rudi1949 | 14.03.2017 08:49 | Windows Firewall (Win10) deaktiviert sich und muß jedes mal mit der Maus aktiviert werden Danke!
Hier ist das erste File
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-03-2017
Ran by Rudi (administrator) on RUDI-PC (14-03-2017 08:18:34)
Running from Z:\Aktuelle Downloads
Loaded Profiles: Rudi (Available Profiles: Rudi & Administrator & DefaultAppPool)
Platform: Windows 10 Pro Version 1607 (X64) Language: Englisch (Vereinigte Staaten)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Sandboxie Holdings, LLC) D:\Program Files\Sandboxie\SbieSvc.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(Apple Computer, Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(New Softwares.net) C:\Windows\SysWOW64\WinFLService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
() D:\Program Files\Atomic Alarm Clock\timeserv.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
(Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Malwarebytes Corporation) D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Panda Security, S.L.) D:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
(Panda Security, S.L.) D:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe
(Apache Software Foundation) C:\Program Files (x86)\Themler\bin\apache\bin\hthemlerd.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Program Files (x86)\Themler\bin\mysql\bin\mythemlerd.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Malwarebytes Corporation) D:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Ascora GmbH) D:\Program Files (x86)\StartupStar\StartupStar.exe
(Apache Software Foundation) C:\Program Files (x86)\Themler\bin\apache\bin\hthemlerd.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
Failed to access process -> FreemakeUtilsService.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
( New Softwares.net) C:\Windows\SysWOW64\WinFLTray.exe
() D:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe
(Celartem, Inc., doing business as Extensis.) D:\Program Files (x86)\Extensis Suitcase Fusion\FMCore.exe
(Panda Security, S.L.) D:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe
(Bartels Media GmbH) D:\Program Files (x86)\PhraseExpress\phraseexpress.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Harry Stahl Software) D:\Program Files (x86)\Timonize\TRemind.EXE
() C:\ProgramData\Abelssoft\AntiRansomware\Program\AntiRansomware.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17012.10301.0_x64__8wekyb3d8bbwe\Video.UI.exe
((C) LINE Corporation) D:\WindowsApps\NAVER.LINEwin8_5.4.7.0_x64__8ptj331gd3tyt\LINE_APP.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585744 2015-10-14] (NVIDIA Corporation)
HKLM\...\Run: [*Restore] => C:\WINDOWS\System32\rstrui.exe [268288 2016-07-16] (Microsoft Corporation)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation)
HKLM-x32\...\Run: [PSUAMain] => D:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [107520 2016-03-18] (Panda Security, S.L.)
HKLM-x32\...\Run: [HPUsageTrackingLEDM] => C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe [30264 2009-08-04] (Hewlett-Packard Company)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [27308304 2017-03-07] (Dropbox, Inc.)
HKU\S-1-5-21-595107073-3459872703-1893278198-1000\...\Run: [SkinClock] => D:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe [4287488 2011-10-25] ()
HKU\S-1-5-21-595107073-3459872703-1893278198-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-595107073-3459872703-1893278198-1000\...\Run: [FMCore.exe] => D:\Program Files (x86)\Extensis Suitcase Fusion\FMCore.exe [10760192 2014-10-16] (Celartem, Inc.,)
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
ShellIconOverlayIdentifiers: [ AcronisDrive] -> {5D74FD4B-4EFB-4586-8022-8637BBE40970} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-01-12] ()
ShellIconOverlayIdentifiers: [ AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-01-12] ()
ShellIconOverlayIdentifiers: [ AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-01-12] ()
ShellIconOverlayIdentifiers: [ AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-01-12] ()
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => -> No File
ShellIconOverlayIdentifiers: ["11CloudOverlayIcon"] -> {7287689B-8C79-4D52-A8C7-CC11D4D8ECE3} => D:\Program Files (x86)\freenet cloud\64\CloudIconOverlay.dll [2015-11-18] ()
ShellIconOverlayIdentifiers: ["12CloudOverlayIcon"] -> {75804F50-7528-4089-91DC-ABD7144EC960} => D:\Program Files (x86)\freenet cloud\64\CloudIconOverlay.dll [2015-11-18] ()
ShellIconOverlayIdentifiers: ["13CloudOverlayIcon"] -> {8B680D9E-7971-4ED5-BC1D-C0B7CA89B5A6} => D:\Program Files (x86)\freenet cloud\64\CloudIconOverlay.dll [2015-11-18] ()
ShellIconOverlayIdentifiers: ["14CloudOverlayIcon"] -> {2FFEFB84-A51D-4FAC-B125-17E44C87BC84} => D:\Program Files (x86)\freenet cloud\64\CloudIconOverlay.dll [2015-11-18] ()
ShellIconOverlayIdentifiers: ["15CloudOverlayIcon"] -> {D0F0E8F3-5536-4A04-80A1-40FB42B296EC} => D:\Program Files (x86)\freenet cloud\64\CloudIconOverlay.dll [2015-11-18] ()
ShellIconOverlayIdentifiers: ["16CloudOverlayIcon"] -> {5B3DEF8D-36B5-4A0C-AF95-BB774BE05E8F} => D:\Program Files (x86)\freenet cloud\64\CloudIconOverlay.dll [2015-11-18] ()
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-03-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-03-07] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2017-02-15] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PhraseExpress.lnk [2017-02-15]
ShortcutTarget: PhraseExpress.lnk -> D:\Program Files (x86)\PhraseExpress\phraseexpress.exe (Bartels Media GmbH)
Startup: C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2017-03-13]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRemind.EXE.lnk [2015-09-24]
ShortcutTarget: TRemind.EXE.lnk -> D:\Program Files (x86)\Timonize\TRemind.EXE (Harry Stahl Software)
Startup: C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WF.msc - Verknüpfung.lnk [2017-02-28]
ShortcutTarget: WF.msc - Verknüpfung.lnk -> C:\Windows\System32\WF.msc ()
GroupPolicy: Restriction - Chrome <======= ATTENTION
GroupPolicy\User: Restriction <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{72c20bae-8251-48ad-b79c-f22df13eacaa}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9158bc68-ff9c-47ef-8194-53b98366daf8}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://th.search.yahoo.com/yhs/web?hspart=itm&hsimp=yhs-001&type=jmb_dnldastr_16_09¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dth%26pa%3DJoomborio%26cd%3D2XzuyEtN2Y1L1QzutDtDtByDtBtB0CtA0C0E0F0CzytA0FyBtN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCyBtFtCtCtFyCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyEzytDzyyCtB0E0DtGtD0CtD0FtGtDzytD0FtGtCzz0BtCtGtByDtByEtC0F0CtDzz0B0ByC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0BtB0B0C0AzyzztGtByCtCzytGyEtCyEzytG0AzzyDtBtGtDzztCyB0AyBtA0ByByC0AtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyDzyyE%26cr%3D1173861011%26a%3Djmb_dnldastr_16_09%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: No Name -> {26C3165B-FC58-4910-802D-250B2E68A04E} -> No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Promt IE Helper -> {1F13CE11-4FAC-49A9-8155-D4F3F0F91A33} -> D:\Program Files (x86)\PRMT12\PRMTIE\prmtie.dll [2014-02-07] (PROMT Ltd.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab
FireFox:
========
FF ProfilePath: C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\08i3m0cl.default [2017-03-05]
FF NewTab: Mozilla\Firefox\Profiles\08i3m0cl.default -> about:newtab
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\08i3m0cl.default -> Yahoo! Powered
FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\08i3m0cl.default -> Bing
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\08i3m0cl.default -> Yahoo! Powered
FF Homepage: Mozilla\Firefox\Profiles\08i3m0cl.default -> hxxp://www.google.de/
FF Keyword.URL: Mozilla\Firefox\Profiles\08i3m0cl.default -> user_pref("keyword.URL", true);
FF Extension: (LastPass) - C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\08i3m0cl.default\Extensions\support@lastpass.com [2017-02-10]
FF Extension: (YesScript) - C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\08i3m0cl.default\Extensions\yesscript@userstyles.org.xpi [2016-08-05]
FF Extension: (Video DownloadHelper) - C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\08i3m0cl.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2017-01-05]
FF Extension: (Adblock Plus) - C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\08i3m0cl.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-12-10]
FF Extension: (BetterPrivacy) - C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\08i3m0cl.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2017-03-05]
FF ProfilePath: C:\Users\Rudi\AppData\Roaming\bitmedia\Contentlauncher\Profiles\16bfeq6a.default [2017-02-25]
FF HKLM\...\Firefox\Extensions: [FFExtnHTML2PDF@foxitsoftware.com] - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi
FF Extension: (Foxit PDF Creator) - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi [2016-11-14]
FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Privacy Suite 15\spmplugin3 => not found
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [FFExtnHTML2PDF@foxitsoftware.com] - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.15@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat DC - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn [2016-12-23]
FF HKU\S-1-5-21-595107073-3459872703-1893278198-1000\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - D:\Program Files (x86)\Internet Download Manage\idmmzcc2.xpi
FF Extension: (IDM integration) - D:\Program Files (x86)\Internet Download Manage\idmmzcc2.xpi [2016-08-03]
FF HKU\S-1-5-21-595107073-3459872703-1893278198-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Rudi\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Rudi\AppData\Roaming\IDM\idmmzcc5 [2016-10-29] [not signed]
FF HKU\S-1-5-21-595107073-3459872703-1893278198-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - D:\Program Files (x86)\Internet Download Manage\idmmzcc2.xpi
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.)
FF Plugin: @lastpass.com/NPLastPass -> D:\Program Files (x86)\LastPass\nplastpass64.dll [2016-08-29] (LastPass)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2012-05-24] (Wacom)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-12-09] (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect -> D:\Program Files\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1225195.dll [2016-09-20] (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> D:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> D:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-04-18] (DivX, LLC)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2016-11-09] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2016-11-09] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2016-11-09] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2016-11-09] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-01-23] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-01-23] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-28] (Oracle Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> D:\Program Files (x86)\LastPass\nplastpass64.dll [2016-08-29] (LastPass)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [No File]
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-11-14] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-11-14] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @photodex.com/PhotodexPresenter -> C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll [2014-08-24] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.10 -> C:\Program Files (x86)\TabletPlugins\npwacom.dll [2011-04-21] (Wacom, Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.0.0.1 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2012-05-23] (Wacom)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2012-05-23] (Wacom)
FF Plugin-x32: @webex.com/npatgpc -> D:\ProgramData\WebEx\npatgpc.dll [2016-10-20] (Cisco WebEx LLC)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2016-10-01] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-12-09] (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect -> D:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems)
FF Plugin HKU\.DEFAULT: @protectdisc.com/NPPDLicenseHelper -> C:\Windows\system32\config\systemprofile\AppData\Roaming\ProtectDisc\License Helper v2\NPPDLicenseHelper.dll [No File]
FF Plugin HKU\S-1-5-21-595107073-3459872703-1893278198-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Rudi\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-11-09] (Citrix Online)
FF Plugin HKU\S-1-5-21-595107073-3459872703-1893278198-1000: @protectdisc.com/NPPDLicenseHelper -> C:\Users\Rudi\AppData\Roaming\ProtectDisc\License Helper v2\NPPDLicenseHelper.dll [2009-06-25] ( )
FF Plugin HKU\S-1-5-21-595107073-3459872703-1893278198-1000: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2012-05-24] (Wacom)
StartMenuInternet: FIREFOX.EXE - D:\Program Files\Mozilla Firefox\firefox.exe
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=de-de
CHR StartupUrls: Default -> "hxxps://www.google.de/?gws_rd=ssl"
CHR Profile: C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default [2017-03-14]
CHR Extension: (ProxFlow) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2017-01-24]
CHR Extension: (uBlock Origin) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-03-09]
CHR Extension: (Copay) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnidaodnidkbaplmghlelgikaiejfhja [2017-02-19]
CHR Extension: (Adobe Acrobat) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-04]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2017-02-25]
CHR Extension: (OkayFreedom) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfnbbbkabnehoejfhcbbhdicagcoobji [2016-07-03]
CHR Extension: (Proxy for Chrome) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iilpibhiihokecnbdkaminemnmecjfed [2016-08-09]
CHR Extension: (Cisco WebEx Extension) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2017-02-09]
CHR Extension: (Video DownloadHelper) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjnegcaeklhafolokijcfjliaokphfk [2016-12-21]
CHR Extension: (Video download helper) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mngdadkapbemiekajhhalpakdpleogfn [2016-10-29]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Proxy List - Free Proxies for everyone) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\omihnninlhneakfglooiofgdbpmnhjgn [2016-06-27]
CHR Extension: (Proxy SwitchyOmega) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\padekgcemlokbadohgkifijomclgjgif [2017-03-12]
CHR Extension: (Chrome Media Router) - C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-07]
CHR HKLM\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\ChromeAddin\ChromeAddin.crx [2016-11-10]
CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - D:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKU\S-1-5-21-595107073-3459872703-1893278198-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - D:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\Creator\ChromeAddin\ChromeAddin.crx [2016-11-10]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - D:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AcronisActiveProtectionService; C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\anti_ransomware_service.exe [1175976 2017-01-16] (Acronis International GmbH)
S4 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [1276464 2017-01-18] ()
S4 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [6086232 2017-01-28] ()
S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2207960 2016-09-26] (Adobe Systems, Incorporated)
R2 AtomicAlarmClock; D:\Program Files\Atomic Alarm Clock\timeserv.exe [2062336 2011-10-25] () [File not signed]
S4 Avira Secure Backup Crawler; C:\Program Files\Avira Secure Backup\Avira Secure BackupCrawler.exe [4121960 2013-06-24] () [File not signed]
S4 becldr3Service; C:\Program Files (x86)\BCL Technologies\easyConverter SDK 3\Common\becldr.exe [225280 2012-08-01] () [File not signed]
S4 CLHNServiceForPowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe [87336 2012-01-12] (CyberLink Corp.)
S4 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2012-12-23] (Creative Labs) [File not signed]
S4 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [307200 2008-11-18] (Creative Technology Ltd) [File not signed]
S4 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [75048 2012-01-12] (CyberLink)
S4 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [296232 2012-01-12] (CyberLink)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-26] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-26] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [46408 2017-01-21] (Dropbox, Inc.)
S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [104448 2017-01-24] (Freemake) [File not signed]
R2 FreemakeVideoCapture; D:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2017-01-24] (Ellora Assets Corp.) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2015-10-14] (NVIDIA Corporation)
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136704 2009-06-24] (HP) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [28552 2016-04-26] (Hewlett-Packard Company)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-01-23] (Intel Corporation)
R2 MBAMScheduler; D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 mmsminisrv; C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe [4679576 2016-12-20] (Acronis International GmbH)
S3 mobile_backup_server; C:\Program Files (x86)\Common Files\Acronis\MobileBackupServer\mobile_backup_server.exe [2908352 2017-01-06] (Acronis International GmbH)
S3 mobile_backup_status_server; C:\Program Files (x86)\Acronis\TrueImageHome\mobile_backup_status_server.exe [1611368 2017-01-18] ()
R2 NanoServiceMain; D:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [150528 2016-03-18] (Panda Security, S.L.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706128 2015-10-14] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833360 2015-10-14] (NVIDIA Corporation)
R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [73176 2016-02-22] (Panda Security, S.L.)
R2 PSUAService; D:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [38136 2016-03-17] (Panda Security, S.L.)
R2 SbieSvc; D:\Program Files\Sandboxie\SbieSvc.exe [197264 2016-09-23] (Sandboxie Holdings, LLC)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-16] (Microsoft Corporation)
S3 ss_conn_service; D:\Program Files\Kies\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
S4 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 syncagentsrv; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [7013704 2016-12-21] ()
R2 ThemlerApache; C:\Program Files (x86)\Themler\bin\apache\bin\hthemlerd.exe [20992 2015-07-13] (Apache Software Foundation) [File not signed]
R2 ThemlerMySql; C:\Program Files (x86)\Themler\bin\mysql\bin\mythemlerd.exe [8148480 2015-07-13] () [File not signed]
S4 UPSmonitor; D:\Program Files (x86)\MonitorSoftware\monitor.exe [114688 2013-03-29] (Macrovision) [File not signed]
S4 UPSRMI; D:\Program Files (x86)\MonitorSoftware\wpRMI.exe [114688 2013-03-29] (Macrovision) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
S4 WinTabService; C:\Windows\System32\Drivers\WTSRV.EXE [53248 2007-05-31] (Tablet Driver) [File not signed]
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-12-11] (Wacom Technology, Corp.)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AntiLog32; C:\Windows\system32\drivers\AntiLog64.sys [49240 2013-09-12] (Zemana Ltd.)
S4 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-03-02] (Samsung Electronics Co., Ltd.)
S4 DgiVecp; C:\Windows\SysWOW64\Drivers\DgiVecp.sys [41984 2004-08-12] (Samsung Electronics Co., Ltd.) [File not signed]
R1 eusk2par; C:\Windows\system32\Drivers\eusk2par-amd64.sys [32336 2008-12-18] (Aladdin Knowledge Systems Ltd.)
R1 Eve; C:\WINDOWS\system32\DRIVERS\eve.sys [41304 2014-04-10] ()
R2 file_protector; C:\WINDOWS\System32\DRIVERS\file_protector.sys [447328 2017-01-28] (Acronis International GmbH)
R0 file_tracker; C:\WINDOWS\System32\DRIVERS\file_tracker.sys [375136 2017-01-28] (Acronis International GmbH)
R0 hotcore3; C:\WINDOWS\System32\DRIVERS\hotcore3.sys [34056 2014-11-17] (Paragon Software Group)
R3 LVPr2M64; C:\WINDOWS\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
S3 LVPr2Mon; C:\WINDOWS\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [136408 2017-03-14] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R1 MpKsl0a5bf91f; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{725266B7-095B-4D5A-A803-53D716526B4C}\MpKsl0a5bf91f.sys [44928 2017-03-14] (Microsoft Corporation)
S3 mvusbews; C:\WINDOWS\System32\Drivers\mvusbews.sys [20480 2012-09-26] (Marvell Semiconductor, Inc.)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R1 NNSALPC; C:\WINDOWS\system32\DRIVERS\NNSALPC.sys [103856 2015-12-10] (Panda Security, S.L.)
R1 NNSHTTP; C:\WINDOWS\system32\DRIVERS\NNSHTTP.sys [210864 2015-12-10] (Panda Security, S.L.)
R1 NNSHTTPS; C:\WINDOWS\system32\DRIVERS\NNSHTTPS.sys [120240 2015-12-10] (Panda Security, S.L.)
R1 NNSIDS; C:\WINDOWS\system32\DRIVERS\NNSIDS.sys [120240 2015-12-10] (Panda Security, S.L.)
R1 NNSNAHSL; C:\WINDOWS\system32\DRIVERS\NNSNAHSL.sys [58616 2015-06-19] (Panda Security, S.L.)
R1 NNSPICC; C:\WINDOWS\system32\DRIVERS\NNSPICC.sys [112560 2015-12-10] (Panda Security, S.L.)
R1 NNSPIHSW; C:\WINDOWS\system32\DRIVERS\NNSPIHSW.sys [82864 2016-03-17] (Panda Security, S.L.)
R1 NNSPOP3; C:\WINDOWS\system32\DRIVERS\NNSPOP3.sys [133552 2015-12-10] (Panda Security, S.L.)
R1 NNSPROT; C:\WINDOWS\system32\DRIVERS\NNSPROT.sys [309680 2015-12-10] (Panda Security, S.L.)
R1 NNSPRV; C:\WINDOWS\system32\DRIVERS\NNSPRV.sys [179632 2016-02-18] (Panda Security, S.L.)
R1 NNSSMTP; C:\WINDOWS\system32\DRIVERS\NNSSMTP.sys [122800 2015-12-10] (Panda Security, S.L.)
R1 NNSSTRM; C:\WINDOWS\system32\DRIVERS\NNSSTRM.sys [267184 2016-02-18] (Panda Security, S.L.)
R1 NNSTLSC; C:\WINDOWS\system32\DRIVERS\NNSTLSC.sys [115632 2015-12-10] (Panda Security, S.L.)
R2 npf; C:\WINDOWS\System32\drivers\npf.sys [35344 2011-02-12] (CACE Technologies, Inc.)
R2 ntk_PowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [82928 2011-10-27] (Cyberlink Corp.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-10-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [38032 2015-10-14] (NVIDIA Corporation)
S3 OSFMount; D:\Program Files\OSFMount\OSFMount.sys [540224 2012-05-09] (PassMark Software)
R2 PSINAflt; C:\WINDOWS\system32\DRIVERS\PSINAflt.sys [174000 2016-02-18] (Panda Security, S.L.)
R2 PSINFile; C:\WINDOWS\System32\DRIVERS\PSINFile.sys [129456 2016-02-18] (Panda Security, S.L.)
R1 PSINKNC; C:\WINDOWS\system32\DRIVERS\PSINKNC.sys [207280 2016-02-18] (Panda Security, S.L.)
R2 PSINProc; C:\WINDOWS\System32\DRIVERS\PSINProc.sys [133552 2016-02-18] (Panda Security, S.L.)
R2 PSINProt; C:\WINDOWS\system32\DRIVERS\PSINProt.sys [146864 2016-02-24] (Panda Security, S.L.)
R2 PSINReg; C:\WINDOWS\system32\DRIVERS\PSINReg.sys [117168 2016-02-18] (Panda Security, S.L.)
S3 PSKMAD; C:\WINDOWS\System32\DRIVERS\PSKMAD.sys [62080 2015-06-16] (Panda Security, S.L.)
R0 PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [56336 2012-08-10] (Corel Corporation)
S3 RSUSBCCID; C:\WINDOWS\system32\DRIVERS\RtsUCcid.sys [56936 2015-12-27] (Realtek Semiconductor Corp.)
S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [404184 2015-12-27] (Realsil Semiconductor Corporation)
R3 SbieDrv; D:\Program Files\Sandboxie\SbieDrv.sys [204944 2016-09-23] (Sandboxie Holdings, LLC)
R1 SLEE_19_DRIVER; C:\WINDOWS\Sleen1964.sys [117848 2014-10-24] (Softwareentwicklung Remus - ArchiCrypt - )
R3 Spyder3; C:\WINDOWS\System32\drivers\Spyder3.sys [15360 2008-09-08] ()
R0 tib; C:\WINDOWS\System32\DRIVERS\tib.sys [1310560 2017-01-28] (Acronis International GmbH)
R2 tib_mounter; C:\WINDOWS\system32\DRIVERS\tib_mounter.sys [214360 2017-01-28] (Acronis International GmbH)
S3 tnd; C:\WINDOWS\system32\DRIVERS\tnd.sys [688864 2017-01-28] (Acronis International GmbH)
R1 UimBus; C:\WINDOWS\System32\drivers\UimBus.sys [92848 2016-08-08] ()
R1 Uim_DEVIM; C:\WINDOWS\System32\drivers\uim_devim.sys [26800 2016-08-08] ()
R1 Uim_IM; C:\WINDOWS\System32\drivers\uim_im.sys [484528 2016-08-08] ()
R1 veracrypt; C:\WINDOWS\System32\drivers\veracrypt.sys [467368 2017-02-28] (IDRIX)
R2 virtual_file; C:\WINDOWS\System32\DRIVERS\virtual_file.sys [324448 2017-01-28] (Acronis International GmbH)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 WsAudio_Device; C:\WINDOWS\System32\drivers\VirtualAudio.sys [31080 2013-03-25] (Wondershare)
R1 ZAM; C:\WINDOWS\System32\drivers\zam64.sys [203680 2016-12-20] (Zemana Ltd.)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2016-12-20] (Zemana Ltd.)
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl [146928 2012-01-11] (CyberLink Corp.)
S3 dbx; system32\DRIVERS\dbx.sys [X]
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-12 14:05 - 2017-03-14 08:12 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-03-12 14:04 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2017-03-12 14:04 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2017-03-10 12:57 - 2017-03-10 13:04 - 435513784 _____ (ON1) C:\Users\Rudi\Downloads\ON1_Effects_10.5.1_Free.exe
2017-03-10 10:50 - 2017-03-10 10:50 - 00000000 ___HD C:\Users\Rudi\ zAnti Ransomeware Honeypot
2017-03-10 10:50 - 2017-03-10 10:50 - 00000000 ___HD C:\Users\Rudi\AppData\Roaming\ zAnti Ransomeware Honeypot
2017-03-10 10:50 - 2017-03-10 10:50 - 00000000 ___HD C:\Users\Rudi\AppData\Roaming\ ! Anti Ransomeware Honeypot
2017-03-10 10:50 - 2017-03-10 10:50 - 00000000 ___HD C:\Users\Rudi\AppData\Local\ zAnti Ransomeware Honeypot
2017-03-10 10:50 - 2017-03-10 10:50 - 00000000 ___HD C:\Users\Rudi\AppData\Local\ ! Anti Ransomeware Honeypot
2017-03-10 10:50 - 2017-03-10 10:50 - 00000000 ___HD C:\Users\Rudi\ ! Anti Ransomeware Honeypot
2017-03-10 10:50 - 2017-03-10 10:50 - 00000000 ____D C:\WINDOWS\System32\Tasks\Abelssoft
2017-03-10 10:50 - 2017-03-10 10:50 - 00000000 ____D C:\ProgramData\Abelssoft
2017-03-10 07:17 - 2017-03-10 07:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-03-09 11:48 - 2017-03-09 11:53 - 00000000 ____D C:\Users\Rudi\Desktop\7
2017-03-07 20:30 - 2017-03-07 20:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TreeSize Professional
2017-03-07 12:42 - 2017-03-07 12:42 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\Affinity
2017-03-07 12:42 - 2017-03-07 12:42 - 00000000 ____D C:\ProgramData\Affinity
2017-03-07 12:40 - 2017-03-07 12:40 - 00000836 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Affinity Photo Trial.lnk
2017-03-07 12:39 - 2017-03-07 12:39 - 00000000 ____D C:\Program Files\Affinity
2017-03-07 03:50 - 2017-03-07 03:50 - 00046184 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2017-03-06 21:01 - 2017-03-06 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MultiBit HD
2017-03-04 16:15 - 2017-03-04 16:15 - 00003254 _____ C:\WINDOWS\System32\Tasks\{9E502815-3FB8-422D-934C-BEAC4F7F61A3}
2017-03-04 15:27 - 2017-03-10 10:39 - 00001824 _____ C:\Users\Rudi\Desktop\Bridge17.lnk
2017-03-03 18:11 - 2017-03-04 14:12 - 00001086 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CC 2017.lnk
2017-02-28 19:12 - 2017-02-28 19:12 - 00467368 _____ (IDRIX) C:\WINDOWS\system32\Drivers\veracrypt.sys
2017-02-28 19:12 - 2017-02-28 19:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VeraCrypt
2017-02-27 14:32 - 2017-02-27 14:32 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2017-02-27 14:32 - 2017-02-27 14:32 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\chc
2017-02-26 16:53 - 2017-02-26 16:53 - 00000207 _____ C:\WINDOWS\tweaking.com-regbackup-RUDI-PC-Windows-10-Pro-(64-bit).dat
2017-02-26 16:53 - 2017-02-26 16:53 - 00000000 ____D C:\RegBackup
2017-02-26 16:04 - 2017-03-04 16:06 - 00000000 __SHD C:\Users\Rudi\xncenz
2017-02-26 16:03 - 2017-02-26 16:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2017-02-26 16:02 - 2017-02-26 16:03 - 00174775 _____ C:\WINDOWS\Tweaking.com - Windows Repair Setup Log.txt
2017-02-26 16:02 - 2017-02-26 16:02 - 00000000 ____D C:\Program Files (x86)\Tweaking.com
2017-02-23 15:30 - 2017-02-23 15:33 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\RGS Fotokalender
2017-02-23 15:30 - 2017-02-23 15:30 - 00000000 ____D C:\Users\Rudi\Documents\RGS Fotokalender
2017-02-23 15:30 - 2017-02-23 15:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RGS Fotokalender (64-bit)
2017-02-22 12:00 - 2017-02-22 12:00 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MagicISO
2017-02-21 21:30 - 2017-02-21 21:30 - 00000098 _____ C:\ProgramData\.SF170
2017-02-21 18:03 - 2017-02-21 18:03 - 00000010 _____ C:\Users\Rudi\AppData\Local\.DG212F11-EC8C-210D-DE1E-D9584D18D740
2017-02-21 18:03 - 2017-02-21 18:03 - 00000010 _____ C:\ProgramData\.D6E5339F-CB2B-32C1-CD2D-C0295C19C822
2017-02-21 16:43 - 2017-02-21 21:24 - 00000000 ____D C:\Users\Rudi\AppData\Local\Extensis
2017-02-21 16:43 - 2017-02-21 16:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Extensis
2017-02-19 17:56 - 2017-02-19 17:57 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\your-app
2017-02-19 17:56 - 2017-02-19 17:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZXPInstaller
2017-02-19 17:56 - 2017-02-19 17:56 - 00000000 ____D C:\Program Files (x86)\ZXPInstaller
2017-02-17 19:09 - 2017-02-17 19:09 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\Bitcoin
2017-02-17 17:01 - 2017-02-17 17:01 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\contentlauncher
2017-02-17 17:01 - 2017-02-17 17:01 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\bitmedia
2017-02-17 17:01 - 2017-02-17 17:01 - 00000000 ____D C:\Users\Rudi\AppData\Local\bitmedia
2017-02-17 14:58 - 2017-02-17 14:58 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bitcoin Core
2017-02-15 15:01 - 2017-02-16 15:15 - 00000000 ____D C:\Users\Rudi\Desktop\8
2017-02-15 14:29 - 2017-02-15 14:29 - 05188646 _____ C:\Users\Rudi\Documents\AutoRuns2.arn
2017-02-15 13:18 - 2017-03-13 17:23 - 00000000 ____D C:\Users\Rudi\Documents\PhraseExpress
2017-02-15 13:18 - 2017-02-15 14:30 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\PhraseExpress
2017-02-15 11:07 - 2017-02-15 12:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhraseExpress
2017-02-15 11:07 - 2017-02-15 11:07 - 00000874 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhraseExpress.lnk
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-14 08:19 - 2016-10-01 16:08 - 00097857 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2017-03-14 08:19 - 2016-08-03 16:07 - 00138054 _____ C:\WINDOWS\ZAM.krnl.trace
2017-03-14 08:03 - 2015-07-23 16:51 - 00000000 ____D C:\Users\Rudi\Desktop\Foto
2017-03-14 07:52 - 2016-10-31 11:22 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-14 07:28 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-14 07:28 - 2016-07-16 18:47 - 00000000 ____D C:\Program Files\WindowsApps
2017-03-14 07:25 - 2016-11-01 02:15 - 00759728 _____ C:\WINDOWS\system32\perfh007.dat
2017-03-14 07:25 - 2016-11-01 02:15 - 00154462 _____ C:\WINDOWS\system32\perfc007.dat
2017-03-14 07:25 - 2016-10-31 11:24 - 01757026 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-14 07:22 - 2013-01-31 19:35 - 00000788 _____ C:\Users\Rudi\AppData\Roaming\AtomicAlarmClock.ini
2017-03-14 07:21 - 2016-10-31 11:42 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-14 07:21 - 2016-10-31 11:23 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-14 07:21 - 2016-01-28 19:53 - 00000000 _____ C:\WINDOWS\system32\Drivers\lvuvc.hs
2017-03-13 20:42 - 2016-07-16 13:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-03-13 19:09 - 2016-12-28 20:23 - 00000000 ____D C:\ProgramData\Package Cache
2017-03-13 12:45 - 2017-01-30 17:11 - 00000000 ____D C:\Users\Rudi\Desktop\9
2017-03-12 20:47 - 2016-10-31 11:22 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2017-03-12 14:38 - 2012-12-23 17:30 - 00000000 ____D C:\Users\Rudi\Desktop\Utilities
2017-03-12 14:36 - 2017-01-10 09:31 - 00000000 ____D C:\Program Files\CCleaner
2017-03-12 14:36 - 2016-10-31 11:25 - 00000000 ____D C:\Users\Rudi
2017-03-12 14:36 - 2012-12-26 04:13 - 00000000 ____D C:\ProgramData\Ashampoo
2017-03-12 14:30 - 2017-01-17 13:04 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\krb
2017-03-12 14:29 - 2016-12-22 20:35 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\Google Chrome
2017-03-12 14:04 - 2013-02-26 05:51 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-03-12 13:41 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-03-12 11:24 - 2012-12-23 18:28 - 00000000 ____D C:\Users\Rudi\Desktop\1
2017-03-10 10:50 - 2016-09-17 14:04 - 00000000 ____D C:\Users\Rudi\AppData\Local\Abelssoft
2017-03-10 07:17 - 2016-08-26 13:00 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-03-09 12:18 - 2013-02-02 08:17 - 00000000 ____D C:\Users\Rudi\AppData\Local\ElevatedDiagnostics
2017-03-08 08:58 - 2012-12-24 11:48 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\vlc
2017-03-08 08:51 - 2017-02-09 11:19 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\dvdcss
2017-03-07 20:33 - 2015-09-30 19:49 - 00000000 ____D C:\ProgramData\TEMP
2017-03-07 13:36 - 2016-07-09 08:25 - 00000000 ____D C:\Users\Rudi\Desktop\Internet
2017-03-07 07:34 - 2012-12-23 17:30 - 00000000 ____D C:\Users\Rudi\Desktop\Favoriten
2017-03-06 15:27 - 2012-12-31 09:23 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\calibre
2017-03-05 18:06 - 2015-04-18 06:51 - 00000000 ____D C:\AdwCleaner
2017-03-05 17:58 - 2017-01-01 14:26 - 00000000 ____D C:\Users\Rudi\AppData\LocalLow\Mozilla
2017-03-04 16:26 - 2015-07-18 07:55 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\962C492D-EA7D-4B2D-AEBD-797E18FE960A
2017-03-04 16:22 - 2016-08-20 10:01 - 00000000 ____D C:\Users\Rudi\Desktop\Media
2017-03-04 16:14 - 2012-12-25 14:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Topaz Labs
2017-03-04 16:14 - 2012-12-25 14:25 - 00000000 ____D C:\Program Files\Common Files\Topaz Labs
2017-03-04 15:48 - 2016-08-12 09:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2017-03-04 15:48 - 2016-08-12 09:56 - 00000000 ____D C:\ProgramData\Freemake
2017-03-03 18:11 - 2012-12-25 05:26 - 00000000 ____D C:\Program Files\Common Files\Adobe
2017-03-01 06:42 - 2016-10-31 11:22 - 06072576 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-02-27 14:32 - 2016-12-20 21:16 - 00000000 ____D C:\Users\Public\Documents\Adobe
2017-02-27 14:29 - 2016-09-27 09:39 - 00063042 _____ C:\Users\Rudi\Documents\MuseLog.txt
2017-02-26 17:51 - 2011-04-12 15:28 - 00000000 ____D C:\WINDOWS\CSC
2017-02-26 17:50 - 2016-07-16 18:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-26 16:33 - 2016-12-21 15:03 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-02-26 15:28 - 2016-12-28 11:53 - 00004152 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{70873BFD-9BBF-42E9-BD13-632471A738CD}
2017-02-25 16:35 - 2016-07-16 18:45 - 00000000 ____D C:\WINDOWS\INF
2017-02-23 18:51 - 2012-12-24 13:01 - 00000000 ____D C:\Users\Rudi\Desktop\Drucken
2017-02-22 16:35 - 2017-01-27 08:21 - 00003272 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-02-22 16:35 - 2016-01-28 20:42 - 00002425 _____ C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-02-22 16:35 - 2016-01-28 20:42 - 00000000 ___RD C:\Users\Rudi\OneDrive
2017-02-20 21:19 - 2016-11-01 02:11 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-02-20 21:19 - 2016-07-16 18:47 - 00000000 ____D C:\WINDOWS\Globalization
2017-02-19 12:27 - 2016-06-18 10:01 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps
2017-02-19 10:23 - 2012-12-23 13:45 - 00000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2017-02-15 14:31 - 2016-11-09 04:55 - 00000668 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-595107073-3459872703-1893278198-1000.job
2017-02-15 14:31 - 2016-11-09 04:55 - 00000572 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-595107073-3459872703-1893278198-1000.job
2017-02-15 14:31 - 2016-08-26 13:00 - 00001226 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2017-02-15 14:19 - 2017-02-01 07:57 - 00002636 _____ C:\WINDOWS\System32\Tasks\waygyehb
2017-02-15 14:19 - 2016-11-09 04:55 - 00003322 _____ C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-595107073-3459872703-1893278198-1000
2017-02-15 14:18 - 2017-01-10 09:32 - 00002278 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2017-02-15 14:18 - 2016-11-09 04:55 - 00003226 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-595107073-3459872703-1893278198-1000
2017-02-15 14:18 - 2016-10-31 11:42 - 00003800 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2017-02-15 12:56 - 2017-02-01 07:57 - 00000000 __SHD C:\Users\Rudi\waygyehb
2017-02-15 12:56 - 2016-12-28 20:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phase One
2017-02-15 12:56 - 2016-10-31 11:25 - 00000000 ____D C:\Users\DefaultAppPool
2017-02-15 12:56 - 2016-10-31 11:25 - 00000000 ____D C:\Users\Administrator
2017-02-15 12:56 - 2012-12-26 15:44 - 00000000 ____D C:\ProgramData\Xara
2017-02-15 12:56 - 2012-12-26 15:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xara
2017-02-15 12:50 - 2017-02-11 13:06 - 00000000 ____D C:\Users\Rudi\AppData\Roaming\Phase One Media Pro
2017-02-15 12:50 - 2017-02-11 13:04 - 00000000 ____D C:\Program Files (x86)\Phase One
2017-02-15 12:50 - 2013-01-26 09:35 - 00000000 ____D C:\ProgramData\ABBYY
2017-02-15 12:50 - 2012-12-25 16:11 - 00000000 ____D C:\Users\Rudi\AppData\Local\Xara
2017-02-12 11:44 - 2014-09-17 13:32 - 00000000 ____D C:\Users\Rudi\AppData\Local\ABBYY
==================== Files in the root of some directories =======
2011-01-12 02:00 - 2011-01-12 02:00 - 0146944 _____ () C:\Program Files (x86)\Common Files\dsfFLACDecoder.dll
2011-01-12 02:00 - 2011-01-12 02:00 - 0221184 _____ () C:\Program Files (x86)\Common Files\dsfFLACEncoder.dll
2011-01-12 02:00 - 2011-01-12 02:00 - 0204800 _____ () C:\Program Files (x86)\Common Files\dsfNativeFLACSource.dll
2012-05-11 14:16 - 2012-05-11 14:16 - 0171520 _____ () C:\Program Files (x86)\Common Files\dsfOggDemux2.dll
2011-01-12 02:00 - 2011-01-12 02:00 - 0240128 _____ () C:\Program Files (x86)\Common Files\dsfVorbisDecoder.dll
2016-08-29 09:13 - 2016-08-29 09:13 - 21874200 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2009-07-11 23:08 - 2009-07-11 23:08 - 0001860 _____ () C:\Program Files (x86)\Common Files\Microsoft.VC90.CRT.manifest
2011-04-18 22:51 - 2011-04-18 22:51 - 0569680 _____ (Microsoft Corporation) C:\Program Files (x86)\Common Files\MSVCP90.dll
2011-04-18 22:51 - 2011-04-18 22:51 - 0653136 _____ (Microsoft Corporation) C:\Program Files (x86)\Common Files\MSVCR90.dll
2010-12-16 21:39 - 2010-12-16 21:39 - 0412672 _____ (Google) C:\Program Files (x86)\Common Files\vp8decoder.dll
2010-12-16 21:39 - 2010-12-16 21:39 - 0701440 _____ (Google) C:\Program Files (x86)\Common Files\vp8encoder.dll
2010-12-16 21:39 - 2010-12-16 21:39 - 0302592 _____ (Google) C:\Program Files (x86)\Common Files\webmmux.dll
2010-12-16 21:39 - 2010-12-16 21:39 - 0292352 _____ (Google) C:\Program Files (x86)\Common Files\webmsplit.dll
2011-01-12 02:00 - 2011-01-12 02:00 - 0030208 _____ () C:\Program Files (x86)\Common Files\wmpinfo.dll
2013-01-31 19:56 - 2016-08-03 18:45 - 0000000 _____ () C:\Users\Rudi\AppData\Roaming\alarms.ini
2013-01-31 19:35 - 2017-03-14 07:22 - 0000788 _____ () C:\Users\Rudi\AppData\Roaming\AtomicAlarmClock.ini
2015-08-13 16:02 - 2015-08-13 16:02 - 5082084 _____ (The Public) C:\Users\Rudi\AppData\Roaming\Avisynth.exe
2015-08-13 16:03 - 2015-08-13 16:03 - 5243208 _____ ( ) C:\Users\Rudi\AppData\Roaming\AvsP.exe
2013-10-06 14:46 - 2013-10-06 15:01 - 0008605 _____ () C:\Users\Rudi\AppData\Roaming\ContactSheetII.log
2016-11-10 11:39 - 2016-11-10 11:39 - 0937776 _____ (AutoIt Team) C:\Users\Rudi\AppData\Roaming\FhcV.exe
2013-07-01 08:38 - 2013-07-01 08:38 - 0000010 _____ () C:\Users\Rudi\AppData\Roaming\hhxprot5
2016-02-28 09:17 - 2016-02-28 09:17 - 0000010 _____ () C:\Users\Rudi\AppData\Roaming\hhxprot6
2014-06-08 10:05 - 2016-01-20 21:38 - 0002937 _____ () C:\Users\Rudi\AppData\Roaming\Image Processor Pro.log
2014-11-09 20:56 - 2016-01-20 21:38 - 0002180 _____ () C:\Users\Rudi\AppData\Roaming\Image Processor Pro.xml
2015-08-13 16:02 - 2015-08-13 16:02 - 2169915 _____ (LIGHTNING UK!) C:\Users\Rudi\AppData\Roaming\Imgburn.exe
2012-12-26 03:20 - 2012-12-26 03:20 - 0012971 _____ () C:\Users\Rudi\AppData\Roaming\Kommagetrennte Werte (DOS).CAL
2013-08-31 18:03 - 2016-03-19 12:52 - 0009320 _____ () C:\Users\Rudi\AppData\Roaming\Kommagetrennte Werte (DOS).EML
2013-10-06 14:46 - 2013-10-06 15:01 - 0000684 _____ () C:\Users\Rudi\AppData\Roaming\Kontaktabzug II.xml
2015-08-13 16:03 - 2015-08-13 16:03 - 1357348 _____ () C:\Users\Rudi\AppData\Roaming\MatroskaSplitter.exe
2015-09-29 19:03 - 2016-03-19 12:52 - 0009317 _____ () C:\Users\Rudi\AppData\Roaming\Microsoft Excel 97-2003.EML
2016-07-06 12:14 - 2016-07-06 12:14 - 0000032 _____ () C:\Users\Rudi\AppData\Roaming\New text document.txt
2015-02-08 11:10 - 2016-12-18 22:02 - 0000166 _____ () C:\Users\Rudi\AppData\Roaming\PLGComp.ini
2015-09-19 09:52 - 2015-09-27 16:37 - 0000622 _____ () C:\Users\Rudi\AppData\Roaming\PS13_panel.log
2012-12-25 17:47 - 2015-06-02 14:21 - 0002910 _____ () C:\Users\Rudi\AppData\Roaming\RUDI-PC.MTBF.txt
2015-08-13 16:03 - 2015-08-13 16:03 - 7760687 _____ (Boraxsoft) C:\Users\Rudi\AppData\Roaming\SetupGFD.exe
2012-12-24 15:07 - 2013-02-08 05:45 - 0001158 _____ () C:\Users\Rudi\AppData\Roaming\ShiftN.ini
2013-07-01 08:40 - 2013-07-03 14:45 - 0000018 _____ () C:\Users\Rudi\AppData\Roaming\sys386ll.dat
2016-02-28 09:20 - 2016-02-28 09:20 - 0000018 _____ () C:\Users\Rudi\AppData\Roaming\sys386ln.dat
2013-01-07 00:23 - 2013-01-07 08:42 - 0001386 ___SH () C:\Users\Rudi\AppData\Roaming\systemFP.$dk
2016-03-03 11:09 - 2016-08-12 11:11 - 0000176 _____ () C:\Users\Rudi\AppData\Roaming\WB.CFG
2016-12-01 16:25 - 2016-12-01 16:25 - 1141760 _____ () C:\Users\Rudi\AppData\Roaming\WinWord.exe
2015-08-13 16:02 - 2015-08-13 16:03 - 0117723 _____ () C:\Users\Rudi\AppData\Roaming\yuvcodecs-1.3.exe
2012-12-25 17:47 - 2015-01-09 10:42 - 0000672 _____ () C:\Users\Rudi\AppData\Roaming\__AvidCloudManager.log
2012-12-25 17:47 - 2015-01-09 10:35 - 0000672 _____ () C:\Users\Rudi\AppData\Roaming\__AvidCloudManagerPrevious.log
2017-02-21 18:03 - 2017-02-21 18:03 - 0000010 _____ () C:\Users\Rudi\AppData\Local\.DG212F11-EC8C-210D-DE1E-D9584D18D740
2015-12-02 18:08 - 2016-11-13 13:22 - 0001078 _____ () C:\Users\Rudi\AppData\Local\297ee9cad53a5fc00aaa2013a9c17a85
2013-02-26 14:03 - 2016-12-17 09:05 - 0001456 _____ () C:\Users\Rudi\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2015-10-25 19:43 - 2016-11-14 14:26 - 0001078 _____ () C:\Users\Rudi\AppData\Local\d63cb09e00919dacd631ce4510c7086d
2012-12-25 17:59 - 2015-05-31 07:22 - 0013312 _____ () C:\Users\Rudi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-04-10 05:39 - 2013-04-10 05:39 - 0000393 _____ () C:\Users\Rudi\AppData\Local\HamsterVideoConverterSettings.cfg
2013-02-20 17:19 - 2013-02-20 17:19 - 0000218 _____ () C:\Users\Rudi\AppData\Local\recently-used.xbel
2015-01-09 19:08 - 2015-07-18 08:57 - 0007625 _____ () C:\Users\Rudi\AppData\Local\Resmon.ResmonCfg
2013-02-02 03:12 - 2013-02-03 10:40 - 0212992 _____ () C:\Users\Rudi\AppData\Local\SageThumbs.db3
2013-01-07 09:02 - 2017-01-06 14:28 - 0000620 ___SH () C:\Users\Rudi\AppData\Local\settingsFL.dat
2013-01-07 08:59 - 2017-01-30 20:43 - 0001906 ___SH () C:\Users\Rudi\AppData\Local\win_fldb_sys.dat
2016-05-11 06:43 - 2017-01-30 20:41 - 0011781 ___SH () C:\Users\Rudi\AppData\Local\win_flfiles_sys.dat
2013-01-07 08:59 - 2017-01-30 20:41 - 0003465 ___SH () C:\Users\Rudi\AppData\Local\win_stlthdb_sys.dat
2014-10-22 19:54 - 2014-10-22 19:56 - 0000000 _____ () C:\Users\Rudi\AppData\Local\{333EDD24-946E-4FFE-BEAA-B16E439B8AEF}
2017-02-21 18:03 - 2017-02-21 18:03 - 0000010 _____ () C:\ProgramData\.D6E5339F-CB2B-32C1-CD2D-C0295C19C822
2017-02-21 21:30 - 2017-02-21 21:30 - 0000098 _____ () C:\ProgramData\.SF170
2015-12-05 16:48 - 2015-12-05 16:48 - 0004934 _____ () C:\ProgramData\mtbjfghn.xbe
2017-02-06 21:18 - 2012-08-31 14:08 - 0024772 _____ () C:\ProgramData\P1100DEF.css
2017-02-06 21:18 - 2017-02-06 21:18 - 0004174 _____ () C:\ProgramData\P1100OS.HTM
2017-02-06 21:18 - 2012-08-31 14:08 - 0002944 _____ () C:\ProgramData\P1100SIG.GIF
2015-03-02 10:16 - 2017-01-30 20:41 - 0002568 ___SH () C:\ProgramData\win_mpwd_sys.dat
Files to move or delete:
====================
C:\ProgramData\win_mpwd_sys.dat
Some files in TEMP:
====================
2017-03-11 17:09 - 2017-03-11 17:09 - 0040448 ____N () C:\Users\Rudi\AppData\Local\Temp\proxy_vole977337317339029466.dll
2017-02-27 07:27 - 2017-02-27 07:27 - 0307200 _____ (Eclipse Foundation) C:\Users\Rudi\AppData\Local\Temp\swt-win32-3347.dll
2015-02-13 23:38 - 2015-02-13 23:38 - 7188536 ____R (Microsoft Corporation) C:\Users\Rudi\AppData\Local\Temp\vcredist_x64.exe
2015-02-13 23:38 - 2015-02-13 23:38 - 6498200 ____R (Microsoft Corporation) C:\Users\Rudi\AppData\Local\Temp\vcredist_x86.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-08 17:30
==================== End of FRST.txt ============================ --- --- ---
--- --- --- |