Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: DHL Spam Mail -> Trojaner/Virus?

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 15.06.2015, 15:45   #1
flowerwithlo
 
DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



Hallo liebes Trojaner Board Team,

es kam vor kurzem eine DHL Spam Mail mit einem PDF Anhang. Mein Vater öffnete diese PDF und klickte darin evtl. (er weiß es nicht mehr genau, ist schon 2 Wochen her) auf einen Link.
Habe nun mit Avira einen Suchlauf gemacht und er hat zwar was gefunden (6 was), es ist jedoch möglich, dass das nur Fehlalarme waren, hab sie auf jeden Fall in Quarantäne verschoben.
Nun stellt sich für mich die Frage: Habe ich einen Trojaner/Virus bzw. wenn ja, wie bekomme ich diesen wieder runter?

PS: Habe Win7

Hoffe ihr könnt mir helfen
flowerwithlo

Geändert von flowerwithlo (15.06.2015 um 16:20 Uhr)

Alt 15.06.2015, 16:56   #2
schrauber
/// the machine
/// TB-Ausbilder
 

DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 15.06.2015, 17:41   #3
flowerwithlo
 
DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



Mein Benutzer ist kein Admin, soll ich den Scan dann einfach mit nem Admin-Konto ausführen (also bei "als Admin ausführen" einen anderen Admin auswählen) oder mein Konto als Admin machen?!

Danke schon mal für deine Hilfe

LG flowerwithlo

So, hab den Scan jetzt einfach mal ohne Admin Rechte gemacht:


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-06-2015
Ran by Philipp (ATTENTION: The logged in user is not administrator) on SCHEFFLER-PC on 15-06-2015 18:34:54
Running from C:\Users\Philipp\Desktop
Loaded Profiles: Jeffel & Philipp & Beamer & Ellen & Manuel & Manuel (Available Profiles: Jeffel & Philipp & Beamer & Ellen & Manuel & Manuel)
Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> lsm.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> atiesrxx.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> ADSMSrv.exe
Failed to access process -> AsLdrSrv.exe
Failed to access process -> GFNEXSrv.exe
Failed to access process -> spoolsv.exe
Failed to access process -> sched.exe
Failed to access process -> svchost.exe
Failed to access process -> armsvc.exe
Failed to access process -> avguard.exe
Failed to access process -> AppleMobileDeviceService.exe
Failed to access process -> mDNSResponder.exe
Failed to access process -> svchost.exe
Failed to access process -> escsvc.exe
Failed to access process -> E_S60RP7.EXE
Failed to access process -> svchost.exe
Failed to access process -> DVMExportService.exe
Failed to access process -> PublicWiFiService.exe
Failed to access process -> spmgr.exe
Failed to access process -> ss_conn_service.exe
Failed to access process -> WLIDSVC.EXE
Failed to access process -> Avira.ServiceHost.exe
Failed to access process -> GoogleCrashHandler.exe
Failed to access process -> WLIDSVCM.EXE
Failed to access process -> WmiPrvSE.exe
Failed to access process -> avshadow.exe
Failed to access process -> svchost.exe
Failed to access process -> SearchIndexer.exe
Failed to access process -> alg.exe
Failed to access process -> TrustedInstaller.exe
Failed to access process -> wmpnetwk.exe
Failed to access process -> FABS.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> dllhost.exe
Failed to access process -> OSPPSVC.EXE
Failed to access process -> svchost.exe
Failed to access process -> WmiPrvSE.exe
Failed to access process -> csrss.exe
Failed to access process -> winlogon.exe
Failed to access process -> atieclxx.exe
Failed to access process -> BatteryLife.exe
Failed to access process -> wcourier.exe
Failed to access process -> HControl.exe
Failed to access process -> ATKOSD.exe
Failed to access process -> KBFiltr.exe
Failed to access process -> WDC.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files\ASUS\ATK Media\DMedia.exe
(AlcorMicro Co., Ltd.) C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
() D:\Gaming Maus\DareUMonitor.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-Agent.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATILEE.EXE
(Dropbox, Inc.) C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
Failed to access process -> WmiPrvSE.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe
(Valve Corporation) D:\Steam\Steam.exe
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe
Failed to access process -> SteamService.exe
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe
Failed to access process -> SearchProtocolHost.exe
Failed to access process -> svchost.exe
Failed to access process -> SearchFilterHost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1549608 2009-08-17] (Synaptics Incorporated)
HKLM\...\Run: [HControlUser] => C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM\...\Run: [ATKOSD2] => C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS)
HKLM\...\Run: [ATKMEDIA] => C:\Program Files\ASUS\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS)
HKLM\...\Run: [AmIcoSinglun] => C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe [233472 2009-07-31] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [ADSMTray] => C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [272952 2009-06-24] (ASUSTek Computer Inc.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [730416 2015-06-11] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Dare-U mouse] => D:\Gaming Maus\DareUMonitor.exe [786432 2012-11-20] ()
HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1065024 2014-05-02] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [BlueStacks Agent] => C:\Program Files\BlueStacks\HD-Agent.exe [884440 2015-05-28] (BlueStack Systems, Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.Systray.exe [130864 2015-05-21] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.)
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [DAEMON Tools Lite] => D:\DT\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [Steam] => D:\Steam\steam.exe [2892992 2015-06-04] (Valve Corporation)
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [21969480 2015-05-19] (Google)
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION)
Lsa: [Notification Packages] scecli C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT
Startup: C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-05-12]
ShortcutTarget: Dropbox.lnk -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2011-03-30]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-12-13]
ShortcutTarget: Dropbox.lnk -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2011-03-31]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ADSMOverlayIcon] -> {A825576B-0042-4F0F-8FB0-93CE0F054E69} => C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll [2007-06-15] ()
ShellIconOverlayIdentifiers: [ADSMOverlayIcon1] -> {A8D448F4-0431-45AC-9F5E-E1B434AB2249} => C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll [2007-06-01] ()
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
GroupPolicyUsers\S-1-5-21-644356114-2566177158-2502637254-1004\User: Group Policy Restriction detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com/
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://www.google.de/
URLSearchHook: [S-1-5-21-644356114-2566177158-2502637254-1000] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} -  No File
URLSearchHook: [S-1-5-21-644356114-2566177158-2502637254-1005] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-21-644356114-2566177158-2502637254-1008] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-21-644356114-2566177158-2502637254-1011] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKLM -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS
SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {76193214-59DA-47ED-BB15-3BCACFC2C36A} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {7B55E28C-0351-41CC-AC14-22094D95924D} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {B1316728-20A2-4B2A-9CD7-B52C1B2CB91A} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q={searchTerms}
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} ->  No File
BHO: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH)
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.177.1

FireFox:
========
FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default
FF DefaultSearchEngine: Google.de
FF SearchEngineOrder.1: Ask.com
FF SelectedSearchEngine: Google.de
FF Homepage: hxxp://de.yahoo.com/|https://www.google.de/
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-20] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2009-09-07] (CANON INC.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-644356114-2566177158-2502637254-1004: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Philipp\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-10-03] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-02-16] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-02-16] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-02-16] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-02-16] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-02-16] (Apple Inc.)
FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\ebay-durchsuchen.xml [2012-10-14]
FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\firefox-add-ons.xml [2011-07-08]
FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\googlede.xml [2012-05-18]
FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\suche-in-wikipedia.xml [2011-07-08]
FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\youtube-videosuche.xml [2012-07-07]
FF Extension: Avira Browser Safety - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\abs@avira.com [2015-05-30]
FF Extension: LavaFox V2-Purple - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\zigboom555@aol.com [2015-05-05]
FF Extension: Blue Fox - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{241aae70-0022-11de-87af-0800200c9a66} [2014-07-31]
FF Extension: Bloody Red - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{2458abc0-f443-11dd-87af-0800200c9a66} [2013-08-19]
FF Extension: FT DeepDark - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2015-04-22]
FF Extension: Add to Amazon Wish List Button - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\amznUWL2@amazon.com.xpi [2013-09-15]
FF Extension: YouTube to MP3 - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\youtube2mp3@mondayx.de.xpi [2012-01-19]
FF Extension: ProxTube - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}.xpi [2014-07-31]
FF Extension: AniWeather - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi [2011-07-08]
FF Extension: Nuri - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{beab8ae9-eb2d-4ded-3b29-d35f6b82bfa5}.xpi [2012-12-23]
FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-07-31]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-06-02]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-12-13]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-06-02]

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.) [File not signed]
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [827184 2015-06-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [450808 2015-06-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [450808 2015-06-11] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1188360 2015-06-11] (Avira Operations GmbH & Co. KG)
R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS)
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed]
R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [208632 2015-05-21] (Avira Operations GmbH & Co. KG)
S3 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [433880 2015-05-28] (BlueStack Systems, Inc.)
S3 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [413400 2015-05-28] (BlueStack Systems, Inc.)
S3 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [806616 2015-05-28] (BlueStack Systems, Inc.)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc.exe [126128 2012-05-17] (Seiko Epson Corporation)
R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE [143424 2013-04-26] (SEIKO EPSON CORPORATION)
R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
S3 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
R2 lmhosts; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 MDES; C:\ASUS.SYS\DVMExportService.exe [307200 2008-10-21] (DeviceVM) [File not signed]
R2 MyPublicWiFiService; C:\Program Files\MyPublicWiFi\PublicWiFiService.exe [756224 2013-04-03] () [File not signed]
R2 NlaSvc; C:\Windows\System32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1997168 2015-06-08] (Electronic Arts)
R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] ()
R2 ss_conn_service; D:\Samsung Kies\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S3 WinHttpAutoProxySvc; winhttp.dll [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AmUStor; C:\Windows\System32\drivers\AmUStor.SYS [25600 2009-07-24] (Alcor Micro, Corp.)
R0 AsDsm; C:\Windows\system32\Drivers\AsDsm.sys [30264 2009-12-25] (ASUSTek Computer Inc)
R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-06-11] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-06-11] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-20] (Avira Operations GmbH & Co. KG)
R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [105728 2014-09-29] (AVM Berlin)
R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [105728 2014-09-29] (AVM Berlin)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-11] (Avira Operations GmbH & Co. KG)
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [131288 2015-05-28] (BlueStack Systems)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-11-21] (Disc Soft Ltd)
R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2009-06-18] (Windows (R) Win 7 DDK provider)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [14392 2009-05-13] (ASUS)
R1 ndiskhaz; C:\Windows\System32\DRIVERS\ndiskhaz.sys [25416 2012-12-07] (Khalil Azzouzi)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1766592 2009-06-05] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [324096 2013-11-21] (Duplex Secure Ltd.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-06-11] (Avira Operations GmbH & Co. KG)
R3 stdriver; C:\Windows\System32\DRIVERS\stdriver32.sys [52312 2012-06-21] (NCH Software)
U3 asify6mi; C:\Windows\system32\Drivers\asify6mi.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
U3 aydu7eur; C:\Windows\system32\Drivers\aydu7eur.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X]
S3 ipswuio; System32\DRIVERS\ipswuio.sys [X]
S3 RTHDMIAzAudService; system32\drivers\RtHDMIV.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-15 18:32 - 2015-06-15 18:36 - 00028900 _____ C:\Users\Philipp\Desktop\FRST.txt
2015-06-15 18:32 - 2015-06-15 18:35 - 00000000 ____D C:\FRST
2015-06-15 18:13 - 2015-06-15 18:13 - 01148416 _____ (Farbar) C:\Users\Philipp\Desktop\FRST.exe
2015-06-14 18:33 - 2015-06-14 18:33 - 00002991 _____ C:\Users\Philipp\AppData\Local\recently-used.xbel
2015-06-14 16:21 - 2015-06-14 16:21 - 00000012 ____H C:\dvmexp.idx
2015-06-14 08:12 - 2015-06-14 08:12 - 00000000 ___HD C:\dvmexp
2015-06-13 14:19 - 2015-06-13 14:19 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-06-13 14:18 - 2015-06-15 18:23 - 00001228 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job
2015-06-13 14:18 - 2015-06-15 14:23 - 00001176 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job
2015-06-13 14:18 - 2015-06-13 14:18 - 00000000 ____D C:\Users\Jeffel\AppData\Local\Dropbox
2015-06-13 14:18 - 2015-06-13 14:18 - 00000000 ____D C:\ProgramData\Dropbox
2015-06-11 18:41 - 2015-06-11 18:41 - 00001085 _____ C:\Users\Public\Desktop\Avira.lnk
2015-06-10 10:09 - 2015-06-02 21:35 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 10:09 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 10:09 - 2015-05-25 19:00 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-10 10:09 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-10 10:09 - 2015-05-23 05:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-10 10:09 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 10:09 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-10 10:09 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-10 10:09 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 10:09 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-10 10:09 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 10:09 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-10 10:09 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-10 10:09 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 10:09 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 10:09 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-10 10:09 - 2015-05-23 05:05 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-10 10:09 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 10:09 - 2015-05-23 05:00 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-10 10:09 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-10 10:09 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-10 10:09 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-10 10:09 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 10:09 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 10:09 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 10:09 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 10:09 - 2015-05-23 04:38 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-10 10:09 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 10:09 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-10 10:09 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 10:09 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 10:09 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 10:09 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 10:09 - 2015-05-22 20:03 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-10 10:09 - 2015-05-22 19:58 - 00901120 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-10 10:09 - 2015-05-21 15:20 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-10 10:08 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-06-10 10:08 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-10 10:08 - 2015-05-25 20:07 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-10 10:08 - 2015-05-25 20:07 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-10 10:08 - 2015-05-25 20:04 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00853504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-10 10:08 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-10 10:08 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-10 10:08 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-10 10:08 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-10 10:08 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-10 10:08 - 2015-05-25 18:53 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 10:08 - 2015-05-09 05:14 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-10 10:08 - 2015-05-09 05:13 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-10 10:08 - 2015-05-09 05:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-10 10:08 - 2015-05-09 05:12 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-10 10:08 - 2015-05-09 05:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 03:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 03:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-10 10:08 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-10 10:08 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-10 10:08 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-10 10:08 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-10 10:08 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-10 10:08 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-09 17:20 - 2015-06-09 17:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2015-06-09 17:20 - 2015-06-09 17:21 - 00000000 ____D C:\Program Files\BlueStacks
2015-06-09 17:20 - 2015-06-09 17:20 - 00000000 ____D C:\ProgramData\BlueStacks
2015-06-09 17:18 - 2015-06-09 17:18 - 15738056 _____ C:\Users\Philipp\Downloads\CloudMusic_official_2.7.1.apk
2015-06-09 17:18 - 2015-06-09 17:18 - 14155832 _____ (BlueStack Systems Inc.) C:\Users\Philipp\Downloads\BlueStacks-ThinInstaller.exe
2015-06-09 15:44 - 2015-05-09 05:14 - 02937344 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 02045952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-06-09 15:44 - 2015-05-09 05:13 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-06-09 15:44 - 2015-05-09 05:13 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-06-09 15:44 - 2015-05-09 05:13 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-06-09 15:44 - 2015-05-09 05:13 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-06-06 18:11 - 2015-06-06 18:11 - 00000000 ____D C:\Users\Beamer\AppData\Local\GWX
2015-06-06 11:34 - 2015-06-07 21:06 - 00000000 ____D C:\Users\Philipp\Documents\Joerg Riesa
2015-06-04 19:22 - 2015-06-04 19:22 - 00002121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-06-03 16:37 - 2015-06-03 16:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2015-06-02 15:47 - 2015-06-04 18:42 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-01 20:38 - 2015-06-01 20:38 - 00000000 ____D C:\Users\Jeffel\AppData\Local\GWX
2015-06-01 18:03 - 2015-06-01 18:03 - 00000000 ____D C:\Users\Philipp\AppData\Local\GWX
2015-05-31 15:23 - 2015-05-31 15:43 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dual Monitor
2015-05-31 15:23 - 2015-05-31 15:23 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dual Monitor
2015-05-20 19:51 - 2015-05-20 19:51 - 00177664 _____ C:\Users\Philipp\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-20 17:18 - 2015-04-11 05:07 - 00054656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-05-20 17:18 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-05-20 17:18 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-05-17 19:56 - 2015-06-15 17:56 - 00000917 _____ C:\Windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job
2015-05-17 19:56 - 2015-06-15 17:56 - 00000731 _____ C:\Windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job
2015-05-16 09:04 - 2015-05-16 09:04 - 00172295 _____ C:\Users\Philipp\Documents\Konfiguration FritzBox.xps

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-15 18:19 - 2012-04-04 22:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-15 18:10 - 2014-12-31 17:10 - 00000917 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job
2015-06-15 18:10 - 2014-12-31 17:10 - 00000731 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job
2015-06-15 18:10 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-06-15 18:04 - 2010-01-31 18:04 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-15 17:04 - 2013-11-21 19:48 - 00000000 ____D C:\Users\Beamer\AppData\Roaming\DAEMON Tools Lite
2015-06-15 16:40 - 2009-12-25 17:20 - 00019456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-15 16:40 - 2009-12-25 17:20 - 00019456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-15 16:39 - 2012-12-17 20:34 - 00000000 ___RD C:\Users\Philipp\Documents\Dropbox
2015-06-15 16:38 - 2014-07-12 11:12 - 00000000 ___RD C:\Users\Philipp\Google Drive
2015-06-15 16:38 - 2010-12-01 14:28 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dropbox
2015-06-15 16:35 - 2010-01-31 18:04 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-15 08:20 - 2009-12-25 18:22 - 01411283 _____ C:\Windows\WindowsUpdate.log
2015-06-15 06:48 - 2010-09-11 19:48 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Skype
2015-06-15 06:45 - 2014-07-30 10:13 - 00000000 __SHD C:\Users\Jeffel\AppData\Local\EmieUserList
2015-06-15 06:45 - 2014-07-30 10:13 - 00000000 __SHD C:\Users\Jeffel\AppData\Local\EmieSiteList
2015-06-15 06:11 - 2009-08-20 05:40 - 01620684 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-14 20:33 - 2012-12-30 21:21 - 00000000 ___RD C:\Users\Jeffel\Dropbox
2015-06-14 20:33 - 2012-12-30 21:17 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Dropbox
2015-06-14 19:33 - 2010-10-18 18:21 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Skype
2015-06-14 18:34 - 2014-11-23 16:42 - 00000000 ____D C:\Users\Philipp\.gimp-2.8
2015-06-14 17:18 - 2013-03-30 18:22 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\.minecraft
2015-06-14 16:36 - 2014-11-23 16:44 - 00000000 ____D C:\Users\Philipp\AppData\Local\gtk-2.0
2015-06-14 16:21 - 2009-08-19 05:27 - 00000000 ___HD C:\temp
2015-06-14 08:15 - 2013-02-10 11:44 - 00000438 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2015-06-14 08:12 - 2015-04-02 11:31 - 00244957 _____ C:\Windows\setupact.log
2015-06-14 08:12 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-13 13:07 - 2014-07-12 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-06-11 18:47 - 2015-04-04 08:21 - 00002266 _____ C:\Windows\PFRO.log
2015-06-11 18:47 - 2011-10-20 18:09 - 00000000 ____D C:\ProgramData\Avira
2015-06-11 18:41 - 2014-08-25 20:44 - 00000000 ____D C:\ProgramData\Package Cache
2015-06-11 18:40 - 2015-03-05 16:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-06-11 18:40 - 2012-11-02 20:39 - 00000000 ____D C:\Program Files\Avira
2015-06-11 12:09 - 2012-11-02 20:40 - 00136728 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-06-11 12:09 - 2012-11-02 20:40 - 00108448 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-06-11 12:09 - 2012-11-02 20:40 - 00031848 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\ssmdrv.sys
2015-06-11 09:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2015-06-11 08:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-06-10 17:55 - 2014-05-29 20:43 - 00000000 ____D C:\Users\Philipp\.android
2015-06-10 17:19 - 2012-04-04 22:24 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-06-10 17:19 - 2011-06-10 19:15 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-06-10 15:43 - 2015-04-02 11:30 - 00572992 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-10 15:05 - 2014-12-10 22:23 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-10 15:05 - 2014-04-26 10:01 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-10 15:04 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2015-06-10 10:31 - 2009-08-19 04:00 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-10 10:25 - 2013-07-28 23:00 - 00000000 ____D C:\Windows\system32\MRT
2015-06-10 10:14 - 2009-12-29 22:28 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-09 17:21 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Libraries
2015-06-08 18:27 - 2013-06-17 09:00 - 00000000 ____D C:\ProgramData\Origin
2015-06-08 18:20 - 2013-06-17 11:51 - 00000000 ____D C:\Users\Beamer\AppData\Roaming\Origin
2015-06-08 18:14 - 2013-06-17 09:00 - 00000000 ____D C:\Program Files\Origin
2015-06-08 17:04 - 2013-11-27 20:45 - 00000000 ____D C:\Program Files\Common Files\Steam
2015-06-07 08:24 - 2009-12-25 20:08 - 00000354 _____ C:\Windows\Tasks\Driver Robot.job
2015-06-06 10:46 - 2012-05-17 13:18 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Notepad++
2015-06-04 19:21 - 2009-08-19 04:20 - 00000000 ____D C:\Program Files\Google
2015-06-04 18:42 - 2012-05-11 15:08 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-06-03 16:42 - 2014-04-28 18:03 - 00000000 ____D C:\Program Files\CCleaner
2015-05-31 15:54 - 2012-12-22 15:49 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Audacity
2015-05-30 22:11 - 2009-11-24 20:19 - 00045056 _____ C:\Windows\system32\acovcnt.exe
2015-05-30 12:55 - 2010-03-06 18:42 - 00000000 ____D C:\Users\Jeffel\Documents\Kigo
2015-05-27 18:16 - 2010-01-25 18:43 - 00000000 ____D C:\Users\Jeffel\Documents\Telefon
2015-05-26 11:56 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-21 21:22 - 2011-08-28 09:47 - 00000000 ____D C:\Users\Beamer
2015-05-20 20:24 - 2012-11-02 20:40 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-05-20 17:19 - 2015-04-04 20:15 - 00000000 ___SD C:\Windows\system32\GWX
2015-05-20 17:07 - 2010-10-21 17:44 - 00000000 ____D C:\Users\Philipp\AppData\Local\Adobe
2015-05-20 17:06 - 2011-08-28 10:41 - 00000000 ____D C:\Users\Beamer\AppData\Local\Adobe
2015-05-16 20:06 - 2012-07-28 22:41 - 00000000 ____D C:\Windows\Minidump
2015-05-16 19:42 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2015-05-16 08:11 - 2010-12-01 14:28 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox

==================== Files in the root of some directories =======

2007-06-12 10:34 - 2007-06-12 10:34 - 0035822 _____ () C:\Program Files\Common Files\ASPG_icon.ico
2008-05-22 09:35 - 2008-05-22 09:35 - 0051962 _____ () C:\Program Files\Common Files\banner.jpg
2009-04-08 11:31 - 2009-04-08 11:31 - 0106496 _____ () C:\Program Files\Common Files\CPInstallAction.dll
2008-08-11 22:45 - 2008-08-11 22:45 - 0155648 _____ (ASUS) C:\Program Files\Common Files\MSIactionall.dll
2013-06-01 21:00 - 2013-06-03 12:18 - 0004143 _____ () C:\Users\Philipp\AppData\Roaming\FTBLauncherLog.txt
2013-06-01 21:00 - 2013-06-03 12:23 - 0078208 _____ () C:\Users\Philipp\AppData\Roaming\MinecraftLog.txt
2012-06-19 14:26 - 2012-06-19 14:26 - 0041472 ___SH () C:\Users\Philipp\AppData\Roaming\Thumbs.db
2010-11-19 20:11 - 2013-02-02 12:46 - 0010240 _____ () C:\Users\Philipp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-14 18:33 - 2015-06-14 18:33 - 0002991 _____ () C:\Users\Philipp\AppData\Local\recently-used.xbel
2012-04-17 18:47 - 2012-04-17 18:47 - 0000017 _____ () C:\Users\Philipp\AppData\Local\resmon.resmoncfg
2010-09-11 19:55 - 2010-09-11 19:55 - 0000056 ____H () C:\ProgramData\ezsidmv.dat

Files to move or delete:
====================
C:\Users\Jeffel\i2errDeu.dll


Some files in TEMP:
====================
C:\Users\Beamer\AppData\Local\Temp\atcMedia1291428144436.exe
C:\Users\Beamer\AppData\Local\Temp\avgnt.exe
C:\Users\Jeffel\AppData\Local\Temp\AskSLib.dll
C:\Users\Jeffel\AppData\Local\Temp\AutoRun.exe
C:\Users\Jeffel\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Jeffel\AppData\Local\Temp\avgnt.exe
C:\Users\Jeffel\AppData\Local\Temp\Delay.exe
C:\Users\Jeffel\AppData\Local\Temp\DirectoryRemovalUtility.exe
C:\Users\Jeffel\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Jeffel\AppData\Local\Temp\drm_dyndata_7370012.dll
C:\Users\Jeffel\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpw138tc.dll
C:\Users\Jeffel\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Jeffel\AppData\Local\Temp\FlashPlayerUpdate01.exe
C:\Users\Jeffel\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Jeffel\AppData\Local\Temp\i4jdel0.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u21-windows-i586-iftw-rv.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u22-windows-i586-iftw-rv.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Jeffel\AppData\Local\Temp\mpsetup.exe
C:\Users\Jeffel\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Jeffel\AppData\Local\Temp\ose00000.exe
C:\Users\Jeffel\AppData\Local\Temp\PicasaUpdater_7e04.exe
C:\Users\Jeffel\AppData\Local\Temp\RemoveGO.exe
C:\Users\Jeffel\AppData\Local\Temp\sdanircmdc.exe
C:\Users\Jeffel\AppData\Local\Temp\sdapskill.exe
C:\Users\Jeffel\AppData\Local\Temp\setup.exe
C:\Users\Jeffel\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Jeffel\AppData\Local\Temp\uninst1.exe
C:\Users\Jeffel\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Jeffel\AppData\Local\Temp\_is9E90.exe
C:\Users\Jeffel\AppData\Local\Temp\_isBF68.exe
C:\Users\Philipp\AppData\Local\Temp\avgnt.exe
C:\Users\Philipp\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpvefjun.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of log ============================
         
--- --- ---



Und noch die Addition.txt:

[CODE]Additional
FRST Logfile:
Code:
ATTFilter
scan result of Farbar Recovery Scan Tool (x86) Version: 13-06-2015
Ran by Philipp at 2015-06-15 18:37:28
Running from C:\Users\Philipp\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-644356114-2566177158-2502637254-500 - Administrator - Disabled)
Beamer (S-1-5-21-644356114-2566177158-2502637254-1005 - Administrator - Enabled) => C:\Users\Beamer
Ellen & Manuel (S-1-5-21-644356114-2566177158-2502637254-1008 - Limited - Enabled) => C:\Users\Ellen & Manuel
Gast (S-1-5-21-644356114-2566177158-2502637254-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-644356114-2566177158-2502637254-1010 - Limited - Enabled)
Jeffel (S-1-5-21-644356114-2566177158-2502637254-1000 - Administrator - Enabled) => C:\Users\Jeffel
Manuel (S-1-5-21-644356114-2566177158-2502637254-1011 - Limited - Enabled) => C:\Users\Manuel
Philipp (S-1-5-21-644356114-2566177158-2502637254-1004 - Limited - Enabled) => C:\Users\Philipp

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

1&1 SmartFax (HKLM\...\1&1 SmartFax) (Version: 2.00.224 - 1&1 Internet AG)
3dPageFlip  Editor (HKLM\...\3dPageFlip PDF Editor_is1) (Version:  - 3dPageFlip Solution)
Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version:  - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adblock Plus für IE (32-Bit) (HKLM\...\{654F389B-E402-4F7B-BA6D-DA732BB57ACB}) (Version: 1.4 - Eyeo GmbH)
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM\...\AmUStor) (Version: 1.4.1217.35202 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (Version: 1.4.1217.35202 - Alcor Micro Corp.) Hidden
Apple Application Support (32-Bit) (HKLM\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASUS CopyProtect (HKLM\...\{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}) (Version: 1.0.0015 - ASUS)
ASUS Data Security Manager (HKLM\...\{FA2092C5-7979-412D-A962-6485274AE1EE}) (Version: 1.00.0014 - ASUS)
ASUS FancyStart (HKLM\...\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}) (Version: 1.0.6 - ASUSTeK Computer Inc.)
ASUS LifeFrame3 (HKLM\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS)
ASUS Live Update (HKLM\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS)
ASUS MultiFrame (HKLM\...\{9D48531D-2135-49FC-BC29-ACCDA5396A76}) (Version: 1.0.0019 - ASUS)
ASUS Power4Gear eXtreme (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.0.19 - ASUS)
ASUS SmartLogon (HKLM\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0007 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0028 - ASUS)
ASUS Touch Pad Extra (HKLM\...\{DB891739-2EB3-45A8-9CBD-941C255CECD4}) (Version:  - )
ASUS Virtual Camera (HKLM\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.19 - asus)
Asus_Camera_ScreenSaver (HKLM\...\Asus_Camera_ScreenSaver) (Version: 2.0.0008 - ASUS)
Atheros Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - Atheros)
ATI Catalyst Install Manager (HKLM\...\{0AE24BD5-185C-436C-D93D-50574523C6C4}) (Version: 3.0.732.0 - ATI Technologies, Inc.)
ATK Generic Function Service (HKLM\...\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}) (Version: 1.00.0008 - ATK)
ATK Hotkey (HKLM\...\{7C05592D-424B-46CB-B505-E0013E8E75C9}) (Version: 1.0.0053 - ASUS)
ATK Media (HKLM\...\{D1E5870E-E3E5-4475-98A6-ADD614524ADF}) (Version: 2.0.0006 - ASUS)
ATKOSD2 (HKLM\...\{3B05F2FB-745B-4012-ADF2-439F36B2E70B}) (Version: 7.0.0006 - ASUS)
aTube Catcher (HKLM\...\aTube Catcher) (Version: 2.9.1462 - DsNET Corp)
aTube Catcher Version 3.8 (HKLM\...\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
Audacity 2.0.2 (HKLM\...\Audacity_is1) (Version: 2.0.2 - Audacity Team)
Avanquest update (HKLM\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.29 - Avanquest Software)
Avidemux 2.6 (32-bit) (HKLM\...\Avidemux 2.6) (Version: 2.6.8.9046 - )
Avira (HKLM\...\{0696cc37-db90-4000-be99-4a173ca7c8af}) (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG)
Avira (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.11.574 - Avira Operations GmbH & Co. KG)
Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION
Bandicam (HKLM\...\Bandicam) (Version: 1.8.5.302 - Bandisoft.com)
Battlefield 1942™ (HKLM\...\{5BE7BD06-512B-43bf-AD78-3BD2A5F5F7B3}) (Version: 1.6.20.0 - Electronic Arts)
Bejeweled® 3 (HKLM\...\{E99C27B2-EB2E-4244-9F5C-A96F55100F0C}) (Version: 1.1.13.4753 - Electronic Arts, Inc.)
BlueStacks App Player (HKLM\...\BlueStacks App Player) (Version: 0.9.27.5408 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM\...\{C1F53C9F-C560-4292-9237-12786FE6BF62}) (Version: 0.9.27.5408 - BlueStack Systems, Inc.)
Bob baut einen Park (HKLM\...\{367EDD83-302F-48E6-8F77-B0B056125C2D}) (Version: 1.0.0 - )
Bob der Baumeister (HKLM\...\{8F2D21F9-F428-4EF2-8111-953EF3299EFB}) (Version: 1.0.0 - )
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\...\CANONIJPLM100) (Version:  - )
Canon MP Navigator EX 3.0 (HKLM\...\MP Navigator EX 3.0) (Version:  - )
Canon MP490 series Benutzerregistrierung (HKLM\...\Canon MP490 series Benutzerregistrierung) (Version:  - )
Canon MP490 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series) (Version:  - )
Canon Utilities Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version:  - )
Canon Utilities My Printer (HKLM\...\CanonMyPrinter) (Version:  - )
Canon Utilities Solution Menu (HKLM\...\CanonSolutionMenu) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform)
Cisco EAP-FAST Module (HKLM\...\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\...\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\...\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.)
Construction-Simulator 2015 (HKLM\...\Steam App 289950) (Version:  - weltenbauer. Software Entwicklung GmbH)
Core Temp version 0.99.7 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 0.99.7 - Arthur Liberman)
Crusader No Remorse (HKLM\...\{2AEA735F-B393-4D89-93EF-5849CB72B4A3}) (Version: 1.0.0.2 - Electronic Arts)
CyberLink LabelPrint (HKLM\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1720 - CyberLink Corp.)
CyberLink Power2Go (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.2713 - CyberLink Corp.)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd)
Diercke Globus Online (HKLM\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH)
dm-Fotowelt (HKLM\...\dm-Fotowelt) (Version: 5.1.7 - CEWE Stiftung u Co. KGaA)
Dolby Control Center (HKLM\...\{0F3C61B5-3051-4DE6-8A6A-45100BCC1F41}) (Version: 1.2.0704 - Dolby)
Dropbox (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Dropbox) (Version: 3.4.6 - Dropbox, Inc.)
Druckerdeinstallation für EPSON XP-312 313 315 Series (HKLM\...\EPSON XP-312 313 315 Series) (Version:  - SEIKO EPSON Corporation)
Druckerdeinstallation für EPSON XP-412 413 415 Series (HKLM\...\EPSON XP-412 413 415 Series) (Version:  - SEIKO EPSON Corporation)
Dual Monitor 1.22 (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{64AA3F94-ED4A-4A4B-B72C-B7A1481ED5D8}_is1) (Version: 1.22.021813 - Cristi Diaconu)
EA SPORTS FIFA World (HKLM\...\{8F9AC744-EEF6-43DB-A4B6-FA1A18F1C640}) (Version: 9.5.0.61021 - Electronic Arts, Inc.)
Epson Connect Printer Setup (HKLM\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.3.0 - SEIKO EPSON CORPORATION)
Epson Event Manager (HKLM\...\{0F13C24A-FFE2-4CD0-8E0B-DC804E0A0E0B}) (Version: 3.10.0035 - Seiko Epson Corporation)
EPSON Scan (HKLM\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON-Handbücher (HKLM\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.32.0.0 - SEIKO EPSON CORPORATION)
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION)
Express Gate (HKLM\...\{62CF8923-31DC-4285-A23C-17CE5AA6A679}) (Version: 1.0.3.2 - DeviceVM, Inc.)
F1 2013 (HKLM\...\Steam App 223670) (Version:  - Codemasters Birmingham)
FIFA 09 (HKLM\...\{2315B23D-3E21-4920-837D-AE6460934ECB}) (Version: 1.0.1.1 - Electronic Arts)
Firebird SQL Server - MAGIX Edition (HKLM\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Globus Fotoservice 4.4 (HKLM\...\Globus Fotoservice_is1) (Version:  - )
Google Drive (HKLM\...\{CBC9F5FD-5CFA-4A33-81CD-369EAB77E3A6}) (Version: 1.22.9403.0223 - Google, Inc.)
Google Earth (HKLM\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
Google+ Auto Backup (HKLM\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
Hot Wheels (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{CF36DD86-81D3-4D91-8F7A-344E0C1A4BFD}) (Version: 1.00.0000 - Activision Value)
iCloud (HKLM\...\{9A07AB4F-6B53-43E9-B7FC-7892E8C26BE3}) (Version: 4.1.1.53 - Apple Inc.)
Isola LEGO 2 (HKLM\...\{85967580-EBC2-11D4-AEA3-0050046A88ED}) (Version:  - )
iTunes (HKLM\...\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.)
Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
KingsoftOfficeXPlats 1.4 (HKLM\...\KingsoftOfficeXPlats) (Version: 1.4 - Kingsoft)
LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version:  - )
LBOTS Top mouse Driver (HKLM\...\{F1A273BD-6A9E-41D8-A111-5E56ACD286F8}) (Version: 1.0 - Togran)
LEGO Racers 2 (HKLM\...\{3DD2E9EA-0544-4162-B8BE-E21E994E9F3B}) (Version:  - )
LEGO® Star Wars™: Die Komplette Saga (HKLM\...\InstallShield_{D596980D-17BE-4425-B8F0-5640719AADE9}) (Version: 1.00.0000 - LucasArts)
LEGO® Star Wars™: The Complete Saga (Version: 1.00.0000 - LucasArts) Hidden
LEGOLAND (HKLM\...\LEGOLANDDeInstKey) (Version:  - )
Logitech Gaming Software (HKLM\...\{648F9C94-EC44-487B-9DA4-44ED72A082CC}) (Version: 4.50 - )
MAGIX Speed burnR (MSI) (HKLM\...\MX.{16884C3D-3512-486D-A2F9-39071551BFEF}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX Video deluxe 2014 (HKLM\...\MX.{EA62B22F-AB0A-406B-80A9-8036D3CE3446}) (Version: 13.0.2.8 - MAGIX AG)
MAGIX Video deluxe 2014 (Version: 13.0.2.8 - MAGIX AG) Hidden
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM\...\{95120000-0122-0407-0000-0000000FF1CE}) (Version: 12.0.6423.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{AC4C38FD-A54C-4CA5-92EE-D983CD81293E}) (Version: 1.20.146.0 - Microsoft)
Minecraft (HKLM\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Minigolf (HKLM\...\Minigolf_is1) (Version:  - Meridian93)
Monkey's Adventures (HKLM\...\Monkey's Adventures_is1) (Version:  - play-publishing.com)
Motorola Driver Installation 3.4.0 (HKLM\...\{81B3BEF9-5D97-4096-86E9-5B48A5BC32D0}) (Version: 3.4.0 - Motorola Inc.)
Motorola Phone Tools (HKLM\...\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}) (Version: 5.0.7a 4/01/2008 - Avanquest Software)
Motorola Phone Tools (Version: 4.30 - BVRP Software) Hidden
Motorola Phone Tools (Version: 5.00 - BVRP Software) Hidden
Mozilla Firefox 38.0.5 (x86 de) (HKLM\...\Mozilla Firefox 38.0.5 (x86 de)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyPublicWiFi 5.1 (HKLM\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version:  - TRUE Software)
Mystery P.I. - The London Caper (HKLM\...\Mystery P.I. - The London Caper) (Version:  - PopCap Games)
NB Probe (HKLM\...\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}) (Version:  - )
Need For Speed™ World (HKLM\...\{3AF1B16A-7DC9-4C80-BAEC-70B088A7C5B8}) (Version: 1.0.0.0 - Electronic Arts)
Net4Switch (HKLM\...\{9D6D7811-43B3-463C-BC79-5D1755269989}) (Version: 1.00.0019 - ASUS)
Norton Internet Security (Version: 16.0.0.125 - Symantec Corporation) Hidden
Notepad++ (HKLM\...\Notepad++) (Version: 6.1.2 - )
OpenAL (HKLM\...\OpenAL) (Version:  - )
Oracle VM VirtualBox 4.3.2 (HKLM\...\{91E5A436-8560-4621-9F26-D7050D078832}) (Version: 4.3.2 - Oracle Corporation)
Origin (HKLM\...\Origin) (Version: 9.2.1.4399 - Electronic Arts, Inc.)
pdfsam (HKLM\...\pdfsam) (Version: 2.2.0 - )
Peter Lustigs Verkehrsschule (HKLM\...\Verkehrsschule) (Version:  - )
Pflanzen gegen Zombies™ (HKLM\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.)
Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.)
QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Roads Of Rome (HKLM\...\Roads Of Rome_is1) (Version:  - Realore Studios)
Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.)
Samsung Kies (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SimCity 2000 Special Edition (HKLM\...\{59D2C751-F7BE-4E9F-9C8C-1F16013802C7}) (Version: 2.0.0.1 - Electronic Arts)
SimCity™ (HKLM\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
Skype™ 7.1 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
Software Updater (HKLM\...\{E1BAD1BA-C0E8-4018-9281-E7D2C6B07474}) (Version: 4.3.6 - SEIKO EPSON CORPORATION)
Steam (HKLM\...\Steam) (Version:  - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.1.1 - Synaptics Incorporated)
Syndicate (HKLM\...\{64CFBAAB-46F7-4628-8D9B-E656A8C11CDB}) (Version: 2.0.0.3 - Electronic Arts)
System Requirements Lab CYRI (HKLM\...\{E77DA909-3532-4C95-AFEB-06310E88462A}) (Version: 6.0.3.0 - Husdawg, LLC)
Theme Hospital (HKLM\...\{5118A4C2-C8A4-4CE5-AC37-F3E51C25402F}) (Version: 3.0.0.2 - Electronic Arts)
TIPP10 Version 2.1.0 (HKLM\...\TIPP10_is1) (Version:  - (c) 2006-2011, Tom Thielicke IT Solutions)
TmNationsForever (HKLM\...\TmNationsForever_is1) (Version:  - Nadeo)
TOGGO PC-Spielebox 2 (HKLM\...\{67EECE0C-8B6C-4D09-989D-D39BC9BBCA0E}) (Version: 1.00.0000 - )
Toyland Racer (HKLM\...\Toyland Racer) (Version:  - )
Unified Remote (HKLM\...\{D7930C67-5816-417B-BF28-54BB75EFDAF9}) (Version: 2.14.4.0 - Unified Remote)
Unity Web Player (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
upapp (HKLM\...\{4EF69D40-4DC9-485E-95D3-B1C22F218FC8}) (Version: 0.20.0000 - Hewlett-Packard)
USB 2.0 1.3M UVC WebCam (HKLM\...\USB 2.0 1.3M UVC WebCam) (Version:  - )
Werksfeuerwehr-Simulator Version 1.0 (HKLM\...\{5F7ED0CD-E04E-4441-9E03-10AFDB654E96}_is1) (Version:  - rondomedia Marketing & Vertriebs GmbH)
Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live ID-Anmelde-Assistent (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows Live Sync (HKLM\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
WinFlash (HKLM\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.29.0 - ASUS)
WinRAR (HKLM\...\WinRAR archiver) (Version:  - )
Wireless Console 2 (HKLM\...\{83F73CB1-7705-49D1-9852-84D839CA2A45}) (Version: 2.0.10 - ATK)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

ATTENTION: System Restore is disabled
Check "winmgmt" service or repair WMI.


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => 
Task: C:\Windows\Tasks\Driver Robot.job => 
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job => 
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job => 
Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job => 
Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job => 
Task: C:\Windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job => 
Task: C:\Windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job => 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => 

==================== Loaded Modules (Whitelisted) ==============

2007-06-15 11:28 - 2007-06-15 11:28 - 00147456 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll
2007-06-01 18:08 - 2007-06-01 18:08 - 00143360 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
2013-12-24 20:39 - 2012-11-20 00:44 - 00786432 _____ () D:\Gaming Maus\DareUMonitor.exe
2013-12-24 20:39 - 2013-03-27 13:48 - 00057344 _____ () D:\Gaming Maus\lan.dll
2013-12-24 20:39 - 2012-04-19 18:15 - 00061440 _____ () D:\Gaming Maus\hiddriver.dll
2015-05-08 20:50 - 2015-05-08 20:50 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2015-06-15 16:36 - 2015-06-15 16:36 - 00043008 _____ () c:\users\philipp\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpvefjun.dll
2015-03-04 23:45 - 2015-03-04 23:45 - 00750080 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-03-04 23:45 - 2015-03-04 23:45 - 00047616 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-03-04 23:45 - 2015-03-04 23:45 - 00865280 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-03-04 23:45 - 2015-03-04 23:45 - 00200704 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2015-06-15 16:35 - 2015-06-15 16:35 - 00098816 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32api.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00110080 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pywintypes27.dll
2015-06-15 16:35 - 2015-06-15 16:35 - 00364544 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pythoncom27.dll
2015-06-15 16:35 - 2015-06-15 16:35 - 00045568 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_socket.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 01161216 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_ssl.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00320512 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32com.shell.shell.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00713216 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_hashlib.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 01175040 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._core_.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00805888 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._gdi_.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00811008 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._windows_.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 01062400 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._controls_.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00735232 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._misc_.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00682496 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pysqlite2._sqlite.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00087552 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_ctypes.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00119808 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32file.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00108544 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32security.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00007168 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\hashobjs_ext.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00026624 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\usb_ext.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00167936 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32gui.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00018432 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32event.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00128512 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_elementtree.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00127488 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pyexpat.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00013824 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\common.time34.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00036864 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_psutil_windows.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00038912 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32inet.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00011264 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32crypt.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00070656 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._html2.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00027136 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_multiprocessing.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00020480 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_yappi.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00035840 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32process.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00686080 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\unicodedata.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00122368 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._wizard.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00024064 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32pipe.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00010240 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\select.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00025600 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32pdh.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00525640 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\windows._lib_cacheinvalidation.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00017408 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32profile.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00022528 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32ts.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00078336 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._animate.pyd
2013-11-27 20:48 - 2015-04-16 19:40 - 00776192 _____ () D:\Steam\SDL2.dll
2015-01-24 17:49 - 2015-04-23 04:16 - 04962816 _____ () D:\Steam\v8.dll
2015-01-24 17:49 - 2015-04-23 04:16 - 01556992 _____ () D:\Steam\icui18n.dll
2015-01-24 17:49 - 2015-04-23 04:16 - 01187840 _____ () D:\Steam\icuuc.dll
2014-05-22 17:04 - 2015-06-04 20:56 - 02407104 _____ () D:\Steam\video.dll
2014-08-31 20:09 - 2014-12-01 23:31 - 02396672 _____ () D:\Steam\libavcodec-56.dll
2014-08-31 20:09 - 2014-12-01 23:31 - 00442880 _____ () D:\Steam\libavutil-54.dll
2014-08-31 20:09 - 2014-12-01 23:31 - 00479744 _____ () D:\Steam\libavformat-56.dll
2014-08-31 20:09 - 2014-12-01 23:31 - 00332800 _____ () D:\Steam\libavresample-2.dll
2014-08-31 20:09 - 2014-12-01 23:31 - 00485888 _____ () D:\Steam\libswscale-3.dll
2013-11-27 20:48 - 2015-06-04 20:56 - 00703168 _____ () D:\Steam\bin\chromehtml.DLL
2013-11-27 20:48 - 2015-05-11 21:01 - 36302728 _____ () D:\Steam\bin\libcef.dll
2015-05-16 07:55 - 2015-05-11 21:01 - 08958344 _____ () D:\Steam\bin\pdf.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Jeffel\Desktop\1.avi:TOC.WMV
AlternateDataStreams: C:\Users\Jeffel\Desktop\2.avi:TOC.WMV
AlternateDataStreams: C:\Users\Jeffel\Desktop\3.avi:TOC.WMV

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.177.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk => C:\Windows\pss\FancyStart daemon.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AlcoholAutomount => "D:\Alcohol 120\axcmd.exe" /automount
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: ASUS Camera ScreenSaver => C:\Windows\AsScrProlog.exe
MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\ASScrPro.exe
MSCONFIG\startupreg: ASUSTPE => C:\Windows\system32\ASUSTPE.exe
MSCONFIG\startupreg: AVMUSBFernanschluss => "C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\AVMAutoStart.exe"
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CanonSolutionMenu => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
MSCONFIG\startupreg: CLMLServer => "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: DAEMON Tools Lite => "D:\DT\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: KiesTrayAgent => D:\Samsung Kies\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: UpdateLBPShortCut => "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
MSCONFIG\startupreg: UpdateP2GoShortCut => "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{98B426BE-4154-48E7-A940-C28AD6AB3C7E}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{A0ED8D77-C475-4A7C-9683-E33EF6CA08AE}] => (Allow) svchost.exe
FirewallRules: [{5A959ABA-B81C-408F-9BF9-A382D827ED17}] => (Allow) C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [TCP Query User{92FF86AB-5408-4239-86CD-713C52CC5E72}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe
FirewallRules: [UDP Query User{756D4762-70FE-4F03-9A42-0F627F10CBF8}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe
FirewallRules: [TCP Query User{F15C73F2-09B2-4D70-B6C1-FCB8C6C3077A}C:\program files\google\google earth\client\googleearth.exe] => (Block) C:\program files\google\google earth\client\googleearth.exe
FirewallRules: [UDP Query User{3518798C-9464-4B02-B79D-33060DE82A80}C:\program files\google\google earth\client\googleearth.exe] => (Block) C:\program files\google\google earth\client\googleearth.exe
FirewallRules: [TCP Query User{F87691B0-9C93-4349-8E2B-69BF1B0D816D}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{0756E3CD-F4D3-4373-BCB1-583FDDA22919}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{6939840F-897B-42B5-8E48-6E97937198B0}] => (Allow) svchost.exe
FirewallRules: [{59E3FF2C-493B-4937-9A37-DA9D1CAAFC4B}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [TCP Query User{A1DE6356-BBC4-48A8-B039-88DEB224609A}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{E3168A96-5F5E-4485-AD0D-7AE6A2596564}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{4AF10D0E-C4C1-40A2-936B-C6F2AB12613B}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [UDP Query User{88D7FF05-F79E-4946-A853-288BD573E814}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [TCP Query User{9EFEAB5F-7210-4BC7-8BA8-231FA6D585A1}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe
FirewallRules: [UDP Query User{375FCB23-571C-4F84-90FE-A0670DEAAC49}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe
FirewallRules: [{55E52E7C-FD6E-4517-8357-F6D71154371A}] => (Allow) C:\Users\Jeffel\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{9C447FBD-4CD0-4507-918C-C3C1FC1BC0BC}] => (Allow) C:\Users\Jeffel\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{424B5F96-6253-4B19-824F-7157B91CE53C}C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{A3FECD29-88C2-49EE-9826-78B12649C757}C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{5518E9F3-F3DC-433F-9E50-A930A0CD15F2}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe
FirewallRules: [UDP Query User{55697CCA-A2DB-4C9F-8442-8DC6C36139AA}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe
FirewallRules: [TCP Query User{3E55C8FD-D431-4830-8F71-22F2B69255C3}C:\program files\ea sports\fifa 09\fifa09.exe] => (Allow) C:\program files\ea sports\fifa 09\fifa09.exe
FirewallRules: [UDP Query User{6B39FD39-72B8-4683-9E30-4221DEFAD5D9}C:\program files\ea sports\fifa 09\fifa09.exe] => (Allow) C:\program files\ea sports\fifa 09\fifa09.exe
FirewallRules: [TCP Query User{EF7EF825-131B-4165-A892-9DEC02FC688F}E:\easysetupassistant\wr841n\easysetupassistant.exe] => (Allow) E:\easysetupassistant\wr841n\easysetupassistant.exe
FirewallRules: [UDP Query User{25BF93E3-CEFC-4077-972C-637BBD3D8D23}E:\easysetupassistant\wr841n\easysetupassistant.exe] => (Allow) E:\easysetupassistant\wr841n\easysetupassistant.exe
FirewallRules: [{BE0F663E-C815-4563-A897-646E54E5E075}] => (Block) E:\easysetupassistant\wr841n\easysetupassistant.exe
FirewallRules: [{C1AD54B1-3E4E-48CD-AA59-46A81630CED6}] => (Block) E:\easysetupassistant\wr841n\easysetupassistant.exe
FirewallRules: [TCP Query User{642462DC-FE55-4283-B3BE-5116D1ABD2D1}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{1543EF59-9BDC-45F3-98C1-666138EE2360}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{F42F3A51-5E79-42CD-97EC-8F46AFB3AEDA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3AF441F6-2448-4E93-AF29-F00F2983A81B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{3A83D0B7-CC23-4E0A-A47F-BA4C727DA59B}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{A30C3FCC-E865-487C-BB2B-94503E562E57}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{C5B4D7F3-5ACD-4113-B7F8-EF24617B930D}] => (Allow) D:\OriginGames\Need for Speed World\GameLauncher.exe
FirewallRules: [{54FB9595-0BFB-47AF-866A-250C8D7B1BAF}] => (Allow) D:\OriginGames\Need for Speed World\GameLauncher.exe
FirewallRules: [{9E1C364E-EA27-4082-AB13-FBEBC90590BA}] => (Allow) D:\OriginGames\Battlefield 1942\BF1942.exe
FirewallRules: [{2EB3B6C7-04D1-43DF-B4B0-B47348DBCD68}] => (Allow) D:\OriginGames\Battlefield 1942\BF1942.exe
FirewallRules: [{DBB13B95-B032-45C2-A416-2E496104A650}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{5456B4DC-0D08-476B-B4CB-8BA97886248B}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{B3C9C811-6617-41F7-8833-D1B66AC7C967}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [TCP Query User{FB78B67C-4DFB-45DA-8910-73B460C08EE9}D:\needforspeed world\data\nfsw.exe] => (Allow) D:\needforspeed world\data\nfsw.exe
FirewallRules: [UDP Query User{514C9672-18B4-476C-B568-2B1D2211DC21}D:\needforspeed world\data\nfsw.exe] => (Allow) D:\needforspeed world\data\nfsw.exe
FirewallRules: [{122DB7AB-303C-4A23-8984-A4089D07A519}] => (Allow) D:\Steam\SteamApps\common\f12013\F1_2013.exe
FirewallRules: [{BA4A4B55-61BE-49C7-B106-9CF16C1FEFCA}] => (Allow) D:\Steam\SteamApps\common\f12013\F1_2013.exe
FirewallRules: [{852A6D93-68A1-49D2-A427-091873A0F8AF}] => (Allow) D:\OriginGames\Plants vs. Zombies\PlantsVsZombies.exe
FirewallRules: [{1C423230-E993-447A-B8BC-B011BD1ABEA4}] => (Allow) D:\OriginGames\Plants vs. Zombies\PlantsVsZombies.exe
FirewallRules: [{5476BAD2-AE20-42B2-BFC6-58B987D9EC81}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{812E2119-243A-400E-B7FE-DEB6D62808AB}] => (Allow) D:\OriginGames\SimCity\SimCity\SimCity.exe
FirewallRules: [{2C4E33E9-EDDF-4059-9790-647FCF83145D}] => (Allow) D:\OriginGames\SimCity\SimCity\SimCity.exe
FirewallRules: [TCP Query User{60D69111-FE19-4415-B387-D97AE26AFD38}C:\program files\tmnationsforever\tmforever.exe] => (Block) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [UDP Query User{F2DF262E-FF7C-484F-AA4E-63FF8880305C}C:\program files\tmnationsforever\tmforever.exe] => (Block) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [{A3C3ECE5-F0B8-458B-BF51-A7F6BF8F5E0E}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{DAA3B140-1FED-47B5-9F25-FB8F35548A03}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{F14B2E24-FBC1-4546-BBB6-CCBF3E3C26CB}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe
FirewallRules: [{1EBAA986-ABD7-469D-8126-C6A22AB47DCF}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe
FirewallRules: [TCP Query User{DF57783D-CA97-4654-B267-AC96484B730F}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{695F1F23-F5F2-4E3A-93D3-C046C30B108D}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [TCP Query User{18759B6E-98BA-4489-983D-ABCF93CE30A2}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{C48C23E4-CF37-4289-AC60-2FF3F377ACD4}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [{BAE39D93-BC07-4545-A838-D128E5D729B1}] => (Allow) C:\Users\Philipp\AppData\Local\Apps\2.0\AKHGTRNK.DG4\BWYE0CZZ.LL7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{BDC2FD03-237D-49E4-A6A2-8AE3211FB11A}] => (Allow) C:\Users\Philipp\AppData\Local\Apps\2.0\AKHGTRNK.DG4\BWYE0CZZ.LL7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{2A33F55E-5BBB-4A44-9852-D7FEA360081E}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{084ED6E8-0CDB-42C1-9716-21D9E1E099C3}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [TCP Query User{5A171416-5B5C-45E6-A06C-FD51ECCBBA01}C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe] => (Block) C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [UDP Query User{EC3DF4E2-12D4-4BEA-9E53-8BD42E933EE3}C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe] => (Block) C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{B3F421E8-5795-4576-A04B-678154A5D42C}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{56B79544-76F5-4B6F-85BD-3CA9415A0BE3}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [TCP Query User{A674A672-4708-4C05-A7DD-7FC78F2ABAD6}C:\program files\unified remote\remoteserver.exe] => (Allow) C:\program files\unified remote\remoteserver.exe
FirewallRules: [UDP Query User{C42108C2-C11D-4BCD-848F-C882C383AFF1}C:\program files\unified remote\remoteserver.exe] => (Allow) C:\program files\unified remote\remoteserver.exe
FirewallRules: [{66918B97-AE64-444C-9DB6-5DB605AE12F7}] => (Allow) D:\OriginGames\Bejeweled 3\Bejeweled3.exe
FirewallRules: [{4D93D20E-753C-494E-8FA6-F47CF535E417}] => (Allow) D:\OriginGames\Bejeweled 3\Bejeweled3.exe
FirewallRules: [{100DFB51-03A7-409A-8436-B1ADEDE290A7}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{3D1CFBF6-1099-4721-A86E-438E12C875EA}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{708B5EAF-95EC-428E-9AA3-7F8A3CC499D7}] => (Allow) D:\OriginGames\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe
FirewallRules: [{252252F8-D1E0-473A-8A33-743C157FAAAB}] => (Allow) D:\OriginGames\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe
FirewallRules: [{12369EEC-4B3E-4804-8395-3B1EE1D1F377}] => (Allow) C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe
FirewallRules: [{23965B5B-2D1F-4BC2-82F2-4E012CDB6110}] => (Allow) C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe
FirewallRules: [{8AD425C4-E4CD-4E0A-B470-71C0186D4419}] => (Allow) D:\OriginGames\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe
FirewallRules: [{79468976-3ED7-4AAD-8CDF-CC32C20626C3}] => (Allow) D:\OriginGames\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe
FirewallRules: [{98C0D637-E762-4100-8AF8-3E756C54A265}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe
FirewallRules: [{533B5FB5-1CB8-4776-8F97-B9D35616A215}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe
FirewallRules: [{D67CAA53-7942-4A91-8D54-03DE16AF77AA}] => (Allow) D:\Steam\SteamApps\common\ConSim2015\ConSim2015.exe
FirewallRules: [{085EB9AF-D4B4-42D7-AA85-2FF13C776871}] => (Allow) D:\Steam\SteamApps\common\ConSim2015\ConSim2015.exe
FirewallRules: [{13EC435C-D4A0-4045-9736-20D5C2A52E0F}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{766D54AC-FE82-4990-81C9-4B3E62FC1D8E}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{8147F4AA-6FEE-48F5-A257-DADCA6B3D1F7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{B59D5117-8BF8-4401-A031-594855C5359E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{C3A2EE98-6FD7-4841-986B-5FF483452073}] => (Allow) D:\OriginGames\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{7894DF2C-B685-420A-810A-505E1663461E}] => (Allow) D:\OriginGames\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{AB875D33-F535-45C7-83AD-4542A38F0A9A}] => (Allow) D:\OriginGames\Syndicate (1993)\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{C8819052-499D-4060-A2CB-63C85B7289F3}] => (Allow) D:\OriginGames\Syndicate (1993)\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [TCP Query User{2405E39F-611A-4841-8667-B7FAB332ED13}D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{98A5CF53-9EE7-4592-86E6-5A255E971ED4}D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{42389642-E7E4-4FA7-99F0-D17483626C6F}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{546675B7-4D5D-41B0-A82B-3C2AE0AED9AE}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{F4820325-C52D-4F14-B0C1-E2F40210A513}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft3077.tmp\fsetup.exe
FirewallRules: [{F8A2199B-EA6F-43B4-BF29-FC040CE4901D}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft3077.tmp\fsetup.exe
FirewallRules: [{0CB53765-513D-49DE-87C5-AECA2C3658C1}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pftAA65.tmp\fsetup.exe
FirewallRules: [{C88A6BB6-DBFF-4572-AA49-2F5929892EA3}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pftAA65.tmp\fsetup.exe
FirewallRules: [{13D83860-A9E7-48A7-A64E-3D805CB1B574}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft96D1.tmp\fsetup.exe
FirewallRules: [{4DDF4814-C41E-4164-81FB-D9C60F8AD319}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft96D1.tmp\fsetup.exe
FirewallRules: [{7870E46B-69E5-4524-B2E7-ECEB9E6D710D}] => (Allow) C:\Program Files\iTunes\iTunes.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/15/2015 06:34:40 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST.exe, Version 13.6.2015.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 26c0

Startzeit: 01d0a788caaf2ddf

Endzeit: 0

Anwendungspfad: C:\Users\Philipp\Desktop\FRST.exe

Berichts-ID: 36209be9-137c-11e5-977e-002618f9ca5d

Error: (06/15/2015 05:07:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: legoland.exe, Version: 0.2.2.9, Zeitstempel: 0x3934d3e8
Name des fehlerhaften Moduls: legoland.exe, Version: 0.2.2.9, Zeitstempel: 0x3934d3e8
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0005241a
ID des fehlerhaften Prozesses: 0x23a0
Startzeit der fehlerhaften Anwendung: 0xlegoland.exe0
Pfad der fehlerhaften Anwendung: legoland.exe1
Pfad des fehlerhaften Moduls: legoland.exe2
Berichtskennung: legoland.exe3

Error: (06/15/2015 02:23:59 PM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005)"

Error: (06/15/2015 06:27:53 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wlmail.exe, Version 14.0.8089.726 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 20bc

Startzeit: 01d0a72357fe1421

Endzeit: 20

Anwendungspfad: C:\Program Files\Windows Live\Mail\wlmail.exe

Berichts-ID: e0ef34aa-1316-11e5-977e-002618f9ca5d

Error: (06/15/2015 06:25:42 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wlmail.exe, Version 14.0.8089.726 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1fec

Startzeit: 01d0a72282aa9518

Endzeit: 40

Anwendungspfad: C:\Program Files\Windows Live\Mail\wlmail.exe

Berichts-ID: 8e335d02-1316-11e5-977e-002618f9ca5d

Error: (06/15/2015 02:09:41 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2492256

Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2492256

Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/14/2015 06:52:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7332


System errors:
=============
Error: (06/15/2015 05:20:20 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:20:10 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:19:15 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:18:50 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:16:54 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:08:49 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:07:51 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:06:06 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 04:43:24 PM) (Source: ipnathlp) (EventID: 31004) (User: )
Description: 0 Bytes Speicher konnten durch den DNS-Proxy-Agent nicht zugeordnet werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner Fehler ist im Speicher-Manager aufgetreten.

Error: (06/15/2015 04:37:52 PM) (Source: ipnathlp) (EventID: 31004) (User: )
Description: 0 Bytes Speicher konnten durch den DNS-Proxy-Agent nicht zugeordnet werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner Fehler ist im Speicher-Manager aufgetreten.


Microsoft Office:
=========================
Error: (06/15/2015 06:34:40 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST.exe13.6.2015.026c001d0a788caaf2ddf0C:\Users\Philipp\Desktop\FRST.exe36209be9-137c-11e5-977e-002618f9ca5d

Error: (06/15/2015 05:07:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: legoland.exe0.2.2.93934d3e8legoland.exe0.2.2.93934d3e8c00000050005241a23a001d0a77cca8cafe5C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exeC:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe4955926e-1370-11e5-977e-002618f9ca5d

Error: (06/15/2015 02:23:59 PM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005)

Error: (06/15/2015 06:27:53 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wlmail.exe14.0.8089.72620bc01d0a72357fe142120C:\Program Files\Windows Live\Mail\wlmail.exee0ef34aa-1316-11e5-977e-002618f9ca5d

Error: (06/15/2015 06:25:42 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wlmail.exe14.0.8089.7261fec01d0a72282aa951840C:\Program Files\Windows Live\Mail\wlmail.exe8e335d02-1316-11e5-977e-002618f9ca5d

Error: (06/15/2015 02:09:41 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\EPSON Software\Download Navigator\EPSDNLMW64.EXE

Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2492256

Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2492256

Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/14/2015 06:52:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7332


==================== Memory info =========================== 

Processor: Intel(R) Core(TM)2 Duo CPU T6500 @ 2.10GHz
Percentage of memory in use: 48%
Total physical RAM: 3071.27 MB
Available physical RAM: 1570.68 MB
Total Pagefile: 6140.86 MB
Available Pagefile: 3668.44 MB
Total Virtual: 3071.88 MB
Available Virtual: 2926.79 MB

==================== Drives ================================

Drive c: (VistaOS) (Fixed) (Total:149.04 GB) (Free:24.31 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:137.33 GB) (Free:68.21 GB) NTFS

==================== MBR & Partition Table ==================

==================== End of log ============================
         
--- --- ---
__________________

Alt 15.06.2015, 17:51   #4
flowerwithlo
 
DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



Nun noch ein Scan als Admin (hab beim Auswahlfenster einfach einen genommen):

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-06-2015
Ran by Beamer (administrator) on SCHEFFLER-PC on 15-06-2015 18:45:13
Running from C:\Users\Philipp\Desktop
Loaded Profiles: Jeffel & Philipp & Beamer & Ellen & Manuel & Manuel (Available Profiles: Jeffel & Philipp & Beamer & Ellen & Manuel & Manuel)
Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE
(DeviceVM) C:\ASUS.SYS\DVMExportService.exe
() C:\Program Files\MyPublicWiFi\PublicWiFiService.exe
() C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
(DEVGURU Co., LTD.) D:\Samsung Kies\USB Drivers\25_escape\conn\ss_conn_service.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(AMD) C:\Windows\System32\atieclxx.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
() C:\Program Files\Wireless Console 2\wcourier.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\WDC.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files\ASUS\ATK Media\DMedia.exe
(AlcorMicro Co., Ltd.) C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
(ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
() D:\Gaming Maus\DareUMonitor.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-Agent.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATILEE.EXE
(Dropbox, Inc.) C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe
(Valve Corporation) D:\Steam\Steam.exe
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1549608 2009-08-17] (Synaptics Incorporated)
HKLM\...\Run: [HControlUser] => C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM\...\Run: [ATKOSD2] => C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS)
HKLM\...\Run: [ATKMEDIA] => C:\Program Files\ASUS\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS)
HKLM\...\Run: [AmIcoSinglun] => C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe [233472 2009-07-31] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [ADSMTray] => C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [272952 2009-06-24] (ASUSTek Computer Inc.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [730416 2015-06-11] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Dare-U mouse] => D:\Gaming Maus\DareUMonitor.exe [786432 2012-11-20] ()
HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1065024 2014-05-02] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [BlueStacks Agent] => C:\Program Files\BlueStacks\HD-Agent.exe [884440 2015-05-28] (BlueStack Systems, Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.Systray.exe [130864 2015-05-21] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [144384 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [DAEMON Tools Lite] => D:\DT\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [Dropbox Update] => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-13] (Dropbox, Inc.)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil32_17_0_0_188_Plugin.exe [927920 2015-05-20] (Adobe Systems Incorporated)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\MountPoints2: {7ed2759d-f168-11de-961b-806e6f6e6963} - E:\NightRacer.EXE
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.)
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [DAEMON Tools Lite] => D:\DT\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [Steam] => D:\Steam\steam.exe [2892992 2015-06-04] (Valve Corporation)
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [21969480 2015-05-19] (Google)
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [EADM] => C:\Program Files\Origin\Origin.exe [3632472 2015-06-08] (Electronic Arts)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\RunOnce: [iCloud] => C:\Program Files\Common Files\Apple\Internet Services\iCloud.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe
HKU\S-1-5-21-644356114-2566177158-2502637254-1008\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-644356114-2566177158-2502637254-1008\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe
HKU\S-1-5-21-644356114-2566177158-2502637254-1008\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-21-644356114-2566177158-2502637254-1011\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe
HKU\S-1-5-21-644356114-2566177158-2502637254-1011\...\MountPoints2: {7ed2759d-f168-11de-961b-806e6f6e6963} - E:\NightRacer.EXE
Lsa: [Notification Packages] scecli C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT
Startup: C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-05-12]
ShortcutTarget: Dropbox.lnk -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2011-03-30]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-12-13]
ShortcutTarget: Dropbox.lnk -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2011-03-31]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ADSMOverlayIcon] -> {A825576B-0042-4F0F-8FB0-93CE0F054E69} => C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll [2007-06-15] ()
ShellIconOverlayIdentifiers: [ADSMOverlayIcon1] -> {A8D448F4-0431-45AC-9F5E-E1B434AB2249} => C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll [2007-06-01] ()
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
GroupPolicyUsers\S-1-5-21-644356114-2566177158-2502637254-1011\User: Group Policy Restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-644356114-2566177158-2502637254-1004\User: Group Policy Restriction detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.de/
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com/
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://www.google.de/
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com
HKU\S-1-5-21-644356114-2566177158-2502637254-1008\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
URLSearchHook: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} -  No File
URLSearchHook: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} -  No File
URLSearchHook: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} -  No File
SearchScopes: HKLM -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS
SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_de
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=IEFM1&q={searchTerms}&src={referrer:source?}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&affID=119649&babsrc=SP_ss&mntrId=9a1a16840000000000002225d303ecbc
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_de
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {7B55E28C-0351-41CC-AC14-22094D95924D} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {76193214-59DA-47ED-BB15-3BCACFC2C36A} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {7B55E28C-0351-41CC-AC14-22094D95924D} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {B1316728-20A2-4B2A-9CD7-B52C1B2CB91A} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> {7B55E28C-0351-41CC-AC14-22094D95924D} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1008 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = 
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1008 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = 
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1011 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = 
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} ->  No File
BHO: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH)
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.177.1

FireFox:
========
FF ProfilePath: C:\Users\Beamer\AppData\Roaming\Mozilla\Firefox\Profiles\5tcpn7ab.default
FF SearchEngineOrder.1: Ask.com
FF SelectedSearchEngine: Ask.com
FF Keyword.URL: hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-4&o=APN10261&locale=de_DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_ptnrs=%5EAGS&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C&apn_dtid=%5EYYYYYY%5EYY%5EDE&&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-20] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2009-09-07] (CANON INC.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-644356114-2566177158-2502637254-1004: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Philipp\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-10-03] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-644356114-2566177158-2502637254-1008: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Ellen & Manuel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-11-25] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-02-16] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-02-16] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-02-16] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-02-16] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-02-16] (Apple Inc.)
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-06-02]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-12-13]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-06-02]

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.) [File not signed]
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [827184 2015-06-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [450808 2015-06-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [450808 2015-06-11] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1188360 2015-06-11] (Avira Operations GmbH & Co. KG)
R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS)
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed]
R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [208632 2015-05-21] (Avira Operations GmbH & Co. KG)
S3 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [433880 2015-05-28] (BlueStack Systems, Inc.)
S3 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [413400 2015-05-28] (BlueStack Systems, Inc.)
S3 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [806616 2015-05-28] (BlueStack Systems, Inc.)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc.exe [126128 2012-05-17] (Seiko Epson Corporation)
R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE [143424 2013-04-26] (SEIKO EPSON CORPORATION)
R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
S3 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
R2 MDES; C:\ASUS.SYS\DVMExportService.exe [307200 2008-10-21] (DeviceVM) [File not signed]
R2 MyPublicWiFiService; C:\Program Files\MyPublicWiFi\PublicWiFiService.exe [756224 2013-04-03] () [File not signed]
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1997168 2015-06-08] (Electronic Arts)
R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] ()
R2 ss_conn_service; D:\Samsung Kies\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
R3 WinHttpAutoProxySvc; winhttp.dll [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AmUStor; C:\Windows\System32\drivers\AmUStor.SYS [25600 2009-07-24] (Alcor Micro, Corp.)
R0 AsDsm; C:\Windows\system32\Drivers\AsDsm.sys [30264 2009-12-25] (ASUSTek Computer Inc)
R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-06-11] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-06-11] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-20] (Avira Operations GmbH & Co. KG)
R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [105728 2014-09-29] (AVM Berlin)
R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [105728 2014-09-29] (AVM Berlin)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-11] (Avira Operations GmbH & Co. KG)
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [131288 2015-05-28] (BlueStack Systems)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-11-21] (Disc Soft Ltd)
R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2009-06-18] (Windows (R) Win 7 DDK provider)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [14392 2009-05-13] (ASUS)
R1 ndiskhaz; C:\Windows\System32\DRIVERS\ndiskhaz.sys [25416 2012-12-07] (Khalil Azzouzi)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1766592 2009-06-05] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [324096 2013-11-21] (Duplex Secure Ltd.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-06-11] (Avira Operations GmbH & Co. KG)
R3 stdriver; C:\Windows\System32\DRIVERS\stdriver32.sys [52312 2012-06-21] (NCH Software)
U3 asify6mi; C:\Windows\system32\Drivers\asify6mi.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
U3 aydu7eur; C:\Windows\system32\Drivers\aydu7eur.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X]
S3 ipswuio; System32\DRIVERS\ipswuio.sys [X]
S3 RTHDMIAzAudService; system32\drivers\RtHDMIV.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-15 18:45 - 2015-06-15 18:46 - 00033138 _____ C:\Users\Philipp\Desktop\FRST.txt
2015-06-15 18:32 - 2015-06-15 18:45 - 00000000 ____D C:\FRST
2015-06-15 18:13 - 2015-06-15 18:13 - 01148416 _____ (Farbar) C:\Users\Philipp\Desktop\FRST.exe
2015-06-14 18:33 - 2015-06-14 18:33 - 00002991 _____ C:\Users\Philipp\AppData\Local\recently-used.xbel
2015-06-14 16:21 - 2015-06-14 16:21 - 00000012 ____H C:\dvmexp.idx
2015-06-14 08:12 - 2015-06-14 08:12 - 00000000 ___HD C:\dvmexp
2015-06-13 14:19 - 2015-06-13 14:19 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-06-13 14:18 - 2015-06-15 18:23 - 00001228 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job
2015-06-13 14:18 - 2015-06-15 14:23 - 00001176 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job
2015-06-13 14:18 - 2015-06-13 14:18 - 00000000 ____D C:\Users\Jeffel\AppData\Local\Dropbox
2015-06-13 14:18 - 2015-06-13 14:18 - 00000000 ____D C:\ProgramData\Dropbox
2015-06-11 20:32 - 2015-06-11 20:32 - 00131180 _____ C:\Users\Manuel\Downloads\Motorrad Profi 4 - kostenlos online spielen.htm
2015-06-11 18:41 - 2015-06-11 18:41 - 00001085 _____ C:\Users\Public\Desktop\Avira.lnk
2015-06-10 10:09 - 2015-06-02 21:35 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 10:09 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 10:09 - 2015-05-25 19:00 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-10 10:09 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-10 10:09 - 2015-05-23 05:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-10 10:09 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 10:09 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-10 10:09 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-10 10:09 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 10:09 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-10 10:09 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 10:09 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-10 10:09 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-10 10:09 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 10:09 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 10:09 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-10 10:09 - 2015-05-23 05:05 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-10 10:09 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 10:09 - 2015-05-23 05:00 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-10 10:09 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-10 10:09 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-10 10:09 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-10 10:09 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 10:09 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 10:09 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 10:09 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 10:09 - 2015-05-23 04:38 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-10 10:09 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 10:09 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-10 10:09 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 10:09 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 10:09 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 10:09 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 10:09 - 2015-05-22 20:03 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-10 10:09 - 2015-05-22 19:58 - 00901120 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-10 10:09 - 2015-05-21 15:20 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-10 10:08 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-06-10 10:08 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-10 10:08 - 2015-05-25 20:07 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-10 10:08 - 2015-05-25 20:07 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-10 10:08 - 2015-05-25 20:04 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00853504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-10 10:08 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-10 10:08 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-10 10:08 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-10 10:08 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-10 10:08 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-10 10:08 - 2015-05-25 18:53 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 10:08 - 2015-05-09 05:14 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-10 10:08 - 2015-05-09 05:13 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-10 10:08 - 2015-05-09 05:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-10 10:08 - 2015-05-09 05:12 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-10 10:08 - 2015-05-09 05:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 03:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 03:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-10 10:08 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-10 10:08 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-10 10:08 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-10 10:08 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-10 10:08 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-10 10:08 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-09 17:20 - 2015-06-09 17:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2015-06-09 17:20 - 2015-06-09 17:21 - 00000000 ____D C:\Program Files\BlueStacks
2015-06-09 17:20 - 2015-06-09 17:20 - 00000000 ____D C:\ProgramData\BlueStacks
2015-06-09 17:18 - 2015-06-09 17:18 - 15738056 _____ C:\Users\Philipp\Downloads\CloudMusic_official_2.7.1.apk
2015-06-09 17:18 - 2015-06-09 17:18 - 14155832 _____ (BlueStack Systems Inc.) C:\Users\Philipp\Downloads\BlueStacks-ThinInstaller.exe
2015-06-09 15:44 - 2015-05-09 05:14 - 02937344 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 02045952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-06-09 15:44 - 2015-05-09 05:13 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-06-09 15:44 - 2015-05-09 05:13 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-06-09 15:44 - 2015-05-09 05:13 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-06-09 15:44 - 2015-05-09 05:13 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-06-06 18:11 - 2015-06-06 18:11 - 00000000 ____D C:\Users\Beamer\AppData\Local\GWX
2015-06-06 11:34 - 2015-06-07 21:06 - 00000000 ____D C:\Users\Philipp\Documents\Joerg Riesa
2015-06-04 20:15 - 2015-06-04 20:16 - 00103104 _____ C:\Users\Manuel\Downloads\Crazy Skater - kostenlos online spielen.htm
2015-06-04 19:22 - 2015-06-04 19:22 - 00002121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-06-03 18:24 - 2015-06-03 18:24 - 00000000 ____D C:\Users\Manuel\AppData\Local\GWX
2015-06-03 16:37 - 2015-06-03 16:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2015-06-02 15:47 - 2015-06-04 18:42 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-01 20:38 - 2015-06-01 20:38 - 00000000 ____D C:\Users\Jeffel\AppData\Local\GWX
2015-06-01 19:02 - 2015-06-01 19:02 - 00000000 ____D C:\Users\Ellen & Manuel\AppData\Local\GWX
2015-06-01 18:03 - 2015-06-01 18:03 - 00000000 ____D C:\Users\Philipp\AppData\Local\GWX
2015-05-31 15:23 - 2015-05-31 15:43 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dual Monitor
2015-05-31 15:23 - 2015-05-31 15:23 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dual Monitor
2015-05-20 19:51 - 2015-05-20 19:51 - 00177664 _____ C:\Users\Philipp\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-20 17:18 - 2015-04-11 05:07 - 00054656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-05-20 17:18 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-05-20 17:18 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-05-17 19:56 - 2015-06-15 17:56 - 00000917 _____ C:\Windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job
2015-05-17 19:56 - 2015-06-15 17:56 - 00000731 _____ C:\Windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job
2015-05-16 20:06 - 2015-05-16 20:06 - 00275744 _____ C:\Windows\Minidump\051615-38750-01.dmp
2015-05-16 09:04 - 2015-05-16 09:04 - 00172295 _____ C:\Users\Philipp\Documents\Konfiguration FritzBox.xps

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-15 18:19 - 2012-04-04 22:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-15 18:10 - 2014-12-31 17:10 - 00000917 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job
2015-06-15 18:10 - 2014-12-31 17:10 - 00000731 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job
2015-06-15 18:10 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-06-15 18:04 - 2010-01-31 18:04 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-15 17:04 - 2013-11-21 19:48 - 00000000 ____D C:\Users\Beamer\AppData\Roaming\DAEMON Tools Lite
2015-06-15 16:40 - 2009-12-25 17:20 - 00019456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-15 16:40 - 2009-12-25 17:20 - 00019456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-15 16:39 - 2012-12-17 20:34 - 00000000 ___RD C:\Users\Philipp\Documents\Dropbox
2015-06-15 16:38 - 2014-07-12 11:12 - 00000000 ___RD C:\Users\Philipp\Google Drive
2015-06-15 16:38 - 2010-12-01 14:28 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dropbox
2015-06-15 16:35 - 2010-01-31 18:04 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-15 08:20 - 2009-12-25 18:22 - 01411283 _____ C:\Windows\WindowsUpdate.log
2015-06-15 06:48 - 2010-09-11 19:48 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Skype
2015-06-15 06:45 - 2014-07-30 10:13 - 00000000 __SHD C:\Users\Jeffel\AppData\Local\EmieUserList
2015-06-15 06:45 - 2014-07-30 10:13 - 00000000 __SHD C:\Users\Jeffel\AppData\Local\EmieSiteList
2015-06-15 06:11 - 2009-08-20 05:40 - 01620684 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-14 20:33 - 2012-12-30 21:21 - 00000000 ___RD C:\Users\Jeffel\Dropbox
2015-06-14 20:33 - 2012-12-30 21:17 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Dropbox
2015-06-14 19:33 - 2010-10-18 18:21 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Skype
2015-06-14 18:34 - 2014-11-23 16:42 - 00000000 ____D C:\Users\Philipp\.gimp-2.8
2015-06-14 17:18 - 2013-03-30 18:22 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\.minecraft
2015-06-14 16:36 - 2014-11-23 16:44 - 00000000 ____D C:\Users\Philipp\AppData\Local\gtk-2.0
2015-06-14 16:21 - 2009-08-19 05:27 - 00000000 ___HD C:\temp
2015-06-14 08:15 - 2013-02-10 11:44 - 00000438 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2015-06-14 08:12 - 2015-04-02 11:31 - 00244957 _____ C:\Windows\setupact.log
2015-06-14 08:12 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-13 13:07 - 2014-07-12 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-06-11 18:47 - 2015-04-04 08:21 - 00002266 _____ C:\Windows\PFRO.log
2015-06-11 18:47 - 2011-10-20 18:09 - 00000000 ____D C:\ProgramData\Avira
2015-06-11 18:41 - 2014-08-25 20:44 - 00000000 ____D C:\ProgramData\Package Cache
2015-06-11 18:40 - 2015-03-05 16:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-06-11 18:40 - 2012-11-02 20:39 - 00000000 ____D C:\Program Files\Avira
2015-06-11 12:09 - 2012-11-02 20:40 - 00136728 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-06-11 12:09 - 2012-11-02 20:40 - 00108448 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-06-11 12:09 - 2012-11-02 20:40 - 00031848 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\ssmdrv.sys
2015-06-11 09:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2015-06-11 08:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-06-10 17:55 - 2014-05-29 20:43 - 00000000 ____D C:\Users\Philipp\.android
2015-06-10 17:19 - 2012-04-04 22:24 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-06-10 17:19 - 2011-06-10 19:15 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-06-10 15:43 - 2015-04-02 11:30 - 00572992 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-10 15:05 - 2014-12-10 22:23 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-10 15:05 - 2014-04-26 10:01 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-10 15:04 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2015-06-10 10:31 - 2009-08-19 04:00 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-10 10:25 - 2013-07-28 23:00 - 00000000 ____D C:\Windows\system32\MRT
2015-06-10 10:14 - 2009-12-29 22:28 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-09 17:21 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Libraries
2015-06-08 18:27 - 2013-06-17 09:00 - 00000000 ____D C:\ProgramData\Origin
2015-06-08 18:20 - 2013-06-17 11:51 - 00000000 ____D C:\Users\Beamer\AppData\Roaming\Origin
2015-06-08 18:14 - 2013-06-17 09:00 - 00000000 ____D C:\Program Files\Origin
2015-06-08 17:04 - 2013-11-27 20:45 - 00000000 ____D C:\Program Files\Common Files\Steam
2015-06-07 08:24 - 2009-12-25 20:08 - 00000354 _____ C:\Windows\Tasks\Driver Robot.job
2015-06-06 10:46 - 2012-05-17 13:18 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Notepad++
2015-06-04 19:21 - 2009-08-19 04:20 - 00000000 ____D C:\Program Files\Google
2015-06-04 18:42 - 2012-05-11 15:08 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-06-03 16:42 - 2014-04-28 18:03 - 00000000 ____D C:\Program Files\CCleaner
2015-05-31 15:54 - 2012-12-22 15:49 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Audacity
2015-05-30 22:11 - 2009-11-24 20:19 - 00045056 _____ C:\Windows\system32\acovcnt.exe
2015-05-30 12:55 - 2010-03-06 18:42 - 00000000 ____D C:\Users\Jeffel\Documents\Kigo
2015-05-27 18:16 - 2010-01-25 18:43 - 00000000 ____D C:\Users\Jeffel\Documents\Telefon
2015-05-26 11:56 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-21 21:22 - 2011-08-28 09:47 - 00000000 ____D C:\Users\Beamer
2015-05-20 20:24 - 2012-11-02 20:40 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-05-20 17:19 - 2015-04-04 20:15 - 00000000 ___SD C:\Windows\system32\GWX
2015-05-20 17:07 - 2010-10-21 17:44 - 00000000 ____D C:\Users\Philipp\AppData\Local\Adobe
2015-05-20 17:06 - 2011-08-28 10:41 - 00000000 ____D C:\Users\Beamer\AppData\Local\Adobe
2015-05-16 20:06 - 2012-07-28 22:41 - 00000000 ____D C:\Windows\Minidump
2015-05-16 19:42 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2015-05-16 08:11 - 2010-12-01 14:28 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox

==================== Files in the root of some directories =======

2007-06-12 10:34 - 2007-06-12 10:34 - 0035822 _____ () C:\Program Files\Common Files\ASPG_icon.ico
2008-05-22 09:35 - 2008-05-22 09:35 - 0051962 _____ () C:\Program Files\Common Files\banner.jpg
2009-04-08 11:31 - 2009-04-08 11:31 - 0106496 _____ () C:\Program Files\Common Files\CPInstallAction.dll
2008-08-11 22:45 - 2008-08-11 22:45 - 0155648 _____ (ASUS) C:\Program Files\Common Files\MSIactionall.dll
2015-01-04 12:55 - 2015-01-04 12:55 - 0000459 _____ () C:\Users\Beamer\AppData\Roaming\Drives Meter_Settings.ini
2012-04-23 18:17 - 2013-05-02 17:27 - 0007598 _____ () C:\Users\Beamer\AppData\Local\Resmon.ResmonCfg
2010-09-11 19:55 - 2010-09-11 19:55 - 0000056 ____H () C:\ProgramData\ezsidmv.dat

Files to move or delete:
====================
C:\Users\Jeffel\i2errDeu.dll


Some files in TEMP:
====================
C:\Users\Beamer\AppData\Local\Temp\atcMedia1291428144436.exe
C:\Users\Beamer\AppData\Local\Temp\avgnt.exe
C:\Users\Ellen & Manuel\AppData\Local\Temp\avgnt.exe
C:\Users\Jeffel\AppData\Local\Temp\AskSLib.dll
C:\Users\Jeffel\AppData\Local\Temp\AutoRun.exe
C:\Users\Jeffel\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Jeffel\AppData\Local\Temp\avgnt.exe
C:\Users\Jeffel\AppData\Local\Temp\Delay.exe
C:\Users\Jeffel\AppData\Local\Temp\DirectoryRemovalUtility.exe
C:\Users\Jeffel\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Jeffel\AppData\Local\Temp\drm_dyndata_7370012.dll
C:\Users\Jeffel\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpw138tc.dll
C:\Users\Jeffel\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Jeffel\AppData\Local\Temp\FlashPlayerUpdate01.exe
C:\Users\Jeffel\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Jeffel\AppData\Local\Temp\i4jdel0.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u21-windows-i586-iftw-rv.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u22-windows-i586-iftw-rv.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Jeffel\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Jeffel\AppData\Local\Temp\mpsetup.exe
C:\Users\Jeffel\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Jeffel\AppData\Local\Temp\ose00000.exe
C:\Users\Jeffel\AppData\Local\Temp\PicasaUpdater_7e04.exe
C:\Users\Jeffel\AppData\Local\Temp\RemoveGO.exe
C:\Users\Jeffel\AppData\Local\Temp\sdanircmdc.exe
C:\Users\Jeffel\AppData\Local\Temp\sdapskill.exe
C:\Users\Jeffel\AppData\Local\Temp\setup.exe
C:\Users\Jeffel\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Jeffel\AppData\Local\Temp\uninst1.exe
C:\Users\Jeffel\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Jeffel\AppData\Local\Temp\_is9E90.exe
C:\Users\Jeffel\AppData\Local\Temp\_isBF68.exe
C:\Users\Manuel\AppData\Local\Temp\avgnt.exe
C:\Users\Philipp\AppData\Local\Temp\avgnt.exe
C:\Users\Philipp\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpvefjun.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-04 23:19

==================== End of log ============================
         

Alt 15.06.2015, 17:52   #5
flowerwithlo
 
DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



[CODE]Additional
FRST Logfile:
Code:
ATTFilter
scan result of Farbar Recovery Scan Tool (x86) Version: 13-06-2015
Ran by Beamer at 2015-06-15 18:47:13
Running from C:\Users\Philipp\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-644356114-2566177158-2502637254-500 - Administrator - Disabled)
Beamer (S-1-5-21-644356114-2566177158-2502637254-1005 - Administrator - Enabled) => C:\Users\Beamer
Ellen & Manuel (S-1-5-21-644356114-2566177158-2502637254-1008 - Limited - Enabled) => C:\Users\Ellen & Manuel
Gast (S-1-5-21-644356114-2566177158-2502637254-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-644356114-2566177158-2502637254-1010 - Limited - Enabled)
Jeffel (S-1-5-21-644356114-2566177158-2502637254-1000 - Administrator - Enabled) => C:\Users\Jeffel
Manuel (S-1-5-21-644356114-2566177158-2502637254-1011 - Limited - Enabled) => C:\Users\Manuel
Philipp (S-1-5-21-644356114-2566177158-2502637254-1004 - Limited - Enabled) => C:\Users\Philipp

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

1&1 SmartFax (HKLM\...\1&1 SmartFax) (Version: 2.00.224 - 1&1 Internet AG)
3dPageFlip  Editor (HKLM\...\3dPageFlip PDF Editor_is1) (Version:  - 3dPageFlip Solution)
Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version:  - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adblock Plus für IE (32-Bit) (HKLM\...\{654F389B-E402-4F7B-BA6D-DA732BB57ACB}) (Version: 1.4 - Eyeo GmbH)
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM\...\AmUStor) (Version: 1.4.1217.35202 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (Version: 1.4.1217.35202 - Alcor Micro Corp.) Hidden
Apple Application Support (32-Bit) (HKLM\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASUS CopyProtect (HKLM\...\{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}) (Version: 1.0.0015 - ASUS)
ASUS Data Security Manager (HKLM\...\{FA2092C5-7979-412D-A962-6485274AE1EE}) (Version: 1.00.0014 - ASUS)
ASUS FancyStart (HKLM\...\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}) (Version: 1.0.6 - ASUSTeK Computer Inc.)
ASUS LifeFrame3 (HKLM\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS)
ASUS Live Update (HKLM\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS)
ASUS MultiFrame (HKLM\...\{9D48531D-2135-49FC-BC29-ACCDA5396A76}) (Version: 1.0.0019 - ASUS)
ASUS Power4Gear eXtreme (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.0.19 - ASUS)
ASUS SmartLogon (HKLM\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0007 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0028 - ASUS)
ASUS Touch Pad Extra (HKLM\...\{DB891739-2EB3-45A8-9CBD-941C255CECD4}) (Version:  - )
ASUS Virtual Camera (HKLM\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.19 - asus)
Asus_Camera_ScreenSaver (HKLM\...\Asus_Camera_ScreenSaver) (Version: 2.0.0008 - ASUS)
Atheros Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - Atheros)
ATI Catalyst Install Manager (HKLM\...\{0AE24BD5-185C-436C-D93D-50574523C6C4}) (Version: 3.0.732.0 - ATI Technologies, Inc.)
ATK Generic Function Service (HKLM\...\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}) (Version: 1.00.0008 - ATK)
ATK Hotkey (HKLM\...\{7C05592D-424B-46CB-B505-E0013E8E75C9}) (Version: 1.0.0053 - ASUS)
ATK Media (HKLM\...\{D1E5870E-E3E5-4475-98A6-ADD614524ADF}) (Version: 2.0.0006 - ASUS)
ATKOSD2 (HKLM\...\{3B05F2FB-745B-4012-ADF2-439F36B2E70B}) (Version: 7.0.0006 - ASUS)
aTube Catcher (HKLM\...\aTube Catcher) (Version: 2.9.1462 - DsNET Corp)
aTube Catcher Version 3.8 (HKLM\...\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
Audacity 2.0.2 (HKLM\...\Audacity_is1) (Version: 2.0.2 - Audacity Team)
Avanquest update (HKLM\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.29 - Avanquest Software)
Avidemux 2.6 (32-bit) (HKLM\...\Avidemux 2.6) (Version: 2.6.8.9046 - )
Avira (HKLM\...\{0696cc37-db90-4000-be99-4a173ca7c8af}) (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG)
Avira (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.11.574 - Avira Operations GmbH & Co. KG)
Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION
Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION
Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION
Bandicam (HKLM\...\Bandicam) (Version: 1.8.5.302 - Bandisoft.com)
Battlefield 1942™ (HKLM\...\{5BE7BD06-512B-43bf-AD78-3BD2A5F5F7B3}) (Version: 1.6.20.0 - Electronic Arts)
Bejeweled® 3 (HKLM\...\{E99C27B2-EB2E-4244-9F5C-A96F55100F0C}) (Version: 1.1.13.4753 - Electronic Arts, Inc.)
BlueStacks App Player (HKLM\...\BlueStacks App Player) (Version: 0.9.27.5408 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM\...\{C1F53C9F-C560-4292-9237-12786FE6BF62}) (Version: 0.9.27.5408 - BlueStack Systems, Inc.)
Bob baut einen Park (HKLM\...\{367EDD83-302F-48E6-8F77-B0B056125C2D}) (Version: 1.0.0 - )
Bob der Baumeister (HKLM\...\{8F2D21F9-F428-4EF2-8111-953EF3299EFB}) (Version: 1.0.0 - )
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\...\CANONIJPLM100) (Version:  - )
Canon MP Navigator EX 3.0 (HKLM\...\MP Navigator EX 3.0) (Version:  - )
Canon MP490 series Benutzerregistrierung (HKLM\...\Canon MP490 series Benutzerregistrierung) (Version:  - )
Canon MP490 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series) (Version:  - )
Canon Utilities Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version:  - )
Canon Utilities My Printer (HKLM\...\CanonMyPrinter) (Version:  - )
Canon Utilities Solution Menu (HKLM\...\CanonSolutionMenu) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform)
Cisco EAP-FAST Module (HKLM\...\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\...\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\...\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.)
Construction-Simulator 2015 (HKLM\...\Steam App 289950) (Version:  - weltenbauer. Software Entwicklung GmbH)
Core Temp version 0.99.7 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 0.99.7 - Arthur Liberman)
Crusader No Remorse (HKLM\...\{2AEA735F-B393-4D89-93EF-5849CB72B4A3}) (Version: 1.0.0.2 - Electronic Arts)
CyberLink LabelPrint (HKLM\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1720 - CyberLink Corp.)
CyberLink Power2Go (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.2713 - CyberLink Corp.)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd)
Diercke Globus Online (HKLM\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH)
dm-Fotowelt (HKLM\...\dm-Fotowelt) (Version: 5.1.7 - CEWE Stiftung u Co. KGaA)
Dolby Control Center (HKLM\...\{0F3C61B5-3051-4DE6-8A6A-45100BCC1F41}) (Version: 1.2.0704 - Dolby)
Dropbox (HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Dropbox) (Version: 3.6.7 - Dropbox, Inc.)
Dropbox (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Dropbox) (Version: 3.4.6 - Dropbox, Inc.)
Druckerdeinstallation für EPSON XP-312 313 315 Series (HKLM\...\EPSON XP-312 313 315 Series) (Version:  - SEIKO EPSON Corporation)
Druckerdeinstallation für EPSON XP-412 413 415 Series (HKLM\...\EPSON XP-412 413 415 Series) (Version:  - SEIKO EPSON Corporation)
Dual Monitor 1.22 (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{64AA3F94-ED4A-4A4B-B72C-B7A1481ED5D8}_is1) (Version: 1.22.021813 - Cristi Diaconu)
EA SPORTS FIFA World (HKLM\...\{8F9AC744-EEF6-43DB-A4B6-FA1A18F1C640}) (Version: 9.5.0.61021 - Electronic Arts, Inc.)
Epson Connect Printer Setup (HKLM\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.3.0 - SEIKO EPSON CORPORATION)
Epson Event Manager (HKLM\...\{0F13C24A-FFE2-4CD0-8E0B-DC804E0A0E0B}) (Version: 3.10.0035 - Seiko Epson Corporation)
EPSON Scan (HKLM\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON-Handbücher (HKLM\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.32.0.0 - SEIKO EPSON CORPORATION)
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION)
Express Gate (HKLM\...\{62CF8923-31DC-4285-A23C-17CE5AA6A679}) (Version: 1.0.3.2 - DeviceVM, Inc.)
F1 2013 (HKLM\...\Steam App 223670) (Version:  - Codemasters Birmingham)
FIFA 09 (HKLM\...\{2315B23D-3E21-4920-837D-AE6460934ECB}) (Version: 1.0.1.1 - Electronic Arts)
Firebird SQL Server - MAGIX Edition (HKLM\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG)
FRITZ!Box USB-Fernanschluss (HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\2db37667170956ee) (Version: 2.3.2.0 - AVM Berlin)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Globus Fotoservice 4.4 (HKLM\...\Globus Fotoservice_is1) (Version:  - )
Google Drive (HKLM\...\{CBC9F5FD-5CFA-4A33-81CD-369EAB77E3A6}) (Version: 1.22.9403.0223 - Google, Inc.)
Google Earth (HKLM\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
Google+ Auto Backup (HKLM\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
Hot Wheels (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{CF36DD86-81D3-4D91-8F7A-344E0C1A4BFD}) (Version: 1.00.0000 - Activision Value)
iCloud (HKLM\...\{9A07AB4F-6B53-43E9-B7FC-7892E8C26BE3}) (Version: 4.1.1.53 - Apple Inc.)
Isola LEGO 2 (HKLM\...\{85967580-EBC2-11D4-AEA3-0050046A88ED}) (Version:  - )
iTunes (HKLM\...\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.)
Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
KingsoftOfficeXPlats 1.4 (HKLM\...\KingsoftOfficeXPlats) (Version: 1.4 - Kingsoft)
LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version:  - )
LBOTS Top mouse Driver (HKLM\...\{F1A273BD-6A9E-41D8-A111-5E56ACD286F8}) (Version: 1.0 - Togran)
LEGO Racers 2 (HKLM\...\{3DD2E9EA-0544-4162-B8BE-E21E994E9F3B}) (Version:  - )
LEGO® Star Wars™: Die Komplette Saga (HKLM\...\InstallShield_{D596980D-17BE-4425-B8F0-5640719AADE9}) (Version: 1.00.0000 - LucasArts)
LEGO® Star Wars™: The Complete Saga (Version: 1.00.0000 - LucasArts) Hidden
LEGOLAND (HKLM\...\LEGOLANDDeInstKey) (Version:  - )
Logitech Gaming Software (HKLM\...\{648F9C94-EC44-487B-9DA4-44ED72A082CC}) (Version: 4.50 - )
MAGIX Speed burnR (MSI) (HKLM\...\MX.{16884C3D-3512-486D-A2F9-39071551BFEF}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX Video deluxe 2014 (HKLM\...\MX.{EA62B22F-AB0A-406B-80A9-8036D3CE3446}) (Version: 13.0.2.8 - MAGIX AG)
MAGIX Video deluxe 2014 (Version: 13.0.2.8 - MAGIX AG) Hidden
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM\...\{95120000-0122-0407-0000-0000000FF1CE}) (Version: 12.0.6423.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{AC4C38FD-A54C-4CA5-92EE-D983CD81293E}) (Version: 1.20.146.0 - Microsoft)
Minecraft (HKLM\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Minigolf (HKLM\...\Minigolf_is1) (Version:  - Meridian93)
Monkey's Adventures (HKLM\...\Monkey's Adventures_is1) (Version:  - play-publishing.com)
Motorola Driver Installation 3.4.0 (HKLM\...\{81B3BEF9-5D97-4096-86E9-5B48A5BC32D0}) (Version: 3.4.0 - Motorola Inc.)
Motorola Phone Tools (HKLM\...\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}) (Version: 5.0.7a 4/01/2008 - Avanquest Software)
Motorola Phone Tools (Version: 4.30 - BVRP Software) Hidden
Motorola Phone Tools (Version: 5.00 - BVRP Software) Hidden
Mozilla Firefox 38.0.5 (x86 de) (HKLM\...\Mozilla Firefox 38.0.5 (x86 de)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyPublicWiFi 5.1 (HKLM\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version:  - TRUE Software)
Mystery P.I. - The London Caper (HKLM\...\Mystery P.I. - The London Caper) (Version:  - PopCap Games)
NB Probe (HKLM\...\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}) (Version:  - )
Need For Speed™ World (HKLM\...\{3AF1B16A-7DC9-4C80-BAEC-70B088A7C5B8}) (Version: 1.0.0.0 - Electronic Arts)
Net4Switch (HKLM\...\{9D6D7811-43B3-463C-BC79-5D1755269989}) (Version: 1.00.0019 - ASUS)
Norton Internet Security (Version: 16.0.0.125 - Symantec Corporation) Hidden
Notepad++ (HKLM\...\Notepad++) (Version: 6.1.2 - )
OpenAL (HKLM\...\OpenAL) (Version:  - )
Oracle VM VirtualBox 4.3.2 (HKLM\...\{91E5A436-8560-4621-9F26-D7050D078832}) (Version: 4.3.2 - Oracle Corporation)
Origin (HKLM\...\Origin) (Version: 9.2.1.4399 - Electronic Arts, Inc.)
pdfsam (HKLM\...\pdfsam) (Version: 2.2.0 - )
Peter Lustigs Verkehrsschule (HKLM\...\Verkehrsschule) (Version:  - )
Pflanzen gegen Zombies™ (HKLM\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.)
Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.)
QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Roads Of Rome (HKLM\...\Roads Of Rome_is1) (Version:  - Realore Studios)
Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.)
Samsung Kies (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SimCity 2000 Special Edition (HKLM\...\{59D2C751-F7BE-4E9F-9C8C-1F16013802C7}) (Version: 2.0.0.1 - Electronic Arts)
SimCity™ (HKLM\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
Skype™ 7.1 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
Software Updater (HKLM\...\{E1BAD1BA-C0E8-4018-9281-E7D2C6B07474}) (Version: 4.3.6 - SEIKO EPSON CORPORATION)
Steam (HKLM\...\Steam) (Version:  - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.1.1 - Synaptics Incorporated)
Syndicate (HKLM\...\{64CFBAAB-46F7-4628-8D9B-E656A8C11CDB}) (Version: 2.0.0.3 - Electronic Arts)
System Requirements Lab CYRI (HKLM\...\{E77DA909-3532-4C95-AFEB-06310E88462A}) (Version: 6.0.3.0 - Husdawg, LLC)
Theme Hospital (HKLM\...\{5118A4C2-C8A4-4CE5-AC37-F3E51C25402F}) (Version: 3.0.0.2 - Electronic Arts)
TIPP10 Version 2.1.0 (HKLM\...\TIPP10_is1) (Version:  - (c) 2006-2011, Tom Thielicke IT Solutions)
TmNationsForever (HKLM\...\TmNationsForever_is1) (Version:  - Nadeo)
TOGGO PC-Spielebox 2 (HKLM\...\{67EECE0C-8B6C-4D09-989D-D39BC9BBCA0E}) (Version: 1.00.0000 - )
Toyland Racer (HKLM\...\Toyland Racer) (Version:  - )
Unified Remote (HKLM\...\{D7930C67-5816-417B-BF28-54BB75EFDAF9}) (Version: 2.14.4.0 - Unified Remote)
Unity Web Player (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Unity Web Player (HKU\S-1-5-21-644356114-2566177158-2502637254-1008\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
upapp (HKLM\...\{4EF69D40-4DC9-485E-95D3-B1C22F218FC8}) (Version: 0.20.0000 - Hewlett-Packard)
USB 2.0 1.3M UVC WebCam (HKLM\...\USB 2.0 1.3M UVC WebCam) (Version:  - )
Werksfeuerwehr-Simulator Version 1.0 (HKLM\...\{5F7ED0CD-E04E-4441-9E03-10AFDB654E96}_is1) (Version:  - rondomedia Marketing & Vertriebs GmbH)
Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live ID-Anmelde-Assistent (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows Live Sync (HKLM\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
WinFlash (HKLM\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.29.0 - ASUS)
WinRAR (HKLM\...\WinRAR archiver) (Version:  - )
Wireless Console 2 (HKLM\...\{83F73CB1-7705-49D1-9852-84D839CA2A45}) (Version: 2.0.10 - ATK)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\ProgramData\Skype\Plugins\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\ProgramData\Skype\Plugins\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Philipp\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{4D72E5BC-BC7C-11E0-83CA-10424824019B}\InprocServer32 -> C:\Users\Philipp\AppData\Local\AskToolbar\Downloaded Program Files\AviraIDW.dll (Ask.com)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{595EF3BD-A186-454A-810C-02015139ACDC}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\Avira.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{7F902AD4-FC6A-4B2F-8B8D-B6DD4E329B76}\InprocServer32 -> C:\Users\Philipp\AppData\Local\AskToolbar\Downloaded Program Files\AviraWidget.dll (Ask.com)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{A0359AE6-F410-4425-A975-684AAB785ABD}\InprocServer32 -> C:\Users\Philipp\AppData\Local\AskToolbar\Downloaded Program Files\AviraBrowserSecurity.dll (Ask.com)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\Philipp\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{EB959CA4-408B-4465-9CF5-7EBA7B885153}\InprocServer32 -> C:\Users\Philipp\AppData\Local\AskToolbar\Downloaded Program Files\AviraSafetyPrivacy.dll (Ask.com)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FBE88A10-FF53-11E0-AB2A-AE904824019B}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\AVIRAI~1.DLL No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\Philipp\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\ProgramData\Skype\Plugins\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\ProgramData\Skype\Plugins\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{4D72E5BC-BC7C-11E0-83CA-10424824019B}\InprocServer32 -> C:\Users\Beamer\AppData\Local\ASKTOO~1\DOWNLO~1\AviraIDW.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{595EF3BD-A186-454A-810C-02015139ACDC}\InprocServer32 -> C:\Users\Beamer\AppData\Local\ASKTOO~1\DOWNLO~1\Avira.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\Beamer\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FBE88A10-FF53-11E0-AB2A-AE904824019B}\InprocServer32 -> C:\Users\Beamer\AppData\Local\ASKTOO~1\DOWNLO~1\AVIRAI~1.DLL No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\Beamer\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll No File

==================== Restore Points =========================

09-06-2015 14:14:35 Windows Update
09-06-2015 15:44:18 Windows Update
10-06-2015 10:13:21 Windows Update
15-06-2015 06:14:31 Windows-Sicherung

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {022E57E0-C220-4A4E-AC90-D2C8DACAFB9D} - System32\Tasks\{4E4F2CAC-AA02-4AC1-8E3F-7F64288279A5} => C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe [2000-05-31] (Krisalis Software Ltd.)
Task: {0381252B-84D7-4E1D-8044-32644EAD1708} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-03-16] (Microsoft Corporation)
Task: {062DB597-D745-4B4F-8444-3530722D8F45} - System32\Tasks\Core Temp Autostart => C:\Program Files\Core Temp\Core Temp.exe [2010-07-05] ()
Task: {08271361-89BF-4F1E-847E-1CA1ED3F6641} - System32\Tasks\{4B77430A-A839-4A8D-9AC6-DFE4CD36D283} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {0CF8F249-C5F7-475C-866F-21E7073015BD} - System32\Tasks\{EBC19F45-7508-4844-801A-11E762E37D12} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {0FB6D721-7BEF-4B45-8E9C-A271B66DE5F2} - System32\Tasks\{07EB860E-F755-4932-9D3F-42431206EE3B} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {10DE5D12-366D-4EFB-9E1B-A5431C45ADC4} - System32\Tasks\{8AC62F6C-CFBA-4FA8-8592-D8DBAF919A41} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {11F32470-4328-4A83-9232-80BC5F42F305} - System32\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE [2013-02-28] (SEIKO EPSON CORPORATION)
Task: {13CEC175-DFF4-4468-A045-29A526295C70} - System32\Tasks\{09EF0FB5-FFC5-4873-8A09-BA67F477983B} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {16A24A9E-DAB7-4860-94FD-851235C89820} - System32\Tasks\{2F3444E4-EAF5-4F9D-B44F-0359C6E1E962} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe
Task: {16E7A595-0943-4C27-81FD-3C0F4846CBB9} - System32\Tasks\{718A9724-BA58-4A15-BA3F-28AD141B9FD7} => C:\Program Files\Logitech\Profiler\LWEmon.exe [2004-05-19] (Logitech Inc.)
Task: {189C40ED-B151-444D-86FA-72B2F6B581EA} - System32\Tasks\{EEA39017-C6C8-42D6-83AD-AC789FF71125} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {1C2351DE-232B-4961-840F-EE0D68EB5EF4} - System32\Tasks\{81FAAD8E-E607-4907-9205-969E20593CF7} => C:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe
Task: {1DD33B99-F5E8-460F-BD30-B40888E8C53E} - System32\Tasks\{DB5AE33D-F764-456D-9421-62DA1F9288C7} => pcalua.exe -a "D:\DT\DAEMON Tools Lite\DTLite.exe" -d "D:\DT\DAEMON Tools Lite"
Task: {1E3565F3-04AA-44DB-B8B7-F35A50CC9057} - System32\Tasks\{07FA7B80-D838-4C87-9F76-696E853348E0} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe
Task: {2262B621-3FBA-4C58-8344-886110A30AF0} - System32\Tasks\{275198ED-E85E-4D37-9669-8DAC2931B05F} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {27685E6B-A6D7-4064-A4B9-1F485556156D} - System32\Tasks\{D1391C33-4665-4D75-B346-6737F2BFE6AE} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.)
Task: {279BEA6F-528A-4E59-B4D6-EF67500EC149} - System32\Tasks\{4CB1BAEC-7E20-4475-942D-B2ECD3C7BDE5} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {2C842B08-3AB4-4249-8416-A5F0C4254CBB} - System32\Tasks\{E26735BF-5210-43CB-908E-8A7923966B55} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {2E316E44-A20D-4E6C-8597-A4349A8F0F7B} - System32\Tasks\{0E84DB2D-E2CE-4939-A87C-0A7FEF5598A0} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe
Task: {2EB3D3F5-13C7-448C-98A4-8E8B09A66A7C} - System32\Tasks\{1833D727-C5CA-45F6-B130-C78FC735305C} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.)
Task: {3701EA83-EDC0-434F-8AB9-FE21AAE4072D} - System32\Tasks\{08709750-B91C-4722-844A-B78F6762E37B} => C:\Program Files\EA Sports\FIFA 09\FIFA09.exe [2008-10-23] ()
Task: {37B9496D-79A9-4BCE-AFE4-B5463740A943} - System32\Tasks\{F9594586-61F2-41B8-A093-C8719E057E91} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.)
Task: {393F6F51-0E95-4952-8BAD-E1DDD5FFF5DA} - System32\Tasks\{01E58447-78A0-4CD3-BFAF-44C036E4F3F7} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {394592EC-79F9-49B8-A307-37950D07C1B9} - System32\Tasks\{E9474EA8-9D29-4DF8-9857-8726D1F8FCD4} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe
Task: {3A161975-54C5-4DBB-8AB5-563F0BA63B7E} - System32\Tasks\{BBCB2F70-2DD9-4FDF-BA21-9F4AC8615359} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {3B9AC8C7-B8FF-4D70-9C79-4FB5EBBB90E9} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-07] (Microsoft Corporation)
Task: {3BC1FA8B-E302-4DEC-8AA9-B70DE9D839F7} - System32\Tasks\{15248D75-D51C-4771-8D5B-C56A5DC1D3F4} => C:\Program Files\OpenOffice.org 3\program\soffice.exe
Task: {3DF4B1BA-C6BA-4565-9C58-0A27C06A1D4C} - System32\Tasks\{10DEF6AD-CAED-48C8-85EB-BD3A12C54209} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {3ECE4DE4-C76E-486F-A045-0713A65EC396} - System32\Tasks\{C5F0B686-DAD5-46B7-8DC1-EEF6742294DF} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.)
Task: {3EF06EA8-17AE-4451-96B0-2ED48FE15BE6} - System32\Tasks\{FFB859B9-8F39-438E-A00B-543A2BC334B5} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {425C2494-05F2-4141-BD10-63B0AC111EEF} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {4299562C-9C52-4B20-9BF8-D294B2969604} - System32\Tasks\{CE1034B1-CDF0-44ED-A78A-0E1B67A19078} => pcalua.exe -a E:\SETUP.EXE -d E:\
Task: {46D08DF3-DE5D-4E6A-B197-11D566275F6D} - System32\Tasks\Driver Robot => C:\Program Files\Driver Robot\1.2.0.5\DriverRobot.exe
Task: {48F7E135-8B4D-421A-B8E8-22BE06815370} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-08] (Piriform Ltd)
Task: {4A3D5C4F-7A49-48E2-BE04-A2DECC4146C2} - System32\Tasks\{4DF731FE-39D2-4735-963D-B33DC6BF1776} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {4B952069-F7C4-4178-932C-D9AD6435A3EE} - System32\Tasks\{9F523BAE-9190-4380-B2B3-96FB780FE112} => pcalua.exe -a C:\Users\Philipp\Desktop\jxpiinstall.exe -d C:\Users\Philipp\Desktop
Task: {4B9BA069-9E54-412A-90D7-CBB925EBF5FA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-10] (Adobe Systems Incorporated)
Task: {4D2676FB-5EC2-4044-897A-45B547B13687} - System32\Tasks\ASUS Live Update => C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2007-11-30] ()
Task: {4D5F48A9-2EB0-4E4E-B34D-95A3DDB466A9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {4D8CE3D9-10E6-4EF4-9C8E-39AD6D90EEEB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13] (Dropbox, Inc.)
Task: {4E453841-EE58-4AA6-8514-3E30F217B1BE} - System32\Tasks\{E56CE78F-3DF9-4305-8336-77785549E0F4} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {542676B6-E1CE-4B5C-BDF2-C00ECFB38DBC} - System32\Tasks\{42963256-E132-413E-A4D9-4AD87B590641} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {543E71B8-E7BE-4FDA-AD19-CC490CA91848} - System32\Tasks\{09D857DD-F75F-4669-84AC-9B2B4F91002A} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {561375CB-FF5A-417B-B297-BA73DE149581} - System32\Tasks\Microsoft\Windows\Wired\GatherWiredInfo => C:\Windows\system32\gatherWiredInfo.vbs
Task: {576416B1-5229-4BB5-8F5F-5EB4CE34693A} - System32\Tasks\{0AD9175A-E960-4F4A-B254-A7FFF532194A} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.)
Task: {592F7F57-9C8F-4F5D-9A75-D8444CAF5A34} - System32\Tasks\{3A608F0C-88F6-4101-A24D-5888FB4E1675} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {5B3DB1D0-2D67-4C1C-BA0C-73372A98F89C} - System32\Tasks\{8B5019D5-0BD6-4708-A1CA-DE33DAF12937} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {5CC8A7A0-EB94-45A9-8C14-10D1FA017AA5} - System32\Tasks\{D6670E02-8F5A-46ED-BFE4-8AEF911AB2FE} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {5D8E271A-4247-422B-BB0B-A0F60CD4F2EE} - System32\Tasks\{CF4F2AC7-7291-4854-8184-33979FBEEA3A} => C:\Program Files\Logitech\Profiler\LWEMon.exe [2004-05-19] (Logitech Inc.)
Task: {6997CFAE-6B39-4219-A1BB-BFCA1A25B735} - System32\Tasks\ACMON => C:\Program Files\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK)
Task: {6BCBF903-EFC8-4841-A00B-8A98F9B42040} - System32\Tasks\{5F24C263-DED9-48A3-85E4-2AF0241EDD56} => pcalua.exe -a C:\PROGRA~1\Stardock\OBJECT~1\DesktopX\UNWISE.EXE -c C:\PROGRA~1\Stardock\OBJECT~1\DesktopX\INSTALL.LOG
Task: {6C2BAF56-D5B0-4D25-BFA4-8A03090E90F4} - System32\Tasks\{35BF4035-207B-4DDB-A7D9-DAE7569EA9A7} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {6C7963B0-501B-464F-85BB-0F1A98CB0EE2} - System32\Tasks\{ACD04780-E85C-4752-806D-C7E0B65CA043} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {6FAF6F7D-1CDF-4408-A9E7-F480AFD09927} - System32\Tasks\{224E176B-C279-4E30-BFAC-74EDBD3DF2AA} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {71707D88-0843-4073-AFAC-21043703B9B5} - System32\Tasks\{B5BE686C-6877-4712-B359-6260EE6BAA94} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {72ED54C5-EAAC-4283-858E-E531B2490992} - System32\Tasks\{795C6E6E-FAAA-4431-A918-937A78C53BB2} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {7504B855-6656-44B8-A9C0-BB031597F97E} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {7585CE6A-F9B1-4E6E-856F-617D6D00D54C} - System32\Tasks\Net4Switch => C:\Program Files\ASUS\Net4Switch\Net4Switch.exe [2007-11-20] (ASUS)
Task: {79B505CA-4391-4F82-93B8-F6A10F007D29} - System32\Tasks\{E9F1D326-BB8E-416E-A09B-6DEFFC535CE7} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {7B9BD304-C851-42BA-B29B-8832C02B513D} - System32\Tasks\{AA91F360-BE81-48A9-9CFE-2565918BACBC} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.)
Task: {7BBE44D8-A420-4877-91D3-43AD4DF8740A} - System32\Tasks\{99B1E97F-436E-4429-ABA3-7E618A478667} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {7D3C7871-A917-4EF0-82E8-5F0A96423051} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => BthUdTask.exe
Task: {805902FB-18D4-403F-9263-0624A07154E2} - System32\Tasks\{1648ED5A-2D13-4C52-AE7C-31297200C10D} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {85417455-F0F1-41C5-8316-B8DFEB8C8918} - System32\Tasks\{1A5C41D9-30DC-4783-B8B0-CEC6F0B3E839} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {86094599-821F-4E9B-8E55-9AF40185191E} - System32\Tasks\{ED62F36F-605A-4AE1-8208-FD5CA76699B4} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe
Task: {8B3014D9-EB90-4483-B8E6-B492402A6DF0} - System32\Tasks\{12845C94-D0B6-4BDA-A9FB-5B154245A6D4} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {8DBA4AC8-B6E1-4E21-92E1-6F5BD04CBC59} - System32\Tasks\{805913F2-AD7E-416D-BA65-5BCB278D42E1} => C:\Program Files\LEGO Schach\Lego Chess.exe
Task: {8EAD5D19-6EF9-4FAD-91E1-C759DDC095FA} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {8FB70F6E-172F-42D9-AD4A-91E5AFF5A7B5} - System32\Tasks\{20881F0F-F213-4B1D-AC68-02FABF50C1CE} => C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe [2000-05-31] (Krisalis Software Ltd.)
Task: {9057296A-F885-41B1-8E01-EF575CEF376C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: {90FFF327-1728-488D-BE4E-FA1232DD7BB6} - System32\Tasks\{14EDE9BC-20F9-4EFA-AC7D-6EB4C5A76C71} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {99C2E64D-3C78-4488-8CF3-672D6E3DB446} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13] (Dropbox, Inc.)
Task: {99C91901-9432-4EA7-87F8-55A525B95ABA} - System32\Tasks\{E2D1EE7B-E7AD-4C2D-AAB0-AC383A6F07CC} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.)
Task: {A0EC8CE0-03D7-4A0E-A8FA-0380AF2A1FF0} - System32\Tasks\{D884D7E7-64A4-45DE-98FD-56D8596FCD34} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {A93B8A4D-244F-453C-9B10-DB60E36A1C57} - System32\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE [2013-02-28] (SEIKO EPSON CORPORATION)
Task: {A9443690-748A-45F1-8D64-6AA0294F58AE} - System32\Tasks\{A5E9A2AB-D783-444B-ACEA-988C9C2827BD} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {AC093D78-AE53-48AF-A35E-7E570F6D5649} - System32\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE [2013-02-28] (SEIKO EPSON CORPORATION)
Task: {B22899B8-49AC-43DA-B2BF-CCB47C542539} - System32\Tasks\{37C1FFED-5F13-4EA4-B8E0-FBC3039B59DA} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe
Task: {B2FDDA94-D222-4673-A9AF-CAE32F13265A} - System32\Tasks\{57123DD4-3701-4890-8F5E-69253F2A254E} => C:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe
Task: {B344FCA0-E424-413D-B0C0-228FD63058F1} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {B3B4709A-B606-4F54-A90A-116F93D8512E} - System32\Tasks\ASPG => C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS)
Task: {B7D4A3DB-3927-46B0-A840-174630359DE6} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files\ASUS\SmartLogon\sensorsrv.exe [2009-05-18] (ASUS)
Task: {BF436BB1-3885-496D-B203-C36CFA947E53} - System32\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE [2013-02-28] (SEIKO EPSON CORPORATION)
Task: {C01F96CD-E814-4B3B-8ADB-B61746C44F27} - System32\Tasks\{47B8FC20-7DB8-48A6-83BC-E7C34E62CC8B} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {C361CDD7-C67A-4CB4-A515-59B3F225DF8C} - System32\Tasks\{6C5CE7EA-6EC5-497C-8FAE-8DDE494754CC} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {C6D305DC-A5B7-4BD2-B434-64B58E96E1B9} - System32\Tasks\{83270C1C-EFD0-435A-B354-DB444A4E64F7} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe
Task: {C71C0104-D3E3-49D0-886E-850A0EA0A519} - System32\Tasks\{629DDE4B-7DAE-4321-B366-19139E71F9C4} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {C8CF8AF5-8F8E-429F-89D8-BBB8B4A35E6E} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
Task: {CCCDE7C4-AC7C-4DD5-98AB-1DDF96CC1A00} - System32\Tasks\{5E36B9A2-EA7B-4338-B839-BA06E700C7A7} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {D21F6024-191F-4454-BBBC-09A650DA2549} - System32\Tasks\Microsoft\Windows\Application Experience\AitAgent => aitagent.exe
Task: {D2D316AA-04AB-4C85-B4E6-0FFA7C1B5CAD} - System32\Tasks\{897420D6-2E83-4F0C-9542-4235DE3ADD9D} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {D428F363-CD1D-4CEC-BCFD-7895783F2746} - System32\Tasks\{740C00F2-0AF4-462D-B602-FAA959059F5E} => C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe [2000-05-31] (Krisalis Software Ltd.)
Task: {D943FB3E-EB45-43CD-91A6-A055E15CE059} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: {DA81BBC7-677C-4A44-A056-CB90DC977864} - System32\Tasks\{0D730403-F736-400F-B631-19B8BC0E1E30} => C:\Program Files\EA Sports\FIFA 09\FIFA09.exe [2008-10-23] ()
Task: {DB85DFE2-B398-4D92-BA2A-821880861383} - System32\Tasks\{846920E1-73B4-4C1B-801F-BA087FE5EEF8} => C:\Program Files\LEGO Schach\Lego Chess.exe
Task: {DC34DD92-92FA-4E52-A136-C3C2FC249AE5} - System32\Tasks\{9D61A73B-0DE2-48FE-A2B3-088709BD7D2C} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {DC6CEF1A-D549-42B2-87D2-274BEC35D662} - System32\Tasks\{C1FB456D-5102-4D69-A102-59FBB9C799C1} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {DE31F299-BD40-4A25-BB8A-10EC1ADC4783} - System32\Tasks\{E39103FF-9002-43CF-B483-1326522EF959} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs
Task: {E54FD084-9DE3-498A-8ECB-F723F22FAB84} - System32\Tasks\{A48CA2AC-8CD3-4B01-9BD2-E56D49ADD8F7} => C:\Program Files\EA Sports\FIFA 09\FIFA09.exe [2008-10-23] ()
Task: {E5AB5213-9D14-427E-BF04-B685E363ABF9} - System32\Tasks\{F8DD370C-1C9B-4B99-A221-D936EDE7FDAD} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {E61935EA-A141-496D-BA9E-CF4C3EF3795D} - System32\Tasks\{3CB8A215-9260-42B8-8D9B-FA81017EED9A} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {EDFDEDC0-7152-4BC4-8E7A-2D96E5C6D8D7} - System32\Tasks\{6DD7CCD6-3D1C-4DA7-B895-4F4F95745358} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {EEA6A0A0-E1CD-4583-B178-0690064E5D8F} - System32\Tasks\{EE69846A-E56D-493D-B5DA-858DE7FA218B} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {F74F66A2-BA11-4AEC-A516-F153CDCD3451} - System32\Tasks\{2EF7C677-995A-413F-93CA-F39A6D35363C} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {F7E36632-B92F-40E5-8FDF-60225CFB5CB3} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Jeffel => C:\Program Files\Windows Calendar\WinCal.exe
Task: {F8E4E8A9-959E-4214-8706-20AE311FFA86} - System32\Tasks\{D1117AB3-5D96-42EF-8AE2-EE14F8692D60} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe
Task: {F8EF940F-03BD-46F5-A998-1540C6587472} - System32\Tasks\{FB7C2341-6721-4B95-A6AE-136D881A01F3} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {F9428F41-B2CF-431B-8A33-32AD9E73E88C} - System32\Tasks\{BF78135C-D9BB-42BD-8E6A-0FBBC5ACA700} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe
Task: {FD11DEA1-27EB-480A-ADD0-60B1E33E6B31} - System32\Tasks\{DA19A5B2-B0BB-49BA-854B-43FECBBC9387} => C:\Program Files\Logitech\Profiler\LWEmon.exe [2004-05-19] (Logitech Inc.)
Task: {FD3008D4-9573-44C7-B144-BA5C02B4BFCA} - System32\Tasks\{3E7DE8B7-79CA-4BC7-A84E-390073C4E375} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Driver Robot.job => C:\Program Files\Driver Robot\1.2.0.5\DriverRobot.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE
Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE:/EXE:{5ED40A39-9E20-4A57-9853-44602CD12F7A} /F:UpdateSYSTEM
Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\Windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE
Task: C:\Windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE:/EXE:{00F3F166-48F4-41CC-97B5-0BCDE58D612F} /F:UpdateSYSTEM
Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2009-08-19 05:08 - 2007-08-08 09:08 - 00094208 _____ () C:\Program Files\ATKGFNEX\GFNEXSrv.exe
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-02-13 05:20 - 2015-02-13 05:20 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-09-25 18:57 - 2013-04-03 14:09 - 00756224 _____ () C:\Program Files\MyPublicWiFi\PublicWiFiService.exe
2009-12-25 19:33 - 2007-08-03 13:24 - 00125496 _____ () C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
2009-12-25 19:33 - 2007-09-14 11:00 - 00147456 _____ () C:\Program Files\ASUS\NB Probe\SPM\spdiskex.dll
2009-12-25 19:33 - 2003-11-28 03:11 - 00135168 _____ () C:\Program Files\ASUS\NB Probe\SPM\spos.dll
2009-12-25 19:33 - 2005-08-29 16:24 - 00081920 _____ () C:\Program Files\ASUS\NB Probe\SPM\spnbacpi.dll
2009-12-25 19:33 - 2003-09-09 17:08 - 00049152 _____ () C:\Program Files\ASUS\NB Probe\SPM\spdmi.dll
2009-12-25 19:33 - 2006-04-04 11:24 - 00036864 _____ () C:\Program Files\ASUS\NB Probe\SPM\ghadmi.dll
2009-12-25 19:33 - 2005-04-07 20:25 - 00077824 _____ () C:\Program Files\ASUS\NB Probe\SPM\spmemory.dll
2009-08-19 04:53 - 2007-07-06 01:53 - 01040384 _____ () C:\Program Files\Wireless Console 2\wcourier.exe
2007-06-15 11:28 - 2007-06-15 11:28 - 00147456 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll
2007-06-01 18:08 - 2007-06-01 18:08 - 00143360 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
2010-01-01 12:48 - 2009-12-12 16:12 - 00141824 _____ () C:\Program Files\WinRAR\rarext.dll
2011-07-18 23:04 - 2011-07-18 23:04 - 00296448 _____ () C:\Program Files\Notepad++\NppShell_04.dll
2013-12-24 20:39 - 2012-11-20 00:44 - 00786432 _____ () D:\Gaming Maus\DareUMonitor.exe
2013-12-24 20:39 - 2013-03-27 13:48 - 00057344 _____ () D:\Gaming Maus\lan.dll
2013-12-24 20:39 - 2012-04-19 18:15 - 00061440 _____ () D:\Gaming Maus\hiddriver.dll
2015-05-08 20:50 - 2015-05-08 20:50 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2015-06-15 16:36 - 2015-06-15 16:36 - 00043008 _____ () c:\users\philipp\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpvefjun.dll
2015-03-04 23:45 - 2015-03-04 23:45 - 00750080 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-03-04 23:45 - 2015-03-04 23:45 - 00047616 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-03-04 23:45 - 2015-03-04 23:45 - 00865280 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-03-04 23:45 - 2015-03-04 23:45 - 00200704 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2015-06-15 16:35 - 2015-06-15 16:35 - 00098816 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32api.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00110080 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pywintypes27.dll
2015-06-15 16:35 - 2015-06-15 16:35 - 00364544 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pythoncom27.dll
2015-06-15 16:35 - 2015-06-15 16:35 - 00045568 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_socket.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 01161216 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_ssl.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00320512 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32com.shell.shell.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00713216 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_hashlib.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 01175040 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._core_.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00805888 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._gdi_.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00811008 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._windows_.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 01062400 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._controls_.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00735232 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._misc_.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00682496 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pysqlite2._sqlite.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00087552 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_ctypes.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00119808 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32file.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00108544 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32security.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00007168 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\hashobjs_ext.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00026624 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\usb_ext.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00167936 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32gui.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00018432 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32event.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00128512 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_elementtree.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00127488 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pyexpat.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00013824 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\common.time34.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00036864 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_psutil_windows.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00038912 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32inet.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00011264 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32crypt.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00070656 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._html2.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00027136 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_multiprocessing.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00020480 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_yappi.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00035840 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32process.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00686080 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\unicodedata.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00122368 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._wizard.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00024064 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32pipe.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00010240 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\select.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00025600 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32pdh.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00525640 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\windows._lib_cacheinvalidation.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00017408 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32profile.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00022528 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32ts.pyd
2015-06-15 16:35 - 2015-06-15 16:35 - 00078336 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._animate.pyd
2013-11-27 20:48 - 2015-04-16 19:40 - 00776192 _____ () D:\Steam\SDL2.dll
2015-01-24 17:49 - 2015-04-23 04:16 - 04962816 _____ () D:\Steam\v8.dll
2015-01-24 17:49 - 2015-04-23 04:16 - 01556992 _____ () D:\Steam\icui18n.dll
2015-01-24 17:49 - 2015-04-23 04:16 - 01187840 _____ () D:\Steam\icuuc.dll
2014-05-22 17:04 - 2015-06-04 20:56 - 02407104 _____ () D:\Steam\video.dll
2014-08-31 20:09 - 2014-12-01 23:31 - 02396672 _____ () D:\Steam\libavcodec-56.dll
2014-08-31 20:09 - 2014-12-01 23:31 - 00442880 _____ () D:\Steam\libavutil-54.dll
2014-08-31 20:09 - 2014-12-01 23:31 - 00479744 _____ () D:\Steam\libavformat-56.dll
2014-08-31 20:09 - 2014-12-01 23:31 - 00332800 _____ () D:\Steam\libavresample-2.dll
2014-08-31 20:09 - 2014-12-01 23:31 - 00485888 _____ () D:\Steam\libswscale-3.dll
2013-11-27 20:48 - 2015-06-04 20:56 - 00703168 _____ () D:\Steam\bin\chromehtml.DLL
2013-11-27 20:48 - 2015-05-11 21:01 - 36302728 _____ () D:\Steam\bin\libcef.dll
2015-05-16 07:55 - 2015-05-11 21:01 - 08958344 _____ () D:\Steam\bin\pdf.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Jeffel\Desktop\1.avi:TOC.WMV
AlternateDataStreams: C:\Users\Jeffel\Desktop\2.avi:TOC.WMV
AlternateDataStreams: C:\Users\Jeffel\Desktop\3.avi:TOC.WMV

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\Beamer\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-644356114-2566177158-2502637254-1008\Control Panel\Desktop\\Wallpaper -> C:\Users\Ellen & Manuel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-644356114-2566177158-2502637254-1011\Control Panel\Desktop\\Wallpaper -> C:\Users\Manuel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.177.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk => C:\Windows\pss\FancyStart daemon.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AlcoholAutomount => "D:\Alcohol 120\axcmd.exe" /automount
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: ASUS Camera ScreenSaver => C:\Windows\AsScrProlog.exe
MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\ASScrPro.exe
MSCONFIG\startupreg: ASUSTPE => C:\Windows\system32\ASUSTPE.exe
MSCONFIG\startupreg: AVMUSBFernanschluss => "C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\AVMAutoStart.exe"
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CanonSolutionMenu => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
MSCONFIG\startupreg: CLMLServer => "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: DAEMON Tools Lite => "D:\DT\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: KiesTrayAgent => D:\Samsung Kies\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: UpdateLBPShortCut => "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
MSCONFIG\startupreg: UpdateP2GoShortCut => "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{98B426BE-4154-48E7-A940-C28AD6AB3C7E}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{A0ED8D77-C475-4A7C-9683-E33EF6CA08AE}] => (Allow) svchost.exe
FirewallRules: [{5A959ABA-B81C-408F-9BF9-A382D827ED17}] => (Allow) C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [TCP Query User{92FF86AB-5408-4239-86CD-713C52CC5E72}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe
FirewallRules: [UDP Query User{756D4762-70FE-4F03-9A42-0F627F10CBF8}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe
FirewallRules: [TCP Query User{F15C73F2-09B2-4D70-B6C1-FCB8C6C3077A}C:\program files\google\google earth\client\googleearth.exe] => (Block) C:\program files\google\google earth\client\googleearth.exe
FirewallRules: [UDP Query User{3518798C-9464-4B02-B79D-33060DE82A80}C:\program files\google\google earth\client\googleearth.exe] => (Block) C:\program files\google\google earth\client\googleearth.exe
FirewallRules: [TCP Query User{F87691B0-9C93-4349-8E2B-69BF1B0D816D}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{0756E3CD-F4D3-4373-BCB1-583FDDA22919}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{6939840F-897B-42B5-8E48-6E97937198B0}] => (Allow) svchost.exe
FirewallRules: [{59E3FF2C-493B-4937-9A37-DA9D1CAAFC4B}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [TCP Query User{A1DE6356-BBC4-48A8-B039-88DEB224609A}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{E3168A96-5F5E-4485-AD0D-7AE6A2596564}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{4AF10D0E-C4C1-40A2-936B-C6F2AB12613B}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [UDP Query User{88D7FF05-F79E-4946-A853-288BD573E814}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [TCP Query User{9EFEAB5F-7210-4BC7-8BA8-231FA6D585A1}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe
FirewallRules: [UDP Query User{375FCB23-571C-4F84-90FE-A0670DEAAC49}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe
FirewallRules: [{55E52E7C-FD6E-4517-8357-F6D71154371A}] => (Allow) C:\Users\Jeffel\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{9C447FBD-4CD0-4507-918C-C3C1FC1BC0BC}] => (Allow) C:\Users\Jeffel\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{424B5F96-6253-4B19-824F-7157B91CE53C}C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{A3FECD29-88C2-49EE-9826-78B12649C757}C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{5518E9F3-F3DC-433F-9E50-A930A0CD15F2}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe
FirewallRules: [UDP Query User{55697CCA-A2DB-4C9F-8442-8DC6C36139AA}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe
FirewallRules: [TCP Query User{3E55C8FD-D431-4830-8F71-22F2B69255C3}C:\program files\ea sports\fifa 09\fifa09.exe] => (Allow) C:\program files\ea sports\fifa 09\fifa09.exe
FirewallRules: [UDP Query User{6B39FD39-72B8-4683-9E30-4221DEFAD5D9}C:\program files\ea sports\fifa 09\fifa09.exe] => (Allow) C:\program files\ea sports\fifa 09\fifa09.exe
FirewallRules: [TCP Query User{EF7EF825-131B-4165-A892-9DEC02FC688F}E:\easysetupassistant\wr841n\easysetupassistant.exe] => (Allow) E:\easysetupassistant\wr841n\easysetupassistant.exe
FirewallRules: [UDP Query User{25BF93E3-CEFC-4077-972C-637BBD3D8D23}E:\easysetupassistant\wr841n\easysetupassistant.exe] => (Allow) E:\easysetupassistant\wr841n\easysetupassistant.exe
FirewallRules: [{BE0F663E-C815-4563-A897-646E54E5E075}] => (Block) E:\easysetupassistant\wr841n\easysetupassistant.exe
FirewallRules: [{C1AD54B1-3E4E-48CD-AA59-46A81630CED6}] => (Block) E:\easysetupassistant\wr841n\easysetupassistant.exe
FirewallRules: [TCP Query User{642462DC-FE55-4283-B3BE-5116D1ABD2D1}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{1543EF59-9BDC-45F3-98C1-666138EE2360}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{F42F3A51-5E79-42CD-97EC-8F46AFB3AEDA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3AF441F6-2448-4E93-AF29-F00F2983A81B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{3A83D0B7-CC23-4E0A-A47F-BA4C727DA59B}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{A30C3FCC-E865-487C-BB2B-94503E562E57}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{C5B4D7F3-5ACD-4113-B7F8-EF24617B930D}] => (Allow) D:\OriginGames\Need for Speed World\GameLauncher.exe
FirewallRules: [{54FB9595-0BFB-47AF-866A-250C8D7B1BAF}] => (Allow) D:\OriginGames\Need for Speed World\GameLauncher.exe
FirewallRules: [{9E1C364E-EA27-4082-AB13-FBEBC90590BA}] => (Allow) D:\OriginGames\Battlefield 1942\BF1942.exe
FirewallRules: [{2EB3B6C7-04D1-43DF-B4B0-B47348DBCD68}] => (Allow) D:\OriginGames\Battlefield 1942\BF1942.exe
FirewallRules: [{DBB13B95-B032-45C2-A416-2E496104A650}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{5456B4DC-0D08-476B-B4CB-8BA97886248B}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{B3C9C811-6617-41F7-8833-D1B66AC7C967}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [TCP Query User{FB78B67C-4DFB-45DA-8910-73B460C08EE9}D:\needforspeed world\data\nfsw.exe] => (Allow) D:\needforspeed world\data\nfsw.exe
FirewallRules: [UDP Query User{514C9672-18B4-476C-B568-2B1D2211DC21}D:\needforspeed world\data\nfsw.exe] => (Allow) D:\needforspeed world\data\nfsw.exe
FirewallRules: [{122DB7AB-303C-4A23-8984-A4089D07A519}] => (Allow) D:\Steam\SteamApps\common\f12013\F1_2013.exe
FirewallRules: [{BA4A4B55-61BE-49C7-B106-9CF16C1FEFCA}] => (Allow) D:\Steam\SteamApps\common\f12013\F1_2013.exe
FirewallRules: [{852A6D93-68A1-49D2-A427-091873A0F8AF}] => (Allow) D:\OriginGames\Plants vs. Zombies\PlantsVsZombies.exe
FirewallRules: [{1C423230-E993-447A-B8BC-B011BD1ABEA4}] => (Allow) D:\OriginGames\Plants vs. Zombies\PlantsVsZombies.exe
FirewallRules: [{5476BAD2-AE20-42B2-BFC6-58B987D9EC81}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{812E2119-243A-400E-B7FE-DEB6D62808AB}] => (Allow) D:\OriginGames\SimCity\SimCity\SimCity.exe
FirewallRules: [{2C4E33E9-EDDF-4059-9790-647FCF83145D}] => (Allow) D:\OriginGames\SimCity\SimCity\SimCity.exe
FirewallRules: [TCP Query User{60D69111-FE19-4415-B387-D97AE26AFD38}C:\program files\tmnationsforever\tmforever.exe] => (Block) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [UDP Query User{F2DF262E-FF7C-484F-AA4E-63FF8880305C}C:\program files\tmnationsforever\tmforever.exe] => (Block) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [{A3C3ECE5-F0B8-458B-BF51-A7F6BF8F5E0E}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{DAA3B140-1FED-47B5-9F25-FB8F35548A03}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{F14B2E24-FBC1-4546-BBB6-CCBF3E3C26CB}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe
FirewallRules: [{1EBAA986-ABD7-469D-8126-C6A22AB47DCF}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe
FirewallRules: [TCP Query User{DF57783D-CA97-4654-B267-AC96484B730F}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{695F1F23-F5F2-4E3A-93D3-C046C30B108D}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [TCP Query User{18759B6E-98BA-4489-983D-ABCF93CE30A2}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{C48C23E4-CF37-4289-AC60-2FF3F377ACD4}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [{BAE39D93-BC07-4545-A838-D128E5D729B1}] => (Allow) C:\Users\Philipp\AppData\Local\Apps\2.0\AKHGTRNK.DG4\BWYE0CZZ.LL7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{BDC2FD03-237D-49E4-A6A2-8AE3211FB11A}] => (Allow) C:\Users\Philipp\AppData\Local\Apps\2.0\AKHGTRNK.DG4\BWYE0CZZ.LL7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{2A33F55E-5BBB-4A44-9852-D7FEA360081E}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{084ED6E8-0CDB-42C1-9716-21D9E1E099C3}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [TCP Query User{5A171416-5B5C-45E6-A06C-FD51ECCBBA01}C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe] => (Block) C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [UDP Query User{EC3DF4E2-12D4-4BEA-9E53-8BD42E933EE3}C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe] => (Block) C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{B3F421E8-5795-4576-A04B-678154A5D42C}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{56B79544-76F5-4B6F-85BD-3CA9415A0BE3}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [TCP Query User{A674A672-4708-4C05-A7DD-7FC78F2ABAD6}C:\program files\unified remote\remoteserver.exe] => (Allow) C:\program files\unified remote\remoteserver.exe
FirewallRules: [UDP Query User{C42108C2-C11D-4BCD-848F-C882C383AFF1}C:\program files\unified remote\remoteserver.exe] => (Allow) C:\program files\unified remote\remoteserver.exe
FirewallRules: [{66918B97-AE64-444C-9DB6-5DB605AE12F7}] => (Allow) D:\OriginGames\Bejeweled 3\Bejeweled3.exe
FirewallRules: [{4D93D20E-753C-494E-8FA6-F47CF535E417}] => (Allow) D:\OriginGames\Bejeweled 3\Bejeweled3.exe
FirewallRules: [{100DFB51-03A7-409A-8436-B1ADEDE290A7}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{3D1CFBF6-1099-4721-A86E-438E12C875EA}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{708B5EAF-95EC-428E-9AA3-7F8A3CC499D7}] => (Allow) D:\OriginGames\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe
FirewallRules: [{252252F8-D1E0-473A-8A33-743C157FAAAB}] => (Allow) D:\OriginGames\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe
FirewallRules: [{12369EEC-4B3E-4804-8395-3B1EE1D1F377}] => (Allow) C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe
FirewallRules: [{23965B5B-2D1F-4BC2-82F2-4E012CDB6110}] => (Allow) C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe
FirewallRules: [{8AD425C4-E4CD-4E0A-B470-71C0186D4419}] => (Allow) D:\OriginGames\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe
FirewallRules: [{79468976-3ED7-4AAD-8CDF-CC32C20626C3}] => (Allow) D:\OriginGames\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe
FirewallRules: [{98C0D637-E762-4100-8AF8-3E756C54A265}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe
FirewallRules: [{533B5FB5-1CB8-4776-8F97-B9D35616A215}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe
FirewallRules: [{D67CAA53-7942-4A91-8D54-03DE16AF77AA}] => (Allow) D:\Steam\SteamApps\common\ConSim2015\ConSim2015.exe
FirewallRules: [{085EB9AF-D4B4-42D7-AA85-2FF13C776871}] => (Allow) D:\Steam\SteamApps\common\ConSim2015\ConSim2015.exe
FirewallRules: [{13EC435C-D4A0-4045-9736-20D5C2A52E0F}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{766D54AC-FE82-4990-81C9-4B3E62FC1D8E}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{8147F4AA-6FEE-48F5-A257-DADCA6B3D1F7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{B59D5117-8BF8-4401-A031-594855C5359E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{C3A2EE98-6FD7-4841-986B-5FF483452073}] => (Allow) D:\OriginGames\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{7894DF2C-B685-420A-810A-505E1663461E}] => (Allow) D:\OriginGames\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{AB875D33-F535-45C7-83AD-4542A38F0A9A}] => (Allow) D:\OriginGames\Syndicate (1993)\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{C8819052-499D-4060-A2CB-63C85B7289F3}] => (Allow) D:\OriginGames\Syndicate (1993)\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [TCP Query User{2405E39F-611A-4841-8667-B7FAB332ED13}D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{98A5CF53-9EE7-4592-86E6-5A255E971ED4}D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{42389642-E7E4-4FA7-99F0-D17483626C6F}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{546675B7-4D5D-41B0-A82B-3C2AE0AED9AE}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{F4820325-C52D-4F14-B0C1-E2F40210A513}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft3077.tmp\fsetup.exe
FirewallRules: [{F8A2199B-EA6F-43B4-BF29-FC040CE4901D}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft3077.tmp\fsetup.exe
FirewallRules: [{0CB53765-513D-49DE-87C5-AECA2C3658C1}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pftAA65.tmp\fsetup.exe
FirewallRules: [{C88A6BB6-DBFF-4572-AA49-2F5929892EA3}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pftAA65.tmp\fsetup.exe
FirewallRules: [{13D83860-A9E7-48A7-A64E-3D805CB1B574}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft96D1.tmp\fsetup.exe
FirewallRules: [{4DDF4814-C41E-4164-81FB-D9C60F8AD319}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft96D1.tmp\fsetup.exe
FirewallRules: [{7870E46B-69E5-4524-B2E7-ECEB9E6D710D}] => (Allow) C:\Program Files\iTunes\iTunes.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/15/2015 06:34:40 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST.exe, Version 13.6.2015.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 26c0

Startzeit: 01d0a788caaf2ddf

Endzeit: 0

Anwendungspfad: C:\Users\Philipp\Desktop\FRST.exe

Berichts-ID: 36209be9-137c-11e5-977e-002618f9ca5d

Error: (06/15/2015 05:07:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: legoland.exe, Version: 0.2.2.9, Zeitstempel: 0x3934d3e8
Name des fehlerhaften Moduls: legoland.exe, Version: 0.2.2.9, Zeitstempel: 0x3934d3e8
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0005241a
ID des fehlerhaften Prozesses: 0x23a0
Startzeit der fehlerhaften Anwendung: 0xlegoland.exe0
Pfad der fehlerhaften Anwendung: legoland.exe1
Pfad des fehlerhaften Moduls: legoland.exe2
Berichtskennung: legoland.exe3

Error: (06/15/2015 02:23:59 PM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005)"

Error: (06/15/2015 06:27:53 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wlmail.exe, Version 14.0.8089.726 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 20bc

Startzeit: 01d0a72357fe1421

Endzeit: 20

Anwendungspfad: C:\Program Files\Windows Live\Mail\wlmail.exe

Berichts-ID: e0ef34aa-1316-11e5-977e-002618f9ca5d

Error: (06/15/2015 06:25:42 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm wlmail.exe, Version 14.0.8089.726 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1fec

Startzeit: 01d0a72282aa9518

Endzeit: 40

Anwendungspfad: C:\Program Files\Windows Live\Mail\wlmail.exe

Berichts-ID: 8e335d02-1316-11e5-977e-002618f9ca5d

Error: (06/15/2015 02:09:41 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2492256

Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2492256

Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/14/2015 06:52:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7332


System errors:
=============
Error: (06/15/2015 05:20:20 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:20:10 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:19:15 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:18:50 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:16:54 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:08:49 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:07:51 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 05:06:06 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (06/15/2015 04:43:24 PM) (Source: ipnathlp) (EventID: 31004) (User: )
Description: 0 Bytes Speicher konnten durch den DNS-Proxy-Agent nicht zugeordnet werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner Fehler ist im Speicher-Manager aufgetreten.

Error: (06/15/2015 04:37:52 PM) (Source: ipnathlp) (EventID: 31004) (User: )
Description: 0 Bytes Speicher konnten durch den DNS-Proxy-Agent nicht zugeordnet werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner Fehler ist im Speicher-Manager aufgetreten.


Microsoft Office:
=========================
Error: (06/15/2015 06:34:40 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST.exe13.6.2015.026c001d0a788caaf2ddf0C:\Users\Philipp\Desktop\FRST.exe36209be9-137c-11e5-977e-002618f9ca5d

Error: (06/15/2015 05:07:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: legoland.exe0.2.2.93934d3e8legoland.exe0.2.2.93934d3e8c00000050005241a23a001d0a77cca8cafe5C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exeC:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe4955926e-1370-11e5-977e-002618f9ca5d

Error: (06/15/2015 02:23:59 PM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005)

Error: (06/15/2015 06:27:53 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wlmail.exe14.0.8089.72620bc01d0a72357fe142120C:\Program Files\Windows Live\Mail\wlmail.exee0ef34aa-1316-11e5-977e-002618f9ca5d

Error: (06/15/2015 06:25:42 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wlmail.exe14.0.8089.7261fec01d0a72282aa951840C:\Program Files\Windows Live\Mail\wlmail.exe8e335d02-1316-11e5-977e-002618f9ca5d

Error: (06/15/2015 02:09:41 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\EPSON Software\Download Navigator\EPSDNLMW64.EXE

Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2492256

Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2492256

Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/14/2015 06:52:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7332


==================== Memory info =========================== 

Processor: Intel(R) Core(TM)2 Duo CPU T6500 @ 2.10GHz
Percentage of memory in use: 61%
Total physical RAM: 3071.27 MB
Available physical RAM: 1180.2 MB
Total Pagefile: 6140.86 MB
Available Pagefile: 3196.06 MB
Total Virtual: 3071.88 MB
Available Virtual: 2927.57 MB

==================== Drives ================================

Drive c: (VistaOS) (Fixed) (Total:149.04 GB) (Free:24.31 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:137.33 GB) (Free:68.21 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 97646C29)
Partition 1: (Not Active) - (Size=11.7 GB) - (Type=1C)
Partition 2: (Active) - (Size=149 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=137.3 GB) - (Type=OF Extended)

==================== End of log ============================
         
--- --- ---


Alt 16.06.2015, 15:25   #6
schrauber
/// the machine
/// TB-Ausbilder
 

DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



Immer mit Adminrechten

Lade Dir bitte von hier Revo Uninstaller Download Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
  • Installiere und starte das Programm. (Bebilderte Anleitung zu Revo Uninstaller)
  • Klicke auf Optionen und wähle als Sprache Deutsch.
  • Suche im Uninstallerfeld nach den Programmen:

    Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION

    Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION

    Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION


  • Wähle die Programme nacheinander aus und klicke jedes Mal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

 






Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.
__________________
--> DHL Spam Mail -> Trojaner/Virus?

Alt 16.06.2015, 17:55   #7
flowerwithlo
 
DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



Der Uninstaller hat scheinbar nur teilweise funktioniert (Fehlermeldung ), jedoch war das Programm nach der teilweisen Deinstallation nicht mehr zu finden.

Malwarebytes:
Code:
ATTFilter
Malwarebytes Anti-Rootkit BETA 1.09.1.1004
www.malwarebytes.org

Database version:
  main:    v2015.06.16.04
  rootkit: v2015.06.15.01

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.17843
Philipp :: SCHEFFLER-PC [administrator]

16.06.2015 17:06:27
mbar-log-2015-06-16 (17-06-27).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged.
Objects scanned: 549724
Time elapsed: 1 hour(s), 30 minute(s), 16 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
         
TDSSKiller:

Code:
ATTFilter
18:40:34.0856 0x0238  TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04
18:40:40.0160 0x0238  ============================================================
18:40:40.0160 0x0238  Current date / time: 2015/06/16 18:40:40.0160
18:40:40.0160 0x0238  SystemInfo:
18:40:40.0160 0x0238  
18:40:40.0160 0x0238  OS Version: 6.1.7601 ServicePack: 1.0
18:40:40.0160 0x0238  Product type: Workstation
18:40:40.0160 0x0238  ComputerName: SCHEFFLER-PC
18:40:40.0175 0x0238  UserName: Philipp
18:40:40.0175 0x0238  Windows directory: C:\Windows
18:40:40.0175 0x0238  System windows directory: C:\Windows
18:40:40.0175 0x0238  Processor architecture: Intel x86
18:40:40.0175 0x0238  Number of processors: 2
18:40:40.0175 0x0238  Page size: 0x1000
18:40:40.0175 0x0238  Boot type: Normal boot
18:40:40.0175 0x0238  ============================================================
18:40:43.0389 0x0238  KLMD registered as C:\Windows\system32\drivers\46743230.sys
18:40:43.0919 0x0238  System UUID: {3D1DEBB9-4086-B209-C6A5-452081E71891}
18:40:44.0824 0x0238  Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:40:44.0840 0x0238  ============================================================
18:40:44.0840 0x0238  \Device\Harddisk0\DR0:
18:40:44.0840 0x0238  MBR partitions:
18:40:44.0840 0x0238  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1770D7A, BlocksNum 0x12A14C00
18:40:44.0855 0x0238  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x141859B9, BlocksNum 0x112A7D08
18:40:44.0855 0x0238  ============================================================
18:40:45.0058 0x0238  C: <-> \Device\Harddisk0\DR0\Partition1
18:40:45.0167 0x0238  D: <-> \Device\Harddisk0\DR0\Partition2
18:40:45.0167 0x0238  ============================================================
18:40:45.0167 0x0238  Initialize success
18:40:45.0167 0x0238  ============================================================
18:41:36.0667 0x1660  ============================================================
18:41:36.0667 0x1660  Scan started
18:41:36.0667 0x1660  Mode: Manual; SigCheck; TDLFS; 
18:41:36.0667 0x1660  ============================================================
18:41:36.0667 0x1660  KSN ping started
18:41:39.0116 0x1660  KSN ping finished: true
18:41:41.0206 0x1660  ================ Scan system memory ========================
18:41:41.0206 0x1660  System memory - ok
18:41:41.0206 0x1660  ================ Scan services =============================
18:41:41.0378 0x1660  [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
18:41:41.0518 0x1660  1394ohci - ok
18:41:41.0565 0x1660  [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI            C:\Windows\system32\drivers\ACPI.sys
18:41:41.0581 0x1660  ACPI - ok
18:41:41.0612 0x1660  [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
18:41:41.0690 0x1660  AcpiPmi - ok
18:41:41.0815 0x1660  [ FC5B75CA6A1DA31EDD4F8D53F5540B98, CDC445F2790ADFC4C5568C40D4DA8BB95CD71991665B38AEC3D84571C99C3520 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
18:41:41.0830 0x1660  AdobeARMservice - ok
18:41:41.0939 0x1660  [ 00CC35F515079F5F94FABC3AC5C7D363, 7CE8B1715009602059DEDD6CBCA9C18EF079EDA344E7809813D6C0A395622B82 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
18:41:41.0955 0x1660  AdobeFlashPlayerUpdateSvc - ok
18:41:42.0002 0x1660  [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx         C:\Windows\system32\DRIVERS\adp94xx.sys
18:41:42.0033 0x1660  adp94xx - ok
18:41:42.0064 0x1660  [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci         C:\Windows\system32\DRIVERS\adpahci.sys
18:41:42.0080 0x1660  adpahci - ok
18:41:42.0111 0x1660  [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320         C:\Windows\system32\DRIVERS\adpu320.sys
18:41:42.0127 0x1660  adpu320 - ok
18:41:42.0220 0x1660  [ C0BF554D2277F7A4C735D475ADE2E3B2, 58ED620CD73239A6AB8F993492494AB0F09705B25E671A842D5163B13F452B15 ] ADSMService     C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
18:41:42.0267 0x1660  ADSMService - detected UnsignedFile.Multi.Generic ( 1 )
18:41:44.0685 0x1660  Detect skipped due to KSN trusted
18:41:44.0685 0x1660  ADSMService - ok
18:41:44.0747 0x1660  [ 12E6A172D72AFC626727B8635DD17E39, 33B3D109C39DF6EA86AFC3C89A93657906E981D3D22FF854401BC7326990CC08 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
18:41:44.0825 0x1660  AeLookupSvc - ok
18:41:44.0872 0x1660  [ D0B388DA1D111A34366E04EB4A5DD156, 60D226F027F4025CC032CAFF73A80FAFB5FA75445654FDCF80CA8C0419C6E938 ] AFD             C:\Windows\system32\drivers\afd.sys
18:41:44.0935 0x1660  AFD - ok
18:41:44.0966 0x1660  [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440          C:\Windows\system32\drivers\agp440.sys
18:41:44.0981 0x1660  agp440 - ok
18:41:45.0028 0x1660  [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx         C:\Windows\system32\DRIVERS\djsvs.sys
18:41:45.0044 0x1660  aic78xx - ok
18:41:45.0091 0x1660  [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG             C:\Windows\System32\alg.exe
18:41:45.0169 0x1660  ALG - ok
18:41:45.0200 0x1660  [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide          C:\Windows\system32\drivers\aliide.sys
18:41:45.0215 0x1660  aliide - ok
18:41:45.0231 0x1660  [ B19505648F033393E907E2E419FDE8B3, BEF76AAD61FE0CA1F2B91C491FD94DE1BE67E776BBB7972D57ADFBE0333E9615 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
18:41:45.0293 0x1660  AMD External Events Utility - ok
18:41:45.0309 0x1660  [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
18:41:45.0325 0x1660  amdagp - ok
18:41:45.0371 0x1660  [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide          C:\Windows\system32\drivers\amdide.sys
18:41:45.0371 0x1660  amdide - ok
18:41:45.0418 0x1660  [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8           C:\Windows\system32\DRIVERS\amdk8.sys
18:41:45.0496 0x1660  AmdK8 - ok
18:41:45.0527 0x1660  [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
18:41:45.0559 0x1660  AmdPPM - ok
18:41:45.0605 0x1660  [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
18:41:45.0637 0x1660  amdsata - ok
18:41:45.0668 0x1660  [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
18:41:45.0699 0x1660  amdsbs - ok
18:41:45.0715 0x1660  [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
18:41:45.0730 0x1660  amdxata - ok
18:41:45.0777 0x1660  [ 4CDC536166F3CADF6496BDAC857B0F58, D02AE2D6E6E9CF26C3333D0B99F06474D0527A0E21E156788250958760130C56 ] AmUStor         C:\Windows\system32\drivers\AmUStor.SYS
18:41:45.0824 0x1660  AmUStor - ok
18:41:45.0902 0x1660  [ 2F8616646215EEDB28C2E40994DB8E38, CD8F58FF13896500367DC3179D60A8DFA5DD17D371664B643E4FDC2C9EA697D0 ] androidusb      C:\Windows\system32\Drivers\ssadadb.sys
18:41:45.0980 0x1660  androidusb - ok
18:41:46.0058 0x1660  [ 3358CAD1887DDDDD2A36B7796B579292, 40BA1A836276C2AA78914F294661C3C918F2D6DFAA9D6EF3FEB6D1EE3B07F584 ] AntiVirMailService C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe
18:41:46.0120 0x1660  AntiVirMailService - ok
18:41:46.0198 0x1660  [ 1892E1DB0B6431720B98B52AE9388C28, 141098794D774265662FF0EBB4E938D70ADB8BD54B62B1C9A19F6C3C1F263FEC ] AntiVirSchedulerService C:\Program Files\Avira\AntiVir Desktop\sched.exe
18:41:46.0229 0x1660  AntiVirSchedulerService - ok
18:41:46.0292 0x1660  [ 1892E1DB0B6431720B98B52AE9388C28, 141098794D774265662FF0EBB4E938D70ADB8BD54B62B1C9A19F6C3C1F263FEC ] AntiVirService  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
18:41:46.0307 0x1660  AntiVirService - ok
18:41:46.0432 0x1660  [ 6FD5165364D88FDABE4FA59E1768376F, B82D11E6FCC297F822E29A49D46C9985955C9F5676D107A397B00D0468F93504 ] AntiVirWebService C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
18:41:46.0479 0x1660  AntiVirWebService - ok
18:41:46.0541 0x1660  [ 81F97D8F8B3FB94A451CC6F7CF8B2965, 8DEBA4E47E1016D69740C0BB7CDD23852D86E0D42C1C1EA5A847ECB115C38CB1 ] AppID           C:\Windows\system32\drivers\appid.sys
18:41:46.0588 0x1660  AppID - ok
18:41:46.0619 0x1660  [ F5090F8FA6757C58E17BAEAA86093636, 5E14CF3032DF5801240F45C59AA93962EA41AA5648A0C6458D16D9B9D95A131F ] AppIDSvc        C:\Windows\System32\appidsvc.dll
18:41:46.0666 0x1660  AppIDSvc - ok
18:41:46.0713 0x1660  [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo         C:\Windows\System32\appinfo.dll
18:41:46.0775 0x1660  Appinfo - ok
18:41:46.0853 0x1660  [ D2B87FC03BE28CD0B33C2B5C1119FD8E, 97EB74CB7F62C0D06D45CB250E3A90657A0F107C2FC20738FF6B2C87B0240080 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
18:41:46.0931 0x1660  Apple Mobile Device - ok
18:41:46.0978 0x1660  [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc             C:\Windows\system32\DRIVERS\arc.sys
18:41:46.0994 0x1660  arc - ok
18:41:47.0009 0x1660  [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
18:41:47.0025 0x1660  arcsas - ok
18:41:47.0072 0x1660  [ 104DB777372411C55850C4A2AE6877EF, 0CB2AD98615507275946A9D7B3AC0E29F9F1CE24921277818C8BCB86D1469522 ] AsDsm           C:\Windows\system32\drivers\AsDsm.sys
18:41:47.0103 0x1660  AsDsm - ok
18:41:47.0165 0x1660  [ 18E5C2F937F9DEB8C282DF66A3761925, 30294C381F8C7DCB45EF9BCF572F410FF47630E12D5AA02259C6C80F07BEF495 ] ASLDRService    C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
18:41:47.0165 0x1660  ASLDRService - ok
18:41:47.0243 0x1660  [ 7B4D08D2017AC06689D422E06C43F0AA, 42BACCEA0FCEB60B79F78098163147A8DD1DED24CB2F0DBB93EDC07DAB66135C ] ASMMAP          C:\Program Files\ATKGFNEX\ASMMAP.sys
18:41:47.0259 0x1660  ASMMAP - ok
18:41:47.0368 0x1660  [ 537B2948976F5D9B5767B74A63EBB395, 1A14F8B582E74AD15B612EDA5B707AA3CB0B2A107ED14572B4232EAA7383B634 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
18:41:47.0415 0x1660  aspnet_state - ok
18:41:47.0431 0x1660  [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
18:41:47.0571 0x1660  AsyncMac - ok
18:41:47.0587 0x1660  [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi           C:\Windows\system32\drivers\atapi.sys
18:41:47.0618 0x1660  atapi - ok
18:41:47.0743 0x1660  [ 31CB2740BFDBAC1E48E2B7EAD38F0D27, D409B06CA4B130BC34C5F8E99A7225E3C1A2A06960897DD1F9DD1A219C11636C ] athr            C:\Windows\system32\DRIVERS\athr.sys
18:41:47.0852 0x1660  athr - ok
18:41:48.0086 0x1660  [ 04F09923A393E4E0E8453A8F78361E73, B5C0B9D1195B87AF823887AD9355CD2B4C4F4DDF34103891EE48EA86F0F544E7 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
18:41:48.0351 0x1660  atikmdag - ok
18:41:48.0429 0x1660  [ 7C157574A181B19B9DCF5F339E25337E, 7CA78363CD420BFE4BFE9A38683CA9E31023AC573D9092666CDAEE6AF4998B60 ] ATKGFNEXSrv     C:\Program Files\ATKGFNEX\GFNEXSrv.exe
18:41:48.0460 0x1660  ATKGFNEXSrv - detected UnsignedFile.Multi.Generic ( 1 )
18:41:50.0925 0x1660  Detect skipped due to KSN trusted
18:41:50.0925 0x1660  ATKGFNEXSrv - ok
18:41:51.0003 0x1660  [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:41:51.0050 0x1660  AudioEndpointBuilder - ok
18:41:51.0081 0x1660  [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
18:41:51.0112 0x1660  Audiosrv - ok
18:41:51.0175 0x1660  [ 18FB1022DAFC9036ADA9ECF432FAFD06, AFA23C96BDAE15DF4AB32F4CCA04A9D5C5C242E704DC12237CBF57757EBC35AE ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
18:41:51.0190 0x1660  avgntflt - ok
18:41:51.0253 0x1660  [ 062494C204553210FFC0FC33EA58EB36, 2A02003334D3F736907E743C5AB04604228E89DD918E060CCA346F8E739BEB16 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
18:41:51.0268 0x1660  avipbb - ok
18:41:51.0409 0x1660  [ 8884C9DDA76D76BADFD390B33D1DE70D, 0C7EE611C6E8255A280F1C13F7BFE493679E78D05986FB47BF5EF799637F6584 ] Avira.ServiceHost C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
18:41:51.0487 0x1660  Avira.ServiceHost - ok
18:41:51.0533 0x1660  [ F80F5DCA8A5D9D93CC5BE933D20CAF05, 2AFBB2D62127FACBCABBB3E78F3568A6BA016ED4A97A1490BAA29A1EFB7A4408 ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
18:41:51.0565 0x1660  avkmgr - ok
18:41:51.0643 0x1660  [ D4920FA1E0DC90FF97D970971410EE64, D3C48E812C8E96CF5C4B0BC565485515013FBF6EBDF6D069CF90F01834019E85 ] avmaudio        C:\Windows\system32\DRIVERS\avmaudio.sys
18:41:51.0721 0x1660  avmaudio - ok
18:41:51.0783 0x1660  [ D4920FA1E0DC90FF97D970971410EE64, D3C48E812C8E96CF5C4B0BC565485515013FBF6EBDF6D069CF90F01834019E85 ] avmaura         C:\Windows\system32\DRIVERS\avmaura.sys
18:41:51.0814 0x1660  avmaura - ok
18:41:51.0892 0x1660  [ 3303FB85532093FC6723632B5947E8C4, F8301069A8EAD7303CAE5B7CAE3F119747E7B7B4402178018EB5254087238A42 ] avnetflt        C:\Windows\system32\DRIVERS\avnetflt.sys
18:41:51.0892 0x1660  avnetflt - ok
18:41:51.0939 0x1660  [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV        C:\Windows\System32\AxInstSV.dll
18:41:52.0033 0x1660  AxInstSV - ok
18:41:52.0079 0x1660  [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv         C:\Windows\system32\DRIVERS\bxvbdx.sys
18:41:52.0173 0x1660  b06bdrv - ok
18:41:52.0220 0x1660  [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x        C:\Windows\system32\DRIVERS\b57nd60x.sys
18:41:52.0251 0x1660  b57nd60x - ok
18:41:52.0313 0x1660  [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC          C:\Windows\System32\bdesvc.dll
18:41:52.0345 0x1660  BDESVC - ok
18:41:52.0360 0x1660  [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep            C:\Windows\system32\drivers\Beep.sys
18:41:52.0423 0x1660  Beep - ok
18:41:52.0485 0x1660  [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE             C:\Windows\System32\bfe.dll
18:41:52.0563 0x1660  BFE - ok
18:41:52.0610 0x1660  [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS            C:\Windows\System32\qmgr.dll
18:41:52.0750 0x1660  BITS - ok
18:41:52.0781 0x1660  [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
18:41:52.0797 0x1660  blbdrive - ok
18:41:52.0875 0x1660  [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A, 10F21999FF6B1D410EBF280F7F27DEACA5289739CF12F4293B614B8FC6C88DCC ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
18:41:52.0891 0x1660  Bonjour Service - ok
18:41:52.0937 0x1660  [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
18:41:52.0984 0x1660  bowser - ok
18:41:53.0015 0x1660  [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
18:41:53.0078 0x1660  BrFiltLo - ok
18:41:53.0093 0x1660  [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
18:41:53.0125 0x1660  BrFiltUp - ok
18:41:53.0171 0x1660  [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser         C:\Windows\System32\browser.dll
18:41:53.0218 0x1660  Browser - ok
18:41:53.0249 0x1660  [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
18:41:53.0312 0x1660  Brserid - ok
18:41:53.0343 0x1660  [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
18:41:53.0374 0x1660  BrSerWdm - ok
18:41:53.0405 0x1660  [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
18:41:53.0421 0x1660  BrUsbMdm - ok
18:41:53.0437 0x1660  [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
18:41:53.0452 0x1660  BrUsbSer - ok
18:41:53.0561 0x1660  [ D06D2E9564B8EB6EFDAF6E44E358C52B, CB9791A28BC255E5C47F19F0345BE796226D0956E33942CB21CA113A1E7867AB ] BstHdAndroidSvc C:\Program Files\BlueStacks\HD-Service.exe
18:41:53.0593 0x1660  BstHdAndroidSvc - ok
18:41:53.0686 0x1660  [ 206629B5F80CAE81D6361ECBFFE7A8C6, 29E1CF7123FC4EAE7CD4D5F06A26A341408CCAE48ABA1B37D23AD22F2586B616 ] BstHdDrv        C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys
18:41:53.0702 0x1660  BstHdDrv - ok
18:41:53.0749 0x1660  [ 0592A705BBDFD7563F3055FD02C939BB, 4712407ACAB144E64A8D130DD271A54FD4495E470A6A8A676E70EA57956B6F90 ] BstHdLogRotatorSvc C:\Program Files\BlueStacks\HD-LogRotatorService.exe
18:41:53.0780 0x1660  BstHdLogRotatorSvc - ok
18:41:53.0842 0x1660  [ 2E0CED88F254A3929AE3167456768992, A7CB4F246DEB84FAF77E5CF7A5EA4DD457CE33EFE3009FD5645CF45D78DF1C0C ] BstHdUpdaterSvc C:\Program Files\BlueStacks\HD-UpdaterService.exe
18:41:53.0889 0x1660  BstHdUpdaterSvc - ok
18:41:53.0905 0x1660  [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
18:41:53.0951 0x1660  BTHMODEM - ok
18:41:53.0998 0x1660  [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv         C:\Windows\system32\bthserv.dll
18:41:54.0045 0x1660  bthserv - ok
18:41:54.0076 0x1660  [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
18:41:54.0123 0x1660  cdfs - ok
18:41:54.0170 0x1660  [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
18:41:54.0217 0x1660  cdrom - ok
18:41:54.0279 0x1660  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc     C:\Windows\System32\certprop.dll
18:41:54.0326 0x1660  CertPropSvc - ok
18:41:54.0373 0x1660  [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
18:41:54.0419 0x1660  circlass - ok
18:41:54.0466 0x1660  [ 33A60554882FDF59CDA3E1806370BBA1, 3DE5451E1CB84AAEBD03F54BEFC670C401447B4881A8B022748B6ECF0F500F01 ] CLFS            C:\Windows\system32\CLFS.sys
18:41:54.0497 0x1660  CLFS - ok
18:41:54.0560 0x1660  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:41:54.0591 0x1660  clr_optimization_v2.0.50727_32 - ok
18:41:54.0653 0x1660  [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:41:54.0685 0x1660  clr_optimization_v4.0.30319_32 - ok
18:41:54.0700 0x1660  [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
18:41:54.0731 0x1660  CmBatt - ok
18:41:54.0763 0x1660  [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
18:41:54.0778 0x1660  cmdide - ok
18:41:54.0841 0x1660  [ 3051724F223EA48968B19567DE2A81F4, DCC27DE1B2B35866FC6DBDE95A368E7D0D346B6C3F31D0BACA63DD39B0A8874E ] CNG             C:\Windows\system32\Drivers\cng.sys
18:41:54.0872 0x1660  CNG - ok
18:41:54.0919 0x1660  [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
18:41:54.0934 0x1660  Compbatt - ok
18:41:54.0965 0x1660  [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
18:41:54.0997 0x1660  CompositeBus - ok
18:41:55.0028 0x1660  COMSysApp - ok
18:41:55.0043 0x1660  [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk         C:\Windows\system32\DRIVERS\crcdisk.sys
18:41:55.0059 0x1660  crcdisk - ok
18:41:55.0121 0x1660  [ 49474B3E37969AF4B5C076F42B623AFF, BDA6B57E9B60EF1B67C74099263D33A367AAA035667239F76AB8B268FD3E8F23 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
18:41:55.0153 0x1660  CryptSvc - ok
18:41:55.0199 0x1660  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch      C:\Windows\system32\rpcss.dll
18:41:55.0277 0x1660  DcomLaunch - ok
18:41:55.0324 0x1660  [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc       C:\Windows\System32\defragsvc.dll
18:41:55.0355 0x1660  defragsvc - ok
18:41:55.0402 0x1660  [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
18:41:55.0449 0x1660  DfsC - ok
18:41:55.0496 0x1660  dgderdrv - ok
18:41:55.0543 0x1660  [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp            C:\Windows\system32\dhcpcore.dll
18:41:55.0605 0x1660  Dhcp - ok
18:41:55.0730 0x1660  [ 7AB2DE012C88870C9274E966EC88AB61, CE2098B152B9C039C29C0573C813BFBF13B2D2E6BEE83985374160884A817133 ] DiagTrack       C:\Windows\system32\diagtrack.dll
18:41:55.0808 0x1660  DiagTrack - ok
18:41:55.0855 0x1660  [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache        C:\Windows\system32\drivers\discache.sys
18:41:55.0901 0x1660  discache - ok
18:41:55.0948 0x1660  [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk            C:\Windows\system32\DRIVERS\disk.sys
18:41:55.0964 0x1660  Disk - ok
18:41:56.0011 0x1660  [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache        C:\Windows\System32\dnsrslvr.dll
18:41:56.0057 0x1660  Dnscache - ok
18:41:56.0089 0x1660  [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc         C:\Windows\System32\dot3svc.dll
18:41:56.0151 0x1660  dot3svc - ok
18:41:56.0198 0x1660  [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS             C:\Windows\system32\dps.dll
18:41:56.0245 0x1660  DPS - ok
18:41:56.0276 0x1660  [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
18:41:56.0307 0x1660  drmkaud - ok
18:41:56.0369 0x1660  [ E6B7D1B24E16FB24CE1FEA964E144EBC, 30F81E0A017163A1AB463FE3A13B5CC2905B973E782AEBC1EB63759BF2470658 ] dtsoftbus01     C:\Windows\system32\DRIVERS\dtsoftbus01.sys
18:41:56.0385 0x1660  dtsoftbus01 - ok
18:41:56.0447 0x1660  [ 3583A5A8CC2E682BFFBD4630D0FEC08B, FD0F184B358FCECAA763444B414074BEF4E871EB7527D88385519FC158435C72 ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
18:41:56.0479 0x1660  DXGKrnl - ok
18:41:56.0525 0x1660  [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost         C:\Windows\System32\eapsvc.dll
18:41:56.0588 0x1660  EapHost - ok
18:41:56.0744 0x1660  [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv           C:\Windows\system32\DRIVERS\evbdx.sys
18:41:56.0947 0x1660  ebdrv - ok
18:41:57.0009 0x1660  [ D2967F6D4205A227AAA7D094C12F7141, 4E0D48F07F230D5D5DFC2CDCA4467C54DF6EEA6B7C6ABC355E9986C73203E104 ] EFS             C:\Windows\System32\lsass.exe
18:41:57.0056 0x1660  EFS - ok
18:41:57.0134 0x1660  [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
18:41:57.0212 0x1660  ehRecvr - ok
18:41:57.0243 0x1660  [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched         C:\Windows\ehome\ehsched.exe
18:41:57.0305 0x1660  ehSched - ok
18:41:57.0352 0x1660  [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor         C:\Windows\system32\DRIVERS\elxstor.sys
18:41:57.0383 0x1660  elxstor - ok
18:41:57.0461 0x1660  [ B538590B338F5379D4B33E266902008B, D73C4152DE0E9D225E29533FC5451D1C4DD344FE66024E6A8122B59ADD1611C8 ] EpsonScanSvc    C:\Windows\system32\EscSvc.exe
18:41:57.0493 0x1660  EpsonScanSvc - ok
18:41:57.0555 0x1660  [ BF732C1D0EBBC2A358BB63D147F7447B, 66E5535BFABA523E795F27F91CA6D355E22C6D3E2A82C454640776BE0C7E906B ] EPSON_PM_RPCV4_06 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE
18:41:57.0571 0x1660  EPSON_PM_RPCV4_06 - ok
18:41:57.0602 0x1660  [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
18:41:57.0617 0x1660  ErrDev - ok
18:41:57.0680 0x1660  [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem     C:\Windows\system32\es.dll
18:41:57.0727 0x1660  EventSystem - ok
18:41:57.0758 0x1660  [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat           C:\Windows\system32\drivers\exfat.sys
18:41:57.0820 0x1660  exfat - ok
18:41:57.0898 0x1660  Fabs - ok
18:41:57.0914 0x1660  [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
18:41:57.0961 0x1660  fastfat - ok
18:41:57.0992 0x1660  [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax             C:\Windows\system32\fxssvc.exe
18:41:58.0070 0x1660  Fax - ok
18:41:58.0085 0x1660  [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
18:41:58.0132 0x1660  fdc - ok
18:41:58.0163 0x1660  [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost         C:\Windows\system32\fdPHost.dll
18:41:58.0226 0x1660  fdPHost - ok
18:41:58.0241 0x1660  [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub        C:\Windows\system32\fdrespub.dll
18:41:58.0304 0x1660  FDResPub - ok
18:41:58.0319 0x1660  [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
18:41:58.0335 0x1660  FileInfo - ok
18:41:58.0382 0x1660  [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
18:41:58.0413 0x1660  Filetrace - ok
18:41:58.0600 0x1660  [ 5BD96D8C5411ACE71A7EAACAF0EF2903, 2AF58E6060C7DEC44B4CA30E14E164473CD4089AE475DAFFC61DFE56990C1147 ] FirebirdServerMAGIXInstance C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
18:41:58.0803 0x1660  FirebirdServerMAGIXInstance - detected UnsignedFile.Multi.Generic ( 1 )
18:42:01.0315 0x1660  Detect skipped due to KSN trusted
18:42:01.0315 0x1660  FirebirdServerMAGIXInstance - ok
18:42:01.0346 0x1660  [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
18:42:01.0393 0x1660  flpydisk - ok
18:42:01.0439 0x1660  [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
18:42:01.0455 0x1660  FltMgr - ok
18:42:01.0549 0x1660  [ 6EC244F102C7F129678E5F7309D1366D, C30DA201AC623DA440B0A0716534557C578218C2A591FA8893CCCBD96B4518F9 ] FontCache       C:\Windows\system32\FntCache.dll
18:42:01.0627 0x1660  FontCache - ok
18:42:01.0689 0x1660  [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
18:42:01.0705 0x1660  FontCache3.0.0.0 - ok
18:42:01.0736 0x1660  [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
18:42:01.0751 0x1660  FsDepends - ok
18:42:01.0783 0x1660  [ B74B0578FD1D3F897E95F2A2B69EA051, 64FCA8452CB37D55679AC8BEF221D6BA1D91E50680D37FFCFB81619ADAA5889C ] fssfltr         C:\Windows\system32\DRIVERS\fssfltr.sys
18:42:01.0814 0x1660  fssfltr - ok
18:42:01.0876 0x1660  [ 206AD9A89BF05DFA1621F1FC7B82592D, EAEE557535D865232237898858F5AE35F868065A1F79BBB48A2173124E2B6F63 ] fsssvc          C:\Program Files\Windows Live\Family Safety\fsssvc.exe
18:42:01.0923 0x1660  fsssvc - ok
18:42:01.0970 0x1660  [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
18:42:01.0985 0x1660  Fs_Rec - ok
18:42:02.0017 0x1660  [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
18:42:02.0048 0x1660  fvevol - ok
18:42:02.0110 0x1660  [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
18:42:02.0141 0x1660  gagp30kx - ok
18:42:02.0188 0x1660  [ 185ADA973B5020655CEE342059A86CBB, D3E352DFAF30761505480A4C557D980083F65EC5BD46E2656B2114D47B272A89 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
18:42:02.0204 0x1660  GEARAspiWDM - ok
18:42:02.0251 0x1660  [ 31B40F40E09513ADDC460F6A297AD474, C3A2A29E32F07BA6534380DE5A1EA7EFCB39B288B9541696DA65FA20DE20AFC4 ] ghaio           C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys
18:42:02.0266 0x1660  ghaio - ok
18:42:02.0329 0x1660  [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc           C:\Windows\System32\gpsvc.dll
18:42:02.0375 0x1660  gpsvc - ok
18:42:02.0485 0x1660  [ 51508F0C2476177E50C31B0BBFBF1BDB, 3F62A05181D54711180C8727AC66D624AFA7FC816A4ACC4DC0CFCF2D2DBE7F87 ] gupdate         C:\Program Files\Google\Update\GoogleUpdate.exe
18:42:02.0516 0x1660  gupdate - ok
18:42:02.0547 0x1660  [ 51508F0C2476177E50C31B0BBFBF1BDB, 3F62A05181D54711180C8727AC66D624AFA7FC816A4ACC4DC0CFCF2D2DBE7F87 ] gupdatem        C:\Program Files\Google\Update\GoogleUpdate.exe
18:42:02.0563 0x1660  gupdatem - ok
18:42:02.0625 0x1660  [ CC839E8D766CC31A7710C9F38CF3E375, 327D57F18B4A2D1CB06C5682D3364097ECD3CF40C2719AA1F41D0B49A26003E4 ] gusvc           C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
18:42:02.0656 0x1660  gusvc - ok
18:42:02.0687 0x1660  [ 833051C6C6C42117191935F734CFBD97, 5EB5672ABC7994A4AFF855A572158B8BE4FC6E541CFD4B9BE4FF2739A9A6AFB8 ] hamachi         C:\Windows\system32\DRIVERS\hamachi.sys
18:42:02.0703 0x1660  hamachi - ok
18:42:02.0719 0x1660  [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
18:42:02.0781 0x1660  hcw85cir - ok
18:42:02.0859 0x1660  [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:42:02.0890 0x1660  HdAudAddService - ok
18:42:02.0937 0x1660  [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus        C:\Windows\system32\drivers\HDAudBus.sys
18:42:02.0984 0x1660  HDAudBus - ok
18:42:03.0015 0x1660  [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt         C:\Windows\system32\DRIVERS\HidBatt.sys
18:42:03.0062 0x1660  HidBatt - ok
18:42:03.0077 0x1660  [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
18:42:03.0109 0x1660  HidBth - ok
18:42:03.0124 0x1660  [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr           C:\Windows\system32\DRIVERS\hidir.sys
18:42:03.0171 0x1660  HidIr - ok
18:42:03.0202 0x1660  [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv         C:\Windows\system32\hidserv.dll
18:42:03.0249 0x1660  hidserv - ok
18:42:03.0280 0x1660  [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
18:42:03.0327 0x1660  HidUsb - ok
18:42:03.0343 0x1660  [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc          C:\Windows\system32\kmsvc.dll
18:42:03.0405 0x1660  hkmsvc - ok
18:42:03.0436 0x1660  [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
18:42:03.0514 0x1660  HomeGroupListener - ok
18:42:03.0545 0x1660  [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
18:42:03.0608 0x1660  HomeGroupProvider - ok
18:42:03.0655 0x1660  [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
18:42:03.0670 0x1660  HpSAMD - ok
18:42:03.0733 0x1660  [ 487569E5DA56A5A432FF8AF6D3599CF9, 7C974D8379C60B4F69A20B01876C49181B0A63AC318C4BD0A21DABFF27A15C9D ] HTTP            C:\Windows\system32\drivers\HTTP.sys
18:42:03.0811 0x1660  HTTP - ok
18:42:03.0842 0x1660  [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
18:42:03.0857 0x1660  hwpolicy - ok
18:42:04.0013 0x1660  [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
18:42:04.0029 0x1660  i8042prt - ok
18:42:04.0232 0x1660  [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
18:42:04.0279 0x1660  iaStorV - ok
18:42:04.0466 0x1660  [ 3E9213A2A050BF429E91898C90F8B4E3, D80ABE5691087661B19F01927B631CB8C5291120B814B6F863F046E0D643E9E4 ] idsvc           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:42:04.0528 0x1660  idsvc - ok
18:42:04.0544 0x1660  IEEtwCollectorService - ok
18:42:04.0591 0x1660  [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp           C:\Windows\system32\DRIVERS\iirsp.sys
18:42:04.0606 0x1660  iirsp - ok
18:42:04.0700 0x1660  [ A06EFD4965F8A3F97A8C9A291D032678, 3B78AFB110A115F7C2136EBFE715CBC073EC341AA0457A1E41D64F9B269DE5BC ] IJPLMSVC        C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
18:42:04.0715 0x1660  IJPLMSVC - ok
18:42:04.0793 0x1660  [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT          C:\Windows\System32\ikeext.dll
18:42:04.0856 0x1660  IKEEXT - ok
18:42:04.0903 0x1660  IntcAzAudAddService - ok
18:42:04.0934 0x1660  [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide        C:\Windows\system32\drivers\intelide.sys
18:42:04.0949 0x1660  intelide - ok
18:42:04.0981 0x1660  [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
18:42:05.0012 0x1660  intelppm - ok
18:42:05.0059 0x1660  [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
18:42:05.0105 0x1660  IPBusEnum - ok
18:42:05.0121 0x1660  [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:42:05.0168 0x1660  IpFilterDriver - ok
18:42:05.0246 0x1660  [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
18:42:05.0324 0x1660  iphlpsvc - ok
18:42:05.0355 0x1660  [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
18:42:05.0402 0x1660  IPMIDRV - ok
18:42:05.0433 0x1660  [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
18:42:05.0480 0x1660  IPNAT - ok
18:42:05.0589 0x1660  [ FB7679FD086C60597F8C6929FF66FAC2, 6333339CB052D2A64CFBE5916D6D8F2A4D6CA84A31B549F70733A91F3C4D6EB8 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
18:42:05.0620 0x1660  iPod Service - ok
18:42:05.0636 0x1660  ipswuio - ok
18:42:05.0683 0x1660  [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
18:42:05.0729 0x1660  IRENUM - ok
18:42:05.0745 0x1660  [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
18:42:05.0761 0x1660  isapnp - ok
18:42:05.0823 0x1660  [ EB34CE31FABD4DC4343FD2AD16D2CAF9, D21C91227A15DA89ECF522345D0AB80B3B7FC24A230596DABDB8BD3B7554CE8C ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
18:42:05.0839 0x1660  iScsiPrt - ok
18:42:05.0870 0x1660  [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
18:42:05.0885 0x1660  kbdclass - ok
18:42:05.0932 0x1660  [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
18:42:05.0963 0x1660  kbdhid - ok
18:42:05.0995 0x1660  [ 3EB803312987FF44265C87CB960DF6AB, D6F44702F92089A0C847044A3933F7311D6A72C4647C3FECB35CDBF96A913A40 ] kbfiltr         C:\Windows\system32\DRIVERS\kbfiltr.sys
18:42:06.0010 0x1660  kbfiltr - ok
18:42:06.0010 0x1660  [ D2967F6D4205A227AAA7D094C12F7141, 4E0D48F07F230D5D5DFC2CDCA4467C54DF6EEA6B7C6ABC355E9986C73203E104 ] KeyIso          C:\Windows\system32\lsass.exe
18:42:06.0041 0x1660  KeyIso - ok
18:42:06.0073 0x1660  [ 3C9D9DFCF517103677D7B6255C727B48, F03252C1EF131AC4FEB83983B7BB3BAAACE0EEB0B1CFA06D0E04A156D527A0FD ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
18:42:06.0088 0x1660  KSecDD - ok
18:42:06.0104 0x1660  [ 0DFC56491C8B56A35AD52EAF770752FE, C887D6A06DD691DB6E6DC73D2ED0072FE5430F46F85111338196CF342C5892D0 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
18:42:06.0119 0x1660  KSecPkg - ok
18:42:06.0151 0x1660  [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm           C:\Windows\system32\msdtckrm.dll
18:42:06.0197 0x1660  KtmRm - ok
18:42:06.0229 0x1660  [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer    C:\Windows\system32\srvsvc.dll
18:42:06.0291 0x1660  LanmanServer - ok
18:42:06.0322 0x1660  [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:42:06.0369 0x1660  LanmanWorkstation - ok
18:42:06.0416 0x1660  [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
18:42:06.0463 0x1660  lltdio - ok
18:42:06.0525 0x1660  [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc         C:\Windows\System32\lltdsvc.dll
18:42:06.0556 0x1660  lltdsvc - ok
18:42:06.0572 0x1660  [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts         C:\Windows\System32\lmhsvc.dll
18:42:06.0603 0x1660  lmhosts - ok
18:42:06.0634 0x1660  [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
18:42:06.0665 0x1660  LSI_FC - ok
18:42:06.0681 0x1660  [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS         C:\Windows\system32\DRIVERS\lsi_sas.sys
18:42:06.0712 0x1660  LSI_SAS - ok
18:42:06.0728 0x1660  [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
18:42:06.0743 0x1660  LSI_SAS2 - ok
18:42:06.0775 0x1660  [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
18:42:06.0790 0x1660  LSI_SCSI - ok
18:42:06.0821 0x1660  [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv           C:\Windows\system32\drivers\luafv.sys
18:42:06.0868 0x1660  luafv - ok
18:42:06.0899 0x1660  [ 969D61D7463D78037DC6B020A435FC0C, 287727E5F6F58D26D79D1FD64E399FA540A32F6E1BF3F5B79628632B5EE5E8E1 ] lullaby         C:\Windows\system32\DRIVERS\lullaby.sys
18:42:06.0915 0x1660  lullaby - ok
18:42:06.0946 0x1660  [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
18:42:06.0993 0x1660  Mcx2Svc - ok
18:42:07.0040 0x1660  [ BA192919D3DC6C71105C9DE071E80E73, B4E9D8A4E43702E66EADE2CE0E0D175502C79467804D2F75E05BA69BE4FA512F ] MDES            C:\ASUS.SYS\DVMExportService.exe
18:42:07.0087 0x1660  MDES - detected UnsignedFile.Multi.Generic ( 1 )
18:42:09.0536 0x1660  Detect skipped due to KSN trusted
18:42:09.0536 0x1660  MDES - ok
18:42:09.0567 0x1660  [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas         C:\Windows\system32\DRIVERS\megasas.sys
18:42:09.0583 0x1660  megasas - ok
18:42:09.0629 0x1660  [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
18:42:09.0661 0x1660  MegaSR - ok
18:42:09.0692 0x1660  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS           C:\Windows\system32\mmcss.dll
18:42:09.0739 0x1660  MMCSS - ok
18:42:09.0770 0x1660  [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem           C:\Windows\system32\drivers\modem.sys
18:42:09.0817 0x1660  Modem - ok
18:42:09.0879 0x1660  [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
18:42:09.0895 0x1660  monitor - ok
18:42:09.0941 0x1660  [ FE80C18BA448DDD76B7BEAD9EB203D37, FC8C14EAD60ACD4AA5B4F61032FAE331F76C36FBC2D881D25BBBC6EB86682166 ] motmodem        C:\Windows\system32\DRIVERS\motmodem.sys
18:42:10.0004 0x1660  motmodem - ok
18:42:10.0035 0x1660  [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
18:42:10.0066 0x1660  mouclass - ok
18:42:10.0097 0x1660  [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
18:42:10.0113 0x1660  mouhid - ok
18:42:10.0144 0x1660  [ 644905A19D0F37F2233DFCE53BC4BC19, F52CB40AA0FD1EBF8CBF0F3BFB20C47142C637719840877FB93F10D085EB8C2B ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
18:42:10.0160 0x1660  mountmgr - ok
18:42:10.0253 0x1660  [ 9FC679D10A7377BB04ECC3D0E2E26B53, 24ACD4EC1618A052C29E4463138B28F62C8B78D442DB82F4925E64FC5849A096 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
18:42:10.0269 0x1660  MozillaMaintenance - ok
18:42:10.0300 0x1660  [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio            C:\Windows\system32\drivers\mpio.sys
18:42:10.0316 0x1660  mpio - ok
18:42:10.0347 0x1660  [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
18:42:10.0409 0x1660  mpsdrv - ok
18:42:10.0456 0x1660  [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc          C:\Windows\system32\mpssvc.dll
18:42:10.0519 0x1660  MpsSvc - ok
18:42:10.0550 0x1660  [ 03F899F521D2AAED1C55008F734DF252, 4E56A51476A13F5630719018037B1F63DF9ACEA1CFE782AF04E669BD696954C5 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
18:42:10.0612 0x1660  MRxDAV - ok
18:42:10.0643 0x1660  [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
18:42:10.0706 0x1660  mrxsmb - ok
18:42:10.0753 0x1660  [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:42:10.0768 0x1660  mrxsmb10 - ok
18:42:10.0799 0x1660  [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:42:10.0831 0x1660  mrxsmb20 - ok
18:42:10.0877 0x1660  [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci          C:\Windows\system32\drivers\msahci.sys
18:42:10.0893 0x1660  msahci - ok
18:42:10.0909 0x1660  [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
18:42:10.0924 0x1660  msdsm - ok
18:42:10.0955 0x1660  [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC           C:\Windows\System32\msdtc.exe
18:42:10.0987 0x1660  MSDTC - ok
18:42:11.0049 0x1660  [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs            C:\Windows\system32\drivers\Msfs.sys
18:42:11.0096 0x1660  Msfs - ok
18:42:11.0127 0x1660  [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
18:42:11.0158 0x1660  mshidkmdf - ok
18:42:11.0189 0x1660  [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
18:42:11.0205 0x1660  msisadrv - ok
18:42:11.0252 0x1660  [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
18:42:11.0299 0x1660  MSiSCSI - ok
18:42:11.0314 0x1660  msiserver - ok
18:42:11.0345 0x1660  [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
18:42:11.0392 0x1660  MSKSSRV - ok
18:42:11.0408 0x1660  [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
18:42:11.0455 0x1660  MSPCLOCK - ok
18:42:11.0486 0x1660  [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
18:42:11.0533 0x1660  MSPQM - ok
18:42:11.0564 0x1660  [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
18:42:11.0579 0x1660  MsRPC - ok
18:42:11.0611 0x1660  [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
18:42:11.0642 0x1660  mssmbios - ok
18:42:11.0673 0x1660  [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
18:42:11.0720 0x1660  MSTEE - ok
18:42:11.0751 0x1660  [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
18:42:11.0782 0x1660  MTConfig - ok
18:42:11.0829 0x1660  [ 2E71504A74BE4E3D4EA94568EFF7556E, 1D8BACC85B7390FB4C826ADBEEC269594ECD3CA43A46D1DE1F2035CFC258BC33 ] MTsensor        C:\Windows\system32\DRIVERS\ATKACPI.sys
18:42:11.0845 0x1660  MTsensor - ok
18:42:11.0876 0x1660  [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup             C:\Windows\system32\Drivers\mup.sys
18:42:11.0891 0x1660  Mup - ok
18:42:12.0001 0x1660  [ CD180A9701D5259E4A30CE25CFF56181, DC34B347D0E15CC95E502B3F5E1A2B9E970B465EA0E317220850A27B5EBB60FF ] MyPublicWiFiService C:\Program Files\MyPublicWiFi\PublicWiFiService.exe
18:42:12.0079 0x1660  MyPublicWiFiService - detected UnsignedFile.Multi.Generic ( 1 )
18:42:14.0575 0x1660  Detect skipped due to KSN trusted
18:42:14.0575 0x1660  MyPublicWiFiService - ok
18:42:14.0637 0x1660  [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent        C:\Windows\system32\qagentRT.dll
18:42:14.0684 0x1660  napagent - ok
18:42:14.0746 0x1660  [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
18:42:14.0793 0x1660  NativeWifiP - ok
18:42:14.0871 0x1660  [ 8C9C922D71F1CD4DEF73F186416B7896, 15FF43CD90C7913F83B35F2E7986561584588E8A45196EBD965C3A355836A9C7 ] NDIS            C:\Windows\system32\drivers\ndis.sys
18:42:14.0902 0x1660  NDIS - ok
18:42:14.0918 0x1660  [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
18:42:14.0980 0x1660  NdisCap - ok
18:42:15.0043 0x1660  [ 79DD76BFF3E869D1EA3290C107E6CCEA, FF0A5187FF67D6DB3162DAC2481689E5E4DBD5A4F3A93591AFD9FB11B7198720 ] ndiskhaz        C:\Windows\system32\DRIVERS\ndiskhaz.sys
18:42:15.0058 0x1660  ndiskhaz - ok
18:42:15.0089 0x1660  [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
18:42:15.0136 0x1660  NdisTapi - ok
18:42:15.0167 0x1660  [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
18:42:15.0199 0x1660  Ndisuio - ok
18:42:15.0230 0x1660  [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
18:42:15.0261 0x1660  NdisWan - ok
18:42:15.0292 0x1660  [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
18:42:15.0339 0x1660  NDProxy - ok
18:42:15.0386 0x1660  [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
18:42:15.0433 0x1660  NetBIOS - ok
18:42:15.0464 0x1660  [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
18:42:15.0511 0x1660  NetBT - ok
18:42:15.0526 0x1660  [ D2967F6D4205A227AAA7D094C12F7141, 4E0D48F07F230D5D5DFC2CDCA4467C54DF6EEA6B7C6ABC355E9986C73203E104 ] Netlogon        C:\Windows\system32\lsass.exe
18:42:15.0542 0x1660  Netlogon - ok
18:42:15.0589 0x1660  [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman          C:\Windows\System32\netman.dll
18:42:15.0651 0x1660  Netman - ok
18:42:15.0713 0x1660  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:42:15.0745 0x1660  NetMsmqActivator - ok
18:42:15.0745 0x1660  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:42:15.0776 0x1660  NetPipeActivator - ok
18:42:15.0807 0x1660  [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm        C:\Windows\System32\netprofm.dll
18:42:15.0885 0x1660  netprofm - ok
18:42:15.0901 0x1660  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:42:15.0916 0x1660  NetTcpActivator - ok
18:42:15.0932 0x1660  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:42:15.0947 0x1660  NetTcpPortSharing - ok
18:42:15.0994 0x1660  [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960         C:\Windows\system32\DRIVERS\nfrd960.sys
18:42:16.0010 0x1660  nfrd960 - ok
18:42:16.0072 0x1660  [ F115C5CD29E512F18BD7138A094B77E5, 90C2CE8B256EE9AABF674ADDE7F85E91DAF48EA368452D03C187A4AE027D4E39 ] NlaSvc          C:\Windows\System32\nlasvc.dll
18:42:16.0103 0x1660  NlaSvc - ok
18:42:16.0119 0x1660  [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
18:42:16.0150 0x1660  Npfs - ok
18:42:16.0181 0x1660  [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi             C:\Windows\system32\nsisvc.dll
18:42:16.0213 0x1660  nsi - ok
18:42:16.0244 0x1660  [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
18:42:16.0291 0x1660  nsiproxy - ok
18:42:16.0369 0x1660  [ C8DFF8D07755A66C7A4A738930F0FEAC, A2CC58312CE57988ABD976155BE91F558DCEC4C23481C6FBE64B361D511A36EA ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
18:42:16.0447 0x1660  Ntfs - ok
18:42:16.0478 0x1660  [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null            C:\Windows\system32\drivers\Null.sys
18:42:16.0525 0x1660  Null - ok
18:42:16.0571 0x1660  [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
18:42:16.0587 0x1660  nvraid - ok
18:42:16.0618 0x1660  [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
18:42:16.0634 0x1660  nvstor - ok
18:42:16.0649 0x1660  [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
18:42:16.0665 0x1660  nv_agp - ok
18:42:16.0681 0x1660  [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
18:42:16.0712 0x1660  ohci1394 - ok
18:42:16.0883 0x1660  [ FCE83ABDE761C87D17EA65960455F0E5, E59C13E26845FE0537AEBF0E4A9DC0AF3E6DF55C7A54247FC8078AC5DE666AD4 ] Origin Client Service C:\Program Files\Origin\OriginClientService.exe
18:42:16.0977 0x1660  Origin Client Service - ok
18:42:17.0071 0x1660  [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose             C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:42:17.0086 0x1660  ose - ok
18:42:17.0336 0x1660  [ 358A9CCA612C68EB2F07DDAD4CE1D8D7, F342100E2E9001F11FDF93F856B50FA43F9B85D2C6B5706EC0433E77206498DA ] osppsvc         C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
18:42:17.0570 0x1660  osppsvc - ok
18:42:17.0632 0x1660  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
18:42:17.0710 0x1660  p2pimsvc - ok
18:42:17.0741 0x1660  [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc          C:\Windows\system32\p2psvc.dll
18:42:17.0804 0x1660  p2psvc - ok
18:42:17.0835 0x1660  [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport         C:\Windows\system32\DRIVERS\parport.sys
18:42:17.0866 0x1660  Parport - ok
18:42:17.0882 0x1660  [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr         C:\Windows\system32\drivers\partmgr.sys
18:42:17.0897 0x1660  partmgr - ok
18:42:17.0913 0x1660  [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm          C:\Windows\system32\DRIVERS\parvdm.sys
18:42:17.0944 0x1660  Parvdm - ok
18:42:17.0991 0x1660  [ 52954BE460EC6C54C0ACB2B3B126FFC6, 9F9878EC5ABC74C5A8EE8E1D940F0934F081895B07D844F42F80A638FE713F7B ] PcaSvc          C:\Windows\System32\pcasvc.dll
18:42:18.0022 0x1660  PcaSvc - ok
18:42:18.0053 0x1660  [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci             C:\Windows\system32\drivers\pci.sys
18:42:18.0069 0x1660  pci - ok
18:42:18.0100 0x1660  [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide          C:\Windows\system32\drivers\pciide.sys
18:42:18.0131 0x1660  pciide - ok
18:42:18.0163 0x1660  [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
18:42:18.0178 0x1660  pcmcia - ok
18:42:18.0209 0x1660  [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw             C:\Windows\system32\drivers\pcw.sys
18:42:18.0225 0x1660  pcw - ok
18:42:18.0287 0x1660  [ AEBC369F7DC72AB3F5B9BDF34FA0D43F, 2A819154AC6C23E97C583D90B4D0C112188B7AE9D8D9B3F88811BFCED124E551 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
18:42:18.0334 0x1660  PEAUTH - ok
18:42:18.0428 0x1660  [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla             C:\Windows\system32\pla.dll
18:42:18.0553 0x1660  pla - ok
18:42:18.0615 0x1660  [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
18:42:18.0646 0x1660  PlugPlay - ok
18:42:18.0677 0x1660  [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
18:42:18.0724 0x1660  PNRPAutoReg - ok
18:42:18.0740 0x1660  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
18:42:18.0771 0x1660  PNRPsvc - ok
18:42:18.0833 0x1660  [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
18:42:18.0880 0x1660  PolicyAgent - ok
18:42:18.0911 0x1660  [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power           C:\Windows\system32\umpo.dll
18:42:18.0958 0x1660  Power - ok
18:42:18.0989 0x1660  [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
18:42:19.0036 0x1660  PptpMiniport - ok
18:42:19.0067 0x1660  [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor       C:\Windows\system32\DRIVERS\processr.sys
18:42:19.0114 0x1660  Processor - ok
18:42:19.0145 0x1660  [ FD9692A3D31E021207D3C2A9DDDC2BE3, 5295EFAD9BD4B59996935A41825392C12A4C968D161BEEA37797F90AF8E54229 ] ProfSvc         C:\Windows\system32\profsvc.dll
18:42:19.0208 0x1660  ProfSvc - ok
18:42:19.0223 0x1660  [ D2967F6D4205A227AAA7D094C12F7141, 4E0D48F07F230D5D5DFC2CDCA4467C54DF6EEA6B7C6ABC355E9986C73203E104 ] ProtectedStorage C:\Windows\system32\lsass.exe
18:42:19.0239 0x1660  ProtectedStorage - ok
18:42:19.0270 0x1660  [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
18:42:19.0317 0x1660  Psched - ok
18:42:19.0411 0x1660  [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
18:42:19.0473 0x1660  ql2300 - ok
18:42:19.0520 0x1660  [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
18:42:19.0551 0x1660  ql40xx - ok
18:42:19.0582 0x1660  [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE           C:\Windows\system32\qwave.dll
18:42:19.0645 0x1660  QWAVE - ok
18:42:19.0676 0x1660  [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
18:42:19.0691 0x1660  QWAVEdrv - ok
18:42:19.0707 0x1660  [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
18:42:19.0754 0x1660  RasAcd - ok
18:42:19.0785 0x1660  [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
18:42:19.0847 0x1660  RasAgileVpn - ok
18:42:19.0879 0x1660  [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto         C:\Windows\System32\rasauto.dll
18:42:19.0925 0x1660  RasAuto - ok
18:42:19.0941 0x1660  [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
18:42:19.0972 0x1660  Rasl2tp - ok
18:42:20.0019 0x1660  [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan          C:\Windows\System32\rasmans.dll
18:42:20.0066 0x1660  RasMan - ok
18:42:20.0081 0x1660  [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
18:42:20.0144 0x1660  RasPppoe - ok
18:42:20.0175 0x1660  [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
18:42:20.0206 0x1660  RasSstp - ok
18:42:20.0237 0x1660  [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
18:42:20.0284 0x1660  rdbss - ok
18:42:20.0315 0x1660  [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
18:42:20.0347 0x1660  rdpbus - ok
18:42:20.0378 0x1660  [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
18:42:20.0425 0x1660  RDPCDD - ok
18:42:20.0456 0x1660  [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
18:42:20.0487 0x1660  RDPENCDD - ok
18:42:20.0503 0x1660  [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
18:42:20.0518 0x1660  RDPREFMP - ok
18:42:20.0612 0x1660  [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
18:42:20.0690 0x1660  RdpVideoMiniport - ok
18:42:20.0737 0x1660  [ CD9214A6AE17D188D17C3CF8CB9CC693, 2E16FF1F7446F0600D6519010FD05A30B94D97167C16B3E7FC396A97D8139D60 ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
18:42:20.0799 0x1660  RDPWD - ok
18:42:20.0846 0x1660  [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
18:42:20.0861 0x1660  rdyboost - ok
18:42:20.0893 0x1660  [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess    C:\Windows\System32\mprdim.dll
18:42:20.0955 0x1660  RemoteAccess - ok
18:42:21.0002 0x1660  [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry  C:\Windows\system32\regsvc.dll
18:42:21.0033 0x1660  RemoteRegistry - ok
18:42:21.0049 0x1660  [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
18:42:21.0080 0x1660  RpcEptMapper - ok
18:42:21.0111 0x1660  [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator      C:\Windows\system32\locator.exe
18:42:21.0158 0x1660  RpcLocator - ok
18:42:21.0205 0x1660  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs           C:\Windows\system32\rpcss.dll
18:42:21.0251 0x1660  RpcSs - ok
18:42:21.0283 0x1660  [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
18:42:21.0329 0x1660  rspndr - ok
18:42:21.0345 0x1660  RTHDMIAzAudService - ok
18:42:21.0376 0x1660  [ D2967F6D4205A227AAA7D094C12F7141, 4E0D48F07F230D5D5DFC2CDCA4467C54DF6EEA6B7C6ABC355E9986C73203E104 ] SamSs           C:\Windows\system32\lsass.exe
18:42:21.0392 0x1660  SamSs - ok
18:42:21.0439 0x1660  [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
18:42:21.0454 0x1660  sbp2port - ok
18:42:21.0470 0x1660  [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
18:42:21.0517 0x1660  SCardSvr - ok
18:42:21.0548 0x1660  [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
18:42:21.0595 0x1660  scfilter - ok
18:42:21.0673 0x1660  [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule        C:\Windows\system32\schedsvc.dll
18:42:21.0735 0x1660  Schedule - ok
18:42:21.0782 0x1660  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc     C:\Windows\System32\certprop.dll
18:42:21.0813 0x1660  SCPolicySvc - ok
18:42:21.0860 0x1660  [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
18:42:21.0922 0x1660  SDRSVC - ok
18:42:21.0953 0x1660  [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
18:42:22.0016 0x1660  secdrv - ok
18:42:22.0047 0x1660  [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon        C:\Windows\system32\seclogon.dll
18:42:22.0094 0x1660  seclogon - ok
18:42:22.0125 0x1660  [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS            C:\Windows\System32\sens.dll
18:42:22.0203 0x1660  SENS - ok
18:42:22.0219 0x1660  [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
18:42:22.0281 0x1660  SensrSvc - ok
18:42:22.0297 0x1660  [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
18:42:22.0343 0x1660  Serenum - ok
18:42:22.0375 0x1660  [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial          C:\Windows\system32\DRIVERS\serial.sys
18:42:22.0406 0x1660  Serial - ok
18:42:22.0437 0x1660  [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
18:42:22.0453 0x1660  sermouse - ok
18:42:22.0499 0x1660  [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv      C:\Windows\system32\sessenv.dll
18:42:22.0531 0x1660  SessionEnv - ok
18:42:22.0562 0x1660  [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
18:42:22.0593 0x1660  sffdisk - ok
18:42:22.0624 0x1660  [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
18:42:22.0655 0x1660  sffp_mmc - ok
18:42:22.0687 0x1660  [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
18:42:22.0718 0x1660  sffp_sd - ok
18:42:22.0749 0x1660  [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
18:42:22.0780 0x1660  sfloppy - ok
18:42:22.0843 0x1660  [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess    C:\Windows\System32\ipnathlp.dll
18:42:22.0905 0x1660  SharedAccess - ok
18:42:22.0952 0x1660  [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:42:22.0999 0x1660  ShellHWDetection - ok
18:42:23.0030 0x1660  [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp          C:\Windows\system32\drivers\sisagp.sys
18:42:23.0045 0x1660  sisagp - ok
18:42:23.0092 0x1660  [ 6F0C643C7F49F2091B01D014EAE72E1A, 5B81BDE24DB0F796999B97753580C5D53BA16AAE62EA310DF529EE6D1B0F43C6 ] SiSGbeLH        C:\Windows\system32\DRIVERS\SiSGB6.sys
18:42:23.0108 0x1660  SiSGbeLH - ok
18:42:23.0139 0x1660  [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
18:42:23.0155 0x1660  SiSRaid2 - ok
18:42:23.0186 0x1660  [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
18:42:23.0201 0x1660  SiSRaid4 - ok
18:42:23.0295 0x1660  [ A9C057A9463C25490CF99EA8DF8A4B35, 8F4D1C40D0F17EDBF84ED455B8946F782C7552383F0A07E410A9B6CFF7F51D63 ] SkypeUpdate     C:\Program Files\Skype\Updater\Updater.exe
18:42:23.0326 0x1660  SkypeUpdate - ok
18:42:23.0357 0x1660  [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
18:42:23.0404 0x1660  Smb - ok
18:42:23.0451 0x1660  [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
18:42:23.0498 0x1660  SNMPTRAP - ok
18:42:23.0607 0x1660  [ 1A122A796DF161477D70CA9088A842EB, D2FF38BC1742E50296F0207B348EB8A0E5CED95733A8F319550EE5A656D91960 ] SNP2UVC         C:\Windows\system32\DRIVERS\snp2uvc.sys
18:42:23.0685 0x1660  SNP2UVC - ok
18:42:23.0716 0x1660  [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr           C:\Windows\system32\drivers\spldr.sys
18:42:23.0732 0x1660  spldr - ok
18:42:23.0763 0x1660  [ 739DB668DBD812285ECC553E64A5E212, 08E99CD042232CEB20BB5A808E914C9F2F0C154099BF921BA40E661B08472CF5 ] spmgr           C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
18:42:23.0779 0x1660  spmgr - ok
18:42:23.0810 0x1660  [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler         C:\Windows\System32\spoolsv.exe
18:42:23.0888 0x1660  Spooler - ok
18:42:24.0044 0x1660  [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc          C:\Windows\system32\sppsvc.exe
18:42:24.0231 0x1660  sppsvc - ok
18:42:24.0293 0x1660  [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify     C:\Windows\system32\sppuinotify.dll
18:42:24.0340 0x1660  sppuinotify - ok
18:42:24.0403 0x1660  [ FEB11DBAA5E152D98BD897C97A6DDCD0, 7ABCCDDE6B9A58CECA480AA57468E7A1F537893A2CB7C20E1A366EC8EEC7FA59 ] sptd            C:\Windows\System32\Drivers\sptd.sys
18:42:24.0418 0x1660  sptd - ok
18:42:24.0465 0x1660  [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv             C:\Windows\system32\DRIVERS\srv.sys
18:42:24.0496 0x1660  srv - ok
18:42:24.0527 0x1660  [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
18:42:24.0543 0x1660  srv2 - ok
18:42:24.0559 0x1660  [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
18:42:24.0574 0x1660  srvnet - ok
18:42:24.0668 0x1660  [ BB6EDB0257860083193CC1581AC7D485, DE2A6AA57C48D4FACF155C2FD876D5F3238A9107F8313FB3D0BF7CE34B0ED559 ] ssadbus         C:\Windows\system32\DRIVERS\ssadbus.sys
18:42:24.0683 0x1660  ssadbus - ok
18:42:24.0730 0x1660  [ 5BCB68F7B62159C07789D3F405750623, 5363AC26FDD7114BB23F09F79541A691FF6E140C4B802F5AE284BCE5F623D5E0 ] ssadmdfl        C:\Windows\system32\DRIVERS\ssadmdfl.sys
18:42:24.0746 0x1660  ssadmdfl - ok
18:42:24.0793 0x1660  [ 1588A89F9CD9E68DE9FCC9F60FDB5C08, E2E547A0AC10DAA55029500052D89A7FB124FFBE7742F16AD41B857890AED50F ] ssadmdm         C:\Windows\system32\DRIVERS\ssadmdm.sys
18:42:24.0808 0x1660  ssadmdm - ok
18:42:24.0855 0x1660  [ 9EFD9F42795C9E90206C1E9A9B25E8D3, CD5E64A95E2022A8B9BBD4710854BDD1AC1772441275F40EFD31508376B2B99B ] ssadserd        C:\Windows\system32\DRIVERS\ssadserd.sys
18:42:24.0871 0x1660  ssadserd - ok
18:42:24.0933 0x1660  [ E6CE6348A4F6E06925548F62527F0F99, AD39D46311F79EDFC4F7DA2922EB95CE0F27C3A1B1642371C4E7E48F6515CB7B ] sscdbus         C:\Windows\system32\DRIVERS\sscdbus.sys
18:42:24.0949 0x1660  sscdbus - ok
18:42:24.0980 0x1660  [ 68820F9A67F0D170A6842094EBDCD924, C1A8B53BF6804D17B30FA5CDEC0ADD0B0252D773F1AECCB687B53BB8BF7FB240 ] sscdmdfl        C:\Windows\system32\DRIVERS\sscdmdfl.sys
18:42:24.0995 0x1660  sscdmdfl - ok
18:42:25.0011 0x1660  [ 0A3B7562002C50F208FCCDEB7380B57B, D2E34E622D37B6820F185B7072F7895410F92C3C064E1419AD7FDC7E594326BB ] sscdmdm         C:\Windows\system32\DRIVERS\sscdmdm.sys
18:42:25.0027 0x1660  sscdmdm - ok
18:42:25.0089 0x1660  [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
18:42:25.0151 0x1660  SSDPSRV - ok
18:42:25.0229 0x1660  [ 424566865D82AA4BD8D6546C1F2065FA, 37B4C04C7C0EE0F3347A9E9F35B095478299F7324CA87AAE487BF989B0E6AE03 ] ssmdrv          C:\Windows\system32\DRIVERS\ssmdrv.sys
18:42:25.0261 0x1660  ssmdrv - ok
18:42:25.0292 0x1660  [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc         C:\Windows\system32\sstpsvc.dll
18:42:25.0339 0x1660  SstpSvc - ok
18:42:25.0510 0x1660  [ 9DA3B55B17B54789AFB8C657D4ACE4D7, 5E4599E682327E3B8097A88A69ED73F96254A29054744D5DFB782054863F131E ] ss_conn_service D:\Samsung Kies\USB Drivers\25_escape\conn\ss_conn_service.exe
18:42:25.0541 0x1660  ss_conn_service - ok
18:42:25.0635 0x1660  [ 7F4FB8D168A19EB7B4B55C73212025F0, 716D25F11020690EF0EE0CCD461A3AADED057EA5159B09E39A42CB671954F7AC ] stdriver        C:\Windows\system32\DRIVERS\stdriver32.sys
18:42:25.0635 0x1660  stdriver - ok
18:42:25.0744 0x1660  [ 0A3544D7E9AF7D8C991C904339157EDC, 1E1DE4D808AE1174B0CB37E93EBADFC98FEBCD70D612CFE393DDA513581CD123 ] Steam Client Service C:\Program Files\Common Files\Steam\SteamService.exe
18:42:25.0775 0x1660  Steam Client Service - ok
18:42:25.0807 0x1660  [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
18:42:25.0822 0x1660  stexstor - ok
18:42:25.0869 0x1660  [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc          C:\Windows\System32\wiaservc.dll
18:42:25.0916 0x1660  StiSvc - ok
18:42:25.0947 0x1660  [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum          C:\Windows\system32\drivers\swenum.sys
18:42:25.0963 0x1660  swenum - ok
18:42:25.0994 0x1660  [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv           C:\Windows\System32\swprv.dll
18:42:26.0041 0x1660  swprv - ok
18:42:26.0103 0x1660  [ 3F4982DE07D89A1084861E9D59F7EBB1, E1D3D91918CF226D7971DD3B5A6F75F00A0D501436B032E0149E2665D04DED48 ] SynTP           C:\Windows\system32\DRIVERS\SynTP.sys
18:42:26.0119 0x1660  SynTP - ok
18:42:26.0197 0x1660  [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain         C:\Windows\system32\sysmain.dll
18:42:26.0259 0x1660  SysMain - ok
18:42:26.0290 0x1660  [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
18:42:26.0306 0x1660  TabletInputService - ok
18:42:26.0337 0x1660  [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv         C:\Windows\System32\tapisrv.dll
18:42:26.0384 0x1660  TapiSrv - ok
18:42:26.0415 0x1660  [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS             C:\Windows\System32\tbssvc.dll
18:42:26.0477 0x1660  TBS - ok
18:42:26.0555 0x1660  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
18:42:26.0618 0x1660  Tcpip - ok
18:42:26.0680 0x1660  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
18:42:26.0743 0x1660  TCPIP6 - ok
18:42:26.0789 0x1660  [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
18:42:26.0805 0x1660  tcpipreg - ok
18:42:26.0836 0x1660  [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
18:42:26.0867 0x1660  TDPIPE - ok
18:42:26.0899 0x1660  [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
18:42:26.0930 0x1660  TDTCP - ok
18:42:26.0977 0x1660  [ 7FE680A3DFA421C4A8E4879AE4C5AAB0, A4C64E155AB2843823CD3586756BA7681CFDEA50812095468221503BBAD30DCD ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
18:42:27.0008 0x1660  tdx - ok
18:42:27.0008 0x1660  [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD          C:\Windows\system32\drivers\termdd.sys
18:42:27.0023 0x1660  TermDD - ok
18:42:27.0101 0x1660  [ FCFD4F50419B4BC72E80066DA10D2E54, 7C2314A57A404525F0444986332DBAE0964A3359374671598387051D7AAE72AE ] TermService     C:\Windows\System32\termsrv.dll
18:42:27.0164 0x1660  TermService - ok
18:42:27.0211 0x1660  [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes          C:\Windows\system32\themeservice.dll
18:42:27.0257 0x1660  Themes - ok
18:42:27.0289 0x1660  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER     C:\Windows\system32\mmcss.dll
18:42:27.0320 0x1660  THREADORDER - ok
18:42:27.0335 0x1660  [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks          C:\Windows\System32\trkwks.dll
18:42:27.0382 0x1660  TrkWks - ok
18:42:27.0429 0x1660  [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:42:27.0538 0x1660  TrustedInstaller - ok
18:42:27.0569 0x1660  [ 6C5139E4283249518F7743D7043775B3, 58684E8C90EBAC65459A97C905CDCFE3A915CFF7E8E96071DE1AC3489F85E67F ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
18:42:27.0601 0x1660  tssecsrv - ok
18:42:27.0679 0x1660  [ C6A5FBD4977305E1FA23E02C042DB463, A6EB5E4B8051A258D40A385609E930318EAA3494C8466F48542B806FE6A7C47A ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
18:42:27.0725 0x1660  TsUsbFlt - ok
18:42:27.0772 0x1660  [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
18:42:27.0819 0x1660  tunnel - ok
18:42:27.0866 0x1660  [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
18:42:27.0881 0x1660  uagp35 - ok
18:42:27.0897 0x1660  [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
18:42:27.0959 0x1660  udfs - ok
18:42:28.0006 0x1660  [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect       C:\Windows\system32\UI0Detect.exe
18:42:28.0037 0x1660  UI0Detect - ok
18:42:28.0084 0x1660  [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
18:42:28.0100 0x1660  uliagpkx - ok
18:42:28.0131 0x1660  [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
18:42:28.0162 0x1660  umbus - ok
18:42:28.0209 0x1660  [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
18:42:28.0271 0x1660  UmPass - ok
18:42:28.0303 0x1660  [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost        C:\Windows\System32\upnphost.dll
18:42:28.0349 0x1660  upnphost - ok
18:42:28.0381 0x1660  [ EC1C23779BB41A8B2AB2AA6FCE308BDE, D027A2B472CAE97AECB16F69BE52E06CB61E1C61AE196C22662050B711C1C72D ] USBAAPL         C:\Windows\system32\Drivers\usbaapl.sys
18:42:28.0412 0x1660  USBAAPL - ok
18:42:28.0459 0x1660  [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
18:42:28.0521 0x1660  usbccgp - ok
18:42:28.0552 0x1660  [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir          C:\Windows\system32\drivers\usbcir.sys
18:42:28.0599 0x1660  usbcir - ok
18:42:28.0615 0x1660  [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
18:42:28.0646 0x1660  usbehci - ok
18:42:28.0708 0x1660  [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
18:42:28.0739 0x1660  usbhub - ok
18:42:28.0755 0x1660  [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci         C:\Windows\system32\DRIVERS\usbohci.sys
18:42:28.0786 0x1660  usbohci - ok
18:42:28.0833 0x1660  [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
18:42:28.0849 0x1660  usbprint - ok
18:42:28.0895 0x1660  [ FC6B21DB4B5B398AB93DBE59CBF11036, A94094C208F376405C07822A6143001EF1B12AE93205CD8002E87F6EB45F6374 ] usbscan         C:\Windows\system32\DRIVERS\usbscan.sys
18:42:28.0927 0x1660  usbscan - ok
18:42:28.0958 0x1660  [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:42:28.0973 0x1660  USBSTOR - ok
18:42:29.0020 0x1660  [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
18:42:29.0051 0x1660  usbuhci - ok
18:42:29.0114 0x1660  [ DE014425522610BEDCA3821BB8C0F1D5, D6FEA0DF07F89834AEEE8C02CC7FD41068D758B6CCECE2EEE5CF4B9DB646FA1E ] usbvideo        C:\Windows\System32\Drivers\usbvideo.sys
18:42:29.0145 0x1660  usbvideo - ok
18:42:29.0192 0x1660  [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms           C:\Windows\System32\uxsms.dll
18:42:29.0254 0x1660  UxSms - ok
18:42:29.0270 0x1660  [ D2967F6D4205A227AAA7D094C12F7141, 4E0D48F07F230D5D5DFC2CDCA4467C54DF6EEA6B7C6ABC355E9986C73203E104 ] VaultSvc        C:\Windows\system32\lsass.exe
18:42:29.0285 0x1660  VaultSvc - ok
18:42:29.0348 0x1660  [ 793E79C7D24E5C96AF7A9EE295CCF4F2, 2939A604FA258BAA26E98F492352DE738B21A5FD88AE4E98D4E89EEFDE0A56F2 ] VBoxDrv         C:\Windows\system32\DRIVERS\VBoxDrv.sys
18:42:29.0363 0x1660  VBoxDrv - ok
18:42:29.0426 0x1660  [ 251DCB17574C6A91A57946C984F3ECFE, A8F6A456941283879AC7C4DA50736EC4077E9E4A25DF2001BF2B4B2CCF221560 ] VBoxUSBMon      C:\Windows\system32\DRIVERS\VBoxUSBMon.sys
18:42:29.0441 0x1660  VBoxUSBMon - ok
18:42:29.0473 0x1660  [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
18:42:29.0488 0x1660  vdrvroot - ok
18:42:29.0535 0x1660  [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds             C:\Windows\System32\vds.exe
18:42:29.0582 0x1660  vds - ok
18:42:29.0613 0x1660  [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
18:42:29.0644 0x1660  vga - ok
18:42:29.0675 0x1660  [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave         C:\Windows\System32\drivers\vga.sys
18:42:29.0707 0x1660  VgaSave - ok
18:42:29.0753 0x1660  [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
18:42:29.0800 0x1660  vhdmp - ok
18:42:29.0831 0x1660  [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp          C:\Windows\system32\drivers\viaagp.sys
18:42:29.0847 0x1660  viaagp - ok
18:42:29.0878 0x1660  [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7           C:\Windows\system32\DRIVERS\viac7.sys
18:42:29.0909 0x1660  ViaC7 - ok
18:42:29.0941 0x1660  [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide          C:\Windows\system32\drivers\viaide.sys
18:42:29.0956 0x1660  viaide - ok
18:42:29.0972 0x1660  [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
18:42:29.0987 0x1660  volmgr - ok
18:42:30.0019 0x1660  [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
18:42:30.0034 0x1660  volmgrx - ok
18:42:30.0081 0x1660  [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
18:42:30.0097 0x1660  volsnap - ok
18:42:30.0143 0x1660  [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid         C:\Windows\system32\DRIVERS\vsmraid.sys
18:42:30.0159 0x1660  vsmraid - ok
18:42:30.0237 0x1660  [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS             C:\Windows\system32\vssvc.exe
18:42:30.0331 0x1660  VSS - ok
18:42:30.0362 0x1660  [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
18:42:30.0393 0x1660  vwifibus - ok
18:42:30.0440 0x1660  [ 7090D3436EEB4E7DA3373090A23448F7, 3A130B28F2BFA7DCEC8596C4CE4E187B019F5ECF1AAC8DD1BBDE9CBD2428FEC2 ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
18:42:30.0487 0x1660  vwififlt - ok
18:42:30.0518 0x1660  [ A3F04CBEA6C2A10E6CB01F8B47611882, 32AFE18B07FECA30BC95831A5DC94C784E543784DF16165334A777DC84E91EF3 ] vwifimp         C:\Windows\system32\DRIVERS\vwifimp.sys
18:42:30.0533 0x1660  vwifimp - ok
18:42:30.0580 0x1660  [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time         C:\Windows\system32\w32time.dll
18:42:30.0627 0x1660  W32Time - ok
18:42:30.0658 0x1660  [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
18:42:30.0689 0x1660  WacomPen - ok
18:42:30.0721 0x1660  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
18:42:30.0767 0x1660  WANARP - ok
18:42:30.0783 0x1660  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
18:42:30.0814 0x1660  Wanarpv6 - ok
18:42:30.0892 0x1660  [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine        C:\Windows\system32\wbengine.exe
18:42:31.0001 0x1660  wbengine - ok
18:42:31.0064 0x1660  [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
18:42:31.0095 0x1660  WbioSrvc - ok
18:42:31.0126 0x1660  [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc         C:\Windows\System32\wcncsvc.dll
18:42:31.0189 0x1660  wcncsvc - ok
18:42:31.0220 0x1660  [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:42:31.0267 0x1660  WcsPlugInService - ok
18:42:31.0313 0x1660  [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd              C:\Windows\system32\DRIVERS\wd.sys
18:42:31.0329 0x1660  Wd - ok
18:42:31.0376 0x1660  [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
18:42:31.0407 0x1660  Wdf01000 - ok
18:42:31.0469 0x1660  [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiServiceHost  C:\Windows\system32\wdi.dll
18:42:31.0532 0x1660  WdiServiceHost - ok
18:42:31.0532 0x1660  [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiSystemHost   C:\Windows\system32\wdi.dll
18:42:31.0563 0x1660  WdiSystemHost - ok
18:42:31.0610 0x1660  [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient       C:\Windows\System32\webclnt.dll
18:42:31.0657 0x1660  WebClient - ok
18:42:31.0688 0x1660  [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc          C:\Windows\system32\wecsvc.dll
18:42:31.0750 0x1660  Wecsvc - ok
18:42:31.0781 0x1660  [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
18:42:31.0828 0x1660  wercplsupport - ok
18:42:31.0859 0x1660  [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc          C:\Windows\System32\WerSvc.dll
18:42:31.0906 0x1660  WerSvc - ok
18:42:31.0922 0x1660  [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
18:42:31.0953 0x1660  WfpLwf - ok
18:42:31.0984 0x1660  [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
18:42:32.0000 0x1660  WIMMount - ok
18:42:32.0078 0x1660  [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend       C:\Program Files\Windows Defender\mpsvc.dll
18:42:32.0156 0x1660  WinDefend - ok
18:42:32.0187 0x1660  WinHttpAutoProxySvc - ok
18:42:32.0234 0x1660  [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
18:42:32.0281 0x1660  Winmgmt - ok
18:42:32.0374 0x1660  [ 1DE9BD23AFA36150586C732D876D9B74, 32CF2C8EC18CFDA677AB72A182EB4B839DCC72BFCD6CA309BE2F434991CAE973 ] WinRM           C:\Windows\system32\WsmSvc.dll
18:42:32.0483 0x1660  WinRM - ok
18:42:32.0546 0x1660  [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb          C:\Windows\system32\drivers\WinUsb.sys
18:42:32.0593 0x1660  WinUsb - ok
18:42:32.0655 0x1660  [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc         C:\Windows\System32\wlansvc.dll
18:42:32.0733 0x1660  Wlansvc - ok
18:42:32.0858 0x1660  [ 5144AE67D60EC653F97DDF3FEED29E77, F6238767284B2356A9F502E2ACCFAAC283FA13CBF238E98B5115A55179526B10 ] wlidsvc         C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
18:42:32.0905 0x1660  wlidsvc - ok
18:42:32.0936 0x1660  [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
18:42:32.0967 0x1660  WmiAcpi - ok
18:42:33.0014 0x1660  [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
18:42:33.0045 0x1660  wmiApSrv - ok
18:42:33.0139 0x1660  [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc   C:\Program Files\Windows Media Player\wmpnetwk.exe
18:42:33.0201 0x1660  WMPNetworkSvc - ok
18:42:33.0232 0x1660  [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
18:42:33.0263 0x1660  WPCSvc - ok
18:42:33.0295 0x1660  [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
18:42:33.0341 0x1660  WPDBusEnum - ok
18:42:33.0373 0x1660  [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
18:42:33.0419 0x1660  ws2ifsl - ok
18:42:33.0451 0x1660  [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc          C:\Windows\System32\wscsvc.dll
18:42:33.0497 0x1660  wscsvc - ok
18:42:33.0560 0x1660  [ 553F6CCD7C58EB98D4A8FBDAF283D7A9, 71FBE50C470D1F54FDAADCECEC2CB021AE240CD59DE4E8EB5BCAA6E7F2F86560 ] WSDPrintDevice  C:\Windows\system32\DRIVERS\WSDPrint.sys
18:42:33.0591 0x1660  WSDPrintDevice - ok
18:42:33.0622 0x1660  [ 7DC0270CFD4A05B4112E3EBBF083B595, DF4FCDE511F0B68B6C6E28C820EB722C34710F31A16023A9A297EAD228E00137 ] WSDScan         C:\Windows\system32\DRIVERS\WSDScan.sys
18:42:33.0669 0x1660  WSDScan - ok
18:42:33.0669 0x1660  WSearch - ok
18:42:33.0778 0x1660  [ B5202CD63C502A16F6C94186089CF602, 0C4B3F92318D81B67820524D71618333539FEAD2877D8ABA5D7D82E66A9A6417 ] wuauserv        C:\Windows\system32\wuaueng.dll
18:42:33.0965 0x1660  wuauserv - ok
18:42:34.0012 0x1660  [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
18:42:34.0121 0x1660  WudfPf - ok
18:42:34.0168 0x1660  [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd          C:\Windows\system32\drivers\WUDFRd.sys
18:42:34.0199 0x1660  WUDFRd - ok
18:42:34.0231 0x1660  [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
18:42:34.0277 0x1660  wudfsvc - ok
18:42:34.0309 0x1660  [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc         C:\Windows\System32\wwansvc.dll
18:42:34.0387 0x1660  WwanSvc - ok
18:42:34.0465 0x1660  [ 276842A27953BE204A2507096F09B1F3, 9D614C5D3BB679CCF15CA6DD044318692EA6D89B89D80D690E79A1C0B941430F ] xusb21          C:\Windows\system32\DRIVERS\xusb21.sys
18:42:34.0480 0x1660  xusb21 - ok
18:42:34.0496 0x1660  ================ Scan global ===============================
18:42:34.0527 0x1660  [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
18:42:34.0574 0x1660  [ A83DD77AC941A8B1B2652035EA589149, 8F879178E154B3F9F367FB3D6F9A21B129F36796CD3B6A76A9E7CFDD0F63332C ] C:\Windows\system32\winsrv.dll
18:42:34.0605 0x1660  [ A83DD77AC941A8B1B2652035EA589149, 8F879178E154B3F9F367FB3D6F9A21B129F36796CD3B6A76A9E7CFDD0F63332C ] C:\Windows\system32\winsrv.dll
18:42:34.0652 0x1660  [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
18:42:34.0730 0x1660  [ 0780A42DBD7D9969F9BF4A19AA4285B5, 8EA41124A4E97732C5DAA616457FBA7111CB38986F3427FA776ED00BC1407171 ] C:\Windows\system32\services.exe
18:42:34.0745 0x1660  [ Global ] - ok
18:42:34.0745 0x1660  ================ Scan MBR ==================================
18:42:34.0792 0x1660  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
18:42:35.0260 0x1660  \Device\Harddisk0\DR0 - ok
18:42:35.0276 0x1660  ================ Scan VBR ==================================
18:42:35.0291 0x1660  [ 7A3388CB4D4AAE2DD24DDA39A2823EDC ] \Device\Harddisk0\DR0\Partition1
18:42:35.0291 0x1660  \Device\Harddisk0\DR0\Partition1 - ok
18:42:35.0307 0x1660  [ 4E4ADE1435B8BE61F1DA11B42E6C1469 ] \Device\Harddisk0\DR0\Partition2
18:42:35.0307 0x1660  \Device\Harddisk0\DR0\Partition2 - ok
18:42:35.0307 0x1660  ================ Scan generic autorun ======================
18:42:35.0447 0x1660  [ 2B39854B1C718BCF918467F6DB175A1A, 4CC16211CB04A398EF6D6205B6C9E25C9C8C5221FBA7BC545D6ED10A245BEF5C ] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
18:42:35.0510 0x1660  SynTPEnh - ok
18:42:35.0541 0x1660  [ 5AEBF6FA9805C9101220AA4FB4FA17E7, A9B2FC41380211A6C44E839A95676A5BA868CEEBB56D83A780230434C2A20836 ] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
18:42:35.0557 0x1660  HControlUser - ok
18:42:35.0837 0x1660  [ 32F43BE36AAC4E10C88EC24B34770C0D, 068DA52F6AE5676E238CB7FE4A7DF14757B8406BFB58EC157150193877F300C9 ] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
18:42:36.0040 0x1660  ATKOSD2 - ok
18:42:36.0103 0x1660  [ 5666955DC9FD455A003D86A21E0483A9, 359E2B5857269EDCE395D6171642EAC8B23170AA5266932B2BAE1E5955E8FE77 ] C:\Program Files\ASUS\ATK Media\DMedia.exe
18:42:36.0118 0x1660  ATKMEDIA - ok
18:42:36.0149 0x1660  [ 3ECCDD3FE310DD8F82D085447089ADB0, A7789451C4340DB7BDA251561CE9A9CF452625FABE8BF2CE355C87214BDC485D ] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
18:42:36.0165 0x1660  ADSMTray - ok
18:42:36.0259 0x1660  [ A6ABD4AF02AB03676DEA55F383ABC7C2, 62F838618C78A297D970EC58F97F2D843EBFEF2D81754D658664BEEED79BFB50 ] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
18:42:36.0274 0x1660  avgnt - ok
18:42:36.0399 0x1660  [ 46E3C93237EB423BE7315470955C24A6, A1C342E8B448448FC490422E1AC06C5E3C93A43580B833397A963F1E1222913A ] D:\Gaming Maus\DareUMonitor.exe
18:42:36.0446 0x1660  Dare-U mouse - detected UnsignedFile.Multi.Generic ( 1 )
18:42:38.0973 0x1660  Dare-U mouse ( UnsignedFile.Multi.Generic ) - warning
18:42:41.0547 0x1660  [ 82F68EBA0FCEA46BA8919D6A264A833E, 093140F47B047134D36A1D195BC01AA1A17B4B0215C7617A3FF846BC405651E6 ] C:\Program Files\Epson Software\Event Manager\EEventManager.exe
18:42:41.0594 0x1660  EEventManager - ok
18:42:41.0672 0x1660  [ 43B5696A844FB705D1E9595E8C3351B6, CF23A783D19F13287A23245B797DED0E993B6F44C2ADBE76685998BF22571C5E ] C:\Program Files\Avira\Launcher\Avira.Systray.exe
18:42:41.0687 0x1660  Avira Systray - ok
18:42:41.0781 0x1660  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
18:42:41.0875 0x1660  Sidebar - ok
18:42:41.0906 0x1660  [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
18:42:41.0937 0x1660  mctadmin - ok
18:42:41.0999 0x1660  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
18:42:42.0046 0x1660  Sidebar - ok
18:42:42.0062 0x1660  [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
18:42:42.0093 0x1660  mctadmin - ok
18:42:42.0124 0x1660  [ A7DC47DBBE3C0384BA719DC4188AFA7E, FCC8F68A8E55AE2AB9B877A6E46DFC28411B68D09AEACA4792625B5150EFDCFD ] C:\Windows\ehome\ehTray.exe
18:42:42.0171 0x1660  ehTray.exe - ok
18:42:42.0249 0x1660  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\sidebar.exe
18:42:42.0296 0x1660  Sidebar - ok
18:42:42.0514 0x1660  [ 683C9DF0582D8EEFAA90CE1514019BC1, 62C875888029BF32C19656B13C5504016209E4553B0B93FAE21F3930149EE9CA ] D:\DT\DAEMON Tools Lite\DTLite.exe
18:42:42.0717 0x1660  DAEMON Tools Lite - ok
18:42:42.0795 0x1660  Skype - ok
18:42:42.0873 0x1660  [ FB9F9392B3D24012D22CDA7F9FF17C18, E66EAA28153AE96CCFA3F8EC4AE8F0A798724C7CE46410A986C7869F7DEFA37B ] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE
18:42:42.0904 0x1660  EPLTarget\P0000000000000000 - ok
18:42:43.0045 0x1660  [ 7C6D524C78A1722AD987B9E47AC1FEE2, FFDC6C92ABB547D0DCD2621EC423C755A78079B061A41FA1751A56799D1A79A5 ] C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe
18:42:43.0123 0x1660  Dropbox Update - ok
18:42:43.0216 0x1660  [ 5F51CC2A6061597BB53A408E98CE2318, 48D4BDAFC289E640779A78AF8E5DB686D712A5CB23492713A2A5B29A762123B5 ] C:\Windows\system32\Macromed\Flash\FlashUtil32_17_0_0_188_Plugin.exe
18:42:43.0263 0x1660  FlashPlayerUpdate - ok
18:42:43.0341 0x1660  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\sidebar.exe
18:42:43.0388 0x1660  Sidebar - ok
18:42:43.0466 0x1660  GoogleDriveSync - ok
18:42:43.0528 0x1660  [ FB9F9392B3D24012D22CDA7F9FF17C18, E66EAA28153AE96CCFA3F8EC4AE8F0A798724C7CE46410A986C7869F7DEFA37B ] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE
18:42:43.0544 0x1660  EPLTarget\P0000000000000001 - ok
18:42:43.0606 0x1660  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\sidebar.exe
18:42:43.0669 0x1660  Sidebar - ok
18:42:43.0669 0x1660  Skype - ok
18:42:43.0887 0x1660  [ D270652063855034758D65001715BDEE, 0EBF559AE8D6B54E4AC035042783D1FA30624F222D0F1E717C724845A082F2CE ] C:\Program Files\Origin\Origin.exe
18:42:44.0059 0x1660  EADM - ok
18:42:44.0355 0x1660  [ EE526B0428581B57FFC571FF57309E28, 1CF4DD251E78F2B67C4B1973E3378D6B87C5698EEC398CA4043621842ACC426C ] C:\Program Files\CCleaner\CCleaner.exe
18:42:44.0636 0x1660  CCleaner Monitoring - ok
18:42:44.0714 0x1660  [ FB9F9392B3D24012D22CDA7F9FF17C18, E66EAA28153AE96CCFA3F8EC4AE8F0A798724C7CE46410A986C7869F7DEFA37B ] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE
18:42:44.0729 0x1660  EPLTarget\P0000000000000000 - ok
18:42:44.0776 0x1660  [ FB9F9392B3D24012D22CDA7F9FF17C18, E66EAA28153AE96CCFA3F8EC4AE8F0A798724C7CE46410A986C7869F7DEFA37B ] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE
18:42:44.0792 0x1660  EPLTarget\P0000000000000001 - ok
18:42:44.0870 0x1660  [ A90E7D7A92712062F64D770636DA148E, F9EAE06EFFF0EBC1CC3073C0B72EC6177F1E1737979FC3206E02817A0CF0F359 ] C:\Program Files\Common Files\Apple\Internet Services\iCloud.exe
18:42:44.0963 0x1660  iCloud - ok
18:42:45.0041 0x1660  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\sidebar.exe
18:42:45.0104 0x1660  Sidebar - ok
18:42:45.0166 0x1660  [ FB9F9392B3D24012D22CDA7F9FF17C18, E66EAA28153AE96CCFA3F8EC4AE8F0A798724C7CE46410A986C7869F7DEFA37B ] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE
18:42:45.0182 0x1660  EPLTarget\P0000000000000000 - ok
18:42:45.0244 0x1660  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\sidebar.exe
18:42:45.0291 0x1660  Sidebar - ok
18:42:45.0291 0x1660  Waiting for KSN requests completion. In queue: 23
18:42:46.0305 0x1660  Waiting for KSN requests completion. In queue: 23
18:42:47.0319 0x1660  Waiting for KSN requests completion. In queue: 23
18:42:48.0333 0x1660  AV detected via SS2: Avira Antivirus, C:\Program Files\Avira\AntiVir Desktop\wsctool.exe ( 15.0.11.550 ), 0x41000 ( enabled : updated )
18:42:48.0349 0x1660  Win FW state via NFP2: enabled
18:42:50.0751 0x1660  ============================================================
18:42:50.0751 0x1660  Scan finished
18:42:50.0751 0x1660  ============================================================
18:42:50.0751 0x07c0  Detected object count: 1
18:42:50.0751 0x07c0  Actual detected object count: 1
18:43:38.0581 0x07c0  Dare-U mouse ( UnsignedFile.Multi.Generic ) - skipped by user
18:43:38.0581 0x07c0  Dare-U mouse ( UnsignedFile.Multi.Generic ) - User select action: Skip 
18:43:49.0516 0x08b0  Deinitialize success
         
Er hat zwar was gefunden, das ist jedoch nur der Treiber von meiner Maus

LG flowerwithlo

Geändert von flowerwithlo (16.06.2015 um 18:00 Uhr)

Alt 17.06.2015, 15:56   #8
schrauber
/// the machine
/// TB-Ausbilder
 

DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



Die Fehlermeldung ist vom programm-eigenen Uninstaller, ncht von Revo


Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 17.06.2015, 17:39   #9
flowerwithlo
 
DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



Habe den Scan nun erstellt. Nach der Combofix Installation bin ich aus dem Zimmer gelaufen, bin erst wiedergekommen als ich mich anmelden musste. Hoffe Combofix hat keinen Mist gemacht . Bemerkt habe ich bis jetzt, dass ich Avira nicht mehr starten kann. Avira Antivirus läuft zwar, und zeigt auch den Echtzeit Scanner als "an" an, jedoch erscheint das Avira Symbol nicht mehr in der Taskleiste. Auch nachdem ich den Computer nochmals neu gestartet habe.

Combofix Log:

Code:
ATTFilter
ComboFix 15-06-09.01 - Philipp 17.06.2015  17:34:56.1.2 - x86
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.3071.1952 [GMT 2:00]
ausgeführt von:: c:\users\Philipp\Desktop\ComboFix.exe
AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\ASPG_icon.ico
c:\programdata\1&1
c:\programdata\1&1\1&1 SmartFax\Settings.xml
c:\users\Jeffel\AppData\Roaming\1&1
c:\users\Jeffel\AppData\Roaming\1&1\1&1 SmartFax\FaxNumberHistory.xml
c:\users\Jeffel\AppData\Roaming\1&1\1&1 SmartFax\Settings.xml
c:\users\Philipp\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\users\Philipp\AppData\Roaming\FTBLauncherLog.txt
c:\windows\IsUn0407.exe
c:\windows\msvcr71.dll
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\regobj.dll
c:\windows\unin0407.exe
c:\windows\wininit.ini
C:\WindowsLive_A.TXT
D:\install.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2015-05-17 bis 2015-06-17  ))))))))))))))))))))))))))))))
.
.
2015-06-17 16:07 . 2015-06-17 16:07	--------	d-----w-	c:\users\Manuel\AppData\Local\temp
2015-06-17 16:07 . 2015-06-17 16:07	--------	d-----w-	c:\users\Jeffel\AppData\Local\temp
2015-06-17 16:06 . 2015-06-17 16:06	--------	d-----w-	c:\users\Ellen & Manuel\AppData\Local\temp
2015-06-17 16:06 . 2015-06-17 16:06	--------	d-----w-	c:\users\Default\AppData\Local\temp
2015-06-17 16:06 . 2015-06-17 16:06	--------	d-----w-	c:\users\Beamer\AppData\Local\temp
2015-06-17 16:06 . 2015-06-17 16:17	--------	d-----w-	c:\users\Philipp\AppData\Local\temp
2015-06-17 15:39 . 2015-06-17 15:39	62576	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B69205F-8817-4463-ADEC-86BE97B0A312}\offreg.5440.dll
2015-06-17 11:43 . 2015-06-17 11:43	--------	d-----w-	c:\users\Philipp\AppData\Local\Dropbox
2015-06-16 15:06 . 2015-06-16 15:06	--------	d-----w-	c:\programdata\Malwarebytes
2015-06-16 15:05 . 2015-06-16 16:36	--------	d-----w-	c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-06-16 15:05 . 2015-06-16 15:05	119512	----a-w-	c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-06-16 15:04 . 2015-06-16 15:04	92888	----a-w-	c:\windows\system32\drivers\mbamchameleon.sys
2015-06-16 11:25 . 2015-05-03 03:42	9265072	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B69205F-8817-4463-ADEC-86BE97B0A312}\mpengine.dll
2015-06-15 16:32 . 2015-06-15 16:48	--------	d-----w-	C:\FRST
2015-06-13 12:18 . 2015-06-13 12:18	--------	d-----w-	c:\users\Jeffel\AppData\Local\Dropbox
2015-06-13 12:18 . 2015-06-13 12:18	--------	d-----w-	c:\programdata\Dropbox
2015-06-10 08:08 . 2015-05-25 18:01	853504	----a-w-	c:\windows\system32\diagtrack.dll
2015-06-09 15:20 . 2015-06-09 15:21	--------	d-----w-	c:\program files\BlueStacks
2015-06-09 15:20 . 2015-06-09 15:20	--------	d-----w-	c:\programdata\BlueStacks
2015-06-09 13:44 . 2015-05-09 03:14	92672	----a-w-	c:\windows\system32\wudriver.dll
2015-06-09 13:44 . 2015-05-09 03:14	35840	----a-w-	c:\windows\system32\wups2.dll
2015-06-09 13:44 . 2015-05-09 03:14	30208	----a-w-	c:\windows\system32\wups.dll
2015-06-09 13:44 . 2015-05-09 03:14	2937344	----a-w-	c:\windows\system32\wucltux.dll
2015-06-09 13:44 . 2015-05-09 03:14	2045952	----a-w-	c:\windows\system32\wuaueng.dll
2015-06-09 13:44 . 2015-05-09 03:14	173056	----a-w-	c:\windows\system32\wuwebv.dll
2015-06-09 13:44 . 2015-05-09 03:14	566784	----a-w-	c:\windows\system32\wuapi.dll
2015-06-09 13:44 . 2015-05-09 03:13	69632	----a-w-	c:\windows\system32\WinSetupUI.dll
2015-06-09 13:44 . 2015-05-09 03:13	11776	----a-w-	c:\windows\system32\wu.upgrade.ps.dll
2015-06-09 13:44 . 2015-05-09 03:13	33792	----a-w-	c:\windows\system32\wuapp.exe
2015-06-09 13:44 . 2015-05-09 03:13	131584	----a-w-	c:\windows\system32\wuauclt.exe
2015-06-06 16:11 . 2015-06-06 16:11	--------	d-----w-	c:\users\Beamer\AppData\Local\GWX
2015-06-03 16:24 . 2015-06-03 16:24	--------	d-----w-	c:\users\Manuel\AppData\Local\GWX
2015-06-01 18:38 . 2015-06-01 18:38	--------	d-----w-	c:\users\Jeffel\AppData\Local\GWX
2015-06-01 17:02 . 2015-06-01 17:02	--------	d-----w-	c:\users\Ellen & Manuel\AppData\Local\GWX
2015-06-01 16:03 . 2015-06-01 16:03	--------	d-----w-	c:\users\Philipp\AppData\Local\GWX
2015-05-31 13:23 . 2015-05-31 13:43	--------	d-----w-	c:\users\Philipp\AppData\Roaming\Dual Monitor
2015-05-22 17:16 . 2015-05-22 17:16	18652352	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
2015-05-20 15:18 . 2015-04-11 03:07	54656	----a-w-	c:\windows\system32\drivers\stream.sys
2015-05-20 15:18 . 2015-03-14 03:04	67584	----a-w-	c:\windows\system32\dwmapi.dll
2015-05-20 15:18 . 2015-03-14 03:04	1372160	----a-w-	c:\windows\system32\dwmcore.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-06-11 10:09 . 2012-11-02 18:40	136728	----a-w-	c:\windows\system32\drivers\avipbb.sys
2015-06-11 10:09 . 2012-11-02 18:40	108448	----a-w-	c:\windows\system32\drivers\avgntflt.sys
2015-06-10 15:19 . 2012-04-04 20:24	778416	----a-w-	c:\windows\system32\FlashPlayerApp.exe
2015-06-10 15:19 . 2011-06-10 17:15	142512	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl
2015-05-30 20:11 . 2009-11-24 18:19	45056	----a-w-	c:\windows\system32\acovcnt.exe
2015-05-20 18:24 . 2012-11-02 18:40	37896	----a-w-	c:\windows\system32\drivers\avkmgr.sys
2015-05-01 13:16 . 2015-05-14 12:20	102608	----a-w-	c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-04-20 02:56 . 2015-05-13 20:35	909312	----a-w-	c:\windows\system32\FntCache.dll
2015-04-20 02:56 . 2015-05-13 20:35	1250816	----a-w-	c:\windows\system32\DWrite.dll
2015-04-18 02:56 . 2015-05-13 20:34	342016	----a-w-	c:\windows\system32\certcli.dll
2015-04-14 01:38 . 2015-04-14 01:38	1217192	----a-w-	c:\windows\system32\FM20.DLL
2015-04-13 03:19 . 2015-05-13 20:34	259072	----a-w-	c:\windows\system32\services.exe
2015-04-08 03:14 . 2015-05-13 20:33	22528	----a-w-	c:\windows\system32\Spool\prtprocs\w32x86\jnwppr.dll
2015-04-08 03:14 . 2015-05-13 20:33	216064	----a-w-	c:\windows\system32\InkEd.dll
2015-04-08 03:14 . 2015-05-13 20:33	19968	----a-w-	c:\windows\system32\jnwmon.dll
2015-04-02 10:25 . 2015-04-02 10:25	0	----a-w-	c:\windows\system32\RENA5C2.tmp
2015-04-02 10:25 . 2015-04-02 10:25	0	----a-w-	c:\windows\system32\RENA5C1.tmp
2009-04-08 09:31 . 2009-04-08 09:31	106496	----a-w-	c:\program files\Common Files\CPInstallAction.dll
2008-08-11 20:45 . 2008-08-11 20:45	155648	----a-w-	c:\program files\Common Files\MSIactionall.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 16:08	143360	----a-w-	c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2015-05-19 13:22	576840	----a-w-	c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-05-19 13:22	576840	----a-w-	c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2015-05-19 13:22	576840	----a-w-	c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2015-05-19 13:22	576840	----a-w-	c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2015-05-19 13:22	576840	----a-w-	c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2015-05-19 21969480]
"EPLTarget\P0000000000000001"="c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE" [2013-01-24 260160]
"Dropbox Update"="c:\users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe" [2015-06-17 134512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-08-17 1549608]
"HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"ATKOSD2"="c:\program files\ASUS\ATKOSD2\ATKOSD2.exe" [2009-08-17 6859392]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2009-08-19 170624]
"ADSMTray"="c:\program files\ASUS\ASUS Data Security Manager\ADSMTray.exe" [2009-06-24 272952]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2015-06-11 730416]
"Dare-U mouse"="d:\gaming maus\DareUMonitor.exe" [2012-11-19 786432]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2014-05-02 1065024]
"Avira Systray"="c:\program files\Avira\Launcher\Avira.Systray.exe" [2015-05-21 130864]
.
c:\users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2015-5-5 43871584]
OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2013-6-25 228552]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages	REG_MULTI_SZ   	scecli c:\program files\ASUS\ASUS Data Security Manager\ASPWDFLT
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
backup=c:\windows\pss\FancyStart daemon.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2014-12-19 07:48	1022152	----a-w-	c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2009-09-30 16:28	203928	----a-w-	d:\alcohol 120\AxCmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmIcoSinglun]
2009-07-31 09:10	233472	----a-w-	c:\program files\AmIcoSingLun\AmIcoSinglun.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2015-03-20 16:12	60712	----a-w-	c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
2009-08-19 03:15	47672	----a-w-	c:\windows\AsScrProlog.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
2009-08-19 03:15	33136	----a-w-	c:\windows\ASScrPro.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSTPE]
2007-10-12 04:44	106496	----a-w-	c:\windows\System32\ASUSTPE.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVMUSBFernanschluss]
2014-09-29 14:48	139264	----a-w-	c:\users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\AVMAutoStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent]
2015-05-28 08:59	884440	----a-w-	c:\program files\BlueStacks\HD-Agent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-07-27 02:10	1983816	----a-w-	c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2009-03-18 01:40	767312	----a-w-	c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
2015-05-08 19:49	6369048	----a-w-	c:\program files\CCleaner\CCleaner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
2008-07-19 02:52	104936	----a-w-	c:\program files\CyberLink\Power2Go\CLMLSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2013-10-28 08:29	3675352	----a-w-	d:\dt\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2015-04-06 22:29	157480	----a-w-	c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2015-02-24 16:31	311616	----a-w-	d:\samsung kies\Kies\KiesTrayAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2014-10-02 13:23	421888	----a-w-	c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2015-01-23 13:40	31087200	----a-r-	c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2015-06-04 18:56	2892992	----a-w-	d:\steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-07-02 07:16	254336	----a-w-	c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
2009-05-20 05:16	222504	----a-w-	c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]
2008-12-04 05:15	218408	----a-w-	c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
2009-09-30 16:57	718688	----a-w-	c:\program files\Microsoft Xbox 360 Accessories\XBoxStat.exe
.
R2 AntiVirMailService;Avira Email-Schutz;c:\program files\Avira\AntiVir Desktop\avmailc7.exe [2015-06-11 827184]
R2 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\avwebg7.exe [2015-06-11 1188360]
R2 Avira.ServiceHost;Avira Service Host;c:\program files\Avira\Launcher\Avira.ServiceHost.exe [2015-05-21 208632]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2009-07-24 25600]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2014-10-13 32064]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2014-10-13 136904]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2014-10-13 17864]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2014-10-13 153672]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2014-10-13 130248]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-07-14 20480]
R4 BstHdAndroidSvc;BlueStacks Android Service;c:\program files\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R4 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files\BlueStacks\HD-LogRotatorService.exe [2015-05-28 413400]
R4 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files\BlueStacks\HD-UpdaterService.exe [2015-05-28 806616]
R4 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc.exe [2012-05-16 126128]
R4 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2011-04-26 2702848]
R4 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-05-23 102912]
R4 MDES;DVM Meta Data Export Service;c:\asus.sys\DVMExportService.exe [2008-10-21 307200]
R4 MyPublicWiFiService;MyPublicWiFi Service;c:\program files\MyPublicWiFi\PublicWiFiService.exe [2013-04-03 756224]
R4 Origin Client Service;Origin Client Service;c:\program files\Origin\OriginClientService.exe [2015-06-08 1997168]
R4 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2015-01-02 315488]
R4 ss_conn_service;SAMSUNG Mobile Connectivity Service;d:\samsung kies\USB Drivers\25_escape\conn\ss_conn_service.exe [2014-10-13 743688]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [2009-06-18 15416]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2015-05-20 37896]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-11-21 243128]
S1 ndiskhaz;Azzouzi HotSpot LightWeight Filter;c:\windows\system32\DRIVERS\ndiskhaz.sys [2012-12-07 25416]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2013-11-01 203024]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2013-11-01 103696]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2015-06-11 450808]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys [2015-03-11 37896]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files\BlueStacks\HD-Hypervisor-x86.sys [2015-05-28 131288]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 EPSON_PM_RPCV4_06;EPSON V3 Service4(06);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE [2013-04-26 143424]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [2012-01-23 1858048]
S3 avmaudio;AVM Audio;c:\windows\system32\DRIVERS\avmaudio.sys [2014-09-29 105728]
S3 avmaura;AVM USB-Fernanschluss;c:\windows\system32\DRIVERS\avmaura.sys [2014-09-29 105728]
S3 SiSGbeLH;NDIS 6.0-Treiber für SiS191/SiS190-Ethernet-Gerät;c:\windows\system32\DRIVERS\SiSGB6.sys [2009-07-13 48128]
S3 stdriver;Sound Tap Upper Class Filter Driver v2.0.0.0;c:\windows\system32\DRIVERS\stdriver32.sys [2012-06-21 52312]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
utcsvc	REG_MULTI_SZ   	DiagTrack
.
Inhalt des "geplante Tasks" Ordners
.
2015-06-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 15:19]
.
2015-06-17 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job
- c:\users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13 12:18]
.
2015-06-17 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job
- c:\users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13 12:18]
.
2015-06-17 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004Core.job
- c:\users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17 11:43]
.
2015-06-17 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004UA.job
- c:\users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17 11:43]
.
2015-06-17 c:\windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job
- c:\windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE [2014-11-29 00:20]
.
2015-06-17 c:\windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job
- c:\windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE [2014-11-29 00:20]
.
2015-06-17 c:\windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job
- c:\windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE [2014-12-10 00:20]
.
2015-06-17 c:\windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job
- c:\windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE [2014-12-10 00:20]
.
2015-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 11:30]
.
2015-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 11:30]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://de.yahoo.com/
mStart Page = about:blank
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: An OneNote s&enden - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.177.1
FF - ProfilePath - c:\users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\
FF - prefs.js: browser.search.selectedEngine - Google.de
FF - prefs.js: browser.startup.homepage - hxxp://de.yahoo.com/|https://www.google.de/
FF - prefs.js: network.proxy.type - 0
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll
AddRemove-LEGOLANDDeInstKey - c:\windows\unin0407.exe
AddRemove-01_Simmental - d:\samsung kies\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - d:\samsung kies\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - d:\samsung kies\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - d:\samsung kies\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - d:\samsung kies\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - d:\samsung kies\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - d:\samsung kies\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - d:\samsung kies\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-20_NXP_Driver - d:\samsung kies\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-24_flashusbdriver - d:\samsung kies\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - d:\samsung kies\USB Drivers\25_escape\Uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-644356114-2566177158-2502637254-1004\Software\SecuROM\License information*]
"datasecu"=hex:03,39,7c,03,77,2a,6a,cb,7e,17,02,c7,3a,42,fe,ce,dc,40,15,de,35,
   ab,79,43,ba,02,aa,15,80,ba,2a,33,01,95,3f,3a,8b,27,3b,9b,dd,f0,a6,c3,79,8a,\
"rkeysecu"=hex:a8,7c,1b,9c,ec,b6,9d,c9,8e,91,03,ed,5f,af,3a,d3
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'lsass.exe'(544)
c:\program files\ASUS\ASUS Data Security Manager\ASPWDFLT.DLL
.
- - - - - - - > 'Explorer.exe'(3284)
c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll
c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files\ASUS\ATK Hotkey\ASLDRSrv.exe
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\taskhost.exe
c:\program files\ASUS\Net4Switch\Net4Switch.exe
c:\program files\ASUS\ASUS CopyProtect\aspg.exe
c:\program files\ASUS\SmartLogon\sensorsrv.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\program files\Google\Update\1.3.27.5\GoogleCrashHandler.exe
c:\windows\system32\conhost.exe
c:\windows\System32\ACEngSvr.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\Wireless Console 2\wcourier.exe
c:\program files\ASUS\ATK Hotkey\HControl.exe
c:\program files\ASUS\ATK Hotkey\ATKOSD.exe
c:\program files\ASUS\ATK Hotkey\KBFiltr.exe
c:\program files\ASUS\ATK Hotkey\WDC.exe
c:\windows\system32\GWX\GWX.exe
c:\windows\system32\DllHost.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-06-17  18:24:21 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2015-06-17 16:24
.
Vor Suchlauf: 10 Verzeichnis(se), 35.480.268.800 Bytes frei
Nach Suchlauf: 23 Verzeichnis(se), 37.120.774.144 Bytes frei
.
- - End Of File - - FE4746EC14087E6A1E13A359DC829F17
A36C5E4F47E84449FF07ED3517B43A31
         
LG flowerwithlo

Alt 18.06.2015, 06:50   #10
schrauber
/// the machine
/// TB-Ausbilder
 

DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 19.06.2015, 19:08   #11
flowerwithlo
 
DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



Hallo Schrauber,

MBAM:

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 19.06.2015
Suchlauf-Zeit: 19:14:40
Logdatei: Log Malwarebytes.txt
Administrator: Ja

Version: 0.00.0.0000
Malware Datenbank: v2015.06.19.04
Rootkit Datenbank: v2015.06.15.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Philipp

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 546619
Verstrichene Zeit: 58 Min, 19 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente gefunden)

Module: 0
(Keine schädliche Elemente gefunden)

Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)

Registrierungswerte: 0
(Keine schädliche Elemente gefunden)

Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)

Ordner: 0
(Keine schädliche Elemente gefunden)

Dateien: 0
(Keine schädliche Elemente gefunden)

Physische Sektoren: 0
(Keine schädliche Elemente gefunden)


(end)
         

AdwCleaner:
Code:
ATTFilter
# AdwCleaner v4.206 - Bericht erstellt 19/06/2015 um 19:45:18
# Aktualisiert 01/06/2015 von Xplode
# Datenbank : 2015-06-17.1 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x86)
# Benutzername : Philipp - SCHEFFLER-PC
# Gestarted von : C:\Users\Philipp\Desktop\AdwCleaner_4.206.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\PC Drivers HeadQuarters
Ordner Gelöscht : C:\Users\Beamer\AppData\LocalLow\AskToolbar
Ordner Gelöscht : C:\Users\Jeffel\AppData\Local\PC_Drivers_Headquarters
Ordner Gelöscht : C:\Users\Jeffel\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Jeffel\AppData\Roaming\download Manager
Ordner Gelöscht : C:\Users\Philipp\AppData\Local\AskToolbar
Ordner Gelöscht : C:\Users\Philipp\AppData\Roaming\KingSoft
Datei Gelöscht : C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\foxydeal.sqlite
Datei Gelöscht : C:\Users\Jeffel\AppData\Roaming\Mozilla\Firefox\Profiles\bv31z8w8.default\user.js
Datei Gelöscht : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js

***** [ Geplante Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SDP
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\VIS
Schlüssel Gelöscht : HKLM\SOFTWARE\Babylon
Schlüssel Gelöscht : HKLM\SOFTWARE\DeviceVM
Schlüssel Gelöscht : HKLM\SOFTWARE\PIP
Schlüssel Gelöscht : HKU\.DEFAULT\Software\IBUpdaterService
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494

***** [ Internetbrowser ] *****

-\\ Internet Explorer v11.0.9600.17840


-\\ Mozilla Firefox v38.0.5 (x86 de)

[5tcpn7ab.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.hiddenOneOffs", "Ask.com,DuckDuckGo,LEO Eng-Deu");
[5tcpn7ab.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.order.1", "Ask.com");
[5tcpn7ab.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "Ask.com");
[5tcpn7ab.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("avg.install.userHPSettings", "hxxp://www.delta-search.com/?affID=119649&babsrc=HP_ss&mntrId=9a1a16840000000000002225d303ecbc");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("avg.install.userSPSettings", "Delta Search");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("avira.safe_search.installed", "[\"safesearch\"]");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("avira.safe_search.prev_newtab", "hxxps://safesearch.avira.com/#?source=newtab");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "hxxps://safesearch.avira.com/#?source=newtab");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaultenginename", "Avira SafeSearch");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-page-button\",\"print-but[...]
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://www.delta-search.com/?affID=119649&babsrc=NT_ss&mntrId=9a1a16840000000000002225d303ecbc");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.safesearch.MP_DISTINCT_ID", "\"14a54c9896557-08217389fecf2e-7f6a1335-0-14a54c98966ee\"");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.safesearch.SAUTH_expires_at", "1431286334");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.safesearch.SAUTH_rndsnr", "\"4473ad5aadf09f2d835eb8fa336508ef604a11b2\"");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.safesearch.SAUTH_userid", "5718734357");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.safesearch.SAUTH_utoken", "\"31d35a556c93ee7b0d2a3a8f93b8f88b0068fb23\"");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.safesearch.install", "1418761701745");
[bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.xpiState", "{\"app-profile\":{\"abs@avira.com\":{\"d\":\"C:\\\\Users\\\\Jeffel\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\bv31z8w8.default\\\\extensions\\\\abs@av[...]
[ynkmsd5b.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.order.1", "Ask.com");
[ynkmsd5b.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.adblockplus.recentReports", "[{\"site\":\"translation.babylon.com\",\"reportURL\":\"hxxps://reports.adblockplus.org/8eb3e8d3-8212-46f6-8486-9f24126b03b2\",\"time\":1369154259425}[...]
[ynkmsd5b.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=kwd&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q=")[...]

-\\ Chromium v


*************************

AdwCleaner[R0].txt - [5948 Bytes] - [19/06/2015 19:37:37]
AdwCleaner[S0].txt - [6066 Bytes] - [19/06/2015 19:45:18]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6125  Bytes] ##########
         
JRT:
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 7.0.2 (06.18.2015:1)
OS: Windows 7 Home Premium x86
Ran by Philipp on 19.06.2015 at 19:56:37,24
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Classes\TypeLib\{006ad7b2-968a-11de-88c9-5bde55d89593}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}



~~~ Files



~~~ Folders



~~~ FireFox






~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19.06.2015 at 20:00:22,07
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
FRST:

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-06-2015
Ran by Philipp (administrator) on SCHEFFLER-PC on 19-06-2015 20:01:38
Running from C:\Users\Philipp\Desktop
Loaded Profiles: Jeffel & Philipp & Beamer & Ellen & Manuel & Manuel (Available Profiles: Jeffel & Philipp & Beamer & Ellen & Manuel & Manuel)
Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1549608 2009-08-17] (Synaptics Incorporated)
HKLM\...\Run: [HControlUser] => C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM\...\Run: [ATKOSD2] => C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS)
HKLM\...\Run: [ATKMEDIA] => C:\Program Files\ASUS\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS)
HKLM\...\Run: [ADSMTray] => C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [272952 2009-06-24] (ASUSTek Computer Inc.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [730416 2015-06-11] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Dare-U mouse] => D:\Gaming Maus\DareUMonitor.exe [786432 2012-11-20] ()
HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1065024 2014-05-02] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.Systray.exe [130864 2015-05-21] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [144384 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [DAEMON Tools Lite] => D:\DT\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [Dropbox Update] => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-13] (Dropbox, Inc.)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil32_17_0_0_188_Plugin.exe [927920 2015-05-20] (Adobe Systems Incorporated)
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\MountPoints2: {7ed2759d-f168-11de-961b-806e6f6e6963} - E:\NightRacer.EXE
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [21969480 2015-05-19] (Google)
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [Dropbox Update] => C:\Users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-17] (Dropbox, Inc.)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [EADM] => C:\Program Files\Origin\Origin.exe [3632472 2015-06-08] (Electronic Arts)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\RunOnce: [iCloud] => C:\Program Files\Common Files\Apple\Internet Services\iCloud.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe
HKU\S-1-5-21-644356114-2566177158-2502637254-1008\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-644356114-2566177158-2502637254-1008\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe
HKU\S-1-5-21-644356114-2566177158-2502637254-1008\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-21-644356114-2566177158-2502637254-1011\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe
HKU\S-1-5-21-644356114-2566177158-2502637254-1011\...\MountPoints2: {7ed2759d-f168-11de-961b-806e6f6e6963} - E:\NightRacer.EXE
Lsa: [Notification Packages] scecli C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT
Startup: C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-05-12]
ShortcutTarget: Dropbox.lnk -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2011-03-30]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-12-13]
ShortcutTarget: Dropbox.lnk -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2011-03-31]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ADSMOverlayIcon] -> {A825576B-0042-4F0F-8FB0-93CE0F054E69} => C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll [2007-06-15] ()
ShellIconOverlayIdentifiers: [ADSMOverlayIcon1] -> {A8D448F4-0431-45AC-9F5E-E1B434AB2249} => C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll [2007-06-01] ()
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google)
GroupPolicyUsers\S-1-5-21-644356114-2566177158-2502637254-1011\User: Group Policy Restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-644356114-2566177158-2502637254-1004\User: Group Policy Restriction detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-644356114-2566177158-2502637254-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.de/
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com/
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com
HKU\S-1-5-21-644356114-2566177158-2502637254-1008\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
URLSearchHook: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} -  No File
URLSearchHook: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} -  No File
SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=IEFM1&q={searchTerms}&src={referrer:source?}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=IEFM1&q={searchTerms}&src={referrer:source?}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_de
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1008 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = 
SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1011 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = 
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} ->  No File
BHO: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH)
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.177.1

FireFox:
========
FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default
FF DefaultSearchEngine: Google.de
FF SelectedSearchEngine: Google.de
FF Homepage: hxxp://de.yahoo.com/|https://www.google.de/
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-20] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2009-09-07] (CANON INC.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-644356114-2566177158-2502637254-1004: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Philipp\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-10-03] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-644356114-2566177158-2502637254-1008: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Ellen & Manuel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-11-25] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-02-16] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-02-16] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-02-16] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-02-16] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-02-16] (Apple Inc.)
FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\ebay-durchsuchen.xml [2012-10-14]
FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\firefox-add-ons.xml [2011-07-08]
FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\googlede.xml [2012-05-18]
FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\suche-in-wikipedia.xml [2011-07-08]
FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\youtube-videosuche.xml [2012-07-07]
FF Extension: Avira Browser Safety - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\abs@avira.com [2015-05-30]
FF Extension: LavaFox V2-Purple - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\zigboom555@aol.com [2015-05-05]
FF Extension: Blue Fox - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{241aae70-0022-11de-87af-0800200c9a66} [2014-07-31]
FF Extension: Bloody Red - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{2458abc0-f443-11dd-87af-0800200c9a66} [2013-08-19]
FF Extension: FT DeepDark - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2015-04-22]
FF Extension: Add to Amazon Wish List Button - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\amznUWL2@amazon.com.xpi [2013-09-15]
FF Extension: YouTube to MP3 - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\youtube2mp3@mondayx.de.xpi [2012-01-19]
FF Extension: ProxTube - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}.xpi [2014-07-31]
FF Extension: AniWeather - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi [2011-07-08]
FF Extension: Nuri - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{beab8ae9-eb2d-4ded-3b29-d35f6b82bfa5}.xpi [2012-12-23]
FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-07-31]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-06-02]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-12-13]

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.) [File not signed]
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [827184 2015-06-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [450808 2015-06-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [450808 2015-06-11] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1188360 2015-06-11] (Avira Operations GmbH & Co. KG)
S2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS)
S4 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed]
S2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [208632 2015-05-21] (Avira Operations GmbH & Co. KG)
S4 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [433880 2015-05-28] (BlueStack Systems, Inc.)
S4 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [413400 2015-05-28] (BlueStack Systems, Inc.)
S4 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [806616 2015-05-28] (BlueStack Systems, Inc.)
S4 EpsonScanSvc; C:\Windows\system32\EscSvc.exe [126128 2012-05-17] (Seiko Epson Corporation)
R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE [143424 2013-04-26] (SEIKO EPSON CORPORATION)
S2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S4 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
S4 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
S2 MBAMScheduler; D:\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; D:\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S4 MDES; C:\ASUS.SYS\DVMExportService.exe [307200 2008-10-21] (DeviceVM) [File not signed]
S4 MyPublicWiFiService; C:\Program Files\MyPublicWiFi\PublicWiFiService.exe [756224 2013-04-03] () [File not signed]
S4 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1997168 2015-06-08] (Electronic Arts)
S4 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] ()
S4 ss_conn_service; D:\Samsung Kies\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AmUStor; C:\Windows\System32\drivers\AmUStor.SYS [25600 2009-07-24] (Alcor Micro, Corp.)
R0 AsDsm; C:\Windows\system32\Drivers\AsDsm.sys [30264 2009-12-25] (ASUSTek Computer Inc)
R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-06-11] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-06-11] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-20] (Avira Operations GmbH & Co. KG)
R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [105728 2014-09-29] (AVM Berlin)
R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [105728 2014-09-29] (AVM Berlin)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-11] (Avira Operations GmbH & Co. KG)
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [131288 2015-05-28] (BlueStack Systems)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-11-21] (Disc Soft Ltd)
R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2009-06-18] (Windows (R) Win 7 DDK provider)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-06-19] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [14392 2009-05-13] (ASUS)
R1 ndiskhaz; C:\Windows\System32\DRIVERS\ndiskhaz.sys [25416 2012-12-07] (Khalil Azzouzi)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1766592 2009-06-05] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [324096 2013-11-21] (Duplex Secure Ltd.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-06-11] (Avira Operations GmbH & Co. KG)
R3 stdriver; C:\Windows\System32\DRIVERS\stdriver32.sys [52312 2012-06-21] (NCH Software)
U3 a4o6zbuq; C:\Windows\system32\Drivers\a4o6zbuq.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
U3 a7bz1tf0; C:\Windows\system32\Drivers\a7bz1tf0.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
S3 ALSysIO; \??\C:\Users\Philipp\AppData\Local\Temp\ALSysIO.sys [X]
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Philipp\AppData\Local\Temp\catchme.sys [X]
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X]
S3 ipswuio; System32\DRIVERS\ipswuio.sys [X]
S3 RTHDMIAzAudService; system32\drivers\RtHDMIV.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-19 20:01 - 2015-06-19 20:03 - 00027909 _____ C:\Users\Philipp\Desktop\FRST.txt
2015-06-19 20:00 - 2015-06-19 20:00 - 00000904 _____ C:\Users\Philipp\Desktop\JRT.txt
2015-06-19 19:56 - 2015-06-19 19:56 - 00000207 _____ C:\Windows\tweaking.com-regbackup-SCHEFFLER-PC-Windows-7-Home-Premium-(32-bit).dat
2015-06-19 19:56 - 2015-06-19 19:56 - 00000000 ____D C:\RegBackup
2015-06-19 19:54 - 2015-06-19 19:55 - 02950477 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe
2015-06-19 19:37 - 2015-06-19 19:45 - 00000000 ____D C:\AdwCleaner
2015-06-19 19:36 - 2015-06-19 19:36 - 02231296 _____ C:\Users\Philipp\Desktop\AdwCleaner_4.206.exe
2015-06-19 16:19 - 2015-06-19 16:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-06-19 16:19 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-19 16:19 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-18 15:15 - 2015-06-18 15:15 - 00011037 _____ C:\Users\Philipp\AppData\Local\recently-used.xbel
2015-06-17 18:30 - 2015-06-19 19:50 - 00000374 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2015-06-17 18:24 - 2015-06-17 18:24 - 00028045 _____ C:\ComboFix.txt
2015-06-17 17:28 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2015-06-17 17:28 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2015-06-17 17:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-06-17 17:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-06-17 17:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-06-17 17:28 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2015-06-17 17:28 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2015-06-17 17:28 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2015-06-17 17:27 - 2015-06-17 18:24 - 00000000 ____D C:\Qoobox
2015-06-17 17:26 - 2015-06-17 18:21 - 00000000 ____D C:\Windows\erdnt
2015-06-17 17:20 - 2015-06-17 17:20 - 05628161 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe
2015-06-17 13:45 - 2015-06-17 13:45 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-06-17 13:43 - 2015-06-19 19:48 - 00001232 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004UA.job
2015-06-17 13:43 - 2015-06-19 13:48 - 00001180 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004Core.job
2015-06-17 13:43 - 2015-06-17 13:43 - 00000000 ____D C:\Users\Philipp\AppData\Local\Dropbox
2015-06-16 18:40 - 2015-06-16 18:40 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Philipp\Desktop\tdsskiller.exe
2015-06-16 17:06 - 2015-06-19 16:19 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-16 17:05 - 2015-06-19 19:50 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-16 17:05 - 2015-06-17 21:22 - 00000000 ____D C:\Users\Philipp\Desktop\Ein jdhd
2015-06-16 17:05 - 2015-06-16 18:36 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-06-16 17:04 - 2015-06-16 18:36 - 00000000 ____D C:\Users\Philipp\Desktop\mbar
2015-06-16 17:04 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-15 18:32 - 2015-06-19 20:01 - 00000000 ____D C:\FRST
2015-06-15 18:13 - 2015-06-15 18:13 - 01148416 _____ (Farbar) C:\Users\Philipp\Desktop\FRST.exe
2015-06-13 14:19 - 2015-06-13 14:19 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-06-13 14:18 - 2015-06-19 19:23 - 00001228 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job
2015-06-13 14:18 - 2015-06-19 14:23 - 00001176 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job
2015-06-13 14:18 - 2015-06-13 14:18 - 00000000 ____D C:\Users\Jeffel\AppData\Local\Dropbox
2015-06-13 14:18 - 2015-06-13 14:18 - 00000000 ____D C:\ProgramData\Dropbox
2015-06-11 20:32 - 2015-06-11 20:32 - 00131180 _____ C:\Users\Manuel\Downloads\Motorrad Profi 4 - kostenlos online spielen.htm
2015-06-11 18:41 - 2015-06-11 18:41 - 00001085 _____ C:\Users\Public\Desktop\Avira.lnk
2015-06-10 10:09 - 2015-06-02 21:35 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 10:09 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 10:09 - 2015-05-25 19:00 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-10 10:09 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-10 10:09 - 2015-05-23 05:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-10 10:09 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 10:09 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-10 10:09 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-10 10:09 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 10:09 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-10 10:09 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 10:09 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-10 10:09 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-10 10:09 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 10:09 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 10:09 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-10 10:09 - 2015-05-23 05:05 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-10 10:09 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 10:09 - 2015-05-23 05:00 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-10 10:09 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-10 10:09 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-10 10:09 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-10 10:09 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 10:09 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 10:09 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 10:09 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 10:09 - 2015-05-23 04:38 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-10 10:09 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 10:09 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-10 10:09 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 10:09 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 10:09 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 10:09 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 10:09 - 2015-05-22 20:03 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-10 10:09 - 2015-05-22 20:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-10 10:09 - 2015-05-22 19:58 - 00901120 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-10 10:09 - 2015-05-21 15:20 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-10 10:08 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-06-10 10:08 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-10 10:08 - 2015-05-25 20:07 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-10 10:08 - 2015-05-25 20:07 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-10 10:08 - 2015-05-25 20:04 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00853504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-10 10:08 - 2015-05-25 20:01 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-10 10:08 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-10 10:08 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-10 10:08 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-10 10:08 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-10 10:08 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-10 10:08 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-10 10:08 - 2015-05-25 18:53 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 10:08 - 2015-05-09 05:14 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-10 10:08 - 2015-05-09 05:13 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-10 10:08 - 2015-05-09 05:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-10 10:08 - 2015-05-09 05:12 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-10 10:08 - 2015-05-09 05:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 03:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 03:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-10 10:08 - 2015-05-09 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-10 10:08 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-10 10:08 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-10 10:08 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-10 10:08 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-10 10:08 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-10 10:08 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-09 17:20 - 2015-06-09 17:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2015-06-09 17:20 - 2015-06-09 17:21 - 00000000 ____D C:\Program Files\BlueStacks
2015-06-09 17:20 - 2015-06-09 17:20 - 00000000 ____D C:\ProgramData\BlueStacks
2015-06-09 17:18 - 2015-06-09 17:18 - 15738056 _____ C:\Users\Philipp\Downloads\CloudMusic_official_2.7.1.apk
2015-06-09 17:18 - 2015-06-09 17:18 - 14155832 _____ (BlueStack Systems Inc.) C:\Users\Philipp\Downloads\BlueStacks-ThinInstaller.exe
2015-06-09 15:44 - 2015-05-09 05:14 - 02937344 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 02045952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-06-09 15:44 - 2015-05-09 05:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-06-09 15:44 - 2015-05-09 05:13 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-06-09 15:44 - 2015-05-09 05:13 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-06-09 15:44 - 2015-05-09 05:13 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-06-09 15:44 - 2015-05-09 05:13 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-06-06 18:11 - 2015-06-06 18:11 - 00000000 ____D C:\Users\Beamer\AppData\Local\GWX
2015-06-06 11:34 - 2015-06-07 21:06 - 00000000 ____D C:\Users\Philipp\Documents\Joerg Riesa
2015-06-04 20:15 - 2015-06-04 20:16 - 00103104 _____ C:\Users\Manuel\Downloads\Crazy Skater - kostenlos online spielen.htm
2015-06-04 19:22 - 2015-06-04 19:22 - 00002121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-06-03 18:24 - 2015-06-03 18:24 - 00000000 ____D C:\Users\Manuel\AppData\Local\GWX
2015-06-03 16:37 - 2015-06-03 16:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2015-06-02 15:47 - 2015-06-04 18:42 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-01 20:38 - 2015-06-01 20:38 - 00000000 ____D C:\Users\Jeffel\AppData\Local\GWX
2015-06-01 19:02 - 2015-06-01 19:02 - 00000000 ____D C:\Users\Ellen & Manuel\AppData\Local\GWX
2015-06-01 18:03 - 2015-06-01 18:03 - 00000000 ____D C:\Users\Philipp\AppData\Local\GWX
2015-05-31 15:23 - 2015-05-31 15:43 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dual Monitor
2015-05-31 15:23 - 2015-05-31 15:23 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dual Monitor
2015-05-20 19:51 - 2015-05-20 19:51 - 00177664 _____ C:\Users\Philipp\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-20 17:18 - 2015-04-11 05:07 - 00054656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-05-20 17:18 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-05-20 17:18 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-19 19:57 - 2009-12-25 17:20 - 00019456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-19 19:57 - 2009-12-25 17:20 - 00019456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-19 19:56 - 2015-05-17 19:56 - 00000917 _____ C:\Windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job
2015-06-19 19:56 - 2015-05-17 19:56 - 00000731 _____ C:\Windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job
2015-06-19 19:56 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-06-19 19:54 - 2009-12-25 18:22 - 01544651 _____ C:\Windows\WindowsUpdate.log
2015-06-19 19:50 - 2012-12-17 20:34 - 00000000 ___RD C:\Users\Philipp\Documents\Dropbox
2015-06-19 19:49 - 2010-12-01 14:28 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dropbox
2015-06-19 19:48 - 2014-07-12 11:12 - 00000000 ___RD C:\Users\Philipp\Google Drive
2015-06-19 19:48 - 2010-01-31 18:04 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-19 19:47 - 2015-04-04 08:21 - 00003934 _____ C:\Windows\PFRO.log
2015-06-19 19:47 - 2015-04-02 11:31 - 00326077 _____ C:\Windows\setupact.log
2015-06-19 19:47 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-19 19:19 - 2012-04-04 22:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-19 19:10 - 2014-12-31 17:10 - 00000917 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job
2015-06-19 19:10 - 2014-12-31 17:10 - 00000731 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job
2015-06-19 19:04 - 2010-01-31 18:04 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-19 06:51 - 2009-08-20 05:40 - 01620684 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-18 15:41 - 2014-11-23 16:42 - 00000000 ____D C:\Users\Philipp\.gimp-2.8
2015-06-18 15:15 - 2014-11-23 16:44 - 00000000 ____D C:\Users\Philipp\AppData\Local\gtk-2.0
2015-06-17 19:46 - 2014-11-23 16:44 - 00000000 ____D C:\Users\Philipp\.thumbnails
2015-06-17 18:24 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2015-06-17 18:17 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2015-06-17 17:21 - 2014-11-15 12:37 - 00000000 __SHD C:\Users\Philipp\AppData\Local\EmieBrowserModeList
2015-06-17 17:21 - 2014-05-07 17:14 - 00000000 __SHD C:\Users\Philipp\AppData\Local\EmieUserList
2015-06-17 17:21 - 2014-05-07 17:14 - 00000000 __SHD C:\Users\Philipp\AppData\Local\EmieSiteList
2015-06-16 16:23 - 2013-03-30 18:22 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\.minecraft
2015-06-16 15:34 - 2010-10-17 11:45 - 00001332 __RSH C:\Users\Philipp\ntuser.pol
2015-06-16 15:34 - 2010-10-17 11:45 - 00000000 ___RD C:\Users\Philipp
2015-06-16 15:22 - 2009-08-19 05:27 - 00000000 ____D C:\temp
2015-06-15 17:04 - 2013-11-21 19:48 - 00000000 ____D C:\Users\Beamer\AppData\Roaming\DAEMON Tools Lite
2015-06-15 06:48 - 2010-09-11 19:48 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Skype
2015-06-15 06:45 - 2014-07-30 10:13 - 00000000 __SHD C:\Users\Jeffel\AppData\Local\EmieUserList
2015-06-15 06:45 - 2014-07-30 10:13 - 00000000 __SHD C:\Users\Jeffel\AppData\Local\EmieSiteList
2015-06-14 20:33 - 2012-12-30 21:21 - 00000000 ___RD C:\Users\Jeffel\Dropbox
2015-06-14 20:33 - 2012-12-30 21:17 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Dropbox
2015-06-14 19:33 - 2010-10-18 18:21 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Skype
2015-06-13 13:07 - 2014-07-12 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-06-11 18:47 - 2011-10-20 18:09 - 00000000 ____D C:\ProgramData\Avira
2015-06-11 18:41 - 2014-08-25 20:44 - 00000000 ____D C:\ProgramData\Package Cache
2015-06-11 18:40 - 2015-03-05 16:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-06-11 18:40 - 2012-11-02 20:39 - 00000000 ____D C:\Program Files\Avira
2015-06-11 12:09 - 2012-11-02 20:40 - 00136728 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-06-11 12:09 - 2012-11-02 20:40 - 00108448 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-06-11 12:09 - 2012-11-02 20:40 - 00031848 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\ssmdrv.sys
2015-06-11 09:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2015-06-11 08:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-06-10 17:55 - 2014-05-29 20:43 - 00000000 ____D C:\Users\Philipp\.android
2015-06-10 17:19 - 2012-04-04 22:24 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-06-10 17:19 - 2011-06-10 19:15 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-06-10 15:43 - 2015-04-02 11:30 - 00572992 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-10 15:05 - 2014-12-10 22:23 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-10 15:05 - 2014-04-26 10:01 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-10 15:04 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2015-06-10 10:31 - 2009-08-19 04:00 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-10 10:25 - 2013-07-28 23:00 - 00000000 ____D C:\Windows\system32\MRT
2015-06-10 10:14 - 2009-12-29 22:28 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-09 17:21 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Libraries
2015-06-08 18:27 - 2013-06-17 09:00 - 00000000 ____D C:\ProgramData\Origin
2015-06-08 18:20 - 2013-06-17 11:51 - 00000000 ____D C:\Users\Beamer\AppData\Roaming\Origin
2015-06-08 18:14 - 2013-06-17 09:00 - 00000000 ____D C:\Program Files\Origin
2015-06-08 17:04 - 2013-11-27 20:45 - 00000000 ____D C:\Program Files\Common Files\Steam
2015-06-06 10:46 - 2012-05-17 13:18 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Notepad++
2015-06-04 19:21 - 2009-08-19 04:20 - 00000000 ____D C:\Program Files\Google
2015-06-04 18:42 - 2012-05-11 15:08 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-06-03 16:42 - 2014-04-28 18:03 - 00000000 ____D C:\Program Files\CCleaner
2015-05-31 15:54 - 2012-12-22 15:49 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Audacity
2015-05-30 22:11 - 2009-11-24 20:19 - 00045056 _____ C:\Windows\system32\acovcnt.exe
2015-05-30 12:55 - 2010-03-06 18:42 - 00000000 ____D C:\Users\Jeffel\Documents\Kigo
2015-05-27 18:16 - 2010-01-25 18:43 - 00000000 ____D C:\Users\Jeffel\Documents\Telefon
2015-05-26 11:56 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-21 21:22 - 2011-08-28 09:47 - 00000000 ____D C:\Users\Beamer
2015-05-20 20:24 - 2012-11-02 20:40 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-05-20 17:19 - 2015-04-04 20:15 - 00000000 ___SD C:\Windows\system32\GWX
2015-05-20 17:07 - 2010-10-21 17:44 - 00000000 ____D C:\Users\Philipp\AppData\Local\Adobe
2015-05-20 17:06 - 2011-08-28 10:41 - 00000000 ____D C:\Users\Beamer\AppData\Local\Adobe

==================== Files in the root of some directories =======

2008-05-22 09:35 - 2008-05-22 09:35 - 0051962 _____ () C:\Program Files\Common Files\banner.jpg
2009-04-08 11:31 - 2009-04-08 11:31 - 0106496 _____ () C:\Program Files\Common Files\CPInstallAction.dll
2008-08-11 22:45 - 2008-08-11 22:45 - 0155648 _____ (ASUS) C:\Program Files\Common Files\MSIactionall.dll
2013-06-01 21:00 - 2013-06-03 12:23 - 0078208 _____ () C:\Users\Philipp\AppData\Roaming\MinecraftLog.txt
2012-06-19 14:26 - 2012-06-19 14:26 - 0041472 ___SH () C:\Users\Philipp\AppData\Roaming\Thumbs.db
2010-11-19 20:11 - 2013-02-02 12:46 - 0010240 _____ () C:\Users\Philipp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-18 15:15 - 2015-06-18 15:15 - 0011037 _____ () C:\Users\Philipp\AppData\Local\recently-used.xbel
2012-04-17 18:47 - 2012-04-17 18:47 - 0000017 _____ () C:\Users\Philipp\AppData\Local\resmon.resmoncfg
2010-09-11 19:55 - 2010-09-11 19:55 - 0000056 ____H () C:\ProgramData\ezsidmv.dat

Files to move or delete:
====================
C:\Users\Jeffel\i2errDeu.dll


Some files in TEMP:
====================
C:\Users\Philipp\AppData\Local\temp\avgnt.exe
C:\Users\Philipp\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp31u4nh.dll
C:\Users\Philipp\AppData\Local\temp\Quarantine.exe
C:\Users\Philipp\AppData\Local\temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-04 23:19

==================== End of log ============================
         

Alt 19.06.2015, 19:09   #12
flowerwithlo
 
DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



Additional:
[CODE]Additional
FRST Logfile:
FRST Logfile:
Code:
ATTFilter
scan result of Farbar Recovery Scan Tool (x86) Version: 13-06-2015
Ran by Philipp at 2015-06-19 20:04:15
Running from C:\Users\Philipp\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-644356114-2566177158-2502637254-500 - Administrator - Disabled)
Beamer (S-1-5-21-644356114-2566177158-2502637254-1005 - Administrator - Enabled) => C:\Users\Beamer
Ellen & Manuel (S-1-5-21-644356114-2566177158-2502637254-1008 - Limited - Enabled) => C:\Users\Ellen & Manuel
Gast (S-1-5-21-644356114-2566177158-2502637254-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-644356114-2566177158-2502637254-1010 - Limited - Enabled)
Jeffel (S-1-5-21-644356114-2566177158-2502637254-1000 - Administrator - Enabled) => C:\Users\Jeffel
Manuel (S-1-5-21-644356114-2566177158-2502637254-1011 - Limited - Enabled) => C:\Users\Manuel
Philipp (S-1-5-21-644356114-2566177158-2502637254-1004 - Administrator - Enabled) => C:\Users\Philipp

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Antivirus (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

1&1 SmartFax (HKLM\...\1&1 SmartFax) (Version: 2.00.224 - 1&1 Internet AG)
3dPageFlip  Editor (HKLM\...\3dPageFlip PDF Editor_is1) (Version:  - 3dPageFlip Solution)
Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version:  - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adblock Plus für IE (32-Bit) (HKLM\...\{654F389B-E402-4F7B-BA6D-DA732BB57ACB}) (Version: 1.4 - Eyeo GmbH)
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM\...\AmUStor) (Version: 1.4.1217.35202 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (Version: 1.4.1217.35202 - Alcor Micro Corp.) Hidden
Apple Application Support (32-Bit) (HKLM\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASUS CopyProtect (HKLM\...\{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}) (Version: 1.0.0015 - ASUS)
ASUS Data Security Manager (HKLM\...\{FA2092C5-7979-412D-A962-6485274AE1EE}) (Version: 1.00.0014 - ASUS)
ASUS FancyStart (HKLM\...\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}) (Version: 1.0.6 - ASUSTeK Computer Inc.)
ASUS LifeFrame3 (HKLM\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS)
ASUS Live Update (HKLM\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS)
ASUS MultiFrame (HKLM\...\{9D48531D-2135-49FC-BC29-ACCDA5396A76}) (Version: 1.0.0019 - ASUS)
ASUS Power4Gear eXtreme (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.0.19 - ASUS)
ASUS SmartLogon (HKLM\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0007 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0028 - ASUS)
ASUS Touch Pad Extra (HKLM\...\{DB891739-2EB3-45A8-9CBD-941C255CECD4}) (Version:  - )
ASUS Virtual Camera (HKLM\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.19 - asus)
Asus_Camera_ScreenSaver (HKLM\...\Asus_Camera_ScreenSaver) (Version: 2.0.0008 - ASUS)
Atheros Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - Atheros)
ATI Catalyst Install Manager (HKLM\...\{0AE24BD5-185C-436C-D93D-50574523C6C4}) (Version: 3.0.732.0 - ATI Technologies, Inc.)
ATK Generic Function Service (HKLM\...\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}) (Version: 1.00.0008 - ATK)
ATK Hotkey (HKLM\...\{7C05592D-424B-46CB-B505-E0013E8E75C9}) (Version: 1.0.0053 - ASUS)
ATK Media (HKLM\...\{D1E5870E-E3E5-4475-98A6-ADD614524ADF}) (Version: 2.0.0006 - ASUS)
ATKOSD2 (HKLM\...\{3B05F2FB-745B-4012-ADF2-439F36B2E70B}) (Version: 7.0.0006 - ASUS)
aTube Catcher (HKLM\...\aTube Catcher) (Version: 2.9.1462 - DsNET Corp)
aTube Catcher Version 3.8 (HKLM\...\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
Audacity 2.0.2 (HKLM\...\Audacity_is1) (Version: 2.0.2 - Audacity Team)
Avanquest update (HKLM\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.29 - Avanquest Software)
Avidemux 2.6 (32-bit) (HKLM\...\Avidemux 2.6) (Version: 2.6.8.9046 - )
Avira (HKLM\...\{0696cc37-db90-4000-be99-4a173ca7c8af}) (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG)
Avira (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.11.574 - Avira Operations GmbH & Co. KG)
Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION
Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION
Bandicam (HKLM\...\Bandicam) (Version: 1.8.5.302 - Bandisoft.com)
Battlefield 1942™ (HKLM\...\{5BE7BD06-512B-43bf-AD78-3BD2A5F5F7B3}) (Version: 1.6.20.0 - Electronic Arts)
Bejeweled® 3 (HKLM\...\{E99C27B2-EB2E-4244-9F5C-A96F55100F0C}) (Version: 1.1.13.4753 - Electronic Arts, Inc.)
BlueStacks App Player (HKLM\...\BlueStacks App Player) (Version: 0.9.27.5408 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM\...\{C1F53C9F-C560-4292-9237-12786FE6BF62}) (Version: 0.9.27.5408 - BlueStack Systems, Inc.)
Bob baut einen Park (HKLM\...\{367EDD83-302F-48E6-8F77-B0B056125C2D}) (Version: 1.0.0 - )
Bob der Baumeister (HKLM\...\{8F2D21F9-F428-4EF2-8111-953EF3299EFB}) (Version: 1.0.0 - )
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\...\CANONIJPLM100) (Version:  - )
Canon MP Navigator EX 3.0 (HKLM\...\MP Navigator EX 3.0) (Version:  - )
Canon MP490 series Benutzerregistrierung (HKLM\...\Canon MP490 series Benutzerregistrierung) (Version:  - )
Canon MP490 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series) (Version:  - )
Canon Utilities Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version:  - )
Canon Utilities My Printer (HKLM\...\CanonMyPrinter) (Version:  - )
Canon Utilities Solution Menu (HKLM\...\CanonSolutionMenu) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform)
Cisco EAP-FAST Module (HKLM\...\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\...\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\...\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.)
Construction-Simulator 2015 (HKLM\...\Steam App 289950) (Version:  - weltenbauer. Software Entwicklung GmbH)
Core Temp version 0.99.7 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 0.99.7 - Arthur Liberman)
Crusader No Remorse (HKLM\...\{2AEA735F-B393-4D89-93EF-5849CB72B4A3}) (Version: 1.0.0.2 - Electronic Arts)
CyberLink LabelPrint (HKLM\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1720 - CyberLink Corp.)
CyberLink Power2Go (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.2713 - CyberLink Corp.)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd)
Diercke Globus Online (HKLM\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH)
dm-Fotowelt (HKLM\...\dm-Fotowelt) (Version: 5.1.7 - CEWE Stiftung u Co. KGaA)
Dolby Control Center (HKLM\...\{0F3C61B5-3051-4DE6-8A6A-45100BCC1F41}) (Version: 1.2.0704 - Dolby)
Dropbox (HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Dropbox) (Version: 3.6.7 - Dropbox, Inc.)
Dropbox (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Dropbox) (Version: 3.6.7 - Dropbox, Inc.)
Druckerdeinstallation für EPSON XP-312 313 315 Series (HKLM\...\EPSON XP-312 313 315 Series) (Version:  - SEIKO EPSON Corporation)
Druckerdeinstallation für EPSON XP-412 413 415 Series (HKLM\...\EPSON XP-412 413 415 Series) (Version:  - SEIKO EPSON Corporation)
Dual Monitor 1.22 (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{64AA3F94-ED4A-4A4B-B72C-B7A1481ED5D8}_is1) (Version: 1.22.021813 - Cristi Diaconu)
EA SPORTS FIFA World (HKLM\...\{8F9AC744-EEF6-43DB-A4B6-FA1A18F1C640}) (Version: 9.5.0.61021 - Electronic Arts, Inc.)
Epson Connect Printer Setup (HKLM\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.3.0 - SEIKO EPSON CORPORATION)
Epson Event Manager (HKLM\...\{0F13C24A-FFE2-4CD0-8E0B-DC804E0A0E0B}) (Version: 3.10.0035 - Seiko Epson Corporation)
EPSON Scan (HKLM\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON-Handbücher (HKLM\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.32.0.0 - SEIKO EPSON CORPORATION)
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION)
Express Gate (HKLM\...\{62CF8923-31DC-4285-A23C-17CE5AA6A679}) (Version: 1.0.3.2 - DeviceVM, Inc.)
F1 2013 (HKLM\...\Steam App 223670) (Version:  - Codemasters Birmingham)
FIFA 09 (HKLM\...\{2315B23D-3E21-4920-837D-AE6460934ECB}) (Version: 1.0.1.1 - Electronic Arts)
Firebird SQL Server - MAGIX Edition (HKLM\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG)
FRITZ!Box USB-Fernanschluss (HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\2db37667170956ee) (Version: 2.3.2.0 - AVM Berlin)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Globus Fotoservice 4.4 (HKLM\...\Globus Fotoservice_is1) (Version:  - )
Google Drive (HKLM\...\{CBC9F5FD-5CFA-4A33-81CD-369EAB77E3A6}) (Version: 1.22.9403.0223 - Google, Inc.)
Google Earth (HKLM\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
Google+ Auto Backup (HKLM\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
Hot Wheels (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{CF36DD86-81D3-4D91-8F7A-344E0C1A4BFD}) (Version: 1.00.0000 - Activision Value)
iCloud (HKLM\...\{9A07AB4F-6B53-43E9-B7FC-7892E8C26BE3}) (Version: 4.1.1.53 - Apple Inc.)
Isola LEGO 2 (HKLM\...\{85967580-EBC2-11D4-AEA3-0050046A88ED}) (Version:  - )
iTunes (HKLM\...\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.)
Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
KingsoftOfficeXPlats 1.4 (HKLM\...\KingsoftOfficeXPlats) (Version: 1.4 - Kingsoft)
LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version:  - )
LBOTS Top mouse Driver (HKLM\...\{F1A273BD-6A9E-41D8-A111-5E56ACD286F8}) (Version: 1.0 - Togran)
LEGO Racers 2 (HKLM\...\{3DD2E9EA-0544-4162-B8BE-E21E994E9F3B}) (Version:  - )
LEGO® Star Wars™: Die Komplette Saga (HKLM\...\InstallShield_{D596980D-17BE-4425-B8F0-5640719AADE9}) (Version: 1.00.0000 - LucasArts)
LEGO® Star Wars™: The Complete Saga (Version: 1.00.0000 - LucasArts) Hidden
Logitech Gaming Software (HKLM\...\{648F9C94-EC44-487B-9DA4-44ED72A082CC}) (Version: 4.50 - )
MAGIX Speed burnR (MSI) (HKLM\...\MX.{16884C3D-3512-486D-A2F9-39071551BFEF}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX Video deluxe 2014 (HKLM\...\MX.{EA62B22F-AB0A-406B-80A9-8036D3CE3446}) (Version: 13.0.2.8 - MAGIX AG)
MAGIX Video deluxe 2014 (Version: 13.0.2.8 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM\...\{95120000-0122-0407-0000-0000000FF1CE}) (Version: 12.0.6423.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{AC4C38FD-A54C-4CA5-92EE-D983CD81293E}) (Version: 1.20.146.0 - Microsoft)
Minecraft (HKLM\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Minigolf (HKLM\...\Minigolf_is1) (Version:  - Meridian93)
Monkey's Adventures (HKLM\...\Monkey's Adventures_is1) (Version:  - play-publishing.com)
Motorola Driver Installation 3.4.0 (HKLM\...\{81B3BEF9-5D97-4096-86E9-5B48A5BC32D0}) (Version: 3.4.0 - Motorola Inc.)
Motorola Phone Tools (HKLM\...\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}) (Version: 5.0.7a 4/01/2008 - Avanquest Software)
Motorola Phone Tools (Version: 4.30 - BVRP Software) Hidden
Motorola Phone Tools (Version: 5.00 - BVRP Software) Hidden
Mozilla Firefox 38.0.5 (x86 de) (HKLM\...\Mozilla Firefox 38.0.5 (x86 de)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyPublicWiFi 5.1 (HKLM\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version:  - TRUE Software)
Mystery P.I. - The London Caper (HKLM\...\Mystery P.I. - The London Caper) (Version:  - PopCap Games)
NB Probe (HKLM\...\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}) (Version:  - )
Need For Speed™ World (HKLM\...\{3AF1B16A-7DC9-4C80-BAEC-70B088A7C5B8}) (Version: 1.0.0.0 - Electronic Arts)
Net4Switch (HKLM\...\{9D6D7811-43B3-463C-BC79-5D1755269989}) (Version: 1.00.0019 - ASUS)
Norton Internet Security (Version: 16.0.0.125 - Symantec Corporation) Hidden
Notepad++ (HKLM\...\Notepad++) (Version: 6.1.2 - )
OpenAL (HKLM\...\OpenAL) (Version:  - )
Oracle VM VirtualBox 4.3.2 (HKLM\...\{91E5A436-8560-4621-9F26-D7050D078832}) (Version: 4.3.2 - Oracle Corporation)
Origin (HKLM\...\Origin) (Version: 9.2.1.4399 - Electronic Arts, Inc.)
pdfsam (HKLM\...\pdfsam) (Version: 2.2.0 - )
Peter Lustigs Verkehrsschule (HKLM\...\Verkehrsschule) (Version:  - )
Pflanzen gegen Zombies™ (HKLM\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.)
Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.)
QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Roads Of Rome (HKLM\...\Roads Of Rome_is1) (Version:  - Realore Studios)
Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.)
Samsung Kies (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SimCity 2000 Special Edition (HKLM\...\{59D2C751-F7BE-4E9F-9C8C-1F16013802C7}) (Version: 2.0.0.1 - Electronic Arts)
SimCity™ (HKLM\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
Skype™ 7.1 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
Software Updater (HKLM\...\{E1BAD1BA-C0E8-4018-9281-E7D2C6B07474}) (Version: 4.3.6 - SEIKO EPSON CORPORATION)
Steam (HKLM\...\Steam) (Version:  - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.1.1 - Synaptics Incorporated)
Syndicate (HKLM\...\{64CFBAAB-46F7-4628-8D9B-E656A8C11CDB}) (Version: 2.0.0.3 - Electronic Arts)
System Requirements Lab CYRI (HKLM\...\{E77DA909-3532-4C95-AFEB-06310E88462A}) (Version: 6.0.3.0 - Husdawg, LLC)
Theme Hospital (HKLM\...\{5118A4C2-C8A4-4CE5-AC37-F3E51C25402F}) (Version: 3.0.0.2 - Electronic Arts)
TIPP10 Version 2.1.0 (HKLM\...\TIPP10_is1) (Version:  - (c) 2006-2011, Tom Thielicke IT Solutions)
TmNationsForever (HKLM\...\TmNationsForever_is1) (Version:  - Nadeo)
TOGGO PC-Spielebox 2 (HKLM\...\{67EECE0C-8B6C-4D09-989D-D39BC9BBCA0E}) (Version: 1.00.0000 - )
Toyland Racer (HKLM\...\Toyland Racer) (Version:  - )
Unified Remote (HKLM\...\{D7930C67-5816-417B-BF28-54BB75EFDAF9}) (Version: 2.14.4.0 - Unified Remote)
Unity Web Player (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Unity Web Player (HKU\S-1-5-21-644356114-2566177158-2502637254-1008\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
upapp (HKLM\...\{4EF69D40-4DC9-485E-95D3-B1C22F218FC8}) (Version: 0.20.0000 - Hewlett-Packard)
USB 2.0 1.3M UVC WebCam (HKLM\...\USB 2.0 1.3M UVC WebCam) (Version:  - )
Werksfeuerwehr-Simulator Version 1.0 (HKLM\...\{5F7ED0CD-E04E-4441-9E03-10AFDB654E96}_is1) (Version:  - rondomedia Marketing & Vertriebs GmbH)
Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live ID-Anmelde-Assistent (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows Live Sync (HKLM\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
WinFlash (HKLM\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.29.0 - ASUS)
WinRAR (HKLM\...\WinRAR archiver) (Version:  - )
Wireless Console 2 (HKLM\...\{83F73CB1-7705-49D1-9852-84D839CA2A45}) (Version: 2.0.10 - ATK)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\ProgramData\Skype\Plugins\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\ProgramData\Skype\Plugins\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Philipp\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{4D72E5BC-BC7C-11E0-83CA-10424824019B}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\AviraIDW.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{595EF3BD-A186-454A-810C-02015139ACDC}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\Avira.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{7F902AD4-FC6A-4B2F-8B8D-B6DD4E329B76}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\AVIRAW~1.DLL No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{A0359AE6-F410-4425-A975-684AAB785ABD}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\AVIRAB~1.DLL No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\Philipp\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{EB959CA4-408B-4465-9CF5-7EBA7B885153}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\AVIRAS~1.DLL No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FBE88A10-FF53-11E0-AB2A-AE904824019B}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\AVIRAI~1.DLL No File
CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\Philipp\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll (Dropbox, Inc.)

==================== Restore Points =========================

15-06-2015 06:14:31 Windows-Sicherung
16-06-2015 13:24:40 Windows Update
16-06-2015 16:55:49 Revo Uninstaller's restore point - Avira SearchFree Toolbar plus Web Protection Updater

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 12:23 - 2015-06-17 18:08 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {022E57E0-C220-4A4E-AC90-D2C8DACAFB9D} - System32\Tasks\{4E4F2CAC-AA02-4AC1-8E3F-7F64288279A5} => C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe [2000-05-31] (Krisalis Software Ltd.)
Task: {0381252B-84D7-4E1D-8044-32644EAD1708} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-03-16] (Microsoft Corporation)
Task: {062DB597-D745-4B4F-8444-3530722D8F45} - System32\Tasks\Core Temp Autostart => C:\Program Files\Core Temp\Core Temp.exe [2010-07-05] ()
Task: {08271361-89BF-4F1E-847E-1CA1ED3F6641} - System32\Tasks\{4B77430A-A839-4A8D-9AC6-DFE4CD36D283} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {0CF8F249-C5F7-475C-866F-21E7073015BD} - System32\Tasks\{EBC19F45-7508-4844-801A-11E762E37D12} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {0FB6D721-7BEF-4B45-8E9C-A271B66DE5F2} - System32\Tasks\{07EB860E-F755-4932-9D3F-42431206EE3B} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {10DE5D12-366D-4EFB-9E1B-A5431C45ADC4} - System32\Tasks\{8AC62F6C-CFBA-4FA8-8592-D8DBAF919A41} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {11F32470-4328-4A83-9232-80BC5F42F305} - System32\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE [2013-02-28] (SEIKO EPSON CORPORATION)
Task: {13CEC175-DFF4-4468-A045-29A526295C70} - System32\Tasks\{09EF0FB5-FFC5-4873-8A09-BA67F477983B} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {16A24A9E-DAB7-4860-94FD-851235C89820} - System32\Tasks\{2F3444E4-EAF5-4F9D-B44F-0359C6E1E962} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe
Task: {16E7A595-0943-4C27-81FD-3C0F4846CBB9} - System32\Tasks\{718A9724-BA58-4A15-BA3F-28AD141B9FD7} => C:\Program Files\Logitech\Profiler\LWEmon.exe [2004-05-19] (Logitech Inc.)
Task: {189C40ED-B151-444D-86FA-72B2F6B581EA} - System32\Tasks\{EEA39017-C6C8-42D6-83AD-AC789FF71125} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {1C2351DE-232B-4961-840F-EE0D68EB5EF4} - System32\Tasks\{81FAAD8E-E607-4907-9205-969E20593CF7} => C:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe
Task: {1DD33B99-F5E8-460F-BD30-B40888E8C53E} - System32\Tasks\{DB5AE33D-F764-456D-9421-62DA1F9288C7} => pcalua.exe -a "D:\DT\DAEMON Tools Lite\DTLite.exe" -d "D:\DT\DAEMON Tools Lite"
Task: {1E3565F3-04AA-44DB-B8B7-F35A50CC9057} - System32\Tasks\{07FA7B80-D838-4C87-9F76-696E853348E0} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe
Task: {2262B621-3FBA-4C58-8344-886110A30AF0} - System32\Tasks\{275198ED-E85E-4D37-9669-8DAC2931B05F} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {27685E6B-A6D7-4064-A4B9-1F485556156D} - System32\Tasks\{D1391C33-4665-4D75-B346-6737F2BFE6AE} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.)
Task: {279BEA6F-528A-4E59-B4D6-EF67500EC149} - System32\Tasks\{4CB1BAEC-7E20-4475-942D-B2ECD3C7BDE5} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {2C842B08-3AB4-4249-8416-A5F0C4254CBB} - System32\Tasks\{E26735BF-5210-43CB-908E-8A7923966B55} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {2E316E44-A20D-4E6C-8597-A4349A8F0F7B} - System32\Tasks\{0E84DB2D-E2CE-4939-A87C-0A7FEF5598A0} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe
Task: {2EB3D3F5-13C7-448C-98A4-8E8B09A66A7C} - System32\Tasks\{1833D727-C5CA-45F6-B130-C78FC735305C} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.)
Task: {3701EA83-EDC0-434F-8AB9-FE21AAE4072D} - System32\Tasks\{08709750-B91C-4722-844A-B78F6762E37B} => C:\Program Files\EA Sports\FIFA 09\FIFA09.exe [2008-10-23] ()
Task: {37B9496D-79A9-4BCE-AFE4-B5463740A943} - System32\Tasks\{F9594586-61F2-41B8-A093-C8719E057E91} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.)
Task: {393F6F51-0E95-4952-8BAD-E1DDD5FFF5DA} - System32\Tasks\{01E58447-78A0-4CD3-BFAF-44C036E4F3F7} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {394592EC-79F9-49B8-A307-37950D07C1B9} - System32\Tasks\{E9474EA8-9D29-4DF8-9857-8726D1F8FCD4} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe
Task: {3A161975-54C5-4DBB-8AB5-563F0BA63B7E} - System32\Tasks\{BBCB2F70-2DD9-4FDF-BA21-9F4AC8615359} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {3B9AC8C7-B8FF-4D70-9C79-4FB5EBBB90E9} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-07] (Microsoft Corporation)
Task: {3BC1FA8B-E302-4DEC-8AA9-B70DE9D839F7} - System32\Tasks\{15248D75-D51C-4771-8D5B-C56A5DC1D3F4} => C:\Program Files\OpenOffice.org 3\program\soffice.exe
Task: {3DF4B1BA-C6BA-4565-9C58-0A27C06A1D4C} - System32\Tasks\{10DEF6AD-CAED-48C8-85EB-BD3A12C54209} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {3ECE4DE4-C76E-486F-A045-0713A65EC396} - System32\Tasks\{C5F0B686-DAD5-46B7-8DC1-EEF6742294DF} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.)
Task: {3EF06EA8-17AE-4451-96B0-2ED48FE15BE6} - System32\Tasks\{FFB859B9-8F39-438E-A00B-543A2BC334B5} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {425C2494-05F2-4141-BD10-63B0AC111EEF} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {4299562C-9C52-4B20-9BF8-D294B2969604} - System32\Tasks\{CE1034B1-CDF0-44ED-A78A-0E1B67A19078} => pcalua.exe -a E:\SETUP.EXE -d E:\
Task: {48F7E135-8B4D-421A-B8E8-22BE06815370} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-08] (Piriform Ltd)
Task: {4A3D5C4F-7A49-48E2-BE04-A2DECC4146C2} - System32\Tasks\{4DF731FE-39D2-4735-963D-B33DC6BF1776} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {4B952069-F7C4-4178-932C-D9AD6435A3EE} - System32\Tasks\{9F523BAE-9190-4380-B2B3-96FB780FE112} => pcalua.exe -a C:\Users\Philipp\Desktop\jxpiinstall.exe -d C:\Users\Philipp\Desktop
Task: {4B9BA069-9E54-412A-90D7-CBB925EBF5FA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-10] (Adobe Systems Incorporated)
Task: {4D2676FB-5EC2-4044-897A-45B547B13687} - System32\Tasks\ASUS Live Update => C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2007-11-30] ()
Task: {4D5F48A9-2EB0-4E4E-B34D-95A3DDB466A9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {4D8CE3D9-10E6-4EF4-9C8E-39AD6D90EEEB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13] (Dropbox, Inc.)
Task: {4E453841-EE58-4AA6-8514-3E30F217B1BE} - System32\Tasks\{E56CE78F-3DF9-4305-8336-77785549E0F4} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {542676B6-E1CE-4B5C-BDF2-C00ECFB38DBC} - System32\Tasks\{42963256-E132-413E-A4D9-4AD87B590641} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {543E71B8-E7BE-4FDA-AD19-CC490CA91848} - System32\Tasks\{09D857DD-F75F-4669-84AC-9B2B4F91002A} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {561375CB-FF5A-417B-B297-BA73DE149581} - System32\Tasks\Microsoft\Windows\Wired\GatherWiredInfo => C:\Windows\system32\gatherWiredInfo.vbs
Task: {576416B1-5229-4BB5-8F5F-5EB4CE34693A} - System32\Tasks\{0AD9175A-E960-4F4A-B254-A7FFF532194A} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.)
Task: {592F7F57-9C8F-4F5D-9A75-D8444CAF5A34} - System32\Tasks\{3A608F0C-88F6-4101-A24D-5888FB4E1675} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {5B3DB1D0-2D67-4C1C-BA0C-73372A98F89C} - System32\Tasks\{8B5019D5-0BD6-4708-A1CA-DE33DAF12937} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {5CC8A7A0-EB94-45A9-8C14-10D1FA017AA5} - System32\Tasks\{D6670E02-8F5A-46ED-BFE4-8AEF911AB2FE} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {5D8E271A-4247-422B-BB0B-A0F60CD4F2EE} - System32\Tasks\{CF4F2AC7-7291-4854-8184-33979FBEEA3A} => C:\Program Files\Logitech\Profiler\LWEMon.exe [2004-05-19] (Logitech Inc.)
Task: {6997CFAE-6B39-4219-A1BB-BFCA1A25B735} - System32\Tasks\ACMON => C:\Program Files\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK)
Task: {6BCBF903-EFC8-4841-A00B-8A98F9B42040} - System32\Tasks\{5F24C263-DED9-48A3-85E4-2AF0241EDD56} => pcalua.exe -a C:\PROGRA~1\Stardock\OBJECT~1\DesktopX\UNWISE.EXE -c C:\PROGRA~1\Stardock\OBJECT~1\DesktopX\INSTALL.LOG
Task: {6C2BAF56-D5B0-4D25-BFA4-8A03090E90F4} - System32\Tasks\{35BF4035-207B-4DDB-A7D9-DAE7569EA9A7} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {6C7963B0-501B-464F-85BB-0F1A98CB0EE2} - System32\Tasks\{ACD04780-E85C-4752-806D-C7E0B65CA043} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {6FAF6F7D-1CDF-4408-A9E7-F480AFD09927} - System32\Tasks\{224E176B-C279-4E30-BFAC-74EDBD3DF2AA} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {71707D88-0843-4073-AFAC-21043703B9B5} - System32\Tasks\{B5BE686C-6877-4712-B359-6260EE6BAA94} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {72ED54C5-EAAC-4283-858E-E531B2490992} - System32\Tasks\{795C6E6E-FAAA-4431-A918-937A78C53BB2} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {7585CE6A-F9B1-4E6E-856F-617D6D00D54C} - System32\Tasks\Net4Switch => C:\Program Files\ASUS\Net4Switch\Net4Switch.exe [2007-11-20] (ASUS)
Task: {79B505CA-4391-4F82-93B8-F6A10F007D29} - System32\Tasks\{E9F1D326-BB8E-416E-A09B-6DEFFC535CE7} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {7B9BD304-C851-42BA-B29B-8832C02B513D} - System32\Tasks\{AA91F360-BE81-48A9-9CFE-2565918BACBC} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.)
Task: {7BBE44D8-A420-4877-91D3-43AD4DF8740A} - System32\Tasks\{99B1E97F-436E-4429-ABA3-7E618A478667} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {805902FB-18D4-403F-9263-0624A07154E2} - System32\Tasks\{1648ED5A-2D13-4C52-AE7C-31297200C10D} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {839450A1-1065-490A-BB58-7CFB79EDF0D6} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {85417455-F0F1-41C5-8316-B8DFEB8C8918} - System32\Tasks\{1A5C41D9-30DC-4783-B8B0-CEC6F0B3E839} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {86094599-821F-4E9B-8E55-9AF40185191E} - System32\Tasks\{ED62F36F-605A-4AE1-8208-FD5CA76699B4} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe
Task: {8B3014D9-EB90-4483-B8E6-B492402A6DF0} - System32\Tasks\{12845C94-D0B6-4BDA-A9FB-5B154245A6D4} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {8DBA4AC8-B6E1-4E21-92E1-6F5BD04CBC59} - System32\Tasks\{805913F2-AD7E-416D-BA65-5BCB278D42E1} => C:\Program Files\LEGO Schach\Lego Chess.exe
Task: {8EAD5D19-6EF9-4FAD-91E1-C759DDC095FA} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {8FB70F6E-172F-42D9-AD4A-91E5AFF5A7B5} - System32\Tasks\{20881F0F-F213-4B1D-AC68-02FABF50C1CE} => C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe [2000-05-31] (Krisalis Software Ltd.)
Task: {9057296A-F885-41B1-8E01-EF575CEF376C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: {90FFF327-1728-488D-BE4E-FA1232DD7BB6} - System32\Tasks\{14EDE9BC-20F9-4EFA-AC7D-6EB4C5A76C71} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {99C2E64D-3C78-4488-8CF3-672D6E3DB446} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13] (Dropbox, Inc.)
Task: {99C91901-9432-4EA7-87F8-55A525B95ABA} - System32\Tasks\{E2D1EE7B-E7AD-4C2D-AAB0-AC383A6F07CC} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.)
Task: {A0215012-5C94-40CA-9A43-2F200B61A4A2} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004UA => C:\Users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17] (Dropbox, Inc.)
Task: {A0EC8CE0-03D7-4A0E-A8FA-0380AF2A1FF0} - System32\Tasks\{D884D7E7-64A4-45DE-98FD-56D8596FCD34} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {A33BE22C-702F-4129-AB69-5361B36F2500} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {A93B8A4D-244F-453C-9B10-DB60E36A1C57} - System32\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE [2013-02-28] (SEIKO EPSON CORPORATION)
Task: {A9443690-748A-45F1-8D64-6AA0294F58AE} - System32\Tasks\{A5E9A2AB-D783-444B-ACEA-988C9C2827BD} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {AC093D78-AE53-48AF-A35E-7E570F6D5649} - System32\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE [2013-02-28] (SEIKO EPSON CORPORATION)
Task: {B22899B8-49AC-43DA-B2BF-CCB47C542539} - System32\Tasks\{37C1FFED-5F13-4EA4-B8E0-FBC3039B59DA} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe
Task: {B2FDDA94-D222-4673-A9AF-CAE32F13265A} - System32\Tasks\{57123DD4-3701-4890-8F5E-69253F2A254E} => C:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe
Task: {B3B4709A-B606-4F54-A90A-116F93D8512E} - System32\Tasks\ASPG => C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS)
Task: {B7D4A3DB-3927-46B0-A840-174630359DE6} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files\ASUS\SmartLogon\sensorsrv.exe [2009-05-18] (ASUS)
Task: {BDC925F9-1584-4227-BF87-557F6DC13464} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004Core => C:\Users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17] (Dropbox, Inc.)
Task: {BF436BB1-3885-496D-B203-C36CFA947E53} - System32\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE [2013-02-28] (SEIKO EPSON CORPORATION)
Task: {C01F96CD-E814-4B3B-8ADB-B61746C44F27} - System32\Tasks\{47B8FC20-7DB8-48A6-83BC-E7C34E62CC8B} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {C361CDD7-C67A-4CB4-A515-59B3F225DF8C} - System32\Tasks\{6C5CE7EA-6EC5-497C-8FAE-8DDE494754CC} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {C6D305DC-A5B7-4BD2-B434-64B58E96E1B9} - System32\Tasks\{83270C1C-EFD0-435A-B354-DB444A4E64F7} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe
Task: {C71C0104-D3E3-49D0-886E-850A0EA0A519} - System32\Tasks\{629DDE4B-7DAE-4321-B366-19139E71F9C4} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {CCCDE7C4-AC7C-4DD5-98AB-1DDF96CC1A00} - System32\Tasks\{5E36B9A2-EA7B-4338-B839-BA06E700C7A7} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {D2D316AA-04AB-4C85-B4E6-0FFA7C1B5CAD} - System32\Tasks\{897420D6-2E83-4F0C-9542-4235DE3ADD9D} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {D428F363-CD1D-4CEC-BCFD-7895783F2746} - System32\Tasks\{740C00F2-0AF4-462D-B602-FAA959059F5E} => C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe [2000-05-31] (Krisalis Software Ltd.)
Task: {D943FB3E-EB45-43CD-91A6-A055E15CE059} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: {DA81BBC7-677C-4A44-A056-CB90DC977864} - System32\Tasks\{0D730403-F736-400F-B631-19B8BC0E1E30} => C:\Program Files\EA Sports\FIFA 09\FIFA09.exe [2008-10-23] ()
Task: {DB85DFE2-B398-4D92-BA2A-821880861383} - System32\Tasks\{846920E1-73B4-4C1B-801F-BA087FE5EEF8} => C:\Program Files\LEGO Schach\Lego Chess.exe
Task: {DC34DD92-92FA-4E52-A136-C3C2FC249AE5} - System32\Tasks\{9D61A73B-0DE2-48FE-A2B3-088709BD7D2C} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {DC6CEF1A-D549-42B2-87D2-274BEC35D662} - System32\Tasks\{C1FB456D-5102-4D69-A102-59FBB9C799C1} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {DE31F299-BD40-4A25-BB8A-10EC1ADC4783} - System32\Tasks\{E39103FF-9002-43CF-B483-1326522EF959} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs
Task: {E54FD084-9DE3-498A-8ECB-F723F22FAB84} - System32\Tasks\{A48CA2AC-8CD3-4B01-9BD2-E56D49ADD8F7} => C:\Program Files\EA Sports\FIFA 09\FIFA09.exe [2008-10-23] ()
Task: {E5AB5213-9D14-427E-BF04-B685E363ABF9} - System32\Tasks\{F8DD370C-1C9B-4B99-A221-D936EDE7FDAD} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe
Task: {E61935EA-A141-496D-BA9E-CF4C3EF3795D} - System32\Tasks\{3CB8A215-9260-42B8-8D9B-FA81017EED9A} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {E9BFC740-3580-4EA6-9861-89784029CF48} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
Task: {EDFDEDC0-7152-4BC4-8E7A-2D96E5C6D8D7} - System32\Tasks\{6DD7CCD6-3D1C-4DA7-B895-4F4F95745358} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {EEA6A0A0-E1CD-4583-B178-0690064E5D8F} - System32\Tasks\{EE69846A-E56D-493D-B5DA-858DE7FA218B} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {F74F66A2-BA11-4AEC-A516-F153CDCD3451} - System32\Tasks\{2EF7C677-995A-413F-93CA-F39A6D35363C} => C:\Program Files\Ford Racing 2\fr2.exe
Task: {F7E36632-B92F-40E5-8FDF-60225CFB5CB3} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Jeffel => C:\Program Files\Windows Calendar\WinCal.exe
Task: {F8E4E8A9-959E-4214-8706-20AE311FFA86} - System32\Tasks\{D1117AB3-5D96-42EF-8AE2-EE14F8692D60} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe
Task: {F8EF940F-03BD-46F5-A998-1540C6587472} - System32\Tasks\{FB7C2341-6721-4B95-A6AE-136D881A01F3} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe
Task: {F9428F41-B2CF-431B-8A33-32AD9E73E88C} - System32\Tasks\{BF78135C-D9BB-42BD-8E6A-0FBBC5ACA700} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe
Task: {FD11DEA1-27EB-480A-ADD0-60B1E33E6B31} - System32\Tasks\{DA19A5B2-B0BB-49BA-854B-43FECBBC9387} => C:\Program Files\Logitech\Profiler\LWEmon.exe [2004-05-19] (Logitech Inc.)
Task: {FD3008D4-9573-44C7-B144-BA5C02B4BFCA} - System32\Tasks\{3E7DE8B7-79CA-4BC7-A84E-390073C4E375} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004Core.job => C:\Users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004UA.job => C:\Users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE
Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE:/EXE:{5ED40A39-9E20-4A57-9853-44602CD12F7A} /F:UpdateSYSTEM
Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\Windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE
Task: C:\Windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE:/EXE:{00F3F166-48F4-41CC-97B5-0BCDE58D612F} /F:UpdateSYSTEM
Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2007-06-15 11:28 - 2007-06-15 11:28 - 00147456 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll
2007-06-01 18:08 - 2007-06-01 18:08 - 00143360 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
2010-01-01 12:48 - 2009-12-12 16:12 - 00141824 _____ () C:\Program Files\WinRAR\rarext.dll
2011-07-18 23:04 - 2011-07-18 23:04 - 00296448 _____ () C:\Program Files\Notepad++\NppShell_04.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Jeffel\Desktop\1.avi:TOC.WMV
AlternateDataStreams: C:\Users\Jeffel\Desktop\2.avi:TOC.WMV
AlternateDataStreams: C:\Users\Jeffel\Desktop\3.avi:TOC.WMV

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-644356114-2566177158-2502637254-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\Beamer\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-644356114-2566177158-2502637254-1008\Control Panel\Desktop\\Wallpaper -> C:\Users\Ellen & Manuel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-644356114-2566177158-2502637254-1011\Control Panel\Desktop\\Wallpaper -> C:\Users\Manuel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.177.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: ATKGFNEXSrv => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: BstHdAndroidSvc => 3
MSCONFIG\Services: BstHdLogRotatorSvc => 3
MSCONFIG\Services: BstHdUpdaterSvc => 3
MSCONFIG\Services: bthserv => 3
MSCONFIG\Services: ehRecvr => 3
MSCONFIG\Services: ehSched => 3
MSCONFIG\Services: EpsonScanSvc => 2
MSCONFIG\Services: FirebirdServerMAGIXInstance => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: gusvc => 3
MSCONFIG\Services: IEEtwCollectorService => 3
MSCONFIG\Services: IJPLMSVC => 3
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: MDES => 2
MSCONFIG\Services: MyPublicWiFiService => 2
MSCONFIG\Services: Origin Client Service => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: spmgr => 2
MSCONFIG\Services: ss_conn_service => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk => C:\Windows\pss\FancyStart daemon.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AlcoholAutomount => "D:\Alcohol 120\axcmd.exe" /automount
MSCONFIG\startupreg: AmIcoSinglun => C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: ASUS Camera ScreenSaver => C:\Windows\AsScrProlog.exe
MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\ASScrPro.exe
MSCONFIG\startupreg: ASUSTPE => C:\Windows\system32\ASUSTPE.exe
MSCONFIG\startupreg: AVMUSBFernanschluss => "C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\AVMAutoStart.exe"
MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CanonSolutionMenu => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: CLMLServer => "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: DAEMON Tools Lite => "D:\DT\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: KiesTrayAgent => D:\Samsung Kies\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Steam => "D:\Steam\steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => C:\Program Files\Common Files\Java\Java Update\jusched.exe
MSCONFIG\startupreg: UpdateLBPShortCut => "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
MSCONFIG\startupreg: UpdateP2GoShortCut => "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{98B426BE-4154-48E7-A940-C28AD6AB3C7E}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{A0ED8D77-C475-4A7C-9683-E33EF6CA08AE}] => (Allow) svchost.exe
FirewallRules: [{5A959ABA-B81C-408F-9BF9-A382D827ED17}] => (Allow) C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [TCP Query User{92FF86AB-5408-4239-86CD-713C52CC5E72}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe
FirewallRules: [UDP Query User{756D4762-70FE-4F03-9A42-0F627F10CBF8}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe
FirewallRules: [TCP Query User{F15C73F2-09B2-4D70-B6C1-FCB8C6C3077A}C:\program files\google\google earth\client\googleearth.exe] => (Block) C:\program files\google\google earth\client\googleearth.exe
FirewallRules: [UDP Query User{3518798C-9464-4B02-B79D-33060DE82A80}C:\program files\google\google earth\client\googleearth.exe] => (Block) C:\program files\google\google earth\client\googleearth.exe
FirewallRules: [TCP Query User{F87691B0-9C93-4349-8E2B-69BF1B0D816D}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{0756E3CD-F4D3-4373-BCB1-583FDDA22919}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{6939840F-897B-42B5-8E48-6E97937198B0}] => (Allow) svchost.exe
FirewallRules: [{59E3FF2C-493B-4937-9A37-DA9D1CAAFC4B}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [TCP Query User{A1DE6356-BBC4-48A8-B039-88DEB224609A}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{E3168A96-5F5E-4485-AD0D-7AE6A2596564}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{4AF10D0E-C4C1-40A2-936B-C6F2AB12613B}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [UDP Query User{88D7FF05-F79E-4946-A853-288BD573E814}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [TCP Query User{9EFEAB5F-7210-4BC7-8BA8-231FA6D585A1}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe
FirewallRules: [UDP Query User{375FCB23-571C-4F84-90FE-A0670DEAAC49}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe
FirewallRules: [{55E52E7C-FD6E-4517-8357-F6D71154371A}] => (Allow) C:\Users\Jeffel\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{9C447FBD-4CD0-4507-918C-C3C1FC1BC0BC}] => (Allow) C:\Users\Jeffel\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{424B5F96-6253-4B19-824F-7157B91CE53C}C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{A3FECD29-88C2-49EE-9826-78B12649C757}C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{5518E9F3-F3DC-433F-9E50-A930A0CD15F2}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe
FirewallRules: [UDP Query User{55697CCA-A2DB-4C9F-8442-8DC6C36139AA}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe
FirewallRules: [TCP Query User{3E55C8FD-D431-4830-8F71-22F2B69255C3}C:\program files\ea sports\fifa 09\fifa09.exe] => (Allow) C:\program files\ea sports\fifa 09\fifa09.exe
FirewallRules: [UDP Query User{6B39FD39-72B8-4683-9E30-4221DEFAD5D9}C:\program files\ea sports\fifa 09\fifa09.exe] => (Allow) C:\program files\ea sports\fifa 09\fifa09.exe
FirewallRules: [TCP Query User{EF7EF825-131B-4165-A892-9DEC02FC688F}E:\easysetupassistant\wr841n\easysetupassistant.exe] => (Allow) E:\easysetupassistant\wr841n\easysetupassistant.exe
FirewallRules: [UDP Query User{25BF93E3-CEFC-4077-972C-637BBD3D8D23}E:\easysetupassistant\wr841n\easysetupassistant.exe] => (Allow) E:\easysetupassistant\wr841n\easysetupassistant.exe
FirewallRules: [{BE0F663E-C815-4563-A897-646E54E5E075}] => (Block) E:\easysetupassistant\wr841n\easysetupassistant.exe
FirewallRules: [{C1AD54B1-3E4E-48CD-AA59-46A81630CED6}] => (Block) E:\easysetupassistant\wr841n\easysetupassistant.exe
FirewallRules: [TCP Query User{642462DC-FE55-4283-B3BE-5116D1ABD2D1}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{1543EF59-9BDC-45F3-98C1-666138EE2360}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{F42F3A51-5E79-42CD-97EC-8F46AFB3AEDA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3AF441F6-2448-4E93-AF29-F00F2983A81B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{3A83D0B7-CC23-4E0A-A47F-BA4C727DA59B}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{A30C3FCC-E865-487C-BB2B-94503E562E57}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{C5B4D7F3-5ACD-4113-B7F8-EF24617B930D}] => (Allow) D:\OriginGames\Need for Speed World\GameLauncher.exe
FirewallRules: [{54FB9595-0BFB-47AF-866A-250C8D7B1BAF}] => (Allow) D:\OriginGames\Need for Speed World\GameLauncher.exe
FirewallRules: [{9E1C364E-EA27-4082-AB13-FBEBC90590BA}] => (Allow) D:\OriginGames\Battlefield 1942\BF1942.exe
FirewallRules: [{2EB3B6C7-04D1-43DF-B4B0-B47348DBCD68}] => (Allow) D:\OriginGames\Battlefield 1942\BF1942.exe
FirewallRules: [{DBB13B95-B032-45C2-A416-2E496104A650}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{5456B4DC-0D08-476B-B4CB-8BA97886248B}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{B3C9C811-6617-41F7-8833-D1B66AC7C967}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [TCP Query User{FB78B67C-4DFB-45DA-8910-73B460C08EE9}D:\needforspeed world\data\nfsw.exe] => (Allow) D:\needforspeed world\data\nfsw.exe
FirewallRules: [UDP Query User{514C9672-18B4-476C-B568-2B1D2211DC21}D:\needforspeed world\data\nfsw.exe] => (Allow) D:\needforspeed world\data\nfsw.exe
FirewallRules: [{122DB7AB-303C-4A23-8984-A4089D07A519}] => (Allow) D:\Steam\SteamApps\common\f12013\F1_2013.exe
FirewallRules: [{BA4A4B55-61BE-49C7-B106-9CF16C1FEFCA}] => (Allow) D:\Steam\SteamApps\common\f12013\F1_2013.exe
FirewallRules: [{852A6D93-68A1-49D2-A427-091873A0F8AF}] => (Allow) D:\OriginGames\Plants vs. Zombies\PlantsVsZombies.exe
FirewallRules: [{1C423230-E993-447A-B8BC-B011BD1ABEA4}] => (Allow) D:\OriginGames\Plants vs. Zombies\PlantsVsZombies.exe
FirewallRules: [{5476BAD2-AE20-42B2-BFC6-58B987D9EC81}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{812E2119-243A-400E-B7FE-DEB6D62808AB}] => (Allow) D:\OriginGames\SimCity\SimCity\SimCity.exe
FirewallRules: [{2C4E33E9-EDDF-4059-9790-647FCF83145D}] => (Allow) D:\OriginGames\SimCity\SimCity\SimCity.exe
FirewallRules: [TCP Query User{60D69111-FE19-4415-B387-D97AE26AFD38}C:\program files\tmnationsforever\tmforever.exe] => (Block) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [UDP Query User{F2DF262E-FF7C-484F-AA4E-63FF8880305C}C:\program files\tmnationsforever\tmforever.exe] => (Block) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [{A3C3ECE5-F0B8-458B-BF51-A7F6BF8F5E0E}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{DAA3B140-1FED-47B5-9F25-FB8F35548A03}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{F14B2E24-FBC1-4546-BBB6-CCBF3E3C26CB}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe
FirewallRules: [{1EBAA986-ABD7-469D-8126-C6A22AB47DCF}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe
FirewallRules: [TCP Query User{DF57783D-CA97-4654-B267-AC96484B730F}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{695F1F23-F5F2-4E3A-93D3-C046C30B108D}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [TCP Query User{18759B6E-98BA-4489-983D-ABCF93CE30A2}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{C48C23E4-CF37-4289-AC60-2FF3F377ACD4}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [{BAE39D93-BC07-4545-A838-D128E5D729B1}] => (Allow) C:\Users\Philipp\AppData\Local\Apps\2.0\AKHGTRNK.DG4\BWYE0CZZ.LL7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{BDC2FD03-237D-49E4-A6A2-8AE3211FB11A}] => (Allow) C:\Users\Philipp\AppData\Local\Apps\2.0\AKHGTRNK.DG4\BWYE0CZZ.LL7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{2A33F55E-5BBB-4A44-9852-D7FEA360081E}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{084ED6E8-0CDB-42C1-9716-21D9E1E099C3}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [TCP Query User{5A171416-5B5C-45E6-A06C-FD51ECCBBA01}C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe] => (Block) C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [UDP Query User{EC3DF4E2-12D4-4BEA-9E53-8BD42E933EE3}C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe] => (Block) C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{B3F421E8-5795-4576-A04B-678154A5D42C}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{56B79544-76F5-4B6F-85BD-3CA9415A0BE3}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [TCP Query User{A674A672-4708-4C05-A7DD-7FC78F2ABAD6}C:\program files\unified remote\remoteserver.exe] => (Allow) C:\program files\unified remote\remoteserver.exe
FirewallRules: [UDP Query User{C42108C2-C11D-4BCD-848F-C882C383AFF1}C:\program files\unified remote\remoteserver.exe] => (Allow) C:\program files\unified remote\remoteserver.exe
FirewallRules: [{66918B97-AE64-444C-9DB6-5DB605AE12F7}] => (Allow) D:\OriginGames\Bejeweled 3\Bejeweled3.exe
FirewallRules: [{4D93D20E-753C-494E-8FA6-F47CF535E417}] => (Allow) D:\OriginGames\Bejeweled 3\Bejeweled3.exe
FirewallRules: [{100DFB51-03A7-409A-8436-B1ADEDE290A7}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{3D1CFBF6-1099-4721-A86E-438E12C875EA}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{708B5EAF-95EC-428E-9AA3-7F8A3CC499D7}] => (Allow) D:\OriginGames\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe
FirewallRules: [{252252F8-D1E0-473A-8A33-743C157FAAAB}] => (Allow) D:\OriginGames\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe
FirewallRules: [{12369EEC-4B3E-4804-8395-3B1EE1D1F377}] => (Allow) C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe
FirewallRules: [{23965B5B-2D1F-4BC2-82F2-4E012CDB6110}] => (Allow) C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe
FirewallRules: [{8AD425C4-E4CD-4E0A-B470-71C0186D4419}] => (Allow) D:\OriginGames\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe
FirewallRules: [{79468976-3ED7-4AAD-8CDF-CC32C20626C3}] => (Allow) D:\OriginGames\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe
FirewallRules: [{98C0D637-E762-4100-8AF8-3E756C54A265}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe
FirewallRules: [{533B5FB5-1CB8-4776-8F97-B9D35616A215}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe
FirewallRules: [{D67CAA53-7942-4A91-8D54-03DE16AF77AA}] => (Allow) D:\Steam\SteamApps\common\ConSim2015\ConSim2015.exe
FirewallRules: [{085EB9AF-D4B4-42D7-AA85-2FF13C776871}] => (Allow) D:\Steam\SteamApps\common\ConSim2015\ConSim2015.exe
FirewallRules: [{13EC435C-D4A0-4045-9736-20D5C2A52E0F}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{766D54AC-FE82-4990-81C9-4B3E62FC1D8E}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe
FirewallRules: [{8147F4AA-6FEE-48F5-A257-DADCA6B3D1F7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{B59D5117-8BF8-4401-A031-594855C5359E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{C3A2EE98-6FD7-4841-986B-5FF483452073}] => (Allow) D:\OriginGames\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{7894DF2C-B685-420A-810A-505E1663461E}] => (Allow) D:\OriginGames\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{AB875D33-F535-45C7-83AD-4542A38F0A9A}] => (Allow) D:\OriginGames\Syndicate (1993)\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{C8819052-499D-4060-A2CB-63C85B7289F3}] => (Allow) D:\OriginGames\Syndicate (1993)\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [TCP Query User{2405E39F-611A-4841-8667-B7FAB332ED13}D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{98A5CF53-9EE7-4592-86E6-5A255E971ED4}D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{42389642-E7E4-4FA7-99F0-D17483626C6F}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{546675B7-4D5D-41B0-A82B-3C2AE0AED9AE}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{F4820325-C52D-4F14-B0C1-E2F40210A513}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft3077.tmp\fsetup.exe
FirewallRules: [{F8A2199B-EA6F-43B4-BF29-FC040CE4901D}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft3077.tmp\fsetup.exe
FirewallRules: [{0CB53765-513D-49DE-87C5-AECA2C3658C1}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pftAA65.tmp\fsetup.exe
FirewallRules: [{C88A6BB6-DBFF-4572-AA49-2F5929892EA3}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pftAA65.tmp\fsetup.exe
FirewallRules: [{13D83860-A9E7-48A7-A64E-3D805CB1B574}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft96D1.tmp\fsetup.exe
FirewallRules: [{4DDF4814-C41E-4164-81FB-D9C60F8AD319}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft96D1.tmp\fsetup.exe
FirewallRules: [{7870E46B-69E5-4524-B2E7-ECEB9E6D710D}] => (Allow) C:\Program Files\iTunes\iTunes.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/19/2015 07:49:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/18/2015 04:34:58 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/17/2015 08:04:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: gimp-2.8.exe, Version: 2.8.14.0, Zeitstempel: 0x00000000
Name des fehlerhaften Moduls: libpixman-1-0.dll, Version: 0.0.0.0, Zeitstempel: 0x0072a5f0
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00084b3b
ID des fehlerhaften Prozesses: 0x1338
Startzeit der fehlerhaften Anwendung: 0xgimp-2.8.exe0
Pfad der fehlerhaften Anwendung: gimp-2.8.exe1
Pfad des fehlerhaften Moduls: gimp-2.8.exe2
Berichtskennung: gimp-2.8.exe3

Error: (06/17/2015 06:29:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/17/2015 06:12:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/17/2015 01:38:25 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2015 08:32:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 38.0.5.5623, Zeitstempel: 0x5563c49a
Name des fehlerhaften Moduls: mozalloc.dll, Version: 38.0.5.5623, Zeitstempel: 0x5563b229
Ausnahmecode: 0x80000003
Fehleroffset: 0x00001aa1
ID des fehlerhaften Prozesses: 0x1264
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3

Error: (06/16/2015 04:55:48 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.


Vorgang:
   Generatordaten werden gesammelt

Kontext:
   Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Generatorname: System Writer
   Generatorinstanz-ID: {24c98460-576e-4efe-898a-0f7fbfad98d1}

Error: (06/16/2015 03:35:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2015 01:48:07 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15585


System errors:
=============
Error: (06/19/2015 07:57:58 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "WMI-Leistungsadapter" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (06/19/2015 07:57:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "FABS - Helping agent for MAGIX media database" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (06/19/2015 07:57:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (06/19/2015 07:57:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Software Protection" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (06/19/2015 07:57:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Modules Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (06/19/2015 07:57:28 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "MBAMService" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (06/19/2015 07:57:28 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "MBAMScheduler" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (06/19/2015 07:57:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Adobe Acrobat Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (06/19/2015 07:57:26 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (06/19/2015 07:57:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "ASLDR Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


Microsoft Office:
=========================
Error: (06/19/2015 07:49:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/18/2015 04:34:58 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/17/2015 08:04:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: gimp-2.8.exe2.8.14.000000000libpixman-1-0.dll0.0.0.00072a5f0c000000500084b3b133801d0a9279a9e94e3D:\GIMP 2\bin\gimp-2.8.exeD:\GIMP 2\bin\libpixman-1-0.dll432e3355-151b-11e5-ac41-002618f9ca5d

Error: (06/17/2015 06:29:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/17/2015 06:12:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/17/2015 01:38:25 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2015 08:32:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe38.0.5.56235563c49amozalloc.dll38.0.5.56235563b2298000000300001aa1126401d0a85c270b00cdC:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dll03eedcfa-1456-11e5-9a84-002618f9ca5d

Error: (06/16/2015 04:55:48 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Zugriff verweigert


Vorgang:
   Generatordaten werden gesammelt

Kontext:
   Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Generatorname: System Writer
   Generatorinstanz-ID: {24c98460-576e-4efe-898a-0f7fbfad98d1}

Error: (06/16/2015 03:35:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/16/2015 01:48:07 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15585


==================== Memory info =========================== 

Processor: Intel(R) Core(TM)2 Duo CPU T6500 @ 2.10GHz
Percentage of memory in use: 43%
Total physical RAM: 3071.27 MB
Available physical RAM: 1744.06 MB
Total Pagefile: 6140.86 MB
Available Pagefile: 4361.31 MB
Total Virtual: 3071.88 MB
Available Virtual: 2927.84 MB

==================== Drives ================================

Drive c: (VistaOS) (Fixed) (Total:149.04 GB) (Free:31.61 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:137.33 GB) (Free:72.24 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 97646C29)
Partition 1: (Not Active) - (Size=11.7 GB) - (Type=1C)
Partition 2: (Active) - (Size=149 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=137.3 GB) - (Type=OF Extended)

==================== End of log ============================
         
--- --- ---

--- --- ---

Alt 20.06.2015, 12:13   #13
schrauber
/// the machine
/// TB-Ausbilder
 

DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 23.06.2015, 05:54   #14
flowerwithlo
 
DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



Ok,

ESET:
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c0c7fff54a27634f9d2006f27ed8248f
# end=init
# utc_time=2015-06-22 03:07:09
# local_time=2015-06-22 05:07:09 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c0c7fff54a27634f9d2006f27ed8248f
# end=init
# utc_time=2015-06-22 05:29:26
# local_time=2015-06-22 07:29:26 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c0c7fff54a27634f9d2006f27ed8248f
# end=init
# utc_time=2015-06-22 05:31:14
# local_time=2015-06-22 07:31:14 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 24446
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c0c7fff54a27634f9d2006f27ed8248f
# end=updated
# utc_time=2015-06-22 05:33:54
# local_time=2015-06-22 07:33:54 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=c0c7fff54a27634f9d2006f27ed8248f
# engine=24446
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-06-23 12:37:48
# local_time=2015-06-23 02:37:48 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 209274 186651059 0 0
# scanned=432286
# found=10
# cleaned=0
# scan_time=25434
sh=3DC2837E9E894C9B971C4DAC9F27C43561C49738 ft=1 fh=f4e11a8294dd61e1 vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Beamer\Downloads\aTube_Catcher.exe"
sh=4CDFFCF08191640A9E441DB241BFD5ABE063742B ft=1 fh=a9082013fbdd22a7 vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Jeffel\Downloads\aTube_Catcher_Setup.exe"
sh=D48DFC2287A65BAF685CD674711BF2CD0A784ADB ft=1 fh=466a3dc1051aac66 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manuel\Downloads\CTcontrol - CHIP-Installer.exe"
sh=D0607EC2B0E991266F690760AE3C67E67ED29B75 ft=0 fh=0000000000000000 vn="Win32/WinloadSDA.C evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-04-25 121650\Backup files 1.zip"
sh=6C46740394AD406A1D35EDDA92FA7B9C2607C267 ft=0 fh=0000000000000000 vn="Win32/FileScout.A evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-04-25 121650\Backup files 108.zip"
sh=E27CEEBCE8F58480E7559E8A1AB70327CC60605F ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-04-25 121650\Backup files 111.zip"
sh=681014B2F904CB93D37DD1691A11D65A67F86B08 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-04-25 121650\Backup files 124.zip"
sh=F263C95C1DEA2C00F1A1096FD49334DACBADF053 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-04-25 121650\Backup files 98.zip"
sh=1BBABDBD8C8F180AA3D2145384B77DE24C3F86F9 ft=0 fh=0000000000000000 vn="Variante von Win32/GetNow.D evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-11-29 223933\Backup files 39.zip"
sh=D096D8035843F8307DDB86D02A31C11C47C2D271 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-11-29 223933\Backup files 43.zip"
         
Security Check: (Java buggt irgendwie rum und ist eigentlich gar nicht mehr installiert)
Code:
ATTFilter
 Results of screen317's Security Check version 1.002  
 Windows 7 Service Pack 1 x86 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
Avira Antivirus   
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 CCleaner     
 Java version 32-bit out of Date! 
 Adobe Flash Player 	17.0.0.188  
 Adobe Reader XI  
 Mozilla Firefox (38.0.5) 
````````Process Check: objlist.exe by Laurent````````  
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 Avira Antivir avgnt.exe 
 Avira Antivir avguard.exe 
 mbamscheduler.exe    
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         

Alt 23.06.2015, 12:16   #15
schrauber
/// the machine
/// TB-Ausbilder
 

DHL Spam Mail -> Trojaner/Virus? - Standard

DHL Spam Mail -> Trojaner/Virus?



und der Rest?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu DHL Spam Mail -> Trojaner/Virus?
avira, board, fehlalarme, frage, gefunde, klick, kurzem, mail, nicht mehr, pdf, quara, quarantäne, runter, spam, spam mail, spammail, suchlauf, troja, trojaner, trojaner board, trojaner/virus, vater, virus, woche, wochen




Ähnliche Themen: DHL Spam Mail -> Trojaner/Virus?


  1. Aus Spam-Mail Link Trojaner Mal/DrodZp-A gefangen?
    Log-Analyse und Auswertung - 08.03.2015 (7)
  2. Spam-Mail mit Virus oder echte Rechnung?
    Plagegeister aller Art und deren Bekämpfung - 26.02.2015 (7)
  3. Spam-Mail als Teil einer abgeschlossenen E-Mail-Konversation!
    Überwachung, Datenschutz und Spam - 23.01.2015 (1)
  4. Android: ELSTER-Spam-Mail geöffnet (angebliche Mail v. Finanzamt)
    Plagegeister aller Art und deren Bekämpfung - 24.09.2014 (3)
  5. ELSTER Spam-Mail geöffnet (angebliche Mail v. Finanzamt)
    Smartphone, Tablet & Handy Security - 23.09.2014 (5)
  6. Aol-Mail Account verschickt Spam - Trojaner?
    Log-Analyse und Auswertung - 27.02.2014 (1)
  7. E-mail Account verschickt Spam Mail mit Viren Anhang an alle Kontakte
    Log-Analyse und Auswertung - 29.10.2013 (16)
  8. Spam-Mail, Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 26.06.2013 (23)
  9. Verdacht auf Trojaner durch Spam Mail
    Plagegeister aller Art und deren Bekämpfung - 25.06.2013 (3)
  10. Ominöse Mail (mit Trojaner) in meinem GMX-Spam-Mail-Ordner
    Überwachung, Datenschutz und Spam - 07.04.2013 (3)
  11. Mail delivery failed-SPAM Mails. E-Mail-Acc kompromittiert?
    Plagegeister aller Art und deren Bekämpfung - 14.02.2013 (1)
  12. Trojaner mit Zahlungsaufforderung, Computer-Sperrung und Spam-Mail
    Plagegeister aller Art und deren Bekämpfung - 03.07.2012 (11)
  13. Spam-Mail von meiner web.de-E-Mail-Adresse an alle Kontakte gesendet
    Log-Analyse und Auswertung - 22.02.2012 (27)
  14. Windows Live Mail verschickt an irgendwelche Adressen haufenweise Spam über meine Mail-Addy
    Plagegeister aller Art und deren Bekämpfung - 28.12.2011 (18)
  15. Spam-Nachrichten von meinem E-Mail-Account verschickt - Befürchtung, daß ich 'nen Virus hab...
    Log-Analyse und Auswertung - 25.11.2011 (12)
  16. spam-mail über mein web.de-account versendet, spam-mail auch im gesendet Ordner
    Log-Analyse und Auswertung - 16.11.2011 (3)
  17. Rätsel für Euch: Kann Spam- Mail auf Virus auf Server verweisen?
    Plagegeister aller Art und deren Bekämpfung - 19.06.2004 (5)

Zum Thema DHL Spam Mail -> Trojaner/Virus? - Hallo liebes Trojaner Board Team, es kam vor kurzem eine DHL Spam Mail mit einem PDF Anhang. Mein Vater öffnete diese PDF und klickte darin evtl. (er weiß es nicht - DHL Spam Mail -> Trojaner/Virus?...
Archiv
Du betrachtest: DHL Spam Mail -> Trojaner/Virus? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.