![]() |
|
Log-Analyse und Auswertung: Win8, DHL-mail geöffnet nach Win-Update HDI-Tastatur keine funktion (Code 19)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
|
![]() | #1 |
| ![]() Win8, DHL-mail geöffnet nach Win-Update HDI-Tastatur keine funktion (Code 19) Hallo, ich bekam vor einigen Tagen eine email von DHL und erst im Nachhinein wurde mir klar ich hätte weder die email noch den Anhang öffnen sollen. Anfangs war alles okay doch der Laptop wurde immer langsamer, gestern wurde ich dann aufgefordert die Grafikkarte und Windows-Updates zu machen und plötzlich ging weder Tastatur noch das mousepad. Ich de-installierte daraufhin alle Updates doch der Fehler blieb weiterhin. Auch der Virus scan ergab keine Lösung. Laut meinem Gerätemanager kann mein Hardwaregerät nicht gestartet werden, da dessen Konfigurationsinfomation (in der Registrierung) unvollständig oder beschädigt sind. ( CODE 19) Das selbe bei, "Erweiterte PC/AT-PS/2-Tastatur (101/102 Tasten). Via bildschirmtastatur hab ich die logfiles erstellt. Schritt 1 : defogger hab ich erledigt. Schritt 2: FRST.txt Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-05-2015 01 Ran by Marco Kerschbaum (administrator) on MARCO on 24-05-2015 02:54:28 Running from C:\Users\Marco Kerschbaum\Downloads Loaded Profiles: Marco Kerschbaum (Available Profiles: Marco Kerschbaum) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe () C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (Toshiba Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe () C:\Windows\SysWOW64\UMonit64.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe (TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\System Setting\TssSrv.exe (Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIKBE.EXE (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIKBE.EXE (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIKBE.EXE (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Dropbox, Inc.) C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\Dropbox.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [] => [X] HKLM-x32\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2556768 2013-08-18] (TOSHIBA Corporation) HKLM-x32\...\Run: [TSSSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe [296520 2013-09-12] (TOSHIBA Corporation) HKLM-x32\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [178016 2013-08-21] (TOSHIBA Corporation) HKLM-x32\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.) HKLM-x32\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3249384 2015-05-19] (ELAN Microelectronics Corp.) HKLM-x32\...\Run: [KeNotify] => C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34160 2013-08-06] (TOSHIBA CORPORATION) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-11] (Avast Software s.r.o.) HKLM-x32\...\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [516512 2013-07-23] (TOSHIBA) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation) HKLM-x32\...\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [642664 2014-07-25] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [863848 2014-07-25] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1065024 2014-05-02] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [911024 2013-03-09] (Microsoft Corporation) HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\Run: [MyPhoneExplorer] => C:\Program Files (x86)\MyPhoneExplorer\MyPhoneExplorer.exe [5442456 2014-08-12] (F.J. Wechselberger) HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8204056 2015-04-23] (Piriform Ltd) HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIKBE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\Run: [EPLTarget\P0000000000000001] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIKBE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\Run: [EPLTarget\P0000000000000002] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIKBE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\RunOnce: [Uninstall C:\Users\Marco Kerschbaum\AppData\Local\Microsoft\OneDrive\17.3.4726.0226] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Marco Kerschbaum\AppData\Local\Microsoft\OneDrive\17.3.4726.0226" HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\MountPoints2: {12e2bbac-9f20-11e4-826b-5c514f51a4fe} - "E:\AutoRun.exe" HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\MountPoints2: {12e2bc1e-9f20-11e4-826b-5c514f51a4fe} - "D:\AutoRun.exe" HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\MountPoints2: {27b71bab-d723-11e4-8271-5c514f51a4fe} - "D:\AutoRun.exe" HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\MountPoints2: {27b71c1f-d723-11e4-8271-5c514f51a4fe} - "D:\AutoRun.exe" HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\MountPoints2: {5aaa1314-7aeb-11e4-8260-5c514f51a4fe} - "D:\AutoRun.exe" HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\MountPoints2: {6776d29d-e037-11e4-8274-201a06788cfd} - "D:\MMMTest.EXE" HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\MountPoints2: {8814bc0d-85e7-11e4-8264-5c514f51a4fe} - "D:\AutoRun.exe" HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\MountPoints2: {99c74ec6-877f-11e4-8264-5c514f51a4fe} - "D:\AutoRun.exe" HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\MountPoints2: {99c74ed5-877f-11e4-8264-5c514f51a4fe} - "D:\AutoRun.exe" HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [589312 2014-10-29] (Microsoft Corporation) AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [175880 2015-04-09] (NVIDIA Corporation) AppInit_DLLs: ,C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [175880 2015-04-09] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [154256 2015-04-09] (NVIDIA Corporation) AppInit_DLLs-x32: ,C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [154256 2015-04-09] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk [2013-10-16] ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-05-23] ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.10.106\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Marco Kerschbaum\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-04-17] ShortcutTarget: Dropbox.lnk -> C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-05-06] (Avast Software s.r.o.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled ProxyServer: [.DEFAULT] => http=127.0.0.1:58524;https=127.0.0.1:58524 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://toshiba.eu/symbaloo_c HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://toshiba.eu/symbaloo_c SearchScopes: HKLM -> {2422C16C-02C3-46F5-8A0E-D98F062B6C10} URL = hxxp://www.startseite24.net/?q={searchTerms} SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002 -> {2422C16C-02C3-46F5-8A0E-D98F062B6C10} URL = hxxp://www.startseite24.net/?q={searchTerms} SearchScopes: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002 -> {2FAD7751-FE8B-4389-8C20-1C732EE407A1} URL = BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-03-09] (Microsoft Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-05-06] (Avast Software s.r.o.) BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.10.106\McAfeeMSS_IE.dll [2014-11-04] (McAfee, Inc.) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-03-09] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-05-05] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-05-06] (Avast Software s.r.o.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-05] (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION) Tcpip\Parameters: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{23437329-2875-488E-9FE9-56F1902A4E30}: [NameServer] 213.162.69.2 213.162.69.170 FireFox: ======== FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-03] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-03] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-05] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-05] (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2014-07-16] (Nitro PDF) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-15] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-15] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-12-03] Chrome: ======= CHR Profile: C:\Users\Marco Kerschbaum\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\Marco Kerschbaum\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-03] CHR Extension: (YouTube) - C:\Users\Marco Kerschbaum\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-03] CHR Extension: (Adblock Plus) - C:\Users\Marco Kerschbaum\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-12-03] CHR Extension: (Google Search) - C:\Users\Marco Kerschbaum\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-03] CHR Extension: (Bookmark Manager) - C:\Users\Marco Kerschbaum\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-17] CHR Extension: (Avast Online Security) - C:\Users\Marco Kerschbaum\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-12-03] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Marco Kerschbaum\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12] CHR Extension: (Google Wallet) - C:\Users\Marco Kerschbaum\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-03] CHR Extension: (Gmail) - C:\Users\Marco Kerschbaum\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-03] CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-05-06] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-06] (Avast Software s.r.o.) R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4034896 2015-05-06] (Avast Software) S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation) R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1429504 2015-03-05] (Microsoft Corporation) R2 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [19792 2013-09-10] () R2 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [662592 2014-07-23] (SEIKO EPSON CORPORATION) R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [147688 2015-05-19] (ELAN Microelectronics Corp.) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [351824 2013-02-06] () R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319888 2014-12-31] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-03] (Intel Corporation) S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [671744 2013-08-16] () [] R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-08-13] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.10.106\McCHSvc.exe [289256 2014-11-04] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-08-07] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-08-07] (McAfee, Inc.) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-08-23] () R2 NitroDriverReadSpool9; C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe [230920 2014-07-16] (Nitro PDF Software) R2 NitroUpdateService; C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe [417800 2014-07-16] () S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-04-20] (Electronic Arts) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5448976 2015-04-17] (TeamViewer GmbH) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3667696 2013-08-23] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-05-06] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-05-06] (Avast Software s.r.o.) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-05-06] (Avast Software s.r.o.) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-05-06] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-05-06] (Avast Software s.r.o.) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-05-06] (Avast Software s.r.o.) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-05-06] (Avast Software s.r.o.) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-05-06] () S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [132608 2015-01-30] (Microsoft Corporation) S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-08-07] (McAfee, Inc.) R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [33344 2015-05-19] (ELAN Microelectronic Corp.) S3 GeneStor; C:\Windows\System32\drivers\GeneStor.sys [100072 2013-08-02] (GenesysLogic) S3 huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [246272 2013-08-16] (Huawei Technologies Co., Ltd.) R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [117192 2013-08-29] (Intel Corporation) S3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21408 2013-08-09] () R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21920 2013-08-09] () R3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-08-08] () R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-08-08] () R3 KovaPlusFltr; C:\Windows\system32\drivers\KovaPlusFltr.sys [15104 2010-01-25] (ROCCAT Development, Inc.) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation) S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179664 2013-08-07] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [310224 2013-08-07] (McAfee, Inc.) S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69264 2013-08-07] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519064 2013-08-07] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [776168 2013-08-07] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343568 2013-08-07] (McAfee, Inc.) R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3589600 2013-09-25] (Intel Corporation) S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation) R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-05] (Scarlet.Crush Productions) R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [32624 2013-08-19] (Windows (R) Win 7 DDK provider) R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-05-06] (Avast Software) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation) S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation) S4 nvvad_WaveExtensible; \SystemRoot\system32\drivers\nvvad64v.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-05-24 02:54 - 2015-05-24 02:54 - 00027658 _____ () C:\Users\Marco Kerschbaum\Downloads\FRST.txt 2015-05-24 02:54 - 2015-05-24 02:54 - 00000000 ____D () C:\FRST 2015-05-24 02:53 - 2015-05-24 02:53 - 00000494 _____ () C:\Users\Marco Kerschbaum\Downloads\defogger_disable.log 2015-05-24 02:53 - 2015-05-24 02:53 - 00000000 _____ () C:\Users\Marco Kerschbaum\defogger_reenable 2015-05-23 22:26 - 2015-05-23 22:26 - 00000257 _____ () C:\WINDOWS\setupact.log 2015-05-23 22:26 - 2015-05-23 22:26 - 00000000 _____ () C:\WINDOWS\setuperr.log 2015-05-23 22:25 - 2015-05-23 22:25 - 00488408 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2015-05-23 20:18 - 2015-05-23 20:18 - 00380416 _____ () C:\Users\Marco Kerschbaum\Downloads\Gmer-19357.exe 2015-05-23 20:16 - 2015-05-23 20:16 - 02108416 _____ (Farbar) C:\Users\Marco Kerschbaum\Downloads\FRST64.exe 2015-05-23 20:13 - 2015-05-23 20:13 - 00050477 _____ () C:\Users\Marco Kerschbaum\Downloads\Defogger.exe 2015-05-23 16:50 - 2015-05-23 16:50 - 00002003 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2015-05-23 16:50 - 2015-05-23 16:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 2015-05-23 16:50 - 2015-05-23 16:50 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2015-05-23 16:50 - 2015-05-23 16:50 - 00000000 ____D () C:\Program Files\McAfee Security Scan 2015-05-23 16:49 - 2015-05-23 16:49 - 08423856 _____ (McAfee, Inc.) C:\Users\Marco Kerschbaum\Downloads\SecurityScan_Release.exe 2015-05-23 16:30 - 2015-05-23 16:30 - 00000144 _____ () C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2015-05-23 16:26 - 2015-05-23 16:26 - 00000000 ____D () C:\Program Files\Elantech 2015-05-23 16:24 - 2014-04-16 01:35 - 00028352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aspnet_counters.dll 2015-05-23 16:24 - 2014-04-16 01:34 - 00029888 _____ (Microsoft Corporation) C:\WINDOWS\system32\aspnet_counters.dll 2015-05-23 16:19 - 2015-05-23 16:19 - 00000451 _____ () C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat 2015-05-23 16:10 - 2015-05-23 16:10 - 00000000 ____D () C:\Intel 2015-05-23 16:08 - 2015-01-06 05:01 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys 2015-05-23 16:08 - 2015-01-06 04:59 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys 2015-05-23 16:08 - 2015-01-06 03:12 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascfg.dll 2015-05-23 16:08 - 2015-01-06 03:02 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rascfg.dll 2015-05-23 16:07 - 2015-04-09 00:41 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rgb9rast.dll 2015-05-23 16:07 - 2015-04-09 00:07 - 00410336 _____ () C:\WINDOWS\system32\ApnDatabase.xml 2015-05-23 16:07 - 2015-04-02 00:42 - 03097600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2015-05-23 16:07 - 2015-04-02 00:30 - 02483712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2015-05-23 16:07 - 2015-03-20 05:49 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll 2015-05-23 16:07 - 2015-03-20 05:08 - 00477184 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll 2015-05-23 16:07 - 2015-03-20 04:37 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll 2015-05-23 16:07 - 2015-03-20 04:07 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2015-05-23 16:07 - 2015-03-02 03:43 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastapi.dll 2015-05-23 16:07 - 2015-03-02 03:21 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastapi.dll 2015-05-23 16:07 - 2014-11-17 22:17 - 00672984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe 2015-05-23 16:07 - 2014-11-17 22:17 - 00273240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2015-05-23 16:07 - 2014-11-15 21:05 - 00801584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2015-05-23 16:07 - 2014-11-15 08:29 - 00962216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2015-05-23 16:07 - 2014-11-14 08:57 - 01027584 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2015-05-23 16:07 - 2014-11-14 08:54 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2015-05-23 16:07 - 2014-11-14 08:46 - 02171904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll 2015-05-23 16:07 - 2014-11-14 07:03 - 00885760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2015-05-23 16:07 - 2014-11-10 20:06 - 02485056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2015-05-23 16:07 - 2014-11-10 20:06 - 00473408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys 2015-05-23 16:07 - 2014-11-10 20:06 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 2015-05-23 16:07 - 2014-11-10 20:06 - 00136512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys 2015-05-23 16:07 - 2014-11-10 04:57 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys 2015-05-23 16:07 - 2014-11-10 03:37 - 00845312 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL 2015-05-23 16:07 - 2014-11-10 03:34 - 01084416 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 2015-05-23 16:07 - 2014-11-10 03:26 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL 2015-05-23 16:07 - 2014-11-10 03:20 - 00420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll 2015-05-23 16:07 - 2014-11-10 03:09 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL 2015-05-23 16:07 - 2014-11-10 03:08 - 00702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2015-05-23 16:07 - 2014-11-10 03:06 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll 2015-05-23 16:07 - 2014-11-10 02:57 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll 2015-05-23 16:07 - 2014-11-10 02:57 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll 2015-05-23 16:07 - 2014-11-08 06:00 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys 2015-05-23 16:07 - 2014-11-08 05:58 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys 2015-05-23 16:07 - 2014-11-08 05:56 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\kmddsp.tsp 2015-05-23 16:07 - 2014-11-08 05:56 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmxs.dll 2015-05-23 16:07 - 2014-11-08 05:56 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasser.dll 2015-05-23 16:07 - 2014-11-08 05:24 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdiag.dll 2015-05-23 16:07 - 2014-11-08 05:13 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kmddsp.tsp 2015-05-23 16:07 - 2014-11-08 05:13 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasmxs.dll 2015-05-23 16:07 - 2014-11-08 05:13 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasser.dll 2015-05-23 16:07 - 2014-11-08 04:48 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdiag.dll 2015-05-23 16:07 - 2014-11-08 04:38 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2015-05-23 16:07 - 2014-11-08 04:17 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2015-05-23 16:07 - 2014-11-08 04:03 - 00733696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll 2015-05-23 16:07 - 2014-11-08 03:58 - 04837376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll 2015-05-23 16:07 - 2014-11-08 03:49 - 01154048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe 2015-05-23 16:07 - 2014-11-07 05:58 - 00952896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2015-05-23 16:07 - 2014-11-07 05:20 - 00786120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2015-05-23 16:07 - 2014-11-05 04:12 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\QSHVHOST.DLL 2015-05-23 16:07 - 2014-11-05 04:12 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\QSVRMGMT.DLL 2015-05-23 16:07 - 2014-11-05 04:06 - 00514048 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll 2015-05-23 16:07 - 2014-11-05 03:44 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll 2015-05-23 16:07 - 2014-11-05 03:43 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll 2015-05-23 16:07 - 2014-11-05 03:41 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll 2015-05-23 16:07 - 2014-11-05 03:39 - 00155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\QSHVHOST.DLL 2015-05-23 16:07 - 2014-11-05 03:39 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\QSVRMGMT.DLL 2015-05-23 16:07 - 2014-11-05 03:33 - 00465408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll 2015-05-23 16:07 - 2014-11-05 03:21 - 00658432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll 2015-05-23 16:07 - 2014-11-05 03:20 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll 2015-05-23 16:07 - 2014-11-05 03:18 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll 2015-05-23 16:07 - 2014-11-05 03:14 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDMon.dll 2015-05-23 16:07 - 2014-11-05 03:06 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll 2015-05-23 16:07 - 2014-11-04 21:33 - 00058176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys 2015-05-23 16:07 - 2014-11-04 21:25 - 00059712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys 2015-05-23 16:07 - 2014-11-04 21:25 - 00051008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys 2015-05-23 16:07 - 2014-11-04 08:55 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys 2015-05-23 16:07 - 2014-11-04 08:54 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys 2015-05-23 16:07 - 2014-11-04 08:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys 2015-05-23 16:07 - 2014-11-04 08:54 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys 2015-05-23 16:07 - 2014-11-04 08:27 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe 2015-05-23 16:07 - 2014-11-04 07:01 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe 2015-05-23 16:07 - 2014-10-31 02:51 - 18823168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2015-05-23 16:07 - 2014-10-31 02:10 - 15158784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2015-05-23 16:07 - 2014-10-29 05:05 - 00551232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2015-05-23 16:07 - 2014-10-29 03:55 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll 2015-05-23 16:07 - 2014-10-29 03:13 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSCard.dll 2015-05-23 16:07 - 2014-10-21 03:59 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\eventcls.dll 2015-05-23 16:07 - 2014-10-21 03:19 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eventcls.dll 2015-05-23 16:07 - 2014-10-21 02:50 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\vsstrace.dll 2015-05-23 16:07 - 2014-10-21 02:31 - 01574400 _____ (Microsoft Corporation) C:\WINDOWS\system32\vssapi.dll 2015-05-23 16:07 - 2014-10-21 02:31 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vsstrace.dll 2015-05-23 16:07 - 2014-10-21 02:30 - 01454080 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe 2015-05-23 16:07 - 2014-10-21 02:20 - 01142272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vssapi.dll 2015-05-23 16:07 - 2014-10-17 06:56 - 00039744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys 2015-05-23 16:07 - 2014-10-17 05:35 - 00086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2015-05-23 16:06 - 2015-04-16 08:17 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2015-05-23 16:06 - 2015-04-14 00:37 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\authz.dll 2015-05-23 16:06 - 2015-04-14 00:34 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authz.dll 2015-05-23 16:06 - 2015-04-10 02:40 - 01249280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2015-05-23 16:06 - 2015-04-10 02:17 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2015-05-23 16:06 - 2015-04-01 06:21 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2015-05-23 16:06 - 2015-04-01 06:18 - 00468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll 2015-05-23 16:06 - 2015-04-01 06:17 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssphtb.dll 2015-05-23 16:06 - 2015-04-01 06:08 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll 2015-05-23 16:06 - 2015-04-01 05:46 - 03633664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2015-05-23 16:06 - 2015-04-01 05:17 - 02551808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2015-05-23 16:06 - 2015-04-01 05:17 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2015-05-23 16:06 - 2015-04-01 04:53 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll 2015-05-23 16:06 - 2015-04-01 04:53 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2015-05-23 16:06 - 2015-04-01 04:45 - 02749952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2015-05-23 16:06 - 2015-04-01 04:45 - 00699392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll 2015-05-23 16:06 - 2015-04-01 04:14 - 01920000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2015-05-23 16:06 - 2015-04-01 04:12 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2015-05-23 15:58 - 2015-05-23 16:12 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV 2015-05-23 15:58 - 2015-05-23 16:12 - 00000000 ____D () C:\WINDOWS\system32\NV 2015-05-23 15:58 - 2015-05-23 15:58 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-05-23 15:58 - 2015-04-08 23:30 - 06841488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2015-05-23 15:58 - 2015-04-08 23:30 - 03478344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2015-05-23 15:58 - 2015-04-08 23:30 - 02558608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2015-05-23 15:58 - 2015-04-08 23:30 - 01047696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2015-05-23 15:58 - 2015-04-08 23:30 - 00936264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2015-05-23 15:58 - 2015-04-08 23:30 - 00385168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2015-05-23 15:58 - 2015-04-08 23:30 - 00075080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2015-05-23 15:58 - 2015-04-08 23:30 - 00062608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2015-05-23 15:58 - 2015-04-08 19:52 - 04336074 _____ () C:\WINDOWS\system32\nvcoproc.bin 2015-05-23 15:57 - 2015-05-23 15:57 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2015-05-23 15:40 - 2015-05-19 08:40 - 02238184 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\ETDUninst.dll 2015-05-23 12:59 - 2015-05-23 21:20 - 00995562 _____ () C:\WINDOWS\WindowsUpdate.log 2015-05-19 16:23 - 2015-05-19 16:26 - 248255373 _____ () C:\Users\Marco Kerschbaum\Downloads\p1080.mp4 2015-05-19 08:40 - 2015-05-19 08:40 - 00452328 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\system32\Drivers\ETD.sys 2015-05-19 08:40 - 2015-05-19 08:40 - 00081640 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\system32\ETDCoInstaller.dll 2015-05-19 08:40 - 2015-05-19 08:40 - 00033344 _____ (ELAN Microelectronic Corp.) C:\WINDOWS\system32\Drivers\ETDSMBus.sys 2015-05-19 00:56 - 2015-05-19 01:02 - 1389122880 _____ () C:\Users\Marco Kerschbaum\Downloads\QIE-Der Schlüssel zum Bewusstsein (finale DVD Version)-HD.mp4 2015-05-16 17:40 - 2015-04-30 22:35 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2015-05-16 17:40 - 2015-04-30 22:35 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2015-05-15 10:16 - 2015-05-15 10:16 - 00000000 ____D () C:\e9a85165dee893a2ecb6 2015-05-13 14:01 - 2015-05-13 14:01 - 00000737 _____ () C:\Users\Marco Kerschbaum\Documents\Desktop - Verknüpfung (2).lnk 2015-05-13 10:18 - 2015-05-01 01:05 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2015-05-13 10:18 - 2015-05-01 00:48 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2015-05-13 10:18 - 2015-04-24 23:32 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll 2015-05-13 10:18 - 2015-04-21 19:14 - 24971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-05-13 10:18 - 2015-04-21 18:31 - 06025728 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2015-05-13 10:18 - 2015-04-21 18:24 - 19691008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-05-13 10:18 - 2015-04-21 17:40 - 14401536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-05-13 10:18 - 2015-04-21 17:17 - 12828672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-05-13 10:18 - 2015-04-14 00:48 - 04180480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2015-05-13 10:18 - 2015-04-10 03:00 - 01996800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2015-05-13 10:18 - 2015-04-10 02:50 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2015-05-13 10:18 - 2015-04-10 02:34 - 02256896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2015-05-13 10:18 - 2015-04-10 02:26 - 01560576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2015-05-13 10:18 - 2015-04-10 02:11 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2015-05-13 10:18 - 2015-04-09 00:55 - 00410128 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2015-05-13 10:18 - 2015-04-03 02:35 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll 2015-05-13 10:18 - 2015-04-03 02:14 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll 2015-05-13 10:18 - 2015-04-02 00:22 - 02985984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2015-05-13 10:18 - 2015-04-02 00:20 - 04417536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2015-05-13 10:18 - 2015-04-01 05:45 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll 2015-05-13 10:18 - 2015-04-01 04:31 - 01207296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll 2015-05-13 10:18 - 2015-03-30 07:47 - 00561928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2015-05-13 10:18 - 2015-03-27 05:27 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2015-05-13 10:18 - 2015-03-27 04:50 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2015-05-13 10:18 - 2015-03-27 04:48 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2015-05-13 10:18 - 2015-03-20 03:56 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys 2015-05-13 10:18 - 2015-03-17 19:26 - 00467776 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2015-05-13 10:18 - 2015-03-13 06:03 - 00239424 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2015-05-13 10:18 - 2015-03-13 06:03 - 00154432 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2015-05-13 10:18 - 2015-03-13 04:02 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys 2015-05-13 10:18 - 2015-03-13 03:11 - 02162176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2015-05-13 10:18 - 2015-03-13 02:39 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2015-05-13 10:18 - 2015-03-11 03:49 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe 2015-05-13 10:18 - 2015-03-11 03:09 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdbinst.exe 2015-05-13 10:18 - 2015-03-09 04:02 - 00057856 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys 2015-05-13 10:18 - 2015-03-06 05:08 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll 2015-05-13 10:18 - 2015-03-06 04:47 - 01696256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2015-05-13 10:18 - 2015-03-06 04:43 - 01969664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll 2015-05-13 10:18 - 2015-03-05 01:09 - 01429504 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2015-05-13 10:18 - 2015-03-04 03:32 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2015-05-13 10:18 - 2015-03-04 03:12 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2015-05-13 10:18 - 2015-02-18 01:19 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2015-05-13 10:18 - 2015-01-30 02:53 - 02819584 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll 2015-05-13 10:18 - 2014-11-14 08:58 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsDatabase.dll 2015-05-13 10:17 - 2015-04-21 18:50 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2015-05-13 10:17 - 2015-04-21 18:50 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec 2015-05-13 10:17 - 2015-04-21 18:49 - 02885120 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-05-13 10:17 - 2015-04-21 18:37 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll 2015-05-13 10:17 - 2015-04-21 18:35 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2015-05-13 10:17 - 2015-04-21 18:13 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\inseng.dll 2015-05-13 10:17 - 2015-04-21 18:11 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2015-05-13 10:17 - 2015-04-21 18:09 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec 2015-05-13 10:17 - 2015-04-21 18:08 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2015-05-13 10:17 - 2015-04-21 18:07 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2015-05-13 10:17 - 2015-04-21 18:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2015-05-13 10:17 - 2015-04-21 18:04 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-05-13 10:17 - 2015-04-21 17:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2015-05-13 10:17 - 2015-04-21 17:58 - 00664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2015-05-13 10:17 - 2015-04-21 17:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2015-05-13 10:17 - 2015-04-21 17:49 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2015-05-13 10:17 - 2015-04-21 17:49 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2015-05-13 10:17 - 2015-04-21 17:49 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2015-05-13 10:17 - 2015-04-21 17:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2015-05-13 10:17 - 2015-04-21 17:38 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2015-05-13 10:17 - 2015-04-21 17:37 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2015-05-13 10:17 - 2015-04-21 17:36 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2015-05-13 10:17 - 2015-04-21 17:32 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2015-05-13 10:17 - 2015-04-21 17:31 - 04305920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2015-05-13 10:17 - 2015-04-21 17:28 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2015-05-13 10:17 - 2015-04-21 17:27 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2015-05-13 10:17 - 2015-04-21 17:26 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2015-05-13 10:17 - 2015-04-21 17:26 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2015-05-13 10:17 - 2015-04-21 17:25 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2015-05-13 10:17 - 2015-04-21 17:15 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-05-13 10:17 - 2015-04-21 17:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2015-05-13 10:17 - 2015-04-21 17:02 - 01882112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2015-05-13 10:17 - 2015-04-21 16:58 - 01310208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-05-13 10:17 - 2015-04-21 16:56 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2015-05-09 17:52 - 2015-05-09 17:52 - 00000380 _____ () C:\Users\Marco Kerschbaum\Desktop\Maklernetz KFZ BlitzRechner 15.04.appref-ms 2015-05-09 16:14 - 2015-05-24 02:14 - 00000931 _____ () C:\WINDOWS\Tasks\EPSON WF-7610 Series Update {29F1BE0F-D6FF-439C-9A74-924EFE4BFEEB}.job 2015-05-09 16:14 - 2015-05-24 02:14 - 00000745 _____ () C:\WINDOWS\Tasks\EPSON WF-7610 Series Invitation {29F1BE0F-D6FF-439C-9A74-924EFE4BFEEB}.job 2015-05-09 16:14 - 2015-05-09 16:14 - 00003962 _____ () C:\WINDOWS\System32\Tasks\EPSON WF-7610 Series Update {29F1BE0F-D6FF-439C-9A74-924EFE4BFEEB} 2015-05-09 16:14 - 2015-05-09 16:14 - 00003776 _____ () C:\WINDOWS\System32\Tasks\EPSON WF-7610 Series Invitation {29F1BE0F-D6FF-439C-9A74-924EFE4BFEEB} 2015-05-08 17:59 - 2015-05-08 17:59 - 00002158 _____ () C:\Users\Public\Desktop\Epson Easy Photo Print.lnk 2015-05-08 17:59 - 2015-05-08 17:59 - 00000000 ____D () C:\ProgramData\UDL 2015-05-08 17:59 - 2015-05-08 17:59 - 00000000 ____D () C:\ProgramData\Sony Corporation 2015-05-08 17:26 - 2015-05-08 17:26 - 00000000 ____D () C:\ProgramData\Osasoi 2015-05-08 17:26 - 2015-05-08 17:26 - 00000000 ____D () C:\Program Files\EPSON 2015-05-08 15:36 - 2015-05-24 02:36 - 00000931 _____ () C:\WINDOWS\Tasks\EPSON WF-7610 Series Update {CE29CF18-0AB1-460B-8309-46B24131E63A}.job 2015-05-08 15:36 - 2015-05-24 02:36 - 00000745 _____ () C:\WINDOWS\Tasks\EPSON WF-7610 Series Invitation {CE29CF18-0AB1-460B-8309-46B24131E63A}.job 2015-05-08 15:36 - 2015-05-08 15:36 - 00003962 _____ () C:\WINDOWS\System32\Tasks\EPSON WF-7610 Series Update {CE29CF18-0AB1-460B-8309-46B24131E63A} 2015-05-08 15:36 - 2015-05-08 15:36 - 00003776 _____ () C:\WINDOWS\System32\Tasks\EPSON WF-7610 Series Invitation {CE29CF18-0AB1-460B-8309-46B24131E63A} 2015-05-08 15:06 - 2015-05-08 15:06 - 00000000 ____D () C:\Program Files\EpsonNet 2015-05-08 15:06 - 2012-11-12 20:41 - 00535552 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\ensppui.dll 2015-05-08 15:06 - 2012-11-12 20:41 - 00535552 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\enppui.dll 2015-05-08 15:06 - 2012-11-12 15:15 - 00558592 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\ensppmon.dll 2015-05-08 15:06 - 2012-11-12 15:15 - 00558592 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\enppmon.dll 2015-05-08 15:06 - 2012-10-22 17:19 - 00219648 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\enspres.dll 2015-05-08 15:06 - 2012-10-22 17:19 - 00219648 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\enpres.dll 2015-05-08 15:05 - 2015-05-24 02:05 - 00000931 _____ () C:\WINDOWS\Tasks\EPSON WF-7610 Series Update {FD026A1A-1AAB-4963-9E70-67874C0ED2B3}.job 2015-05-08 15:05 - 2015-05-24 02:05 - 00000745 _____ () C:\WINDOWS\Tasks\EPSON WF-7610 Series Invitation {FD026A1A-1AAB-4963-9E70-67874C0ED2B3}.job 2015-05-08 15:05 - 2015-05-08 15:05 - 00003962 _____ () C:\WINDOWS\System32\Tasks\EPSON WF-7610 Series Update {FD026A1A-1AAB-4963-9E70-67874C0ED2B3} 2015-05-08 15:05 - 2015-05-08 15:05 - 00003776 _____ () C:\WINDOWS\System32\Tasks\EPSON WF-7610 Series Invitation {FD026A1A-1AAB-4963-9E70-67874C0ED2B3} 2015-05-08 15:05 - 2015-05-08 15:05 - 00000000 ____D () C:\Program Files\Common Files\EPSON 2015-05-08 14:42 - 2015-05-09 17:32 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Roaming\Epson 2015-05-08 14:42 - 2015-05-08 18:08 - 00000000 ____D () C:\Program Files (x86)\Epson Software 2015-05-08 14:42 - 2015-05-08 18:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software 2015-05-08 14:41 - 2015-05-08 18:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 2015-05-08 14:41 - 2015-05-08 17:58 - 00000000 ____D () C:\Program Files (x86)\epson 2015-05-08 14:41 - 2015-05-08 14:41 - 00000961 _____ () C:\Users\Public\Desktop\EPSON Scan.lnk 2015-05-08 14:41 - 2013-10-22 04:04 - 00179712 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_YLMBKBE.DLL 2015-05-08 14:41 - 2012-07-24 00:00 - 00466432 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\esxw2ud.dll 2015-05-08 14:41 - 2012-05-17 00:00 - 00144560 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\escsvc64.exe 2015-05-08 14:41 - 2011-03-15 03:03 - 00083968 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_YD4BKBE.DLL 2015-05-08 14:41 - 2010-11-22 13:27 - 00147472 _____ (TWAIN Working Group) C:\WINDOWS\SysWOW64\twaindsm.dll 2015-05-08 14:41 - 2007-04-10 01:06 - 00010752 _____ (SEIKO EPSON CORP.) C:\WINDOWS\system32\E_GCINST.DLL 2015-05-08 14:39 - 2015-05-09 17:32 - 00000000 ____D () C:\ProgramData\Epson 2015-05-07 19:09 - 2015-05-07 19:09 - 00003230 _____ () C:\WINDOWS\System32\Tasks\HPPSdr Restart Diagnose 2015-05-07 18:42 - 2015-05-07 18:42 - 00000295 _____ () C:\Users\Marco Kerschbaum\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Papierkorb.lnk 2015-05-07 14:49 - 2015-05-07 14:49 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Roaming\HpUpdate 2015-05-07 14:47 - 2015-05-08 14:22 - 00000000 ____D () C:\ProgramData\HP 2015-05-07 14:47 - 2015-05-07 15:02 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Local\HP 2015-05-07 14:47 - 2015-05-07 14:47 - 00000057 _____ () C:\ProgramData\Ament.ini 2015-05-07 14:39 - 2015-05-08 14:22 - 00000000 ____D () C:\Program Files (x86)\Hp 2015-05-07 14:39 - 2015-05-08 14:19 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard 2015-05-07 12:18 - 2015-05-07 12:18 - 00002806 _____ () C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2015-05-07 12:18 - 2015-05-07 12:18 - 00000845 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2015-05-07 12:18 - 2015-05-07 12:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2015-05-07 12:18 - 2015-05-07 12:18 - 00000000 ____D () C:\Program Files\CCleaner 2015-05-07 11:57 - 2015-05-07 11:58 - 00000000 ____D () C:\AdwCleaner 2015-05-07 11:37 - 2015-05-08 17:25 - 00000000 ____D () C:\Users\Marco Kerschbaum\Documents\Drucker Epson 2015-05-07 11:23 - 2012-08-06 08:33 - 00050176 _____ (Brother Industries Ltd.) C:\WINDOWS\SysWOW64\BRPRTINK.DLL 2015-05-07 11:23 - 2012-08-05 18:06 - 00222720 _____ (Brother Industries, Ltd.) C:\WINDOWS\system32\BRCOI12I.DLL 2015-05-07 11:23 - 2012-07-27 07:07 - 00087040 _____ (Brother Industries, Ltd.) C:\WINDOWS\system32\BrNetSti.dll 2015-05-07 11:23 - 2012-06-12 09:38 - 00054272 _____ (Brother Industries,Ltd) C:\WINDOWS\system32\Brnsplg.dll 2015-05-07 11:23 - 2012-04-11 06:27 - 00058880 _____ (Brother Industries,Ltd.) C:\WINDOWS\system32\BrWiaNCp.dll 2015-05-07 11:23 - 2012-03-19 06:09 - 00316928 _____ (brother) C:\WINDOWS\system32\NSSRH64.dll 2015-05-07 11:23 - 2005-04-22 06:36 - 00143360 _____ () C:\WINDOWS\system32\BrSNMP64.dll 2015-05-06 23:30 - 2015-03-03 15:17 - 00295552 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2015-05-06 23:26 - 2015-05-06 23:26 - 00000000 ____D () C:\WINDOWS\%LOCALAPPDATA% 2015-05-06 23:20 - 2015-05-06 23:19 - 00364472 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\aswBoot.exe 2015-05-06 23:19 - 2015-05-06 23:19 - 00043112 _____ (Avast Software s.r.o.) C:\WINDOWS\avastSS.scr 2015-05-06 21:53 - 2015-05-06 21:54 - 00000000 ____D () C:\Users\Marco Kerschbaum\Downloads\www.blockbusters.cc...Microsoft.Office.2010.Professional.Plus.GERMAN.x86.x64.FRiENDS.ONLY-BIE 2015-05-06 21:52 - 2015-05-06 21:52 - 00000861 _____ () C:\Users\Marco Kerschbaum\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2015-04-25 10:10 - 2015-04-25 10:10 - 00164352 _____ () C:\Users\Marco Kerschbaum\Downloads\qualitaetssicherung.ppt 2015-04-25 10:08 - 2015-04-25 10:08 - 00486400 _____ () C:\Users\Marco Kerschbaum\Downloads\Designgesten_ars_D_1_3.ppt ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-05-24 02:53 - 2014-12-03 00:15 - 00000000 ____D () C:\Users\Marco Kerschbaum 2015-05-24 02:01 - 2014-12-03 00:27 - 00001130 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-05-24 01:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2015-05-23 22:37 - 2014-12-03 00:21 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2379928720-2357665539-2892362255-1002 2015-05-23 22:27 - 2014-12-03 00:27 - 00001126 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-05-23 22:26 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-05-23 20:38 - 2014-12-03 00:24 - 00003962 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{D97625EB-C93D-4BB1-9720-3526D13DEE65} 2015-05-23 17:45 - 2014-12-02 22:12 - 00000000 ____D () C:\Users\Marco Kerschbaum\Documents\Outlook-Dateien 2015-05-23 16:38 - 2014-12-06 22:24 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Local\CrashDumps 2015-05-23 16:36 - 2013-08-22 17:20 - 00000000 ____D () C:\WINDOWS\CbsTemp 2015-05-23 16:30 - 2015-04-17 12:20 - 00000000 ___RD () C:\Users\Marco Kerschbaum\Dropbox 2015-05-23 16:30 - 2015-04-17 12:10 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox 2015-05-23 16:27 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2015-05-23 16:15 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\setup 2015-05-23 16:15 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\setup 2015-05-23 15:58 - 2013-10-16 04:55 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2015-05-23 15:58 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Help 2015-05-23 15:56 - 2013-10-16 04:56 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2015-05-23 15:52 - 2014-12-03 00:46 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Local\NVIDIA Corporation 2015-05-23 15:47 - 2015-03-21 12:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2015-05-23 15:47 - 2015-03-21 12:24 - 00000000 ____D () C:\Program Files (x86)\Samsung 2015-05-23 15:39 - 2015-02-07 11:45 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Roaming\vlc 2015-05-23 15:13 - 2013-09-21 23:01 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-05-23 15:13 - 2013-08-28 11:59 - 00765582 _____ () C:\WINDOWS\system32\perfh007.dat 2015-05-23 15:13 - 2013-08-28 11:59 - 00159366 _____ () C:\WINDOWS\system32\perfc007.dat 2015-05-23 13:07 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF 2015-05-23 13:03 - 2014-12-03 00:28 - 00002166 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-05-21 13:51 - 2015-04-05 11:42 - 00000000 ___SD () C:\WINDOWS\SysWOW64\GWX 2015-05-21 13:51 - 2015-04-05 11:42 - 00000000 ___SD () C:\WINDOWS\system32\GWX 2015-05-18 16:06 - 2015-01-12 13:09 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Roaming\MyPhoneExplorer 2015-05-18 13:07 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2015-05-18 11:49 - 2014-12-03 16:40 - 00025511 _____ () C:\WINDOWS\system32\lvcoinst.log 2015-05-18 11:32 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2015-05-18 11:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel 2015-05-18 11:28 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\AdvancedInstallers 2015-05-18 10:54 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2015-05-15 14:56 - 2014-12-03 00:27 - 00004102 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2015-05-15 14:56 - 2014-12-03 00:27 - 00003866 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2015-05-15 10:16 - 2014-12-03 02:29 - 140425016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-05-15 10:16 - 2014-12-03 02:29 - 00000000 ____D () C:\WINDOWS\system32\MRT 2015-05-15 10:09 - 2013-08-22 21:11 - 00000000 ____D () C:\Program Files\Windows Journal 2015-05-13 13:34 - 2014-12-10 12:15 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2015-05-12 09:45 - 2015-04-17 12:15 - 00001073 _____ () C:\Users\Marco Kerschbaum\Desktop\Dropbox.lnk 2015-05-12 09:45 - 2015-04-17 12:14 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-05-11 10:58 - 2015-04-16 12:30 - 00000954 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2015-05-11 10:58 - 2015-04-16 12:30 - 00000942 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk 2015-05-11 10:58 - 2015-04-16 12:30 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2015-05-09 19:43 - 2014-12-03 00:55 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Roaming\Nitro 2015-05-09 17:53 - 2014-12-03 00:27 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Local\Deployment 2015-05-09 17:52 - 2015-02-14 11:35 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zürich Versicherungs-Aktiengesellschaft 2015-05-09 14:39 - 2014-12-03 00:52 - 00001959 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Pro 9.lnk 2015-05-09 14:39 - 2014-12-03 00:52 - 00001947 _____ () C:\Users\Public\Desktop\Nitro Pro 9.lnk 2015-05-08 17:59 - 2013-09-21 23:27 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-05-08 17:24 - 2014-12-03 00:15 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Local\VirtualStore 2015-05-08 16:36 - 2014-12-03 12:48 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Roaming\Nitro PDF 2015-05-08 15:28 - 2014-12-03 01:00 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Local\Microsoft Help 2015-05-07 19:11 - 2014-12-03 01:08 - 00000000 __RDO () C:\Users\Marco Kerschbaum\SkyDrive 2015-05-07 15:55 - 2014-12-03 00:15 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Local\Packages 2015-05-07 12:22 - 2014-12-04 13:03 - 00000000 ____D () C:\Program Files (x86)\Brother 2015-05-07 12:21 - 2014-12-03 16:41 - 00000000 ____D () C:\Program Files (x86)\ControlCenter4 2015-05-07 12:20 - 2015-04-06 14:43 - 00000000 ____D () C:\Users\Marco Kerschbaum\AppData\Roaming\uTorrent 2015-05-07 12:20 - 2014-12-17 14:18 - 00000000 ____D () C:\WINDOWS\Minidump 2015-05-07 12:20 - 2013-09-22 08:31 - 00000000 ____D () C:\WINDOWS\Panther 2015-05-07 12:00 - 2014-12-03 00:35 - 00004182 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update 2015-05-07 09:47 - 2014-12-03 01:00 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-05-06 23:31 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2015-05-06 23:20 - 2014-12-03 00:35 - 00442264 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswSP.sys 2015-05-06 23:20 - 2014-12-03 00:35 - 00272248 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys 2015-05-06 23:20 - 2014-12-03 00:35 - 00137288 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswStm.sys 2015-05-06 23:20 - 2014-12-03 00:35 - 00089944 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2015-05-06 23:20 - 2014-12-03 00:35 - 00065736 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys 2015-05-06 23:19 - 2014-12-03 00:35 - 01047320 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswSnx.sys 2015-05-06 23:19 - 2014-12-03 00:35 - 00093528 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2015-05-06 23:19 - 2014-12-03 00:35 - 00029168 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys 2015-05-05 19:59 - 2015-03-13 14:32 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-05-05 19:59 - 2015-03-13 14:32 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-05-05 17:06 - 2015-02-07 11:44 - 00001057 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2015-05-05 17:01 - 2015-02-14 11:39 - 00000000 ____D () C:\Program Files (x86)\Java 2015-05-05 17:00 - 2015-02-14 11:40 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2015-04-29 15:29 - 2015-03-14 13:45 - 00000000 ____D () C:\AragPuls 2015-04-24 13:18 - 2015-03-03 19:23 - 00000000 ____D () C:\ProgramData\Origin ==================== Files in the root of some directories ======= 2015-03-23 14:00 - 2015-03-23 14:00 - 0004096 ____H () C:\Users\Marco Kerschbaum\AppData\Local\keyfile3.drm 2015-04-20 17:33 - 2015-04-20 17:33 - 0007597 _____ () C:\Users\Marco Kerschbaum\AppData\Local\Resmon.ResmonCfg 2015-05-07 14:47 - 2015-05-07 14:47 - 0000057 _____ () C:\ProgramData\Ament.ini 2013-10-16 05:00 - 2013-10-16 05:00 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some files in TEMP: ==================== C:\Users\Marco Kerschbaum\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp7jzghx.dll C:\Users\Marco Kerschbaum\AppData\Local\Temp\Execute2App.exe C:\Users\Marco Kerschbaum\AppData\Local\Temp\msvcp90.dll C:\Users\Marco Kerschbaum\AppData\Local\Temp\msvcr90.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-23 12:55 ==================== End of log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-05-2015 01 Ran by Marco Kerschbaum at 2015-05-24 02:55:12 Running from C:\Users\Marco Kerschbaum\Downloads Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2379928720-2357665539-2892362255-500 - Administrator - Disabled) Gast (S-1-5-21-2379928720-2357665539-2892362255-501 - Limited - Disabled) Marco Kerschbaum (S-1-5-21-2379928720-2357665539-2892362255-1002 - Administrator - Enabled) => C:\Users\Marco Kerschbaum ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) A1 Dashboard (x32 Version: 1.8.4.0 - A1 Telekom Austria AG) Hidden Adobe Photoshop Lightroom 5 64-bit (HKLM\...\{6C1A010F-9108-4162-A26F-9FEC4AC0F0F0}) (Version: 5.0.1 - Adobe) Adobe Reader XI (11.0.11) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Apple Application Support (32-Bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.) Apple Application Support (64-Bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) AragPuls Version 15.1 (HKLM-x32\...\AragPuls_is1) (Version: 15.1 - ) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software) Bonnprint/iText (HKLM-x32\...\BPiText) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 5.05 - Piriform) DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation) Dropbox (HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\Dropbox) (Version: 3.4.6 - Dropbox, Inc.) DTS Studio Sound (HKLM-x32\...\{2DFA9084-CEB3-4A48-B9F7-9038FEF1B8F4}) (Version: 1.01.2700 - DTS, Inc.) EA SPORTS™ FIFA 15 (HKLM-x32\...\{3D4ADA2B-F028-4307-ADF4-6F9AA44725DA}) (Version: 1.4.0.0 - Electronic Arts) ELAN Touchpad 11.8.43.1_X64_WHQL (HKLM\...\Elantech) (Version: 11.8.43.1 - ELAN Microelectronic Corp.) Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.3.0 - SEIKO EPSON CORPORATION) Epson Customer Research Participation (HKLM\...\{B26449A6-6007-4460-B4FE-C4776115BCEA}) (Version: 1.70.0000 - EPSON) Epson Easy Photo Print 2 (HKLM-x32\...\{71E90740-5E5F-4D43-AB8F-CAC1D93DBB5B}) (Version: 2.5.0.0 - SEIKO EPSON CORPORATION) Epson Event Manager (HKLM-x32\...\{0F13C24A-FFE2-4CD0-8E0B-DC804E0A0E0B}) (Version: 3.10.0035 - Seiko Epson Corporation) Epson FAX Utility (HKLM-x32\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.52.00 - SEIKO EPSON CORPORATION) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON WF-7610 Series Printer Uninstall (HKLM\...\EPSON WF-7610 Series) (Version: - SEIKO EPSON Corporation) EPSON-Handbücher (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.40.0.0 - SEIKO EPSON CORPORATION) EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION) Free YouTube Download version 3.2.56.324 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.56.324 - DVDVideoSoft Ltd.) Genesys Logic USB2.0 Card Reader (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: 4.3.0.7 - Genesys Logic) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.65 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden Gothaer Angebotssystem Leben - Kompakt - Version 2014.4.0 (HKLM-x32\...\Gothaer Angebotssystem Leben - Kompakt_is1) (Version: - Gothaer Lebensversicherung AG) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3282 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.2.1000 - Intel Corporation) Intel(R) Smart Connect Technology (HKLM\...\{9B5FD763-5074-474C-B898-24567E6450C8}) (Version: 4.2.40.2439 - Intel Corporation) Intel(R) Wireless Bluetooth(R) 4.0 (HKLM-x32\...\{38561F82-2984-4C99-ADD7-D1166BC3D552}) (Version: 3.0.1335.05 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{72814a2c-2e03-4a50-b30a-43e7884b3934}) (Version: 16.5.1 - Intel Corporation) Internet Manager (HKLM-x32\...\Internet Manager) (Version: 22.001.18.87.55 - Huawei Technologies Co.,Ltd) iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.) Java 7 Update 75 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217075FF}) (Version: 7.0.750 - Oracle) Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) Maklernetz KFZ BlitzRechner 15.04 (HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\81e1f5ffb113af1d) (Version: 15.4.0.0 - Zürich Versicherungs-Aktiengesellschaft) MASnet Version 6.3.9 (HKLM-x32\...\MASnet) (Version: - Merkur Versicherung AG) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.10.106.1 - McAfee, Inc.) Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Outlook Hotmail Connector 64-Bit (HKLM\...\{95140000-0081-0407-1000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{d07b0db5-8dad-40e1-be90-88026298a46b}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{2749c485-3a8b-4533-92ff-7cf6e8221cff}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Preview Redistributable (x64) - 12.0.20617 (HKLM-x32\...\{448652c1-f5f3-4230-98c6-68c10c88b1fb}) (Version: 12.0.20617.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Preview Redistributable (x86) - 12.0.20617 (HKLM-x32\...\{1f407217-9aec-4146-8504-e64ac959c534}) (Version: 12.0.20617.1 - Microsoft Corporation) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.6 - F.J. Wechselberger) Nitro Pro 9 (HKLM\...\{4A53F617-750C-4322-86FC-02F467B0CA70}) (Version: 9.5.2.29 - Nitro) NVIDIA Grafiktreiber 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 350.12 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.5.5.2850 - Electronic Arts, Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.19.726.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden Software Updater (HKLM-x32\...\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.41459 - TeamViewer) TOSHIBA Addendum (HKLM-x32\...\{CE0374A6-B204-4336-8293-63FBB1DADBF4}) (Version: 1.00 - TOSHIBA) TOSHIBA Desktop Assist (HKLM\...\{95CCACF0-010D-45F0-82BF-858643D8BC02}) (Version: 1.02.01.6407 - Toshiba Corporation) TOSHIBA Display Utility (HKLM\...\{F64E9295-E1B3-4EEA-86D3-AF44A0087B06}) (Version: 1.1.16.0 - Toshiba Corporation) TOSHIBA eco Utility (HKLM\...\{5944B9D4-3C2A-48DE-931E-26B31714A2F7}) (Version: 2.2.0.6404 - Toshiba Corporation) TOSHIBA Flash Cards Support Utility (HKLM-x32\...\InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}) (Version: 1.51.81.1C - TOSHIBA CORPORATION) TOSHIBA Function Key (HKLM\...\{16562A90-71BC-41A0-B890-D91B0C267120}) (Version: 1.1.0001.6403 - Toshiba Corporation) TOSHIBA Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.14 - TOSHIBA) TOSHIBA Password Utility (HKLM-x32\...\InstallShield_{59358FD4-252B-4B38-AB81-955C491A494F}) (Version: 2.0.0.9C - Toshiba Corporation) TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 3.1.02.55065006 - Toshiba Corporation) TOSHIBA Service Station (HKLM\...\{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}) (Version: 2.6.8 - Toshiba Corporation) TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0030 - Toshiba Corporation) TOSHIBA System Settings (HKLM-x32\...\{05A55927-DB9B-4E26-BA44-828EBFF829F0}) (Version: 1.1.2.32001 - Toshiba Corporation) Utility Common Driver (x32 Version: 1.0.53.3 - Compal) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) CustomCLSID: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2379928720-2357665539-2892362255-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) ==================== Restore Points ========================= 08-05-2015 14:19:27 Removed HP Support Solutions Framework 15-05-2015 10:08:08 Windows Update 21-05-2015 13:50:11 Windows Update 23-05-2015 13:33:59 Installed Samsung Kies3 ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {05FD34D9-CF8A-4ECD-929D-11E0F079A0A8} - System32\Tasks\EPSON WF-7610 Series Invitation {29F1BE0F-D6FF-439C-9A74-924EFE4BFEEB} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKBE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {130E6837-DE38-4A34-8B9B-6160D9FD4925} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-03] (Google Inc.) Task: {1DC731F1-9E68-4F77-B9C3-5C2CF4916882} - System32\Tasks\EPSON WF-7610 Series Invitation {CE29CF18-0AB1-460B-8309-46B24131E63A} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKBE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {282EFAFA-75C8-43AB-BC0E-37EEA4A0D6A2} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {28D1617A-AF82-4F3A-9CD2-A196A2204C88} - System32\Tasks\UMonitor Task => C:\Windows\SysWOW64\UMonit64.exe [2013-08-08] () Task: {3CAEBBA3-1BFB-44B8-8080-587296055A68} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {403F1DA1-CC34-42D6-82BF-F1BA366CA012} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-05-15] (Microsoft Corporation) Task: {43FFC7AB-CFFE-4109-AA8B-7AA45540ACFA} - System32\Tasks\EPSON WF-7610 Series Invitation {FD026A1A-1AAB-4963-9E70-67874C0ED2B3} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKBE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {56AC0B89-06CC-4719-A188-AB055DDD4F22} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-04-30] (Oracle Corporation) Task: {595E817C-8966-4D23-A9B7-310C39A29B3C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-04-23] (Piriform Ltd) Task: {60E45C30-7DED-4C43-9ADA-329023F50660} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-03] (Google Inc.) Task: {62B81400-B6E9-48C2-820F-C5ED1D6CE42E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-05-06] (Avast Software s.r.o.) Task: {6617CB91-55B6-4BE7-876C-BCB32706FC9A} - System32\Tasks\HPPSdr Restart Diagnose => C:\Users\MARCOK~1\AppData\Local\Temp\7zS6376\HPDiagnosticCoreUI.exe <==== ATTENTION Task: {697541CC-2EC6-4796-9055-C1D616F9FD7B} - System32\Tasks\EPSON WF-7610 Series Update {CE29CF18-0AB1-460B-8309-46B24131E63A} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKBE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {7B0DC902-EF19-4B80-929A-BD1D400D8871} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-06] (Microsoft Corporation) Task: {8810E2F0-9360-4785-A52F-0E0717C944A9} - System32\Tasks\EPSON WF-7610 Series Update {FD026A1A-1AAB-4963-9E70-67874C0ED2B3} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKBE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {A240DCE5-A4B8-4496-B294-0DE30C5FB6B0} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation) Task: {E0D39FD3-9190-47F9-98EE-D919921CAEFD} - System32\Tasks\Resolution+ Setting Task => C:\Program Files\Toshiba\TOSHIBA Smart View Utility\Plugins\ResolutionPlus\TosRegPermissionChg.exe [2013-11-07] (TOSHIBA Corporation) Task: {F003C073-82C6-47D2-82B2-55A0FB94DF52} - System32\Tasks\EPSON WF-7610 Series Update {29F1BE0F-D6FF-439C-9A74-924EFE4BFEEB} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKBE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: C:\WINDOWS\Tasks\EPSON WF-7610 Series Invitation {29F1BE0F-D6FF-439C-9A74-924EFE4BFEEB}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKBE.EXE Task: C:\WINDOWS\Tasks\EPSON WF-7610 Series Invitation {CE29CF18-0AB1-460B-8309-46B24131E63A}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKBE.EXE Task: C:\WINDOWS\Tasks\EPSON WF-7610 Series Invitation {FD026A1A-1AAB-4963-9E70-67874C0ED2B3}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKBE.EXE Task: C:\WINDOWS\Tasks\EPSON WF-7610 Series Update {29F1BE0F-D6FF-439C-9A74-924EFE4BFEEB}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKBE.EXE:/EXE:{29F1BE0F-D6FF-439C-9A74-924EFE4BFEEB} /F:UpdateWORKGROUP\MARCO$ Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\EPSON WF-7610 Series Update {CE29CF18-0AB1-460B-8309-46B24131E63A}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKBE.EXE:/EXE:{CE29CF18-0AB1-460B-8309-46B24131E63A} /F:UpdateWORKGROUP\MARCO$ Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\EPSON WF-7610 Series Update {FD026A1A-1AAB-4963-9E70-67874C0ED2B3}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKBE.EXE:/EXE:{FD026A1A-1AAB-4963-9E70-67874C0ED2B3} /F:UpdateWORKGROUP\MARCO$ Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2015-04-14 19:17 - 2015-04-09 02:58 - 00012104 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2015-05-23 15:58 - 2015-04-08 23:30 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-03-20 18:12 - 2015-03-20 18:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-03-20 18:12 - 2015-03-20 18:12 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-09-10 21:54 - 2013-09-10 21:54 - 00019792 _____ () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe 2013-02-06 08:10 - 2013-02-06 08:10 - 00351824 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2015-01-20 15:51 - 2013-08-16 08:53 - 00671744 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe 2013-08-13 04:06 - 2013-08-13 04:06 - 00198120 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe 2013-08-13 04:06 - 2013-08-13 04:06 - 00054760 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll 2013-08-13 04:06 - 2013-08-13 04:06 - 00034792 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll 2014-07-16 15:50 - 2014-07-16 15:50 - 00417800 _____ () C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe 2013-04-04 02:09 - 2013-04-04 02:09 - 04300432 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2013-10-16 05:07 - 2013-08-08 19:08 - 00065536 _____ () C:\Windows\SysWOW64\UMonit64.exe 2012-07-19 03:38 - 2012-07-19 03:38 - 00020904 _____ () C:\Program Files\TOSHIBA\Hotkey\SmoothView.dll 2015-04-08 21:53 - 2015-04-08 21:53 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2015-05-06 23:19 - 2015-05-06 23:19 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-05-06 23:19 - 2015-05-06 23:19 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-05-23 20:17 - 2015-05-23 20:17 - 02931200 _____ () C:\Program Files\AVAST Software\Avast\defs\15052302\algo.dll 2015-01-20 15:51 - 2013-08-16 08:53 - 00011362 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll 2015-01-20 15:51 - 2013-08-16 08:53 - 00043008 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll 2015-01-20 15:51 - 2013-08-16 08:53 - 02417152 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll 2015-01-20 15:51 - 2013-08-16 08:53 - 01148416 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll 2015-05-06 23:19 - 2015-05-06 23:19 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-05-23 22:27 - 2015-05-23 22:27 - 00043008 _____ () c:\Users\Marco Kerschbaum\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp7jzghx.dll 2015-03-04 23:45 - 2015-03-04 23:45 - 00750080 _____ () C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2015-03-04 23:45 - 2015-03-04 23:45 - 00047616 _____ () C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\libEGL.dll 2015-03-04 23:45 - 2015-03-04 23:45 - 00865280 _____ () C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll 2015-03-04 23:45 - 2015-03-04 23:45 - 00200704 _____ () C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll 2013-10-16 04:51 - 2013-09-03 16:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Marco Kerschbaum\SkyDrive:ms-properties AlternateDataStreams: C:\Users\Marco Kerschbaum\Desktop\Telefonaquise.docx:com.dropbox.attributes ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Marco Kerschbaum\AppData\Roaming\Microsoft\Windows Photo Viewer\Hintergrundbild der Windows-Fotoanzeige.jpg DNS Servers: Media is not connected to internet. ==================== MSCONFIG/TASK MANAGER Error getting == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk" HKLM\...\StartupApproved\Run: => "BCSSync" HKLM\...\StartupApproved\Run: => "Nvtmru" HKLM\...\StartupApproved\Run: => "TecoResident" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\StartupApproved\Run: => "OfficeSyncProcess" HKU\S-1-5-21-2379928720-2357665539-2892362255-1002\...\StartupApproved\Run: => "MyPhoneExplorer" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{A313CB27-5D03-40AB-917E-495E0580537D}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [TCP Query User{8D83DB93-8ABA-4002-9D1C-602938882937}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe] => (Allow) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe FirewallRules: [UDP Query User{3301A368-F834-46EA-A96B-D8AD0F6EE391}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe] => (Allow) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe FirewallRules: [TCP Query User{4FE1F838-9B80-4525-AA05-243D0E2894CE}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe] => (Allow) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe FirewallRules: [UDP Query User{A8B77F60-0D87-4597-89B2-0883608F11E4}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe] => (Allow) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe FirewallRules: [TCP Query User{D9F6D0ED-FC98-4D90-81D2-034F0F31258A}C:\merkur\masnet\java\bin\javaw.exe] => (Allow) C:\merkur\masnet\java\bin\javaw.exe FirewallRules: [UDP Query User{92024090-F375-4D52-9531-217589F69573}C:\merkur\masnet\java\bin\javaw.exe] => (Allow) C:\merkur\masnet\java\bin\javaw.exe FirewallRules: [{36F30D26-9E1F-426D-9620-6E5BD99FE2CF}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 15\fifasetup\fifaconfig.exe FirewallRules: [{A69D93FF-4FBD-4AEE-A62C-A48F12CA3825}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 15\fifasetup\fifaconfig.exe FirewallRules: [TCP Query User{81B4DFC7-154E-4772-949C-26359B63597F}C:\merkur\masnet\java\bin\javaw.exe] => (Allow) C:\merkur\masnet\java\bin\javaw.exe FirewallRules: [UDP Query User{D1EF5CDA-CE47-411E-B926-F6A95989FAAE}C:\merkur\masnet\java\bin\javaw.exe] => (Allow) C:\merkur\masnet\java\bin\javaw.exe FirewallRules: [{691E520F-90B4-4E55-BEAB-E262D45AFAA7}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [TCP Query User{27FBE9FF-565B-45C0-8EAC-C31AE32FF24D}C:\program files (x86)\origin games\fifa 15\fifa15.exe] => (Allow) C:\program files (x86)\origin games\fifa 15\fifa15.exe FirewallRules: [UDP Query User{0A1F0CF7-6442-4EBC-A90A-87D12DC0FA90}C:\program files (x86)\origin games\fifa 15\fifa15.exe] => (Allow) C:\program files (x86)\origin games\fifa 15\fifa15.exe FirewallRules: [TCP Query User{4E412416-1536-4367-9A71-5280594668F8}C:\users\marco kerschbaum\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\marco kerschbaum\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{A79433DA-6C32-4788-B112-4C25C0A47A29}C:\users\marco kerschbaum\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\marco kerschbaum\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{782C07B4-4B6D-41D5-970D-A09550F0B1F6}] => (Allow) C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{FC389D05-3CD9-49F0-9A65-B09836522838}] => (Allow) C:\Users\Marco Kerschbaum\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{C20A0A4C-0F20-4F5B-80A0-608B2A8B0FAA}] => (Allow) C:\Users\Marco Kerschbaum\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{1E187511-F035-4B3D-8D3B-F9FDDEAEFA1C}] => (Allow) C:\Users\Marco Kerschbaum\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{08B6067D-FE6D-4DEB-A230-CDFCF9966535}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{6024BC43-BD60-4BD3-BE98-C04203445D5C}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{18F57946-940D-48B2-949F-C723AFC16555}] => (Allow) C:\Program Files (x86)\Epson Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{5F5FDA8C-D72D-491E-9214-4034A9BDF959}] => (Allow) C:\Program Files (x86)\Epson Software\ECPrinterSetup\ENPApp.exe FirewallRules: [TCP Query User{9D82B022-8B97-4365-B073-EE9C4E4EB8A3}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{4CD26325-A8D1-4A1A-A44B-0BFE3A71D897}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{6723A29F-DDB4-43C9-AB69-073952747F3B}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{59181C15-A70B-42F1-8F7F-42089A93FCA8}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [{A91DDECA-E5FD-4807-AA2B-47BB7E66714C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{CF2E381D-3A7F-4629-919D-4DDD6E7560BC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{09E972BF-AEA8-48B4-AB63-113395BDC8A8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{E4586875-0D15-410A-A86E-F41368E1013E}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{A2954533-AE84-4124-8C0F-63B775A44CD1}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= Name: HID-Tastatur Description: HID-Tastatur Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: kbdhid Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19) Resolution: A registry problem was detected. This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options: On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver. Name: ELAN Input Device Description: ELAN Input Device Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: ELAN Service: i8042prt Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Erweiterte PC/AT-PS/2-Tastatur (101/102 Tasten) Description: Erweiterte PC/AT-PS/2-Tastatur (101/102 Tasten) Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19) Resolution: A registry problem was detected. This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options: On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver. ==================== Event log errors: ========================= Application errors: ================== Error: (05/23/2015 10:45:33 PM) (Source: VSS) (EventID: 12294) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen einer Routine auf dem Schattenkopieanbieter "{b5946137-7b9f-4925-af80-51abd60b20d5}" ist ein Fehler aufgetreten. Die Routine hat E_INVALIDARG zurückgegeben. Routinedetails GetSnapshot({00000000-0000-0000-0000-000000000000},000000703C4F6B00). Vorgang: Eigenschaften der Schattenkopie abrufen Kontext: Ausführungskontext: Coordinator Error: (05/23/2015 09:16:42 PM) (Source: Windows Search Service) (EventID: 1019) (User: ) Description: Die Liste der eingeschlossenen und ausgeschlossenen Adressen konnte vvon Windows Search nicht verarbeitet werden. Fehler: <30, 0x80040d07, "iehistory://{S-1-5-21-2379928720-2357665539-2892362255-1002}/">. Error: (05/23/2015 08:34:00 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.3.9600.17415 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 149c Startzeit: 01d095864dc298d3 Endzeit: 4294967295 Anwendungspfad: C:\WINDOWS\syswow64\wwahost.exe Berichts-ID: 4143f013-017a-11e5-828d-201a06788cfd Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App Error: (05/23/2015 06:29:31 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.3.9600.17415 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 10bc Startzeit: 01d0957159496fec Endzeit: 4294967295 Anwendungspfad: C:\WINDOWS\syswow64\wwahost.exe Berichts-ID: cca172a0-0168-11e5-828d-201a06788cfd Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App Error: (05/23/2015 05:52:03 PM) (Source: Windows Search Service) (EventID: 1019) (User: ) Description: Die Liste der eingeschlossenen und ausgeschlossenen Adressen konnte vvon Windows Search nicht verarbeitet werden. Fehler: <30, 0x80040d07, "iehistory://{S-1-5-21-2379928720-2357665539-2892362255-1002}/">. Error: (05/23/2015 05:51:16 PM) (Source: Windows Search Service) (EventID: 1019) (User: ) Description: Die Liste der eingeschlossenen und ausgeschlossenen Adressen konnte vvon Windows Search nicht verarbeitet werden. Fehler: <30, 0x80040d07, "iehistory://{S-1-5-21-2379928720-2357665539-2892362255-1002}/">. Error: (05/23/2015 05:48:06 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.3.9600.17415 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 5ac Startzeit: 01d0956f25306f14 Endzeit: 4294967295 Anwendungspfad: C:\WINDOWS\syswow64\wwahost.exe Berichts-ID: 18852058-0163-11e5-828d-201a06788cfd Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App Error: (05/23/2015 05:44:28 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm CCleaner64.exe, Version 5.5.0.5176 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1714 Startzeit: 01d09569ecf6a9bd Endzeit: 5530 Anwendungspfad: C:\Program Files\CCleaner\CCleaner64.exe Berichts-ID: 5e515a5f-0161-11e5-828d-201a06788cfd Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (05/23/2015 05:43:21 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm CCleaner64.exe, Version 5.5.0.5176 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1720 Startzeit: 01d09565d99b9ca2 Endzeit: 1765 Anwendungspfad: C:\Program Files\CCleaner\CCleaner64.exe Berichts-ID: 6782ee8e-0162-11e5-828d-201a06788cfd Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (05/23/2015 05:30:30 PM) (Source: Windows Search Service) (EventID: 1019) (User: ) Description: Die Liste der eingeschlossenen und ausgeschlossenen Adressen konnte vvon Windows Search nicht verarbeitet werden. Fehler: <30, 0x80040d07, "iehistory://{S-1-5-21-2379928720-2357665539-2892362255-1002}/">. System errors: ============= Error: (05/23/2015 10:26:44 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (05/23/2015 10:26:44 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht. Error: (05/23/2015 07:46:37 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst defragsvc erreicht. Error: (05/23/2015 04:29:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (05/23/2015 04:29:11 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht. Error: (05/23/2015 04:27:05 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070103 fehlgeschlagen: Elan - Other hardware - ELAN Input Device Error: (05/23/2015 04:26:41 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x8024ce0a fehlgeschlagen: Elan - Other hardware - ELAN Input Device Error: (05/23/2015 04:19:48 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0841 fehlgeschlagen: Update für Windows 8.1 für x64-Systeme (KB3034348) Error: (05/23/2015 04:19:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (05/23/2015 04:19:05 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht. Microsoft Office: ========================= Error: (05/23/2015 10:45:33 PM) (Source: VSS) (EventID: 12294) (User: ) Description: {b5946137-7b9f-4925-af80-51abd60b20d5}GetSnapshot({00000000-0000-0000-0000-000000000000},000000703C4F6B00) Vorgang: Eigenschaften der Schattenkopie abrufen Kontext: Ausführungskontext: Coordinator Error: (05/23/2015 09:16:42 PM) (Source: Windows Search Service) (EventID: 1019) (User: ) Description: 300x80040d07iehistory://{S-1-5-21-2379928720-2357665539-2892362255-1002}/ Error: (05/23/2015 08:34:00 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.3.9600.17415149c01d095864dc298d34294967295C:\WINDOWS\syswow64\wwahost.exe4143f013-017a-11e5-828d-201a06788cfdMicrosoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5cApp Error: (05/23/2015 06:29:31 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.3.9600.1741510bc01d0957159496fec4294967295C:\WINDOWS\syswow64\wwahost.execca172a0-0168-11e5-828d-201a06788cfdMicrosoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5cApp Error: (05/23/2015 05:52:03 PM) (Source: Windows Search Service) (EventID: 1019) (User: ) Description: 300x80040d07iehistory://{S-1-5-21-2379928720-2357665539-2892362255-1002}/ Error: (05/23/2015 05:51:16 PM) (Source: Windows Search Service) (EventID: 1019) (User: ) Description: 300x80040d07iehistory://{S-1-5-21-2379928720-2357665539-2892362255-1002}/ Error: (05/23/2015 05:48:06 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.3.9600.174155ac01d0956f25306f144294967295C:\WINDOWS\syswow64\wwahost.exe18852058-0163-11e5-828d-201a06788cfdMicrosoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5cApp Error: (05/23/2015 05:44:28 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: CCleaner64.exe5.5.0.5176171401d09569ecf6a9bd5530C:\Program Files\CCleaner\CCleaner64.exe5e515a5f-0161-11e5-828d-201a06788cfd Error: (05/23/2015 05:43:21 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: CCleaner64.exe5.5.0.5176172001d09565d99b9ca21765C:\Program Files\CCleaner\CCleaner64.exe6782ee8e-0162-11e5-828d-201a06788cfd Error: (05/23/2015 05:30:30 PM) (Source: Windows Search Service) (EventID: 1019) (User: ) Description: 300x80040d07iehistory://{S-1-5-21-2379928720-2357665539-2892362255-1002}/ ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4200U CPU @ 1.60GHz Percentage of memory in use: 19% Total physical RAM: 8107.68 MB Available physical RAM: 6515.36 MB Total Pagefile: 9387.68 MB Available Pagefile: 7784.34 MB Total Virtual: 131072 MB Available Virtual: 131071.8 MB ==================== Drives ================================ Drive c: (TI31217500A) (Fixed) (Total:687.32 GB) (Free:530.55 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 698.6 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End of log ============================ Danke Mfg |
Themen zu Win8, DHL-mail geöffnet nach Win-Update HDI-Tastatur keine funktion (Code 19) |
adobe, adware, antivirus, bildschirm, browser, cpu, defender, desktop, email, error, failed, fehler, installation, mozilla, onedrive, programm, registry, scan, security, software, svchost.exe, system, tastatur, udp, usb, virus |