174891A0EBFA03E1905CAF0AA25ADDBBCFBE369A853A63A83C6 ] BTDevManager    C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
17:11:15.0850 0x1ab4  BTDevManager - ok
17:11:15.0880 0x1ab4  [ CF98190A94F62E405C8CB255018B2315, E1B2540023C4FE9FD588E4B6AE6347DFA565EB3898F21E5360882BF3E8B5E781 ] BthEnum        C:\windows\system32\DRIVERS\BthEnum.sys
17:11:15.0890 0x1ab4  BthEnum - ok
17:11:15.0900 0x1ab4  [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM        C:\windows\system32\drivers\bthmodem.sys
17:11:15.0900 0x1ab4  BTHMODEM - ok
17:11:15.0940 0x1ab4  [ 02DD601B708DD0667E1331FA8518E9FF, 7DE6CC4DBB621CD03B01D9CE6CF66EAFE31D39030A391562CD0E278E1D70ADE1 ] BthPan          C:\windows\system32\DRIVERS\bthpan.sys
17:11:15.0950 0x1ab4  BthPan - ok
17:11:15.0970 0x1ab4  [ 738D0E9272F59EB7A1449C3EC118E6C4, FE3D32C2A5E4DC21376A0F89C0B2EE024ECF1A3FB99213CC9BBC986ADF7AF080 ] BTHPORT        C:\windows\system32\Drivers\BTHport.sys
17:11:15.0980 0x1ab4  BTHPORT - ok
17:11:16.0010 0x1ab4  [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv        C:\windows\system32\bthserv.dll
17:11:16.0010 0x1ab4  bthserv - ok
17:11:16.0030 0x1ab4  [ F188B7394D81010767B6DF3178519A37, 576304E92FD94908F093A6AB5F4D328F25829BE32EC3CA0D29EBFDF5DE83539B ] BTHUSB          C:\windows\system32\Drivers\BTHUSB.sys
17:11:16.0030 0x1ab4  BTHUSB - ok
17:11:16.0083 0x1ab4  [ E41F70406C34F1CB667B4B27D81AD162, 8869C7EB9CBF68B90640765D15DB5B8DACEF45025C1E580AA94D96E32560274B ] ccSet_NARA      C:\windows\system32\drivers\NARAx64\0403000.00E\ccSetx64.sys
17:11:16.0093 0x1ab4  ccSet_NARA - ok
17:11:16.0138 0x1ab4  [ A5C13600F63EB92F8D15123D64BA9895, 16683BDDD32525741FDE4505B9C224382047CC8EE9A7DB35FF0FDF32F7D731F8 ] ccSet_NAT      C:\windows\system32\drivers\NATx64\0106000.011\ccSetx64.sys
17:11:16.0143 0x1ab4  ccSet_NAT - ok
17:11:16.0172 0x1ab4  [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs            C:\windows\system32\DRIVERS\cdfs.sys
17:11:16.0175 0x1ab4  cdfs - ok
17:11:16.0208 0x1ab4  [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom          C:\windows\system32\DRIVERS\cdrom.sys
17:11:16.0211 0x1ab4  cdrom - ok
17:11:16.0231 0x1ab4  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc    C:\windows\System32\certprop.dll
17:11:16.0235 0x1ab4  CertPropSvc - ok
17:11:16.0250 0x1ab4  [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass        C:\windows\system32\drivers\circlass.sys
17:11:16.0252 0x1ab4  circlass - ok
17:11:16.0287 0x1ab4  [ FF60401F1C659CA2ED4BAE85D3FD14DA, 71EEA0078E1545A2F80B0020BE7113843B713DE1A5CC20D9810BD9F3889A4DB0 ] CISVC          C:\windows\system32\CISVC.EXE
17:11:16.0289 0x1ab4  CISVC - ok
17:11:16.0356 0x1ab4  [ 3D67C27DD17B254D7915FA16A5AE3573, 5B3A6C6A7F940C06362775DAF13CEADA37C7AA84A509458A57C23B4369970A90 ] CLFS            C:\windows\system32\CLFS.sys
17:11:16.0366 0x1ab4  CLFS - ok
17:11:16.0434 0x1ab4  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:11:16.0440 0x1ab4  clr_optimization_v2.0.50727_32 - ok
17:11:16.0490 0x1ab4  [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
17:11:16.0497 0x1ab4  clr_optimization_v2.0.50727_64 - ok
17:11:16.0557 0x1ab4  [ 5BAF4F1296D4D91FC28560CDB4C37C4B, ACA4BC57ED1F8432F18F0F215EC7FF956BAEF6E02760779E264E4008A979E9DD ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:11:16.0565 0x1ab4  clr_optimization_v4.0.30319_32 - ok
17:11:16.0610 0x1ab4  [ 569B54004A7E85A74FD92841DE6058E2, 58949313D0F6B1C06359B2F3C68E29940B1655A17E93FFC3718F6D2EAE1633E4 ] clr_optimization_v4.0.30319_64 C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
17:11:16.0640 0x1ab4  clr_optimization_v4.0.30319_64 - ok
17:11:16.0680 0x1ab4  [ E13A438F9E51DD034730678E33B73290, 3BB111DFDAEAB8DA6124600C7F6E080C2950A0BB420803FC12560343E1A9280A ] clwvd          C:\windows\system32\DRIVERS\clwvd.sys
17:11:16.0680 0x1ab4  clwvd - ok
17:11:16.0710 0x1ab4  [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt          C:\windows\system32\DRIVERS\CmBatt.sys
17:11:16.0720 0x1ab4  CmBatt - ok
17:11:16.0738 0x1ab4  [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide          C:\windows\system32\drivers\cmdide.sys
17:11:16.0739 0x1ab4  cmdide - ok
17:11:16.0762 0x1ab4  [ A98CED39AD91B445E2E442A9BD67E8B4, B4189DEEF1C0EE22AE983119047B1A40FFDD8F3E163DFFABD7C2706231B0B1B0 ] CNG            C:\windows\system32\Drivers\cng.sys
17:11:16.0772 0x1ab4  CNG - ok
17:11:16.0782 0x1ab4  [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt        C:\windows\system32\drivers\compbatt.sys
17:11:16.0792 0x1ab4  Compbatt - ok
17:11:16.0812 0x1ab4  [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus    C:\windows\system32\drivers\CompositeBus.sys
17:11:16.0812 0x1ab4  CompositeBus - ok
17:11:16.0812 0x1ab4  COMSysApp - ok
17:11:16.0932 0x1ab4  [ 3A92DDB2F7B7FE2E71AA1418804EBC3C, 1B84033A6DDB9D371AC34F8D65AB0F729E8A77B0D26C8DCA0965CE265474BD64 ] cphs            C:\windows\SysWow64\IntelCpHeciSvc.exe
17:11:16.0942 0x1ab4  cphs - ok
17:11:16.0962 0x1ab4  [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk        C:\windows\system32\drivers\crcdisk.sys
17:11:16.0972 0x1ab4  crcdisk - ok
17:11:16.0992 0x1ab4  [ 2C6632CECFDBBE793FDA8AF9CA55A9CC, 335188515F798483660E529204A13012E4D21B0ECA489224A11C26F91A5B3CCE ] CryptSvc        C:\windows\system32\cryptsvc.dll
17:11:17.0002 0x1ab4  CryptSvc - ok
17:11:17.0037 0x1ab4  [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] DcomLaunch      C:\windows\system32\rpcss.dll
17:11:17.0047 0x1ab4  DcomLaunch - ok
17:11:17.0088 0x1ab4  [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc      C:\windows\System32\defragsvc.dll
17:11:17.0095 0x1ab4  defragsvc - ok
17:11:17.0165 0x1ab4  [ 9B38580063D281A99E68EF5813022A5F, D91676B0E0A8E2A090E3E5DD340ABCFC20AE0F55B4C82869D6CFB34239BD27DA ] DfsC            C:\windows\system32\Drivers\dfsc.sys
17:11:17.0168 0x1ab4  DfsC - ok
17:11:17.0192 0x1ab4  [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp            C:\windows\system32\dhcpcore.dll
17:11:17.0199 0x1ab4  Dhcp - ok
17:11:17.0290 0x1ab4  [ EE9954237F15BE4DD9304D12E4D305ED, F295C9BAF20F0E669B673AFCC16B4969EE31B6A3808980DAB93D9B0F167DA3C0 ] DiagTrack      C:\windows\system32\diagtrack.dll
17:11:17.0457 0x1ab4  DiagTrack - ok
17:11:17.0487 0x1ab4  [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache        C:\windows\system32\drivers\discache.sys
17:11:17.0487 0x1ab4  discache - ok
17:11:17.0517 0x1ab4  [ 616387BBD83372220B09DE95F4E67BBC, 5E2D5280BB775576E7CDE3FA6BDE494E183123635E5908CF7EBF1FF52966D07D ] Disk            C:\windows\system32\drivers\disk.sys
17:11:17.0527 0x1ab4  Disk - ok
17:11:17.0557 0x1ab4  [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache        C:\windows\System32\dnsrslvr.dll
17:11:17.0557 0x1ab4  Dnscache - ok
17:11:17.0577 0x1ab4  [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc        C:\windows\System32\dot3svc.dll
17:11:17.0587 0x1ab4  dot3svc - ok
17:11:17.0607 0x1ab4  [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS            C:\windows\system32\dps.dll
17:11:17.0607 0x1ab4  DPS - ok
17:11:17.0627 0x1ab4  [ 26FE888505E5A945B0536AF9A2A27A6F, A6B16ED498BAFE300E1F0E0A241E3D62F7A1C5973EE775904ED14F33A2BC08A6 ] drmkaud        C:\windows\system32\drivers\drmkaud.sys
17:11:17.0627 0x1ab4  drmkaud - ok
17:11:17.0737 0x1ab4  [ 3A9D7D464BDB3B70D7ECF689ADABBD4D, B4F5B23705EA1BA453FE30791CA245E1A5F7FBEABAD026E4A8A15A9FC44E8C9C ] DXGKrnl        C:\windows\System32\drivers\dxgkrnl.sys
17:11:17.0797 0x1ab4  DXGKrnl - ok
17:11:17.0817 0x1ab4  [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost        C:\windows\System32\eapsvc.dll
17:11:17.0827 0x1ab4  EapHost - ok
17:11:17.0977 0x1ab4  [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv          C:\windows\system32\drivers\evbda.sys
17:11:18.0079 0x1ab4  ebdrv - ok
17:11:18.0118 0x1ab4  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] EFS            C:\windows\System32\lsass.exe
17:11:18.0119 0x1ab4  EFS - ok
17:11:18.0202 0x1ab4  [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr        C:\windows\ehome\ehRecvr.exe
17:11:18.0228 0x1ab4  ehRecvr - ok
17:11:18.0239 0x1ab4  [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched        C:\windows\ehome\ehsched.exe
17:11:18.0243 0x1ab4  ehSched - ok
17:11:18.0279 0x1ab4  [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor        C:\windows\system32\drivers\elxstor.sys
17:11:18.0298 0x1ab4  elxstor - ok
17:11:18.0301 0x1ab4  [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev          C:\windows\system32\drivers\errdev.sys
17:11:18.0301 0x1ab4  ErrDev - ok
17:11:18.0341 0x1ab4  [ 4D7F3114147C31390262F19F74E5BF07, E89F5304149B51327DFE1314AE13352923B752BC24585FF42F28EF5F00936A6A ] ESProtectionDriver C:\windows\system32\drivers\mbae64.sys
17:11:18.0341 0x1ab4  ESProtectionDriver - ok
17:11:18.0361 0x1ab4  [ 39EC51A5BC3E1C0D438E8AC70956DE0A, 456AE9C6E059442CA627AAB667CA498AA6F6A6812A177DCCB36D9CC24F11231A ] ETD            C:\windows\system32\DRIVERS\ETD.sys
17:11:18.0371 0x1ab4  ETD - ok
17:11:18.0431 0x1ab4  [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem    C:\windows\system32\es.dll
17:11:18.0461 0x1ab4  EventSystem - ok
17:11:18.0501 0x1ab4  [ 8ADACFFAD67394C711698EA074CE3BAB, 02793393584762224D87C487D80080D6DBCD09192098A7A1399CA16C17886C5D ] ewusbnet        C:\windows\system32\DRIVERS\ewusbnet.sys
17:11:18.0511 0x1ab4  ewusbnet - ok
17:11:18.0551 0x1ab4  [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat          C:\windows\system32\drivers\exfat.sys
17:11:18.0561 0x1ab4  exfat - ok
17:11:18.0621 0x1ab4  Fabs - ok
17:11:18.0661 0x1ab4  [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat        C:\windows\system32\drivers\fastfat.sys
17:11:18.0681 0x1ab4  fastfat - ok
17:11:18.0741 0x1ab4  [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax            C:\windows\system32\fxssvc.exe
17:11:18.0771 0x1ab4  Fax - ok
17:11:18.0801 0x1ab4  [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc            C:\windows\system32\drivers\fdc.sys
17:11:18.0801 0x1ab4  fdc - ok
17:11:18.0841 0x1ab4  [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost        C:\windows\system32\fdPHost.dll
17:11:18.0841 0x1ab4  fdPHost - ok
17:11:18.0861 0x1ab4  [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub        C:\windows\system32\fdrespub.dll
17:11:18.0861 0x1ab4  FDResPub - ok
17:11:18.0911 0x1ab4  [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo        C:\windows\system32\drivers\fileinfo.sys
17:11:18.0911 0x1ab4  FileInfo - ok
17:11:18.0921 0x1ab4  [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace      C:\windows\system32\drivers\filetrace.sys
17:11:18.0931 0x1ab4  Filetrace - ok
17:11:19.0031 0x1ab4  [ FFF1130F7C9FA01D093A1EDFC5CCE8FC, 159EAA1893D871C309A063829CB3BC51A019FBCA1E07530B5CA1A382B2CCAF61 ] FirebirdServerMAGIXInstance C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
17:11:19.0122 0x1ab4  FirebirdServerMAGIXInstance - ok
17:11:19.0152 0x1ab4  [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk        C:\windows\system32\drivers\flpydisk.sys
17:11:19.0153 0x1ab4  flpydisk - ok
17:11:19.0194 0x1ab4  [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr          C:\windows\system32\drivers\fltmgr.sys
17:11:19.0203 0x1ab4  FltMgr - ok
17:11:19.0300 0x1ab4  [ 700A5373FA66F1DAAECBD2CFB88C73ED, D6C1C4C846BC24EB6539ECC701A456FA53BB6679C79391F5B70580D47B6CE395 ] FontCache      C:\windows\system32\FntCache.dll
17:11:19.0339 0x1ab4  FontCache - ok
17:11:19.0376 0x1ab4  [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
17:11:19.0386 0x1ab4  FontCache3.0.0.0 - ok
17:11:19.0406 0x1ab4  [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends      C:\windows\system32\drivers\FsDepends.sys
17:11:19.0416 0x1ab4  FsDepends - ok
17:11:19.0456 0x1ab4  [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec          C:\windows\system32\drivers\Fs_Rec.sys
17:11:19.0466 0x1ab4  Fs_Rec - ok
17:11:19.0506 0x1ab4  [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol          C:\windows\system32\DRIVERS\fvevol.sys
17:11:19.0516 0x1ab4  fvevol - ok
17:11:19.0536 0x1ab4  [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx        C:\windows\system32\drivers\gagp30kx.sys
17:11:19.0546 0x1ab4  gagp30kx - ok
17:11:19.0606 0x1ab4  [ E4AE497857409127ED57562AF913A903, 262ADD713B1FBF6200550967D1F8635B55D01BBD8FA2E753536E71A4EC87867B ] gpsvc          C:\windows\System32\gpsvc.dll
17:11:19.0636 0x1ab4  gpsvc - ok
17:11:19.0716 0x1ab4  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:11:19.0716 0x1ab4  gupdate - ok
17:11:19.0746 0x1ab4  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:11:19.0746 0x1ab4  gupdatem - ok
17:11:19.0766 0x1ab4  [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir        C:\windows\system32\drivers\hcw85cir.sys
17:11:19.0766 0x1ab4  hcw85cir - ok
17:11:19.0786 0x1ab4  [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
17:11:19.0806 0x1ab4  HdAudAddService - ok
17:11:19.0836 0x1ab4  [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus        C:\windows\system32\DRIVERS\HDAudBus.sys
17:11:19.0836 0x1ab4  HDAudBus - ok
17:11:19.0856 0x1ab4  [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt        C:\windows\system32\drivers\HidBatt.sys
17:11:19.0866 0x1ab4  HidBatt - ok
17:11:19.0866 0x1ab4  [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth          C:\windows\system32\drivers\hidbth.sys
17:11:19.0876 0x1ab4  HidBth - ok
17:11:19.0876 0x1ab4  [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr          C:\windows\system32\drivers\hidir.sys
17:11:19.0876 0x1ab4  HidIr - ok
17:11:19.0916 0x1ab4  [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv        C:\windows\system32\hidserv.dll
17:11:19.0916 0x1ab4  hidserv - ok
17:11:19.0956 0x1ab4  [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb          C:\windows\system32\DRIVERS\hidusb.sys
17:11:19.0956 0x1ab4  HidUsb - ok
17:11:19.0986 0x1ab4  [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc          C:\windows\system32\kmsvc.dll
17:11:19.0996 0x1ab4  hkmsvc - ok
17:11:20.0016 0x1ab4  [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\windows\system32\ListSvc.dll
17:11:20.0016 0x1ab4  HomeGroupListener - ok
17:11:20.0046 0x1ab4  [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\windows\system32\provsvc.dll
17:11:20.0046 0x1ab4  HomeGroupProvider - ok
17:11:20.0086 0x1ab4  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD          C:\windows\system32\drivers\HpSAMD.sys
17:11:20.0088 0x1ab4  HpSAMD - ok
17:11:20.0151 0x1ab4  [ F61634BEC53F73702A10DE69F6DCAF57, BBA7344CF3AB96A46D1A6F1D50F2758EA8D097FE558C38B4EF45C8C334AF96E1 ] HTTP            C:\windows\system32\drivers\HTTP.sys
17:11:20.0174 0x1ab4  HTTP - ok
17:11:20.0207 0x1ab4  [ D969D0E26C5B1E813B17066A8318D5D4, 27308902D216CD38F40B9341F40AFDCFEC09EA3122FB88E7C7A5C42D0433315D ] hwdatacard      C:\windows\system32\DRIVERS\ewusbmdm.sys
17:11:20.0210 0x1ab4  hwdatacard - ok
17:11:20.0231 0x1ab4  [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy        C:\windows\system32\drivers\hwpolicy.sys
17:11:20.0232 0x1ab4  hwpolicy - ok
17:11:20.0263 0x1ab4  [ B45B3647BA32749B94FA689175EC8C26, F0876ECA6FA66A296DB7E11FA9E4094D96064AE87EC21CC752C9B7E6A7DFEDD2 ] hwusbdev        C:\windows\system32\DRIVERS\ewusbdev.sys
17:11:20.0266 0x1ab4  hwusbdev - ok
17:11:20.0289 0x1ab4  [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt        C:\windows\system32\DRIVERS\i8042prt.sys
17:11:20.0292 0x1ab4  i8042prt - ok
17:11:20.0320 0x1ab4  [ B9E489CC1EA3284FEED33799DC70612D, 0DD714A3A37C391B38F4EEEB3F85C3C3C056F4AAB4A5EFA63835AD967BC25B51 ] iaStorA        C:\windows\system32\drivers\iaStorA.sys
17:11:20.0331 0x1ab4  iaStorA - ok
17:11:20.0402 0x1ab4  [ 3AEE4C821114AC707699A28988F27ABB, 033A25A19E2A649DA059AE3BCACB8605C00D4F10D356C5E3167B84C01B9359A9 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
17:11:20.0402 0x1ab4  IAStorDataMgrSvc - ok
17:11:20.0462 0x1ab4  [ CC096E5C9BAABEB8EF12CDFAFFD888CF, 9D61736CB83DE04FC44FB25122AB6D09951C915E577E1A18188D4D5F35EACD76 ] iaStorF        C:\windows\system32\drivers\iaStorF.sys
17:11:20.0462 0x1ab4  iaStorF - ok
17:11:20.0502 0x1ab4  [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV        C:\windows\system32\drivers\iaStorV.sys
17:11:20.0532 0x1ab4  iaStorV - ok
17:11:20.0582 0x1ab4  [ 1B904E09172A2D63CB728F56B9DC72AA, E83D8A55319B378EB76A88EF778F69F560C8F2541BBD58151754509008D1A2C5 ] ICCWDT          C:\windows\system32\DRIVERS\ICCWDT.sys
17:11:20.0582 0x1ab4  ICCWDT - ok
17:11:20.0652 0x1ab4  [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc          C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
17:11:20.0692 0x1ab4  idsvc - ok
17:11:20.0702 0x1ab4  IEEtwCollectorService - ok
17:11:20.0882 0x1ab4  [ 5268F385C889BB942E0F9596DE83373F, 011280191EEF8053CD413734A0B08F5DF88CD8408CD8354AABF2216F4C59F921 ] igfx            C:\windows\system32\DRIVERS\igdkmd64.sys
17:11:21.0012 0x1ab4  igfx - ok
17:11:21.0043 0x1ab4  [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp          C:\windows\system32\drivers\iirsp.sys
17:11:21.0045 0x1ab4  iirsp - ok
17:11:21.0086 0x1ab4  [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT          C:\windows\System32\ikeext.dll
17:11:21.0120 0x1ab4  IKEEXT - ok
17:11:21.0277 0x1ab4  [ D739148367AAE1DA0C12160DE141ECED, 471E6EA03F2BD7DD1E2812B56EFB00EDDCAA87E974833B75114B8EE93DC358A5 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHD64.sys
17:11:21.0410 0x1ab4  IntcAzAudAddService - ok
17:11:21.0462 0x1ab4  [ 0E0B99617ED3FDB6C5F0E2D62709B5DF, A656CA3A60E62BE16A015150B23136CE150F9876B4035E9E8D8E73D1707B37A4 ] IntcDAud        C:\windows\system32\DRIVERS\IntcDAud.sys
17:11:21.0469 0x1ab4  IntcDAud - ok
17:11:21.0528 0x1ab4  [ C6128F2E3DC6156C6F8828F9F1B96010, 612C1191AFB8F69BA5634E8C52BDDE608F57D98FA4C76C5A337676A5F1E8191D ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
17:11:21.0562 0x1ab4  Intel(R) Capability Licensing Service Interface - ok
17:11:21.0605 0x1ab4  [ 729AB4F0608E95EFF8FDEF23596283E2, 62A2091FF440C65505AB3E38436A86D9B0978BCB9485960EFCE0C5CBC8E06201 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
17:11:21.0637 0x1ab4  Intel(R) Capability Licensing Service TCP IP Interface - ok
17:11:21.0667 0x1ab4  [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide        C:\windows\system32\drivers\intelide.sys
17:11:21.0667 0x1ab4  intelide - ok
17:11:21.0707 0x1ab4  [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm        C:\windows\system32\DRIVERS\intelppm.sys
17:11:21.0707 0x1ab4  intelppm - ok
17:11:21.0727 0x1ab4  [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum      C:\windows\system32\ipbusenum.dll
17:11:21.0737 0x1ab4  IPBusEnum - ok
17:11:21.0747 0x1ab4  [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver  C:\windows\system32\DRIVERS\ipfltdrv.sys
17:11:21.0747 0x1ab4  IpFilterDriver - ok
17:11:21.0777 0x1ab4  [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc        C:\windows\System32\iphlpsvc.dll
17:11:21.0797 0x1ab4  iphlpsvc - ok
17:11:21.0797 0x1ab4  [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV        C:\windows\system32\drivers\IPMIDrv.sys
17:11:21.0807 0x1ab4  IPMIDRV - ok
17:11:21.0807 0x1ab4  [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT          C:\windows\system32\drivers\ipnat.sys
17:11:21.0807 0x1ab4  IPNAT - ok
17:11:21.0817 0x1ab4  [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM          C:\windows\system32\drivers\irenum.sys
17:11:21.0827 0x1ab4  IRENUM - ok
17:11:21.0837 0x1ab4  [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp          C:\windows\system32\drivers\isapnp.sys
17:11:21.0837 0x1ab4  isapnp - ok
17:11:21.0867 0x1ab4  [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt        C:\windows\system32\drivers\msiscsi.sys
17:11:21.0877 0x1ab4  iScsiPrt - ok
17:11:21.0897 0x1ab4  [ 78D369F8A81A341109FBA1DB64B4C512, E584F693255CCBF7006E7D35984149CF599BB0849A8F02EFDD6223DF0D606049 ] iusb3hcs        C:\windows\system32\drivers\iusb3hcs.sys
17:11:21.0897 0x1ab4  iusb3hcs - ok
17:11:21.0967 0x1ab4  [ 5B632ABA038CE2E2D5D2D1115C6B26D1, 605A8FFA704E4369CF9D17DF8630DC9E196B8920D47F1CC5151759E60B234C1F ] iusb3hub        C:\windows\system32\DRIVERS\iusb3hub.sys
17:11:22.0017 0x1ab4  iusb3hub - ok
17:11:22.0068 0x1ab4  [ EA841584EF59528D11F20355770E427E, 515737761BB2A0A233F4AD141E28D93E3B9789320A15B7D5FB3DB5AC3CD8E249 ] iusb3xhc        C:\windows\system32\DRIVERS\iusb3xhc.sys
17:11:22.0092 0x1ab4  iusb3xhc - ok
17:11:22.0146 0x1ab4  [ 924019BC58FEDDE04A08C45EC1CF1847, F18C581FE5C25C5BE4514185AD44C561EB715B98AFBE81EF0D673E103EA8E8EE ] jhi_service    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
17:11:22.0150 0x1ab4  jhi_service - ok
17:11:22.0174 0x1ab4  [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass        C:\windows\system32\DRIVERS\kbdclass.sys
17:11:22.0176 0x1ab4  kbdclass - ok
17:11:22.0186 0x1ab4  [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid          C:\windows\system32\drivers\kbdhid.sys
17:11:22.0188 0x1ab4  kbdhid - ok
17:11:22.0203 0x1ab4  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] KeyIso          C:\windows\system32\lsass.exe
17:11:22.0204 0x1ab4  KeyIso - ok
17:11:22.0241 0x1ab4  [ 6F5F0C6160EF237F0243C1E416EEBA98, 8BA8AA0D71350A74E294A731226B1638C6059013D645ABDE7188F7733E320FBD ] KSecDD          C:\windows\system32\Drivers\ksecdd.sys
17:11:22.0244 0x1ab4  KSecDD - ok
17:11:22.0266 0x1ab4  [ 05529E53B286FD60E7EF04EF138CABFD, 6C045750DCD3EE76F748582513AD4FA99C0E8E56B616725CD48DCA1068FF8923 ] KSecPkg        C:\windows\system32\Drivers\ksecpkg.sys
17:11:22.0269 0x1ab4  KSecPkg - ok
17:11:22.0284 0x1ab4  [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk        C:\windows\system32\drivers\ksthunk.sys
17:11:22.0285 0x1ab4  ksthunk - ok
17:11:22.0328 0x1ab4  [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm          C:\windows\system32\msdtckrm.dll
17:11:22.0348 0x1ab4  KtmRm - ok
17:11:22.0358 0x1ab4  [ A6131EE7C440992458688C7D0989C584, 94FEB4A6677262BAA590F77329141D9F539D3466D6E9473D639880AA6D5A103C ] L1C            C:\windows\system32\DRIVERS\L1C62x64.sys
17:11:22.0368 0x1ab4  L1C - ok
17:11:22.0408 0x1ab4  [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer    C:\windows\system32\srvsvc.dll
17:11:22.0448 0x1ab4  LanmanServer - ok
17:11:22.0478 0x1ab4  [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\windows\System32\wkssvc.dll
17:11:22.0488 0x1ab4  LanmanWorkstation - ok
17:11:22.0618 0x1ab4  [ B91987F22C206191683F50085B160F4B, B55452540A9C28F14CDEB0A4514E2C6D0440710441673356485CA18165863AE7 ] LavasoftTcpService C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.2.9.5\LavasoftTcpService.exe
17:11:22.0648 0x1ab4  LavasoftTcpService - ok
17:11:22.0658 0x1ab4  [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio          C:\windows\system32\DRIVERS\lltdio.sys
17:11:22.0658 0x1ab4  lltdio - ok
17:11:22.0698 0x1ab4  [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc        C:\windows\System32\lltdsvc.dll
17:11:22.0698 0x1ab4  lltdsvc - ok
17:11:22.0708 0x1ab4  [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts        C:\windows\System32\lmhsvc.dll
17:11:22.0708 0x1ab4  lmhosts - ok
17:11:22.0758 0x1ab4  [ EC90A0554EAC7E37139F2DAD8C56FB04, F62DBB7B174A270700631EA590B3293FE558940FB72F84C242391530E1DF78B5 ] LMS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
17:11:22.0768 0x1ab4  LMS - ok
17:11:22.0798 0x1ab4  [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC          C:\windows\system32\drivers\lsi_fc.sys
17:11:22.0798 0x1ab4  LSI_FC - ok
17:11:22.0808 0x1ab4  [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS        C:\windows\system32\drivers\lsi_sas.sys
17:11:22.0818 0x1ab4  LSI_SAS - ok
17:11:22.0828 0x1ab4  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2        C:\windows\system32\drivers\lsi_sas2.sys
17:11:22.0828 0x1ab4  LSI_SAS2 - ok
17:11:22.0828 0x1ab4  [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI        C:\windows\system32\drivers\lsi_scsi.sys
17:11:22.0838 0x1ab4  LSI_SCSI - ok
17:11:22.0878 0x1ab4  [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv          C:\windows\system32\drivers\luafv.sys
17:11:22.0878 0x1ab4  luafv - ok
17:11:22.0898 0x1ab4  [ 3BEC6134F1E45AEF5E971F69F0D38510, 245D7CEEB6561166EE0472551D39A9D3CFDDA52A6BF2E924AB243CCA7FBC9009 ] MBAMChameleon  C:\windows\system32\drivers\MBAMChameleon.sys
17:11:22.0908 0x1ab4  MBAMChameleon - ok
17:11:22.0968 0x1ab4  [ F3960CA85778E5D7611EE0F501972340, 0DE5C8509A9A66C8185B9FAA7EAF69C0FA9C28CD9DE84AA23E128E4FF8E06BF4 ] MBAMFarflt      C:\windows\system32\drivers\farflt.sys
17:11:22.0978 0x1ab4  MBAMFarflt - ok
17:11:23.0045 0x1ab4  [ 88BD122C3A35DE63D75D382DF75554CE, ABDF59543CAD186A6ED4E66257205D9CF5047732A5DA74A96A28B468B41BC396 ] MBAMProtection  C:\windows\system32\drivers\mbam.sys
17:11:23.0048 0x1ab4  MBAMProtection - ok
17:11:23.0230 0x1ab4  [ 28E521A6ABA9DE062A3719452816F495, B312A37DA052229DFB19353170CD5828582F8AC6426E857CA7C8ACA0DD91C160 ] MBAMService    C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
17:11:23.0301 0x1ab4  MBAMService - ok
17:11:23.0345 0x1ab4  [ ABB371D9AEF728B0489B0E6872B4A1C0, E9539A4F85FE30F5BAED742778CA74C879995728668ABE6877C37633716D8770 ] MBAMSwissArmy  C:\windows\system32\drivers\MBAMSwissArmy.sys
17:11:23.0355 0x1ab4  MBAMSwissArmy - ok
17:11:23.0395 0x1ab4  [ 8FF2D95CBA49B405C5DE27039FF0BF35, 03BF7FC7F1C2C76EDB583BA342EA1C325DB8058517744EF2A78529D3938F4DC1 ] MBfilt          C:\windows\system32\drivers\MBfilt64.sys
17:11:23.0395 0x1ab4  MBfilt - ok
17:11:23.0495 0x1ab4  [ 1704A8189EE5580AB147CFD25C5C8770, DFA076FD36B5CC844D4BE3B865E9A1F809E14CCB1D78D82A2D8D8EE38210E6EB ] McComponentHostService C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
17:11:23.0525 0x1ab4  McComponentHostService - ok
17:11:23.0545 0x1ab4  [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc        C:\windows\system32\Mcx2Svc.dll
17:11:23.0555 0x1ab4  Mcx2Svc - ok
17:11:23.0565 0x1ab4  [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas        C:\windows\system32\drivers\megasas.sys
17:11:23.0565 0x1ab4  megasas - ok
17:11:23.0575 0x1ab4  [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR          C:\windows\system32\drivers\MegaSR.sys
17:11:23.0585 0x1ab4  MegaSR - ok
17:11:23.0615 0x1ab4  [ 2BB3EAE2EA641515D4B205CAB29E1624, D3F18EE393EB1B0F919484281269A3C55A092D023E62C59D74CB63A55612024B ] MEIx64          C:\windows\system32\drivers\HECIx64.sys
17:11:23.0625 0x1ab4  MEIx64 - ok
17:11:23.0645 0x1ab4  MGHwCtrl - ok
17:11:23.0685 0x1ab4  [ 71C6748EE8DE938532057EF10B4B7E44, 455175332156939B3CDA4511A2A6C213ABBFDB85EEECA98B6AB014C994F532C4 ] Micro Star SCM  C:\Program Files (x86)\SCM\MSIService.exe
17:11:23.0695 0x1ab4  Micro Star SCM - ok
17:11:23.0715 0x1ab4  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS          C:\windows\system32\mmcss.dll
17:11:23.0725 0x1ab4  MMCSS - ok
17:11:23.0745 0x1ab4  [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem          C:\windows\system32\drivers\modem.sys
17:11:23.0755 0x1ab4  Modem - ok
17:11:23.0795 0x1ab4  [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor        C:\windows\system32\DRIVERS\monitor.sys
17:11:23.0795 0x1ab4  monitor - ok
17:11:23.0815 0x1ab4  [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass        C:\windows\system32\DRIVERS\mouclass.sys
17:11:23.0815 0x1ab4  mouclass - ok
17:11:23.0845 0x1ab4  [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid          C:\windows\system32\DRIVERS\mouhid.sys
17:11:23.0845 0x1ab4  mouhid - ok
17:11:23.0885 0x1ab4  [ 8ADB5445B29941CB41AF2846FD5C93C7, 689582430FE29EC0845B1DB841D3CC49D5D09DE264586E3999EEFE616986D12B ] mountmgr        C:\windows\system32\drivers\mountmgr.sys
17:11:23.0895 0x1ab4  mountmgr - ok
17:11:23.0945 0x1ab4  [ E464A0A92E2E354D07DDA713D3E10DE4, D5CF213F03DF54EF9933027A7A7D4413371C1ECBFF61E4DE818D50FA72C8C5FC ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
17:11:23.0965 0x1ab4  MozillaMaintenance - ok
17:11:24.0005 0x1ab4  [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio            C:\windows\system32\drivers\mpio.sys
17:11:24.0005 0x1ab4  mpio - ok
17:11:24.0048 0x1ab4  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv          C:\windows\system32\drivers\mpsdrv.sys
17:11:24.0050 0x1ab4  mpsdrv - ok
17:11:24.0094 0x1ab4  [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc          C:\windows\system32\mpssvc.dll
17:11:24.0129 0x1ab4  MpsSvc - ok
17:11:24.0168 0x1ab4  [ 98DB1790F0A584E0A2528B92B052417F, 9AA04CA73AFE599810CD233B9CEC212E16D44DCEDF5C7D0181C7257F498068B5 ] MRxDAV          C:\windows\system32\drivers\mrxdav.sys
17:11:24.0172 0x1ab4  MRxDAV - ok
17:11:24.0211 0x1ab4  [ 632E8A00090E4F85F304E152C92C7F2C, A3098941251A8327C95E6B1122384D54FB0ED705A9215577D968EA5B5FD88C87 ] mrxsmb          C:\windows\system32\DRIVERS\mrxsmb.sys
17:11:24.0219 0x1ab4  mrxsmb - ok
17:11:24.0273 0x1ab4  [ 0D9C05484F2F4BD9D33A615D5DBE67EA, 1E164B631B1CD85DD5B205284CB547B189609946490AAABD22741743BFB413DF ] mrxsmb10        C:\windows\system32\DRIVERS\mrxsmb10.sys
17:11:24.0293 0x1ab4  mrxsmb10 - ok
17:11:24.0325 0x1ab4  [ 6123E6FECC1C164022868FB1982271BE, 417E6C7AFF8B014B31AFCC202B0DCEECBDBB73205DF8C3EFC7E313664E284178 ] mrxsmb20        C:\windows\system32\DRIVERS\mrxsmb20.sys
17:11:24.0325 0x1ab4  mrxsmb20 - ok
17:11:24.0355 0x1ab4  [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci          C:\windows\system32\drivers\msahci.sys
17:11:24.0355 0x1ab4  msahci - ok
17:11:24.0385 0x1ab4  [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm          C:\windows\system32\drivers\msdsm.sys
17:11:24.0395 0x1ab4  msdsm - ok
17:11:24.0425 0x1ab4  [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC          C:\windows\System32\msdtc.exe
17:11:24.0435 0x1ab4  MSDTC - ok
17:11:24.0445 0x1ab4  [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs            C:\windows\system32\drivers\Msfs.sys
17:11:24.0455 0x1ab4  Msfs - ok
17:11:24.0465 0x1ab4  [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf      C:\windows\System32\drivers\mshidkmdf.sys
17:11:24.0465 0x1ab4  mshidkmdf - ok
17:11:24.0515 0x1ab4  [ 87B9DAF6D123EC06C19B41D5295441AD, 2066EA70D85B9F17CA3121D69DB25E2E17C4AFAECB68CC97FFF4A3062099FF0C ] MSI Foundation Service C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe
17:11:24.0515 0x1ab4  MSI Foundation Service - ok
17:11:24.0555 0x1ab4  [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv        C:\windows\system32\drivers\msisadrv.sys
17:11:24.0555 0x1ab4  msisadrv - ok
17:11:24.0585 0x1ab4  [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI        C:\windows\system32\iscsiexe.dll
17:11:24.0595 0x1ab4  MSiSCSI - ok
17:11:24.0605 0x1ab4  msiserver - ok
17:11:24.0625 0x1ab4  [ 6DC2A478749CB24DC2DCE92A92DE3288, 86D74A6002E16C0ED7B9A933E88DF006E3D9299D14D29A05D61B5BD48E05BE87 ] MSI_SuperCharger C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
17:11:24.0625 0x1ab4  MSI_SuperCharger - ok
17:11:24.0655 0x1ab4  [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV        C:\windows\system32\drivers\MSKSSRV.sys
17:11:24.0655 0x1ab4  MSKSSRV - ok
17:11:24.0665 0x1ab4  [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK        C:\windows\system32\drivers\MSPCLOCK.sys
17:11:24.0665 0x1ab4  MSPCLOCK - ok
17:11:24.0685 0x1ab4  [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM          C:\windows\system32\drivers\MSPQM.sys
17:11:24.0685 0x1ab4  MSPQM - ok
17:11:24.0715 0x1ab4  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC          C:\windows\system32\drivers\MsRPC.sys
17:11:24.0725 0x1ab4  MsRPC - ok
17:11:24.0755 0x1ab4  [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios        C:\windows\system32\drivers\mssmbios.sys
17:11:24.0755 0x1ab4  mssmbios - ok
17:11:24.0765 0x1ab4  [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE          C:\windows\system32\drivers\MSTEE.sys
17:11:24.0765 0x1ab4  MSTEE - ok
17:11:24.0775 0x1ab4  [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig        C:\windows\system32\drivers\MTConfig.sys
17:11:24.0775 0x1ab4  MTConfig - ok
17:11:24.0795 0x1ab4  [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup            C:\windows\system32\Drivers\mup.sys
17:11:24.0795 0x1ab4  Mup - ok
17:11:24.0825 0x1ab4  [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent        C:\windows\system32\qagentRT.dll
17:11:24.0835 0x1ab4  napagent - ok
17:11:24.0885 0x1ab4  [ 8D11DA92F83D8C8281689739BEF05FD5, AD1D95CE084D1BD8310F6AA1CB27BEA98D9354E334AEC448AD6E6F68B52EEBC7 ] NAT            C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe
17:11:24.0885 0x1ab4  NAT - ok
17:11:24.0935 0x1ab4  [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP    C:\windows\system32\DRIVERS\nwifi.sys
17:11:24.0965 0x1ab4  NativeWifiP - ok
17:11:25.0061 0x1ab4  [ F7309F42555F8AAB7144A51A1F2585B0, 065277A8AFAEE3888C997A76D2F751070F92DF4C3354D16B194860B4BDAFF937 ] NDIS            C:\windows\system32\drivers\ndis.sys
17:11:25.0111 0x1ab4  NDIS - ok
17:11:25.0176 0x1ab4  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap        C:\windows\system32\DRIVERS\ndiscap.sys
17:11:25.0178 0x1ab4  NdisCap - ok
17:11:25.0195 0x1ab4  [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi        C:\windows\system32\DRIVERS\ndistapi.sys
17:11:25.0197 0x1ab4  NdisTapi - ok
17:11:25.0232 0x1ab4  [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio        C:\windows\system32\DRIVERS\ndisuio.sys
17:11:25.0236 0x1ab4  Ndisuio - ok
17:11:25.0252 0x1ab4  [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan        C:\windows\system32\DRIVERS\ndiswan.sys
17:11:25.0257 0x1ab4  NdisWan - ok
17:11:25.0292 0x1ab4  [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy        C:\windows\system32\drivers\NDProxy.sys
17:11:25.0294 0x1ab4  NDProxy - ok
17:11:25.0311 0x1ab4  [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS        C:\windows\system32\DRIVERS\netbios.sys
17:11:25.0321 0x1ab4  NetBIOS - ok
17:11:25.0381 0x1ab4  [ E47D571FEC2C76E867935109AB2A770C, F349D25890B6F476B106FD75BFB081DB737CA9B224D95E44927942FFF2DF82CD ] NetBT          C:\windows\system32\DRIVERS\netbt.sys
17:11:25.0391 0x1ab4  NetBT - ok
17:11:25.0421 0x1ab4  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] Netlogon        C:\windows\system32\lsass.exe
17:11:25.0421 0x1ab4  Netlogon - ok
17:11:25.0471 0x1ab4  [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman          C:\windows\System32\netman.dll
17:11:25.0511 0x1ab4  Netman - ok
17:11:25.0581 0x1ab4  [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetMsmqActivator C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:11:25.0601 0x1ab4  NetMsmqActivator - ok
17:11:25.0611 0x1ab4  [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetPipeActivator C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:11:25.0611 0x1ab4  NetPipeActivator - ok
17:11:25.0641 0x1ab4  [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm        C:\windows\System32\netprofm.dll
17:11:25.0651 0x1ab4  netprofm - ok
17:11:25.0661 0x1ab4  [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetTcpActivator C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:11:25.0661 0x1ab4  NetTcpActivator - ok
17:11:25.0671 0x1ab4  [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:11:25.0671 0x1ab4  NetTcpPortSharing - ok
17:11:25.0701 0x1ab4  [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960        C:\windows\system32\drivers\nfrd960.sys
17:11:25.0701 0x1ab4  nfrd960 - ok
17:11:25.0721 0x1ab4  [ 8B301D474B478E9A92823BAB50A7BC49, 8181816035F41B1DABEC05E65E4F67BCD785F56760A61F1049E91BA39D42F01D ] NlaSvc          C:\windows\System32\nlasvc.dll
17:11:25.0731 0x1ab4  NlaSvc - ok
17:11:25.0901 0x1ab4  [ FD8082D64C151589F12A4F620DBA3030, 649D61BF958ED50C0B5F7E0D2E633D20C8AAA00706A7AE9528DA78E2B6B3492E ] NOBU            C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
17:11:26.0031 0x1ab4  NOBU - ok
17:11:26.0065 0x1ab4  Norton PC Checkup Application Launcher - ok
17:11:26.0086 0x1ab4  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs            C:\windows\system32\drivers\Npfs.sys
17:11:26.0087 0x1ab4  Npfs - ok
17:11:26.0106 0x1ab4  [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi            C:\windows\system32\nsisvc.dll
17:11:26.0109 0x1ab4  nsi - ok
17:11:26.0157 0x1ab4  [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy        C:\windows\system32\drivers\nsiproxy.sys
17:11:26.0158 0x1ab4  nsiproxy - ok
17:11:26.0252 0x1ab4  [ 47B2D0B31BDC3EBE6090228E2BA3764D, 984A4B38300954164BCBF57EC1A09C18B53779E60A26E9618B50E26016735787 ] Ntfs            C:\windows\system32\drivers\Ntfs.sys
17:11:26.0303 0x1ab4  Ntfs - ok
17:11:26.0364 0x1ab4  [ 23CF3DA010497EB2BF39A5C5A57E437C, 39CFDE7D401EFCE4F550E0A9461F5FC4D71FA07235E1336E4F0B4882BD76550E ] NTIOLib_1_0_3  C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys
17:11:26.0364 0x1ab4  NTIOLib_1_0_3 - ok
17:11:26.0414 0x1ab4  [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null            C:\windows\system32\drivers\Null.sys
17:11:26.0414 0x1ab4  Null - ok
17:11:26.0444 0x1ab4  [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid          C:\windows\system32\drivers\nvraid.sys
17:11:26.0454 0x1ab4  nvraid - ok
17:11:26.0454 0x1ab4  [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor          C:\windows\system32\drivers\nvstor.sys
17:11:26.0464 0x1ab4  nvstor - ok
17:11:26.0474 0x1ab4  [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp          C:\windows\system32\drivers\nv_agp.sys
17:11:26.0474 0x1ab4  nv_agp - ok
17:11:26.0484 0x1ab4  [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394        C:\windows\system32\drivers\ohci1394.sys
17:11:26.0484 0x1ab4  ohci1394 - ok
17:11:26.0514 0x1ab4  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc        C:\windows\system32\pnrpsvc.dll
17:11:26.0524 0x1ab4  p2pimsvc - ok
17:11:26.0554 0x1ab4  [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc          C:\windows\system32\p2psvc.dll
17:11:26.0564 0x1ab4  p2psvc - ok
17:11:26.0584 0x1ab4  panda_url_filtering - ok
17:11:26.0634 0x1ab4  [ 6925454E20B184E482CD65F297D51DB5, 9386542E9B20C370FCB275C7F8005DAD45C86BBC2F7B8DB3552FA49B474C5EED ] panda_url_filteringd C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys
17:11:26.0634 0x1ab4  panda_url_filteringd - ok
17:11:26.0664 0x1ab4  [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport        C:\windows\system32\drivers\parport.sys
17:11:26.0674 0x1ab4  Parport - ok
17:11:26.0704 0x1ab4  [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr        C:\windows\system32\drivers\partmgr.sys
17:11:26.0704 0x1ab4  partmgr - ok
17:11:26.0814 0x1ab4  [ 64DAD6D8A41725325BDAD78E566ACB34, 6599C5C1F8DF5BB85C0DBE4300DF1F4C015E00720B28951149D5924D65FD3DF8 ] pbamw_service  C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\AmwService.exe
17:11:26.0824 0x1ab4  pbamw_service - ok
17:11:26.0864 0x1ab4  [ 3CD83692C43D87088E85E3C916146FFB, 9E812535E8FBA045FDA30F68E9EB2031132C37721D542A2DC9D4C33E2B137FCF ] PcaSvc          C:\windows\System32\pcasvc.dll
17:11:26.0884 0x1ab4  PcaSvc - ok
17:11:26.0924 0x1ab4  [ 2F86BE1818C2D7AC90478E3323EE7FCB, CE721FCFFDC9D24483DEB6BB77DAFEBE79BA143CA2EE68BF28E2A9297AADB2D4 ] PCCUJobMgr      C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe
17:11:26.0924 0x1ab4  PCCUJobMgr - ok
17:11:26.0974 0x1ab4  [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci            C:\windows\system32\drivers\pci.sys
17:11:26.0984 0x1ab4  pci - ok
17:11:27.0014 0x1ab4  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide          C:\windows\system32\drivers\pciide.sys
17:11:27.0014 0x1ab4  pciide - ok
17:11:27.0051 0x1ab4  [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia          C:\windows\system32\drivers\pcmcia.sys
17:11:27.0062 0x1ab4  pcmcia - ok
17:11:27.0107 0x1ab4  [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw            C:\windows\system32\drivers\pcw.sys
17:11:27.0109 0x1ab4  pcw - ok
17:11:27.0208 0x1ab4  [ 8F98C4BC605261B4B6E568FE791EB67A, 7B0D99D972A60423F7378BEE886061695FDA79B59AFF939744A130721E0174A1 ] PDF Architect 2 C:\Program Files (x86)\PDF Architect 2\ws.exe
17:11:27.0265 0x1ab4  PDF Architect 2 - ok
17:11:27.0355 0x1ab4  [ B2309F132A31AF03C0A249AEDE8CF289, BBAE32AA55E495ACB9A8089C090ADD78BE1DC16233CAA61BBED1456CA718D430 ] PDF Architect 2 Creator C:\Program Files (x86)\PDF Architect 2\creator-ws.exe
17:11:27.0365 0x1ab4  PDF Architect 2 Creator - ok
17:11:27.0405 0x1ab4  [ 9077A3059AB47834633AEAAED465F3D9, 9CA662E9CBA30795E4E5DAB3E309D2062FFDC2053C261054E24EF7EE5300F69F ] pdfforge CrashHandler C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe
17:11:27.0435 0x1ab4  pdfforge CrashHandler - ok
17:11:27.0505 0x1ab4  [ EA4D67448BE493D543F1730D6CD04694, 24717C5E41B7CA522F3330EF2228B6685E710A5259396E9887A1C1E7A413F8CA ] PEAUTH          C:\windows\system32\drivers\peauth.sys
17:11:27.0535 0x1ab4  PEAUTH - ok
17:11:27.0605 0x1ab4  [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost        C:\windows\SysWow64\perfhost.exe
17:11:27.0605 0x1ab4  PerfHost - ok
17:11:27.0685 0x1ab4  [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla            C:\windows\system32\pla.dll
17:11:27.0735 0x1ab4  pla - ok
17:11:27.0795 0x1ab4  [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay        C:\windows\system32\umpnpmgr.dll
17:11:27.0815 0x1ab4  PlugPlay - ok
17:11:27.0835 0x1ab4  [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg    C:\windows\system32\pnrpauto.dll
17:11:27.0835 0x1ab4  PNRPAutoReg - ok
17:11:27.0855 0x1ab4  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc        C:\windows\system32\pnrpsvc.dll
17:11:27.0865 0x1ab4  PNRPsvc - ok
17:11:27.0895 0x1ab4  [ 80D6B0563ED2BF10656B1D4748331082, B7E6B5E1148B7EE537E8D5C3A65450876B61CD45A395267D08699746E98AD574 ] PolicyAgent    C:\windows\System32\ipsecsvc.dll
17:11:27.0905 0x1ab4  PolicyAgent - ok
17:11:27.0935 0x1ab4  [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power          C:\windows\system32\umpo.dll
17:11:27.0935 0x1ab4  Power - ok
17:11:27.0955 0x1ab4  [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport    C:\windows\system32\DRIVERS\raspptp.sys
17:11:27.0955 0x1ab4  PptpMiniport - ok
17:11:27.0985 0x1ab4  [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor      C:\windows\system32\drivers\processr.sys
17:11:27.0985 0x1ab4  Processor - ok
17:11:28.0005 0x1ab4  [ B6A58491307B4CADA572583D863DC602, 5C44936605E52C9533E4CE22F18FAB8211475877F71EFD88DA4D02FD608C90A3 ] ProfSvc        C:\windows\system32\profsvc.dll
17:11:28.0015 0x1ab4  ProfSvc - ok
17:11:28.0037 0x1ab4  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] ProtectedStorage C:\windows\system32\lsass.exe
17:11:28.0039 0x1ab4  ProtectedStorage - ok
17:11:28.0086 0x1ab4  [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched          C:\windows\system32\DRIVERS\pacer.sys
17:11:28.0090 0x1ab4  Psched - ok
17:11:28.0147 0x1ab4  [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300          C:\windows\system32\drivers\ql2300.sys
17:11:28.0191 0x1ab4  ql2300 - ok
17:11:28.0209 0x1ab4  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx          C:\windows\system32\drivers\ql40xx.sys
17:11:28.0212 0x1ab4  ql40xx - ok
17:11:28.0245 0x1ab4  [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE          C:\windows\system32\qwave.dll
17:11:28.0253 0x1ab4  QWAVE - ok
17:11:28.0266 0x1ab4  [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv        C:\windows\system32\drivers\qwavedrv.sys
17:11:28.0268 0x1ab4  QWAVEdrv - ok
17:11:28.0327 0x1ab4  [ A55E7D0D873B2C97585B3B5926AC6ADE, 3BE3895DA7F0888E85B1941525878BA0846A8F215AD39ED8138BB39615468E32 ] RapiMgr        C:\windows\WindowsMobile\rapimgr.dll
17:11:28.0337 0x1ab4  RapiMgr - ok
17:11:28.0357 0x1ab4  [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd          C:\windows\system32\DRIVERS\rasacd.sys
17:11:28.0357 0x1ab4  RasAcd - ok
17:11:28.0377 0x1ab4  [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn    C:\windows\system32\DRIVERS\AgileVpn.sys
17:11:28.0377 0x1ab4  RasAgileVpn - ok
17:11:28.0407 0x1ab4  [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto        C:\windows\System32\rasauto.dll
17:11:28.0407 0x1ab4  RasAuto - ok
17:11:28.0447 0x1ab4  [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp        C:\windows\system32\DRIVERS\rasl2tp.sys
17:11:28.0447 0x1ab4  Rasl2tp - ok
17:11:28.0477 0x1ab4  [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan          C:\windows\System32\rasmans.dll
17:11:28.0487 0x1ab4  RasMan - ok
17:11:28.0497 0x1ab4  [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe        C:\windows\system32\DRIVERS\raspppoe.sys
17:11:28.0507 0x1ab4  RasPppoe - ok
17:11:28.0517 0x1ab4  [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp        C:\windows\system32\DRIVERS\rassstp.sys
17:11:28.0517 0x1ab4  RasSstp - ok
17:11:28.0587 0x1ab4  [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss          C:\windows\system32\DRIVERS\rdbss.sys
17:11:28.0617 0x1ab4  rdbss - ok
17:11:28.0627 0x1ab4  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus          C:\windows\system32\drivers\rdpbus.sys
17:11:28.0637 0x1ab4  rdpbus - ok
17:11:28.0647 0x1ab4  [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD          C:\windows\system32\DRIVERS\RDPCDD.sys
17:11:28.0647 0x1ab4  RDPCDD - ok
17:11:28.0667 0x1ab4  [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD        C:\windows\system32\drivers\rdpencdd.sys
17:11:28.0667 0x1ab4  RDPENCDD - ok
17:11:28.0677 0x1ab4  [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP        C:\windows\system32\drivers\rdprefmp.sys
17:11:28.0677 0x1ab4  RDPREFMP - ok
17:11:28.0767 0x1ab4  [ 313F68E1A3E6345A4F47A36B07062F34, B8318A0AE06BDE278931CA52F960B9FE226FD9894B076858DDB755AE26E1E66F ] RdpVideoMiniport C:\windows\system32\drivers\rdpvideominiport.sys
17:11:28.0767 0x1ab4  RdpVideoMiniport - ok
17:11:28.0807 0x1ab4  [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD          C:\windows\system32\drivers\RDPWD.sys
17:11:28.0807 0x1ab4  RDPWD - ok
17:11:28.0837 0x1ab4  [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost        C:\windows\system32\drivers\rdyboost.sys
17:11:28.0837 0x1ab4  rdyboost - ok
17:11:28.0887 0x1ab4  [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess    C:\windows\System32\mprdim.dll
17:11:28.0897 0x1ab4  RemoteAccess - ok
17:11:28.0917 0x1ab4  [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry  C:\windows\system32\regsvc.dll
17:11:28.0927 0x1ab4  RemoteRegistry - ok
17:11:28.0957 0x1ab4  [ 3DD798846E2C28102B922C56E71B7932, 30B111615D74CB2213997A5C08DD9C8613ADE441D9423CC1C49A753D13CE524D ] RFCOMM          C:\windows\system32\DRIVERS\rfcomm.sys
17:11:28.0967 0x1ab4  RFCOMM - ok
17:11:28.0977 0x1ab4  [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper    C:\windows\System32\RpcEpMap.dll
17:11:28.0987 0x1ab4  RpcEptMapper - ok
17:11:28.0997 0x1ab4  [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator      C:\windows\system32\locator.exe
17:11:28.0997 0x1ab4  RpcLocator - ok
17:11:29.0087 0x1ab4  [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] RpcSs          C:\windows\system32\rpcss.dll
17:11:29.0102 0x1ab4  RpcSs - ok
17:11:29.0143 0x1ab4  [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr          C:\windows\system32\DRIVERS\rspndr.sys
17:11:29.0146 0x1ab4  rspndr - ok
17:11:29.0201 0x1ab4  [ 135A64530D7699AD48F29D73A658DD11, 35838AE8ACFD9047C68DD0C8910557A82998E5CD778D5B98D4767AFA4BCE85BB ] RSUSBSTOR      C:\windows\System32\Drivers\RtsUStor.sys
17:11:29.0206 0x1ab4  RSUSBSTOR - ok
17:11:29.0253 0x1ab4  [ 8FA11ECB00AED22ACFEA154B7981D9E6, E72363AB33B17B4942187DADEC8DD9ECB047D2BCAE359148FA2F70EEF935264E ] RtkAvrcp        C:\windows\system32\drivers\RtkAvrcp.sys
17:11:29.0257 0x1ab4  RtkAvrcp - ok
17:11:29.0285 0x1ab4  [ 8008A68D94F4CF164CD636E8A4F8FB0A, 3E8E9DFC397737798AEE920A75D5355651FF823685309641711E9A6396AA6D5F ] RtkAvrcpCtrlr  C:\windows\system32\drivers\RtkAvrcpCtrlr.sys
17:11:29.0289 0x1ab4  RtkAvrcpCtrlr - ok
17:11:29.0343 0x1ab4  [ 543AFFECD35CFABD4490661F83685A0D, 819C022284E54C950D1144B9260C944D493CB4646713B30790818EFC99B82CCB ] RtkBleServ      C:\Program Files (x86)\REALTEK\Realtek Bluetooth\RtkBleServ.exe
17:11:29.0343 0x1ab4  RtkBleServ - ok
17:11:29.0393 0x1ab4  [ 0772C3A9B2AB1907FCB68F2109F18E3B, FECAF1916CE9224D1784F5F99267B95A21969937DB57833FCD6C6118D0A442DC ] RtkBtFilter    C:\windows\system32\DRIVERS\RtkBtfilter.sys
17:11:29.0433 0x1ab4  RtkBtFilter - ok
17:11:29.0553 0x1ab4  [ F84917461BDB7C51B2ED7FF062B3A64A, 0DC81BA49BDDB4F425F526A21357E1CF70C94D67E99B3020E9FF14B680851EEC ] RTWlanE        C:\windows\system32\DRIVERS\rtwlane.sys
17:11:29.0613 0x1ab4  RTWlanE - ok
17:11:29.0633 0x1ab4  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] SamSs          C:\windows\system32\lsass.exe
17:11:29.0643 0x1ab4  SamSs - ok
17:11:29.0673 0x1ab4  [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port        C:\windows\system32\drivers\sbp2port.sys
17:11:29.0683 0x1ab4  sbp2port - ok
17:11:29.0733 0x1ab4  [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr        C:\windows\System32\SCardSvr.dll
17:11:29.0753 0x1ab4  SCardSvr - ok
17:11:29.0793 0x1ab4  [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter        C:\windows\system32\DRIVERS\scfilter.sys
17:11:29.0793 0x1ab4  scfilter - ok
17:11:29.0883 0x1ab4  [ 40686B59C127F0C93B4234E4A1E3472A, B2DD61CB796C6AA8AFD285D43472B94646CA6D331D282818E0FDC9DE28DDE9CF ] Schedule        C:\windows\system32\schedsvc.dll
17:11:29.0923 0x1ab4  Schedule - ok
17:11:29.0953 0x1ab4  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc    C:\windows\System32\certprop.dll
17:11:29.0953 0x1ab4  SCPolicySvc - ok
17:11:29.0973 0x1ab4  [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC          C:\windows\System32\SDRSVC.dll
17:11:29.0983 0x1ab4  SDRSVC - ok
17:11:30.0049 0x1ab4  [ 07EEDE29DF77E80EC93AE709CCD80B41, B5DF5F3108815094F0259004E093F56551A70AF6CBE02C3CBDC894589E3ADD38 ] SearchProtectionService C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
17:11:30.0051 0x1ab4  SearchProtectionService - ok
17:11:30.0099 0x1ab4  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\windows\system32\drivers\secdrv.sys
17:11:30.0102 0x1ab4  secdrv - ok
17:11:30.0136 0x1ab4  [ A19623BDD61E66A12AB53992002B4F3A, E351CEEC086084A417BA3BD0EEF46114D3147EC38E3EF8BE49B724F9D028CC56 ] seclogon        C:\windows\system32\seclogon.dll
17:11:30.0139 0x1ab4  seclogon - ok
17:11:30.0166 0x1ab4  [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS            C:\windows\System32\sens.dll
17:11:30.0170 0x1ab4  SENS - ok
17:11:30.0185 0x1ab4  [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc        C:\windows\system32\sensrsvc.dll
17:11:30.0187 0x1ab4  SensrSvc - ok
17:11:30.0204 0x1ab4  [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum        C:\windows\system32\drivers\serenum.sys
17:11:30.0206 0x1ab4  Serenum - ok
17:11:30.0210 0x1ab4  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial          C:\windows\system32\drivers\serial.sys
17:11:30.0214 0x1ab4  Serial - ok
17:11:30.0217 0x1ab4  [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse        C:\windows\system32\drivers\sermouse.sys
17:11:30.0218 0x1ab4  sermouse - ok
17:11:30.0236 0x1ab4  [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv      C:\windows\system32\sessenv.dll
17:11:30.0240 0x1ab4  SessionEnv - ok
17:11:30.0245 0x1ab4  [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk        C:\windows\system32\drivers\sffdisk.sys
17:11:30.0246 0x1ab4  sffdisk - ok
17:11:30.0250 0x1ab4  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc        C:\windows\system32\drivers\sffp_mmc.sys
17:11:30.0251 0x1ab4  sffp_mmc - ok
17:11:30.0255 0x1ab4  [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd        C:\windows\system32\drivers\sffp_sd.sys
17:11:30.0256 0x1ab4  sffp_sd - ok
17:11:30.0262 0x1ab4  [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy        C:\windows\system32\drivers\sfloppy.sys
17:11:30.0264 0x1ab4  sfloppy - ok
17:11:30.0319 0x1ab4  [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess    C:\windows\System32\ipnathlp.dll
17:11:30.0319 0x1ab4  SharedAccess - ok
17:11:30.0349 0x1ab4  [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\windows\System32\shsvcs.dll
17:11:30.0359 0x1ab4  ShellHWDetection - ok
17:11:30.0379 0x1ab4  [ E9E830D540EDEDED650F906628468548, 9800160C6807B28A2A1E57810151473C96F1484F2EF75D3E378E8C96440CD4CE ] simptcp        C:\windows\System32\tcpsvcs.exe
17:11:30.0379 0x1ab4  simptcp - ok
17:11:30.0399 0x1ab4  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2        C:\windows\system32\drivers\SiSRaid2.sys
17:11:30.0409 0x1ab4  SiSRaid2 - ok
17:11:30.0409 0x1ab4  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4        C:\windows\system32\drivers\sisraid4.sys
17:11:30.0409 0x1ab4  SiSRaid4 - ok
17:11:30.0509 0x1ab4  [ F3AAB7DF6408431C762D8721B68F46E4, 56ED764AA660955B8B06322703D086B3A52106625A83CCAF195B08BCBDEDA88F ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
17:11:30.0529 0x1ab4  SkypeUpdate - ok
17:11:30.0539 0x1ab4  [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb            C:\windows\system32\DRIVERS\smb.sys
17:11:30.0539 0x1ab4  Smb - ok
17:11:30.0579 0x1ab4  [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP        C:\windows\System32\snmptrap.exe
17:11:30.0579 0x1ab4  SNMPTRAP - ok
17:11:30.0619 0x1ab4  [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr          C:\windows\system32\drivers\spldr.sys
17:11:30.0619 0x1ab4  spldr - ok
17:11:30.0649 0x1ab4  [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler        C:\windows\System32\spoolsv.exe
17:11:30.0669 0x1ab4  Spooler - ok
17:11:30.0769 0x1ab4  [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc          C:\windows\system32\sppsvc.exe
17:11:30.0899 0x1ab4  sppsvc - ok
17:11:30.0959 0x1ab4  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify    C:\windows\system32\sppuinotify.dll
17:11:30.0969 0x1ab4  sppuinotify - ok
17:11:31.0074 0x1ab4  [ EC666682FE8344CF7E6ED69E74FA9F4F, DCD2A1C046425630689E2C9A6A6E356FE5A2A6664D12C20CFE236FCB32240DF9 ] srv            C:\windows\system32\DRIVERS\srv.sys
17:11:31.0091 0x1ab4  srv - ok
17:11:31.0125 0x1ab4  [ E450C0318DCE8ED28ED272C8806B8495, D2FD459F8C5E42103EF2F71421FA175A4F0821F8C2A3763093122D433D1C50FB ] srv2            C:\windows\system32\DRIVERS\srv2.sys
17:11:31.0134 0x1ab4  srv2 - ok
17:11:31.0149 0x1ab4  [ 9C12C78AD36C23D925711A4640228225, FF72C23F2A08EDF0C41BAF1EB0245AB44FF91365C5466F09C47A8F0928D20994 ] srvnet          C:\windows\system32\DRIVERS\srvnet.sys
17:11:31.0153 0x1ab4  srvnet - ok
17:11:31.0230 0x1ab4  [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV        C:\windows\System32\ssdpsrv.dll
17:11:31.0235 0x1ab4  SSDPSRV - ok
17:11:31.0360 0x1ab4  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc        C:\windows\system32\sstpsvc.dll
17:11:31.0369 0x1ab4  SstpSvc - ok
17:11:31.0403 0x1ab4  [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor        C:\windows\system32\drivers\stexstor.sys
17:11:31.0406 0x1ab4  stexstor - ok
17:11:31.0474 0x1ab4  [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc          C:\windows\System32\wiaservc.dll
17:11:31.0520 0x1ab4  stisvc - ok
17:11:31.0575 0x1ab4  [ 04CF20310145DEC63D5387BEAFF77D9A, 5017AF8C2DFBFE1F9946FF5AF229D62D141118EA923EEFA994EB4C7B52DEF208 ] SWDUMon        C:\windows\system32\DRIVERS\SWDUMon.sys
17:11:31.0577 0x1ab4  SWDUMon - ok
17:11:31.0591 0x1ab4  [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum          C:\windows\system32\drivers\swenum.sys
17:11:31.0593 0x1ab4  swenum - ok
17:11:31.0627 0x1ab4  [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv          C:\windows\System32\swprv.dll
17:11:31.0647 0x1ab4  swprv - ok
17:11:31.0787 0x1ab4  [ 2E730941CC5BF6200A4F56D1E9C24AAD, 758836D55DC84F3EBE9917DC6FAB8E6170A5B238FEDBCFDB6D7C5C6EA98E08B2 ] SysMain        C:\windows\system32\sysmain.dll
17:11:31.0907 0x1ab4  SysMain - ok
17:11:31.0947 0x1ab4  [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\windows\System32\TabSvc.dll
17:11:31.0947 0x1ab4  TabletInputService - ok
17:11:31.0967 0x1ab4  [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv        C:\windows\System32\tapisrv.dll
17:11:31.0977 0x1ab4  TapiSrv - ok
17:11:32.0037 0x1ab4  [ B2875D7ABB82867DC3AA03D991940201, F954C33FBA912A517B59330F6438C1953F9F1D8F4D8FD25945EB836A1DB07ABB ] Tcpip          C:\windows\system32\drivers\tcpip.sys
17:11:32.0102 0x1ab4  Tcpip - ok
17:11:32.0146 0x1ab4  [ B2875D7ABB82867DC3AA03D991940201, F954C33FBA912A517B59330F6438C1953F9F1D8F4D8FD25945EB836A1DB07ABB ] TCPIP6          C:\windows\system32\DRIVERS\tcpip.sys
17:11:32.0183 0x1ab4  TCPIP6 - ok
17:11:32.0221 0x1ab4  [ 7FE5586314EE7D6AA8483264A089E5AF, 4E3EA68713A45C22F1B9A1AA125E15D06D0C5E637B815537431ADFB6D7563879 ] tcpipreg        C:\windows\system32\drivers\tcpipreg.sys
17:11:32.0223 0x1ab4  tcpipreg - ok
17:11:32.0254 0x1ab4  [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE          C:\windows\system32\drivers\tdpipe.sys
17:11:32.0256 0x1ab4  TDPIPE - ok
17:11:32.0286 0x1ab4  [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP          C:\windows\system32\drivers\tdtcp.sys
17:11:32.0288 0x1ab4  TDTCP - ok
17:11:32.0323 0x1ab4  [ AA77EB517D2F07A947294F260E3ACA83, B7A5DF3066830C0C2302B059778A67419792058A0D300C471DE40AB245EA7E58 ] tdx            C:\windows\system32\DRIVERS\tdx.sys
17:11:32.0333 0x1ab4  tdx - ok
17:11:32.0353 0x1ab4  [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD          C:\windows\system32\drivers\termdd.sys
17:11:32.0363 0x1ab4  TermDD - ok
17:11:32.0423 0x1ab4  [ 008CD4EBFABCF78D0F19B3778492648C, 9050490EEE0AD86E73F0A82D83E4FC29DF84F6B6FDB389AE135FD712B5F425BE ] TermService    C:\windows\System32\termsrv.dll
17:11:32.0453 0x1ab4  TermService - ok
17:11:32.0463 0x1ab4  [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes          C:\windows\system32\themeservice.dll
17:11:32.0473 0x1ab4  Themes - ok
17:11:32.0493 0x1ab4  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER    C:\windows\system32\mmcss.dll
17:11:32.0503 0x1ab4  THREADORDER - ok
17:11:32.0523 0x1ab4  [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks          C:\windows\System32\trkwks.dll
17:11:32.0523 0x1ab4  TrkWks - ok
17:11:32.0573 0x1ab4  [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
17:11:32.0573 0x1ab4  TrustedInstaller - ok
17:11:32.0613 0x1ab4  [ 19BEDA57F3E0A06B8D5EB6D619BD5624, 952D5FAFD662C93628C12A6F7EB8E240A44216C0A15CBD2F5016BC357CBFE821 ] tssecsrv        C:\windows\system32\DRIVERS\tssecsrv.sys
17:11:32.0613 0x1ab4  tssecsrv - ok
17:11:32.0643 0x1ab4  [ E9981ECE8D894CEF7038FD1D040EB426, DCDDCE933CAECE8180A3447199B07F2F0413704EEC1A09606EE357901A84A7CF ] TsUsbFlt        C:\windows\system32\drivers\tsusbflt.sys
17:11:32.0643 0x1ab4  TsUsbFlt - ok
17:11:32.0683 0x1ab4  [ AD64450A4ABE076F5CB34CC08EEACB07, B5C386635441A19178E7FEEE299BA430C8D72F9110866C13A216B12A1080AD12 ] TsUsbGD        C:\windows\system32\drivers\TsUsbGD.sys
17:11:32.0683 0x1ab4  TsUsbGD - ok
17:11:32.0723 0x1ab4  [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel          C:\windows\system32\DRIVERS\tunnel.sys
17:11:32.0733 0x1ab4  tunnel - ok
17:11:32.0773 0x1ab4  [ 42350E49DA754D2D77362FDAE3491651, F29E8BA444ECB0484066B02C0A3DCE09B8417159EE37D7A2E05D4C06A98449C4 ] TurboB          C:\windows\system32\DRIVERS\TurboB.sys
17:11:32.0773 0x1ab4  TurboB - ok
17:11:32.0843 0x1ab4  [ 4F4B0AB2FB69C414CCBCEF7CF2E1C8D8, E1F197554369C97DBF61389346B4CB0233F40AAA2575F5D2FEC809AC9123FC69 ] TurboBoost      C:\Program Files\Intel\TurboBoost\TurboBoost.exe
17:11:32.0853 0x1ab4  TurboBoost - ok
17:11:32.0873 0x1ab4  [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35          C:\windows\system32\drivers\uagp35.sys
17:11:32.0873 0x1ab4  uagp35 - ok
17:11:32.0903 0x1ab4  [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs            C:\windows\system32\DRIVERS\udfs.sys
17:11:32.0913 0x1ab4  udfs - ok
17:11:32.0943 0x1ab4  [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect      C:\windows\system32\UI0Detect.exe
17:11:32.0953 0x1ab4  UI0Detect - ok
17:11:32.0963 0x1ab4  [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx        C:\windows\system32\drivers\uliagpkx.sys
17:11:32.0963 0x1ab4  uliagpkx - ok
17:11:32.0993 0x1ab4  [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus          C:\windows\system32\DRIVERS\umbus.sys
17:11:32.0993 0x1ab4  umbus - ok
17:11:32.0993 0x1ab4  [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass          C:\windows\system32\drivers\umpass.sys
17:11:33.0003 0x1ab4  UmPass - ok
17:11:33.0071 0x1ab4  [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost        C:\windows\System32\upnphost.dll
17:11:33.0085 0x1ab4  upnphost - ok
17:11:33.0109 0x1ab4  [ 28B81917A195B67617AF7DCF4DFE5736, 40A4D2AAE1BDE5ABA8708ED150396E913C566ECD5CDA40D6C6DB256F1B9FD4A9 ] usbccgp        C:\windows\system32\DRIVERS\usbccgp.sys
17:11:33.0112 0x1ab4  usbccgp - ok
17:11:33.0139 0x1ab4  [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir          C:\windows\system32\drivers\usbcir.sys
17:11:33.0142 0x1ab4  usbcir - ok
17:11:33.0226 0x1ab4  [ B626F048318DAE65A3317F0592BE592C, 284D8FFE1D35F852EFDA182A72288AC3A10D6ED825FE2CC5812497D3FE291AF1 ] usbehci        C:\windows\system32\drivers\usbehci.sys
17:11:33.0228 0x1ab4  usbehci - ok
17:11:33.0291 0x1ab4  [ 390109E8E05BA00375DCB1ED64DC60AF, B8628502590B423BEFB6F7C8C69FAD0667AD0746FF6B444EE02016E8E1052B78 ] usbhub          C:\windows\system32\drivers\usbhub.sys
17:11:33.0306 0x1ab4  usbhub - ok
17:11:33.0403 0x1ab4  [ B4DF0F4C1D9D25DFE1DAD1D8670F1D4F, 4317C2DEDC639527B53864BAEC46CBE022D298C0503E29E1072DD1C851D92BFC ] usbohci        C:\windows\system32\drivers\usbohci.sys
17:11:33.0403 0x1ab4  usbohci - ok
17:11:33.0433 0x1ab4  [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint        C:\windows\system32\DRIVERS\usbprint.sys
17:11:33.0433 0x1ab4  usbprint - ok
17:11:33.0533 0x1ab4  [ 9661DA76B4531B2DA272ECCE25A8AF24, FEA93254A21E71A7EB8AD35FCCAD2C1E41F7329EC33B1734F5B41307A34D8637 ] usbscan        C:\windows\system32\DRIVERS\usbscan.sys
17:11:33.0533 0x1ab4  usbscan - ok
17:11:33.0583 0x1ab4  [ D029DD09E22EB24318A8FC3D8138BA43, C95805E8BF75ECB939520AE86420B16467B0771C161C51C9F1A37649ADFADCD0 ] USBSTOR        C:\windows\system32\drivers\USBSTOR.SYS
17:11:33.0583 0x1ab4  USBSTOR - ok
17:11:33.0643 0x1ab4  [ CFEAAF96E666E3DCBD8F6DFF516784AE, 006218A3DB5851790CC0A7F3DCD7B3AF82F624DA679296DE507AFD36C5468317 ] usbuhci        C:\windows\system32\drivers\usbuhci.sys
17:11:33.0643 0x1ab4  usbuhci - ok
17:11:33.0683 0x1ab4  [ 1F775DA4CF1A3A1834207E975A72E9D7, 6D3DE5BD3EF3A76E997E5BAF900C51D25308F5A9682D1F62017F577A24095B90 ] usbvideo        C:\windows\system32\Drivers\usbvideo.sys
17:11:33.0703 0x1ab4  usbvideo - ok
17:11:33.0733 0x1ab4  [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms          C:\windows\System32\uxsms.dll
17:11:33.0733 0x1ab4  UxSms - ok
17:11:33.0753 0x1ab4  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] VaultSvc        C:\windows\system32\lsass.exe
17:11:33.0763 0x1ab4  VaultSvc - ok
17:11:33.0793 0x1ab4  [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot        C:\windows\system32\drivers\vdrvroot.sys
17:11:33.0803 0x1ab4  vdrvroot - ok
17:11:33.0863 0x1ab4  [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds            C:\windows\System32\vds.exe
17:11:33.0913 0x1ab4  vds - ok
17:11:33.0953 0x1ab4  [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga            C:\windows\system32\DRIVERS\vgapnp.sys
17:11:33.0953 0x1ab4  vga - ok
17:11:33.0983 0x1ab4  [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave        C:\windows\System32\drivers\vga.sys
17:11:33.0983 0x1ab4  VgaSave - ok
17:11:33.0993 0x1ab4  [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp          C:\windows\system32\drivers\vhdmp.sys
17:11:34.0003 0x1ab4  vhdmp - ok
17:11:34.0033 0x1ab4  [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide          C:\windows\system32\drivers\viaide.sys
17:11:34.0033 0x1ab4  viaide - ok
17:11:34.0050 0x1ab4  [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr          C:\windows\system32\drivers\volmgr.sys
17:11:34.0053 0x1ab4  volmgr - ok
17:11:34.0069 0x1ab4  [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx        C:\windows\system32\drivers\volmgrx.sys
17:11:34.0077 0x1ab4  volmgrx - ok
17:11:34.0124 0x1ab4  [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap        C:\windows\system32\drivers\volsnap.sys
17:11:34.0131 0x1ab4  volsnap - ok
17:11:34.0164 0x1ab4  [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid        C:\windows\system32\drivers\vsmraid.sys
17:11:34.0168 0x1ab4  vsmraid - ok
17:11:34.0224 0x1ab4  [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS            C:\windows\system32\vssvc.exe
17:11:34.0291 0x1ab4  VSS - ok
17:11:34.0333 0x1ab4  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus        C:\windows\system32\DRIVERS\vwifibus.sys
17:11:34.0333 0x1ab4  vwifibus - ok
17:11:34.0363 0x1ab4  [ 6A3D66263414FF0D6FA754C646612F3F, 30F6BA594B0D3B94113064015A16D97811CD989DF1715CCE21CEAB9894C1B4FB ] vwififlt        C:\windows\system32\DRIVERS\vwififlt.sys
17:11:34.0363 0x1ab4  vwififlt - ok
17:11:34.0383 0x1ab4  [ 6A638FC4BFDDC4D9B186C28C91BD1A01, 5521F1DC515586777EC4837E0AEAA3E613CC178AF1074031C4D0D0C695A93168 ] vwifimp        C:\windows\system32\DRIVERS\vwifimp.sys
17:11:34.0383 0x1ab4  vwifimp - ok
17:11:34.0403 0x1ab4  [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time        C:\windows\system32\w32time.dll
17:11:34.0413 0x1ab4  W32Time - ok
17:11:34.0513 0x1ab4  [ B32009DB1972E7F2C227499289C4384A, D491CD90ACE895EC60A5A2F995EAE39F8ED662B71BC548C3FF5BBDBC60054788 ] W3SVC          C:\windows\system32\inetsrv\iisw3adm.dll
17:11:34.0573 0x1ab4  W3SVC - ok
17:11:34.0633 0x1ab4  [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen        C:\windows\system32\drivers\wacompen.sys
17:11:34.0643 0x1ab4  WacomPen - ok
17:11:34.0663 0x1ab4  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP          C:\windows\system32\DRIVERS\wanarp.sys
17:11:34.0673 0x1ab4  WANARP - ok
17:11:34.0713 0x1ab4  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6        C:\windows\system32\DRIVERS\wanarp.sys
17:11:34.0723 0x1ab4  Wanarpv6 - ok
17:11:34.0793 0x1ab4  [ B32009DB1972E7F2C227499289C4384A, D491CD90ACE895EC60A5A2F995EAE39F8ED662B71BC548C3FF5BBDBC60054788 ] WAS            C:\windows\system32\inetsrv\iisw3adm.dll
17:11:34.0803 0x1ab4  WAS - ok
17:11:34.0863 0x1ab4  [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine        C:\windows\system32\wbengine.exe
17:11:34.0903 0x1ab4  wbengine - ok
17:11:34.0913 0x1ab4  [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc        C:\windows\System32\wbiosrvc.dll
17:11:34.0923 0x1ab4  WbioSrvc - ok
17:11:34.0953 0x1ab4  [ 8BDA6DB43AA54E8BB5E0794541DDC209, 8753C507BE77B019A3403AF5252434A01DB9F9332E58AC3783ABCE3D21AD9DD4 ] WcesComm        C:\windows\WindowsMobile\wcescomm.dll
17:11:34.0963 0x1ab4  WcesComm - ok
17:11:34.0993 0x1ab4  [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc        C:\windows\System32\wcncsvc.dll
17:11:35.0003 0x1ab4  wcncsvc - ok
17:11:35.0043 0x1ab4  [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
17:11:35.0046 0x1ab4  WcsPlugInService - ok
17:11:35.0086 0x1ab4  [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd              C:\windows\system32\drivers\wd.sys
17:11:35.0087 0x1ab4  Wd - ok
17:11:35.0172 0x1ab4  [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000        C:\windows\system32\drivers\Wdf01000.sys
17:11:35.0188 0x1ab4  Wdf01000 - ok
17:11:35.0218 0x1ab4  [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiServiceHost  C:\windows\system32\wdi.dll
17:11:35.0221 0x1ab4  WdiServiceHost - ok
17:11:35.0231 0x1ab4  [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiSystemHost  C:\windows\system32\wdi.dll
17:11:35.0235 0x1ab4  WdiSystemHost - ok
17:11:35.0281 0x1ab4  [ EE841B6D1F2B9508D3ABAE52AC05A94F, F1AE981FCDBFC4672A4EABABD41382E93762EFC2EDAD96E75530E7ACA5AF1FD8 ] WebClient      C:\windows\System32\webclnt.dll
17:11:35.0303 0x1ab4  WebClient - ok
17:11:35.0329 0x1ab4  [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc          C:\windows\system32\wecsvc.dll
17:11:35.0339 0x1ab4  Wecsvc - ok
17:11:35.0369 0x1ab4  [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport  C:\windows\System32\wercplsupport.dll
17:11:35.0379 0x1ab4  wercplsupport - ok
17:11:35.0399 0x1ab4  [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc          C:\windows\System32\WerSvc.dll
17:11:35.0399 0x1ab4  WerSvc - ok
17:11:35.0439 0x1ab4  [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf          C:\windows\system32\DRIVERS\wfplwf.sys
17:11:35.0439 0x1ab4  WfpLwf - ok
17:11:35.0449 0x1ab4  [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount        C:\windows\system32\drivers\wimmount.sys
17:11:35.0459 0x1ab4  WIMMount - ok
17:11:35.0479 0x1ab4  WinDefend - ok
17:11:35.0489 0x1ab4  WinHttpAutoProxySvc - ok
17:11:35.0569 0x1ab4  [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt        C:\windows\system32\wbem\WMIsvc.dll
17:11:35.0589 0x1ab4  Winmgmt - ok
17:11:35.0729 0x1ab4  [ EBDA1B0F15CB9B2CBCC6C94824E4E054, C51314F7D611E4903DA00EFA8EB99365414436324D256083CE0B5A8E055E8E06 ] WinRM          C:\windows\system32\WsmSvc.dll
17:11:35.0829 0x1ab4  WinRM - ok
17:11:35.0909 0x1ab4  [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb          C:\windows\system32\DRIVERS\WinUsb.sys
17:11:35.0919 0x1ab4  WinUsb - ok
17:11:35.0979 0x1ab4  [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc        C:\windows\System32\wlansvc.dll
17:11:36.0061 0x1ab4  Wlansvc - ok
17:11:36.0232 0x1ab4  [ 357CABBF155AFD1D3926E62539D2A3A7, C43CFF84E7D930B4999DC061AB0766B57AAD7540B3E6EE54605B10ECE90825F5 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
17:11:36.0287 0x1ab4  wlidsvc - ok
17:11:36.0331 0x1ab4  [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi        C:\windows\system32\drivers\wmiacpi.sys
17:11:36.0331 0x1ab4  WmiAcpi - ok
17:11:36.0381 0x1ab4  [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv        C:\windows\system32\wbem\WmiApSrv.exe
17:11:36.0391 0x1ab4  wmiApSrv - ok
17:11:36.0411 0x1ab4  WMPNetworkSvc - ok
17:11:36.0431 0x1ab4  [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc          C:\windows\System32\wpcsvc.dll
17:11:36.0431 0x1ab4  WPCSvc - ok
17:11:36.0451 0x1ab4  [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum      C:\windows\system32\wpdbusenum.dll
17:11:36.0461 0x1ab4  WPDBusEnum - ok
17:11:36.0491 0x1ab4  [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl        C:\windows\system32\drivers\ws2ifsl.sys
17:11:36.0491 0x1ab4  ws2ifsl - ok
17:11:36.0511 0x1ab4  [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc          C:\windows\System32\wscsvc.dll
17:11:36.0511 0x1ab4  wscsvc - ok
17:11:36.0521 0x1ab4  WSearch - ok
17:11:36.0661 0x1ab4  [ 31F32E0C1A8BA9A37EEC23DE5F27F847, 0180832BC6172C9A4C32B5B222BB3F91EA615A5EBDA98DB79ED4FED258C2D257 ] wuauserv        C:\windows\system32\wuaueng.dll
17:11:36.0741 0x1ab4  wuauserv - ok
17:11:36.0771 0x1ab4  [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf          C:\windows\system32\drivers\WudfPf.sys
17:11:36.0781 0x1ab4  WudfPf - ok
17:11:36.0821 0x1ab4  [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd          C:\windows\system32\DRIVERS\WUDFRd.sys
17:11:36.0831 0x1ab4  WUDFRd - ok
17:11:36.0851 0x1ab4  [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc        C:\windows\System32\WUDFSvc.dll
17:11:36.0861 0x1ab4  wudfsvc - ok
17:11:36.0881 0x1ab4  [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc        C:\windows\System32\wwansvc.dll
17:11:36.0881 0x1ab4  WwanSvc - ok
17:11:36.0901 0x1ab4  ================ Scan global ===============================
17:11:36.0961 0x1ab4  [ 168EA9CD9BD6056BB6F60B57D5304BBE, 5A2F98754F042A7D80E7483842967EB362F01D57CE9720B24C7EDAA047F24C6F ] C:\windows\system32\basesrv.dll
17:11:37.0001 0x1ab4  [ 93E5D2B763374F484918A0909724B3EB, 900F1CCAEFCF77AB678C74D542ABDDA7134CD33D7811537E2829FC69E99F2B3E ] C:\windows\system32\winsrv.dll
17:11:37.0060 0x1ab4  [ 93E5D2B763374F484918A0909724B3EB, 900F1CCAEFCF77AB678C74D542ABDDA7134CD33D7811537E2829FC69E99F2B3E ] C:\windows\system32\winsrv.dll
17:11:37.0105 0x1ab4  [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\windows\system32\sxssrv.dll
17:11:37.0141 0x1ab4  [ 71C85477DF9347FE8E7BC55768473FCA, A86D6A6D1F5A0EFCD649792A06F3AE9B37158D48493D2ECA7F52DCC1CB9B6536 ] C:\windows\system32\services.exe
17:11:37.0149 0x1ab4  [ Global ] - ok
17:11:37.0151 0x1ab4  ================ Scan MBR ==================================
17:11:37.0173 0x1ab4  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:11:37.0553 0x1ab4  \Device\Harddisk0\DR0 - ok
17:11:37.0553 0x1ab4  ================ Scan VBR ==================================
17:11:37.0573 0x1ab4  [ 0705F560CF61D5EE61FCE46DC97D99F9 ] \Device\Harddisk0\DR0\Partition1
17:11:37.0573 0x1ab4  \Device\Harddisk0\DR0\Partition1 - ok
17:11:37.0593 0x1ab4  [ 89E86E8C7CA58358959D25AD32A5A90E ] \Device\Harddisk0\DR0\Partition2
17:11:37.0593 0x1ab4  \Device\Harddisk0\DR0\Partition2 - ok
17:11:37.0593 0x1ab4  ================ Scan generic autorun ======================
17:11:38.0043 0x1ab4  [ E05849E5D0E51EB52080E7D2987B9D3B, E68E43CF0FFD69C193C5B692A019CE13D3FB58197E5827720B3ACDDE0812AAFA ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
17:11:38.0384 0x1ab4  RTHDVCPL - ok
17:11:38.0416 0x1ab4  [ 8B87D9E466055B958EE24270BF187512, 7A1994398C5A2CEB7738006F375C12E5AAC9142786783189E7C57AB8E1E75F3C ] C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe
17:11:38.0416 0x1ab4  BtServer - ok
17:11:38.0556 0x1ab4  [ 0A892ED5ECB5C821DE71EF523DC71C78, 47F54D1148C615BE2E4F3355F5392B530A843736E7B9DFB888871F24B6E355CA ] C:\Program Files\Elantech\ETDCtrl.exe
17:11:38.0606 0x1ab4  ETDCtrl - ok
17:11:38.0666 0x1ab4  [ 815F6E3727453C978FFD721B2BDF48A5, E33A85E8EF80C662C84F705080585B35A899F8E588E8481D48538BA1224B5E57 ] C:\Program Files (x86)\SCM\Radio Manager.exe
17:11:38.0666 0x1ab4  Radio Manager - ok
17:11:38.0696 0x1ab4  [ 679119AAB80584EA5646B53F4779F86E, 57BE842AF59544ABE7E8F6AF2E0E106E7F7C681A2923BD156403F6E8335BAD5D ] C:\Program Files (x86)\SCM\SCM.exe
17:11:38.0706 0x1ab4  SCM - ok
17:11:38.0706 0x1ab4  IntelTBRunOnce - ok
17:11:38.0736 0x1ab4  [ 2E48CB664239B71FA40D9583FCB39860, EAFF430D91AD30AEF9D9FA6E7F3CB6217C6ACD519F1EE31351506445EED15D9C ] C:\windows\system32\igfxtray.exe
17:11:38.0746 0x1ab4  IgfxTray - ok
17:11:38.0776 0x1ab4  [ A491FFC9A3E69336AA5D4A065B42C8F8, 7DE6E7FD751C40B6CD1D059CC086307E0D11620642A36805C56C0F451E4412CD ] C:\windows\system32\hkcmd.exe
17:11:38.0776 0x1ab4  HotKeysCmds - ok
17:11:38.0796 0x1ab4  [ FF6659185BD54E9E5DE619CA1C2CD5B2, 0573634F7F69A41E0CAFCEDA8203DA26726BF77CBD6FD9FB9258D78691629E30 ] C:\windows\system32\igfxpers.exe
17:11:38.0806 0x1ab4  Persistence - ok
17:11:38.0846 0x1ab4  [ 233A10D4B3F6897899112E4EC60F1906, 1F7E768E57064938114DF2EFC5B219EB0D30A7D9E574924E9CED054462505AF0 ] C:\windows\WindowsMobile\wmdcBase.exe
17:11:38.0866 0x1ab4  Windows Mobile-based device management - ok
17:11:39.0056 0x1ab4  [ 666FEA598D1776C7F8EDD7746F0F7F59, 54E330BCDBAB646B555DACC15F9CFB0AD6A05BF4E273F73C5133259EEE976C21 ] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe
17:11:39.0104 0x1ab4  Malwarebytes TrayApp - ok
17:11:39.0136 0x1ab4  [ B00F98FF6FE8682FF941BEB2559BF191, EB443E294C5609F426BF6EE388F3A4B71EFE2C6A8216C0F6DE7AE6DB382BF620 ] C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
17:11:39.0139 0x1ab4  YouCam Mirage - ok
17:11:39.0168 0x1ab4  [ 15A69FE13459EF81FB2105CC986AF394, 2078EAFEA0F00D155EDE6DA40BFBE6E8347DB19078FBD52DFA2122FB439BD9E9 ] C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe
17:11:39.0172 0x1ab4  YouCam Tray - ok
17:11:39.0234 0x1ab4  [ 27B3D4706E8EBC4B870F1D177EBC54B2, 34CD55E4BA687E38BD88B36A25B187DFF591F2D747ADD4D9BD22C071B48468F0 ] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
17:11:39.0243 0x1ab4  Super-Charger - ok
17:11:39.0351 0x1ab4  [ 2B282A4050FE3B4B70EF9E3070BBFF78, 019B667781F5CE411AEB569EAA4095FA2B9942E43A6A1DFC6EEBB2DA214131FE ] C:\Program Files (x86)\FreePDF_XP\fpassist.exe
17:11:39.0371 0x1ab4  FreePDF Assistant - ok
17:11:39.0531 0x1ab4  [ AF905BC023A0018F7325FD4B0019B5C0, 9F65DE0C3D8B90295B70528ADD2411CC1771AC089B70ABEC426D6F2D5D7A104A ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
17:11:39.0531 0x1ab4  APSDaemon - ok
17:11:39.0621 0x1ab4  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
17:11:39.0671 0x1ab4  Sidebar - ok
17:11:39.0701 0x1ab4  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
17:11:39.0701 0x1ab4  mctadmin - ok
17:11:39.0741 0x1ab4  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
17:11:39.0761 0x1ab4  Sidebar - ok
17:11:39.0771 0x1ab4  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
17:11:39.0771 0x1ab4  mctadmin - ok
17:11:39.0831 0x1ab4  [ B88EC3510D74D3E7C2F7E68610DA8C45, 09A5715B65A19F7447C247484E1D5B096434EA9EC03689E48F781B6F33C0B858 ] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
17:11:39.0861 0x1ab4  Web Companion - ok
17:11:39.0881 0x1ab4  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
17:11:39.0901 0x1ab4  Sidebar - ok
17:11:39.0911 0x1ab4  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
17:11:39.0911 0x1ab4  mctadmin - ok
17:11:39.0911 0x1ab4  Waiting for KSN requests completion. In queue: 135
17:11:40.0953 0x1ab4  AV detected via SS2: Malwarebytes, C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe ( 3.0.0.134 ), 0x61000 ( enabled : updated )
17:11:40.0983 0x1ab4  Win FW state via NFP2: enabled ( trusted )
17:11:41.0154 0x1ab4  ============================================================
17:11:41.0154 0x1ab4  Scan finished
17:11:41.0154 0x1ab4  ============================================================
17:11:41.0162 0x18e0  Detected object count: 0
17:11:41.0162 0x18e0  Actual detected object count: 0
17:12:20.0654 0x18f4  Deinitialize success


cosinus 13.01.2017 19:03

Zitat:

17:11:00.0233 0x1ab4 Scan started
17:11:00.0233 0x1ab4 Mode: Manual;
tdsskiller wurde falsch eingestellt, bitte Anleitung richtig lesen und umsetzen

milkit54 13.01.2017 21:36

Entschuldigung Cosinus, hoffe diesmal habe ich es rchtig gemacht. MS-Michael

Code:

21:12:52.0112 0x187c  TDSS rootkit removing tool 3.1.0.12 Nov  7 2016 07:10:01
21:13:51.0747 0x187c  ============================================================
21:13:51.0747 0x187c  Current date / time: 2017/01/13 21:13:51.0747
21:13:51.0747 0x187c  SystemInfo:
21:13:51.0747 0x187c 
21:13:51.0747 0x187c  OS Version: 6.1.7601 ServicePack: 1.0
21:13:51.0747 0x187c  Product type: Workstation
21:13:51.0747 0x187c  ComputerName: MICHA-MSI
21:13:51.0747 0x187c  UserName: Micha
21:13:51.0747 0x187c  Windows directory: C:\windows
21:13:51.0747 0x187c  System windows directory: C:\windows
21:13:51.0747 0x187c  Running under WOW64
21:13:51.0747 0x187c  Processor architecture: Intel x64
21:13:51.0747 0x187c  Number of processors: 2
21:13:51.0747 0x187c  Page size: 0x1000
21:13:51.0747 0x187c  Boot type: Normal boot
21:13:51.0747 0x187c  CodeIntegrityOptions = 0x00000001
21:13:51.0747 0x187c  ============================================================
21:13:53.0395 0x187c  KLMD registered as C:\windows\system32\drivers\09792759.sys
21:13:53.0395 0x187c  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 7601.23572, osProperties = 0x1
21:13:53.0737 0x187c  System UUID: {200DC177-E40D-48B4-4F9D-F09300A0C18B}
21:13:54.0369 0x187c  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:13:54.0389 0x187c  ============================================================
21:13:54.0389 0x187c  \Device\Harddisk0\DR0:
21:13:54.0389 0x187c  MBR partitions:
21:13:54.0389 0x187c  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x16AC800, BlocksNum 0x2214F000
21:13:54.0389 0x187c  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x237FB800, BlocksNum 0x16B8A800
21:13:54.0389 0x187c  ============================================================
21:13:54.0409 0x187c  C: <-> \Device\Harddisk0\DR0\Partition1
21:13:54.0459 0x187c  D: <-> \Device\Harddisk0\DR0\Partition2
21:13:54.0459 0x187c  ============================================================
21:13:54.0459 0x187c  Initialize success
21:13:54.0459 0x187c  ============================================================
21:19:21.0816 0x187c  ============================================================
21:19:21.0816 0x187c  Scan started
21:19:21.0816 0x187c  Mode: Manual; SigCheck; TDLFS;
21:19:21.0816 0x187c  ============================================================
21:19:21.0816 0x187c  KSN ping started
21:19:34.0125 0x187c  KSN ping finished: true
21:19:35.0113 0x187c  ================ Scan system memory ========================
21:19:35.0113 0x187c  System memory - ok
21:19:35.0113 0x187c  ================ Scan services =============================
21:19:35.0263 0x187c  [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci        C:\windows\system32\drivers\1394ohci.sys
21:19:35.0463 0x187c  1394ohci - ok
21:19:35.0503 0x187c  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI            C:\windows\system32\drivers\ACPI.sys
21:19:35.0523 0x187c  ACPI - ok
21:19:35.0533 0x187c  [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi        C:\windows\system32\drivers\acpipmi.sys
21:19:35.0633 0x187c  AcpiPmi - ok
21:19:35.0743 0x187c  [ B932E0EE190778D840F1442DFC0F9612, 8780963F14D57279FDD585BE945ED40F24590D32676C7A9EF94002D38B8BA643 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
21:19:35.0853 0x187c  AdobeARMservice - ok
21:19:35.0973 0x187c  [ CA363F172E1978FD155764F2840B0BE8, CB14E2C94ABB8C8809F4E96472F6D1A9A3A0860217631F592E0F62F043165575 ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:19:36.0039 0x187c  AdobeFlashPlayerUpdateSvc - ok
21:19:36.0083 0x187c  [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx        C:\windows\system32\drivers\adp94xx.sys
21:19:36.0106 0x187c  adp94xx - ok
21:19:36.0122 0x187c  [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci        C:\windows\system32\drivers\adpahci.sys
21:19:36.0142 0x187c  adpahci - ok
21:19:36.0158 0x187c  [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320        C:\windows\system32\drivers\adpu320.sys
21:19:36.0174 0x187c  adpu320 - ok
21:19:36.0218 0x187c  [ 262D7C87D0AC20B96EF9877D3CA478A0, 54F7E5A5F8991C5525500C1ECCF3D3135D13F48866C366E52DF1D052DB2EE15B ] AeLookupSvc    C:\windows\System32\aelupsvc.dll
21:19:36.0268 0x187c  AeLookupSvc - ok
21:19:36.0328 0x187c  [ 9A4A1EEE802BF2F878EE8EAB407B21B7, 177EB7DF4B35FE4C0E45E775A0FD5D48D39B410052E3EE18BDEEC809E152D9D8 ] AFD            C:\windows\system32\drivers\afd.sys
21:19:36.0428 0x187c  AFD - ok
21:19:36.0468 0x187c  [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440          C:\windows\system32\drivers\agp440.sys
21:19:36.0488 0x187c  agp440 - ok
21:19:36.0528 0x187c  [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG            C:\windows\System32\alg.exe
21:19:36.0588 0x187c  ALG - ok
21:19:36.0618 0x187c  [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide          C:\windows\system32\drivers\aliide.sys
21:19:36.0628 0x187c  aliide - ok
21:19:36.0658 0x187c  [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide          C:\windows\system32\drivers\amdide.sys
21:19:36.0678 0x187c  amdide - ok
21:19:36.0698 0x187c  [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8          C:\windows\system32\drivers\amdk8.sys
21:19:36.0738 0x187c  AmdK8 - ok
21:19:36.0748 0x187c  [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM          C:\windows\system32\drivers\amdppm.sys
21:19:36.0788 0x187c  AmdPPM - ok
21:19:36.0808 0x187c  [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata        C:\windows\system32\drivers\amdsata.sys
21:19:36.0828 0x187c  amdsata - ok
21:19:36.0848 0x187c  [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs          C:\windows\system32\drivers\amdsbs.sys
21:19:36.0868 0x187c  amdsbs - ok
21:19:36.0888 0x187c  [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata        C:\windows\system32\drivers\amdxata.sys
21:19:36.0898 0x187c  amdxata - ok
21:19:36.0978 0x187c  [ 59D01FA91962C9C1E9B4022B2D3B46DB, 3A111588538B77F010B5C900FB8425DDE55A08DBAC308CA7FB7BD9FCCCDEC69F ] AppHostSvc      C:\windows\system32\inetsrv\apphostsvc.dll
21:19:37.0068 0x187c  AppHostSvc - ok
21:19:37.0112 0x187c  [ FCE5C79717A487BDC71F3DEC78A684CA, F5520F112A4EBDD10444AA5E9FDB9125219FCF768FEB95AB608BC84D60136816 ] AppID          C:\windows\system32\drivers\appid.sys
21:19:37.0193 0x187c  AppID - ok
21:19:37.0244 0x187c  [ 8921E1D8AE5171691F186A7C5B98B630, 4A37313BB94D4B49D0294C9439AD0793DE328F9F4DA1C47E34E6ACEA46AF6E14 ] AppIDSvc        C:\windows\System32\appidsvc.dll
21:19:37.0279 0x187c  AppIDSvc - ok
21:19:37.0301 0x187c  [ DE23E052E557580674785CDF45B613F3, A955ADC6CC7D816BA7CE1065F911E7A3295A1908C22BE0A3C506C38CFEE8DE0D ] Appinfo        C:\windows\System32\appinfo.dll
21:19:37.0311 0x187c  Appinfo - ok
21:19:37.0341 0x187c  [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc            C:\windows\system32\drivers\arc.sys
21:19:37.0361 0x187c  arc - ok
21:19:37.0361 0x187c  [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas          C:\windows\system32\drivers\arcsas.sys
21:19:37.0381 0x187c  arcsas - ok
21:19:37.0471 0x187c  [ EE424A5CE56E3923D59BB7DE2E15036D, 8B8196870EFE74D43EDA72674021A46846D370E97A6A058134D84A721AECD091 ] aspnet_state    C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
21:19:37.0501 0x187c  aspnet_state - ok
21:19:37.0541 0x187c  [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac        C:\windows\system32\DRIVERS\asyncmac.sys
21:19:37.0721 0x187c  AsyncMac - ok
21:19:37.0761 0x187c  [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi          C:\windows\system32\drivers\atapi.sys
21:19:37.0801 0x187c  atapi - ok
21:19:37.0861 0x187c  [ E857EEE6B92AAA473EBB3465ADD8F7E7, 1C7E4737E649A025B3C4974A4F7D1353EAB85561FC8ED54E5C22A777E1A189B3 ] athr            C:\windows\system32\DRIVERS\athrx.sys
21:19:37.0973 0x187c  athr - ok
21:19:38.0077 0x187c  [ 67C717EC24FCAAE7B518D9E06AD036AB, F08550E4FCEC2899FACEF2A18CEE3D068D5911FFD2FF5534E4921E56FB0AEF59 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
21:19:38.0183 0x187c  AudioEndpointBuilder - ok
21:19:38.0225 0x187c  [ 67C717EC24FCAAE7B518D9E06AD036AB, F08550E4FCEC2899FACEF2A18CEE3D068D5911FFD2FF5534E4921E56FB0AEF59 ] AudioSrv        C:\windows\System32\Audiosrv.dll
21:19:38.0260 0x187c  AudioSrv - ok
21:19:38.0353 0x187c  [ C4EEE661379D86429ACEAB31F3FD0391, D67F5D6863B066D974567521A00A48C50F0D9B6F6B16565FF8958E2020C651FD ] AvrcpService    C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe
21:19:38.0403 0x187c  AvrcpService - detected UnsignedFile.Multi.Generic ( 1 )
21:19:38.0573 0x187c  Detect skipped due to KSN trusted
21:19:38.0573 0x187c  AvrcpService - ok
21:19:38.0623 0x187c  [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV        C:\windows\System32\AxInstSV.dll
21:19:38.0723 0x187c  AxInstSV - ok
21:19:38.0763 0x187c  [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv        C:\windows\system32\drivers\bxvbda.sys
21:19:38.0853 0x187c  b06bdrv - ok
21:19:38.0873 0x187c  [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a        C:\windows\system32\DRIVERS\b57nd60a.sys
21:19:38.0935 0x187c  b57nd60a - ok
21:19:38.0965 0x187c  [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC          C:\windows\System32\bdesvc.dll
21:19:39.0015 0x187c  BDESVC - ok
21:19:39.0056 0x187c  [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep            C:\windows\system32\drivers\Beep.sys
21:19:39.0113 0x187c  Beep - ok
21:19:39.0166 0x187c  [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE            C:\windows\System32\bfe.dll
21:19:39.0235 0x187c  BFE - ok
21:19:39.0321 0x187c  [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS            C:\windows\System32\qmgr.dll
21:19:39.0511 0x187c  BITS - ok
21:19:39.0571 0x187c  [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive        C:\windows\system32\drivers\blbdrive.sys
21:19:39.0621 0x187c  blbdrive - ok
21:19:39.0731 0x187c  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD, 17BFFC5DF609CE3B2F0CAB4BD6C118608C66A3AD86116A47E90B2BB7D8954122 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
21:19:39.0761 0x187c  Bonjour Service - ok
21:19:39.0811 0x187c  [ ABA3984C822E4D3F889699912D85D6C5, 2251FA135CC290DA13DAE4743F393C7CC9E6A737C054707CB8D72C369D1FFACB ] bowser          C:\windows\system32\DRIVERS\bowser.sys
21:19:39.0891 0x187c  bowser - ok
21:19:39.0911 0x187c  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\windows\system32\drivers\BrFiltLo.sys
21:19:39.0951 0x187c  BrFiltLo - ok
21:19:39.0971 0x187c  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\windows\system32\drivers\BrFiltUp.sys
21:19:40.0021 0x187c  BrFiltUp - ok
21:19:40.0056 0x187c  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser        C:\windows\System32\browser.dll
21:19:40.0105 0x187c  Browser - ok
21:19:40.0114 0x187c  [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid        C:\windows\System32\Drivers\Brserid.sys
21:19:40.0194 0x187c  Brserid - ok
21:19:40.0199 0x187c  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\windows\System32\Drivers\BrSerWdm.sys
21:19:40.0233 0x187c  BrSerWdm - ok
21:19:40.0238 0x187c  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\windows\System32\Drivers\BrUsbMdm.sys
21:19:40.0258 0x187c  BrUsbMdm - ok
21:19:40.0262 0x187c  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\windows\System32\Drivers\BrUsbSer.sys
21:19:40.0292 0x187c  BrUsbSer - ok
21:19:40.0315 0x187c  [ FB38F90DE58996A4906A04F1152C3C3B, DA4A226FAE045174891A0EBFA03E1905CAF0AA25ADDBBCFBE369A853A63A83C6 ] BTDevManager    C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
21:19:40.0345 0x187c  BTDevManager - detected UnsignedFile.Multi.Generic ( 1 )
21:19:40.0717 0x187c  Detect skipped due to KSN trusted
21:19:40.0717 0x187c  BTDevManager - ok
21:19:40.0747 0x187c  [ CF98190A94F62E405C8CB255018B2315, E1B2540023C4FE9FD588E4B6AE6347DFA565EB3898F21E5360882BF3E8B5E781 ] BthEnum        C:\windows\system32\DRIVERS\BthEnum.sys
21:19:40.0857 0x187c  BthEnum - ok
21:19:40.0867 0x187c  [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM        C:\windows\system32\drivers\bthmodem.sys
21:19:40.0927 0x187c  BTHMODEM - ok
21:19:40.0979 0x187c  [ 02DD601B708DD0667E1331FA8518E9FF, 7DE6CC4DBB621CD03B01D9CE6CF66EAFE31D39030A391562CD0E278E1D70ADE1 ] BthPan          C:\windows\system32\DRIVERS\bthpan.sys
21:19:41.0009 0x187c  BthPan - ok
21:19:41.0039 0x187c  [ 738D0E9272F59EB7A1449C3EC118E6C4, FE3D32C2A5E4DC21376A0F89C0B2EE024ECF1A3FB99213CC9BBC986ADF7AF080 ] BTHPORT        C:\windows\system32\Drivers\BTHport.sys
21:19:41.0131 0x187c  BTHPORT - ok
21:19:41.0170 0x187c  [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv        C:\windows\system32\bthserv.dll
21:19:41.0227 0x187c  bthserv - ok
21:19:41.0264 0x187c  [ F188B7394D81010767B6DF3178519A37, 576304E92FD94908F093A6AB5F4D328F25829BE32EC3CA0D29EBFDF5DE83539B ] BTHUSB          C:\windows\system32\Drivers\BTHUSB.sys
21:19:41.0306 0x187c  BTHUSB - ok
21:19:41.0351 0x187c  [ E41F70406C34F1CB667B4B27D81AD162, 8869C7EB9CBF68B90640765D15DB5B8DACEF45025C1E580AA94D96E32560274B ] ccSet_NARA      C:\windows\system32\drivers\NARAx64\0403000.00E\ccSetx64.sys
21:19:41.0371 0x187c  ccSet_NARA - ok
21:19:41.0401 0x187c  [ A5C13600F63EB92F8D15123D64BA9895, 16683BDDD32525741FDE4505B9C224382047CC8EE9A7DB35FF0FDF32F7D731F8 ] ccSet_NAT      C:\windows\system32\drivers\NATx64\0106000.011\ccSetx64.sys
21:19:41.0411 0x187c  ccSet_NAT - ok
21:19:41.0441 0x187c  [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs            C:\windows\system32\DRIVERS\cdfs.sys
21:19:41.0481 0x187c  cdfs - ok
21:19:41.0511 0x187c  [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom          C:\windows\system32\DRIVERS\cdrom.sys
21:19:41.0541 0x187c  cdrom - ok
21:19:41.0571 0x187c  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc    C:\windows\System32\certprop.dll
21:19:41.0621 0x187c  CertPropSvc - ok
21:19:41.0641 0x187c  [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass        C:\windows\system32\drivers\circlass.sys
21:19:41.0671 0x187c  circlass - ok
21:19:41.0691 0x187c  [ FF60401F1C659CA2ED4BAE85D3FD14DA, 71EEA0078E1545A2F80B0020BE7113843B713DE1A5CC20D9810BD9F3889A4DB0 ] CISVC          C:\windows\system32\CISVC.EXE
21:19:41.0731 0x187c  CISVC - ok
21:19:41.0791 0x187c  [ 3D67C27DD17B254D7915FA16A5AE3573, 5B3A6C6A7F940C06362775DAF13CEADA37C7AA84A509458A57C23B4369970A90 ] CLFS            C:\windows\system32\CLFS.sys
21:19:41.0821 0x187c  CLFS - ok
21:19:41.0881 0x187c  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:19:41.0901 0x187c  clr_optimization_v2.0.50727_32 - ok
21:19:41.0951 0x187c  [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
21:19:41.0961 0x187c  clr_optimization_v2.0.50727_64 - ok
21:19:42.0001 0x187c  [ 5BAF4F1296D4D91FC28560CDB4C37C4B, ACA4BC57ED1F8432F18F0F215EC7FF956BAEF6E02760779E264E4008A979E9DD ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:19:42.0021 0x187c  clr_optimization_v4.0.30319_32 - ok
21:19:42.0062 0x187c  [ 569B54004A7E85A74FD92841DE6058E2, 58949313D0F6B1C06359B2F3C68E29940B1655A17E93FFC3718F6D2EAE1633E4 ] clr_optimization_v4.0.30319_64 C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
21:19:42.0080 0x187c  clr_optimization_v4.0.30319_64 - ok
21:19:42.0112 0x187c  [ E13A438F9E51DD034730678E33B73290, 3BB111DFDAEAB8DA6124600C7F6E080C2950A0BB420803FC12560343E1A9280A ] clwvd          C:\windows\system32\DRIVERS\clwvd.sys
21:19:42.0125 0x187c  clwvd - ok
21:19:42.0140 0x187c  [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt          C:\windows\system32\DRIVERS\CmBatt.sys
21:19:42.0173 0x187c  CmBatt - ok
21:19:42.0192 0x187c  [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide          C:\windows\system32\drivers\cmdide.sys
21:19:42.0205 0x187c  cmdide - ok
21:19:42.0230 0x187c  [ A98CED39AD91B445E2E442A9BD67E8B4, B4189DEEF1C0EE22AE983119047B1A40FFDD8F3E163DFFABD7C2706231B0B1B0 ] CNG            C:\windows\system32\Drivers\cng.sys
21:19:42.0258 0x187c  CNG - ok
21:19:42.0278 0x187c  [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt        C:\windows\system32\drivers\compbatt.sys
21:19:42.0291 0x187c  Compbatt - ok
21:19:42.0304 0x187c  [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus    C:\windows\system32\drivers\CompositeBus.sys
21:19:42.0336 0x187c  CompositeBus - ok
21:19:42.0336 0x187c  COMSysApp - ok
21:19:42.0446 0x187c  [ 3A92DDB2F7B7FE2E71AA1418804EBC3C, 1B84033A6DDB9D371AC34F8D65AB0F729E8A77B0D26C8DCA0965CE265474BD64 ] cphs            C:\windows\SysWow64\IntelCpHeciSvc.exe
21:19:42.0486 0x187c  cphs - ok
21:19:42.0496 0x187c  [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk        C:\windows\system32\drivers\crcdisk.sys
21:19:42.0516 0x187c  crcdisk - ok
21:19:42.0546 0x187c  [ 2C6632CECFDBBE793FDA8AF9CA55A9CC, 335188515F798483660E529204A13012E4D21B0ECA489224A11C26F91A5B3CCE ] CryptSvc        C:\windows\system32\cryptsvc.dll
21:19:42.0596 0x187c  CryptSvc - ok
21:19:42.0626 0x187c  [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] DcomLaunch      C:\windows\system32\rpcss.dll
21:19:42.0716 0x187c  DcomLaunch - ok
21:19:42.0756 0x187c  [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc      C:\windows\System32\defragsvc.dll
21:19:42.0816 0x187c  defragsvc - ok
21:19:42.0876 0x187c  [ 9B38580063D281A99E68EF5813022A5F, D91676B0E0A8E2A090E3E5DD340ABCFC20AE0F55B4C82869D6CFB34239BD27DA ] DfsC            C:\windows\system32\Drivers\dfsc.sys
21:19:42.0956 0x187c  DfsC - ok
21:19:42.0986 0x187c  [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp            C:\windows\system32\dhcpcore.dll
21:19:43.0026 0x187c  Dhcp - ok
21:19:43.0115 0x187c  [ EE9954237F15BE4DD9304D12E4D305ED, F295C9BAF20F0E669B673AFCC16B4969EE31B6A3808980DAB93D9B0F167DA3C0 ] DiagTrack      C:\windows\system32\diagtrack.dll
21:19:43.0220 0x187c  DiagTrack - ok
21:19:43.0258 0x187c  [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache        C:\windows\system32\drivers\discache.sys
21:19:43.0292 0x187c  discache - ok
21:19:43.0330 0x187c  [ 616387BBD83372220B09DE95F4E67BBC, 5E2D5280BB775576E7CDE3FA6BDE494E183123635E5908CF7EBF1FF52966D07D ] Disk            C:\windows\system32\drivers\disk.sys
21:19:43.0340 0x187c  Disk - ok
21:19:43.0370 0x187c  [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache        C:\windows\System32\dnsrslvr.dll
21:19:43.0420 0x187c  Dnscache - ok
21:19:43.0440 0x187c  [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc        C:\windows\System32\dot3svc.dll
21:19:43.0480 0x187c  dot3svc - ok
21:19:43.0500 0x187c  [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS            C:\windows\system32\dps.dll
21:19:43.0550 0x187c  DPS - ok
21:19:43.0570 0x187c  [ 26FE888505E5A945B0536AF9A2A27A6F, A6B16ED498BAFE300E1F0E0A241E3D62F7A1C5973EE775904ED14F33A2BC08A6 ] drmkaud        C:\windows\system32\drivers\drmkaud.sys
21:19:43.0630 0x187c  drmkaud - ok
21:19:43.0740 0x187c  [ 3A9D7D464BDB3B70D7ECF689ADABBD4D, B4F5B23705EA1BA453FE30791CA245E1A5F7FBEABAD026E4A8A15A9FC44E8C9C ] DXGKrnl        C:\windows\System32\drivers\dxgkrnl.sys
21:19:43.0770 0x187c  DXGKrnl - ok
21:19:43.0800 0x187c  [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost        C:\windows\System32\eapsvc.dll
21:19:43.0840 0x187c  EapHost - ok
21:19:43.0954 0x187c  [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv          C:\windows\system32\drivers\evbda.sys
21:19:44.0062 0x187c  ebdrv - ok
21:19:44.0103 0x187c  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] EFS            C:\windows\System32\lsass.exe
21:19:44.0131 0x187c  EFS - ok
21:19:44.0189 0x187c  [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr        C:\windows\ehome\ehRecvr.exe
21:19:44.0237 0x187c  ehRecvr - ok
21:19:44.0258 0x187c  [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched        C:\windows\ehome\ehsched.exe
21:19:44.0295 0x187c  ehSched - ok
21:19:44.0339 0x187c  [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor        C:\windows\system32\drivers\elxstor.sys
21:19:44.0359 0x187c  elxstor - ok
21:19:44.0359 0x187c  [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev          C:\windows\system32\drivers\errdev.sys
21:19:44.0389 0x187c  ErrDev - ok
21:19:44.0429 0x187c  [ 4D7F3114147C31390262F19F74E5BF07, E89F5304149B51327DFE1314AE13352923B752BC24585FF42F28EF5F00936A6A ] ESProtectionDriver C:\windows\system32\drivers\mbae64.sys
21:19:44.0459 0x187c  ESProtectionDriver - ok
21:19:44.0479 0x187c  [ 39EC51A5BC3E1C0D438E8AC70956DE0A, 456AE9C6E059442CA627AAB667CA498AA6F6A6812A177DCCB36D9CC24F11231A ] ETD            C:\windows\system32\DRIVERS\ETD.sys
21:19:44.0499 0x187c  ETD - ok
21:19:44.0569 0x187c  [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem    C:\windows\system32\es.dll
21:19:44.0651 0x187c  EventSystem - ok
21:19:44.0681 0x187c  [ 8ADACFFAD67394C711698EA074CE3BAB, 02793393584762224D87C487D80080D6DBCD09192098A7A1399CA16C17886C5D ] ewusbnet        C:\windows\system32\DRIVERS\ewusbnet.sys
21:19:44.0741 0x187c  ewusbnet - ok
21:19:44.0771 0x187c  [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat          C:\windows\system32\drivers\exfat.sys
21:19:44.0861 0x187c  exfat - ok
21:19:44.0931 0x187c  Fabs - ok
21:19:44.0961 0x187c  [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat        C:\windows\system32\drivers\fastfat.sys
21:19:45.0011 0x187c  fastfat - ok
21:19:45.0077 0x187c  [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax            C:\windows\system32\fxssvc.exe
21:19:45.0132 0x187c  Fax - ok
21:19:45.0158 0x187c  [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc            C:\windows\system32\drivers\fdc.sys
21:19:45.0185 0x187c  fdc - ok
21:19:45.0216 0x187c  [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost        C:\windows\system32\fdPHost.dll
21:19:45.0263 0x187c  fdPHost - ok
21:19:45.0289 0x187c  [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub        C:\windows\system32\fdrespub.dll
21:19:45.0324 0x187c  FDResPub - ok
21:19:45.0376 0x187c  [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo        C:\windows\system32\drivers\fileinfo.sys
21:19:45.0406 0x187c  FileInfo - ok
21:19:45.0416 0x187c  [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace      C:\windows\system32\drivers\filetrace.sys
21:19:45.0466 0x187c  Filetrace - ok
21:19:45.0576 0x187c  [ FFF1130F7C9FA01D093A1EDFC5CCE8FC, 159EAA1893D871C309A063829CB3BC51A019FBCA1E07530B5CA1A382B2CCAF61 ] FirebirdServerMAGIXInstance C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
21:19:45.0676 0x187c  FirebirdServerMAGIXInstance - detected UnsignedFile.Multi.Generic ( 1 )
21:19:45.0896 0x187c  Detect skipped due to KSN trusted
21:19:45.0896 0x187c  FirebirdServerMAGIXInstance - ok
21:19:45.0916 0x187c  [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk        C:\windows\system32\drivers\flpydisk.sys
21:19:45.0956 0x187c  flpydisk - ok
21:19:46.0006 0x187c  [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr          C:\windows\system32\drivers\fltmgr.sys
21:19:46.0026 0x187c  FltMgr - ok
21:19:46.0086 0x187c  [ 700A5373FA66F1DAAECBD2CFB88C73ED, D6C1C4C846BC24EB6539ECC701A456FA53BB6679C79391F5B70580D47B6CE395 ] FontCache      C:\windows\system32\FntCache.dll
21:19:46.0188 0x187c  FontCache - ok
21:19:46.0228 0x187c  [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:19:46.0258 0x187c  FontCache3.0.0.0 - ok
21:19:46.0278 0x187c  [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends      C:\windows\system32\drivers\FsDepends.sys
21:19:46.0298 0x187c  FsDepends - ok
21:19:46.0338 0x187c  [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec          C:\windows\system32\drivers\Fs_Rec.sys
21:19:46.0358 0x187c  Fs_Rec - ok
21:19:46.0378 0x187c  [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol          C:\windows\system32\DRIVERS\fvevol.sys
21:19:46.0398 0x187c  fvevol - ok
21:19:46.0418 0x187c  [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx        C:\windows\system32\drivers\gagp30kx.sys
21:19:46.0438 0x187c  gagp30kx - ok
21:19:46.0488 0x187c  [ E4AE497857409127ED57562AF913A903, 262ADD713B1FBF6200550967D1F8635B55D01BBD8FA2E753536E71A4EC87867B ] gpsvc          C:\windows\System32\gpsvc.dll
21:19:46.0558 0x187c  gpsvc - ok
21:19:46.0618 0x187c  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:19:46.0638 0x187c  gupdate - ok
21:19:46.0649 0x187c  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:19:46.0664 0x187c  gupdatem - ok
21:19:46.0680 0x187c  [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir        C:\windows\system32\drivers\hcw85cir.sys
21:19:46.0760 0x187c  hcw85cir - ok
21:19:46.0790 0x187c  [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
21:19:46.0830 0x187c  HdAudAddService - ok
21:19:46.0860 0x187c  [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus        C:\windows\system32\DRIVERS\HDAudBus.sys
21:19:46.0920 0x187c  HDAudBus - ok
21:19:46.0940 0x187c  [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt        C:\windows\system32\drivers\HidBatt.sys
21:19:46.0960 0x187c  HidBatt - ok
21:19:46.0970 0x187c  [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth          C:\windows\system32\drivers\hidbth.sys
21:19:47.0010 0x187c  HidBth - ok
21:19:47.0020 0x187c  [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr          C:\windows\system32\drivers\hidir.sys
21:19:47.0068 0x187c  HidIr - ok
21:19:47.0100 0x187c  [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv        C:\windows\system32\hidserv.dll
21:19:47.0155 0x187c  hidserv - ok
21:19:47.0195 0x187c  [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb          C:\windows\system32\DRIVERS\hidusb.sys
21:19:47.0242 0x187c  HidUsb - ok
21:19:47.0266 0x187c  [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc          C:\windows\system32\kmsvc.dll
21:19:47.0315 0x187c  hkmsvc - ok
21:19:47.0335 0x187c  [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\windows\system32\ListSvc.dll
21:19:47.0375 0x187c  HomeGroupListener - ok
21:19:47.0405 0x187c  [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\windows\system32\provsvc.dll
21:19:47.0445 0x187c  HomeGroupProvider - ok
21:19:47.0485 0x187c  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD          C:\windows\system32\drivers\HpSAMD.sys
21:19:47.0525 0x187c  HpSAMD - ok
21:19:47.0615 0x187c  [ F61634BEC53F73702A10DE69F6DCAF57, BBA7344CF3AB96A46D1A6F1D50F2758EA8D097FE558C38B4EF45C8C334AF96E1 ] HTTP            C:\windows\system32\drivers\HTTP.sys
21:19:47.0665 0x187c  HTTP - ok
21:19:47.0705 0x187c  [ D969D0E26C5B1E813B17066A8318D5D4, 27308902D216CD38F40B9341F40AFDCFEC09EA3122FB88E7C7A5C42D0433315D ] hwdatacard      C:\windows\system32\DRIVERS\ewusbmdm.sys
21:19:47.0745 0x187c  hwdatacard - ok
21:19:47.0785 0x187c  [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy        C:\windows\system32\drivers\hwpolicy.sys
21:19:47.0825 0x187c  hwpolicy - ok
21:19:47.0865 0x187c  [ B45B3647BA32749B94FA689175EC8C26, F0876ECA6FA66A296DB7E11FA9E4094D96064AE87EC21CC752C9B7E6A7DFEDD2 ] hwusbdev        C:\windows\system32\DRIVERS\ewusbdev.sys
21:19:47.0915 0x187c  hwusbdev - ok
21:19:47.0958 0x187c  [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt        C:\windows\system32\DRIVERS\i8042prt.sys
21:19:47.0986 0x187c  i8042prt - ok
21:19:48.0027 0x187c  [ B9E489CC1EA3284FEED33799DC70612D, 0DD714A3A37C391B38F4EEEB3F85C3C3C056F4AAB4A5EFA63835AD967BC25B51 ] iaStorA        C:\windows\system32\drivers\iaStorA.sys
21:19:48.0063 0x187c  iaStorA - ok
21:19:48.0162 0x187c  [ 3AEE4C821114AC707699A28988F27ABB, 033A25A19E2A649DA059AE3BCACB8605C00D4F10D356C5E3167B84C01B9359A9 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
21:19:48.0184 0x187c  IAStorDataMgrSvc - ok
21:19:48.0230 0x187c  [ CC096E5C9BAABEB8EF12CDFAFFD888CF, 9D61736CB83DE04FC44FB25122AB6D09951C915E577E1A18188D4D5F35EACD76 ] iaStorF        C:\windows\system32\drivers\iaStorF.sys
21:19:48.0243 0x187c  iaStorF - ok
21:19:48.0274 0x187c  [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV        C:\windows\system32\drivers\iaStorV.sys
21:19:48.0295 0x187c  iaStorV - ok
21:19:48.0341 0x187c  [ 1B904E09172A2D63CB728F56B9DC72AA, E83D8A55319B378EB76A88EF778F69F560C8F2541BBD58151754509008D1A2C5 ] ICCWDT          C:\windows\system32\DRIVERS\ICCWDT.sys
21:19:48.0370 0x187c  ICCWDT - ok
21:19:48.0450 0x187c  [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc          C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
21:19:48.0490 0x187c  idsvc - ok
21:19:48.0500 0x187c  IEEtwCollectorService - ok
21:19:48.0676 0x187c  [ 5268F385C889BB942E0F9596DE83373F, 011280191EEF8053CD413734A0B08F5DF88CD8408CD8354AABF2216F4C59F921 ] igfx            C:\windows\system32\DRIVERS\igdkmd64.sys
21:19:48.0850 0x187c  igfx - ok
21:19:48.0900 0x187c  [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp          C:\windows\system32\drivers\iirsp.sys
21:19:48.0930 0x187c  iirsp - ok
21:19:48.0982 0x187c  [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT          C:\windows\System32\ikeext.dll
21:19:49.0056 0x187c  IKEEXT - ok
21:19:49.0228 0x187c  [ D739148367AAE1DA0C12160DE141ECED, 471E6EA03F2BD7DD1E2812B56EFB00EDDCAA87E974833B75114B8EE93DC358A5 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHD64.sys
21:19:49.0312 0x187c  IntcAzAudAddService - ok
21:19:49.0380 0x187c  [ 0E0B99617ED3FDB6C5F0E2D62709B5DF, A656CA3A60E62BE16A015150B23136CE150F9876B4035E9E8D8E73D1707B37A4 ] IntcDAud        C:\windows\system32\DRIVERS\IntcDAud.sys
21:19:49.0430 0x187c  IntcDAud - ok
21:19:49.0500 0x187c  [ C6128F2E3DC6156C6F8828F9F1B96010, 612C1191AFB8F69BA5634E8C52BDDE608F57D98FA4C76C5A337676A5F1E8191D ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
21:19:49.0540 0x187c  Intel(R) Capability Licensing Service Interface - detected UnsignedFile.Multi.Generic ( 1 )
21:19:49.0922 0x187c  Detect skipped due to KSN trusted
21:19:49.0922 0x187c  Intel(R) Capability Licensing Service Interface - ok
21:19:49.0972 0x187c  [ 729AB4F0608E95EFF8FDEF23596283E2, 62A2091FF440C65505AB3E38436A86D9B0978BCB9485960EFCE0C5CBC8E06201 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
21:19:50.0044 0x187c  Intel(R) Capability Licensing Service TCP IP Interface - ok
21:19:50.0064 0x187c  [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide        C:\windows\system32\drivers\intelide.sys
21:19:50.0074 0x187c  intelide - ok
21:19:50.0114 0x187c  [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm        C:\windows\system32\DRIVERS\intelppm.sys
21:19:50.0174 0x187c  intelppm - ok
21:19:50.0204 0x187c  [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum      C:\windows\system32\ipbusenum.dll
21:19:50.0254 0x187c  IPBusEnum - ok
21:19:50.0274 0x187c  [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver  C:\windows\system32\DRIVERS\ipfltdrv.sys
21:19:50.0314 0x187c  IpFilterDriver - ok
21:19:50.0344 0x187c  [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc        C:\windows\System32\iphlpsvc.dll
21:19:50.0374 0x187c  iphlpsvc - ok
21:19:50.0374 0x187c  [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV        C:\windows\system32\drivers\IPMIDrv.sys
21:19:50.0404 0x187c  IPMIDRV - ok
21:19:50.0424 0x187c  [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT          C:\windows\system32\drivers\ipnat.sys
21:19:50.0474 0x187c  IPNAT - ok
21:19:50.0494 0x187c  [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM          C:\windows\system32\drivers\irenum.sys
21:19:50.0564 0x187c  IRENUM - ok
21:19:50.0584 0x187c  [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp          C:\windows\system32\drivers\isapnp.sys
21:19:50.0614 0x187c  isapnp - ok
21:19:50.0644 0x187c  [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt        C:\windows\system32\drivers\msiscsi.sys
21:19:50.0674 0x187c  iScsiPrt - ok
21:19:50.0684 0x187c  [ 78D369F8A81A341109FBA1DB64B4C512, E584F693255CCBF7006E7D35984149CF599BB0849A8F02EFDD6223DF0D606049 ] iusb3hcs        C:\windows\system32\drivers\iusb3hcs.sys
21:19:50.0704 0x187c  iusb3hcs - ok
21:19:50.0784 0x187c  [ 5B632ABA038CE2E2D5D2D1115C6B26D1, 605A8FFA704E4369CF9D17DF8630DC9E196B8920D47F1CC5151759E60B234C1F ] iusb3hub        C:\windows\system32\DRIVERS\iusb3hub.sys
21:19:50.0824 0x187c  iusb3hub - ok
21:19:50.0876 0x187c  [ EA841584EF59528D11F20355770E427E, 515737761BB2A0A233F4AD141E28D93E3B9789320A15B7D5FB3DB5AC3CD8E249 ] iusb3xhc        C:\windows\system32\DRIVERS\iusb3xhc.sys
21:19:50.0896 0x187c  iusb3xhc - ok
21:19:50.0972 0x187c  [ 924019BC58FEDDE04A08C45EC1CF1847, F18C581FE5C25C5BE4514185AD44C561EB715B98AFBE81EF0D673E103EA8E8EE ] jhi_service    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
21:19:51.0007 0x187c  jhi_service - ok
21:19:51.0038 0x187c  [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass        C:\windows\system32\DRIVERS\kbdclass.sys
21:19:51.0058 0x187c  kbdclass - ok
21:19:51.0072 0x187c  [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid          C:\windows\system32\drivers\kbdhid.sys
21:19:51.0103 0x187c  kbdhid - ok
21:19:51.0122 0x187c  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] KeyIso          C:\windows\system32\lsass.exe
21:19:51.0137 0x187c  KeyIso - ok
21:19:51.0174 0x187c  [ 6F5F0C6160EF237F0243C1E416EEBA98, 8BA8AA0D71350A74E294A731226B1638C6059013D645ABDE7188F7733E320FBD ] KSecDD          C:\windows\system32\Drivers\ksecdd.sys
21:19:51.0206 0x187c  KSecDD - ok
21:19:51.0230 0x187c  [ 05529E53B286FD60E7EF04EF138CABFD, 6C045750DCD3EE76F748582513AD4FA99C0E8E56B616725CD48DCA1068FF8923 ] KSecPkg        C:\windows\system32\Drivers\ksecpkg.sys
21:19:51.0246 0x187c  KSecPkg - ok
21:19:51.0281 0x187c  [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk        C:\windows\system32\drivers\ksthunk.sys
21:19:51.0325 0x187c  ksthunk - ok
21:19:51.0395 0x187c  [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm          C:\windows\system32\msdtckrm.dll
21:19:51.0505 0x187c  KtmRm - ok
21:19:51.0525 0x187c  [ A6131EE7C440992458688C7D0989C584, 94FEB4A6677262BAA590F77329141D9F539D3466D6E9473D639880AA6D5A103C ] L1C            C:\windows\system32\DRIVERS\L1C62x64.sys
21:19:51.0535 0x187c  L1C - ok
21:19:51.0595 0x187c  [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer    C:\windows\system32\srvsvc.dll
21:19:51.0705 0x187c  LanmanServer - ok
21:19:51.0725 0x187c  [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\windows\System32\wkssvc.dll
21:19:51.0775 0x187c  LanmanWorkstation - ok
21:19:51.0895 0x187c  [ B91987F22C206191683F50085B160F4B, B55452540A9C28F14CDEB0A4514E2C6D0440710441673356485CA18165863AE7 ] LavasoftTcpService C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.2.9.5\LavasoftTcpService.exe
21:19:51.0935 0x187c  LavasoftTcpService - ok
21:19:51.0955 0x187c  [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio          C:\windows\system32\DRIVERS\lltdio.sys
21:19:52.0015 0x187c  lltdio - ok
21:19:52.0071 0x187c  [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc        C:\windows\System32\lltdsvc.dll
21:19:52.0122 0x187c  lltdsvc - ok
21:19:52.0143 0x187c  [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts        C:\windows\System32\lmhsvc.dll
21:19:52.0195 0x187c  lmhosts - ok
21:19:52.0263 0x187c  [ EC90A0554EAC7E37139F2DAD8C56FB04, F62DBB7B174A270700631EA590B3293FE558940FB72F84C242391530E1DF78B5 ] LMS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
21:19:52.0287 0x187c  LMS - ok
21:19:52.0305 0x187c  [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC          C:\windows\system32\drivers\lsi_fc.sys
21:19:52.0320 0x187c  LSI_FC - ok
21:19:52.0331 0x187c  [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS        C:\windows\system32\drivers\lsi_sas.sys
21:19:52.0341 0x187c  LSI_SAS - ok
21:19:52.0361 0x187c  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2        C:\windows\system32\drivers\lsi_sas2.sys
21:19:52.0381 0x187c  LSI_SAS2 - ok
21:19:52.0381 0x187c  [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI        C:\windows\system32\drivers\lsi_scsi.sys
21:19:52.0401 0x187c  LSI_SCSI - ok
21:19:52.0441 0x187c  [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv          C:\windows\system32\drivers\luafv.sys
21:19:52.0471 0x187c  luafv - ok
21:19:52.0501 0x187c  [ 3BEC6134F1E45AEF5E971F69F0D38510, 245D7CEEB6561166EE0472551D39A9D3CFDDA52A6BF2E924AB243CCA7FBC9009 ] MBAMChameleon  C:\windows\system32\drivers\MBAMChameleon.sys
21:19:52.0511 0x187c  MBAMChameleon - ok
21:19:52.0571 0x187c  [ F3960CA85778E5D7611EE0F501972340, 0DE5C8509A9A66C8185B9FAA7EAF69C0FA9C28CD9DE84AA23E128E4FF8E06BF4 ] MBAMFarflt      C:\windows\system32\drivers\farflt.sys
21:19:52.0611 0x187c  MBAMFarflt - ok
21:19:52.0671 0x187c  [ 88BD122C3A35DE63D75D382DF75554CE, ABDF59543CAD186A6ED4E66257205D9CF5047732A5DA74A96A28B468B41BC396 ] MBAMProtection  C:\windows\system32\drivers\mbam.sys
21:19:52.0711 0x187c  MBAMProtection - ok
21:19:52.0943 0x187c  [ 28E521A6ABA9DE062A3719452816F495, B312A37DA052229DFB19353170CD5828582F8AC6426E857CA7C8ACA0DD91C160 ] MBAMService    C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
21:19:53.0062 0x187c  MBAMService - ok
21:19:53.0103 0x187c  [ ABB371D9AEF728B0489B0E6872B4A1C0, E9539A4F85FE30F5BAED742778CA74C879995728668ABE6877C37633716D8770 ] MBAMSwissArmy  C:\windows\system32\drivers\MBAMSwissArmy.sys
21:19:53.0121 0x187c  MBAMSwissArmy - ok
21:19:53.0171 0x187c  [ 8FF2D95CBA49B405C5DE27039FF0BF35, 03BF7FC7F1C2C76EDB583BA342EA1C325DB8058517744EF2A78529D3938F4DC1 ] MBfilt          C:\windows\system32\drivers\MBfilt64.sys
21:19:53.0198 0x187c  MBfilt - ok
21:19:53.0291 0x187c  [ 1704A8189EE5580AB147CFD25C5C8770, DFA076FD36B5CC844D4BE3B865E9A1F809E14CCB1D78D82A2D8D8EE38210E6EB ] McComponentHostService C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
21:19:53.0319 0x187c  McComponentHostService - ok
21:19:53.0339 0x187c  [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc        C:\windows\system32\Mcx2Svc.dll
21:19:53.0389 0x187c  Mcx2Svc - ok
21:19:53.0429 0x187c  [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas        C:\windows\system32\drivers\megasas.sys
21:19:53.0459 0x187c  megasas - ok
21:19:53.0479 0x187c  [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR          C:\windows\system32\drivers\MegaSR.sys
21:19:53.0499 0x187c  MegaSR - ok
21:19:53.0519 0x187c  [ 2BB3EAE2EA641515D4B205CAB29E1624, D3F18EE393EB1B0F919484281269A3C55A092D023E62C59D74CB63A55612024B ] MEIx64          C:\windows\system32\drivers\HECIx64.sys
21:19:53.0539 0x187c  MEIx64 - ok
21:19:53.0549 0x187c  MGHwCtrl - ok
21:19:53.0599 0x187c  [ 71C6748EE8DE938532057EF10B4B7E44, 455175332156939B3CDA4511A2A6C213ABBFDB85EEECA98B6AB014C994F532C4 ] Micro Star SCM  C:\Program Files (x86)\SCM\MSIService.exe
21:19:53.0609 0x187c  Micro Star SCM - detected UnsignedFile.Multi.Generic ( 1 )
21:19:53.0819 0x187c  Detect skipped due to KSN trusted
21:19:53.0819 0x187c  Micro Star SCM - ok
21:19:53.0859 0x187c  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS          C:\windows\system32\mmcss.dll
21:19:53.0949 0x187c  MMCSS - ok
21:19:53.0999 0x187c  [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem          C:\windows\system32\drivers\modem.sys
21:19:54.0065 0x187c  Modem - ok
21:19:54.0099 0x187c  [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor        C:\windows\system32\DRIVERS\monitor.sys
21:19:54.0137 0x187c  monitor - ok
21:19:54.0153 0x187c  [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass        C:\windows\system32\DRIVERS\mouclass.sys
21:19:54.0166 0x187c  mouclass - ok
21:19:54.0198 0x187c  [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid          C:\windows\system32\DRIVERS\mouhid.sys
21:19:54.0249 0x187c  mouhid - ok
21:19:54.0283 0x187c  [ 8ADB5445B29941CB41AF2846FD5C93C7, 689582430FE29EC0845B1DB841D3CC49D5D09DE264586E3999EEFE616986D12B ] mountmgr        C:\windows\system32\drivers\mountmgr.sys
21:19:54.0304 0x187c  mountmgr - ok
21:19:54.0383 0x187c  [ E464A0A92E2E354D07DDA713D3E10DE4, D5CF213F03DF54EF9933027A7A7D4413371C1ECBFF61E4DE818D50FA72C8C5FC ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
21:19:54.0393 0x187c  MozillaMaintenance - ok
21:19:54.0433 0x187c  [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio            C:\windows\system32\drivers\mpio.sys
21:19:56.0460 0x187c  mpio - ok
21:19:56.0550 0x187c  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv          C:\windows\system32\drivers\mpsdrv.sys
21:19:56.0610 0x187c  mpsdrv - ok
21:19:56.0660 0x187c  [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc          C:\windows\system32\mpssvc.dll
21:19:56.0720 0x187c  MpsSvc - ok
21:19:56.0760 0x187c  [ 98DB1790F0A584E0A2528B92B052417F, 9AA04CA73AFE599810CD233B9CEC212E16D44DCEDF5C7D0181C7257F498068B5 ] MRxDAV          C:\windows\system32\drivers\mrxdav.sys
21:19:56.0790 0x187c  MRxDAV - ok
21:19:56.0830 0x187c  [ 632E8A00090E4F85F304E152C92C7F2C, A3098941251A8327C95E6B1122384D54FB0ED705A9215577D968EA5B5FD88C87 ] mrxsmb          C:\windows\system32\DRIVERS\mrxsmb.sys
21:19:56.0910 0x187c  mrxsmb - ok
21:19:56.0960 0x187c  [ 0D9C05484F2F4BD9D33A615D5DBE67EA, 1E164B631B1CD85DD5B205284CB547B189609946490AAABD22741743BFB413DF ] mrxsmb10        C:\windows\system32\DRIVERS\mrxsmb10.sys
21:19:56.0980 0x187c  mrxsmb10 - ok
21:19:57.0030 0x187c  [ 6123E6FECC1C164022868FB1982271BE, 417E6C7AFF8B014B31AFCC202B0DCEECBDBB73205DF8C3EFC7E313664E284178 ] mrxsmb20        C:\windows\system32\DRIVERS\mrxsmb20.sys
21:19:57.0078 0x187c  mrxsmb20 - ok
21:19:57.0098 0x187c  [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci          C:\windows\system32\drivers\msahci.sys
21:19:57.0119 0x187c  msahci - ok
21:19:57.0154 0x187c  [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm          C:\windows\system32\drivers\msdsm.sys
21:19:57.0169 0x187c  msdsm - ok
21:19:57.0211 0x187c  [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC          C:\windows\System32\msdtc.exe
21:19:57.0271 0x187c  MSDTC - ok
21:19:57.0314 0x187c  [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs            C:\windows\system32\drivers\Msfs.sys
21:19:57.0368 0x187c  Msfs - ok
21:19:57.0378 0x187c  [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf      C:\windows\System32\drivers\mshidkmdf.sys
21:19:57.0438 0x187c  mshidkmdf - ok
21:19:57.0488 0x187c  [ 87B9DAF6D123EC06C19B41D5295441AD, 2066EA70D85B9F17CA3121D69DB25E2E17C4AFAECB68CC97FFF4A3062099FF0C ] MSI Foundation Service C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe
21:19:57.0508 0x187c  MSI Foundation Service - detected UnsignedFile.Multi.Generic ( 1 )
21:19:58.0048 0x187c  Detect skipped due to KSN trusted
21:19:58.0048 0x187c  MSI Foundation Service - ok
21:19:58.0098 0x187c  [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv        C:\windows\system32\drivers\msisadrv.sys
21:19:58.0118 0x187c  msisadrv - ok
21:19:58.0158 0x187c  [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI        C:\windows\system32\iscsiexe.dll
21:19:58.0208 0x187c  MSiSCSI - ok
21:19:58.0208 0x187c  msiserver - ok
21:19:58.0248 0x187c  [ 6DC2A478749CB24DC2DCE92A92DE3288, 86D74A6002E16C0ED7B9A933E88DF006E3D9299D14D29A05D61B5BD48E05BE87 ] MSI_SuperCharger C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
21:19:58.0268 0x187c  MSI_SuperCharger - ok
21:19:58.0278 0x187c  [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV        C:\windows\system32\drivers\MSKSSRV.sys
21:19:58.0328 0x187c  MSKSSRV - ok
21:19:58.0328 0x187c  [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK        C:\windows\system32\drivers\MSPCLOCK.sys
21:19:58.0368 0x187c  MSPCLOCK - ok
21:19:58.0388 0x187c  [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM          C:\windows\system32\drivers\MSPQM.sys
21:19:58.0418 0x187c  MSPQM - ok
21:19:58.0448 0x187c  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC          C:\windows\system32\drivers\MsRPC.sys
21:19:58.0468 0x187c  MsRPC - ok
21:19:58.0508 0x187c  [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios        C:\windows\system32\drivers\mssmbios.sys
21:19:58.0518 0x187c  mssmbios - ok
21:19:58.0518 0x187c  [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE          C:\windows\system32\drivers\MSTEE.sys
21:19:58.0568 0x187c  MSTEE - ok
21:19:58.0578 0x187c  [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig        C:\windows\system32\drivers\MTConfig.sys
21:19:58.0608 0x187c  MTConfig - ok
21:19:58.0628 0x187c  [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup            C:\windows\system32\Drivers\mup.sys
21:19:58.0638 0x187c  Mup - ok
21:19:58.0668 0x187c  [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent        C:\windows\system32\qagentRT.dll
21:19:58.0728 0x187c  napagent - ok
21:19:58.0788 0x187c  [ 8D11DA92F83D8C8281689739BEF05FD5, AD1D95CE084D1BD8310F6AA1CB27BEA98D9354E334AEC448AD6E6F68B52EEBC7 ] NAT            C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe
21:19:58.0798 0x187c  NAT - ok
21:19:58.0838 0x187c  [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP    C:\windows\system32\DRIVERS\nwifi.sys
21:19:58.0868 0x187c  NativeWifiP - ok
21:19:58.0918 0x187c  [ F7309F42555F8AAB7144A51A1F2585B0, 065277A8AFAEE3888C997A76D2F751070F92DF4C3354D16B194860B4BDAFF937 ] NDIS            C:\windows\system32\drivers\ndis.sys
21:19:58.0948 0x187c  NDIS - ok
21:19:58.0978 0x187c  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap        C:\windows\system32\DRIVERS\ndiscap.sys
21:19:59.0029 0x187c  NdisCap - ok
21:19:59.0052 0x187c  [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi        C:\windows\system32\DRIVERS\ndistapi.sys
21:19:59.0112 0x187c  NdisTapi - ok
21:19:59.0143 0x187c  [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio        C:\windows\system32\DRIVERS\ndisuio.sys
21:19:59.0196 0x187c  Ndisuio - ok
21:19:59.0217 0x187c  [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan        C:\windows\system32\DRIVERS\ndiswan.sys
21:19:59.0263 0x187c  NdisWan - ok
21:19:59.0292 0x187c  [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy        C:\windows\system32\drivers\NDProxy.sys
21:19:59.0336 0x187c  NDProxy - ok
21:19:59.0346 0x187c  [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS        C:\windows\system32\DRIVERS\netbios.sys
21:19:59.0396 0x187c  NetBIOS - ok
21:19:59.0446 0x187c  [ E47D571FEC2C76E867935109AB2A770C, F349D25890B6F476B106FD75BFB081DB737CA9B224D95E44927942FFF2DF82CD ] NetBT          C:\windows\system32\DRIVERS\netbt.sys
21:19:59.0466 0x187c  NetBT - ok
21:19:59.0486 0x187c  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] Netlogon        C:\windows\system32\lsass.exe
21:19:59.0506 0x187c  Netlogon - ok
21:19:59.0536 0x187c  [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman          C:\windows\System32\netman.dll
21:19:59.0576 0x187c  Netman - ok
21:19:59.0636 0x187c  [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetMsmqActivator C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:19:59.0676 0x187c  NetMsmqActivator - ok
21:19:59.0686 0x187c  [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetPipeActivator C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:19:59.0706 0x187c  NetPipeActivator - ok
21:19:59.0746 0x187c  [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm        C:\windows\System32\netprofm.dll
21:19:59.0796 0x187c  netprofm - ok
21:19:59.0806 0x187c  [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetTcpActivator C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:19:59.0826 0x187c  NetTcpActivator - ok
21:19:59.0826 0x187c  [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:19:59.0846 0x187c  NetTcpPortSharing - ok
21:19:59.0866 0x187c  [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960        C:\windows\system32\drivers\nfrd960.sys
21:19:59.0876 0x187c  nfrd960 - ok
21:19:59.0906 0x187c  [ 8B301D474B478E9A92823BAB50A7BC49, 8181816035F41B1DABEC05E65E4F67BCD785F56760A61F1049E91BA39D42F01D ] NlaSvc          C:\windows\System32\nlasvc.dll
21:19:59.0956 0x187c  NlaSvc - ok
21:20:00.0116 0x187c  [ FD8082D64C151589F12A4F620DBA3030, 649D61BF958ED50C0B5F7E0D2E633D20C8AAA00706A7AE9528DA78E2B6B3492E ] NOBU            C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
21:20:00.0218 0x187c  NOBU - ok
21:20:00.0248 0x187c  Norton PC Checkup Application Launcher - ok
21:20:00.0268 0x187c  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs            C:\windows\system32\drivers\Npfs.sys
21:20:00.0328 0x187c  Npfs - ok
21:20:00.0358 0x187c  [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi            C:\windows\system32\nsisvc.dll
21:20:00.0408 0x187c  nsi - ok
21:20:00.0438 0x187c  [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy        C:\windows\system32\drivers\nsiproxy.sys
21:20:00.0508 0x187c  nsiproxy - ok
21:20:00.0588 0x187c  [ 47B2D0B31BDC3EBE6090228E2BA3764D, 984A4B38300954164BCBF57EC1A09C18B53779E60A26E9618B50E26016735787 ] Ntfs            C:\windows\system32\drivers\Ntfs.sys
21:20:00.0628 0x187c  Ntfs - ok
21:20:00.0688 0x187c  [ 23CF3DA010497EB2BF39A5C5A57E437C, 39CFDE7D401EFCE4F550E0A9461F5FC4D71FA07235E1336E4F0B4882BD76550E ] NTIOLib_1_0_3  C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys
21:20:00.0718 0x187c  NTIOLib_1_0_3 - ok
21:20:00.0768 0x187c  [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null            C:\windows\system32\drivers\Null.sys
21:20:00.0808 0x187c  Null - ok
21:20:00.0828 0x187c  [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid          C:\windows\system32\drivers\nvraid.sys
21:20:00.0848 0x187c  nvraid - ok
21:20:00.0848 0x187c  [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor          C:\windows\system32\drivers\nvstor.sys
21:20:00.0868 0x187c  nvstor - ok
21:20:00.0868 0x187c  [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp          C:\windows\system32\drivers\nv_agp.sys
21:20:00.0888 0x187c  nv_agp - ok
21:20:00.0888 0x187c  [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394        C:\windows\system32\drivers\ohci1394.sys
21:20:00.0908 0x187c  ohci1394 - ok
21:20:00.0938 0x187c  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc        C:\windows\system32\pnrpsvc.dll
21:20:01.0038 0x187c  p2pimsvc - ok
21:20:01.0070 0x187c  [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc          C:\windows\system32\p2psvc.dll
21:20:01.0120 0x187c  p2psvc - ok
21:20:01.0143 0x187c  panda_url_filtering - ok
21:20:01.0190 0x187c  [ 6925454E20B184E482CD65F297D51DB5, 9386542E9B20C370FCB275C7F8005DAD45C86BBC2F7B8DB3552FA49B474C5EED ] panda_url_filteringd C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys
21:20:01.0204 0x187c  panda_url_filteringd - ok
21:20:01.0234 0x187c  [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport        C:\windows\system32\drivers\parport.sys
21:20:01.0264 0x187c  Parport - ok
21:20:01.0293 0x187c  [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr        C:\windows\system32\drivers\partmgr.sys
21:20:01.0308 0x187c  partmgr - ok
21:20:01.0425 0x187c  [ 64DAD6D8A41725325BDAD78E566ACB34, 6599C5C1F8DF5BB85C0DBE4300DF1F4C015E00720B28951149D5924D65FD3DF8 ] pbamw_service  C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\AmwService.exe
21:20:01.0465 0x187c  pbamw_service - ok
21:20:01.0495 0x187c  [ 3CD83692C43D87088E85E3C916146FFB, 9E812535E8FBA045FDA30F68E9EB2031132C37721D542A2DC9D4C33E2B137FCF ] PcaSvc          C:\windows\System32\pcasvc.dll
21:20:01.0565 0x187c  PcaSvc - ok
21:20:01.0595 0x187c  [ 2F86BE1818C2D7AC90478E3323EE7FCB, CE721FCFFDC9D24483DEB6BB77DAFEBE79BA143CA2EE68BF28E2A9297AADB2D4 ] PCCUJobMgr      C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe
21:20:01.0605 0x187c  PCCUJobMgr - ok
21:20:01.0655 0x187c  [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci            C:\windows\system32\drivers\pci.sys
21:20:01.0665 0x187c  pci - ok
21:20:01.0685 0x187c  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide          C:\windows\system32\drivers\pciide.sys
21:20:01.0705 0x187c  pciide - ok
21:20:01.0715 0x187c  [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia          C:\windows\system32\drivers\pcmcia.sys
21:20:01.0735 0x187c  pcmcia - ok
21:20:01.0765 0x187c  [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw            C:\windows\system32\drivers\pcw.sys
21:20:01.0785 0x187c  pcw - ok
21:20:01.0895 0x187c  [ 8F98C4BC605261B4B6E568FE791EB67A, 7B0D99D972A60423F7378BEE886061695FDA79B59AFF939744A130721E0174A1 ] PDF Architect 2 C:\Program Files (x86)\PDF Architect 2\ws.exe
21:20:01.0945 0x187c  PDF Architect 2 - ok
21:20:01.0985 0x187c  [ B2309F132A31AF03C0A249AEDE8CF289, BBAE32AA55E495ACB9A8089C090ADD78BE1DC16233CAA61BBED1456CA718D430 ] PDF Architect 2 Creator C:\Program Files (x86)\PDF Architect 2\creator-ws.exe
21:20:02.0015 0x187c  PDF Architect 2 Creator - ok
21:20:02.0054 0x187c  [ 9077A3059AB47834633AEAAED465F3D9, 9CA662E9CBA30795E4E5DAB3E309D2062FFDC2053C261054E24EF7EE5300F69F ] pdfforge CrashHandler C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe
21:20:02.0082 0x187c  pdfforge CrashHandler - ok
21:20:02.0136 0x187c  [ EA4D67448BE493D543F1730D6CD04694, 24717C5E41B7CA522F3330EF2228B6685E710A5259396E9887A1C1E7A413F8CA ] PEAUTH          C:\windows\system32\drivers\peauth.sys
21:20:02.0182 0x187c  PEAUTH - ok
21:20:02.0248 0x187c  [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost        C:\windows\SysWow64\perfhost.exe
21:20:02.0301 0x187c  PerfHost - ok
21:20:02.0377 0x187c  [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla            C:\windows\system32\pla.dll
21:20:02.0447 0x187c  pla - ok
21:20:02.0517 0x187c  [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay        C:\windows\system32\umpnpmgr.dll
21:20:02.0577 0x187c  PlugPlay - ok
21:20:02.0587 0x187c  [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg    C:\windows\system32\pnrpauto.dll
21:20:02.0617 0x187c  PNRPAutoReg - ok
21:20:02.0637 0x187c  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc        C:\windows\system32\pnrpsvc.dll
21:20:02.0667 0x187c  PNRPsvc - ok
21:20:02.0697 0x187c  [ 80D6B0563ED2BF10656B1D4748331082, B7E6B5E1148B7EE537E8D5C3A65450876B61CD45A395267D08699746E98AD574 ] PolicyAgent    C:\windows\System32\ipsecsvc.dll
21:20:02.0747 0x187c  PolicyAgent - ok
21:20:02.0767 0x187c  [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power          C:\windows\system32\umpo.dll
21:20:02.0817 0x187c  Power - ok
21:20:02.0857 0x187c  [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport    C:\windows\system32\DRIVERS\raspptp.sys
21:20:02.0897 0x187c  PptpMiniport - ok
21:20:02.0937 0x187c  [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor      C:\windows\system32\drivers\processr.sys
21:20:02.0977 0x187c  Processor - ok
21:20:03.0007 0x187c  [ B6A58491307B4CADA572583D863DC602, 5C44936605E52C9533E4CE22F18FAB8211475877F71EFD88DA4D02FD608C90A3 ] ProfSvc        C:\windows\system32\profsvc.dll
21:20:03.0086 0x187c  ProfSvc - ok
21:20:03.0112 0x187c  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] ProtectedStorage C:\windows\system32\lsass.exe
21:20:03.0134 0x187c  ProtectedStorage - ok
21:20:03.0172 0x187c  [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched          C:\windows\system32\DRIVERS\pacer.sys
21:20:03.0223 0x187c  Psched - ok
21:20:03.0275 0x187c  [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300          C:\windows\system32\drivers\ql2300.sys
21:20:03.0319 0x187c  ql2300 - ok
21:20:03.0335 0x187c  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx          C:\windows\system32\drivers\ql40xx.sys
21:20:03.0345 0x187c  ql40xx - ok
21:20:03.0375 0x187c  [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE          C:\windows\system32\qwave.dll
21:20:03.0395 0x187c  QWAVE - ok
21:20:03.0405 0x187c  [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv        C:\windows\system32\drivers\qwavedrv.sys
21:20:03.0435 0x187c  QWAVEdrv - ok
21:20:03.0505 0x187c  [ A55E7D0D873B2C97585B3B5926AC6ADE, 3BE3895DA7F0888E85B1941525878BA0846A8F215AD39ED8138BB39615468E32 ] RapiMgr        C:\windows\WindowsMobile\rapimgr.dll
21:20:03.0545 0x187c  RapiMgr - ok
21:20:03.0555 0x187c  [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd          C:\windows\system32\DRIVERS\rasacd.sys
21:20:03.0625 0x187c  RasAcd - ok
21:20:03.0645 0x187c  [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn    C:\windows\system32\DRIVERS\AgileVpn.sys
21:20:03.0685 0x187c  RasAgileVpn - ok
21:20:03.0705 0x187c  [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto        C:\windows\System32\rasauto.dll
21:20:03.0745 0x187c  RasAuto - ok
21:20:03.0775 0x187c  [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp        C:\windows\system32\DRIVERS\rasl2tp.sys
21:20:03.0805 0x187c  Rasl2tp - ok
21:20:03.0825 0x187c  [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan          C:\windows\System32\rasmans.dll
21:20:03.0875 0x187c  RasMan - ok
21:20:03.0895 0x187c  [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe        C:\windows\system32\DRIVERS\raspppoe.sys
21:20:03.0945 0x187c  RasPppoe - ok
21:20:03.0955 0x187c  [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp        C:\windows\system32\DRIVERS\rassstp.sys
21:20:04.0005 0x187c  RasSstp - ok
21:20:04.0065 0x187c  [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss          C:\windows\system32\DRIVERS\rdbss.sys
21:20:04.0125 0x187c  rdbss - ok
21:20:04.0135 0x187c  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus          C:\windows\system32\drivers\rdpbus.sys
21:20:04.0175 0x187c  rdpbus - ok
21:20:04.0195 0x187c  [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD          C:\windows\system32\DRIVERS\RDPCDD.sys
21:20:04.0245 0x187c  RDPCDD - ok
21:20:04.0255 0x187c  [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD        C:\windows\system32\drivers\rdpencdd.sys
21:20:04.0305 0x187c  RDPENCDD - ok
21:20:04.0325 0x187c  [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP        C:\windows\system32\drivers\rdprefmp.sys
21:20:04.0375 0x187c  RDPREFMP - ok
21:20:04.0465 0x187c  [ 313F68E1A3E6345A4F47A36B07062F34, B8318A0AE06BDE278931CA52F960B9FE226FD9894B076858DDB755AE26E1E66F ] RdpVideoMiniport C:\windows\system32\drivers\rdpvideominiport.sys
21:20:04.0535 0x187c  RdpVideoMiniport - ok
21:20:04.0575 0x187c  [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD          C:\windows\system32\drivers\RDPWD.sys
21:20:04.0645 0x187c  RDPWD - ok
21:20:04.0675 0x187c  [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost        C:\windows\system32\drivers\rdyboost.sys
21:20:04.0705 0x187c  rdyboost - ok
21:20:04.0747 0x187c  [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess    C:\windows\System32\mprdim.dll
21:20:04.0807 0x187c  RemoteAccess - ok
21:20:04.0827 0x187c  [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry  C:\windows\system32\regsvc.dll
21:20:04.0877 0x187c  RemoteRegistry - ok
21:20:04.0907 0x187c  [ 3DD798846E2C28102B922C56E71B7932, 30B111615D74CB2213997A5C08DD9C8613ADE441D9423CC1C49A753D13CE524D ] RFCOMM          C:\windows\system32\DRIVERS\rfcomm.sys
21:20:04.0937 0x187c  RFCOMM - ok
21:20:04.0967 0x187c  [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper    C:\windows\System32\RpcEpMap.dll
21:20:05.0017 0x187c  RpcEptMapper - ok
21:20:05.0064 0x187c  [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator      C:\windows\system32\locator.exe
21:20:05.0130 0x187c  RpcLocator - ok
21:20:05.0175 0x187c  [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] RpcSs          C:\windows\system32\rpcss.dll
21:20:05.0207 0x187c  RpcSs - ok
21:20:05.0274 0x187c  [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr          C:\windows\system32\DRIVERS\rspndr.sys
21:20:05.0361 0x187c  rspndr - ok
21:20:05.0411 0x187c  [ 135A64530D7699AD48F29D73A658DD11, 35838AE8ACFD9047C68DD0C8910557A82998E5CD778D5B98D4767AFA4BCE85BB ] RSUSBSTOR      C:\windows\System32\Drivers\RtsUStor.sys
21:20:05.0431 0x187c  RSUSBSTOR - ok
21:20:05.0461 0x187c  [ 8FA11ECB00AED22ACFEA154B7981D9E6, E72363AB33B17B4942187DADEC8DD9ECB047D2BCAE359148FA2F70EEF935264E ] RtkAvrcp        C:\windows\system32\drivers\RtkAvrcp.sys
21:20:05.0471 0x187c  RtkAvrcp - ok
21:20:05.0491 0x187c  [ 8008A68D94F4CF164CD636E8A4F8FB0A, 3E8E9DFC397737798AEE920A75D5355651FF823685309641711E9A6396AA6D5F ] RtkAvrcpCtrlr  C:\windows\system32\drivers\RtkAvrcpCtrlr.sys
21:20:05.0511 0x187c  RtkAvrcpCtrlr - ok
21:20:05.0561 0x187c  [ 543AFFECD35CFABD4490661F83685A0D, 819C022284E54C950D1144B9260C944D493CB4646713B30790818EFC99B82CCB ] RtkBleServ      C:\Program Files (x86)\REALTEK\Realtek Bluetooth\RtkBleServ.exe
21:20:05.0561 0x187c  RtkBleServ - detected UnsignedFile.Multi.Generic ( 1 )
21:20:05.0801 0x187c  Detect skipped due to KSN trusted
21:20:05.0801 0x187c  RtkBleServ - ok
21:20:05.0841 0x187c  [ 0772C3A9B2AB1907FCB68F2109F18E3B, FECAF1916CE9224D1784F5F99267B95A21969937DB57833FCD6C6118D0A442DC ] RtkBtFilter    C:\windows\system32\DRIVERS\RtkBtfilter.sys
21:20:05.0871 0x187c  RtkBtFilter - ok
21:20:05.0981 0x187c  [ F84917461BDB7C51B2ED7FF062B3A64A, 0DC81BA49BDDB4F425F526A21357E1CF70C94D67E99B3020E9FF14B680851EEC ] RTWlanE        C:\windows\system32\DRIVERS\rtwlane.sys
21:20:06.0021 0x187c  RTWlanE - ok
21:20:06.0057 0x187c  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] SamSs          C:\windows\system32\lsass.exe
21:20:06.0076 0x187c  SamSs - ok
21:20:06.0107 0x187c  [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port        C:\windows\system32\drivers\sbp2port.sys
21:20:06.0130 0x187c  sbp2port - ok
21:20:06.0177 0x187c  [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr        C:\windows\System32\SCardSvr.dll
21:20:06.0228 0x187c  SCardSvr - ok
21:20:06.0245 0x187c  [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter        C:\windows\system32\DRIVERS\scfilter.sys
21:20:06.0291 0x187c  scfilter - ok
21:20:06.0354 0x187c  [ 40686B59C127F0C93B4234E4A1E3472A, B2DD61CB796C6AA8AFD285D43472B94646CA6D331D282818E0FDC9DE28DDE9CF ] Schedule        C:\windows\system32\schedsvc.dll
21:20:06.0424 0x187c  Schedule - ok
21:20:06.0444 0x187c  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc    C:\windows\System32\certprop.dll
21:20:06.0484 0x187c  SCPolicySvc - ok
21:20:06.0514 0x187c  [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC          C:\windows\System32\SDRSVC.dll
21:20:06.0544 0x187c  SDRSVC - ok
21:20:06.0607 0x187c  [ 07EEDE29DF77E80EC93AE709CCD80B41, B5DF5F3108815094F0259004E093F56551A70AF6CBE02C3CBDC894589E3ADD38 ] SearchProtectionService C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
21:20:06.0641 0x187c  SearchProtectionService - ok
21:20:06.0691 0x187c  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\windows\system32\drivers\secdrv.sys
21:20:06.0759 0x187c  secdrv - ok
21:20:06.0794 0x187c  [ A19623BDD61E66A12AB53992002B4F3A, E351CEEC086084A417BA3BD0EEF46114D3147EC38E3EF8BE49B724F9D028CC56 ] seclogon        C:\windows\system32\seclogon.dll
21:20:06.0842 0x187c  seclogon - ok
21:20:06.0869 0x187c  [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS            C:\windows\System32\sens.dll
21:20:06.0907 0x187c  SENS - ok
21:20:06.0927 0x187c  [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc        C:\windows\system32\sensrsvc.dll
21:20:06.0977 0x187c  SensrSvc - ok
21:20:06.0987 0x187c  [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum        C:\windows\system32\drivers\serenum.sys
21:20:07.0007 0x187c  Serenum - ok
21:20:07.0017 0x187c  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial          C:\windows\system32\drivers\serial.sys
21:20:07.0057 0x187c  Serial - ok
21:20:07.0061 0x187c  [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse        C:\windows\system32\drivers\sermouse.sys
21:20:07.0077 0x187c  sermouse - ok
21:20:07.0104 0x187c  [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv      C:\windows\system32\sessenv.dll
21:20:07.0164 0x187c  SessionEnv - ok
21:20:07.0170 0x187c  [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk        C:\windows\system32\drivers\sffdisk.sys
21:20:07.0196 0x187c  sffdisk - ok
21:20:07.0200 0x187c  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc        C:\windows\system32\drivers\sffp_mmc.sys
21:20:07.0227 0x187c  sffp_mmc - ok
21:20:07.0230 0x187c  [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd        C:\windows\system32\drivers\sffp_sd.sys
21:20:07.0262 0x187c  sffp_sd - ok
21:20:07.0265 0x187c  [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy        C:\windows\system32\drivers\sfloppy.sys
21:20:07.0281 0x187c  sfloppy - ok
21:20:07.0336 0x187c  [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess    C:\windows\System32\ipnathlp.dll
21:20:07.0386 0x187c  SharedAccess - ok
21:20:07.0446 0x187c  [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\windows\System32\shsvcs.dll
21:20:07.0526 0x187c  ShellHWDetection - ok
21:20:07.0556 0x187c  [ E9E830D540EDEDED650F906628468548, 9800160C6807B28A2A1E57810151473C96F1484F2EF75D3E378E8C96440CD4CE ] simptcp        C:\windows\System32\tcpsvcs.exe
21:20:07.0576 0x187c  simptcp - ok
21:20:07.0606 0x187c  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2        C:\windows\system32\drivers\SiSRaid2.sys
21:20:07.0616 0x187c  SiSRaid2 - ok
21:20:07.0626 0x187c  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4        C:\windows\system32\drivers\sisraid4.sys
21:20:07.0636 0x187c  SiSRaid4 - ok
21:20:07.0746 0x187c  [ F3AAB7DF6408431C762D8721B68F46E4, 56ED764AA660955B8B06322703D086B3A52106625A83CCAF195B08BCBDEDA88F ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
21:20:07.0786 0x187c  SkypeUpdate - ok
21:20:07.0796 0x187c  [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb            C:\windows\system32\DRIVERS\smb.sys
21:20:07.0836 0x187c  Smb - ok
21:20:07.0876 0x187c  [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP        C:\windows\System32\snmptrap.exe
21:20:07.0896 0x187c  SNMPTRAP - ok
21:20:07.0926 0x187c  [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr          C:\windows\system32\drivers\spldr.sys
21:20:07.0936 0x187c  spldr - ok
21:20:07.0966 0x187c  [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler        C:\windows\System32\spoolsv.exe
21:20:08.0006 0x187c  Spooler - ok
21:20:08.0115 0x187c  [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc          C:\windows\system32\sppsvc.exe
21:20:08.0241 0x187c  sppsvc - ok
21:20:08.0271 0x187c  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify    C:\windows\system32\sppuinotify.dll
21:20:08.0316 0x187c  sppuinotify - ok
21:20:08.0406 0x187c  [ EC666682FE8344CF7E6ED69E74FA9F4F, DCD2A1C046425630689E2C9A6A6E356FE5A2A6664D12C20CFE236FCB32240DF9 ] srv            C:\windows\system32\DRIVERS\srv.sys
21:20:08.0466 0x187c  srv - ok
21:20:08.0506 0x187c  [ E450C0318DCE8ED28ED272C8806B8495, D2FD459F8C5E42103EF2F71421FA175A4F0821F8C2A3763093122D433D1C50FB ] srv2            C:\windows\system32\DRIVERS\srv2.sys
21:20:08.0536 0x187c  srv2 - ok
21:20:08.0566 0x187c  [ 9C12C78AD36C23D925711A4640228225, FF72C23F2A08EDF0C41BAF1EB0245AB44FF91365C5466F09C47A8F0928D20994 ] srvnet          C:\windows\system32\DRIVERS\srvnet.sys
21:20:08.0586 0x187c  srvnet - ok
21:20:08.0616 0x187c  [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV        C:\windows\System32\ssdpsrv.dll
21:20:08.0666 0x187c  SSDPSRV - ok
21:20:08.0676 0x187c  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc        C:\windows\system32\sstpsvc.dll
21:20:08.0726 0x187c  SstpSvc - ok
21:20:08.0756 0x187c  [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor        C:\windows\system32\drivers\stexstor.sys
21:20:08.0766 0x187c  stexstor - ok
21:20:08.0826 0x187c  [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc          C:\windows\System32\wiaservc.dll
21:20:08.0876 0x187c  stisvc - ok
21:20:08.0926 0x187c  [ 04CF20310145DEC63D5387BEAFF77D9A, 5017AF8C2DFBFE1F9946FF5AF229D62D141118EA923EEFA994EB4C7B52DEF208 ] SWDUMon        C:\windows\system32\DRIVERS\SWDUMon.sys
21:20:08.0936 0x187c  SWDUMon - ok
21:20:08.0956 0x187c  [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum          C:\windows\system32\drivers\swenum.sys
21:20:08.0966 0x187c  swenum - ok
21:20:09.0006 0x187c  [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv          C:\windows\System32\swprv.dll
21:20:09.0126 0x187c  swprv - ok
21:20:09.0196 0x187c  [ 2E730941CC5BF6200A4F56D1E9C24AAD, 758836D55DC84F3EBE9917DC6FAB8E6170A5B238FEDBCFDB6D7C5C6EA98E08B2 ] SysMain        C:\windows\system32\sysmain.dll
21:20:09.0258 0x187c  SysMain - ok
21:20:09.0278 0x187c  [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\windows\System32\TabSvc.dll
21:20:09.0308 0x187c  TabletInputService - ok
21:20:09.0338 0x187c  [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv        C:\windows\System32\tapisrv.dll
21:20:09.0378 0x187c  TapiSrv - ok
21:20:09.0448 0x187c  [ B2875D7ABB82867DC3AA03D991940201, F954C33FBA912A517B59330F6438C1953F9F1D8F4D8FD25945EB836A1DB07ABB ] Tcpip          C:\windows\system32\drivers\tcpip.sys
21:20:09.0498 0x187c  Tcpip - ok
21:20:09.0568 0x187c  [ B2875D7ABB82867DC3AA03D991940201, F954C33FBA912A517B59330F6438C1953F9F1D8F4D8FD25945EB836A1DB07ABB ] TCPIP6          C:\windows\system32\DRIVERS\tcpip.sys
21:20:09.0618 0x187c  TCPIP6 - ok
21:20:09.0648 0x187c  [ 7FE5586314EE7D6AA8483264A089E5AF, 4E3EA68713A45C22F1B9A1AA125E15D06D0C5E637B815537431ADFB6D7563879 ] tcpipreg        C:\windows\system32\drivers\tcpipreg.sys
21:20:09.0688 0x187c  tcpipreg - ok
21:20:09.0718 0x187c  [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE          C:\windows\system32\drivers\tdpipe.sys
21:20:09.0748 0x187c  TDPIPE - ok
21:20:09.0778 0x187c  [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP          C:\windows\system32\drivers\tdtcp.sys
21:20:09.0808 0x187c  TDTCP - ok
21:20:09.0868 0x187c  [ AA77EB517D2F07A947294F260E3ACA83, B7A5DF3066830C0C2302B059778A67419792058A0D300C471DE40AB245EA7E58 ] tdx            C:\windows\system32\DRIVERS\tdx.sys
21:20:09.0918 0x187c  tdx - ok
21:20:09.0938 0x187c  [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD          C:\windows\system32\drivers\termdd.sys
21:20:09.0958 0x187c  TermDD - ok
21:20:10.0008 0x187c  [ 008CD4EBFABCF78D0F19B3778492648C, 9050490EEE0AD86E73F0A82D83E4FC29DF84F6B6FDB389AE135FD712B5F425BE ] TermService    C:\windows\System32\termsrv.dll
21:20:10.0068 0x187c  TermService - ok
21:20:10.0088 0x187c  [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes          C:\windows\system32\themeservice.dll
21:20:10.0108 0x187c  Themes - ok
21:20:10.0138 0x187c  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER    C:\windows\system32\mmcss.dll
21:20:10.0178 0x187c  THREADORDER - ok
21:20:10.0198 0x187c  [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks          C:\windows\System32\trkwks.dll
21:20:10.0238 0x187c  TrkWks - ok
21:20:10.0278 0x187c  [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
21:20:10.0328 0x187c  TrustedInstaller - ok
21:20:10.0358 0x187c  [ 19BEDA57F3E0A06B8D5EB6D619BD5624, 952D5FAFD662C93628C12A6F7EB8E240A44216C0A15CBD2F5016BC357CBFE821 ] tssecsrv        C:\windows\system32\DRIVERS\tssecsrv.sys
21:20:10.0428 0x187c  tssecsrv - ok
21:20:10.0468 0x187c  [ E9981ECE8D894CEF7038FD1D040EB426, DCDDCE933CAECE8180A3447199B07F2F0413704EEC1A09606EE357901A84A7CF ] TsUsbFlt        C:\windows\system32\drivers\tsusbflt.sys
21:20:10.0528 0x187c  TsUsbFlt - ok
21:20:10.0568 0x187c  [ AD64450A4ABE076F5CB34CC08EEACB07, B5C386635441A19178E7FEEE299BA430C8D72F9110866C13A216B12A1080AD12 ] TsUsbGD        C:\windows\system32\drivers\TsUsbGD.sys
21:20:10.0618 0x187c  TsUsbGD - ok
21:20:10.0668 0x187c  [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel          C:\windows\system32\DRIVERS\tunnel.sys
21:20:10.0738 0x187c  tunnel - ok
21:20:10.0778 0x187c  [ 42350E49DA754D2D77362FDAE3491651, F29E8BA444ECB0484066B02C0A3DCE09B8417159EE37D7A2E05D4C06A98449C4 ] TurboB          C:\windows\system32\DRIVERS\TurboB.sys
21:20:10.0788 0x187c  TurboB - ok
21:20:10.0858 0x187c  [ 4F4B0AB2FB69C414CCBCEF7CF2E1C8D8, E1F197554369C97DBF61389346B4CB0233F40AAA2575F5D2FEC809AC9123FC69 ] TurboBoost      C:\Program Files\Intel\TurboBoost\TurboBoost.exe
21:20:10.0878 0x187c  TurboBoost - ok
21:20:10.0898 0x187c  [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35          C:\windows\system32\drivers\uagp35.sys
21:20:10.0908 0x187c  uagp35 - ok
21:20:10.0918 0x187c  [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs            C:\windows\system32\DRIVERS\udfs.sys
21:20:10.0958 0x187c  udfs - ok
21:20:10.0988 0x187c  [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect      C:\windows\system32\UI0Detect.exe
21:20:11.0018 0x187c  UI0Detect - ok
21:20:11.0038 0x187c  [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx        C:\windows\system32\drivers\uliagpkx.sys
21:20:11.0056 0x187c  uliagpkx - ok
21:20:11.0083 0x187c  [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus          C:\windows\system32\DRIVERS\umbus.sys
21:20:11.0112 0x187c  umbus - ok
21:20:11.0127 0x187c  [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass          C:\windows\system32\drivers\umpass.sys
21:20:11.0153 0x187c  UmPass - ok
21:20:11.0191 0x187c  [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost        C:\windows\System32\upnphost.dll
21:20:11.0250 0x187c  upnphost - ok
21:20:11.0284 0x187c  [ 28B81917A195B67617AF7DCF4DFE5736, 40A4D2AAE1BDE5ABA8708ED150396E913C566ECD5CDA40D6C6DB256F1B9FD4A9 ] usbccgp        C:\windows\system32\DRIVERS\usbccgp.sys
21:20:11.0332 0x187c  usbccgp - ok
21:20:11.0362 0x187c  [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir          C:\windows\system32\drivers\usbcir.sys
21:20:11.0412 0x187c  usbcir - ok
21:20:11.0462 0x187c  [ B626F048318DAE65A3317F0592BE592C, 284D8FFE1D35F852EFDA182A72288AC3A10D6ED825FE2CC5812497D3FE291AF1 ] usbehci        C:\windows\system32\drivers\usbehci.sys
21:20:11.0542 0x187c  usbehci - ok
21:20:11.0582 0x187c  [ 390109E8E05BA00375DCB1ED64DC60AF, B8628502590B423BEFB6F7C8C69FAD0667AD0746FF6B444EE02016E8E1052B78 ] usbhub          C:\windows\system32\drivers\usbhub.sys
21:20:11.0632 0x187c  usbhub - ok
21:20:11.0652 0x187c  [ B4DF0F4C1D9D25DFE1DAD1D8670F1D4F, 4317C2DEDC639527B53864BAEC46CBE022D298C0503E29E1072DD1C851D92BFC ] usbohci        C:\windows\system32\drivers\usbohci.sys
21:20:11.0672 0x187c  usbohci - ok
21:20:11.0692 0x187c  [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint        C:\windows\system32\DRIVERS\usbprint.sys
21:20:11.0722 0x187c  usbprint - ok
21:20:11.0762 0x187c  [ 9661DA76B4531B2DA272ECCE25A8AF24, FEA93254A21E71A7EB8AD35FCCAD2C1E41F7329EC33B1734F5B41307A34D8637 ] usbscan        C:\windows\system32\DRIVERS\usbscan.sys
21:20:11.0812 0x187c  usbscan - ok
21:20:11.0842 0x187c  [ D029DD09E22EB24318A8FC3D8138BA43, C95805E8BF75ECB939520AE86420B16467B0771C161C51C9F1A37649ADFADCD0 ] USBSTOR        C:\windows\system32\drivers\USBSTOR.SYS
21:20:11.0892 0x187c  USBSTOR - ok
21:20:11.0952 0x187c  [ CFEAAF96E666E3DCBD8F6DFF516784AE, 006218A3DB5851790CC0A7F3DCD7B3AF82F624DA679296DE507AFD36C5468317 ] usbuhci        C:\windows\system32\drivers\usbuhci.sys
21:20:11.0982 0x187c  usbuhci - ok
21:20:12.0022 0x187c  [ 1F775DA4CF1A3A1834207E975A72E9D7, 6D3DE5BD3EF3A76E997E5BAF900C51D25308F5A9682D1F62017F577A24095B90 ] usbvideo        C:\windows\system32\Drivers\usbvideo.sys
21:20:12.0052 0x187c  usbvideo - ok
21:20:12.0092 0x187c  [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms          C:\windows\System32\uxsms.dll
21:20:12.0152 0x187c  UxSms - ok
21:20:12.0172 0x187c  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] VaultSvc        C:\windows\system32\lsass.exe
21:20:12.0202 0x187c  VaultSvc - ok
21:20:12.0242 0x187c  [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot        C:\windows\system32\drivers\vdrvroot.sys
21:20:12.0252 0x187c  vdrvroot - ok
21:20:12.0272 0x187c  [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds            C:\windows\System32\vds.exe
21:20:12.0332 0x187c  vds - ok
21:20:12.0352 0x187c  [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga            C:\windows\system32\DRIVERS\vgapnp.sys
21:20:12.0372 0x187c  vga - ok
21:20:12.0402 0x187c  [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave        C:\windows\System32\drivers\vga.sys
21:20:12.0442 0x187c  VgaSave - ok
21:20:12.0452 0x187c  [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp          C:\windows\system32\drivers\vhdmp.sys
21:20:12.0462 0x187c  vhdmp - ok
21:20:12.0492 0x187c  [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide          C:\windows\system32\drivers\viaide.sys
21:20:12.0512 0x187c  viaide - ok
21:20:12.0522 0x187c  [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr          C:\windows\system32\drivers\volmgr.sys
21:20:12.0532 0x187c  volmgr - ok
21:20:12.0552 0x187c  [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx        C:\windows\system32\drivers\volmgrx.sys
21:20:12.0572 0x187c  volmgrx - ok
21:20:12.0602 0x187c  [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap        C:\windows\system32\drivers\volsnap.sys
21:20:12.0622 0x187c  volsnap - ok
21:20:12.0642 0x187c  [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid        C:\windows\system32\drivers\vsmraid.sys
21:20:12.0662 0x187c  vsmraid - ok
21:20:12.0712 0x187c  [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS            C:\windows\system32\vssvc.exe
21:20:12.0782 0x187c  VSS - ok
21:20:12.0812 0x187c  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus        C:\windows\system32\DRIVERS\vwifibus.sys
21:20:12.0862 0x187c  vwifibus - ok
21:20:12.0904 0x187c  [ 6A3D66263414FF0D6FA754C646612F3F, 30F6BA594B0D3B94113064015A16D97811CD989DF1715CCE21CEAB9894C1B4FB ] vwififlt        C:\windows\system32\DRIVERS\vwififlt.sys
21:20:12.0944 0x187c  vwififlt - ok
21:20:12.0974 0x187c  [ 6A638FC4BFDDC4D9B186C28C91BD1A01, 5521F1DC515586777EC4837E0AEAA3E613CC178AF1074031C4D0D0C695A93168 ] vwifimp        C:\windows\system32\DRIVERS\vwifimp.sys
21:20:12.0994 0x187c  vwifimp - ok
21:20:13.0014 0x187c  [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time        C:\windows\system32\w32time.dll
21:20:13.0075 0x187c  W32Time - ok
21:20:13.0155 0x187c  [ B32009DB1972E7F2C227499289C4384A, D491CD90ACE895EC60A5A2F995EAE39F8ED662B71BC548C3FF5BBDBC60054788 ] W3SVC          C:\windows\system32\inetsrv\iisw3adm.dll
21:20:13.0188 0x187c  W3SVC - ok
21:20:13.0214 0x187c  [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen        C:\windows\system32\drivers\wacompen.sys
21:20:13.0241 0x187c  WacomPen - ok
21:20:13.0264 0x187c  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP          C:\windows\system32\DRIVERS\wanarp.sys
21:20:13.0298 0x187c  WANARP - ok
21:20:13.0317 0x187c  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6        C:\windows\system32\DRIVERS\wanarp.sys
21:20:13.0347 0x187c  Wanarpv6 - ok
21:20:13.0397 0x187c  [ B32009DB1972E7F2C227499289C4384A, D491CD90ACE895EC60A5A2F995EAE39F8ED662B71BC548C3FF5BBDBC60054788 ] WAS            C:\windows\system32\inetsrv\iisw3adm.dll
21:20:13.0417 0x187c  WAS - ok
21:20:13.0477 0x187c  [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine        C:\windows\system32\wbengine.exe
21:20:13.0537 0x187c  wbengine - ok
21:20:13.0547 0x187c  [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc        C:\windows\System32\wbiosrvc.dll
21:20:13.0567 0x187c  WbioSrvc - ok
21:20:13.0607 0x187c  [ 8BDA6DB43AA54E8BB5E0794541DDC209, 8753C507BE77B019A3403AF5252434A01DB9F9332E58AC3783ABCE3D21AD9DD4 ] WcesComm        C:\windows\WindowsMobile\wcescomm.dll
21:20:13.0627 0x187c  WcesComm - ok
21:20:13.0657 0x187c  [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc        C:\windows\System32\wcncsvc.dll
21:20:13.0687 0x187c  wcncsvc - ok
21:20:13.0697 0x187c  [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
21:20:13.0737 0x187c  WcsPlugInService - ok
21:20:13.0767 0x187c  [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd              C:\windows\system32\drivers\wd.sys
21:20:13.0777 0x187c  Wd - ok
21:20:13.0827 0x187c  [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000        C:\windows\system32\drivers\Wdf01000.sys
21:20:13.0857 0x187c  Wdf01000 - ok
21:20:13.0897 0x187c  [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiServiceHost  C:\windows\system32\wdi.dll
21:20:13.0927 0x187c  WdiServiceHost - ok
21:20:13.0947 0x187c  [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiSystemHost  C:\windows\system32\wdi.dll
21:20:13.0967 0x187c  WdiSystemHost - ok
21:20:13.0997 0x187c  [ EE841B6D1F2B9508D3ABAE52AC05A94F, F1AE981FCDBFC4672A4EABABD41382E93762EFC2EDAD96E75530E7ACA5AF1FD8 ] WebClient      C:\windows\System32\webclnt.dll
21:20:14.0027 0x187c  WebClient - ok
21:20:14.0062 0x187c  [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc          C:\windows\system32\wecsvc.dll
21:20:14.0102 0x187c  Wecsvc - ok
21:20:14.0114 0x187c  [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport  C:\windows\System32\wercplsupport.dll
21:20:14.0174 0x187c  wercplsupport - ok
21:20:14.0194 0x187c  [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc          C:\windows\System32\WerSvc.dll
21:20:14.0233 0x187c  WerSvc - ok
21:20:14.0255 0x187c  [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf          C:\windows\system32\DRIVERS\wfplwf.sys
21:20:14.0288 0x187c  WfpLwf - ok
21:20:14.0307 0x187c  [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount        C:\windows\system32\drivers\wimmount.sys
21:20:14.0317 0x187c  WIMMount - ok
21:20:14.0347 0x187c  WinDefend - ok
21:20:14.0347 0x187c  WinHttpAutoProxySvc - ok
21:20:14.0417 0x187c  [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt        C:\windows\system32\wbem\WMIsvc.dll
21:20:14.0487 0x187c  Winmgmt - ok
21:20:14.0567 0x187c  [ EBDA1B0F15CB9B2CBCC6C94824E4E054, C51314F7D611E4903DA00EFA8EB99365414436324D256083CE0B5A8E055E8E06 ] WinRM          C:\windows\system32\WsmSvc.dll
21:20:14.0647 0x187c  WinRM - ok
21:20:14.0697 0x187c  [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb          C:\windows\system32\DRIVERS\WinUsb.sys
21:20:14.0737 0x187c  WinUsb - ok
21:20:14.0777 0x187c  [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc        C:\windows\System32\wlansvc.dll
21:20:14.0817 0x187c  Wlansvc - ok
21:20:14.0937 0x187c  [ 357CABBF155AFD1D3926E62539D2A3A7, C43CFF84E7D930B4999DC061AB0766B57AAD7540B3E6EE54605B10ECE90825F5 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
21:20:14.0987 0x187c  wlidsvc - ok
21:20:15.0043 0x187c  [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi        C:\windows\system32\drivers\wmiacpi.sys
21:20:15.0076 0x187c  WmiAcpi - ok
21:20:15.0113 0x187c  [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv        C:\windows\system32\wbem\WmiApSrv.exe
21:20:15.0149 0x187c  wmiApSrv - ok
21:20:15.0169 0x187c  WMPNetworkSvc - ok
21:20:15.0185 0x187c  [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc          C:\windows\System32\wpcsvc.dll
21:20:15.0224 0x187c  WPCSvc - ok
21:20:15.0240 0x187c  [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum      C:\windows\system32\wpdbusenum.dll
21:20:15.0272 0x187c  WPDBusEnum - ok
21:20:15.0301 0x187c  [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl        C:\windows\system32\drivers\ws2ifsl.sys
21:20:15.0328 0x187c  ws2ifsl - ok
21:20:15.0348 0x187c  [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc          C:\windows\System32\wscsvc.dll
21:20:15.0408 0x187c  wscsvc - ok
21:20:15.0418 0x187c  WSearch - ok
21:20:15.0568 0x187c  [ 31F32E0C1A8BA9A37EEC23DE5F27F847, 0180832BC6172C9A4C32B5B222BB3F91EA615A5EBDA98DB79ED4FED258C2D257 ] wuauserv        C:\windows\system32\wuaueng.dll
21:20:15.0688 0x187c  wuauserv - ok
21:20:15.0718 0x187c  [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf          C:\windows\system32\drivers\WudfPf.sys
21:20:15.0758 0x187c  WudfPf - ok
21:20:15.0808 0x187c  [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd          C:\windows\system32\DRIVERS\WUDFRd.sys
21:20:15.0868 0x187c  WUDFRd - ok
21:20:15.0888 0x187c  [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc        C:\windows\System32\WUDFSvc.dll
21:20:15.0938 0x187c  wudfsvc - ok
21:20:15.0968 0x187c  [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc        C:\windows\System32\wwansvc.dll
21:20:16.0018 0x187c  WwanSvc - ok
21:20:16.0051 0x187c  ================ Scan global ===============================
21:20:16.0103 0x187c  [ 168EA9CD9BD6056BB6F60B57D5304BBE, 5A2F98754F042A7D80E7483842967EB362F01D57CE9720B24C7EDAA047F24C6F ] C:\windows\system32\basesrv.dll
21:20:16.0128 0x187c  [ 93E5D2B763374F484918A0909724B3EB, 900F1CCAEFCF77AB678C74D542ABDDA7134CD33D7811537E2829FC69E99F2B3E ] C:\windows\system32\winsrv.dll
21:20:16.0149 0x187c  [ 93E5D2B763374F484918A0909724B3EB, 900F1CCAEFCF77AB678C74D542ABDDA7134CD33D7811537E2829FC69E99F2B3E ] C:\windows\system32\winsrv.dll
21:20:16.0187 0x187c  [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\windows\system32\sxssrv.dll
21:20:16.0211 0x187c  [ 71C85477DF9347FE8E7BC55768473FCA, A86D6A6D1F5A0EFCD649792A06F3AE9B37158D48493D2ECA7F52DCC1CB9B6536 ] C:\windows\system32\services.exe
21:20:16.0218 0x187c  [ Global ] - ok
21:20:16.0218 0x187c  ================ Scan MBR ==================================
21:20:16.0233 0x187c  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
21:20:16.0650 0x187c  \Device\Harddisk0\DR0 - ok
21:20:16.0652 0x187c  ================ Scan VBR ==================================
21:20:16.0655 0x187c  [ 0705F560CF61D5EE61FCE46DC97D99F9 ] \Device\Harddisk0\DR0\Partition1
21:20:16.0658 0x187c  \Device\Harddisk0\DR0\Partition1 - ok
21:20:16.0663 0x187c  [ 89E86E8C7CA58358959D25AD32A5A90E ] \Device\Harddisk0\DR0\Partition2
21:20:16.0666 0x187c  \Device\Harddisk0\DR0\Partition2 - ok
21:20:16.0667 0x187c  ================ Scan generic autorun ======================
21:20:17.0095 0x187c  [ E05849E5D0E51EB52080E7D2987B9D3B, E68E43CF0FFD69C193C5B692A019CE13D3FB58197E5827720B3ACDDE0812AAFA ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
21:20:17.0410 0x187c  RTHDVCPL - ok
21:20:17.0490 0x187c  [ 8B87D9E466055B958EE24270BF187512, 7A1994398C5A2CEB7738006F375C12E5AAC9142786783189E7C57AB8E1E75F3C ] C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe
21:20:17.0530 0x187c  BtServer - detected UnsignedFile.Multi.Generic ( 1 )
21:20:17.0940 0x187c  Detect skipped due to KSN trusted
21:20:17.0940 0x187c  BtServer - ok
21:20:18.0100 0x187c  [ 0A892ED5ECB5C821DE71EF523DC71C78, 47F54D1148C615BE2E4F3355F5392B530A843736E7B9DFB888871F24B6E355CA ] C:\Program Files\Elantech\ETDCtrl.exe
21:20:18.0180 0x187c  ETDCtrl - ok
21:20:18.0237 0x187c  [ 815F6E3727453C978FFD721B2BDF48A5, E33A85E8EF80C662C84F705080585B35A899F8E588E8481D48538BA1224B5E57 ] C:\Program Files (x86)\SCM\Radio Manager.exe
21:20:18.0253 0x187c  Radio Manager - detected UnsignedFile.Multi.Generic ( 1 )
21:20:18.0596 0x187c  Detect skipped due to KSN trusted
21:20:18.0596 0x187c  Radio Manager - ok
21:20:18.0666 0x187c  [ 679119AAB80584EA5646B53F4779F86E, 57BE842AF59544ABE7E8F6AF2E0E106E7F7C681A2923BD156403F6E8335BAD5D ] C:\Program Files (x86)\SCM\SCM.exe
21:20:18.0716 0x187c  SCM - detected UnsignedFile.Multi.Generic ( 1 )
21:20:19.0263 0x187c  Detect skipped due to KSN trusted
21:20:19.0263 0x187c  SCM - ok
21:20:19.0265 0x187c  IntelTBRunOnce - ok
21:20:19.0300 0x187c  [ 2E48CB664239B71FA40D9583FCB39860, EAFF430D91AD30AEF9D9FA6E7F3CB6217C6ACD519F1EE31351506445EED15D9C ] C:\windows\system32\igfxtray.exe
21:20:19.0316 0x187c  IgfxTray - ok
21:20:19.0343 0x187c  [ A491FFC9A3E69336AA5D4A065B42C8F8, 7DE6E7FD751C40B6CD1D059CC086307E0D11620642A36805C56C0F451E4412CD ] C:\windows\system32\hkcmd.exe
21:20:19.0363 0x187c  HotKeysCmds - ok
21:20:19.0383 0x187c  [ FF6659185BD54E9E5DE619CA1C2CD5B2, 0573634F7F69A41E0CAFCEDA8203DA26726BF77CBD6FD9FB9258D78691629E30 ] C:\windows\system32\igfxpers.exe
21:20:19.0403 0x187c  Persistence - ok
21:20:19.0453 0x187c  [ 233A10D4B3F6897899112E4EC60F1906, 1F7E768E57064938114DF2EFC5B219EB0D30A7D9E574924E9CED054462505AF0 ] C:\windows\WindowsMobile\wmdcBase.exe
21:20:19.0473 0x187c  Windows Mobile-based device management - ok
21:20:19.0683 0x187c  [ 666FEA598D1776C7F8EDD7746F0F7F59, 54E330BCDBAB646B555DACC15F9CFB0AD6A05BF4E273F73C5133259EEE976C21 ] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe
21:20:19.0743 0x187c  Malwarebytes TrayApp - ok
21:20:19.0783 0x187c  [ B00F98FF6FE8682FF941BEB2559BF191, EB443E294C5609F426BF6EE388F3A4B71EFE2C6A8216C0F6DE7AE6DB382BF620 ] C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
21:20:19.0813 0x187c  YouCam Mirage - ok
21:20:19.0843 0x187c  [ 15A69FE13459EF81FB2105CC986AF394, 2078EAFEA0F00D155EDE6DA40BFBE6E8347DB19078FBD52DFA2122FB439BD9E9 ] C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe
21:20:19.0853 0x187c  YouCam Tray - ok
21:20:19.0933 0x187c  [ 27B3D4706E8EBC4B870F1D177EBC54B2, 34CD55E4BA687E38BD88B36A25B187DFF591F2D747ADD4D9BD22C071B48468F0 ] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
21:20:19.0983 0x187c  Super-Charger - ok
21:20:20.0037 0x187c  [ 2B282A4050FE3B4B70EF9E3070BBFF78, 019B667781F5CE411AEB569EAA4095FA2B9942E43A6A1DFC6EEBB2DA214131FE ] C:\Program Files (x86)\FreePDF_XP\fpassist.exe
21:20:20.0068 0x187c  FreePDF Assistant - detected UnsignedFile.Multi.Generic ( 1 )
21:20:20.0447 0x187c  Detect skipped due to KSN trusted
21:20:20.0447 0x187c  FreePDF Assistant - ok
21:20:20.0617 0x187c  [ AF905BC023A0018F7325FD4B0019B5C0, 9F65DE0C3D8B90295B70528ADD2411CC1771AC089B70ABEC426D6F2D5D7A104A ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
21:20:20.0647 0x187c  APSDaemon - ok
21:20:20.0737 0x187c  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
21:20:20.0797 0x187c  Sidebar - ok
21:20:20.0827 0x187c  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
21:20:20.0857 0x187c  mctadmin - ok
21:20:20.0907 0x187c  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
21:20:20.0947 0x187c  Sidebar - ok
21:20:20.0947 0x187c  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
21:20:20.0967 0x187c  mctadmin - ok
21:20:21.0017 0x187c  [ B88EC3510D74D3E7C2F7E68610DA8C45, 09A5715B65A19F7447C247484E1D5B096434EA9EC03689E48F781B6F33C0B858 ] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
21:20:21.0057 0x187c  Web Companion - ok
21:20:21.0092 0x187c  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
21:20:21.0131 0x187c  Sidebar - ok
21:20:21.0137 0x187c  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
21:20:21.0158 0x187c  mctadmin - ok
21:20:21.0161 0x187c  Waiting for KSN requests completion. In queue: 124
21:20:22.0163 0x187c  Waiting for KSN requests completion. In queue: 124
21:20:23.0215 0x187c  AV detected via SS2: Malwarebytes, C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe ( 3.0.0.134 ), 0x61000 ( enabled : updated )
21:20:23.0222 0x187c  Win FW state via NFP2: enabled ( trusted )
21:20:23.0390 0x187c  ============================================================
21:20:23.0390 0x187c  Scan finished
21:20:23.0390 0x187c  ============================================================
21:20:23.0400 0x1090  Detected object count: 0
21:20:23.0400 0x1090  Actual detected object count: 0


cosinus 13.01.2017 22:03

Adware/Junkware/Toolbars entfernen

Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!
Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren!


1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


milkit54 14.01.2017 20:04

Hallo Cosinus,
vorab erstmal Entschuldigung. Ich mußte unterbrechen. Hoffe jedoch das trotzdem etwas brauchbares herausgekoomen ist. Leider geht die Maus nicht, so daß ich über touchpad arbeiten mußte, und mir war nicht klar wie ich die Schutzsoftware beenden soll/kann sorry.

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.0 (12.05.2016)
Operating System: Windows 7 Home Premium x64
Ran by Micha (Administrator) on 14.01.2017 at 18:26:46,08
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 2

Failed to delete: C:\ProgramData\lavasoft\web companion (Folder)
Failed to delete: C:\Program Files (x86)\lavasoft\web companion (Folder)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14.01.2017 at 18:30:06,19
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Code:

# AdwCleaner v6.042 - Bericht erstellt am 14/01/2017 um 19:16:29
# Aktualisiert am 06/01/2017 von Malwarebytes
# Datenbank : 2017-01-11.1 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (X64)
# Benutzername : Micha - MICHA-MSI
# Gestartet von : C:\Users\Micha\Desktop\AdwCleaner_6.042.exe
# Modus: Suchlauf
# Unterstützung : https://www.malwarebytes.com/support



***** [ Dienste ] *****

Dienst Gefunden: swdumon
Dienst Gefunden: LavasoftTcpService
Dienst Gefunden: SearchProtectionService


***** [ Ordner ] *****

Ordner Gefunden: C:\ProgramData\Avg_Update_0215tb
Ordner Gefunden: C:\ProgramData\Avg_Update_1215tb
Ordner Gefunden: C:\windows\Installer\{A9888F42-BFFE-4ACA-AC10-51983972C2DF}
Ordner Gefunden: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\extensions\_dqMembers_@www.downspeedtest.com
Ordner Gefunden: C:\Users\Micha\AppData\LocalLow\pandasecuritytb
Ordner Gefunden: C:\Users\Micha\AppData\Roaming\RHEng
Ordner Gefunden: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\DownSpeedTest_dq
Ordner Gefunden: C:\ProgramData\lavasoft\web companion
Ordner Gefunden: C:\ProgramData\Application Data\lavasoft\web companion
Ordner Gefunden: C:\Program Files (x86)\lavasoft\web companion
Ordner Gefunden: C:\Program Files (x86)\pandasecuritytb
Ordner Gefunden: C:\windows\SysWOW64\config\systemprofile\AppData\LocalLow\avg web tuneup
Ordner Gefunden: C:\windows\SysWOW64\config\systemprofile\AppData\LocalLow\pandasecuritytb


***** [ Dateien ] *****

Datei Gefunden: C:\windows\SysNative\LavasoftTcpService64.dll
Datei Gefunden: C:\windows\SysNative\LavasoftTcpServiceOff.ini
Datei Gefunden: C:\windows\SysWOW64\lavasofttcpservice.dll
Datei Gefunden: C:\windows\SysWOW64\LavasoftTcpServiceOff.ini
Datei Gefunden: C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
Datei Gefunden: C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
Datei Gefunden: C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
Datei Gefunden: C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage
Datei Gefunden: C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage-journal


***** [ DLL ] *****

Keine infizierten DLLs gefunden.


***** [ WMI ] *****

Keine schädlichen Schlüssel gefunden.


***** [ Verknüpfungen ] *****

Keine infizierten Verknüpfungen gefunden.


***** [ Aufgabenplanung ] *****

Keine schädlichen Aufgaben gefunden.


***** [ Registrierungsdatenbank ] *****

Schlüssel Gefunden: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A9888F42-BFFE-4ACA-AC10-51983972C2DF}
Schlüssel Gefunden: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A9888F42-BFFE-4ACA-AC10-51983972C2DF}_is1
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer.1
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController.1
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable.1
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields.1
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder.1
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic.1
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager.1
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController.1
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer.1
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController.1
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable.1
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields.1
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder.1
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic.1
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager.1
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController.1
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\CLSID\{0015CAC9-FC30-4CD0-BFAA-7412CC2C4DD9}
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\CLSID\{26C7AFDB-3690-449E-B979-B0AF5CC56DD4}
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\CLSID\{3A5A5381-DAAF-4C0D-B032-2C66B3EE4A8D}
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\CLSID\{472EF1D2-4AAE-470D-AE85-6AF8177916FD}
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\CLSID\{8F010D54-C023-457F-AF03-497EACB6D519}
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\CLSID\{9A754403-27B1-4ED7-96D7-588F07888EBF}
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\CLSID\{FCAA532B-E807-4027-940C-BA16B9D50105}
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\TypeLib\{ED62BC6E-64F1-46BE-866F-4C8DC0DF7057}
Schlüssel Gefunden: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Schlüssel Gefunden: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Schlüssel Gefunden: HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Software\Ciuvo
Schlüssel Gefunden: HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Software\SlimWare Utilities Inc
Schlüssel Gefunden: HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Software\AppDataLow\Software\adawarebp
Schlüssel Gefunden: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2198626584-3468660724-23365673-1000\Software\Ciuvo
Schlüssel Gefunden: HKCU\Software\Ciuvo
Schlüssel Gefunden: HKCU\Software\SlimWare Utilities Inc
Schlüssel Gefunden: HKCU\Software\AppDataLow\Software\adawarebp
Schlüssel Gefunden: HKLM\SOFTWARE\SLIMWARE UTILITIES, INC.
Schlüssel Gefunden: HKLM\SOFTWARE\SlimWare Utilities Inc
Schlüssel Gefunden: HKLM\SOFTWARE\Lavasoft\Web Companion
Schlüssel Gefunden: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2198626584-3468660724-23365673-1000\Software\Ciuvo
Schlüssel Gefunden: [x64] HKCU\Software\Ciuvo
Schlüssel Gefunden: [x64] HKCU\Software\SlimWare Utilities Inc
Schlüssel Gefunden: [x64] HKCU\Software\AppDataLow\Software\adawarebp
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\SLIMWARE UTILITIES, INC.
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Reimage
Schlüssel Gefunden: HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\50D2BAFD096C90345A82B25A790BDF69
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\50D2BAFD096C90345A82B25A790BDF69
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\50D2BAFD096C90345A82B25A790BDF69
Schlüssel Gefunden: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
Schlüssel Gefunden: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
Schlüssel Gefunden: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mysearch.avg.com
Schlüssel Gefunden: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
Schlüssel Gefunden: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
Schlüssel Gefunden: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mysearch.avg.com
Wert Gefunden: HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Software\Microsoft\Windows\CurrentVersion\Run [Web Companion]
Wert Gefunden: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Web Companion]
Wert Gefunden: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Web Companion]


***** [ Internetbrowser ] *****

Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "browser.startup.homepage" -  "hxxp://hp.myway.com/downspeedtest/ttab02/index.html?coId=db9de8384d804
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.BUTTON_STRUCTURE" -  "[{\"b\":224180039,\"c\":\"mindspark.m
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.browser.startup.homepage.prev" -  "hxxp://www.n-tv.de"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.browser.startup.homepage.savedPrev" -  "true"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.browser.startup.homepage.tb" -  "hxxp://hp.myway.com/downsp
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.browser.startup.page.savedPrev" -  1
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.browser.startup.page.tb" -  1
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.browser.version.last" -  "50.0"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.coId" -  "db9de8384d8040ac93524301c1b30367"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.firstKnownVersion" -  "7.102.10.3827"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.homepage" -  "hxxp://hp.myway.com/downspeedtest/ttab02/inde
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.hp.enabled" -  true
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.hp.guardType" -  "HPR"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.hp.user.defined" -  false
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.initialized" -  true
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.installType" -  "XPI"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.installation.dlpCountryCode" -  "DE"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.installation.installDate" -  "2017010903"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.installation.partnerId" -  "^BXM^xdm001^TTAB02^de"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.installation.pixelUrl" -  "hxxp://www.downspeedtest.com/ins
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.installation.success" -  true
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.installation.toolbarId" -  "4E16B681-6380-4409-98AE-5BA6F85
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.lastActivePing" -  "1484403901982"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.lastKnownVersion" -  "7.102.10.3827"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.lssState" -  "{\"previousLocales\":[\"de\",\"en-US\",\"en\"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.options.defaultSearch" -  false
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.options.homePageEnabled" -  true
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.options.keywordEnabled" -  false
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.options.tabEnabled" -  true
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.partnerPixelFired" -  true
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.productDeliveryOption.language" -  "de"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.productDeliveryOption.newTabURL" -  "hxxp://hp.myway.com/do
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.productDeliveryOption.type" -  "ToolTab"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.successUrl" -  "hxxp://www.downspeedtest.com/installComplet
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.toolbarCollapsed" -  true
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.uninstallSurveyUrl" -  "hxxp://www.research.net/r/HYSCVNM?C
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark._dqMembers_.uninstallTasks" -  "{\"prefBranchesToDelete\":[\"extensions
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark.hp.enabled" -  true
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark.hp.enabled.guid" -  "downspeedtest@mindspark.com"
Firefox pref Gefunden: [C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\prefs.js] - "extensions.toolbar.mindspark.lastInstalled" -  "downspeedtest@mindspark.com"
Chrome pref Gefunden: [C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - bopakagnckmlgajfccecajhnimjiiedh

*************************

C:\AdwCleaner\AdwCleaner[S0].txt - [17914 Bytes] - [14/01/2017 19:16:29]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [17988 Bytes] ##########


cosinus 14.01.2017 21:47

In dienem Fall musst du garnix beenden. Aber Anleitung richtig lesen, denn die Funde mit dem AdwCleaner müssen gelöscht werden.

milkit54 15.01.2017 09:31

guten Morgen Cosinus,
habe ich gelöscht,heute morgen beim Neustart ist der Computer weiterhin als Problem "Treiberprobleme bei Microsoft Tunneling Adapter" in der Sytemsteuerung, die automatische Geräterkenung geht nicht ebenso Maus

cosinus 15.01.2017 11:49

Naja, adwCleane rbehebt auch keine Treiberprobleme. Dein Treiberproblem ist was völlig anderes als der Adwarebefall.

Log vom adwCleaner nach dem Löschen fehlt.

milkit54 15.01.2017 12:16

Code:

AdwCleaner v6.042 - Bericht erstellt am 14/01/2017 um 22:20:53
# Aktualisiert am 06/01/2017 von Malwarebytes
# Datenbank : 2017-01-11.1 [Lokal]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (X64)
# Benutzername : Micha - MICHA-MSI
# Gestartet von : C:\Users\Micha\Desktop\AdwCleaner_6.042.exe
# Modus: Suchlauf
# Unterstützung : https://www.malwarebytes.com/support



***** [ Dienste ] *****

Keine schädlichen Dienste gefunden.


***** [ Ordner ] *****

Keine schädlichen Ordner gefunden.


***** [ Dateien ] *****

Keine schädlichen Dateien gefunden.


***** [ DLL ] *****

Keine infizierten DLLs gefunden.


***** [ WMI ] *****

Keine schädlichen Schlüssel gefunden.


***** [ Verknüpfungen ] *****

Keine infizierten Verknüpfungen gefunden.


***** [ Aufgabenplanung ] *****

Keine schädlichen Aufgaben gefunden.


***** [ Registrierungsdatenbank ] *****

Keine schädlichen Elemente in der Registrierungsdatenbank gefunden.


***** [ Internetbrowser ] *****

Keine schädlichen Elemente in Firefox basierten Browsern gefunden.
Keine schädlichen Elemente in Chrome basierten Browsern gefunden.

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [19428 Bytes] - [14/01/2017 22:05:12]
C:\AdwCleaner\AdwCleaner[C2].txt - [1531 Bytes] - [14/01/2017 22:14:16]
C:\AdwCleaner\AdwCleaner[S0].txt - [18180 Bytes] - [14/01/2017 19:16:29]
C:\AdwCleaner\AdwCleaner[S1].txt - [18253 Bytes] - [14/01/2017 22:03:06]
C:\AdwCleaner\AdwCleaner[S2].txt - [1607 Bytes] - [14/01/2017 22:13:28]
C:\AdwCleaner\AdwCleaner[S3].txt - [1576 Bytes] - [14/01/2017 22:20:53]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1649 Bytes] ##########


cosinus 15.01.2017 12:25

eigentlich meinte ich das Löschlog aber egal :kaffee:

Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Untersuchen klicken

http://www.trojaner-board.de/picture...&pictureid=611

milkit54 15.01.2017 17:48

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-01-2017
durchgeführt von Micha (Administrator) auf MICHA-MSI (15-01-2017 14:43:02)
Gestartet von C:\Users\Micha\Downloads
Geladene Profile: Micha (Verfügbare Profile: Micha & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\AvrcpService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Microsoft Corporation) C:\Windows\System32\CISVC.EXE
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(MSI) C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe
(Visicom Media Inc.) C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe
(PLUMBYTES) C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\AmwService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\ws.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\creator-ws.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\RtkBleServ.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Symantec Corporation) C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\SkypePlugin.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(MSI) C:\Program Files (x86)\SCM\Radio Manager.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(© 2015 Microsoft Corporation) C:\Users\Micha\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\SymcPCCULaunchSvc.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_24_0_0_194.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_24_0_0_194.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe

==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13538376 2013-05-21] (Realtek Semiconductor)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [253440 2013-04-23] (Realtek Semiconductor Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2875728 2013-03-04] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2013-07-05] (MSI)
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [399528 2013-07-05] (MSI)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [Windows Mobile-based device management] => C:\windows\WindowsMobile\wmdcBase.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-10-13] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [230696 2011-10-13] (CyberLink Corp.)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [490480 2013-02-01] (MSI)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2014-03-18] (shbox.de)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-10-05] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series (Kopie 1)] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series (Kopie 2)] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-10-05] (Apple Inc.)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [BingSvc] => C:\Users\Micha\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27230168 2016-11-15] (Skype Technologies S.A.)
HKU\S-1-5-18\...\Run: [EPSON SX100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-18\...\RunOnce: [panda] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f
HKU\S-1-5-18\...\RunOnce: [panda_XP] => reg.exe delete "HKCU\Software\panda" /f
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Keine Datei
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop(777).ini [2009-07-14] ()
Startup: C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.6.lnk [2013-07-31]
ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.6.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2
Tcpip\..\Interfaces\{19590355-955C-4F75-9574-A5178867FB8F}: [DhcpNameServer] 192.168.0.1 192.168.0.2
Tcpip\..\Interfaces\{7AFF0EF0-F8B5-4E22-BED7-5BAC51243C58}: [NameServer] 193.189.244.206 193.189.244.225

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.n-tv.de/
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {2BA0719B-B10C-4176-8BB1-AF2B6E7453E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAM3&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {2BA0719B-B10C-4176-8BB1-AF2B6E7453E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAM3&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO-x32: PDF Architect Helper -> {691B33B0-B86E-47F3-81C7-56E4FE3B929C} -> C:\Program Files (x86)\PDF Architect 2\creator-ie-helper.dll [2014-10-10] (pdfforge GmbH)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
Toolbar: HKLM-x32 - Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - C:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH)

FireFox:
========
FF ProfilePath: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 [2017-01-15]
FF NewTab: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> hxxp://www.n-tv.de/
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> Google
FF Homepage: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> hxxp://www.n-tv.de/
FF Extension: (Test Pilot) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\@testpilot-addon.xpi [2017-01-11]
FF Extension: (GMX MailCheck) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\browser-mailcheck@gmx.net [2016-11-23]
FF Extension: (Awesome Screenshot - Capture, Annotate & More) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2017-01-10]
FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: (PDF Architect 2 Creator) - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2015-01-20] [ist nicht signiert]
FF HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\jsjjbqd4.default\extensions\cliqz@cliqz.com => nicht gefunden
FF HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: (McAfee Security Scan Plus) - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] [ist nicht signiert]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\pandasecuritytb.xml [2015-05-27]
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-10] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-10] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-02-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-02-16] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll [2014-10-10] (pdfforge GmbH)

Chrome:
=======
CHR DefaultProfile: Default
CHR HKU\S-1-5-21-2198626584-3468660724-23365673-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fkkcgfbgohboipdhliafmacjnhjbhmim] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fdhbkaahephniejapepaiggngjnedpci] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AvrcpService; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe [35328 2013-04-02] (Realtek Semiconductor Corporation) [Datei ist nicht signiert]
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [47104 2013-04-26] () [Datei ist nicht signiert]
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [Datei ist nicht signiert]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [Datei ist nicht signiert]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-02-16] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2013-07-05] (Micro-Star International Co., Ltd.) [Datei ist nicht signiert]
R2 MSI Foundation Service; C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe [12800 2010-07-17] (MSI) [Datei ist nicht signiert]
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [143856 2013-02-01] (MSI)
R2 NAT; C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe [143928 2012-08-19] (Symantec Corporation)
S3 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4230016 2013-01-28] (Symantec Corporation)
R2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\SymcPCCULaunchSvc.exe [123320 2012-08-13] (Symantec Corporation)
R2 panda_url_filtering; C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe [287752 2015-10-02] (Visicom Media Inc.)
R2 pbamw_service; C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\AmwService.exe [125712 2016-11-08] (PLUMBYTES)
R2 PCCUJobMgr; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe [126392 2012-08-13] (Symantec Corporation)
R2 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1771560 2014-10-10] (pdfforge GmbH)
R2 PDF Architect 2 Creator; C:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
R2 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-10-10] (pdfforge GmbH)
R2 RtkBleServ; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\RtkBleServ.exe [42496 2013-04-26] (Realtek Semiconductor Corporation) [Datei ist nicht signiert]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ccSet_NARA; C:\windows\system32\drivers\NARAx64\0403000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
S3 ccSet_NAT; C:\windows\system32\drivers\NATx64\0106000.011\ccSetx64.sys [168096 2012-08-07] (Symantec Corporation)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [77416 2016-12-14] ()
S3 ewusbnet; C:\windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
R0 iaStorF; C:\windows\System32\drivers\iaStorF.sys [28656 2013-03-22] (Intel Corporation)
R3 L1C; C:\windows\System32\DRIVERS\L1C62x64.sys [118504 2013-05-07] (Qualcomm Atheros Co., Ltd.)
R2 MBAMChameleon; C:\windows\system32\drivers\MBAMChameleon.sys [176064 2017-01-10] (Malwarebytes)
R3 MBAMFarflt; C:\windows\system32\drivers\farflt.sys [102856 2017-01-15] (Malwarebytes)
R3 MBAMProtection; C:\windows\system32\drivers\mbam.sys [43968 2017-01-15] (Malwarebytes)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [250816 2017-01-15] (Malwarebytes)
R3 MBAMWebProtection; C:\windows\system32\drivers\mwac.sys [81696 2017-01-15] (Malwarebytes)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-26] (MSI)
R3 panda_url_filteringd; C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys [51288 2014-03-19] (Visicom Media Inc.)
S3 RtkAvrcp; C:\windows\system32\drivers\RtkAvrcp.sys [61152 2012-12-27] (Realtek Semiconductor Corporation)
S3 RtkAvrcpCtrlr; C:\windows\system32\drivers\RtkAvrcpCtrlr.sys [66376 2013-04-08] (Realtek Semiconductor Corporation)
R3 RtkBtFilter; C:\windows\System32\DRIVERS\RtkBtfilter.sys [535624 2013-03-28] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\windows\System32\DRIVERS\rtwlane.sys [1514568 2013-05-02] (Realtek Semiconductor Corporation                          )
S3 MGHwCtrl; \??\C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-01-15 14:42 - 2017-01-15 14:42 - 00000000 ____D C:\Users\Micha\Downloads\FRST-OlderVersion
2017-01-15 12:09 - 2017-01-15 13:43 - 00001729 _____ C:\Users\Micha\Desktop\AdwCleaner[S3].txt
2017-01-14 22:09 - 2017-01-14 22:09 - 00019431 _____ C:\Users\Micha\Desktop\AdwCleaner[C0].txt
2017-01-14 20:02 - 2017-01-14 19:16 - 00018180 _____ C:\Users\Micha\Desktop\AdwCleaner[S0].txt
2017-01-14 18:21 - 2017-01-14 18:21 - 00000268 _____ C:\Users\Micha\Desktop\Junkware Removal Tool - Download - Filepony.URL
2017-01-14 18:19 - 2017-01-14 18:19 - 01663040 _____ (Malwarebytes) C:\Users\Micha\Downloads\JRT(1).exe
2017-01-14 18:15 - 2017-01-14 18:30 - 00000696 _____ C:\Users\Micha\Desktop\JRT.txt
2017-01-14 18:10 - 2017-01-14 18:10 - 01663040 _____ (Malwarebytes) C:\Users\Micha\Downloads\JRT.exe
2017-01-14 18:06 - 2017-01-14 18:06 - 00017147 _____ C:\Users\Micha\Desktop\w2WQUGsI.htm
2017-01-14 17:40 - 2017-01-14 22:20 - 00000000 ____D C:\AdwCleaner
2017-01-14 17:37 - 2017-01-14 17:37 - 03988944 _____ C:\Users\Micha\Desktop\AdwCleaner_6.042.exe
2017-01-13 21:12 - 2017-01-13 22:37 - 00222352 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_21.12.52_log.txt
2017-01-13 21:09 - 2017-01-13 21:12 - 00219050 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_21.09.19_log.txt
2017-01-13 21:04 - 2017-01-13 21:05 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Micha\Downloads\tdsskiller(1).exe
2017-01-13 17:15 - 2017-01-13 17:29 - 00219050 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_17.15.21_log.txt
2017-01-13 17:09 - 2017-01-13 17:12 - 00219050 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_17.09.39_log.txt
2017-01-13 17:07 - 2017-01-13 17:07 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Micha\Desktop\tdsskiller.exe
2017-01-13 15:23 - 2017-01-14 22:06 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-01-13 15:17 - 2017-01-13 16:56 - 00000000 ____D C:\Users\Micha\Desktop\mbar
2017-01-13 15:07 - 2017-01-13 15:08 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Micha\Desktop\mbar-1.09.3.1001.exe
2017-01-13 08:17 - 2017-01-13 08:17 - 00000000 ____D C:\Users\Micha\Documents\MAGIX Downloads
2017-01-12 23:06 - 2017-01-13 11:42 - 00000000 ____D C:\Users\Micha\Desktop\Trboard
2017-01-12 10:56 - 2017-01-12 10:57 - 00084152 _____ C:\Users\Micha\Downloads\Addition .txt
2017-01-10 20:59 - 2017-01-05 19:55 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2017-01-10 20:59 - 2017-01-05 19:55 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2017-01-10 20:59 - 2017-01-05 19:52 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2017-01-10 20:59 - 2017-01-05 18:42 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2017-01-10 20:59 - 2017-01-05 18:32 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2017-01-10 20:59 - 2017-01-05 18:25 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2017-01-10 20:59 - 2017-01-05 18:23 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2017-01-10 20:59 - 2017-01-05 18:19 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2017-01-10 20:56 - 2017-01-10 20:56 - 00083124 _____ C:\Users\Micha\Downloads\FRST01102017.txt
2017-01-10 20:55 - 2017-01-10 20:55 - 00041706 _____ C:\Users\Micha\Downloads\Addition01102017.txt
2017-01-10 16:22 - 2017-01-10 16:22 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Vorlagen
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Startmenü
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Netzwerkumgebung
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Lokale Einstellungen
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Eigene Dateien
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Druckumgebung
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Videos
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Musik
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Bilder
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Verlauf
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Anwendungsdaten
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Anwendungsdaten
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 ____D C:\Users\DefaultAppPool
2017-01-10 16:22 - 2016-11-30 06:27 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\AVG
2017-01-10 16:22 - 2013-07-31 22:25 - 00002110 _____ C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
2017-01-10 16:22 - 2013-07-31 19:31 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\Media Center Programs
2017-01-10 09:38 - 2017-01-10 09:38 - 00176064 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMChameleon.sys
2017-01-10 09:37 - 2017-01-15 14:02 - 00081696 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2017-01-10 09:37 - 2017-01-15 08:00 - 00250816 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-10 09:37 - 2017-01-15 08:00 - 00102856 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2017-01-10 09:37 - 2017-01-15 08:00 - 00043968 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2017-01-10 09:37 - 2017-01-10 09:37 - 00001837 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-01-10 09:37 - 2017-01-10 09:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-01-10 09:37 - 2017-01-10 09:37 - 00000000 ____D C:\Program Files\Malwarebytes
2017-01-10 09:37 - 2016-12-14 12:55 - 00077416 _____ C:\windows\system32\Drivers\mbae64.sys
2017-01-10 09:35 - 2017-01-10 09:36 - 54199488 _____ (Malwarebytes ) C:\Users\Micha\Downloads\mb3-setup-consumer-3.0.5.1299(1).exe
2017-01-10 08:39 - 2017-01-10 08:39 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plumbytes Anti-Malware
2017-01-10 08:39 - 2017-01-10 08:39 - 00000000 ____D C:\Program Files\Plumbytes Software
2017-01-09 15:57 - 2017-01-12 10:52 - 00042109 _____ C:\Users\Micha\Downloads\Addition.txt
2017-01-09 15:55 - 2017-01-15 14:43 - 00022422 _____ C:\Users\Micha\Downloads\FRST.txt
2017-01-09 15:55 - 2017-01-15 14:43 - 00000000 ____D C:\FRST
2017-01-09 15:54 - 2017-01-15 14:42 - 02419200 _____ (Farbar) C:\Users\Micha\Downloads\FRST64.exe
2017-01-05 20:02 - 2017-01-05 20:02 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk
2017-01-05 20:02 - 2017-01-05 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-01-05 00:41 - 2015-07-16 20:12 - 06131200 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2017-01-05 00:41 - 2015-07-16 20:12 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2017-01-05 00:41 - 2015-07-16 20:12 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 07077376 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 01057792 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2017-01-05 00:41 - 2015-07-11 14:15 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2017-01-04 19:30 - 2015-12-20 19:50 - 03180544 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2017-01-04 19:30 - 2015-12-20 19:50 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2017-01-04 19:30 - 2015-12-20 15:08 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2017-01-04 19:29 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2017-01-04 15:08 - 2017-01-04 15:08 - 54199488 _____ (Malwarebytes ) C:\Users\Micha\Downloads\mb3-setup-consumer-3.0.5.1299.exe
2017-01-04 13:53 - 2017-01-04 13:53 - 13425152 _____ (ReviverSoft) C:\Users\Micha\Downloads\DriverReviverSetup_ppc(2).exe
2017-01-04 10:30 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2017-01-04 10:30 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2017-01-04 10:30 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2017-01-04 10:30 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2017-01-04 10:30 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2017-01-04 10:30 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2017-01-04 10:30 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2017-01-04 10:30 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2017-01-04 10:30 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2017-01-04 10:30 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2017-01-04 10:28 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2017-01-04 10:28 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbGD.sys
2017-01-04 10:28 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2017-01-04 10:28 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2017-01-04 10:25 - 2015-08-05 18:56 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\icaapi.dll
2017-01-04 10:25 - 2015-08-05 18:06 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2017-01-04 09:59 - 2017-01-04 09:59 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ICCWDT_01009.Wdf
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\kbdgeoqw.dll
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZEL.DLL
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZE.DLL
2017-01-04 09:25 - 2015-12-16 19:48 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZE.DLL
2017-01-04 09:25 - 2015-12-16 19:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\kbdgeoqw.dll
2017-01-04 09:25 - 2015-12-16 19:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZEL.DLL
2017-01-04 02:04 - 2017-01-04 02:04 - 03279864 _____ (SPAMfighter ApS) C:\Users\Micha\Downloads\DRIVERfighter_Web(1).exe
2017-01-04 01:03 - 2017-01-04 01:04 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Fighters
2017-01-04 01:02 - 2017-01-04 02:18 - 00000000 ____D C:\ProgramData\Fighters
2017-01-04 01:00 - 2017-01-04 01:01 - 03279864 _____ (SPAMfighter ApS) C:\Users\Micha\Downloads\DRIVERfighter_Web.exe
2017-01-04 00:54 - 2017-01-04 00:55 - 13425152 _____ (ReviverSoft) C:\Users\Micha\Downloads\DriverReviverSetup_ppc(1).exe
2016-12-30 10:41 - 2016-12-30 10:41 - 00178564 _____ C:\Users\Micha\Downloads\HERMES_label_2016-12-30_10_40_52.pdf
2016-12-30 10:35 - 2016-12-30 10:35 - 00178968 _____ C:\Users\Micha\Downloads\HERMES_label_2016-12-30_10_33_49.pdf
2016-12-24 23:14 - 2016-12-24 23:14 - 00025199 _____ C:\Users\Micha\Documents\freelancer200855.vcf
2016-12-24 10:33 - 2012-06-01 06:39 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\wamregps.dll
2016-12-24 10:33 - 2012-06-01 06:36 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\iisRtl.dll
2016-12-24 10:33 - 2012-06-01 06:36 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\iisrstap.dll
2016-12-24 10:33 - 2012-06-01 06:35 - 00060928 _____ (Microsoft Corporation) C:\windows\system32\ahadmin.dll
2016-12-24 10:33 - 2012-06-01 06:34 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\admwprox.dll
2016-12-24 10:33 - 2012-06-01 06:33 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\iisreset.exe
2016-12-24 10:33 - 2012-06-01 05:40 - 00010752 _____ (Microsoft Corporation) C:\windows\SysWOW64\wamregps.dll
2016-12-24 10:33 - 2012-06-01 05:37 - 00154624 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisRtl.dll
2016-12-24 10:33 - 2012-06-01 05:37 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisrstap.dll
2016-12-24 10:33 - 2012-06-01 05:35 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\admwprox.dll
2016-12-24 10:33 - 2012-06-01 05:35 - 00026624 _____ (Microsoft Corporation) C:\windows\SysWOW64\ahadmin.dll
2016-12-24 10:33 - 2012-06-01 05:34 - 00015360 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisreset.exe
2016-12-24 02:30 - 2017-01-15 00:36 - 03052850 ____H C:\Users\Micha\AppData\Local\IconCache.db
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\windows\SysWOW64\BestPractices
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\windows\system32\BestPractices
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\inetpub
2016-12-23 17:25 - 2016-12-23 17:25 - 43886552 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\SkypeSetupFull(2).exe
2016-12-23 17:25 - 2016-12-23 17:25 - 00003142 _____ C:\windows\System32\Tasks\{42239007-962A-405B-897B-E4E0207270AF}
2016-12-23 17:23 - 2016-12-23 17:24 - 01463424 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\skypesetup.exe
2016-12-23 16:13 - 2017-01-03 14:27 - 00524288 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TMContainer00000000000000000001.regtrans-ms
2016-12-23 16:13 - 2017-01-03 14:27 - 00065536 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TM.blf
2016-12-23 16:13 - 2016-12-23 16:17 - 00524288 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 15:52 - 2016-12-23 15:52 - 00000000 __SHD C:\found.000
2016-12-18 14:28 - 2016-12-18 14:28 - 00000000 ____D C:\Users\Micha\Tracing
2016-12-18 14:25 - 2016-12-18 14:25 - 43872728 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\SkypeSetupFull(1).exe
2016-12-18 14:20 - 2016-12-18 14:20 - 43878872 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\SkypeSetupFull.exe
2016-12-18 14:12 - 2017-01-15 14:28 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Skype
2016-12-18 14:12 - 2016-12-18 14:28 - 00000000 ____D C:\Users\Micha\AppData\Local\Skype
2016-12-18 11:45 - 2016-12-18 11:45 - 00003202 _____ C:\windows\System32\Tasks\{7C15C6ED-AB8F-4479-AB67-B366BCA58406}
2016-12-16 09:55 - 2016-12-16 09:57 - 00000000 ____D C:\Users\Micha\Documents\Fax
2016-12-16 09:55 - 2016-12-16 09:55 - 00000000 ___RD C:\Users\Micha\Documents\Scanned Documents
2016-12-16 01:19 - 2016-12-16 01:19 - 00307001 _____ C:\Users\Micha\Downloads\urkunden(2).jpeg

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-01-15 14:17 - 2014-12-14 15:17 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2017-01-15 13:02 - 2015-05-27 15:08 - 00000000 ____D C:\ProgramData\panda_url_filtering
2017-01-15 09:09 - 2016-11-22 11:54 - 00000000 ____D C:\Users\Micha\AppData\LocalLow\Mozilla
2017-01-15 09:05 - 2014-12-19 22:43 - 00000000 ____D C:\Users\Micha\Documents\Youcam
2017-01-15 08:09 - 2009-07-14 05:45 - 00024432 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-15 08:09 - 2009-07-14 05:45 - 00024432 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-15 07:59 - 2015-02-27 20:57 - 00000000 ____D C:\Users\Micha\AppData\Local\FreePDF_XP
2017-01-15 07:58 - 2013-07-31 21:55 - 00000000 ____D C:\ProgramData\Realtek
2017-01-15 07:58 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-01-14 22:04 - 2015-01-05 13:28 - 00000000 ____D C:\Program Files (x86)\Lavasoft
2017-01-14 22:04 - 2015-01-05 13:24 - 00000000 ____D C:\ProgramData\Lavasoft
2017-01-14 18:12 - 2015-01-05 13:26 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Lavasoft
2017-01-13 15:52 - 2015-01-02 10:15 - 00000000 ____D C:\Users\Micha\AppData\Roaming\DesktopIconAmazon
2017-01-13 15:23 - 2016-11-06 01:54 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-01-13 12:30 - 2015-07-24 19:26 - 00000000 ____D C:\Program Files (x86)\360
2017-01-13 12:16 - 2015-01-05 13:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2017-01-13 08:17 - 2014-12-14 00:10 - 00000000 ____D C:\Users\Micha\Documents\MAGIX_MusicMaker16_Download-Version
2017-01-11 21:01 - 2014-12-19 21:37 - 00010240 _____ C:\Users\Micha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-01-11 12:42 - 2015-07-15 11:33 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-11 12:40 - 2015-01-21 09:55 - 00004476 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2017-01-11 01:25 - 2009-07-14 06:08 - 00032640 _____ C:\windows\Tasks\SCHEDLGU.TXT
2017-01-11 00:03 - 2014-12-14 16:17 - 00000000 ____D C:\windows\system32\MRT
2017-01-11 00:02 - 2014-12-20 03:20 - 135657872 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2017-01-10 16:17 - 2014-12-14 15:17 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2017-01-10 16:17 - 2014-12-14 15:17 - 00000000 ____D C:\windows\system32\Macromed
2017-01-10 16:17 - 2013-07-31 22:22 - 00802904 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2017-01-10 16:17 - 2013-07-31 22:22 - 00144472 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-01-10 16:17 - 2013-07-31 22:22 - 00000000 ____D C:\windows\SysWOW64\Macromed
2017-01-09 15:53 - 2015-09-21 09:06 - 00000000 __SHD C:\$360Section
2017-01-09 15:53 - 2015-09-02 15:13 - 00000000 ____D C:\ProgramData\360Quarant
2017-01-05 20:02 - 2013-07-31 22:29 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-01-05 20:02 - 2013-07-31 22:28 - 00000000 ____D C:\ProgramData\Skype
2017-01-04 13:31 - 2014-12-14 15:54 - 00000000 ____D C:\Program Files (x86)\chip
2017-01-04 10:35 - 2009-07-14 05:45 - 00313104 _____ C:\windows\system32\FNTCACHE.DAT
2017-01-04 10:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\PolicyDefinitions
2017-01-04 10:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\inf
2017-01-04 10:31 - 2013-07-31 21:39 - 01687534 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2017-01-04 10:31 - 2013-07-31 19:42 - 00738178 _____ C:\windows\system32\perfh007.dat
2017-01-04 10:31 - 2013-07-31 19:42 - 00160894 _____ C:\windows\system32\perfc007.dat
2017-01-04 10:31 - 2009-07-14 06:13 - 01687534 _____ C:\windows\system32\PerfStringBackup.INI
2017-01-04 10:31 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\inetsrv
2017-01-04 09:47 - 2016-06-30 15:21 - 00000000 ____D C:\Users\Micha\AppData\Local\ElevatedDiagnostics
2017-01-04 02:21 - 2014-12-14 00:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2017-01-04 02:05 - 2009-07-14 03:34 - 00000568 _____ C:\windows\win.ini
2017-01-03 17:08 - 2015-09-24 19:26 - 00000356 _____ C:\Users\Micha\Desktop\Zitate.txt
2016-12-28 22:36 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\migration
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\inetsrv
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\migration
2016-12-24 20:13 - 2009-07-14 04:18 - 00000000 __SHD C:\$Recycle.Bin
2016-12-24 00:58 - 2014-12-31 14:21 - 00000000 ____D C:\ProgramData\Freemake
2016-12-24 00:58 - 2014-12-31 14:21 - 00000000 ____D C:\Program Files (x86)\Freemake
2016-12-24 00:00 - 2009-07-14 04:20 - 00000000 __RSD C:\windows\assembly
2016-12-24 00:00 - 2009-07-14 04:20 - 00000000 ____D C:\windows\Microsoft.NET
2016-12-23 23:52 - 2014-12-14 00:06 - 00000000 ___RD C:\Users\Micha\Videos
2016-12-23 23:20 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2016-12-23 23:18 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-12-23 23:18 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Microsoft Games
2016-12-23 23:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\Drivers\etc
2016-12-23 23:18 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-12-23 19:30 - 2009-07-14 04:20 - 00000000 ____D C:\windows\AppPatch
2016-12-23 15:29 - 2016-11-02 17:00 - 00524288 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 15:29 - 2016-11-02 17:00 - 00065536 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TM.blf
2016-12-23 15:02 - 2016-11-02 17:00 - 00524288 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TMContainer00000000000000000001.regtrans-ms
2016-12-18 14:28 - 2014-12-14 00:06 - 00000000 ____D C:\Users\Micha\AppData\Local\Microsoft
2016-12-18 14:28 - 2014-12-14 00:06 - 00000000 ____D C:\Users\Micha
2016-12-18 12:19 - 2014-12-14 00:07 - 00072008 _____ C:\Users\Micha\AppData\Local\GDIPFONTCACHEV1.DAT
2016-12-18 12:13 - 2015-05-27 15:05 - 00000000 ____D C:\Program Files (x86)\Panda Security
2016-12-18 12:07 - 2015-05-27 15:03 - 00000000 ____D C:\ProgramData\Panda Security
2016-12-18 12:06 - 2015-05-27 15:06 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Panda Security
2016-12-18 01:40 - 2014-12-14 00:06 - 00000000 ___RD C:\Users\Micha\Pictures
2016-12-17 01:20 - 2014-12-21 14:52 - 00003542 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-12-17 01:20 - 2014-12-21 14:52 - 00003414 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2014-09-01 09:18 - 2014-09-01 09:18 - 0001248 _____ () C:\Users\Micha\AppData\Roaming\FODX
2014-12-14 00:06 - 2017-01-15 13:27 - 0094901 _____ () C:\Users\Micha\AppData\Local\BTServer.log
2014-12-19 21:37 - 2017-01-11 21:01 - 0010240 _____ () C:\Users\Micha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Einige Dateien in TEMP:
====================
C:\Users\Micha\AppData\Local\Temp\DllMonoCtrl.dll


==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert

LastRegBack: 2017-01-03 14:36

==================== Ende von FRST.txt ============================

noch einmal, Gruß MS-Michael
Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-01-2017
durchgeführt von Micha (15-01-2017 17:43:59)
Gestartet von C:\Users\Micha\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2014-12-13 23:06:40)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2198626584-3468660724-23365673-500 - Administrator - Disabled)
Gast (S-1-5-21-2198626584-3468660724-23365673-501 - Limited - Disabled)
Micha (S-1-5-21-2198626584-3468660724-23365673-1000 - Administrator - Enabled) => C:\Users\Micha

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Ad-Aware Web Companion (x32 Version: 1.1.844.1586 - Lavasoft) Hidden
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.023.20053 - Adobe Systems Incorporated)
Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.194 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated)
Apple Application Support (32-Bit) (HKLM-x32\...\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BurnRecovery (HKLM-x32\...\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 3.0.1103.1801 - Micro-Star International Co., Ltd.)
Camera RAW Plug-In for EPSON Creativity Suite (HKLM-x32\...\{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}) (Version: 2.1.0.0 - )
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.31 - Cliqz.com)
concept/design onlineTV 11 (HKLM-x32\...\{8A4C3184-DA2F-4553-BF61-83F5690C3048}_is1) (Version: 11.0.0.0 - concept/design GmbH)
CX4300_5500_DX4400 Handbuch (HKLM-x32\...\CX4300_5500_DX4400 Handbuch) (Version:  - )
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.4612 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
EPSON Attach To Email (HKLM-x32\...\InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON)
EPSON Attach To Email (x32 Version: 1.01.0000 - SEIKO EPSON) Hidden
EPSON Copy Utility 3 (HKLM-x32\...\{67EDD823-135A-4D59-87BD-950616D6E857}) (Version: 3.2.0.0 - )
EPSON File Manager (HKLM-x32\...\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}) (Version: 1.3.0.0 - )
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
EPSON Scan Assistant (HKLM-x32\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - )
EPSON SX100 Series Printer Uninstall (HKLM\...\EPSON SX100 Series) (Version:  - SEIKO EPSON Corporation)
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version:  - SEIKO EPSON Corporation)
ETDWare PS/2-X64 11.13.2.4_WHQL (HKLM\...\Elantech) (Version: 11.13.2.4 - ELAN Microelectronic Corp.)
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}) (Version: 2.1.27.0 - MAGIX AG)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
FreePDF (Remove only) (HKLM-x32\...\FreePDF_XP) (Version:  - )
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
GPL Ghostscript (HKLM\...\GPL Ghostscript 9.07) (Version: 9.07 - Artifex Software Inc.)
GPL Ghostscript (HKLM-x32\...\GPL Ghostscript 9.15) (Version: 9.15 - Artifex Software Inc.)
iCloud (HKLM\...\{29AAC3D3-23FC-496D-8266-0E3833686758}) (Version: 6.0.2.10 - Apple Inc.)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1310 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3186 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.5.0.1066 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.6 (HKLM\...\{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.6.2.0 - Intel)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
LavasoftTcpService (x32 Version: 2.2.9.5 - Lavasoft) Hidden
MAGIX Music Maker 16 Download-Version (HKLM-x32\...\MAGIX Music Maker 16 Download-Version D) (Version: 16.0.3.0 - MAGIX AG)
MAGIX Online Druck Service (HKLM-x32\...\MAGIX Online Druck Service D) (Version: 3.4.3.0 - MAGIX AG)
MAGIX Screenshare (HKLM-x32\...\MAGIX Screenshare D) (Version: 4.3.6.1987 - MAGIX AG)
MAGIX Speed burnR (HKLM-x32\...\MAGIX Speed burnR D) (Version: 7.0.2.6 - MAGIX AG)
Malwarebytes Version 3.0.5.1299 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mobile Partner (HKLM-x32\...\Mobile Partner) (Version: 16.002.03.01.40 - Huawei Technologies Co.,Ltd)
Movavi Video Suite 14 (HKLM-x32\...\Movavi Video Suite 14) (Version: 14.0.1 - Movavi)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 50.1.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 de)) (Version: 50.1.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla)
MSI Battery Calibration (HKLM-x32\...\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.0.1 - Micro-Star International Co., Ltd.)
MSI HOUSE (HKLM-x32\...\{DA5597C9-9216-44FF-9670-D1E48817B998}) (Version: 10.07.1601 - MSI)
MSI Software Install (HKLM-x32\...\{332EBFE0-C39E-42D1-99B5-ABBBECAD71B6}) (Version: 4.0.1105.1701 - Micro-Star International Co., Ltd.)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Norton Anti-Theft (HKLM-x32\...\NAT) (Version: 1.6.0.17 - Symantec Corporation)
Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.7.0.24 - Symantec Corporation)
Norton Online Backup ARA (x32 Version: 4.3.0.14 - Symantec Corporation) Hidden
Norton PC Checkup (HKLM-x32\...\NortonPCCheckup) (Version: 2.0.18.16 - Symantec Corporation)
OpenOffice 4.1.2 (HKLM-x32\...\{F5CAB1AF-7B1A-4CEC-B829-A3F699473AE1}) (Version: 4.12.9782 - Apache Software Foundation)
Panda Security Toolbar (HKLM-x32\...\pandasecuritytb) (Version: 4.3.1.9 - Panda Security and Visicom Media Inc.)
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.51.17865 - pdfforge GmbH)
PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Edit Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 View Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.1 - pdfforge)
Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.13 - Qualcomm Atheros Communications Inc.)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.728.728.042813 - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6914 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0212 - )
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: 1.90 - Ghostgum Software Pty Ltd)
SCM (HKLM\...\{CA85D7A7-6B45-4011-9BCC-C01F31EDE157}) (Version: 14.013.07054 -  )
Shotcut (HKLM-x32\...\Shotcut) (Version:  - )
Skype™ 7.30 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.30.105 - Skype Technologies S.A.)
SoftMaker FreeOffice (HKLM-x32\...\{8EBB8452-274B-465D-8324-00B0832FBB02}) (Version: 1.0.3475 - SoftMaker Software GmbH)
Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.017 - MSI)
Sweepi 5.4.00 (HKLM-x32\...\Sweepi_is1) (Version: 5.4.00 - YooApplications)
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
Web Companion (HKLM-x32\...\{D5116390-5C95-4FEA-A719-78C3C8B5DFB5}_WebCompanion) (Version: 1.1.844.1586 - Lavasoft)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinZip 19.0 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E4}) (Version: 19.0.11293 - WinZip Computing, S.L. )

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {17608ADD-35B5-4F2A-A369-E67C96C0B20E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {2B68F8A1-F7BA-4699-885D-EAF51F2DBD90} - System32\Tasks\{551F8A14-3EE5-4B8B-83D3-D11EB5BC5F15} => pcalua.exe -a "C:\Program Files (x86)\FreePDF_XP\setup.exe" -d "C:\Program Files (x86)\Mozilla Firefox" -c C:\Users\Micha\AppData\Local\Temp\Paketschein-14.pdf <==== ACHTUNG
Task: {3CDF7212-D471-42F4-A121-ED4D70251682} - System32\Tasks\{7C15C6ED-AB8F-4479-AB67-B366BCA58406} => pcalua.exe -a "C:\Program Files (x86)\DriverUpdate\UninstallStub.exe" -c --log {a9888f42-bffe-4aca-ac10-51983972c2df}
Task: {3DA3586E-C068-4460-B103-15DDD7C51B40} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-10] (Adobe Systems Incorporated)
Task: {3E09C0A2-D6E6-407F-A239-AAAECEF79B78} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {3F283151-7529-496F-9366-FCAEC83C2694} - System32\Tasks\1215tbUpdateInfo => C:\ProgramData\Avg_Update_1215tb\1215tb_{4D479988-B227-4153-A15F-3D6D13E85735}.exe
Task: {58A9DC7B-AC64-4449-B51A-1CA3922D1961} - System32\Tasks\Norton Online Backup ARA => C:\Program Files (x86)\Norton Online Backup ARA\Engine\4.3.0.14\\Ara.exe [2013-08-27] (Symantec Corporation)
Task: {63050248-0821-4CF1-A0FA-3D7C370A627F} - System32\Tasks\{42239007-962A-405B-897B-E4E0207270AF} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.24.0.104&amp;LastError=404
Task: {96FEB751-76F6-4B79-B85A-B188D39EBB02} - System32\Tasks\{DDE7AD7B-E373-4700-9749-EFD63E11B429} => C:\Windows\twain_32\escndv\escndv.exe [2008-04-06] (SEIKO EPSON CORP.)
Task: {B2A759E8-D7A6-40F4-8583-1B21178BF297} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: {CB02601F-EC46-425D-981C-29E9B6680ED3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {DF814115-C649-4F46-9705-DDBEC44F373C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {E499296A-F20A-4ACE-9CD0-242A1F09B9A3} - System32\Tasks\{129E23B6-40C3-4E2D-BA39-481FE58B2A62} => C:\Program Files\PDFCreator\PDFCreator.exe [2014-12-16] (pdfforge)
Task: {FB0D8A3E-E462-456A-A960-0E05DB4FE8BC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-01-09 01:19 - 2012-06-21 07:25 - 00113152 _____ () C:\windows\System32\redmon64.dll
2013-07-31 21:55 - 2013-04-26 00:32 - 00047104 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
2017-01-10 09:37 - 2016-12-14 12:55 - 02259232 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-01-10 09:37 - 2016-12-14 12:55 - 02813904 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll
2017-01-10 09:37 - 2016-12-14 12:55 - 02247632 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2013-07-31 21:55 - 2013-04-09 22:42 - 00265728 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\SkypePlugin.exe
2012-05-30 21:15 - 2012-05-30 21:15 - 00404008 _____ () C:\Program Files\Intel\TurboBoost\de\SignalIslandUi.resources.dll
2016-10-05 18:18 - 2016-10-05 18:18 - 01041720 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2016-10-05 18:18 - 2016-10-05 18:18 - 00080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2016-10-05 18:18 - 2016-10-05 18:18 - 00189752 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2011-10-13 08:46 - 2011-10-13 08:46 - 00116008 _____ () C:\Program Files (x86)\CyberLink\YouCam\Intel945ScreenRotate.dll
2011-10-13 08:46 - 2011-10-13 08:46 - 00058664 _____ () C:\Program Files (x86)\CyberLink\YouCam\IntelGMAScreenRotate.dll
2011-10-13 08:47 - 2011-10-13 08:47 - 00054568 _____ () C:\Program Files (x86)\CyberLink\YouCam\NVScreenRotate.dll
2011-10-13 08:47 - 2011-10-13 08:47 - 00087336 _____ () C:\Program Files (x86)\CyberLink\YouCam\koan\_ctypes.pyd
2011-10-13 08:47 - 2011-10-13 08:47 - 00058664 _____ () C:\Program Files (x86)\CyberLink\YouCam\koan\_socket.pyd
2011-10-13 08:47 - 2011-10-13 08:47 - 00660776 _____ () C:\Program Files (x86)\CyberLink\YouCam\koan\_ssl.pyd
2011-10-13 08:48 - 2011-10-13 08:48 - 00484648 _____ () C:\Program Files (x86)\CyberLink\YouCam\subsys\YouCam\MediaObj.dll
2011-10-13 08:48 - 2011-10-13 08:48 - 00062760 _____ () C:\Program Files (x86)\CyberLink\YouCam\subsys\YouCam\XUControl.dll
2011-10-13 08:48 - 2011-10-13 08:48 - 00066856 _____ () C:\Program Files (x86)\CyberLink\YouCam\subsys\YouCam\ImageWrapper.dll
2011-10-13 08:45 - 2011-10-13 08:45 - 00275752 _____ () C:\Program Files (x86)\CyberLink\YouCam\subsys\YouCam\BlackCat.dll
2011-10-13 08:47 - 2011-10-13 08:47 - 00140584 _____ () C:\Program Files (x86)\CyberLink\YouCam\koan\pyexpat.pyd
2013-07-31 21:37 - 2013-02-16 00:15 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2017-01-10 16:17 - 2017-01-10 16:17 - 19762776 _____ () C:\windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1 - 192.168.0.2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [TCP Query User{F5428C65-02FD-4258-9D3B-DBA9131CD043}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{58EAA851-0F4D-4025-A9FA-82AAC4EEC077}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{FC62AAD4-D5DF-4232-B263-4FC654D0457F}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{9D370156-D01D-4231-A5C5-E72B2D7C382D}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{EB01AC34-1000-4725-AB7E-266EF7070BAE}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6AED153C-CE2F-4F79-A73D-5DA437D8EDD9}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4AE2CA5C-F80C-436A-B9FF-2E8E125414F6}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{4B1F3D68-AEF2-4EE3-A176-82754C956CCF}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{535793E5-DA7A-48C6-9675-333B3C13480E}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1A36325C-7D02-4CAE-968A-A8054B57A386}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{EEBD56D9-AD50-4F27-871C-9FFB87C817E6}] => C:\Program Files (x86)\pandasecuritytb\cleanupie.exe
FirewallRules: [{DD826058-D556-4DB6-B195-3CFDAD7FE9C3}] => C:\Program Files (x86)\pandasecuritytb\cleanupie.exe
FirewallRules: [{1B35008A-2B15-4C6A-A7D9-6EF5E4509617}] => C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{933C0AF3-CFB0-49D7-8613-7113DE462D2F}] => C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{4E8E84F9-07C1-415A-A528-90BE6E2BCCBC}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{36E73BFD-7CEF-4516-8259-755DA03A06E5}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{CED2D614-329E-4C55-BAF4-F84F23D9BBB5}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4CAD39BB-8FD9-48ED-9A96-B3DABD7B4683}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{60005B18-84B8-4665-9D35-482C3A16A343}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{2FA7CE91-EAFF-49F9-B2DF-C5687CA4B179}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{72F59172-3120-434F-8648-B19F920FA80F}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{76C646E5-E59E-4079-91C6-6DB2955E5955}] => C:\Program Files (x86)\Skype\Phone\Skype.exe

==================== Wiederherstellungspunkte =========================

10-11-2016 06:10:16 Windows Update
26-11-2016 13:55:57 Geplanter Prüfpunkt
27-11-2016 17:27:32 Installed Windows Mobile-Gerätecenter
05-12-2016 20:53:37 AA11
09-12-2016 20:06:44 Removed Visual Studio 2012 x86 Redistributables
09-12-2016 20:08:07 Removed Visual Studio 2012 x64 Redistributables
15-12-2016 03:00:20 Windows Update
15-12-2016 19:14:17 AA11
16-12-2016 01:31:33 Windows Update
18-12-2016 11:42:27 Removed DriverUpdate
18-12-2016 11:45:52 Removed DriverUpdate
23-12-2016 16:08:55 Wiederherstellungsvorgang
23-12-2016 23:16:31 Windows Modules Installer
25-12-2016 00:00:28 Windows Update
03-01-2017 23:19:17 Wiederherstellungsvorgang
04-01-2017 01:02:43 Installed DRIVERfighter.
04-01-2017 02:23:30 Removed DriverUpdate
04-01-2017 09:36:49 Windows Update
04-01-2017 09:58:19 Windows Update
04-01-2017 10:00:56 Windows Update
04-01-2017 10:02:20 Windows Update
04-01-2017 10:26:13 Windows Update
04-01-2017 13:27:41 Removed DriverUpdate
04-01-2017 13:30:28 Removed CHIP Best Deal
04-01-2017 13:44:48 Konfiguriert Camera RAW Plug-In for EPSON Creativity Suite
04-01-2017 14:01:35 Driver Reviver (04/01/2017 14:01)
04-01-2017 17:31:04 Removed Skype™ 7.30
04-01-2017 18:18:15 Windows Update
05-01-2017 00:00:55 Windows Update
05-01-2017 00:41:14 Windows Update
05-01-2017 00:48:52 Windows Update
05-01-2017 00:54:51 Windows Update
10-01-2017 15:42:24 Installed DriverUpdate
10-01-2017 19:40:37 Windows Update
10-01-2017 19:45:26 Windows Update
10-01-2017 19:56:24 Windows Update
10-01-2017 19:58:33 Windows Update
10-01-2017 20:27:38 Windows Update
11-01-2017 00:00:21 Windows Update
11-01-2017 01:01:28 Wiederherstellungsvorgang
13-01-2017 12:14:21 AA11
13-01-2017 15:52:00 Malwarebytes Anti-Rootkit Restore Point
14-01-2017 18:11:18 JRT Pre-Junkware Removal
14-01-2017 18:26:46 JRT Pre-Junkware Removal

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Microsoft-Teredo-Tunneling-Adapter
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Unknown Device
Description: Unknown Device
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Standard-USB-Hostcontroller)
Service:
Problem: : This device is disabled because the firmware of the device did not give it the required resources. (Code 29)
Resolution: Enable the device in the BIOS of the device.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (01/15/2017 01:02:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 12651

Error: (01/15/2017 01:02:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 12651

Error: (01/15/2017 01:02:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/15/2017 01:02:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 11653

Error: (01/15/2017 01:02:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 11653

Error: (01/15/2017 01:02:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/15/2017 01:02:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 10655

Error: (01/15/2017 01:02:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 10655

Error: (01/15/2017 01:02:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/15/2017 01:02:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9625


Systemfehler:
=============
Error: (01/15/2017 11:18:49 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst PCCUJobMgr erreicht.

Error: (01/14/2017 10:35:23 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.

Error: (01/14/2017 10:14:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde aufgrund folgenden Fehlers nicht gestartet:
Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden.

Error: (01/14/2017 10:14:32 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "WMPNetworkSvc" konnte sich nicht als "NT AUTHORITY\NetworkService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
Die Anforderung wird nicht unterstützt.


Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (01/14/2017 10:14:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet:
Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden.

Error: (01/14/2017 10:14:32 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "WSearch" konnte sich nicht als "NT AUTHORITY\SYSTEM" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
Die Anforderung wird nicht unterstützt.


Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (01/14/2017 10:14:28 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\windows\system32\Rtlihvs.dll

Error: (01/14/2017 10:14:02 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Software Protection" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (01/14/2017 10:14:02 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.

Error: (01/14/2017 10:14:02 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Norton PC Checkup Application Launcher" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


==================== Speicherinformationen ===========================

Prozessor: Intel(R) Pentium(R) CPU 3560M @ 2.40GHz
Prozentuale Nutzung des RAM: 65%
Installierter physikalischer RAM: 4016.81 MB
Verfügbarer physikalischer RAM: 1373.92 MB
Summe virtueller Speicher: 8031.8 MB
Verfügbarer virtueller Speicher: 4744.88 MB

==================== Laufwerke ================================

Drive c: (OS_Install) (Fixed) (Total:272.65 GB) (Free:111.78 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive d: (Data) (Fixed) (Total:181.77 GB) (Free:181.63 GB) NTFS
Drive w: (BIOS_RVY) (Fixed) (Total:11.24 GB) (Free:0.28 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C54CB572)
Partition 1: (Not Active) - (Size=11.2 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=27)
Partition 3: (Not Active) - (Size=272.7 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=181.8 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================


cosinus 16.01.2017 12:03

Zitat:

OpenOffice 4.1.2
QuickTime 7
Beides deinstallieren. OpenOffice wird kaum noch weiterentwickelt und auf deinem Rechner installierte Version ist veraltet. Steig um auf ein aktuelles LibreOffice.

Quicktime wird von Apple nicht mehr supportet.


Wir können auch alles mit revo gleich wegkloppen plus anderen unnützen Kram:


Lade Dir bitte von hier Revo Uninstaller Download Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
  • Installiere und starte das Programm. (Bebilderte Anleitung zu Revo Uninstaller)
  • Klicke auf Optionen und wähle als Sprache Deutsch.
  • Suche im Uninstallerfeld nach den Programmen:

    McAfee Security Scan Plus

    Panda Security Toolbar

    OpenOffice 4.1.2

    QuickTime 7

  • Wähle die Programme nacheinander aus und klicke jedes Mal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

 


milkit54 16.01.2017 13:41

Hallo Cosinus, habe ich gemacht brauche ich irgendwas von Apple? Gruß MS-Michael

cosinus 16.01.2017 13:54

ob du was von Apple willst und brauchst soll ich bitte woher wissen :confused:

milkit54 16.01.2017 14:38

sorry cosinus, das war ne dumme und unpräzise Frage. ich hatte nur 217mb programm von apple gesehen welches du nicht aufgelistet hattest. hab ich jetzt ebenfalls rausgeschmissen. soll ich fibre offficde selber suchen oder schickst du mir einen lnk? Gruß MS-Micha

cosinus 16.01.2017 14:55

http://donate.libreoffice.org/de/dl/....4_Win_x64.msi



und neue FRST Logs bitte

milkit54 16.01.2017 15:27

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-01-2017
durchgeführt von Micha (16-01-2017 15:20:49)
Gestartet von C:\Users\Micha\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2014-12-13 23:06:40)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2198626584-3468660724-23365673-500 - Administrator - Disabled)
Gast (S-1-5-21-2198626584-3468660724-23365673-501 - Limited - Disabled)
Micha (S-1-5-21-2198626584-3468660724-23365673-1000 - Administrator - Enabled) => C:\Users\Micha

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Ad-Aware Web Companion (x32 Version: 1.1.844.1586 - Lavasoft) Hidden
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.023.20053 - Adobe Systems Incorporated)
Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.194 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated)
BurnRecovery (HKLM-x32\...\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 3.0.1103.1801 - Micro-Star International Co., Ltd.)
Camera RAW Plug-In for EPSON Creativity Suite (HKLM-x32\...\{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}) (Version: 2.1.0.0 - )
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.31 - Cliqz.com)
concept/design onlineTV 11 (HKLM-x32\...\{8A4C3184-DA2F-4553-BF61-83F5690C3048}_is1) (Version: 11.0.0.0 - concept/design GmbH)
CX4300_5500_DX4400 Handbuch (HKLM-x32\...\CX4300_5500_DX4400 Handbuch) (Version:  - )
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.4612 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
EPSON Attach To Email (HKLM-x32\...\InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON)
EPSON Attach To Email (x32 Version: 1.01.0000 - SEIKO EPSON) Hidden
EPSON Copy Utility 3 (HKLM-x32\...\{67EDD823-135A-4D59-87BD-950616D6E857}) (Version: 3.2.0.0 - )
EPSON File Manager (HKLM-x32\...\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}) (Version: 1.3.0.0 - )
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
EPSON Scan Assistant (HKLM-x32\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - )
EPSON SX100 Series Printer Uninstall (HKLM\...\EPSON SX100 Series) (Version:  - SEIKO EPSON Corporation)
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version:  - SEIKO EPSON Corporation)
ETDWare PS/2-X64 11.13.2.4_WHQL (HKLM\...\Elantech) (Version: 11.13.2.4 - ELAN Microelectronic Corp.)
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}) (Version: 2.1.27.0 - MAGIX AG)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
FreePDF (Remove only) (HKLM-x32\...\FreePDF_XP) (Version:  - )
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
GPL Ghostscript (HKLM\...\GPL Ghostscript 9.07) (Version: 9.07 - Artifex Software Inc.)
GPL Ghostscript (HKLM-x32\...\GPL Ghostscript 9.15) (Version: 9.15 - Artifex Software Inc.)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1310 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3186 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.5.0.1066 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.6 (HKLM\...\{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.6.2.0 - Intel)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
LavasoftTcpService (x32 Version: 2.2.9.5 - Lavasoft) Hidden
MAGIX Music Maker 16 Download-Version (HKLM-x32\...\MAGIX Music Maker 16 Download-Version D) (Version: 16.0.3.0 - MAGIX AG)
MAGIX Online Druck Service (HKLM-x32\...\MAGIX Online Druck Service D) (Version: 3.4.3.0 - MAGIX AG)
MAGIX Screenshare (HKLM-x32\...\MAGIX Screenshare D) (Version: 4.3.6.1987 - MAGIX AG)
MAGIX Speed burnR (HKLM-x32\...\MAGIX Speed burnR D) (Version: 7.0.2.6 - MAGIX AG)
Malwarebytes Version 3.0.5.1299 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mobile Partner (HKLM-x32\...\Mobile Partner) (Version: 16.002.03.01.40 - Huawei Technologies Co.,Ltd)
Movavi Video Suite 14 (HKLM-x32\...\Movavi Video Suite 14) (Version: 14.0.1 - Movavi)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 50.1.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 de)) (Version: 50.1.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla)
MSI Battery Calibration (HKLM-x32\...\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.0.1 - Micro-Star International Co., Ltd.)
MSI HOUSE (HKLM-x32\...\{DA5597C9-9216-44FF-9670-D1E48817B998}) (Version: 10.07.1601 - MSI)
MSI Software Install (HKLM-x32\...\{332EBFE0-C39E-42D1-99B5-ABBBECAD71B6}) (Version: 4.0.1105.1701 - Micro-Star International Co., Ltd.)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Norton Anti-Theft (HKLM-x32\...\NAT) (Version: 1.6.0.17 - Symantec Corporation)
Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.7.0.24 - Symantec Corporation)
Norton Online Backup ARA (x32 Version: 4.3.0.14 - Symantec Corporation) Hidden
Norton PC Checkup (HKLM-x32\...\NortonPCCheckup) (Version: 2.0.18.16 - Symantec Corporation)
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.51.17865 - pdfforge GmbH)
PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Edit Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 View Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.1 - pdfforge)
Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.13 - Qualcomm Atheros Communications Inc.)
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.728.728.042813 - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6914 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0212 - )
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: 1.90 - Ghostgum Software Pty Ltd)
Revo Uninstaller 2.0.2 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.2 - VS Revo Group, Ltd.)
SCM (HKLM\...\{CA85D7A7-6B45-4011-9BCC-C01F31EDE157}) (Version: 14.013.07054 -  )
Shotcut (HKLM-x32\...\Shotcut) (Version:  - )
Skype™ 7.30 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.30.105 - Skype Technologies S.A.)
SoftMaker FreeOffice (HKLM-x32\...\{8EBB8452-274B-465D-8324-00B0832FBB02}) (Version: 1.0.3475 - SoftMaker Software GmbH)
Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.017 - MSI)
Sweepi 5.4.00 (HKLM-x32\...\Sweepi_is1) (Version: 5.4.00 - YooApplications)
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
Web Companion (HKLM-x32\...\{D5116390-5C95-4FEA-A719-78C3C8B5DFB5}_WebCompanion) (Version: 1.1.844.1586 - Lavasoft)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinZip 19.0 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E4}) (Version: 19.0.11293 - WinZip Computing, S.L. )

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {17608ADD-35B5-4F2A-A369-E67C96C0B20E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {2B68F8A1-F7BA-4699-885D-EAF51F2DBD90} - System32\Tasks\{551F8A14-3EE5-4B8B-83D3-D11EB5BC5F15} => pcalua.exe -a "C:\Program Files (x86)\FreePDF_XP\setup.exe" -d "C:\Program Files (x86)\Mozilla Firefox" -c C:\Users\Micha\AppData\Local\Temp\Paketschein-14.pdf <==== ACHTUNG
Task: {3CDF7212-D471-42F4-A121-ED4D70251682} - System32\Tasks\{7C15C6ED-AB8F-4479-AB67-B366BCA58406} => pcalua.exe -a "C:\Program Files (x86)\DriverUpdate\UninstallStub.exe" -c --log {a9888f42-bffe-4aca-ac10-51983972c2df}
Task: {3DA3586E-C068-4460-B103-15DDD7C51B40} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-10] (Adobe Systems Incorporated)
Task: {3E09C0A2-D6E6-407F-A239-AAAECEF79B78} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {3F283151-7529-496F-9366-FCAEC83C2694} - System32\Tasks\1215tbUpdateInfo => C:\ProgramData\Avg_Update_1215tb\1215tb_{4D479988-B227-4153-A15F-3D6D13E85735}.exe
Task: {58A9DC7B-AC64-4449-B51A-1CA3922D1961} - System32\Tasks\Norton Online Backup ARA => C:\Program Files (x86)\Norton Online Backup ARA\Engine\4.3.0.14\\Ara.exe [2013-08-27] (Symantec Corporation)
Task: {63050248-0821-4CF1-A0FA-3D7C370A627F} - System32\Tasks\{42239007-962A-405B-897B-E4E0207270AF} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.24.0.104&amp;LastError=404
Task: {96FEB751-76F6-4B79-B85A-B188D39EBB02} - System32\Tasks\{DDE7AD7B-E373-4700-9749-EFD63E11B429} => C:\Windows\twain_32\escndv\escndv.exe [2008-04-06] (SEIKO EPSON CORP.)
Task: {B2A759E8-D7A6-40F4-8583-1B21178BF297} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: {DF814115-C649-4F46-9705-DDBEC44F373C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {E499296A-F20A-4ACE-9CD0-242A1F09B9A3} - System32\Tasks\{129E23B6-40C3-4E2D-BA39-481FE58B2A62} => C:\Program Files\PDFCreator\PDFCreator.exe [2014-12-16] (pdfforge)
Task: {FB0D8A3E-E462-456A-A960-0E05DB4FE8BC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-01-09 01:19 - 2012-06-21 07:25 - 00113152 _____ () C:\windows\System32\redmon64.dll
2013-07-31 21:55 - 2013-04-26 00:32 - 00047104 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
2017-01-10 09:37 - 2016-12-14 12:55 - 02259232 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-01-10 09:37 - 2016-12-14 12:55 - 02813904 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll
2017-01-10 09:37 - 2016-12-14 12:55 - 02247632 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2013-07-31 21:55 - 2013-04-09 22:42 - 00265728 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\SkypePlugin.exe
2012-05-30 21:15 - 2012-05-30 21:15 - 00404008 _____ () C:\Program Files\Intel\TurboBoost\de\SignalIslandUi.resources.dll
2013-07-31 21:37 - 2013-02-16 00:15 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2017-01-10 16:17 - 2017-01-10 16:17 - 19762776 _____ () C:\windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1 - 192.168.0.2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [TCP Query User{F5428C65-02FD-4258-9D3B-DBA9131CD043}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{58EAA851-0F4D-4025-A9FA-82AAC4EEC077}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{FC62AAD4-D5DF-4232-B263-4FC654D0457F}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{9D370156-D01D-4231-A5C5-E72B2D7C382D}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{EB01AC34-1000-4725-AB7E-266EF7070BAE}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6AED153C-CE2F-4F79-A73D-5DA437D8EDD9}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4AE2CA5C-F80C-436A-B9FF-2E8E125414F6}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{4B1F3D68-AEF2-4EE3-A176-82754C956CCF}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{535793E5-DA7A-48C6-9675-333B3C13480E}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1A36325C-7D02-4CAE-968A-A8054B57A386}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{60005B18-84B8-4665-9D35-482C3A16A343}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{2FA7CE91-EAFF-49F9-B2DF-C5687CA4B179}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{72F59172-3120-434F-8648-B19F920FA80F}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{76C646E5-E59E-4079-91C6-6DB2955E5955}] => C:\Program Files (x86)\Skype\Phone\Skype.exe

==================== Wiederherstellungspunkte =========================

10-11-2016 06:10:16 Windows Update
26-11-2016 13:55:57 Geplanter Prüfpunkt
27-11-2016 17:27:32 Installed Windows Mobile-Gerätecenter
05-12-2016 20:53:37 AA11
09-12-2016 20:06:44 Removed Visual Studio 2012 x86 Redistributables
09-12-2016 20:08:07 Removed Visual Studio 2012 x64 Redistributables
15-12-2016 03:00:20 Windows Update
15-12-2016 19:14:17 AA11
16-12-2016 01:31:33 Windows Update
18-12-2016 11:42:27 Removed DriverUpdate
18-12-2016 11:45:52 Removed DriverUpdate
23-12-2016 16:08:55 Wiederherstellungsvorgang
23-12-2016 23:16:31 Windows Modules Installer
25-12-2016 00:00:28 Windows Update
03-01-2017 23:19:17 Wiederherstellungsvorgang
04-01-2017 01:02:43 Installed DRIVERfighter.
04-01-2017 02:23:30 Removed DriverUpdate
04-01-2017 09:36:49 Windows Update
04-01-2017 09:58:19 Windows Update
04-01-2017 10:00:56 Windows Update
04-01-2017 10:02:20 Windows Update
04-01-2017 10:26:13 Windows Update
04-01-2017 13:27:41 Removed DriverUpdate
04-01-2017 13:30:28 Removed CHIP Best Deal
04-01-2017 13:44:48 Konfiguriert Camera RAW Plug-In for EPSON Creativity Suite
04-01-2017 14:01:35 Driver Reviver (04/01/2017 14:01)
04-01-2017 17:31:04 Removed Skype™ 7.30
04-01-2017 18:18:15 Windows Update
05-01-2017 00:00:55 Windows Update
05-01-2017 00:41:14 Windows Update
05-01-2017 00:48:52 Windows Update
05-01-2017 00:54:51 Windows Update
10-01-2017 15:42:24 Installed DriverUpdate
10-01-2017 19:40:37 Windows Update
10-01-2017 19:45:26 Windows Update
10-01-2017 19:56:24 Windows Update
10-01-2017 19:58:33 Windows Update
10-01-2017 20:27:38 Windows Update
11-01-2017 00:00:21 Windows Update
11-01-2017 01:01:28 Wiederherstellungsvorgang
13-01-2017 12:14:21 AA11
13-01-2017 15:52:00 Malwarebytes Anti-Rootkit Restore Point
14-01-2017 18:11:18 JRT Pre-Junkware Removal
14-01-2017 18:26:46 JRT Pre-Junkware Removal
16-01-2017 12:41:07 Revo Uninstaller's restore point - QuickTime 7
16-01-2017 12:46:53 Revo Uninstaller's restore point - Panda Security Toolbar
16-01-2017 12:50:16 Revo Uninstaller's restore point - Mobile Partner
16-01-2017 13:03:08 Revo Uninstaller's restore point - McAfee Security Scan Plus
16-01-2017 13:06:34 Revo Uninstaller's restore point - OpenOffice 4.1.2
16-01-2017 13:37:14 Revo Uninstaller's restore point - Apple Application Support (32-Bit)
16-01-2017 14:06:03 Revo Uninstaller's restore point - Apple Application Support (32-Bit)
16-01-2017 14:10:54 Revo Uninstaller's restore point - Apple Application Support (64-Bit)
16-01-2017 14:13:17 Revo Uninstaller's restore point - Apple Software Update
16-01-2017 14:15:35 Revo Uninstaller's restore point - iCloud
16-01-2017 14:18:04 Revo Uninstaller's restore point - Bonjour
16-01-2017 14:18:25 Removed Bonjour
16-01-2017 14:19:56 Revo Uninstaller's restore point - iCloud
16-01-2017 15:15:12 Installed iCloud

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Microsoft-Teredo-Tunneling-Adapter
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (01/16/2017 12:41:06 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.


Vorgang:
  Generatordaten werden gesammelt

Kontext:
  Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
  Generatorname: System Writer
  Generatorinstanz-ID: {69345d75-ab26-4814-bf57-c7d8deb42e35}

Error: (01/16/2017 11:49:46 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 6911

Error: (01/16/2017 11:49:46 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 6911

Error: (01/16/2017 11:49:46 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/16/2017 11:49:45 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5835

Error: (01/16/2017 11:49:45 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5835

Error: (01/16/2017 11:49:45 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/16/2017 11:49:44 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4649

Error: (01/16/2017 11:49:44 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4649

Error: (01/16/2017 11:49:44 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


Systemfehler:
=============
Error: (01/16/2017 05:56:03 AM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: Dienst "WMPNetworkSvc" konnte nicht ordnungsgemäß gestartet werden, da ein Fehler "0x80004005" in "CoCreateInstance(CLSID_UPnPDeviceFinder)" aufgetreten ist. Überprüfen Sie, ob der Dienst "UPnPHost" ausgeführt wird und ob die Windows-Komponente "UPnPHost" richtig installiert ist.

Error: (01/16/2017 05:52:43 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎16.‎01.‎2017 um 05:45:23 unerwartet heruntergefahren.

Error: (01/15/2017 11:18:49 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst PCCUJobMgr erreicht.

Error: (01/14/2017 10:35:23 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.

Error: (01/14/2017 10:14:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde aufgrund folgenden Fehlers nicht gestartet:
Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden.

Error: (01/14/2017 10:14:32 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "WMPNetworkSvc" konnte sich nicht als "NT AUTHORITY\NetworkService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
Die Anforderung wird nicht unterstützt.


Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (01/14/2017 10:14:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet:
Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden.

Error: (01/14/2017 10:14:32 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "WSearch" konnte sich nicht als "NT AUTHORITY\SYSTEM" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
Die Anforderung wird nicht unterstützt.


Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (01/14/2017 10:14:28 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\windows\system32\Rtlihvs.dll

Error: (01/14/2017 10:14:02 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Software Protection" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.


==================== Speicherinformationen ===========================

Prozessor: Intel(R) Pentium(R) CPU 3560M @ 2.40GHz
Prozentuale Nutzung des RAM: 72%
Installierter physikalischer RAM: 4016.81 MB
Verfügbarer physikalischer RAM: 1089.51 MB
Summe virtueller Speicher: 8031.8 MB
Verfügbarer virtueller Speicher: 4898.44 MB

==================== Laufwerke ================================

Drive c: (OS_Install) (Fixed) (Total:272.65 GB) (Free:89.33 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive d: (Data) (Fixed) (Total:181.77 GB) (Free:181.63 GB) NTFS
Drive w: (BIOS_RVY) (Fixed) (Total:11.24 GB) (Free:0.28 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C54CB572)
Partition 1: (Not Active) - (Size=11.2 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=27)
Partition 3: (Not Active) - (Size=272.7 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=181.8 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-01-2017
durchgeführt von Micha (Administrator) auf MICHA-MSI (16-01-2017 15:19:47)
Gestartet von C:\Users\Micha\Desktop
Geladene Profile: Micha (Verfügbare Profile: Micha & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\AvrcpService.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Microsoft Corporation) C:\Windows\System32\CISVC.EXE
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(MSI) C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe
(Visicom Media Inc.) C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe
(PLUMBYTES) C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\AmwService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\ws.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\creator-ws.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\RtkBleServ.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Symantec Corporation) C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\SkypePlugin.exe
(MSI) C:\Program Files (x86)\SCM\Radio Manager.exe
(MSI) C:\Program Files (x86)\SCM\SCM.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(© 2015 Microsoft Corporation) C:\Users\Micha\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\SymcPCCULaunchSvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_24_0_0_194.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_24_0_0_194.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(VS Revo Group) C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe

==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13538376 2013-05-21] (Realtek Semiconductor)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [253440 2013-04-23] (Realtek Semiconductor Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2875728 2013-03-04] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2013-07-05] (MSI)
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [399528 2013-07-05] (MSI)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [Windows Mobile-based device management] => C:\windows\WindowsMobile\wmdcBase.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-10-13] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [230696 2011-10-13] (CyberLink Corp.)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [490480 2013-02-01] (MSI)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2014-03-18] (shbox.de)
HKLM-x32\...\Run: [APSDaemon] => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series (Kopie 1)] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series (Kopie 2)] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [BingSvc] => C:\Users\Micha\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27230168 2016-11-15] (Skype Technologies S.A.)
HKU\S-1-5-18\...\Run: [EPSON SX100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-18\...\RunOnce: [panda] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f
HKU\S-1-5-18\...\RunOnce: [panda_XP] => reg.exe delete "HKCU\Software\panda" /f
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Keine Datei
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop(777).ini [2009-07-14] ()
Startup: C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.6.lnk [2013-07-31]
ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.6.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2
Tcpip\..\Interfaces\{19590355-955C-4F75-9574-A5178867FB8F}: [DhcpNameServer] 192.168.0.1 192.168.0.2
Tcpip\..\Interfaces\{7AFF0EF0-F8B5-4E22-BED7-5BAC51243C58}: [NameServer] 193.189.244.206 193.189.244.225

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.n-tv.de/
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {2BA0719B-B10C-4176-8BB1-AF2B6E7453E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAM3&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {2BA0719B-B10C-4176-8BB1-AF2B6E7453E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAM3&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={18DC9A1B-75F8-4C91-A21F-328A8F8FCFB0}&mid=2f112f36b90e47cd86aa856e587a95e0-b67d740e056757739f071bdf1b00435729c4d0a4&lang=de&ds=AVG&coid=avgtbavg&cmpid=1016tb&pr=fr&d=2015-01-05 13:55:51&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={18DC9A1B-75F8-4C91-A21F-328A8F8FCFB0}&mid=2f112f36b90e47cd86aa856e587a95e0-b67d740e056757739f071bdf1b00435729c4d0a4&lang=de&ds=AVG&coid=avgtbavg&cmpid=1016tb&pr=fr&d=2015-01-05 13:55:51&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll => Keine Datei
BHO-x32: PDF Architect Helper -> {691B33B0-B86E-47F3-81C7-56E4FE3B929C} -> C:\Program Files (x86)\PDF Architect 2\creator-ie-helper.dll [2014-10-10] (pdfforge GmbH)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
Toolbar: HKLM-x32 - Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - C:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH)

FireFox:
========
FF ProfilePath: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 [2017-01-16]
FF NewTab: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> hxxp://www.n-tv.de/
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> Google
FF Homepage: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> hxxp://www.n-tv.de/
FF Extension: (Test Pilot) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\@testpilot-addon.xpi [2017-01-11]
FF Extension: (GMX MailCheck) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\browser-mailcheck@gmx.net [2016-11-23]
FF Extension: (Awesome Screenshot - Capture, Annotate & More) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2017-01-10]
FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: (PDF Architect 2 Creator) - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2015-01-20] [ist nicht signiert]
FF HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\jsjjbqd4.default\extensions\cliqz@cliqz.com => nicht gefunden
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\pandasecuritytb.xml [2015-05-27]
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-10] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-10] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-02-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-02-16] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll [2014-10-10] (pdfforge GmbH)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=de-de
CHR DefaultSearchURL: Default -> hxxp://pandasecurity.mystart.com/results.php?searchsource=omnibar&pr=vmn&id=pandasecuritytb&v=2_3&ent=ds_671&q={searchTerms}
CHR DefaultSearchKeyword: Default -> yahoo
CHR Profile: C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default [2017-01-15]
CHR Extension: (Google Präsentationen) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-01-15]
CHR Extension: (Google Docs) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-15]
CHR Extension: (Google Drive) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-15]
CHR Extension: (YouTube) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-15]
CHR Extension: (Adobe Acrobat) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-15]
CHR Extension: (Yahoo!) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdhbkaahephniejapepaiggngjnedpci [2017-01-15]
CHR Extension: (Google Tabellen) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-01-15]
CHR Extension: (MSN Homepage) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkcgfbgohboipdhliafmacjnhjbhmim [2017-01-15]
CHR Extension: (Google Docs Offline) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-15]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-15]
CHR Extension: (Google Mail) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-15]
CHR Extension: (Chrome Media Router) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-15]
CHR HKU\S-1-5-21-2198626584-3468660724-23365673-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fkkcgfbgohboipdhliafmacjnhjbhmim] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fdhbkaahephniejapepaiggngjnedpci] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AvrcpService; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe [35328 2013-04-02] (Realtek Semiconductor Corporation) [Datei ist nicht signiert]
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [47104 2013-04-26] () [Datei ist nicht signiert]
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [Datei ist nicht signiert]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [Datei ist nicht signiert]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-02-16] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes)
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2013-07-05] (Micro-Star International Co., Ltd.) [Datei ist nicht signiert]
R2 MSI Foundation Service; C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe [12800 2010-07-17] (MSI) [Datei ist nicht signiert]
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [143856 2013-02-01] (MSI)
R2 NAT; C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe [143928 2012-08-19] (Symantec Corporation)
S3 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4230016 2013-01-28] (Symantec Corporation)
R2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\SymcPCCULaunchSvc.exe [123320 2012-08-13] (Symantec Corporation)
R2 panda_url_filtering; C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe [287752 2015-10-02] (Visicom Media Inc.)
R2 pbamw_service; C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\AmwService.exe [125712 2016-11-08] (PLUMBYTES)
R2 PCCUJobMgr; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe [126392 2012-08-13] (Symantec Corporation)
R2 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1771560 2014-10-10] (pdfforge GmbH)
R2 PDF Architect 2 Creator; C:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
R2 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-10-10] (pdfforge GmbH)
R2 RtkBleServ; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\RtkBleServ.exe [42496 2013-04-26] (Realtek Semiconductor Corporation) [Datei ist nicht signiert]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 McComponentHostService; "C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe" [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ccSet_NARA; C:\windows\system32\drivers\NARAx64\0403000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
S3 ccSet_NAT; C:\windows\system32\drivers\NATx64\0106000.011\ccSetx64.sys [168096 2012-08-07] (Symantec Corporation)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [77416 2016-12-14] ()
S3 ewusbnet; C:\windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
R0 iaStorF; C:\windows\System32\drivers\iaStorF.sys [28656 2013-03-22] (Intel Corporation)
R3 L1C; C:\windows\System32\DRIVERS\L1C62x64.sys [118504 2013-05-07] (Qualcomm Atheros Co., Ltd.)
R2 MBAMChameleon; C:\windows\system32\drivers\MBAMChameleon.sys [176064 2017-01-10] (Malwarebytes)
R3 MBAMFarflt; C:\windows\system32\drivers\farflt.sys [102856 2017-01-16] (Malwarebytes)
R3 MBAMProtection; C:\windows\system32\drivers\mbam.sys [43968 2017-01-16] (Malwarebytes)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [250816 2017-01-16] (Malwarebytes)
R3 MBAMWebProtection; C:\windows\system32\drivers\mwac.sys [81696 2017-01-16] (Malwarebytes)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-26] (MSI)
R3 panda_url_filteringd; C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys [51288 2014-03-19] (Visicom Media Inc.)
S3 RtkAvrcp; C:\windows\system32\drivers\RtkAvrcp.sys [61152 2012-12-27] (Realtek Semiconductor Corporation)
S3 RtkAvrcpCtrlr; C:\windows\system32\drivers\RtkAvrcpCtrlr.sys [66376 2013-04-08] (Realtek Semiconductor Corporation)
R3 RtkBtFilter; C:\windows\System32\DRIVERS\RtkBtfilter.sys [535624 2013-03-28] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\windows\System32\DRIVERS\rtwlane.sys [1514568 2013-05-02] (Realtek Semiconductor Corporation                          )
S3 MGHwCtrl; \??\C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-01-16 15:19 - 2017-01-16 15:20 - 00024516 _____ C:\Users\Micha\Desktop\FRST.txt
2017-01-16 12:29 - 2017-01-16 14:05 - 00001004 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2017-01-16 12:29 - 2017-01-16 14:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2017-01-16 12:29 - 2017-01-16 12:29 - 00000000 ____D C:\Program Files\VS Revo Group
2017-01-16 12:27 - 2017-01-16 12:27 - 07097928 _____ (VS Revo Group ) C:\Users\Micha\Desktop\revo202setup.exe
2017-01-15 17:46 - 2017-01-15 17:46 - 00032851 _____ C:\Users\Micha\Downloads\Addition01152017.txt
2017-01-15 14:42 - 2017-01-15 14:42 - 00000000 ____D C:\Users\Micha\Downloads\FRST-OlderVersion
2017-01-15 12:09 - 2017-01-15 13:43 - 00001729 _____ C:\Users\Micha\Desktop\AdwCleaner[S3].txt
2017-01-14 22:09 - 2017-01-14 22:09 - 00019431 _____ C:\Users\Micha\Desktop\AdwCleaner[C0].txt
2017-01-14 20:02 - 2017-01-14 19:16 - 00018180 _____ C:\Users\Micha\Desktop\AdwCleaner[S0].txt
2017-01-14 18:21 - 2017-01-14 18:21 - 00000268 _____ C:\Users\Micha\Desktop\Junkware Removal Tool - Download - Filepony.URL
2017-01-14 18:19 - 2017-01-14 18:19 - 01663040 _____ (Malwarebytes) C:\Users\Micha\Downloads\JRT(1).exe
2017-01-14 18:15 - 2017-01-14 18:30 - 00000696 _____ C:\Users\Micha\Desktop\JRT.txt
2017-01-14 18:10 - 2017-01-14 18:10 - 01663040 _____ (Malwarebytes) C:\Users\Micha\Downloads\JRT.exe
2017-01-14 18:06 - 2017-01-14 18:06 - 00017147 _____ C:\Users\Micha\Desktop\w2WQUGsI.htm
2017-01-14 17:40 - 2017-01-14 22:20 - 00000000 ____D C:\AdwCleaner
2017-01-14 17:37 - 2017-01-14 17:37 - 03988944 _____ C:\Users\Micha\Desktop\AdwCleaner_6.042.exe
2017-01-13 21:12 - 2017-01-13 22:37 - 00222352 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_21.12.52_log.txt
2017-01-13 21:09 - 2017-01-13 21:12 - 00219050 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_21.09.19_log.txt
2017-01-13 21:04 - 2017-01-13 21:05 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Micha\Downloads\tdsskiller(1).exe
2017-01-13 17:15 - 2017-01-13 17:29 - 00219050 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_17.15.21_log.txt
2017-01-13 17:09 - 2017-01-13 17:12 - 00219050 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_17.09.39_log.txt
2017-01-13 17:07 - 2017-01-13 17:07 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Micha\Desktop\tdsskiller.exe
2017-01-13 15:23 - 2017-01-14 22:06 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-01-13 15:17 - 2017-01-13 16:56 - 00000000 ____D C:\Users\Micha\Desktop\mbar
2017-01-13 15:07 - 2017-01-13 15:08 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Micha\Desktop\mbar-1.09.3.1001.exe
2017-01-13 08:17 - 2017-01-13 08:17 - 00000000 ____D C:\Users\Micha\Documents\MAGIX Downloads
2017-01-12 23:06 - 2017-01-13 11:42 - 00000000 ____D C:\Users\Micha\Desktop\Trboard
2017-01-12 10:56 - 2017-01-12 10:57 - 00084152 _____ C:\Users\Micha\Downloads\Addition .txt
2017-01-10 20:59 - 2017-01-05 19:55 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2017-01-10 20:59 - 2017-01-05 19:55 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2017-01-10 20:59 - 2017-01-05 19:52 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2017-01-10 20:59 - 2017-01-05 18:42 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2017-01-10 20:59 - 2017-01-05 18:32 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2017-01-10 20:59 - 2017-01-05 18:25 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2017-01-10 20:59 - 2017-01-05 18:23 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2017-01-10 20:59 - 2017-01-05 18:19 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2017-01-10 20:56 - 2017-01-10 20:56 - 00083124 _____ C:\Users\Micha\Downloads\FRST01102017.txt
2017-01-10 20:55 - 2017-01-10 20:55 - 00041706 _____ C:\Users\Micha\Downloads\Addition01102017.txt
2017-01-10 16:22 - 2017-01-10 16:22 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Vorlagen
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Startmenü
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Netzwerkumgebung
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Lokale Einstellungen
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Eigene Dateien
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Druckumgebung
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Videos
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Musik
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Bilder
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Verlauf
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Anwendungsdaten
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Anwendungsdaten
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 ____D C:\Users\DefaultAppPool
2017-01-10 16:22 - 2016-11-30 06:27 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\AVG
2017-01-10 16:22 - 2013-07-31 22:25 - 00002110 _____ C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
2017-01-10 16:22 - 2013-07-31 19:31 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\Media Center Programs
2017-01-10 09:38 - 2017-01-10 09:38 - 00176064 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMChameleon.sys
2017-01-10 09:37 - 2017-01-16 15:03 - 00081696 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2017-01-10 09:37 - 2017-01-16 08:54 - 00102856 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2017-01-10 09:37 - 2017-01-16 08:53 - 00250816 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-10 09:37 - 2017-01-16 08:53 - 00043968 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2017-01-10 09:37 - 2017-01-10 09:37 - 00001837 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-01-10 09:37 - 2017-01-10 09:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-01-10 09:37 - 2017-01-10 09:37 - 00000000 ____D C:\Program Files\Malwarebytes
2017-01-10 09:37 - 2016-12-14 12:55 - 00077416 _____ C:\windows\system32\Drivers\mbae64.sys
2017-01-10 09:35 - 2017-01-10 09:36 - 54199488 _____ (Malwarebytes ) C:\Users\Micha\Downloads\mb3-setup-consumer-3.0.5.1299(1).exe
2017-01-10 08:39 - 2017-01-10 08:39 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plumbytes Anti-Malware
2017-01-10 08:39 - 2017-01-10 08:39 - 00000000 ____D C:\Program Files\Plumbytes Software
2017-01-09 15:57 - 2017-01-15 17:44 - 00032848 _____ C:\Users\Micha\Downloads\Addition.txt
2017-01-09 15:55 - 2017-01-16 15:19 - 00000000 ____D C:\FRST
2017-01-09 15:55 - 2017-01-15 17:44 - 00051050 _____ C:\Users\Micha\Downloads\FRST.txt
2017-01-09 15:54 - 2017-01-15 14:42 - 02419200 _____ (Farbar) C:\Users\Micha\Desktop\FRST64.exe
2017-01-05 20:02 - 2017-01-05 20:02 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk
2017-01-05 20:02 - 2017-01-05 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-01-05 00:41 - 2015-07-16 20:12 - 06131200 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2017-01-05 00:41 - 2015-07-16 20:12 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2017-01-05 00:41 - 2015-07-16 20:12 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 07077376 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 01057792 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2017-01-05 00:41 - 2015-07-11 14:15 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2017-01-04 19:30 - 2015-12-20 19:50 - 03180544 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2017-01-04 19:30 - 2015-12-20 19:50 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2017-01-04 19:30 - 2015-12-20 15:08 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2017-01-04 19:29 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2017-01-04 15:08 - 2017-01-04 15:08 - 54199488 _____ (Malwarebytes ) C:\Users\Micha\Downloads\mb3-setup-consumer-3.0.5.1299.exe
2017-01-04 13:53 - 2017-01-04 13:53 - 13425152 _____ (ReviverSoft) C:\Users\Micha\Downloads\DriverReviverSetup_ppc(2).exe
2017-01-04 10:30 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2017-01-04 10:30 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2017-01-04 10:30 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2017-01-04 10:30 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2017-01-04 10:30 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2017-01-04 10:30 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2017-01-04 10:30 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2017-01-04 10:30 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2017-01-04 10:30 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2017-01-04 10:30 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2017-01-04 10:28 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2017-01-04 10:28 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbGD.sys
2017-01-04 10:28 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2017-01-04 10:28 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2017-01-04 10:25 - 2015-08-05 18:56 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\icaapi.dll
2017-01-04 10:25 - 2015-08-05 18:06 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2017-01-04 09:59 - 2017-01-04 09:59 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ICCWDT_01009.Wdf
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\kbdgeoqw.dll
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZEL.DLL
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZE.DLL
2017-01-04 09:25 - 2015-12-16 19:48 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZE.DLL
2017-01-04 09:25 - 2015-12-16 19:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\kbdgeoqw.dll
2017-01-04 09:25 - 2015-12-16 19:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZEL.DLL
2017-01-04 02:04 - 2017-01-04 02:04 - 03279864 _____ (SPAMfighter ApS) C:\Users\Micha\Downloads\DRIVERfighter_Web(1).exe
2017-01-04 01:03 - 2017-01-04 01:04 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Fighters
2017-01-04 01:02 - 2017-01-04 02:18 - 00000000 ____D C:\ProgramData\Fighters
2017-01-04 01:00 - 2017-01-04 01:01 - 03279864 _____ (SPAMfighter ApS) C:\Users\Micha\Downloads\DRIVERfighter_Web.exe
2017-01-04 00:54 - 2017-01-04 00:55 - 13425152 _____ (ReviverSoft) C:\Users\Micha\Downloads\DriverReviverSetup_ppc(1).exe
2016-12-30 10:41 - 2016-12-30 10:41 - 00178564 _____ C:\Users\Micha\Downloads\HERMES_label_2016-12-30_10_40_52.pdf
2016-12-30 10:35 - 2016-12-30 10:35 - 00178968 _____ C:\Users\Micha\Downloads\HERMES_label_2016-12-30_10_33_49.pdf
2016-12-24 23:14 - 2016-12-24 23:14 - 00025199 _____ C:\Users\Micha\Documents\freelancer200855.vcf
2016-12-24 10:33 - 2012-06-01 06:39 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\wamregps.dll
2016-12-24 10:33 - 2012-06-01 06:36 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\iisRtl.dll
2016-12-24 10:33 - 2012-06-01 06:36 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\iisrstap.dll
2016-12-24 10:33 - 2012-06-01 06:35 - 00060928 _____ (Microsoft Corporation) C:\windows\system32\ahadmin.dll
2016-12-24 10:33 - 2012-06-01 06:34 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\admwprox.dll
2016-12-24 10:33 - 2012-06-01 06:33 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\iisreset.exe
2016-12-24 10:33 - 2012-06-01 05:40 - 00010752 _____ (Microsoft Corporation) C:\windows\SysWOW64\wamregps.dll
2016-12-24 10:33 - 2012-06-01 05:37 - 00154624 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisRtl.dll
2016-12-24 10:33 - 2012-06-01 05:37 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisrstap.dll
2016-12-24 10:33 - 2012-06-01 05:35 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\admwprox.dll
2016-12-24 10:33 - 2012-06-01 05:35 - 00026624 _____ (Microsoft Corporation) C:\windows\SysWOW64\ahadmin.dll
2016-12-24 10:33 - 2012-06-01 05:34 - 00015360 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisreset.exe
2016-12-24 02:30 - 2017-01-15 00:36 - 03052850 ____H C:\Users\Micha\AppData\Local\IconCache.db
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\windows\SysWOW64\BestPractices
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\windows\system32\BestPractices
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\inetpub
2016-12-23 17:25 - 2016-12-23 17:25 - 43886552 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\SkypeSetupFull(2).exe
2016-12-23 17:25 - 2016-12-23 17:25 - 00003142 _____ C:\windows\System32\Tasks\{42239007-962A-405B-897B-E4E0207270AF}
2016-12-23 17:23 - 2016-12-23 17:24 - 01463424 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\skypesetup.exe
2016-12-23 16:13 - 2017-01-03 14:27 - 00524288 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TMContainer00000000000000000001.regtrans-ms
2016-12-23 16:13 - 2017-01-03 14:27 - 00065536 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TM.blf
2016-12-23 16:13 - 2016-12-23 16:17 - 00524288 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 15:52 - 2016-12-23 15:52 - 00000000 __SHD C:\found.000
2016-12-18 14:28 - 2016-12-18 14:28 - 00000000 ____D C:\Users\Micha\Tracing
2016-12-18 14:25 - 2016-12-18 14:25 - 43872728 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\SkypeSetupFull(1).exe
2016-12-18 14:20 - 2016-12-18 14:20 - 43878872 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\SkypeSetupFull.exe
2016-12-18 14:12 - 2017-01-16 15:06 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Skype
2016-12-18 14:12 - 2016-12-18 14:28 - 00000000 ____D C:\Users\Micha\AppData\Local\Skype
2016-12-18 11:45 - 2016-12-18 11:45 - 00003202 _____ C:\windows\System32\Tasks\{7C15C6ED-AB8F-4479-AB67-B366BCA58406}

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-01-16 15:17 - 2014-12-14 15:17 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2017-01-16 14:20 - 2016-12-07 22:28 - 00000000 ____D C:\Program Files\Common Files\Apple
2017-01-16 14:20 - 2014-12-27 00:03 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Apple Computer
2017-01-16 14:10 - 2014-12-27 00:00 - 00000000 ____D C:\ProgramData\Apple
2017-01-16 13:02 - 2015-05-27 15:08 - 00000000 ____D C:\ProgramData\panda_url_filtering
2017-01-16 12:45 - 2014-12-27 00:04 - 00000000 ____D C:\Users\Micha\AppData\Local\Apple Computer
2017-01-16 09:02 - 2009-07-14 05:45 - 00024432 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-16 09:02 - 2009-07-14 05:45 - 00024432 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-16 08:58 - 2016-11-22 11:54 - 00000000 ____D C:\Users\Micha\AppData\LocalLow\Mozilla
2017-01-16 08:53 - 2015-02-27 20:57 - 00000000 ____D C:\Users\Micha\AppData\Local\FreePDF_XP
2017-01-16 08:52 - 2013-07-31 21:55 - 00000000 ____D C:\ProgramData\Realtek
2017-01-16 08:52 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-01-15 09:05 - 2014-12-19 22:43 - 00000000 ____D C:\Users\Micha\Documents\Youcam
2017-01-14 22:04 - 2015-01-05 13:28 - 00000000 ____D C:\Program Files (x86)\Lavasoft
2017-01-14 22:04 - 2015-01-05 13:24 - 00000000 ____D C:\ProgramData\Lavasoft
2017-01-14 18:12 - 2015-01-05 13:26 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Lavasoft
2017-01-13 15:52 - 2015-01-02 10:15 - 00000000 ____D C:\Users\Micha\AppData\Roaming\DesktopIconAmazon
2017-01-13 15:23 - 2016-11-06 01:54 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-01-13 12:30 - 2015-07-24 19:26 - 00000000 ____D C:\Program Files (x86)\360
2017-01-13 12:16 - 2015-01-05 13:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2017-01-13 08:17 - 2014-12-14 00:10 - 00000000 ____D C:\Users\Micha\Documents\MAGIX_MusicMaker16_Download-Version
2017-01-11 21:01 - 2014-12-19 21:37 - 00010240 _____ C:\Users\Micha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-01-11 12:42 - 2015-07-15 11:33 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-11 12:40 - 2015-01-21 09:55 - 00004476 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2017-01-11 01:25 - 2009-07-14 06:08 - 00032640 _____ C:\windows\Tasks\SCHEDLGU.TXT
2017-01-11 00:03 - 2014-12-14 16:17 - 00000000 ____D C:\windows\system32\MRT
2017-01-11 00:02 - 2014-12-20 03:20 - 135657872 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2017-01-10 16:17 - 2014-12-14 15:17 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2017-01-10 16:17 - 2014-12-14 15:17 - 00000000 ____D C:\windows\system32\Macromed
2017-01-10 16:17 - 2013-07-31 22:22 - 00802904 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2017-01-10 16:17 - 2013-07-31 22:22 - 00144472 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-01-10 16:17 - 2013-07-31 22:22 - 00000000 ____D C:\windows\SysWOW64\Macromed
2017-01-09 15:53 - 2015-09-21 09:06 - 00000000 __SHD C:\$360Section
2017-01-09 15:53 - 2015-09-02 15:13 - 00000000 ____D C:\ProgramData\360Quarant
2017-01-05 20:02 - 2013-07-31 22:29 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-01-05 20:02 - 2013-07-31 22:28 - 00000000 ____D C:\ProgramData\Skype
2017-01-04 13:31 - 2014-12-14 15:54 - 00000000 ____D C:\Program Files (x86)\chip
2017-01-04 10:35 - 2009-07-14 05:45 - 00313104 _____ C:\windows\system32\FNTCACHE.DAT
2017-01-04 10:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\PolicyDefinitions
2017-01-04 10:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\inf
2017-01-04 10:31 - 2013-07-31 21:39 - 01687534 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2017-01-04 10:31 - 2013-07-31 19:42 - 00738178 _____ C:\windows\system32\perfh007.dat
2017-01-04 10:31 - 2013-07-31 19:42 - 00160894 _____ C:\windows\system32\perfc007.dat
2017-01-04 10:31 - 2009-07-14 06:13 - 01687534 _____ C:\windows\system32\PerfStringBackup.INI
2017-01-04 10:31 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\inetsrv
2017-01-04 09:47 - 2016-06-30 15:21 - 00000000 ____D C:\Users\Micha\AppData\Local\ElevatedDiagnostics
2017-01-04 02:21 - 2014-12-14 00:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2017-01-04 02:05 - 2009-07-14 03:34 - 00000568 _____ C:\windows\win.ini
2017-01-03 17:08 - 2015-09-24 19:26 - 00000356 _____ C:\Users\Micha\Desktop\Zitate.txt
2016-12-28 22:36 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\migration
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\inetsrv
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\migration
2016-12-24 20:13 - 2009-07-14 04:18 - 00000000 __SHD C:\$Recycle.Bin
2016-12-24 00:58 - 2014-12-31 14:21 - 00000000 ____D C:\ProgramData\Freemake
2016-12-24 00:58 - 2014-12-31 14:21 - 00000000 ____D C:\Program Files (x86)\Freemake
2016-12-24 00:00 - 2009-07-14 04:20 - 00000000 ____D C:\windows\Microsoft.NET
2016-12-23 23:52 - 2014-12-14 00:06 - 00000000 ___RD C:\Users\Micha\Videos
2016-12-23 23:20 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2016-12-23 23:18 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-12-23 23:18 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Microsoft Games
2016-12-23 23:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\Drivers\etc
2016-12-23 23:18 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-12-23 19:30 - 2009-07-14 04:20 - 00000000 ____D C:\windows\AppPatch
2016-12-23 15:29 - 2016-11-02 17:00 - 00524288 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 15:29 - 2016-11-02 17:00 - 00065536 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TM.blf
2016-12-23 15:02 - 2016-11-02 17:00 - 00524288 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TMContainer00000000000000000001.regtrans-ms
2016-12-18 14:28 - 2014-12-14 00:06 - 00000000 ____D C:\Users\Micha\AppData\Local\Microsoft
2016-12-18 14:28 - 2014-12-14 00:06 - 00000000 ____D C:\Users\Micha
2016-12-18 12:19 - 2014-12-14 00:07 - 00072008 _____ C:\Users\Micha\AppData\Local\GDIPFONTCACHEV1.DAT
2016-12-18 12:13 - 2015-05-27 15:05 - 00000000 ____D C:\Program Files (x86)\Panda Security
2016-12-18 12:07 - 2015-05-27 15:03 - 00000000 ____D C:\ProgramData\Panda Security
2016-12-18 12:06 - 2015-05-27 15:06 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Panda Security
2016-12-18 01:40 - 2014-12-14 00:06 - 00000000 ___RD C:\Users\Micha\Pictures
2016-12-17 01:20 - 2014-12-21 14:52 - 00003542 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-12-17 01:20 - 2014-12-21 14:52 - 00003414 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2014-09-01 09:18 - 2014-09-01 09:18 - 0001248 _____ () C:\Users\Micha\AppData\Roaming\FODX
2014-12-14 00:06 - 2017-01-16 12:03 - 0097470 _____ () C:\Users\Micha\AppData\Local\BTServer.log
2014-12-19 21:37 - 2017-01-11 21:01 - 0010240 _____ () C:\Users\Micha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Einige Dateien in TEMP:
====================
C:\Users\Micha\AppData\Local\Temp\DllMonoCtrl.dll


==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert

LastRegBack: 2017-01-03 14:36

==================== Ende von FRST.txt ============================

Hoffe es fehlt nichts, bin etwas verwirrt, Sch... MS
Gruß MS-Micha

cosinus 16.01.2017 15:39

FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Keine Datei
Toolbar: HKLM-x32 - Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
CHR DefaultSearchURL: Default -> http://pandasecurity.mystart.com/results.php?searchsource=omnibar&pr=vmn&id=pandasecuritytb&v=2_3&ent=ds_671&q={searchTerms}
Task: {3E09C0A2-D6E6-407F-A239-AAAECEF79B78} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
C:\Program Files (x86)\AVG
Task: {3CDF7212-D471-42F4-A121-ED4D70251682} - System32\Tasks\{7C15C6ED-AB8F-4479-AB67-B366BCA58406} => pcalua.exe -a "C:\Program Files (x86)\DriverUpdate\UninstallStub.exe" -c --log {a9888f42-bffe-4aca-ac10-51983972c2df}
Task: {2B68F8A1-F7BA-4699-885D-EAF51F2DBD90} - System32\Tasks\{551F8A14-3EE5-4B8B-83D3-D11EB5BC5F15} => pcalua.exe -a "C:\Program Files (x86)\FreePDF_XP\setup.exe" -d "C:\Program Files (x86)\Mozilla Firefox" -c C:\Users\Micha\AppData\Local\Temp\Paketschein-14.pdf <==== ACHTUNG
emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


milkit54 16.01.2017 21:49

sorry cosinus, der erste mailversuch ging daneben, jetzt noch einmal
Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-01-2017
durchgeführt von Micha (16-01-2017 16:41:22) Run:1
Gestartet von C:\Users\Micha\Downloads
Geladene Profile: Micha (Verfügbare Profile: Micha & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Keine Datei
Toolbar: HKLM-x32 - Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
CHR DefaultSearchURL: Default -> hxxp://pandasecurity.mystart.com/results.php?searchsource=omnibar&pr=vmn&id=pandasecuritytb&v=2_3&ent=ds_671&q={searchTerms}
Task: {3E09C0A2-D6E6-407F-A239-AAAECEF79B78} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
C:\Program Files (x86)\AVG
Task: {3CDF7212-D471-42F4-A121-ED4D70251682} - System32\Tasks\{7C15C6ED-AB8F-4479-AB67-B366BCA58406} => pcalua.exe -a "C:\Program Files (x86)\DriverUpdate\UninstallStub.exe" -c --log {a9888f42-bffe-4aca-ac10-51983972c2df}
Task: {2B68F8A1-F7BA-4699-885D-EAF51F2DBD90} - System32\Tasks\{551F8A14-3EE5-4B8B-83D3-D11EB5BC5F15} => pcalua.exe -a "C:\Program Files (x86)\FreePDF_XP\setup.exe" -d "C:\Program Files (x86)\Mozilla Firefox" -c C:\Users\Micha\AppData\Local\Temp\Paketschein-14.pdf <==== ACHTUNG
emptytemp:
       
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => Schlüssel erfolgreich entfernt
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Schlüssel nicht gefunden.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Wert erfolgreich entfernt
HKCR\Wow6432Node\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Schlüssel nicht gefunden.
Chrome DefaultSearchURL => erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3E09C0A2-D6E6-407F-A239-AAAECEF79B78} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E09C0A2-D6E6-407F-A239-AAAECEF79B78} => Schlüssel erfolgreich entfernt
C:\windows\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => erfolgreich verschoben
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVGPCTuneUp_Task_BkGndMaintenance => Schlüssel erfolgreich entfernt
C:\Program Files (x86)\AVG => erfolgreich verschoben
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3CDF7212-D471-42F4-A121-ED4D70251682} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3CDF7212-D471-42F4-A121-ED4D70251682} => Schlüssel erfolgreich entfernt
C:\windows\System32\Tasks\{7C15C6ED-AB8F-4479-AB67-B366BCA58406} => erfolgreich verschoben
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7C15C6ED-AB8F-4479-AB67-B366BCA58406} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2B68F8A1-F7BA-4699-885D-EAF51F2DBD90} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B68F8A1-F7BA-4699-885D-EAF51F2DBD90} => Schlüssel erfolgreich entfernt
C:\windows\System32\Tasks\{551F8A14-3EE5-4B8B-83D3-D11EB5BC5F15} => erfolgreich verschoben
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{551F8A14-3EE5-4B8B-83D3-D11EB5BC5F15} => Schlüssel erfolgreich entfernt

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 13011444 B
Java, Flash, Steam htmlcache => 127920 B
Windows/system/drivers => 4731347 B
Edge => 0 B
Chrome => 15950036 B
Firefox => 371449959 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 58535568 B
systemprofile32 => 908949953 B
LocalService => 0 B
NetworkService => 0 B
Micha => 18664995 B
DefaultAppPool => 0 B

RecycleBin => 16501862 B
EmptyTemp: => 1.3 GB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 16:42:21 ====

Hallo Cosinus,
bin wahrscheinlich lästig, aber ich glaube es muss mal funktionieren. Hoffe du hast es jetzt nicht doppelt bekommen
Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-01-2017
durchgeführt von Micha (16-01-2017 16:41:22) Run:1
Gestartet von C:\Users\Micha\Downloads
Geladene Profile: Micha (Verfügbare Profile: Micha & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Keine Datei
Toolbar: HKLM-x32 - Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  Keine Datei
CHR DefaultSearchURL: Default -> hxxp://pandasecurity.mystart.com/results.php?searchsource=omnibar&pr=vmn&id=pandasecuritytb&v=2_3&ent=ds_671&q={searchTerms}
Task: {3E09C0A2-D6E6-407F-A239-AAAECEF79B78} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
C:\Program Files (x86)\AVG
Task: {3CDF7212-D471-42F4-A121-ED4D70251682} - System32\Tasks\{7C15C6ED-AB8F-4479-AB67-B366BCA58406} => pcalua.exe -a "C:\Program Files (x86)\DriverUpdate\UninstallStub.exe" -c --log {a9888f42-bffe-4aca-ac10-51983972c2df}
Task: {2B68F8A1-F7BA-4699-885D-EAF51F2DBD90} - System32\Tasks\{551F8A14-3EE5-4B8B-83D3-D11EB5BC5F15} => pcalua.exe -a "C:\Program Files (x86)\FreePDF_XP\setup.exe" -d "C:\Program Files (x86)\Mozilla Firefox" -c C:\Users\Micha\AppData\Local\Temp\Paketschein-14.pdf <==== ACHTUNG
emptytemp:
       
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => Schlüssel erfolgreich entfernt
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Schlüssel nicht gefunden.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Wert erfolgreich entfernt
HKCR\Wow6432Node\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Schlüssel nicht gefunden.
Chrome DefaultSearchURL => erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3E09C0A2-D6E6-407F-A239-AAAECEF79B78} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E09C0A2-D6E6-407F-A239-AAAECEF79B78} => Schlüssel erfolgreich entfernt
C:\windows\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => erfolgreich verschoben
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVGPCTuneUp_Task_BkGndMaintenance => Schlüssel erfolgreich entfernt
C:\Program Files (x86)\AVG => erfolgreich verschoben
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3CDF7212-D471-42F4-A121-ED4D70251682} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3CDF7212-D471-42F4-A121-ED4D70251682} => Schlüssel erfolgreich entfernt
C:\windows\System32\Tasks\{7C15C6ED-AB8F-4479-AB67-B366BCA58406} => erfolgreich verschoben
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7C15C6ED-AB8F-4479-AB67-B366BCA58406} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2B68F8A1-F7BA-4699-885D-EAF51F2DBD90} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B68F8A1-F7BA-4699-885D-EAF51F2DBD90} => Schlüssel erfolgreich entfernt
C:\windows\System32\Tasks\{551F8A14-3EE5-4B8B-83D3-D11EB5BC5F15} => erfolgreich verschoben
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{551F8A14-3EE5-4B8B-83D3-D11EB5BC5F15} => Schlüssel erfolgreich entfernt

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 13011444 B
Java, Flash, Steam htmlcache => 127920 B
Windows/system/drivers => 4731347 B
Edge => 0 B
Chrome => 15950036 B
Firefox => 371449959 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 58535568 B
systemprofile32 => 908949953 B
LocalService => 0 B
NetworkService => 0 B
Micha => 18664995 B
DefaultAppPool => 0 B

RecycleBin => 16501862 B
EmptyTemp: => 1.3 GB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 16:42:21 ====


cosinus 16.01.2017 22:25

Kontrollscans mit (1) MBAM, (2) ESET und (3) SecurityCheck bitte:


1. Schritt: MBAM

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




2. Schritt: ESET

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




3. Schritt: SecurityCheck

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

milkit54 17.01.2017 02:20

als erstes die mbam
Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlaufdatum: 23.12.2016
Suchlaufzeit: 19:04
Protokolldatei: mbam.txt
Administrator: Ja

Version: 2.2.1.1043
Malware-Datenbank: v2016.12.23.08
Rootkit-Datenbank: v2016.11.20.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Micha

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 315108
Abgelaufene Zeit: 22 Min., 22 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 3
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\SLIMWARE UTILITIES INC\DriverUpdate, In Quarantäne, [8b395298940696a0003e136f9f61a35d],
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\SlimWare Utilities, Inc.\DriverApp, In Quarantäne, [b90b1dcd0f8b57df1615037ae9171ce4],
PUP.Optional.DriverUpdate, HKU\S-1-5-21-2198626584-3468660724-23365673-1000\SOFTWARE\SLIMWARE UTILITIES INC\DriverUpdate, In Quarantäne, [2b999d4d8b0f8bab05c8b1cb7c847b85],

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 3
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Images, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],

Dateien: 11
PUP.Optional.DriverUpdate, C:\Users\Micha\Downloads\DriverUpdate-setup.exe, In Quarantäne, [5272c426bae07cbac5087cee3ac649b7],
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\ignores.dat, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\rupdates.db, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\settings.db, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\supdates.db, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\SWDUMon.cat, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\SWDUMon.inf, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\SWDUMon.sys, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Images\acer.png, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs\2016-12-18  11-00-36 0.log, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],
PUP.Optional.DriverUpdate, C:\Users\Micha\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs\2016-12-18  11-00-51 0.log, In Quarantäne, [f2d25793afeb92a4459bfe7e2cd4ad53],

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)

sorry bin nur bis zu eset schließen gekommen, explorer paßte nicht zur Bildvorlage danach kam ich nicht weiter

Gruß MS-Micha

cosinus 17.01.2017 09:23

Zitat:

explorer paßte nicht zur Bildvorlage danach kam ich nicht weiter
Das soll bitte was heißen? :glaskugel:
Anleitung mal richtig gelesen??

milkit54 17.01.2017 15:01

Hallo Cosinus, hoffe ich habe jetzt die richtige Datei gefunden,
Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=34729f8e79946e49bb879ad8e66c98cb
# end=init
# utc_time=2017-01-16 10:46:40
# local_time=2017-01-16 11:46:40 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 32084
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=34729f8e79946e49bb879ad8e66c98cb
# end=updated
# utc_time=2017-01-16 10:50:02
# local_time=2017-01-16 11:50:02 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=34729f8e79946e49bb879ad8e66c98cb
# engine=32084
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2017-01-17 12:03:27
# local_time=2017-01-17 01:03:27 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 10514 236241257 0 0
# scanned=213778
# found=20
# cleaned=0
# scan_time=4404
sh=C81214BEF922A09B347F10ECAD857635E78B175A ft=1 fh=70f34604069d89e9 vn="Variante von Win64/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\irrhezafpuzappwydpnliethvfskmzjt.back"
sh=C81214BEF922A09B347F10ECAD857635E78B175A ft=1 fh=70f34604069d89e9 vn="Variante von Win64/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\uoxnvyorcizesvxqusoqroplcowxasfc.back"
sh=0AA495433A70EB588E5157F44909D284DB405766 ft=1 fh=fc7510d09bb476bc vn="Variante von Win32/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\xogjrveqwroavaipvefcmiehrwzybkcv.back"
sh=A0F0122AB62BF0CAAF8E347005C3C39E995CCFAB ft=0 fh=0000000000000000 vn="JS/Mindspark.D eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\dfmngcyepfncwhtbuajqqszlocwlcfxg\bootstrap.js"
sh=C6E9C18B997F9A82B1AFD311B13681C5DC54A01F ft=1 fh=4ea2f57798fab6e9 vn="Variante von Win32/Toolbar.Visicom.E eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\kcqxdodtquhqlhqxjwuzylmxydwxzlby\ToolbarCleaner.exe"
sh=5208ECDCC250F219019AA972749BA71FD06417B1 ft=1 fh=4fae1286e66135e9 vn="Variante von Win32/Toolbar.Visicom.E eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\kcqxdodtquhqlhqxjwuzylmxydwxzlby\uninstall.exe"
sh=4987C09FAEEF68697D7146133A3DD83253055107 ft=1 fh=4a137e6a49660203 vn="Variante von Win32/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\mylmuviaqpjwyfdeiohrefecvjdgkyyt\TcpService\2.2.9.5\LavasoftTcpService.exe"
sh=A238EA288673814DB53D5CC63EC28CFA5CDA8FD3 ft=1 fh=e87790b871be25af vn="Variante von Win32/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\mylmuviaqpjwyfdeiohrefecvjdgkyyt\TcpService\2.2.9.5\LavasoftTcpServiceCert.dll"
sh=EE2D8A0C16CB4F60E07AD30BC8F4AF2D25E4FF62 ft=1 fh=c2a60ef126908cf5 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSS.exe"
sh=24A108C48173FDD9962F7CC3D4DB4B852D864838 ft=1 fh=0501d0dc4c9a869f vn="Variante von Win32/Systweak.N eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSHelper.dll"
sh=915239C2678EFCE5C2E45012595BEA0C050864B4 ft=1 fh=9ca6c4d86ffea4d8 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSPrivacyProtector.exe"
sh=67A75BAA7A5BBB2EEEBB99D490F00F82D0BB1E09 ft=1 fh=5d5a0ac2ab2c0a85 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSRegClean.exe"
sh=2C09414F7BCF16F3C9A358B5CCD4492EF7EEF08E ft=1 fh=5545a1a02bc092d6 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSRegistryOptimizer.exe"
sh=322DCE4CCA5EB266FFEDD900C6D628769AD18300 ft=1 fh=b3d66e50f9e4f6b1 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSSystemCleaner.exe"
sh=06AEEE97A8E40D82E97A0945E61C9EF1C0E7DDE7 ft=1 fh=8c61c410b53542e1 vn="Variante von Win32/SlowPCfighter.A eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Micha\AppData\Roaming\Fighters\Tray\AutoInstall\DM.exe"
sh=D22385CE4D7F8CBC2A83C4CC6397839950B423C4 ft=1 fh=aadf2fa769f3cd1f vn="Variante von Win32/Toolbar.Visicom.C eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Micha\Desktop\Alte Firefox-Daten\jsjjbqd4-1.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\dtUser.exe"
sh=2AB20B5FB718DC8D006F0F8A11C250FA44EED984 ft=1 fh=17b2900a6c3a46de vn="Win32/InstallMonetizer.AQ eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Micha\Downloads\PDFCreator-2_0_1-setup.exe"
sh=552464E3A61B57248E7ABBB9E78047923105E150 ft=1 fh=8e19f37ab9b5e3fe vn="Win32/InstallMonetizer.AQ eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Micha\Downloads\PDFCreator-2_3_0-Setup.exe"
sh=894DFE6342C1917D2B12F804793CFDA39292C0F0 ft=1 fh=2fc74339d695553b vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Micha\Downloads\Sweepi - CHIP-Installer(1).exe"
sh=E3456A1B53C01899C68FBCEA73ED2AEB08A6A40D ft=1 fh=88468a33544a88f3 vn="Variante von Win32/DownloadSponsor.C eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Micha\Downloads\Sweepi - CHIP-Installer.exe"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=34729f8e79946e49bb879ad8e66c98cb
# end=init
# utc_time=2017-01-17 12:29:39
# local_time=2017-01-17 01:29:39 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 32090
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=34729f8e79946e49bb879ad8e66c98cb
# end=updated
# utc_time=2017-01-17 12:30:37
# local_time=2017-01-17 01:30:37 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=34729f8e79946e49bb879ad8e66c98cb
# engine=32090
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2017-01-17 12:49:36
# local_time=2017-01-17 01:49:36 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 23126 236287226 0 0
# scanned=69284
# found=14
# cleaned=0
# scan_time=1138
sh=C81214BEF922A09B347F10ECAD857635E78B175A ft=1 fh=70f34604069d89e9 vn="Variante von Win64/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\irrhezafpuzappwydpnliethvfskmzjt.back"
sh=C81214BEF922A09B347F10ECAD857635E78B175A ft=1 fh=70f34604069d89e9 vn="Variante von Win64/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\uoxnvyorcizesvxqusoqroplcowxasfc.back"
sh=0AA495433A70EB588E5157F44909D284DB405766 ft=1 fh=fc7510d09bb476bc vn="Variante von Win32/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\xogjrveqwroavaipvefcmiehrwzybkcv.back"
sh=A0F0122AB62BF0CAAF8E347005C3C39E995CCFAB ft=0 fh=0000000000000000 vn="JS/Mindspark.D eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\dfmngcyepfncwhtbuajqqszlocwlcfxg\bootstrap.js"
sh=C6E9C18B997F9A82B1AFD311B13681C5DC54A01F ft=1 fh=4ea2f57798fab6e9 vn="Variante von Win32/Toolbar.Visicom.E eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\kcqxdodtquhqlhqxjwuzylmxydwxzlby\ToolbarCleaner.exe"
sh=5208ECDCC250F219019AA972749BA71FD06417B1 ft=1 fh=4fae1286e66135e9 vn="Variante von Win32/Toolbar.Visicom.E eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\kcqxdodtquhqlhqxjwuzylmxydwxzlby\uninstall.exe"
sh=4987C09FAEEF68697D7146133A3DD83253055107 ft=1 fh=4a137e6a49660203 vn="Variante von Win32/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\mylmuviaqpjwyfdeiohrefecvjdgkyyt\TcpService\2.2.9.5\LavasoftTcpService.exe"
sh=A238EA288673814DB53D5CC63EC28CFA5CDA8FD3 ft=1 fh=e87790b871be25af vn="Variante von Win32/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\mylmuviaqpjwyfdeiohrefecvjdgkyyt\TcpService\2.2.9.5\LavasoftTcpServiceCert.dll"
sh=EE2D8A0C16CB4F60E07AD30BC8F4AF2D25E4FF62 ft=1 fh=c2a60ef126908cf5 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSS.exe"
sh=24A108C48173FDD9962F7CC3D4DB4B852D864838 ft=1 fh=0501d0dc4c9a869f vn="Variante von Win32/Systweak.N eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSHelper.dll"
sh=915239C2678EFCE5C2E45012595BEA0C050864B4 ft=1 fh=9ca6c4d86ffea4d8 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSPrivacyProtector.exe"
sh=67A75BAA7A5BBB2EEEBB99D490F00F82D0BB1E09 ft=1 fh=5d5a0ac2ab2c0a85 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSRegClean.exe"
sh=2C09414F7BCF16F3C9A358B5CCD4492EF7EEF08E ft=1 fh=5545a1a02bc092d6 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSRegistryOptimizer.exe"
sh=322DCE4CCA5EB266FFEDD900C6D628769AD18300 ft=1 fh=b3d66e50f9e4f6b1 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSSystemCleaner.exe"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=34729f8e79946e49bb879ad8e66c98cb
# end=init
# utc_time=2017-01-17 12:50:27
# local_time=2017-01-17 01:50:27 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 32092
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=34729f8e79946e49bb879ad8e66c98cb
# end=updated
# utc_time=2017-01-17 12:51:18
# local_time=2017-01-17 01:51:18 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=34729f8e79946e49bb879ad8e66c98cb
# engine=32092
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2017-01-17 01:12:06
# local_time=2017-01-17 02:12:06 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 20876 236288576 0 0
# scanned=77845
# found=16
# cleaned=0
# scan_time=1247
sh=C81214BEF922A09B347F10ECAD857635E78B175A ft=1 fh=70f34604069d89e9 vn="Variante von Win64/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\irrhezafpuzappwydpnliethvfskmzjt.back"
sh=C81214BEF922A09B347F10ECAD857635E78B175A ft=1 fh=70f34604069d89e9 vn="Variante von Win64/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\uoxnvyorcizesvxqusoqroplcowxasfc.back"
sh=0AA495433A70EB588E5157F44909D284DB405766 ft=1 fh=fc7510d09bb476bc vn="Variante von Win32/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\xogjrveqwroavaipvefcmiehrwzybkcv.back"
sh=A0F0122AB62BF0CAAF8E347005C3C39E995CCFAB ft=0 fh=0000000000000000 vn="JS/Mindspark.D eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\dfmngcyepfncwhtbuajqqszlocwlcfxg\bootstrap.js"
sh=C6E9C18B997F9A82B1AFD311B13681C5DC54A01F ft=1 fh=4ea2f57798fab6e9 vn="Variante von Win32/Toolbar.Visicom.E eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\kcqxdodtquhqlhqxjwuzylmxydwxzlby\ToolbarCleaner.exe"
sh=5208ECDCC250F219019AA972749BA71FD06417B1 ft=1 fh=4fae1286e66135e9 vn="Variante von Win32/Toolbar.Visicom.E eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\kcqxdodtquhqlhqxjwuzylmxydwxzlby\uninstall.exe"
sh=4987C09FAEEF68697D7146133A3DD83253055107 ft=1 fh=4a137e6a49660203 vn="Variante von Win32/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\mylmuviaqpjwyfdeiohrefecvjdgkyyt\TcpService\2.2.9.5\LavasoftTcpService.exe"
sh=A238EA288673814DB53D5CC63EC28CFA5CDA8FD3 ft=1 fh=e87790b871be25af vn="Variante von Win32/Packed.Komodia.A verdächtige Datei" ac=I fn="C:\AdwCleaner\quarantine\files\mylmuviaqpjwyfdeiohrefecvjdgkyyt\TcpService\2.2.9.5\LavasoftTcpServiceCert.dll"
sh=EE2D8A0C16CB4F60E07AD30BC8F4AF2D25E4FF62 ft=1 fh=c2a60ef126908cf5 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSS.exe"
sh=24A108C48173FDD9962F7CC3D4DB4B852D864838 ft=1 fh=0501d0dc4c9a869f vn="Variante von Win32/Systweak.N eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSHelper.dll"
sh=915239C2678EFCE5C2E45012595BEA0C050864B4 ft=1 fh=9ca6c4d86ffea4d8 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSPrivacyProtector.exe"
sh=67A75BAA7A5BBB2EEEBB99D490F00F82D0BB1E09 ft=1 fh=5d5a0ac2ab2c0a85 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSRegClean.exe"
sh=2C09414F7BCF16F3C9A358B5CCD4492EF7EEF08E ft=1 fh=5545a1a02bc092d6 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSRegistryOptimizer.exe"
sh=322DCE4CCA5EB266FFEDD900C6D628769AD18300 ft=1 fh=b3d66e50f9e4f6b1 vn="Variante von Win32/Systweak.L eventuell unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\WinZip\Utils\WzSysScan\WINZIPSSSystemCleaner.exe"
sh=06AEEE97A8E40D82E97A0945E61C9EF1C0E7DDE7 ft=1 fh=8c61c410b53542e1 vn="Variante von Win32/SlowPCfighter.A eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Micha\AppData\Roaming\Fighters\Tray\AutoInstall\DM.exe"
sh=D22385CE4D7F8CBC2A83C4CC6397839950B423C4 ft=1 fh=aadf2fa769f3cd1f vn="Variante von Win32/Toolbar.Visicom.C eventuell unerwünschte Anwendung" ac=I fn="C:\Users\Micha\Desktop\Alte Firefox-Daten\jsjjbqd4-1.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\dtUser.exe"


cosinus 17.01.2017 23:32

Zitat:

C:\Users\Micha\Downloads\Sweepi - CHIP-Installer(1).exe
C:\Users\Micha\Downloads\Sweepi - CHIP-Installer.exe

Keine Downloads mehr von CHIP.de!!!

Die verarschen ihre Kunden aus reiner Profitgier. Siehe auch http://www.trojaner-board.de/168364-...mpfehlung.html und CHIP-Installer - was ist das? - Anleitungen



FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Program Files (x86)\WinZip\Utils\WzSysScan
C:\Users\Micha\AppData\Roaming\Fighters
C:\Users\Micha\Desktop\Alte Firefox-Daten\jsjjbqd4-1.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\dtUser.exe
C:\Users\Micha\Downloads\PDFCreator*.exe
C:\Users\Micha\Downloads\*CHIP-Installer(1).exe
C:\Users\Micha\Downloads\*CHIP-Installer.exe
emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


milkit54 18.01.2017 00:32

Hallo Cosinus, brauche leider vorab eine Hilfe wie deaktiviere ich den Virenscanner? Bin ganz schön dumm/hilflos MS-Michael

cosinus 18.01.2017 11:08

in deinem Fall ist das irrelevant. einfach den Fix machen.

milkit54 18.01.2017 12:44

hat wg-neustart etwas gedauert

Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-01-2017
durchgeführt von Micha (18-01-2017 12:19:36) Run:2
Gestartet von C:\Users\Micha\Downloads
Geladene Profile: Micha (Verfügbare Profile: Micha & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
C:\Program Files (x86)\WinZip\Utils\WzSysScan
C:\Users\Micha\AppData\Roaming\Fighters
C:\Users\Micha\Desktop\Alte Firefox-Daten\jsjjbqd4-1.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\dtUser.exe
C:\Users\Micha\Downloads\PDFCreator*.exe
C:\Users\Micha\Downloads\*CHIP-Installer(1).exe
C:\Users\Micha\Downloads\*CHIP-Installer.exe
emptytemp:
       
*****************

C:\Program Files (x86)\WinZip\Utils\WzSysScan => erfolgreich verschoben
C:\Users\Micha\AppData\Roaming\Fighters => erfolgreich verschoben
C:\Users\Micha\Desktop\Alte Firefox-Daten\jsjjbqd4-1.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\dtUser.exe => erfolgreich verschoben

=========== "C:\Users\Micha\Downloads\PDFCreator*.exe" ==========

C:\Users\Micha\Downloads\PDFCreator-2_0_1-setup.exe => erfolgreich verschoben
C:\Users\Micha\Downloads\PDFCreator-2_3_0-Setup.exe => erfolgreich verschoben
C:\Users\Micha\Downloads\PDFCreatorWebSetup.exe => erfolgreich verschoben

========= Ende -> "C:\Users\Micha\Downloads\PDFCreator*.exe" ========


=========== "C:\Users\Micha\Downloads\*CHIP-Installer(1).exe" ==========

C:\Users\Micha\Downloads\Sweepi - CHIP-Installer(1).exe => erfolgreich verschoben

========= Ende -> "C:\Users\Micha\Downloads\*CHIP-Installer(1).exe" ========


=========== "C:\Users\Micha\Downloads\*CHIP-Installer.exe" ==========

C:\Users\Micha\Downloads\Sweepi - CHIP-Installer.exe => erfolgreich verschoben

========= Ende -> "C:\Users\Micha\Downloads\*CHIP-Installer.exe" ========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 5279017 B
Java, Flash, Steam htmlcache => 2279 B
Windows/system/drivers => 13266 B
Edge => 0 B
Chrome => 7019066 B
Firefox => 360201030 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 0 B
systemprofile32 => 3183640 B
LocalService => 0 B
NetworkService => 0 B
Micha => 39721112 B
DefaultAppPool => 0 B

RecycleBin => 0 B
EmptyTemp: => 404.2 MB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 12:21:24 ====


cosinus 18.01.2017 12:59

Ok. Log von SC fehlt noch.

milkit54 18.01.2017 13:15

Hallo Cosinus,
bin mal wieder total irritiert was ist SC? welchen log muß ich suchen? Gruß MS-Micha

cosinus 18.01.2017 13:19

Anleitung bitte richtig lesen => 3. Schritt Security Check (SC)

milkit54 18.01.2017 13:55

Hi Cosinus, bin unfähig den Schritt 3 (die komplette Anleitung) auf meinem Rechner zu finden,

cosinus 18.01.2017 14:13

Meine Güte, du musst doch einfach nur mal zurückscrollen, ich poste Anleitungen hier ins Forum und nicht auf deinen Rechner! :wtf:

milkit54 18.01.2017 16:19

Zitat:

Zitat von cosinus (Beitrag 1634940)
Meine Güte, du musst doch einfach nur mal zurückscrollen, ich poste Anleitungen hier ins Forum und nicht auf deinen Rechner! :wtf:

hallo cosinus, habe wohl neben der MS im Kopf noch ein Brett vor demselben. beim scrollen komme ich über die Stelle "Schritt 1, Schritt 2, Lesestofffe; nicht weiter tut mir echt leid, daß ich mich so blöd anstelle, was jetzt??

Hi Cosinus, müsste jetzt mal meinen Rollator satteln und mich in die Stadt quälen sonst habe ich kein Futter und keine Getränke mehr. dauert ca 1-2 std. würde mich freuen wenn wir dann weitermachen könnten, auch wenn es mit mir so schwierig ist. Gruß MS-Micha

Hi Cosinus, müsste jetzt mal meinen Rollator satteln und mich in die Stadt quälen sonst habe ich kein Futter und keine Getränke mehr. dauert ca 1-2 std. würde mich freuen wenn wir dann weitermachen könnten, auch wenn es mit mir so schwierig ist. Gruß MS-Micha

cosinus 18.01.2017 17:25

Posting #30 einfach mal richtig lesen

milkit54 18.01.2017 21:45

nochmal gelaufen Inhalt

Code:

Results of screen317's Security Check version 1.009 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
Malwarebytes 
  (On Access scanning disabled!)
 Error obtaining update status for antivirus! 
`````````Anti-malware/Other Utilities Check:`````````
 Ad-Aware
 Adobe Flash Player 24.0.0.194 
 Mozilla Firefox (50.1.0)
 Google Chrome (55.0.2883.87)
 Google Chrome (SetupMetrics...)
````````Process Check: objlist.exe by Laurent```````` 
 Norton ccSvcHst.exe
 Ad-Aware AAWService.exe is disabled!
 Ad-Aware AAWTray.exe is disabled!
 Malwarebytes Anti-Malware mbamservice.exe 
 Malwarebytes Anti-Malware mbam.exe 
 Malwarebytes Anti-Malware mbamscheduler.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````

habe nochmal laufen lassen ok?

log ist
Code:

Results of screen317's Security Check version 1.009 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
Malwarebytes 
  (On Access scanning disabled!)
 Error obtaining update status for antivirus! 
`````````Anti-malware/Other Utilities Check:`````````
 Ad-Aware
 Adobe Flash Player 24.0.0.194 
 Mozilla Firefox (50.1.0)
 Google Chrome (55.0.2883.87)
 Google Chrome (SetupMetrics...)
````````Process Check: objlist.exe by Laurent```````` 
 Norton ccSvcHst.exe
 Ad-Aware AAWService.exe is disabled!
 Ad-Aware AAWTray.exe is disabled!
 Malwarebytes Anti-Malware mbamservice.exe 
 Malwarebytes Anti-Malware mbam.exe 
 Malwarebytes Anti-Malware mbamscheduler.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````


cosinus 18.01.2017 21:57

Zitat:

Norton ccSvcHst.exe
Ad-Aware AAWService.exe is disabled!
Ad-Aware AAWTray.exe is disabled!
Bitte ma checken was da noch an Resten ist. Mit revo deinstallieren.

milkit54 18.01.2017 23:03

bei Symantec werden noch 3 Programme Norton Anti-Theft, Norton PC Checkup, Norton online Backup aufgelistet,
bei Lavasoft wird Companion angezeigt
wo könnte ich die Reste noch suchen ? Gruß MS-Micha

cosinus 18.01.2017 23:06

Einfach mit revo und dann damit deinstallieren. Zu revo gibt es in Post #22 eine Anleitung.

milkit54 19.01.2017 10:51

Zitat:

Zitat von cosinus (Beitrag 1635119)
Einfach mit revo und dann damit deinstallieren. Zu revo gibt es in Post #22 eine Anleitung.

hab ich gelöscht sende dir hier Teil 1 FRST
teil2 addition folgt

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 18-01-2017
durchgeführt von Micha (Administrator) auf MICHA-MSI (19-01-2017 00:25:07)
Gestartet von C:\Users\Micha\Downloads
Geladene Profile: Micha (Verfügbare Profile: Micha & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\AvrcpService.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Microsoft Corporation) C:\Windows\System32\CISVC.EXE
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(MSI) C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Visicom Media Inc.) C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\ws.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\creator-ws.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\RtkBleServ.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\SkypePlugin.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(MSI) C:\Program Files (x86)\SCM\Radio Manager.exe
(MSI) C:\Program Files (x86)\SCM\SCM.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(© 2015 Microsoft Corporation) C:\Users\Micha\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(VS Revo Group) C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe

==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13538376 2013-05-21] (Realtek Semiconductor)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [253440 2013-04-23] (Realtek Semiconductor Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2875728 2013-03-04] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2013-07-05] (MSI)
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [399528 2013-07-05] (MSI)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [Windows Mobile-based device management] => C:\windows\WindowsMobile\wmdcBase.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-10-13] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [230696 2011-10-13] (CyberLink Corp.)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [490480 2013-02-01] (MSI)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2014-03-18] (shbox.de)
HKLM-x32\...\Run: [APSDaemon] => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series (Kopie 1)] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series (Kopie 2)] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [BingSvc] => C:\Users\Micha\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27230168 2016-11-15] (Skype Technologies S.A.)
HKU\S-1-5-18\...\Run: [EPSON SX100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-18\...\RunOnce: [panda] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f
HKU\S-1-5-18\...\RunOnce: [panda_XP] => reg.exe delete "HKCU\Software\panda" /f
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Keine Datei
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop(777).ini [2009-07-14] ()
Startup: C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.6.lnk [2013-07-31]
ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.6.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2
Tcpip\..\Interfaces\{19590355-955C-4F75-9574-A5178867FB8F}: [DhcpNameServer] 192.168.0.1 192.168.0.2
Tcpip\..\Interfaces\{7AFF0EF0-F8B5-4E22-BED7-5BAC51243C58}: [NameServer] 193.189.244.206 193.189.244.225

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.n-tv.de/
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {2BA0719B-B10C-4176-8BB1-AF2B6E7453E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAM3&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {2BA0719B-B10C-4176-8BB1-AF2B6E7453E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAM3&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={18DC9A1B-75F8-4C91-A21F-328A8F8FCFB0}&mid=2f112f36b90e47cd86aa856e587a95e0-b67d740e056757739f071bdf1b00435729c4d0a4&lang=de&ds=AVG&coid=avgtbavg&cmpid=1016tb&pr=fr&d=2015-01-05 13:55:51&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={18DC9A1B-75F8-4C91-A21F-328A8F8FCFB0}&mid=2f112f36b90e47cd86aa856e587a95e0-b67d740e056757739f071bdf1b00435729c4d0a4&lang=de&ds=AVG&coid=avgtbavg&cmpid=1016tb&pr=fr&d=2015-01-05 13:55:51&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll => Keine Datei
BHO-x32: PDF Architect Helper -> {691B33B0-B86E-47F3-81C7-56E4FE3B929C} -> C:\Program Files (x86)\PDF Architect 2\creator-ie-helper.dll [2014-10-10] (pdfforge GmbH)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - C:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH)

FireFox:
========
FF ProfilePath: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 [2017-01-19]
FF NewTab: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> hxxp://www.n-tv.de/
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> Google
FF Homepage: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> hxxp://www.n-tv.de/
FF Extension: (Test Pilot) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\@testpilot-addon.xpi [2017-01-11]
FF Extension: (GMX MailCheck) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\browser-mailcheck@gmx.net [2016-11-23]
FF Extension: (Awesome Screenshot - Capture, Annotate & More) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2017-01-10]
FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: (PDF Architect 2 Creator) - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2015-01-20] [ist nicht signiert]
FF HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\jsjjbqd4.default\extensions\cliqz@cliqz.com => nicht gefunden
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\pandasecuritytb.xml [2015-05-27]
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-10] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-10] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-02-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-02-16] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll [2014-10-10] (pdfforge GmbH)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=de-de
CHR DefaultSearchURL: Default -> hxxp://pandasecurity.mystart.com/results.php?searchsource=omnibar&pr=vmn&id=pandasecuritytb&v=2_3&ent=ds_671&q={searchTerms}
CHR DefaultSearchKeyword: Default -> yahoo
CHR Profile: C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default [2017-01-18]
CHR Extension: (Kein Name) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-15]
CHR Extension: (Adobe Acrobat) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-18]
CHR Extension: (Yahoo!) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdhbkaahephniejapepaiggngjnedpci [2017-01-18]
CHR Extension: (MSN Homepage) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkcgfbgohboipdhliafmacjnhjbhmim [2017-01-18]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-18]
CHR Extension: (Chrome Media Router) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-18]
CHR HKU\S-1-5-21-2198626584-3468660724-23365673-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fkkcgfbgohboipdhliafmacjnhjbhmim] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fdhbkaahephniejapepaiggngjnedpci] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AvrcpService; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe [35328 2013-04-02] (Realtek Semiconductor Corporation) [Datei ist nicht signiert]
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [47104 2013-04-26] () [Datei ist nicht signiert]
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [Datei ist nicht signiert]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [Datei ist nicht signiert]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-02-16] (Intel Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2013-07-05] (Micro-Star International Co., Ltd.) [Datei ist nicht signiert]
R2 MSI Foundation Service; C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe [12800 2010-07-17] (MSI) [Datei ist nicht signiert]
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [143856 2013-02-01] (MSI)
S2 NAT; C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe [143928 2012-08-19] (Symantec Corporation)
R2 panda_url_filtering; C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe [287752 2015-10-02] (Visicom Media Inc.)
R2 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1771560 2014-10-10] (pdfforge GmbH)
R2 PDF Architect 2 Creator; C:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
R2 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-10-10] (pdfforge GmbH)
R2 RtkBleServ; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\RtkBleServ.exe [42496 2013-04-26] (Realtek Semiconductor Corporation) [Datei ist nicht signiert]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 McComponentHostService; "C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe" [X]
S2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\SymcPCCULaunchSvc.exe /s [X]
S2 PCCUJobMgr; "C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe" /s "PCCUJobMgr" /m "C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\diMaster.dll" /prefetch:1

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ccSet_NAT; C:\windows\system32\drivers\NATx64\0106000.011\ccSetx64.sys [168096 2012-08-07] (Symantec Corporation)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [77416 2016-12-14] ()
S3 ewusbnet; C:\windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
R0 iaStorF; C:\windows\System32\drivers\iaStorF.sys [28656 2013-03-22] (Intel Corporation)
R3 L1C; C:\windows\System32\DRIVERS\L1C62x64.sys [118504 2013-05-07] (Qualcomm Atheros Co., Ltd.)
R2 MBAMChameleon; C:\windows\system32\drivers\MBAMChameleon.sys [140672 2016-03-10] (Malwarebytes)
S3 MBAMFarflt; C:\windows\system32\drivers\farflt.sys [102856 2017-01-16] (Malwarebytes)
S3 MBAMProtection; C:\windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-01-19] (Malwarebytes)
S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [81696 2017-01-16] (Malwarebytes)
S3 MBAMWebProtection; C:\windows\system32\drivers\mwac.sys [81696 2017-01-16] (Malwarebytes)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-26] (MSI)
R3 panda_url_filteringd; C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys [51288 2014-03-19] (Visicom Media Inc.)
S3 RtkAvrcp; C:\windows\system32\drivers\RtkAvrcp.sys [61152 2012-12-27] (Realtek Semiconductor Corporation)
S3 RtkAvrcpCtrlr; C:\windows\system32\drivers\RtkAvrcpCtrlr.sys [66376 2013-04-08] (Realtek Semiconductor Corporation)
R3 RtkBtFilter; C:\windows\System32\DRIVERS\RtkBtfilter.sys [535624 2013-03-28] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\windows\System32\DRIVERS\rtwlane.sys [1514568 2013-05-02] (Realtek Semiconductor Corporation                          )
S3 MGHwCtrl; \??\C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-01-19 00:15 - 2017-01-19 00:17 - 00000000 ____D C:\Users\Micha\Desktop\Trojy-18012017
2017-01-18 21:09 - 2017-01-18 21:09 - 00001071 _____ C:\Users\Micha\Downloads\checkup.txt
2017-01-18 21:04 - 2017-01-18 21:04 - 00852720 _____ C:\Users\Micha\Desktop\SecurityCheck.exe
2017-01-16 23:45 - 2017-01-17 13:48 - 02870984 _____ (ESET) C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe
2017-01-16 22:45 - 2017-01-16 22:45 - 00001112 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2017-01-16 22:45 - 2017-01-16 22:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2017-01-16 22:45 - 2017-01-16 22:45 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2017-01-16 22:41 - 2017-01-16 22:41 - 22851472 _____ (Malwarebytes ) C:\Users\Micha\Desktop\mbam-setup-2.2.1.1043.exe
2017-01-16 16:41 - 2017-01-18 12:42 - 00002630 _____ C:\Users\Micha\Downloads\Fixlog.txt
2017-01-16 16:37 - 2017-01-16 16:37 - 00013295 _____ C:\Users\Micha\Desktop\FRST64.exe - Verknüpfung.lnk
2017-01-16 15:19 - 2017-01-16 15:44 - 00053850 _____ C:\Users\Micha\Desktop\FRST.txt
2017-01-16 12:29 - 2017-01-16 14:05 - 00001004 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2017-01-16 12:29 - 2017-01-16 14:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2017-01-16 12:29 - 2017-01-16 12:29 - 00000000 ____D C:\Program Files\VS Revo Group
2017-01-16 12:27 - 2017-01-16 12:27 - 07097928 _____ (VS Revo Group ) C:\Users\Micha\Desktop\revo202setup.exe
2017-01-15 17:46 - 2017-01-15 17:46 - 00032851 _____ C:\Users\Micha\Downloads\Addition01152017.txt
2017-01-15 14:42 - 2017-01-19 00:24 - 00000000 ____D C:\Users\Micha\Downloads\FRST-OlderVersion
2017-01-15 12:09 - 2017-01-15 13:43 - 00001729 _____ C:\Users\Micha\Desktop\AdwCleaner[S3].txt
2017-01-14 22:09 - 2017-01-14 22:09 - 00019431 _____ C:\Users\Micha\Desktop\AdwCleaner[C0].txt
2017-01-14 20:02 - 2017-01-14 19:16 - 00018180 _____ C:\Users\Micha\Desktop\AdwCleaner[S0].txt
2017-01-14 18:21 - 2017-01-14 18:21 - 00000268 _____ C:\Users\Micha\Desktop\Junkware Removal Tool - Download - Filepony.URL
2017-01-14 18:19 - 2017-01-14 18:19 - 01663040 _____ (Malwarebytes) C:\Users\Micha\Downloads\JRT(1).exe
2017-01-14 18:15 - 2017-01-14 18:30 - 00000696 _____ C:\Users\Micha\Desktop\JRT.txt
2017-01-14 18:10 - 2017-01-14 18:10 - 01663040 _____ (Malwarebytes) C:\Users\Micha\Downloads\JRT.exe
2017-01-14 18:06 - 2017-01-14 18:06 - 00017147 _____ C:\Users\Micha\Desktop\w2WQUGsI.htm
2017-01-14 17:40 - 2017-01-14 22:20 - 00000000 ____D C:\AdwCleaner
2017-01-14 17:37 - 2017-01-14 17:37 - 03988944 _____ C:\Users\Micha\Desktop\AdwCleaner_6.042.exe
2017-01-13 21:12 - 2017-01-13 22:37 - 00222352 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_21.12.52_log.txt
2017-01-13 21:09 - 2017-01-13 21:12 - 00219050 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_21.09.19_log.txt
2017-01-13 21:04 - 2017-01-13 21:05 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Micha\Downloads\tdsskiller(1).exe
2017-01-13 17:15 - 2017-01-13 17:29 - 00219050 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_17.15.21_log.txt
2017-01-13 17:09 - 2017-01-13 17:12 - 00219050 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_17.09.39_log.txt
2017-01-13 17:07 - 2017-01-13 17:07 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Micha\Desktop\tdsskiller.exe
2017-01-13 15:23 - 2017-01-14 22:06 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-01-13 15:17 - 2017-01-13 16:56 - 00000000 ____D C:\Users\Micha\Desktop\mbar
2017-01-13 15:07 - 2017-01-13 15:08 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Micha\Desktop\mbar-1.09.3.1001.exe
2017-01-13 08:17 - 2017-01-13 08:17 - 00000000 ____D C:\Users\Micha\Documents\MAGIX Downloads
2017-01-12 23:06 - 2017-01-13 11:42 - 00000000 ____D C:\Users\Micha\Desktop\Trboard
2017-01-12 10:56 - 2017-01-12 10:57 - 00084152 _____ C:\Users\Micha\Downloads\Addition .txt
2017-01-10 20:59 - 2017-01-05 19:55 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2017-01-10 20:59 - 2017-01-05 19:55 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2017-01-10 20:59 - 2017-01-05 19:52 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2017-01-10 20:59 - 2017-01-05 18:42 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2017-01-10 20:59 - 2017-01-05 18:32 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2017-01-10 20:59 - 2017-01-05 18:25 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2017-01-10 20:59 - 2017-01-05 18:23 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2017-01-10 20:59 - 2017-01-05 18:19 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2017-01-10 20:56 - 2017-01-10 20:56 - 00083124 _____ C:\Users\Micha\Downloads\FRST01102017.txt
2017-01-10 20:55 - 2017-01-10 20:55 - 00041706 _____ C:\Users\Micha\Downloads\Addition01102017.txt
2017-01-10 16:22 - 2017-01-10 16:22 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Vorlagen
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Startmenü
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Netzwerkumgebung
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Lokale Einstellungen
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Eigene Dateien
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Druckumgebung
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Videos
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Musik
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Bilder
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Verlauf
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Anwendungsdaten
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Anwendungsdaten
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 ____D C:\Users\DefaultAppPool
2017-01-10 16:22 - 2016-11-30 06:27 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\AVG
2017-01-10 16:22 - 2013-07-31 22:25 - 00002110 _____ C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
2017-01-10 16:22 - 2013-07-31 19:31 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\Media Center Programs
2017-01-10 09:38 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2017-01-10 09:37 - 2017-01-19 00:01 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-10 09:37 - 2017-01-16 22:45 - 00081696 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2017-01-10 09:37 - 2017-01-16 16:45 - 00102856 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2017-01-10 09:37 - 2017-01-10 09:37 - 00001837 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-01-10 09:37 - 2017-01-10 09:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-01-10 09:37 - 2017-01-10 09:37 - 00000000 ____D C:\Program Files\Malwarebytes
2017-01-10 09:37 - 2016-12-14 12:55 - 00077416 _____ C:\windows\system32\Drivers\mbae64.sys
2017-01-10 09:37 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2017-01-10 09:35 - 2017-01-10 09:36 - 54199488 _____ (Malwarebytes ) C:\Users\Micha\Downloads\mb3-setup-consumer-3.0.5.1299(1).exe
2017-01-09 15:57 - 2017-01-18 11:47 - 00034287 _____ C:\Users\Micha\Downloads\Addition.txt
2017-01-09 15:55 - 2017-01-19 00:25 - 00022557 _____ C:\Users\Micha\Downloads\FRST.txt
2017-01-09 15:55 - 2017-01-19 00:25 - 00000000 ____D C:\FRST
2017-01-09 15:54 - 2017-01-19 00:24 - 02419712 _____ (Farbar) C:\Users\Micha\Downloads\FRST64.exe
2017-01-05 20:02 - 2017-01-05 20:02 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk
2017-01-05 20:02 - 2017-01-05 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-01-05 00:41 - 2015-07-16 20:12 - 06131200 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2017-01-05 00:41 - 2015-07-16 20:12 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2017-01-05 00:41 - 2015-07-16 20:12 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 07077376 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 01057792 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2017-01-05 00:41 - 2015-07-11 14:15 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2017-01-04 19:30 - 2015-12-20 19:50 - 03180544 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2017-01-04 19:30 - 2015-12-20 19:50 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2017-01-04 19:30 - 2015-12-20 15:08 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2017-01-04 19:29 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2017-01-04 15:08 - 2017-01-04 15:08 - 54199488 _____ (Malwarebytes ) C:\Users\Micha\Downloads\mb3-setup-consumer-3.0.5.1299.exe
2017-01-04 13:53 - 2017-01-04 13:53 - 13425152 _____ (ReviverSoft) C:\Users\Micha\Downloads\DriverReviverSetup_ppc(2).exe
2017-01-04 10:30 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2017-01-04 10:30 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2017-01-04 10:30 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2017-01-04 10:30 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2017-01-04 10:30 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2017-01-04 10:30 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2017-01-04 10:30 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2017-01-04 10:30 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2017-01-04 10:30 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2017-01-04 10:30 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2017-01-04 10:28 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2017-01-04 10:28 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbGD.sys
2017-01-04 10:28 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2017-01-04 10:28 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2017-01-04 10:25 - 2015-08-05 18:56 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\icaapi.dll
2017-01-04 10:25 - 2015-08-05 18:06 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2017-01-04 09:59 - 2017-01-04 09:59 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ICCWDT_01009.Wdf
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\kbdgeoqw.dll
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZEL.DLL
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZE.DLL
2017-01-04 09:25 - 2015-12-16 19:48 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZE.DLL
2017-01-04 09:25 - 2015-12-16 19:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\kbdgeoqw.dll
2017-01-04 09:25 - 2015-12-16 19:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZEL.DLL
2017-01-04 02:04 - 2017-01-04 02:04 - 03279864 _____ (SPAMfighter ApS) C:\Users\Micha\Downloads\DRIVERfighter_Web(1).exe
2017-01-04 01:02 - 2017-01-04 02:18 - 00000000 ____D C:\ProgramData\Fighters
2017-01-04 01:00 - 2017-01-04 01:01 - 03279864 _____ (SPAMfighter ApS) C:\Users\Micha\Downloads\DRIVERfighter_Web.exe
2017-01-04 00:54 - 2017-01-04 00:55 - 13425152 _____ (ReviverSoft) C:\Users\Micha\Downloads\DriverReviverSetup_ppc(1).exe
2016-12-30 10:41 - 2016-12-30 10:41 - 00178564 _____ C:\Users\Micha\Downloads\HERMES_label_2016-12-30_10_40_52.pdf
2016-12-30 10:35 - 2016-12-30 10:35 - 00178968 _____ C:\Users\Micha\Downloads\HERMES_label_2016-12-30_10_33_49.pdf
2016-12-24 23:14 - 2016-12-24 23:14 - 00025199 _____ C:\Users\Micha\Documents\freelancer200855.vcf
2016-12-24 10:33 - 2012-06-01 06:39 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\wamregps.dll
2016-12-24 10:33 - 2012-06-01 06:36 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\iisRtl.dll
2016-12-24 10:33 - 2012-06-01 06:36 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\iisrstap.dll
2016-12-24 10:33 - 2012-06-01 06:35 - 00060928 _____ (Microsoft Corporation) C:\windows\system32\ahadmin.dll
2016-12-24 10:33 - 2012-06-01 06:34 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\admwprox.dll
2016-12-24 10:33 - 2012-06-01 06:33 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\iisreset.exe
2016-12-24 10:33 - 2012-06-01 05:40 - 00010752 _____ (Microsoft Corporation) C:\windows\SysWOW64\wamregps.dll
2016-12-24 10:33 - 2012-06-01 05:37 - 00154624 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisRtl.dll
2016-12-24 10:33 - 2012-06-01 05:37 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisrstap.dll
2016-12-24 10:33 - 2012-06-01 05:35 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\admwprox.dll
2016-12-24 10:33 - 2012-06-01 05:35 - 00026624 _____ (Microsoft Corporation) C:\windows\SysWOW64\ahadmin.dll
2016-12-24 10:33 - 2012-06-01 05:34 - 00015360 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisreset.exe
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\windows\SysWOW64\BestPractices
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\windows\system32\BestPractices
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\inetpub
2016-12-23 17:25 - 2016-12-23 17:25 - 43886552 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\SkypeSetupFull(2).exe
2016-12-23 17:25 - 2016-12-23 17:25 - 00003142 _____ C:\windows\System32\Tasks\{42239007-962A-405B-897B-E4E0207270AF}
2016-12-23 17:23 - 2016-12-23 17:24 - 01463424 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\skypesetup.exe
2016-12-23 16:13 - 2017-01-03 14:27 - 00524288 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TMContainer00000000000000000001.regtrans-ms
2016-12-23 16:13 - 2017-01-03 14:27 - 00065536 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TM.blf
2016-12-23 16:13 - 2016-12-23 16:17 - 00524288 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 15:52 - 2016-12-23 15:52 - 00000000 __SHD C:\found.000

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-01-19 00:23 - 2016-12-18 14:12 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Skype
2017-01-19 00:17 - 2014-12-14 15:17 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2017-01-19 00:07 - 2009-07-14 05:45 - 00024432 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-19 00:07 - 2009-07-14 05:45 - 00024432 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-19 00:03 - 2016-11-22 11:54 - 00000000 ____D C:\Users\Micha\AppData\LocalLow\Mozilla
2017-01-19 00:00 - 2015-02-27 20:57 - 00000000 ____D C:\Users\Micha\AppData\Local\FreePDF_XP
2017-01-19 00:00 - 2013-07-31 21:55 - 00000000 ____D C:\ProgramData\Realtek
2017-01-18 23:58 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-01-18 23:57 - 2015-05-27 15:08 - 00000000 ____D C:\ProgramData\panda_url_filtering
2017-01-18 23:57 - 2013-07-31 22:23 - 00000000 ____D C:\ProgramData\Norton
2017-01-18 23:41 - 2013-07-31 22:23 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-01-18 23:35 - 2013-07-31 22:28 - 00000000 ____D C:\Program Files (x86)\Norton Anti-Theft
2017-01-16 17:17 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2017-01-16 14:20 - 2016-12-07 22:28 - 00000000 ____D C:\Program Files\Common Files\Apple
2017-01-16 14:20 - 2014-12-27 00:03 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Apple Computer
2017-01-16 14:10 - 2014-12-27 00:00 - 00000000 ____D C:\ProgramData\Apple
2017-01-16 12:45 - 2014-12-27 00:04 - 00000000 ____D C:\Users\Micha\AppData\Local\Apple Computer
2017-01-15 09:05 - 2014-12-19 22:43 - 00000000 ____D C:\Users\Micha\Documents\Youcam
2017-01-14 22:04 - 2015-01-05 13:28 - 00000000 ____D C:\Program Files (x86)\Lavasoft
2017-01-14 22:04 - 2015-01-05 13:24 - 00000000 ____D C:\ProgramData\Lavasoft
2017-01-14 18:12 - 2015-01-05 13:26 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Lavasoft
2017-01-13 15:52 - 2015-01-02 10:15 - 00000000 ____D C:\Users\Micha\AppData\Roaming\DesktopIconAmazon
2017-01-13 15:23 - 2016-11-06 01:54 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-01-13 12:30 - 2015-07-24 19:26 - 00000000 ____D C:\Program Files (x86)\360
2017-01-13 08:17 - 2014-12-14 00:10 - 00000000 ____D C:\Users\Micha\Documents\MAGIX_MusicMaker16_Download-Version
2017-01-11 21:01 - 2014-12-19 21:37 - 00010240 _____ C:\Users\Micha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-01-11 12:42 - 2015-07-15 11:33 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-11 12:40 - 2015-01-21 09:55 - 00004476 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2017-01-11 01:25 - 2009-07-14 06:08 - 00032640 _____ C:\windows\Tasks\SCHEDLGU.TXT
2017-01-11 00:03 - 2014-12-14 16:17 - 00000000 ____D C:\windows\system32\MRT
2017-01-11 00:02 - 2014-12-20 03:20 - 135657872 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2017-01-10 16:17 - 2014-12-14 15:17 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2017-01-10 16:17 - 2014-12-14 15:17 - 00000000 ____D C:\windows\system32\Macromed
2017-01-10 16:17 - 2013-07-31 22:22 - 00802904 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2017-01-10 16:17 - 2013-07-31 22:22 - 00144472 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-01-10 16:17 - 2013-07-31 22:22 - 00000000 ____D C:\windows\SysWOW64\Macromed
2017-01-09 15:53 - 2015-09-21 09:06 - 00000000 __SHD C:\$360Section
2017-01-09 15:53 - 2015-09-02 15:13 - 00000000 ____D C:\ProgramData\360Quarant
2017-01-05 20:02 - 2013-07-31 22:29 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-01-05 20:02 - 2013-07-31 22:28 - 00000000 ____D C:\ProgramData\Skype
2017-01-04 13:31 - 2014-12-14 15:54 - 00000000 ____D C:\Program Files (x86)\chip
2017-01-04 10:35 - 2009-07-14 05:45 - 00313104 _____ C:\windows\system32\FNTCACHE.DAT
2017-01-04 10:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\PolicyDefinitions
2017-01-04 10:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\inf
2017-01-04 10:31 - 2013-07-31 21:39 - 01687534 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2017-01-04 10:31 - 2013-07-31 19:42 - 00738178 _____ C:\windows\system32\perfh007.dat
2017-01-04 10:31 - 2013-07-31 19:42 - 00160894 _____ C:\windows\system32\perfc007.dat
2017-01-04 10:31 - 2009-07-14 06:13 - 01687534 _____ C:\windows\system32\PerfStringBackup.INI
2017-01-04 10:31 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\inetsrv
2017-01-04 09:47 - 2016-06-30 15:21 - 00000000 ____D C:\Users\Micha\AppData\Local\ElevatedDiagnostics
2017-01-04 02:21 - 2014-12-14 00:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2017-01-04 02:05 - 2009-07-14 03:34 - 00000568 _____ C:\windows\win.ini
2017-01-03 17:08 - 2015-09-24 19:26 - 00000356 _____ C:\Users\Micha\Desktop\Zitate.txt
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\migration
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\inetsrv
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\migration
2016-12-24 20:13 - 2009-07-14 04:18 - 00000000 __SHD C:\$Recycle.Bin
2016-12-24 00:58 - 2014-12-31 14:21 - 00000000 ____D C:\ProgramData\Freemake
2016-12-24 00:58 - 2014-12-31 14:21 - 00000000 ____D C:\Program Files (x86)\Freemake
2016-12-24 00:00 - 2009-07-14 04:20 - 00000000 ____D C:\windows\Microsoft.NET
2016-12-23 23:52 - 2014-12-14 00:06 - 00000000 ___RD C:\Users\Micha\Videos
2016-12-23 23:20 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2016-12-23 23:18 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-12-23 23:18 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Microsoft Games
2016-12-23 23:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\Drivers\etc
2016-12-23 23:18 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-12-23 19:30 - 2009-07-14 04:20 - 00000000 ____D C:\windows\AppPatch
2016-12-23 15:29 - 2016-11-02 17:00 - 00524288 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 15:29 - 2016-11-02 17:00 - 00065536 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TM.blf
2016-12-23 15:02 - 2016-11-02 17:00 - 00524288 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TMContainer00000000000000000001.regtrans-ms

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2014-09-01 09:18 - 2014-09-01 09:18 - 0001248 _____ () C:\Users\Micha\AppData\Roaming\FODX
2014-12-14 00:06 - 2017-01-19 00:00 - 0003593 _____ () C:\Users\Micha\AppData\Local\BTServer.log
2014-12-19 21:37 - 2017-01-11 21:01 - 0010240 _____ () C:\Users\Micha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert

LastRegBack: 2017-01-16 17:06

==================== Ende von FRST.txt ============================

hier Teil 2
Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 18-01-2017
durchgeführt von Micha (19-01-2017 00:25:58)
Gestartet von C:\Users\Micha\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2014-12-13 23:06:40)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2198626584-3468660724-23365673-500 - Administrator - Disabled)
Gast (S-1-5-21-2198626584-3468660724-23365673-501 - Limited - Disabled)
Micha (S-1-5-21-2198626584-3468660724-23365673-1000 - Administrator - Enabled) => C:\Users\Micha

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.023.20053 - Adobe Systems Incorporated)
Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.194 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated)
BurnRecovery (HKLM-x32\...\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 3.0.1103.1801 - Micro-Star International Co., Ltd.)
Camera RAW Plug-In for EPSON Creativity Suite (HKLM-x32\...\{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}) (Version: 2.1.0.0 - )
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.31 - Cliqz.com)
concept/design onlineTV 11 (HKLM-x32\...\{8A4C3184-DA2F-4553-BF61-83F5690C3048}_is1) (Version: 11.0.0.0 - concept/design GmbH)
CX4300_5500_DX4400 Handbuch (HKLM-x32\...\CX4300_5500_DX4400 Handbuch) (Version:  - )
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.4612 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
EPSON Attach To Email (HKLM-x32\...\InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON)
EPSON Attach To Email (x32 Version: 1.01.0000 - SEIKO EPSON) Hidden
EPSON Copy Utility 3 (HKLM-x32\...\{67EDD823-135A-4D59-87BD-950616D6E857}) (Version: 3.2.0.0 - )
EPSON File Manager (HKLM-x32\...\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}) (Version: 1.3.0.0 - )
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
EPSON Scan Assistant (HKLM-x32\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - )
EPSON SX100 Series Printer Uninstall (HKLM\...\EPSON SX100 Series) (Version:  - SEIKO EPSON Corporation)
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version:  - SEIKO EPSON Corporation)
ETDWare PS/2-X64 11.13.2.4_WHQL (HKLM\...\Elantech) (Version: 11.13.2.4 - ELAN Microelectronic Corp.)
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}) (Version: 2.1.27.0 - MAGIX AG)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
FreePDF (Remove only) (HKLM-x32\...\FreePDF_XP) (Version:  - )
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
GPL Ghostscript (HKLM\...\GPL Ghostscript 9.07) (Version: 9.07 - Artifex Software Inc.)
GPL Ghostscript (HKLM-x32\...\GPL Ghostscript 9.15) (Version: 9.15 - Artifex Software Inc.)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1310 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3186 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.5.0.1066 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.6 (HKLM\...\{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.6.2.0 - Intel)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
LavasoftTcpService (x32 Version: 2.2.9.5 - Lavasoft) Hidden
MAGIX Music Maker 16 Download-Version (HKLM-x32\...\MAGIX Music Maker 16 Download-Version D) (Version: 16.0.3.0 - MAGIX AG)
MAGIX Online Druck Service (HKLM-x32\...\MAGIX Online Druck Service D) (Version: 3.4.3.0 - MAGIX AG)
MAGIX Screenshare (HKLM-x32\...\MAGIX Screenshare D) (Version: 4.3.6.1987 - MAGIX AG)
MAGIX Speed burnR (HKLM-x32\...\MAGIX Speed burnR D) (Version: 7.0.2.6 - MAGIX AG)
Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Malwarebytes Version 3.0.5.1299 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mobile Partner (HKLM-x32\...\Mobile Partner) (Version: 16.002.03.01.40 - Huawei Technologies Co.,Ltd)
Movavi Video Suite 14 (HKLM-x32\...\Movavi Video Suite 14) (Version: 14.0.1 - Movavi)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 50.1.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 de)) (Version: 50.1.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla)
MSI Battery Calibration (HKLM-x32\...\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.0.1 - Micro-Star International Co., Ltd.)
MSI HOUSE (HKLM-x32\...\{DA5597C9-9216-44FF-9670-D1E48817B998}) (Version: 10.07.1601 - MSI)
MSI Software Install (HKLM-x32\...\{332EBFE0-C39E-42D1-99B5-ABBBECAD71B6}) (Version: 4.0.1105.1701 - Micro-Star International Co., Ltd.)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.51.17865 - pdfforge GmbH)
PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Edit Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 View Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.1 - pdfforge)
Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.13 - Qualcomm Atheros Communications Inc.)
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.728.728.042813 - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6914 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0212 - )
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: 1.90 - Ghostgum Software Pty Ltd)
Revo Uninstaller 2.0.2 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.2 - VS Revo Group, Ltd.)
SCM (HKLM\...\{CA85D7A7-6B45-4011-9BCC-C01F31EDE157}) (Version: 14.013.07054 -  )
Shotcut (HKLM-x32\...\Shotcut) (Version:  - )
Skype™ 7.30 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.30.105 - Skype Technologies S.A.)
SoftMaker FreeOffice (HKLM-x32\...\{8EBB8452-274B-465D-8324-00B0832FBB02}) (Version: 1.0.3475 - SoftMaker Software GmbH)
Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.017 - MSI)
Sweepi 5.4.00 (HKLM-x32\...\Sweepi_is1) (Version: 5.4.00 - YooApplications)
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinZip 19.0 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E4}) (Version: 19.0.11293 - WinZip Computing, S.L. )

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {17608ADD-35B5-4F2A-A369-E67C96C0B20E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {3DA3586E-C068-4460-B103-15DDD7C51B40} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-10] (Adobe Systems Incorporated)
Task: {3F283151-7529-496F-9366-FCAEC83C2694} - System32\Tasks\1215tbUpdateInfo => C:\ProgramData\Avg_Update_1215tb\1215tb_{4D479988-B227-4153-A15F-3D6D13E85735}.exe
Task: {63050248-0821-4CF1-A0FA-3D7C370A627F} - System32\Tasks\{42239007-962A-405B-897B-E4E0207270AF} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.24.0.104&amp;LastError=404
Task: {96FEB751-76F6-4B79-B85A-B188D39EBB02} - System32\Tasks\{DDE7AD7B-E373-4700-9749-EFD63E11B429} => C:\Windows\twain_32\escndv\escndv.exe [2008-04-06] (SEIKO EPSON CORP.)
Task: {B2A759E8-D7A6-40F4-8583-1B21178BF297} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: {DF814115-C649-4F46-9705-DDBEC44F373C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {E499296A-F20A-4ACE-9CD0-242A1F09B9A3} - System32\Tasks\{129E23B6-40C3-4E2D-BA39-481FE58B2A62} => C:\Program Files\PDFCreator\PDFCreator.exe [2014-12-16] (pdfforge)
Task: {FB0D8A3E-E462-456A-A960-0E05DB4FE8BC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-01-09 01:19 - 2012-06-21 07:25 - 00113152 _____ () C:\windows\System32\redmon64.dll
2013-07-31 21:55 - 2013-04-26 00:32 - 00047104 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
2013-07-31 21:55 - 2013-04-09 22:42 - 00265728 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\SkypePlugin.exe
2012-05-30 21:15 - 2012-05-30 21:15 - 00404008 _____ () C:\Program Files\Intel\TurboBoost\de\SignalIslandUi.resources.dll
2013-07-31 21:37 - 2013-02-16 00:15 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1 - 192.168.0.2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [TCP Query User{F5428C65-02FD-4258-9D3B-DBA9131CD043}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{58EAA851-0F4D-4025-A9FA-82AAC4EEC077}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{FC62AAD4-D5DF-4232-B263-4FC654D0457F}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{9D370156-D01D-4231-A5C5-E72B2D7C382D}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{EB01AC34-1000-4725-AB7E-266EF7070BAE}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6AED153C-CE2F-4F79-A73D-5DA437D8EDD9}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4AE2CA5C-F80C-436A-B9FF-2E8E125414F6}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{4B1F3D68-AEF2-4EE3-A176-82754C956CCF}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{535793E5-DA7A-48C6-9675-333B3C13480E}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1A36325C-7D02-4CAE-968A-A8054B57A386}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{60005B18-84B8-4665-9D35-482C3A16A343}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{2FA7CE91-EAFF-49F9-B2DF-C5687CA4B179}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{72F59172-3120-434F-8648-B19F920FA80F}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{76C646E5-E59E-4079-91C6-6DB2955E5955}] => C:\Program Files (x86)\Skype\Phone\Skype.exe

==================== Wiederherstellungspunkte =========================

10-11-2016 06:10:16 Windows Update
26-11-2016 13:55:57 Geplanter Prüfpunkt
27-11-2016 17:27:32 Installed Windows Mobile-Gerätecenter
05-12-2016 20:53:37 AA11
09-12-2016 20:06:44 Removed Visual Studio 2012 x86 Redistributables
09-12-2016 20:08:07 Removed Visual Studio 2012 x64 Redistributables
15-12-2016 03:00:20 Windows Update
15-12-2016 19:14:17 AA11
16-12-2016 01:31:33 Windows Update
18-12-2016 11:42:27 Removed DriverUpdate
18-12-2016 11:45:52 Removed DriverUpdate
23-12-2016 16:08:55 Wiederherstellungsvorgang
23-12-2016 23:16:31 Windows Modules Installer
25-12-2016 00:00:28 Windows Update
03-01-2017 23:19:17 Wiederherstellungsvorgang
04-01-2017 01:02:43 Installed DRIVERfighter.
04-01-2017 02:23:30 Removed DriverUpdate
04-01-2017 09:36:49 Windows Update
04-01-2017 09:58:19 Windows Update
04-01-2017 10:00:56 Windows Update
04-01-2017 10:02:20 Windows Update
04-01-2017 10:26:13 Windows Update
04-01-2017 13:27:41 Removed DriverUpdate
04-01-2017 13:30:28 Removed CHIP Best Deal
04-01-2017 13:44:48 Konfiguriert Camera RAW Plug-In for EPSON Creativity Suite
04-01-2017 14:01:35 Driver Reviver (04/01/2017 14:01)
04-01-2017 17:31:04 Removed Skype™ 7.30
04-01-2017 18:18:15 Windows Update
05-01-2017 00:00:55 Windows Update
05-01-2017 00:41:14 Windows Update
05-01-2017 00:48:52 Windows Update
05-01-2017 00:54:51 Windows Update
10-01-2017 15:42:24 Installed DriverUpdate
10-01-2017 19:40:37 Windows Update
10-01-2017 19:45:26 Windows Update
10-01-2017 19:56:24 Windows Update
10-01-2017 19:58:33 Windows Update
10-01-2017 20:27:38 Windows Update
11-01-2017 00:00:21 Windows Update
11-01-2017 01:01:28 Wiederherstellungsvorgang
13-01-2017 12:14:21 AA11
13-01-2017 15:52:00 Malwarebytes Anti-Rootkit Restore Point
14-01-2017 18:11:18 JRT Pre-Junkware Removal
14-01-2017 18:26:46 JRT Pre-Junkware Removal
16-01-2017 12:41:07 Revo Uninstaller's restore point - QuickTime 7
16-01-2017 12:46:53 Revo Uninstaller's restore point - Panda Security Toolbar
16-01-2017 12:50:16 Revo Uninstaller's restore point - Mobile Partner
16-01-2017 13:03:08 Revo Uninstaller's restore point - McAfee Security Scan Plus
16-01-2017 13:06:34 Revo Uninstaller's restore point - OpenOffice 4.1.2
16-01-2017 13:37:14 Revo Uninstaller's restore point - Apple Application Support (32-Bit)
16-01-2017 14:06:03 Revo Uninstaller's restore point - Apple Application Support (32-Bit)
16-01-2017 14:10:54 Revo Uninstaller's restore point - Apple Application Support (64-Bit)
16-01-2017 14:13:17 Revo Uninstaller's restore point - Apple Software Update
16-01-2017 14:15:35 Revo Uninstaller's restore point - iCloud
16-01-2017 14:18:04 Revo Uninstaller's restore point - Bonjour
16-01-2017 14:18:25 Removed Bonjour
16-01-2017 14:19:56 Revo Uninstaller's restore point - iCloud
16-01-2017 15:15:12 Installed iCloud
17-01-2017 08:23:19 Windows Update
18-01-2017 23:31:45 Revo Uninstaller's restore point - Norton Anti-Theft
18-01-2017 23:37:54 Revo Uninstaller's restore point - Norton PC Checkup
18-01-2017 23:40:44 Revo Uninstaller's restore point - Norton Online Backup
18-01-2017 23:41:09 Removed Norton Online Backup
18-01-2017 23:45:03 Revo Uninstaller's restore point - Web Companion

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Microsoft-Teredo-Tunneling-Adapter
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (01/18/2017 11:31:44 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.


Vorgang:
  Generatordaten werden gesammelt

Kontext:
  Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
  Generatorname: System Writer
  Generatorinstanz-ID: {4d71648a-bf67-4c49-a3fe-9561b2e67d11}

Error: (01/18/2017 08:46:26 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/18/2017 08:46:25 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/18/2017 10:42:28 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "c:\users\micha\downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/17/2017 01:50:08 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/17/2017 01:50:00 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/17/2017 01:49:07 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/17/2017 01:29:19 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/17/2017 01:28:48 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/17/2017 01:28:47 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.


Systemfehler:
=============
Error: (01/19/2017 12:02:32 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: Der Server "{F36AD0D0-B5F0-4C69-AF08-603D177FEF0E}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (01/19/2017 12:01:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Norton PC Checkup Application Launcher" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.

Error: (01/18/2017 11:58:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Common Client Job Manager Service" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.

Error: (01/18/2017 11:58:20 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Norton Anti-Theft" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1.

Error: (01/18/2017 11:41:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Common Client Job Manager Service" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.

Error: (01/18/2017 11:39:02 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Common Client Job Manager Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (01/18/2017 11:39:00 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Norton PC Checkup Application Launcher" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (01/18/2017 11:37:36 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Norton Anti-Theft" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1.

Error: (01/18/2017 11:35:36 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Norton Anti-Theft" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (01/18/2017 12:32:00 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Der Server "{F36AD0D0-B5F0-4C69-AF08-603D177FEF0E}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.


==================== Speicherinformationen ===========================

Prozessor: Intel(R) Pentium(R) CPU 3560M @ 2.40GHz
Prozentuale Nutzung des RAM: 47%
Installierter physikalischer RAM: 4016.81 MB
Verfügbarer physikalischer RAM: 2114.03 MB
Summe virtueller Speicher: 8031.8 MB
Verfügbarer virtueller Speicher: 5536.13 MB

==================== Laufwerke ================================

Drive c: (OS_Install) (Fixed) (Total:272.65 GB) (Free:79.78 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive d: (Data) (Fixed) (Total:181.77 GB) (Free:181.63 GB) NTFS
Drive w: (BIOS_RVY) (Fixed) (Total:11.24 GB) (Free:0.28 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C54CB572)
Partition 1: (Not Active) - (Size=11.2 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=27)
Partition 3: (Not Active) - (Size=272.7 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=181.8 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================

guten morgen Cosinus, sind die Daten für dich verwendbar? wäre nett wenn du mir sagen würdest was ich jetzt weiter nachen kann / soll. weiter mit dem nächsten Schritt aus Post 22 oder ganz neu anfangen?

Gruß MS-Micha

cosinus 19.01.2017 11:59

Diesen Cliqz Müll bitte auch deinstallieren. Und danach ein Fix:


FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\S-1-5-18\...\RunOnce: [panda] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f
HKU\S-1-5-18\...\RunOnce: [panda_XP] => reg.exe delete "HKCU\Software\panda" /f
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop(777).ini [2009-07-14] ()
FF HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\jsjjbqd4.default\extensions\cliqz@cliqz.com => nicht gefunden
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\pandasecuritytb.xml [2015-05-27]
CHR DefaultSearchURL: Default -> http://pandasecurity.mystart.com/results.php?searchsource=omnibar&pr=vmn&id=pandasecuritytb&v=2_3&ent=ds_671&q={searchTerms}
R2 panda_url_filtering; C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe [287752 2015-10-02] (Visicom Media Inc.)
R3 panda_url_filteringd; C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys [51288 2014-03-19] (Visicom Media Inc.)
S2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\SymcPCCULaunchSvc.exe /s [X]
S2 PCCUJobMgr; "C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe" /s "PCCUJobMgr" /m "C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\diMaster.dll" /prefetch:1
C:\Program Files (x86)\Norton PC Checkup
C:\ProgramData\Norton
C:\ProgramData\boost_interprocess
C:\Program Files (x86)\Norton Anti-Theft
C:\Program Files (x86)\360
C:\ProgramData\360Quarant
C:\Program Files (x86)\chip
C:\Program Files (x86)\Lavasoft
C:\ProgramData\Lavasoft
C:\Users\Micha\AppData\Roaming\Lavasoft
emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


milkit54 19.01.2017 12:48

ok soweit hoffentlich richtig gemacht. nachrichlich virenscanner nicht deaktiviert und es kam mal eine Meldung über Ablauf der Testphase MWB (ignoriert)

Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 18-01-2017
durchgeführt von Micha (19-01-2017 12:20:44) Run:3
Gestartet von C:\Users\Micha\Downloads
Geladene Profile: Micha (Verfügbare Profile: Micha & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
HKU\S-1-5-18\...\RunOnce: [panda] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f
HKU\S-1-5-18\...\RunOnce: [panda_XP] => reg.exe delete "HKCU\Software\panda" /f
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop(777).ini [2009-07-14] ()
FF HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\jsjjbqd4.default\extensions\cliqz@cliqz.com => nicht gefunden
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\pandasecuritytb.xml [2015-05-27]
CHR DefaultSearchURL: Default -> hxxp://pandasecurity.mystart.com/results.php?searchsource=omnibar&pr=vmn&id=pandasecuritytb&v=2_3&ent=ds_671&q={searchTerms}
R2 panda_url_filtering; C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe [287752 2015-10-02] (Visicom Media Inc.)
R3 panda_url_filteringd; C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys [51288 2014-03-19] (Visicom Media Inc.)
S2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\SymcPCCULaunchSvc.exe /s [X]
S2 PCCUJobMgr; "C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe" /s "PCCUJobMgr" /m "C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\diMaster.dll" /prefetch:1
C:\Program Files (x86)\Norton PC Checkup
C:\ProgramData\Norton
C:\ProgramData\boost_interprocess
C:\Program Files (x86)\Norton Anti-Theft
C:\Program Files (x86)\360
C:\ProgramData\360Quarant
C:\Program Files (x86)\chip
C:\Program Files (x86)\Lavasoft
C:\ProgramData\Lavasoft
C:\Users\Micha\AppData\Roaming\Lavasoft
emptytemp:
       
*****************

HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\panda => Wert erfolgreich entfernt
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\panda_XP => Wert erfolgreich entfernt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop(777).ini => erfolgreich verschoben
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Software\Mozilla\Firefox\Extensions\\cliqz@cliqz.com => Wert nicht gefunden.
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\pandasecuritytb.xml => erfolgreich verschoben
Chrome DefaultSearchURL => erfolgreich entfernt
panda_url_filtering => Dienst erfolgreich gestoppt.
HKLM\System\CurrentControlSet\Services\panda_url_filtering => Schlüssel erfolgreich entfernt
panda_url_filtering => Dienst erfolgreich entfernt
panda_url_filteringd => Dienst nicht gefunden.
HKLM\System\CurrentControlSet\Services\Norton PC Checkup Application Launcher => Schlüssel erfolgreich entfernt
Norton PC Checkup Application Launcher => Dienst erfolgreich entfernt
HKLM\System\CurrentControlSet\Services\PCCUJobMgr => Schlüssel erfolgreich entfernt
PCCUJobMgr => Dienst erfolgreich entfernt
"C:\Program Files (x86)\Norton PC Checkup" => nicht gefunden.
C:\ProgramData\Norton => erfolgreich verschoben
C:\ProgramData\boost_interprocess => erfolgreich verschoben
C:\Program Files (x86)\Norton Anti-Theft => erfolgreich verschoben
C:\Program Files (x86)\360 => erfolgreich verschoben
C:\ProgramData\360Quarant => erfolgreich verschoben
C:\Program Files (x86)\chip => erfolgreich verschoben
C:\Program Files (x86)\Lavasoft => erfolgreich verschoben
C:\ProgramData\Lavasoft => erfolgreich verschoben
C:\Users\Micha\AppData\Roaming\Lavasoft => erfolgreich verschoben

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12362219 B
Java, Flash, Steam htmlcache => 1668 B
Windows/system/drivers => 5364 B
Edge => 0 B
Chrome => 7011925 B
Firefox => 144688821 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
Micha => 3538835 B
DefaultAppPool => 0 B

RecycleBin => 107071027 B
EmptyTemp: => 262 MB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 12:21:03 ====


cosinus 19.01.2017 14:32

neue FRST Logs bitte

milkit54 19.01.2017 15:48

hallo Cosinus, ich habe ein Problem die Dateien bei meinem PC wiederzufinden, oder ich bin zu unsicher.
Das Programm FRST64.exe ist als Verknüpfung auf meinem Bildschirm zu finden.
Die Frst log und addition finde ich in der Bibliothek Bilder ? versteh ich alles nicht aber egal ich hoffe du kannst mit den Dateien trotzdem was anfangen ?
als erstes die Addition
Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 18-01-2017
durchgeführt von Micha (19-01-2017 15:30:29)
Gestartet von C:\Users\Micha\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2014-12-13 23:06:40)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2198626584-3468660724-23365673-500 - Administrator - Disabled)
Gast (S-1-5-21-2198626584-3468660724-23365673-501 - Limited - Disabled)
Micha (S-1-5-21-2198626584-3468660724-23365673-1000 - Administrator - Enabled) => C:\Users\Micha

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.023.20053 - Adobe Systems Incorporated)
Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.194 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated)
BurnRecovery (HKLM-x32\...\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 3.0.1103.1801 - Micro-Star International Co., Ltd.)
Camera RAW Plug-In for EPSON Creativity Suite (HKLM-x32\...\{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}) (Version: 2.1.0.0 - )
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
concept/design onlineTV 11 (HKLM-x32\...\{8A4C3184-DA2F-4553-BF61-83F5690C3048}_is1) (Version: 11.0.0.0 - concept/design GmbH)
CX4300_5500_DX4400 Handbuch (HKLM-x32\...\CX4300_5500_DX4400 Handbuch) (Version:  - )
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.4612 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
EPSON Attach To Email (HKLM-x32\...\InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON)
EPSON Attach To Email (x32 Version: 1.01.0000 - SEIKO EPSON) Hidden
EPSON Copy Utility 3 (HKLM-x32\...\{67EDD823-135A-4D59-87BD-950616D6E857}) (Version: 3.2.0.0 - )
EPSON File Manager (HKLM-x32\...\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}) (Version: 1.3.0.0 - )
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
EPSON Scan Assistant (HKLM-x32\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - )
EPSON SX100 Series Printer Uninstall (HKLM\...\EPSON SX100 Series) (Version:  - SEIKO EPSON Corporation)
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version:  - SEIKO EPSON Corporation)
ETDWare PS/2-X64 11.13.2.4_WHQL (HKLM\...\Elantech) (Version: 11.13.2.4 - ELAN Microelectronic Corp.)
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}) (Version: 2.1.27.0 - MAGIX AG)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
FreePDF (Remove only) (HKLM-x32\...\FreePDF_XP) (Version:  - )
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
GPL Ghostscript (HKLM\...\GPL Ghostscript 9.07) (Version: 9.07 - Artifex Software Inc.)
GPL Ghostscript (HKLM-x32\...\GPL Ghostscript 9.15) (Version: 9.15 - Artifex Software Inc.)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1310 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3186 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.5.0.1066 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.6 (HKLM\...\{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.6.2.0 - Intel)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
LavasoftTcpService (x32 Version: 2.2.9.5 - Lavasoft) Hidden
MAGIX Music Maker 16 Download-Version (HKLM-x32\...\MAGIX Music Maker 16 Download-Version D) (Version: 16.0.3.0 - MAGIX AG)
MAGIX Online Druck Service (HKLM-x32\...\MAGIX Online Druck Service D) (Version: 3.4.3.0 - MAGIX AG)
MAGIX Screenshare (HKLM-x32\...\MAGIX Screenshare D) (Version: 4.3.6.1987 - MAGIX AG)
MAGIX Speed burnR (HKLM-x32\...\MAGIX Speed burnR D) (Version: 7.0.2.6 - MAGIX AG)
Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Malwarebytes Version 3.0.5.1299 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mobile Partner (HKLM-x32\...\Mobile Partner) (Version: 16.002.03.01.40 - Huawei Technologies Co.,Ltd)
Movavi Video Suite 14 (HKLM-x32\...\Movavi Video Suite 14) (Version: 14.0.1 - Movavi)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 50.1.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 de)) (Version: 50.1.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla)
MSI Battery Calibration (HKLM-x32\...\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.0.1 - Micro-Star International Co., Ltd.)
MSI HOUSE (HKLM-x32\...\{DA5597C9-9216-44FF-9670-D1E48817B998}) (Version: 10.07.1601 - MSI)
MSI Software Install (HKLM-x32\...\{332EBFE0-C39E-42D1-99B5-ABBBECAD71B6}) (Version: 4.0.1105.1701 - Micro-Star International Co., Ltd.)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.51.17865 - pdfforge GmbH)
PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Edit Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 View Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.1 - pdfforge)
Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.13 - Qualcomm Atheros Communications Inc.)
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.728.728.042813 - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6914 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0212 - )
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: 1.90 - Ghostgum Software Pty Ltd)
Revo Uninstaller 2.0.2 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.2 - VS Revo Group, Ltd.)
SCM (HKLM\...\{CA85D7A7-6B45-4011-9BCC-C01F31EDE157}) (Version: 14.013.07054 -  )
Shotcut (HKLM-x32\...\Shotcut) (Version:  - )
Skype™ 7.30 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.30.105 - Skype Technologies S.A.)
SoftMaker FreeOffice (HKLM-x32\...\{8EBB8452-274B-465D-8324-00B0832FBB02}) (Version: 1.0.3475 - SoftMaker Software GmbH)
Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.017 - MSI)
Sweepi 5.4.00 (HKLM-x32\...\Sweepi_is1) (Version: 5.4.00 - YooApplications)
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinZip 19.0 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E4}) (Version: 19.0.11293 - WinZip Computing, S.L. )

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {17608ADD-35B5-4F2A-A369-E67C96C0B20E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {3DA3586E-C068-4460-B103-15DDD7C51B40} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-10] (Adobe Systems Incorporated)
Task: {3F283151-7529-496F-9366-FCAEC83C2694} - System32\Tasks\1215tbUpdateInfo => C:\ProgramData\Avg_Update_1215tb\1215tb_{4D479988-B227-4153-A15F-3D6D13E85735}.exe
Task: {63050248-0821-4CF1-A0FA-3D7C370A627F} - System32\Tasks\{42239007-962A-405B-897B-E4E0207270AF} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.24.0.104&amp;LastError=404
Task: {96FEB751-76F6-4B79-B85A-B188D39EBB02} - System32\Tasks\{DDE7AD7B-E373-4700-9749-EFD63E11B429} => C:\Windows\twain_32\escndv\escndv.exe [2008-04-06] (SEIKO EPSON CORP.)
Task: {B2A759E8-D7A6-40F4-8583-1B21178BF297} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: {DF814115-C649-4F46-9705-DDBEC44F373C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {E499296A-F20A-4ACE-9CD0-242A1F09B9A3} - System32\Tasks\{129E23B6-40C3-4E2D-BA39-481FE58B2A62} => C:\Program Files\PDFCreator\PDFCreator.exe [2014-12-16] (pdfforge)
Task: {FB0D8A3E-E462-456A-A960-0E05DB4FE8BC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-01-09 01:19 - 2012-06-21 07:25 - 00113152 _____ () C:\windows\System32\redmon64.dll
2013-07-31 21:55 - 2013-04-26 00:32 - 00047104 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
2013-07-31 21:55 - 2013-04-09 22:42 - 00265728 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\SkypePlugin.exe
2012-05-30 21:15 - 2012-05-30 21:15 - 00404008 _____ () C:\Program Files\Intel\TurboBoost\de\SignalIslandUi.resources.dll
2013-07-31 21:37 - 2013-02-16 00:15 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)


==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1 - 192.168.0.2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==


==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [TCP Query User{F5428C65-02FD-4258-9D3B-DBA9131CD043}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{58EAA851-0F4D-4025-A9FA-82AAC4EEC077}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{FC62AAD4-D5DF-4232-B263-4FC654D0457F}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{9D370156-D01D-4231-A5C5-E72B2D7C382D}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{EB01AC34-1000-4725-AB7E-266EF7070BAE}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6AED153C-CE2F-4F79-A73D-5DA437D8EDD9}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4AE2CA5C-F80C-436A-B9FF-2E8E125414F6}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{4B1F3D68-AEF2-4EE3-A176-82754C956CCF}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{535793E5-DA7A-48C6-9675-333B3C13480E}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1A36325C-7D02-4CAE-968A-A8054B57A386}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{60005B18-84B8-4665-9D35-482C3A16A343}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{2FA7CE91-EAFF-49F9-B2DF-C5687CA4B179}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{72F59172-3120-434F-8648-B19F920FA80F}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{76C646E5-E59E-4079-91C6-6DB2955E5955}] => C:\Program Files (x86)\Skype\Phone\Skype.exe

==================== Wiederherstellungspunkte =========================

26-11-2016 13:55:57 Geplanter Prüfpunkt
27-11-2016 17:27:32 Installed Windows Mobile-Gerätecenter
05-12-2016 20:53:37 AA11
09-12-2016 20:06:44 Removed Visual Studio 2012 x86 Redistributables
09-12-2016 20:08:07 Removed Visual Studio 2012 x64 Redistributables
15-12-2016 03:00:20 Windows Update
15-12-2016 19:14:17 AA11
16-12-2016 01:31:33 Windows Update
18-12-2016 11:42:27 Removed DriverUpdate
18-12-2016 11:45:52 Removed DriverUpdate
23-12-2016 16:08:55 Wiederherstellungsvorgang
23-12-2016 23:16:31 Windows Modules Installer
25-12-2016 00:00:28 Windows Update
03-01-2017 23:19:17 Wiederherstellungsvorgang
04-01-2017 01:02:43 Installed DRIVERfighter.
04-01-2017 02:23:30 Removed DriverUpdate
04-01-2017 09:36:49 Windows Update
04-01-2017 09:58:19 Windows Update
04-01-2017 10:00:56 Windows Update
04-01-2017 10:02:20 Windows Update
04-01-2017 10:26:13 Windows Update
04-01-2017 13:27:41 Removed DriverUpdate
04-01-2017 13:30:28 Removed CHIP Best Deal
04-01-2017 13:44:48 Konfiguriert Camera RAW Plug-In for EPSON Creativity Suite
04-01-2017 14:01:35 Driver Reviver (04/01/2017 14:01)
04-01-2017 17:31:04 Removed Skype™ 7.30
04-01-2017 18:18:15 Windows Update
05-01-2017 00:00:55 Windows Update
05-01-2017 00:41:14 Windows Update
05-01-2017 00:48:52 Windows Update
05-01-2017 00:54:51 Windows Update
10-01-2017 15:42:24 Installed DriverUpdate
10-01-2017 19:40:37 Windows Update
10-01-2017 19:45:26 Windows Update
10-01-2017 19:56:24 Windows Update
10-01-2017 19:58:33 Windows Update
10-01-2017 20:27:38 Windows Update
11-01-2017 00:00:21 Windows Update
11-01-2017 01:01:28 Wiederherstellungsvorgang
13-01-2017 12:14:21 AA11
13-01-2017 15:52:00 Malwarebytes Anti-Rootkit Restore Point
14-01-2017 18:11:18 JRT Pre-Junkware Removal
14-01-2017 18:26:46 JRT Pre-Junkware Removal
16-01-2017 12:41:07 Revo Uninstaller's restore point - QuickTime 7
16-01-2017 12:46:53 Revo Uninstaller's restore point - Panda Security Toolbar
16-01-2017 12:50:16 Revo Uninstaller's restore point - Mobile Partner
16-01-2017 13:03:08 Revo Uninstaller's restore point - McAfee Security Scan Plus
16-01-2017 13:06:34 Revo Uninstaller's restore point - OpenOffice 4.1.2
16-01-2017 13:37:14 Revo Uninstaller's restore point - Apple Application Support (32-Bit)
16-01-2017 14:06:03 Revo Uninstaller's restore point - Apple Application Support (32-Bit)
16-01-2017 14:10:54 Revo Uninstaller's restore point - Apple Application Support (64-Bit)
16-01-2017 14:13:17 Revo Uninstaller's restore point - Apple Software Update
16-01-2017 14:15:35 Revo Uninstaller's restore point - iCloud
16-01-2017 14:18:04 Revo Uninstaller's restore point - Bonjour
16-01-2017 14:18:25 Removed Bonjour
16-01-2017 14:19:56 Revo Uninstaller's restore point - iCloud
16-01-2017 15:15:12 Installed iCloud
17-01-2017 08:23:19 Windows Update
18-01-2017 23:31:45 Revo Uninstaller's restore point - Norton Anti-Theft
18-01-2017 23:37:54 Revo Uninstaller's restore point - Norton PC Checkup
18-01-2017 23:40:44 Revo Uninstaller's restore point - Norton Online Backup
18-01-2017 23:41:09 Removed Norton Online Backup
18-01-2017 23:45:03 Revo Uninstaller's restore point - Web Companion
19-01-2017 12:04:41 Revo Uninstaller's restore point - Cliqz

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Microsoft-Teredo-Tunneling-Adapter
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (01/19/2017 12:04:40 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.


Vorgang:
  Generatordaten werden gesammelt

Kontext:
  Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
  Generatorname: System Writer
  Generatorinstanz-ID: {9038023d-378f-4a5b-94d2-33130369551a}

Error: (01/18/2017 11:31:44 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.


Vorgang:
  Generatordaten werden gesammelt

Kontext:
  Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
  Generatorname: System Writer
  Generatorinstanz-ID: {4d71648a-bf67-4c49-a3fe-9561b2e67d11}

Error: (01/18/2017 08:46:26 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/18/2017 08:46:25 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/18/2017 10:42:28 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "c:\users\micha\downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/17/2017 01:50:08 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/17/2017 01:50:00 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/17/2017 01:49:07 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/17/2017 01:29:19 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error: (01/17/2017 01:28:48 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe". Fehler in
Manifest- oder Richtliniendatei "" in Zeile .
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.


Systemfehler:
=============
Error: (01/19/2017 12:28:20 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Der Server "{F36AD0D0-B5F0-4C69-AF08-603D177FEF0E}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (01/19/2017 12:25:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Norton Anti-Theft" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.

Error: (01/19/2017 12:02:32 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: Der Server "{F36AD0D0-B5F0-4C69-AF08-603D177FEF0E}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (01/19/2017 12:01:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Norton PC Checkup Application Launcher" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.

Error: (01/18/2017 11:58:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Common Client Job Manager Service" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.

Error: (01/18/2017 11:58:20 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Norton Anti-Theft" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1.

Error: (01/18/2017 11:41:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Common Client Job Manager Service" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.

Error: (01/18/2017 11:39:02 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Common Client Job Manager Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (01/18/2017 11:39:00 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Norton PC Checkup Application Launcher" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (01/18/2017 11:37:36 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Norton Anti-Theft" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1.


==================== Speicherinformationen ===========================

Prozessor: Intel(R) Pentium(R) CPU 3560M @ 2.40GHz
Prozentuale Nutzung des RAM: 61%
Installierter physikalischer RAM: 4016.81 MB
Verfügbarer physikalischer RAM: 1565.34 MB
Summe virtueller Speicher: 8031.8 MB
Verfügbarer virtueller Speicher: 5251.22 MB

==================== Laufwerke ================================

Drive c: (OS_Install) (Fixed) (Total:272.65 GB) (Free:81.36 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive d: (Data) (Fixed) (Total:181.77 GB) (Free:181.63 GB) NTFS
Drive w: (BIOS_RVY) (Fixed) (Total:11.24 GB) (Free:0.28 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C54CB572)
Partition 1: (Not Active) - (Size=11.2 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=27)
Partition 3: (Not Active) - (Size=272.7 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=181.8 GB) - (Type=07 NTFS)

==================== Ende von Addition.txt ============================

als 2. die Frst

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 18-01-2017
durchgeführt von Micha (Administrator) auf MICHA-MSI (19-01-2017 15:30:08)
Gestartet von C:\Users\Micha\Downloads
Geladene Profile: Micha (Verfügbare Profile: Micha & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\AvrcpService.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Microsoft Corporation) C:\Windows\System32\CISVC.EXE
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(MSI) C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\ws.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\creator-ws.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\RtkBleServ.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\SkypePlugin.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(MSI) C:\Program Files (x86)\SCM\Radio Manager.exe
(MSI) C:\Program Files (x86)\SCM\SCM.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdcBase.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(© 2015 Microsoft Corporation) C:\Users\Micha\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Intel® Corporation) C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13538376 2013-05-21] (Realtek Semiconductor)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [253440 2013-04-23] (Realtek Semiconductor Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2875728 2013-03-04] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2013-07-05] (MSI)
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [399528 2013-07-05] (MSI)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [Windows Mobile-based device management] => C:\windows\WindowsMobile\wmdcBase.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-10-13] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [230696 2011-10-13] (CyberLink Corp.)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [490480 2013-02-01] (MSI)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2014-03-18] (shbox.de)
HKLM-x32\...\Run: [APSDaemon] => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series (Kopie 1)] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [EPSON SX100 Series (Kopie 2)] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [BingSvc] => C:\Users\Micha\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27230168 2016-11-15] (Skype Technologies S.A.)
HKU\S-1-5-18\...\Run: [EPSON SX100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [221696 2008-02-05] (SEIKO EPSON CORPORATION)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Keine Datei
Startup: C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.6.lnk [2013-07-31]
ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.6.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2
Tcpip\..\Interfaces\{19590355-955C-4F75-9574-A5178867FB8F}: [DhcpNameServer] 192.168.0.1 192.168.0.2
Tcpip\..\Interfaces\{7AFF0EF0-F8B5-4E22-BED7-5BAC51243C58}: [NameServer] 193.189.244.206 193.189.244.225

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.n-tv.de/
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {2BA0719B-B10C-4176-8BB1-AF2B6E7453E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAM3&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {2BA0719B-B10C-4176-8BB1-AF2B6E7453E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAM3&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={18DC9A1B-75F8-4C91-A21F-328A8F8FCFB0}&mid=2f112f36b90e47cd86aa856e587a95e0-b67d740e056757739f071bdf1b00435729c4d0a4&lang=de&ds=AVG&coid=avgtbavg&cmpid=1016tb&pr=fr&d=2015-01-05 13:55:51&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2198626584-3468660724-23365673-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={18DC9A1B-75F8-4C91-A21F-328A8F8FCFB0}&mid=2f112f36b90e47cd86aa856e587a95e0-b67d740e056757739f071bdf1b00435729c4d0a4&lang=de&ds=AVG&coid=avgtbavg&cmpid=1016tb&pr=fr&d=2015-01-05 13:55:51&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll => Keine Datei
BHO-x32: PDF Architect Helper -> {691B33B0-B86E-47F3-81C7-56E4FE3B929C} -> C:\Program Files (x86)\PDF Architect 2\creator-ie-helper.dll [2014-10-10] (pdfforge GmbH)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - C:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH)

FireFox:
========
FF ProfilePath: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 [2017-01-19]
FF NewTab: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> hxxp://www.n-tv.de/
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> Google
FF Homepage: Mozilla\Firefox\Profiles\0h0153di.default-1478642192766 -> hxxp://www.n-tv.de/
FF Extension: (Test Pilot) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\@testpilot-addon.xpi [2017-01-11]
FF Extension: (GMX MailCheck) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\browser-mailcheck@gmx.net [2016-11-23]
FF Extension: (Awesome Screenshot - Capture, Annotate & More) - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\0h0153di.default-1478642192766\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2017-01-10]
FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: (PDF Architect 2 Creator) - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2015-01-20] [ist nicht signiert]
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-10] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-10] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-02-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-02-16] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll [2014-10-10] (pdfforge GmbH)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=de-de
CHR DefaultSearchKeyword: Default -> yahoo
CHR Profile: C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default [2017-01-19]
CHR Extension: (Kein Name) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-15]
CHR Extension: (Adobe Acrobat) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-18]
CHR Extension: (Yahoo!) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdhbkaahephniejapepaiggngjnedpci [2017-01-18]
CHR Extension: (MSN Homepage) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkcgfbgohboipdhliafmacjnhjbhmim [2017-01-18]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-18]
CHR Extension: (Chrome Media Router) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-18]
CHR HKU\S-1-5-21-2198626584-3468660724-23365673-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fkkcgfbgohboipdhliafmacjnhjbhmim] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fdhbkaahephniejapepaiggngjnedpci] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AvrcpService; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe [35328 2013-04-02] (Realtek Semiconductor Corporation) [Datei ist nicht signiert]
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [47104 2013-04-26] () [Datei ist nicht signiert]
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [Datei ist nicht signiert]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [Datei ist nicht signiert]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-02-16] (Intel Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2013-07-05] (Micro-Star International Co., Ltd.) [Datei ist nicht signiert]
R2 MSI Foundation Service; C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe [12800 2010-07-17] (MSI) [Datei ist nicht signiert]
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [143856 2013-02-01] (MSI)
R2 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1771560 2014-10-10] (pdfforge GmbH)
R2 PDF Architect 2 Creator; C:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
R2 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-10-10] (pdfforge GmbH)
R2 RtkBleServ; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\RtkBleServ.exe [42496 2013-04-26] (Realtek Semiconductor Corporation) [Datei ist nicht signiert]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 McComponentHostService; "C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe" [X]
S2 NAT; "C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe" /s "NAT" /m "C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\diMaster.dll" /prefetch:1

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ccSet_NAT; C:\windows\system32\drivers\NATx64\0106000.011\ccSetx64.sys [168096 2012-08-07] (Symantec Corporation)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [77416 2016-12-14] ()
S3 ewusbnet; C:\windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 hwusbdev; C:\windows\System32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
R0 iaStorF; C:\windows\System32\drivers\iaStorF.sys [28656 2013-03-22] (Intel Corporation)
R3 L1C; C:\windows\System32\DRIVERS\L1C62x64.sys [118504 2013-05-07] (Qualcomm Atheros Co., Ltd.)
R2 MBAMChameleon; C:\windows\system32\drivers\MBAMChameleon.sys [140672 2016-03-10] (Malwarebytes)
S3 MBAMFarflt; C:\windows\system32\drivers\farflt.sys [102856 2017-01-16] (Malwarebytes)
S3 MBAMProtection; C:\windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-01-19] (Malwarebytes)
S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [81696 2017-01-16] (Malwarebytes)
S3 MBAMWebProtection; C:\windows\system32\drivers\mwac.sys [81696 2017-01-16] (Malwarebytes)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-26] (MSI)
S3 RtkAvrcp; C:\windows\system32\drivers\RtkAvrcp.sys [61152 2012-12-27] (Realtek Semiconductor Corporation)
S3 RtkAvrcpCtrlr; C:\windows\system32\drivers\RtkAvrcpCtrlr.sys [66376 2013-04-08] (Realtek Semiconductor Corporation)
R3 RtkBtFilter; C:\windows\System32\DRIVERS\RtkBtfilter.sys [535624 2013-03-28] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\windows\System32\DRIVERS\rtwlane.sys [1514568 2013-05-02] (Realtek Semiconductor Corporation                          )
S3 MGHwCtrl; \??\C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-01-19 15:00 - 2017-01-19 14:51 - 00001713 _____ C:\Users\Default\Downloads\Fixlist.txt
2017-01-19 15:00 - 2017-01-19 14:51 - 00001713 _____ C:\Users\Default User\Downloads\Fixlist.txt
2017-01-19 14:46 - 2017-01-19 14:46 - 00049192 _____ C:\Users\Micha\Desktop\FRST-1.txt
2017-01-19 14:46 - 2017-01-19 14:46 - 00033309 _____ C:\Users\Micha\Desktop\Addition-1.txt
2017-01-19 12:40 - 2017-01-19 12:40 - 00004558 _____ C:\Users\Micha\Desktop\Fixlog.txt
2017-01-19 12:13 - 2017-01-19 14:51 - 00001713 _____ C:\Users\Micha\Desktop\Fixlist.txt
2017-01-19 00:29 - 2017-01-19 00:29 - 00051103 _____ C:\Users\Micha\Desktop\FRST01192017.txt
2017-01-19 00:27 - 2017-01-19 00:27 - 00033578 _____ C:\Users\Micha\Desktop\Addition.txt
2017-01-19 00:15 - 2017-01-19 00:39 - 00000000 ____D C:\Users\Micha\Desktop\Trojy-18012017
2017-01-18 21:09 - 2017-01-18 21:09 - 00001071 _____ C:\Users\Micha\Downloads\checkup.txt
2017-01-18 21:04 - 2017-01-18 21:04 - 00852720 _____ C:\Users\Micha\Desktop\SecurityCheck.exe
2017-01-16 23:45 - 2017-01-17 13:48 - 02870984 _____ (ESET) C:\Users\Micha\Downloads\esetsmartinstaller_deu.exe
2017-01-16 22:45 - 2017-01-16 22:45 - 00001112 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2017-01-16 22:45 - 2017-01-16 22:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2017-01-16 22:45 - 2017-01-16 22:45 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2017-01-16 22:41 - 2017-01-16 22:41 - 22851472 _____ (Malwarebytes ) C:\Users\Micha\Desktop\mbam-setup-2.2.1.1043.exe
2017-01-16 16:41 - 2017-01-19 12:21 - 00004555 _____ C:\Users\Micha\Downloads\Fixlog.txt
2017-01-16 16:37 - 2017-01-16 16:37 - 00013295 _____ C:\Users\Micha\Desktop\FRST64.exe - Verknüpfung.lnk
2017-01-16 12:29 - 2017-01-16 14:05 - 00001004 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2017-01-16 12:29 - 2017-01-16 14:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2017-01-16 12:29 - 2017-01-16 12:29 - 00000000 ____D C:\Program Files\VS Revo Group
2017-01-16 12:27 - 2017-01-16 12:27 - 07097928 _____ (VS Revo Group ) C:\Users\Micha\Desktop\revo202setup.exe
2017-01-15 17:46 - 2017-01-15 17:46 - 00032851 _____ C:\Users\Micha\Downloads\Addition01152017.txt
2017-01-15 14:42 - 2017-01-19 00:24 - 00000000 ____D C:\Users\Micha\Downloads\FRST-OlderVersion
2017-01-15 12:09 - 2017-01-15 13:43 - 00001729 _____ C:\Users\Micha\Desktop\AdwCleaner[S3].txt
2017-01-14 22:09 - 2017-01-14 22:09 - 00019431 _____ C:\Users\Micha\Desktop\AdwCleaner[C0].txt
2017-01-14 20:02 - 2017-01-14 19:16 - 00018180 _____ C:\Users\Micha\Desktop\AdwCleaner[S0].txt
2017-01-14 18:21 - 2017-01-14 18:21 - 00000268 _____ C:\Users\Micha\Desktop\Junkware Removal Tool - Download - Filepony.URL
2017-01-14 18:19 - 2017-01-14 18:19 - 01663040 _____ (Malwarebytes) C:\Users\Micha\Downloads\JRT(1).exe
2017-01-14 18:15 - 2017-01-14 18:30 - 00000696 _____ C:\Users\Micha\Desktop\JRT.txt
2017-01-14 18:10 - 2017-01-14 18:10 - 01663040 _____ (Malwarebytes) C:\Users\Micha\Downloads\JRT.exe
2017-01-14 18:06 - 2017-01-14 18:06 - 00017147 _____ C:\Users\Micha\Desktop\w2WQUGsI.htm
2017-01-14 17:40 - 2017-01-14 22:20 - 00000000 ____D C:\AdwCleaner
2017-01-14 17:37 - 2017-01-14 17:37 - 03988944 _____ C:\Users\Micha\Desktop\AdwCleaner_6.042.exe
2017-01-13 21:12 - 2017-01-13 22:37 - 00222352 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_21.12.52_log.txt
2017-01-13 21:09 - 2017-01-13 21:12 - 00219050 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_21.09.19_log.txt
2017-01-13 21:04 - 2017-01-13 21:05 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Micha\Downloads\tdsskiller(1).exe
2017-01-13 17:15 - 2017-01-13 17:29 - 00219050 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_17.15.21_log.txt
2017-01-13 17:09 - 2017-01-13 17:12 - 00219050 _____ C:\TDSSKiller.3.1.0.12_13.01.2017_17.09.39_log.txt
2017-01-13 17:07 - 2017-01-13 17:07 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Micha\Desktop\tdsskiller.exe
2017-01-13 15:23 - 2017-01-14 22:06 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-01-13 15:17 - 2017-01-13 16:56 - 00000000 ____D C:\Users\Micha\Desktop\mbar
2017-01-13 15:07 - 2017-01-13 15:08 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Micha\Desktop\mbar-1.09.3.1001.exe
2017-01-13 08:17 - 2017-01-13 08:17 - 00000000 ____D C:\Users\Micha\Documents\MAGIX Downloads
2017-01-12 23:06 - 2017-01-13 11:42 - 00000000 ____D C:\Users\Micha\Desktop\Trboard
2017-01-12 10:56 - 2017-01-12 10:57 - 00084152 _____ C:\Users\Micha\Downloads\Addition .txt
2017-01-10 20:59 - 2017-01-05 19:55 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2017-01-10 20:59 - 2017-01-05 19:55 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2017-01-10 20:59 - 2017-01-05 19:52 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2017-01-10 20:59 - 2017-01-05 19:52 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2017-01-10 20:59 - 2017-01-05 18:43 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2017-01-10 20:59 - 2017-01-05 18:42 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2017-01-10 20:59 - 2017-01-05 18:32 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2017-01-10 20:59 - 2017-01-05 18:25 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2017-01-10 20:59 - 2017-01-05 18:24 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2017-01-10 20:59 - 2017-01-05 18:23 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2017-01-10 20:59 - 2017-01-05 18:19 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2017-01-10 20:56 - 2017-01-10 20:56 - 00083124 _____ C:\Users\Micha\Downloads\FRST01102017.txt
2017-01-10 20:55 - 2017-01-10 20:55 - 00041706 _____ C:\Users\Micha\Downloads\Addition01102017.txt
2017-01-10 16:22 - 2017-01-10 16:22 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Vorlagen
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Startmenü
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Netzwerkumgebung
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Lokale Einstellungen
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Eigene Dateien
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Druckumgebung
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Videos
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Musik
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Eigene Bilder
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Verlauf
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Anwendungsdaten
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 _SHDL C:\Users\DefaultAppPool\Anwendungsdaten
2017-01-10 16:22 - 2017-01-10 16:22 - 00000000 ____D C:\Users\DefaultAppPool
2017-01-10 16:22 - 2016-11-30 06:27 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\AVG
2017-01-10 16:22 - 2013-07-31 22:25 - 00002110 _____ C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
2017-01-10 16:22 - 2013-07-31 19:31 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\Media Center Programs
2017-01-10 09:38 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2017-01-10 09:37 - 2017-01-19 12:26 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-10 09:37 - 2017-01-16 22:45 - 00081696 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2017-01-10 09:37 - 2017-01-16 16:45 - 00102856 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2017-01-10 09:37 - 2017-01-10 09:37 - 00001837 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-01-10 09:37 - 2017-01-10 09:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-01-10 09:37 - 2017-01-10 09:37 - 00000000 ____D C:\Program Files\Malwarebytes
2017-01-10 09:37 - 2016-12-14 12:55 - 00077416 _____ C:\windows\system32\Drivers\mbae64.sys
2017-01-10 09:37 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2017-01-10 09:35 - 2017-01-10 09:36 - 54199488 _____ (Malwarebytes ) C:\Users\Micha\Downloads\mb3-setup-consumer-3.0.5.1299(1).exe
2017-01-09 15:57 - 2017-01-19 14:44 - 00033306 _____ C:\Users\Micha\Downloads\Addition.txt
2017-01-09 15:55 - 2017-01-19 15:30 - 00021245 _____ C:\Users\Micha\Downloads\FRST.txt
2017-01-09 15:55 - 2017-01-19 15:30 - 00000000 ____D C:\FRST
2017-01-09 15:54 - 2017-01-19 00:24 - 02419712 _____ (Farbar) C:\Users\Micha\Downloads\FRST64.exe
2017-01-05 20:02 - 2017-01-05 20:02 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk
2017-01-05 20:02 - 2017-01-05 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-01-05 00:41 - 2015-07-16 20:12 - 06131200 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2017-01-05 00:41 - 2015-07-16 20:12 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2017-01-05 00:41 - 2015-07-16 20:12 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 07077376 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 01057792 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2017-01-05 00:41 - 2015-07-16 20:11 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2017-01-05 00:41 - 2015-07-11 14:15 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2017-01-04 19:30 - 2015-12-20 19:50 - 03180544 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2017-01-04 19:30 - 2015-12-20 19:50 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2017-01-04 19:30 - 2015-12-20 15:08 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2017-01-04 19:29 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2017-01-04 15:08 - 2017-01-04 15:08 - 54199488 _____ (Malwarebytes ) C:\Users\Micha\Downloads\mb3-setup-consumer-3.0.5.1299.exe
2017-01-04 13:53 - 2017-01-04 13:53 - 13425152 _____ (ReviverSoft) C:\Users\Micha\Downloads\DriverReviverSetup_ppc(2).exe
2017-01-04 10:30 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2017-01-04 10:30 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2017-01-04 10:30 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2017-01-04 10:30 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2017-01-04 10:30 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2017-01-04 10:30 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2017-01-04 10:30 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2017-01-04 10:30 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2017-01-04 10:30 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2017-01-04 10:30 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2017-01-04 10:28 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2017-01-04 10:28 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbGD.sys
2017-01-04 10:28 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2017-01-04 10:28 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2017-01-04 10:25 - 2015-08-05 18:56 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\icaapi.dll
2017-01-04 10:25 - 2015-08-05 18:06 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2017-01-04 09:59 - 2017-01-04 09:59 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ICCWDT_01009.Wdf
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\kbdgeoqw.dll
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZEL.DLL
2017-01-04 09:25 - 2015-12-16 19:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZE.DLL
2017-01-04 09:25 - 2015-12-16 19:48 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZE.DLL
2017-01-04 09:25 - 2015-12-16 19:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\kbdgeoqw.dll
2017-01-04 09:25 - 2015-12-16 19:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZEL.DLL
2017-01-04 02:04 - 2017-01-04 02:04 - 03279864 _____ (SPAMfighter ApS) C:\Users\Micha\Downloads\DRIVERfighter_Web(1).exe
2017-01-04 01:02 - 2017-01-04 02:18 - 00000000 ____D C:\ProgramData\Fighters
2017-01-04 01:00 - 2017-01-04 01:01 - 03279864 _____ (SPAMfighter ApS) C:\Users\Micha\Downloads\DRIVERfighter_Web.exe
2017-01-04 00:54 - 2017-01-04 00:55 - 13425152 _____ (ReviverSoft) C:\Users\Micha\Downloads\DriverReviverSetup_ppc(1).exe
2016-12-30 10:41 - 2016-12-30 10:41 - 00178564 _____ C:\Users\Micha\Downloads\HERMES_label_2016-12-30_10_40_52.pdf
2016-12-30 10:35 - 2016-12-30 10:35 - 00178968 _____ C:\Users\Micha\Downloads\HERMES_label_2016-12-30_10_33_49.pdf
2016-12-24 23:14 - 2016-12-24 23:14 - 00025199 _____ C:\Users\Micha\Documents\freelancer200855.vcf
2016-12-24 10:33 - 2012-06-01 06:39 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\wamregps.dll
2016-12-24 10:33 - 2012-06-01 06:36 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\iisRtl.dll
2016-12-24 10:33 - 2012-06-01 06:36 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\iisrstap.dll
2016-12-24 10:33 - 2012-06-01 06:35 - 00060928 _____ (Microsoft Corporation) C:\windows\system32\ahadmin.dll
2016-12-24 10:33 - 2012-06-01 06:34 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\admwprox.dll
2016-12-24 10:33 - 2012-06-01 06:33 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\iisreset.exe
2016-12-24 10:33 - 2012-06-01 05:40 - 00010752 _____ (Microsoft Corporation) C:\windows\SysWOW64\wamregps.dll
2016-12-24 10:33 - 2012-06-01 05:37 - 00154624 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisRtl.dll
2016-12-24 10:33 - 2012-06-01 05:37 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisrstap.dll
2016-12-24 10:33 - 2012-06-01 05:35 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\admwprox.dll
2016-12-24 10:33 - 2012-06-01 05:35 - 00026624 _____ (Microsoft Corporation) C:\windows\SysWOW64\ahadmin.dll
2016-12-24 10:33 - 2012-06-01 05:34 - 00015360 _____ (Microsoft Corporation) C:\windows\SysWOW64\iisreset.exe
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\windows\SysWOW64\BestPractices
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\windows\system32\BestPractices
2016-12-23 23:18 - 2016-12-23 23:18 - 00000000 ____D C:\inetpub
2016-12-23 17:25 - 2016-12-23 17:25 - 43886552 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\SkypeSetupFull(2).exe
2016-12-23 17:25 - 2016-12-23 17:25 - 00003142 _____ C:\windows\System32\Tasks\{42239007-962A-405B-897B-E4E0207270AF}
2016-12-23 17:23 - 2016-12-23 17:24 - 01463424 _____ (Skype Technologies S.A.) C:\Users\Micha\Downloads\skypesetup.exe
2016-12-23 16:13 - 2017-01-03 14:27 - 00524288 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TMContainer00000000000000000001.regtrans-ms
2016-12-23 16:13 - 2017-01-03 14:27 - 00065536 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TM.blf
2016-12-23 16:13 - 2016-12-23 16:17 - 00524288 ___SH C:\windows\system32\config\components{2f89a682-c922-11e6-aa72-54271e9e7c13}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 15:52 - 2016-12-23 15:52 - 00000000 __SHD C:\found.000

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2017-01-19 15:27 - 2016-12-18 14:12 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Skype
2017-01-19 15:17 - 2014-12-14 15:17 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2017-01-19 12:35 - 2016-11-22 11:54 - 00000000 ____D C:\Users\Micha\AppData\LocalLow\Mozilla
2017-01-19 12:35 - 2009-07-14 05:45 - 00024432 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-19 12:35 - 2009-07-14 05:45 - 00024432 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-19 12:26 - 2015-02-27 20:57 - 00000000 ____D C:\Users\Micha\AppData\Local\FreePDF_XP
2017-01-19 12:25 - 2013-07-31 21:55 - 00000000 ____D C:\ProgramData\Realtek
2017-01-19 12:25 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-01-18 23:57 - 2015-05-27 15:08 - 00000000 ____D C:\ProgramData\panda_url_filtering
2017-01-16 17:17 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2017-01-16 14:20 - 2016-12-07 22:28 - 00000000 ____D C:\Program Files\Common Files\Apple
2017-01-16 14:20 - 2014-12-27 00:03 - 00000000 ____D C:\Users\Micha\AppData\Roaming\Apple Computer
2017-01-16 14:10 - 2014-12-27 00:00 - 00000000 ____D C:\ProgramData\Apple
2017-01-16 12:45 - 2014-12-27 00:04 - 00000000 ____D C:\Users\Micha\AppData\Local\Apple Computer
2017-01-15 09:05 - 2014-12-19 22:43 - 00000000 ____D C:\Users\Micha\Documents\Youcam
2017-01-13 15:52 - 2015-01-02 10:15 - 00000000 ____D C:\Users\Micha\AppData\Roaming\DesktopIconAmazon
2017-01-13 15:23 - 2016-11-06 01:54 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-01-13 08:17 - 2014-12-14 00:10 - 00000000 ____D C:\Users\Micha\Documents\MAGIX_MusicMaker16_Download-Version
2017-01-11 21:01 - 2014-12-19 21:37 - 00010240 _____ C:\Users\Micha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-01-11 12:42 - 2015-07-15 11:33 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-11 12:40 - 2015-01-21 09:55 - 00004476 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2017-01-11 01:25 - 2009-07-14 06:08 - 00032640 _____ C:\windows\Tasks\SCHEDLGU.TXT
2017-01-11 00:03 - 2014-12-14 16:17 - 00000000 ____D C:\windows\system32\MRT
2017-01-11 00:02 - 2014-12-20 03:20 - 135657872 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2017-01-10 16:17 - 2014-12-14 15:17 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2017-01-10 16:17 - 2014-12-14 15:17 - 00000000 ____D C:\windows\system32\Macromed
2017-01-10 16:17 - 2013-07-31 22:22 - 00802904 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2017-01-10 16:17 - 2013-07-31 22:22 - 00144472 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-01-10 16:17 - 2013-07-31 22:22 - 00000000 ____D C:\windows\SysWOW64\Macromed
2017-01-09 15:53 - 2015-09-21 09:06 - 00000000 __SHD C:\$360Section
2017-01-05 20:02 - 2013-07-31 22:29 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-01-05 20:02 - 2013-07-31 22:28 - 00000000 ____D C:\ProgramData\Skype
2017-01-04 10:35 - 2009-07-14 05:45 - 00313104 _____ C:\windows\system32\FNTCACHE.DAT
2017-01-04 10:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\PolicyDefinitions
2017-01-04 10:34 - 2009-07-14 04:20 - 00000000 ____D C:\windows\inf
2017-01-04 10:31 - 2013-07-31 21:39 - 01687534 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2017-01-04 10:31 - 2013-07-31 19:42 - 00738178 _____ C:\windows\system32\perfh007.dat
2017-01-04 10:31 - 2013-07-31 19:42 - 00160894 _____ C:\windows\system32\perfc007.dat
2017-01-04 10:31 - 2009-07-14 06:13 - 01687534 _____ C:\windows\system32\PerfStringBackup.INI
2017-01-04 10:31 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\inetsrv
2017-01-04 09:47 - 2016-06-30 15:21 - 00000000 ____D C:\Users\Micha\AppData\Local\ElevatedDiagnostics
2017-01-04 02:21 - 2014-12-14 00:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2017-01-04 02:05 - 2009-07-14 03:34 - 00000568 _____ C:\windows\win.ini
2017-01-03 17:08 - 2015-09-24 19:26 - 00000356 _____ C:\Users\Micha\Desktop\Zitate.txt
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\migration
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\inetsrv
2016-12-25 00:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\migration
2016-12-24 20:13 - 2009-07-14 04:18 - 00000000 __SHD C:\$Recycle.Bin
2016-12-24 00:58 - 2014-12-31 14:21 - 00000000 ____D C:\ProgramData\Freemake
2016-12-24 00:58 - 2014-12-31 14:21 - 00000000 ____D C:\Program Files (x86)\Freemake
2016-12-24 00:00 - 2009-07-14 04:20 - 00000000 ____D C:\windows\Microsoft.NET
2016-12-23 23:52 - 2014-12-14 00:06 - 00000000 ___RD C:\Users\Micha\Videos
2016-12-23 23:20 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2016-12-23 23:18 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-12-23 23:18 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Microsoft Games
2016-12-23 23:18 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\Drivers\etc
2016-12-23 23:18 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-12-23 19:30 - 2009-07-14 04:20 - 00000000 ____D C:\windows\AppPatch
2016-12-23 15:29 - 2016-11-02 17:00 - 00524288 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TMContainer00000000000000000002.regtrans-ms
2016-12-23 15:29 - 2016-11-02 17:00 - 00065536 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TM.blf
2016-12-23 15:02 - 2016-11-02 17:00 - 00524288 ___SH C:\windows\system32\config\components{36abe97a-a115-11e6-9f6c-54271e9e7c13}.TMContainer00000000000000000001.regtrans-ms

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2014-09-01 09:18 - 2014-09-01 09:18 - 0001248 _____ () C:\Users\Micha\AppData\Roaming\FODX
2014-12-14 00:06 - 2017-01-19 13:13 - 0005044 _____ () C:\Users\Micha\AppData\Local\BTServer.log
2014-12-19 21:37 - 2017-01-11 21:01 - 0010240 _____ () C:\Users\Micha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert

LastRegBack: 2017-01-16 17:06

==================== Ende von FRST.txt ============================


cosinus 20.01.2017 09:46

So, ein letzter Fix:


FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

Task: {3F283151-7529-496F-9366-FCAEC83C2694} - System32\Tasks\1215tbUpdateInfo => C:\ProgramData\Avg_Update_1215tb\1215tb_{4D479988-B227-4153-A15F-3D6D13E85735}.exe
S2 NAT; "C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe" /s "NAT" /m "C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\diMaster.dll" /prefetch:1
S3 McComponentHostService; "C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe" [X]
C:\Program Files (x86)\Norton Anti-Theft
C:\Program Files\McAfee Security Scan
C:\Users\DefaultAppPool\AppData\Local\AVG
C:\ProgramData\Avg_Update_1215tb
emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


milkit54 21.01.2017 01:27

Hallo Cosinus,

hat zu erst nicht gestartet, habs dann doch hinbekommen. hoffe es ist ok so? wünsche dir eine angenehme Nacht falls wir jetzt 01:26 nicht weitermachen. Gruß MS-Micha

Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 18-01-2017
durchgeführt von Micha (21-01-2017 00:32:28) Run:4
Gestartet von C:\Users\Micha\Downloads
Geladene Profile: Micha (Verfügbare Profile: Micha & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
HKU\S-1-5-18\...\RunOnce: [panda] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f
HKU\S-1-5-18\...\RunOnce: [panda_XP] => reg.exe delete "HKCU\Software\panda" /f
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop(777).ini [2009-07-14] ()
FF HKU\S-1-5-21-2198626584-3468660724-23365673-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\jsjjbqd4.default\extensions\cliqz@cliqz.com => nicht gefunden
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\pandasecuritytb.xml [2015-05-27]
CHR DefaultSearchURL: Default -> hxxp://pandasecurity.mystart.com/results.php?searchsource=omnibar&pr=vmn&id=pandasecuritytb&v=2_3&ent=ds_671&q={searchTerms}
R2 panda_url_filtering; C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe [287752 2015-10-02] (Visicom Media Inc.)
R3 panda_url_filteringd; C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys [51288 2014-03-19] (Visicom Media Inc.)
S2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\SymcPCCULaunchSvc.exe /s [X]
S2 PCCUJobMgr; "C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\ccSvcHst.exe" /s "PCCUJobMgr" /m "C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.18.16\diMaster.dll" /prefetch:1
C:\Program Files (x86)\Norton PC Checkup
C:\ProgramData\Norton
C:\ProgramData\boost_interprocess
C:\Program Files (x86)\Norton Anti-Theft
C:\Program Files (x86)\360
C:\ProgramData\360Quarant
C:\Program Files (x86)\chip
C:\Program Files (x86)\Lavasoft
C:\ProgramData\Lavasoft
C:\Users\Micha\AppData\Roaming\Lavasoft
emptytemp:
       
*****************

HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\panda => Wert nicht gefunden.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\panda_XP => Wert nicht gefunden.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop(777).ini => nicht gefunden.
HKU\S-1-5-21-2198626584-3468660724-23365673-1000\Software\Mozilla\Firefox\Extensions\\cliqz@cliqz.com => Wert nicht gefunden.
"C:\Program Files (x86)\mozilla firefox\browser\searchplugins\pandasecuritytb.xml" => nicht gefunden.
Chrome DefaultSearchURL => nicht gefunden.
panda_url_filtering => Dienst nicht gefunden.
panda_url_filteringd => Dienst nicht gefunden.
Norton PC Checkup Application Launcher => Dienst nicht gefunden.
PCCUJobMgr => Dienst nicht gefunden.
"C:\Program Files (x86)\Norton PC Checkup" => nicht gefunden.
"C:\ProgramData\Norton" => nicht gefunden.
"C:\ProgramData\boost_interprocess" => nicht gefunden.
"C:\Program Files (x86)\Norton Anti-Theft" => nicht gefunden.
"C:\Program Files (x86)\360" => nicht gefunden.
"C:\ProgramData\360Quarant" => nicht gefunden.
"C:\Program Files (x86)\chip" => nicht gefunden.
"C:\Program Files (x86)\Lavasoft" => nicht gefunden.
"C:\ProgramData\Lavasoft" => nicht gefunden.
"C:\Users\Micha\AppData\Roaming\Lavasoft" => nicht gefunden.

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 17289229 B
Java, Flash, Steam htmlcache => 3489 B
Windows/system/drivers => 277276 B
Edge => 0 B
Chrome => 0 B
Firefox => 370187539 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
Micha => 422026 B
DefaultAppPool => 0 B

RecycleBin => 0 B
EmptyTemp: => 370.2 MB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 00:32:48 ====


cosinus 21.01.2017 15:39

ANleitungen bitte richtig lesen und umsetzen. Du hast die fixlist nicht neu gemacht.

milkit54 21.01.2017 17:47

Hi Cosinus, hoffe diesmal ist es richtig, der Neustart am Ende von Frst ist für mich irrritierend. kann aber auch an der MS liegen. Danke für deine Ausdauer und Geduld Gruß MS-Micha
Code:

Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 18-01-2017
durchgeführt von Micha (21-01-2017 17:31:19) Run:7
Gestartet von C:\Users\Micha\Desktop
Geladene Profile: Micha (Verfügbare Profile: Micha & DefaultAppPool)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
Task: {3F283151-7529-496F-9366-FCAEC83C2694} - System32\Tasks\1215tbUpdateInfo => C:\ProgramData\Avg_Update_1215tb\1215tb_{4D479988-B227-4153-A15F-3D6D13E85735}.exe
S2 NAT; "C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\ccSvcHst.exe" /s "NAT" /m "C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\diMaster.dll" /prefetch:1
S3 McComponentHostService; "C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe" [X]
C:\Program Files (x86)\Norton Anti-Theft
C:\Program Files\McAfee Security Scan
C:\Users\DefaultAppPool\AppData\Local\AVG
C:\ProgramData\Avg_Update_1215tb
emptytemp:
       
*****************

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3F283151-7529-496F-9366-FCAEC83C2694} => Schlüssel erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3F283151-7529-496F-9366-FCAEC83C2694} => Schlüssel erfolgreich entfernt
C:\windows\System32\Tasks\1215tbUpdateInfo => erfolgreich verschoben
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1215tbUpdateInfo => Schlüssel erfolgreich entfernt
HKLM\System\CurrentControlSet\Services\NAT => Schlüssel erfolgreich entfernt
NAT => Dienst erfolgreich entfernt
HKLM\System\CurrentControlSet\Services\McComponentHostService => Schlüssel erfolgreich entfernt
McComponentHostService => Dienst erfolgreich entfernt
"C:\Program Files (x86)\Norton Anti-Theft" => nicht gefunden.
"C:\Program Files\McAfee Security Scan" => nicht gefunden.
C:\Users\DefaultAppPool\AppData\Local\AVG => erfolgreich verschoben
"C:\ProgramData\Avg_Update_1215tb" => nicht gefunden.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 4317405 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 2674 B
Edge => 0 B
Chrome => 0 B
Firefox => 4821599 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
Micha => 104175 B
DefaultAppPool => 0 B

RecycleBin => 0 B
EmptyTemp: => 16.8 MB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 17:31:27 ====


cosinus 21.01.2017 20:41

Was ist jetzt noch an Problemen Offen?

milkit54 21.01.2017 22:02

Hi Cosinus,
laienhaft ausgedrückt / beschrieben
der Lap Top wird in der Gerätesteuerung immer noch als Problem angezeigt
Treiberprobleme bei Toredo Tunneling adapter

Skype erkennt die interne Kamera nicht, ich weiß aber nicht ob sie überhaupt eingeschaltet ist

es kommt regelmäßig ein "Fehlerton"

Gruß MS-Michael

cosinus 22.01.2017 00:57

Das ganze hat nichts mit Malware zu tun. Mach dazu einen neuen Thread im Windows-Bereich auf.

milkit54 24.01.2017 20:59

Hi Cosinus, meine MS macht im Moment wohl größere Probleme als mein rechner, habe es trotzdem geschafft ein neues Thema zu erstllen. hofffentlich richtig. Danke dir recht herzlich für deine Hilfe, geduld und Zusammenarbeit. Gruß MS-Micha

cosinus 24.01.2017 22:16

Dann wären wir in diesem Thread durch! :daumenhoc

Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...:dankeschoen:und/oder das Forum mit einer kleinen Spende http://www.trojaner-board.de/extra/spende.png unterstützen. :applaus:

Abschließend müssen wir noch ein paar Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern.

http://deeprybka.trojaner-board.de/b...cleanupneu.png
Cleanup:


Alle Logs gepostet? Dann lade Dir bitte http://filepony.de/icon/tiny/delfix.pngDelFix herunter.
  • Schließe alle offenen Programme.
  • Starte die delfix.exe mit einem Doppelklick.
  • Setze vor jede Funktion ein Häkchen.
  • Klicke auf Start.

Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen.

http://deeprybka.trojaner-board.de/b...ast/schild.png
Absicherung:
Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen - sofern benötigt, wenn nicht benötigt natürlich sinnigerweise deinstallieren oder Alternativen verwenden (und diese aktuell halten).
  • Browser (Internet Explorer, Edge, Firefox, Chrome, ...)
  • Java (bitte wirklich nur installieren/installiert lassen wenn unbedingt nötig!)
  • Flash-Player (nach Möglichkeit deinstallieren und HTML5 verwenden siehe zB https://www.youtube.com/html5 )
  • PDF-Reader (nach Möglichkeit nicht den Adobe Reader verwenden)

Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren.
Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen.

Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig.


[b]Schutzsoftware[b]: Vorab sei erwähnt, dass man niemals die Schutzwirkung eines Virenscanners überbewerten darf! Die Dinger sind mittlerweile auch unter Windows stark umstritten und können Probleme bereiten, die man so ohne AV einfach nicht haben wird. Zudem werden sie auch niemals jeden Schädling finden können. Aussagen der Anbieter dieser Software entpuppen sich regelmäßig als Marketinggeblubber. Lies mal => Aus aktuellem Anlass: Antivirus-Schlangenöl | Elias Schwerdtfeger und Antivirensoftware: Die Schlangenöl-Branche - Golem.de

Verwende also MAXIMAL ein einziges der folgenden Antivirusprogramme mit Echtzeitscanner und stets aktueller Signaturendatenbank:

   
 

Microsoft Security Essentials (MSE) ist ab Windows 8 fest eingebaut, wenn du also Windows 8, 8.1 oder 10 und dich für MSE entschieden hast, brauchst du nicht extra MSE zu installieren. Bei Windows 7 muss es aber manuell installiert oder über die Windows Updates als optionales Update bezogen werden. Selbstverständlich ist ein legales/aktiviertes Windows Voraussetzung dafür.

Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und/oder mit dem ESET Online Scanner scannen.

Optional:

http://filepony.de/icon/noscript.png NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen. NoScript kann gerade bei technisch nicht allzu versierten Nutzern beim Surfen zum Nervfaktor werden; ob das Tool geeignet ist, muss jeder selbst mal ausprobieren und dann für sich entscheiden. Alternativen zu NoScript (wenn um das das Verhindern von Usertracking und Werbung auf Webseiten) geht wären da Ghostery oder uBlock. Ghostery ist eine sehr bekannte Erweiterung, die aber auch in Kritik geraten ist, vgl. dazu bitte diesen Thread => Ghostery schleift Werbung durch

http://filepony.de/icon/malwarebytes_anti_exploit.pngMalwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen.


Lade Software von einem sauberen Portal wie http://filepony.de/images/microbanner.gif.
Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen.
Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwcleaner .


Abschließend noch ein paar grundsätzliche Bemerkungen:
Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems.
Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann.

milkit54 24.01.2017 23:28

hallo cosinus,
bin heute ziemlich fertig, kann nicht mehr dank ms. ich glaube den neuen thread müßte man löschen bzw zurückstellen wenn das irgendwie geht?
ich gebe dir morgen mal an was ich mit dem Rechner mache bzw. welche programme ich glaube zu brauchen.
geld bekomme ich erst am Monatsende von daher ist im moment nichts möglich.
alle logs gepostet verstehe ich nicht,
vorab 2 dinge
1. was mache ich mit norton die wollen verlängern wenn ich deinen text richtig gelesen habe brauche ich die zukünftig nicht und könnte aussteigen.
2. umsteigen auf ein anderes window kostet doch oder?

gruß ms-micha

cosinus 25.01.2017 00:26

1. Spenden ist nur freiwillig und auch wirklich nur dann wenn du es dir wirklich leisten kannst
2. alle LOgs gepostet => hast du, Thema erledigt
3. Norton => Ist totaler Müll, dafür auch noch Kohle raushauen ist Unfug, nimm den kostenlosen Windows Defender siehe mein Abschlussposting Thema Virenscanner
4. Upgrade auf W10 geht immer noch ohne Kosten, das aber bitte im Windows-Bereich klären

cosinus 25.01.2017 00:26

1. Spenden ist nur freiwillig und auch wirklich nur dann wenn du es dir wirklich leisten kannst
2. alle LOgs gepostet => hast du, Thema erledigt
3. Norton => Ist totaler Müll, dafür auch noch Kohle raushauen ist Unfug, nimm den kostenlosen Windows Defender siehe mein Abschlussposting Thema Virenscanner
4. Upgrade auf W10 geht immer noch ohne Kosten, das aber bitte im Windows-Bereich klären

milkit54 26.01.2017 16:34

Hallo Cosinus,
zunächst mal Danke für deine Antwort, habe die Verlängerung von Norton abgelehnt, sobald das Geld wieder auf dem Konto ist kann ich meine Spende leisten.

Nachrichtlich gebe ich dir noch eine Auflistung genutzter Programme/Portale falls du irgend etwas sehr Negatives erkennst bitte kurze Nachricht

hier die Liste
Code:


1. e-mail schreibe ich über gmx.de bzw. gmx.net

2. browser firefox

3. private karten und glückwünsche nutze ich cool photos.de

4. ich mache einiges bei ebay (kauf und verkauf) von dort kommt glaube ich java automatisch

5. Suchen laufen über google.de, gmx.de

6. ich bin noch bei finya.de

7. quoka.de

8. seniorentreff.de

9. Nachrichten und gleichzeitig Startseite nutze ich n-tv.de

werde jetzt versuchen deine letzten Punkte abzuarbeiten, drück mir die Daumen, ist noch ziemlich unangenehm, das die Maus nicht erkannt wird, der Thread unter windows ist noch offen kann das so bleiben?

Gruß MS Michael

Hallo Cosinus,
hast du meine letzte Nachricht noch lesen können? zu meinem neuen Thread hat sich noch niemand gemeldet weiter warten ist ok? danke für deine Rückmeldung
Gruß MS-Micha


Alle Zeitangaben in WEZ +1. Es ist jetzt 05:38 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22