|
Plagegeister aller Art und deren Bekämpfung: Telekom Deutschland - Fake Rechnung 13.11.2014Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
25.11.2014, 12:12 | #1 |
| Telekom Deutschland - Fake Rechnung 13.11.2014 Hi, am 13.11.2014 kam mal wieder eine fake Telekom Rechnung, die leider aus Versehen im Link angeklickt wurde. Der Link (mittlerweile broken - lt. Kaspersky, die so nichts tun können) lautete: hxxp://ifairpeople.com/IpFWX0KoO3 Soviel zum Thema 'FUND', denn der Computer zeigt trotz kurzem DOS Window Aufflackerns nach dem Anklicken des Links zur Zeit nichts ungewöhnliches, aber das heißt ja nichts. Vielleicht erinnert sich ja noch jemand daran. Die Email hängt als JPG hier mit dran. Bisherige Aktionen: unmittelbare Systemwiederherstellung von vor dem Ereignis plus hijackthis, JRT, Kasperky Scan, alle ohne Ergebnis. Mal abgesehen von 538 Löschungen von JRT... wow, trotzdem. Anbei alle Auswertungen von Defogger, FRST & Gmer (letztere als ZIP) mit der Bitte um Untersuchung, um auszuschließen, das da ein Trojaner auf Geld lungert... Vielen Dank für Unterstützung! kein-janer Geändert von kein-janer (25.11.2014 um 12:19 Uhr) |
25.11.2014, 12:56 | #2 |
/// the machine /// TB-Ausbilder | Telekom Deutschland - Fake Rechnung 13.11.2014 Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. Ich kann auf Arbeit keine Anhänge öffnen, danke. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
25.11.2014, 13:12 | #3 |
| Delogger ErgebnisCode:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 11:07 on 25/11/2014 (Helge Hartz) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-11-2014 01 Ran by Helge Hartz at 2014-11-25 11:09:15 Running from C:\Users\Helge Hartz\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Acronis True Image 2014 (HKLM-x32\...\{3ECDD663-5AF8-489B-9E3C-561F33A271BD}Visible) (Version: 17.0.6673 - Acronis) Acronis True Image 2014 (x32 Version: 17.0.6673 - Acronis) Hidden Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.9.0.1030 - Adobe Systems Incorporated) Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.223 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.223 - Adobe Systems Incorporated) Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.) Advertising Center (x32 Version: 0.0.0.1 - Nero AG) Hidden Anytime USB Charge Utility (HKLM-x32\...\{549BF60D-FDDA-4E4C-ABE3-9E897BC09E79}) (Version: 1.00.00.001 - FUJITSU LIMITED) Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ArcSoft PhotoStudio 6 (HKLM-x32\...\{ED8EF3C2-FA5B-4A1E-950D-5A0227161F97}) (Version: 6.0.1.134 - ArcSoft) ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.10 - Michael Tippach) Assimil Norwegisch ohne Mühe (HKLM-x32\...\{E4BF3D82-0D8D-460F-9123-554A59DB9253}}_is1) (Version: d_no - Assimil) Assimil Schwedisch ohne Mühe (HKLM-x32\...\{1F75067E-86AE-4C09-AEA9-9EFA9C390B36}}_is1) (Version: d_se - Assimil) AusweisApp (HKLM-x32\...\{BA6CDB7A-F5D7-4341-99E1-1FF0AAEAF1D8}) (Version: 1.13.0 - OpenLimit SignCubes AG) AuthenTec Fingerprint Software (HKLM\...\{5F1DFCC1-595D-4235-A044-E05B706D800A}) (Version: 9.0.8.35 - AuthenTec, Inc.) Auto Rotation Utility (HKLM-x32\...\InstallShield_{9D90DF69-ABFF-4A8D-8B0D-27FA46509DE3}) (Version: 1.01.10.003 - FUJITSU LIMITED) Auto Rotation Utility (Version: 1.01.10.003 - FUJITSU LIMITED) Hidden Avi to Mpeg 3.5 (HKLM-x32\...\{14BF164E-80A4-422E-BE43-39FB759666C2}_is1) (Version: 3.5 - Avi to Mpeg) AvMap USB device driver (HKLM-x32\...\AvMap USB device driver_is1) (Version: 2.2.0.6 - AvMap) Battery Utility (HKLM-x32\...\{1054208F-DD88-43C9-8B3A-CA3D9786E52B}) (Version: 3.01.16.005 - FUJITSU LIMITED) BB FlashBack Express (HKLM-x32\...\BB FlashBack Express) (Version: 4.1.8.2960 - Blueberry) Bing-Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.171.0 - Microsoft Corporation) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - ) Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.) Canon MG5300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5300_series) (Version: - Canon Inc.) Canon MP Navigator EX 2.1 (HKLM-x32\...\MP Navigator EX 2.1) (Version: - ) CanoScan LiDE 700F Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_cnq9601) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.19 - Piriform) CHIRP (HKLM-x32\...\CHIRP) (Version: - ) Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) cyberJack Base Components (HKLM-x32\...\{FC338210-F594-11D3-BA24-00001C3AB4DF}) (Version: 6.10.0 - REINER SCT) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DEM25 Deutschland (HKLM-x32\...\DEM25 Deutschland_is1) (Version: 6 - QuoVadis Software GmbH) DeskUpdate (HKLM-x32\...\DeskUpdate_is1) (Version: 4.15.0134 - Fujitsu Technology Solutions) Deutschland Top25 QV-Map (HKLM-x32\...\Deutschland Top25 QV-Map_is1) (Version: 6 - QuoVadis Software GmbH) Dimension 4 v5.0 (HKLM-x32\...\{935FF092-EEBA-4E97-8C1B-CD2364F392A4}) (Version: 5.0.33 - Thinking Man Software) Dl-Fldigi 3.21.50 (HKLM-x32\...\Dl-Fldigi-3.21.50) (Version: 3.21.50 - Fldigi developers) Dropbox (HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\Dropbox) (Version: 2.10.52 - Dropbox, Inc.) EasyTransfer 5.0. Build 23 (HKLM-x32\...\EasyTransfer_1.0.0) (Version: - ) EchoLink (HKLM-x32\...\{DC33421C-0E1C-470A-BE37-7B7C82677812}) (Version: 2.0.908 - Synergenics, LLC) Ekiga (nur entfernen) (HKLM-x32\...\Ekiga) (Version: - ) ElsterFormular (HKLM-x32\...\ElsterFormular 13.2.0.8623p) (Version: 15.0.13315 - Landesfinanzdirektion Thüringen) Europa West-Ost Here 2014 (HKLM-x32\...\Europa West-Ost Here 2014_is1) (Version: 6 - QuoVadis Software GmbH) EZCast (HKLM-x32\...\{74CECDD9-4B8E-4AE3-9571-8070A17F3C34}) (Version: 1.1.0.130 - Actions-Micro) FileZilla Client 3.9.0.6 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse) FJ Camera (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.52019.0 - Sonix) Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com) Fujitsu Button Utilities (HKLM\...\{207E8B60-07D2-4B7F-97FE-0DA448606861}) (Version: 7.02.0902.2009 - Fujitsu America, Inc.) Fujitsu Display Manager (HKLM-x32\...\InstallShield_{4108974B-DE87-4AD4-9167-930C62C45691}) (Version: - ) Fujitsu Display Manager (Version: 7.01.20.203 - FUJITSU LIMITED) Hidden Fujitsu Hotkey Utility (HKLM-x32\...\InstallShield_{C8E4B31D-337C-483D-822D-16F11441669B}) (Version: 3.70.0.0 - FUJITSU LIMITED) Fujitsu Hotkey Utility (x32 Version: 3.70.0.0 - FUJITSU LIMITED) Hidden Fujitsu MobilityCenter Extension Utility (HKLM-x32\...\InstallShield_{EC314CDF-3521-482B-A21C-65AC95664814}) (Version: 3.01.00.001 - FUJITSU LIMITED) Fujitsu MobilityCenter Extension Utility (Version: 3.01.00.001 - FUJITSU LIMITED) Hidden Fujitsu System Extension Utility (HKLM-x32\...\InstallShield_{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}) (Version: 3.3.0.0 - FUJITSU LIMITED) Fujitsu System Extension Utility (Version: 3.3.0.0 - FUJITSU LIMITED) Hidden Galería de fotos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Galerie de photos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Garmin Training Center (HKLM-x32\...\{50C913B1-A091-48B8-A434-6C9670284888}) (Version: 3.6.5 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries) Geosat MapConverter 1.2 (HKLM-x32\...\Geosat MapConverter) (Version: 1.2 - AvMap) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden GPSBabel 1.4.3 (HKLM-x32\...\{1B8FE958-A304-4902-BF7A-4E2F0F5B7017}_is1) (Version: - GPSBabel) GPS-Format-Konverter V1.23 (HKLM-x32\...\GPS-Format-Konverter_is1) (Version: - ASTR-Software) GTK2-Runtime (HKLM-x32\...\GTK2-Runtime) (Version: 2.22.0-2010-10-21-ash - Alexander Shaduri) Ham CAP 1.80 (HKLM-x32\...\Ham CAP_is1) (Version: - Alex Shovkoplyas, VE3NEA) Hauppauge WinTV 7 (HKLM-x32\...\Hauppauge WinTV 7) (Version: v7.0.32168 (CD 3.5) - Hauppauge Computer Works) Icom CS-5100 (HKLM-x32\...\{440F9936-6D35-459E-A97F-AEF4F9B97481}) (Version: 1.10 - Icom Inc.) Icom USB-to-Serial (HKLM-x32\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.00.000 - Icom) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden Integrity Tool (HKLM-x32\...\{5B37CD1D-1F72-42DD-99B9-9D92FA8C3342}) (Version: 1.10.0 - OpenLimit SignCubes AG) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2372 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\...\{90F00673-A276-4A58-B675-B426D39D1E09}) (Version: 15.3.0.0398 - Intel Corporation) Intel(R) WiDi (HKLM-x32\...\{25680C01-6753-4FE9-A891-7857F26457C1}) (Version: 2.1.35.0 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel® PROSet/Wireless WiFi-Software (HKLM\...\{ECE5B218-A086-4E18-A362-D11181681457}) (Version: 15.03.1000.1637 - Intel Corporation) IonoProbe 1.39 (HKLM-x32\...\IonoProbe_is1) (Version: - Afreet Software, Inc.) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.36 - Irfan Skiljan) ISD Tablet (HKLM\...\ISD Tablet Driver) (Version: 7.0.2-17 - Wacom Technology Corp.) ITS HF Propagation 2014.11.14 (HKLM\...\{1B328085-F1A5-4AB8-8986-0103C5800216}) (Version: 2014.11.14 - US Department of Commerce NTIA/ITS) iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.) IZArc 4.1.8 (HKLM-x32\...\{97C82B44-D408-4F14-9252-47FC1636D23E}_is1) (Version: 4.1.8 - Ivan Zahariev) Japanese Fonts Support For Adobe Reader X (HKLM-x32\...\{AC76BA86-7AD7-5760-0000-A00000000003}) (Version: 10.0.0 - Adobe Systems Incorporated) Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) JOSM 6060 (HKLM-x32\...\OSM) (Version: 6060 - The OpenStreetMap developer community, hxxp://www.openstreetmap.org/) Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Internet Security (x32 Version: 14.0.0.4651 - Kaspersky Lab) Hidden KENWOOD ARCP-480 (HKLM-x32\...\{33E5F114-8272-40F9-AB33-58A39CAA5EC8}) (Version: 1.10.000 - JVC KENWOOD Corporation) Kopplungswerkzeuge für Rapoo-Maus und -Tastatur V3.2 (HKLM-x32\...\{1899FF3C-B115-4C6C-A81A-9F1FBBCEAF36}_is1) (Version: - Rapoo Inc.) Logitech Webcam-Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.31 - Logitech Inc.) MCP-2A (Remove only) (HKLM-x32\...\{10CA63B1-DEF1-4718-A122-268486A6EF66}) (Version: 3.21.000 - JVC KENWOOD Corporation) MCP-4A (HKLM-x32\...\{4CBC4137-823A-4D3F-ACCA-060C5C1A4D92}) (Version: 1.03.0013 - JVC KENWOOD Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Expression Encoder 4 (HKLM-x32\...\Encoder_4.0.4276.0) (Version: 4.0.4276.0 - Microsoft Corporation) Microsoft Expression Encoder 4 Screen Capture Codec (HKLM-x32\...\{E5AB3F65-7FAC-41C6-B176-7599D2404BB2}) (Version: 4.0.4276.0 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office XP Professional (HKLM-x32\...\{91110407-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) mIRC (HKLM-x32\...\mIRC) (Version: 7.34 - mIRC Co. Ltd.) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 33.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.1 (x86 de)) (Version: 33.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyFreeCodec (HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\MyFreeCodec) (Version: - ) Nero 9 Essentials (HKLM-x32\...\{5fbb433b-7ef0-49ee-8e62-8f9730339edb}) (Version: - Nero AG) Netzmanager (HKLM-x32\...\Netzmanager) (Version: 1.071 - Deutsche Telekom AG) Netzmanager (Version: 1.071 - Deutsche Telekom AG, Marmiko IT-Solutions GmbH) Hidden O2Micro Flash Memory Card Windows Driver (HKLM-x32\...\InstallShield_{5CB9660D-919E-421A-AE17-DD6C925E1AF3}) (Version: 3.1.00.18 - O2Micro International LTD.) O2Micro Flash Memory Card Windows Driver (Version: 3.1.00.18 - O2Micro International LTD.) Hidden O2Micro OZ776 SCR Driver (HKLM-x32\...\InstallShield_{26208444-C11B-4820-B224-7F66549B0E16}) (Version: 2.1.4.210GS - O2Micro) O2Micro OZ776 SCR Driver (Version: 2.1.4.210GS - O2Micro) Hidden Orbitron - Satellite Tracking System (HKLM-x32\...\Orbitron_is1) (Version: 3.71 - Sebastian Stoff) OWOK 2.0.0.4 NPAPI (HKLM-x32\...\OWOK-NPAPI-20) (Version: 2.0.0.4 - REINER Kartengeraete GmbH und Co. KG) Paxon 2.00 (HKLM-x32\...\Paxon) (Version: 2.00 - Ulf Haueisen) PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia) PComm Lite Ver1.6 (HKLM\...\PComm Lite Ver1.6_is1) (Version: - Moxa Inc.) PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.9.3 - pdfforge) Photo Common (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden PL-2303 USB-to-Serial (HKLM-x32\...\{A9111573-EF12-4D80-A5B9-55F620D5BCA1}) (Version: 1.00.000 - Prolific Technology INC) Plugfree NETWORK (HKLM\...\{7BA64D21-EE46-4a9a-8145-52B0175C3F86}) (Version: 5.4.0.1 - FUJITSU LIMITED) Plugfree NETWORK (Version: 5.4.001 - FUJITSU LIMITED) Hidden POIConverter (HKLM-x32\...\POIConverter) (Version: 4.11 - Richard Davies) Pointing Device Utility (HKLM-x32\...\InstallShield_{DDC49774-40B9-47AE-9C63-5569C08C4082}) (Version: 1.0.1.0 - FUJITSU LIMITED) Pointing Device Utility (x32 Version: 1.0.1.0 - FUJITSU LIMITED) Hidden Power Saving Utility (HKLM-x32\...\{49A588CF-5FD4-4774-BFBF-0764287DE82B}) (Version: 32.01.10.016 - FUJITSU LIMITED) PSPad editor (HKLM-x32\...\PSPad editor_is1) (Version: 4.5.7.2450 - Jan Fiala) Python 2.7.3 (64-bit) (HKLM\...\{C0C31BCC-56FB-42a7-8766-D29E1BD74C7d}) (Version: 2.7.3150 - Python Software Foundation) QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) QuoVadis 7 (HKLM-x32\...\QuoVadis 7_is1) (Version: 7 - Flemming Software Development CC) QuoVadis NaviSpeech 7 (HKLM-x32\...\QuoVadis NaviSpeech 7_is1) (Version: 7 - QuoVadis Software GmbH) QuoVadis Ortsdatenbank Welt (HKLM-x32\...\QuoVadis Ortsdatenbank Welt_is1) (Version: 4 - QuoVadis Software GmbH) Raccolta foto (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6263 - Realtek Semiconductor Corp.) RefManager 1.0 (HKLM-x32\...\RefManager_is1) (Version: - Afreet Software, Inc.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden RMS Express (HKLM-x32\...\{93EDD4EF-B076-4625-A497-06803F9F5CD1}) (Version: 1.1.0 - Winlink 2000) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.1.13105_7 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.6.1.13105_7 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.) SARTrack Version 0.9.609 Beta (HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\SARTrack_is1) (Version: 0.9.609 - SARTrack Limited) Security Panel (HKLM-x32\...\InstallShield_{45CA9B23-5EF8-43AA-9851-E9E062BF0147}) (Version: 2.2.0.0 - FUJITSU LIMITED) Security Panel Application (x32 Version: 2.2.0.0 - FUJITSU LIMITED) Hidden Security Panel Application for Supervisor (x32 Version: 2.2.0.0 - FUJITSU LIMITED) Hidden Security Panel for Supervisor (HKLM-x32\...\InstallShield_{17F82182-0E3D-4A14-8843-5ECBFAF4F12F}) (Version: 2.2.0.0 - FUJITSU LIMITED) Sierra Wireless QMI Driver Package (HKLM-x32\...\SWIQMIDrvInstaller) (Version: 1.0.0.9 - Sierra Wireless Inc.) Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM-x32\...\SLABCOMM&10C4&EA60) (Version: - Silicon Laboratories) Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7_2 (c:\SiLabs\MCU\CP210x\Windows_XP_S2K3_Vista_7_2) (HKLM-x32\...\{332D993E-D680-44AA-8A0D-424AA2FE9F8F}) (Version: 6.4 - Silicon Laboratories, Inc.) Skype™ 6.21 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.) Steinberg Cubase LE (HKLM-x32\...\Steinberg Cubase LE) (Version: - ) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.11.1 - Synaptics Incorporated) TCX Converter 2.0.29 (HKLM-x32\...\{9F74B6DE-B89C-4532-AFED-5AB0CCAAC1DF}_is1) (Version: - DDAAXX) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.35436 Beta - TeamViewer) Touch Launcher (HKLM-x32\...\{8A90AF02-C1C3-4489-B60A-902D1AA53D37}) (Version: V1.2L04 - FUJITSU LIMITED) UE Music Library 10.0.4 (HKLM-x32\...\UE Music Library_is1) (Version: 10.0.4 - Logitech) UI-View32 (HKLM-x32\...\UI-View32_is1) (Version: 2.03 - Peak Systems) UM-1-Treiber (HKLM\...\RolandRDID0009) (Version: - Roland Corporation) UZ7HO Soundmodem .41 Beta (HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\UZ7HO Soundmodem .41 Beta ) (Version: - ) VOAProp (HKLM-x32\...\VOAProp) (Version: 1.1 - G4ILO Software) Vokabeltrainer Norsk for deg (HKLM-x32\...\de.klett.vokabeltrainer.norskForDeg.640931D04D7FB29612090B9316373CF9A4E7C6C5.1) (Version: 1.0.1 - Ernst Klett Sprachen GmbH) Vokabeltrainer Norsk for deg (x32 Version: 1.0.1 - Ernst Klett Sprachen GmbH) Hidden Wave Editor 3.2.1.0 (HKLM-x32\...\Wave Editor_is1) (Version: 3.2.1.0 - AbyssMedia.com) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.6900 - Broadcom Corporation) Windows Driver Package - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2) (HKLM\...\24DA573F901348FFDFF7717497830D45BE0C362E) (Version: 07/07/2009 1.12.2 - Dynastream Innovations) Windows Driver Package - Fujitsu America, Inc. (FjBtnDrv) HIDClass (08/27/2009 4.2.0827.2009) (HKLM\...\C1556C282D8A9FB37C3F3925E582B76545A344EF) (Version: 08/27/2009 4.2.0827.2009 - Fujitsu America, Inc.) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) (HKLM\...\49CF605F02C7954F4E139D18828DE298CD59217C) (Version: 06/03/2009 2.3.0.0 - Garmin) Windows Driver Package - SCS SCS Driver Package - Bus/D2XX Driver (04/10/2012 2.08.24) (HKLM\...\BC00913D027C41CC21E744CFDA8F3DF6DF45E2CF) (Version: 04/10/2012 2.08.24 - SCS) Windows Driver Package - SCS SCS Driver Package - VCP Driver 1 (04/10/2012 2.08.24) (HKLM\...\7811E449E9CAA643E49707C43F2FAE3A35462D0D) (Version: 04/10/2012 2.08.24 - SCS) Windows Driver Package - SCS SCS Driver Package - VCP Driver 2 (04/10/2012 2.08.24) (HKLM\...\3BFF416D0CF83690179331AC3C8309B77A6D18FA) (Version: 04/10/2012 2.08.24 - SCS) Windows Driver Package - SCS SCS Driver Package - VCP Driver 3 (04/10/2012 2.08.24) (HKLM\...\0B6DDC331557B47917A9CF022C536EA39D735575) (Version: 04/10/2012 2.08.24 - SCS) Windows Driver Package - Silicon Laboratories (silabenm) Ports (12/10/2012 6.6.1.0) (HKLM\...\D680DEE0F68D64EC53D0C5769879D15D387054CC) (Version: 12/10/2012 6.6.1.0 - Silicon Laboratories) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows Mobile-Gerätecenter: Treiberupdate (HKLM\...\{92DBCA36-9B41-4DD1-941A-AED149DD37F0}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) Windows-Treiberpaket - Silicon Laboratories (silabenm) Ports (03/19/2014 6.7.0.0) (HKLM\...\B97004A400E30DCF940971EFA7A0C13C6B0A4B66) (Version: 03/19/2014 6.7.0.0 - Silicon Laboratories) Windows-Treiberpaket - Silicon Laboratories (silabenm) Ports (10/18/2013 6.6.1.0) (HKLM\...\F92C2D6CB4EA0EE558BDF5F8BDD69083DFC62179) (Version: 10/18/2013 6.6.1.0 - Silicon Laboratories) WinHTTrack Website Copier 3.45-4 (HKLM-x32\...\WinHTTrack Website Copier_is1) (Version: 3.45.4 - HTTrack) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ==================== Restore Points ========================= 25-11-2014 06:33:44 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0AA05706-3CF6-47E6-B2A9-1E2D0F356015} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-10-23] (Piriform Ltd) Task: {44510234-7A6D-45C7-BE27-CD04ACA340EE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-12] (Adobe Systems Incorporated) Task: {666A020D-B599-4E83-8841-212CB99D79FC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-22] (Google Inc.) Task: {A078082D-527C-4B5D-9521-AFDEB40769DA} - System32\Tasks\Fujitsu\DeskUpdate => c:\Fujitsu\Programs\DeskUpdate\ducmd.exe [2013-12-11] (Fujitsu Technology Solutions) Task: {A22EEE67-C128-46D2-8B1E-0BACB561CED8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-22] (Google Inc.) Task: {C24E6D89-AA1F-4C9A-A470-C7DAE167F09D} - System32\Tasks\Metar2APRS => cmd Task: {CD439C62-7727-4341-A09B-43084756DA60} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2012-05-22 20:10 - 2011-02-23 05:11 - 01182576 _____ () C:\Program Files\Tablet\ISD\libxml2.dll 2011-05-10 11:48 - 2011-04-15 02:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-10-23 20:19 - 2014-10-23 20:19 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2010-10-15 18:08 - 2010-10-15 18:08 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2011-03-01 07:55 - 2011-02-03 11:56 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll 2013-10-01 10:32 - 2013-10-01 10:32 - 02818216 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll 2013-07-08 00:13 - 2012-07-20 13:39 - 02469888 _____ () C:\Program Files (x86)\IZArc\IZArcCM64.dll 2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-06-17 11:35 - 2013-06-17 11:35 - 00478400 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll 2013-05-08 13:52 - 2013-05-08 13:52 - 01270464 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll 2012-11-20 10:07 - 2007-05-31 07:38 - 00167936 ____N () C:\Windows\SysWOW64\SerialXP.dll 2014-07-28 16:32 - 2014-02-14 09:59 - 00025600 _____ () C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServerps.dll 2014-07-28 16:32 - 2011-08-23 10:04 - 00057344 _____ () C:\Program Files (x86)\WinTV\TVServer\libhdhomerun.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00028774 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024679 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\c5cce8d16a1bd48692b421dcf46d3396\Util.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024701 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00028779 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00020601 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\4461f48e31bde5c56b31b973b773de09\List.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00118918 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00082048 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00020576 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00036964 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\f233f63b6654362865c7577442edb9e3\Win32.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00020590 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00082033 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024676 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00061540 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\e56c61f7248672819579325af3387035\POSIX.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00094334 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\eb138ef0e4282611dbf485a302784646\LibYAML.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00053340 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00184414 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\bd5179a413bc0c4b82eedc22c6cab101\re.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024701 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3860\93e7e3d6030f426844228042348210cf\Service.dll 2011-03-01 07:55 - 2011-02-03 11:56 - 00066856 _____ () C:\WINDOWS\SysWOW64\SynTPEnhPS.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00043008 ____N () c:\Users\Helge Hartz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmphfz4hk.dll 2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\libcef.dll 2014-02-04 18:25 - 2014-02-04 18:25 - 00036672 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\qt_icontray_ex.dll 2014-02-04 18:25 - 2014-02-04 18:25 - 00028992 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\thread_pool.dll 2013-10-10 12:02 - 2013-10-10 12:02 - 00013120 _____ () C:\Program Files (x86)\Common Files\Acronis\TibMounter\icudt38.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00020576 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00036964 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\f233f63b6654362865c7577442edb9e3\Win32.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024676 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00061540 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\e56c61f7248672819579325af3387035\POSIX.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00020590 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00082033 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00118918 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00082048 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00028779 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00020601 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\4461f48e31bde5c56b31b973b773de09\List.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024681 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\c199d3c1960e7aeeecb599487952bed2\HiRes.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00090213 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\961b0d62fa52b1dd29c795a822fbf1cf\DBI.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024679 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\c5cce8d16a1bd48692b421dcf46d3396\Util.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00077824 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\7f177c338672436e01c4f0bdbcf94491\EV.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00138752 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\44727051c604ef6b79894b64d4c63832\Expat.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00041080 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\2b1fc61b36a6711ea149b18bf3b41500\Parser.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00030720 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\dacfd0ab9b5fd029ed8d29e4482b0775\XS.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00020590 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\fa9e3c814aa32db2ad5f17bdfbc22746\attributes.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024694 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\c344fd5536724b2af2e6453833b60203\SHA1.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00094334 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\eb138ef0e4282611dbf485a302784646\LibYAML.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00053340 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00184414 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\bd5179a413bc0c4b82eedc22c6cab101\re.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00020592 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\b979ace6da01e63d651cce9ee2474fdc\Name.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00028774 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00182272 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\d0bf009923f29116535c26d228271d6d\Scan.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024672 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\17d0b152e63e6bfe81b4b19588538896\mro.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00020596 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\3b7106dd14676048b10bbb09a990f74c\XS.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00032878 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024695 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\cf5fe81e2f5dcbfecfd0495e1648c991\Unicode.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024670 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\3a8764e0d7c5d453e01d9ad08cf7fb58\IO.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00361472 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\aff7ee779ea184f884ed432c30a58f5d\Scale.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024701 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00061546 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\4f2c03383aab0133b8dc0a3fa2dd92fa\Storable.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00110705 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\7f2598c08178217a0e2c754f3d568f28\Byte.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00024679 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\c19d5e3dc664d9f4ce700001e2621cee\MD5.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00608256 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\e2e81dd6b3e5a36f0bdae076393cc11d\SQLite.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00001024 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\e2e81dd6b3e5a36f0bdae076393cc11d\icudt46.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00020596 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\d1c77e404b5c4b954fa537ed63c8fb7b\File.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00030208 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\0665c25e931c1ac0151b062449e91028\XSAccessor.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00020587 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\c668a322917d32a5ea22894518aa9897\Base64.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00017920 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\8fedeb86a4a984edfc1fb255d4ea965c\XS.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00061547 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\bc147d83c7c868eeee67082dcf55430c\File.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00032881 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\b6bd87c968599725b8ab2e5c25d3046a\API.dll 2014-11-25 07:29 - 2014-11-25 07:29 - 00098415 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4988\19febd96672ffdb7ea244cef36aaa062\Zlib.dll 2014-02-04 18:28 - 2014-02-04 18:28 - 00420160 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AutoStart IR.lnk => C:\Windows\pss\AutoStart IR.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinTV Recording Status.lnk => C:\Windows\pss\WinTV Recording Status.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Helge Hartz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Ekiga.lnk => C:\Windows\pss\Ekiga.lnk.Startup MSCONFIG\startupreg: ANT Agent => C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: ArcSoft Connection Service => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe MSCONFIG\startupreg: BingDesktop => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey MSCONFIG\startupreg: DeskUpdateNotifier => "c:\Fujitsu\Programs\DeskUpdate\DeskUpdateNotifier.exe" MSCONFIG\startupreg: IJNetworkScannerSelectorEX => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: snp2uvc => C:\Windows\vsnp2uvc.exe ========================= Accounts: ========================== Administrator (S-1-5-21-4011218287-2957974095-3496630771-500 - Administrator - Disabled) Gast (S-1-5-21-4011218287-2957974095-3496630771-501 - Limited - Enabled) Helge Hartz (S-1-5-21-4011218287-2957974095-3496630771-1000 - Administrator - Enabled) => C:\Users\Helge Hartz HomeGroupUser$ (S-1-5-21-4011218287-2957974095-3496630771-1006 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= Name: Intel(R) 82579LM Gigabit Network Connection Description: Intel(R) 82579LM Gigabit Network Connection Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Intel Service: e1cexpress Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Bluetooth-Gerät (PAN) Description: Bluetooth-Gerät (PAN) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: BthPan Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (11/25/2014 11:05:01 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: DropboxExt64.24.dll, Version: 1.0.0.24, Zeitstempel: 0x53a8c70f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000008d57 ID des fehlerhaften Prozesses: 0x878 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/25/2014 07:29:11 AM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/24/2014 07:13:19 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/24/2014 06:28:18 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/24/2014 06:07:28 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/24/2014 01:28:09 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/24/2014 07:18:05 AM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/23/2014 07:00:01 PM) (Source: Windows Backup) (EventID: 4103) (User: ) Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "D:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)" Error: (11/23/2014 03:22:24 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/23/2014 00:24:00 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. System errors: ============= Error: (11/25/2014 07:29:21 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom hwinterface Error: (11/25/2014 07:28:54 AM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\hwinterface.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (11/24/2014 07:58:09 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {51FA2736-5DEE-11D4-98E8-006008BF430C} Error: (11/24/2014 07:13:31 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom hwinterface Error: (11/24/2014 07:13:04 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\hwinterface.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (11/24/2014 06:28:28 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom hwinterface Error: (11/24/2014 06:28:10 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 24.11.2014 um 18:26:23 unerwartet heruntergefahren. Error: (11/24/2014 06:28:02 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\hwinterface.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (11/24/2014 06:07:39 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom hwinterface Error: (11/24/2014 06:07:13 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\hwinterface.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Microsoft Office Sessions: ========================= Error: (11/25/2014 11:05:01 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Explorer.EXE6.1.7601.175674d672ee4DropboxExt64.24.dll1.0.0.2453a8c70fc00000050000000000008d5787801d008791d8971e5C:\Windows\Explorer.EXEC:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll84ba721e-748a-11e4-bce4-904508044f70 Error: (11/25/2014 07:29:11 AM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/24/2014 07:13:19 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/24/2014 06:28:18 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/24/2014 06:07:28 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/24/2014 01:28:09 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/24/2014 07:18:05 AM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/23/2014 07:00:01 PM) (Source: Windows Backup) (EventID: 4103) (User: ) Description: D:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006) Error: (11/23/2014 03:22:24 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/23/2014 00:24:00 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2014-09-11 08:06:59.540 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-11 08:06:59.524 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-11 08:06:59.524 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-11 08:06:59.524 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-11 08:02:26.991 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-11 08:02:26.913 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-24 18:42:28.341 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-24 18:42:28.341 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-24 18:42:28.341 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-24 18:42:28.325 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-2640M CPU @ 2.80GHz Percentage of memory in use: 42% Total physical RAM: 7930.85 MB Available physical RAM: 4547.25 MB Total Pagefile: 15859.88 MB Available Pagefile: 12959.09 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:445.14 GB) (Free:282.73 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 499F1625) Partition 1: (Active) - (Size=2.1 GB) - (Type=27) Partition 2: (Not Active) - (Size=463.7 GB) - (Type=05) ==================== End Of Log ============================ |
25.11.2014, 13:13 | #4 |
| FRSTFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-11-2014 01 Ran by Helge Hartz (administrator) on NAVIGATOR on 25-11-2014 11:08:47 Running from C:\Users\Helge Hartz\Desktop Loaded Profile: Helge Hartz (Available profiles: Helge Hartz) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AuthenTec, Inc.) C:\Program Files\Fingerprint Sensor\ATService.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_TouchService.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Wacom Technology, Inc) C:\Program Files\Tablet\CalibrationAssistant.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_TouchUser.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Hauppauge Computer Works) C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\BatteryAid2\BatteryDaemon.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\AutoRotation\AutoRotation.exe (AuthenTec, Inc.) C:\Program Files\Fingerprint Sensor\ATSwpNav.exe (Fujitsu Computer Systems Corporation) C:\Program Files\Fujitsu\Utils\FjDspMon.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (Fujitsu Computer Systems Corporation) C:\Program Files\Fujitsu\Utils\FjEvents.exe (Fujitsu Computer Systems) C:\Program Files\Fujitsu\Utils\FjLidMon.exe (Fujitsu America, Inc.) C:\Program Files\Fujitsu\Utils\FjMnuIco.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (O2Micro International) C:\Windows\System32\drivers\o2flash.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\UE Music Library\UEMLTray.exe (Hauppauge Computer Works, Inc.) C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\PointingDeviceUtility\FJPDAutoSet.exe (Dropbox, Inc.) C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (Sierra Wireless, Inc.) C:\Program Files (x86)\Sierra Wireless Inc\Gobi\QDLService\GobiQDLService.exe (Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE (Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Fujitsu Technology Solutions) C:\Fujitsu\Programs\DeskUpdate\DeskUpdateNotifier.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_Tablet.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_TabletUser.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\UE Music Library\server\ueml.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Hauppauge Computer Works) C:\Program Files (x86)\WinTV\TVServer\CaptureDLNA.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.exe (Hauppauge Computer Works) C:\Program Files (x86)\WinTV\TVServer\CaptureDLNA.exe (Hauppauge Computer Works) C:\Program Files (x86)\WinTV\TVServer\CaptureDLNA.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_Tablet.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [] => [X] HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-03] (Synaptics Incorporated) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11663464 2010-12-07] (Realtek Semiconductor) HKLM\...\Run: [PfNet] => C:\Program Files\Fujitsu\Plugfree NETWORK\PfNet.exe [6311424 2010-10-07] (FUJITSU LIMITED) HKLM\...\Run: [FDM7] => C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe [164200 2009-10-19] (FUJITSU LIMITED) HKLM\...\Run: [FjStrtAp] => C:\Program Files\Fujitsu\Utils\FjStrtAp.exe [19800 2010-12-01] (Fujitsu America, Inc..) HKLM\...\Run: [LoadFUJ02E3] => C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [45680 2010-06-08] (FUJITSU LIMITED) HKLM\...\Run: [PSUTility] => C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [199528 2010-11-13] (FUJITSU LIMITED) HKLM\...\Run: [FJBATAID2] => C:\Program Files\Fujitsu\BatteryAid2\BatteryDaemon.exe [124776 2010-10-30] (FUJITSU LIMITED) HKLM\...\Run: [FJAutoR] => C:\Program Files\Fujitsu\AutoRotation\AutoRotation.exe [98664 2011-04-22] (FUJITSU LIMITED) HKLM\...\Run: [ATSwpNav] => "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [519408 2013-07-18] (Acronis) HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [StartFujitsuPointingDeviceUtility] => C:\Program Files (x86)\Fujitsu\PointingDeviceUtility\FJPDAutoSet.exe [85104 2011-02-02] (FUJITSU LIMITED) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-02-01] (Intel Corporation) HKLM-x32\...\Run: [IndicatorUtility] => C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [48752 2010-09-30] (FUJITSU LIMITED) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [7843744 2014-02-04] (Acronis) HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1104616 2013-10-10] (Acronis International GmbH) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [DeskUpdateNotifier] => c:\Fujitsu\Programs\DeskUpdate\DeskUpdateNotifier.exe [101728 2013-12-11] (Fujitsu Technology Solutions) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\Run: [ccleaner] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd) HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1562264 2014-07-25] (Samsung) HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd) HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\MountPoints2: {e8d0cf7c-8ffe-11e2-842b-5026901736a1} - D:\AutoRun.exe HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\MountPoints2: {e8d0cf89-8ffe-11e2-842b-5026901736a1} - D:\AutoRun.exe HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\MountPoints2: {fcef9c32-9777-11e2-8168-00a0c6000000} - D:\AutoRun.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoStart IR.lnk ShortcutTarget: AutoStart IR.lnk -> C:\Program Files (x86)\WinTV\Ir.exe (Hauppauge Computer Works) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UE Music Library-Taskleisten-Tool.lnk ShortcutTarget: UE Music Library-Taskleisten-Tool.lnk -> C:\Program Files (x86)\Logitech\UE Music Library\UEMLTray.exe (Logitech Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinTV Recording Status.lnk ShortcutTarget: WinTV Recording Status.lnk -> C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe (Hauppauge Computer Works, Inc.) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk ShortcutTarget: LaunchCenter.lnk -> C:\Program Files\Fujitsu\LaunchCenter\lcStarter.exe (Fujitsu Technology Solutions) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk ShortcutTarget: LaunchCenter.lnk -> C:\Program Files\Fujitsu\LaunchCenter\lcStarter.exe (Fujitsu Technology Solutions) Startup: C:\Users\Helge Hartz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll () ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll () ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ts.fujitsu.com HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=FTSG&bmod=FTSG SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000 -> DefaultScope {6ECB67EF-A2FD-472D-B996-DF36EB8CA573} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000 -> {6ECB67EF-A2FD-472D-B996-DF36EB8CA573} URL = https://www.google.com/search?q={searchTerms} BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: AusweisApp 1.12.0.0 -> {C9EE92B7-EDD5-4ad9-8029-2EC6818E653A} -> C:\Program Files (x86)\AusweisApp\siqeCardClientIE64.ols (OpenLimit SignCubes AG) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: HKLM-x32 {FC11A119-C2F7-46F4-9E32-937ABA26816E} file:///E:/CDVIEWER/CdViewer.cab Handler-x32: http - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler-x32: x-mem1 - {C3719F83-7EF8-4BA0-89B0-3360C7AFB7CC} - C:\Windows\SysWow64\wowctl2.dll (EzTools Software) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{E084680B-75DA-4035-B0D1-AD567EBD036B}: [NameServer] 10.74.210.210 10.74.210.211 FireFox: ======== FF ProfilePath: C:\Users\Helge Hartz\AppData\Roaming\Mozilla\Firefox\Profiles\xltyg14t.default FF SelectedSearchEngine: Google FF Homepage: Google FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @reiner-sct.com/OWOK,version=2.0.0.4 -> C:\Program Files (x86)\REINER SCT\OWOK\NPAPI-20\nprsct_owok_npapi-2004.dll (REINER Kartengeräte GmbH und Co. KG.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Helge Hartz\AppData\Roaming\Mozilla\Firefox\Profiles\xltyg14t.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Helge Hartz\AppData\Roaming\Mozilla\Firefox\Profiles\xltyg14t.default\searchplugins\google-maps.xml FF SearchPlugin: C:\Users\Helge Hartz\AppData\Roaming\Mozilla\Firefox\Profiles\xltyg14t.default\searchplugins\youtube-ssl-de.xml FF Extension: FRITZ!Box AddOn - C:\Users\Helge Hartz\AppData\Roaming\Mozilla\Firefox\Profiles\xltyg14t.default\Extensions\fb_add_on@avm.de [2013-04-13] FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [{4F3D26C8-9907-48ff-BC74-B8C572D317BF}] - C:\Program Files (x86)\AusweisApp\mozilla\eCardClientExt_FFxx_Win FF Extension: AusweisApp - C:\Program Files (x86)\AusweisApp\mozilla\eCardClientExt_FFxx_Win [2014-06-18] FF HKLM-x32\...\Firefox\Extensions: [{4F0963A3-1658-4fde-9585-23A25CC288BF}] - C:\Program Files (x86)\AusweisApp\mozilla\eCardClientPIn_FFxx_Win FF Extension: AusweisApp - C:\Program Files (x86)\AusweisApp\mozilla\eCardClientPIn_FFxx_Win [2014-06-18] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-08-22] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-08-22] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-08-22] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-08-22] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-08-22] FF Extension: No Name - {4F0963A3-1658-4fde-9585-23A25CC288BF} [Not Found] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-20] (Microsoft Corp.) R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [514128 2012-03-19] (REINER SCT) R2 HauppaugeTVServer; C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [579584 2014-02-14] (Hauppauge Computer Works) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed] S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272688 2012-08-23] () R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed] R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [331776 2010-10-07] (FUJITSU LIMITED) [File not signed] R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63336 2010-06-17] (FUJITSU LIMITED) R2 Sierra Wireless QDL Service; C:\Program Files (x86)\Sierra Wireless Inc\Gobi\QDLService\GobiQDLService.exe [308592 2011-02-16] (Sierra Wireless, Inc.) R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation) R2 TabletServiceISD; C:\Program Files\Tablet\ISD\ISD_Tablet.exe [5640048 2011-02-23] (Wacom Technology, Corp.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5405456 2014-11-12] (TeamViewer GmbH) S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation) R2 TouchServiceISD; C:\Program Files\Tablet\ISD\ISD_TouchService.exe [449904 2011-02-23] (Wacom Technology, Corp.) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3342640 2012-08-23] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 AVMAP_CP_amd64; C:\Windows\System32\Drivers\avmcpx64.sys [22528 2007-11-23] (AvMap) R3 bbcap; C:\Windows\System32\DRIVERS\bbcap.sys [4608 2012-10-10] (Windows (R) Codename Longhorn DDK provider) R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [131112 2010-10-04] (Broadcom Corporation.) S3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [34672 2011-03-29] (REINER SCT) R0 FBIOSDRV; C:\Windows\System32\Drivers\FBIOSDRV.sys [21104 2009-06-24] (FUJITSU LIMITED) R3 Fjbtndrv; C:\Windows\system32\drivers\FjBtnDrv.sys [23040 2009-08-27] (Fujitsu America, Inc.) R0 FJGSDisk; C:\Windows\System32\DRIVERS\FJGSDisk.sys [15208 2012-05-22] (FUJITSU LIMITED) S3 FscEfDmi; C:\Windows\System32\DRIVERS\FscEfDmi.sys [25416 2012-10-31] (Fujitsu Technology Solutions) S3 FscGabi; C:\Windows\System32\DRIVERS\FscGabi.sys [29512 2012-10-31] (Fujitsu Technology Solutions) R3 FUJ02B1; C:\Windows\system32\drivers\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED) R3 FUJ02E3; C:\Windows\system32\drivers\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED) R3 guardian2; C:\Windows\System32\Drivers\oz776x64.sys [85736 2010-08-06] (O2Micro) S3 hcw17bda; C:\Windows\System32\drivers\hcw17b64.sys [78192 2012-10-23] (Hauppauge Computer Works, Inc.) S1 hwinterface; C:\Windows\SysWOW64\Drivers\hwinterface.sys [3026 2013-03-08] (Logix4u) [File not signed] R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-08-22] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-08-22] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-08-22] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-08-22] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-08-22] (Kaspersky Lab ZAO) S3 RDID1009; C:\Windows\System32\Drivers\rdwm1009.sys [81920 2012-05-23] (Roland Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1801216 2010-10-09] () R3 subvgaproduct64; C:\Windows\System32\DRIVERS\subvga64.sys [5120 2014-05-26] (Windows (R) Win 7 DDK provider) S3 swg3kflt00; C:\Windows\System32\DRIVERS\swg3kflt00.sys [34304 2011-02-04] (Sierra Wireless Incorporated) S3 swg3kmbb00; C:\Windows\System32\DRIVERS\swg3kmbb00.sys [424448 2011-02-04] (Sierra Wireless Incorporated) S3 swg3knmea00; C:\Windows\System32\DRIVERS\swg3knmea00.sys [256384 2011-02-04] (Sierra Wireless Incorporated) S3 swg3kser00; C:\Windows\System32\DRIVERS\swg3kser00.sys [256384 2011-02-04] (Sierra Wireless Incorporated) S3 swibus00; C:\Windows\System32\DRIVERS\swibus00.sys [73216 2011-02-04] (Sierra Wireless Inc.) S3 swibusflt00; C:\Windows\System32\DRIVERS\swibusflt00.sys [73216 2011-02-04] (Sierra Wireless Inc.) S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2013-12-17] (Acronis International GmbH) R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [198432 2013-12-17] (Acronis International GmbH) S3 ubloxVcp; C:\Windows\System32\DRIVERS\ubloxVcp.sys [60416 2012-04-18] (u-blox) [File not signed] S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed] R0 vidsflt; C:\Windows\System32\DRIVERS\vidsflt.sys [117024 2013-12-17] (Acronis International GmbH) R3 wacomvthid; C:\Windows\System32\DRIVERS\WacomVTHid.sys [16368 2010-12-02] (Wacom Technology) S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X] S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-25 11:08 - 2014-11-25 11:08 - 00032706 _____ () C:\Users\Helge Hartz\Desktop\FRST.txt 2014-11-25 11:08 - 2014-11-25 11:08 - 00000000 ____D () C:\FRST 2014-11-25 11:07 - 2014-11-25 11:07 - 00000484 _____ () C:\Users\Helge Hartz\Desktop\defogger_disable.log 2014-11-25 11:07 - 2014-11-25 11:07 - 00000000 _____ () C:\Users\Helge Hartz\defogger_reenable 2014-11-25 11:05 - 2014-11-25 10:29 - 00380416 _____ () C:\Users\Helge Hartz\Desktop\Gmer-19357.exe 2014-11-25 11:05 - 2014-11-25 10:28 - 02118144 _____ (Farbar) C:\Users\Helge Hartz\Desktop\FRST64.exe 2014-11-25 11:05 - 2014-11-25 10:26 - 00050477 _____ () C:\Users\Helge Hartz\Desktop\Defogger.exe 2014-11-25 10:29 - 2014-11-25 10:29 - 00000112 _____ () C:\Windows\setupact.log 2014-11-25 10:29 - 2014-11-25 10:29 - 00000000 _____ () C:\Windows\setuperr.log 2014-11-25 07:31 - 2014-11-25 08:54 - 00034511 ____N () C:\Windows\WindowsUpdate.log 2014-11-23 17:31 - 2014-11-23 17:31 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017356_3.tmp 2014-11-23 12:41 - 2014-11-23 12:41 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014620_2.tmp 2014-11-22 22:22 - 2014-11-22 22:22 - 00000000 ____D () C:\Windows\ERUNT 2014-11-22 21:39 - 2014-11-22 21:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ITS HF Propagation 2014-11-22 16:46 - 2014-11-22 16:46 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Assimil_d_se 2014-11-22 10:56 - 2011-05-13 11:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll 2014-11-22 10:56 - 2011-03-25 19:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll 2014-11-21 11:06 - 2014-11-21 11:06 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RouteConverter 2014-11-21 11:06 - 2014-11-21 11:06 - 00000000 ____D () C:\Users\Helge Hartz\.routeconverter 2014-11-21 07:54 - 2014-11-21 07:54 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017452_1.tmp 2014-11-21 07:50 - 2014-11-21 07:50 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014576_2.tmp 2014-11-20 10:18 - 2014-11-20 10:40 - 00000000 ____D () C:\Users\Helge Hartz\Wirtschaft 2014-11-19 17:43 - 2014-11-19 17:43 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014932_2.tmp 2014-11-19 17:08 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-19 17:08 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-19 17:08 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-11-19 17:08 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2014-11-17 08:32 - 2014-11-17 08:32 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011188_1.tmp 2014-11-17 08:31 - 2014-11-17 08:31 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017440_1.tmp 2014-11-17 08:30 - 2014-11-17 08:30 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018864_1.tmp 2014-11-17 07:54 - 2014-11-17 07:54 - 00000000 ____D () C:\Program Files (x86)\CHIRP 2014-11-17 07:44 - 2014-11-17 07:45 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\CHIRP 2014-11-17 07:41 - 2014-11-17 07:41 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CHIRP 2014-11-17 07:41 - 2014-11-17 07:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIRP 2014-11-14 17:28 - 2014-11-14 17:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UE Music Library 2014-11-12 14:37 - 2014-11-12 14:37 - 00000000 __SHD () C:\Users\Helge Hartz\AppData\Local\EmieBrowserModeList 2014-11-12 12:16 - 2014-11-07 20:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-11-12 12:16 - 2014-11-07 20:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-11-12 12:16 - 2014-11-06 05:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-11-12 12:16 - 2014-11-06 05:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-11-12 12:16 - 2014-11-06 05:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-11-12 12:16 - 2014-11-06 04:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-11-12 12:16 - 2014-11-06 04:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-11-12 12:16 - 2014-11-06 04:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-11-12 12:16 - 2014-11-06 04:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-11-12 12:16 - 2014-11-06 04:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-11-12 12:16 - 2014-11-06 04:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-11-12 12:16 - 2014-11-06 04:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-11-12 12:16 - 2014-11-06 04:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-11-12 12:16 - 2014-11-06 04:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-11-12 12:16 - 2014-11-06 04:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-11-12 12:16 - 2014-11-06 04:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-11-12 12:16 - 2014-11-06 04:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-11-12 12:16 - 2014-11-06 04:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-11-12 12:16 - 2014-11-06 04:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-11-12 12:16 - 2014-11-06 04:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-11-12 12:16 - 2014-11-06 04:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-11-12 12:16 - 2014-11-06 04:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-11-12 12:16 - 2014-11-06 04:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-11-12 12:16 - 2014-11-06 04:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-11-12 12:16 - 2014-11-06 04:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-11-12 12:16 - 2014-11-06 04:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-11-12 12:16 - 2014-11-06 04:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-11-12 12:16 - 2014-11-06 04:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-11-12 12:16 - 2014-11-06 04:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-11-12 12:16 - 2014-11-06 04:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-11-12 12:16 - 2014-11-06 04:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-11-12 12:16 - 2014-11-06 04:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-11-12 12:16 - 2014-11-06 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-11-12 12:16 - 2014-11-06 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-11-12 12:16 - 2014-11-06 03:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-11-12 12:16 - 2014-11-06 03:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-11-12 12:16 - 2014-11-06 03:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-11-12 12:16 - 2014-11-06 03:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-11-12 12:16 - 2014-11-06 03:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-11-12 12:16 - 2014-11-06 03:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-11-12 12:16 - 2014-11-06 03:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-11-12 12:16 - 2014-11-06 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-11-12 12:16 - 2014-11-06 03:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-11-12 12:16 - 2014-11-06 03:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-11-12 12:16 - 2014-11-06 03:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-11-12 12:16 - 2014-11-06 03:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-11-12 12:16 - 2014-11-06 03:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-11-12 12:16 - 2014-11-06 03:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-11-12 12:16 - 2014-11-06 03:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-11-12 12:16 - 2014-11-06 03:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-11-12 12:16 - 2014-11-06 03:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-11-12 12:16 - 2014-11-06 03:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-11-12 12:16 - 2014-11-06 02:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-11-12 12:16 - 2014-11-06 02:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-11-12 12:16 - 2014-11-06 02:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-11-12 12:16 - 2014-11-06 02:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-11-12 12:08 - 2014-11-05 18:56 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-11-12 12:08 - 2014-11-05 18:56 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-11-12 12:08 - 2014-11-05 18:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-11-12 12:08 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-12 12:08 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-11-12 12:08 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-12 12:08 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2014-11-12 12:08 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-12 12:08 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-11-12 12:08 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-11-12 12:08 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-12 12:08 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-12 12:08 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-12 12:08 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-11-12 12:08 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-11-12 12:08 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-11-12 12:08 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2014-11-12 12:08 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2014-11-12 12:08 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-12 12:08 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-12 12:08 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-12 12:08 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-11-12 12:08 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-11-12 12:08 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-12 12:08 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2014-11-12 12:08 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2014-11-12 12:08 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2014-11-12 12:08 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-12 12:08 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-11-12 12:08 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-11-12 12:08 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-11-12 12:08 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-11-12 12:08 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-11-12 12:08 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-11-12 12:08 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-11-12 12:08 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2014-11-12 12:08 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-11-12 12:08 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-11-12 12:08 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-11-12 12:08 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-11-12 12:08 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-11-12 12:08 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-11-12 12:08 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-11-12 12:08 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-11-12 12:08 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL 2014-11-11 17:21 - 2014-11-14 18:08 - 00000995 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2014-11-10 17:26 - 2014-11-23 17:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-11-10 10:21 - 2014-11-10 10:21 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012176_3.tmp 2014-11-10 10:19 - 2014-11-10 10:19 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016664_2.tmp 2014-11-10 10:17 - 2014-11-10 10:17 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011316_3.tmp 2014-11-09 12:16 - 2014-11-09 12:16 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018796_2.tmp 2014-11-09 12:13 - 2014-11-09 12:13 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018684_2.tmp 2014-11-09 12:13 - 2014-11-09 12:13 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017920_3.tmp 2014-11-09 12:12 - 2014-11-09 12:12 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018588_4.tmp 2014-11-09 12:12 - 2014-11-09 12:12 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018576_1.tmp 2014-11-09 12:11 - 2014-11-09 12:11 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014564_1.tmp 2014-11-09 12:10 - 2014-11-09 12:10 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018808_2.tmp 2014-11-09 12:07 - 2014-11-09 12:07 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon080901796_1.tmp 2014-11-09 12:04 - 2014-11-09 12:04 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018772_2.tmp 2014-11-09 12:03 - 2014-11-09 12:03 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018704_3.tmp 2014-11-09 12:02 - 2014-11-09 12:02 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017220_2.tmp 2014-11-09 12:02 - 2014-11-09 12:02 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014308_1.tmp 2014-11-09 11:59 - 2014-11-09 11:59 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015744_2.tmp 2014-11-09 11:57 - 2014-11-09 11:57 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019056_2.tmp 2014-11-09 11:57 - 2014-11-09 11:57 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017080_2.tmp 2014-11-09 11:56 - 2014-11-09 11:56 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016308_1.tmp 2014-11-09 11:55 - 2014-11-09 11:55 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015628_1.tmp 2014-11-09 11:35 - 2014-11-09 11:35 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018484_1.tmp 2014-11-09 10:23 - 2014-11-09 10:23 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017420_1.tmp 2014-11-09 10:21 - 2014-11-09 10:21 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012684_2.tmp 2014-11-09 10:19 - 2014-11-09 10:19 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018176_3.tmp 2014-11-09 10:17 - 2014-11-09 10:17 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017900_1.tmp 2014-11-09 10:17 - 2014-11-09 10:17 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016192_1.tmp 2014-11-09 09:57 - 2014-11-09 09:57 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017084_1.tmp 2014-11-04 16:19 - 2014-11-04 16:19 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019964_1.tmp 2014-11-04 16:19 - 2014-11-04 16:19 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014324_1.tmp 2014-11-02 11:09 - 2014-11-02 11:09 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016944_3.tmp 2014-11-02 10:53 - 2014-11-03 09:27 - 00000000 ____D () C:\metar2aprsobj 2014-11-01 16:05 - 2014-11-01 16:05 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019656_1.tmp 2014-11-01 14:34 - 2014-11-01 14:34 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014968_2.tmp 2014-11-01 14:34 - 2014-11-01 14:34 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011988_2.tmp 2014-11-01 14:33 - 2014-11-01 14:33 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017428_3.tmp 2014-10-31 20:51 - 2014-10-31 20:51 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-10-31 19:38 - 2014-10-31 19:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CS-5100 2014-10-31 19:17 - 2014-10-31 19:17 - 10485760 _____ () C:\vgaexte.dat 2014-10-31 11:01 - 2014-10-31 11:00 - 00079360 _____ (Silicon Laboratories) C:\Windows\system32\Drivers\silabser.sys 2014-10-31 11:01 - 2014-10-31 11:00 - 00023552 _____ (Silicon Laboratories) C:\Windows\system32\Drivers\silabenm.sys 2014-10-31 07:43 - 2014-10-31 07:43 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017612_3.tmp 2014-10-31 07:42 - 2014-10-31 07:42 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012348_1.tmp 2014-10-30 14:46 - 2014-10-30 14:46 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018688_2.tmp 2014-10-30 14:45 - 2014-10-30 14:45 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017348_3.tmp 2014-10-30 14:37 - 2014-10-30 14:37 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018768_1.tmp 2014-10-30 14:33 - 2014-10-30 14:33 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019092_2.tmp 2014-10-30 14:33 - 2014-10-30 14:33 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017296_3.tmp 2014-10-30 14:33 - 2014-10-30 14:33 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011424_1.tmp 2014-10-30 14:29 - 2014-10-30 14:29 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016032_2.tmp 2014-10-30 14:19 - 2014-10-30 14:19 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016064_1.tmp 2014-10-30 14:18 - 2014-10-30 14:18 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013648_2.tmp 2014-10-30 14:16 - 2014-10-30 14:16 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014740_1.tmp 2014-10-30 14:16 - 2014-10-30 14:16 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014168_1.tmp 2014-10-30 14:15 - 2014-10-30 14:15 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016988_2.tmp 2014-10-30 14:13 - 2014-10-30 14:13 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014492_2.tmp 2014-10-30 14:12 - 2014-10-30 14:12 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018780_1.tmp 2014-10-30 14:12 - 2014-10-30 14:12 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018688_1.tmp 2014-10-30 14:06 - 2014-10-30 14:06 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016356_1.tmp 2014-10-30 13:58 - 2014-10-30 13:59 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018624_1.tmp 2014-10-30 13:57 - 2014-10-30 13:57 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019080_2.tmp 2014-10-30 13:42 - 2014-10-30 13:42 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018404_2.tmp 2014-10-30 13:41 - 2014-10-30 13:41 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016724_2.tmp 2014-10-30 13:40 - 2014-10-30 13:40 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019092_1.tmp 2014-10-30 13:31 - 2014-10-30 13:31 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018040_1.tmp 2014-10-30 08:34 - 2014-10-30 08:34 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016992_1.tmp 2014-10-30 08:34 - 2014-10-30 08:34 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012344_1.tmp 2014-10-30 08:33 - 2014-10-30 08:33 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018268_3.tmp 2014-10-30 08:28 - 2014-10-30 08:28 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon080901676_1.tmp 2014-10-30 08:26 - 2014-10-30 08:26 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017960_2.tmp 2014-10-30 08:25 - 2014-10-30 08:25 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017648_1.tmp 2014-10-30 08:23 - 2014-10-30 08:23 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016772_2.tmp 2014-10-30 08:13 - 2014-10-30 08:13 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017872_1.tmp 2014-10-30 08:08 - 2014-10-30 08:08 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012524_1.tmp 2014-10-30 08:01 - 2014-10-30 08:01 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013136_1.tmp 2014-10-30 07:59 - 2014-10-30 07:59 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013724_1.tmp 2014-10-30 07:58 - 2014-10-30 07:58 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015900_1.tmp 2014-10-30 07:58 - 2014-10-30 07:58 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012008_1.tmp 2014-10-30 07:43 - 2014-10-30 07:43 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013024_1.tmp 2014-10-30 07:42 - 2014-10-30 07:42 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016920_1.tmp 2014-10-30 07:39 - 2014-10-30 07:39 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon080901964_2.tmp 2014-10-30 07:37 - 2014-10-30 07:37 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015400_1.tmp 2014-10-30 07:34 - 2014-10-30 07:34 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011668_1.tmp 2014-10-28 08:30 - 2014-10-28 08:30 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014800_2.tmp 2014-10-27 14:37 - 2014-10-27 15:39 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\DriverTurbo 2014-10-27 08:05 - 2014-10-27 08:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-10-27 08:05 - 2014-10-27 08:05 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-10-26 14:49 - 2014-10-26 14:49 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012800_2.tmp 2014-10-26 12:17 - 2014-10-26 12:17 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017476_2.tmp 2014-10-26 12:17 - 2014-10-26 12:17 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014588_2.tmp 2014-10-26 12:16 - 2014-10-26 12:16 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018400_1.tmp 2014-10-26 12:15 - 2014-10-26 12:15 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014488_2.tmp 2014-10-26 12:13 - 2014-10-26 12:13 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012464_1.tmp 2014-10-26 12:12 - 2014-10-26 12:12 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016500_1.tmp 2014-10-26 12:09 - 2014-10-26 12:09 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014952_1.tmp 2014-10-26 12:08 - 2014-10-26 12:08 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015984_2.tmp 2014-10-26 12:06 - 2014-10-26 12:06 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018416_1.tmp 2014-10-26 12:06 - 2014-10-26 12:06 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015088_1.tmp 2014-10-26 12:04 - 2014-10-26 12:04 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017888_2.tmp ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-25 11:07 - 2012-05-22 12:21 - 00000000 ____D () C:\Users\Helge Hartz 2014-11-25 11:05 - 2012-05-29 12:04 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Local\CrashDumps 2014-11-25 10:55 - 2012-05-22 14:09 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-11-25 10:27 - 2012-05-18 22:07 - 00000000 ____D () C:\Users\Helge Hartz\Eigene Programme 2014-11-25 10:18 - 2014-10-21 10:12 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-11-25 10:14 - 2012-05-22 16:31 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-25 10:07 - 2011-04-11 18:26 - 00714458 _____ () C:\Windows\system32\perfh007.dat 2014-11-25 10:07 - 2011-04-11 18:26 - 00154510 _____ () C:\Windows\system32\perfc007.dat 2014-11-25 10:07 - 2009-07-14 06:13 - 01649592 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-25 08:14 - 2012-05-22 16:31 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-25 08:12 - 2012-05-22 16:10 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\FileZilla 2014-11-25 07:36 - 2009-07-14 05:45 - 00031536 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-25 07:36 - 2009-07-14 05:45 - 00031536 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-25 07:31 - 2014-09-18 14:10 - 00000000 ___RD () C:\Users\Helge Hartz\Sync 2014-11-25 07:29 - 2014-04-05 21:44 - 00000000 ___RD () C:\Users\Helge Hartz\Dropbox 2014-11-25 07:29 - 2014-04-05 21:43 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Dropbox 2014-11-25 07:29 - 2012-10-11 05:21 - 00000031 _____ () C:\Windows\system32\bbcap.err 2014-11-25 07:29 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-24 18:38 - 2012-05-22 14:35 - 00003958 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896} 2014-11-24 09:39 - 2013-11-22 19:00 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-11-23 09:44 - 2012-05-23 00:22 - 00000000 ____D () C:\Users\Helge Hartz\Administration 2014-11-23 08:44 - 2012-05-22 21:02 - 00000000 ____D () C:\Program Files (x86)\VOAProp 2014-11-22 22:36 - 2012-05-22 17:37 - 00000000 ____D () C:\Users\Helge Hartz\Documents\Registry Files Backup 2014-11-22 21:39 - 2012-05-22 21:38 - 00000000 ____D () C:\itshfbc 2014-11-22 16:44 - 2013-09-30 13:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assimil Verlag 2014-11-22 16:37 - 2013-09-30 13:25 - 00000000 ____D () C:\Program Files (x86)\Assimil 2014-11-22 10:10 - 2013-07-08 12:39 - 00000000 ____D () C:\Users\Public\Documents\QV7_Data 2014-11-20 13:01 - 2012-05-22 19:57 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Skype 2014-11-20 12:29 - 2013-05-12 06:40 - 00000000 ____D () C:\Program Files (x86)\Icom 2014-11-20 12:29 - 2011-05-18 18:44 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-11-19 08:13 - 2014-10-09 19:55 - 00001048 _____ () C:\Users\Helge Hartz\DesktopSARTrack.lnk 2014-11-19 08:13 - 2012-12-21 09:20 - 00000000 ____D () C:\Users\Helge Hartz\Documents\SARTrack 2014-11-18 18:52 - 2012-05-22 20:30 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-11-18 08:38 - 2013-07-10 12:19 - 00001096 _____ () C:\Users\Helge Hartz\Desktop\QuoVadis 7.lnk 2014-11-18 08:38 - 2013-07-08 12:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuoVadis 7 2014-11-18 08:38 - 2013-07-08 12:39 - 00000000 ____D () C:\Program Files (x86)\QuoVadis7 2014-11-17 07:39 - 2012-05-22 10:35 - 00000000 ____D () C:\Users\Helge Hartz\Funk 2014-11-15 21:08 - 2012-09-03 21:33 - 00000000 ____D () C:\Windows\Minidump 2014-11-15 08:41 - 2014-04-05 21:43 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-11-14 20:32 - 2014-07-27 09:30 - 00026630 _____ () C:\Users\Helge Hartz\AppData\Roaming\ekiga.conf 2014-11-13 10:48 - 2012-05-23 23:50 - 00065120 _____ () C:\Users\Helge Hartz\AppData\Roaming\GDIPFONTCACHEV1.DAT 2014-11-13 08:09 - 2012-05-22 16:31 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-11-13 08:09 - 2012-05-22 16:31 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-11-12 20:18 - 2014-10-21 10:12 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-11-12 20:18 - 2013-09-29 05:59 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-11-12 20:18 - 2013-09-29 05:59 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-11-12 18:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-11-12 12:21 - 2009-07-14 05:45 - 00298464 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-12 12:20 - 2014-04-26 11:27 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-11-12 12:18 - 2013-07-11 17:49 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-12 12:16 - 2012-05-23 11:20 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-11 17:22 - 2012-05-22 12:21 - 00065120 _____ () C:\Users\Helge Hartz\AppData\Local\GDIPFONTCACHEV1.DAT 2014-11-10 18:03 - 2012-07-21 09:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-11-10 17:02 - 2012-08-29 15:41 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Canon 2014-11-10 17:02 - 2012-05-22 21:58 - 00000000 ____D () C:\RMS Express 2014-11-10 17:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2014-11-05 14:58 - 2012-11-11 10:00 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client 2014-11-04 21:40 - 2012-06-09 17:47 - 00000000 ____D () C:\Alpha 2014-11-04 18:23 - 2014-03-04 11:05 - 00000000 ____D () C:\Users\Helge Hartz\Documents\Email 2014-11-04 14:30 - 2010-11-21 04:27 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-11-04 07:43 - 2012-05-22 10:45 - 00000000 ____D () C:\Users\Helge Hartz\Defender 2014-11-02 22:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-10-31 20:51 - 2013-10-15 05:51 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-31 20:51 - 2013-10-15 05:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-31 20:51 - 2012-05-22 17:29 - 00000000 ____D () C:\Program Files (x86)\Java 2014-10-31 18:19 - 2014-08-23 09:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZCast 2014-10-31 18:19 - 2014-08-22 19:05 - 00000000 ____D () C:\Program Files (x86)\EZCast 2014-10-31 11:01 - 2013-05-10 11:34 - 00000000 ____D () C:\Users\Helge Hartz\Eigene Treiber 2014-10-27 14:32 - 2014-05-09 14:45 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\mIRC 2014-10-27 14:32 - 2014-05-09 14:45 - 00000000 ____D () C:\Program Files (x86)\mIRC Some content of TEMP: ==================== C:\Users\Helge Hartz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmphfz4hk.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-15 22:07 ==================== End Of Log ============================ |
25.11.2014, 13:22 | #5 |
| Gmer Sorry GMER zu groß (183857 Zeichen) . Es bleibt bei der ZIP. Ansonsten bitte ich um Nachsicht. Bin neu hier, ein guter WIN user, aber kein Programmer. Bin nach Anleitung unter: http://www.trojaner-board.de/69886-a...-beachten.html Punkt für Strich für Komma durchgegangen... Up to the best to my knowledge and understanding... Danke, ich hoffe alles paßt jetzt kein-janer |
26.11.2014, 08:39 | #6 |
/// the machine /// TB-Ausbilder | Telekom Deutschland - Fake Rechnung 13.11.2014 hi, Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
__________________ --> Telekom Deutschland - Fake Rechnung 13.11.2014 |
26.11.2014, 10:27 | #7 |
| Telekom Deutschland - Fake Rechnung 13.11.2014 Gemacht. 1 Threat gefunden ! Sorry wieder größer 120000 Zeichen und hier kann ich keine ZIP anhängen. Ich schneide das File dann einfach irgendwo durch und hoffe das geht klar. Danke derweil schon mal! Code:
ATTFilter 10:14:48.0676 0x23a8 TDSS rootkit removing tool 3.0.0.41 Oct 28 2014 17:58:34 10:14:57.0007 0x23a8 ============================================================ 10:14:57.0007 0x23a8 Current date / time: 2014/11/26 10:14:57.0007 10:14:57.0007 0x23a8 SystemInfo: 10:14:57.0007 0x23a8 10:14:57.0007 0x23a8 OS Version: 6.1.7601 ServicePack: 1.0 10:14:57.0007 0x23a8 Product type: Workstation 10:14:57.0007 0x23a8 ComputerName: NAVIGATOR 10:14:57.0007 0x23a8 UserName: Helge Hartz 10:14:57.0007 0x23a8 Windows directory: C:\Windows 10:14:57.0007 0x23a8 System windows directory: C:\Windows 10:14:57.0007 0x23a8 Running under WOW64 10:14:57.0007 0x23a8 Processor architecture: Intel x64 10:14:57.0007 0x23a8 Number of processors: 4 10:14:57.0007 0x23a8 Page size: 0x1000 10:14:57.0007 0x23a8 Boot type: Normal boot 10:14:57.0007 0x23a8 ============================================================ 10:14:57.0085 0x23a8 KLMD registered as C:\Windows\system32\drivers\28635430.sys 10:14:57.0178 0x23a8 System UUID: {908F5083-4DD9-9CDE-AEE1-959FF461CD9E} 10:14:57.0506 0x23a8 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 10:14:57.0506 0x23a8 ============================================================ 10:14:57.0506 0x23a8 \Device\Harddisk0\DR0: 10:14:57.0506 0x23a8 MBR partitions: 10:14:57.0506 0x23a8 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x420000, BlocksNum 0x37A4A000 10:14:57.0506 0x23a8 ============================================================ 10:14:57.0506 0x23a8 C: <-> \Device\Harddisk0\DR0\Partition1 10:14:57.0506 0x23a8 ============================================================ 10:14:57.0506 0x23a8 Initialize success 10:14:57.0506 0x23a8 ============================================================ 10:15:42.0091 0x179c ============================================================ 10:15:42.0091 0x179c Scan started 10:15:42.0091 0x179c Mode: Manual; SigCheck; TDLFS; 10:15:42.0091 0x179c ============================================================ 10:15:42.0091 0x179c KSN ping started 10:15:44.0758 0x179c KSN ping finished: true 10:15:46.0428 0x179c ================ Scan system memory ======================== 10:15:46.0428 0x179c System memory - ok 10:15:46.0428 0x179c ================ Scan services ============================= 10:15:46.0459 0x179c [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 10:15:46.0506 0x179c 1394ohci - ok 10:15:46.0506 0x179c [ ADC420616C501B45D26C0FD3EF1E54E4, 29FC41D40A35AC5476E2A673CE5B12684E0CFA12A1AEBEEBE5883FBA5CA68B67 ] ACDaemon C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 10:15:46.0521 0x179c ACDaemon - ok 10:15:46.0537 0x179c [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI C:\Windows\system32\drivers\ACPI.sys 10:15:46.0552 0x179c ACPI - ok 10:15:46.0552 0x179c [ 12C5274CD87449A2A37A607CDB321922, 50FA524E66A8FA04037DC954D3AB5383C633898F111A3B7488630B649B897370 ] acpials C:\Windows\system32\DRIVERS\acpials.sys 10:15:46.0568 0x179c acpials - ok 10:15:46.0568 0x179c [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 10:15:46.0568 0x179c AcpiPmi - ok 10:15:46.0599 0x179c [ CD41DFA7A778555B2055E2D388F5CB33, AE149AB7823AE3A97E2826C06968F32A7E50331484203E4581C83E441A1680F9 ] AcrSch2Svc C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe 10:15:46.0630 0x179c AcrSch2Svc - ok 10:15:46.0630 0x179c [ C5679E5186B2FC95BC76A8A9870D5456, 70AC61850B811A0A902532F098AE1D5DF4622455E56C78B89D4ABDBE4A061A48 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 10:15:46.0646 0x179c AdobeARMservice - ok 10:15:46.0662 0x179c [ D51145F6B0CE987850F13A61DAD5E531, 67CB6AB8C42781FA717CBEF81F3C658747E3B7814383056A56EDA99583FDBFD5 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 10:15:46.0677 0x179c AdobeFlashPlayerUpdateSvc - ok 10:15:46.0693 0x179c [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 10:15:46.0708 0x179c adp94xx - ok 10:15:46.0724 0x179c [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci C:\Windows\system32\drivers\adpahci.sys 10:15:46.0740 0x179c adpahci - ok 10:15:46.0740 0x179c [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 10:15:46.0755 0x179c adpu320 - ok 10:15:46.0755 0x179c [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B253C7329949156 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 10:15:46.0833 0x179c AeLookupSvc - ok 10:15:46.0833 0x179c [ ABCF9C80EAACE03021BB7F450EB8993F, 8E38726C423E82954CA85266D6F38B605D010A659420A4EF99D29035A9474BFB ] afcdp C:\Windows\system32\DRIVERS\afcdp.sys 10:15:46.0849 0x179c afcdp - ok 10:15:46.0958 0x179c [ 3B1C11CB7006495F799F8A2AB8B2D530, B7B0C4922A1843BBF8104CDC705C4FEA1F1A760C1CC2BD6BC5E4213A0E4ED9FD ] afcdpsrv C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe 10:15:47.0036 0x179c afcdpsrv - ok 10:15:47.0052 0x179c [ FA886682CFC5D36718D3E436AACF10B9, F80AB4F91AA6B5C7ECCB000D8E1BC2CF776DC3D69B3D9EBC2558C19035A6B3AB ] AFD C:\Windows\system32\drivers\afd.sys 10:15:47.0067 0x179c AFD - ok 10:15:47.0067 0x179c [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440 C:\Windows\system32\drivers\agp440.sys 10:15:47.0083 0x179c agp440 - ok 10:15:47.0083 0x179c [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG C:\Windows\System32\alg.exe 10:15:47.0098 0x179c ALG - ok 10:15:47.0098 0x179c [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide C:\Windows\system32\drivers\aliide.sys 10:15:47.0098 0x179c aliide - ok 10:15:47.0114 0x179c [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide C:\Windows\system32\drivers\amdide.sys 10:15:47.0114 0x179c amdide - ok 10:15:47.0114 0x179c [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 10:15:47.0130 0x179c AmdK8 - ok 10:15:47.0130 0x179c [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 10:15:47.0145 0x179c AmdPPM - ok 10:15:47.0145 0x179c [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata C:\Windows\system32\drivers\amdsata.sys 10:15:47.0161 0x179c amdsata - ok 10:15:47.0161 0x179c [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 10:15:47.0176 0x179c amdsbs - ok 10:15:47.0176 0x179c [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata C:\Windows\system32\drivers\amdxata.sys 10:15:47.0176 0x179c amdxata - ok 10:15:47.0192 0x179c [ 18A8E8A19CD826D31D2E74E740220001, C410291201006158D3D71C1DB91287BE518B444D818E6BEB7A1C5EFB79C3FCD5 ] AMPPAL C:\Windows\system32\DRIVERS\AMPPAL.sys 10:15:47.0208 0x179c AMPPAL - ok 10:15:47.0208 0x179c [ 18A8E8A19CD826D31D2E74E740220001, C410291201006158D3D71C1DB91287BE518B444D818E6BEB7A1C5EFB79C3FCD5 ] AMPPALP C:\Windows\system32\DRIVERS\amppal.sys 10:15:47.0223 0x179c AMPPALP - ok 10:15:47.0239 0x179c [ B4837176B2DBBC8E3D6F31D4853EEAEB, 1860C603D9041612C455B72A29C234BFDC2C58C1CC896045E56D56E6D7A773A8 ] AMPPALR3 C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe 10:15:47.0254 0x179c AMPPALR3 - ok 10:15:47.0254 0x179c [ 80B9412C4DE09147581FC935FB4C97AB, 0C9661F7B5EF7F9D61981790B7AB64E3375BD117962166619D0CC546A2D014D3 ] AppID C:\Windows\system32\drivers\appid.sys 10:15:47.0270 0x179c AppID - ok 10:15:47.0270 0x179c [ F71CA01C24FC3798A717B5A6F682F9AD, 8CF1C209E7BBBAD02D6D087293C0B681CDA3170AF119CA2916C2708D8801E749 ] AppIDSvc C:\Windows\System32\appidsvc.dll 10:15:47.0286 0x179c AppIDSvc - ok 10:15:47.0286 0x179c [ 9D2A2369AB4B08A4905FE72DB104498F, D6FA1705018BABABFA2362E05691A0D6408D14DE7B76129B16D0A1DAD6378E58 ] Appinfo C:\Windows\System32\appinfo.dll 10:15:47.0301 0x179c Appinfo - ok 10:15:47.0301 0x179c [ 650D03E40F93FAE323CB841F80368E5C, F67B97CFDCE2EE9294977725268EFDB0DD724BD16E7ED5BFCA45375AA8EBA5BB ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 10:15:47.0301 0x179c Apple Mobile Device - ok 10:15:47.0317 0x179c [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt C:\Windows\System32\appmgmts.dll 10:15:47.0332 0x179c AppMgmt - ok 10:15:47.0332 0x179c [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc C:\Windows\system32\drivers\arc.sys 10:15:47.0348 0x179c arc - ok 10:15:47.0348 0x179c [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas C:\Windows\system32\drivers\arcsas.sys 10:15:47.0348 0x179c arcsas - ok 10:15:47.0364 0x179c [ 9A262EDD17F8473B91B333D6B031A901, 05DFBD3A7D83FDE1D062EA719ACA9EC48CB7FD42D17DDD88B82E5D25469ADD23 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 10:15:47.0379 0x179c aspnet_state - ok 10:15:47.0379 0x179c [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 10:15:47.0395 0x179c AsyncMac - ok 10:15:47.0410 0x179c [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi C:\Windows\system32\drivers\atapi.sys 10:15:47.0410 0x179c atapi - ok 10:15:47.0473 0x179c [ FA47E65AA0C1DBC6DFEB7E9C6F12A5EA, 26B3908845D2F325AF806B5564510CB93F39206BC20D2D784F4BE426B3250709 ] ATService C:\Program Files\Fingerprint Sensor\ATService.exe 10:15:47.0520 0x179c ATService - ok 10:15:47.0551 0x179c [ 4131DABB573D70FDA332A55F206F6CFF, E6869CAC2B79502C84D8D2BB8566D90F7A24A95B9F44B461D61A00200C9F436B ] ATSwpWDF C:\Windows\system32\Drivers\ATSwpWDF.sys 10:15:47.0566 0x179c ATSwpWDF - ok 10:15:47.0582 0x179c [ DE3E38431B00C2EA247C53675DCF01A0, 8965192096C94203A1F16689DCDA45FE0EDF3A6FB75B70FC378C2008E8E71C9B ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 10:15:47.0598 0x179c AudioEndpointBuilder - ok 10:15:47.0613 0x179c [ DE3E38431B00C2EA247C53675DCF01A0, 8965192096C94203A1F16689DCDA45FE0EDF3A6FB75B70FC378C2008E8E71C9B ] AudioSrv C:\Windows\System32\Audiosrv.dll 10:15:47.0644 0x179c AudioSrv - ok 10:15:47.0644 0x179c [ 74B58B00AF00D6F793DF54307F90ED05, 9A76761F4541D48F973CD9C7096769714341E3F06A80AE449C1DB930E72053DC ] AVMAP_CP_amd64 C:\Windows\system32\Drivers\avmcpx64.sys 10:15:47.0644 0x179c AVMAP_CP_amd64 - ok 10:15:47.0660 0x179c [ 0D2F8F4055903A762AD46204E5A42E86, D3270039E4F066C69D844060388D3F895137C37C0FBE4C106BE1C71AE9DBC17A ] AVP C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe 10:15:47.0676 0x179c AVP - ok 10:15:47.0676 0x179c [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV C:\Windows\System32\AxInstSV.dll 10:15:47.0691 0x179c AxInstSV - ok 10:15:47.0707 0x179c [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 10:15:47.0722 0x179c b06bdrv - ok 10:15:47.0738 0x179c [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 10:15:47.0754 0x179c b57nd60a - ok 10:15:47.0754 0x179c [ 849EA7A204F9F77E7B2ADB8699F7BFC8, EB0334336B16F60BD8552718213159B81251AB6A535AA1DE317FF3CADCEE5057 ] bbcap C:\Windows\system32\DRIVERS\bbcap.sys 10:15:47.0769 0x179c bbcap - ok 10:15:47.0769 0x179c [ 6F29CA4EA1DB1888016EB22ADAE4227D, F86263AF9832382304448D198B0FBAC0F1FFA64D8395226148028A6D703DA171 ] bcbtums C:\Windows\system32\drivers\bcbtums.sys 10:15:47.0769 0x179c bcbtums - ok 10:15:47.0785 0x179c [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC C:\Windows\System32\bdesvc.dll 10:15:47.0800 0x179c BDESVC - ok 10:15:47.0800 0x179c [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep C:\Windows\system32\drivers\Beep.sys 10:15:47.0816 0x179c Beep - ok 10:15:47.0847 0x179c [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE C:\Windows\System32\bfe.dll 10:15:47.0863 0x179c BFE - ok 10:15:47.0863 0x179c [ 65608C44E71D7BA056C9EFCD8A00A7FE, A6B581A8354C7E2902AA1FFDD87C9465EFA2CD75A920CE3098E774292E4825CE ] BingDesktopUpdate C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe 10:15:47.0878 0x179c BingDesktopUpdate - ok 10:15:47.0910 0x179c [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS C:\Windows\System32\qmgr.dll 10:15:47.0941 0x179c BITS - ok 10:15:47.0941 0x179c [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys 10:15:47.0956 0x179c blbdrive - ok 10:15:47.0972 0x179c [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD, 17BFFC5DF609CE3B2F0CAB4BD6C118608C66A3AD86116A47E90B2BB7D8954122 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 10:15:47.0988 0x179c Bonjour Service - ok 10:15:47.0988 0x179c [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 10:15:48.0003 0x179c bowser - ok 10:15:48.0003 0x179c [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 10:15:48.0019 0x179c BrFiltLo - ok 10:15:48.0019 0x179c [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 10:15:48.0034 0x179c BrFiltUp - ok 10:15:48.0034 0x179c [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser C:\Windows\System32\browser.dll 10:15:48.0050 0x179c Browser - ok 10:15:48.0050 0x179c [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid C:\Windows\System32\Drivers\Brserid.sys 10:15:48.0066 0x179c Brserid - ok 10:15:48.0081 0x179c [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 10:15:48.0081 0x179c BrSerWdm - ok 10:15:48.0097 0x179c [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 10:15:48.0097 0x179c BrUsbMdm - ok 10:15:48.0097 0x179c [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 10:15:48.0112 0x179c BrUsbSer - ok 10:15:48.0112 0x179c [ CF98190A94F62E405C8CB255018B2315, E1B2540023C4FE9FD588E4B6AE6347DFA565EB3898F21E5360882BF3E8B5E781 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys 10:15:48.0128 0x179c BthEnum - ok 10:15:48.0128 0x179c [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 10:15:48.0144 0x179c BTHMODEM - ok 10:15:48.0144 0x179c [ 02DD601B708DD0667E1331FA8518E9FF, 7DE6CC4DBB621CD03B01D9CE6CF66EAFE31D39030A391562CD0E278E1D70ADE1 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 10:15:48.0159 0x179c BthPan - ok 10:15:48.0175 0x179c [ 738D0E9272F59EB7A1449C3EC118E6C4, FE3D32C2A5E4DC21376A0F89C0B2EE024ECF1A3FB99213CC9BBC986ADF7AF080 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys 10:15:48.0190 0x179c BTHPORT - ok 10:15:48.0190 0x179c [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv C:\Windows\system32\bthserv.dll 10:15:48.0222 0x179c bthserv - ok 10:15:48.0222 0x179c [ B9D49E4288F56C053B4C12D2F9042948, 5E9C9866FA953526B23AAA05DB23879D3AF55A0909287ED5EB76E010D499B9A4 ] BTHSSecurityMgr C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe 10:15:48.0237 0x179c BTHSSecurityMgr - ok 10:15:48.0237 0x179c [ F188B7394D81010767B6DF3178519A37, 576304E92FD94908F093A6AB5F4D328F25829BE32EC3CA0D29EBFDF5DE83539B ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys 10:15:48.0237 0x179c BTHUSB - ok 10:15:48.0253 0x179c [ 72CC5DCC4E67E7927F94801166CFDCDA, 2D86D3B1F0C96CA41283AE30D0856BA5B3D6155609F5EEA930E73C611DE254DC ] BTWAMPFL C:\Windows\system32\DRIVERS\btwampfl.sys 10:15:48.0268 0x179c BTWAMPFL - ok 10:15:48.0268 0x179c [ F6135859A582A7294BA7A3336E08BAA1, DE30457F91C25950C2713CE3A2AE1F1EFFBB068DD3B0BCC87700E7CBAF73C818 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys 10:15:48.0284 0x179c btwaudio - ok 10:15:48.0284 0x179c [ 3DEF2370E414B4E299673558BA171A51, 5A0923D9F941ABD34EC9BEE0EB62A62F135CBF128061239CC6EA0E6752791636 ] btwavdt C:\Windows\system32\drivers\btwavdt.sys 10:15:48.0300 0x179c btwavdt - ok 10:15:48.0315 0x179c [ 36E3016BEDC45274E00E2943B591AEEF, D569925A87D924AA8079DE89D6F8EF68B64D90997110999258F718714C5D926B ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe 10:15:48.0346 0x179c btwdins - ok 10:15:48.0346 0x179c [ 07096D2BC22CCB6CEA5A532DF0BE8A75, A9B7F2EFFDF1E4EC0A5DC098F0ED2BE44E271844A4F1CBAD2FA1655DE1E03F6E ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys 10:15:48.0346 0x179c btwl2cap - ok 10:15:48.0362 0x179c [ 9937E0E4DFC0030560A6DFE9D3A94B39, 0B9CF1932D4534BD7B1F5D7B7BD5FBF9C8D156838D24ABBDE475E79EEF1150F1 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys 10:15:48.0362 0x179c btwrchid - ok 10:15:48.0362 0x179c [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 10:15:48.0393 0x179c cdfs - ok 10:15:48.0409 0x179c [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 10:15:48.0409 0x179c cdrom - ok 10:15:48.0424 0x179c [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc C:\Windows\System32\certprop.dll 10:15:48.0440 0x179c CertPropSvc - ok 10:15:48.0456 0x179c [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass C:\Windows\system32\drivers\circlass.sys 10:15:48.0456 0x179c circlass - ok 10:15:48.0487 0x179c [ ED81E81752CA817AFA740C14AD05BC6C, 9E4B04D4604B96866B3ED18433914BF7ECF3F746CDB34ED856FFC418AAB3C04F ] cjpcsc C:\Windows\SysWOW64\cjpcsc.exe 10:15:48.0502 0x179c cjpcsc - ok 10:15:48.0518 0x179c [ 06E1F5228399FC49A8D026DA38DB6784, 5554071E5C55FC7EF3C7C95F0BC565509C3F0C03E0814C98376932A9D1C32AA6 ] cjusb C:\Windows\system32\DRIVERS\cjusb.sys 10:15:48.0518 0x179c cjusb - ok 10:15:48.0534 0x179c [ FE1EC06F2253F691FE36217C592A0206, B9F122DB5E665ECDF29A5CB8BB6B531236F31A54A95769D6C5C1924C87FE70CE ] CLFS C:\Windows\system32\CLFS.sys 10:15:48.0549 0x179c CLFS - ok 10:15:48.0549 0x179c [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 10:15:48.0565 0x179c clr_optimization_v2.0.50727_32 - ok 10:15:48.0565 0x179c [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 10:15:48.0565 0x179c clr_optimization_v2.0.50727_64 - ok 10:15:48.0580 0x179c [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 10:15:48.0596 0x179c clr_optimization_v4.0.30319_32 - ok 10:15:48.0596 0x179c [ 4AEDAB50F83580D0B4D6CF78191F92AA, D113C47013B018B45161911B96E93AF96A2F3B34FA47061BF6E7A71FBA03194A ] clr_optimization_v4.0.30319_64 C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 10:15:48.0612 0x179c clr_optimization_v4.0.30319_64 - ok 10:15:48.0612 0x179c [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt C:\Windows\system32\drivers\CmBatt.sys 10:15:48.0627 0x179c CmBatt - ok 10:15:48.0627 0x179c [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide C:\Windows\system32\drivers\cmdide.sys 10:15:48.0627 0x179c cmdide - ok 10:15:48.0643 0x179c [ EBF28856F69CF094A902F884CF989706, AD6C9F0BC20AA49EEE5478DA0F856F0EA2B414B63208C5FFB03C9D7F5B59765F ] CNG C:\Windows\system32\Drivers\cng.sys 10:15:48.0658 0x179c CNG - ok 10:15:48.0658 0x179c [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt C:\Windows\system32\drivers\compbatt.sys 10:15:48.0674 0x179c Compbatt - ok 10:15:48.0674 0x179c [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 10:15:48.0690 0x179c CompositeBus - ok 10:15:48.0690 0x179c COMSysApp - ok 10:15:48.0690 0x179c [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 10:15:48.0690 0x179c crcdisk - ok 10:15:48.0705 0x179c [ 19D511CC455C19DE1ADF60E6C39C85B6, 2A05DD5EF3D0BEC2C9F4EA186E0E2D0F7BE0BF6A473D51194B09D33773AC7FAA ] CryptSvc C:\Windows\system32\cryptsvc.dll 10:15:48.0721 0x179c CryptSvc - ok 10:15:48.0736 0x179c [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC C:\Windows\system32\drivers\csc.sys 10:15:48.0752 0x179c CSC - ok 10:15:48.0768 0x179c [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService C:\Windows\System32\cscsvc.dll 10:15:48.0783 0x179c CscService - ok 10:15:48.0799 0x179c [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch C:\Windows\system32\rpcss.dll 10:15:48.0830 0x179c DcomLaunch - ok 10:15:48.0846 0x179c [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc C:\Windows\System32\defragsvc.dll 10:15:48.0877 0x179c defragsvc - ok 10:15:48.0877 0x179c [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC C:\Windows\system32\Drivers\dfsc.sys 10:15:48.0908 0x179c DfsC - ok 10:15:48.0908 0x179c [ 30710AEFCE721CEEE0F35EB6A01C263C, FB062EC86474D38BBC38E11E2618A9505001C287430B495C482977BBE58017C8 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys 10:15:48.0924 0x179c dg_ssudbus - ok 10:15:48.0924 0x179c [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp C:\Windows\system32\dhcpcore.dll 10:15:48.0939 0x179c Dhcp - ok 10:15:48.0939 0x179c [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache C:\Windows\system32\drivers\discache.sys 10:15:48.0970 0x179c discache - ok 10:15:48.0970 0x179c [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk C:\Windows\system32\drivers\disk.sys 10:15:48.0986 0x179c Disk - ok 10:15:48.0986 0x179c [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc C:\Windows\system32\drivers\dmvsc.sys 10:15:48.0986 0x179c dmvsc - ok 10:15:49.0002 0x179c [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache C:\Windows\System32\dnsrslvr.dll 10:15:49.0017 0x179c Dnscache - ok 10:15:49.0017 0x179c [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc C:\Windows\System32\dot3svc.dll 10:15:49.0048 0x179c dot3svc - ok 10:15:49.0048 0x179c [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS C:\Windows\system32\dps.dll 10:15:49.0080 0x179c DPS - ok 10:15:49.0080 0x179c [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 10:15:49.0095 0x179c drmkaud - ok 10:15:49.0111 0x179c [ 87CE5C8965E101CCCED1F4675557E868, 077D98F0F130B2FC710208BA34016EF2B2506EE2BD71740B228145E34A3046F1 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 10:15:49.0142 0x179c DXGKrnl - ok 10:15:49.0158 0x179c [ DC1776D086AA9733B1929A3D979D9FDD, C7EEF160C615948CCCDE3B56C43F8A1E348B4E1212E0DDDB8A9EC2EC14FF73EE ] e1cexpress C:\Windows\system32\DRIVERS\e1c62x64.sys 10:15:49.0158 0x179c e1cexpress - ok 10:15:49.0173 0x179c [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost C:\Windows\System32\eapsvc.dll 10:15:49.0189 0x179c EapHost - ok 10:15:49.0298 0x179c [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv C:\Windows\system32\drivers\evbda.sys 10:15:49.0360 0x179c ebdrv - ok 10:15:49.0376 0x179c [ 204F3F58212B3E422C90BD9691A2DF28, D748A8CEE4D59B4248C9B1ACA5155D0FF6635A29564B4391B7FAC6261F93FE99 ] EFS C:\Windows\System32\lsass.exe 10:15:49.0376 0x179c EFS - ok 10:15:49.0407 0x179c [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 10:15:49.0423 0x179c ehRecvr - ok 10:15:49.0423 0x179c [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched C:\Windows\ehome\ehsched.exe 10:15:49.0438 0x179c ehSched - ok 10:15:49.0454 0x179c [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor C:\Windows\system32\drivers\elxstor.sys 10:15:49.0470 0x179c elxstor - ok 10:15:49.0470 0x179c [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev C:\Windows\system32\drivers\errdev.sys 10:15:49.0485 0x179c ErrDev - ok 10:15:49.0501 0x179c [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem C:\Windows\system32\es.dll 10:15:49.0532 0x179c EventSystem - ok 10:15:49.0563 0x179c [ 770B15B8261A444B817F296EC27CE71E, 528E2ADBD22D72E9BD5F37504073AA1EBFFD037B6D4C3AABB4769DE9F1A10A55 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe 10:15:49.0579 0x179c EvtEng - ok 10:15:49.0579 0x179c ew_hwusbdev - ok 10:15:49.0594 0x179c ew_usbenumfilter - ok 10:15:49.0610 0x179c [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat C:\Windows\system32\drivers\exfat.sys 10:15:49.0626 0x179c exfat - ok 10:15:49.0641 0x179c [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat C:\Windows\system32\drivers\fastfat.sys 10:15:49.0672 0x2180 Object required for P2P: [ D51145F6B0CE987850F13A61DAD5E531 ] AdobeFlashPlayerUpdateSvc 10:15:49.0672 0x179c fastfat - ok 10:15:49.0688 0x179c [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax C:\Windows\system32\fxssvc.exe 10:15:49.0719 0x179c Fax - ok 10:15:49.0719 0x179c [ 9955BF48FD2FA8D481848CD3024EDD0B, 327E290141625C3E810D741CA106651C5A8EEF5DFA6477ACC5843D9D80DFC6FA ] FBIOSDRV C:\Windows\system32\Drivers\FBIOSDRV.sys 10:15:49.0719 0x179c FBIOSDRV - ok 10:15:49.0735 0x179c [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc C:\Windows\system32\drivers\fdc.sys 10:15:49.0735 0x179c fdc - ok 10:15:49.0735 0x179c [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost C:\Windows\system32\fdPHost.dll 10:15:49.0766 0x179c fdPHost - ok 10:15:49.0766 0x179c [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub C:\Windows\system32\fdrespub.dll 10:15:49.0797 0x179c FDResPub - ok 10:15:49.0797 0x179c [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 10:15:49.0797 0x179c FileInfo - ok 10:15:49.0813 0x179c [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 10:15:49.0828 0x179c Filetrace - ok 10:15:49.0828 0x179c [ 5E5203A036F5477B302EF15494D8A9D4, A70E8BAC9CC0DFAF3891F7A85AD24682B2654DE509A51C37FD480F0FD573B29D ] Fjbtndrv C:\Windows\system32\drivers\FjBtnDrv.sys 10:15:49.0844 0x179c Fjbtndrv - ok 10:15:49.0844 0x179c [ 2FA407147F273D7852FEB7BDA71E54E1, 068829EC42D652D75AD2183105865943FADD9DF41DA6FD5F38C5CD9A4AB4E058 ] FJGSDisk C:\Windows\system32\DRIVERS\FJGSDisk.sys 10:15:49.0844 0x179c FJGSDisk - ok 10:15:49.0860 0x179c [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 10:15:49.0860 0x179c flpydisk - ok 10:15:49.0875 0x179c [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 10:15:49.0875 0x179c FltMgr - ok 10:15:49.0891 0x179c [ FDD776FAC4159A2983940D1E411FE9F3, 3B147B4D3C5CC67117D65152FA8BD3A603728C92B023AE45CD166E6FF3F474C5 ] fltsrv C:\Windows\system32\DRIVERS\fltsrv.sys 10:15:49.0891 0x179c fltsrv - ok 10:15:49.0922 0x179c [ C4C183E6551084039EC862DA1C945E3D, 0874A2ACDD24D64965AA9A76E9C818E216880AE4C9A2E07ED932EE404585CEE6 ] FontCache C:\Windows\system32\FntCache.dll 10:15:49.0953 0x179c FontCache - ok 10:15:49.0969 0x179c [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 10:15:49.0969 0x179c FontCache3.0.0.0 - ok 10:15:49.0969 0x179c [ B9E19421B9CA13C2929AAFFFF13324D1, 48FACDFCE10AE41DF92AA9BB070C96114672685BD50F6CF823A78E8224ABC4E5 ] FscEfDmi C:\Windows\system32\DRIVERS\FscEfDmi.sys 10:15:49.0984 0x179c FscEfDmi - ok 10:15:49.0984 0x179c [ 54BD9A8DF2330E41EB7FC13A3894A161, 64587F11DE7FE503E264F45D51717CA229BA874A9DCD7A526A9625367FA96DE8 ] FscGabi C:\Windows\system32\DRIVERS\FscGabi.sys 10:15:49.0984 0x179c FscGabi - ok 10:15:50.0000 0x179c [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 10:15:50.0000 0x179c FsDepends - ok 10:15:50.0000 0x179c [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 10:15:50.0016 0x179c Fs_Rec - ok 10:15:50.0016 0x179c [ 35FD2BB5131714E657B7AB3A78642854, C24AC6D4E0E76B39625FC9051E092439642C3A10122F712C11A562860703F27A ] FTDIBUS C:\Windows\system32\drivers\ftdibus.sys 10:15:50.0016 0x179c FTDIBUS - ok 10:15:50.0031 0x179c [ 196C9BDDBEF9B6D0973F398BEF5B2EEE, D4F9C5CED1E33446B45BD2AFFA6E716B4332AF8716477A80437220AC20C6DFE0 ] FTSER2K C:\Windows\system32\drivers\ftser2k.sys 10:15:50.0031 0x179c FTSER2K - ok 10:15:50.0031 0x179c [ BA0C1FFDA496D8BCBCAC63F8D98D20E3, 28D37F07A58D5AFA48A18BB4A780A36A3F8D49E94DE8CA5071071CCF16C0C090 ] FUJ02B1 C:\Windows\system32\drivers\FUJ02B1.sys 10:15:50.0047 0x179c FUJ02B1 - ok 10:15:50.0047 0x179c [ 7135030CBF87D724B6037BB023923730, 1F6D9A7D7033226507DEDD53CB686C0F3CDC15FD7E77DBC5263256E8EB541E4E ] FUJ02E3 C:\Windows\system32\drivers\FUJ02E3.sys 10:15:50.0062 0x179c FUJ02E3 - ok 10:15:50.0062 0x179c [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 10:15:50.0078 0x179c fvevol - ok 10:15:50.0078 0x179c [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 10:15:50.0094 0x179c gagp30kx - ok 10:15:50.0094 0x179c [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 10:15:50.0094 0x179c GEARAspiWDM - ok 10:15:50.0125 0x179c [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc C:\Windows\System32\gpsvc.dll 10:15:50.0156 0x179c gpsvc - ok 10:15:50.0156 0x179c [ FB9AD1E93E445AB84594931B8552501A, 613ECBADF123727F58398EB1D94EB746D4A3F0DCB75A2365D9264A9710B47F29 ] guardian2 C:\Windows\system32\Drivers\oz776x64.sys 10:15:50.0172 0x179c guardian2 - ok 10:15:50.0172 0x179c [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 10:15:50.0172 0x179c gupdate - ok 10:15:50.0187 0x179c [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 10:15:50.0187 0x179c gupdatem - ok 10:15:50.0203 0x179c [ 2EC3AFFE3AC7776AE9DA4028D370593F, AF46A23F278F0316B734462D8E4510AA6B5B3A0B630CA6566FBBCD535ECE2148 ] HauppaugeTVServer C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe 10:15:50.0218 0x179c HauppaugeTVServer - detected UnsignedFile.Multi.Generic ( 1 ) 10:15:52.0168 0x2180 Object send P2P result: true 10:15:52.0636 0x179c Detect skipped due to KSN trusted 10:15:52.0636 0x179c HauppaugeTVServer - ok 10:15:52.0636 0x179c [ 7E103E98BAEF11E83062756E8BB5A1A4, F3F1F330C02FFE59BBAC26DD7F4F4CD835780B7FD21F5E9EE93AFA924E32E012 ] hcw17bda C:\Windows\system32\drivers\hcw17b64.sys 10:15:52.0652 0x179c hcw17bda - ok 10:15:52.0668 0x179c [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 10:15:52.0683 0x179c hcw85cir - ok 10:15:52.0699 0x179c [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 10:15:52.0714 0x179c HdAudAddService - ok 10:15:52.0714 0x179c [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 10:15:52.0730 0x179c HDAudBus - ok 10:15:52.0730 0x179c [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 10:15:52.0746 0x179c HidBatt - ok 10:15:52.0746 0x179c [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth C:\Windows\system32\drivers\hidbth.sys 10:15:52.0761 0x179c HidBth - ok 10:15:52.0761 0x179c [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr C:\Windows\system32\drivers\hidir.sys 10:15:52.0777 0x179c HidIr - ok 10:15:52.0777 0x179c [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv C:\Windows\system32\hidserv.dll 10:15:52.0792 0x179c hidserv - ok 10:15:52.0808 0x179c [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 10:15:52.0808 0x179c HidUsb - ok 10:15:52.0824 0x179c [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc C:\Windows\system32\kmsvc.dll 10:15:52.0839 0x179c hkmsvc - ok 10:15:52.0855 0x179c [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll 10:15:52.0870 0x179c HomeGroupListener - ok 10:15:52.0870 0x179c [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 10:15:52.0886 0x179c HomeGroupProvider - ok 10:15:52.0886 0x179c [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 10:15:52.0902 0x179c HpSAMD - ok 10:15:52.0917 0x179c [ 0EA7DE1ACB728DD5A369FD742D6EEE28, 21C489412EB33A12B22290EB701C19BA57006E8702E76F730954F0784DDE9779 ] HTTP C:\Windows\system32\drivers\HTTP.sys 10:15:52.0948 0x179c HTTP - ok 10:15:52.0948 0x179c huawei_cdcacm - ok 10:15:52.0948 0x179c huawei_enumerator - ok 10:15:52.0964 0x179c huawei_ext_ctrl - ok 10:15:52.0964 0x179c huawei_wwanecm - ok 10:15:52.0964 0x179c hwinterface - ok 10:15:52.0964 0x179c [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 10:15:52.0980 0x179c hwpolicy - ok 10:15:52.0980 0x179c [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 10:15:52.0995 0x179c i8042prt - ok 10:15:53.0011 0x179c [ 53CC5BF8B5A219119953C7ABB19A7705, F342A9732978D893729EA2591CB72E5F5BD1B3E6C9E4DBFFE54EC866E534A8C0 ] iaStor C:\Windows\system32\drivers\iaStor.sys 10:15:53.0026 0x179c iaStor - ok 10:15:53.0026 0x179c [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 10:15:53.0042 0x179c iaStorV - ok 10:15:53.0058 0x179c [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe 10:15:53.0058 0x179c IDriverT - detected UnsignedFile.Multi.Generic ( 1 ) 10:15:55.0444 0x179c Detect skipped due to KSN trusted 10:15:55.0460 0x179c IDriverT - ok 10:15:55.0507 0x179c [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 10:15:55.0522 0x179c idsvc - ok 10:15:55.0538 0x179c IEEtwCollectorService - ok 10:15:55.0834 0x179c [ 6383899C5F964D71B0F96B81FBE59BB8, 780B2B5945CF266CD0807B6F91177A558EC1E568F9D7D850C172A137414394E6 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 10:15:56.0068 0x179c igfx - ok 10:15:56.0084 0x179c [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp C:\Windows\system32\drivers\iirsp.sys 10:15:56.0084 0x179c iirsp - ok 10:15:56.0100 0x179c [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT C:\Windows\System32\ikeext.dll 10:15:56.0131 0x179c IKEEXT - ok 10:15:56.0131 0x179c [ CADDF0927DAC63EDAE48F5C35A61D87D, C46006461311B1563C1D149B9D60B202F30147265B9D93069B084D03A09D2BEC ] intaud_WaveExtensible C:\Windows\system32\drivers\intelaud.sys 10:15:56.0131 0x179c intaud_WaveExtensible - ok 10:15:56.0209 0x179c [ D492D3B5A8DDDE1D6621A8C53855EABF, 22505264F9645B07920B468FA58E7F0D27492CFD04C12FD26C14305D93020C6B ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 10:15:56.0256 0x179c IntcAzAudAddService - ok 10:15:56.0271 0x179c [ FC727061C0F47C8059E88E05D5C8E381, C7A3782F5D86C7FDE57AA1F2EE81638C5FC3072ACC6E572BA2EC7B3CFF389800 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys 10:15:56.0287 0x179c IntcDAud - ok 10:15:56.0287 0x179c [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide C:\Windows\system32\drivers\intelide.sys 10:15:56.0287 0x179c intelide - ok 10:15:56.0302 0x179c [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 10:15:56.0302 0x179c intelppm - ok 10:15:56.0302 0x179c [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum C:\Windows\system32\ipbusenum.dll 10:15:56.0334 0x179c IPBusEnum - ok 10:15:56.0334 0x179c [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 10:15:56.0365 0x179c IpFilterDriver - ok 10:15:56.0380 0x179c [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 10:15:56.0396 0x179c iphlpsvc - ok 10:15:56.0396 0x179c [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 10:15:56.0412 0x179c IPMIDRV - ok 10:15:56.0412 0x179c [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT C:\Windows\system32\drivers\ipnat.sys 10:15:56.0443 0x179c IPNAT - ok 10:15:56.0458 0x179c [ 7FAE5B6CDB18B0B2E81F32869F595022, D873A7EE94749E1700E8F6B8BB7B485AE1B0B83388D63BE06335720498D4794F ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 10:15:56.0474 0x179c iPod Service - ok 10:15:56.0474 0x179c [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM C:\Windows\system32\drivers\irenum.sys 10:15:56.0490 0x179c IRENUM - ok 10:15:56.0490 0x179c [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp C:\Windows\system32\drivers\isapnp.sys 10:15:56.0490 0x179c isapnp - ok 10:15:56.0505 0x179c [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 10:15:56.0521 0x179c iScsiPrt - ok 10:15:56.0521 0x179c [ 716F66336F10885D935B08174DC54242, 1992708956A2A45A8870CFCB532F3ABF24B1143B75EF32AB1F59D5D86E65F493 ] iwdbus C:\Windows\system32\DRIVERS\iwdbus.sys 10:15:56.0521 0x179c iwdbus - ok 10:15:56.0536 0x179c [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 10:15:56.0536 0x179c kbdclass - ok 10:15:56.0536 0x179c [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 10:15:56.0552 0x179c kbdhid - ok 10:15:56.0552 0x179c [ 204F3F58212B3E422C90BD9691A2DF28, D748A8CEE4D59B4248C9B1ACA5155D0FF6635A29564B4391B7FAC6261F93FE99 ] KeyIso C:\Windows\system32\lsass.exe 10:15:56.0552 0x179c KeyIso - ok 10:15:56.0568 0x179c [ 795EC29BA21F1D948FD6FD740C00B599, 780900717A812C5DB78C67057010BD62DF2C756C087599A6F8C67CB4EFA7518C ] kl1 C:\Windows\system32\DRIVERS\kl1.sys 10:15:56.0583 0x179c kl1 - ok 10:15:56.0583 0x179c [ D0C3AEF67932D2A80736FBCB956C017D, 166C2FD5F1B6FFE7A71CD821DFDD02B68D25CBF0D44BD6F2522C65CF1DEB363C ] klflt C:\Windows\system32\DRIVERS\klflt.sys 10:15:56.0599 0x179c klflt - ok 10:15:56.0614 0x179c [ 41DF293A7F0418F5DDED9F0297DC68F3, 25DE4BB7F2D915FCF576ABD46EEDC5574B694A2D1E5CB7AB565792C7BB57C76B ] KLIF C:\Windows\system32\DRIVERS\klif.sys 10:15:56.0630 0x179c KLIF - ok 10:15:56.0630 0x179c [ 31B69BFF28348503E4BD10C2A4F66D05, 891318C2DDF85E43DFCEE73717AEFCE79BC3DCD83FCD58E6F794AB6BF1739688 ] KLIM6 C:\Windows\system32\DRIVERS\klim6.sys 10:15:56.0630 0x179c KLIM6 - ok 10:15:56.0646 0x179c [ 8DA5BC75C3E8A995335642F26CAEA54B, 3995AAB499A37077AA4FB372E75CD9259BA3EA7020B961CF482AC948D2D47AB4 ] klkbdflt C:\Windows\system32\DRIVERS\klkbdflt.sys 10:15:56.0646 0x179c klkbdflt - ok 10:15:56.0646 0x179c [ 72CF64FBF38CD681FA7F37176047E967, BE5683C119DCEF7E678EE477D6CADF873E32D42372A253B7E86B8C335DF28E1C ] klmouflt C:\Windows\system32\DRIVERS\klmouflt.sys 10:15:56.0661 0x179c klmouflt - ok 10:15:56.0661 0x179c [ 8C0EC95AD65A0DE3D6C040591D02BF02, 272FB83752B73684FA7BDBE256FAFD56138E4755AAEFED9E7EF8F0E3D0ACFAF2 ] klpd C:\Windows\system32\DRIVERS\klpd.sys 10:15:56.0661 0x179c klpd - ok 10:15:56.0677 0x179c [ 4828B3D2BC89B05E07101C6E60CE0A6A, C2D40EA03A526286AEDF27DE80CB0576EB59EB7581C9E9ECFCB867349593D7CE ] kltdi C:\Windows\system32\DRIVERS\kltdi.sys 10:15:56.0677 0x179c kltdi - ok 10:15:56.0677 0x179c [ 91BC1C5B00275A4D7FD669EFF0DDEB2A, B745518E1916441A49565478EA77C8DBC784E7B4D9DAD1EA1F648ED1727F413D ] kneps C:\Windows\system32\DRIVERS\kneps.sys 10:15:56.0692 0x179c kneps - ok 10:15:56.0692 0x179c [ 353009DEDF918B2A51414F330CF72DEC, BF157D6E329F26E02FA16271B751B421396040DBB1D7BF9B2E0A21BC569672E2 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 10:15:56.0708 0x179c KSecDD - ok 10:15:56.0708 0x179c [ 41774FF331F609EF442B7398EE6202B1, AD67DA06A74895C384F4A1F1CF47050DAEE9C6CE8AD12F1A116FC977B6C3A864 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 10:15:56.0724 0x179c KSecPkg - ok 10:15:56.0724 0x179c [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 10:15:56.0739 0x179c ksthunk - ok 10:15:56.0755 0x179c [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm C:\Windows\system32\msdtckrm.dll 10:15:56.0786 0x179c KtmRm - ok 10:15:56.0802 0x179c [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer C:\Windows\system32\srvsvc.dll 10:15:56.0833 0x179c LanmanServer - ok 10:15:56.0833 0x179c [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 10:15:56.0848 0x179c LanmanWorkstation - ok 10:15:56.0864 0x179c [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 10:15:56.0880 0x179c lltdio - ok 10:15:56.0895 0x179c [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc C:\Windows\System32\lltdsvc.dll 10:15:56.0926 0x179c lltdsvc - ok 10:15:56.0926 0x179c [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts C:\Windows\System32\lmhsvc.dll 10:15:56.0942 0x179c lmhosts - ok 10:15:56.0958 0x179c [ A63B719F4F8657F3FCD84436D09378C8, 770B979204D8A34463880D53BD51CB93B9CC2B37A04B56D2098E879A4922D721 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 10:15:56.0973 0x179c LMS - ok 10:15:56.0973 0x179c [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 10:15:56.0973 0x179c LSI_FC - ok 10:15:56.0989 0x179c [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 10:15:56.0989 0x179c LSI_SAS - ok 10:15:57.0004 0x179c [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 10:15:57.0004 0x179c LSI_SAS2 - ok 10:15:57.0004 0x179c [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 10:15:57.0020 0x179c LSI_SCSI - ok 10:15:57.0020 0x179c [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv C:\Windows\system32\drivers\luafv.sys 10:15:57.0051 0x179c luafv - ok 10:15:57.0051 0x179c [ 0C85B2B6FB74B36A251792D45E0EF860, 2E04204560C1159ABC25F273B0B7F81FDF9BA5E88C17929FD924C4E945DE5020 ] LVRS64 C:\Windows\system32\DRIVERS\lvrs64.sys 10:15:57.0067 0x179c LVRS64 - ok 10:15:57.0207 0x179c [ FF3A488924B0032B1A9CA6948C1FA9E8, 6F05852B75498210926F5CDF49D2A6DD97C39CD93D32E3200D7240AADA3E7BEE ] LVUVC64 C:\Windows\system32\DRIVERS\lvuvc64.sys 10:15:57.0301 0x179c LVUVC64 - ok 10:15:57.0316 0x179c [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 10:15:57.0316 0x179c Mcx2Svc - ok 10:15:57.0316 0x179c [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas C:\Windows\system32\drivers\megasas.sys 10:15:57.0332 0x179c megasas - ok 10:15:57.0332 0x179c [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 10:15:57.0348 0x179c MegaSR - ok 10:15:57.0348 0x179c [ A6518DCC42F7A6E999BB3BEA8FD87567, 8A9AE992F93F37E0723761EA271A7E1AA8172702C471041A17324474FC96B9BC ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 10:15:57.0363 0x179c MEIx64 - ok 10:15:57.0363 0x179c [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS C:\Windows\system32\mmcss.dll 10:15:57.0394 0x179c MMCSS - ok 10:15:57.0394 0x179c [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem C:\Windows\system32\drivers\modem.sys 10:15:57.0410 0x179c Modem - ok 10:15:57.0410 0x179c [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 10:15:57.0426 0x179c monitor - ok 10:15:57.0426 0x179c [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 10:15:57.0441 0x179c mouclass - ok 10:15:57.0441 0x179c [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 10:15:57.0457 0x179c mouhid - ok 10:15:57.0457 0x179c [ 32E7A3D591D671A6DF2DB515A5CBE0FA, 47CED0B9067AE8BF5EEF60B17ADEE5906BEDCC56E4CB460B7BFBC12BB9A69E63 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 10:15:57.0457 0x179c mountmgr - ok 10:15:57.0472 0x179c [ DEA022193DF8C88F6E2B3E33D148A5DB, 97DFC47DB83E04A975A1969AA120385463FCAF4E1A9984FD3220442D7026B45A ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 10:15:57.0472 0x179c MozillaMaintenance - ok 10:15:57.0488 0x179c [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio C:\Windows\system32\drivers\mpio.sys 10:15:57.0488 0x179c mpio - ok |
26.11.2014, 10:27 | #8 |
| Telekom Deutschland - Fake Rechnung 13.11.2014Code:
ATTFilter 10:15:57.0504 0x179c [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 10:15:57.0519 0x179c mpsdrv - ok 10:15:57.0535 0x179c [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc C:\Windows\system32\mpssvc.dll 10:15:57.0582 0x179c MpsSvc - ok 10:15:57.0582 0x179c [ 1A4F75E63C9FB84B85DFFC6B63FD5404, 01AFA6DBB4CDE55FE4EA05BBE8F753A4266F8D072EA1EE01DB79F5126780C21F ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 10:15:57.0597 0x179c MRxDAV - ok 10:15:57.0597 0x179c [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE35020785387F307E231FBE4 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 10:15:57.0613 0x179c mrxsmb - ok 10:15:57.0628 0x179c [ D711B3C1D5F42C0C2415687BE09FC163, 9B3013AC60BD2D0FF52086658BA5FF486ADE15954A552D7DD590580E8BAE3EFF ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 10:15:57.0644 0x179c mrxsmb10 - ok 10:15:57.0644 0x179c [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B7720888F67B9644CC ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 10:15:57.0644 0x179c mrxsmb20 - ok 10:15:57.0660 0x179c [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci C:\Windows\system32\drivers\msahci.sys 10:15:57.0660 0x179c msahci - ok 10:15:57.0675 0x179c [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm C:\Windows\system32\drivers\msdsm.sys 10:15:57.0675 0x179c msdsm - ok 10:15:57.0675 0x179c [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC C:\Windows\System32\msdtc.exe 10:15:57.0691 0x179c MSDTC - ok 10:15:57.0691 0x179c [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs C:\Windows\system32\drivers\Msfs.sys 10:15:57.0722 0x179c Msfs - ok 10:15:57.0722 0x179c [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 10:15:57.0738 0x179c mshidkmdf - ok 10:15:57.0753 0x179c [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 10:15:57.0753 0x179c msisadrv - ok 10:15:57.0769 0x179c [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 10:15:57.0784 0x179c MSiSCSI - ok 10:15:57.0784 0x179c msiserver - ok 10:15:57.0784 0x179c [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 10:15:57.0816 0x179c MSKSSRV - ok 10:15:57.0816 0x179c [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 10:15:57.0847 0x179c MSPCLOCK - ok 10:15:57.0847 0x179c [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 10:15:57.0862 0x179c MSPQM - ok 10:15:57.0878 0x179c [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 10:15:57.0894 0x179c MsRPC - ok 10:15:57.0894 0x179c [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 10:15:57.0894 0x179c mssmbios - ok 10:15:57.0909 0x179c [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 10:15:57.0925 0x179c MSTEE - ok 10:15:57.0925 0x179c [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 10:15:57.0940 0x179c MTConfig - ok 10:15:57.0940 0x179c [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup C:\Windows\system32\Drivers\mup.sys 10:15:57.0940 0x179c Mup - ok 10:15:57.0956 0x179c [ 7B5094DF1671E35D2F2EDDBF12D3D77D, 24637DD03A2DF40E4AFD3EF69B5E117C1F83A38AA8E80091D973677FCE8E035E ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe 10:15:57.0972 0x179c MyWiFiDHCPDNS - ok 10:15:57.0987 0x179c [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent C:\Windows\system32\qagentRT.dll 10:15:58.0018 0x179c napagent - ok 10:15:58.0018 0x179c [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 10:15:58.0034 0x179c NativeWifiP - ok 10:15:58.0065 0x179c [ 760E38053BF56E501D562B70AD796B88, F856E81A975D44F8684A6F2466549CEEDFAEB3950191698555A93A1206E0A42D ] NDIS C:\Windows\system32\drivers\ndis.sys 10:15:58.0081 0x179c NDIS - ok 10:15:58.0096 0x179c [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 10:15:58.0112 0x179c NdisCap - ok 10:15:58.0112 0x179c [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 10:15:58.0143 0x179c NdisTapi - ok 10:15:58.0143 0x179c [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 10:15:58.0159 0x179c Ndisuio - ok 10:15:58.0174 0x179c [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 10:15:58.0190 0x179c NdisWan - ok 10:15:58.0206 0x179c [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 10:15:58.0221 0x179c NDProxy - ok 10:15:58.0252 0x179c [ B90E093E7A7250906F1054418B5339C0, F9A0BAC5B4B29F14B5CACA1047F8928A495EFD56E485492BF71C856B296476D6 ] Nero BackItUp Scheduler 4.0 C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe 10:15:58.0268 0x179c Nero BackItUp Scheduler 4.0 - ok 10:15:58.0268 0x179c [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 10:15:58.0299 0x179c NetBIOS - ok 10:15:58.0299 0x179c [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D12158AC22CCCE37 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 10:15:58.0330 0x179c NetBT - ok 10:15:58.0330 0x179c [ 204F3F58212B3E422C90BD9691A2DF28, D748A8CEE4D59B4248C9B1ACA5155D0FF6635A29564B4391B7FAC6261F93FE99 ] Netlogon C:\Windows\system32\lsass.exe 10:15:58.0346 0x179c Netlogon - ok 10:15:58.0362 0x179c [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman C:\Windows\System32\netman.dll 10:15:58.0377 0x179c Netman - ok 10:15:58.0393 0x179c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 10:15:58.0393 0x179c NetMsmqActivator - ok 10:15:58.0408 0x179c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 10:15:58.0424 0x179c NetPipeActivator - ok 10:15:58.0424 0x179c [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm C:\Windows\System32\netprofm.dll 10:15:58.0455 0x179c netprofm - ok 10:15:58.0471 0x179c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 10:15:58.0471 0x179c NetTcpActivator - ok 10:15:58.0486 0x179c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 10:15:58.0486 0x179c NetTcpPortSharing - ok 10:15:58.0814 0x179c [ 98CF53F7B23F77D082805D5DBBD99A4E, 84285D0192B945262F69FE902C76519741425BD7C674364D6E11F96D2BC38B10 ] NETwNs64 C:\Windows\system32\DRIVERS\Netwsw00.sys 10:15:59.0017 0x179c NETwNs64 - ok 10:15:59.0095 0x179c [ 82FFC84EC3AFC2F2D38DB880F50157C0, 4D37A44A5BBD3ECA2B29FE8565FC5840093E5BB41D197BEDA406BCE4A7C3479A ] Netzmanager Service C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe 10:15:59.0142 0x179c Netzmanager Service - detected UnsignedFile.Multi.Generic ( 1 ) 10:16:01.0544 0x179c Detect skipped due to KSN trusted 10:16:01.0544 0x179c Netzmanager Service - ok 10:16:01.0544 0x179c [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 10:16:01.0575 0x179c nfrd960 - ok 10:16:01.0591 0x179c [ 8AD77806D336673F270DB31645267293, E23F324913554A23CD043DD27D4305AF62F48C0561A0FC7B7811E55B74B1BE79 ] NlaSvc C:\Windows\System32\nlasvc.dll 10:16:01.0606 0x179c NlaSvc - ok 10:16:01.0622 0x179c [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs C:\Windows\system32\drivers\Npfs.sys 10:16:01.0638 0x179c Npfs - ok 10:16:01.0638 0x179c [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi C:\Windows\system32\nsisvc.dll 10:16:01.0669 0x179c nsi - ok 10:16:01.0669 0x179c [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 10:16:01.0684 0x179c nsiproxy - ok 10:16:01.0731 0x179c [ 1A29A59A4C5BA6F8C85062A613B7E2B2, CC137F499A12C724D4166C2D85E9F447413419A0683DAC6F1A802B7F210C77F1 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 10:16:01.0778 0x179c Ntfs - ok 10:16:01.0778 0x179c [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null C:\Windows\system32\drivers\Null.sys 10:16:01.0794 0x179c Null - ok 10:16:01.0809 0x179c [ 158AD24745BD85BA9BE3C51C38F48C32, B053A3B5A5CAE2CBC47E2C19E636AD70F376334EFFBB391A76562E67CBF3AC86 ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys 10:16:01.0809 0x179c nusb3hub - ok 10:16:01.0825 0x179c [ D40A13B2C0891E218F9523B376955DB6, 9A2AAAF960868B860A65579EAD507B35C64CFD6C3581F8D731ADF975F778D10E ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys 10:16:01.0825 0x179c nusb3xhc - ok 10:16:01.0840 0x179c [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid C:\Windows\system32\drivers\nvraid.sys 10:16:01.0840 0x179c nvraid - ok 10:16:01.0856 0x179c [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor C:\Windows\system32\drivers\nvstor.sys 10:16:01.0856 0x179c nvstor - ok 10:16:01.0872 0x179c [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 10:16:01.0872 0x179c nv_agp - ok 10:16:01.0887 0x179c [ 4E37455DB16AEC75862B1D0BC35B589E, F60FCE0C3E6C1559B0A8E0A032AFD30216E1DE2142E8E4C181C43DB6C4B5A443 ] O2FLASH C:\Windows\system32\DRIVERS\o2flash.exe 10:16:01.0887 0x179c O2FLASH - ok 10:16:01.0887 0x179c [ 6172DB160FC566CF24307941C0E94D8E, 81040AEF4E9D56F3514EC46ACF97CCEE38EF2E17CA18DC4FAE4A20561BA3B23C ] O2MDFRDR C:\Windows\system32\drivers\O2MDFw7x64.sys 10:16:01.0903 0x179c O2MDFRDR - ok 10:16:01.0903 0x179c [ 8ED738ABA394BBF6D7802698BE453112, E91E8C27FA111CC20CCB05F41CBF181C398F48A980B523A041CACE242990F77A ] O2MDRRDR C:\Windows\system32\drivers\O2MDRw7x64.sys 10:16:01.0903 0x179c O2MDRRDR - ok 10:16:01.0918 0x179c [ F9C35982D4CFC7DAA739125476E8F139, 027EE07C78F4D7BD4291B308B4AE9F4A0D0FE2C503A2122084FBDBDAECA1ED99 ] O2SDJRDR C:\Windows\system32\drivers\o2sdjw7x64.sys 10:16:01.0918 0x179c O2SDJRDR - ok 10:16:01.0918 0x179c [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 10:16:01.0934 0x179c ohci1394 - ok 10:16:01.0950 0x179c [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 10:16:01.0965 0x179c p2pimsvc - ok 10:16:01.0981 0x179c [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc C:\Windows\system32\p2psvc.dll 10:16:01.0996 0x179c p2psvc - ok 10:16:01.0996 0x179c [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport C:\Windows\system32\drivers\parport.sys 10:16:02.0012 0x179c Parport - ok 10:16:02.0012 0x179c [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr C:\Windows\system32\drivers\partmgr.sys 10:16:02.0012 0x179c partmgr - ok 10:16:02.0028 0x179c [ 256390425414F90FCBC12F525A84EB11, A4992020BF6A239AD8A77125426E2C39980C9ABC971C4DBCB24B358F946AD7F9 ] PcaSvc C:\Windows\System32\pcasvc.dll 10:16:02.0043 0x179c PcaSvc - ok 10:16:02.0043 0x179c [ 3FDE033DFB0D07F8B7D5C9A3044AA121, 2C23B4FA34BA3060884B0168A830DD395A3853855CD6DF4065FBB303DFB4A87E ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfdx64.sys 10:16:02.0043 0x179c pccsmcfd - ok 10:16:02.0059 0x179c [ B26E102E0F54773119B162F56C9DD994, B28724DF87E838CFF7AC0E70E66C5F8FFA21B66BAEF8AE9CA148A7B51EF316CF ] pci C:\Windows\system32\drivers\pci.sys 10:16:02.0059 0x179c pci - ok 10:16:02.0074 0x179c [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide C:\Windows\system32\drivers\pciide.sys 10:16:02.0074 0x179c pciide - ok 10:16:02.0090 0x179c [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 10:16:02.0090 0x179c pcmcia - ok 10:16:02.0090 0x179c [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw C:\Windows\system32\drivers\pcw.sys 10:16:02.0106 0x179c pcw - ok 10:16:02.0121 0x179c [ 946010CDFA91469351B22E2620CEBCD8, F099C92706D42ADC289B72724F7932E5D4F62A427AEC967DDB0A1D728AE59A63 ] PEAUTH C:\Windows\system32\drivers\peauth.sys 10:16:02.0137 0x179c PEAUTH - ok 10:16:02.0168 0x179c [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 10:16:02.0199 0x179c PeerDistSvc - ok 10:16:02.0230 0x179c [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost C:\Windows\SysWow64\perfhost.exe 10:16:02.0230 0x179c PerfHost - ok 10:16:02.0246 0x179c [ 6CE8BB00A615A4F3FA2F36FDB2EF4EFA, EE2F91904AC9BA8658D1BF93C9F93F71D4E2443E88F5FF792DC0AF5DAD3B5102 ] PFNService C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe 10:16:02.0262 0x179c PFNService - detected UnsignedFile.Multi.Generic ( 1 ) 10:16:04.0648 0x179c Detect skipped due to KSN trusted 10:16:04.0648 0x179c PFNService - ok 10:16:04.0742 0x179c [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla C:\Windows\system32\pla.dll 10:16:04.0804 0x179c pla - ok 10:16:04.0820 0x179c [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 10:16:04.0836 0x179c PlugPlay - ok 10:16:04.0836 0x179c [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 10:16:04.0836 0x179c PNRPAutoReg - ok 10:16:04.0851 0x179c [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 10:16:04.0867 0x179c PNRPsvc - ok 10:16:04.0882 0x179c [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D654D9F7A5C12A044 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 10:16:04.0914 0x179c PolicyAgent - ok 10:16:04.0914 0x179c [ A2CCA4FB273E6050F17A0A416CFF2FCD, C42BA18DF0C8E3F7358669A784E51E4DC7A4112096345EA699EDC95F561E0255 ] Power C:\Windows\system32\umpo.dll 10:16:04.0929 0x179c Power - ok 10:16:04.0929 0x179c [ 76FF4836EFA78DBF3F39F612D88CA7E7, 3F684F85B2EB19CB039A08D4123836C1362B81AD1535C7F6A0E0375968020503 ] PowerSavingUtilityService C:\Program Files\Fujitsu\PSUtility\PSUService.exe 10:16:04.0945 0x179c PowerSavingUtilityService - ok 10:16:04.0945 0x179c [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 10:16:04.0960 0x179c PptpMiniport - ok 10:16:04.0976 0x179c [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor C:\Windows\system32\drivers\processr.sys 10:16:04.0976 0x179c Processor - ok 10:16:04.0992 0x179c [ 53E83F1F6CF9D62F32801CF66D8352A8, 1225FED810BE8E0729EEAE5B340035CCBB9BACD3EF247834400F9B72D05ACE48 ] ProfSvc C:\Windows\system32\profsvc.dll 10:16:05.0007 0x179c ProfSvc - ok 10:16:05.0007 0x179c [ 204F3F58212B3E422C90BD9691A2DF28, D748A8CEE4D59B4248C9B1ACA5155D0FF6635A29564B4391B7FAC6261F93FE99 ] ProtectedStorage C:\Windows\system32\lsass.exe 10:16:05.0007 0x179c ProtectedStorage - ok 10:16:05.0023 0x179c [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched C:\Windows\system32\DRIVERS\pacer.sys 10:16:05.0038 0x179c Psched - ok 10:16:05.0085 0x179c [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 10:16:05.0116 0x179c ql2300 - ok 10:16:05.0116 0x179c [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 10:16:05.0132 0x179c ql40xx - ok 10:16:05.0132 0x179c [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE C:\Windows\system32\qwave.dll 10:16:05.0148 0x179c QWAVE - ok 10:16:05.0163 0x179c [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 10:16:05.0163 0x179c QWAVEdrv - ok 10:16:05.0179 0x179c [ A55E7D0D873B2C97585B3B5926AC6ADE, 3BE3895DA7F0888E85B1941525878BA0846A8F215AD39ED8138BB39615468E32 ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll 10:16:05.0194 0x179c RapiMgr - ok 10:16:05.0194 0x179c [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 10:16:05.0210 0x179c RasAcd - ok 10:16:05.0226 0x179c [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 10:16:05.0241 0x179c RasAgileVpn - ok 10:16:05.0241 0x179c [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto C:\Windows\System32\rasauto.dll 10:16:05.0272 0x179c RasAuto - ok 10:16:05.0272 0x179c [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 10:16:05.0304 0x179c Rasl2tp - ok 10:16:05.0319 0x179c [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan C:\Windows\System32\rasmans.dll 10:16:05.0335 0x179c RasMan - ok 10:16:05.0350 0x179c [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 10:16:05.0366 0x179c RasPppoe - ok 10:16:05.0382 0x179c [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 10:16:05.0397 0x179c RasSstp - ok 10:16:05.0413 0x179c [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 10:16:05.0444 0x179c rdbss - ok 10:16:05.0444 0x179c [ 7A32254EA22F47C679309C7D1D2085B3, D62727A751E31AF2C9A245C148ED502F6D3B84138AFCA286BC3EB264E211AE17 ] RDID1009 C:\Windows\system32\Drivers\rdwm1009.sys 10:16:05.0444 0x179c RDID1009 - ok 10:16:05.0460 0x179c [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 10:16:05.0460 0x179c rdpbus - ok 10:16:05.0460 0x179c [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 10:16:05.0491 0x179c RDPCDD - ok 10:16:05.0491 0x179c [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 10:16:05.0506 0x179c RDPDR - ok 10:16:05.0506 0x179c [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 10:16:05.0538 0x179c RDPENCDD - ok 10:16:05.0538 0x179c [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 10:16:05.0553 0x179c RDPREFMP - ok 10:16:05.0569 0x179c [ 313F68E1A3E6345A4F47A36B07062F34, B8318A0AE06BDE278931CA52F960B9FE226FD9894B076858DDB755AE26E1E66F ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 10:16:05.0569 0x179c RdpVideoMiniport - ok 10:16:05.0584 0x179c [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 10:16:05.0600 0x179c RDPWD - ok 10:16:05.0600 0x179c [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 10:16:05.0616 0x179c rdyboost - ok 10:16:05.0616 0x179c [ 992E3160D3AB2D8F083B6808D73A4016, BFB0C76A03472827D577783270B01AEADAC32EE644177C2A8027CDC593179E13 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 10:16:05.0631 0x179c RegSrvc - ok 10:16:05.0631 0x179c [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess C:\Windows\System32\mprdim.dll 10:16:05.0662 0x179c RemoteAccess - ok 10:16:05.0662 0x179c [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry C:\Windows\system32\regsvc.dll 10:16:05.0694 0x179c RemoteRegistry - ok 10:16:05.0694 0x179c [ 3DD798846E2C28102B922C56E71B7932, 30B111615D74CB2213997A5C08DD9C8613ADE441D9423CC1C49A753D13CE524D ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 10:16:05.0709 0x179c RFCOMM - ok 10:16:05.0709 0x179c [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 10:16:05.0740 0x179c RpcEptMapper - ok 10:16:05.0740 0x179c [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator C:\Windows\system32\locator.exe 10:16:05.0740 0x179c RpcLocator - ok 10:16:05.0756 0x179c [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] RpcSs C:\Windows\system32\rpcss.dll 10:16:05.0787 0x179c RpcSs - ok 10:16:05.0803 0x179c [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 10:16:05.0818 0x179c rspndr - ok 10:16:05.0818 0x179c [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap C:\Windows\system32\drivers\vms3cap.sys 10:16:05.0834 0x179c s3cap - ok 10:16:05.0834 0x179c [ 204F3F58212B3E422C90BD9691A2DF28, D748A8CEE4D59B4248C9B1ACA5155D0FF6635A29564B4391B7FAC6261F93FE99 ] SamSs C:\Windows\system32\lsass.exe 10:16:05.0850 0x179c SamSs - ok 10:16:05.0850 0x179c [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 10:16:05.0850 0x179c sbp2port - ok 10:16:05.0865 0x179c [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr C:\Windows\System32\SCardSvr.dll 10:16:05.0896 0x179c SCardSvr - ok 10:16:05.0896 0x179c [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 10:16:05.0912 0x179c scfilter - ok 10:16:05.0943 0x179c [ 262F6592C3299C005FD6BEC90FC4463A, 54095E37F0B6CC677A3E9BDD40F4647C713273D197DB341063AA7F342A60C4A7 ] Schedule C:\Windows\system32\schedsvc.dll 10:16:05.0990 0x179c Schedule - ok 10:16:05.0990 0x179c [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc C:\Windows\System32\certprop.dll 10:16:06.0021 0x179c SCPolicySvc - ok 10:16:06.0021 0x179c [ 111E0EBC0AD79CB0FA014B907B231CF0, B7D43D156C2524938503CF8E99C4D1F7A5C55E16C0368F57F4CD23C6D833B38F ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys 10:16:06.0037 0x179c sdbus - ok 10:16:06.0037 0x179c [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC C:\Windows\System32\SDRSVC.dll 10:16:06.0052 0x179c SDRSVC - ok 10:16:06.0052 0x179c [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\Windows\system32\drivers\secdrv.sys 10:16:06.0084 0x179c secdrv - ok 10:16:06.0084 0x179c [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C7060829E8204A2297F9 ] seclogon C:\Windows\system32\seclogon.dll 10:16:06.0099 0x179c seclogon - ok 10:16:06.0115 0x179c [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS C:\Windows\System32\sens.dll 10:16:06.0130 0x179c SENS - ok 10:16:06.0130 0x179c [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc C:\Windows\system32\sensrsvc.dll 10:16:06.0146 0x179c SensrSvc - ok 10:16:06.0146 0x179c [ 8167B3DF18CF957BB87F328F131D5570, 10D9F7691BF67773D8F1276D3A63D43FB2CF5F618B701F0E1DC11E348CB12E79 ] Ser2pl C:\Windows\system32\DRIVERS\ser2pl64.sys 10:16:06.0162 0x179c Ser2pl - ok 10:16:06.0162 0x179c [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 10:16:06.0177 0x179c Serenum - ok 10:16:06.0177 0x179c [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial C:\Windows\system32\DRIVERS\serial.sys 10:16:06.0193 0x179c Serial - ok 10:16:06.0193 0x179c [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 10:16:06.0208 0x179c sermouse - ok 10:16:06.0224 0x179c [ 78F7BB9F4924BE164294C59B8C3FC096, 75051A6A8B0DBB16CD70855A408134270EEAF0C127BAAE5B592DB53BB87C085B ] ServiceLayer C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe 10:16:06.0240 0x179c ServiceLayer - ok 10:16:06.0255 0x179c [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv C:\Windows\system32\sessenv.dll 10:16:06.0271 0x179c SessionEnv - ok 10:16:06.0271 0x179c [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 10:16:06.0286 0x179c sffdisk - ok 10:16:06.0286 0x179c [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 10:16:06.0302 0x179c sffp_mmc - ok 10:16:06.0302 0x179c [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 10:16:06.0318 0x179c sffp_sd - ok 10:16:06.0318 0x179c [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 10:16:06.0318 0x179c sfloppy - ok 10:16:06.0333 0x179c [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess C:\Windows\System32\ipnathlp.dll 10:16:06.0364 0x179c SharedAccess - ok 10:16:06.0380 0x179c [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 10:16:06.0396 0x179c ShellHWDetection - ok 10:16:06.0411 0x179c [ F16269F0A47CBBF4578204283AC0D6B3, 16BBD37338762E927E1955E899D2D1E4DAED576954A52A9E1CA2D800EE67E878 ] Sierra Wireless QDL Service C:\Program Files (x86)\Sierra Wireless Inc\Gobi\QDLService\GobiQDLService.exe 10:16:06.0427 0x179c Sierra Wireless QDL Service - ok 10:16:06.0427 0x179c [ 8C61B219882C9C9ECA09BEDB82B0DDB1, 711681040D9CD93D603F55AB8D62371F5D51917C14818F27859E23E2D60EB18F ] silabenm C:\Windows\system32\DRIVERS\silabenm.sys 10:16:06.0442 0x179c silabenm - ok 10:16:06.0442 0x179c [ 2641655FAD6C1EA0F3677978E2BF28C1, E703CE74D09E901BF531589E181DCF95B9C63E09FE1B99E38DEA9EE47EE458BA ] silabser C:\Windows\system32\DRIVERS\silabser.sys 10:16:06.0442 0x179c silabser - ok 10:16:06.0458 0x179c [ E9E830D540EDEDED650F906628468548, 9800160C6807B28A2A1E57810151473C96F1484F2EF75D3E378E8C96440CD4CE ] simptcp C:\Windows\System32\tcpsvcs.exe 10:16:06.0458 0x179c simptcp - ok 10:16:06.0458 0x179c [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 10:16:06.0474 0x179c SiSRaid2 - ok 10:16:06.0474 0x179c [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 10:16:06.0489 0x179c SiSRaid4 - ok 10:16:06.0489 0x179c [ 050A4112B00BCA2E13314CDE48C1DEEE, 86C679CD494DEEB984372BF954EFBB8982AC7995FBF89FCF83BC228991D1B825 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 10:16:06.0505 0x179c SkypeUpdate - ok 10:16:06.0505 0x179c [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb C:\Windows\system32\DRIVERS\smb.sys 10:16:06.0536 0x179c Smb - ok 10:16:06.0552 0x179c [ FBE0201AB61E18934C812C34D31A4403, 549E51FC11CCA30B21970C90F4799D6CB94481CDC623B8C319F16DAEFC8A190B ] snapman C:\Windows\system32\DRIVERS\snapman.sys 10:16:06.0552 0x179c snapman - ok 10:16:06.0567 0x179c [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 10:16:06.0567 0x179c SNMPTRAP - ok 10:16:06.0614 0x179c [ 9CD1C53490EB5601870A69A8E40F7B12, 0F7E471E31D5CA7EEEF1BDC5D38384EE3C90E6949174707432CD16B59AC59266 ] SNP2UVC C:\Windows\system32\DRIVERS\snp2uvc.sys 10:16:06.0661 0x179c SNP2UVC - ok 10:16:06.0661 0x179c [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr C:\Windows\system32\drivers\spldr.sys 10:16:06.0661 0x179c spldr - ok 10:16:06.0676 0x179c [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler C:\Windows\System32\spoolsv.exe 10:16:06.0708 0x179c Spooler - ok 10:16:06.0786 0x179c [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc C:\Windows\system32\sppsvc.exe 10:16:06.0879 0x179c sppsvc - ok 10:16:06.0879 0x179c [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify C:\Windows\system32\sppuinotify.dll 10:16:06.0910 0x179c sppuinotify - ok 10:16:06.0910 0x179c [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7CD1863FDB8932C0 ] srv C:\Windows\system32\DRIVERS\srv.sys 10:16:06.0926 0x179c srv - ok 10:16:06.0942 0x179c [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE4A8C9DB29E87F7 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 10:16:06.0957 0x179c srv2 - ok 10:16:06.0973 0x179c [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF39FF9AF3646D9E6 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 10:16:06.0973 0x179c srvnet - ok 10:16:06.0988 0x179c [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 10:16:07.0004 0x179c SSDPSRV - ok 10:16:07.0020 0x179c [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc C:\Windows\system32\sstpsvc.dll 10:16:07.0035 0x179c SstpSvc - ok 10:16:07.0051 0x179c [ 91310683D7B6B292B746D60734B59322, 2C56C3E4AA7356FB544B52F80ABDA39A80473390CB2059C69BDCCAD40FE56325 ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys 10:16:07.0051 0x179c ssudmdm - ok 10:16:07.0066 0x179c [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor C:\Windows\system32\drivers\stexstor.sys 10:16:07.0066 0x179c stexstor - ok 10:16:07.0082 0x179c [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc C:\Windows\System32\wiaservc.dll 10:16:07.0113 0x179c stisvc - ok 10:16:07.0113 0x179c [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt C:\Windows\system32\drivers\vmstorfl.sys 10:16:07.0113 0x179c storflt - ok 10:16:07.0129 0x179c [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc C:\Windows\system32\storsvc.dll 10:16:07.0129 0x179c StorSvc - ok 10:16:07.0129 0x179c [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc C:\Windows\system32\drivers\storvsc.sys 10:16:07.0144 0x179c storvsc - ok 10:16:07.0144 0x179c [ FD1134B9DACF371240A6F9CD7AE8D488, 3563147CB448B9B7CF1EA594FD3C72BFA6F157B3A1B0F1F11868B36BCC960B88 ] subvgaproduct64 C:\Windows\system32\DRIVERS\subvga64.sys 10:16:07.0160 0x179c subvgaproduct64 - ok 10:16:07.0160 0x179c [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum C:\Windows\system32\drivers\swenum.sys 10:16:07.0160 0x179c swenum - ok 10:16:07.0160 0x179c [ 27FA8EBC9A28B57658F6747473CB5C8E, C095EB064D4B999D7CE1E5D9B56F88AC0BE3CDD7FE08E7402C04C2B69D13B657 ] swg3kflt00 C:\Windows\system32\DRIVERS\swg3kflt00.sys 10:16:07.0176 0x179c swg3kflt00 - ok 10:16:07.0191 0x179c [ D74305444436E41BEB59FF2260A6394A, 506DFB4344EADC174D142CE31D09125B22C10347179FC9C06B5473D8F3886F1D ] swg3kmbb00 C:\Windows\system32\DRIVERS\swg3kmbb00.sys 10:16:07.0207 0x179c swg3kmbb00 - ok 10:16:07.0207 0x179c [ 143B763E71DF2ED586C278541F89432D, 896C5B286195FB0089A7A1BD586A7426570202FBA97E61E2BD3AD3AF51E14BAA ] swg3knmea00 C:\Windows\system32\DRIVERS\swg3knmea00.sys 10:16:07.0222 0x179c swg3knmea00 - ok 10:16:07.0238 0x179c [ 143B763E71DF2ED586C278541F89432D, 896C5B286195FB0089A7A1BD586A7426570202FBA97E61E2BD3AD3AF51E14BAA ] swg3kser00 C:\Windows\system32\DRIVERS\swg3kser00.sys 10:16:07.0238 0x179c swg3kser00 - ok 10:16:07.0254 0x179c [ B49E9DB5401ECC28A104E64F5434A38E, 8BF061B2DE8C0A917F9BB6B087C8088C58B403951EEF6AE42AC9552879D33751 ] swibus00 C:\Windows\system32\DRIVERS\swibus00.sys 10:16:07.0254 0x179c swibus00 - ok 10:16:07.0254 0x179c [ B49E9DB5401ECC28A104E64F5434A38E, 8BF061B2DE8C0A917F9BB6B087C8088C58B403951EEF6AE42AC9552879D33751 ] swibusflt00 C:\Windows\system32\DRIVERS\swibusflt00.sys 10:16:07.0269 0x179c swibusflt00 - ok 10:16:07.0285 0x179c [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv C:\Windows\System32\swprv.dll 10:16:07.0316 0x179c swprv - ok 10:16:07.0503 0x179c [ 0FE29D81F372CA2DCE9E49736A3BD3E6, 10ED93BEE7ECBD2AF5E7AB0197CC82A5424FD63A2ED90F0417B266AD06E5F32C ] syncagentsrv C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe 10:16:07.0628 0x179c syncagentsrv - ok 10:16:07.0675 0x179c [ F5B46DF59FEAA48A442AED7EEB754D4B, 8415FDD5E7B4D4819BB9B0937CDF254548C871045787958BCF708096204B1714 ] SynTP C:\Windows\system32\drivers\SynTP.sys 10:16:07.0706 0x179c SynTP - ok 10:16:07.0753 0x179c [ BF9CCC0BF39B418C8D0AE8B05CF95B7D, 3C13217548BE61F2BDB8BD41F77345CDDA1F97BF0AE17241C335B9807EB3DBB8 ] SysMain C:\Windows\system32\sysmain.dll 10:16:07.0800 0x179c SysMain - ok 10:16:07.0800 0x179c [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll 10:16:07.0815 0x179c TabletInputService - ok 10:16:08.0002 0x179c [ 765FD4777D284BCE6325C98B33814F24, 03AFED0C796EF999E3EABCC1DB66C5C97AF1FDE9621497CD5EEBA364A46705D4 ] TabletServiceISD C:\Program Files\Tablet\ISD\ISD_Tablet.exe 10:16:08.0112 0x179c TabletServiceISD - ok 10:16:08.0127 0x179c [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv C:\Windows\System32\tapisrv.dll 10:16:08.0143 0x179c TapiSrv - ok 10:16:08.0158 0x179c [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS C:\Windows\System32\tbssvc.dll 10:16:08.0174 0x179c TBS - ok 10:16:08.0221 0x179c [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 10:16:08.0268 0x179c Tcpip - ok 10:16:08.0314 0x179c [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 10:16:08.0346 0x179c TCPIP6 - ok 10:16:08.0346 0x179c [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 10:16:08.0361 0x179c tcpipreg - ok 10:16:08.0361 0x179c [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 10:16:08.0377 0x179c TDPIPE - ok 10:16:08.0408 0x179c [ 07330E30921C70E9D9B416EE43A06349, 398500C12E685BCF732C7F80A2C0E95181E5377A0E6C14CF9A3EE8580083A556 ] tdrpman C:\Windows\system32\DRIVERS\tdrpman.sys 10:16:08.0439 0x179c tdrpman - ok 10:16:08.0439 0x179c [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 10:16:08.0455 0x179c TDTCP - ok 10:16:08.0455 0x179c [ DDAD5A7AB24D8B65F8D724F5C20FD806, B71F2967A4EE7395E4416C1526CB85368AEA988BDD1F2C9719C48B08FAFA9661 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 10:16:08.0486 0x179c tdx - ok 10:16:08.0580 0x179c [ 19ADFE7E7861372D9FAC774252AB1AC7, 76EF484F51A34C592CEECAFA400094F88B92D85EE3267C0AA36E79B73185C48C ] TeamViewer C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe 10:16:08.0689 0x179c TeamViewer - ok 10:16:08.0689 0x179c [ 4283D7125BA4BD0CB50BB0F78B54257A, A9DBFC45CDF7444BA7AD92734E66E3E4F844BF036AC19FD43F915151191F12C5 ] TelekomNM6 C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys 10:16:08.0704 0x179c TelekomNM6 - ok 10:16:08.0704 0x179c [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD C:\Windows\system32\drivers\termdd.sys 10:16:08.0704 0x179c TermDD - ok 10:16:08.0720 0x179c [ 008CD4EBFABCF78D0F19B3778492648C, 9050490EEE0AD86E73F0A82D83E4FC29DF84F6B6FDB389AE135FD712B5F425BE ] TermService C:\Windows\System32\termsrv.dll 10:16:08.0751 0x179c TermService - ok 10:16:08.0751 0x179c [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes C:\Windows\system32\themeservice.dll 10:16:08.0767 0x179c Themes - ok 10:16:08.0767 0x179c [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER C:\Windows\system32\mmcss.dll 10:16:08.0782 0x179c THREADORDER - ok 10:16:08.0814 0x179c [ DE604462206F7D8C203F767F425FCA8D, 149FBF6367C45415B939A9B1A7A10DA7A5E19F28CE533BCBE2B20DA4B78F8645 ] tib C:\Windows\system32\DRIVERS\tib.sys 10:16:08.0845 0x179c tib - ok 10:16:08.0845 0x179c [ 3C29FB9FC9B4C511AD69DC50257FEC75, 4906DADE076FD363C53044C805602EEA4D0EF6E92041C693E1BED2286614B36E ] tib_mounter C:\Windows\system32\DRIVERS\tib_mounter.sys 10:16:08.0860 0x179c tib_mounter - ok 10:16:08.0860 0x179c [ 519CB7D7F697F4BA47DE05845C20F158, F4B40014CB5047463FC40C28D9CFF0DA5E8592A2A9ED8E938A0A9D43DBD0A516 ] TlntSvr C:\Windows\System32\tlntsvr.exe 10:16:08.0876 0x179c TlntSvr - ok 10:16:08.0892 0x179c [ BCF185C3EDB87FB2A0FB71E3576B402E, BD3033A0091130A8C37531E9606DF0FBE7CE5632542E72C5F57828484F92F7D2 ] TouchServiceISD C:\Program Files\Tablet\ISD\ISD_TouchService.exe 10:16:08.0907 0x179c TouchServiceISD - ok 10:16:08.0907 0x179c [ DBCC20C02E8A3E43B03C304A4E40A84F, BF5F3ACCB0342304A6870E94D2576644B08DBF307C853C7DBA4B82B0C7309DA4 ] TPM C:\Windows\system32\drivers\tpm.sys 10:16:08.0907 0x179c TPM - ok 10:16:08.0923 0x179c [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks C:\Windows\System32\trkwks.dll 10:16:08.0938 0x179c TrkWks - ok 10:16:08.0954 0x179c [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 10:16:08.0970 0x179c TrustedInstaller - ok 10:16:08.0985 0x179c [ E232A3B43A894BB327FC161529BD9ED1, F2673DA8C920F21ACCECC25F7C59A05822E5E577D47F126EDF9C94FEB4B30C5F ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 10:16:08.0985 0x179c tssecsrv - ok 10:16:09.0001 0x179c [ E9981ECE8D894CEF7038FD1D040EB426, DCDDCE933CAECE8180A3447199B07F2F0413704EEC1A09606EE357901A84A7CF ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 10:16:09.0001 0x179c TsUsbFlt - ok 10:16:09.0001 0x179c [ AD64450A4ABE076F5CB34CC08EEACB07, B5C386635441A19178E7FEEE299BA430C8D72F9110866C13A216B12A1080AD12 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 10:16:09.0016 0x179c TsUsbGD - ok 10:16:09.0016 0x179c [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 10:16:09.0048 0x179c tunnel - ok 10:16:09.0048 0x179c [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 10:16:09.0063 0x179c uagp35 - ok 10:16:09.0063 0x179c [ F623D724FE9F9BB41BB5056C9982BB4C, C7F67C2EA11D563487512DF91BA89BBCB2CF56B7B1A45F0DD340F1AC9BCE0BF7 ] ubloxVcp C:\Windows\system32\DRIVERS\ubloxVcp.sys 10:16:09.0063 0x179c ubloxVcp - detected UnsignedFile.Multi.Generic ( 1 ) 10:16:11.0512 0x179c ubloxVcp ( UnsignedFile.Multi.Generic ) - warning 10:16:13.0962 0x179c [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 10:16:14.0008 0x179c udfs - ok 10:16:14.0008 0x179c [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect C:\Windows\system32\UI0Detect.exe 10:16:14.0024 0x179c UI0Detect - ok 10:16:14.0024 0x179c [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 10:16:14.0040 0x179c uliagpkx - ok 10:16:14.0040 0x179c [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus C:\Windows\system32\DRIVERS\umbus.sys 10:16:14.0040 0x179c umbus - ok 10:16:14.0055 0x179c [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass C:\Windows\system32\drivers\umpass.sys 10:16:14.0055 0x179c UmPass - ok 10:16:14.0071 0x179c [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService C:\Windows\System32\umrdp.dll 10:16:14.0071 0x179c UmRdpService - ok 10:16:14.0086 0x179c [ 67A95B9D129ED5399E7965CD09CF30E7, F1F2F684146F1CCB293BB9871117B8CFC1D04588A830F67CE5D3F0D034D93B2A ] UMVPFSrv C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe 10:16:14.0102 0x179c UMVPFSrv - ok 10:16:14.0164 0x179c [ E419566C7918A4C8E9497AFBD502FB2A, 3A206F603A46E8B536032942E78D1026A22B64FC84FFD4677A387763354E3321 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 10:16:14.0227 0x179c UNS - ok 10:16:14.0227 0x179c [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost C:\Windows\System32\upnphost.dll 10:16:14.0258 0x179c upnphost - ok 10:16:14.0274 0x179c [ C9E9D59C0099A9FF51697E9306A44240, 78D9A7A5E5742962B6978F475BF06CB32262F1D214699D3D40538476A58012A1 ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 10:16:14.0274 0x179c USBAAPL64 - detected UnsignedFile.Multi.Generic ( 1 ) 10:16:16.0676 0x179c Detect skipped due to KSN trusted 10:16:16.0676 0x179c USBAAPL64 - ok 10:16:16.0692 0x179c [ B0435098C81D04CAFFF80DDB746CD3A2, A17B207740382E38729571F0B0BC98FF874E856A7C7CE9EB930328A2AD88F52A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 10:16:16.0707 0x179c usbaudio - ok 10:16:16.0723 0x179c [ 91D3C92A44FC682DD791147604E79152, AA0B6799BF9C26C2C1793C91295288A4989AA43EC5E070B650DA7F0A142817CE ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 10:16:16.0738 0x179c usbccgp - ok 10:16:16.0738 0x179c [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir C:\Windows\system32\drivers\usbcir.sys 10:16:16.0754 0x179c usbcir - ok 10:16:16.0770 0x179c [ F7FFDF2A1D19A76A87759126B244C816, C91F09D77E22D976952A46F7B93F611B719EDAF694D538242FA8FAF1BA9BB2F0 ] usbehci C:\Windows\system32\drivers\usbehci.sys 10:16:16.0770 0x179c usbehci - ok 10:16:16.0785 0x179c [ 245FE7FC634D6A993E682E0A9EBA4ABB, F7A536D215EE3A63358EC8B5946D7BB3B56357BF91347B07013E00DAC98775B6 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 10:16:16.0801 0x179c usbhub - ok 10:16:16.0801 0x179c [ C1A8966E0D09BFB501045105B30D86F2, 5BB95FBA441B898E258A3BFE174FC1042A04C19E25C59DE1FD90594290B11DA9 ] usbohci C:\Windows\system32\drivers\usbohci.sys 10:16:16.0801 0x179c usbohci - ok 10:16:16.0816 0x179c [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 10:16:16.0816 0x179c usbprint - ok 10:16:16.0816 0x179c [ 9661DA76B4531B2DA272ECCE25A8AF24, FEA93254A21E71A7EB8AD35FCCAD2C1E41F7329EC33B1734F5B41307A34D8637 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 10:16:16.0832 0x179c usbscan - ok 10:16:16.0832 0x179c [ B57B4F0BEC4270A281B9F8537EB2FA04, 554273482EE85F010DC62E412C9933E65BD63AA09911BD25D86F86D2618EF382 ] usbser C:\Windows\system32\drivers\usbser.sys 10:16:16.0848 0x179c usbser - ok 10:16:16.0848 0x179c [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D5711D9C19DEB96 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 10:16:16.0863 0x179c USBSTOR - ok 10:16:16.0863 0x179c [ 2E682DCE4319A90E02A327F8A427544A, 3528C5A4669BAD53041085C3E72C64388D308E42AD9D1FAC85B6F2FFD81610FB ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 10:16:16.0879 0x179c usbuhci - ok 10:16:16.0879 0x179c [ 1F775DA4CF1A3A1834207E975A72E9D7, 6D3DE5BD3EF3A76E997E5BAF900C51D25308F5A9682D1F62017F577A24095B90 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys 10:16:16.0894 0x179c usbvideo - ok 10:16:16.0894 0x179c [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms C:\Windows\System32\uxsms.dll 10:16:16.0910 0x179c UxSms - ok 10:16:16.0926 0x179c [ 204F3F58212B3E422C90BD9691A2DF28, D748A8CEE4D59B4248C9B1ACA5155D0FF6635A29564B4391B7FAC6261F93FE99 ] VaultSvc C:\Windows\system32\lsass.exe 10:16:16.0926 0x179c VaultSvc - ok 10:16:16.0926 0x179c [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 10:16:16.0941 0x179c vdrvroot - ok 10:16:16.0957 0x179c [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds C:\Windows\System32\vds.exe 10:16:16.0988 0x179c vds - ok 10:16:16.0988 0x179c [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 10:16:17.0004 0x179c vga - ok 10:16:17.0004 0x179c [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave C:\Windows\System32\drivers\vga.sys 10:16:17.0019 0x179c VgaSave - ok 10:16:17.0035 0x179c [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 10:16:17.0050 0x179c vhdmp - ok 10:16:17.0050 0x179c [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide C:\Windows\system32\drivers\viaide.sys 10:16:17.0050 0x179c viaide - ok 10:16:17.0066 0x179c [ 35E8A18D1C558D5C2FF2FFED2FD396F6, 5516AC03964DD33CF239AB3FB1D41BAB7454DB35FB38C45907614C3DB8F23391 ] vididr C:\Windows\system32\DRIVERS\vididr.sys 10:16:17.0066 0x179c vididr - ok 10:16:17.0082 0x179c [ 0DCD5C8F2E0B3650C4A29F6569C074FD, 8FB24D79ADE1541C5DD6241A3395EF2E6575A8376111294CD5C87ECA798EDCFD ] vidsflt C:\Windows\system32\DRIVERS\vidsflt.sys 10:16:17.0082 0x179c vidsflt - ok 10:16:17.0097 0x179c [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus C:\Windows\system32\drivers\vmbus.sys 10:16:17.0097 0x179c vmbus - ok 10:16:17.0113 0x179c [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 10:16:17.0113 0x179c VMBusHID - ok 10:16:17.0113 0x179c [ 071E1B172D49154EE1D23A2ACC472EFB, 2E75ECE68F911F1FB0E8BEEFD8C7B8F794164335E1A1F2CE5D14126C9445BB7C ] volmgr C:\Windows\system32\drivers\volmgr.sys 10:16:17.0128 0x179c volmgr - ok 10:16:17.0144 0x179c [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 10:16:17.0144 0x179c volmgrx - ok 10:16:17.0160 0x179c [ DF8126BD41180351A093A3AD2FC8903B, AEFF4AA89CDDAAAD43CDE17C6B6EB2A397A0AC1651CBD51B889161EC2BC6527A ] volsnap C:\Windows\system32\drivers\volsnap.sys 10:16:17.0175 0x179c volsnap - ok 10:16:17.0175 0x179c [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 10:16:17.0191 0x179c vsmraid - ok 10:16:17.0238 0x179c [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS C:\Windows\system32\vssvc.exe 10:16:17.0284 0x179c VSS - ok 10:16:17.0284 0x179c [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 10:16:17.0300 0x179c vwifibus - ok 10:16:17.0300 0x179c [ 6A3D66263414FF0D6FA754C646612F3F, 30F6BA594B0D3B94113064015A16D97811CD989DF1715CCE21CEAB9894C1B4FB ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 10:16:17.0316 0x179c vwififlt - ok 10:16:17.0316 0x179c [ 6A638FC4BFDDC4D9B186C28C91BD1A01, 5521F1DC515586777EC4837E0AEAA3E613CC178AF1074031C4D0D0C695A93168 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 10:16:17.0331 0x179c vwifimp - ok 10:16:17.0347 0x179c [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time C:\Windows\system32\w32time.dll 10:16:17.0378 0x179c W32Time - ok 10:16:17.0378 0x179c [ E04D43C7D1641E95D35CAE6086C7E350, BF08ED680EC835D70C522B91560B8987F206793E8E2987117C1D7B77DEFF8556 ] wacommousefilter C:\Windows\system32\DRIVERS\wacommousefilter.sys 10:16:17.0378 0x179c wacommousefilter - ok 10:16:17.0378 0x179c [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 10:16:17.0394 0x179c WacomPen - ok 10:16:17.0394 0x179c [ EC1CEB237E365330C1FCFC4876AA0AC0, 9BFF9062AC5E4B9D0C6502D8DE7E59B887903ED29F26157A5F82966932F1EBD0 ] wacomvhid C:\Windows\system32\DRIVERS\wacomvhid.sys 10:16:17.0394 0x179c wacomvhid - ok 10:16:17.0409 0x179c [ EF4D5242C0E2F74BA8E74C31F57A11CB, 9E27E03A055FF8A073487CF5B26137A354A69050A4D01426E99148F826CEE453 ] wacomvthid C:\Windows\system32\DRIVERS\WacomVTHid.sys 10:16:17.0409 0x179c wacomvthid - ok 10:16:17.0409 0x179c [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 10:16:17.0440 0x179c WANARP - ok 10:16:17.0440 0x179c [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 10:16:17.0472 0x179c Wanarpv6 - ok 10:16:17.0487 0x179c [ 3CEC96DE223E49EAAE3651FCF8FAEA6C, 4150DAB33E8D61076F1D4767BCAFC9B4ECCCCBD58FD4FB3CFE5B8D27DCDCAB61 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 10:16:17.0518 0x179c WatAdminSvc - ok 10:16:17.0565 0x179c [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine C:\Windows\system32\wbengine.exe 10:16:17.0596 0x179c wbengine - ok 10:16:17.0612 0x179c [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 10:16:17.0628 0x179c WbioSrvc - ok 10:16:17.0643 0x179c [ 8BDA6DB43AA54E8BB5E0794541DDC209, 8753C507BE77B019A3403AF5252434A01DB9F9332E58AC3783ABCE3D21AD9DD4 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll 10:16:17.0659 0x179c WcesComm - ok 10:16:17.0674 0x179c [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc C:\Windows\System32\wcncsvc.dll 10:16:17.0690 0x179c wcncsvc - ok 10:16:17.0690 0x179c [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 10:16:17.0706 0x179c WcsPlugInService - ok 10:16:17.0706 0x179c [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd C:\Windows\system32\drivers\wd.sys 10:16:17.0721 0x179c Wd - ok 10:16:17.0737 0x179c [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 10:16:17.0752 0x179c Wdf01000 - ok 10:16:17.0768 0x179c [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiServiceHost C:\Windows\system32\wdi.dll 10:16:17.0799 0x179c WdiServiceHost - ok 10:16:17.0799 0x179c [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiSystemHost C:\Windows\system32\wdi.dll 10:16:17.0815 0x179c WdiSystemHost - ok 10:16:17.0830 0x179c [ 0EB0E5D22B1760F2DBCE632F2DD7A54D, B8A4CC62F88768947FB0A161CF9564DB28FD9C1C037B5475DF192982DE035C22 ] WebClient C:\Windows\System32\webclnt.dll 10:16:17.0830 0x179c WebClient - ok 10:16:17.0846 0x179c [ D5BA7D43FA2EF656BF7E98A188391E40, 56CF132B7C43A0F9C7C4D070730315FE7AFD2E87E94014DFC3D7107BB52B9C64 ] Wecsvc C:\Windows\system32\wecsvc.dll 10:16:17.0862 0x179c Wecsvc - ok 10:16:17.0862 0x179c [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport C:\Windows\System32\wercplsupport.dll 10:16:17.0893 0x179c wercplsupport - ok 10:16:17.0893 0x179c [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc C:\Windows\System32\WerSvc.dll 10:16:17.0908 0x179c WerSvc - ok 10:16:17.0924 0x179c [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 10:16:17.0940 0x179c WfpLwf - ok 10:16:17.0940 0x179c [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount C:\Windows\system32\drivers\wimmount.sys 10:16:17.0955 0x179c WIMMount - ok 10:16:17.0955 0x179c WinDefend - ok 10:16:17.0955 0x179c WinHttpAutoProxySvc - ok 10:16:17.0971 0x179c [ 136760C1E9697BAF4ECDEAE5590A0806, 12E80D0923D794F4C520FEA7CB98EF581231B996FB1876EB20995E6E457EFF56 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 10:16:17.0986 0x179c Winmgmt - ok 10:16:18.0049 0x179c [ 3BB6B401A780BF434C8F58137DE10BF7, 1A377C39B78B92A1A1FED699EE5E5ED0271A6FFAC143F1D29FC1FDF4D726A522 ] WinRM C:\Windows\system32\WsmSvc.dll 10:16:18.0111 0x179c WinRM - ok 10:16:18.0127 0x179c [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb C:\Windows\system32\DRIVERS\WinUSB.sys 10:16:18.0127 0x179c WinUsb - ok 10:16:18.0158 0x179c [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc C:\Windows\System32\wlansvc.dll 10:16:18.0189 0x179c Wlansvc - ok 10:16:18.0236 0x179c [ 357CABBF155AFD1D3926E62539D2A3A7, C43CFF84E7D930B4999DC061AB0766B57AAD7540B3E6EE54605B10ECE90825F5 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 10:16:18.0283 0x179c wlidsvc - ok 10:16:18.0283 0x179c [ 680A7846370000D20D7E74917D5B7936, 55B77B358039672845D361CA4205F3482D1F30A4654B610FD785A1337EFDC316 ] WmBEnum C:\Windows\system32\drivers\WmBEnum.sys 10:16:18.0283 0x179c WmBEnum - ok 10:16:18.0298 0x179c [ 14C35BA8189C6F65D839163AA285E954, 8981AA488320C75E26E1ABDF884B721A4065F5D28F54782598B03F21B8CDC020 ] WmFilter C:\Windows\system32\drivers\WmFilter.sys 10:16:18.0298 0x179c WmFilter - ok 10:16:18.0298 0x179c [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 10:16:18.0314 0x179c WmiAcpi - ok 10:16:18.0314 0x179c [ 4DF841632B62A7CF19A79A05046A8AB1, D80F28FD7FEB95DB83976EAFECB2E9AE1423DA4D34EC5D820FC39A33444B82DA ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 10:16:18.0330 0x179c wmiApSrv - ok 10:16:18.0330 0x179c WMPNetworkSvc - ok 10:16:18.0330 0x179c [ 8488DD91A3EE54A8E29F02AD7BB8201E, D428ED991D9E4A8765C240B21884A262854278698D60862117AC5949713231F9 ] WmVirHid C:\Windows\system32\drivers\WmVirHid.sys 10:16:18.0345 0x179c WmVirHid - ok 10:16:18.0345 0x179c [ 14802B3A30AA849C97CB968CCC813BF3, 330AD828ABD040ECDBF58F7162978CD61BFC093CAD404FD2BCAC74E3F2EC542A ] WmXlCore C:\Windows\system32\drivers\WmXlCore.sys 10:16:18.0345 0x179c WmXlCore - ok 10:16:18.0345 0x179c [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc C:\Windows\System32\wpcsvc.dll 10:16:18.0361 0x179c WPCSvc - ok 10:16:18.0361 0x179c [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 10:16:18.0376 0x179c WPDBusEnum - ok 10:16:18.0376 0x179c [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 10:16:18.0408 0x179c ws2ifsl - ok 10:16:18.0408 0x179c [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc C:\Windows\System32\wscsvc.dll 10:16:18.0423 0x179c wscsvc - ok 10:16:18.0423 0x179c WSearch - ok 10:16:18.0486 0x179c [ 61FF576450CCC80564B850BC3FB6713A, B2843BC9E2F62D27DCF6787D063378926748CE75002BADA1873DCB5039883705 ] wuauserv C:\Windows\system32\wuaueng.dll 10:16:18.0532 0x179c wuauserv - ok 10:16:18.0532 0x179c [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 10:16:18.0548 0x179c WudfPf - ok 10:16:18.0548 0x179c [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 10:16:18.0564 0x179c WUDFRd - ok 10:16:18.0564 0x179c [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 10:16:18.0579 0x179c wudfsvc - ok 10:16:18.0595 0x179c [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc C:\Windows\System32\wwansvc.dll 10:16:18.0595 0x179c WwanSvc - ok 10:16:18.0720 0x179c [ 9FA1347D0E96998C3793F51BB94D7AC3, D4C692E8313B96D03AB5A37C1CF15B7F7D8B76948555B4CFBA1ADA4D3E051C3B ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe 10:16:18.0782 0x179c ZeroConfigService - ok 10:16:18.0798 0x179c ================ Scan global =============================== 10:16:18.0798 0x179c [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618DD5859E8ADBF1A8 ] C:\Windows\system32\basesrv.dll 10:16:18.0798 0x179c [ 88EDD0B34EED542745931E581AD21A32, DC2B93E1CEF5B0BCEE08D72669BB0F3AD0E8E6E75BDC08858407ED92F6FFA031 ] C:\Windows\system32\winsrv.dll 10:16:18.0813 0x179c [ 88EDD0B34EED542745931E581AD21A32, DC2B93E1CEF5B0BCEE08D72669BB0F3AD0E8E6E75BDC08858407ED92F6FFA031 ] C:\Windows\system32\winsrv.dll 10:16:18.0829 0x179c [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll 10:16:18.0829 0x179c [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885F668CF42C5E7E2 ] C:\Windows\system32\services.exe 10:16:18.0844 0x179c [ Global ] - ok 10:16:18.0844 0x179c ================ Scan MBR ================================== 10:16:18.0844 0x179c [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 10:16:18.0938 0x179c \Device\Harddisk0\DR0 - ok 10:16:18.0938 0x179c ================ Scan VBR ================================== 10:16:18.0938 0x179c [ 264D3A17495D4B6A8B406F5E0C956EAC ] \Device\Harddisk0\DR0\Partition1 10:16:18.0938 0x179c \Device\Harddisk0\DR0\Partition1 - ok 10:16:18.0938 0x179c ================ Scan generic autorun ====================== 10:16:18.0938 0x179c [ 9D51EA92A612B37E76E5E4621650C50A, 00BD61C8527A80C0F684882379A0AC2E5A54E8BBECC797087B960CDC8454C373 ] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe 10:16:18.0954 0x179c NUSB3MON - ok 10:16:18.0969 0x179c [ 7B89EF5A5A46D4B5924D392D74437CAA, F83E9BE96BCF55CD02CB0B50B345E24E6FD78ADA52EBF859E357E8DD81947B9C ] C:\Program Files (x86)\Fujitsu\PointingDeviceUtility\FJPDAutoSet.exe 10:16:18.0969 0x179c StartFujitsuPointingDeviceUtility - ok 10:16:18.0985 0x179c [ 65FF4F0192EAA8649F066DCF7D8C4854, F88982AE941F79492B4B7164185B2E4403F21176CCB5B8891B494CFD9DE90762 ] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe 10:16:18.0985 0x179c IMSS - ok 10:16:19.0000 0x179c [ DEBF34BCF45FC4764CFF6F4CEBD1E03C, BD82FBC62B14181BD6714D797CA0869AD5E2D8F69D05EAEF295BB069730A9289 ] C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe 10:16:19.0000 0x179c IndicatorUtility - ok 10:16:19.0016 0x179c [ 47EA5F76FAB723C61AB4A0D79BAD512C, A7A38EB0A7068B160E6949945EF639F999A06AE35746F6E79C7350745798E5C9 ] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe 10:16:19.0047 0x179c Adobe ARM - ok 10:16:19.0266 0x179c [ B8434467D90B65E5A2D697C7FF511802, A0F5D234A1CA1384160FB63AF40B169B4649DF7D77534DE1B16E1063EC922A87 ] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe 10:16:19.0406 0x179c TrueImageMonitor.exe - ok 10:16:19.0437 0x179c [ 5FF9A79628D4A0BA3DCD6CF5EC8FD3BF, 9818AAF8F1F1C0CBD8B89352DBAF1ADBEA1F19928543517EB6473C112E95A38D ] C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe 10:16:19.0453 0x179c AcronisTibMounterMonitor - ok 10:16:19.0468 0x179c [ F8A3337DE768B126B061F1B7CD38A436, F93EE8D8D7CA28658587F82C38AE6C13D51A03CFE8DE6AC3BA35DC6A1DB986CE ] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe 10:16:19.0468 0x179c KiesTrayAgent - ok 10:16:19.0484 0x179c [ 6623776D9B4420326020DD3DC950E36D, B12B3EC45AFF4AE853B73B2FA8627356023BA6753AD6FA2697540602B7DB2E90 ] c:\Fujitsu\Programs\DeskUpdate\DeskUpdateNotifier.exe 10:16:19.0484 0x179c DeskUpdateNotifier - ok 10:16:19.0484 0x179c [ 0EF0822810009D58118CCDFD098FA9F4, 9FAA263057898BCDBCB0A064C463F48D149474AA339A3C4C47626CC118750D2D ] C:\Program Files (x86)\iTunes\iTunesHelper.exe 10:16:19.0500 0x179c iTunesHelper - ok 10:16:19.0515 0x179c [ 271B0D188430670509CB9943D5229205, 74CB5A9D8B5988AE08C0F65C601FC54F8745BAB6825B6FEEFBA8F068D656D8D7 ] C:\Program Files (x86)\QuickTime\QTTask.exe 10:16:19.0515 0x179c QuickTime Task - detected UnsignedFile.Multi.Generic ( 1 ) 10:16:21.0918 0x179c Detect skipped due to KSN trusted 10:16:21.0918 0x179c QuickTime Task - ok 10:16:21.0949 0x179c [ 887CAA31048EB8ED09A0CBD0E6F46F09, BBCED0BD4EB00C3FECFC9448223D4C441A868787877291F5489B07B43FAB65A4 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe 10:16:21.0980 0x179c SunJavaUpdateSched - ok 10:16:22.0027 0x179c [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe 10:16:22.0058 0x179c Sidebar - ok 10:16:22.0058 0x179c [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe 10:16:22.0074 0x179c mctadmin - ok 10:16:22.0105 0x179c [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe 10:16:22.0136 0x179c Sidebar - ok 10:16:22.0136 0x179c [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe 10:16:22.0152 0x179c mctadmin - ok 10:16:22.0292 0x179c [ DEB55C327597E42FA14E41F5858F3263, 199300A8E1B0000A82D04CDA2D32C482945AFFE47A037AAA58F89E3EDF059684 ] C:\Program Files\CCleaner\CCleaner64.exe 10:16:22.0417 0x179c ccleaner - ok 10:16:22.0448 0x179c [ 2F85D5E63A1ECE08085D32C1B615BBFD, 7263F4E0CC7D375CBAA44406F90F427E6EC9382184B3CD62A90C0DD6B7D88372 ] C:\Program Files (x86)\Samsung\Kies\Kies.exe 10:16:22.0479 0x179c KiesPreload - ok 10:16:22.0604 0x179c [ DEB55C327597E42FA14E41F5858F3263, 199300A8E1B0000A82D04CDA2D32C482945AFFE47A037AAA58F89E3EDF059684 ] C:\Program Files\CCleaner\CCleaner64.exe 10:16:22.0713 0x179c CCleaner Monitoring - ok 10:16:22.0760 0x179c [ FEB1D1811C7F5E39F48BBBE063162E4A, F922B3A0EE13652A086C0056386AB35C4DA0B46AC26844641592427E45AF107C ] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_15_0_0_223_Plugin.exe 10:16:22.0776 0x179c FlashPlayerUpdate - ok 10:16:22.0776 0x179c Waiting for KSN requests completion. In queue: 94 10:16:23.0790 0x179c Waiting for KSN requests completion. In queue: 94 10:16:24.0804 0x179c Waiting for KSN requests completion. In queue: 94 10:16:25.0194 0x17f8 Object required for P2P: [ FEB1D1811C7F5E39F48BBBE063162E4A ] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_15_0_0_223_Plugin.exe 10:16:25.0818 0x179c Waiting for KSN requests completion. In queue: 1 10:16:26.0832 0x179c Waiting for KSN requests completion. In queue: 1 10:16:27.0736 0x17f8 Object send P2P result: true 10:16:27.0877 0x179c AV detected via SS2: Kaspersky Internet Security, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\wmiav.exe ( 14.0.0.4651 ), 0x41000 ( enabled : updated ) 10:16:27.0877 0x179c FW detected via SS2: Kaspersky Internet Security, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\wmifw.exe ( 14.0.0.4651 ), 0x41010 ( enabled ) 10:16:30.0388 0x179c ============================================================ 10:16:30.0388 0x179c Scan finished 10:16:30.0388 0x179c ============================================================ 10:16:30.0404 0x1cd4 Detected object count: 1 10:16:30.0404 0x1cd4 Actual detected object count: 1 10:16:58.0375 0x1cd4 ubloxVcp ( UnsignedFile.Multi.Generic ) - skipped by user 10:16:58.0375 0x1cd4 ubloxVcp ( UnsignedFile.Multi.Generic ) - User select action: Skip |
27.11.2014, 08:10 | #9 |
/// the machine /// TB-Ausbilder | Telekom Deutschland - Fake Rechnung 13.11.2014 hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.11.2014, 12:07 | #10 |
| Telekom Deutschland - Fake Rechnung 13.11.2014 Combofix Logfile: Code:
ATTFilter ComboFix 14-11-25.01 - Helge Hartz 27.11.2014 10:50:05.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.7931.5829 [GMT 1:00] ausgeführt von:: c:\users\Helge Hartz\Desktop\ComboFix.exe AV: Kaspersky Internet Security *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886} FW: Kaspersky Internet Security *Disabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} SP: Kaspersky Internet Security *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\install.exe c:\programdata\ntuser.pol c:\programdata\Roaming c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\0665c25e931c1ac0151b062449e91028\XSAccessor.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\17d0b152e63e6bfe81b4b19588538896\mro.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\19febd96672ffdb7ea244cef36aaa062\Zlib.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\2b1fc61b36a6711ea149b18bf3b41500\Parser.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\3a8764e0d7c5d453e01d9ad08cf7fb58\IO.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\3b7106dd14676048b10bbb09a990f74c\XS.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\4461f48e31bde5c56b31b973b773de09\List.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\44727051c604ef6b79894b64d4c63832\Expat.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\4f2c03383aab0133b8dc0a3fa2dd92fa\Storable.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\7f177c338672436e01c4f0bdbcf94491\EV.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\7f2598c08178217a0e2c754f3d568f28\Byte.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\8fedeb86a4a984edfc1fb255d4ea965c\XS.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\961b0d62fa52b1dd29c795a822fbf1cf\DBI.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\aff7ee779ea184f884ed432c30a58f5d\Scale.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\b6bd87c968599725b8ab2e5c25d3046a\API.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\b979ace6da01e63d651cce9ee2474fdc\Name.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\bc147d83c7c868eeee67082dcf55430c\File.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\bd5179a413bc0c4b82eedc22c6cab101\re.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\c199d3c1960e7aeeecb599487952bed2\HiRes.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\c19d5e3dc664d9f4ce700001e2621cee\MD5.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\c344fd5536724b2af2e6453833b60203\SHA1.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\c5cce8d16a1bd48692b421dcf46d3396\Util.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\c668a322917d32a5ea22894518aa9897\Base64.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\cf5fe81e2f5dcbfecfd0495e1648c991\Unicode.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\d0bf009923f29116535c26d228271d6d\Scan.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\d1c77e404b5c4b954fa537ed63c8fb7b\File.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\dacfd0ab9b5fd029ed8d29e4482b0775\XS.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\e2e81dd6b3e5a36f0bdae076393cc11d\icudt46.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\e2e81dd6b3e5a36f0bdae076393cc11d\icuin46.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\e2e81dd6b3e5a36f0bdae076393cc11d\icuuc46.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\e2e81dd6b3e5a36f0bdae076393cc11d\SQLite.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\e56c61f7248672819579325af3387035\POSIX.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\eb138ef0e4282611dbf485a302784646\LibYAML.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\f233f63b6654362865c7577442edb9e3\Win32.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\fa9e3c814aa32db2ad5f17bdfbc22746\attributes.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3684\perl514.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\4461f48e31bde5c56b31b973b773de09\List.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\93e7e3d6030f426844228042348210cf\Service.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\bd5179a413bc0c4b82eedc22c6cab101\re.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\c5cce8d16a1bd48692b421dcf46d3396\Util.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\e56c61f7248672819579325af3387035\POSIX.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\eb138ef0e4282611dbf485a302784646\LibYAML.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\f233f63b6654362865c7577442edb9e3\Win32.dll c:\users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3772\perl514.dll c:\users\Helge Hartz\AppData\Roaming\mIRC\logs\status.log c:\users\Helge Hartz\Documents\~WRL0559.tmp c:\users\Helge Hartz\Documents\~WRL2638.tmp c:\users\Helge Hartz\Documents\~WRL2863.tmp c:\users\Helge Hartz\Documents\~WRL3063.tmp c:\users\Helge Hartz\Documents\~WRL3805.tmp c:\users\Helge Hartz\Documents\~WRL3982.tmp c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\0665c25e931c1ac0151b062449e91028\XSAccessor.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\17d0b152e63e6bfe81b4b19588538896\mro.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\19febd96672ffdb7ea244cef36aaa062\Zlib.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\2b1fc61b36a6711ea149b18bf3b41500\Parser.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\3a8764e0d7c5d453e01d9ad08cf7fb58\IO.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\3b7106dd14676048b10bbb09a990f74c\XS.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\4461f48e31bde5c56b31b973b773de09\List.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\44727051c604ef6b79894b64d4c63832\Expat.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\4f2c03383aab0133b8dc0a3fa2dd92fa\Storable.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\7f177c338672436e01c4f0bdbcf94491\EV.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\7f2598c08178217a0e2c754f3d568f28\Byte.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\8fedeb86a4a984edfc1fb255d4ea965c\XS.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\961b0d62fa52b1dd29c795a822fbf1cf\DBI.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\aff7ee779ea184f884ed432c30a58f5d\Scale.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\b6bd87c968599725b8ab2e5c25d3046a\API.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\b979ace6da01e63d651cce9ee2474fdc\Name.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\bc147d83c7c868eeee67082dcf55430c\File.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\bd5179a413bc0c4b82eedc22c6cab101\re.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\c199d3c1960e7aeeecb599487952bed2\HiRes.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\c19d5e3dc664d9f4ce700001e2621cee\MD5.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\c344fd5536724b2af2e6453833b60203\SHA1.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\c5cce8d16a1bd48692b421dcf46d3396\Util.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\c668a322917d32a5ea22894518aa9897\Base64.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\cf5fe81e2f5dcbfecfd0495e1648c991\Unicode.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\d0bf009923f29116535c26d228271d6d\Scan.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\d1c77e404b5c4b954fa537ed63c8fb7b\File.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\dacfd0ab9b5fd029ed8d29e4482b0775\XS.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\e2e81dd6b3e5a36f0bdae076393cc11d\icudt46.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\e2e81dd6b3e5a36f0bdae076393cc11d\icuin46.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\e2e81dd6b3e5a36f0bdae076393cc11d\icuuc46.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\e2e81dd6b3e5a36f0bdae076393cc11d\SQLite.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\e56c61f7248672819579325af3387035\POSIX.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\eb138ef0e4282611dbf485a302784646\LibYAML.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\f233f63b6654362865c7577442edb9e3\Win32.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\fa9e3c814aa32db2ad5f17bdfbc22746\attributes.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3684\perl514.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\4461f48e31bde5c56b31b973b773de09\List.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\93e7e3d6030f426844228042348210cf\Service.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\bd5179a413bc0c4b82eedc22c6cab101\re.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\c5cce8d16a1bd48692b421dcf46d3396\Util.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\e56c61f7248672819579325af3387035\POSIX.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\eb138ef0e4282611dbf485a302784646\LibYAML.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\f233f63b6654362865c7577442edb9e3\Win32.dll c:\users\HELGEH~1\AppData\Local\Temp\pdk-Helge_Hartz-3772\perl514.dll c:\windows\IsUn0407.exe c:\windows\ST6UNST.000 c:\windows\SysWow64\drivers\hwinterface.sys . . ((((((((((((((((((((((( Dateien erstellt von 2014-10-27 bis 2014-11-27 )))))))))))))))))))))))))))))) . . 2014-11-27 10:01 . 2014-11-27 10:01 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-11-26 13:09 . 2014-11-26 13:09 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018368_1.tmp 2014-11-26 13:07 . 2014-11-26 13:07 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014744_1.tmp 2014-11-26 13:05 . 2014-11-26 13:05 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016796_2.tmp 2014-11-25 11:14 . 2014-11-25 11:14 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016048_1.tmp 2014-11-25 10:08 . 2014-11-25 10:09 -------- d-----w- C:\FRST 2014-11-25 06:33 . 2014-11-02 04:20 11632448 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D2D836EF-6E57-4C40-BC25-184DFEAAFDEB}\mpengine.dll 2014-11-23 16:31 . 2014-11-23 16:31 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017356_3.tmp 2014-11-23 11:41 . 2014-11-23 11:41 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014620_2.tmp 2014-11-22 21:22 . 2014-11-22 21:22 -------- d-----w- c:\windows\ERUNT 2014-11-22 15:46 . 2014-11-22 15:46 -------- d-----w- c:\users\Helge Hartz\AppData\Roaming\Assimil_d_se 2014-11-22 09:56 . 2011-05-13 10:16 493056 ----a-w- c:\windows\SysWow64\dhRichClient3.dll 2014-11-22 09:56 . 2011-03-25 18:42 338432 ----a-w- c:\windows\SysWow64\sqlite36_engine.dll 2014-11-21 10:06 . 2014-11-21 10:06 -------- d-----w- c:\users\Helge Hartz\.routeconverter 2014-11-21 06:54 . 2014-11-21 06:54 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017452_1.tmp 2014-11-21 06:50 . 2014-11-21 06:50 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014576_2.tmp 2014-11-20 09:18 . 2014-11-20 09:40 -------- d-----w- c:\users\Helge Hartz\Wirtschaft 2014-11-19 16:43 . 2014-11-19 16:43 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014932_2.tmp 2014-11-19 16:08 . 2014-11-11 03:08 241152 ----a-w- c:\windows\system32\pku2u.dll 2014-11-19 16:08 . 2014-11-11 03:08 728064 ----a-w- c:\windows\system32\kerberos.dll 2014-11-19 16:08 . 2014-11-11 02:44 186880 ----a-w- c:\windows\SysWow64\pku2u.dll 2014-11-19 16:08 . 2014-11-11 02:44 550912 ----a-w- c:\windows\SysWow64\kerberos.dll 2014-11-17 07:32 . 2014-11-17 07:32 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011188_1.tmp 2014-11-17 07:31 . 2014-11-17 07:31 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017440_1.tmp 2014-11-17 07:30 . 2014-11-17 07:30 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018864_1.tmp 2014-11-17 06:54 . 2014-11-17 06:54 -------- d-----w- c:\program files (x86)\CHIRP 2014-11-17 06:44 . 2014-11-17 06:45 -------- d-----w- c:\users\Helge Hartz\AppData\Roaming\CHIRP 2014-11-12 13:37 . 2014-11-12 13:37 -------- d-sh--w- c:\users\Helge Hartz\AppData\Local\EmieBrowserModeList 2014-11-12 11:08 . 2014-11-05 17:56 304640 ----a-w- c:\windows\system32\generaltel.dll 2014-11-10 09:21 . 2014-11-10 09:21 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012176_3.tmp 2014-11-10 09:19 . 2014-11-10 09:19 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016664_2.tmp 2014-11-10 09:17 . 2014-11-10 09:17 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011316_3.tmp 2014-11-09 11:16 . 2014-11-09 11:16 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018796_2.tmp 2014-11-09 11:13 . 2014-11-09 11:13 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017920_3.tmp 2014-11-09 11:13 . 2014-11-09 11:13 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018684_2.tmp 2014-11-09 11:12 . 2014-11-09 11:12 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018576_1.tmp 2014-11-09 11:12 . 2014-11-09 11:12 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018588_4.tmp 2014-11-09 11:11 . 2014-11-09 11:11 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014564_1.tmp 2014-11-09 11:10 . 2014-11-09 11:10 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018808_2.tmp 2014-11-09 11:07 . 2014-11-09 11:07 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon080901796_1.tmp 2014-11-09 11:04 . 2014-11-09 11:04 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018772_2.tmp 2014-11-09 11:03 . 2014-11-09 11:03 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018704_3.tmp 2014-11-09 11:02 . 2014-11-09 11:02 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017220_2.tmp 2014-11-09 11:02 . 2014-11-09 11:02 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014308_1.tmp 2014-11-09 10:59 . 2014-11-09 10:59 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015744_2.tmp 2014-11-09 10:57 . 2014-11-09 10:57 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019056_2.tmp 2014-11-09 10:57 . 2014-11-09 10:57 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017080_2.tmp 2014-11-09 10:56 . 2014-11-09 10:56 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016308_1.tmp 2014-11-09 10:55 . 2014-11-09 10:55 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015628_1.tmp 2014-11-09 10:35 . 2014-11-09 10:35 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018484_1.tmp 2014-11-09 09:23 . 2014-11-09 09:23 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017420_1.tmp 2014-11-09 09:21 . 2014-11-09 09:21 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012684_2.tmp 2014-11-09 09:19 . 2014-11-09 09:19 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018176_3.tmp 2014-11-09 09:17 . 2014-11-09 09:17 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017900_1.tmp 2014-11-09 09:17 . 2014-11-09 09:17 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016192_1.tmp 2014-11-09 08:57 . 2014-11-09 08:57 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017084_1.tmp 2014-11-04 15:19 . 2014-11-04 15:19 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019964_1.tmp 2014-11-04 15:19 . 2014-11-04 15:19 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014324_1.tmp 2014-11-02 10:09 . 2014-11-02 10:09 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016944_3.tmp 2014-11-02 09:53 . 2014-11-03 08:27 -------- d-----w- C:\metar2aprsobj 2014-11-01 15:05 . 2014-11-01 15:05 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019656_1.tmp 2014-11-01 13:34 . 2014-11-01 13:34 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014968_2.tmp 2014-11-01 13:34 . 2014-11-01 13:34 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011988_2.tmp 2014-11-01 13:33 . 2014-11-01 13:33 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017428_3.tmp 2014-10-31 19:51 . 2014-10-31 19:51 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2014-10-31 10:01 . 2014-10-31 10:00 79360 ----a-w- c:\windows\system32\drivers\silabser.sys 2014-10-31 10:01 . 2014-10-31 10:00 23552 ----a-w- c:\windows\system32\drivers\silabenm.sys 2014-10-31 06:43 . 2014-10-31 06:43 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017612_3.tmp 2014-10-31 06:42 . 2014-10-31 06:42 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012348_1.tmp 2014-10-30 13:46 . 2014-10-30 13:46 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018688_2.tmp 2014-10-30 13:45 . 2014-10-30 13:45 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017348_3.tmp 2014-10-30 13:37 . 2014-10-30 13:37 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018768_1.tmp 2014-10-30 13:33 . 2014-10-30 13:33 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019092_2.tmp 2014-10-30 13:33 . 2014-10-30 13:33 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017296_3.tmp 2014-10-30 13:33 . 2014-10-30 13:33 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011424_1.tmp 2014-10-30 13:29 . 2014-10-30 13:29 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016032_2.tmp 2014-10-30 13:19 . 2014-10-30 13:19 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016064_1.tmp 2014-10-30 13:18 . 2014-10-30 13:18 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013648_2.tmp 2014-10-30 13:16 . 2014-10-30 13:16 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014740_1.tmp 2014-10-30 13:16 . 2014-10-30 13:16 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014168_1.tmp 2014-10-30 13:15 . 2014-10-30 13:15 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016988_2.tmp 2014-10-30 13:13 . 2014-10-30 13:13 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014492_2.tmp 2014-10-30 13:12 . 2014-10-30 13:12 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018780_1.tmp 2014-10-30 13:12 . 2014-10-30 13:12 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018688_1.tmp 2014-10-30 13:06 . 2014-10-30 13:06 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016356_1.tmp 2014-10-30 12:58 . 2014-10-30 12:59 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018624_1.tmp 2014-10-30 12:57 . 2014-10-30 12:57 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019080_2.tmp 2014-10-30 12:42 . 2014-10-30 12:42 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018404_2.tmp 2014-10-30 12:41 . 2014-10-30 12:41 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016724_2.tmp 2014-10-30 12:40 . 2014-10-30 12:40 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019092_1.tmp 2014-10-30 12:31 . 2014-10-30 12:31 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018040_1.tmp 2014-10-30 07:34 . 2014-10-30 07:34 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012344_1.tmp 2014-10-30 07:34 . 2014-10-30 07:34 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016992_1.tmp 2014-10-30 07:33 . 2014-10-30 07:33 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018268_3.tmp 2014-10-30 07:28 . 2014-10-30 07:28 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon080901676_1.tmp 2014-10-30 07:26 . 2014-10-30 07:26 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017960_2.tmp 2014-10-30 07:25 . 2014-10-30 07:25 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017648_1.tmp 2014-10-30 07:23 . 2014-10-30 07:23 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016772_2.tmp 2014-10-30 07:13 . 2014-10-30 07:13 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017872_1.tmp 2014-10-30 07:08 . 2014-10-30 07:08 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012524_1.tmp 2014-10-30 07:01 . 2014-10-30 07:01 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013136_1.tmp 2014-10-30 06:59 . 2014-10-30 06:59 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013724_1.tmp 2014-10-30 06:58 . 2014-10-30 06:58 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015900_1.tmp 2014-10-30 06:58 . 2014-10-30 06:58 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012008_1.tmp 2014-10-30 06:43 . 2014-10-30 06:43 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013024_1.tmp 2014-10-30 06:42 . 2014-10-30 06:42 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016920_1.tmp 2014-10-30 06:39 . 2014-10-30 06:39 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon080901964_2.tmp 2014-10-30 06:37 . 2014-10-30 06:37 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015400_1.tmp 2014-10-30 06:34 . 2014-10-30 06:34 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011668_1.tmp . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-11-26 16:18 . 2013-09-29 04:59 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-11-26 16:18 . 2013-09-29 04:59 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-11-12 11:16 . 2012-05-23 10:20 103374192 ----a-w- c:\windows\system32\MRT.exe 2014-11-04 13:30 . 2010-11-21 03:27 275080 ------w- c:\windows\system32\MpSigStub.exe 2014-10-28 07:30 . 2014-10-28 07:30 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014800_2.tmp 2014-10-26 13:49 . 2014-10-26 13:49 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012800_2.tmp 2014-10-26 11:17 . 2014-10-26 11:17 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014588_2.tmp 2014-10-26 11:17 . 2014-10-26 11:17 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017476_2.tmp 2014-10-26 11:16 . 2014-10-26 11:16 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018400_1.tmp 2014-10-26 11:15 . 2014-10-26 11:15 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014488_2.tmp 2014-10-26 11:13 . 2014-10-26 11:13 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012464_1.tmp 2014-10-26 11:12 . 2014-10-26 11:12 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016500_1.tmp 2014-10-26 11:09 . 2014-10-26 11:09 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014952_1.tmp 2014-10-26 11:08 . 2014-10-26 11:08 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015984_2.tmp 2014-10-26 11:06 . 2014-10-26 11:06 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015088_1.tmp 2014-10-26 11:06 . 2014-10-26 11:06 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018416_1.tmp 2014-10-26 11:04 . 2014-10-26 11:04 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017888_2.tmp 2014-10-21 08:46 . 2014-10-21 08:46 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012636_1.tmp 2014-10-09 08:32 . 2014-10-09 08:32 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018724_1.tmp 2014-10-09 08:31 . 2014-10-09 08:31 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018776_2.tmp 2014-10-09 08:30 . 2014-10-09 08:30 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018028_2.tmp 2014-10-09 08:21 . 2014-10-09 08:21 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011184_3.tmp 2014-10-09 08:19 . 2014-10-09 08:19 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011104_2.tmp 2014-10-09 08:18 . 2014-10-09 08:18 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013324_1.tmp 2014-10-08 18:10 . 2014-10-08 18:10 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011516_3.tmp 2014-10-08 18:07 . 2014-10-08 18:07 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013664_2.tmp 2014-10-08 18:03 . 2014-10-08 18:03 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019580_1.tmp 2014-10-08 18:00 . 2014-10-08 18:00 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018396_1.tmp 2014-10-08 17:56 . 2014-10-08 17:56 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011336_1.tmp 2014-10-06 12:39 . 2014-10-06 12:39 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017596_3.tmp 2014-10-06 12:31 . 2014-10-06 12:31 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015488_1.tmp 2014-10-04 09:10 . 2014-10-04 09:10 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011088_2.tmp 2014-10-04 09:08 . 2014-10-04 09:08 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon08090118772_1.tmp 2014-10-04 09:07 . 2014-10-04 09:07 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018632_1.tmp 2014-10-03 06:21 . 2014-10-03 06:21 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018588_3.tmp 2014-10-02 13:23 . 2014-10-02 13:23 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx 2014-10-02 13:23 . 2014-10-02 13:23 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts 2014-10-01 18:38 . 2014-10-01 18:38 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018432_2.tmp 2014-10-01 18:09 . 2014-10-01 18:09 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016032_1.tmp 2014-09-30 05:43 . 2014-09-30 05:43 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011104_1.tmp 2014-09-29 17:11 . 2014-09-29 17:11 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon080901184_1.tmp 2014-09-29 17:09 . 2014-09-29 17:09 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013664_1.tmp 2014-09-26 11:09 . 2014-09-26 11:09 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016900_2.tmp 2014-09-26 11:02 . 2014-09-26 11:02 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014608_1.tmp 2014-09-26 08:14 . 2014-09-26 08:14 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014048_1.tmp 2014-09-25 12:49 . 2014-09-25 12:49 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019136_1.tmp 2014-09-25 08:19 . 2014-09-25 08:19 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013524_1.tmp 2014-09-25 02:08 . 2014-10-01 11:29 371712 ----a-w- c:\windows\system32\qdvd.dll 2014-09-25 01:40 . 2014-10-01 11:29 519680 ----a-w- c:\windows\SysWow64\qdvd.dll 2014-09-24 10:20 . 2014-09-24 10:20 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014768_1.tmp 2014-09-23 13:45 . 2014-09-23 13:45 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon08090113016_1.tmp 2014-09-22 16:36 . 2014-09-22 16:36 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon080901964_1.tmp 2014-09-22 14:32 . 2014-09-22 14:32 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019072_1.tmp 2014-09-22 14:32 . 2014-09-22 14:32 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015744_1.tmp 2014-09-22 10:05 . 2014-09-22 10:05 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018116_2.tmp 2014-09-21 18:10 . 2014-09-21 18:10 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012684_1.tmp 2014-09-21 18:08 . 2014-09-21 18:08 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016012_2.tmp 2014-09-21 17:17 . 2014-09-21 17:17 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018684_1.tmp 2014-09-21 17:16 . 2014-09-21 17:16 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013312_1.tmp 2014-09-21 17:15 . 2014-09-21 17:15 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019828_1.tmp 2014-09-21 08:04 . 2014-09-21 08:04 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013640_1.tmp 2014-09-21 08:02 . 2014-09-21 08:02 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011900_1.tmp 2014-09-21 07:18 . 2014-09-21 07:18 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018868_3.tmp 2014-09-18 11:18 . 2014-09-18 11:18 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017340_2.tmp 2014-09-17 18:36 . 2014-09-17 18:36 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015168_2.tmp 2014-09-17 18:28 . 2014-09-17 18:28 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011252_1.tmp 2014-09-17 18:21 . 2014-09-17 18:21 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014724_1.tmp 2014-09-17 15:31 . 2014-09-17 15:31 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013692_1.tmp 2014-09-17 15:29 . 2014-09-17 15:29 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013264_1.tmp 2014-09-17 06:35 . 2014-09-17 06:35 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016440_2.tmp 2014-09-17 06:10 . 2014-09-17 06:10 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012064_3.tmp 2014-09-17 05:48 . 2014-09-17 05:48 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon080901728_2.tmp 2014-09-13 19:51 . 2014-09-13 19:51 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013288_1.tmp 2014-09-13 12:58 . 2014-09-13 12:58 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019048_1.tmp 2014-09-13 12:56 . 2014-09-13 12:56 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017356_2.tmp 2014-09-09 22:11 . 2014-09-24 05:55 2048 ----a-w- c:\windows\system32\tzres.dll 2014-09-09 21:47 . 2014-09-24 05:55 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2014-09-09 11:44 . 2014-09-09 11:44 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015104_3.tmp 2014-09-09 09:57 . 2014-09-09 09:57 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019056_1.tmp 2014-09-09 09:56 . 2014-09-09 09:56 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017500_2.tmp 2014-09-05 02:11 . 2014-10-14 19:43 6584320 ----a-w- c:\windows\system32\mstscax.dll 2014-09-05 01:52 . 2014-10-14 19:43 5703168 ----a-w- c:\windows\SysWow64\mstscax.dll 2014-09-04 05:23 . 2014-10-14 19:43 424448 ----a-w- c:\windows\system32\rastls.dll 2014-09-04 05:04 . 2014-10-14 19:43 372736 ----a-w- c:\windows\SysWow64\rastls.dll 2014-08-30 10:07 . 2014-08-30 10:07 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014092_1.tmp 2014-08-30 10:06 . 2014-08-30 10:06 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015928_1.tmp 2014-08-30 10:05 . 2014-08-30 10:05 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013828_1.tmp 2014-08-30 10:02 . 2014-08-30 10:02 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018636_1.tmp 2014-08-30 10:00 . 2014-08-30 10:00 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011548_2.tmp 2014-08-30 09:58 . 2014-08-30 09:58 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017892_2.tmp 2014-08-30 09:57 . 2014-08-30 09:57 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018404_1.tmp 2014-08-30 09:56 . 2014-08-30 09:56 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016596_2.tmp 2014-08-30 09:54 . 2014-08-30 09:54 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015940_1.tmp 2014-08-30 09:53 . 2014-08-30 09:53 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018692_1.tmp 2014-08-30 09:43 . 2014-08-30 09:43 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018696_1.tmp 2014-08-30 09:43 . 2014-08-30 09:43 520 ----a-w- c:\users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017284_3.tmp . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2014-08-02 12:14 223432 ----a-w- c:\users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2014-08-02 12:14 223432 ----a-w- c:\users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2014-08-02 12:14 223432 ----a-w- c:\users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"] @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"] @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"] @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"] @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ccleaner"="c:\program files\CCleaner\CCleaner64.exe" [2014-10-23 6501656] "KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2014-07-25 1562264] "CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2014-10-23 6501656] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288] "StartFujitsuPointingDeviceUtility"="c:\program files (x86)\Fujitsu\PointingDeviceUtility\FJPDAutoSet.exe" [2011-02-02 85104] "IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2011-02-01 112152] "IndicatorUtility"="c:\program files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2010-09-30 48752] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176] "TrueImageMonitor.exe"="c:\program files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" [2014-02-04 7843744] "AcronisTibMounterMonitor"="c:\program files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe" [2013-10-10 1104616] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2014-07-25 311616] "DeskUpdateNotifier"="c:\fujitsu\Programs\DeskUpdate\DeskUpdateNotifier.exe" [2013-12-11 101728] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-10-15 157480] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-10-02 421888] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-10-07 507776] . c:\users\Helge Hartz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-11-13 35419192] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ AutoStart IR.lnk - c:\program files (x86)\WinTV\Ir.exe /QUIET [2014-7-28 118544] Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-10-15 1133856] Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office10\OSA.EXE -b -l [2001-2-13 83360] UE Music Library-Taskleisten-Tool.lnk - c:\program files (x86)\Logitech\UE Music Library\UEMLTray.exe [2014-2-21 3981411] WinTV Recording Status.lnk - c:\program files (x86)\WinTV\WinTV7\WinTVTray.exe [2014-7-28 151552] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ LaunchCenter.lnk - c:\program files\Fujitsu\LaunchCenter\lcStarter.exe [2010-11-4 21504] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux9"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 Netzmanager Service;Netzmanager Infrastruktur Informationssystem Dienst;c:\program files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe ;c:\program files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x] R3 AVMAP_CP_amd64;AvMap Chart Plotter USB Driver (x64);c:\windows\system32\Drivers\avmcpx64.sys;c:\windows\SYSNATIVE\Drivers\avmcpx64.sys [x] R3 cjusb;REINER SCT cyberJack USB Driver;c:\windows\system32\DRIVERS\cjusb.sys;c:\windows\SYSNATIVE\DRIVERS\cjusb.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys;c:\windows\SYSNATIVE\DRIVERS\ew_hwusbdev.sys [x] R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys;c:\windows\SYSNATIVE\DRIVERS\ew_usbenumfilter.sys [x] R3 FscEfDmi;FscEfDmi;c:\windows\system32\DRIVERS\FscEfDmi.sys;c:\windows\SYSNATIVE\DRIVERS\FscEfDmi.sys [x] R3 FscGabi;FscGabi;c:\windows\system32\DRIVERS\FscGabi.sys;c:\windows\SYSNATIVE\DRIVERS\FscGabi.sys [x] R3 hcw17bda;Hauppauge SMS1000-based;c:\windows\system32\drivers\hcw17b64.sys;c:\windows\SYSNATIVE\drivers\hcw17b64.sys [x] R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jucdcacm.sys [x] R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jubusenum.sys [x] R3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\system32\DRIVERS\ew_juextctrl.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juextctrl.sys [x] R3 huawei_wwanecm;huawei_wwanecm;c:\windows\system32\DRIVERS\ew_juwwanecm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juwwanecm.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys;c:\windows\SYSNATIVE\drivers\intelaud.sys [x] R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x] R3 LVUVC64;Logitech Webcam Pro 9000(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 O2MDFRDR;O2MDFRDR;c:\windows\system32\drivers\O2MDFw7x64.sys;c:\windows\SYSNATIVE\drivers\O2MDFw7x64.sys [x] R3 RDID1009;UM-1;c:\windows\system32\Drivers\rdwm1009.sys;c:\windows\SYSNATIVE\Drivers\rdwm1009.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 swg3kflt00;Sierra Wireless USB Composite Device Filter Driver 00;c:\windows\system32\DRIVERS\swg3kflt00.sys;c:\windows\SYSNATIVE\DRIVERS\swg3kflt00.sys [x] R3 swg3kmbb00;Sierra Wireless QMI USB-NDIS 6.20 miniport;c:\windows\system32\DRIVERS\swg3kmbb00.sys;c:\windows\SYSNATIVE\DRIVERS\swg3kmbb00.sys [x] R3 swg3knmea00;Sierra Wireless QMI NMEA Serial Communication;c:\windows\system32\DRIVERS\swg3knmea00.sys;c:\windows\SYSNATIVE\DRIVERS\swg3knmea00.sys [x] R3 swg3kser00;Sierra Wireless QMI USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\swg3kser00.sys;c:\windows\SYSNATIVE\DRIVERS\swg3kser00.sys [x] R3 swibus00;Sierra Wireless Bus Enumerator 00;c:\windows\system32\DRIVERS\swibus00.sys;c:\windows\SYSNATIVE\DRIVERS\swibus00.sys [x] R3 swibusflt00;Sierra Wireless Bus Enumerator Filter 00;c:\windows\system32\DRIVERS\swibusflt00.sys;c:\windows\SYSNATIVE\DRIVERS\swibusflt00.sys [x] R3 TelekomNM6;Telekom Netzmanager Packet Filter Driver;c:\program files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys;c:\program files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 ubloxVcp;u-blox Virtual COM port driver;c:\windows\system32\DRIVERS\ubloxVcp.sys;c:\windows\SYSNATIVE\DRIVERS\ubloxVcp.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 klflt;klflt;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x] S0 FBIOSDRV;Fujitsu BIOS Driver;c:\windows\System32\Drivers\FBIOSDRV.sys;c:\windows\SYSNATIVE\Drivers\FBIOSDRV.sys [x] S0 FJGSDisk;G-Sensor Application Filter Driver;c:\windows\system32\DRIVERS\FJGSDisk.sys;c:\windows\SYSNATIVE\DRIVERS\FJGSDisk.sys [x] S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys;c:\windows\SYSNATIVE\DRIVERS\fltsrv.sys [x] S0 tib;Acronis TIB Manager;c:\windows\system32\DRIVERS\tib.sys;c:\windows\SYSNATIVE\DRIVERS\tib.sys [x] S0 tib_mounter;Acronis TIB Mounter;c:\windows\system32\DRIVERS\tib_mounter.sys;c:\windows\SYSNATIVE\DRIVERS\tib_mounter.sys [x] S0 vididr;Acronis Virtual Disk;c:\windows\system32\DRIVERS\vididr.sys;c:\windows\SYSNATIVE\DRIVERS\vididr.sys [x] S0 vidsflt;Acronis Disk Storage Filter;c:\windows\system32\DRIVERS\vidsflt.sys;c:\windows\SYSNATIVE\DRIVERS\vidsflt.sys [x] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x] S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x] S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x] S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x] S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [x] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x] S2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\ATService.exe;c:\program files\Fingerprint Sensor\ATService.exe [x] S2 BingDesktopUpdate;Bing Desktop Update service;c:\program files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe;c:\program files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [x] S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x] S2 cjpcsc;cyberJack PC/SC COM Service ;c:\windows\SysWOW64\cjpcsc.exe;c:\windows\SysWOW64\cjpcsc.exe [x] S2 HauppaugeTVServer;HauppaugeTVServer;c:\program files (x86)\WinTV\TVServer\HauppaugeTVServer.exe;c:\program files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [x] S2 PFNService;PFNService;c:\program files\Fujitsu\Plugfree NETWORK\PFNService.exe;c:\program files\Fujitsu\Plugfree NETWORK\PFNService.exe [x] S2 PowerSavingUtilityService;PowerSavingUtilityService;c:\program files\Fujitsu\PSUtility\PSUService.exe;c:\program files\Fujitsu\PSUtility\PSUService.exe [x] S2 Sierra Wireless QDL Service;Sierra Wireless QDL Service;c:\program files (x86)\Sierra Wireless Inc\Gobi\QDLService\GobiQDLService.exe;c:\program files (x86)\Sierra Wireless Inc\Gobi\QDLService\GobiQDLService.exe [x] S2 syncagentsrv;Acronis Sync Agent Service;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [x] S2 TabletServiceISD;TabletServiceISD;c:\program files\Tablet\ISD\ISD_Tablet.exe;c:\program files\Tablet\ISD\ISD_Tablet.exe [x] S2 TouchServiceISD;Wacom ISD Touch Service;c:\program files\Tablet\ISD\ISD_TouchService.exe;c:\program files\Tablet\ISD\ISD_TouchService.exe [x] S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x] S3 acpials;ALS Sensor Filter;c:\windows\system32\DRIVERS\acpials.sys;c:\windows\SYSNATIVE\DRIVERS\acpials.sys [x] S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys;c:\windows\SYSNATIVE\DRIVERS\afcdp.sys [x] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x] S3 ATSwpWDF;AuthenTec TruePrint USB Driver;c:\windows\system32\Drivers\ATSwpWDF.sys;c:\windows\SYSNATIVE\Drivers\ATSwpWDF.sys [x] S3 bbcap;bb_capture_driver;c:\windows\system32\DRIVERS\bbcap.sys;c:\windows\SYSNATIVE\DRIVERS\bbcap.sys [x] S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys;c:\windows\SYSNATIVE\drivers\bcbtums.sys [x] S3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys;c:\windows\SYSNATIVE\DRIVERS\btwampfl.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x] S3 Fjbtndrv;Fujitsu Button Driver;c:\windows\system32\drivers\FjBtnDrv.sys;c:\windows\SYSNATIVE\drivers\FjBtnDrv.sys [x] S3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\drivers\FUJ02E3.sys;c:\windows\SYSNATIVE\drivers\FUJ02E3.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys;c:\windows\SYSNATIVE\DRIVERS\iwdbus.sys [x] S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x] S3 O2MDRRDR;O2MDRRDR;c:\windows\system32\drivers\O2MDRw7x64.sys;c:\windows\SYSNATIVE\drivers\O2MDRw7x64.sys [x] S3 O2SDJRDR;O2SDJRDR;c:\windows\system32\drivers\o2sdjw7x64.sys;c:\windows\SYSNATIVE\drivers\o2sdjw7x64.sys [x] S3 silabenm;Silicon Labs CP210x USB to UART Bridge Serial Port Enumerator Driver;c:\windows\system32\DRIVERS\silabenm.sys;c:\windows\SYSNATIVE\DRIVERS\silabenm.sys [x] S3 silabser;Silicon Labs CP210x USB to UART Bridge Driver;c:\windows\system32\DRIVERS\silabser.sys;c:\windows\SYSNATIVE\DRIVERS\silabser.sys [x] S3 subvgaproduct64;subvgaproduct64;c:\windows\system32\DRIVERS\subvga64.sys;c:\windows\SYSNATIVE\DRIVERS\subvga64.sys [x] S3 wacomvthid;Virtual Touch Driver;c:\windows\system32\DRIVERS\WacomVTHid.sys;c:\windows\SYSNATIVE\DRIVERS\WacomVTHid.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . Inhalt des "geplante Tasks" Ordners . 2014-11-27 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-29 16:18] . 2014-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-22 15:31] . 2014-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-22 15:31] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2014-08-02 12:14 262344 ----a-w- c:\users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2014-08-02 12:14 262344 ----a-w- c:\users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2014-08-02 12:14 262344 ----a-w- c:\users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"] @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"] @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"] @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"] @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncError] @="{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}" [HKEY_CLASSES_ROOT\CLSID\{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}] 2013-10-01 09:32 2818216 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncInProgress] @="{00F848DC-B1D4-4892-9C25-CAADC86A215D}" [HKEY_CLASSES_ROOT\CLSID\{00F848DC-B1D4-4892-9C25-CAADC86A215D}] 2013-10-01 09:32 2818216 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncOk] @="{71573297-552E-46fc-BE3D-3DFAF88D47B7}" [HKEY_CLASSES_ROOT\CLSID\{71573297-552E-46fc-BE3D-3DFAF88D47B7}] 2013-10-01 09:32 2818216 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATSwpNav"="c:\program files\Fingerprint Sensor\ATSwpNav -run" [X] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-12-07 11663464] "PfNet"="c:\program files\Fujitsu\Plugfree NETWORK\PfNet.exe" [2010-10-07 6311424] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-20 416024] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-20 168216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-20 392472] "FDM7"="c:\program files\Fujitsu\FDM7\FdmDaemon.exe" [2009-10-19 164200] "FjStrtAp"="c:\program files\Fujitsu\Utils\FjStrtAp.exe" [2010-12-01 19800] "LoadFUJ02E3"="c:\program files\Fujitsu\FUJ02E3\FUJ02E3.exe" [2010-06-08 45680] "PSUTility"="c:\program files\Fujitsu\PSUtility\TrayManager.exe" [2010-11-13 199528] "FJBATAID2"="c:\program files\Fujitsu\BatteryAid2\BatteryDaemon.exe" [2010-10-29 124776] "FJAutoR"="c:\program files\Fujitsu\AutoRotation\AutoRotation.exe" [2011-04-22 98664] "Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2013-07-18 519408] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://google.de/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~3\Office10\EXCEL.EXE/3000 IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 192.168.178.1 TCP: Interfaces\{E084680B-75DA-4035-B0D1-AD567EBD036B}: NameServer = 10.74.210.210 10.74.210.211 FF - ProfilePath - c:\users\Helge Hartz\AppData\Roaming\Mozilla\Firefox\Profiles\xltyg14t.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - Google . . ------- Dateityp-Verknüpfung ------- . txtfile="c:\program files (x86)\PSPad editor\PSPad.exe" "%1" . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-SLABCOMM&10C4&EA60 - c:\program files (x86)\Silabs\MCU\DriverUninstall\DriverUninstaller.exe VCP CP210x Cardinal\SLABCOMM&10C4&EA60 AddRemove-VOAProp - c:\windows\system32\tpunins5.exe AddRemove-MyFreeCodec - c:\program files (x86)\MyFree Codec\1.0b beta\uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_239_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_239_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_239_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_239_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.15" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000001 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe c:\program files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe c:\windows\system32\DRIVERS\o2flash.exe c:\program files (x86)\TeamViewer\TeamViewer_Service.exe c:\program files (x86)\WinTV\TVServer\CaptureDLNA.exe c:\program files (x86)\WinTV\TVServer\CaptureDLNA.exe c:\program files (x86)\WinTV\TVServer\CaptureDLNA.exe c:\users\Helge Hartz\AppData\Roaming\Dropbox\bin\Dropbox.exe c:\progra~2\Logitech\UEMUSI~1\server\ueml.exe c:\windows\SysWOW64\RunDll32.exe c:\program files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-11-27 11:33:11 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-11-27 10:32 . Vor Suchlauf: 30 Verzeichnis(se), 303.056.031.744 Bytes frei Nach Suchlauf: 33 Verzeichnis(se), 302.611.333.120 Bytes frei . - - End Of File - - 6D478597E28B83F0BE3A001FF01F1D16 Hab mich an Punkt und Komma gehalten. Nach dem Neustart kam über Combo Fenster eine Plugin-Fehlermeldung. Da ich dachte das Logfile war schon erstellt habe ich "WEITER" gedrückt und ein Windows Plug-in Manager ging auf. Den habe ich dann einfach geschlossen. Dies zur einzigen Anomalie, die im Prozess vorkam. Ich hoffe das File ist trotzdem zu brauchen. Was ist mit der einzigen Fehlermeldung aus der TDSS? Da geht es um einen Virtual COMport. Ich halte das nicht für einen Bug, da ich von der Firma Kenwood solche virtuellen COMports extra installiert habe... Nur zur Info Vielen Dank bis zu dieser Stelle für die Hilfe! LG |
28.11.2014, 08:37 | #11 |
/// the machine /// TB-Ausbilder | Telekom Deutschland - Fake Rechnung 13.11.2014 Deswegen haben wir den Fund von TDSS ja auch in Ruhe gelassen Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.11.2014, 12:32 | #12 |
| Telekom Deutschland - Fake Rechnung 13.11.2014 Falsch Geändert von kein-janer (28.11.2014 um 12:39 Uhr) Grund: Neue Schritte noch nicht eingearbeitet |
28.11.2014, 14:20 | #13 |
| Telekom Deutschland - Fake Rechnung 13.11.2014 Falsch So, jetzt gilt es. Alles durchlaufen. MBAM hatte wohl 6 Beanstandungen!? Jedenfalls habe ich wie instruiert nur das txt erstellt. Anbei die Resultate, wiederum mit großen Dank für 's Engagement! LG Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 28.11.2014 Scan Time: 13:08:38 Logfile: mbam.txt Administrator: Yes Version: 2.00.3.1025 Malware Database: v2014.11.28.04 Rootkit Database: v2014.11.22.01 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: Helge Hartz Scan Type: Threat Scan Result: Completed Objects Scanned: 357741 Time Elapsed: 7 min, 48 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 4 PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, , [67bdfa475824a0969cc8be04837f6e92], PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, , [bd67ba87aece310533760e4b72914db3], PUP.Optional.Softonic.A, HKU\S-1-5-21-4011218287-2957974095-3496630771-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [40e4b58c116b81b5fbf4bcb161a246ba], PUP.Optional.SystemSpeedup, HKU\S-1-5-21-4011218287-2957974095-3496630771-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, , [e341df62abd191a5abfd2039ab589a66], Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 2 PUP.Optional.Softonic, C:\ProgramData\VirtualWifiRouter\newVersion.txt, , [978d162b9fdd8da992797ca4976aee12], PUP.Optional.RegCleanPro, C:\Windows\System32\roboot64.exe, , [8b99e160a8d43ef8bfd7ceea45bc30d0], Physical Sectors: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v4.102 - Bericht erstellt am 28/11/2014 um 14:03:57 # Aktualisiert 23/11/2014 von Xplode # Database : 2014-11-27.1 [Live] # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Helge Hartz - NAVIGATOR # Gestartet von : C:\Users\Helge Hartz\Desktop\AdwCleaner_4.102.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Helge Hartz\AppData\Local\PackageAware Ordner Gelöscht : C:\Users\Helge Hartz\AppData\Roaming\DriverTurbo Datei Gelöscht : C:\Windows\System32\roboot64.exe ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Schlüssel Gelöscht : HKCU\Software\BI Schlüssel Gelöscht : HKCU\Software\Myfree Codec Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\systweak Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\lyricspal Schlüssel Gelöscht : HKLM\SOFTWARE\Myfree Codec Schlüssel Gelöscht : HKLM\SOFTWARE\systweak ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17420 -\\ Mozilla Firefox v33.1 (x86 de) ************************* AdwCleaner[R0].txt - [3071 octets] - [28/11/2014 13:48:19] AdwCleaner[S0].txt - [2732 octets] - [28/11/2014 14:03:57] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2792 octets] ########## JRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.3.9 (11.15.2014:2) OS: Windows 7 Professional x64 Ran by Helge Hartz on 28.11.2014 at 14:07:06,19 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Helge Hartz\AppData\Roaming\mozilla\firefox\profiles\xltyg14t.default\minidumps [538 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 28.11.2014 at 14:11:20,91 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-11-2014 01 Ran by Helge Hartz (administrator) on NAVIGATOR on 28-11-2014 14:13:56 Running from C:\Users\Helge Hartz\Desktop Loaded Profile: Helge Hartz (Available profiles: Helge Hartz) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AuthenTec, Inc.) C:\Program Files\Fingerprint Sensor\ATService.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_TouchService.exe (Wacom Technology, Inc) C:\Program Files\Tablet\CalibrationAssistant.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_TouchUser.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe (Hauppauge Computer Works) C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\BatteryAid2\BatteryDaemon.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\AutoRotation\AutoRotation.exe (AuthenTec, Inc.) C:\Program Files\Fingerprint Sensor\ATSwpNav.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Fujitsu Computer Systems Corporation) C:\Program Files\Fujitsu\Utils\FjDspMon.exe (Fujitsu Computer Systems Corporation) C:\Program Files\Fujitsu\Utils\FjEvents.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Fujitsu Computer Systems) C:\Program Files\Fujitsu\Utils\FjLidMon.exe (Fujitsu America, Inc.) C:\Program Files\Fujitsu\Utils\FjMnuIco.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\UE Music Library\UEMLTray.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Hauppauge Computer Works, Inc.) C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe (Dropbox, Inc.) C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\Dropbox.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\PointingDeviceUtility\FJPDAutoSet.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Fujitsu Technology Solutions) C:\Fujitsu\Programs\DeskUpdate\DeskUpdateNotifier.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (O2Micro International) C:\Windows\System32\drivers\o2flash.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\UE Music Library\server\ueml.exe (Sierra Wireless, Inc.) C:\Program Files (x86)\Sierra Wireless Inc\Gobi\QDLService\GobiQDLService.exe (Hauppauge Computer Works) C:\Program Files (x86)\WinTV\TVServer\CaptureDLNA.exe (Hauppauge Computer Works) C:\Program Files (x86)\WinTV\TVServer\CaptureDLNA.exe (Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE (Hauppauge Computer Works) C:\Program Files (x86)\WinTV\TVServer\CaptureDLNA.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_Tablet.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_TabletUser.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_Tablet.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-03] (Synaptics Incorporated) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11663464 2010-12-07] (Realtek Semiconductor) HKLM\...\Run: [PfNet] => C:\Program Files\Fujitsu\Plugfree NETWORK\PfNet.exe [6311424 2010-10-07] (FUJITSU LIMITED) HKLM\...\Run: [FDM7] => C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe [164200 2009-10-19] (FUJITSU LIMITED) HKLM\...\Run: [FjStrtAp] => C:\Program Files\Fujitsu\Utils\FjStrtAp.exe [19800 2010-12-01] (Fujitsu America, Inc..) HKLM\...\Run: [LoadFUJ02E3] => C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [45680 2010-06-08] (FUJITSU LIMITED) HKLM\...\Run: [PSUTility] => C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [199528 2010-11-13] (FUJITSU LIMITED) HKLM\...\Run: [FJBATAID2] => C:\Program Files\Fujitsu\BatteryAid2\BatteryDaemon.exe [124776 2010-10-30] (FUJITSU LIMITED) HKLM\...\Run: [FJAutoR] => C:\Program Files\Fujitsu\AutoRotation\AutoRotation.exe [98664 2011-04-22] (FUJITSU LIMITED) HKLM\...\Run: [ATSwpNav] => "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [519408 2013-07-18] (Acronis) HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [StartFujitsuPointingDeviceUtility] => C:\Program Files (x86)\Fujitsu\PointingDeviceUtility\FJPDAutoSet.exe [85104 2011-02-02] (FUJITSU LIMITED) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-02-01] (Intel Corporation) HKLM-x32\...\Run: [IndicatorUtility] => C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [48752 2010-09-30] (FUJITSU LIMITED) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [7843744 2014-02-04] (Acronis) HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1104616 2013-10-10] (Acronis International GmbH) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [DeskUpdateNotifier] => c:\Fujitsu\Programs\DeskUpdate\DeskUpdateNotifier.exe [101728 2013-12-11] (Fujitsu Technology Solutions) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\Run: [ccleaner] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd) HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1562264 2014-07-25] (Samsung) HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoStart IR.lnk ShortcutTarget: AutoStart IR.lnk -> C:\Program Files (x86)\WinTV\Ir.exe (Hauppauge Computer Works) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UE Music Library-Taskleisten-Tool.lnk ShortcutTarget: UE Music Library-Taskleisten-Tool.lnk -> C:\Program Files (x86)\Logitech\UE Music Library\UEMLTray.exe (Logitech Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinTV Recording Status.lnk ShortcutTarget: WinTV Recording Status.lnk -> C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe (Hauppauge Computer Works, Inc.) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk ShortcutTarget: LaunchCenter.lnk -> C:\Program Files\Fujitsu\LaunchCenter\lcStarter.exe (Fujitsu Technology Solutions) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk ShortcutTarget: LaunchCenter.lnk -> C:\Program Files\Fujitsu\LaunchCenter\lcStarter.exe (Fujitsu Technology Solutions) Startup: C:\Users\Helge Hartz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll () ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll () ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/ HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=FTSG&bmod=FTSG HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000 -> DefaultScope {6ECB67EF-A2FD-472D-B996-DF36EB8CA573} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000 -> {6ECB67EF-A2FD-472D-B996-DF36EB8CA573} URL = https://www.google.com/search?q={searchTerms} BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: AusweisApp 1.12.0.0 -> {C9EE92B7-EDD5-4ad9-8029-2EC6818E653A} -> C:\Program Files (x86)\AusweisApp\siqeCardClientIE64.ols (OpenLimit SignCubes AG) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: HKLM-x32 {FC11A119-C2F7-46F4-9E32-937ABA26816E} file:///E:/CDVIEWER/CdViewer.cab Handler-x32: http - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler-x32: x-mem1 - {C3719F83-7EF8-4BA0-89B0-3360C7AFB7CC} - C:\Windows\SysWow64\wowctl2.dll (EzTools Software) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{E084680B-75DA-4035-B0D1-AD567EBD036B}: [NameServer] 10.74.210.210 10.74.210.211 FireFox: ======== FF ProfilePath: C:\Users\Helge Hartz\AppData\Roaming\Mozilla\Firefox\Profiles\xltyg14t.default FF SelectedSearchEngine: Google FF Homepage: Google FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @reiner-sct.com/OWOK,version=2.0.0.4 -> C:\Program Files (x86)\REINER SCT\OWOK\NPAPI-20\nprsct_owok_npapi-2004.dll (REINER Kartengeräte GmbH und Co. KG.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Helge Hartz\AppData\Roaming\Mozilla\Firefox\Profiles\xltyg14t.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Helge Hartz\AppData\Roaming\Mozilla\Firefox\Profiles\xltyg14t.default\searchplugins\google-maps.xml FF SearchPlugin: C:\Users\Helge Hartz\AppData\Roaming\Mozilla\Firefox\Profiles\xltyg14t.default\searchplugins\youtube-ssl-de.xml FF Extension: FRITZ!Box AddOn - C:\Users\Helge Hartz\AppData\Roaming\Mozilla\Firefox\Profiles\xltyg14t.default\Extensions\fb_add_on@avm.de [2014-11-26] FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [{4F3D26C8-9907-48ff-BC74-B8C572D317BF}] - C:\Program Files (x86)\AusweisApp\mozilla\eCardClientExt_FFxx_Win FF Extension: AusweisApp - C:\Program Files (x86)\AusweisApp\mozilla\eCardClientExt_FFxx_Win [2014-06-18] FF HKLM-x32\...\Firefox\Extensions: [{4F0963A3-1658-4fde-9585-23A25CC288BF}] - C:\Program Files (x86)\AusweisApp\mozilla\eCardClientPIn_FFxx_Win FF Extension: AusweisApp - C:\Program Files (x86)\AusweisApp\mozilla\eCardClientPIn_FFxx_Win [2014-06-18] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-08-22] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-08-22] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-08-22] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-08-22] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-08-22] FF Extension: No Name - {4F0963A3-1658-4fde-9585-23A25CC288BF} [Not Found] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-20] (Microsoft Corp.) R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [514128 2012-03-19] (REINER SCT) R2 HauppaugeTVServer; C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [579584 2014-02-14] (Hauppauge Computer Works) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed] R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272688 2012-08-23] () R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed] R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [331776 2010-10-07] (FUJITSU LIMITED) [File not signed] R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63336 2010-06-17] (FUJITSU LIMITED) R2 Sierra Wireless QDL Service; C:\Program Files (x86)\Sierra Wireless Inc\Gobi\QDLService\GobiQDLService.exe [308592 2011-02-16] (Sierra Wireless, Inc.) R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation) R2 TabletServiceISD; C:\Program Files\Tablet\ISD\ISD_Tablet.exe [5640048 2011-02-23] (Wacom Technology, Corp.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5405456 2014-11-12] (TeamViewer GmbH) S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation) R2 TouchServiceISD; C:\Program Files\Tablet\ISD\ISD_TouchService.exe [449904 2011-02-23] (Wacom Technology, Corp.) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3342640 2012-08-23] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 AVMAP_CP_amd64; C:\Windows\System32\Drivers\avmcpx64.sys [22528 2007-11-23] (AvMap) R3 bbcap; C:\Windows\System32\DRIVERS\bbcap.sys [4608 2012-10-10] (Windows (R) Codename Longhorn DDK provider) R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [131112 2010-10-04] (Broadcom Corporation.) S3 cjusb; C:\Windows\System32\DRIVERS\cjusb.sys [34672 2011-03-29] (REINER SCT) R0 FBIOSDRV; C:\Windows\System32\Drivers\FBIOSDRV.sys [21104 2009-06-24] (FUJITSU LIMITED) R3 Fjbtndrv; C:\Windows\system32\drivers\FjBtnDrv.sys [23040 2009-08-27] (Fujitsu America, Inc.) R0 FJGSDisk; C:\Windows\System32\DRIVERS\FJGSDisk.sys [15208 2012-05-22] (FUJITSU LIMITED) S3 FscEfDmi; C:\Windows\System32\DRIVERS\FscEfDmi.sys [25416 2012-10-31] (Fujitsu Technology Solutions) S3 FscGabi; C:\Windows\System32\DRIVERS\FscGabi.sys [29512 2012-10-31] (Fujitsu Technology Solutions) R3 FUJ02B1; C:\Windows\system32\drivers\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED) R3 FUJ02E3; C:\Windows\system32\drivers\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED) R3 guardian2; C:\Windows\System32\Drivers\oz776x64.sys [85736 2010-08-06] (O2Micro) S3 hcw17bda; C:\Windows\System32\drivers\hcw17b64.sys [78192 2012-10-23] (Hauppauge Computer Works, Inc.) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-08-22] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-08-22] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-08-22] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-08-22] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-08-22] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-11-28] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation) S3 RDID1009; C:\Windows\System32\Drivers\rdwm1009.sys [81920 2012-05-23] (Roland Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1801216 2010-10-09] () R3 subvgaproduct64; C:\Windows\System32\DRIVERS\subvga64.sys [5120 2014-05-26] (Windows (R) Win 7 DDK provider) S3 swg3kflt00; C:\Windows\System32\DRIVERS\swg3kflt00.sys [34304 2011-02-04] (Sierra Wireless Incorporated) S3 swg3kmbb00; C:\Windows\System32\DRIVERS\swg3kmbb00.sys [424448 2011-02-04] (Sierra Wireless Incorporated) S3 swg3knmea00; C:\Windows\System32\DRIVERS\swg3knmea00.sys [256384 2011-02-04] (Sierra Wireless Incorporated) S3 swg3kser00; C:\Windows\System32\DRIVERS\swg3kser00.sys [256384 2011-02-04] (Sierra Wireless Incorporated) S3 swibus00; C:\Windows\System32\DRIVERS\swibus00.sys [73216 2011-02-04] (Sierra Wireless Inc.) S3 swibusflt00; C:\Windows\System32\DRIVERS\swibusflt00.sys [73216 2011-02-04] (Sierra Wireless Inc.) S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2013-12-17] (Acronis International GmbH) R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [198432 2013-12-17] (Acronis International GmbH) S3 ubloxVcp; C:\Windows\System32\DRIVERS\ubloxVcp.sys [60416 2012-04-18] (u-blox) [File not signed] S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed] R0 vidsflt; C:\Windows\System32\DRIVERS\vidsflt.sys [117024 2013-12-17] (Acronis International GmbH) R3 wacomvthid; C:\Windows\System32\DRIVERS\WacomVTHid.sys [16368 2010-12-02] (Wacom Technology) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X] S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X] S1 hwinterface; System32\Drivers\hwinterface.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-28 14:13 - 2014-11-28 14:14 - 00033311 _____ () C:\Users\Helge Hartz\Desktop\FRST.txt 2014-11-28 14:13 - 2014-11-28 12:22 - 02117632 _____ (Farbar) C:\Users\Helge Hartz\Desktop\FRST64.exe 2014-11-28 14:11 - 2014-11-28 14:11 - 00000770 _____ () C:\Users\Helge Hartz\Desktop\JRT.txt 2014-11-28 14:07 - 2014-11-28 14:08 - 00006025 _____ () C:\Windows\WindowsUpdate.log 2014-11-28 14:05 - 2014-11-28 14:05 - 00002884 _____ () C:\Users\Helge Hartz\Desktop\AdwCleaner[S0].txt 2014-11-28 13:48 - 2014-11-28 14:03 - 00000000 ____D () C:\AdwCleaner 2014-11-28 13:20 - 2014-11-28 13:20 - 00001863 _____ () C:\Users\Helge Hartz\Desktop\mbam.txt 2014-11-28 13:08 - 2014-11-28 14:05 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-11-28 13:07 - 2014-11-28 13:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-11-28 13:07 - 2014-11-28 13:07 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-11-28 13:07 - 2014-11-28 13:07 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-11-28 13:07 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-11-28 13:07 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-11-28 13:07 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-11-28 11:28 - 2014-11-28 11:28 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014084_2.tmp 2014-11-28 10:16 - 2014-11-28 10:16 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017852_1.tmp 2014-11-28 10:16 - 2014-11-28 10:16 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012908_2.tmp 2014-11-28 10:11 - 2014-11-28 10:11 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012196_2.tmp 2014-11-28 08:45 - 2014-11-28 08:45 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018208_1.tmp 2014-11-28 08:13 - 2014-11-28 08:13 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017136_2.tmp 2014-11-28 07:50 - 2014-11-28 07:50 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019088_1.tmp 2014-11-28 07:48 - 2014-11-28 07:48 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015960_1.tmp 2014-11-27 10:48 - 2014-11-27 11:35 - 00000000 ____D () C:\Qoobox 2014-11-27 10:48 - 2014-11-27 11:22 - 00000000 ____D () C:\Windows\erdnt 2014-11-27 10:48 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-11-27 10:48 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-11-27 10:48 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-11-27 10:48 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-11-27 10:48 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-11-27 10:48 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-11-27 10:48 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-11-27 10:48 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-11-26 14:09 - 2014-11-26 14:09 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018368_1.tmp 2014-11-26 14:07 - 2014-11-26 14:07 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014744_1.tmp 2014-11-26 14:05 - 2014-11-26 14:05 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016796_2.tmp 2014-11-25 12:14 - 2014-11-25 12:14 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016048_1.tmp 2014-11-25 11:23 - 2014-11-25 11:23 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte 2014-11-25 11:08 - 2014-11-28 14:13 - 00000000 ____D () C:\FRST 2014-11-25 11:07 - 2014-11-25 11:07 - 00000000 _____ () C:\Users\Helge Hartz\defogger_reenable 2014-11-23 17:31 - 2014-11-23 17:31 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017356_3.tmp 2014-11-23 12:41 - 2014-11-23 12:41 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014620_2.tmp 2014-11-22 22:22 - 2014-11-22 22:22 - 00000000 ____D () C:\Windows\ERUNT 2014-11-22 21:39 - 2014-11-22 21:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ITS HF Propagation 2014-11-22 16:46 - 2014-11-22 16:46 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Assimil_d_se 2014-11-22 10:56 - 2011-05-13 11:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll 2014-11-22 10:56 - 2011-03-25 19:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll 2014-11-21 11:06 - 2014-11-21 11:06 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RouteConverter 2014-11-21 11:06 - 2014-11-21 11:06 - 00000000 ____D () C:\Users\Helge Hartz\.routeconverter 2014-11-21 07:54 - 2014-11-21 07:54 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017452_1.tmp 2014-11-21 07:50 - 2014-11-21 07:50 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014576_2.tmp 2014-11-20 10:18 - 2014-11-20 10:40 - 00000000 ____D () C:\Users\Helge Hartz\Wirtschaft 2014-11-19 17:43 - 2014-11-19 17:43 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014932_2.tmp 2014-11-19 17:08 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-19 17:08 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-19 17:08 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-11-19 17:08 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2014-11-17 08:32 - 2014-11-17 08:32 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011188_1.tmp 2014-11-17 08:31 - 2014-11-17 08:31 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017440_1.tmp 2014-11-17 08:30 - 2014-11-17 08:30 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018864_1.tmp 2014-11-17 07:54 - 2014-11-17 07:54 - 00000000 ____D () C:\Program Files (x86)\CHIRP 2014-11-17 07:44 - 2014-11-17 07:45 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\CHIRP 2014-11-17 07:41 - 2014-11-17 07:41 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CHIRP 2014-11-17 07:41 - 2014-11-17 07:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIRP 2014-11-14 17:28 - 2014-11-14 17:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UE Music Library 2014-11-12 14:37 - 2014-11-12 14:37 - 00000000 __SHD () C:\Users\Helge Hartz\AppData\Local\EmieBrowserModeList 2014-11-12 12:16 - 2014-11-07 20:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-11-12 12:16 - 2014-11-07 20:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-11-12 12:16 - 2014-11-06 05:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-11-12 12:16 - 2014-11-06 05:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-11-12 12:16 - 2014-11-06 05:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-11-12 12:16 - 2014-11-06 04:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-11-12 12:16 - 2014-11-06 04:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-11-12 12:16 - 2014-11-06 04:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-11-12 12:16 - 2014-11-06 04:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-11-12 12:16 - 2014-11-06 04:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-11-12 12:16 - 2014-11-06 04:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-11-12 12:16 - 2014-11-06 04:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-11-12 12:16 - 2014-11-06 04:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-11-12 12:16 - 2014-11-06 04:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-11-12 12:16 - 2014-11-06 04:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-11-12 12:16 - 2014-11-06 04:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-11-12 12:16 - 2014-11-06 04:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-11-12 12:16 - 2014-11-06 04:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-11-12 12:16 - 2014-11-06 04:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-11-12 12:16 - 2014-11-06 04:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-11-12 12:16 - 2014-11-06 04:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-11-12 12:16 - 2014-11-06 04:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-11-12 12:16 - 2014-11-06 04:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-11-12 12:16 - 2014-11-06 04:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-11-12 12:16 - 2014-11-06 04:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-11-12 12:16 - 2014-11-06 04:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-11-12 12:16 - 2014-11-06 04:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-11-12 12:16 - 2014-11-06 04:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-11-12 12:16 - 2014-11-06 04:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-11-12 12:16 - 2014-11-06 04:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-11-12 12:16 - 2014-11-06 04:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-11-12 12:16 - 2014-11-06 04:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-11-12 12:16 - 2014-11-06 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-11-12 12:16 - 2014-11-06 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-11-12 12:16 - 2014-11-06 03:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-11-12 12:16 - 2014-11-06 03:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-11-12 12:16 - 2014-11-06 03:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-11-12 12:16 - 2014-11-06 03:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-11-12 12:16 - 2014-11-06 03:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-11-12 12:16 - 2014-11-06 03:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-11-12 12:16 - 2014-11-06 03:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-11-12 12:16 - 2014-11-06 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-11-12 12:16 - 2014-11-06 03:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-11-12 12:16 - 2014-11-06 03:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-11-12 12:16 - 2014-11-06 03:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-11-12 12:16 - 2014-11-06 03:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-11-12 12:16 - 2014-11-06 03:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-11-12 12:16 - 2014-11-06 03:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-11-12 12:16 - 2014-11-06 03:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-11-12 12:16 - 2014-11-06 03:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-11-12 12:16 - 2014-11-06 03:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-11-12 12:16 - 2014-11-06 03:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-11-12 12:16 - 2014-11-06 02:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-11-12 12:16 - 2014-11-06 02:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-11-12 12:16 - 2014-11-06 02:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-11-12 12:16 - 2014-11-06 02:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-11-12 12:08 - 2014-11-05 18:56 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-11-12 12:08 - 2014-11-05 18:56 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-11-12 12:08 - 2014-11-05 18:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-11-12 12:08 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-12 12:08 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-11-12 12:08 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-12 12:08 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2014-11-12 12:08 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-12 12:08 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-11-12 12:08 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-11-12 12:08 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-12 12:08 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-12 12:08 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-12 12:08 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-11-12 12:08 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-11-12 12:08 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-11-12 12:08 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2014-11-12 12:08 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2014-11-12 12:08 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-12 12:08 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-12 12:08 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-12 12:08 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-11-12 12:08 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-11-12 12:08 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-12 12:08 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2014-11-12 12:08 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2014-11-12 12:08 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2014-11-12 12:08 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-12 12:08 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-11-12 12:08 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-11-12 12:08 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-11-12 12:08 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-11-12 12:08 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-11-12 12:08 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-11-12 12:08 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-11-12 12:08 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2014-11-12 12:08 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-11-12 12:08 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-11-12 12:08 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-11-12 12:08 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-11-12 12:08 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-11-12 12:08 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-11-12 12:08 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-11-12 12:08 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-11-12 12:08 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL 2014-11-11 17:21 - 2014-11-14 18:08 - 00000995 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2014-11-10 17:26 - 2014-11-23 17:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-11-10 10:21 - 2014-11-10 10:21 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012176_3.tmp 2014-11-10 10:19 - 2014-11-10 10:19 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016664_2.tmp 2014-11-10 10:17 - 2014-11-10 10:17 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011316_3.tmp 2014-11-09 12:16 - 2014-11-09 12:16 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018796_2.tmp 2014-11-09 12:13 - 2014-11-09 12:13 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018684_2.tmp 2014-11-09 12:13 - 2014-11-09 12:13 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017920_3.tmp 2014-11-09 12:12 - 2014-11-09 12:12 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018588_4.tmp 2014-11-09 12:12 - 2014-11-09 12:12 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018576_1.tmp 2014-11-09 12:11 - 2014-11-09 12:11 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014564_1.tmp 2014-11-09 12:10 - 2014-11-09 12:10 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018808_2.tmp 2014-11-09 12:07 - 2014-11-09 12:07 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon080901796_1.tmp 2014-11-09 12:04 - 2014-11-09 12:04 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018772_2.tmp 2014-11-09 12:03 - 2014-11-09 12:03 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018704_3.tmp 2014-11-09 12:02 - 2014-11-09 12:02 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017220_2.tmp 2014-11-09 12:02 - 2014-11-09 12:02 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014308_1.tmp 2014-11-09 11:59 - 2014-11-09 11:59 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015744_2.tmp 2014-11-09 11:57 - 2014-11-09 11:57 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019056_2.tmp 2014-11-09 11:57 - 2014-11-09 11:57 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017080_2.tmp 2014-11-09 11:56 - 2014-11-09 11:56 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016308_1.tmp 2014-11-09 11:55 - 2014-11-09 11:55 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015628_1.tmp 2014-11-09 11:35 - 2014-11-09 11:35 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018484_1.tmp 2014-11-09 10:23 - 2014-11-09 10:23 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017420_1.tmp 2014-11-09 10:21 - 2014-11-09 10:21 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012684_2.tmp 2014-11-09 10:19 - 2014-11-09 10:19 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018176_3.tmp 2014-11-09 10:17 - 2014-11-09 10:17 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017900_1.tmp 2014-11-09 10:17 - 2014-11-09 10:17 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016192_1.tmp 2014-11-09 09:57 - 2014-11-09 09:57 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017084_1.tmp 2014-11-04 16:19 - 2014-11-04 16:19 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019964_1.tmp 2014-11-04 16:19 - 2014-11-04 16:19 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014324_1.tmp 2014-11-02 11:09 - 2014-11-02 11:09 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016944_3.tmp 2014-11-02 10:53 - 2014-11-03 09:27 - 00000000 ____D () C:\metar2aprsobj 2014-11-01 16:05 - 2014-11-01 16:05 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019656_1.tmp 2014-11-01 14:34 - 2014-11-01 14:34 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014968_2.tmp 2014-11-01 14:34 - 2014-11-01 14:34 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011988_2.tmp 2014-11-01 14:33 - 2014-11-01 14:33 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017428_3.tmp 2014-10-31 20:51 - 2014-10-31 20:51 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-10-31 19:38 - 2014-10-31 19:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CS-5100 2014-10-31 19:17 - 2014-10-31 19:17 - 10485760 _____ () C:\vgaexte.dat 2014-10-31 11:01 - 2014-10-31 11:00 - 00079360 _____ (Silicon Laboratories) C:\Windows\system32\Drivers\silabser.sys 2014-10-31 11:01 - 2014-10-31 11:00 - 00023552 _____ (Silicon Laboratories) C:\Windows\system32\Drivers\silabenm.sys 2014-10-31 07:43 - 2014-10-31 07:43 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017612_3.tmp 2014-10-31 07:42 - 2014-10-31 07:42 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012348_1.tmp 2014-10-30 14:46 - 2014-10-30 14:46 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018688_2.tmp 2014-10-30 14:45 - 2014-10-30 14:45 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017348_3.tmp 2014-10-30 14:37 - 2014-10-30 14:37 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018768_1.tmp 2014-10-30 14:33 - 2014-10-30 14:33 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019092_2.tmp 2014-10-30 14:33 - 2014-10-30 14:33 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017296_3.tmp 2014-10-30 14:33 - 2014-10-30 14:33 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011424_1.tmp 2014-10-30 14:29 - 2014-10-30 14:29 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016032_2.tmp 2014-10-30 14:19 - 2014-10-30 14:19 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016064_1.tmp 2014-10-30 14:18 - 2014-10-30 14:18 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013648_2.tmp 2014-10-30 14:16 - 2014-10-30 14:16 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014740_1.tmp 2014-10-30 14:16 - 2014-10-30 14:16 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014168_1.tmp 2014-10-30 14:15 - 2014-10-30 14:15 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016988_2.tmp 2014-10-30 14:13 - 2014-10-30 14:13 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809014492_2.tmp 2014-10-30 14:12 - 2014-10-30 14:12 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018780_1.tmp 2014-10-30 14:12 - 2014-10-30 14:12 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018688_1.tmp 2014-10-30 14:06 - 2014-10-30 14:06 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016356_1.tmp 2014-10-30 13:58 - 2014-10-30 13:59 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018624_1.tmp 2014-10-30 13:57 - 2014-10-30 13:57 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019080_2.tmp 2014-10-30 13:42 - 2014-10-30 13:42 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018404_2.tmp 2014-10-30 13:41 - 2014-10-30 13:41 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016724_2.tmp 2014-10-30 13:40 - 2014-10-30 13:40 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809019092_1.tmp 2014-10-30 13:31 - 2014-10-30 13:31 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018040_1.tmp 2014-10-30 08:34 - 2014-10-30 08:34 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016992_1.tmp 2014-10-30 08:34 - 2014-10-30 08:34 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012344_1.tmp 2014-10-30 08:33 - 2014-10-30 08:33 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809018268_3.tmp 2014-10-30 08:28 - 2014-10-30 08:28 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon080901676_1.tmp 2014-10-30 08:26 - 2014-10-30 08:26 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017960_2.tmp 2014-10-30 08:25 - 2014-10-30 08:25 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017648_1.tmp 2014-10-30 08:23 - 2014-10-30 08:23 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016772_2.tmp 2014-10-30 08:13 - 2014-10-30 08:13 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809017872_1.tmp 2014-10-30 08:08 - 2014-10-30 08:08 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012524_1.tmp 2014-10-30 08:01 - 2014-10-30 08:01 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013136_1.tmp 2014-10-30 07:59 - 2014-10-30 07:59 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013724_1.tmp 2014-10-30 07:58 - 2014-10-30 07:58 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015900_1.tmp 2014-10-30 07:58 - 2014-10-30 07:58 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809012008_1.tmp 2014-10-30 07:43 - 2014-10-30 07:43 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809013024_1.tmp 2014-10-30 07:42 - 2014-10-30 07:42 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809016920_1.tmp 2014-10-30 07:39 - 2014-10-30 07:39 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon080901964_2.tmp 2014-10-30 07:37 - 2014-10-30 07:37 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809015400_1.tmp 2014-10-30 07:34 - 2014-10-30 07:34 - 00000520 _____ () C:\Users\Helge Hartz\AppData\Local\TempPSTEMPFILEon0809011668_1.tmp ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-28 14:14 - 2012-05-22 16:31 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-28 14:12 - 2009-07-14 05:45 - 00031536 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-28 14:12 - 2009-07-14 05:45 - 00031536 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-28 14:09 - 2011-04-11 18:26 - 00714458 _____ () C:\Windows\system32\perfh007.dat 2014-11-28 14:09 - 2011-04-11 18:26 - 00154510 _____ () C:\Windows\system32\perfc007.dat 2014-11-28 14:09 - 2009-07-14 06:13 - 01649592 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-28 14:07 - 2014-09-18 14:10 - 00000000 ___RD () C:\Users\Helge Hartz\Sync 2014-11-28 14:05 - 2014-04-05 21:44 - 00000000 ___RD () C:\Users\Helge Hartz\Dropbox 2014-11-28 14:05 - 2014-04-05 21:43 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Dropbox 2014-11-28 14:05 - 2012-10-11 05:21 - 00000031 _____ () C:\Windows\system32\bbcap.err 2014-11-28 14:05 - 2012-05-22 16:31 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-28 14:05 - 2012-05-22 14:09 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-11-28 14:05 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-28 13:18 - 2014-10-21 10:12 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-11-28 12:02 - 2012-05-22 16:10 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\FileZilla 2014-11-28 07:31 - 2012-05-22 14:35 - 00003958 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896} 2014-11-27 13:28 - 2012-12-21 09:20 - 00000000 ____D () C:\Users\Helge Hartz\Documents\SARTrack 2014-11-27 13:27 - 2012-05-22 17:37 - 00000000 ____D () C:\Users\Helge Hartz\Documents\Registry Files Backup 2014-11-27 12:21 - 2012-05-22 19:57 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Skype 2014-11-27 11:04 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-11-26 17:18 - 2014-10-21 10:12 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-11-26 17:18 - 2013-09-29 05:59 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-11-26 17:18 - 2013-09-29 05:59 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-11-26 14:07 - 2012-05-22 16:39 - 00000000 ____D () C:\Users\Helge Hartz\Webseiten 2014-11-25 15:08 - 2012-05-22 18:01 - 00000000 ____D () C:\Program Files (x86)\Kenwood 2014-11-25 11:23 - 2012-05-29 12:04 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Local\CrashDumps 2014-11-25 11:07 - 2012-05-22 12:21 - 00000000 ____D () C:\Users\Helge Hartz 2014-11-25 10:27 - 2012-05-18 22:07 - 00000000 ____D () C:\Users\Helge Hartz\Eigene Programme 2014-11-24 09:39 - 2013-11-22 19:00 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-11-23 09:44 - 2012-05-23 00:22 - 00000000 ____D () C:\Users\Helge Hartz\Administration 2014-11-23 08:44 - 2012-05-22 21:02 - 00000000 ____D () C:\Program Files (x86)\VOAProp 2014-11-22 21:39 - 2012-05-22 21:38 - 00000000 ____D () C:\itshfbc 2014-11-22 16:44 - 2013-09-30 13:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assimil Verlag 2014-11-22 16:37 - 2013-09-30 13:25 - 00000000 ____D () C:\Program Files (x86)\Assimil 2014-11-22 10:10 - 2013-07-08 12:39 - 00000000 ____D () C:\Users\Public\Documents\QV7_Data 2014-11-20 12:29 - 2013-05-12 06:40 - 00000000 ____D () C:\Program Files (x86)\Icom 2014-11-20 12:29 - 2011-05-18 18:44 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-11-19 08:13 - 2014-10-09 19:55 - 00001048 _____ () C:\Users\Helge Hartz\DesktopSARTrack.lnk 2014-11-18 18:52 - 2012-05-22 20:30 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-11-18 08:38 - 2013-07-10 12:19 - 00001096 _____ () C:\Users\Helge Hartz\Desktop\QuoVadis 7.lnk 2014-11-18 08:38 - 2013-07-08 12:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuoVadis 7 2014-11-18 08:38 - 2013-07-08 12:39 - 00000000 ____D () C:\Program Files (x86)\QuoVadis7 2014-11-17 07:39 - 2012-05-22 10:35 - 00000000 ____D () C:\Users\Helge Hartz\Funk 2014-11-15 21:08 - 2012-09-03 21:33 - 00000000 ____D () C:\Windows\Minidump 2014-11-15 08:41 - 2014-04-05 21:43 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-11-14 20:32 - 2014-07-27 09:30 - 00026630 _____ () C:\Users\Helge Hartz\AppData\Roaming\ekiga.conf 2014-11-13 10:48 - 2012-05-23 23:50 - 00065120 _____ () C:\Users\Helge Hartz\AppData\Roaming\GDIPFONTCACHEV1.DAT 2014-11-13 08:09 - 2012-05-22 16:31 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-11-13 08:09 - 2012-05-22 16:31 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-11-12 18:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-11-12 12:21 - 2009-07-14 05:45 - 00298464 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-12 12:20 - 2014-04-26 11:27 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-11-12 12:18 - 2013-07-11 17:49 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-12 12:16 - 2012-05-23 11:20 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-11 17:22 - 2012-05-22 12:21 - 00065120 _____ () C:\Users\Helge Hartz\AppData\Local\GDIPFONTCACHEV1.DAT 2014-11-10 18:03 - 2012-07-21 09:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-11-10 17:02 - 2012-08-29 15:41 - 00000000 ____D () C:\Users\Helge Hartz\AppData\Roaming\Canon 2014-11-10 17:02 - 2012-05-22 21:58 - 00000000 ____D () C:\RMS Express 2014-11-10 17:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2014-11-05 14:58 - 2012-11-11 10:00 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client 2014-11-04 21:40 - 2012-06-09 17:47 - 00000000 ____D () C:\Alpha 2014-11-04 18:23 - 2014-03-04 11:05 - 00000000 ____D () C:\Users\Helge Hartz\Documents\Email 2014-11-04 14:30 - 2010-11-21 04:27 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-11-04 07:43 - 2012-05-22 10:45 - 00000000 ____D () C:\Users\Helge Hartz\Defender 2014-11-02 22:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-10-31 20:51 - 2013-10-15 05:51 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-31 20:51 - 2013-10-15 05:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-31 20:51 - 2012-05-22 17:29 - 00000000 ____D () C:\Program Files (x86)\Java 2014-10-31 18:19 - 2014-08-23 09:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZCast 2014-10-31 18:19 - 2014-08-22 19:05 - 00000000 ____D () C:\Program Files (x86)\EZCast 2014-10-31 11:01 - 2013-05-10 11:34 - 00000000 ____D () C:\Users\Helge Hartz\Eigene Treiber Some content of TEMP: ==================== C:\Users\Helge Hartz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpccw0ax.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-26 17:01 ==================== End Of Log ============================ --- --- --- Geändert von kein-janer (28.11.2014 um 12:40 Uhr) Grund: Neue Schritte noch nicht eingearbeitet |
28.11.2014, 14:22 | #14 |
| Telekom Deutschland - Fake Rechnung 13.11.2014 FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-11-2014 01 Ran by Helge Hartz at 2014-11-28 14:14:19 Running from C:\Users\Helge Hartz\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Kaspersky Internet Security (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Internet Security (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Disabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Acronis True Image 2014 (HKLM-x32\...\{3ECDD663-5AF8-489B-9E3C-561F33A271BD}Visible) (Version: 17.0.6673 - Acronis) Acronis True Image 2014 (x32 Version: 17.0.6673 - Acronis) Hidden Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.9.0.1030 - Adobe Systems Incorporated) Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.239 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated) Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.) Advertising Center (x32 Version: 0.0.0.1 - Nero AG) Hidden Anytime USB Charge Utility (HKLM-x32\...\{549BF60D-FDDA-4E4C-ABE3-9E897BC09E79}) (Version: 1.00.00.001 - FUJITSU LIMITED) Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ArcSoft PhotoStudio 6 (HKLM-x32\...\{ED8EF3C2-FA5B-4A1E-950D-5A0227161F97}) (Version: 6.0.1.134 - ArcSoft) ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.10 - Michael Tippach) Assimil Norwegisch ohne Mühe (HKLM-x32\...\{E4BF3D82-0D8D-460F-9123-554A59DB9253}}_is1) (Version: d_no - Assimil) Assimil Schwedisch ohne Mühe (HKLM-x32\...\{1F75067E-86AE-4C09-AEA9-9EFA9C390B36}}_is1) (Version: d_se - Assimil) AusweisApp (HKLM-x32\...\{BA6CDB7A-F5D7-4341-99E1-1FF0AAEAF1D8}) (Version: 1.13.0 - OpenLimit SignCubes AG) AuthenTec Fingerprint Software (HKLM\...\{5F1DFCC1-595D-4235-A044-E05B706D800A}) (Version: 9.0.8.35 - AuthenTec, Inc.) Auto Rotation Utility (HKLM-x32\...\InstallShield_{9D90DF69-ABFF-4A8D-8B0D-27FA46509DE3}) (Version: 1.01.10.003 - FUJITSU LIMITED) Auto Rotation Utility (Version: 1.01.10.003 - FUJITSU LIMITED) Hidden Avi to Mpeg 3.5 (HKLM-x32\...\{14BF164E-80A4-422E-BE43-39FB759666C2}_is1) (Version: 3.5 - Avi to Mpeg) AvMap USB device driver (HKLM-x32\...\AvMap USB device driver_is1) (Version: 2.2.0.6 - AvMap) Battery Utility (HKLM-x32\...\{1054208F-DD88-43C9-8B3A-CA3D9786E52B}) (Version: 3.01.16.005 - FUJITSU LIMITED) BB FlashBack Express (HKLM-x32\...\BB FlashBack Express) (Version: 4.1.8.2960 - Blueberry) Bing-Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.171.0 - Microsoft Corporation) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - ) Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.) Canon MG5300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5300_series) (Version: - Canon Inc.) Canon MP Navigator EX 2.1 (HKLM-x32\...\MP Navigator EX 2.1) (Version: - ) CanoScan LiDE 700F Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_cnq9601) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.19 - Piriform) CHIRP (HKLM-x32\...\CHIRP) (Version: - ) Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) cyberJack Base Components (HKLM-x32\...\{FC338210-F594-11D3-BA24-00001C3AB4DF}) (Version: 6.10.0 - REINER SCT) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DEM25 Deutschland (HKLM-x32\...\DEM25 Deutschland_is1) (Version: 6 - QuoVadis Software GmbH) DeskUpdate (HKLM-x32\...\DeskUpdate_is1) (Version: 4.15.0134 - Fujitsu Technology Solutions) Deutschland Top25 QV-Map (HKLM-x32\...\Deutschland Top25 QV-Map_is1) (Version: 6 - QuoVadis Software GmbH) Dimension 4 v5.0 (HKLM-x32\...\{935FF092-EEBA-4E97-8C1B-CD2364F392A4}) (Version: 5.0.33 - Thinking Man Software) Dl-Fldigi 3.21.50 (HKLM-x32\...\Dl-Fldigi-3.21.50) (Version: 3.21.50 - Fldigi developers) Dropbox (HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\Dropbox) (Version: 2.10.52 - Dropbox, Inc.) EasyTransfer 5.0. Build 23 (HKLM-x32\...\EasyTransfer_1.0.0) (Version: - ) EchoLink (HKLM-x32\...\{DC33421C-0E1C-470A-BE37-7B7C82677812}) (Version: 2.0.908 - Synergenics, LLC) Ekiga (nur entfernen) (HKLM-x32\...\Ekiga) (Version: - ) ElsterFormular (HKLM-x32\...\ElsterFormular 13.2.0.8623p) (Version: 15.0.13315 - Landesfinanzdirektion Thüringen) Europa West-Ost Here 2014 (HKLM-x32\...\Europa West-Ost Here 2014_is1) (Version: 6 - QuoVadis Software GmbH) EZCast (HKLM-x32\...\{74CECDD9-4B8E-4AE3-9571-8070A17F3C34}) (Version: 1.1.0.130 - Actions-Micro) FileZilla Client 3.9.0.6 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse) FJ Camera (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.52019.0 - Sonix) Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com) Fujitsu Button Utilities (HKLM\...\{207E8B60-07D2-4B7F-97FE-0DA448606861}) (Version: 7.02.0902.2009 - Fujitsu America, Inc.) Fujitsu Display Manager (HKLM-x32\...\InstallShield_{4108974B-DE87-4AD4-9167-930C62C45691}) (Version: - ) Fujitsu Display Manager (Version: 7.01.20.203 - FUJITSU LIMITED) Hidden Fujitsu Hotkey Utility (HKLM-x32\...\InstallShield_{C8E4B31D-337C-483D-822D-16F11441669B}) (Version: 3.70.0.0 - FUJITSU LIMITED) Fujitsu Hotkey Utility (x32 Version: 3.70.0.0 - FUJITSU LIMITED) Hidden Fujitsu MobilityCenter Extension Utility (HKLM-x32\...\InstallShield_{EC314CDF-3521-482B-A21C-65AC95664814}) (Version: 3.01.00.001 - FUJITSU LIMITED) Fujitsu MobilityCenter Extension Utility (Version: 3.01.00.001 - FUJITSU LIMITED) Hidden Fujitsu System Extension Utility (HKLM-x32\...\InstallShield_{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}) (Version: 3.3.0.0 - FUJITSU LIMITED) Fujitsu System Extension Utility (Version: 3.3.0.0 - FUJITSU LIMITED) Hidden Galería de fotos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Galerie de photos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Garmin Training Center (HKLM-x32\...\{50C913B1-A091-48B8-A434-6C9670284888}) (Version: 3.6.5 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries) Geosat MapConverter 1.2 (HKLM-x32\...\Geosat MapConverter) (Version: 1.2 - AvMap) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden GPSBabel 1.4.3 (HKLM-x32\...\{1B8FE958-A304-4902-BF7A-4E2F0F5B7017}_is1) (Version: - GPSBabel) GPS-Format-Konverter V1.23 (HKLM-x32\...\GPS-Format-Konverter_is1) (Version: - ASTR-Software) GTK2-Runtime (HKLM-x32\...\GTK2-Runtime) (Version: 2.22.0-2010-10-21-ash - Alexander Shaduri) Ham CAP 1.80 (HKLM-x32\...\Ham CAP_is1) (Version: - Alex Shovkoplyas, VE3NEA) Hauppauge WinTV 7 (HKLM-x32\...\Hauppauge WinTV 7) (Version: v7.0.32168 (CD 3.5) - Hauppauge Computer Works) Icom CS-5100 (HKLM-x32\...\{440F9936-6D35-459E-A97F-AEF4F9B97481}) (Version: 1.10 - Icom Inc.) Icom USB-to-Serial (HKLM-x32\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.00.000 - Icom) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden Integrity Tool (HKLM-x32\...\{5B37CD1D-1F72-42DD-99B9-9D92FA8C3342}) (Version: 1.10.0 - OpenLimit SignCubes AG) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2372 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\...\{90F00673-A276-4A58-B675-B426D39D1E09}) (Version: 15.3.0.0398 - Intel Corporation) Intel(R) WiDi (HKLM-x32\...\{25680C01-6753-4FE9-A891-7857F26457C1}) (Version: 2.1.35.0 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel® PROSet/Wireless WiFi-Software (HKLM\...\{ECE5B218-A086-4E18-A362-D11181681457}) (Version: 15.03.1000.1637 - Intel Corporation) IonoProbe 1.39 (HKLM-x32\...\IonoProbe_is1) (Version: - Afreet Software, Inc.) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.36 - Irfan Skiljan) ISD Tablet (HKLM\...\ISD Tablet Driver) (Version: 7.0.2-17 - Wacom Technology Corp.) ITS HF Propagation 2014.11.14 (HKLM\...\{1B328085-F1A5-4AB8-8986-0103C5800216}) (Version: 2014.11.14 - US Department of Commerce NTIA/ITS) iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.) IZArc 4.1.8 (HKLM-x32\...\{97C82B44-D408-4F14-9252-47FC1636D23E}_is1) (Version: 4.1.8 - Ivan Zahariev) Japanese Fonts Support For Adobe Reader X (HKLM-x32\...\{AC76BA86-7AD7-5760-0000-A00000000003}) (Version: 10.0.0 - Adobe Systems Incorporated) Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) JOSM 6060 (HKLM-x32\...\OSM) (Version: 6060 - The OpenStreetMap developer community, hxxp://www.openstreetmap.org/) Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Internet Security (x32 Version: 14.0.0.4651 - Kaspersky Lab) Hidden KENWOOD ARCP-480 (HKLM-x32\...\{33E5F114-8272-40F9-AB33-58A39CAA5EC8}) (Version: 1.10.000 - JVC KENWOOD Corporation) Kopplungswerkzeuge für Rapoo-Maus und -Tastatur V3.2 (HKLM-x32\...\{1899FF3C-B115-4C6C-A81A-9F1FBBCEAF36}_is1) (Version: - Rapoo Inc.) Logitech Webcam-Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.31 - Logitech Inc.) Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation) MCP-2A (Remove only) (HKLM-x32\...\{10CA63B1-DEF1-4718-A122-268486A6EF66}) (Version: 3.21.000 - JVC KENWOOD Corporation) MCP-4A (HKLM-x32\...\{4CBC4137-823A-4D3F-ACCA-060C5C1A4D92}) (Version: 1.03.0013 - JVC KENWOOD Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Expression Encoder 4 (HKLM-x32\...\Encoder_4.0.4276.0) (Version: 4.0.4276.0 - Microsoft Corporation) Microsoft Expression Encoder 4 Screen Capture Codec (HKLM-x32\...\{E5AB3F65-7FAC-41C6-B176-7599D2404BB2}) (Version: 4.0.4276.0 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office XP Professional (HKLM-x32\...\{91110407-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) mIRC (HKLM-x32\...\mIRC) (Version: 7.34 - mIRC Co. Ltd.) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 33.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.1 (x86 de)) (Version: 33.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 9 Essentials (HKLM-x32\...\{5fbb433b-7ef0-49ee-8e62-8f9730339edb}) (Version: - Nero AG) Netzmanager (HKLM-x32\...\Netzmanager) (Version: 1.071 - Deutsche Telekom AG) Netzmanager (Version: 1.071 - Deutsche Telekom AG, Marmiko IT-Solutions GmbH) Hidden O2Micro Flash Memory Card Windows Driver (HKLM-x32\...\InstallShield_{5CB9660D-919E-421A-AE17-DD6C925E1AF3}) (Version: 3.1.00.18 - O2Micro International LTD.) O2Micro Flash Memory Card Windows Driver (Version: 3.1.00.18 - O2Micro International LTD.) Hidden O2Micro OZ776 SCR Driver (HKLM-x32\...\InstallShield_{26208444-C11B-4820-B224-7F66549B0E16}) (Version: 2.1.4.210GS - O2Micro) O2Micro OZ776 SCR Driver (Version: 2.1.4.210GS - O2Micro) Hidden Orbitron - Satellite Tracking System (HKLM-x32\...\Orbitron_is1) (Version: 3.71 - Sebastian Stoff) OWOK 2.0.0.4 NPAPI (HKLM-x32\...\OWOK-NPAPI-20) (Version: 2.0.0.4 - REINER Kartengeraete GmbH und Co. KG) Paxon 2.00 (HKLM-x32\...\Paxon) (Version: 2.00 - Ulf Haueisen) PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia) PComm Lite Ver1.6 (HKLM\...\PComm Lite Ver1.6_is1) (Version: - Moxa Inc.) PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.9.3 - pdfforge) Photo Common (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden PL-2303 USB-to-Serial (HKLM-x32\...\{A9111573-EF12-4D80-A5B9-55F620D5BCA1}) (Version: 1.00.000 - Prolific Technology INC) Plugfree NETWORK (HKLM\...\{7BA64D21-EE46-4a9a-8145-52B0175C3F86}) (Version: 5.4.0.1 - FUJITSU LIMITED) Plugfree NETWORK (Version: 5.4.001 - FUJITSU LIMITED) Hidden POIConverter (HKLM-x32\...\POIConverter) (Version: 4.11 - Richard Davies) Pointing Device Utility (HKLM-x32\...\InstallShield_{DDC49774-40B9-47AE-9C63-5569C08C4082}) (Version: 1.0.1.0 - FUJITSU LIMITED) Pointing Device Utility (x32 Version: 1.0.1.0 - FUJITSU LIMITED) Hidden Power Saving Utility (HKLM-x32\...\{49A588CF-5FD4-4774-BFBF-0764287DE82B}) (Version: 32.01.10.016 - FUJITSU LIMITED) PSPad editor (HKLM-x32\...\PSPad editor_is1) (Version: 4.5.7.2450 - Jan Fiala) Python 2.7.3 (64-bit) (HKLM\...\{C0C31BCC-56FB-42a7-8766-D29E1BD74C7d}) (Version: 2.7.3150 - Python Software Foundation) QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) QuoVadis 7 (HKLM-x32\...\QuoVadis 7_is1) (Version: 7 - Flemming Software Development CC) QuoVadis NaviSpeech 7 (HKLM-x32\...\QuoVadis NaviSpeech 7_is1) (Version: 7 - QuoVadis Software GmbH) QuoVadis Ortsdatenbank Welt (HKLM-x32\...\QuoVadis Ortsdatenbank Welt_is1) (Version: 4 - QuoVadis Software GmbH) Raccolta foto (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6263 - Realtek Semiconductor Corp.) RefManager 1.0 (HKLM-x32\...\RefManager_is1) (Version: - Afreet Software, Inc.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden RMS Express (HKLM-x32\...\{93EDD4EF-B076-4625-A497-06803F9F5CD1}) (Version: 1.1.0 - Winlink 2000) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.1.13105_7 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.6.1.13105_7 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.) SARTrack Version 0.9.609 Beta (HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\SARTrack_is1) (Version: 0.9.609 - SARTrack Limited) Security Panel (HKLM-x32\...\InstallShield_{45CA9B23-5EF8-43AA-9851-E9E062BF0147}) (Version: 2.2.0.0 - FUJITSU LIMITED) Security Panel Application (x32 Version: 2.2.0.0 - FUJITSU LIMITED) Hidden Security Panel Application for Supervisor (x32 Version: 2.2.0.0 - FUJITSU LIMITED) Hidden Security Panel for Supervisor (HKLM-x32\...\InstallShield_{17F82182-0E3D-4A14-8843-5ECBFAF4F12F}) (Version: 2.2.0.0 - FUJITSU LIMITED) Sierra Wireless QMI Driver Package (HKLM-x32\...\SWIQMIDrvInstaller) (Version: 1.0.0.9 - Sierra Wireless Inc.) Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM-x32\...\SLABCOMM&10C4&EA60) (Version: - Silicon Laboratories) Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7_2 (c:\SiLabs\MCU\CP210x\Windows_XP_S2K3_Vista_7_2) (HKLM-x32\...\{332D993E-D680-44AA-8A0D-424AA2FE9F8F}) (Version: 6.4 - Silicon Laboratories, Inc.) Skype™ 6.21 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.) Steinberg Cubase LE (HKLM-x32\...\Steinberg Cubase LE) (Version: - ) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.11.1 - Synaptics Incorporated) TCX Converter 2.0.29 (HKLM-x32\...\{9F74B6DE-B89C-4532-AFED-5AB0CCAAC1DF}_is1) (Version: - DDAAXX) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.35436 Beta - TeamViewer) Touch Launcher (HKLM-x32\...\{8A90AF02-C1C3-4489-B60A-902D1AA53D37}) (Version: V1.2L04 - FUJITSU LIMITED) UE Music Library 10.0.4 (HKLM-x32\...\UE Music Library_is1) (Version: 10.0.4 - Logitech) UI-View32 (HKLM-x32\...\UI-View32_is1) (Version: 2.03 - Peak Systems) UM-1-Treiber (HKLM\...\RolandRDID0009) (Version: - Roland Corporation) UZ7HO Soundmodem .41 Beta (HKU\S-1-5-21-4011218287-2957974095-3496630771-1000\...\UZ7HO Soundmodem .41 Beta ) (Version: - ) VOAProp (HKLM-x32\...\VOAProp) (Version: 1.1 - G4ILO Software) Vokabeltrainer Norsk for deg (HKLM-x32\...\de.klett.vokabeltrainer.norskForDeg.640931D04D7FB29612090B9316373CF9A4E7C6C5.1) (Version: 1.0.1 - Ernst Klett Sprachen GmbH) Vokabeltrainer Norsk for deg (x32 Version: 1.0.1 - Ernst Klett Sprachen GmbH) Hidden Wave Editor 3.2.1.0 (HKLM-x32\...\Wave Editor_is1) (Version: 3.2.1.0 - AbyssMedia.com) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.6900 - Broadcom Corporation) Windows Driver Package - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2) (HKLM\...\24DA573F901348FFDFF7717497830D45BE0C362E) (Version: 07/07/2009 1.12.2 - Dynastream Innovations) Windows Driver Package - Fujitsu America, Inc. (FjBtnDrv) HIDClass (08/27/2009 4.2.0827.2009) (HKLM\...\C1556C282D8A9FB37C3F3925E582B76545A344EF) (Version: 08/27/2009 4.2.0827.2009 - Fujitsu America, Inc.) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) (HKLM\...\49CF605F02C7954F4E139D18828DE298CD59217C) (Version: 06/03/2009 2.3.0.0 - Garmin) Windows Driver Package - SCS SCS Driver Package - Bus/D2XX Driver (04/10/2012 2.08.24) (HKLM\...\BC00913D027C41CC21E744CFDA8F3DF6DF45E2CF) (Version: 04/10/2012 2.08.24 - SCS) Windows Driver Package - SCS SCS Driver Package - VCP Driver 1 (04/10/2012 2.08.24) (HKLM\...\7811E449E9CAA643E49707C43F2FAE3A35462D0D) (Version: 04/10/2012 2.08.24 - SCS) Windows Driver Package - SCS SCS Driver Package - VCP Driver 2 (04/10/2012 2.08.24) (HKLM\...\3BFF416D0CF83690179331AC3C8309B77A6D18FA) (Version: 04/10/2012 2.08.24 - SCS) Windows Driver Package - SCS SCS Driver Package - VCP Driver 3 (04/10/2012 2.08.24) (HKLM\...\0B6DDC331557B47917A9CF022C536EA39D735575) (Version: 04/10/2012 2.08.24 - SCS) Windows Driver Package - Silicon Laboratories (silabenm) Ports (12/10/2012 6.6.1.0) (HKLM\...\D680DEE0F68D64EC53D0C5769879D15D387054CC) (Version: 12/10/2012 6.6.1.0 - Silicon Laboratories) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows Mobile-Gerätecenter: Treiberupdate (HKLM\...\{92DBCA36-9B41-4DD1-941A-AED149DD37F0}) (Version: 6.1.6965.0 - Microsoft Corporation) Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) Windows-Treiberpaket - Silicon Laboratories (silabenm) Ports (03/19/2014 6.7.0.0) (HKLM\...\B97004A400E30DCF940971EFA7A0C13C6B0A4B66) (Version: 03/19/2014 6.7.0.0 - Silicon Laboratories) Windows-Treiberpaket - Silicon Laboratories (silabenm) Ports (10/18/2013 6.6.1.0) (HKLM\...\F92C2D6CB4EA0EE558BDF5F8BDD69083DFC62179) (Version: 10/18/2013 6.6.1.0 - Silicon Laboratories) WinHTTrack Website Copier 3.45-4 (HKLM-x32\...\WinHTTrack Website Copier_is1) (Version: 3.45.4 - HTTrack) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4011218287-2957974095-3496630771-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ==================== Restore Points ========================= 25-11-2014 06:33:44 Windows Update 27-11-2014 09:48:23 ComboFix created restore point ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2014-11-27 11:03 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0AA05706-3CF6-47E6-B2A9-1E2D0F356015} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-10-23] (Piriform Ltd) Task: {44510234-7A6D-45C7-BE27-CD04ACA340EE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-26] (Adobe Systems Incorporated) Task: {666A020D-B599-4E83-8841-212CB99D79FC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-22] (Google Inc.) Task: {A078082D-527C-4B5D-9521-AFDEB40769DA} - System32\Tasks\Fujitsu\DeskUpdate => c:\Fujitsu\Programs\DeskUpdate\ducmd.exe [2013-12-11] (Fujitsu Technology Solutions) Task: {A22EEE67-C128-46D2-8B1E-0BACB561CED8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-22] (Google Inc.) Task: {C24E6D89-AA1F-4C9A-A470-C7DAE167F09D} - System32\Tasks\Metar2APRS => cmd Task: {CD439C62-7727-4341-A09B-43084756DA60} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2012-05-22 20:10 - 2011-02-23 05:11 - 01182576 _____ () C:\Program Files\Tablet\ISD\libxml2.dll 2011-05-10 11:48 - 2011-04-15 02:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-10-23 20:19 - 2014-10-23 20:19 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2010-10-15 18:08 - 2010-10-15 18:08 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2011-03-01 07:55 - 2011-02-03 11:56 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll 2013-10-01 10:32 - 2013-10-01 10:32 - 02818216 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll 2014-05-01 20:29 - 2014-05-01 20:29 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2013-07-08 00:13 - 2012-07-20 13:39 - 02469888 _____ () C:\Program Files (x86)\IZArc\IZArcCM64.dll 2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2012-11-20 10:07 - 2007-05-31 07:38 - 00167936 ____N () C:\Windows\SysWOW64\SerialXP.dll 2014-07-28 16:32 - 2014-02-14 09:59 - 00025600 _____ () C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServerps.dll 2014-07-28 16:32 - 2011-08-23 10:04 - 00057344 _____ () C:\Program Files (x86)\WinTV\TVServer\libhdhomerun.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00028774 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024679 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\c5cce8d16a1bd48692b421dcf46d3396\Util.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024701 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00028779 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00020601 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\4461f48e31bde5c56b31b973b773de09\List.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00118918 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00082048 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00020576 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00036964 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\f233f63b6654362865c7577442edb9e3\Win32.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00020590 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00082033 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024676 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00061540 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\e56c61f7248672819579325af3387035\POSIX.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00094334 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\eb138ef0e4282611dbf485a302784646\LibYAML.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00053340 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00184414 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\bd5179a413bc0c4b82eedc22c6cab101\re.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024701 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-3648\93e7e3d6030f426844228042348210cf\Service.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00043008 ____N () c:\Users\Helge Hartz\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpccw0ax.dll 2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\Helge Hartz\AppData\Roaming\Dropbox\bin\libcef.dll 2011-03-01 07:55 - 2011-02-03 11:56 - 00066856 _____ () C:\WINDOWS\SysWOW64\SynTPEnhPS.dll 2014-02-04 18:25 - 2014-02-04 18:25 - 00036672 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\qt_icontray_ex.dll 2014-02-04 18:25 - 2014-02-04 18:25 - 00028992 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\thread_pool.dll 2013-10-10 12:02 - 2013-10-10 12:02 - 00013120 _____ () C:\Program Files (x86)\Common Files\Acronis\TibMounter\icudt38.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00020576 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00036964 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\f233f63b6654362865c7577442edb9e3\Win32.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024676 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00061540 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\e56c61f7248672819579325af3387035\POSIX.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00020590 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00082033 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00118918 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00082048 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00028779 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00020601 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\4461f48e31bde5c56b31b973b773de09\List.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024681 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\c199d3c1960e7aeeecb599487952bed2\HiRes.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00090213 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\961b0d62fa52b1dd29c795a822fbf1cf\DBI.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024679 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\c5cce8d16a1bd48692b421dcf46d3396\Util.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00077824 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\7f177c338672436e01c4f0bdbcf94491\EV.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00138752 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\44727051c604ef6b79894b64d4c63832\Expat.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00041080 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\2b1fc61b36a6711ea149b18bf3b41500\Parser.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00030720 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\dacfd0ab9b5fd029ed8d29e4482b0775\XS.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00020590 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\fa9e3c814aa32db2ad5f17bdfbc22746\attributes.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024694 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\c344fd5536724b2af2e6453833b60203\SHA1.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00094334 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\eb138ef0e4282611dbf485a302784646\LibYAML.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00053340 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00184414 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\bd5179a413bc0c4b82eedc22c6cab101\re.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00020592 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\b979ace6da01e63d651cce9ee2474fdc\Name.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00028774 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00182272 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\d0bf009923f29116535c26d228271d6d\Scan.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024672 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\17d0b152e63e6bfe81b4b19588538896\mro.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00020596 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\3b7106dd14676048b10bbb09a990f74c\XS.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00032878 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024695 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\cf5fe81e2f5dcbfecfd0495e1648c991\Unicode.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024670 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\3a8764e0d7c5d453e01d9ad08cf7fb58\IO.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00361472 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\aff7ee779ea184f884ed432c30a58f5d\Scale.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024701 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00061546 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\4f2c03383aab0133b8dc0a3fa2dd92fa\Storable.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00110705 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\7f2598c08178217a0e2c754f3d568f28\Byte.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00024679 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\c19d5e3dc664d9f4ce700001e2621cee\MD5.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00608256 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\e2e81dd6b3e5a36f0bdae076393cc11d\SQLite.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00001024 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\e2e81dd6b3e5a36f0bdae076393cc11d\icudt46.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00020596 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\d1c77e404b5c4b954fa537ed63c8fb7b\File.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00030208 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\0665c25e931c1ac0151b062449e91028\XSAccessor.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00020587 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\c668a322917d32a5ea22894518aa9897\Base64.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00017920 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\8fedeb86a4a984edfc1fb255d4ea965c\XS.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00061547 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\bc147d83c7c868eeee67082dcf55430c\File.dll 2014-11-28 14:05 - 2014-11-28 14:05 - 00032881 ____N () C:\Users\Helge Hartz\AppData\Local\Temp\pdk-Helge_Hartz-4784\b6bd87c968599725b8ab2e5c25d3046a\API.dll 2014-02-04 18:28 - 2014-02-04 18:28 - 00420160 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AutoStart IR.lnk => C:\Windows\pss\AutoStart IR.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinTV Recording Status.lnk => C:\Windows\pss\WinTV Recording Status.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Helge Hartz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Ekiga.lnk => C:\Windows\pss\Ekiga.lnk.Startup MSCONFIG\startupreg: ANT Agent => C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: ArcSoft Connection Service => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe MSCONFIG\startupreg: BingDesktop => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey MSCONFIG\startupreg: DeskUpdateNotifier => "c:\Fujitsu\Programs\DeskUpdate\DeskUpdateNotifier.exe" MSCONFIG\startupreg: IJNetworkScannerSelectorEX => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: snp2uvc => C:\Windows\vsnp2uvc.exe ========================= Accounts: ========================== Administrator (S-1-5-21-4011218287-2957974095-3496630771-500 - Administrator - Disabled) Gast (S-1-5-21-4011218287-2957974095-3496630771-501 - Limited - Enabled) Helge Hartz (S-1-5-21-4011218287-2957974095-3496630771-1000 - Administrator - Enabled) => C:\Users\Helge Hartz HomeGroupUser$ (S-1-5-21-4011218287-2957974095-3496630771-1006 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= Name: Intel(R) 82579LM Gigabit Network Connection Description: Intel(R) 82579LM Gigabit Network Connection Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Intel Service: e1cexpress Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Bluetooth-Gerät (PAN) Description: Bluetooth-Gerät (PAN) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: BthPan Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2014-11-27 10:56:29.706 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-11-27 10:56:29.690 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-09-11 08:06:59.540 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-11 08:06:59.524 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-11 08:06:59.524 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-11 08:06:59.524 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-11 08:02:26.991 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-11 08:02:26.913 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-24 18:42:28.341 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-08-24 18:42:28.341 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-2640M CPU @ 2.80GHz Percentage of memory in use: 30% Total physical RAM: 7930.85 MB Available physical RAM: 5521.51 MB Total Pagefile: 15859.88 MB Available Pagefile: 13383.83 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:445.14 GB) (Free:281.21 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 499F1625) Partition 1: (Active) - (Size=2.1 GB) - (Type=27) Partition 2: (Not Active) - (Size=463.7 GB) - (Type=05) ==================== End Of Log ============================ |
29.11.2014, 10:47 | #15 |
/// the machine /// TB-Ausbilder | Telekom Deutschland - Fake Rechnung 13.11.2014ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Telekom Deutschland - Fake Rechnung 13.11.2014 |
computer, fehlercode 0x0, fehlercode 0x81000006, fehlercode 0xc0000005, fehlercode 22, fehlercode windows, hijack, hijackthis, kaspersky, klicke, klicken, nichts, pup.optional.regcleanpro, pup.optional.searchprotect.a, pup.optional.softonic, pup.optional.softonic.a, pup.optional.systemspeedup, rechnung, systemwiederherstellung, telekom, telekom deutschland, this device is disabled. (code 22), trojaner, verlinkung, win64/systemweak.a |