|
Plagegeister aller Art und deren Bekämpfung: DHL Spam Mail -> Trojaner/Virus?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
15.06.2015, 15:45 | #1 |
| DHL Spam Mail -> Trojaner/Virus? Hallo liebes Trojaner Board Team, es kam vor kurzem eine DHL Spam Mail mit einem PDF Anhang. Mein Vater öffnete diese PDF und klickte darin evtl. (er weiß es nicht mehr genau, ist schon 2 Wochen her) auf einen Link. Habe nun mit Avira einen Suchlauf gemacht und er hat zwar was gefunden (6 was), es ist jedoch möglich, dass das nur Fehlalarme waren, hab sie auf jeden Fall in Quarantäne verschoben. Nun stellt sich für mich die Frage: Habe ich einen Trojaner/Virus bzw. wenn ja, wie bekomme ich diesen wieder runter? PS: Habe Win7 Hoffe ihr könnt mir helfen flowerwithlo Geändert von flowerwithlo (15.06.2015 um 16:20 Uhr) |
15.06.2015, 16:56 | #2 |
/// the machine /// TB-Ausbilder | DHL Spam Mail -> Trojaner/Virus? hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
15.06.2015, 17:41 | #3 |
| DHL Spam Mail -> Trojaner/Virus? Mein Benutzer ist kein Admin, soll ich den Scan dann einfach mit nem Admin-Konto ausführen (also bei "als Admin ausführen" einen anderen Admin auswählen) oder mein Konto als Admin machen?!
__________________Danke schon mal für deine Hilfe LG flowerwithlo So, hab den Scan jetzt einfach mal ohne Admin Rechte gemacht: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-06-2015 Ran by Philipp (ATTENTION: The logged in user is not administrator) on SCHEFFLER-PC on 15-06-2015 18:34:54 Running from C:\Users\Philipp\Desktop Loaded Profiles: Jeffel & Philipp & Beamer & Ellen & Manuel & Manuel (Available Profiles: Jeffel & Philipp & Beamer & Ellen & Manuel & Manuel) Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) Failed to access process -> smss.exe Failed to access process -> csrss.exe Failed to access process -> wininit.exe Failed to access process -> services.exe Failed to access process -> lsass.exe Failed to access process -> lsm.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> atiesrxx.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> ADSMSrv.exe Failed to access process -> AsLdrSrv.exe Failed to access process -> GFNEXSrv.exe Failed to access process -> spoolsv.exe Failed to access process -> sched.exe Failed to access process -> svchost.exe Failed to access process -> armsvc.exe Failed to access process -> avguard.exe Failed to access process -> AppleMobileDeviceService.exe Failed to access process -> mDNSResponder.exe Failed to access process -> svchost.exe Failed to access process -> escsvc.exe Failed to access process -> E_S60RP7.EXE Failed to access process -> svchost.exe Failed to access process -> DVMExportService.exe Failed to access process -> PublicWiFiService.exe Failed to access process -> spmgr.exe Failed to access process -> ss_conn_service.exe Failed to access process -> WLIDSVC.EXE Failed to access process -> Avira.ServiceHost.exe Failed to access process -> GoogleCrashHandler.exe Failed to access process -> WLIDSVCM.EXE Failed to access process -> WmiPrvSE.exe Failed to access process -> avshadow.exe Failed to access process -> svchost.exe Failed to access process -> SearchIndexer.exe Failed to access process -> alg.exe Failed to access process -> TrustedInstaller.exe Failed to access process -> wmpnetwk.exe Failed to access process -> FABS.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> dllhost.exe Failed to access process -> OSPPSVC.EXE Failed to access process -> svchost.exe Failed to access process -> WmiPrvSE.exe Failed to access process -> csrss.exe Failed to access process -> winlogon.exe Failed to access process -> atieclxx.exe Failed to access process -> BatteryLife.exe Failed to access process -> wcourier.exe Failed to access process -> HControl.exe Failed to access process -> ATKOSD.exe Failed to access process -> KBFiltr.exe Failed to access process -> WDC.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (ASUS) C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files\ASUS\ATK Media\DMedia.exe (AlcorMicro Co., Ltd.) C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe (ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe () D:\Gaming Maus\DareUMonitor.exe (SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\Event Manager\EEventManager.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-Agent.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Google) C:\Program Files\Google\Drive\googledrivesync.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATILEE.EXE (Dropbox, Inc.) C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Google) C:\Program Files\Google\Drive\googledrivesync.exe Failed to access process -> WmiPrvSE.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe (Valve Corporation) D:\Steam\Steam.exe (Valve Corporation) D:\Steam\bin\steamwebhelper.exe Failed to access process -> SteamService.exe (Valve Corporation) D:\Steam\bin\steamwebhelper.exe (Valve Corporation) D:\Steam\bin\steamwebhelper.exe Failed to access process -> SearchProtocolHost.exe Failed to access process -> svchost.exe Failed to access process -> SearchFilterHost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1549608 2009-08-17] (Synaptics Incorporated) HKLM\...\Run: [HControlUser] => C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM\...\Run: [ATKOSD2] => C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS) HKLM\...\Run: [ATKMEDIA] => C:\Program Files\ASUS\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS) HKLM\...\Run: [AmIcoSinglun] => C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe [233472 2009-07-31] (AlcorMicro Co., Ltd.) HKLM\...\Run: [ADSMTray] => C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [272952 2009-06-24] (ASUSTek Computer Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [730416 2015-06-11] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Dare-U mouse] => D:\Gaming Maus\DareUMonitor.exe [786432 2012-11-20] () HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1065024 2014-05-02] (SEIKO EPSON CORPORATION) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [BlueStacks Agent] => C:\Program Files\BlueStacks\HD-Agent.exe [884440 2015-05-28] (BlueStack Systems, Inc.) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.Systray.exe [130864 2015-05-21] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [DAEMON Tools Lite] => D:\DT\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [Steam] => D:\Steam\steam.exe [2892992 2015-06-04] (Valve Corporation) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [21969480 2015-05-19] (Google) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION) Lsa: [Notification Packages] scecli C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT Startup: C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-05-12] ShortcutTarget: Dropbox.lnk -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2011-03-30] ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-12-13] ShortcutTarget: Dropbox.lnk -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2011-03-31] ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ShellIconOverlayIdentifiers: [ADSMOverlayIcon] -> {A825576B-0042-4F0F-8FB0-93CE0F054E69} => C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll [2007-06-15] () ShellIconOverlayIdentifiers: [ADSMOverlayIcon1] -> {A8D448F4-0431-45AC-9F5E-E1B434AB2249} => C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll [2007-06-01] () ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) GroupPolicyUsers\S-1-5-21-644356114-2566177158-2502637254-1004\User: Group Policy Restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com/ HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://www.google.de/ URLSearchHook: [S-1-5-21-644356114-2566177158-2502637254-1000] ATTENTION ==> Default URLSearchHook is missing. URLSearchHook: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File URLSearchHook: [S-1-5-21-644356114-2566177158-2502637254-1005] ATTENTION ==> Default URLSearchHook is missing. URLSearchHook: [S-1-5-21-644356114-2566177158-2502637254-1008] ATTENTION ==> Default URLSearchHook is missing. URLSearchHook: [S-1-5-21-644356114-2566177158-2502637254-1011] ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKLM -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {76193214-59DA-47ED-BB15-3BCACFC2C36A} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {7B55E28C-0351-41CC-AC14-22094D95924D} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {B1316728-20A2-4B2A-9CD7-B52C1B2CB91A} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q={searchTerms} BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File BHO: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH) Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation) Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.177.1 FireFox: ======== FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default FF DefaultSearchEngine: Google.de FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Google.de FF Homepage: hxxp://de.yahoo.com/|https://www.google.de/ FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-20] () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2009-09-07] (CANON INC.) FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-644356114-2566177158-2502637254-1004: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Philipp\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-10-03] (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-02-16] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-02-16] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-02-16] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-02-16] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-02-16] (Apple Inc.) FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\ebay-durchsuchen.xml [2012-10-14] FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\firefox-add-ons.xml [2011-07-08] FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\googlede.xml [2012-05-18] FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\suche-in-wikipedia.xml [2011-07-08] FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\youtube-videosuche.xml [2012-07-07] FF Extension: Avira Browser Safety - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\abs@avira.com [2015-05-30] FF Extension: LavaFox V2-Purple - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\zigboom555@aol.com [2015-05-05] FF Extension: Blue Fox - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{241aae70-0022-11de-87af-0800200c9a66} [2014-07-31] FF Extension: Bloody Red - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{2458abc0-f443-11dd-87af-0800200c9a66} [2013-08-19] FF Extension: FT DeepDark - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2015-04-22] FF Extension: Add to Amazon Wish List Button - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\amznUWL2@amazon.com.xpi [2013-09-15] FF Extension: YouTube to MP3 - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\youtube2mp3@mondayx.de.xpi [2012-01-19] FF Extension: ProxTube - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}.xpi [2014-07-31] FF Extension: AniWeather - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi [2011-07-08] FF Extension: Nuri - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{beab8ae9-eb2d-4ded-3b29-d35f6b82bfa5}.xpi [2012-12-23] FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-07-31] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-06-02] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-12-13] FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-06-02] Chrome: ======= CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.) [File not signed] S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [827184 2015-06-11] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [450808 2015-06-11] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [450808 2015-06-11] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1188360 2015-06-11] (Avira Operations GmbH & Co. KG) R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS) R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed] R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [208632 2015-05-21] (Avira Operations GmbH & Co. KG) S3 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [433880 2015-05-28] (BlueStack Systems, Inc.) S3 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [413400 2015-05-28] (BlueStack Systems, Inc.) S3 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [806616 2015-05-28] (BlueStack Systems, Inc.) R2 EpsonScanSvc; C:\Windows\system32\EscSvc.exe [126128 2012-05-17] (Seiko Epson Corporation) R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE [143424 2013-04-26] (SEIKO EPSON CORPORATION) R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed] S3 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] () R2 lmhosts; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 MDES; C:\ASUS.SYS\DVMExportService.exe [307200 2008-10-21] (DeviceVM) [File not signed] R2 MyPublicWiFiService; C:\Program Files\MyPublicWiFi\PublicWiFiService.exe [756224 2013-04-03] () [File not signed] R2 NlaSvc; C:\Windows\System32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1997168 2015-06-08] (Electronic Arts) R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () R2 ss_conn_service; D:\Samsung Kies\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) S3 WinHttpAutoProxySvc; winhttp.dll [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AmUStor; C:\Windows\System32\drivers\AmUStor.SYS [25600 2009-07-24] (Alcor Micro, Corp.) R0 AsDsm; C:\Windows\system32\Drivers\AsDsm.sys [30264 2009-12-25] (ASUSTek Computer Inc) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-06-11] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-06-11] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-20] (Avira Operations GmbH & Co. KG) R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [105728 2014-09-29] (AVM Berlin) R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [105728 2014-09-29] (AVM Berlin) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-11] (Avira Operations GmbH & Co. KG) R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [131288 2015-05-28] (BlueStack Systems) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-11-21] (Disc Soft Ltd) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] () S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( ) R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2009-06-18] (Windows (R) Win 7 DDK provider) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [14392 2009-05-13] (ASUS) R1 ndiskhaz; C:\Windows\System32\DRIVERS\ndiskhaz.sys [25416 2012-12-07] (Khalil Azzouzi) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1766592 2009-06-05] () R0 sptd; C:\Windows\System32\Drivers\sptd.sys [324096 2013-11-21] (Duplex Secure Ltd.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-06-11] (Avira Operations GmbH & Co. KG) R3 stdriver; C:\Windows\System32\DRIVERS\stdriver32.sys [52312 2012-06-21] (NCH Software) U3 asify6mi; C:\Windows\system32\Drivers\asify6mi.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder) U3 aydu7eur; C:\Windows\system32\Drivers\aydu7eur.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder) S3 dgderdrv; System32\drivers\dgderdrv.sys [X] S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X] S3 ipswuio; System32\DRIVERS\ipswuio.sys [X] S3 RTHDMIAzAudService; system32\drivers\RtHDMIV.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-15 18:32 - 2015-06-15 18:36 - 00028900 _____ C:\Users\Philipp\Desktop\FRST.txt 2015-06-15 18:32 - 2015-06-15 18:35 - 00000000 ____D C:\FRST 2015-06-15 18:13 - 2015-06-15 18:13 - 01148416 _____ (Farbar) C:\Users\Philipp\Desktop\FRST.exe 2015-06-14 18:33 - 2015-06-14 18:33 - 00002991 _____ C:\Users\Philipp\AppData\Local\recently-used.xbel 2015-06-14 16:21 - 2015-06-14 16:21 - 00000012 ____H C:\dvmexp.idx 2015-06-14 08:12 - 2015-06-14 08:12 - 00000000 ___HD C:\dvmexp 2015-06-13 14:19 - 2015-06-13 14:19 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-06-13 14:18 - 2015-06-15 18:23 - 00001228 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job 2015-06-13 14:18 - 2015-06-15 14:23 - 00001176 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job 2015-06-13 14:18 - 2015-06-13 14:18 - 00000000 ____D C:\Users\Jeffel\AppData\Local\Dropbox 2015-06-13 14:18 - 2015-06-13 14:18 - 00000000 ____D C:\ProgramData\Dropbox 2015-06-11 18:41 - 2015-06-11 18:41 - 00001085 _____ C:\Users\Public\Desktop\Avira.lnk 2015-06-10 10:09 - 2015-06-02 21:35 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-06-10 10:09 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-06-10 10:09 - 2015-05-25 19:00 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-06-10 10:09 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-06-10 10:09 - 2015-05-23 05:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-06-10 10:09 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-06-10 10:09 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-06-10 10:09 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-06-10 10:09 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-06-10 10:09 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-06-10 10:09 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-06-10 10:09 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-06-10 10:09 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-06-10 10:09 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-06-10 10:09 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-06-10 10:09 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-06-10 10:09 - 2015-05-23 05:05 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-06-10 10:09 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-06-10 10:09 - 2015-05-23 05:00 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-06-10 10:09 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-06-10 10:09 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-06-10 10:09 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-06-10 10:09 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-06-10 10:09 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-06-10 10:09 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-06-10 10:09 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-06-10 10:09 - 2015-05-23 04:38 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-06-10 10:09 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-06-10 10:09 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-06-10 10:09 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-06-10 10:09 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-06-10 10:09 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-06-10 10:09 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-06-10 10:09 - 2015-05-22 20:03 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-06-10 10:09 - 2015-05-22 19:58 - 00901120 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-06-10 10:09 - 2015-05-21 15:20 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-06-10 10:08 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-06-10 10:08 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-06-10 10:08 - 2015-05-25 20:07 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-06-10 10:08 - 2015-05-25 20:07 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-06-10 10:08 - 2015-05-25 20:04 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00853504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-06-10 10:08 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe 2015-06-10 10:08 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-06-10 10:08 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-06-10 10:08 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-06-10 10:08 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-06-10 10:08 - 2015-05-25 18:53 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2015-06-10 10:08 - 2015-05-09 05:14 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-06-10 10:08 - 2015-05-09 05:13 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-06-10 10:08 - 2015-05-09 05:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-06-10 10:08 - 2015-05-09 05:12 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-06-10 10:08 - 2015-05-09 05:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 03:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 03:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-06-10 10:08 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-06-10 10:08 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-06-10 10:08 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-06-10 10:08 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-06-10 10:08 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-06-10 10:08 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-06-09 17:20 - 2015-06-09 17:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 2015-06-09 17:20 - 2015-06-09 17:21 - 00000000 ____D C:\Program Files\BlueStacks 2015-06-09 17:20 - 2015-06-09 17:20 - 00000000 ____D C:\ProgramData\BlueStacks 2015-06-09 17:18 - 2015-06-09 17:18 - 15738056 _____ C:\Users\Philipp\Downloads\CloudMusic_official_2.7.1.apk 2015-06-09 17:18 - 2015-06-09 17:18 - 14155832 _____ (BlueStack Systems Inc.) C:\Users\Philipp\Downloads\BlueStacks-ThinInstaller.exe 2015-06-09 15:44 - 2015-05-09 05:14 - 02937344 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 02045952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-06-09 15:44 - 2015-05-09 05:13 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-06-09 15:44 - 2015-05-09 05:13 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-06-09 15:44 - 2015-05-09 05:13 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-06-09 15:44 - 2015-05-09 05:13 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-06-06 18:11 - 2015-06-06 18:11 - 00000000 ____D C:\Users\Beamer\AppData\Local\GWX 2015-06-06 11:34 - 2015-06-07 21:06 - 00000000 ____D C:\Users\Philipp\Documents\Joerg Riesa 2015-06-04 19:22 - 2015-06-04 19:22 - 00002121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2015-06-03 16:37 - 2015-06-03 16:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2015-06-02 15:47 - 2015-06-04 18:42 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-06-01 20:38 - 2015-06-01 20:38 - 00000000 ____D C:\Users\Jeffel\AppData\Local\GWX 2015-06-01 18:03 - 2015-06-01 18:03 - 00000000 ____D C:\Users\Philipp\AppData\Local\GWX 2015-05-31 15:23 - 2015-05-31 15:43 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dual Monitor 2015-05-31 15:23 - 2015-05-31 15:23 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dual Monitor 2015-05-20 19:51 - 2015-05-20 19:51 - 00177664 _____ C:\Users\Philipp\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-20 17:18 - 2015-04-11 05:07 - 00054656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys 2015-05-20 17:18 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-05-20 17:18 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll 2015-05-17 19:56 - 2015-06-15 17:56 - 00000917 _____ C:\Windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job 2015-05-17 19:56 - 2015-06-15 17:56 - 00000731 _____ C:\Windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job 2015-05-16 09:04 - 2015-05-16 09:04 - 00172295 _____ C:\Users\Philipp\Documents\Konfiguration FritzBox.xps ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-15 18:19 - 2012-04-04 22:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-06-15 18:10 - 2014-12-31 17:10 - 00000917 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job 2015-06-15 18:10 - 2014-12-31 17:10 - 00000731 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job 2015-06-15 18:10 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\system32\FxsTmp 2015-06-15 18:04 - 2010-01-31 18:04 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-06-15 17:04 - 2013-11-21 19:48 - 00000000 ____D C:\Users\Beamer\AppData\Roaming\DAEMON Tools Lite 2015-06-15 16:40 - 2009-12-25 17:20 - 00019456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-06-15 16:40 - 2009-12-25 17:20 - 00019456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-06-15 16:39 - 2012-12-17 20:34 - 00000000 ___RD C:\Users\Philipp\Documents\Dropbox 2015-06-15 16:38 - 2014-07-12 11:12 - 00000000 ___RD C:\Users\Philipp\Google Drive 2015-06-15 16:38 - 2010-12-01 14:28 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dropbox 2015-06-15 16:35 - 2010-01-31 18:04 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-06-15 08:20 - 2009-12-25 18:22 - 01411283 _____ C:\Windows\WindowsUpdate.log 2015-06-15 06:48 - 2010-09-11 19:48 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Skype 2015-06-15 06:45 - 2014-07-30 10:13 - 00000000 __SHD C:\Users\Jeffel\AppData\Local\EmieUserList 2015-06-15 06:45 - 2014-07-30 10:13 - 00000000 __SHD C:\Users\Jeffel\AppData\Local\EmieSiteList 2015-06-15 06:11 - 2009-08-20 05:40 - 01620684 _____ C:\Windows\system32\PerfStringBackup.INI 2015-06-14 20:33 - 2012-12-30 21:21 - 00000000 ___RD C:\Users\Jeffel\Dropbox 2015-06-14 20:33 - 2012-12-30 21:17 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Dropbox 2015-06-14 19:33 - 2010-10-18 18:21 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Skype 2015-06-14 18:34 - 2014-11-23 16:42 - 00000000 ____D C:\Users\Philipp\.gimp-2.8 2015-06-14 17:18 - 2013-03-30 18:22 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\.minecraft 2015-06-14 16:36 - 2014-11-23 16:44 - 00000000 ____D C:\Users\Philipp\AppData\Local\gtk-2.0 2015-06-14 16:21 - 2009-08-19 05:27 - 00000000 ___HD C:\temp 2015-06-14 08:15 - 2013-02-10 11:44 - 00000438 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2015-06-14 08:12 - 2015-04-02 11:31 - 00244957 _____ C:\Windows\setupact.log 2015-06-14 08:12 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-06-13 13:07 - 2014-07-12 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2015-06-11 18:47 - 2015-04-04 08:21 - 00002266 _____ C:\Windows\PFRO.log 2015-06-11 18:47 - 2011-10-20 18:09 - 00000000 ____D C:\ProgramData\Avira 2015-06-11 18:41 - 2014-08-25 20:44 - 00000000 ____D C:\ProgramData\Package Cache 2015-06-11 18:40 - 2015-03-05 16:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-06-11 18:40 - 2012-11-02 20:39 - 00000000 ____D C:\Program Files\Avira 2015-06-11 12:09 - 2012-11-02 20:40 - 00136728 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-06-11 12:09 - 2012-11-02 20:40 - 00108448 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-06-11 12:09 - 2012-11-02 20:40 - 00031848 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\ssmdrv.sys 2015-06-11 09:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2015-06-11 08:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2015-06-10 17:55 - 2014-05-29 20:43 - 00000000 ____D C:\Users\Philipp\.android 2015-06-10 17:19 - 2012-04-04 22:24 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-06-10 17:19 - 2011-06-10 19:15 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-06-10 15:43 - 2015-04-02 11:30 - 00572992 _____ C:\Windows\system32\FNTCACHE.DAT 2015-06-10 15:05 - 2014-12-10 22:23 - 00000000 ____D C:\Windows\system32\appraiser 2015-06-10 15:05 - 2014-04-26 10:01 - 00000000 ___SD C:\Windows\system32\CompatTel 2015-06-10 15:04 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2015-06-10 10:31 - 2009-08-19 04:00 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-06-10 10:25 - 2013-07-28 23:00 - 00000000 ____D C:\Windows\system32\MRT 2015-06-10 10:14 - 2009-12-29 22:28 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-06-09 17:21 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Libraries 2015-06-08 18:27 - 2013-06-17 09:00 - 00000000 ____D C:\ProgramData\Origin 2015-06-08 18:20 - 2013-06-17 11:51 - 00000000 ____D C:\Users\Beamer\AppData\Roaming\Origin 2015-06-08 18:14 - 2013-06-17 09:00 - 00000000 ____D C:\Program Files\Origin 2015-06-08 17:04 - 2013-11-27 20:45 - 00000000 ____D C:\Program Files\Common Files\Steam 2015-06-07 08:24 - 2009-12-25 20:08 - 00000354 _____ C:\Windows\Tasks\Driver Robot.job 2015-06-06 10:46 - 2012-05-17 13:18 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Notepad++ 2015-06-04 19:21 - 2009-08-19 04:20 - 00000000 ____D C:\Program Files\Google 2015-06-04 18:42 - 2012-05-11 15:08 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-06-03 16:42 - 2014-04-28 18:03 - 00000000 ____D C:\Program Files\CCleaner 2015-05-31 15:54 - 2012-12-22 15:49 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Audacity 2015-05-30 22:11 - 2009-11-24 20:19 - 00045056 _____ C:\Windows\system32\acovcnt.exe 2015-05-30 12:55 - 2010-03-06 18:42 - 00000000 ____D C:\Users\Jeffel\Documents\Kigo 2015-05-27 18:16 - 2010-01-25 18:43 - 00000000 ____D C:\Users\Jeffel\Documents\Telefon 2015-05-26 11:56 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2015-05-21 21:22 - 2011-08-28 09:47 - 00000000 ____D C:\Users\Beamer 2015-05-20 20:24 - 2012-11-02 20:40 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2015-05-20 17:19 - 2015-04-04 20:15 - 00000000 ___SD C:\Windows\system32\GWX 2015-05-20 17:07 - 2010-10-21 17:44 - 00000000 ____D C:\Users\Philipp\AppData\Local\Adobe 2015-05-20 17:06 - 2011-08-28 10:41 - 00000000 ____D C:\Users\Beamer\AppData\Local\Adobe 2015-05-16 20:06 - 2012-07-28 22:41 - 00000000 ____D C:\Windows\Minidump 2015-05-16 19:42 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2015-05-16 08:11 - 2010-12-01 14:28 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox ==================== Files in the root of some directories ======= 2007-06-12 10:34 - 2007-06-12 10:34 - 0035822 _____ () C:\Program Files\Common Files\ASPG_icon.ico 2008-05-22 09:35 - 2008-05-22 09:35 - 0051962 _____ () C:\Program Files\Common Files\banner.jpg 2009-04-08 11:31 - 2009-04-08 11:31 - 0106496 _____ () C:\Program Files\Common Files\CPInstallAction.dll 2008-08-11 22:45 - 2008-08-11 22:45 - 0155648 _____ (ASUS) C:\Program Files\Common Files\MSIactionall.dll 2013-06-01 21:00 - 2013-06-03 12:18 - 0004143 _____ () C:\Users\Philipp\AppData\Roaming\FTBLauncherLog.txt 2013-06-01 21:00 - 2013-06-03 12:23 - 0078208 _____ () C:\Users\Philipp\AppData\Roaming\MinecraftLog.txt 2012-06-19 14:26 - 2012-06-19 14:26 - 0041472 ___SH () C:\Users\Philipp\AppData\Roaming\Thumbs.db 2010-11-19 20:11 - 2013-02-02 12:46 - 0010240 _____ () C:\Users\Philipp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-06-14 18:33 - 2015-06-14 18:33 - 0002991 _____ () C:\Users\Philipp\AppData\Local\recently-used.xbel 2012-04-17 18:47 - 2012-04-17 18:47 - 0000017 _____ () C:\Users\Philipp\AppData\Local\resmon.resmoncfg 2010-09-11 19:55 - 2010-09-11 19:55 - 0000056 ____H () C:\ProgramData\ezsidmv.dat Files to move or delete: ==================== C:\Users\Jeffel\i2errDeu.dll Some files in TEMP: ==================== C:\Users\Beamer\AppData\Local\Temp\atcMedia1291428144436.exe C:\Users\Beamer\AppData\Local\Temp\avgnt.exe C:\Users\Jeffel\AppData\Local\Temp\AskSLib.dll C:\Users\Jeffel\AppData\Local\Temp\AutoRun.exe C:\Users\Jeffel\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Jeffel\AppData\Local\Temp\avgnt.exe C:\Users\Jeffel\AppData\Local\Temp\Delay.exe C:\Users\Jeffel\AppData\Local\Temp\DirectoryRemovalUtility.exe C:\Users\Jeffel\AppData\Local\Temp\drm_dialogs.dll C:\Users\Jeffel\AppData\Local\Temp\drm_dyndata_7370012.dll C:\Users\Jeffel\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpw138tc.dll C:\Users\Jeffel\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\Jeffel\AppData\Local\Temp\FlashPlayerUpdate01.exe C:\Users\Jeffel\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe C:\Users\Jeffel\AppData\Local\Temp\i4jdel0.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u21-windows-i586-iftw-rv.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u22-windows-i586-iftw-rv.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe C:\Users\Jeffel\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe C:\Users\Jeffel\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Jeffel\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Jeffel\AppData\Local\Temp\mpsetup.exe C:\Users\Jeffel\AppData\Local\Temp\MSETUP4.EXE C:\Users\Jeffel\AppData\Local\Temp\ose00000.exe C:\Users\Jeffel\AppData\Local\Temp\PicasaUpdater_7e04.exe C:\Users\Jeffel\AppData\Local\Temp\RemoveGO.exe C:\Users\Jeffel\AppData\Local\Temp\sdanircmdc.exe C:\Users\Jeffel\AppData\Local\Temp\sdapskill.exe C:\Users\Jeffel\AppData\Local\Temp\setup.exe C:\Users\Jeffel\AppData\Local\Temp\SkypeSetup.exe C:\Users\Jeffel\AppData\Local\Temp\uninst1.exe C:\Users\Jeffel\AppData\Local\Temp\vcredist_x86.exe C:\Users\Jeffel\AppData\Local\Temp\_is9E90.exe C:\Users\Jeffel\AppData\Local\Temp\_isBF68.exe C:\Users\Philipp\AppData\Local\Temp\avgnt.exe C:\Users\Philipp\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpvefjun.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed ==================== End of log ============================ Und noch die Addition.txt: [CODE]Additional FRST Logfile: Code:
ATTFilter scan result of Farbar Recovery Scan Tool (x86) Version: 13-06-2015 Ran by Philipp at 2015-06-15 18:37:28 Running from C:\Users\Philipp\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-644356114-2566177158-2502637254-500 - Administrator - Disabled) Beamer (S-1-5-21-644356114-2566177158-2502637254-1005 - Administrator - Enabled) => C:\Users\Beamer Ellen & Manuel (S-1-5-21-644356114-2566177158-2502637254-1008 - Limited - Enabled) => C:\Users\Ellen & Manuel Gast (S-1-5-21-644356114-2566177158-2502637254-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-644356114-2566177158-2502637254-1010 - Limited - Enabled) Jeffel (S-1-5-21-644356114-2566177158-2502637254-1000 - Administrator - Enabled) => C:\Users\Jeffel Manuel (S-1-5-21-644356114-2566177158-2502637254-1011 - Limited - Enabled) => C:\Users\Manuel Philipp (S-1-5-21-644356114-2566177158-2502637254-1004 - Limited - Enabled) => C:\Users\Philipp ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 1&1 SmartFax (HKLM\...\1&1 SmartFax) (Version: 2.00.224 - 1&1 Internet AG) 3dPageFlip Editor (HKLM\...\3dPageFlip PDF Editor_is1) (Version: - 3dPageFlip Solution) Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adblock Plus für IE (32-Bit) (HKLM\...\{654F389B-E402-4F7B-BA6D-DA732BB57ACB}) (Version: 1.4 - Eyeo GmbH) Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated) Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Alcor Micro USB Card Reader (HKLM\...\AmUStor) (Version: 1.4.1217.35202 - Alcor Micro Corp.) Alcor Micro USB Card Reader (Version: 1.4.1217.35202 - Alcor Micro Corp.) Hidden Apple Application Support (32-Bit) (HKLM\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASUS CopyProtect (HKLM\...\{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}) (Version: 1.0.0015 - ASUS) ASUS Data Security Manager (HKLM\...\{FA2092C5-7979-412D-A962-6485274AE1EE}) (Version: 1.00.0014 - ASUS) ASUS FancyStart (HKLM\...\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}) (Version: 1.0.6 - ASUSTeK Computer Inc.) ASUS LifeFrame3 (HKLM\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS) ASUS Live Update (HKLM\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS) ASUS MultiFrame (HKLM\...\{9D48531D-2135-49FC-BC29-ACCDA5396A76}) (Version: 1.0.0019 - ASUS) ASUS Power4Gear eXtreme (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.0.19 - ASUS) ASUS SmartLogon (HKLM\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0007 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0028 - ASUS) ASUS Touch Pad Extra (HKLM\...\{DB891739-2EB3-45A8-9CBD-941C255CECD4}) (Version: - ) ASUS Virtual Camera (HKLM\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.19 - asus) Asus_Camera_ScreenSaver (HKLM\...\Asus_Camera_ScreenSaver) (Version: 2.0.0008 - ASUS) Atheros Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - Atheros) ATI Catalyst Install Manager (HKLM\...\{0AE24BD5-185C-436C-D93D-50574523C6C4}) (Version: 3.0.732.0 - ATI Technologies, Inc.) ATK Generic Function Service (HKLM\...\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}) (Version: 1.00.0008 - ATK) ATK Hotkey (HKLM\...\{7C05592D-424B-46CB-B505-E0013E8E75C9}) (Version: 1.0.0053 - ASUS) ATK Media (HKLM\...\{D1E5870E-E3E5-4475-98A6-ADD614524ADF}) (Version: 2.0.0006 - ASUS) ATKOSD2 (HKLM\...\{3B05F2FB-745B-4012-ADF2-439F36B2E70B}) (Version: 7.0.0006 - ASUS) aTube Catcher (HKLM\...\aTube Catcher) (Version: 2.9.1462 - DsNET Corp) aTube Catcher Version 3.8 (HKLM\...\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp) Audacity 2.0.2 (HKLM\...\Audacity_is1) (Version: 2.0.2 - Audacity Team) Avanquest update (HKLM\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.29 - Avanquest Software) Avidemux 2.6 (32-bit) (HKLM\...\Avidemux 2.6) (Version: 2.6.8.9046 - ) Avira (HKLM\...\{0696cc37-db90-4000-be99-4a173ca7c8af}) (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG) Hidden Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.11.574 - Avira Operations GmbH & Co. KG) Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION Bandicam (HKLM\...\Bandicam) (Version: 1.8.5.302 - Bandisoft.com) Battlefield 1942™ (HKLM\...\{5BE7BD06-512B-43bf-AD78-3BD2A5F5F7B3}) (Version: 1.6.20.0 - Electronic Arts) Bejeweled® 3 (HKLM\...\{E99C27B2-EB2E-4244-9F5C-A96F55100F0C}) (Version: 1.1.13.4753 - Electronic Arts, Inc.) BlueStacks App Player (HKLM\...\BlueStacks App Player) (Version: 0.9.27.5408 - BlueStack Systems, Inc.) BlueStacks Notification Center (HKLM\...\{C1F53C9F-C560-4292-9237-12786FE6BF62}) (Version: 0.9.27.5408 - BlueStack Systems, Inc.) Bob baut einen Park (HKLM\...\{367EDD83-302F-48E6-8F77-B0B056125C2D}) (Version: 1.0.0 - ) Bob der Baumeister (HKLM\...\{8F2D21F9-F428-4EF2-8111-953EF3299EFB}) (Version: 1.0.0 - ) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\...\CANONIJPLM100) (Version: - ) Canon MP Navigator EX 3.0 (HKLM\...\MP Navigator EX 3.0) (Version: - ) Canon MP490 series Benutzerregistrierung (HKLM\...\Canon MP490 series Benutzerregistrierung) (Version: - ) Canon MP490 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series) (Version: - ) Canon Utilities Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version: - ) Canon Utilities My Printer (HKLM\...\CanonMyPrinter) (Version: - ) Canon Utilities Solution Menu (HKLM\...\CanonSolutionMenu) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform) Cisco EAP-FAST Module (HKLM\...\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM\...\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM\...\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.) Construction-Simulator 2015 (HKLM\...\Steam App 289950) (Version: - weltenbauer. Software Entwicklung GmbH) Core Temp version 0.99.7 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 0.99.7 - Arthur Liberman) Crusader No Remorse (HKLM\...\{2AEA735F-B393-4D89-93EF-5849CB72B4A3}) (Version: 1.0.0.2 - Electronic Arts) CyberLink LabelPrint (HKLM\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1720 - CyberLink Corp.) CyberLink Power2Go (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.2713 - CyberLink Corp.) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd) Diercke Globus Online (HKLM\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH) dm-Fotowelt (HKLM\...\dm-Fotowelt) (Version: 5.1.7 - CEWE Stiftung u Co. KGaA) Dolby Control Center (HKLM\...\{0F3C61B5-3051-4DE6-8A6A-45100BCC1F41}) (Version: 1.2.0704 - Dolby) Dropbox (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Dropbox) (Version: 3.4.6 - Dropbox, Inc.) Druckerdeinstallation für EPSON XP-312 313 315 Series (HKLM\...\EPSON XP-312 313 315 Series) (Version: - SEIKO EPSON Corporation) Druckerdeinstallation für EPSON XP-412 413 415 Series (HKLM\...\EPSON XP-412 413 415 Series) (Version: - SEIKO EPSON Corporation) Dual Monitor 1.22 (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{64AA3F94-ED4A-4A4B-B72C-B7A1481ED5D8}_is1) (Version: 1.22.021813 - Cristi Diaconu) EA SPORTS FIFA World (HKLM\...\{8F9AC744-EEF6-43DB-A4B6-FA1A18F1C640}) (Version: 9.5.0.61021 - Electronic Arts, Inc.) Epson Connect Printer Setup (HKLM\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.3.0 - SEIKO EPSON CORPORATION) Epson Event Manager (HKLM\...\{0F13C24A-FFE2-4CD0-8E0B-DC804E0A0E0B}) (Version: 3.10.0035 - Seiko Epson Corporation) EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON-Handbücher (HKLM\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.32.0.0 - SEIKO EPSON CORPORATION) EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION) Express Gate (HKLM\...\{62CF8923-31DC-4285-A23C-17CE5AA6A679}) (Version: 1.0.3.2 - DeviceVM, Inc.) F1 2013 (HKLM\...\Steam App 223670) (Version: - Codemasters Birmingham) FIFA 09 (HKLM\...\{2315B23D-3E21-4920-837D-AE6460934ECB}) (Version: 1.0.1.1 - Electronic Arts) Firebird SQL Server - MAGIX Edition (HKLM\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG) GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team) Globus Fotoservice 4.4 (HKLM\...\Globus Fotoservice_is1) (Version: - ) Google Drive (HKLM\...\{CBC9F5FD-5CFA-4A33-81CD-369EAB77E3A6}) (Version: 1.22.9403.0223 - Google, Inc.) Google Earth (HKLM\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden Google+ Auto Backup (HKLM\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google) Hot Wheels (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{CF36DD86-81D3-4D91-8F7A-344E0C1A4BFD}) (Version: 1.00.0000 - Activision Value) iCloud (HKLM\...\{9A07AB4F-6B53-43E9-B7FC-7892E8C26BE3}) (Version: 4.1.1.53 - Apple Inc.) Isola LEGO 2 (HKLM\...\{85967580-EBC2-11D4-AEA3-0050046A88ED}) (Version: - ) iTunes (HKLM\...\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.) Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden KingsoftOfficeXPlats 1.4 (HKLM\...\KingsoftOfficeXPlats) (Version: 1.4 - Kingsoft) LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version: - ) LBOTS Top mouse Driver (HKLM\...\{F1A273BD-6A9E-41D8-A111-5E56ACD286F8}) (Version: 1.0 - Togran) LEGO Racers 2 (HKLM\...\{3DD2E9EA-0544-4162-B8BE-E21E994E9F3B}) (Version: - ) LEGO® Star Wars™: Die Komplette Saga (HKLM\...\InstallShield_{D596980D-17BE-4425-B8F0-5640719AADE9}) (Version: 1.00.0000 - LucasArts) LEGO® Star Wars™: The Complete Saga (Version: 1.00.0000 - LucasArts) Hidden LEGOLAND (HKLM\...\LEGOLANDDeInstKey) (Version: - ) Logitech Gaming Software (HKLM\...\{648F9C94-EC44-487B-9DA4-44ED72A082CC}) (Version: 4.50 - ) MAGIX Speed burnR (MSI) (HKLM\...\MX.{16884C3D-3512-486D-A2F9-39071551BFEF}) (Version: 7.0.2.6 - MAGIX AG) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden MAGIX Video deluxe 2014 (HKLM\...\MX.{EA62B22F-AB0A-406B-80A9-8036D3CE3446}) (Version: 13.0.2.8 - MAGIX AG) MAGIX Video deluxe 2014 (Version: 13.0.2.8 - MAGIX AG) Hidden Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Outlook Connector (HKLM\...\{95120000-0122-0407-0000-0000000FF1CE}) (Version: 12.0.6423.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{AC4C38FD-A54C-4CA5-92EE-D983CD81293E}) (Version: 1.20.146.0 - Microsoft) Minecraft (HKLM\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) Minigolf (HKLM\...\Minigolf_is1) (Version: - Meridian93) Monkey's Adventures (HKLM\...\Monkey's Adventures_is1) (Version: - play-publishing.com) Motorola Driver Installation 3.4.0 (HKLM\...\{81B3BEF9-5D97-4096-86E9-5B48A5BC32D0}) (Version: 3.4.0 - Motorola Inc.) Motorola Phone Tools (HKLM\...\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}) (Version: 5.0.7a 4/01/2008 - Avanquest Software) Motorola Phone Tools (Version: 4.30 - BVRP Software) Hidden Motorola Phone Tools (Version: 5.00 - BVRP Software) Hidden Mozilla Firefox 38.0.5 (x86 de) (HKLM\...\Mozilla Firefox 38.0.5 (x86 de)) (Version: 38.0.5 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyPublicWiFi 5.1 (HKLM\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version: - TRUE Software) Mystery P.I. - The London Caper (HKLM\...\Mystery P.I. - The London Caper) (Version: - PopCap Games) NB Probe (HKLM\...\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}) (Version: - ) Need For Speed™ World (HKLM\...\{3AF1B16A-7DC9-4C80-BAEC-70B088A7C5B8}) (Version: 1.0.0.0 - Electronic Arts) Net4Switch (HKLM\...\{9D6D7811-43B3-463C-BC79-5D1755269989}) (Version: 1.00.0019 - ASUS) Norton Internet Security (Version: 16.0.0.125 - Symantec Corporation) Hidden Notepad++ (HKLM\...\Notepad++) (Version: 6.1.2 - ) OpenAL (HKLM\...\OpenAL) (Version: - ) Oracle VM VirtualBox 4.3.2 (HKLM\...\{91E5A436-8560-4621-9F26-D7050D078832}) (Version: 4.3.2 - Oracle Corporation) Origin (HKLM\...\Origin) (Version: 9.2.1.4399 - Electronic Arts, Inc.) pdfsam (HKLM\...\pdfsam) (Version: 2.2.0 - ) Peter Lustigs Verkehrsschule (HKLM\...\Verkehrsschule) (Version: - ) Pflanzen gegen Zombies™ (HKLM\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.) QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) Roads Of Rome (HKLM\...\Roads Of Rome_is1) (Version: - Realore Studios) Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.) Samsung Kies (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) SimCity 2000 Special Edition (HKLM\...\{59D2C751-F7BE-4E9F-9C8C-1F16013802C7}) (Version: 2.0.0.1 - Electronic Arts) SimCity™ (HKLM\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts) Skype™ 7.1 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.) Software Updater (HKLM\...\{E1BAD1BA-C0E8-4018-9281-E7D2C6B07474}) (Version: 4.3.6 - SEIKO EPSON CORPORATION) Steam (HKLM\...\Steam) (Version: - Valve Corporation) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.1.1 - Synaptics Incorporated) Syndicate (HKLM\...\{64CFBAAB-46F7-4628-8D9B-E656A8C11CDB}) (Version: 2.0.0.3 - Electronic Arts) System Requirements Lab CYRI (HKLM\...\{E77DA909-3532-4C95-AFEB-06310E88462A}) (Version: 6.0.3.0 - Husdawg, LLC) Theme Hospital (HKLM\...\{5118A4C2-C8A4-4CE5-AC37-F3E51C25402F}) (Version: 3.0.0.2 - Electronic Arts) TIPP10 Version 2.1.0 (HKLM\...\TIPP10_is1) (Version: - (c) 2006-2011, Tom Thielicke IT Solutions) TmNationsForever (HKLM\...\TmNationsForever_is1) (Version: - Nadeo) TOGGO PC-Spielebox 2 (HKLM\...\{67EECE0C-8B6C-4D09-989D-D39BC9BBCA0E}) (Version: 1.00.0000 - ) Toyland Racer (HKLM\...\Toyland Racer) (Version: - ) Unified Remote (HKLM\...\{D7930C67-5816-417B-BF28-54BB75EFDAF9}) (Version: 2.14.4.0 - Unified Remote) Unity Web Player (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\UnityWebPlayer) (Version: - Unity Technologies ApS) upapp (HKLM\...\{4EF69D40-4DC9-485E-95D3-B1C22F218FC8}) (Version: 0.20.0000 - Hewlett-Packard) USB 2.0 1.3M UVC WebCam (HKLM\...\USB 2.0 1.3M UVC WebCam) (Version: - ) Werksfeuerwehr-Simulator Version 1.0 (HKLM\...\{5F7ED0CD-E04E-4441-9E03-10AFDB654E96}_is1) (Version: - rondomedia Marketing & Vertriebs GmbH) Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live ID-Anmelde-Assistent (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Live Sync (HKLM\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation) Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) WinFlash (HKLM\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.29.0 - ASUS) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) Wireless Console 2 (HKLM\...\{83F73CB1-7705-49D1-9852-84D839CA2A45}) (Version: 2.0.10 - ATK) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= ATTENTION: System Restore is disabled Check "winmgmt" service or repair WMI. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => Task: C:\Windows\Tasks\Driver Robot.job => Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job => Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job => Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job => Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job => Task: C:\Windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job => Task: C:\Windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job => Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ==================== Loaded Modules (Whitelisted) ============== 2007-06-15 11:28 - 2007-06-15 11:28 - 00147456 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll 2007-06-01 18:08 - 2007-06-01 18:08 - 00143360 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll 2013-12-24 20:39 - 2012-11-20 00:44 - 00786432 _____ () D:\Gaming Maus\DareUMonitor.exe 2013-12-24 20:39 - 2013-03-27 13:48 - 00057344 _____ () D:\Gaming Maus\lan.dll 2013-12-24 20:39 - 2012-04-19 18:15 - 00061440 _____ () D:\Gaming Maus\hiddriver.dll 2015-05-08 20:50 - 2015-05-08 20:50 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2015-06-15 16:36 - 2015-06-15 16:36 - 00043008 _____ () c:\users\philipp\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpvefjun.dll 2015-03-04 23:45 - 2015-03-04 23:45 - 00750080 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2015-03-04 23:45 - 2015-03-04 23:45 - 00047616 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\libEGL.dll 2015-03-04 23:45 - 2015-03-04 23:45 - 00865280 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll 2015-03-04 23:45 - 2015-03-04 23:45 - 00200704 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll 2015-06-15 16:35 - 2015-06-15 16:35 - 00098816 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32api.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00110080 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pywintypes27.dll 2015-06-15 16:35 - 2015-06-15 16:35 - 00364544 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pythoncom27.dll 2015-06-15 16:35 - 2015-06-15 16:35 - 00045568 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_socket.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 01161216 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_ssl.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00320512 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32com.shell.shell.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00713216 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_hashlib.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 01175040 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._core_.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00805888 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._gdi_.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00811008 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._windows_.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 01062400 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._controls_.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00735232 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._misc_.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00682496 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pysqlite2._sqlite.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00087552 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_ctypes.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00119808 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32file.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00108544 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32security.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00007168 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\hashobjs_ext.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00026624 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\usb_ext.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00167936 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32gui.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00018432 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32event.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00128512 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_elementtree.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00127488 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pyexpat.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00013824 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\common.time34.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00036864 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_psutil_windows.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00038912 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32inet.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00011264 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32crypt.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00070656 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._html2.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00027136 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_multiprocessing.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00020480 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_yappi.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00035840 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32process.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00686080 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\unicodedata.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00122368 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._wizard.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00024064 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32pipe.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00010240 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\select.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00025600 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32pdh.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00525640 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\windows._lib_cacheinvalidation.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00017408 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32profile.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00022528 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32ts.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00078336 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._animate.pyd 2013-11-27 20:48 - 2015-04-16 19:40 - 00776192 _____ () D:\Steam\SDL2.dll 2015-01-24 17:49 - 2015-04-23 04:16 - 04962816 _____ () D:\Steam\v8.dll 2015-01-24 17:49 - 2015-04-23 04:16 - 01556992 _____ () D:\Steam\icui18n.dll 2015-01-24 17:49 - 2015-04-23 04:16 - 01187840 _____ () D:\Steam\icuuc.dll 2014-05-22 17:04 - 2015-06-04 20:56 - 02407104 _____ () D:\Steam\video.dll 2014-08-31 20:09 - 2014-12-01 23:31 - 02396672 _____ () D:\Steam\libavcodec-56.dll 2014-08-31 20:09 - 2014-12-01 23:31 - 00442880 _____ () D:\Steam\libavutil-54.dll 2014-08-31 20:09 - 2014-12-01 23:31 - 00479744 _____ () D:\Steam\libavformat-56.dll 2014-08-31 20:09 - 2014-12-01 23:31 - 00332800 _____ () D:\Steam\libavresample-2.dll 2014-08-31 20:09 - 2014-12-01 23:31 - 00485888 _____ () D:\Steam\libswscale-3.dll 2013-11-27 20:48 - 2015-06-04 20:56 - 00703168 _____ () D:\Steam\bin\chromehtml.DLL 2013-11-27 20:48 - 2015-05-11 21:01 - 36302728 _____ () D:\Steam\bin\libcef.dll 2015-05-16 07:55 - 2015-05-11 21:01 - 08958344 _____ () D:\Steam\bin\pdf.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Jeffel\Desktop\1.avi:TOC.WMV AlternateDataStreams: C:\Users\Jeffel\Desktop\2.avi:TOC.WMV AlternateDataStreams: C:\Users\Jeffel\Desktop\3.avi:TOC.WMV ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.177.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk => C:\Windows\pss\FancyStart daemon.lnk.CommonStartup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: AlcoholAutomount => "D:\Alcohol 120\axcmd.exe" /automount MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: ASUS Camera ScreenSaver => C:\Windows\AsScrProlog.exe MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\ASScrPro.exe MSCONFIG\startupreg: ASUSTPE => C:\Windows\system32\ASUSTPE.exe MSCONFIG\startupreg: AVMUSBFernanschluss => "C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\AVMAutoStart.exe" MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon MSCONFIG\startupreg: CanonSolutionMenu => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon MSCONFIG\startupreg: CLMLServer => "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: DAEMON Tools Lite => "D:\DT\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: KiesTrayAgent => D:\Samsung Kies\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: UpdateLBPShortCut => "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" MSCONFIG\startupreg: UpdateP2GoShortCut => "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{98B426BE-4154-48E7-A940-C28AD6AB3C7E}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{A0ED8D77-C475-4A7C-9683-E33EF6CA08AE}] => (Allow) svchost.exe FirewallRules: [{5A959ABA-B81C-408F-9BF9-A382D827ED17}] => (Allow) C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [TCP Query User{92FF86AB-5408-4239-86CD-713C52CC5E72}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [UDP Query User{756D4762-70FE-4F03-9A42-0F627F10CBF8}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [TCP Query User{F15C73F2-09B2-4D70-B6C1-FCB8C6C3077A}C:\program files\google\google earth\client\googleearth.exe] => (Block) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [UDP Query User{3518798C-9464-4B02-B79D-33060DE82A80}C:\program files\google\google earth\client\googleearth.exe] => (Block) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [TCP Query User{F87691B0-9C93-4349-8E2B-69BF1B0D816D}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{0756E3CD-F4D3-4373-BCB1-583FDDA22919}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{6939840F-897B-42B5-8E48-6E97937198B0}] => (Allow) svchost.exe FirewallRules: [{59E3FF2C-493B-4937-9A37-DA9D1CAAFC4B}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe FirewallRules: [TCP Query User{A1DE6356-BBC4-48A8-B039-88DEB224609A}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{E3168A96-5F5E-4485-AD0D-7AE6A2596564}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{4AF10D0E-C4C1-40A2-936B-C6F2AB12613B}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe FirewallRules: [UDP Query User{88D7FF05-F79E-4946-A853-288BD573E814}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe FirewallRules: [TCP Query User{9EFEAB5F-7210-4BC7-8BA8-231FA6D585A1}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe FirewallRules: [UDP Query User{375FCB23-571C-4F84-90FE-A0670DEAAC49}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe FirewallRules: [{55E52E7C-FD6E-4517-8357-F6D71154371A}] => (Allow) C:\Users\Jeffel\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{9C447FBD-4CD0-4507-918C-C3C1FC1BC0BC}] => (Allow) C:\Users\Jeffel\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{424B5F96-6253-4B19-824F-7157B91CE53C}C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{A3FECD29-88C2-49EE-9826-78B12649C757}C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{5518E9F3-F3DC-433F-9E50-A930A0CD15F2}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe FirewallRules: [UDP Query User{55697CCA-A2DB-4C9F-8442-8DC6C36139AA}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe FirewallRules: [TCP Query User{3E55C8FD-D431-4830-8F71-22F2B69255C3}C:\program files\ea sports\fifa 09\fifa09.exe] => (Allow) C:\program files\ea sports\fifa 09\fifa09.exe FirewallRules: [UDP Query User{6B39FD39-72B8-4683-9E30-4221DEFAD5D9}C:\program files\ea sports\fifa 09\fifa09.exe] => (Allow) C:\program files\ea sports\fifa 09\fifa09.exe FirewallRules: [TCP Query User{EF7EF825-131B-4165-A892-9DEC02FC688F}E:\easysetupassistant\wr841n\easysetupassistant.exe] => (Allow) E:\easysetupassistant\wr841n\easysetupassistant.exe FirewallRules: [UDP Query User{25BF93E3-CEFC-4077-972C-637BBD3D8D23}E:\easysetupassistant\wr841n\easysetupassistant.exe] => (Allow) E:\easysetupassistant\wr841n\easysetupassistant.exe FirewallRules: [{BE0F663E-C815-4563-A897-646E54E5E075}] => (Block) E:\easysetupassistant\wr841n\easysetupassistant.exe FirewallRules: [{C1AD54B1-3E4E-48CD-AA59-46A81630CED6}] => (Block) E:\easysetupassistant\wr841n\easysetupassistant.exe FirewallRules: [TCP Query User{642462DC-FE55-4283-B3BE-5116D1ABD2D1}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{1543EF59-9BDC-45F3-98C1-666138EE2360}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [{F42F3A51-5E79-42CD-97EC-8F46AFB3AEDA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{3AF441F6-2448-4E93-AF29-F00F2983A81B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{3A83D0B7-CC23-4E0A-A47F-BA4C727DA59B}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{A30C3FCC-E865-487C-BB2B-94503E562E57}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [{C5B4D7F3-5ACD-4113-B7F8-EF24617B930D}] => (Allow) D:\OriginGames\Need for Speed World\GameLauncher.exe FirewallRules: [{54FB9595-0BFB-47AF-866A-250C8D7B1BAF}] => (Allow) D:\OriginGames\Need for Speed World\GameLauncher.exe FirewallRules: [{9E1C364E-EA27-4082-AB13-FBEBC90590BA}] => (Allow) D:\OriginGames\Battlefield 1942\BF1942.exe FirewallRules: [{2EB3B6C7-04D1-43DF-B4B0-B47348DBCD68}] => (Allow) D:\OriginGames\Battlefield 1942\BF1942.exe FirewallRules: [{DBB13B95-B032-45C2-A416-2E496104A650}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{5456B4DC-0D08-476B-B4CB-8BA97886248B}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{B3C9C811-6617-41F7-8833-D1B66AC7C967}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [TCP Query User{FB78B67C-4DFB-45DA-8910-73B460C08EE9}D:\needforspeed world\data\nfsw.exe] => (Allow) D:\needforspeed world\data\nfsw.exe FirewallRules: [UDP Query User{514C9672-18B4-476C-B568-2B1D2211DC21}D:\needforspeed world\data\nfsw.exe] => (Allow) D:\needforspeed world\data\nfsw.exe FirewallRules: [{122DB7AB-303C-4A23-8984-A4089D07A519}] => (Allow) D:\Steam\SteamApps\common\f12013\F1_2013.exe FirewallRules: [{BA4A4B55-61BE-49C7-B106-9CF16C1FEFCA}] => (Allow) D:\Steam\SteamApps\common\f12013\F1_2013.exe FirewallRules: [{852A6D93-68A1-49D2-A427-091873A0F8AF}] => (Allow) D:\OriginGames\Plants vs. Zombies\PlantsVsZombies.exe FirewallRules: [{1C423230-E993-447A-B8BC-B011BD1ABEA4}] => (Allow) D:\OriginGames\Plants vs. Zombies\PlantsVsZombies.exe FirewallRules: [{5476BAD2-AE20-42B2-BFC6-58B987D9EC81}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [{812E2119-243A-400E-B7FE-DEB6D62808AB}] => (Allow) D:\OriginGames\SimCity\SimCity\SimCity.exe FirewallRules: [{2C4E33E9-EDDF-4059-9790-647FCF83145D}] => (Allow) D:\OriginGames\SimCity\SimCity\SimCity.exe FirewallRules: [TCP Query User{60D69111-FE19-4415-B387-D97AE26AFD38}C:\program files\tmnationsforever\tmforever.exe] => (Block) C:\program files\tmnationsforever\tmforever.exe FirewallRules: [UDP Query User{F2DF262E-FF7C-484F-AA4E-63FF8880305C}C:\program files\tmnationsforever\tmforever.exe] => (Block) C:\program files\tmnationsforever\tmforever.exe FirewallRules: [{A3C3ECE5-F0B8-458B-BF51-A7F6BF8F5E0E}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{DAA3B140-1FED-47B5-9F25-FB8F35548A03}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{F14B2E24-FBC1-4546-BBB6-CCBF3E3C26CB}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe FirewallRules: [{1EBAA986-ABD7-469D-8126-C6A22AB47DCF}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe FirewallRules: [TCP Query User{DF57783D-CA97-4654-B267-AC96484B730F}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{695F1F23-F5F2-4E3A-93D3-C046C30B108D}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{18759B6E-98BA-4489-983D-ABCF93CE30A2}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{C48C23E4-CF37-4289-AC60-2FF3F377ACD4}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe FirewallRules: [{BAE39D93-BC07-4545-A838-D128E5D729B1}] => (Allow) C:\Users\Philipp\AppData\Local\Apps\2.0\AKHGTRNK.DG4\BWYE0CZZ.LL7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{BDC2FD03-237D-49E4-A6A2-8AE3211FB11A}] => (Allow) C:\Users\Philipp\AppData\Local\Apps\2.0\AKHGTRNK.DG4\BWYE0CZZ.LL7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{2A33F55E-5BBB-4A44-9852-D7FEA360081E}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{084ED6E8-0CDB-42C1-9716-21D9E1E099C3}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [TCP Query User{5A171416-5B5C-45E6-A06C-FD51ECCBBA01}C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe] => (Block) C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [UDP Query User{EC3DF4E2-12D4-4BEA-9E53-8BD42E933EE3}C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe] => (Block) C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{B3F421E8-5795-4576-A04B-678154A5D42C}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{56B79544-76F5-4B6F-85BD-3CA9415A0BE3}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [TCP Query User{A674A672-4708-4C05-A7DD-7FC78F2ABAD6}C:\program files\unified remote\remoteserver.exe] => (Allow) C:\program files\unified remote\remoteserver.exe FirewallRules: [UDP Query User{C42108C2-C11D-4BCD-848F-C882C383AFF1}C:\program files\unified remote\remoteserver.exe] => (Allow) C:\program files\unified remote\remoteserver.exe FirewallRules: [{66918B97-AE64-444C-9DB6-5DB605AE12F7}] => (Allow) D:\OriginGames\Bejeweled 3\Bejeweled3.exe FirewallRules: [{4D93D20E-753C-494E-8FA6-F47CF535E417}] => (Allow) D:\OriginGames\Bejeweled 3\Bejeweled3.exe FirewallRules: [{100DFB51-03A7-409A-8436-B1ADEDE290A7}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{3D1CFBF6-1099-4721-A86E-438E12C875EA}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{708B5EAF-95EC-428E-9AA3-7F8A3CC499D7}] => (Allow) D:\OriginGames\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe FirewallRules: [{252252F8-D1E0-473A-8A33-743C157FAAAB}] => (Allow) D:\OriginGames\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe FirewallRules: [{12369EEC-4B3E-4804-8395-3B1EE1D1F377}] => (Allow) C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{23965B5B-2D1F-4BC2-82F2-4E012CDB6110}] => (Allow) C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{8AD425C4-E4CD-4E0A-B470-71C0186D4419}] => (Allow) D:\OriginGames\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe FirewallRules: [{79468976-3ED7-4AAD-8CDF-CC32C20626C3}] => (Allow) D:\OriginGames\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe FirewallRules: [{98C0D637-E762-4100-8AF8-3E756C54A265}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe FirewallRules: [{533B5FB5-1CB8-4776-8F97-B9D35616A215}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe FirewallRules: [{D67CAA53-7942-4A91-8D54-03DE16AF77AA}] => (Allow) D:\Steam\SteamApps\common\ConSim2015\ConSim2015.exe FirewallRules: [{085EB9AF-D4B4-42D7-AA85-2FF13C776871}] => (Allow) D:\Steam\SteamApps\common\ConSim2015\ConSim2015.exe FirewallRules: [{13EC435C-D4A0-4045-9736-20D5C2A52E0F}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{766D54AC-FE82-4990-81C9-4B3E62FC1D8E}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{8147F4AA-6FEE-48F5-A257-DADCA6B3D1F7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{B59D5117-8BF8-4401-A031-594855C5359E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{C3A2EE98-6FD7-4841-986B-5FF483452073}] => (Allow) D:\OriginGames\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [{7894DF2C-B685-420A-810A-505E1663461E}] => (Allow) D:\OriginGames\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [{AB875D33-F535-45C7-83AD-4542A38F0A9A}] => (Allow) D:\OriginGames\Syndicate (1993)\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [{C8819052-499D-4060-A2CB-63C85B7289F3}] => (Allow) D:\OriginGames\Syndicate (1993)\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [TCP Query User{2405E39F-611A-4841-8667-B7FAB332ED13}D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{98A5CF53-9EE7-4592-86E6-5A255E971ED4}D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{42389642-E7E4-4FA7-99F0-D17483626C6F}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{546675B7-4D5D-41B0-A82B-3C2AE0AED9AE}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [{F4820325-C52D-4F14-B0C1-E2F40210A513}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft3077.tmp\fsetup.exe FirewallRules: [{F8A2199B-EA6F-43B4-BF29-FC040CE4901D}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft3077.tmp\fsetup.exe FirewallRules: [{0CB53765-513D-49DE-87C5-AECA2C3658C1}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pftAA65.tmp\fsetup.exe FirewallRules: [{C88A6BB6-DBFF-4572-AA49-2F5929892EA3}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pftAA65.tmp\fsetup.exe FirewallRules: [{13D83860-A9E7-48A7-A64E-3D805CB1B574}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft96D1.tmp\fsetup.exe FirewallRules: [{4DDF4814-C41E-4164-81FB-D9C60F8AD319}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft96D1.tmp\fsetup.exe FirewallRules: [{7870E46B-69E5-4524-B2E7-ECEB9E6D710D}] => (Allow) C:\Program Files\iTunes\iTunes.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/15/2015 06:34:40 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm FRST.exe, Version 13.6.2015.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 26c0 Startzeit: 01d0a788caaf2ddf Endzeit: 0 Anwendungspfad: C:\Users\Philipp\Desktop\FRST.exe Berichts-ID: 36209be9-137c-11e5-977e-002618f9ca5d Error: (06/15/2015 05:07:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: legoland.exe, Version: 0.2.2.9, Zeitstempel: 0x3934d3e8 Name des fehlerhaften Moduls: legoland.exe, Version: 0.2.2.9, Zeitstempel: 0x3934d3e8 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0005241a ID des fehlerhaften Prozesses: 0x23a0 Startzeit der fehlerhaften Anwendung: 0xlegoland.exe0 Pfad der fehlerhaften Anwendung: legoland.exe1 Pfad des fehlerhaften Moduls: legoland.exe2 Berichtskennung: legoland.exe3 Error: (06/15/2015 02:23:59 PM) (Source: Windows Backup) (EventID: 4104) (User: ) Description: Die Sicherung war nicht erfolgreich. Fehler: "Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005)" Error: (06/15/2015 06:27:53 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wlmail.exe, Version 14.0.8089.726 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 20bc Startzeit: 01d0a72357fe1421 Endzeit: 20 Anwendungspfad: C:\Program Files\Windows Live\Mail\wlmail.exe Berichts-ID: e0ef34aa-1316-11e5-977e-002618f9ca5d Error: (06/15/2015 06:25:42 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wlmail.exe, Version 14.0.8089.726 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1fec Startzeit: 01d0a72282aa9518 Endzeit: 40 Anwendungspfad: C:\Program Files\Windows Live\Mail\wlmail.exe Berichts-ID: 8e335d02-1316-11e5-977e-002618f9ca5d Error: (06/15/2015 02:09:41 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2492256 Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2492256 Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/14/2015 06:52:19 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7332 System errors: ============= Error: (06/15/2015 05:20:20 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:20:10 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:19:15 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:18:50 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:16:54 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:08:49 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:07:51 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:06:06 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 04:43:24 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Bytes Speicher konnten durch den DNS-Proxy-Agent nicht zugeordnet werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner Fehler ist im Speicher-Manager aufgetreten. Error: (06/15/2015 04:37:52 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Bytes Speicher konnten durch den DNS-Proxy-Agent nicht zugeordnet werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner Fehler ist im Speicher-Manager aufgetreten. Microsoft Office: ========================= Error: (06/15/2015 06:34:40 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: FRST.exe13.6.2015.026c001d0a788caaf2ddf0C:\Users\Philipp\Desktop\FRST.exe36209be9-137c-11e5-977e-002618f9ca5d Error: (06/15/2015 05:07:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: legoland.exe0.2.2.93934d3e8legoland.exe0.2.2.93934d3e8c00000050005241a23a001d0a77cca8cafe5C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exeC:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe4955926e-1370-11e5-977e-002618f9ca5d Error: (06/15/2015 02:23:59 PM) (Source: Windows Backup) (EventID: 4104) (User: ) Description: Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005) Error: (06/15/2015 06:27:53 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wlmail.exe14.0.8089.72620bc01d0a72357fe142120C:\Program Files\Windows Live\Mail\wlmail.exee0ef34aa-1316-11e5-977e-002618f9ca5d Error: (06/15/2015 06:25:42 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wlmail.exe14.0.8089.7261fec01d0a72282aa951840C:\Program Files\Windows Live\Mail\wlmail.exe8e335d02-1316-11e5-977e-002618f9ca5d Error: (06/15/2015 02:09:41 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\EPSON Software\Download Navigator\EPSDNLMW64.EXE Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2492256 Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2492256 Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/14/2015 06:52:19 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7332 ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T6500 @ 2.10GHz Percentage of memory in use: 48% Total physical RAM: 3071.27 MB Available physical RAM: 1570.68 MB Total Pagefile: 6140.86 MB Available Pagefile: 3668.44 MB Total Virtual: 3071.88 MB Available Virtual: 2926.79 MB ==================== Drives ================================ Drive c: (VistaOS) (Fixed) (Total:149.04 GB) (Free:24.31 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:137.33 GB) (Free:68.21 GB) NTFS ==================== MBR & Partition Table ================== ==================== End of log ============================ |
15.06.2015, 17:51 | #4 |
| DHL Spam Mail -> Trojaner/Virus? Nun noch ein Scan als Admin (hab beim Auswahlfenster einfach einen genommen): Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-06-2015 Ran by Beamer (administrator) on SCHEFFLER-PC on 15-06-2015 18:45:13 Running from C:\Users\Philipp\Desktop Loaded Profiles: Jeffel & Philipp & Beamer & Ellen & Manuel & Manuel (Available Profiles: Jeffel & Philipp & Beamer & Ellen & Manuel & Manuel) Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE (DeviceVM) C:\ASUS.SYS\DVMExportService.exe () C:\Program Files\MyPublicWiFi\PublicWiFiService.exe () C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe (DEVGURU Co., LTD.) D:\Samsung Kies\USB Drivers\25_escape\conn\ss_conn_service.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe (Google Inc.) C:\Program Files\Google\Update\1.3.27.5\GoogleCrashHandler.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (AMD) C:\Windows\System32\atieclxx.exe (ATK) C:\Program Files\P4G\BatteryLife.exe () C:\Program Files\Wireless Console 2\wcourier.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\WDC.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (ASUS) C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files\ASUS\ATK Media\DMedia.exe (AlcorMicro Co., Ltd.) C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe (ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe () D:\Gaming Maus\DareUMonitor.exe (SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\Event Manager\EEventManager.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-Agent.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Google) C:\Program Files\Google\Drive\googledrivesync.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATILEE.EXE (Dropbox, Inc.) C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Google) C:\Program Files\Google\Drive\googledrivesync.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe (Valve Corporation) D:\Steam\Steam.exe (Valve Corporation) D:\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation) D:\Steam\bin\steamwebhelper.exe (Valve Corporation) D:\Steam\bin\steamwebhelper.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1549608 2009-08-17] (Synaptics Incorporated) HKLM\...\Run: [HControlUser] => C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM\...\Run: [ATKOSD2] => C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS) HKLM\...\Run: [ATKMEDIA] => C:\Program Files\ASUS\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS) HKLM\...\Run: [AmIcoSinglun] => C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe [233472 2009-07-31] (AlcorMicro Co., Ltd.) HKLM\...\Run: [ADSMTray] => C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [272952 2009-06-24] (ASUSTek Computer Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [730416 2015-06-11] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Dare-U mouse] => D:\Gaming Maus\DareUMonitor.exe [786432 2012-11-20] () HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1065024 2014-05-02] (SEIKO EPSON CORPORATION) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [BlueStacks Agent] => C:\Program Files\BlueStacks\HD-Agent.exe [884440 2015-05-28] (BlueStack Systems, Inc.) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.Systray.exe [130864 2015-05-21] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [144384 2010-11-20] (Microsoft Corporation) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [DAEMON Tools Lite] => D:\DT\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [Dropbox Update] => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-13] (Dropbox, Inc.) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil32_17_0_0_188_Plugin.exe [927920 2015-05-20] (Adobe Systems Incorporated) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\MountPoints2: {7ed2759d-f168-11de-961b-806e6f6e6963} - E:\NightRacer.EXE HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [DAEMON Tools Lite] => D:\DT\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [Steam] => D:\Steam\steam.exe [2892992 2015-06-04] (Valve Corporation) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [21969480 2015-05-19] (Google) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [EADM] => C:\Program Files\Origin\Origin.exe [3632472 2015-06-08] (Electronic Arts) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\RunOnce: [iCloud] => C:\Program Files\Common Files\Apple\Internet Services\iCloud.exe [43816 2015-04-26] (Apple Inc.) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe HKU\S-1-5-21-644356114-2566177158-2502637254-1008\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-644356114-2566177158-2502637254-1008\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe HKU\S-1-5-21-644356114-2566177158-2502637254-1008\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation) HKU\S-1-5-21-644356114-2566177158-2502637254-1011\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe HKU\S-1-5-21-644356114-2566177158-2502637254-1011\...\MountPoints2: {7ed2759d-f168-11de-961b-806e6f6e6963} - E:\NightRacer.EXE Lsa: [Notification Packages] scecli C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT Startup: C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-05-12] ShortcutTarget: Dropbox.lnk -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) Startup: C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2011-03-30] ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-12-13] ShortcutTarget: Dropbox.lnk -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2011-03-31] ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ShellIconOverlayIdentifiers: [ADSMOverlayIcon] -> {A825576B-0042-4F0F-8FB0-93CE0F054E69} => C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll [2007-06-15] () ShellIconOverlayIdentifiers: [ADSMOverlayIcon1] -> {A8D448F4-0431-45AC-9F5E-E1B434AB2249} => C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll [2007-06-01] () ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) GroupPolicyUsers\S-1-5-21-644356114-2566177158-2502637254-1011\User: Group Policy Restriction detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-644356114-2566177158-2502637254-1004\User: Group Policy Restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.de/ HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/ HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com/ HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://www.google.de/ HKU\S-1-5-21-644356114-2566177158-2502637254-1005\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs HKU\S-1-5-21-644356114-2566177158-2502637254-1005\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com HKU\S-1-5-21-644356114-2566177158-2502637254-1008\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp URLSearchHook: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File URLSearchHook: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File URLSearchHook: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File SearchScopes: HKLM -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_de SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=IEFM1&q={searchTerms}&src={referrer:source?} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&affID=119649&babsrc=SP_ss&mntrId=9a1a16840000000000002225d303ecbc SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_de SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {7B55E28C-0351-41CC-AC14-22094D95924D} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {76193214-59DA-47ED-BB15-3BCACFC2C36A} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {7B55E28C-0351-41CC-AC14-22094D95924D} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {B1316728-20A2-4B2A-9CD7-B52C1B2CB91A} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> {7B55E28C-0351-41CC-AC14-22094D95924D} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1008 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1008 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1011 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File BHO: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH) Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation) Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.177.1 FireFox: ======== FF ProfilePath: C:\Users\Beamer\AppData\Roaming\Mozilla\Firefox\Profiles\5tcpn7ab.default FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Ask.com FF Keyword.URL: hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-4&o=APN10261&locale=de_DE&apn_uid=71BBFB7C-F00D-4E16-9DA1-51512365ABFE&apn_ptnrs=%5EAGS&apn_sauid=A57E7053-3C73-4602-928F-51C6D1D21E5C&apn_dtid=%5EYYYYYY%5EYY%5EDE&&q= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-20] () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2009-09-07] (CANON INC.) FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-644356114-2566177158-2502637254-1004: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Philipp\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-10-03] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-644356114-2566177158-2502637254-1008: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Ellen & Manuel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-11-25] (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-02-16] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-02-16] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-02-16] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-02-16] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-02-16] (Apple Inc.) FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-06-02] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-12-13] FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-06-02] Chrome: ======= CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.) [File not signed] S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [827184 2015-06-11] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [450808 2015-06-11] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [450808 2015-06-11] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1188360 2015-06-11] (Avira Operations GmbH & Co. KG) R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS) R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed] R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [208632 2015-05-21] (Avira Operations GmbH & Co. KG) S3 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [433880 2015-05-28] (BlueStack Systems, Inc.) S3 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [413400 2015-05-28] (BlueStack Systems, Inc.) S3 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [806616 2015-05-28] (BlueStack Systems, Inc.) R2 EpsonScanSvc; C:\Windows\system32\EscSvc.exe [126128 2012-05-17] (Seiko Epson Corporation) R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE [143424 2013-04-26] (SEIKO EPSON CORPORATION) R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed] S3 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] () R2 MDES; C:\ASUS.SYS\DVMExportService.exe [307200 2008-10-21] (DeviceVM) [File not signed] R2 MyPublicWiFiService; C:\Program Files\MyPublicWiFi\PublicWiFiService.exe [756224 2013-04-03] () [File not signed] S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1997168 2015-06-08] (Electronic Arts) R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () R2 ss_conn_service; D:\Samsung Kies\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) R3 WinHttpAutoProxySvc; winhttp.dll [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AmUStor; C:\Windows\System32\drivers\AmUStor.SYS [25600 2009-07-24] (Alcor Micro, Corp.) R0 AsDsm; C:\Windows\system32\Drivers\AsDsm.sys [30264 2009-12-25] (ASUSTek Computer Inc) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-06-11] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-06-11] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-20] (Avira Operations GmbH & Co. KG) R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [105728 2014-09-29] (AVM Berlin) R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [105728 2014-09-29] (AVM Berlin) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-11] (Avira Operations GmbH & Co. KG) R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [131288 2015-05-28] (BlueStack Systems) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-11-21] (Disc Soft Ltd) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] () S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( ) R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2009-06-18] (Windows (R) Win 7 DDK provider) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [14392 2009-05-13] (ASUS) R1 ndiskhaz; C:\Windows\System32\DRIVERS\ndiskhaz.sys [25416 2012-12-07] (Khalil Azzouzi) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1766592 2009-06-05] () R0 sptd; C:\Windows\System32\Drivers\sptd.sys [324096 2013-11-21] (Duplex Secure Ltd.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-06-11] (Avira Operations GmbH & Co. KG) R3 stdriver; C:\Windows\System32\DRIVERS\stdriver32.sys [52312 2012-06-21] (NCH Software) U3 asify6mi; C:\Windows\system32\Drivers\asify6mi.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder) U3 aydu7eur; C:\Windows\system32\Drivers\aydu7eur.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder) S3 dgderdrv; System32\drivers\dgderdrv.sys [X] S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X] S3 ipswuio; System32\DRIVERS\ipswuio.sys [X] S3 RTHDMIAzAudService; system32\drivers\RtHDMIV.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-15 18:45 - 2015-06-15 18:46 - 00033138 _____ C:\Users\Philipp\Desktop\FRST.txt 2015-06-15 18:32 - 2015-06-15 18:45 - 00000000 ____D C:\FRST 2015-06-15 18:13 - 2015-06-15 18:13 - 01148416 _____ (Farbar) C:\Users\Philipp\Desktop\FRST.exe 2015-06-14 18:33 - 2015-06-14 18:33 - 00002991 _____ C:\Users\Philipp\AppData\Local\recently-used.xbel 2015-06-14 16:21 - 2015-06-14 16:21 - 00000012 ____H C:\dvmexp.idx 2015-06-14 08:12 - 2015-06-14 08:12 - 00000000 ___HD C:\dvmexp 2015-06-13 14:19 - 2015-06-13 14:19 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-06-13 14:18 - 2015-06-15 18:23 - 00001228 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job 2015-06-13 14:18 - 2015-06-15 14:23 - 00001176 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job 2015-06-13 14:18 - 2015-06-13 14:18 - 00000000 ____D C:\Users\Jeffel\AppData\Local\Dropbox 2015-06-13 14:18 - 2015-06-13 14:18 - 00000000 ____D C:\ProgramData\Dropbox 2015-06-11 20:32 - 2015-06-11 20:32 - 00131180 _____ C:\Users\Manuel\Downloads\Motorrad Profi 4 - kostenlos online spielen.htm 2015-06-11 18:41 - 2015-06-11 18:41 - 00001085 _____ C:\Users\Public\Desktop\Avira.lnk 2015-06-10 10:09 - 2015-06-02 21:35 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-06-10 10:09 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-06-10 10:09 - 2015-05-25 19:00 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-06-10 10:09 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-06-10 10:09 - 2015-05-23 05:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-06-10 10:09 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-06-10 10:09 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-06-10 10:09 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-06-10 10:09 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-06-10 10:09 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-06-10 10:09 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-06-10 10:09 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-06-10 10:09 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-06-10 10:09 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-06-10 10:09 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-06-10 10:09 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-06-10 10:09 - 2015-05-23 05:05 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-06-10 10:09 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-06-10 10:09 - 2015-05-23 05:00 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-06-10 10:09 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-06-10 10:09 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-06-10 10:09 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-06-10 10:09 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-06-10 10:09 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-06-10 10:09 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-06-10 10:09 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-06-10 10:09 - 2015-05-23 04:38 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-06-10 10:09 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-06-10 10:09 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-06-10 10:09 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-06-10 10:09 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-06-10 10:09 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-06-10 10:09 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-06-10 10:09 - 2015-05-22 20:03 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-06-10 10:09 - 2015-05-22 19:58 - 00901120 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-06-10 10:09 - 2015-05-21 15:20 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-06-10 10:08 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-06-10 10:08 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-06-10 10:08 - 2015-05-25 20:07 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-06-10 10:08 - 2015-05-25 20:07 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-06-10 10:08 - 2015-05-25 20:04 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00853504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-06-10 10:08 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe 2015-06-10 10:08 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-06-10 10:08 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-06-10 10:08 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-06-10 10:08 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-06-10 10:08 - 2015-05-25 18:53 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2015-06-10 10:08 - 2015-05-09 05:14 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-06-10 10:08 - 2015-05-09 05:13 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-06-10 10:08 - 2015-05-09 05:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-06-10 10:08 - 2015-05-09 05:12 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-06-10 10:08 - 2015-05-09 05:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 03:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 03:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-06-10 10:08 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-06-10 10:08 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-06-10 10:08 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-06-10 10:08 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-06-10 10:08 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-06-10 10:08 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-06-09 17:20 - 2015-06-09 17:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 2015-06-09 17:20 - 2015-06-09 17:21 - 00000000 ____D C:\Program Files\BlueStacks 2015-06-09 17:20 - 2015-06-09 17:20 - 00000000 ____D C:\ProgramData\BlueStacks 2015-06-09 17:18 - 2015-06-09 17:18 - 15738056 _____ C:\Users\Philipp\Downloads\CloudMusic_official_2.7.1.apk 2015-06-09 17:18 - 2015-06-09 17:18 - 14155832 _____ (BlueStack Systems Inc.) C:\Users\Philipp\Downloads\BlueStacks-ThinInstaller.exe 2015-06-09 15:44 - 2015-05-09 05:14 - 02937344 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 02045952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-06-09 15:44 - 2015-05-09 05:13 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-06-09 15:44 - 2015-05-09 05:13 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-06-09 15:44 - 2015-05-09 05:13 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-06-09 15:44 - 2015-05-09 05:13 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-06-06 18:11 - 2015-06-06 18:11 - 00000000 ____D C:\Users\Beamer\AppData\Local\GWX 2015-06-06 11:34 - 2015-06-07 21:06 - 00000000 ____D C:\Users\Philipp\Documents\Joerg Riesa 2015-06-04 20:15 - 2015-06-04 20:16 - 00103104 _____ C:\Users\Manuel\Downloads\Crazy Skater - kostenlos online spielen.htm 2015-06-04 19:22 - 2015-06-04 19:22 - 00002121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2015-06-03 18:24 - 2015-06-03 18:24 - 00000000 ____D C:\Users\Manuel\AppData\Local\GWX 2015-06-03 16:37 - 2015-06-03 16:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2015-06-02 15:47 - 2015-06-04 18:42 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-06-01 20:38 - 2015-06-01 20:38 - 00000000 ____D C:\Users\Jeffel\AppData\Local\GWX 2015-06-01 19:02 - 2015-06-01 19:02 - 00000000 ____D C:\Users\Ellen & Manuel\AppData\Local\GWX 2015-06-01 18:03 - 2015-06-01 18:03 - 00000000 ____D C:\Users\Philipp\AppData\Local\GWX 2015-05-31 15:23 - 2015-05-31 15:43 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dual Monitor 2015-05-31 15:23 - 2015-05-31 15:23 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dual Monitor 2015-05-20 19:51 - 2015-05-20 19:51 - 00177664 _____ C:\Users\Philipp\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-20 17:18 - 2015-04-11 05:07 - 00054656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys 2015-05-20 17:18 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-05-20 17:18 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll 2015-05-17 19:56 - 2015-06-15 17:56 - 00000917 _____ C:\Windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job 2015-05-17 19:56 - 2015-06-15 17:56 - 00000731 _____ C:\Windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job 2015-05-16 20:06 - 2015-05-16 20:06 - 00275744 _____ C:\Windows\Minidump\051615-38750-01.dmp 2015-05-16 09:04 - 2015-05-16 09:04 - 00172295 _____ C:\Users\Philipp\Documents\Konfiguration FritzBox.xps ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-15 18:19 - 2012-04-04 22:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-06-15 18:10 - 2014-12-31 17:10 - 00000917 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job 2015-06-15 18:10 - 2014-12-31 17:10 - 00000731 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job 2015-06-15 18:10 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\system32\FxsTmp 2015-06-15 18:04 - 2010-01-31 18:04 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-06-15 17:04 - 2013-11-21 19:48 - 00000000 ____D C:\Users\Beamer\AppData\Roaming\DAEMON Tools Lite 2015-06-15 16:40 - 2009-12-25 17:20 - 00019456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-06-15 16:40 - 2009-12-25 17:20 - 00019456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-06-15 16:39 - 2012-12-17 20:34 - 00000000 ___RD C:\Users\Philipp\Documents\Dropbox 2015-06-15 16:38 - 2014-07-12 11:12 - 00000000 ___RD C:\Users\Philipp\Google Drive 2015-06-15 16:38 - 2010-12-01 14:28 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dropbox 2015-06-15 16:35 - 2010-01-31 18:04 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-06-15 08:20 - 2009-12-25 18:22 - 01411283 _____ C:\Windows\WindowsUpdate.log 2015-06-15 06:48 - 2010-09-11 19:48 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Skype 2015-06-15 06:45 - 2014-07-30 10:13 - 00000000 __SHD C:\Users\Jeffel\AppData\Local\EmieUserList 2015-06-15 06:45 - 2014-07-30 10:13 - 00000000 __SHD C:\Users\Jeffel\AppData\Local\EmieSiteList 2015-06-15 06:11 - 2009-08-20 05:40 - 01620684 _____ C:\Windows\system32\PerfStringBackup.INI 2015-06-14 20:33 - 2012-12-30 21:21 - 00000000 ___RD C:\Users\Jeffel\Dropbox 2015-06-14 20:33 - 2012-12-30 21:17 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Dropbox 2015-06-14 19:33 - 2010-10-18 18:21 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Skype 2015-06-14 18:34 - 2014-11-23 16:42 - 00000000 ____D C:\Users\Philipp\.gimp-2.8 2015-06-14 17:18 - 2013-03-30 18:22 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\.minecraft 2015-06-14 16:36 - 2014-11-23 16:44 - 00000000 ____D C:\Users\Philipp\AppData\Local\gtk-2.0 2015-06-14 16:21 - 2009-08-19 05:27 - 00000000 ___HD C:\temp 2015-06-14 08:15 - 2013-02-10 11:44 - 00000438 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2015-06-14 08:12 - 2015-04-02 11:31 - 00244957 _____ C:\Windows\setupact.log 2015-06-14 08:12 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-06-13 13:07 - 2014-07-12 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2015-06-11 18:47 - 2015-04-04 08:21 - 00002266 _____ C:\Windows\PFRO.log 2015-06-11 18:47 - 2011-10-20 18:09 - 00000000 ____D C:\ProgramData\Avira 2015-06-11 18:41 - 2014-08-25 20:44 - 00000000 ____D C:\ProgramData\Package Cache 2015-06-11 18:40 - 2015-03-05 16:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-06-11 18:40 - 2012-11-02 20:39 - 00000000 ____D C:\Program Files\Avira 2015-06-11 12:09 - 2012-11-02 20:40 - 00136728 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-06-11 12:09 - 2012-11-02 20:40 - 00108448 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-06-11 12:09 - 2012-11-02 20:40 - 00031848 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\ssmdrv.sys 2015-06-11 09:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2015-06-11 08:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2015-06-10 17:55 - 2014-05-29 20:43 - 00000000 ____D C:\Users\Philipp\.android 2015-06-10 17:19 - 2012-04-04 22:24 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-06-10 17:19 - 2011-06-10 19:15 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-06-10 15:43 - 2015-04-02 11:30 - 00572992 _____ C:\Windows\system32\FNTCACHE.DAT 2015-06-10 15:05 - 2014-12-10 22:23 - 00000000 ____D C:\Windows\system32\appraiser 2015-06-10 15:05 - 2014-04-26 10:01 - 00000000 ___SD C:\Windows\system32\CompatTel 2015-06-10 15:04 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2015-06-10 10:31 - 2009-08-19 04:00 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-06-10 10:25 - 2013-07-28 23:00 - 00000000 ____D C:\Windows\system32\MRT 2015-06-10 10:14 - 2009-12-29 22:28 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-06-09 17:21 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Libraries 2015-06-08 18:27 - 2013-06-17 09:00 - 00000000 ____D C:\ProgramData\Origin 2015-06-08 18:20 - 2013-06-17 11:51 - 00000000 ____D C:\Users\Beamer\AppData\Roaming\Origin 2015-06-08 18:14 - 2013-06-17 09:00 - 00000000 ____D C:\Program Files\Origin 2015-06-08 17:04 - 2013-11-27 20:45 - 00000000 ____D C:\Program Files\Common Files\Steam 2015-06-07 08:24 - 2009-12-25 20:08 - 00000354 _____ C:\Windows\Tasks\Driver Robot.job 2015-06-06 10:46 - 2012-05-17 13:18 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Notepad++ 2015-06-04 19:21 - 2009-08-19 04:20 - 00000000 ____D C:\Program Files\Google 2015-06-04 18:42 - 2012-05-11 15:08 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-06-03 16:42 - 2014-04-28 18:03 - 00000000 ____D C:\Program Files\CCleaner 2015-05-31 15:54 - 2012-12-22 15:49 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Audacity 2015-05-30 22:11 - 2009-11-24 20:19 - 00045056 _____ C:\Windows\system32\acovcnt.exe 2015-05-30 12:55 - 2010-03-06 18:42 - 00000000 ____D C:\Users\Jeffel\Documents\Kigo 2015-05-27 18:16 - 2010-01-25 18:43 - 00000000 ____D C:\Users\Jeffel\Documents\Telefon 2015-05-26 11:56 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2015-05-21 21:22 - 2011-08-28 09:47 - 00000000 ____D C:\Users\Beamer 2015-05-20 20:24 - 2012-11-02 20:40 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2015-05-20 17:19 - 2015-04-04 20:15 - 00000000 ___SD C:\Windows\system32\GWX 2015-05-20 17:07 - 2010-10-21 17:44 - 00000000 ____D C:\Users\Philipp\AppData\Local\Adobe 2015-05-20 17:06 - 2011-08-28 10:41 - 00000000 ____D C:\Users\Beamer\AppData\Local\Adobe 2015-05-16 20:06 - 2012-07-28 22:41 - 00000000 ____D C:\Windows\Minidump 2015-05-16 19:42 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF 2015-05-16 08:11 - 2010-12-01 14:28 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox ==================== Files in the root of some directories ======= 2007-06-12 10:34 - 2007-06-12 10:34 - 0035822 _____ () C:\Program Files\Common Files\ASPG_icon.ico 2008-05-22 09:35 - 2008-05-22 09:35 - 0051962 _____ () C:\Program Files\Common Files\banner.jpg 2009-04-08 11:31 - 2009-04-08 11:31 - 0106496 _____ () C:\Program Files\Common Files\CPInstallAction.dll 2008-08-11 22:45 - 2008-08-11 22:45 - 0155648 _____ (ASUS) C:\Program Files\Common Files\MSIactionall.dll 2015-01-04 12:55 - 2015-01-04 12:55 - 0000459 _____ () C:\Users\Beamer\AppData\Roaming\Drives Meter_Settings.ini 2012-04-23 18:17 - 2013-05-02 17:27 - 0007598 _____ () C:\Users\Beamer\AppData\Local\Resmon.ResmonCfg 2010-09-11 19:55 - 2010-09-11 19:55 - 0000056 ____H () C:\ProgramData\ezsidmv.dat Files to move or delete: ==================== C:\Users\Jeffel\i2errDeu.dll Some files in TEMP: ==================== C:\Users\Beamer\AppData\Local\Temp\atcMedia1291428144436.exe C:\Users\Beamer\AppData\Local\Temp\avgnt.exe C:\Users\Ellen & Manuel\AppData\Local\Temp\avgnt.exe C:\Users\Jeffel\AppData\Local\Temp\AskSLib.dll C:\Users\Jeffel\AppData\Local\Temp\AutoRun.exe C:\Users\Jeffel\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Jeffel\AppData\Local\Temp\avgnt.exe C:\Users\Jeffel\AppData\Local\Temp\Delay.exe C:\Users\Jeffel\AppData\Local\Temp\DirectoryRemovalUtility.exe C:\Users\Jeffel\AppData\Local\Temp\drm_dialogs.dll C:\Users\Jeffel\AppData\Local\Temp\drm_dyndata_7370012.dll C:\Users\Jeffel\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpw138tc.dll C:\Users\Jeffel\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\Jeffel\AppData\Local\Temp\FlashPlayerUpdate01.exe C:\Users\Jeffel\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe C:\Users\Jeffel\AppData\Local\Temp\i4jdel0.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u21-windows-i586-iftw-rv.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u22-windows-i586-iftw-rv.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe C:\Users\Jeffel\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe C:\Users\Jeffel\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe C:\Users\Jeffel\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Jeffel\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Jeffel\AppData\Local\Temp\mpsetup.exe C:\Users\Jeffel\AppData\Local\Temp\MSETUP4.EXE C:\Users\Jeffel\AppData\Local\Temp\ose00000.exe C:\Users\Jeffel\AppData\Local\Temp\PicasaUpdater_7e04.exe C:\Users\Jeffel\AppData\Local\Temp\RemoveGO.exe C:\Users\Jeffel\AppData\Local\Temp\sdanircmdc.exe C:\Users\Jeffel\AppData\Local\Temp\sdapskill.exe C:\Users\Jeffel\AppData\Local\Temp\setup.exe C:\Users\Jeffel\AppData\Local\Temp\SkypeSetup.exe C:\Users\Jeffel\AppData\Local\Temp\uninst1.exe C:\Users\Jeffel\AppData\Local\Temp\vcredist_x86.exe C:\Users\Jeffel\AppData\Local\Temp\_is9E90.exe C:\Users\Jeffel\AppData\Local\Temp\_isBF68.exe C:\Users\Manuel\AppData\Local\Temp\avgnt.exe C:\Users\Philipp\AppData\Local\Temp\avgnt.exe C:\Users\Philipp\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpvefjun.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-06-04 23:19 ==================== End of log ============================ |
15.06.2015, 17:52 | #5 |
| DHL Spam Mail -> Trojaner/Virus? [CODE]Additional FRST Logfile: Code:
ATTFilter scan result of Farbar Recovery Scan Tool (x86) Version: 13-06-2015 Ran by Beamer at 2015-06-15 18:47:13 Running from C:\Users\Philipp\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-644356114-2566177158-2502637254-500 - Administrator - Disabled) Beamer (S-1-5-21-644356114-2566177158-2502637254-1005 - Administrator - Enabled) => C:\Users\Beamer Ellen & Manuel (S-1-5-21-644356114-2566177158-2502637254-1008 - Limited - Enabled) => C:\Users\Ellen & Manuel Gast (S-1-5-21-644356114-2566177158-2502637254-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-644356114-2566177158-2502637254-1010 - Limited - Enabled) Jeffel (S-1-5-21-644356114-2566177158-2502637254-1000 - Administrator - Enabled) => C:\Users\Jeffel Manuel (S-1-5-21-644356114-2566177158-2502637254-1011 - Limited - Enabled) => C:\Users\Manuel Philipp (S-1-5-21-644356114-2566177158-2502637254-1004 - Limited - Enabled) => C:\Users\Philipp ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 1&1 SmartFax (HKLM\...\1&1 SmartFax) (Version: 2.00.224 - 1&1 Internet AG) 3dPageFlip Editor (HKLM\...\3dPageFlip PDF Editor_is1) (Version: - 3dPageFlip Solution) Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adblock Plus für IE (32-Bit) (HKLM\...\{654F389B-E402-4F7B-BA6D-DA732BB57ACB}) (Version: 1.4 - Eyeo GmbH) Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated) Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Alcor Micro USB Card Reader (HKLM\...\AmUStor) (Version: 1.4.1217.35202 - Alcor Micro Corp.) Alcor Micro USB Card Reader (Version: 1.4.1217.35202 - Alcor Micro Corp.) Hidden Apple Application Support (32-Bit) (HKLM\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASUS CopyProtect (HKLM\...\{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}) (Version: 1.0.0015 - ASUS) ASUS Data Security Manager (HKLM\...\{FA2092C5-7979-412D-A962-6485274AE1EE}) (Version: 1.00.0014 - ASUS) ASUS FancyStart (HKLM\...\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}) (Version: 1.0.6 - ASUSTeK Computer Inc.) ASUS LifeFrame3 (HKLM\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS) ASUS Live Update (HKLM\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS) ASUS MultiFrame (HKLM\...\{9D48531D-2135-49FC-BC29-ACCDA5396A76}) (Version: 1.0.0019 - ASUS) ASUS Power4Gear eXtreme (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.0.19 - ASUS) ASUS SmartLogon (HKLM\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0007 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0028 - ASUS) ASUS Touch Pad Extra (HKLM\...\{DB891739-2EB3-45A8-9CBD-941C255CECD4}) (Version: - ) ASUS Virtual Camera (HKLM\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.19 - asus) Asus_Camera_ScreenSaver (HKLM\...\Asus_Camera_ScreenSaver) (Version: 2.0.0008 - ASUS) Atheros Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - Atheros) ATI Catalyst Install Manager (HKLM\...\{0AE24BD5-185C-436C-D93D-50574523C6C4}) (Version: 3.0.732.0 - ATI Technologies, Inc.) ATK Generic Function Service (HKLM\...\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}) (Version: 1.00.0008 - ATK) ATK Hotkey (HKLM\...\{7C05592D-424B-46CB-B505-E0013E8E75C9}) (Version: 1.0.0053 - ASUS) ATK Media (HKLM\...\{D1E5870E-E3E5-4475-98A6-ADD614524ADF}) (Version: 2.0.0006 - ASUS) ATKOSD2 (HKLM\...\{3B05F2FB-745B-4012-ADF2-439F36B2E70B}) (Version: 7.0.0006 - ASUS) aTube Catcher (HKLM\...\aTube Catcher) (Version: 2.9.1462 - DsNET Corp) aTube Catcher Version 3.8 (HKLM\...\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp) Audacity 2.0.2 (HKLM\...\Audacity_is1) (Version: 2.0.2 - Audacity Team) Avanquest update (HKLM\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.29 - Avanquest Software) Avidemux 2.6 (32-bit) (HKLM\...\Avidemux 2.6) (Version: 2.6.8.9046 - ) Avira (HKLM\...\{0696cc37-db90-4000-be99-4a173ca7c8af}) (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG) Hidden Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.11.574 - Avira Operations GmbH & Co. KG) Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION Bandicam (HKLM\...\Bandicam) (Version: 1.8.5.302 - Bandisoft.com) Battlefield 1942™ (HKLM\...\{5BE7BD06-512B-43bf-AD78-3BD2A5F5F7B3}) (Version: 1.6.20.0 - Electronic Arts) Bejeweled® 3 (HKLM\...\{E99C27B2-EB2E-4244-9F5C-A96F55100F0C}) (Version: 1.1.13.4753 - Electronic Arts, Inc.) BlueStacks App Player (HKLM\...\BlueStacks App Player) (Version: 0.9.27.5408 - BlueStack Systems, Inc.) BlueStacks Notification Center (HKLM\...\{C1F53C9F-C560-4292-9237-12786FE6BF62}) (Version: 0.9.27.5408 - BlueStack Systems, Inc.) Bob baut einen Park (HKLM\...\{367EDD83-302F-48E6-8F77-B0B056125C2D}) (Version: 1.0.0 - ) Bob der Baumeister (HKLM\...\{8F2D21F9-F428-4EF2-8111-953EF3299EFB}) (Version: 1.0.0 - ) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\...\CANONIJPLM100) (Version: - ) Canon MP Navigator EX 3.0 (HKLM\...\MP Navigator EX 3.0) (Version: - ) Canon MP490 series Benutzerregistrierung (HKLM\...\Canon MP490 series Benutzerregistrierung) (Version: - ) Canon MP490 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series) (Version: - ) Canon Utilities Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version: - ) Canon Utilities My Printer (HKLM\...\CanonMyPrinter) (Version: - ) Canon Utilities Solution Menu (HKLM\...\CanonSolutionMenu) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform) Cisco EAP-FAST Module (HKLM\...\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM\...\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM\...\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.) Construction-Simulator 2015 (HKLM\...\Steam App 289950) (Version: - weltenbauer. Software Entwicklung GmbH) Core Temp version 0.99.7 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 0.99.7 - Arthur Liberman) Crusader No Remorse (HKLM\...\{2AEA735F-B393-4D89-93EF-5849CB72B4A3}) (Version: 1.0.0.2 - Electronic Arts) CyberLink LabelPrint (HKLM\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1720 - CyberLink Corp.) CyberLink Power2Go (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.2713 - CyberLink Corp.) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd) Diercke Globus Online (HKLM\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH) dm-Fotowelt (HKLM\...\dm-Fotowelt) (Version: 5.1.7 - CEWE Stiftung u Co. KGaA) Dolby Control Center (HKLM\...\{0F3C61B5-3051-4DE6-8A6A-45100BCC1F41}) (Version: 1.2.0704 - Dolby) Dropbox (HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Dropbox) (Version: 3.6.7 - Dropbox, Inc.) Dropbox (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Dropbox) (Version: 3.4.6 - Dropbox, Inc.) Druckerdeinstallation für EPSON XP-312 313 315 Series (HKLM\...\EPSON XP-312 313 315 Series) (Version: - SEIKO EPSON Corporation) Druckerdeinstallation für EPSON XP-412 413 415 Series (HKLM\...\EPSON XP-412 413 415 Series) (Version: - SEIKO EPSON Corporation) Dual Monitor 1.22 (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{64AA3F94-ED4A-4A4B-B72C-B7A1481ED5D8}_is1) (Version: 1.22.021813 - Cristi Diaconu) EA SPORTS FIFA World (HKLM\...\{8F9AC744-EEF6-43DB-A4B6-FA1A18F1C640}) (Version: 9.5.0.61021 - Electronic Arts, Inc.) Epson Connect Printer Setup (HKLM\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.3.0 - SEIKO EPSON CORPORATION) Epson Event Manager (HKLM\...\{0F13C24A-FFE2-4CD0-8E0B-DC804E0A0E0B}) (Version: 3.10.0035 - Seiko Epson Corporation) EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON-Handbücher (HKLM\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.32.0.0 - SEIKO EPSON CORPORATION) EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION) Express Gate (HKLM\...\{62CF8923-31DC-4285-A23C-17CE5AA6A679}) (Version: 1.0.3.2 - DeviceVM, Inc.) F1 2013 (HKLM\...\Steam App 223670) (Version: - Codemasters Birmingham) FIFA 09 (HKLM\...\{2315B23D-3E21-4920-837D-AE6460934ECB}) (Version: 1.0.1.1 - Electronic Arts) Firebird SQL Server - MAGIX Edition (HKLM\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG) FRITZ!Box USB-Fernanschluss (HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\2db37667170956ee) (Version: 2.3.2.0 - AVM Berlin) GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team) Globus Fotoservice 4.4 (HKLM\...\Globus Fotoservice_is1) (Version: - ) Google Drive (HKLM\...\{CBC9F5FD-5CFA-4A33-81CD-369EAB77E3A6}) (Version: 1.22.9403.0223 - Google, Inc.) Google Earth (HKLM\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden Google+ Auto Backup (HKLM\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google) Hot Wheels (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{CF36DD86-81D3-4D91-8F7A-344E0C1A4BFD}) (Version: 1.00.0000 - Activision Value) iCloud (HKLM\...\{9A07AB4F-6B53-43E9-B7FC-7892E8C26BE3}) (Version: 4.1.1.53 - Apple Inc.) Isola LEGO 2 (HKLM\...\{85967580-EBC2-11D4-AEA3-0050046A88ED}) (Version: - ) iTunes (HKLM\...\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.) Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden KingsoftOfficeXPlats 1.4 (HKLM\...\KingsoftOfficeXPlats) (Version: 1.4 - Kingsoft) LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version: - ) LBOTS Top mouse Driver (HKLM\...\{F1A273BD-6A9E-41D8-A111-5E56ACD286F8}) (Version: 1.0 - Togran) LEGO Racers 2 (HKLM\...\{3DD2E9EA-0544-4162-B8BE-E21E994E9F3B}) (Version: - ) LEGO® Star Wars™: Die Komplette Saga (HKLM\...\InstallShield_{D596980D-17BE-4425-B8F0-5640719AADE9}) (Version: 1.00.0000 - LucasArts) LEGO® Star Wars™: The Complete Saga (Version: 1.00.0000 - LucasArts) Hidden LEGOLAND (HKLM\...\LEGOLANDDeInstKey) (Version: - ) Logitech Gaming Software (HKLM\...\{648F9C94-EC44-487B-9DA4-44ED72A082CC}) (Version: 4.50 - ) MAGIX Speed burnR (MSI) (HKLM\...\MX.{16884C3D-3512-486D-A2F9-39071551BFEF}) (Version: 7.0.2.6 - MAGIX AG) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden MAGIX Video deluxe 2014 (HKLM\...\MX.{EA62B22F-AB0A-406B-80A9-8036D3CE3446}) (Version: 13.0.2.8 - MAGIX AG) MAGIX Video deluxe 2014 (Version: 13.0.2.8 - MAGIX AG) Hidden Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Outlook Connector (HKLM\...\{95120000-0122-0407-0000-0000000FF1CE}) (Version: 12.0.6423.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{AC4C38FD-A54C-4CA5-92EE-D983CD81293E}) (Version: 1.20.146.0 - Microsoft) Minecraft (HKLM\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) Minigolf (HKLM\...\Minigolf_is1) (Version: - Meridian93) Monkey's Adventures (HKLM\...\Monkey's Adventures_is1) (Version: - play-publishing.com) Motorola Driver Installation 3.4.0 (HKLM\...\{81B3BEF9-5D97-4096-86E9-5B48A5BC32D0}) (Version: 3.4.0 - Motorola Inc.) Motorola Phone Tools (HKLM\...\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}) (Version: 5.0.7a 4/01/2008 - Avanquest Software) Motorola Phone Tools (Version: 4.30 - BVRP Software) Hidden Motorola Phone Tools (Version: 5.00 - BVRP Software) Hidden Mozilla Firefox 38.0.5 (x86 de) (HKLM\...\Mozilla Firefox 38.0.5 (x86 de)) (Version: 38.0.5 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyPublicWiFi 5.1 (HKLM\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version: - TRUE Software) Mystery P.I. - The London Caper (HKLM\...\Mystery P.I. - The London Caper) (Version: - PopCap Games) NB Probe (HKLM\...\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}) (Version: - ) Need For Speed™ World (HKLM\...\{3AF1B16A-7DC9-4C80-BAEC-70B088A7C5B8}) (Version: 1.0.0.0 - Electronic Arts) Net4Switch (HKLM\...\{9D6D7811-43B3-463C-BC79-5D1755269989}) (Version: 1.00.0019 - ASUS) Norton Internet Security (Version: 16.0.0.125 - Symantec Corporation) Hidden Notepad++ (HKLM\...\Notepad++) (Version: 6.1.2 - ) OpenAL (HKLM\...\OpenAL) (Version: - ) Oracle VM VirtualBox 4.3.2 (HKLM\...\{91E5A436-8560-4621-9F26-D7050D078832}) (Version: 4.3.2 - Oracle Corporation) Origin (HKLM\...\Origin) (Version: 9.2.1.4399 - Electronic Arts, Inc.) pdfsam (HKLM\...\pdfsam) (Version: 2.2.0 - ) Peter Lustigs Verkehrsschule (HKLM\...\Verkehrsschule) (Version: - ) Pflanzen gegen Zombies™ (HKLM\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.) QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) Roads Of Rome (HKLM\...\Roads Of Rome_is1) (Version: - Realore Studios) Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.) Samsung Kies (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) SimCity 2000 Special Edition (HKLM\...\{59D2C751-F7BE-4E9F-9C8C-1F16013802C7}) (Version: 2.0.0.1 - Electronic Arts) SimCity™ (HKLM\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts) Skype™ 7.1 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.) Software Updater (HKLM\...\{E1BAD1BA-C0E8-4018-9281-E7D2C6B07474}) (Version: 4.3.6 - SEIKO EPSON CORPORATION) Steam (HKLM\...\Steam) (Version: - Valve Corporation) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.1.1 - Synaptics Incorporated) Syndicate (HKLM\...\{64CFBAAB-46F7-4628-8D9B-E656A8C11CDB}) (Version: 2.0.0.3 - Electronic Arts) System Requirements Lab CYRI (HKLM\...\{E77DA909-3532-4C95-AFEB-06310E88462A}) (Version: 6.0.3.0 - Husdawg, LLC) Theme Hospital (HKLM\...\{5118A4C2-C8A4-4CE5-AC37-F3E51C25402F}) (Version: 3.0.0.2 - Electronic Arts) TIPP10 Version 2.1.0 (HKLM\...\TIPP10_is1) (Version: - (c) 2006-2011, Tom Thielicke IT Solutions) TmNationsForever (HKLM\...\TmNationsForever_is1) (Version: - Nadeo) TOGGO PC-Spielebox 2 (HKLM\...\{67EECE0C-8B6C-4D09-989D-D39BC9BBCA0E}) (Version: 1.00.0000 - ) Toyland Racer (HKLM\...\Toyland Racer) (Version: - ) Unified Remote (HKLM\...\{D7930C67-5816-417B-BF28-54BB75EFDAF9}) (Version: 2.14.4.0 - Unified Remote) Unity Web Player (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Unity Web Player (HKU\S-1-5-21-644356114-2566177158-2502637254-1008\...\UnityWebPlayer) (Version: - Unity Technologies ApS) upapp (HKLM\...\{4EF69D40-4DC9-485E-95D3-B1C22F218FC8}) (Version: 0.20.0000 - Hewlett-Packard) USB 2.0 1.3M UVC WebCam (HKLM\...\USB 2.0 1.3M UVC WebCam) (Version: - ) Werksfeuerwehr-Simulator Version 1.0 (HKLM\...\{5F7ED0CD-E04E-4441-9E03-10AFDB654E96}_is1) (Version: - rondomedia Marketing & Vertriebs GmbH) Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live ID-Anmelde-Assistent (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Live Sync (HKLM\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation) Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) WinFlash (HKLM\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.29.0 - ASUS) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) Wireless Console 2 (HKLM\...\{83F73CB1-7705-49D1-9852-84D839CA2A45}) (Version: 2.0.10 - ATK) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\ProgramData\Skype\Plugins\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\ProgramData\Skype\Plugins\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Philipp\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{4D72E5BC-BC7C-11E0-83CA-10424824019B}\InprocServer32 -> C:\Users\Philipp\AppData\Local\AskToolbar\Downloaded Program Files\AviraIDW.dll (Ask.com) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{595EF3BD-A186-454A-810C-02015139ACDC}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\Avira.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{7F902AD4-FC6A-4B2F-8B8D-B6DD4E329B76}\InprocServer32 -> C:\Users\Philipp\AppData\Local\AskToolbar\Downloaded Program Files\AviraWidget.dll (Ask.com) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{A0359AE6-F410-4425-A975-684AAB785ABD}\InprocServer32 -> C:\Users\Philipp\AppData\Local\AskToolbar\Downloaded Program Files\AviraBrowserSecurity.dll (Ask.com) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\Philipp\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{EB959CA4-408B-4465-9CF5-7EBA7B885153}\InprocServer32 -> C:\Users\Philipp\AppData\Local\AskToolbar\Downloaded Program Files\AviraSafetyPrivacy.dll (Ask.com) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FBE88A10-FF53-11E0-AB2A-AE904824019B}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\AVIRAI~1.DLL No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\Philipp\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\ProgramData\Skype\Plugins\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\ProgramData\Skype\Plugins\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{4D72E5BC-BC7C-11E0-83CA-10424824019B}\InprocServer32 -> C:\Users\Beamer\AppData\Local\ASKTOO~1\DOWNLO~1\AviraIDW.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{595EF3BD-A186-454A-810C-02015139ACDC}\InprocServer32 -> C:\Users\Beamer\AppData\Local\ASKTOO~1\DOWNLO~1\Avira.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\Beamer\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Beamer\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FBE88A10-FF53-11E0-AB2A-AE904824019B}\InprocServer32 -> C:\Users\Beamer\AppData\Local\ASKTOO~1\DOWNLO~1\AVIRAI~1.DLL No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1005_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\Beamer\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll No File ==================== Restore Points ========================= 09-06-2015 14:14:35 Windows Update 09-06-2015 15:44:18 Windows Update 10-06-2015 10:13:21 Windows Update 15-06-2015 06:14:31 Windows-Sicherung ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {022E57E0-C220-4A4E-AC90-D2C8DACAFB9D} - System32\Tasks\{4E4F2CAC-AA02-4AC1-8E3F-7F64288279A5} => C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe [2000-05-31] (Krisalis Software Ltd.) Task: {0381252B-84D7-4E1D-8044-32644EAD1708} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-03-16] (Microsoft Corporation) Task: {062DB597-D745-4B4F-8444-3530722D8F45} - System32\Tasks\Core Temp Autostart => C:\Program Files\Core Temp\Core Temp.exe [2010-07-05] () Task: {08271361-89BF-4F1E-847E-1CA1ED3F6641} - System32\Tasks\{4B77430A-A839-4A8D-9AC6-DFE4CD36D283} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {0CF8F249-C5F7-475C-866F-21E7073015BD} - System32\Tasks\{EBC19F45-7508-4844-801A-11E762E37D12} => C:\Program Files\Ford Racing 2\fr2.exe Task: {0FB6D721-7BEF-4B45-8E9C-A271B66DE5F2} - System32\Tasks\{07EB860E-F755-4932-9D3F-42431206EE3B} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {10DE5D12-366D-4EFB-9E1B-A5431C45ADC4} - System32\Tasks\{8AC62F6C-CFBA-4FA8-8592-D8DBAF919A41} => C:\Program Files\Ford Racing 2\fr2.exe Task: {11F32470-4328-4A83-9232-80BC5F42F305} - System32\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {13CEC175-DFF4-4468-A045-29A526295C70} - System32\Tasks\{09EF0FB5-FFC5-4873-8A09-BA67F477983B} => C:\Program Files\Ford Racing 2\fr2.exe Task: {16A24A9E-DAB7-4860-94FD-851235C89820} - System32\Tasks\{2F3444E4-EAF5-4F9D-B44F-0359C6E1E962} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe Task: {16E7A595-0943-4C27-81FD-3C0F4846CBB9} - System32\Tasks\{718A9724-BA58-4A15-BA3F-28AD141B9FD7} => C:\Program Files\Logitech\Profiler\LWEmon.exe [2004-05-19] (Logitech Inc.) Task: {189C40ED-B151-444D-86FA-72B2F6B581EA} - System32\Tasks\{EEA39017-C6C8-42D6-83AD-AC789FF71125} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {1C2351DE-232B-4961-840F-EE0D68EB5EF4} - System32\Tasks\{81FAAD8E-E607-4907-9205-969E20593CF7} => C:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe Task: {1DD33B99-F5E8-460F-BD30-B40888E8C53E} - System32\Tasks\{DB5AE33D-F764-456D-9421-62DA1F9288C7} => pcalua.exe -a "D:\DT\DAEMON Tools Lite\DTLite.exe" -d "D:\DT\DAEMON Tools Lite" Task: {1E3565F3-04AA-44DB-B8B7-F35A50CC9057} - System32\Tasks\{07FA7B80-D838-4C87-9F76-696E853348E0} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe Task: {2262B621-3FBA-4C58-8344-886110A30AF0} - System32\Tasks\{275198ED-E85E-4D37-9669-8DAC2931B05F} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {27685E6B-A6D7-4064-A4B9-1F485556156D} - System32\Tasks\{D1391C33-4665-4D75-B346-6737F2BFE6AE} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.) Task: {279BEA6F-528A-4E59-B4D6-EF67500EC149} - System32\Tasks\{4CB1BAEC-7E20-4475-942D-B2ECD3C7BDE5} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {2C842B08-3AB4-4249-8416-A5F0C4254CBB} - System32\Tasks\{E26735BF-5210-43CB-908E-8A7923966B55} => C:\Program Files\Ford Racing 2\fr2.exe Task: {2E316E44-A20D-4E6C-8597-A4349A8F0F7B} - System32\Tasks\{0E84DB2D-E2CE-4939-A87C-0A7FEF5598A0} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe Task: {2EB3D3F5-13C7-448C-98A4-8E8B09A66A7C} - System32\Tasks\{1833D727-C5CA-45F6-B130-C78FC735305C} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.) Task: {3701EA83-EDC0-434F-8AB9-FE21AAE4072D} - System32\Tasks\{08709750-B91C-4722-844A-B78F6762E37B} => C:\Program Files\EA Sports\FIFA 09\FIFA09.exe [2008-10-23] () Task: {37B9496D-79A9-4BCE-AFE4-B5463740A943} - System32\Tasks\{F9594586-61F2-41B8-A093-C8719E057E91} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.) Task: {393F6F51-0E95-4952-8BAD-E1DDD5FFF5DA} - System32\Tasks\{01E58447-78A0-4CD3-BFAF-44C036E4F3F7} => C:\Program Files\Ford Racing 2\fr2.exe Task: {394592EC-79F9-49B8-A307-37950D07C1B9} - System32\Tasks\{E9474EA8-9D29-4DF8-9857-8726D1F8FCD4} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe Task: {3A161975-54C5-4DBB-8AB5-563F0BA63B7E} - System32\Tasks\{BBCB2F70-2DD9-4FDF-BA21-9F4AC8615359} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {3B9AC8C7-B8FF-4D70-9C79-4FB5EBBB90E9} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-07] (Microsoft Corporation) Task: {3BC1FA8B-E302-4DEC-8AA9-B70DE9D839F7} - System32\Tasks\{15248D75-D51C-4771-8D5B-C56A5DC1D3F4} => C:\Program Files\OpenOffice.org 3\program\soffice.exe Task: {3DF4B1BA-C6BA-4565-9C58-0A27C06A1D4C} - System32\Tasks\{10DEF6AD-CAED-48C8-85EB-BD3A12C54209} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {3ECE4DE4-C76E-486F-A045-0713A65EC396} - System32\Tasks\{C5F0B686-DAD5-46B7-8DC1-EEF6742294DF} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.) Task: {3EF06EA8-17AE-4451-96B0-2ED48FE15BE6} - System32\Tasks\{FFB859B9-8F39-438E-A00B-543A2BC334B5} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {425C2494-05F2-4141-BD10-63B0AC111EEF} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {4299562C-9C52-4B20-9BF8-D294B2969604} - System32\Tasks\{CE1034B1-CDF0-44ED-A78A-0E1B67A19078} => pcalua.exe -a E:\SETUP.EXE -d E:\ Task: {46D08DF3-DE5D-4E6A-B197-11D566275F6D} - System32\Tasks\Driver Robot => C:\Program Files\Driver Robot\1.2.0.5\DriverRobot.exe Task: {48F7E135-8B4D-421A-B8E8-22BE06815370} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-08] (Piriform Ltd) Task: {4A3D5C4F-7A49-48E2-BE04-A2DECC4146C2} - System32\Tasks\{4DF731FE-39D2-4735-963D-B33DC6BF1776} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {4B952069-F7C4-4178-932C-D9AD6435A3EE} - System32\Tasks\{9F523BAE-9190-4380-B2B3-96FB780FE112} => pcalua.exe -a C:\Users\Philipp\Desktop\jxpiinstall.exe -d C:\Users\Philipp\Desktop Task: {4B9BA069-9E54-412A-90D7-CBB925EBF5FA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-10] (Adobe Systems Incorporated) Task: {4D2676FB-5EC2-4044-897A-45B547B13687} - System32\Tasks\ASUS Live Update => C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2007-11-30] () Task: {4D5F48A9-2EB0-4E4E-B34D-95A3DDB466A9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {4D8CE3D9-10E6-4EF4-9C8E-39AD6D90EEEB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13] (Dropbox, Inc.) Task: {4E453841-EE58-4AA6-8514-3E30F217B1BE} - System32\Tasks\{E56CE78F-3DF9-4305-8336-77785549E0F4} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {542676B6-E1CE-4B5C-BDF2-C00ECFB38DBC} - System32\Tasks\{42963256-E132-413E-A4D9-4AD87B590641} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {543E71B8-E7BE-4FDA-AD19-CC490CA91848} - System32\Tasks\{09D857DD-F75F-4669-84AC-9B2B4F91002A} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {561375CB-FF5A-417B-B297-BA73DE149581} - System32\Tasks\Microsoft\Windows\Wired\GatherWiredInfo => C:\Windows\system32\gatherWiredInfo.vbs Task: {576416B1-5229-4BB5-8F5F-5EB4CE34693A} - System32\Tasks\{0AD9175A-E960-4F4A-B254-A7FFF532194A} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.) Task: {592F7F57-9C8F-4F5D-9A75-D8444CAF5A34} - System32\Tasks\{3A608F0C-88F6-4101-A24D-5888FB4E1675} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {5B3DB1D0-2D67-4C1C-BA0C-73372A98F89C} - System32\Tasks\{8B5019D5-0BD6-4708-A1CA-DE33DAF12937} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {5CC8A7A0-EB94-45A9-8C14-10D1FA017AA5} - System32\Tasks\{D6670E02-8F5A-46ED-BFE4-8AEF911AB2FE} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {5D8E271A-4247-422B-BB0B-A0F60CD4F2EE} - System32\Tasks\{CF4F2AC7-7291-4854-8184-33979FBEEA3A} => C:\Program Files\Logitech\Profiler\LWEMon.exe [2004-05-19] (Logitech Inc.) Task: {6997CFAE-6B39-4219-A1BB-BFCA1A25B735} - System32\Tasks\ACMON => C:\Program Files\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK) Task: {6BCBF903-EFC8-4841-A00B-8A98F9B42040} - System32\Tasks\{5F24C263-DED9-48A3-85E4-2AF0241EDD56} => pcalua.exe -a C:\PROGRA~1\Stardock\OBJECT~1\DesktopX\UNWISE.EXE -c C:\PROGRA~1\Stardock\OBJECT~1\DesktopX\INSTALL.LOG Task: {6C2BAF56-D5B0-4D25-BFA4-8A03090E90F4} - System32\Tasks\{35BF4035-207B-4DDB-A7D9-DAE7569EA9A7} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {6C7963B0-501B-464F-85BB-0F1A98CB0EE2} - System32\Tasks\{ACD04780-E85C-4752-806D-C7E0B65CA043} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {6FAF6F7D-1CDF-4408-A9E7-F480AFD09927} - System32\Tasks\{224E176B-C279-4E30-BFAC-74EDBD3DF2AA} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {71707D88-0843-4073-AFAC-21043703B9B5} - System32\Tasks\{B5BE686C-6877-4712-B359-6260EE6BAA94} => C:\Program Files\Ford Racing 2\fr2.exe Task: {72ED54C5-EAAC-4283-858E-E531B2490992} - System32\Tasks\{795C6E6E-FAAA-4431-A918-937A78C53BB2} => C:\Program Files\Ford Racing 2\fr2.exe Task: {7504B855-6656-44B8-A9C0-BB031597F97E} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {7585CE6A-F9B1-4E6E-856F-617D6D00D54C} - System32\Tasks\Net4Switch => C:\Program Files\ASUS\Net4Switch\Net4Switch.exe [2007-11-20] (ASUS) Task: {79B505CA-4391-4F82-93B8-F6A10F007D29} - System32\Tasks\{E9F1D326-BB8E-416E-A09B-6DEFFC535CE7} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {7B9BD304-C851-42BA-B29B-8832C02B513D} - System32\Tasks\{AA91F360-BE81-48A9-9CFE-2565918BACBC} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.) Task: {7BBE44D8-A420-4877-91D3-43AD4DF8740A} - System32\Tasks\{99B1E97F-436E-4429-ABA3-7E618A478667} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {7D3C7871-A917-4EF0-82E8-5F0A96423051} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => BthUdTask.exe Task: {805902FB-18D4-403F-9263-0624A07154E2} - System32\Tasks\{1648ED5A-2D13-4C52-AE7C-31297200C10D} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {85417455-F0F1-41C5-8316-B8DFEB8C8918} - System32\Tasks\{1A5C41D9-30DC-4783-B8B0-CEC6F0B3E839} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {86094599-821F-4E9B-8E55-9AF40185191E} - System32\Tasks\{ED62F36F-605A-4AE1-8208-FD5CA76699B4} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe Task: {8B3014D9-EB90-4483-B8E6-B492402A6DF0} - System32\Tasks\{12845C94-D0B6-4BDA-A9FB-5B154245A6D4} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {8DBA4AC8-B6E1-4E21-92E1-6F5BD04CBC59} - System32\Tasks\{805913F2-AD7E-416D-BA65-5BCB278D42E1} => C:\Program Files\LEGO Schach\Lego Chess.exe Task: {8EAD5D19-6EF9-4FAD-91E1-C759DDC095FA} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {8FB70F6E-172F-42D9-AD4A-91E5AFF5A7B5} - System32\Tasks\{20881F0F-F213-4B1D-AC68-02FABF50C1CE} => C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe [2000-05-31] (Krisalis Software Ltd.) Task: {9057296A-F885-41B1-8E01-EF575CEF376C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.) Task: {90FFF327-1728-488D-BE4E-FA1232DD7BB6} - System32\Tasks\{14EDE9BC-20F9-4EFA-AC7D-6EB4C5A76C71} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {99C2E64D-3C78-4488-8CF3-672D6E3DB446} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13] (Dropbox, Inc.) Task: {99C91901-9432-4EA7-87F8-55A525B95ABA} - System32\Tasks\{E2D1EE7B-E7AD-4C2D-AAB0-AC383A6F07CC} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.) Task: {A0EC8CE0-03D7-4A0E-A8FA-0380AF2A1FF0} - System32\Tasks\{D884D7E7-64A4-45DE-98FD-56D8596FCD34} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {A93B8A4D-244F-453C-9B10-DB60E36A1C57} - System32\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {A9443690-748A-45F1-8D64-6AA0294F58AE} - System32\Tasks\{A5E9A2AB-D783-444B-ACEA-988C9C2827BD} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {AC093D78-AE53-48AF-A35E-7E570F6D5649} - System32\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {B22899B8-49AC-43DA-B2BF-CCB47C542539} - System32\Tasks\{37C1FFED-5F13-4EA4-B8E0-FBC3039B59DA} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe Task: {B2FDDA94-D222-4673-A9AF-CAE32F13265A} - System32\Tasks\{57123DD4-3701-4890-8F5E-69253F2A254E} => C:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe Task: {B344FCA0-E424-413D-B0C0-228FD63058F1} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {B3B4709A-B606-4F54-A90A-116F93D8512E} - System32\Tasks\ASPG => C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS) Task: {B7D4A3DB-3927-46B0-A840-174630359DE6} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files\ASUS\SmartLogon\sensorsrv.exe [2009-05-18] (ASUS) Task: {BF436BB1-3885-496D-B203-C36CFA947E53} - System32\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {C01F96CD-E814-4B3B-8ADB-B61746C44F27} - System32\Tasks\{47B8FC20-7DB8-48A6-83BC-E7C34E62CC8B} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {C361CDD7-C67A-4CB4-A515-59B3F225DF8C} - System32\Tasks\{6C5CE7EA-6EC5-497C-8FAE-8DDE494754CC} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {C6D305DC-A5B7-4BD2-B434-64B58E96E1B9} - System32\Tasks\{83270C1C-EFD0-435A-B354-DB444A4E64F7} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe Task: {C71C0104-D3E3-49D0-886E-850A0EA0A519} - System32\Tasks\{629DDE4B-7DAE-4321-B366-19139E71F9C4} => C:\Program Files\Ford Racing 2\fr2.exe Task: {C8CF8AF5-8F8E-429F-89D8-BBB8B4A35E6E} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks Task: {CCCDE7C4-AC7C-4DD5-98AB-1DDF96CC1A00} - System32\Tasks\{5E36B9A2-EA7B-4338-B839-BA06E700C7A7} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {D21F6024-191F-4454-BBBC-09A650DA2549} - System32\Tasks\Microsoft\Windows\Application Experience\AitAgent => aitagent.exe Task: {D2D316AA-04AB-4C85-B4E6-0FFA7C1B5CAD} - System32\Tasks\{897420D6-2E83-4F0C-9542-4235DE3ADD9D} => C:\Program Files\Ford Racing 2\fr2.exe Task: {D428F363-CD1D-4CEC-BCFD-7895783F2746} - System32\Tasks\{740C00F2-0AF4-462D-B602-FAA959059F5E} => C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe [2000-05-31] (Krisalis Software Ltd.) Task: {D943FB3E-EB45-43CD-91A6-A055E15CE059} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.) Task: {DA81BBC7-677C-4A44-A056-CB90DC977864} - System32\Tasks\{0D730403-F736-400F-B631-19B8BC0E1E30} => C:\Program Files\EA Sports\FIFA 09\FIFA09.exe [2008-10-23] () Task: {DB85DFE2-B398-4D92-BA2A-821880861383} - System32\Tasks\{846920E1-73B4-4C1B-801F-BA087FE5EEF8} => C:\Program Files\LEGO Schach\Lego Chess.exe Task: {DC34DD92-92FA-4E52-A136-C3C2FC249AE5} - System32\Tasks\{9D61A73B-0DE2-48FE-A2B3-088709BD7D2C} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {DC6CEF1A-D549-42B2-87D2-274BEC35D662} - System32\Tasks\{C1FB456D-5102-4D69-A102-59FBB9C799C1} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {DE31F299-BD40-4A25-BB8A-10EC1ADC4783} - System32\Tasks\{E39103FF-9002-43CF-B483-1326522EF959} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs Task: {E54FD084-9DE3-498A-8ECB-F723F22FAB84} - System32\Tasks\{A48CA2AC-8CD3-4B01-9BD2-E56D49ADD8F7} => C:\Program Files\EA Sports\FIFA 09\FIFA09.exe [2008-10-23] () Task: {E5AB5213-9D14-427E-BF04-B685E363ABF9} - System32\Tasks\{F8DD370C-1C9B-4B99-A221-D936EDE7FDAD} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {E61935EA-A141-496D-BA9E-CF4C3EF3795D} - System32\Tasks\{3CB8A215-9260-42B8-8D9B-FA81017EED9A} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {EDFDEDC0-7152-4BC4-8E7A-2D96E5C6D8D7} - System32\Tasks\{6DD7CCD6-3D1C-4DA7-B895-4F4F95745358} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {EEA6A0A0-E1CD-4583-B178-0690064E5D8F} - System32\Tasks\{EE69846A-E56D-493D-B5DA-858DE7FA218B} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {F74F66A2-BA11-4AEC-A516-F153CDCD3451} - System32\Tasks\{2EF7C677-995A-413F-93CA-F39A6D35363C} => C:\Program Files\Ford Racing 2\fr2.exe Task: {F7E36632-B92F-40E5-8FDF-60225CFB5CB3} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Jeffel => C:\Program Files\Windows Calendar\WinCal.exe Task: {F8E4E8A9-959E-4214-8706-20AE311FFA86} - System32\Tasks\{D1117AB3-5D96-42EF-8AE2-EE14F8692D60} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe Task: {F8EF940F-03BD-46F5-A998-1540C6587472} - System32\Tasks\{FB7C2341-6721-4B95-A6AE-136D881A01F3} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {F9428F41-B2CF-431B-8A33-32AD9E73E88C} - System32\Tasks\{BF78135C-D9BB-42BD-8E6A-0FBBC5ACA700} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe Task: {FD11DEA1-27EB-480A-ADD0-60B1E33E6B31} - System32\Tasks\{DA19A5B2-B0BB-49BA-854B-43FECBBC9387} => C:\Program Files\Logitech\Profiler\LWEmon.exe [2004-05-19] (Logitech Inc.) Task: {FD3008D4-9573-44C7-B144-BA5C02B4BFCA} - System32\Tasks\{3E7DE8B7-79CA-4BC7-A84E-390073C4E375} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Driver Robot.job => C:\Program Files\Driver Robot\1.2.0.5\DriverRobot.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE:/EXE:{5ED40A39-9E20-4A57-9853-44602CD12F7A} /F:UpdateSYSTEM Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\Windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE Task: C:\Windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE:/EXE:{00F3F166-48F4-41CC-97B5-0BCDE58D612F} /F:UpdateSYSTEM Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2009-08-19 05:08 - 2007-08-08 09:08 - 00094208 _____ () C:\Program Files\ATKGFNEX\GFNEXSrv.exe 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-02-13 05:20 - 2015-02-13 05:20 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-09-25 18:57 - 2013-04-03 14:09 - 00756224 _____ () C:\Program Files\MyPublicWiFi\PublicWiFiService.exe 2009-12-25 19:33 - 2007-08-03 13:24 - 00125496 _____ () C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe 2009-12-25 19:33 - 2007-09-14 11:00 - 00147456 _____ () C:\Program Files\ASUS\NB Probe\SPM\spdiskex.dll 2009-12-25 19:33 - 2003-11-28 03:11 - 00135168 _____ () C:\Program Files\ASUS\NB Probe\SPM\spos.dll 2009-12-25 19:33 - 2005-08-29 16:24 - 00081920 _____ () C:\Program Files\ASUS\NB Probe\SPM\spnbacpi.dll 2009-12-25 19:33 - 2003-09-09 17:08 - 00049152 _____ () C:\Program Files\ASUS\NB Probe\SPM\spdmi.dll 2009-12-25 19:33 - 2006-04-04 11:24 - 00036864 _____ () C:\Program Files\ASUS\NB Probe\SPM\ghadmi.dll 2009-12-25 19:33 - 2005-04-07 20:25 - 00077824 _____ () C:\Program Files\ASUS\NB Probe\SPM\spmemory.dll 2009-08-19 04:53 - 2007-07-06 01:53 - 01040384 _____ () C:\Program Files\Wireless Console 2\wcourier.exe 2007-06-15 11:28 - 2007-06-15 11:28 - 00147456 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll 2007-06-01 18:08 - 2007-06-01 18:08 - 00143360 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll 2010-01-01 12:48 - 2009-12-12 16:12 - 00141824 _____ () C:\Program Files\WinRAR\rarext.dll 2011-07-18 23:04 - 2011-07-18 23:04 - 00296448 _____ () C:\Program Files\Notepad++\NppShell_04.dll 2013-12-24 20:39 - 2012-11-20 00:44 - 00786432 _____ () D:\Gaming Maus\DareUMonitor.exe 2013-12-24 20:39 - 2013-03-27 13:48 - 00057344 _____ () D:\Gaming Maus\lan.dll 2013-12-24 20:39 - 2012-04-19 18:15 - 00061440 _____ () D:\Gaming Maus\hiddriver.dll 2015-05-08 20:50 - 2015-05-08 20:50 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2015-06-15 16:36 - 2015-06-15 16:36 - 00043008 _____ () c:\users\philipp\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpvefjun.dll 2015-03-04 23:45 - 2015-03-04 23:45 - 00750080 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2015-03-04 23:45 - 2015-03-04 23:45 - 00047616 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\libEGL.dll 2015-03-04 23:45 - 2015-03-04 23:45 - 00865280 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll 2015-03-04 23:45 - 2015-03-04 23:45 - 00200704 _____ () C:\Users\Philipp\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll 2015-06-15 16:35 - 2015-06-15 16:35 - 00098816 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32api.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00110080 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pywintypes27.dll 2015-06-15 16:35 - 2015-06-15 16:35 - 00364544 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pythoncom27.dll 2015-06-15 16:35 - 2015-06-15 16:35 - 00045568 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_socket.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 01161216 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_ssl.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00320512 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32com.shell.shell.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00713216 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_hashlib.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 01175040 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._core_.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00805888 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._gdi_.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00811008 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._windows_.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 01062400 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._controls_.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00735232 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._misc_.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00682496 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pysqlite2._sqlite.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00087552 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_ctypes.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00119808 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32file.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00108544 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32security.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00007168 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\hashobjs_ext.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00026624 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\usb_ext.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00167936 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32gui.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00018432 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32event.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00128512 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_elementtree.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00127488 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\pyexpat.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00013824 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\common.time34.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00036864 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_psutil_windows.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00038912 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32inet.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00011264 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32crypt.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00070656 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._html2.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00027136 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_multiprocessing.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00020480 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\_yappi.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00035840 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32process.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00686080 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\unicodedata.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00122368 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._wizard.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00024064 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32pipe.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00010240 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\select.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00025600 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32pdh.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00525640 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\windows._lib_cacheinvalidation.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00017408 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32profile.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00022528 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\win32ts.pyd 2015-06-15 16:35 - 2015-06-15 16:35 - 00078336 _____ () C:\Users\Philipp\AppData\Local\Temp\_MEI62202\wx._animate.pyd 2013-11-27 20:48 - 2015-04-16 19:40 - 00776192 _____ () D:\Steam\SDL2.dll 2015-01-24 17:49 - 2015-04-23 04:16 - 04962816 _____ () D:\Steam\v8.dll 2015-01-24 17:49 - 2015-04-23 04:16 - 01556992 _____ () D:\Steam\icui18n.dll 2015-01-24 17:49 - 2015-04-23 04:16 - 01187840 _____ () D:\Steam\icuuc.dll 2014-05-22 17:04 - 2015-06-04 20:56 - 02407104 _____ () D:\Steam\video.dll 2014-08-31 20:09 - 2014-12-01 23:31 - 02396672 _____ () D:\Steam\libavcodec-56.dll 2014-08-31 20:09 - 2014-12-01 23:31 - 00442880 _____ () D:\Steam\libavutil-54.dll 2014-08-31 20:09 - 2014-12-01 23:31 - 00479744 _____ () D:\Steam\libavformat-56.dll 2014-08-31 20:09 - 2014-12-01 23:31 - 00332800 _____ () D:\Steam\libavresample-2.dll 2014-08-31 20:09 - 2014-12-01 23:31 - 00485888 _____ () D:\Steam\libswscale-3.dll 2013-11-27 20:48 - 2015-06-04 20:56 - 00703168 _____ () D:\Steam\bin\chromehtml.DLL 2013-11-27 20:48 - 2015-05-11 21:01 - 36302728 _____ () D:\Steam\bin\libcef.dll 2015-05-16 07:55 - 2015-05-11 21:01 - 08958344 _____ () D:\Steam\bin\pdf.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Jeffel\Desktop\1.avi:TOC.WMV AlternateDataStreams: C:\Users\Jeffel\Desktop\2.avi:TOC.WMV AlternateDataStreams: C:\Users\Jeffel\Desktop\3.avi:TOC.WMV ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-644356114-2566177158-2502637254-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\Beamer\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-644356114-2566177158-2502637254-1008\Control Panel\Desktop\\Wallpaper -> C:\Users\Ellen & Manuel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-644356114-2566177158-2502637254-1011\Control Panel\Desktop\\Wallpaper -> C:\Users\Manuel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.177.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk => C:\Windows\pss\FancyStart daemon.lnk.CommonStartup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: AlcoholAutomount => "D:\Alcohol 120\axcmd.exe" /automount MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: ASUS Camera ScreenSaver => C:\Windows\AsScrProlog.exe MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\ASScrPro.exe MSCONFIG\startupreg: ASUSTPE => C:\Windows\system32\ASUSTPE.exe MSCONFIG\startupreg: AVMUSBFernanschluss => "C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\AVMAutoStart.exe" MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon MSCONFIG\startupreg: CanonSolutionMenu => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon MSCONFIG\startupreg: CLMLServer => "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: DAEMON Tools Lite => "D:\DT\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: KiesTrayAgent => D:\Samsung Kies\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: UpdateLBPShortCut => "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" MSCONFIG\startupreg: UpdateP2GoShortCut => "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{98B426BE-4154-48E7-A940-C28AD6AB3C7E}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{A0ED8D77-C475-4A7C-9683-E33EF6CA08AE}] => (Allow) svchost.exe FirewallRules: [{5A959ABA-B81C-408F-9BF9-A382D827ED17}] => (Allow) C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [TCP Query User{92FF86AB-5408-4239-86CD-713C52CC5E72}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [UDP Query User{756D4762-70FE-4F03-9A42-0F627F10CBF8}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [TCP Query User{F15C73F2-09B2-4D70-B6C1-FCB8C6C3077A}C:\program files\google\google earth\client\googleearth.exe] => (Block) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [UDP Query User{3518798C-9464-4B02-B79D-33060DE82A80}C:\program files\google\google earth\client\googleearth.exe] => (Block) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [TCP Query User{F87691B0-9C93-4349-8E2B-69BF1B0D816D}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{0756E3CD-F4D3-4373-BCB1-583FDDA22919}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{6939840F-897B-42B5-8E48-6E97937198B0}] => (Allow) svchost.exe FirewallRules: [{59E3FF2C-493B-4937-9A37-DA9D1CAAFC4B}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe FirewallRules: [TCP Query User{A1DE6356-BBC4-48A8-B039-88DEB224609A}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{E3168A96-5F5E-4485-AD0D-7AE6A2596564}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{4AF10D0E-C4C1-40A2-936B-C6F2AB12613B}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe FirewallRules: [UDP Query User{88D7FF05-F79E-4946-A853-288BD573E814}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe FirewallRules: [TCP Query User{9EFEAB5F-7210-4BC7-8BA8-231FA6D585A1}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe FirewallRules: [UDP Query User{375FCB23-571C-4F84-90FE-A0670DEAAC49}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe FirewallRules: [{55E52E7C-FD6E-4517-8357-F6D71154371A}] => (Allow) C:\Users\Jeffel\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{9C447FBD-4CD0-4507-918C-C3C1FC1BC0BC}] => (Allow) C:\Users\Jeffel\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{424B5F96-6253-4B19-824F-7157B91CE53C}C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{A3FECD29-88C2-49EE-9826-78B12649C757}C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{5518E9F3-F3DC-433F-9E50-A930A0CD15F2}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe FirewallRules: [UDP Query User{55697CCA-A2DB-4C9F-8442-8DC6C36139AA}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe FirewallRules: [TCP Query User{3E55C8FD-D431-4830-8F71-22F2B69255C3}C:\program files\ea sports\fifa 09\fifa09.exe] => (Allow) C:\program files\ea sports\fifa 09\fifa09.exe FirewallRules: [UDP Query User{6B39FD39-72B8-4683-9E30-4221DEFAD5D9}C:\program files\ea sports\fifa 09\fifa09.exe] => (Allow) C:\program files\ea sports\fifa 09\fifa09.exe FirewallRules: [TCP Query User{EF7EF825-131B-4165-A892-9DEC02FC688F}E:\easysetupassistant\wr841n\easysetupassistant.exe] => (Allow) E:\easysetupassistant\wr841n\easysetupassistant.exe FirewallRules: [UDP Query User{25BF93E3-CEFC-4077-972C-637BBD3D8D23}E:\easysetupassistant\wr841n\easysetupassistant.exe] => (Allow) E:\easysetupassistant\wr841n\easysetupassistant.exe FirewallRules: [{BE0F663E-C815-4563-A897-646E54E5E075}] => (Block) E:\easysetupassistant\wr841n\easysetupassistant.exe FirewallRules: [{C1AD54B1-3E4E-48CD-AA59-46A81630CED6}] => (Block) E:\easysetupassistant\wr841n\easysetupassistant.exe FirewallRules: [TCP Query User{642462DC-FE55-4283-B3BE-5116D1ABD2D1}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{1543EF59-9BDC-45F3-98C1-666138EE2360}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [{F42F3A51-5E79-42CD-97EC-8F46AFB3AEDA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{3AF441F6-2448-4E93-AF29-F00F2983A81B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{3A83D0B7-CC23-4E0A-A47F-BA4C727DA59B}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{A30C3FCC-E865-487C-BB2B-94503E562E57}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [{C5B4D7F3-5ACD-4113-B7F8-EF24617B930D}] => (Allow) D:\OriginGames\Need for Speed World\GameLauncher.exe FirewallRules: [{54FB9595-0BFB-47AF-866A-250C8D7B1BAF}] => (Allow) D:\OriginGames\Need for Speed World\GameLauncher.exe FirewallRules: [{9E1C364E-EA27-4082-AB13-FBEBC90590BA}] => (Allow) D:\OriginGames\Battlefield 1942\BF1942.exe FirewallRules: [{2EB3B6C7-04D1-43DF-B4B0-B47348DBCD68}] => (Allow) D:\OriginGames\Battlefield 1942\BF1942.exe FirewallRules: [{DBB13B95-B032-45C2-A416-2E496104A650}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{5456B4DC-0D08-476B-B4CB-8BA97886248B}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{B3C9C811-6617-41F7-8833-D1B66AC7C967}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [TCP Query User{FB78B67C-4DFB-45DA-8910-73B460C08EE9}D:\needforspeed world\data\nfsw.exe] => (Allow) D:\needforspeed world\data\nfsw.exe FirewallRules: [UDP Query User{514C9672-18B4-476C-B568-2B1D2211DC21}D:\needforspeed world\data\nfsw.exe] => (Allow) D:\needforspeed world\data\nfsw.exe FirewallRules: [{122DB7AB-303C-4A23-8984-A4089D07A519}] => (Allow) D:\Steam\SteamApps\common\f12013\F1_2013.exe FirewallRules: [{BA4A4B55-61BE-49C7-B106-9CF16C1FEFCA}] => (Allow) D:\Steam\SteamApps\common\f12013\F1_2013.exe FirewallRules: [{852A6D93-68A1-49D2-A427-091873A0F8AF}] => (Allow) D:\OriginGames\Plants vs. Zombies\PlantsVsZombies.exe FirewallRules: [{1C423230-E993-447A-B8BC-B011BD1ABEA4}] => (Allow) D:\OriginGames\Plants vs. Zombies\PlantsVsZombies.exe FirewallRules: [{5476BAD2-AE20-42B2-BFC6-58B987D9EC81}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [{812E2119-243A-400E-B7FE-DEB6D62808AB}] => (Allow) D:\OriginGames\SimCity\SimCity\SimCity.exe FirewallRules: [{2C4E33E9-EDDF-4059-9790-647FCF83145D}] => (Allow) D:\OriginGames\SimCity\SimCity\SimCity.exe FirewallRules: [TCP Query User{60D69111-FE19-4415-B387-D97AE26AFD38}C:\program files\tmnationsforever\tmforever.exe] => (Block) C:\program files\tmnationsforever\tmforever.exe FirewallRules: [UDP Query User{F2DF262E-FF7C-484F-AA4E-63FF8880305C}C:\program files\tmnationsforever\tmforever.exe] => (Block) C:\program files\tmnationsforever\tmforever.exe FirewallRules: [{A3C3ECE5-F0B8-458B-BF51-A7F6BF8F5E0E}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{DAA3B140-1FED-47B5-9F25-FB8F35548A03}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{F14B2E24-FBC1-4546-BBB6-CCBF3E3C26CB}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe FirewallRules: [{1EBAA986-ABD7-469D-8126-C6A22AB47DCF}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe FirewallRules: [TCP Query User{DF57783D-CA97-4654-B267-AC96484B730F}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{695F1F23-F5F2-4E3A-93D3-C046C30B108D}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{18759B6E-98BA-4489-983D-ABCF93CE30A2}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{C48C23E4-CF37-4289-AC60-2FF3F377ACD4}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe FirewallRules: [{BAE39D93-BC07-4545-A838-D128E5D729B1}] => (Allow) C:\Users\Philipp\AppData\Local\Apps\2.0\AKHGTRNK.DG4\BWYE0CZZ.LL7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{BDC2FD03-237D-49E4-A6A2-8AE3211FB11A}] => (Allow) C:\Users\Philipp\AppData\Local\Apps\2.0\AKHGTRNK.DG4\BWYE0CZZ.LL7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{2A33F55E-5BBB-4A44-9852-D7FEA360081E}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{084ED6E8-0CDB-42C1-9716-21D9E1E099C3}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [TCP Query User{5A171416-5B5C-45E6-A06C-FD51ECCBBA01}C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe] => (Block) C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [UDP Query User{EC3DF4E2-12D4-4BEA-9E53-8BD42E933EE3}C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe] => (Block) C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{B3F421E8-5795-4576-A04B-678154A5D42C}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{56B79544-76F5-4B6F-85BD-3CA9415A0BE3}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [TCP Query User{A674A672-4708-4C05-A7DD-7FC78F2ABAD6}C:\program files\unified remote\remoteserver.exe] => (Allow) C:\program files\unified remote\remoteserver.exe FirewallRules: [UDP Query User{C42108C2-C11D-4BCD-848F-C882C383AFF1}C:\program files\unified remote\remoteserver.exe] => (Allow) C:\program files\unified remote\remoteserver.exe FirewallRules: [{66918B97-AE64-444C-9DB6-5DB605AE12F7}] => (Allow) D:\OriginGames\Bejeweled 3\Bejeweled3.exe FirewallRules: [{4D93D20E-753C-494E-8FA6-F47CF535E417}] => (Allow) D:\OriginGames\Bejeweled 3\Bejeweled3.exe FirewallRules: [{100DFB51-03A7-409A-8436-B1ADEDE290A7}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{3D1CFBF6-1099-4721-A86E-438E12C875EA}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{708B5EAF-95EC-428E-9AA3-7F8A3CC499D7}] => (Allow) D:\OriginGames\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe FirewallRules: [{252252F8-D1E0-473A-8A33-743C157FAAAB}] => (Allow) D:\OriginGames\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe FirewallRules: [{12369EEC-4B3E-4804-8395-3B1EE1D1F377}] => (Allow) C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{23965B5B-2D1F-4BC2-82F2-4E012CDB6110}] => (Allow) C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{8AD425C4-E4CD-4E0A-B470-71C0186D4419}] => (Allow) D:\OriginGames\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe FirewallRules: [{79468976-3ED7-4AAD-8CDF-CC32C20626C3}] => (Allow) D:\OriginGames\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe FirewallRules: [{98C0D637-E762-4100-8AF8-3E756C54A265}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe FirewallRules: [{533B5FB5-1CB8-4776-8F97-B9D35616A215}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe FirewallRules: [{D67CAA53-7942-4A91-8D54-03DE16AF77AA}] => (Allow) D:\Steam\SteamApps\common\ConSim2015\ConSim2015.exe FirewallRules: [{085EB9AF-D4B4-42D7-AA85-2FF13C776871}] => (Allow) D:\Steam\SteamApps\common\ConSim2015\ConSim2015.exe FirewallRules: [{13EC435C-D4A0-4045-9736-20D5C2A52E0F}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{766D54AC-FE82-4990-81C9-4B3E62FC1D8E}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{8147F4AA-6FEE-48F5-A257-DADCA6B3D1F7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{B59D5117-8BF8-4401-A031-594855C5359E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{C3A2EE98-6FD7-4841-986B-5FF483452073}] => (Allow) D:\OriginGames\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [{7894DF2C-B685-420A-810A-505E1663461E}] => (Allow) D:\OriginGames\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [{AB875D33-F535-45C7-83AD-4542A38F0A9A}] => (Allow) D:\OriginGames\Syndicate (1993)\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [{C8819052-499D-4060-A2CB-63C85B7289F3}] => (Allow) D:\OriginGames\Syndicate (1993)\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [TCP Query User{2405E39F-611A-4841-8667-B7FAB332ED13}D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{98A5CF53-9EE7-4592-86E6-5A255E971ED4}D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{42389642-E7E4-4FA7-99F0-D17483626C6F}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{546675B7-4D5D-41B0-A82B-3C2AE0AED9AE}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [{F4820325-C52D-4F14-B0C1-E2F40210A513}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft3077.tmp\fsetup.exe FirewallRules: [{F8A2199B-EA6F-43B4-BF29-FC040CE4901D}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft3077.tmp\fsetup.exe FirewallRules: [{0CB53765-513D-49DE-87C5-AECA2C3658C1}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pftAA65.tmp\fsetup.exe FirewallRules: [{C88A6BB6-DBFF-4572-AA49-2F5929892EA3}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pftAA65.tmp\fsetup.exe FirewallRules: [{13D83860-A9E7-48A7-A64E-3D805CB1B574}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft96D1.tmp\fsetup.exe FirewallRules: [{4DDF4814-C41E-4164-81FB-D9C60F8AD319}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft96D1.tmp\fsetup.exe FirewallRules: [{7870E46B-69E5-4524-B2E7-ECEB9E6D710D}] => (Allow) C:\Program Files\iTunes\iTunes.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/15/2015 06:34:40 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm FRST.exe, Version 13.6.2015.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 26c0 Startzeit: 01d0a788caaf2ddf Endzeit: 0 Anwendungspfad: C:\Users\Philipp\Desktop\FRST.exe Berichts-ID: 36209be9-137c-11e5-977e-002618f9ca5d Error: (06/15/2015 05:07:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: legoland.exe, Version: 0.2.2.9, Zeitstempel: 0x3934d3e8 Name des fehlerhaften Moduls: legoland.exe, Version: 0.2.2.9, Zeitstempel: 0x3934d3e8 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0005241a ID des fehlerhaften Prozesses: 0x23a0 Startzeit der fehlerhaften Anwendung: 0xlegoland.exe0 Pfad der fehlerhaften Anwendung: legoland.exe1 Pfad des fehlerhaften Moduls: legoland.exe2 Berichtskennung: legoland.exe3 Error: (06/15/2015 02:23:59 PM) (Source: Windows Backup) (EventID: 4104) (User: ) Description: Die Sicherung war nicht erfolgreich. Fehler: "Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005)" Error: (06/15/2015 06:27:53 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wlmail.exe, Version 14.0.8089.726 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 20bc Startzeit: 01d0a72357fe1421 Endzeit: 20 Anwendungspfad: C:\Program Files\Windows Live\Mail\wlmail.exe Berichts-ID: e0ef34aa-1316-11e5-977e-002618f9ca5d Error: (06/15/2015 06:25:42 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wlmail.exe, Version 14.0.8089.726 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1fec Startzeit: 01d0a72282aa9518 Endzeit: 40 Anwendungspfad: C:\Program Files\Windows Live\Mail\wlmail.exe Berichts-ID: 8e335d02-1316-11e5-977e-002618f9ca5d Error: (06/15/2015 02:09:41 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2492256 Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2492256 Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/14/2015 06:52:19 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7332 System errors: ============= Error: (06/15/2015 05:20:20 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:20:10 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:19:15 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:18:50 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:16:54 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:08:49 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:07:51 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 05:06:06 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (06/15/2015 04:43:24 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Bytes Speicher konnten durch den DNS-Proxy-Agent nicht zugeordnet werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner Fehler ist im Speicher-Manager aufgetreten. Error: (06/15/2015 04:37:52 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Bytes Speicher konnten durch den DNS-Proxy-Agent nicht zugeordnet werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner Fehler ist im Speicher-Manager aufgetreten. Microsoft Office: ========================= Error: (06/15/2015 06:34:40 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: FRST.exe13.6.2015.026c001d0a788caaf2ddf0C:\Users\Philipp\Desktop\FRST.exe36209be9-137c-11e5-977e-002618f9ca5d Error: (06/15/2015 05:07:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: legoland.exe0.2.2.93934d3e8legoland.exe0.2.2.93934d3e8c00000050005241a23a001d0a77cca8cafe5C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exeC:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe4955926e-1370-11e5-977e-002618f9ca5d Error: (06/15/2015 02:23:59 PM) (Source: Windows Backup) (EventID: 4104) (User: ) Description: Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005) Error: (06/15/2015 06:27:53 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wlmail.exe14.0.8089.72620bc01d0a72357fe142120C:\Program Files\Windows Live\Mail\wlmail.exee0ef34aa-1316-11e5-977e-002618f9ca5d Error: (06/15/2015 06:25:42 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wlmail.exe14.0.8089.7261fec01d0a72282aa951840C:\Program Files\Windows Live\Mail\wlmail.exe8e335d02-1316-11e5-977e-002618f9ca5d Error: (06/15/2015 02:09:41 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\EPSON Software\Download Navigator\EPSDNLMW64.EXE Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2492256 Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2492256 Error: (06/14/2015 07:33:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/14/2015 06:52:19 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7332 ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T6500 @ 2.10GHz Percentage of memory in use: 61% Total physical RAM: 3071.27 MB Available physical RAM: 1180.2 MB Total Pagefile: 6140.86 MB Available Pagefile: 3196.06 MB Total Virtual: 3071.88 MB Available Virtual: 2927.57 MB ==================== Drives ================================ Drive c: (VistaOS) (Fixed) (Total:149.04 GB) (Free:24.31 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:137.33 GB) (Free:68.21 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 97646C29) Partition 1: (Not Active) - (Size=11.7 GB) - (Type=1C) Partition 2: (Active) - (Size=149 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=137.3 GB) - (Type=OF Extended) ==================== End of log ============================ |
16.06.2015, 15:25 | #6 |
/// the machine /// TB-Ausbilder | DHL Spam Mail -> Trojaner/Virus? Immer mit Adminrechten Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
__________________ --> DHL Spam Mail -> Trojaner/Virus? |
16.06.2015, 17:55 | #7 |
| DHL Spam Mail -> Trojaner/Virus? Der Uninstaller hat scheinbar nur teilweise funktioniert (Fehlermeldung ), jedoch war das Programm nach der teilweisen Deinstallation nicht mehr zu finden. Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.09.1.1004 www.malwarebytes.org Database version: main: v2015.06.16.04 rootkit: v2015.06.15.01 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 11.0.9600.17843 Philipp :: SCHEFFLER-PC [administrator] 16.06.2015 17:06:27 mbar-log-2015-06-16 (17-06-27).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged. Objects scanned: 549724 Time elapsed: 1 hour(s), 30 minute(s), 16 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Code:
ATTFilter 18:40:34.0856 0x0238 TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04 18:40:40.0160 0x0238 ============================================================ 18:40:40.0160 0x0238 Current date / time: 2015/06/16 18:40:40.0160 18:40:40.0160 0x0238 SystemInfo: 18:40:40.0160 0x0238 18:40:40.0160 0x0238 OS Version: 6.1.7601 ServicePack: 1.0 18:40:40.0160 0x0238 Product type: Workstation 18:40:40.0160 0x0238 ComputerName: SCHEFFLER-PC 18:40:40.0175 0x0238 UserName: Philipp 18:40:40.0175 0x0238 Windows directory: C:\Windows 18:40:40.0175 0x0238 System windows directory: C:\Windows 18:40:40.0175 0x0238 Processor architecture: Intel x86 18:40:40.0175 0x0238 Number of processors: 2 18:40:40.0175 0x0238 Page size: 0x1000 18:40:40.0175 0x0238 Boot type: Normal boot 18:40:40.0175 0x0238 ============================================================ 18:40:43.0389 0x0238 KLMD registered as C:\Windows\system32\drivers\46743230.sys 18:40:43.0919 0x0238 System UUID: {3D1DEBB9-4086-B209-C6A5-452081E71891} 18:40:44.0824 0x0238 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 18:40:44.0840 0x0238 ============================================================ 18:40:44.0840 0x0238 \Device\Harddisk0\DR0: 18:40:44.0840 0x0238 MBR partitions: 18:40:44.0840 0x0238 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1770D7A, BlocksNum 0x12A14C00 18:40:44.0855 0x0238 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x141859B9, BlocksNum 0x112A7D08 18:40:44.0855 0x0238 ============================================================ 18:40:45.0058 0x0238 C: <-> \Device\Harddisk0\DR0\Partition1 18:40:45.0167 0x0238 D: <-> \Device\Harddisk0\DR0\Partition2 18:40:45.0167 0x0238 ============================================================ 18:40:45.0167 0x0238 Initialize success 18:40:45.0167 0x0238 ============================================================ 18:41:36.0667 0x1660 ============================================================ 18:41:36.0667 0x1660 Scan started 18:41:36.0667 0x1660 Mode: Manual; SigCheck; TDLFS; 18:41:36.0667 0x1660 ============================================================ 18:41:36.0667 0x1660 KSN ping started 18:41:39.0116 0x1660 KSN ping finished: true 18:41:41.0206 0x1660 ================ Scan system memory ======================== 18:41:41.0206 0x1660 System memory - ok 18:41:41.0206 0x1660 ================ Scan services ============================= 18:41:41.0378 0x1660 [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 18:41:41.0518 0x1660 1394ohci - ok 18:41:41.0565 0x1660 [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI C:\Windows\system32\drivers\ACPI.sys 18:41:41.0581 0x1660 ACPI - ok 18:41:41.0612 0x1660 [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 18:41:41.0690 0x1660 AcpiPmi - ok 18:41:41.0815 0x1660 [ FC5B75CA6A1DA31EDD4F8D53F5540B98, CDC445F2790ADFC4C5568C40D4DA8BB95CD71991665B38AEC3D84571C99C3520 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 18:41:41.0830 0x1660 AdobeARMservice - ok 18:41:41.0939 0x1660 [ 00CC35F515079F5F94FABC3AC5C7D363, 7CE8B1715009602059DEDD6CBCA9C18EF079EDA344E7809813D6C0A395622B82 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 18:41:41.0955 0x1660 AdobeFlashPlayerUpdateSvc - ok 18:41:42.0002 0x1660 [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 18:41:42.0033 0x1660 adp94xx - ok 18:41:42.0064 0x1660 [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 18:41:42.0080 0x1660 adpahci - ok 18:41:42.0111 0x1660 [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 18:41:42.0127 0x1660 adpu320 - ok 18:41:42.0220 0x1660 [ C0BF554D2277F7A4C735D475ADE2E3B2, 58ED620CD73239A6AB8F993492494AB0F09705B25E671A842D5163B13F452B15 ] ADSMService C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe 18:41:42.0267 0x1660 ADSMService - detected UnsignedFile.Multi.Generic ( 1 ) 18:41:44.0685 0x1660 Detect skipped due to KSN trusted 18:41:44.0685 0x1660 ADSMService - ok 18:41:44.0747 0x1660 [ 12E6A172D72AFC626727B8635DD17E39, 33B3D109C39DF6EA86AFC3C89A93657906E981D3D22FF854401BC7326990CC08 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 18:41:44.0825 0x1660 AeLookupSvc - ok 18:41:44.0872 0x1660 [ D0B388DA1D111A34366E04EB4A5DD156, 60D226F027F4025CC032CAFF73A80FAFB5FA75445654FDCF80CA8C0419C6E938 ] AFD C:\Windows\system32\drivers\afd.sys 18:41:44.0935 0x1660 AFD - ok 18:41:44.0966 0x1660 [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440 C:\Windows\system32\drivers\agp440.sys 18:41:44.0981 0x1660 agp440 - ok 18:41:45.0028 0x1660 [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys 18:41:45.0044 0x1660 aic78xx - ok 18:41:45.0091 0x1660 [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG C:\Windows\System32\alg.exe 18:41:45.0169 0x1660 ALG - ok 18:41:45.0200 0x1660 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide C:\Windows\system32\drivers\aliide.sys 18:41:45.0215 0x1660 aliide - ok 18:41:45.0231 0x1660 [ B19505648F033393E907E2E419FDE8B3, BEF76AAD61FE0CA1F2B91C491FD94DE1BE67E776BBB7972D57ADFBE0333E9615 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe 18:41:45.0293 0x1660 AMD External Events Utility - ok 18:41:45.0309 0x1660 [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp C:\Windows\system32\drivers\amdagp.sys 18:41:45.0325 0x1660 amdagp - ok 18:41:45.0371 0x1660 [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide C:\Windows\system32\drivers\amdide.sys 18:41:45.0371 0x1660 amdide - ok 18:41:45.0418 0x1660 [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 18:41:45.0496 0x1660 AmdK8 - ok 18:41:45.0527 0x1660 [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 18:41:45.0559 0x1660 AmdPPM - ok 18:41:45.0605 0x1660 [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata C:\Windows\system32\drivers\amdsata.sys 18:41:45.0637 0x1660 amdsata - ok 18:41:45.0668 0x1660 [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 18:41:45.0699 0x1660 amdsbs - ok 18:41:45.0715 0x1660 [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata C:\Windows\system32\drivers\amdxata.sys 18:41:45.0730 0x1660 amdxata - ok 18:41:45.0777 0x1660 [ 4CDC536166F3CADF6496BDAC857B0F58, D02AE2D6E6E9CF26C3333D0B99F06474D0527A0E21E156788250958760130C56 ] AmUStor C:\Windows\system32\drivers\AmUStor.SYS 18:41:45.0824 0x1660 AmUStor - ok 18:41:45.0902 0x1660 [ 2F8616646215EEDB28C2E40994DB8E38, CD8F58FF13896500367DC3179D60A8DFA5DD17D371664B643E4FDC2C9EA697D0 ] androidusb C:\Windows\system32\Drivers\ssadadb.sys 18:41:45.0980 0x1660 androidusb - ok 18:41:46.0058 0x1660 [ 3358CAD1887DDDDD2A36B7796B579292, 40BA1A836276C2AA78914F294661C3C918F2D6DFAA9D6EF3FEB6D1EE3B07F584 ] AntiVirMailService C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe 18:41:46.0120 0x1660 AntiVirMailService - ok 18:41:46.0198 0x1660 [ 1892E1DB0B6431720B98B52AE9388C28, 141098794D774265662FF0EBB4E938D70ADB8BD54B62B1C9A19F6C3C1F263FEC ] AntiVirSchedulerService C:\Program Files\Avira\AntiVir Desktop\sched.exe 18:41:46.0229 0x1660 AntiVirSchedulerService - ok 18:41:46.0292 0x1660 [ 1892E1DB0B6431720B98B52AE9388C28, 141098794D774265662FF0EBB4E938D70ADB8BD54B62B1C9A19F6C3C1F263FEC ] AntiVirService C:\Program Files\Avira\AntiVir Desktop\avguard.exe 18:41:46.0307 0x1660 AntiVirService - ok 18:41:46.0432 0x1660 [ 6FD5165364D88FDABE4FA59E1768376F, B82D11E6FCC297F822E29A49D46C9985955C9F5676D107A397B00D0468F93504 ] AntiVirWebService C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe 18:41:46.0479 0x1660 AntiVirWebService - ok 18:41:46.0541 0x1660 [ 81F97D8F8B3FB94A451CC6F7CF8B2965, 8DEBA4E47E1016D69740C0BB7CDD23852D86E0D42C1C1EA5A847ECB115C38CB1 ] AppID C:\Windows\system32\drivers\appid.sys 18:41:46.0588 0x1660 AppID - ok 18:41:46.0619 0x1660 [ F5090F8FA6757C58E17BAEAA86093636, 5E14CF3032DF5801240F45C59AA93962EA41AA5648A0C6458D16D9B9D95A131F ] AppIDSvc C:\Windows\System32\appidsvc.dll 18:41:46.0666 0x1660 AppIDSvc - ok 18:41:46.0713 0x1660 [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo C:\Windows\System32\appinfo.dll 18:41:46.0775 0x1660 Appinfo - ok 18:41:46.0853 0x1660 [ D2B87FC03BE28CD0B33C2B5C1119FD8E, 97EB74CB7F62C0D06D45CB250E3A90657A0F107C2FC20738FF6B2C87B0240080 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 18:41:46.0931 0x1660 Apple Mobile Device - ok 18:41:46.0978 0x1660 [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc C:\Windows\system32\DRIVERS\arc.sys 18:41:46.0994 0x1660 arc - ok 18:41:47.0009 0x1660 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 18:41:47.0025 0x1660 arcsas - ok 18:41:47.0072 0x1660 [ 104DB777372411C55850C4A2AE6877EF, 0CB2AD98615507275946A9D7B3AC0E29F9F1CE24921277818C8BCB86D1469522 ] AsDsm C:\Windows\system32\drivers\AsDsm.sys 18:41:47.0103 0x1660 AsDsm - ok 18:41:47.0165 0x1660 [ 18E5C2F937F9DEB8C282DF66A3761925, 30294C381F8C7DCB45EF9BCF572F410FF47630E12D5AA02259C6C80F07BEF495 ] ASLDRService C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe 18:41:47.0165 0x1660 ASLDRService - ok 18:41:47.0243 0x1660 [ 7B4D08D2017AC06689D422E06C43F0AA, 42BACCEA0FCEB60B79F78098163147A8DD1DED24CB2F0DBB93EDC07DAB66135C ] ASMMAP C:\Program Files\ATKGFNEX\ASMMAP.sys 18:41:47.0259 0x1660 ASMMAP - ok 18:41:47.0368 0x1660 [ 537B2948976F5D9B5767B74A63EBB395, 1A14F8B582E74AD15B612EDA5B707AA3CB0B2A107ED14572B4232EAA7383B634 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe 18:41:47.0415 0x1660 aspnet_state - ok 18:41:47.0431 0x1660 [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 18:41:47.0571 0x1660 AsyncMac - ok 18:41:47.0587 0x1660 [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi C:\Windows\system32\drivers\atapi.sys 18:41:47.0618 0x1660 atapi - ok 18:41:47.0743 0x1660 [ 31CB2740BFDBAC1E48E2B7EAD38F0D27, D409B06CA4B130BC34C5F8E99A7225E3C1A2A06960897DD1F9DD1A219C11636C ] athr C:\Windows\system32\DRIVERS\athr.sys 18:41:47.0852 0x1660 athr - ok 18:41:48.0086 0x1660 [ 04F09923A393E4E0E8453A8F78361E73, B5C0B9D1195B87AF823887AD9355CD2B4C4F4DDF34103891EE48EA86F0F544E7 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys 18:41:48.0351 0x1660 atikmdag - ok 18:41:48.0429 0x1660 [ 7C157574A181B19B9DCF5F339E25337E, 7CA78363CD420BFE4BFE9A38683CA9E31023AC573D9092666CDAEE6AF4998B60 ] ATKGFNEXSrv C:\Program Files\ATKGFNEX\GFNEXSrv.exe 18:41:48.0460 0x1660 ATKGFNEXSrv - detected UnsignedFile.Multi.Generic ( 1 ) 18:41:50.0925 0x1660 Detect skipped due to KSN trusted 18:41:50.0925 0x1660 ATKGFNEXSrv - ok 18:41:51.0003 0x1660 [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 18:41:51.0050 0x1660 AudioEndpointBuilder - ok 18:41:51.0081 0x1660 [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] Audiosrv C:\Windows\System32\Audiosrv.dll 18:41:51.0112 0x1660 Audiosrv - ok 18:41:51.0175 0x1660 [ 18FB1022DAFC9036ADA9ECF432FAFD06, AFA23C96BDAE15DF4AB32F4CCA04A9D5C5C242E704DC12237CBF57757EBC35AE ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 18:41:51.0190 0x1660 avgntflt - ok 18:41:51.0253 0x1660 [ 062494C204553210FFC0FC33EA58EB36, 2A02003334D3F736907E743C5AB04604228E89DD918E060CCA346F8E739BEB16 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 18:41:51.0268 0x1660 avipbb - ok 18:41:51.0409 0x1660 [ 8884C9DDA76D76BADFD390B33D1DE70D, 0C7EE611C6E8255A280F1C13F7BFE493679E78D05986FB47BF5EF799637F6584 ] Avira.ServiceHost C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe 18:41:51.0487 0x1660 Avira.ServiceHost - ok 18:41:51.0533 0x1660 [ F80F5DCA8A5D9D93CC5BE933D20CAF05, 2AFBB2D62127FACBCABBB3E78F3568A6BA016ED4A97A1490BAA29A1EFB7A4408 ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 18:41:51.0565 0x1660 avkmgr - ok 18:41:51.0643 0x1660 [ D4920FA1E0DC90FF97D970971410EE64, D3C48E812C8E96CF5C4B0BC565485515013FBF6EBDF6D069CF90F01834019E85 ] avmaudio C:\Windows\system32\DRIVERS\avmaudio.sys 18:41:51.0721 0x1660 avmaudio - ok 18:41:51.0783 0x1660 [ D4920FA1E0DC90FF97D970971410EE64, D3C48E812C8E96CF5C4B0BC565485515013FBF6EBDF6D069CF90F01834019E85 ] avmaura C:\Windows\system32\DRIVERS\avmaura.sys 18:41:51.0814 0x1660 avmaura - ok 18:41:51.0892 0x1660 [ 3303FB85532093FC6723632B5947E8C4, F8301069A8EAD7303CAE5B7CAE3F119747E7B7B4402178018EB5254087238A42 ] avnetflt C:\Windows\system32\DRIVERS\avnetflt.sys 18:41:51.0892 0x1660 avnetflt - ok 18:41:51.0939 0x1660 [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV C:\Windows\System32\AxInstSV.dll 18:41:52.0033 0x1660 AxInstSV - ok 18:41:52.0079 0x1660 [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys 18:41:52.0173 0x1660 b06bdrv - ok 18:41:52.0220 0x1660 [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys 18:41:52.0251 0x1660 b57nd60x - ok 18:41:52.0313 0x1660 [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC C:\Windows\System32\bdesvc.dll 18:41:52.0345 0x1660 BDESVC - ok 18:41:52.0360 0x1660 [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep C:\Windows\system32\drivers\Beep.sys 18:41:52.0423 0x1660 Beep - ok 18:41:52.0485 0x1660 [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE C:\Windows\System32\bfe.dll 18:41:52.0563 0x1660 BFE - ok 18:41:52.0610 0x1660 [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS C:\Windows\System32\qmgr.dll 18:41:52.0750 0x1660 BITS - ok 18:41:52.0781 0x1660 [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 18:41:52.0797 0x1660 blbdrive - ok 18:41:52.0875 0x1660 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A, 10F21999FF6B1D410EBF280F7F27DEACA5289739CF12F4293B614B8FC6C88DCC ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 18:41:52.0891 0x1660 Bonjour Service - ok 18:41:52.0937 0x1660 [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 18:41:52.0984 0x1660 bowser - ok 18:41:53.0015 0x1660 [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 18:41:53.0078 0x1660 BrFiltLo - ok 18:41:53.0093 0x1660 [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 18:41:53.0125 0x1660 BrFiltUp - ok 18:41:53.0171 0x1660 [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser C:\Windows\System32\browser.dll 18:41:53.0218 0x1660 Browser - ok 18:41:53.0249 0x1660 [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid C:\Windows\System32\Drivers\Brserid.sys 18:41:53.0312 0x1660 Brserid - ok 18:41:53.0343 0x1660 [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 18:41:53.0374 0x1660 BrSerWdm - ok 18:41:53.0405 0x1660 [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 18:41:53.0421 0x1660 BrUsbMdm - ok 18:41:53.0437 0x1660 [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 18:41:53.0452 0x1660 BrUsbSer - ok 18:41:53.0561 0x1660 [ D06D2E9564B8EB6EFDAF6E44E358C52B, CB9791A28BC255E5C47F19F0345BE796226D0956E33942CB21CA113A1E7867AB ] BstHdAndroidSvc C:\Program Files\BlueStacks\HD-Service.exe 18:41:53.0593 0x1660 BstHdAndroidSvc - ok 18:41:53.0686 0x1660 [ 206629B5F80CAE81D6361ECBFFE7A8C6, 29E1CF7123FC4EAE7CD4D5F06A26A341408CCAE48ABA1B37D23AD22F2586B616 ] BstHdDrv C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys 18:41:53.0702 0x1660 BstHdDrv - ok 18:41:53.0749 0x1660 [ 0592A705BBDFD7563F3055FD02C939BB, 4712407ACAB144E64A8D130DD271A54FD4495E470A6A8A676E70EA57956B6F90 ] BstHdLogRotatorSvc C:\Program Files\BlueStacks\HD-LogRotatorService.exe 18:41:53.0780 0x1660 BstHdLogRotatorSvc - ok 18:41:53.0842 0x1660 [ 2E0CED88F254A3929AE3167456768992, A7CB4F246DEB84FAF77E5CF7A5EA4DD457CE33EFE3009FD5645CF45D78DF1C0C ] BstHdUpdaterSvc C:\Program Files\BlueStacks\HD-UpdaterService.exe 18:41:53.0889 0x1660 BstHdUpdaterSvc - ok 18:41:53.0905 0x1660 [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 18:41:53.0951 0x1660 BTHMODEM - ok 18:41:53.0998 0x1660 [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv C:\Windows\system32\bthserv.dll 18:41:54.0045 0x1660 bthserv - ok 18:41:54.0076 0x1660 [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 18:41:54.0123 0x1660 cdfs - ok 18:41:54.0170 0x1660 [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 18:41:54.0217 0x1660 cdrom - ok 18:41:54.0279 0x1660 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc C:\Windows\System32\certprop.dll 18:41:54.0326 0x1660 CertPropSvc - ok 18:41:54.0373 0x1660 [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass C:\Windows\system32\DRIVERS\circlass.sys 18:41:54.0419 0x1660 circlass - ok 18:41:54.0466 0x1660 [ 33A60554882FDF59CDA3E1806370BBA1, 3DE5451E1CB84AAEBD03F54BEFC670C401447B4881A8B022748B6ECF0F500F01 ] CLFS C:\Windows\system32\CLFS.sys 18:41:54.0497 0x1660 CLFS - ok 18:41:54.0560 0x1660 [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 18:41:54.0591 0x1660 clr_optimization_v2.0.50727_32 - ok 18:41:54.0653 0x1660 [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 18:41:54.0685 0x1660 clr_optimization_v4.0.30319_32 - ok 18:41:54.0700 0x1660 [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 18:41:54.0731 0x1660 CmBatt - ok 18:41:54.0763 0x1660 [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide C:\Windows\system32\drivers\cmdide.sys 18:41:54.0778 0x1660 cmdide - ok 18:41:54.0841 0x1660 [ 3051724F223EA48968B19567DE2A81F4, DCC27DE1B2B35866FC6DBDE95A368E7D0D346B6C3F31D0BACA63DD39B0A8874E ] CNG C:\Windows\system32\Drivers\cng.sys 18:41:54.0872 0x1660 CNG - ok 18:41:54.0919 0x1660 [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 18:41:54.0934 0x1660 Compbatt - ok 18:41:54.0965 0x1660 [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 18:41:54.0997 0x1660 CompositeBus - ok 18:41:55.0028 0x1660 COMSysApp - ok 18:41:55.0043 0x1660 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 18:41:55.0059 0x1660 crcdisk - ok 18:41:55.0121 0x1660 [ 49474B3E37969AF4B5C076F42B623AFF, BDA6B57E9B60EF1B67C74099263D33A367AAA035667239F76AB8B268FD3E8F23 ] CryptSvc C:\Windows\system32\cryptsvc.dll 18:41:55.0153 0x1660 CryptSvc - ok 18:41:55.0199 0x1660 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch C:\Windows\system32\rpcss.dll 18:41:55.0277 0x1660 DcomLaunch - ok 18:41:55.0324 0x1660 [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc C:\Windows\System32\defragsvc.dll 18:41:55.0355 0x1660 defragsvc - ok 18:41:55.0402 0x1660 [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 18:41:55.0449 0x1660 DfsC - ok 18:41:55.0496 0x1660 dgderdrv - ok 18:41:55.0543 0x1660 [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp C:\Windows\system32\dhcpcore.dll 18:41:55.0605 0x1660 Dhcp - ok 18:41:55.0730 0x1660 [ 7AB2DE012C88870C9274E966EC88AB61, CE2098B152B9C039C29C0573C813BFBF13B2D2E6BEE83985374160884A817133 ] DiagTrack C:\Windows\system32\diagtrack.dll 18:41:55.0808 0x1660 DiagTrack - ok 18:41:55.0855 0x1660 [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache C:\Windows\system32\drivers\discache.sys 18:41:55.0901 0x1660 discache - ok 18:41:55.0948 0x1660 [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk C:\Windows\system32\DRIVERS\disk.sys 18:41:55.0964 0x1660 Disk - ok 18:41:56.0011 0x1660 [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache C:\Windows\System32\dnsrslvr.dll 18:41:56.0057 0x1660 Dnscache - ok 18:41:56.0089 0x1660 [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc C:\Windows\System32\dot3svc.dll 18:41:56.0151 0x1660 dot3svc - ok 18:41:56.0198 0x1660 [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS C:\Windows\system32\dps.dll 18:41:56.0245 0x1660 DPS - ok 18:41:56.0276 0x1660 [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 18:41:56.0307 0x1660 drmkaud - ok 18:41:56.0369 0x1660 [ E6B7D1B24E16FB24CE1FEA964E144EBC, 30F81E0A017163A1AB463FE3A13B5CC2905B973E782AEBC1EB63759BF2470658 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys 18:41:56.0385 0x1660 dtsoftbus01 - ok 18:41:56.0447 0x1660 [ 3583A5A8CC2E682BFFBD4630D0FEC08B, FD0F184B358FCECAA763444B414074BEF4E871EB7527D88385519FC158435C72 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 18:41:56.0479 0x1660 DXGKrnl - ok 18:41:56.0525 0x1660 [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost C:\Windows\System32\eapsvc.dll 18:41:56.0588 0x1660 EapHost - ok 18:41:56.0744 0x1660 [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys 18:41:56.0947 0x1660 ebdrv - ok 18:41:57.0009 0x1660 [ D2967F6D4205A227AAA7D094C12F7141, 4E0D48F07F230D5D5DFC2CDCA4467C54DF6EEA6B7C6ABC355E9986C73203E104 ] EFS C:\Windows\System32\lsass.exe 18:41:57.0056 0x1660 EFS - ok 18:41:57.0134 0x1660 [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr C:\Windows\ehome\ehRecvr.exe 18:41:57.0212 0x1660 ehRecvr - ok 18:41:57.0243 0x1660 [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched C:\Windows\ehome\ehsched.exe 18:41:57.0305 0x1660 ehSched - ok 18:41:57.0352 0x1660 [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 18:41:57.0383 0x1660 elxstor - ok 18:41:57.0461 0x1660 [ B538590B338F5379D4B33E266902008B, D73C4152DE0E9D225E29533FC5451D1C4DD344FE66024E6A8122B59ADD1611C8 ] EpsonScanSvc C:\Windows\system32\EscSvc.exe 18:41:57.0493 0x1660 EpsonScanSvc - ok 18:41:57.0555 0x1660 [ BF732C1D0EBBC2A358BB63D147F7447B, 66E5535BFABA523E795F27F91CA6D355E22C6D3E2A82C454640776BE0C7E906B ] EPSON_PM_RPCV4_06 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE 18:41:57.0571 0x1660 EPSON_PM_RPCV4_06 - ok 18:41:57.0602 0x1660 [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev C:\Windows\system32\drivers\errdev.sys 18:41:57.0617 0x1660 ErrDev - ok 18:41:57.0680 0x1660 [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem C:\Windows\system32\es.dll 18:41:57.0727 0x1660 EventSystem - ok 18:41:57.0758 0x1660 [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat C:\Windows\system32\drivers\exfat.sys 18:41:57.0820 0x1660 exfat - ok 18:41:57.0898 0x1660 Fabs - ok 18:41:57.0914 0x1660 [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat C:\Windows\system32\drivers\fastfat.sys 18:41:57.0961 0x1660 fastfat - ok 18:41:57.0992 0x1660 [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax C:\Windows\system32\fxssvc.exe 18:41:58.0070 0x1660 Fax - ok 18:41:58.0085 0x1660 [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc C:\Windows\system32\DRIVERS\fdc.sys 18:41:58.0132 0x1660 fdc - ok 18:41:58.0163 0x1660 [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost C:\Windows\system32\fdPHost.dll 18:41:58.0226 0x1660 fdPHost - ok 18:41:58.0241 0x1660 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub C:\Windows\system32\fdrespub.dll 18:41:58.0304 0x1660 FDResPub - ok 18:41:58.0319 0x1660 [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 18:41:58.0335 0x1660 FileInfo - ok 18:41:58.0382 0x1660 [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 18:41:58.0413 0x1660 Filetrace - ok 18:41:58.0600 0x1660 [ 5BD96D8C5411ACE71A7EAACAF0EF2903, 2AF58E6060C7DEC44B4CA30E14E164473CD4089AE475DAFFC61DFE56990C1147 ] FirebirdServerMAGIXInstance C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe 18:41:58.0803 0x1660 FirebirdServerMAGIXInstance - detected UnsignedFile.Multi.Generic ( 1 ) 18:42:01.0315 0x1660 Detect skipped due to KSN trusted 18:42:01.0315 0x1660 FirebirdServerMAGIXInstance - ok 18:42:01.0346 0x1660 [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 18:42:01.0393 0x1660 flpydisk - ok 18:42:01.0439 0x1660 [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 18:42:01.0455 0x1660 FltMgr - ok 18:42:01.0549 0x1660 [ 6EC244F102C7F129678E5F7309D1366D, C30DA201AC623DA440B0A0716534557C578218C2A591FA8893CCCBD96B4518F9 ] FontCache C:\Windows\system32\FntCache.dll 18:42:01.0627 0x1660 FontCache - ok 18:42:01.0689 0x1660 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 18:42:01.0705 0x1660 FontCache3.0.0.0 - ok 18:42:01.0736 0x1660 [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 18:42:01.0751 0x1660 FsDepends - ok 18:42:01.0783 0x1660 [ B74B0578FD1D3F897E95F2A2B69EA051, 64FCA8452CB37D55679AC8BEF221D6BA1D91E50680D37FFCFB81619ADAA5889C ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys 18:42:01.0814 0x1660 fssfltr - ok 18:42:01.0876 0x1660 [ 206AD9A89BF05DFA1621F1FC7B82592D, EAEE557535D865232237898858F5AE35F868065A1F79BBB48A2173124E2B6F63 ] fsssvc C:\Program Files\Windows Live\Family Safety\fsssvc.exe 18:42:01.0923 0x1660 fsssvc - ok 18:42:01.0970 0x1660 [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 18:42:01.0985 0x1660 Fs_Rec - ok 18:42:02.0017 0x1660 [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 18:42:02.0048 0x1660 fvevol - ok 18:42:02.0110 0x1660 [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 18:42:02.0141 0x1660 gagp30kx - ok 18:42:02.0188 0x1660 [ 185ADA973B5020655CEE342059A86CBB, D3E352DFAF30761505480A4C557D980083F65EC5BD46E2656B2114D47B272A89 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 18:42:02.0204 0x1660 GEARAspiWDM - ok 18:42:02.0251 0x1660 [ 31B40F40E09513ADDC460F6A297AD474, C3A2A29E32F07BA6534380DE5A1EA7EFCB39B288B9541696DA65FA20DE20AFC4 ] ghaio C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys 18:42:02.0266 0x1660 ghaio - ok 18:42:02.0329 0x1660 [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc C:\Windows\System32\gpsvc.dll 18:42:02.0375 0x1660 gpsvc - ok 18:42:02.0485 0x1660 [ 51508F0C2476177E50C31B0BBFBF1BDB, 3F62A05181D54711180C8727AC66D624AFA7FC816A4ACC4DC0CFCF2D2DBE7F87 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 18:42:02.0516 0x1660 gupdate - ok 18:42:02.0547 0x1660 [ 51508F0C2476177E50C31B0BBFBF1BDB, 3F62A05181D54711180C8727AC66D624AFA7FC816A4ACC4DC0CFCF2D2DBE7F87 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 18:42:02.0563 0x1660 gupdatem - ok 18:42:02.0625 0x1660 [ CC839E8D766CC31A7710C9F38CF3E375, 327D57F18B4A2D1CB06C5682D3364097ECD3CF40C2719AA1F41D0B49A26003E4 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 18:42:02.0656 0x1660 gusvc - ok 18:42:02.0687 0x1660 [ 833051C6C6C42117191935F734CFBD97, 5EB5672ABC7994A4AFF855A572158B8BE4FC6E541CFD4B9BE4FF2739A9A6AFB8 ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys 18:42:02.0703 0x1660 hamachi - ok 18:42:02.0719 0x1660 [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 18:42:02.0781 0x1660 hcw85cir - ok 18:42:02.0859 0x1660 [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 18:42:02.0890 0x1660 HdAudAddService - ok 18:42:02.0937 0x1660 [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 18:42:02.0984 0x1660 HDAudBus - ok 18:42:03.0015 0x1660 [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 18:42:03.0062 0x1660 HidBatt - ok 18:42:03.0077 0x1660 [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 18:42:03.0109 0x1660 HidBth - ok 18:42:03.0124 0x1660 [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 18:42:03.0171 0x1660 HidIr - ok 18:42:03.0202 0x1660 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv C:\Windows\system32\hidserv.dll 18:42:03.0249 0x1660 hidserv - ok 18:42:03.0280 0x1660 [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 18:42:03.0327 0x1660 HidUsb - ok 18:42:03.0343 0x1660 [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc C:\Windows\system32\kmsvc.dll 18:42:03.0405 0x1660 hkmsvc - ok 18:42:03.0436 0x1660 [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll 18:42:03.0514 0x1660 HomeGroupListener - ok 18:42:03.0545 0x1660 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 18:42:03.0608 0x1660 HomeGroupProvider - ok 18:42:03.0655 0x1660 [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 18:42:03.0670 0x1660 HpSAMD - ok 18:42:03.0733 0x1660 [ 487569E5DA56A5A432FF8AF6D3599CF9, 7C974D8379C60B4F69A20B01876C49181B0A63AC318C4BD0A21DABFF27A15C9D ] HTTP C:\Windows\system32\drivers\HTTP.sys 18:42:03.0811 0x1660 HTTP - ok 18:42:03.0842 0x1660 [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 18:42:03.0857 0x1660 hwpolicy - ok 18:42:04.0013 0x1660 [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 18:42:04.0029 0x1660 i8042prt - ok 18:42:04.0232 0x1660 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 18:42:04.0279 0x1660 iaStorV - ok 18:42:04.0466 0x1660 [ 3E9213A2A050BF429E91898C90F8B4E3, D80ABE5691087661B19F01927B631CB8C5291120B814B6F863F046E0D643E9E4 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 18:42:04.0528 0x1660 idsvc - ok 18:42:04.0544 0x1660 IEEtwCollectorService - ok 18:42:04.0591 0x1660 [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 18:42:04.0606 0x1660 iirsp - ok 18:42:04.0700 0x1660 [ A06EFD4965F8A3F97A8C9A291D032678, 3B78AFB110A115F7C2136EBFE715CBC073EC341AA0457A1E41D64F9B269DE5BC ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE 18:42:04.0715 0x1660 IJPLMSVC - ok 18:42:04.0793 0x1660 [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT C:\Windows\System32\ikeext.dll 18:42:04.0856 0x1660 IKEEXT - ok 18:42:04.0903 0x1660 IntcAzAudAddService - ok 18:42:04.0934 0x1660 [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide C:\Windows\system32\drivers\intelide.sys 18:42:04.0949 0x1660 intelide - ok 18:42:04.0981 0x1660 [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 18:42:05.0012 0x1660 intelppm - ok 18:42:05.0059 0x1660 [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 18:42:05.0105 0x1660 IPBusEnum - ok 18:42:05.0121 0x1660 [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 18:42:05.0168 0x1660 IpFilterDriver - ok 18:42:05.0246 0x1660 [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 18:42:05.0324 0x1660 iphlpsvc - ok 18:42:05.0355 0x1660 [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 18:42:05.0402 0x1660 IPMIDRV - ok 18:42:05.0433 0x1660 [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 18:42:05.0480 0x1660 IPNAT - ok 18:42:05.0589 0x1660 [ FB7679FD086C60597F8C6929FF66FAC2, 6333339CB052D2A64CFBE5916D6D8F2A4D6CA84A31B549F70733A91F3C4D6EB8 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 18:42:05.0620 0x1660 iPod Service - ok 18:42:05.0636 0x1660 ipswuio - ok 18:42:05.0683 0x1660 [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM C:\Windows\system32\drivers\irenum.sys 18:42:05.0729 0x1660 IRENUM - ok 18:42:05.0745 0x1660 [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp C:\Windows\system32\drivers\isapnp.sys 18:42:05.0761 0x1660 isapnp - ok 18:42:05.0823 0x1660 [ EB34CE31FABD4DC4343FD2AD16D2CAF9, D21C91227A15DA89ECF522345D0AB80B3B7FC24A230596DABDB8BD3B7554CE8C ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 18:42:05.0839 0x1660 iScsiPrt - ok 18:42:05.0870 0x1660 [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 18:42:05.0885 0x1660 kbdclass - ok 18:42:05.0932 0x1660 [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 18:42:05.0963 0x1660 kbdhid - ok 18:42:05.0995 0x1660 [ 3EB803312987FF44265C87CB960DF6AB, D6F44702F92089A0C847044A3933F7311D6A72C4647C3FECB35CDBF96A913A40 ] kbfiltr C:\Windows\system32\DRIVERS\kbfiltr.sys 18:42:06.0010 0x1660 kbfiltr - ok 18:42:06.0010 0x1660 [ D2967F6D4205A227AAA7D094C12F7141, 4E0D48F07F230D5D5DFC2CDCA4467C54DF6EEA6B7C6ABC355E9986C73203E104 ] KeyIso C:\Windows\system32\lsass.exe 18:42:06.0041 0x1660 KeyIso - ok 18:42:06.0073 0x1660 [ 3C9D9DFCF517103677D7B6255C727B48, F03252C1EF131AC4FEB83983B7BB3BAAACE0EEB0B1CFA06D0E04A156D527A0FD ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 18:42:06.0088 0x1660 KSecDD - ok 18:42:06.0104 0x1660 [ 0DFC56491C8B56A35AD52EAF770752FE, C887D6A06DD691DB6E6DC73D2ED0072FE5430F46F85111338196CF342C5892D0 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 18:42:06.0119 0x1660 KSecPkg - ok 18:42:06.0151 0x1660 [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm C:\Windows\system32\msdtckrm.dll 18:42:06.0197 0x1660 KtmRm - ok 18:42:06.0229 0x1660 [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer C:\Windows\system32\srvsvc.dll 18:42:06.0291 0x1660 LanmanServer - ok 18:42:06.0322 0x1660 [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 18:42:06.0369 0x1660 LanmanWorkstation - ok 18:42:06.0416 0x1660 [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 18:42:06.0463 0x1660 lltdio - ok 18:42:06.0525 0x1660 [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc C:\Windows\System32\lltdsvc.dll 18:42:06.0556 0x1660 lltdsvc - ok 18:42:06.0572 0x1660 [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts C:\Windows\System32\lmhsvc.dll 18:42:06.0603 0x1660 lmhosts - ok 18:42:06.0634 0x1660 [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 18:42:06.0665 0x1660 LSI_FC - ok 18:42:06.0681 0x1660 [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 18:42:06.0712 0x1660 LSI_SAS - ok 18:42:06.0728 0x1660 [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 18:42:06.0743 0x1660 LSI_SAS2 - ok 18:42:06.0775 0x1660 [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 18:42:06.0790 0x1660 LSI_SCSI - ok 18:42:06.0821 0x1660 [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv C:\Windows\system32\drivers\luafv.sys 18:42:06.0868 0x1660 luafv - ok 18:42:06.0899 0x1660 [ 969D61D7463D78037DC6B020A435FC0C, 287727E5F6F58D26D79D1FD64E399FA540A32F6E1BF3F5B79628632B5EE5E8E1 ] lullaby C:\Windows\system32\DRIVERS\lullaby.sys 18:42:06.0915 0x1660 lullaby - ok 18:42:06.0946 0x1660 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 18:42:06.0993 0x1660 Mcx2Svc - ok 18:42:07.0040 0x1660 [ BA192919D3DC6C71105C9DE071E80E73, B4E9D8A4E43702E66EADE2CE0E0D175502C79467804D2F75E05BA69BE4FA512F ] MDES C:\ASUS.SYS\DVMExportService.exe 18:42:07.0087 0x1660 MDES - detected UnsignedFile.Multi.Generic ( 1 ) 18:42:09.0536 0x1660 Detect skipped due to KSN trusted 18:42:09.0536 0x1660 MDES - ok 18:42:09.0567 0x1660 [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 18:42:09.0583 0x1660 megasas - ok 18:42:09.0629 0x1660 [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 18:42:09.0661 0x1660 MegaSR - ok 18:42:09.0692 0x1660 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS C:\Windows\system32\mmcss.dll 18:42:09.0739 0x1660 MMCSS - ok 18:42:09.0770 0x1660 [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem C:\Windows\system32\drivers\modem.sys 18:42:09.0817 0x1660 Modem - ok 18:42:09.0879 0x1660 [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 18:42:09.0895 0x1660 monitor - ok 18:42:09.0941 0x1660 [ FE80C18BA448DDD76B7BEAD9EB203D37, FC8C14EAD60ACD4AA5B4F61032FAE331F76C36FBC2D881D25BBBC6EB86682166 ] motmodem C:\Windows\system32\DRIVERS\motmodem.sys 18:42:10.0004 0x1660 motmodem - ok 18:42:10.0035 0x1660 [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 18:42:10.0066 0x1660 mouclass - ok 18:42:10.0097 0x1660 [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 18:42:10.0113 0x1660 mouhid - ok 18:42:10.0144 0x1660 [ 644905A19D0F37F2233DFCE53BC4BC19, F52CB40AA0FD1EBF8CBF0F3BFB20C47142C637719840877FB93F10D085EB8C2B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 18:42:10.0160 0x1660 mountmgr - ok 18:42:10.0253 0x1660 [ 9FC679D10A7377BB04ECC3D0E2E26B53, 24ACD4EC1618A052C29E4463138B28F62C8B78D442DB82F4925E64FC5849A096 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 18:42:10.0269 0x1660 MozillaMaintenance - ok 18:42:10.0300 0x1660 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio C:\Windows\system32\drivers\mpio.sys 18:42:10.0316 0x1660 mpio - ok 18:42:10.0347 0x1660 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 18:42:10.0409 0x1660 mpsdrv - ok 18:42:10.0456 0x1660 [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc C:\Windows\system32\mpssvc.dll 18:42:10.0519 0x1660 MpsSvc - ok 18:42:10.0550 0x1660 [ 03F899F521D2AAED1C55008F734DF252, 4E56A51476A13F5630719018037B1F63DF9ACEA1CFE782AF04E669BD696954C5 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 18:42:10.0612 0x1660 MRxDAV - ok 18:42:10.0643 0x1660 [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 18:42:10.0706 0x1660 mrxsmb - ok 18:42:10.0753 0x1660 [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 18:42:10.0768 0x1660 mrxsmb10 - ok 18:42:10.0799 0x1660 [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 18:42:10.0831 0x1660 mrxsmb20 - ok 18:42:10.0877 0x1660 [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci C:\Windows\system32\drivers\msahci.sys 18:42:10.0893 0x1660 msahci - ok 18:42:10.0909 0x1660 [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm C:\Windows\system32\drivers\msdsm.sys 18:42:10.0924 0x1660 msdsm - ok 18:42:10.0955 0x1660 [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC C:\Windows\System32\msdtc.exe 18:42:10.0987 0x1660 MSDTC - ok 18:42:11.0049 0x1660 [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs C:\Windows\system32\drivers\Msfs.sys 18:42:11.0096 0x1660 Msfs - ok 18:42:11.0127 0x1660 [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 18:42:11.0158 0x1660 mshidkmdf - ok 18:42:11.0189 0x1660 [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 18:42:11.0205 0x1660 msisadrv - ok 18:42:11.0252 0x1660 [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI C:\Windows\system32\iscsiexe.dll 18:42:11.0299 0x1660 MSiSCSI - ok 18:42:11.0314 0x1660 msiserver - ok 18:42:11.0345 0x1660 [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 18:42:11.0392 0x1660 MSKSSRV - ok 18:42:11.0408 0x1660 [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 18:42:11.0455 0x1660 MSPCLOCK - ok 18:42:11.0486 0x1660 [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 18:42:11.0533 0x1660 MSPQM - ok 18:42:11.0564 0x1660 [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 18:42:11.0579 0x1660 MsRPC - ok 18:42:11.0611 0x1660 [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 18:42:11.0642 0x1660 mssmbios - ok 18:42:11.0673 0x1660 [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 18:42:11.0720 0x1660 MSTEE - ok 18:42:11.0751 0x1660 [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 18:42:11.0782 0x1660 MTConfig - ok 18:42:11.0829 0x1660 [ 2E71504A74BE4E3D4EA94568EFF7556E, 1D8BACC85B7390FB4C826ADBEEC269594ECD3CA43A46D1DE1F2035CFC258BC33 ] MTsensor C:\Windows\system32\DRIVERS\ATKACPI.sys 18:42:11.0845 0x1660 MTsensor - ok 18:42:11.0876 0x1660 [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup C:\Windows\system32\Drivers\mup.sys 18:42:11.0891 0x1660 Mup - ok 18:42:12.0001 0x1660 [ CD180A9701D5259E4A30CE25CFF56181, DC34B347D0E15CC95E502B3F5E1A2B9E970B465EA0E317220850A27B5EBB60FF ] MyPublicWiFiService C:\Program Files\MyPublicWiFi\PublicWiFiService.exe 18:42:12.0079 0x1660 MyPublicWiFiService - detected UnsignedFile.Multi.Generic ( 1 ) 18:42:14.0575 0x1660 Detect skipped due to KSN trusted 18:42:14.0575 0x1660 MyPublicWiFiService - ok 18:42:14.0637 0x1660 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent C:\Windows\system32\qagentRT.dll 18:42:14.0684 0x1660 napagent - ok 18:42:14.0746 0x1660 [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 18:42:14.0793 0x1660 NativeWifiP - ok 18:42:14.0871 0x1660 [ 8C9C922D71F1CD4DEF73F186416B7896, 15FF43CD90C7913F83B35F2E7986561584588E8A45196EBD965C3A355836A9C7 ] NDIS C:\Windows\system32\drivers\ndis.sys 18:42:14.0902 0x1660 NDIS - ok 18:42:14.0918 0x1660 [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 18:42:14.0980 0x1660 NdisCap - ok 18:42:15.0043 0x1660 [ 79DD76BFF3E869D1EA3290C107E6CCEA, FF0A5187FF67D6DB3162DAC2481689E5E4DBD5A4F3A93591AFD9FB11B7198720 ] ndiskhaz C:\Windows\system32\DRIVERS\ndiskhaz.sys 18:42:15.0058 0x1660 ndiskhaz - ok 18:42:15.0089 0x1660 [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 18:42:15.0136 0x1660 NdisTapi - ok 18:42:15.0167 0x1660 [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 18:42:15.0199 0x1660 Ndisuio - ok 18:42:15.0230 0x1660 [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 18:42:15.0261 0x1660 NdisWan - ok 18:42:15.0292 0x1660 [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 18:42:15.0339 0x1660 NDProxy - ok 18:42:15.0386 0x1660 [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 18:42:15.0433 0x1660 NetBIOS - ok 18:42:15.0464 0x1660 [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 18:42:15.0511 0x1660 NetBT - ok 18:42:15.0526 0x1660 [ D2967F6D4205A227AAA7D094C12F7141, 4E0D48F07F230D5D5DFC2CDCA4467C54DF6EEA6B7C6ABC355E9986C73203E104 ] Netlogon C:\Windows\system32\lsass.exe 18:42:15.0542 0x1660 Netlogon - ok 18:42:15.0589 0x1660 [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman C:\Windows\System32\netman.dll 18:42:15.0651 0x1660 Netman - ok 18:42:15.0713 0x1660 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 18:42:15.0745 0x1660 NetMsmqActivator - ok 18:42:15.0745 0x1660 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 18:42:15.0776 0x1660 NetPipeActivator - ok 18:42:15.0807 0x1660 [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm C:\Windows\System32\netprofm.dll 18:42:15.0885 0x1660 netprofm - ok 18:42:15.0901 0x1660 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 18:42:15.0916 0x1660 NetTcpActivator - ok 18:42:15.0932 0x1660 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 18:42:15.0947 0x1660 NetTcpPortSharing - ok 18:42:15.0994 0x1660 [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 18:42:16.0010 0x1660 nfrd960 - ok 18:42:16.0072 0x1660 [ F115C5CD29E512F18BD7138A094B77E5, 90C2CE8B256EE9AABF674ADDE7F85E91DAF48EA368452D03C187A4AE027D4E39 ] NlaSvc C:\Windows\System32\nlasvc.dll 18:42:16.0103 0x1660 NlaSvc - ok 18:42:16.0119 0x1660 [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs C:\Windows\system32\drivers\Npfs.sys 18:42:16.0150 0x1660 Npfs - ok 18:42:16.0181 0x1660 [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi C:\Windows\system32\nsisvc.dll 18:42:16.0213 0x1660 nsi - ok 18:42:16.0244 0x1660 [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 18:42:16.0291 0x1660 nsiproxy - ok 18:42:16.0369 0x1660 [ C8DFF8D07755A66C7A4A738930F0FEAC, A2CC58312CE57988ABD976155BE91F558DCEC4C23481C6FBE64B361D511A36EA ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 18:42:16.0447 0x1660 Ntfs - ok 18:42:16.0478 0x1660 [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null C:\Windows\system32\drivers\Null.sys 18:42:16.0525 0x1660 Null - ok 18:42:16.0571 0x1660 [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid C:\Windows\system32\drivers\nvraid.sys 18:42:16.0587 0x1660 nvraid - ok 18:42:16.0618 0x1660 [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor C:\Windows\system32\drivers\nvstor.sys 18:42:16.0634 0x1660 nvstor - ok 18:42:16.0649 0x1660 [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 18:42:16.0665 0x1660 nv_agp - ok 18:42:16.0681 0x1660 [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 18:42:16.0712 0x1660 ohci1394 - ok 18:42:16.0883 0x1660 [ FCE83ABDE761C87D17EA65960455F0E5, E59C13E26845FE0537AEBF0E4A9DC0AF3E6DF55C7A54247FC8078AC5DE666AD4 ] Origin Client Service C:\Program Files\Origin\OriginClientService.exe 18:42:16.0977 0x1660 Origin Client Service - ok 18:42:17.0071 0x1660 [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 18:42:17.0086 0x1660 ose - ok 18:42:17.0336 0x1660 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7, F342100E2E9001F11FDF93F856B50FA43F9B85D2C6B5706EC0433E77206498DA ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 18:42:17.0570 0x1660 osppsvc - ok 18:42:17.0632 0x1660 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 18:42:17.0710 0x1660 p2pimsvc - ok 18:42:17.0741 0x1660 [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc C:\Windows\system32\p2psvc.dll 18:42:17.0804 0x1660 p2psvc - ok 18:42:17.0835 0x1660 [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport C:\Windows\system32\DRIVERS\parport.sys 18:42:17.0866 0x1660 Parport - ok 18:42:17.0882 0x1660 [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr C:\Windows\system32\drivers\partmgr.sys 18:42:17.0897 0x1660 partmgr - ok 18:42:17.0913 0x1660 [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys 18:42:17.0944 0x1660 Parvdm - ok 18:42:17.0991 0x1660 [ 52954BE460EC6C54C0ACB2B3B126FFC6, 9F9878EC5ABC74C5A8EE8E1D940F0934F081895B07D844F42F80A638FE713F7B ] PcaSvc C:\Windows\System32\pcasvc.dll 18:42:18.0022 0x1660 PcaSvc - ok 18:42:18.0053 0x1660 [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci C:\Windows\system32\drivers\pci.sys 18:42:18.0069 0x1660 pci - ok 18:42:18.0100 0x1660 [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide C:\Windows\system32\drivers\pciide.sys 18:42:18.0131 0x1660 pciide - ok 18:42:18.0163 0x1660 [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 18:42:18.0178 0x1660 pcmcia - ok 18:42:18.0209 0x1660 [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw C:\Windows\system32\drivers\pcw.sys 18:42:18.0225 0x1660 pcw - ok 18:42:18.0287 0x1660 [ AEBC369F7DC72AB3F5B9BDF34FA0D43F, 2A819154AC6C23E97C583D90B4D0C112188B7AE9D8D9B3F88811BFCED124E551 ] PEAUTH C:\Windows\system32\drivers\peauth.sys 18:42:18.0334 0x1660 PEAUTH - ok 18:42:18.0428 0x1660 [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla C:\Windows\system32\pla.dll 18:42:18.0553 0x1660 pla - ok 18:42:18.0615 0x1660 [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay C:\Windows\system32\umpnpmgr.dll 18:42:18.0646 0x1660 PlugPlay - ok 18:42:18.0677 0x1660 [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 18:42:18.0724 0x1660 PNRPAutoReg - ok 18:42:18.0740 0x1660 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 18:42:18.0771 0x1660 PNRPsvc - ok 18:42:18.0833 0x1660 [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 18:42:18.0880 0x1660 PolicyAgent - ok 18:42:18.0911 0x1660 [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power C:\Windows\system32\umpo.dll 18:42:18.0958 0x1660 Power - ok 18:42:18.0989 0x1660 [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 18:42:19.0036 0x1660 PptpMiniport - ok 18:42:19.0067 0x1660 [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor C:\Windows\system32\DRIVERS\processr.sys 18:42:19.0114 0x1660 Processor - ok 18:42:19.0145 0x1660 [ FD9692A3D31E021207D3C2A9DDDC2BE3, 5295EFAD9BD4B59996935A41825392C12A4C968D161BEEA37797F90AF8E54229 ] ProfSvc C:\Windows\system32\profsvc.dll 18:42:19.0208 0x1660 ProfSvc - ok 18:42:19.0223 0x1660 [ D2967F6D4205A227AAA7D094C12F7141, 4E0D48F07F230D5D5DFC2CDCA4467C54DF6EEA6B7C6ABC355E9986C73203E104 ] ProtectedStorage C:\Windows\system32\lsass.exe 18:42:19.0239 0x1660 ProtectedStorage - ok 18:42:19.0270 0x1660 [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched C:\Windows\system32\DRIVERS\pacer.sys 18:42:19.0317 0x1660 Psched - ok 18:42:19.0411 0x1660 [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 18:42:19.0473 0x1660 ql2300 - ok 18:42:19.0520 0x1660 [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 18:42:19.0551 0x1660 ql40xx - ok 18:42:19.0582 0x1660 [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE C:\Windows\system32\qwave.dll 18:42:19.0645 0x1660 QWAVE - ok 18:42:19.0676 0x1660 [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 18:42:19.0691 0x1660 QWAVEdrv - ok 18:42:19.0707 0x1660 [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 18:42:19.0754 0x1660 RasAcd - ok 18:42:19.0785 0x1660 [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 18:42:19.0847 0x1660 RasAgileVpn - ok 18:42:19.0879 0x1660 [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto C:\Windows\System32\rasauto.dll 18:42:19.0925 0x1660 RasAuto - ok 18:42:19.0941 0x1660 [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 18:42:19.0972 0x1660 Rasl2tp - ok 18:42:20.0019 0x1660 [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan C:\Windows\System32\rasmans.dll 18:42:20.0066 0x1660 RasMan - ok 18:42:20.0081 0x1660 [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 18:42:20.0144 0x1660 RasPppoe - ok 18:42:20.0175 0x1660 [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 18:42:20.0206 0x1660 RasSstp - ok 18:42:20.0237 0x1660 [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 18:42:20.0284 0x1660 rdbss - ok 18:42:20.0315 0x1660 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 18:42:20.0347 0x1660 rdpbus - ok 18:42:20.0378 0x1660 [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 18:42:20.0425 0x1660 RDPCDD - ok 18:42:20.0456 0x1660 [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 18:42:20.0487 0x1660 RDPENCDD - ok 18:42:20.0503 0x1660 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 18:42:20.0518 0x1660 RDPREFMP - ok 18:42:20.0612 0x1660 [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 18:42:20.0690 0x1660 RdpVideoMiniport - ok 18:42:20.0737 0x1660 [ CD9214A6AE17D188D17C3CF8CB9CC693, 2E16FF1F7446F0600D6519010FD05A30B94D97167C16B3E7FC396A97D8139D60 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 18:42:20.0799 0x1660 RDPWD - ok 18:42:20.0846 0x1660 [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 18:42:20.0861 0x1660 rdyboost - ok 18:42:20.0893 0x1660 [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess C:\Windows\System32\mprdim.dll 18:42:20.0955 0x1660 RemoteAccess - ok 18:42:21.0002 0x1660 [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry C:\Windows\system32\regsvc.dll 18:42:21.0033 0x1660 RemoteRegistry - ok 18:42:21.0049 0x1660 [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 18:42:21.0080 0x1660 RpcEptMapper - ok 18:42:21.0111 0x1660 [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator C:\Windows\system32\locator.exe 18:42:21.0158 0x1660 RpcLocator - ok 18:42:21.0205 0x1660 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs C:\Windows\system32\rpcss.dll 18:42:21.0251 0x1660 RpcSs - ok 18:42:21.0283 0x1660 [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 18:42:21.0329 0x1660 rspndr - ok 18:42:21.0345 0x1660 RTHDMIAzAudService - ok 18:42:21.0376 0x1660 [ D2967F6D4205A227AAA7D094C12F7141, 4E0D48F07F230D5D5DFC2CDCA4467C54DF6EEA6B7C6ABC355E9986C73203E104 ] SamSs C:\Windows\system32\lsass.exe 18:42:21.0392 0x1660 SamSs - ok 18:42:21.0439 0x1660 [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 18:42:21.0454 0x1660 sbp2port - ok 18:42:21.0470 0x1660 [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr C:\Windows\System32\SCardSvr.dll 18:42:21.0517 0x1660 SCardSvr - ok 18:42:21.0548 0x1660 [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 18:42:21.0595 0x1660 scfilter - ok 18:42:21.0673 0x1660 [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule C:\Windows\system32\schedsvc.dll 18:42:21.0735 0x1660 Schedule - ok 18:42:21.0782 0x1660 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc C:\Windows\System32\certprop.dll 18:42:21.0813 0x1660 SCPolicySvc - ok 18:42:21.0860 0x1660 [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC C:\Windows\System32\SDRSVC.dll 18:42:21.0922 0x1660 SDRSVC - ok 18:42:21.0953 0x1660 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys 18:42:22.0016 0x1660 secdrv - ok 18:42:22.0047 0x1660 [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon C:\Windows\system32\seclogon.dll 18:42:22.0094 0x1660 seclogon - ok 18:42:22.0125 0x1660 [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS C:\Windows\System32\sens.dll 18:42:22.0203 0x1660 SENS - ok 18:42:22.0219 0x1660 [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc C:\Windows\system32\sensrsvc.dll 18:42:22.0281 0x1660 SensrSvc - ok 18:42:22.0297 0x1660 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 18:42:22.0343 0x1660 Serenum - ok 18:42:22.0375 0x1660 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial C:\Windows\system32\DRIVERS\serial.sys 18:42:22.0406 0x1660 Serial - ok 18:42:22.0437 0x1660 [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 18:42:22.0453 0x1660 sermouse - ok 18:42:22.0499 0x1660 [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv C:\Windows\system32\sessenv.dll 18:42:22.0531 0x1660 SessionEnv - ok 18:42:22.0562 0x1660 [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 18:42:22.0593 0x1660 sffdisk - ok 18:42:22.0624 0x1660 [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 18:42:22.0655 0x1660 sffp_mmc - ok 18:42:22.0687 0x1660 [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 18:42:22.0718 0x1660 sffp_sd - ok 18:42:22.0749 0x1660 [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 18:42:22.0780 0x1660 sfloppy - ok 18:42:22.0843 0x1660 [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess C:\Windows\System32\ipnathlp.dll 18:42:22.0905 0x1660 SharedAccess - ok 18:42:22.0952 0x1660 [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 18:42:22.0999 0x1660 ShellHWDetection - ok 18:42:23.0030 0x1660 [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp C:\Windows\system32\drivers\sisagp.sys 18:42:23.0045 0x1660 sisagp - ok 18:42:23.0092 0x1660 [ 6F0C643C7F49F2091B01D014EAE72E1A, 5B81BDE24DB0F796999B97753580C5D53BA16AAE62EA310DF529EE6D1B0F43C6 ] SiSGbeLH C:\Windows\system32\DRIVERS\SiSGB6.sys 18:42:23.0108 0x1660 SiSGbeLH - ok 18:42:23.0139 0x1660 [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 18:42:23.0155 0x1660 SiSRaid2 - ok 18:42:23.0186 0x1660 [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 18:42:23.0201 0x1660 SiSRaid4 - ok 18:42:23.0295 0x1660 [ A9C057A9463C25490CF99EA8DF8A4B35, 8F4D1C40D0F17EDBF84ED455B8946F782C7552383F0A07E410A9B6CFF7F51D63 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe 18:42:23.0326 0x1660 SkypeUpdate - ok 18:42:23.0357 0x1660 [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb C:\Windows\system32\DRIVERS\smb.sys 18:42:23.0404 0x1660 Smb - ok 18:42:23.0451 0x1660 [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 18:42:23.0498 0x1660 SNMPTRAP - ok 18:42:23.0607 0x1660 [ 1A122A796DF161477D70CA9088A842EB, D2FF38BC1742E50296F0207B348EB8A0E5CED95733A8F319550EE5A656D91960 ] SNP2UVC C:\Windows\system32\DRIVERS\snp2uvc.sys 18:42:23.0685 0x1660 SNP2UVC - ok 18:42:23.0716 0x1660 [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr C:\Windows\system32\drivers\spldr.sys 18:42:23.0732 0x1660 spldr - ok 18:42:23.0763 0x1660 [ 739DB668DBD812285ECC553E64A5E212, 08E99CD042232CEB20BB5A808E914C9F2F0C154099BF921BA40E661B08472CF5 ] spmgr C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe 18:42:23.0779 0x1660 spmgr - ok 18:42:23.0810 0x1660 [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler C:\Windows\System32\spoolsv.exe 18:42:23.0888 0x1660 Spooler - ok 18:42:24.0044 0x1660 [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc C:\Windows\system32\sppsvc.exe 18:42:24.0231 0x1660 sppsvc - ok 18:42:24.0293 0x1660 [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify C:\Windows\system32\sppuinotify.dll 18:42:24.0340 0x1660 sppuinotify - ok 18:42:24.0403 0x1660 [ FEB11DBAA5E152D98BD897C97A6DDCD0, 7ABCCDDE6B9A58CECA480AA57468E7A1F537893A2CB7C20E1A366EC8EEC7FA59 ] sptd C:\Windows\System32\Drivers\sptd.sys 18:42:24.0418 0x1660 sptd - ok 18:42:24.0465 0x1660 [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv C:\Windows\system32\DRIVERS\srv.sys 18:42:24.0496 0x1660 srv - ok 18:42:24.0527 0x1660 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 18:42:24.0543 0x1660 srv2 - ok 18:42:24.0559 0x1660 [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 18:42:24.0574 0x1660 srvnet - ok 18:42:24.0668 0x1660 [ BB6EDB0257860083193CC1581AC7D485, DE2A6AA57C48D4FACF155C2FD876D5F3238A9107F8313FB3D0BF7CE34B0ED559 ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys 18:42:24.0683 0x1660 ssadbus - ok 18:42:24.0730 0x1660 [ 5BCB68F7B62159C07789D3F405750623, 5363AC26FDD7114BB23F09F79541A691FF6E140C4B802F5AE284BCE5F623D5E0 ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys 18:42:24.0746 0x1660 ssadmdfl - ok 18:42:24.0793 0x1660 [ 1588A89F9CD9E68DE9FCC9F60FDB5C08, E2E547A0AC10DAA55029500052D89A7FB124FFBE7742F16AD41B857890AED50F ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys 18:42:24.0808 0x1660 ssadmdm - ok 18:42:24.0855 0x1660 [ 9EFD9F42795C9E90206C1E9A9B25E8D3, CD5E64A95E2022A8B9BBD4710854BDD1AC1772441275F40EFD31508376B2B99B ] ssadserd C:\Windows\system32\DRIVERS\ssadserd.sys 18:42:24.0871 0x1660 ssadserd - ok 18:42:24.0933 0x1660 [ E6CE6348A4F6E06925548F62527F0F99, AD39D46311F79EDFC4F7DA2922EB95CE0F27C3A1B1642371C4E7E48F6515CB7B ] sscdbus C:\Windows\system32\DRIVERS\sscdbus.sys 18:42:24.0949 0x1660 sscdbus - ok 18:42:24.0980 0x1660 [ 68820F9A67F0D170A6842094EBDCD924, C1A8B53BF6804D17B30FA5CDEC0ADD0B0252D773F1AECCB687B53BB8BF7FB240 ] sscdmdfl C:\Windows\system32\DRIVERS\sscdmdfl.sys 18:42:24.0995 0x1660 sscdmdfl - ok 18:42:25.0011 0x1660 [ 0A3B7562002C50F208FCCDEB7380B57B, D2E34E622D37B6820F185B7072F7895410F92C3C064E1419AD7FDC7E594326BB ] sscdmdm C:\Windows\system32\DRIVERS\sscdmdm.sys 18:42:25.0027 0x1660 sscdmdm - ok 18:42:25.0089 0x1660 [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 18:42:25.0151 0x1660 SSDPSRV - ok 18:42:25.0229 0x1660 [ 424566865D82AA4BD8D6546C1F2065FA, 37B4C04C7C0EE0F3347A9E9F35B095478299F7324CA87AAE487BF989B0E6AE03 ] ssmdrv C:\Windows\system32\DRIVERS\ssmdrv.sys 18:42:25.0261 0x1660 ssmdrv - ok 18:42:25.0292 0x1660 [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc C:\Windows\system32\sstpsvc.dll 18:42:25.0339 0x1660 SstpSvc - ok 18:42:25.0510 0x1660 [ 9DA3B55B17B54789AFB8C657D4ACE4D7, 5E4599E682327E3B8097A88A69ED73F96254A29054744D5DFB782054863F131E ] ss_conn_service D:\Samsung Kies\USB Drivers\25_escape\conn\ss_conn_service.exe 18:42:25.0541 0x1660 ss_conn_service - ok 18:42:25.0635 0x1660 [ 7F4FB8D168A19EB7B4B55C73212025F0, 716D25F11020690EF0EE0CCD461A3AADED057EA5159B09E39A42CB671954F7AC ] stdriver C:\Windows\system32\DRIVERS\stdriver32.sys 18:42:25.0635 0x1660 stdriver - ok 18:42:25.0744 0x1660 [ 0A3544D7E9AF7D8C991C904339157EDC, 1E1DE4D808AE1174B0CB37E93EBADFC98FEBCD70D612CFE393DDA513581CD123 ] Steam Client Service C:\Program Files\Common Files\Steam\SteamService.exe 18:42:25.0775 0x1660 Steam Client Service - ok 18:42:25.0807 0x1660 [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 18:42:25.0822 0x1660 stexstor - ok 18:42:25.0869 0x1660 [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc C:\Windows\System32\wiaservc.dll 18:42:25.0916 0x1660 StiSvc - ok 18:42:25.0947 0x1660 [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum C:\Windows\system32\drivers\swenum.sys 18:42:25.0963 0x1660 swenum - ok 18:42:25.0994 0x1660 [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv C:\Windows\System32\swprv.dll 18:42:26.0041 0x1660 swprv - ok 18:42:26.0103 0x1660 [ 3F4982DE07D89A1084861E9D59F7EBB1, E1D3D91918CF226D7971DD3B5A6F75F00A0D501436B032E0149E2665D04DED48 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys 18:42:26.0119 0x1660 SynTP - ok 18:42:26.0197 0x1660 [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain C:\Windows\system32\sysmain.dll 18:42:26.0259 0x1660 SysMain - ok 18:42:26.0290 0x1660 [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll 18:42:26.0306 0x1660 TabletInputService - ok 18:42:26.0337 0x1660 [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv C:\Windows\System32\tapisrv.dll 18:42:26.0384 0x1660 TapiSrv - ok 18:42:26.0415 0x1660 [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS C:\Windows\System32\tbssvc.dll 18:42:26.0477 0x1660 TBS - ok 18:42:26.0555 0x1660 [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 18:42:26.0618 0x1660 Tcpip - ok 18:42:26.0680 0x1660 [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 18:42:26.0743 0x1660 TCPIP6 - ok 18:42:26.0789 0x1660 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 18:42:26.0805 0x1660 tcpipreg - ok 18:42:26.0836 0x1660 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 18:42:26.0867 0x1660 TDPIPE - ok 18:42:26.0899 0x1660 [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 18:42:26.0930 0x1660 TDTCP - ok 18:42:26.0977 0x1660 [ 7FE680A3DFA421C4A8E4879AE4C5AAB0, A4C64E155AB2843823CD3586756BA7681CFDEA50812095468221503BBAD30DCD ] tdx C:\Windows\system32\DRIVERS\tdx.sys 18:42:27.0008 0x1660 tdx - ok 18:42:27.0008 0x1660 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD C:\Windows\system32\drivers\termdd.sys 18:42:27.0023 0x1660 TermDD - ok 18:42:27.0101 0x1660 [ FCFD4F50419B4BC72E80066DA10D2E54, 7C2314A57A404525F0444986332DBAE0964A3359374671598387051D7AAE72AE ] TermService C:\Windows\System32\termsrv.dll 18:42:27.0164 0x1660 TermService - ok 18:42:27.0211 0x1660 [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes C:\Windows\system32\themeservice.dll 18:42:27.0257 0x1660 Themes - ok 18:42:27.0289 0x1660 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER C:\Windows\system32\mmcss.dll 18:42:27.0320 0x1660 THREADORDER - ok 18:42:27.0335 0x1660 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks C:\Windows\System32\trkwks.dll 18:42:27.0382 0x1660 TrkWks - ok 18:42:27.0429 0x1660 [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 18:42:27.0538 0x1660 TrustedInstaller - ok 18:42:27.0569 0x1660 [ 6C5139E4283249518F7743D7043775B3, 58684E8C90EBAC65459A97C905CDCFE3A915CFF7E8E96071DE1AC3489F85E67F ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 18:42:27.0601 0x1660 tssecsrv - ok 18:42:27.0679 0x1660 [ C6A5FBD4977305E1FA23E02C042DB463, A6EB5E4B8051A258D40A385609E930318EAA3494C8466F48542B806FE6A7C47A ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 18:42:27.0725 0x1660 TsUsbFlt - ok 18:42:27.0772 0x1660 [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 18:42:27.0819 0x1660 tunnel - ok 18:42:27.0866 0x1660 [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 18:42:27.0881 0x1660 uagp35 - ok 18:42:27.0897 0x1660 [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 18:42:27.0959 0x1660 udfs - ok 18:42:28.0006 0x1660 [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect C:\Windows\system32\UI0Detect.exe 18:42:28.0037 0x1660 UI0Detect - ok 18:42:28.0084 0x1660 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 18:42:28.0100 0x1660 uliagpkx - ok 18:42:28.0131 0x1660 [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 18:42:28.0162 0x1660 umbus - ok 18:42:28.0209 0x1660 [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 18:42:28.0271 0x1660 UmPass - ok 18:42:28.0303 0x1660 [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost C:\Windows\System32\upnphost.dll 18:42:28.0349 0x1660 upnphost - ok 18:42:28.0381 0x1660 [ EC1C23779BB41A8B2AB2AA6FCE308BDE, D027A2B472CAE97AECB16F69BE52E06CB61E1C61AE196C22662050B711C1C72D ] USBAAPL C:\Windows\system32\Drivers\usbaapl.sys 18:42:28.0412 0x1660 USBAAPL - ok 18:42:28.0459 0x1660 [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 18:42:28.0521 0x1660 usbccgp - ok 18:42:28.0552 0x1660 [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir C:\Windows\system32\drivers\usbcir.sys 18:42:28.0599 0x1660 usbcir - ok 18:42:28.0615 0x1660 [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 18:42:28.0646 0x1660 usbehci - ok 18:42:28.0708 0x1660 [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 18:42:28.0739 0x1660 usbhub - ok 18:42:28.0755 0x1660 [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys 18:42:28.0786 0x1660 usbohci - ok 18:42:28.0833 0x1660 [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 18:42:28.0849 0x1660 usbprint - ok 18:42:28.0895 0x1660 [ FC6B21DB4B5B398AB93DBE59CBF11036, A94094C208F376405C07822A6143001EF1B12AE93205CD8002E87F6EB45F6374 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 18:42:28.0927 0x1660 usbscan - ok 18:42:28.0958 0x1660 [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 18:42:28.0973 0x1660 USBSTOR - ok 18:42:29.0020 0x1660 [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 18:42:29.0051 0x1660 usbuhci - ok 18:42:29.0114 0x1660 [ DE014425522610BEDCA3821BB8C0F1D5, D6FEA0DF07F89834AEEE8C02CC7FD41068D758B6CCECE2EEE5CF4B9DB646FA1E ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys 18:42:29.0145 0x1660 usbvideo - ok 18:42:29.0192 0x1660 [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms C:\Windows\System32\uxsms.dll 18:42:29.0254 0x1660 UxSms - ok 18:42:29.0270 0x1660 [ D2967F6D4205A227AAA7D094C12F7141, 4E0D48F07F230D5D5DFC2CDCA4467C54DF6EEA6B7C6ABC355E9986C73203E104 ] VaultSvc C:\Windows\system32\lsass.exe 18:42:29.0285 0x1660 VaultSvc - ok 18:42:29.0348 0x1660 [ 793E79C7D24E5C96AF7A9EE295CCF4F2, 2939A604FA258BAA26E98F492352DE738B21A5FD88AE4E98D4E89EEFDE0A56F2 ] VBoxDrv C:\Windows\system32\DRIVERS\VBoxDrv.sys 18:42:29.0363 0x1660 VBoxDrv - ok 18:42:29.0426 0x1660 [ 251DCB17574C6A91A57946C984F3ECFE, A8F6A456941283879AC7C4DA50736EC4077E9E4A25DF2001BF2B4B2CCF221560 ] VBoxUSBMon C:\Windows\system32\DRIVERS\VBoxUSBMon.sys 18:42:29.0441 0x1660 VBoxUSBMon - ok 18:42:29.0473 0x1660 [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 18:42:29.0488 0x1660 vdrvroot - ok 18:42:29.0535 0x1660 [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds C:\Windows\System32\vds.exe 18:42:29.0582 0x1660 vds - ok 18:42:29.0613 0x1660 [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 18:42:29.0644 0x1660 vga - ok 18:42:29.0675 0x1660 [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave C:\Windows\System32\drivers\vga.sys 18:42:29.0707 0x1660 VgaSave - ok 18:42:29.0753 0x1660 [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 18:42:29.0800 0x1660 vhdmp - ok 18:42:29.0831 0x1660 [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp C:\Windows\system32\drivers\viaagp.sys 18:42:29.0847 0x1660 viaagp - ok 18:42:29.0878 0x1660 [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys 18:42:29.0909 0x1660 ViaC7 - ok 18:42:29.0941 0x1660 [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide C:\Windows\system32\drivers\viaide.sys 18:42:29.0956 0x1660 viaide - ok 18:42:29.0972 0x1660 [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr C:\Windows\system32\drivers\volmgr.sys 18:42:29.0987 0x1660 volmgr - ok 18:42:30.0019 0x1660 [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 18:42:30.0034 0x1660 volmgrx - ok 18:42:30.0081 0x1660 [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap C:\Windows\system32\drivers\volsnap.sys 18:42:30.0097 0x1660 volsnap - ok 18:42:30.0143 0x1660 [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 18:42:30.0159 0x1660 vsmraid - ok 18:42:30.0237 0x1660 [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS C:\Windows\system32\vssvc.exe 18:42:30.0331 0x1660 VSS - ok 18:42:30.0362 0x1660 [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 18:42:30.0393 0x1660 vwifibus - ok 18:42:30.0440 0x1660 [ 7090D3436EEB4E7DA3373090A23448F7, 3A130B28F2BFA7DCEC8596C4CE4E187B019F5ECF1AAC8DD1BBDE9CBD2428FEC2 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 18:42:30.0487 0x1660 vwififlt - ok 18:42:30.0518 0x1660 [ A3F04CBEA6C2A10E6CB01F8B47611882, 32AFE18B07FECA30BC95831A5DC94C784E543784DF16165334A777DC84E91EF3 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 18:42:30.0533 0x1660 vwifimp - ok 18:42:30.0580 0x1660 [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time C:\Windows\system32\w32time.dll 18:42:30.0627 0x1660 W32Time - ok 18:42:30.0658 0x1660 [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 18:42:30.0689 0x1660 WacomPen - ok 18:42:30.0721 0x1660 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 18:42:30.0767 0x1660 WANARP - ok 18:42:30.0783 0x1660 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 18:42:30.0814 0x1660 Wanarpv6 - ok 18:42:30.0892 0x1660 [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine C:\Windows\system32\wbengine.exe 18:42:31.0001 0x1660 wbengine - ok 18:42:31.0064 0x1660 [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 18:42:31.0095 0x1660 WbioSrvc - ok 18:42:31.0126 0x1660 [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc C:\Windows\System32\wcncsvc.dll 18:42:31.0189 0x1660 wcncsvc - ok 18:42:31.0220 0x1660 [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 18:42:31.0267 0x1660 WcsPlugInService - ok 18:42:31.0313 0x1660 [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd C:\Windows\system32\DRIVERS\wd.sys 18:42:31.0329 0x1660 Wd - ok 18:42:31.0376 0x1660 [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 18:42:31.0407 0x1660 Wdf01000 - ok 18:42:31.0469 0x1660 [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiServiceHost C:\Windows\system32\wdi.dll 18:42:31.0532 0x1660 WdiServiceHost - ok 18:42:31.0532 0x1660 [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiSystemHost C:\Windows\system32\wdi.dll 18:42:31.0563 0x1660 WdiSystemHost - ok 18:42:31.0610 0x1660 [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient C:\Windows\System32\webclnt.dll 18:42:31.0657 0x1660 WebClient - ok 18:42:31.0688 0x1660 [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc C:\Windows\system32\wecsvc.dll 18:42:31.0750 0x1660 Wecsvc - ok 18:42:31.0781 0x1660 [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport C:\Windows\System32\wercplsupport.dll 18:42:31.0828 0x1660 wercplsupport - ok 18:42:31.0859 0x1660 [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc C:\Windows\System32\WerSvc.dll 18:42:31.0906 0x1660 WerSvc - ok 18:42:31.0922 0x1660 [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 18:42:31.0953 0x1660 WfpLwf - ok 18:42:31.0984 0x1660 [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount C:\Windows\system32\drivers\wimmount.sys 18:42:32.0000 0x1660 WIMMount - ok 18:42:32.0078 0x1660 [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll 18:42:32.0156 0x1660 WinDefend - ok 18:42:32.0187 0x1660 WinHttpAutoProxySvc - ok 18:42:32.0234 0x1660 [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 18:42:32.0281 0x1660 Winmgmt - ok 18:42:32.0374 0x1660 [ 1DE9BD23AFA36150586C732D876D9B74, 32CF2C8EC18CFDA677AB72A182EB4B839DCC72BFCD6CA309BE2F434991CAE973 ] WinRM C:\Windows\system32\WsmSvc.dll 18:42:32.0483 0x1660 WinRM - ok 18:42:32.0546 0x1660 [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb C:\Windows\system32\drivers\WinUsb.sys 18:42:32.0593 0x1660 WinUsb - ok 18:42:32.0655 0x1660 [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc C:\Windows\System32\wlansvc.dll 18:42:32.0733 0x1660 Wlansvc - ok 18:42:32.0858 0x1660 [ 5144AE67D60EC653F97DDF3FEED29E77, F6238767284B2356A9F502E2ACCFAAC283FA13CBF238E98B5115A55179526B10 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 18:42:32.0905 0x1660 wlidsvc - ok 18:42:32.0936 0x1660 [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 18:42:32.0967 0x1660 WmiAcpi - ok 18:42:33.0014 0x1660 [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 18:42:33.0045 0x1660 wmiApSrv - ok 18:42:33.0139 0x1660 [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe 18:42:33.0201 0x1660 WMPNetworkSvc - ok 18:42:33.0232 0x1660 [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc C:\Windows\System32\wpcsvc.dll 18:42:33.0263 0x1660 WPCSvc - ok 18:42:33.0295 0x1660 [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 18:42:33.0341 0x1660 WPDBusEnum - ok 18:42:33.0373 0x1660 [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 18:42:33.0419 0x1660 ws2ifsl - ok 18:42:33.0451 0x1660 [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc C:\Windows\System32\wscsvc.dll 18:42:33.0497 0x1660 wscsvc - ok 18:42:33.0560 0x1660 [ 553F6CCD7C58EB98D4A8FBDAF283D7A9, 71FBE50C470D1F54FDAADCECEC2CB021AE240CD59DE4E8EB5BCAA6E7F2F86560 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys 18:42:33.0591 0x1660 WSDPrintDevice - ok 18:42:33.0622 0x1660 [ 7DC0270CFD4A05B4112E3EBBF083B595, DF4FCDE511F0B68B6C6E28C820EB722C34710F31A16023A9A297EAD228E00137 ] WSDScan C:\Windows\system32\DRIVERS\WSDScan.sys 18:42:33.0669 0x1660 WSDScan - ok 18:42:33.0669 0x1660 WSearch - ok 18:42:33.0778 0x1660 [ B5202CD63C502A16F6C94186089CF602, 0C4B3F92318D81B67820524D71618333539FEAD2877D8ABA5D7D82E66A9A6417 ] wuauserv C:\Windows\system32\wuaueng.dll 18:42:33.0965 0x1660 wuauserv - ok 18:42:34.0012 0x1660 [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 18:42:34.0121 0x1660 WudfPf - ok 18:42:34.0168 0x1660 [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd C:\Windows\system32\drivers\WUDFRd.sys 18:42:34.0199 0x1660 WUDFRd - ok 18:42:34.0231 0x1660 [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc C:\Windows\System32\WUDFSvc.dll 18:42:34.0277 0x1660 wudfsvc - ok 18:42:34.0309 0x1660 [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc C:\Windows\System32\wwansvc.dll 18:42:34.0387 0x1660 WwanSvc - ok 18:42:34.0465 0x1660 [ 276842A27953BE204A2507096F09B1F3, 9D614C5D3BB679CCF15CA6DD044318692EA6D89B89D80D690E79A1C0B941430F ] xusb21 C:\Windows\system32\DRIVERS\xusb21.sys 18:42:34.0480 0x1660 xusb21 - ok 18:42:34.0496 0x1660 ================ Scan global =============================== 18:42:34.0527 0x1660 [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll 18:42:34.0574 0x1660 [ A83DD77AC941A8B1B2652035EA589149, 8F879178E154B3F9F367FB3D6F9A21B129F36796CD3B6A76A9E7CFDD0F63332C ] C:\Windows\system32\winsrv.dll 18:42:34.0605 0x1660 [ A83DD77AC941A8B1B2652035EA589149, 8F879178E154B3F9F367FB3D6F9A21B129F36796CD3B6A76A9E7CFDD0F63332C ] C:\Windows\system32\winsrv.dll 18:42:34.0652 0x1660 [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll 18:42:34.0730 0x1660 [ 0780A42DBD7D9969F9BF4A19AA4285B5, 8EA41124A4E97732C5DAA616457FBA7111CB38986F3427FA776ED00BC1407171 ] C:\Windows\system32\services.exe 18:42:34.0745 0x1660 [ Global ] - ok 18:42:34.0745 0x1660 ================ Scan MBR ================================== 18:42:34.0792 0x1660 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 18:42:35.0260 0x1660 \Device\Harddisk0\DR0 - ok 18:42:35.0276 0x1660 ================ Scan VBR ================================== 18:42:35.0291 0x1660 [ 7A3388CB4D4AAE2DD24DDA39A2823EDC ] \Device\Harddisk0\DR0\Partition1 18:42:35.0291 0x1660 \Device\Harddisk0\DR0\Partition1 - ok 18:42:35.0307 0x1660 [ 4E4ADE1435B8BE61F1DA11B42E6C1469 ] \Device\Harddisk0\DR0\Partition2 18:42:35.0307 0x1660 \Device\Harddisk0\DR0\Partition2 - ok 18:42:35.0307 0x1660 ================ Scan generic autorun ====================== 18:42:35.0447 0x1660 [ 2B39854B1C718BCF918467F6DB175A1A, 4CC16211CB04A398EF6D6205B6C9E25C9C8C5221FBA7BC545D6ED10A245BEF5C ] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 18:42:35.0510 0x1660 SynTPEnh - ok 18:42:35.0541 0x1660 [ 5AEBF6FA9805C9101220AA4FB4FA17E7, A9B2FC41380211A6C44E839A95676A5BA868CEEBB56D83A780230434C2A20836 ] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe 18:42:35.0557 0x1660 HControlUser - ok 18:42:35.0837 0x1660 [ 32F43BE36AAC4E10C88EC24B34770C0D, 068DA52F6AE5676E238CB7FE4A7DF14757B8406BFB58EC157150193877F300C9 ] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe 18:42:36.0040 0x1660 ATKOSD2 - ok 18:42:36.0103 0x1660 [ 5666955DC9FD455A003D86A21E0483A9, 359E2B5857269EDCE395D6171642EAC8B23170AA5266932B2BAE1E5955E8FE77 ] C:\Program Files\ASUS\ATK Media\DMedia.exe 18:42:36.0118 0x1660 ATKMEDIA - ok 18:42:36.0149 0x1660 [ 3ECCDD3FE310DD8F82D085447089ADB0, A7789451C4340DB7BDA251561CE9A9CF452625FABE8BF2CE355C87214BDC485D ] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe 18:42:36.0165 0x1660 ADSMTray - ok 18:42:36.0259 0x1660 [ A6ABD4AF02AB03676DEA55F383ABC7C2, 62F838618C78A297D970EC58F97F2D843EBFEF2D81754D658664BEEED79BFB50 ] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe 18:42:36.0274 0x1660 avgnt - ok 18:42:36.0399 0x1660 [ 46E3C93237EB423BE7315470955C24A6, A1C342E8B448448FC490422E1AC06C5E3C93A43580B833397A963F1E1222913A ] D:\Gaming Maus\DareUMonitor.exe 18:42:36.0446 0x1660 Dare-U mouse - detected UnsignedFile.Multi.Generic ( 1 ) 18:42:38.0973 0x1660 Dare-U mouse ( UnsignedFile.Multi.Generic ) - warning 18:42:41.0547 0x1660 [ 82F68EBA0FCEA46BA8919D6A264A833E, 093140F47B047134D36A1D195BC01AA1A17B4B0215C7617A3FF846BC405651E6 ] C:\Program Files\Epson Software\Event Manager\EEventManager.exe 18:42:41.0594 0x1660 EEventManager - ok 18:42:41.0672 0x1660 [ 43B5696A844FB705D1E9595E8C3351B6, CF23A783D19F13287A23245B797DED0E993B6F44C2ADBE76685998BF22571C5E ] C:\Program Files\Avira\Launcher\Avira.Systray.exe 18:42:41.0687 0x1660 Avira Systray - ok 18:42:41.0781 0x1660 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe 18:42:41.0875 0x1660 Sidebar - ok 18:42:41.0906 0x1660 [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe 18:42:41.0937 0x1660 mctadmin - ok 18:42:41.0999 0x1660 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe 18:42:42.0046 0x1660 Sidebar - ok 18:42:42.0062 0x1660 [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe 18:42:42.0093 0x1660 mctadmin - ok 18:42:42.0124 0x1660 [ A7DC47DBBE3C0384BA719DC4188AFA7E, FCC8F68A8E55AE2AB9B877A6E46DFC28411B68D09AEACA4792625B5150EFDCFD ] C:\Windows\ehome\ehTray.exe 18:42:42.0171 0x1660 ehTray.exe - ok 18:42:42.0249 0x1660 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\sidebar.exe 18:42:42.0296 0x1660 Sidebar - ok 18:42:42.0514 0x1660 [ 683C9DF0582D8EEFAA90CE1514019BC1, 62C875888029BF32C19656B13C5504016209E4553B0B93FAE21F3930149EE9CA ] D:\DT\DAEMON Tools Lite\DTLite.exe 18:42:42.0717 0x1660 DAEMON Tools Lite - ok 18:42:42.0795 0x1660 Skype - ok 18:42:42.0873 0x1660 [ FB9F9392B3D24012D22CDA7F9FF17C18, E66EAA28153AE96CCFA3F8EC4AE8F0A798724C7CE46410A986C7869F7DEFA37B ] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE 18:42:42.0904 0x1660 EPLTarget\P0000000000000000 - ok 18:42:43.0045 0x1660 [ 7C6D524C78A1722AD987B9E47AC1FEE2, FFDC6C92ABB547D0DCD2621EC423C755A78079B061A41FA1751A56799D1A79A5 ] C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe 18:42:43.0123 0x1660 Dropbox Update - ok 18:42:43.0216 0x1660 [ 5F51CC2A6061597BB53A408E98CE2318, 48D4BDAFC289E640779A78AF8E5DB686D712A5CB23492713A2A5B29A762123B5 ] C:\Windows\system32\Macromed\Flash\FlashUtil32_17_0_0_188_Plugin.exe 18:42:43.0263 0x1660 FlashPlayerUpdate - ok 18:42:43.0341 0x1660 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\sidebar.exe 18:42:43.0388 0x1660 Sidebar - ok 18:42:43.0466 0x1660 GoogleDriveSync - ok 18:42:43.0528 0x1660 [ FB9F9392B3D24012D22CDA7F9FF17C18, E66EAA28153AE96CCFA3F8EC4AE8F0A798724C7CE46410A986C7869F7DEFA37B ] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE 18:42:43.0544 0x1660 EPLTarget\P0000000000000001 - ok 18:42:43.0606 0x1660 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\sidebar.exe 18:42:43.0669 0x1660 Sidebar - ok 18:42:43.0669 0x1660 Skype - ok 18:42:43.0887 0x1660 [ D270652063855034758D65001715BDEE, 0EBF559AE8D6B54E4AC035042783D1FA30624F222D0F1E717C724845A082F2CE ] C:\Program Files\Origin\Origin.exe 18:42:44.0059 0x1660 EADM - ok 18:42:44.0355 0x1660 [ EE526B0428581B57FFC571FF57309E28, 1CF4DD251E78F2B67C4B1973E3378D6B87C5698EEC398CA4043621842ACC426C ] C:\Program Files\CCleaner\CCleaner.exe 18:42:44.0636 0x1660 CCleaner Monitoring - ok 18:42:44.0714 0x1660 [ FB9F9392B3D24012D22CDA7F9FF17C18, E66EAA28153AE96CCFA3F8EC4AE8F0A798724C7CE46410A986C7869F7DEFA37B ] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE 18:42:44.0729 0x1660 EPLTarget\P0000000000000000 - ok 18:42:44.0776 0x1660 [ FB9F9392B3D24012D22CDA7F9FF17C18, E66EAA28153AE96CCFA3F8EC4AE8F0A798724C7CE46410A986C7869F7DEFA37B ] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE 18:42:44.0792 0x1660 EPLTarget\P0000000000000001 - ok 18:42:44.0870 0x1660 [ A90E7D7A92712062F64D770636DA148E, F9EAE06EFFF0EBC1CC3073C0B72EC6177F1E1737979FC3206E02817A0CF0F359 ] C:\Program Files\Common Files\Apple\Internet Services\iCloud.exe 18:42:44.0963 0x1660 iCloud - ok 18:42:45.0041 0x1660 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\sidebar.exe 18:42:45.0104 0x1660 Sidebar - ok 18:42:45.0166 0x1660 [ FB9F9392B3D24012D22CDA7F9FF17C18, E66EAA28153AE96CCFA3F8EC4AE8F0A798724C7CE46410A986C7869F7DEFA37B ] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE 18:42:45.0182 0x1660 EPLTarget\P0000000000000000 - ok 18:42:45.0244 0x1660 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\sidebar.exe 18:42:45.0291 0x1660 Sidebar - ok 18:42:45.0291 0x1660 Waiting for KSN requests completion. In queue: 23 18:42:46.0305 0x1660 Waiting for KSN requests completion. In queue: 23 18:42:47.0319 0x1660 Waiting for KSN requests completion. In queue: 23 18:42:48.0333 0x1660 AV detected via SS2: Avira Antivirus, C:\Program Files\Avira\AntiVir Desktop\wsctool.exe ( 15.0.11.550 ), 0x41000 ( enabled : updated ) 18:42:48.0349 0x1660 Win FW state via NFP2: enabled 18:42:50.0751 0x1660 ============================================================ 18:42:50.0751 0x1660 Scan finished 18:42:50.0751 0x1660 ============================================================ 18:42:50.0751 0x07c0 Detected object count: 1 18:42:50.0751 0x07c0 Actual detected object count: 1 18:43:38.0581 0x07c0 Dare-U mouse ( UnsignedFile.Multi.Generic ) - skipped by user 18:43:38.0581 0x07c0 Dare-U mouse ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:43:49.0516 0x08b0 Deinitialize success LG flowerwithlo Geändert von flowerwithlo (16.06.2015 um 18:00 Uhr) |
17.06.2015, 15:56 | #8 |
/// the machine /// TB-Ausbilder | DHL Spam Mail -> Trojaner/Virus? Die Fehlermeldung ist vom programm-eigenen Uninstaller, ncht von Revo Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.06.2015, 17:39 | #9 |
| DHL Spam Mail -> Trojaner/Virus? Habe den Scan nun erstellt. Nach der Combofix Installation bin ich aus dem Zimmer gelaufen, bin erst wiedergekommen als ich mich anmelden musste. Hoffe Combofix hat keinen Mist gemacht . Bemerkt habe ich bis jetzt, dass ich Avira nicht mehr starten kann. Avira Antivirus läuft zwar, und zeigt auch den Echtzeit Scanner als "an" an, jedoch erscheint das Avira Symbol nicht mehr in der Taskleiste. Auch nachdem ich den Computer nochmals neu gestartet habe. Combofix Log: Code:
ATTFilter ComboFix 15-06-09.01 - Philipp 17.06.2015 17:34:56.1.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3071.1952 [GMT 2:00] ausgeführt von:: c:\users\Philipp\Desktop\ComboFix.exe AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Common Files\ASPG_icon.ico c:\programdata\1&1 c:\programdata\1&1\1&1 SmartFax\Settings.xml c:\users\Jeffel\AppData\Roaming\1&1 c:\users\Jeffel\AppData\Roaming\1&1\1&1 SmartFax\FaxNumberHistory.xml c:\users\Jeffel\AppData\Roaming\1&1\1&1 SmartFax\Settings.xml c:\users\Philipp\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll c:\users\Philipp\AppData\Roaming\FTBLauncherLog.txt c:\windows\IsUn0407.exe c:\windows\msvcr71.dll c:\windows\system32\drivers\etc\hosts.ics c:\windows\system32\regobj.dll c:\windows\unin0407.exe c:\windows\wininit.ini C:\WindowsLive_A.TXT D:\install.exe . . ((((((((((((((((((((((( Dateien erstellt von 2015-05-17 bis 2015-06-17 )))))))))))))))))))))))))))))) . . 2015-06-17 16:07 . 2015-06-17 16:07 -------- d-----w- c:\users\Manuel\AppData\Local\temp 2015-06-17 16:07 . 2015-06-17 16:07 -------- d-----w- c:\users\Jeffel\AppData\Local\temp 2015-06-17 16:06 . 2015-06-17 16:06 -------- d-----w- c:\users\Ellen & Manuel\AppData\Local\temp 2015-06-17 16:06 . 2015-06-17 16:06 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-06-17 16:06 . 2015-06-17 16:06 -------- d-----w- c:\users\Beamer\AppData\Local\temp 2015-06-17 16:06 . 2015-06-17 16:17 -------- d-----w- c:\users\Philipp\AppData\Local\temp 2015-06-17 15:39 . 2015-06-17 15:39 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B69205F-8817-4463-ADEC-86BE97B0A312}\offreg.5440.dll 2015-06-17 11:43 . 2015-06-17 11:43 -------- d-----w- c:\users\Philipp\AppData\Local\Dropbox 2015-06-16 15:06 . 2015-06-16 15:06 -------- d-----w- c:\programdata\Malwarebytes 2015-06-16 15:05 . 2015-06-16 16:36 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable) 2015-06-16 15:05 . 2015-06-16 15:05 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2015-06-16 15:04 . 2015-06-16 15:04 92888 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2015-06-16 11:25 . 2015-05-03 03:42 9265072 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B69205F-8817-4463-ADEC-86BE97B0A312}\mpengine.dll 2015-06-15 16:32 . 2015-06-15 16:48 -------- d-----w- C:\FRST 2015-06-13 12:18 . 2015-06-13 12:18 -------- d-----w- c:\users\Jeffel\AppData\Local\Dropbox 2015-06-13 12:18 . 2015-06-13 12:18 -------- d-----w- c:\programdata\Dropbox 2015-06-10 08:08 . 2015-05-25 18:01 853504 ----a-w- c:\windows\system32\diagtrack.dll 2015-06-09 15:20 . 2015-06-09 15:21 -------- d-----w- c:\program files\BlueStacks 2015-06-09 15:20 . 2015-06-09 15:20 -------- d-----w- c:\programdata\BlueStacks 2015-06-09 13:44 . 2015-05-09 03:14 92672 ----a-w- c:\windows\system32\wudriver.dll 2015-06-09 13:44 . 2015-05-09 03:14 35840 ----a-w- c:\windows\system32\wups2.dll 2015-06-09 13:44 . 2015-05-09 03:14 30208 ----a-w- c:\windows\system32\wups.dll 2015-06-09 13:44 . 2015-05-09 03:14 2937344 ----a-w- c:\windows\system32\wucltux.dll 2015-06-09 13:44 . 2015-05-09 03:14 2045952 ----a-w- c:\windows\system32\wuaueng.dll 2015-06-09 13:44 . 2015-05-09 03:14 173056 ----a-w- c:\windows\system32\wuwebv.dll 2015-06-09 13:44 . 2015-05-09 03:14 566784 ----a-w- c:\windows\system32\wuapi.dll 2015-06-09 13:44 . 2015-05-09 03:13 69632 ----a-w- c:\windows\system32\WinSetupUI.dll 2015-06-09 13:44 . 2015-05-09 03:13 11776 ----a-w- c:\windows\system32\wu.upgrade.ps.dll 2015-06-09 13:44 . 2015-05-09 03:13 33792 ----a-w- c:\windows\system32\wuapp.exe 2015-06-09 13:44 . 2015-05-09 03:13 131584 ----a-w- c:\windows\system32\wuauclt.exe 2015-06-06 16:11 . 2015-06-06 16:11 -------- d-----w- c:\users\Beamer\AppData\Local\GWX 2015-06-03 16:24 . 2015-06-03 16:24 -------- d-----w- c:\users\Manuel\AppData\Local\GWX 2015-06-01 18:38 . 2015-06-01 18:38 -------- d-----w- c:\users\Jeffel\AppData\Local\GWX 2015-06-01 17:02 . 2015-06-01 17:02 -------- d-----w- c:\users\Ellen & Manuel\AppData\Local\GWX 2015-06-01 16:03 . 2015-06-01 16:03 -------- d-----w- c:\users\Philipp\AppData\Local\GWX 2015-05-31 13:23 . 2015-05-31 13:43 -------- d-----w- c:\users\Philipp\AppData\Roaming\Dual Monitor 2015-05-22 17:16 . 2015-05-22 17:16 18652352 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE14\MSO.DLL 2015-05-20 15:18 . 2015-04-11 03:07 54656 ----a-w- c:\windows\system32\drivers\stream.sys 2015-05-20 15:18 . 2015-03-14 03:04 67584 ----a-w- c:\windows\system32\dwmapi.dll 2015-05-20 15:18 . 2015-03-14 03:04 1372160 ----a-w- c:\windows\system32\dwmcore.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-06-11 10:09 . 2012-11-02 18:40 136728 ----a-w- c:\windows\system32\drivers\avipbb.sys 2015-06-11 10:09 . 2012-11-02 18:40 108448 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2015-06-10 15:19 . 2012-04-04 20:24 778416 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2015-06-10 15:19 . 2011-06-10 17:15 142512 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2015-05-30 20:11 . 2009-11-24 18:19 45056 ----a-w- c:\windows\system32\acovcnt.exe 2015-05-20 18:24 . 2012-11-02 18:40 37896 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2015-05-01 13:16 . 2015-05-14 12:20 102608 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-04-20 02:56 . 2015-05-13 20:35 909312 ----a-w- c:\windows\system32\FntCache.dll 2015-04-20 02:56 . 2015-05-13 20:35 1250816 ----a-w- c:\windows\system32\DWrite.dll 2015-04-18 02:56 . 2015-05-13 20:34 342016 ----a-w- c:\windows\system32\certcli.dll 2015-04-14 01:38 . 2015-04-14 01:38 1217192 ----a-w- c:\windows\system32\FM20.DLL 2015-04-13 03:19 . 2015-05-13 20:34 259072 ----a-w- c:\windows\system32\services.exe 2015-04-08 03:14 . 2015-05-13 20:33 22528 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\jnwppr.dll 2015-04-08 03:14 . 2015-05-13 20:33 216064 ----a-w- c:\windows\system32\InkEd.dll 2015-04-08 03:14 . 2015-05-13 20:33 19968 ----a-w- c:\windows\system32\jnwmon.dll 2015-04-02 10:25 . 2015-04-02 10:25 0 ----a-w- c:\windows\system32\RENA5C2.tmp 2015-04-02 10:25 . 2015-04-02 10:25 0 ----a-w- c:\windows\system32\RENA5C1.tmp 2009-04-08 09:31 . 2009-04-08 09:31 106496 ----a-w- c:\program files\Common Files\CPInstallAction.dll 2008-08-11 20:45 . 2008-08-11 20:45 155648 ----a-w- c:\program files\Common Files\MSIactionall.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-01 16:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}] 2015-05-19 13:22 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}] 2015-05-19 13:22 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}] 2015-05-19 13:22 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}] 2015-05-19 13:22 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}] 2015-05-19 13:22 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] "GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2015-05-19 21969480] "EPLTarget\P0000000000000001"="c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE" [2013-01-24 260160] "Dropbox Update"="c:\users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe" [2015-06-17 134512] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-08-17 1549608] "HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "ATKOSD2"="c:\program files\ASUS\ATKOSD2\ATKOSD2.exe" [2009-08-17 6859392] "ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2009-08-19 170624] "ADSMTray"="c:\program files\ASUS\ASUS Data Security Manager\ADSMTray.exe" [2009-06-24 272952] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2015-06-11 730416] "Dare-U mouse"="d:\gaming maus\DareUMonitor.exe" [2012-11-19 786432] "EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2014-05-02 1065024] "Avira Systray"="c:\program files\Avira\Launcher\Avira.Systray.exe" [2015-05-21 130864] . c:\users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2015-5-5 43871584] OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2013-6-25 228552] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli c:\program files\ASUS\ASUS Data Security Manager\ASPWDFLT . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk backup=c:\windows\pss\FancyStart daemon.lnk.CommonStartup backupExtension=.CommonStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2014-12-19 07:48 1022152 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount] 2009-09-30 16:28 203928 ----a-w- d:\alcohol 120\AxCmd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmIcoSinglun] 2009-07-31 09:10 233472 ----a-w- c:\program files\AmIcoSingLun\AmIcoSinglun.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2015-03-20 16:12 60712 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver] 2009-08-19 03:15 47672 ----a-w- c:\windows\AsScrProlog.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector] 2009-08-19 03:15 33136 ----a-w- c:\windows\ASScrPro.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSTPE] 2007-10-12 04:44 106496 ----a-w- c:\windows\System32\ASUSTPE.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVMUSBFernanschluss] 2014-09-29 14:48 139264 ----a-w- c:\users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\AVMAutoStart.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent] 2015-05-28 08:59 884440 ----a-w- c:\program files\BlueStacks\HD-Agent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter] 2009-07-27 02:10 1983816 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu] 2009-03-18 01:40 767312 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring] 2015-05-08 19:49 6369048 ----a-w- c:\program files\CCleaner\CCleaner.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer] 2008-07-19 02:52 104936 ----a-w- c:\program files\CyberLink\Power2Go\CLMLSvc.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite] 2013-10-28 08:29 3675352 ----a-w- d:\dt\DAEMON Tools Lite\DTLite.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2015-04-06 22:29 157480 ----a-w- c:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent] 2015-02-24 16:31 311616 ----a-w- d:\samsung kies\Kies\KiesTrayAgent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2014-10-02 13:23 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2015-01-23 13:40 31087200 ----a-r- c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] 2015-06-04 18:56 2892992 ----a-w- d:\steam\Steam.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2013-07-02 07:16 254336 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut] 2009-05-20 05:16 222504 ----a-w- c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut] 2008-12-04 05:15 218408 ----a-w- c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat] 2009-09-30 16:57 718688 ----a-w- c:\program files\Microsoft Xbox 360 Accessories\XBoxStat.exe . R2 AntiVirMailService;Avira Email-Schutz;c:\program files\Avira\AntiVir Desktop\avmailc7.exe [2015-06-11 827184] R2 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\avwebg7.exe [2015-06-11 1188360] R2 Avira.ServiceHost;Avira Service Host;c:\program files\Avira\Launcher\Avira.ServiceHost.exe [2015-05-21 208632] R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2009-07-24 25600] R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2014-10-13 32064] R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x] R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2014-10-13 136904] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2014-10-13 17864] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2014-10-13 153672] R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2014-10-13 130248] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152] R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-07-14 20480] R4 BstHdAndroidSvc;BlueStacks Android Service;c:\program files\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x] R4 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files\BlueStacks\HD-LogRotatorService.exe [2015-05-28 413400] R4 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files\BlueStacks\HD-UpdaterService.exe [2015-05-28 806616] R4 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc.exe [2012-05-16 126128] R4 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2011-04-26 2702848] R4 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-05-23 102912] R4 MDES;DVM Meta Data Export Service;c:\asus.sys\DVMExportService.exe [2008-10-21 307200] R4 MyPublicWiFiService;MyPublicWiFi Service;c:\program files\MyPublicWiFi\PublicWiFiService.exe [2013-04-03 756224] R4 Origin Client Service;Origin Client Service;c:\program files\Origin\OriginClientService.exe [2015-06-08 1997168] R4 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2015-01-02 315488] R4 ss_conn_service;SAMSUNG Mobile Connectivity Service;d:\samsung kies\USB Drivers\25_escape\conn\ss_conn_service.exe [2014-10-13 743688] S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [2009-06-18 15416] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2015-05-20 37896] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-11-21 243128] S1 ndiskhaz;Azzouzi HotSpot LightWeight Filter;c:\windows\system32\DRIVERS\ndiskhaz.sys [2012-12-07 25416] S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2013-11-01 203024] S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2013-11-01 103696] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128] S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2015-06-11 450808] S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys [2015-03-11 37896] S2 BstHdDrv;BlueStacks Hypervisor;c:\program files\BlueStacks\HD-Hypervisor-x86.sys [2015-05-28 131288] S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992] S2 EPSON_PM_RPCV4_06;EPSON V3 Service4(06);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE [2013-04-26 143424] S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [2012-01-23 1858048] S3 avmaudio;AVM Audio;c:\windows\system32\DRIVERS\avmaudio.sys [2014-09-29 105728] S3 avmaura;AVM USB-Fernanschluss;c:\windows\system32\DRIVERS\avmaura.sys [2014-09-29 105728] S3 SiSGbeLH;NDIS 6.0-Treiber für SiS191/SiS190-Ethernet-Gerät;c:\windows\system32\DRIVERS\SiSGB6.sys [2009-07-13 48128] S3 stdriver;Sound Tap Upper Class Filter Driver v2.0.0.0;c:\windows\system32\DRIVERS\stdriver32.sys [2012-06-21 52312] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] utcsvc REG_MULTI_SZ DiagTrack . Inhalt des "geplante Tasks" Ordners . 2015-06-17 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 15:19] . 2015-06-17 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job - c:\users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13 12:18] . 2015-06-17 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job - c:\users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13 12:18] . 2015-06-17 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004Core.job - c:\users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17 11:43] . 2015-06-17 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004UA.job - c:\users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17 11:43] . 2015-06-17 c:\windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job - c:\windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE [2014-11-29 00:20] . 2015-06-17 c:\windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job - c:\windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE [2014-11-29 00:20] . 2015-06-17 c:\windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job - c:\windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE [2014-12-10 00:20] . 2015-06-17 c:\windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job - c:\windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE [2014-12-10 00:20] . 2015-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 11:30] . 2015-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 11:30] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://de.yahoo.com/ mStart Page = about:blank IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: An OneNote s&enden - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.177.1 FF - ProfilePath - c:\users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\ FF - prefs.js: browser.search.selectedEngine - Google.de FF - prefs.js: browser.startup.homepage - hxxp://de.yahoo.com/|https://www.google.de/ FF - prefs.js: network.proxy.type - 0 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file) Toolbar-Locked - (no file) ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll AddRemove-LEGOLANDDeInstKey - c:\windows\unin0407.exe AddRemove-01_Simmental - d:\samsung kies\USB Drivers\01_Simmental\Uninstall.exe AddRemove-02_Siberian - d:\samsung kies\USB Drivers\02_Siberian\Uninstall.exe AddRemove-03_Swallowtail - d:\samsung kies\USB Drivers\03_Swallowtail\Uninstall.exe AddRemove-04_semseyite - d:\samsung kies\USB Drivers\04_semseyite\Uninstall.exe AddRemove-07_Schorl - d:\samsung kies\USB Drivers\07_Schorl\Uninstall.exe AddRemove-09_Hsp - d:\samsung kies\USB Drivers\09_Hsp\Uninstall.exe AddRemove-11_HSP_Plus_Default - d:\samsung kies\USB Drivers\11_HSP_Plus_Default\Uninstall.exe AddRemove-16_Shrewsbury - d:\samsung kies\USB Drivers\16_Shrewsbury\Uninstall.exe AddRemove-20_NXP_Driver - d:\samsung kies\USB Drivers\20_NXP_Driver\Uninstall.exe AddRemove-24_flashusbdriver - d:\samsung kies\USB Drivers\24_flashusbdriver\Uninstall.exe AddRemove-25_escape - d:\samsung kies\USB Drivers\25_escape\Uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-644356114-2566177158-2502637254-1004\Software\SecuROM\License information*] "datasecu"=hex:03,39,7c,03,77,2a,6a,cb,7e,17,02,c7,3a,42,fe,ce,dc,40,15,de,35, ab,79,43,ba,02,aa,15,80,ba,2a,33,01,95,3f,3a,8b,27,3b,9b,dd,f0,a6,c3,79,8a,\ "rkeysecu"=hex:a8,7c,1b,9c,ec,b6,9d,c9,8e,91,03,ed,5f,af,3a,d3 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- . - - - - - - - > 'lsass.exe'(544) c:\program files\ASUS\ASUS Data Security Manager\ASPWDFLT.DLL . - - - - - - - > 'Explorer.exe'(3284) c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files\ASUS\ASUS Data Security Manager\ADSMSrv.exe c:\program files\ASUS\ATK Hotkey\ASLDRSrv.exe c:\windows\system32\atieclxx.exe c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Avira\AntiVir Desktop\avshadow.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\system32\taskhost.exe c:\program files\ASUS\Net4Switch\Net4Switch.exe c:\program files\ASUS\ASUS CopyProtect\aspg.exe c:\program files\ASUS\SmartLogon\sensorsrv.exe c:\program files\ASUS\Splendid\ACMON.exe c:\program files\Google\Update\1.3.27.5\GoogleCrashHandler.exe c:\windows\system32\conhost.exe c:\windows\System32\ACEngSvr.exe c:\program files\P4G\BatteryLife.exe c:\program files\Wireless Console 2\wcourier.exe c:\program files\ASUS\ATK Hotkey\HControl.exe c:\program files\ASUS\ATK Hotkey\ATKOSD.exe c:\program files\ASUS\ATK Hotkey\KBFiltr.exe c:\program files\ASUS\ATK Hotkey\WDC.exe c:\windows\system32\GWX\GWX.exe c:\windows\system32\DllHost.exe . ************************************************************************** . Zeit der Fertigstellung: 2015-06-17 18:24:21 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2015-06-17 16:24 . Vor Suchlauf: 10 Verzeichnis(se), 35.480.268.800 Bytes frei Nach Suchlauf: 23 Verzeichnis(se), 37.120.774.144 Bytes frei . - - End Of File - - FE4746EC14087E6A1E13A359DC829F17 A36C5E4F47E84449FF07ED3517B43A31 |
18.06.2015, 06:50 | #10 |
/// the machine /// TB-Ausbilder | DHL Spam Mail -> Trojaner/Virus? Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.06.2015, 19:08 | #11 |
| DHL Spam Mail -> Trojaner/Virus? Hallo Schrauber, MBAM: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 19.06.2015 Suchlauf-Zeit: 19:14:40 Logdatei: Log Malwarebytes.txt Administrator: Ja Version: 0.00.0.0000 Malware Datenbank: v2015.06.19.04 Rootkit Datenbank: v2015.06.15.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: Philipp Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 546619 Verstrichene Zeit: 58 Min, 19 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente gefunden) Module: 0 (Keine schädliche Elemente gefunden) Registrierungsschlüssel: 0 (Keine schädliche Elemente gefunden) Registrierungswerte: 0 (Keine schädliche Elemente gefunden) Registrierungsdaten: 0 (Keine schädliche Elemente gefunden) Ordner: 0 (Keine schädliche Elemente gefunden) Dateien: 0 (Keine schädliche Elemente gefunden) Physische Sektoren: 0 (Keine schädliche Elemente gefunden) (end) AdwCleaner: Code:
ATTFilter # AdwCleaner v4.206 - Bericht erstellt 19/06/2015 um 19:45:18 # Aktualisiert 01/06/2015 von Xplode # Datenbank : 2015-06-17.1 [Server] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (x86) # Benutzername : Philipp - SCHEFFLER-PC # Gestarted von : C:\Users\Philipp\Desktop\AdwCleaner_4.206.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Ask Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\PC Drivers HeadQuarters Ordner Gelöscht : C:\Users\Beamer\AppData\LocalLow\AskToolbar Ordner Gelöscht : C:\Users\Jeffel\AppData\Local\PC_Drivers_Headquarters Ordner Gelöscht : C:\Users\Jeffel\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\Jeffel\AppData\Roaming\download Manager Ordner Gelöscht : C:\Users\Philipp\AppData\Local\AskToolbar Ordner Gelöscht : C:\Users\Philipp\AppData\Roaming\KingSoft Datei Gelöscht : C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\foxydeal.sqlite Datei Gelöscht : C:\Users\Jeffel\AppData\Roaming\Mozilla\Firefox\Profiles\bv31z8w8.default\user.js Datei Gelöscht : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SDP Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\VIS Schlüssel Gelöscht : HKLM\SOFTWARE\Babylon Schlüssel Gelöscht : HKLM\SOFTWARE\DeviceVM Schlüssel Gelöscht : HKLM\SOFTWARE\PIP Schlüssel Gelöscht : HKU\.DEFAULT\Software\IBUpdaterService Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494 ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17840 -\\ Mozilla Firefox v38.0.5 (x86 de) [5tcpn7ab.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.hiddenOneOffs", "Ask.com,DuckDuckGo,LEO Eng-Deu"); [5tcpn7ab.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.order.1", "Ask.com"); [5tcpn7ab.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "Ask.com"); [5tcpn7ab.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", ""); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("avg.install.userHPSettings", "hxxp://www.delta-search.com/?affID=119649&babsrc=HP_ss&mntrId=9a1a16840000000000002225d303ecbc"); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("avg.install.userSPSettings", "Delta Search"); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("avira.safe_search.installed", "[\"safesearch\"]"); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("avira.safe_search.prev_newtab", "hxxps://safesearch.avira.com/#?source=newtab"); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "hxxps://safesearch.avira.com/#?source=newtab"); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaultenginename", "Avira SafeSearch"); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-page-button\",\"print-but[...] [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://www.delta-search.com/?affID=119649&babsrc=NT_ss&mntrId=9a1a16840000000000002225d303ecbc"); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.safesearch.MP_DISTINCT_ID", "\"14a54c9896557-08217389fecf2e-7f6a1335-0-14a54c98966ee\""); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.safesearch.SAUTH_expires_at", "1431286334"); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.safesearch.SAUTH_rndsnr", "\"4473ad5aadf09f2d835eb8fa336508ef604a11b2\""); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.safesearch.SAUTH_userid", "5718734357"); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.safesearch.SAUTH_utoken", "\"31d35a556c93ee7b0d2a3a8f93b8f88b0068fb23\""); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.safesearch.install", "1418761701745"); [bv31z8w8.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.xpiState", "{\"app-profile\":{\"abs@avira.com\":{\"d\":\"C:\\\\Users\\\\Jeffel\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\bv31z8w8.default\\\\extensions\\\\abs@av[...] [ynkmsd5b.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.order.1", "Ask.com"); [ynkmsd5b.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.adblockplus.recentReports", "[{\"site\":\"translation.babylon.com\",\"reportURL\":\"hxxps://reports.adblockplus.org/8eb3e8d3-8212-46f6-8486-9f24126b03b2\",\"time\":1369154259425}[...] [ynkmsd5b.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://eu.ask.com/web?l=dis&o=APN10147&gct=kwd&qsrc=2869&apn_dtid=^YYYYYY^YY^DE&apn_ptnrs=^A6E&apn_uid=1404014489394795&p2=^A6E^YYYYYY^YY^DE&q=")[...] -\\ Chromium v ************************* AdwCleaner[R0].txt - [5948 Bytes] - [19/06/2015 19:37:37] AdwCleaner[S0].txt - [6066 Bytes] - [19/06/2015 19:45:18] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6125 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 7.0.2 (06.18.2015:1) OS: Windows 7 Home Premium x86 Ran by Philipp on 19.06.2015 at 19:56:37,24 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Tasks ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Classes\TypeLib\{006ad7b2-968a-11de-88c9-5bde55d89593} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} ~~~ Files ~~~ Folders ~~~ FireFox ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 19.06.2015 at 20:00:22,07 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-06-2015 Ran by Philipp (administrator) on SCHEFFLER-PC on 19-06-2015 20:01:38 Running from C:\Users\Philipp\Desktop Loaded Profiles: Jeffel & Philipp & Beamer & Ellen & Manuel & Manuel (Available Profiles: Jeffel & Philipp & Beamer & Ellen & Manuel & Manuel) Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avcenter.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1549608 2009-08-17] (Synaptics Incorporated) HKLM\...\Run: [HControlUser] => C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM\...\Run: [ATKOSD2] => C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS) HKLM\...\Run: [ATKMEDIA] => C:\Program Files\ASUS\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS) HKLM\...\Run: [ADSMTray] => C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [272952 2009-06-24] (ASUSTek Computer Inc.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [730416 2015-06-11] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Dare-U mouse] => D:\Gaming Maus\DareUMonitor.exe [786432 2012-11-20] () HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1065024 2014-05-02] (SEIKO EPSON CORPORATION) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.Systray.exe [130864 2015-05-21] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [144384 2010-11-20] (Microsoft Corporation) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [DAEMON Tools Lite] => D:\DT\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Run: [Dropbox Update] => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-13] (Dropbox, Inc.) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil32_17_0_0_188_Plugin.exe [927920 2015-05-20] (Adobe Systems Incorporated) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\MountPoints2: {7ed2759d-f168-11de-961b-806e6f6e6963} - E:\NightRacer.EXE HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [21969480 2015-05-19] (Google) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Run: [Dropbox Update] => C:\Users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-17] (Dropbox, Inc.) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [EADM] => C:\Program Files\Origin\Origin.exe [3632472 2015-06-08] (Electronic Arts) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILFE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\RunOnce: [iCloud] => C:\Program Files\Common Files\Apple\Internet Services\iCloud.exe [43816 2015-04-26] (Apple Inc.) HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe HKU\S-1-5-21-644356114-2566177158-2502637254-1008\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATILEE.EXE [260160 2013-01-24] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-644356114-2566177158-2502637254-1008\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe HKU\S-1-5-21-644356114-2566177158-2502637254-1008\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation) HKU\S-1-5-21-644356114-2566177158-2502637254-1011\...\MountPoints2: {1574b094-52d4-11e3-a17e-002618f9ca5d} - F:\Autorun.exe HKU\S-1-5-21-644356114-2566177158-2502637254-1011\...\MountPoints2: {7ed2759d-f168-11de-961b-806e6f6e6963} - E:\NightRacer.EXE Lsa: [Notification Packages] scecli C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT Startup: C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-05-12] ShortcutTarget: Dropbox.lnk -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2011-03-30] ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-12-13] ShortcutTarget: Dropbox.lnk -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2011-03-31] ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ShellIconOverlayIdentifiers: [ADSMOverlayIcon] -> {A825576B-0042-4F0F-8FB0-93CE0F054E69} => C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll [2007-06-15] () ShellIconOverlayIdentifiers: [ADSMOverlayIcon1] -> {A8D448F4-0431-45AC-9F5E-E1B434AB2249} => C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll [2007-06-01] () ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-05-19] (Google) GroupPolicyUsers\S-1-5-21-644356114-2566177158-2502637254-1011\User: Group Policy Restriction detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-644356114-2566177158-2502637254-1004\User: Group Policy Restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-644356114-2566177158-2502637254-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.de/ HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/ HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com/ HKU\S-1-5-21-644356114-2566177158-2502637254-1005\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs HKU\S-1-5-21-644356114-2566177158-2502637254-1005\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com HKU\S-1-5-21-644356114-2566177158-2502637254-1008\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp URLSearchHook: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File URLSearchHook: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=IEFM1&q={searchTerms}&src={referrer:source?} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=IEFM1&q={searchTerms}&src={referrer:source?} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_de SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1008 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKU\S-1-5-21-644356114-2566177158-2502637254-1011 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File BHO: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH) Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1004 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKU\S-1-5-21-644356114-2566177158-2502637254-1005 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation) Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.177.1 FireFox: ======== FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default FF DefaultSearchEngine: Google.de FF SelectedSearchEngine: Google.de FF Homepage: hxxp://de.yahoo.com/|https://www.google.de/ FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-20] () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2009-09-07] (CANON INC.) FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-644356114-2566177158-2502637254-1004: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Philipp\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-10-03] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-644356114-2566177158-2502637254-1008: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Ellen & Manuel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-11-25] (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-02-16] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-02-16] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-02-16] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-02-16] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-02-16] (Apple Inc.) FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\ebay-durchsuchen.xml [2012-10-14] FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\firefox-add-ons.xml [2011-07-08] FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\googlede.xml [2012-05-18] FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\suche-in-wikipedia.xml [2011-07-08] FF SearchPlugin: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\searchplugins\youtube-videosuche.xml [2012-07-07] FF Extension: Avira Browser Safety - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\abs@avira.com [2015-05-30] FF Extension: LavaFox V2-Purple - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\zigboom555@aol.com [2015-05-05] FF Extension: Blue Fox - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{241aae70-0022-11de-87af-0800200c9a66} [2014-07-31] FF Extension: Bloody Red - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{2458abc0-f443-11dd-87af-0800200c9a66} [2013-08-19] FF Extension: FT DeepDark - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2015-04-22] FF Extension: Add to Amazon Wish List Button - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\amznUWL2@amazon.com.xpi [2013-09-15] FF Extension: YouTube to MP3 - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\youtube2mp3@mondayx.de.xpi [2012-01-19] FF Extension: ProxTube - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}.xpi [2014-07-31] FF Extension: AniWeather - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi [2011-07-08] FF Extension: Nuri - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{beab8ae9-eb2d-4ded-3b29-d35f6b82bfa5}.xpi [2012-12-23] FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\ynkmsd5b.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-07-31] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-06-02] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-12-13] Chrome: ======= CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.) [File not signed] S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [827184 2015-06-11] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [450808 2015-06-11] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [450808 2015-06-11] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1188360 2015-06-11] (Avira Operations GmbH & Co. KG) S2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS) S4 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed] S2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [208632 2015-05-21] (Avira Operations GmbH & Co. KG) S4 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [433880 2015-05-28] (BlueStack Systems, Inc.) S4 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [413400 2015-05-28] (BlueStack Systems, Inc.) S4 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [806616 2015-05-28] (BlueStack Systems, Inc.) S4 EpsonScanSvc; C:\Windows\system32\EscSvc.exe [126128 2012-05-17] (Seiko Epson Corporation) R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RP7.EXE [143424 2013-04-26] (SEIKO EPSON CORPORATION) S2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed] S4 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed] S4 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] () S2 MBAMScheduler; D:\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation) S2 MBAMService; D:\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) S4 MDES; C:\ASUS.SYS\DVMExportService.exe [307200 2008-10-21] (DeviceVM) [File not signed] S4 MyPublicWiFiService; C:\Program Files\MyPublicWiFi\PublicWiFiService.exe [756224 2013-04-03] () [File not signed] S4 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1997168 2015-06-08] (Electronic Arts) S4 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () S4 ss_conn_service; D:\Samsung Kies\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AmUStor; C:\Windows\System32\drivers\AmUStor.SYS [25600 2009-07-24] (Alcor Micro, Corp.) R0 AsDsm; C:\Windows\system32\Drivers\AsDsm.sys [30264 2009-12-25] (ASUSTek Computer Inc) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-06-11] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-06-11] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-20] (Avira Operations GmbH & Co. KG) R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [105728 2014-09-29] (AVM Berlin) R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [105728 2014-09-29] (AVM Berlin) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-11] (Avira Operations GmbH & Co. KG) R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [131288 2015-05-28] (BlueStack Systems) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-11-21] (Disc Soft Ltd) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] () S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( ) R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2009-06-18] (Windows (R) Win 7 DDK provider) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-06-19] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [14392 2009-05-13] (ASUS) R1 ndiskhaz; C:\Windows\System32\DRIVERS\ndiskhaz.sys [25416 2012-12-07] (Khalil Azzouzi) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1766592 2009-06-05] () R0 sptd; C:\Windows\System32\Drivers\sptd.sys [324096 2013-11-21] (Duplex Secure Ltd.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-06-11] (Avira Operations GmbH & Co. KG) R3 stdriver; C:\Windows\System32\DRIVERS\stdriver32.sys [52312 2012-06-21] (NCH Software) U3 a4o6zbuq; C:\Windows\system32\Drivers\a4o6zbuq.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder) U3 a7bz1tf0; C:\Windows\system32\Drivers\a7bz1tf0.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder) S3 ALSysIO; \??\C:\Users\Philipp\AppData\Local\Temp\ALSysIO.sys [X] U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\Philipp\AppData\Local\Temp\catchme.sys [X] S3 dgderdrv; System32\drivers\dgderdrv.sys [X] S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X] S3 ipswuio; System32\DRIVERS\ipswuio.sys [X] S3 RTHDMIAzAudService; system32\drivers\RtHDMIV.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-19 20:01 - 2015-06-19 20:03 - 00027909 _____ C:\Users\Philipp\Desktop\FRST.txt 2015-06-19 20:00 - 2015-06-19 20:00 - 00000904 _____ C:\Users\Philipp\Desktop\JRT.txt 2015-06-19 19:56 - 2015-06-19 19:56 - 00000207 _____ C:\Windows\tweaking.com-regbackup-SCHEFFLER-PC-Windows-7-Home-Premium-(32-bit).dat 2015-06-19 19:56 - 2015-06-19 19:56 - 00000000 ____D C:\RegBackup 2015-06-19 19:54 - 2015-06-19 19:55 - 02950477 _____ (Thisisu) C:\Users\Philipp\Desktop\JRT.exe 2015-06-19 19:37 - 2015-06-19 19:45 - 00000000 ____D C:\AdwCleaner 2015-06-19 19:36 - 2015-06-19 19:36 - 02231296 _____ C:\Users\Philipp\Desktop\AdwCleaner_4.206.exe 2015-06-19 16:19 - 2015-06-19 16:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-06-19 16:19 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-06-19 16:19 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-06-18 15:15 - 2015-06-18 15:15 - 00011037 _____ C:\Users\Philipp\AppData\Local\recently-used.xbel 2015-06-17 18:30 - 2015-06-19 19:50 - 00000374 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2015-06-17 18:24 - 2015-06-17 18:24 - 00028045 _____ C:\ComboFix.txt 2015-06-17 17:28 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2015-06-17 17:28 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2015-06-17 17:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-06-17 17:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-06-17 17:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-06-17 17:28 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2015-06-17 17:28 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2015-06-17 17:28 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2015-06-17 17:27 - 2015-06-17 18:24 - 00000000 ____D C:\Qoobox 2015-06-17 17:26 - 2015-06-17 18:21 - 00000000 ____D C:\Windows\erdnt 2015-06-17 17:20 - 2015-06-17 17:20 - 05628161 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe 2015-06-17 13:45 - 2015-06-17 13:45 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-06-17 13:43 - 2015-06-19 19:48 - 00001232 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004UA.job 2015-06-17 13:43 - 2015-06-19 13:48 - 00001180 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004Core.job 2015-06-17 13:43 - 2015-06-17 13:43 - 00000000 ____D C:\Users\Philipp\AppData\Local\Dropbox 2015-06-16 18:40 - 2015-06-16 18:40 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Philipp\Desktop\tdsskiller.exe 2015-06-16 17:06 - 2015-06-19 16:19 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-06-16 17:05 - 2015-06-19 19:50 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-06-16 17:05 - 2015-06-17 21:22 - 00000000 ____D C:\Users\Philipp\Desktop\Ein jdhd 2015-06-16 17:05 - 2015-06-16 18:36 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2015-06-16 17:04 - 2015-06-16 18:36 - 00000000 ____D C:\Users\Philipp\Desktop\mbar 2015-06-16 17:04 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-06-15 18:32 - 2015-06-19 20:01 - 00000000 ____D C:\FRST 2015-06-15 18:13 - 2015-06-15 18:13 - 01148416 _____ (Farbar) C:\Users\Philipp\Desktop\FRST.exe 2015-06-13 14:19 - 2015-06-13 14:19 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-06-13 14:18 - 2015-06-19 19:23 - 00001228 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job 2015-06-13 14:18 - 2015-06-19 14:23 - 00001176 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job 2015-06-13 14:18 - 2015-06-13 14:18 - 00000000 ____D C:\Users\Jeffel\AppData\Local\Dropbox 2015-06-13 14:18 - 2015-06-13 14:18 - 00000000 ____D C:\ProgramData\Dropbox 2015-06-11 20:32 - 2015-06-11 20:32 - 00131180 _____ C:\Users\Manuel\Downloads\Motorrad Profi 4 - kostenlos online spielen.htm 2015-06-11 18:41 - 2015-06-11 18:41 - 00001085 _____ C:\Users\Public\Desktop\Avira.lnk 2015-06-10 10:09 - 2015-06-02 21:35 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-06-10 10:09 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-06-10 10:09 - 2015-05-25 19:00 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-06-10 10:09 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-06-10 10:09 - 2015-05-23 05:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-06-10 10:09 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-06-10 10:09 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-06-10 10:09 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-06-10 10:09 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-06-10 10:09 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-06-10 10:09 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-06-10 10:09 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-06-10 10:09 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-06-10 10:09 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-06-10 10:09 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-06-10 10:09 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-06-10 10:09 - 2015-05-23 05:05 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-06-10 10:09 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-06-10 10:09 - 2015-05-23 05:00 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-06-10 10:09 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-06-10 10:09 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-06-10 10:09 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-06-10 10:09 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-06-10 10:09 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-06-10 10:09 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-06-10 10:09 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-06-10 10:09 - 2015-05-23 04:38 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-06-10 10:09 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-06-10 10:09 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-06-10 10:09 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-06-10 10:09 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-06-10 10:09 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-06-10 10:09 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-06-10 10:09 - 2015-05-22 20:03 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-06-10 10:09 - 2015-05-22 20:02 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-06-10 10:09 - 2015-05-22 19:58 - 00901120 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-06-10 10:09 - 2015-05-21 15:20 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-06-10 10:08 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-06-10 10:08 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-06-10 10:08 - 2015-05-25 20:07 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-06-10 10:08 - 2015-05-25 20:07 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-06-10 10:08 - 2015-05-25 20:04 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00853504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-06-10 10:08 - 2015-05-25 20:01 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-06-10 10:08 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-06-10 10:08 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe 2015-06-10 10:08 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-06-10 10:08 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-06-10 10:08 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-06-10 10:08 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-06-10 10:08 - 2015-05-25 18:53 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2015-06-10 10:08 - 2015-05-09 05:14 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-06-10 10:08 - 2015-05-09 05:13 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-06-10 10:08 - 2015-05-09 05:13 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-06-10 10:08 - 2015-05-09 05:12 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-06-10 10:08 - 2015-05-09 05:08 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 05:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 03:59 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 03:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-06-10 10:08 - 2015-05-09 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-06-10 10:08 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-06-10 10:08 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-06-10 10:08 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-06-10 10:08 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-06-10 10:08 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-06-10 10:08 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-06-09 17:20 - 2015-06-09 17:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 2015-06-09 17:20 - 2015-06-09 17:21 - 00000000 ____D C:\Program Files\BlueStacks 2015-06-09 17:20 - 2015-06-09 17:20 - 00000000 ____D C:\ProgramData\BlueStacks 2015-06-09 17:18 - 2015-06-09 17:18 - 15738056 _____ C:\Users\Philipp\Downloads\CloudMusic_official_2.7.1.apk 2015-06-09 17:18 - 2015-06-09 17:18 - 14155832 _____ (BlueStack Systems Inc.) C:\Users\Philipp\Downloads\BlueStacks-ThinInstaller.exe 2015-06-09 15:44 - 2015-05-09 05:14 - 02937344 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 02045952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-06-09 15:44 - 2015-05-09 05:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-06-09 15:44 - 2015-05-09 05:13 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-06-09 15:44 - 2015-05-09 05:13 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-06-09 15:44 - 2015-05-09 05:13 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-06-09 15:44 - 2015-05-09 05:13 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-06-06 18:11 - 2015-06-06 18:11 - 00000000 ____D C:\Users\Beamer\AppData\Local\GWX 2015-06-06 11:34 - 2015-06-07 21:06 - 00000000 ____D C:\Users\Philipp\Documents\Joerg Riesa 2015-06-04 20:15 - 2015-06-04 20:16 - 00103104 _____ C:\Users\Manuel\Downloads\Crazy Skater - kostenlos online spielen.htm 2015-06-04 19:22 - 2015-06-04 19:22 - 00002121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2015-06-03 18:24 - 2015-06-03 18:24 - 00000000 ____D C:\Users\Manuel\AppData\Local\GWX 2015-06-03 16:37 - 2015-06-03 16:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2015-06-02 15:47 - 2015-06-04 18:42 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-06-01 20:38 - 2015-06-01 20:38 - 00000000 ____D C:\Users\Jeffel\AppData\Local\GWX 2015-06-01 19:02 - 2015-06-01 19:02 - 00000000 ____D C:\Users\Ellen & Manuel\AppData\Local\GWX 2015-06-01 18:03 - 2015-06-01 18:03 - 00000000 ____D C:\Users\Philipp\AppData\Local\GWX 2015-05-31 15:23 - 2015-05-31 15:43 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dual Monitor 2015-05-31 15:23 - 2015-05-31 15:23 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dual Monitor 2015-05-20 19:51 - 2015-05-20 19:51 - 00177664 _____ C:\Users\Philipp\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-20 17:18 - 2015-04-11 05:07 - 00054656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys 2015-05-20 17:18 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-05-20 17:18 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-19 19:57 - 2009-12-25 17:20 - 00019456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-06-19 19:57 - 2009-12-25 17:20 - 00019456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-06-19 19:56 - 2015-05-17 19:56 - 00000917 _____ C:\Windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job 2015-06-19 19:56 - 2015-05-17 19:56 - 00000731 _____ C:\Windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job 2015-06-19 19:56 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\system32\FxsTmp 2015-06-19 19:54 - 2009-12-25 18:22 - 01544651 _____ C:\Windows\WindowsUpdate.log 2015-06-19 19:50 - 2012-12-17 20:34 - 00000000 ___RD C:\Users\Philipp\Documents\Dropbox 2015-06-19 19:49 - 2010-12-01 14:28 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dropbox 2015-06-19 19:48 - 2014-07-12 11:12 - 00000000 ___RD C:\Users\Philipp\Google Drive 2015-06-19 19:48 - 2010-01-31 18:04 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-06-19 19:47 - 2015-04-04 08:21 - 00003934 _____ C:\Windows\PFRO.log 2015-06-19 19:47 - 2015-04-02 11:31 - 00326077 _____ C:\Windows\setupact.log 2015-06-19 19:47 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-06-19 19:19 - 2012-04-04 22:24 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-06-19 19:10 - 2014-12-31 17:10 - 00000917 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job 2015-06-19 19:10 - 2014-12-31 17:10 - 00000731 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job 2015-06-19 19:04 - 2010-01-31 18:04 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-06-19 06:51 - 2009-08-20 05:40 - 01620684 _____ C:\Windows\system32\PerfStringBackup.INI 2015-06-18 15:41 - 2014-11-23 16:42 - 00000000 ____D C:\Users\Philipp\.gimp-2.8 2015-06-18 15:15 - 2014-11-23 16:44 - 00000000 ____D C:\Users\Philipp\AppData\Local\gtk-2.0 2015-06-17 19:46 - 2014-11-23 16:44 - 00000000 ____D C:\Users\Philipp\.thumbnails 2015-06-17 18:24 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public 2015-06-17 18:17 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini 2015-06-17 17:21 - 2014-11-15 12:37 - 00000000 __SHD C:\Users\Philipp\AppData\Local\EmieBrowserModeList 2015-06-17 17:21 - 2014-05-07 17:14 - 00000000 __SHD C:\Users\Philipp\AppData\Local\EmieUserList 2015-06-17 17:21 - 2014-05-07 17:14 - 00000000 __SHD C:\Users\Philipp\AppData\Local\EmieSiteList 2015-06-16 16:23 - 2013-03-30 18:22 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\.minecraft 2015-06-16 15:34 - 2010-10-17 11:45 - 00001332 __RSH C:\Users\Philipp\ntuser.pol 2015-06-16 15:34 - 2010-10-17 11:45 - 00000000 ___RD C:\Users\Philipp 2015-06-16 15:22 - 2009-08-19 05:27 - 00000000 ____D C:\temp 2015-06-15 17:04 - 2013-11-21 19:48 - 00000000 ____D C:\Users\Beamer\AppData\Roaming\DAEMON Tools Lite 2015-06-15 06:48 - 2010-09-11 19:48 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Skype 2015-06-15 06:45 - 2014-07-30 10:13 - 00000000 __SHD C:\Users\Jeffel\AppData\Local\EmieUserList 2015-06-15 06:45 - 2014-07-30 10:13 - 00000000 __SHD C:\Users\Jeffel\AppData\Local\EmieSiteList 2015-06-14 20:33 - 2012-12-30 21:21 - 00000000 ___RD C:\Users\Jeffel\Dropbox 2015-06-14 20:33 - 2012-12-30 21:17 - 00000000 ____D C:\Users\Jeffel\AppData\Roaming\Dropbox 2015-06-14 19:33 - 2010-10-18 18:21 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Skype 2015-06-13 13:07 - 2014-07-12 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2015-06-11 18:47 - 2011-10-20 18:09 - 00000000 ____D C:\ProgramData\Avira 2015-06-11 18:41 - 2014-08-25 20:44 - 00000000 ____D C:\ProgramData\Package Cache 2015-06-11 18:40 - 2015-03-05 16:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-06-11 18:40 - 2012-11-02 20:39 - 00000000 ____D C:\Program Files\Avira 2015-06-11 12:09 - 2012-11-02 20:40 - 00136728 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-06-11 12:09 - 2012-11-02 20:40 - 00108448 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-06-11 12:09 - 2012-11-02 20:40 - 00031848 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\ssmdrv.sys 2015-06-11 09:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2015-06-11 08:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2015-06-10 17:55 - 2014-05-29 20:43 - 00000000 ____D C:\Users\Philipp\.android 2015-06-10 17:19 - 2012-04-04 22:24 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-06-10 17:19 - 2011-06-10 19:15 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-06-10 15:43 - 2015-04-02 11:30 - 00572992 _____ C:\Windows\system32\FNTCACHE.DAT 2015-06-10 15:05 - 2014-12-10 22:23 - 00000000 ____D C:\Windows\system32\appraiser 2015-06-10 15:05 - 2014-04-26 10:01 - 00000000 ___SD C:\Windows\system32\CompatTel 2015-06-10 15:04 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2015-06-10 10:31 - 2009-08-19 04:00 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-06-10 10:25 - 2013-07-28 23:00 - 00000000 ____D C:\Windows\system32\MRT 2015-06-10 10:14 - 2009-12-29 22:28 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-06-09 17:21 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Libraries 2015-06-08 18:27 - 2013-06-17 09:00 - 00000000 ____D C:\ProgramData\Origin 2015-06-08 18:20 - 2013-06-17 11:51 - 00000000 ____D C:\Users\Beamer\AppData\Roaming\Origin 2015-06-08 18:14 - 2013-06-17 09:00 - 00000000 ____D C:\Program Files\Origin 2015-06-08 17:04 - 2013-11-27 20:45 - 00000000 ____D C:\Program Files\Common Files\Steam 2015-06-06 10:46 - 2012-05-17 13:18 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Notepad++ 2015-06-04 19:21 - 2009-08-19 04:20 - 00000000 ____D C:\Program Files\Google 2015-06-04 18:42 - 2012-05-11 15:08 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-06-03 16:42 - 2014-04-28 18:03 - 00000000 ____D C:\Program Files\CCleaner 2015-05-31 15:54 - 2012-12-22 15:49 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Audacity 2015-05-30 22:11 - 2009-11-24 20:19 - 00045056 _____ C:\Windows\system32\acovcnt.exe 2015-05-30 12:55 - 2010-03-06 18:42 - 00000000 ____D C:\Users\Jeffel\Documents\Kigo 2015-05-27 18:16 - 2010-01-25 18:43 - 00000000 ____D C:\Users\Jeffel\Documents\Telefon 2015-05-26 11:56 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2015-05-21 21:22 - 2011-08-28 09:47 - 00000000 ____D C:\Users\Beamer 2015-05-20 20:24 - 2012-11-02 20:40 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2015-05-20 17:19 - 2015-04-04 20:15 - 00000000 ___SD C:\Windows\system32\GWX 2015-05-20 17:07 - 2010-10-21 17:44 - 00000000 ____D C:\Users\Philipp\AppData\Local\Adobe 2015-05-20 17:06 - 2011-08-28 10:41 - 00000000 ____D C:\Users\Beamer\AppData\Local\Adobe ==================== Files in the root of some directories ======= 2008-05-22 09:35 - 2008-05-22 09:35 - 0051962 _____ () C:\Program Files\Common Files\banner.jpg 2009-04-08 11:31 - 2009-04-08 11:31 - 0106496 _____ () C:\Program Files\Common Files\CPInstallAction.dll 2008-08-11 22:45 - 2008-08-11 22:45 - 0155648 _____ (ASUS) C:\Program Files\Common Files\MSIactionall.dll 2013-06-01 21:00 - 2013-06-03 12:23 - 0078208 _____ () C:\Users\Philipp\AppData\Roaming\MinecraftLog.txt 2012-06-19 14:26 - 2012-06-19 14:26 - 0041472 ___SH () C:\Users\Philipp\AppData\Roaming\Thumbs.db 2010-11-19 20:11 - 2013-02-02 12:46 - 0010240 _____ () C:\Users\Philipp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-06-18 15:15 - 2015-06-18 15:15 - 0011037 _____ () C:\Users\Philipp\AppData\Local\recently-used.xbel 2012-04-17 18:47 - 2012-04-17 18:47 - 0000017 _____ () C:\Users\Philipp\AppData\Local\resmon.resmoncfg 2010-09-11 19:55 - 2010-09-11 19:55 - 0000056 ____H () C:\ProgramData\ezsidmv.dat Files to move or delete: ==================== C:\Users\Jeffel\i2errDeu.dll Some files in TEMP: ==================== C:\Users\Philipp\AppData\Local\temp\avgnt.exe C:\Users\Philipp\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp31u4nh.dll C:\Users\Philipp\AppData\Local\temp\Quarantine.exe C:\Users\Philipp\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-06-04 23:19 ==================== End of log ============================ |
19.06.2015, 19:09 | #12 |
| DHL Spam Mail -> Trojaner/Virus? Additional: [CODE]Additional FRST Logfile: FRST Logfile: Code:
ATTFilter scan result of Farbar Recovery Scan Tool (x86) Version: 13-06-2015 Ran by Philipp at 2015-06-19 20:04:15 Running from C:\Users\Philipp\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-644356114-2566177158-2502637254-500 - Administrator - Disabled) Beamer (S-1-5-21-644356114-2566177158-2502637254-1005 - Administrator - Enabled) => C:\Users\Beamer Ellen & Manuel (S-1-5-21-644356114-2566177158-2502637254-1008 - Limited - Enabled) => C:\Users\Ellen & Manuel Gast (S-1-5-21-644356114-2566177158-2502637254-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-644356114-2566177158-2502637254-1010 - Limited - Enabled) Jeffel (S-1-5-21-644356114-2566177158-2502637254-1000 - Administrator - Enabled) => C:\Users\Jeffel Manuel (S-1-5-21-644356114-2566177158-2502637254-1011 - Limited - Enabled) => C:\Users\Manuel Philipp (S-1-5-21-644356114-2566177158-2502637254-1004 - Administrator - Enabled) => C:\Users\Philipp ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Antivirus (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 1&1 SmartFax (HKLM\...\1&1 SmartFax) (Version: 2.00.224 - 1&1 Internet AG) 3dPageFlip Editor (HKLM\...\3dPageFlip PDF Editor_is1) (Version: - 3dPageFlip Solution) Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adblock Plus für IE (32-Bit) (HKLM\...\{654F389B-E402-4F7B-BA6D-DA732BB57ACB}) (Version: 1.4 - Eyeo GmbH) Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated) Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Alcor Micro USB Card Reader (HKLM\...\AmUStor) (Version: 1.4.1217.35202 - Alcor Micro Corp.) Alcor Micro USB Card Reader (Version: 1.4.1217.35202 - Alcor Micro Corp.) Hidden Apple Application Support (32-Bit) (HKLM\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASUS CopyProtect (HKLM\...\{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}) (Version: 1.0.0015 - ASUS) ASUS Data Security Manager (HKLM\...\{FA2092C5-7979-412D-A962-6485274AE1EE}) (Version: 1.00.0014 - ASUS) ASUS FancyStart (HKLM\...\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}) (Version: 1.0.6 - ASUSTeK Computer Inc.) ASUS LifeFrame3 (HKLM\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS) ASUS Live Update (HKLM\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS) ASUS MultiFrame (HKLM\...\{9D48531D-2135-49FC-BC29-ACCDA5396A76}) (Version: 1.0.0019 - ASUS) ASUS Power4Gear eXtreme (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.0.19 - ASUS) ASUS SmartLogon (HKLM\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0007 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0028 - ASUS) ASUS Touch Pad Extra (HKLM\...\{DB891739-2EB3-45A8-9CBD-941C255CECD4}) (Version: - ) ASUS Virtual Camera (HKLM\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.19 - asus) Asus_Camera_ScreenSaver (HKLM\...\Asus_Camera_ScreenSaver) (Version: 2.0.0008 - ASUS) Atheros Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - Atheros) ATI Catalyst Install Manager (HKLM\...\{0AE24BD5-185C-436C-D93D-50574523C6C4}) (Version: 3.0.732.0 - ATI Technologies, Inc.) ATK Generic Function Service (HKLM\...\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}) (Version: 1.00.0008 - ATK) ATK Hotkey (HKLM\...\{7C05592D-424B-46CB-B505-E0013E8E75C9}) (Version: 1.0.0053 - ASUS) ATK Media (HKLM\...\{D1E5870E-E3E5-4475-98A6-ADD614524ADF}) (Version: 2.0.0006 - ASUS) ATKOSD2 (HKLM\...\{3B05F2FB-745B-4012-ADF2-439F36B2E70B}) (Version: 7.0.0006 - ASUS) aTube Catcher (HKLM\...\aTube Catcher) (Version: 2.9.1462 - DsNET Corp) aTube Catcher Version 3.8 (HKLM\...\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp) Audacity 2.0.2 (HKLM\...\Audacity_is1) (Version: 2.0.2 - Audacity Team) Avanquest update (HKLM\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.29 - Avanquest Software) Avidemux 2.6 (32-bit) (HKLM\...\Avidemux 2.6) (Version: 2.6.8.9046 - ) Avira (HKLM\...\{0696cc37-db90-4000-be99-4a173ca7c8af}) (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG) Avira (Version: 1.1.39.17987 - Avira Operations GmbH & Co. KG) Hidden Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.11.574 - Avira Operations GmbH & Co. KG) Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION Avira SearchFree Toolbar plus Web Protection Updater (HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29781 - Ask.com) <==== ATTENTION Bandicam (HKLM\...\Bandicam) (Version: 1.8.5.302 - Bandisoft.com) Battlefield 1942™ (HKLM\...\{5BE7BD06-512B-43bf-AD78-3BD2A5F5F7B3}) (Version: 1.6.20.0 - Electronic Arts) Bejeweled® 3 (HKLM\...\{E99C27B2-EB2E-4244-9F5C-A96F55100F0C}) (Version: 1.1.13.4753 - Electronic Arts, Inc.) BlueStacks App Player (HKLM\...\BlueStacks App Player) (Version: 0.9.27.5408 - BlueStack Systems, Inc.) BlueStacks Notification Center (HKLM\...\{C1F53C9F-C560-4292-9237-12786FE6BF62}) (Version: 0.9.27.5408 - BlueStack Systems, Inc.) Bob baut einen Park (HKLM\...\{367EDD83-302F-48E6-8F77-B0B056125C2D}) (Version: 1.0.0 - ) Bob der Baumeister (HKLM\...\{8F2D21F9-F428-4EF2-8111-953EF3299EFB}) (Version: 1.0.0 - ) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\...\CANONIJPLM100) (Version: - ) Canon MP Navigator EX 3.0 (HKLM\...\MP Navigator EX 3.0) (Version: - ) Canon MP490 series Benutzerregistrierung (HKLM\...\Canon MP490 series Benutzerregistrierung) (Version: - ) Canon MP490 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series) (Version: - ) Canon Utilities Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version: - ) Canon Utilities My Printer (HKLM\...\CanonMyPrinter) (Version: - ) Canon Utilities Solution Menu (HKLM\...\CanonSolutionMenu) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform) Cisco EAP-FAST Module (HKLM\...\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM\...\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM\...\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.) Construction-Simulator 2015 (HKLM\...\Steam App 289950) (Version: - weltenbauer. Software Entwicklung GmbH) Core Temp version 0.99.7 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 0.99.7 - Arthur Liberman) Crusader No Remorse (HKLM\...\{2AEA735F-B393-4D89-93EF-5849CB72B4A3}) (Version: 1.0.0.2 - Electronic Arts) CyberLink LabelPrint (HKLM\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1720 - CyberLink Corp.) CyberLink Power2Go (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.2713 - CyberLink Corp.) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd) Diercke Globus Online (HKLM\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH) dm-Fotowelt (HKLM\...\dm-Fotowelt) (Version: 5.1.7 - CEWE Stiftung u Co. KGaA) Dolby Control Center (HKLM\...\{0F3C61B5-3051-4DE6-8A6A-45100BCC1F41}) (Version: 1.2.0704 - Dolby) Dropbox (HKU\S-1-5-21-644356114-2566177158-2502637254-1000\...\Dropbox) (Version: 3.6.7 - Dropbox, Inc.) Dropbox (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\Dropbox) (Version: 3.6.7 - Dropbox, Inc.) Druckerdeinstallation für EPSON XP-312 313 315 Series (HKLM\...\EPSON XP-312 313 315 Series) (Version: - SEIKO EPSON Corporation) Druckerdeinstallation für EPSON XP-412 413 415 Series (HKLM\...\EPSON XP-412 413 415 Series) (Version: - SEIKO EPSON Corporation) Dual Monitor 1.22 (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{64AA3F94-ED4A-4A4B-B72C-B7A1481ED5D8}_is1) (Version: 1.22.021813 - Cristi Diaconu) EA SPORTS FIFA World (HKLM\...\{8F9AC744-EEF6-43DB-A4B6-FA1A18F1C640}) (Version: 9.5.0.61021 - Electronic Arts, Inc.) Epson Connect Printer Setup (HKLM\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.3.0 - SEIKO EPSON CORPORATION) Epson Event Manager (HKLM\...\{0F13C24A-FFE2-4CD0-8E0B-DC804E0A0E0B}) (Version: 3.10.0035 - Seiko Epson Corporation) EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON-Handbücher (HKLM\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.32.0.0 - SEIKO EPSON CORPORATION) EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION) Express Gate (HKLM\...\{62CF8923-31DC-4285-A23C-17CE5AA6A679}) (Version: 1.0.3.2 - DeviceVM, Inc.) F1 2013 (HKLM\...\Steam App 223670) (Version: - Codemasters Birmingham) FIFA 09 (HKLM\...\{2315B23D-3E21-4920-837D-AE6460934ECB}) (Version: 1.0.1.1 - Electronic Arts) Firebird SQL Server - MAGIX Edition (HKLM\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG) FRITZ!Box USB-Fernanschluss (HKU\S-1-5-21-644356114-2566177158-2502637254-1005\...\2db37667170956ee) (Version: 2.3.2.0 - AVM Berlin) GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team) Globus Fotoservice 4.4 (HKLM\...\Globus Fotoservice_is1) (Version: - ) Google Drive (HKLM\...\{CBC9F5FD-5CFA-4A33-81CD-369EAB77E3A6}) (Version: 1.22.9403.0223 - Google, Inc.) Google Earth (HKLM\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden Google+ Auto Backup (HKLM\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google) Hot Wheels (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\{CF36DD86-81D3-4D91-8F7A-344E0C1A4BFD}) (Version: 1.00.0000 - Activision Value) iCloud (HKLM\...\{9A07AB4F-6B53-43E9-B7FC-7892E8C26BE3}) (Version: 4.1.1.53 - Apple Inc.) Isola LEGO 2 (HKLM\...\{85967580-EBC2-11D4-AEA3-0050046A88ED}) (Version: - ) iTunes (HKLM\...\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.) Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden KingsoftOfficeXPlats 1.4 (HKLM\...\KingsoftOfficeXPlats) (Version: 1.4 - Kingsoft) LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version: - ) LBOTS Top mouse Driver (HKLM\...\{F1A273BD-6A9E-41D8-A111-5E56ACD286F8}) (Version: 1.0 - Togran) LEGO Racers 2 (HKLM\...\{3DD2E9EA-0544-4162-B8BE-E21E994E9F3B}) (Version: - ) LEGO® Star Wars™: Die Komplette Saga (HKLM\...\InstallShield_{D596980D-17BE-4425-B8F0-5640719AADE9}) (Version: 1.00.0000 - LucasArts) LEGO® Star Wars™: The Complete Saga (Version: 1.00.0000 - LucasArts) Hidden Logitech Gaming Software (HKLM\...\{648F9C94-EC44-487B-9DA4-44ED72A082CC}) (Version: 4.50 - ) MAGIX Speed burnR (MSI) (HKLM\...\MX.{16884C3D-3512-486D-A2F9-39071551BFEF}) (Version: 7.0.2.6 - MAGIX AG) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden MAGIX Video deluxe 2014 (HKLM\...\MX.{EA62B22F-AB0A-406B-80A9-8036D3CE3446}) (Version: 13.0.2.8 - MAGIX AG) MAGIX Video deluxe 2014 (Version: 13.0.2.8 - MAGIX AG) Hidden Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Outlook Connector (HKLM\...\{95120000-0122-0407-0000-0000000FF1CE}) (Version: 12.0.6423.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{AC4C38FD-A54C-4CA5-92EE-D983CD81293E}) (Version: 1.20.146.0 - Microsoft) Minecraft (HKLM\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) Minigolf (HKLM\...\Minigolf_is1) (Version: - Meridian93) Monkey's Adventures (HKLM\...\Monkey's Adventures_is1) (Version: - play-publishing.com) Motorola Driver Installation 3.4.0 (HKLM\...\{81B3BEF9-5D97-4096-86E9-5B48A5BC32D0}) (Version: 3.4.0 - Motorola Inc.) Motorola Phone Tools (HKLM\...\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}) (Version: 5.0.7a 4/01/2008 - Avanquest Software) Motorola Phone Tools (Version: 4.30 - BVRP Software) Hidden Motorola Phone Tools (Version: 5.00 - BVRP Software) Hidden Mozilla Firefox 38.0.5 (x86 de) (HKLM\...\Mozilla Firefox 38.0.5 (x86 de)) (Version: 38.0.5 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyPublicWiFi 5.1 (HKLM\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version: - TRUE Software) Mystery P.I. - The London Caper (HKLM\...\Mystery P.I. - The London Caper) (Version: - PopCap Games) NB Probe (HKLM\...\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}) (Version: - ) Need For Speed™ World (HKLM\...\{3AF1B16A-7DC9-4C80-BAEC-70B088A7C5B8}) (Version: 1.0.0.0 - Electronic Arts) Net4Switch (HKLM\...\{9D6D7811-43B3-463C-BC79-5D1755269989}) (Version: 1.00.0019 - ASUS) Norton Internet Security (Version: 16.0.0.125 - Symantec Corporation) Hidden Notepad++ (HKLM\...\Notepad++) (Version: 6.1.2 - ) OpenAL (HKLM\...\OpenAL) (Version: - ) Oracle VM VirtualBox 4.3.2 (HKLM\...\{91E5A436-8560-4621-9F26-D7050D078832}) (Version: 4.3.2 - Oracle Corporation) Origin (HKLM\...\Origin) (Version: 9.2.1.4399 - Electronic Arts, Inc.) pdfsam (HKLM\...\pdfsam) (Version: 2.2.0 - ) Peter Lustigs Verkehrsschule (HKLM\...\Verkehrsschule) (Version: - ) Pflanzen gegen Zombies™ (HKLM\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.) QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Roads Of Rome (HKLM\...\Roads Of Rome_is1) (Version: - Realore Studios) Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.) Samsung Kies (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) SimCity 2000 Special Edition (HKLM\...\{59D2C751-F7BE-4E9F-9C8C-1F16013802C7}) (Version: 2.0.0.1 - Electronic Arts) SimCity™ (HKLM\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts) Skype™ 7.1 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.) Software Updater (HKLM\...\{E1BAD1BA-C0E8-4018-9281-E7D2C6B07474}) (Version: 4.3.6 - SEIKO EPSON CORPORATION) Steam (HKLM\...\Steam) (Version: - Valve Corporation) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.1.1 - Synaptics Incorporated) Syndicate (HKLM\...\{64CFBAAB-46F7-4628-8D9B-E656A8C11CDB}) (Version: 2.0.0.3 - Electronic Arts) System Requirements Lab CYRI (HKLM\...\{E77DA909-3532-4C95-AFEB-06310E88462A}) (Version: 6.0.3.0 - Husdawg, LLC) Theme Hospital (HKLM\...\{5118A4C2-C8A4-4CE5-AC37-F3E51C25402F}) (Version: 3.0.0.2 - Electronic Arts) TIPP10 Version 2.1.0 (HKLM\...\TIPP10_is1) (Version: - (c) 2006-2011, Tom Thielicke IT Solutions) TmNationsForever (HKLM\...\TmNationsForever_is1) (Version: - Nadeo) TOGGO PC-Spielebox 2 (HKLM\...\{67EECE0C-8B6C-4D09-989D-D39BC9BBCA0E}) (Version: 1.00.0000 - ) Toyland Racer (HKLM\...\Toyland Racer) (Version: - ) Unified Remote (HKLM\...\{D7930C67-5816-417B-BF28-54BB75EFDAF9}) (Version: 2.14.4.0 - Unified Remote) Unity Web Player (HKU\S-1-5-21-644356114-2566177158-2502637254-1004\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Unity Web Player (HKU\S-1-5-21-644356114-2566177158-2502637254-1008\...\UnityWebPlayer) (Version: - Unity Technologies ApS) upapp (HKLM\...\{4EF69D40-4DC9-485E-95D3-B1C22F218FC8}) (Version: 0.20.0000 - Hewlett-Packard) USB 2.0 1.3M UVC WebCam (HKLM\...\USB 2.0 1.3M UVC WebCam) (Version: - ) Werksfeuerwehr-Simulator Version 1.0 (HKLM\...\{5F7ED0CD-E04E-4441-9E03-10AFDB654E96}_is1) (Version: - rondomedia Marketing & Vertriebs GmbH) Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live ID-Anmelde-Assistent (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Live Sync (HKLM\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation) Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) WinFlash (HKLM\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.29.0 - ASUS) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) Wireless Console 2 (HKLM\...\{83F73CB1-7705-49D1-9852-84D839CA2A45}) (Version: 2.0.10 - ATK) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\ProgramData\Skype\Plugins\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\ProgramData\Skype\Plugins\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Philipp\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{4D72E5BC-BC7C-11E0-83CA-10424824019B}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\AviraIDW.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{595EF3BD-A186-454A-810C-02015139ACDC}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\Avira.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{7F902AD4-FC6A-4B2F-8B8D-B6DD4E329B76}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\AVIRAW~1.DLL No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{A0359AE6-F410-4425-A975-684AAB785ABD}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\AVIRAB~1.DLL No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\Jeffel\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\Philipp\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{EB959CA4-408B-4465-9CF5-7EBA7B885153}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\AVIRAS~1.DLL No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FBE88A10-FF53-11E0-AB2A-AE904824019B}\InprocServer32 -> C:\Users\Philipp\AppData\Local\ASKTOO~1\DOWNLO~1\AVIRAI~1.DLL No File CustomCLSID: HKU\S-1-5-21-644356114-2566177158-2502637254-1004_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\Philipp\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll (Dropbox, Inc.) ==================== Restore Points ========================= 15-06-2015 06:14:31 Windows-Sicherung 16-06-2015 13:24:40 Windows Update 16-06-2015 16:55:49 Revo Uninstaller's restore point - Avira SearchFree Toolbar plus Web Protection Updater ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 12:23 - 2015-06-17 18:08 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {022E57E0-C220-4A4E-AC90-D2C8DACAFB9D} - System32\Tasks\{4E4F2CAC-AA02-4AC1-8E3F-7F64288279A5} => C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe [2000-05-31] (Krisalis Software Ltd.) Task: {0381252B-84D7-4E1D-8044-32644EAD1708} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-03-16] (Microsoft Corporation) Task: {062DB597-D745-4B4F-8444-3530722D8F45} - System32\Tasks\Core Temp Autostart => C:\Program Files\Core Temp\Core Temp.exe [2010-07-05] () Task: {08271361-89BF-4F1E-847E-1CA1ED3F6641} - System32\Tasks\{4B77430A-A839-4A8D-9AC6-DFE4CD36D283} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {0CF8F249-C5F7-475C-866F-21E7073015BD} - System32\Tasks\{EBC19F45-7508-4844-801A-11E762E37D12} => C:\Program Files\Ford Racing 2\fr2.exe Task: {0FB6D721-7BEF-4B45-8E9C-A271B66DE5F2} - System32\Tasks\{07EB860E-F755-4932-9D3F-42431206EE3B} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {10DE5D12-366D-4EFB-9E1B-A5431C45ADC4} - System32\Tasks\{8AC62F6C-CFBA-4FA8-8592-D8DBAF919A41} => C:\Program Files\Ford Racing 2\fr2.exe Task: {11F32470-4328-4A83-9232-80BC5F42F305} - System32\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {13CEC175-DFF4-4468-A045-29A526295C70} - System32\Tasks\{09EF0FB5-FFC5-4873-8A09-BA67F477983B} => C:\Program Files\Ford Racing 2\fr2.exe Task: {16A24A9E-DAB7-4860-94FD-851235C89820} - System32\Tasks\{2F3444E4-EAF5-4F9D-B44F-0359C6E1E962} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe Task: {16E7A595-0943-4C27-81FD-3C0F4846CBB9} - System32\Tasks\{718A9724-BA58-4A15-BA3F-28AD141B9FD7} => C:\Program Files\Logitech\Profiler\LWEmon.exe [2004-05-19] (Logitech Inc.) Task: {189C40ED-B151-444D-86FA-72B2F6B581EA} - System32\Tasks\{EEA39017-C6C8-42D6-83AD-AC789FF71125} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {1C2351DE-232B-4961-840F-EE0D68EB5EF4} - System32\Tasks\{81FAAD8E-E607-4907-9205-969E20593CF7} => C:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe Task: {1DD33B99-F5E8-460F-BD30-B40888E8C53E} - System32\Tasks\{DB5AE33D-F764-456D-9421-62DA1F9288C7} => pcalua.exe -a "D:\DT\DAEMON Tools Lite\DTLite.exe" -d "D:\DT\DAEMON Tools Lite" Task: {1E3565F3-04AA-44DB-B8B7-F35A50CC9057} - System32\Tasks\{07FA7B80-D838-4C87-9F76-696E853348E0} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe Task: {2262B621-3FBA-4C58-8344-886110A30AF0} - System32\Tasks\{275198ED-E85E-4D37-9669-8DAC2931B05F} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {27685E6B-A6D7-4064-A4B9-1F485556156D} - System32\Tasks\{D1391C33-4665-4D75-B346-6737F2BFE6AE} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.) Task: {279BEA6F-528A-4E59-B4D6-EF67500EC149} - System32\Tasks\{4CB1BAEC-7E20-4475-942D-B2ECD3C7BDE5} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {2C842B08-3AB4-4249-8416-A5F0C4254CBB} - System32\Tasks\{E26735BF-5210-43CB-908E-8A7923966B55} => C:\Program Files\Ford Racing 2\fr2.exe Task: {2E316E44-A20D-4E6C-8597-A4349A8F0F7B} - System32\Tasks\{0E84DB2D-E2CE-4939-A87C-0A7FEF5598A0} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe Task: {2EB3D3F5-13C7-448C-98A4-8E8B09A66A7C} - System32\Tasks\{1833D727-C5CA-45F6-B130-C78FC735305C} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.) Task: {3701EA83-EDC0-434F-8AB9-FE21AAE4072D} - System32\Tasks\{08709750-B91C-4722-844A-B78F6762E37B} => C:\Program Files\EA Sports\FIFA 09\FIFA09.exe [2008-10-23] () Task: {37B9496D-79A9-4BCE-AFE4-B5463740A943} - System32\Tasks\{F9594586-61F2-41B8-A093-C8719E057E91} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.) Task: {393F6F51-0E95-4952-8BAD-E1DDD5FFF5DA} - System32\Tasks\{01E58447-78A0-4CD3-BFAF-44C036E4F3F7} => C:\Program Files\Ford Racing 2\fr2.exe Task: {394592EC-79F9-49B8-A307-37950D07C1B9} - System32\Tasks\{E9474EA8-9D29-4DF8-9857-8726D1F8FCD4} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe Task: {3A161975-54C5-4DBB-8AB5-563F0BA63B7E} - System32\Tasks\{BBCB2F70-2DD9-4FDF-BA21-9F4AC8615359} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {3B9AC8C7-B8FF-4D70-9C79-4FB5EBBB90E9} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-07] (Microsoft Corporation) Task: {3BC1FA8B-E302-4DEC-8AA9-B70DE9D839F7} - System32\Tasks\{15248D75-D51C-4771-8D5B-C56A5DC1D3F4} => C:\Program Files\OpenOffice.org 3\program\soffice.exe Task: {3DF4B1BA-C6BA-4565-9C58-0A27C06A1D4C} - System32\Tasks\{10DEF6AD-CAED-48C8-85EB-BD3A12C54209} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {3ECE4DE4-C76E-486F-A045-0713A65EC396} - System32\Tasks\{C5F0B686-DAD5-46B7-8DC1-EEF6742294DF} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.) Task: {3EF06EA8-17AE-4451-96B0-2ED48FE15BE6} - System32\Tasks\{FFB859B9-8F39-438E-A00B-543A2BC334B5} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {425C2494-05F2-4141-BD10-63B0AC111EEF} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {4299562C-9C52-4B20-9BF8-D294B2969604} - System32\Tasks\{CE1034B1-CDF0-44ED-A78A-0E1B67A19078} => pcalua.exe -a E:\SETUP.EXE -d E:\ Task: {48F7E135-8B4D-421A-B8E8-22BE06815370} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-08] (Piriform Ltd) Task: {4A3D5C4F-7A49-48E2-BE04-A2DECC4146C2} - System32\Tasks\{4DF731FE-39D2-4735-963D-B33DC6BF1776} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {4B952069-F7C4-4178-932C-D9AD6435A3EE} - System32\Tasks\{9F523BAE-9190-4380-B2B3-96FB780FE112} => pcalua.exe -a C:\Users\Philipp\Desktop\jxpiinstall.exe -d C:\Users\Philipp\Desktop Task: {4B9BA069-9E54-412A-90D7-CBB925EBF5FA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-10] (Adobe Systems Incorporated) Task: {4D2676FB-5EC2-4044-897A-45B547B13687} - System32\Tasks\ASUS Live Update => C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2007-11-30] () Task: {4D5F48A9-2EB0-4E4E-B34D-95A3DDB466A9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {4D8CE3D9-10E6-4EF4-9C8E-39AD6D90EEEB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13] (Dropbox, Inc.) Task: {4E453841-EE58-4AA6-8514-3E30F217B1BE} - System32\Tasks\{E56CE78F-3DF9-4305-8336-77785549E0F4} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {542676B6-E1CE-4B5C-BDF2-C00ECFB38DBC} - System32\Tasks\{42963256-E132-413E-A4D9-4AD87B590641} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {543E71B8-E7BE-4FDA-AD19-CC490CA91848} - System32\Tasks\{09D857DD-F75F-4669-84AC-9B2B4F91002A} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {561375CB-FF5A-417B-B297-BA73DE149581} - System32\Tasks\Microsoft\Windows\Wired\GatherWiredInfo => C:\Windows\system32\gatherWiredInfo.vbs Task: {576416B1-5229-4BB5-8F5F-5EB4CE34693A} - System32\Tasks\{0AD9175A-E960-4F4A-B254-A7FFF532194A} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.) Task: {592F7F57-9C8F-4F5D-9A75-D8444CAF5A34} - System32\Tasks\{3A608F0C-88F6-4101-A24D-5888FB4E1675} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {5B3DB1D0-2D67-4C1C-BA0C-73372A98F89C} - System32\Tasks\{8B5019D5-0BD6-4708-A1CA-DE33DAF12937} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {5CC8A7A0-EB94-45A9-8C14-10D1FA017AA5} - System32\Tasks\{D6670E02-8F5A-46ED-BFE4-8AEF911AB2FE} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {5D8E271A-4247-422B-BB0B-A0F60CD4F2EE} - System32\Tasks\{CF4F2AC7-7291-4854-8184-33979FBEEA3A} => C:\Program Files\Logitech\Profiler\LWEMon.exe [2004-05-19] (Logitech Inc.) Task: {6997CFAE-6B39-4219-A1BB-BFCA1A25B735} - System32\Tasks\ACMON => C:\Program Files\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK) Task: {6BCBF903-EFC8-4841-A00B-8A98F9B42040} - System32\Tasks\{5F24C263-DED9-48A3-85E4-2AF0241EDD56} => pcalua.exe -a C:\PROGRA~1\Stardock\OBJECT~1\DesktopX\UNWISE.EXE -c C:\PROGRA~1\Stardock\OBJECT~1\DesktopX\INSTALL.LOG Task: {6C2BAF56-D5B0-4D25-BFA4-8A03090E90F4} - System32\Tasks\{35BF4035-207B-4DDB-A7D9-DAE7569EA9A7} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {6C7963B0-501B-464F-85BB-0F1A98CB0EE2} - System32\Tasks\{ACD04780-E85C-4752-806D-C7E0B65CA043} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {6FAF6F7D-1CDF-4408-A9E7-F480AFD09927} - System32\Tasks\{224E176B-C279-4E30-BFAC-74EDBD3DF2AA} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {71707D88-0843-4073-AFAC-21043703B9B5} - System32\Tasks\{B5BE686C-6877-4712-B359-6260EE6BAA94} => C:\Program Files\Ford Racing 2\fr2.exe Task: {72ED54C5-EAAC-4283-858E-E531B2490992} - System32\Tasks\{795C6E6E-FAAA-4431-A918-937A78C53BB2} => C:\Program Files\Ford Racing 2\fr2.exe Task: {7585CE6A-F9B1-4E6E-856F-617D6D00D54C} - System32\Tasks\Net4Switch => C:\Program Files\ASUS\Net4Switch\Net4Switch.exe [2007-11-20] (ASUS) Task: {79B505CA-4391-4F82-93B8-F6A10F007D29} - System32\Tasks\{E9F1D326-BB8E-416E-A09B-6DEFFC535CE7} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {7B9BD304-C851-42BA-B29B-8832C02B513D} - System32\Tasks\{AA91F360-BE81-48A9-9CFE-2565918BACBC} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.) Task: {7BBE44D8-A420-4877-91D3-43AD4DF8740A} - System32\Tasks\{99B1E97F-436E-4429-ABA3-7E618A478667} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {805902FB-18D4-403F-9263-0624A07154E2} - System32\Tasks\{1648ED5A-2D13-4C52-AE7C-31297200C10D} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {839450A1-1065-490A-BB58-7CFB79EDF0D6} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {85417455-F0F1-41C5-8316-B8DFEB8C8918} - System32\Tasks\{1A5C41D9-30DC-4783-B8B0-CEC6F0B3E839} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {86094599-821F-4E9B-8E55-9AF40185191E} - System32\Tasks\{ED62F36F-605A-4AE1-8208-FD5CA76699B4} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe Task: {8B3014D9-EB90-4483-B8E6-B492402A6DF0} - System32\Tasks\{12845C94-D0B6-4BDA-A9FB-5B154245A6D4} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {8DBA4AC8-B6E1-4E21-92E1-6F5BD04CBC59} - System32\Tasks\{805913F2-AD7E-416D-BA65-5BCB278D42E1} => C:\Program Files\LEGO Schach\Lego Chess.exe Task: {8EAD5D19-6EF9-4FAD-91E1-C759DDC095FA} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {8FB70F6E-172F-42D9-AD4A-91E5AFF5A7B5} - System32\Tasks\{20881F0F-F213-4B1D-AC68-02FABF50C1CE} => C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe [2000-05-31] (Krisalis Software Ltd.) Task: {9057296A-F885-41B1-8E01-EF575CEF376C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.) Task: {90FFF327-1728-488D-BE4E-FA1232DD7BB6} - System32\Tasks\{14EDE9BC-20F9-4EFA-AC7D-6EB4C5A76C71} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {99C2E64D-3C78-4488-8CF3-672D6E3DB446} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13] (Dropbox, Inc.) Task: {99C91901-9432-4EA7-87F8-55A525B95ABA} - System32\Tasks\{E2D1EE7B-E7AD-4C2D-AAB0-AC383A6F07CC} => C:\Program Files\Janosch\Verkehr.exe [1998-04-16] (Macromedia, Inc.) Task: {A0215012-5C94-40CA-9A43-2F200B61A4A2} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004UA => C:\Users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17] (Dropbox, Inc.) Task: {A0EC8CE0-03D7-4A0E-A8FA-0380AF2A1FF0} - System32\Tasks\{D884D7E7-64A4-45DE-98FD-56D8596FCD34} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {A33BE22C-702F-4129-AB69-5361B36F2500} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {A93B8A4D-244F-453C-9B10-DB60E36A1C57} - System32\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {A9443690-748A-45F1-8D64-6AA0294F58AE} - System32\Tasks\{A5E9A2AB-D783-444B-ACEA-988C9C2827BD} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {AC093D78-AE53-48AF-A35E-7E570F6D5649} - System32\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {B22899B8-49AC-43DA-B2BF-CCB47C542539} - System32\Tasks\{37C1FFED-5F13-4EA4-B8E0-FBC3039B59DA} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe Task: {B2FDDA94-D222-4673-A9AF-CAE32F13265A} - System32\Tasks\{57123DD4-3701-4890-8F5E-69253F2A254E} => C:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe Task: {B3B4709A-B606-4F54-A90A-116F93D8512E} - System32\Tasks\ASPG => C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS) Task: {B7D4A3DB-3927-46B0-A840-174630359DE6} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files\ASUS\SmartLogon\sensorsrv.exe [2009-05-18] (ASUS) Task: {BDC925F9-1584-4227-BF87-557F6DC13464} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004Core => C:\Users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17] (Dropbox, Inc.) Task: {BF436BB1-3885-496D-B203-C36CFA947E53} - System32\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {C01F96CD-E814-4B3B-8ADB-B61746C44F27} - System32\Tasks\{47B8FC20-7DB8-48A6-83BC-E7C34E62CC8B} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {C361CDD7-C67A-4CB4-A515-59B3F225DF8C} - System32\Tasks\{6C5CE7EA-6EC5-497C-8FAE-8DDE494754CC} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {C6D305DC-A5B7-4BD2-B434-64B58E96E1B9} - System32\Tasks\{83270C1C-EFD0-435A-B354-DB444A4E64F7} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe Task: {C71C0104-D3E3-49D0-886E-850A0EA0A519} - System32\Tasks\{629DDE4B-7DAE-4321-B366-19139E71F9C4} => C:\Program Files\Ford Racing 2\fr2.exe Task: {CCCDE7C4-AC7C-4DD5-98AB-1DDF96CC1A00} - System32\Tasks\{5E36B9A2-EA7B-4338-B839-BA06E700C7A7} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {D2D316AA-04AB-4C85-B4E6-0FFA7C1B5CAD} - System32\Tasks\{897420D6-2E83-4F0C-9542-4235DE3ADD9D} => C:\Program Files\Ford Racing 2\fr2.exe Task: {D428F363-CD1D-4CEC-BCFD-7895783F2746} - System32\Tasks\{740C00F2-0AF4-462D-B602-FAA959059F5E} => C:\Program Files\LEGO Media\Spiele\LEGOLAND\legoland.exe [2000-05-31] (Krisalis Software Ltd.) Task: {D943FB3E-EB45-43CD-91A6-A055E15CE059} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.) Task: {DA81BBC7-677C-4A44-A056-CB90DC977864} - System32\Tasks\{0D730403-F736-400F-B631-19B8BC0E1E30} => C:\Program Files\EA Sports\FIFA 09\FIFA09.exe [2008-10-23] () Task: {DB85DFE2-B398-4D92-BA2A-821880861383} - System32\Tasks\{846920E1-73B4-4C1B-801F-BA087FE5EEF8} => C:\Program Files\LEGO Schach\Lego Chess.exe Task: {DC34DD92-92FA-4E52-A136-C3C2FC249AE5} - System32\Tasks\{9D61A73B-0DE2-48FE-A2B3-088709BD7D2C} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {DC6CEF1A-D549-42B2-87D2-274BEC35D662} - System32\Tasks\{C1FB456D-5102-4D69-A102-59FBB9C799C1} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {DE31F299-BD40-4A25-BB8A-10EC1ADC4783} - System32\Tasks\{E39103FF-9002-43CF-B483-1326522EF959} => C:\Program Files\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs Task: {E54FD084-9DE3-498A-8ECB-F723F22FAB84} - System32\Tasks\{A48CA2AC-8CD3-4B01-9BD2-E56D49ADD8F7} => C:\Program Files\EA Sports\FIFA 09\FIFA09.exe [2008-10-23] () Task: {E5AB5213-9D14-427E-BF04-B685E363ABF9} - System32\Tasks\{F8DD370C-1C9B-4B99-A221-D936EDE7FDAD} => C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe Task: {E61935EA-A141-496D-BA9E-CF4C3EF3795D} - System32\Tasks\{3CB8A215-9260-42B8-8D9B-FA81017EED9A} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {E9BFC740-3580-4EA6-9861-89784029CF48} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks Task: {EDFDEDC0-7152-4BC4-8E7A-2D96E5C6D8D7} - System32\Tasks\{6DD7CCD6-3D1C-4DA7-B895-4F4F95745358} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {EEA6A0A0-E1CD-4583-B178-0690064E5D8F} - System32\Tasks\{EE69846A-E56D-493D-B5DA-858DE7FA218B} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {F74F66A2-BA11-4AEC-A516-F153CDCD3451} - System32\Tasks\{2EF7C677-995A-413F-93CA-F39A6D35363C} => C:\Program Files\Ford Racing 2\fr2.exe Task: {F7E36632-B92F-40E5-8FDF-60225CFB5CB3} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Jeffel => C:\Program Files\Windows Calendar\WinCal.exe Task: {F8E4E8A9-959E-4214-8706-20AE311FFA86} - System32\Tasks\{D1117AB3-5D96-42EF-8AE2-EE14F8692D60} => C:\Program Files\LEGO Interactive\Island Xtreme Stunts\FindDisc.exe Task: {F8EF940F-03BD-46F5-A998-1540C6587472} - System32\Tasks\{FB7C2341-6721-4B95-A6AE-136D881A01F3} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe Task: {F9428F41-B2CF-431B-8A33-32AD9E73E88C} - System32\Tasks\{BF78135C-D9BB-42BD-8E6A-0FBBC5ACA700} => C:\Program Files\LEGO Media\Island Xtreme Stunts\FindDisc.exe Task: {FD11DEA1-27EB-480A-ADD0-60B1E33E6B31} - System32\Tasks\{DA19A5B2-B0BB-49BA-854B-43FECBBC9387} => C:\Program Files\Logitech\Profiler\LWEmon.exe [2004-05-19] (Logitech Inc.) Task: {FD3008D4-9573-44C7-B144-BA5C02B4BFCA} - System32\Tasks\{3E7DE8B7-79CA-4BC7-A84E-390073C4E375} => C:\Program Files\LEGO Media\Games\LEGO Schach\Lego Chess.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000Core.job => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1000UA.job => C:\Users\Jeffel\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004Core.job => C:\Users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-644356114-2566177158-2502637254-1004UA.job => C:\Users\Philipp\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {5ED40A39-9E20-4A57-9853-44602CD12F7A}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLFE.EXE:/EXE:{5ED40A39-9E20-4A57-9853-44602CD12F7A} /F:UpdateSYSTEM Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\Windows\Tasks\EPSON XP-412 413 415 Series Invitation {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE Task: C:\Windows\Tasks\EPSON XP-412 413 415 Series Update {00F3F166-48F4-41CC-97B5-0BCDE58D612F}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FTSLEE.EXE:/EXE:{00F3F166-48F4-41CC-97B5-0BCDE58D612F} /F:UpdateSYSTEM Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2007-06-15 11:28 - 2007-06-15 11:28 - 00147456 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll 2007-06-01 18:08 - 2007-06-01 18:08 - 00143360 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll 2010-01-01 12:48 - 2009-12-12 16:12 - 00141824 _____ () C:\Program Files\WinRAR\rarext.dll 2011-07-18 23:04 - 2011-07-18 23:04 - 00296448 _____ () C:\Program Files\Notepad++\NppShell_04.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Jeffel\Desktop\1.avi:TOC.WMV AlternateDataStreams: C:\Users\Jeffel\Desktop\2.avi:TOC.WMV AlternateDataStreams: C:\Users\Jeffel\Desktop\3.avi:TOC.WMV ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-644356114-2566177158-2502637254-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Jeffel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-644356114-2566177158-2502637254-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-644356114-2566177158-2502637254-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\Beamer\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-644356114-2566177158-2502637254-1008\Control Panel\Desktop\\Wallpaper -> C:\Users\Ellen & Manuel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-644356114-2566177158-2502637254-1011\Control Panel\Desktop\\Wallpaper -> C:\Users\Manuel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.177.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: Apple Mobile Device => 2 MSCONFIG\Services: ATKGFNEXSrv => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: BstHdAndroidSvc => 3 MSCONFIG\Services: BstHdLogRotatorSvc => 3 MSCONFIG\Services: BstHdUpdaterSvc => 3 MSCONFIG\Services: bthserv => 3 MSCONFIG\Services: ehRecvr => 3 MSCONFIG\Services: ehSched => 3 MSCONFIG\Services: EpsonScanSvc => 2 MSCONFIG\Services: FirebirdServerMAGIXInstance => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: gusvc => 3 MSCONFIG\Services: IEEtwCollectorService => 3 MSCONFIG\Services: IJPLMSVC => 3 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: MDES => 2 MSCONFIG\Services: MyPublicWiFiService => 2 MSCONFIG\Services: Origin Client Service => 3 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\Services: spmgr => 2 MSCONFIG\Services: ss_conn_service => 2 MSCONFIG\Services: Steam Client Service => 3 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk => C:\Windows\pss\FancyStart daemon.lnk.CommonStartup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: AlcoholAutomount => "D:\Alcohol 120\axcmd.exe" /automount MSCONFIG\startupreg: AmIcoSinglun => C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: ASUS Camera ScreenSaver => C:\Windows\AsScrProlog.exe MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\ASScrPro.exe MSCONFIG\startupreg: ASUSTPE => C:\Windows\system32\ASUSTPE.exe MSCONFIG\startupreg: AVMUSBFernanschluss => "C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\AVMAutoStart.exe" MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files\BlueStacks\HD-Agent.exe MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon MSCONFIG\startupreg: CanonSolutionMenu => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR MSCONFIG\startupreg: CLMLServer => "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: DAEMON Tools Lite => "D:\DT\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: KiesTrayAgent => D:\Samsung Kies\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: Steam => "D:\Steam\steam.exe" -silent MSCONFIG\startupreg: SunJavaUpdateSched => C:\Program Files\Common Files\Java\Java Update\jusched.exe MSCONFIG\startupreg: UpdateLBPShortCut => "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" MSCONFIG\startupreg: UpdateP2GoShortCut => "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{98B426BE-4154-48E7-A940-C28AD6AB3C7E}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{A0ED8D77-C475-4A7C-9683-E33EF6CA08AE}] => (Allow) svchost.exe FirewallRules: [{5A959ABA-B81C-408F-9BF9-A382D827ED17}] => (Allow) C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [TCP Query User{92FF86AB-5408-4239-86CD-713C52CC5E72}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [UDP Query User{756D4762-70FE-4F03-9A42-0F627F10CBF8}C:\program files\google\google earth\client\googleearth.exe] => (Allow) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [TCP Query User{F15C73F2-09B2-4D70-B6C1-FCB8C6C3077A}C:\program files\google\google earth\client\googleearth.exe] => (Block) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [UDP Query User{3518798C-9464-4B02-B79D-33060DE82A80}C:\program files\google\google earth\client\googleearth.exe] => (Block) C:\program files\google\google earth\client\googleearth.exe FirewallRules: [TCP Query User{F87691B0-9C93-4349-8E2B-69BF1B0D816D}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{0756E3CD-F4D3-4373-BCB1-583FDDA22919}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{6939840F-897B-42B5-8E48-6E97937198B0}] => (Allow) svchost.exe FirewallRules: [{59E3FF2C-493B-4937-9A37-DA9D1CAAFC4B}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe FirewallRules: [TCP Query User{A1DE6356-BBC4-48A8-B039-88DEB224609A}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{E3168A96-5F5E-4485-AD0D-7AE6A2596564}C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\philipp\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{4AF10D0E-C4C1-40A2-936B-C6F2AB12613B}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe FirewallRules: [UDP Query User{88D7FF05-F79E-4946-A853-288BD573E814}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe FirewallRules: [TCP Query User{9EFEAB5F-7210-4BC7-8BA8-231FA6D585A1}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe FirewallRules: [UDP Query User{375FCB23-571C-4F84-90FE-A0670DEAAC49}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe FirewallRules: [{55E52E7C-FD6E-4517-8357-F6D71154371A}] => (Allow) C:\Users\Jeffel\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{9C447FBD-4CD0-4507-918C-C3C1FC1BC0BC}] => (Allow) C:\Users\Jeffel\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{424B5F96-6253-4B19-824F-7157B91CE53C}C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{A3FECD29-88C2-49EE-9826-78B12649C757}C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\jeffel\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{5518E9F3-F3DC-433F-9E50-A930A0CD15F2}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe FirewallRules: [UDP Query User{55697CCA-A2DB-4C9F-8442-8DC6C36139AA}C:\windows\system32\javaw.exe] => (Allow) C:\windows\system32\javaw.exe FirewallRules: [TCP Query User{3E55C8FD-D431-4830-8F71-22F2B69255C3}C:\program files\ea sports\fifa 09\fifa09.exe] => (Allow) C:\program files\ea sports\fifa 09\fifa09.exe FirewallRules: [UDP Query User{6B39FD39-72B8-4683-9E30-4221DEFAD5D9}C:\program files\ea sports\fifa 09\fifa09.exe] => (Allow) C:\program files\ea sports\fifa 09\fifa09.exe FirewallRules: [TCP Query User{EF7EF825-131B-4165-A892-9DEC02FC688F}E:\easysetupassistant\wr841n\easysetupassistant.exe] => (Allow) E:\easysetupassistant\wr841n\easysetupassistant.exe FirewallRules: [UDP Query User{25BF93E3-CEFC-4077-972C-637BBD3D8D23}E:\easysetupassistant\wr841n\easysetupassistant.exe] => (Allow) E:\easysetupassistant\wr841n\easysetupassistant.exe FirewallRules: [{BE0F663E-C815-4563-A897-646E54E5E075}] => (Block) E:\easysetupassistant\wr841n\easysetupassistant.exe FirewallRules: [{C1AD54B1-3E4E-48CD-AA59-46A81630CED6}] => (Block) E:\easysetupassistant\wr841n\easysetupassistant.exe FirewallRules: [TCP Query User{642462DC-FE55-4283-B3BE-5116D1ABD2D1}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{1543EF59-9BDC-45F3-98C1-666138EE2360}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [{F42F3A51-5E79-42CD-97EC-8F46AFB3AEDA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{3AF441F6-2448-4E93-AF29-F00F2983A81B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{3A83D0B7-CC23-4E0A-A47F-BA4C727DA59B}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{A30C3FCC-E865-487C-BB2B-94503E562E57}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [{C5B4D7F3-5ACD-4113-B7F8-EF24617B930D}] => (Allow) D:\OriginGames\Need for Speed World\GameLauncher.exe FirewallRules: [{54FB9595-0BFB-47AF-866A-250C8D7B1BAF}] => (Allow) D:\OriginGames\Need for Speed World\GameLauncher.exe FirewallRules: [{9E1C364E-EA27-4082-AB13-FBEBC90590BA}] => (Allow) D:\OriginGames\Battlefield 1942\BF1942.exe FirewallRules: [{2EB3B6C7-04D1-43DF-B4B0-B47348DBCD68}] => (Allow) D:\OriginGames\Battlefield 1942\BF1942.exe FirewallRules: [{DBB13B95-B032-45C2-A416-2E496104A650}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{5456B4DC-0D08-476B-B4CB-8BA97886248B}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{B3C9C811-6617-41F7-8833-D1B66AC7C967}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [TCP Query User{FB78B67C-4DFB-45DA-8910-73B460C08EE9}D:\needforspeed world\data\nfsw.exe] => (Allow) D:\needforspeed world\data\nfsw.exe FirewallRules: [UDP Query User{514C9672-18B4-476C-B568-2B1D2211DC21}D:\needforspeed world\data\nfsw.exe] => (Allow) D:\needforspeed world\data\nfsw.exe FirewallRules: [{122DB7AB-303C-4A23-8984-A4089D07A519}] => (Allow) D:\Steam\SteamApps\common\f12013\F1_2013.exe FirewallRules: [{BA4A4B55-61BE-49C7-B106-9CF16C1FEFCA}] => (Allow) D:\Steam\SteamApps\common\f12013\F1_2013.exe FirewallRules: [{852A6D93-68A1-49D2-A427-091873A0F8AF}] => (Allow) D:\OriginGames\Plants vs. Zombies\PlantsVsZombies.exe FirewallRules: [{1C423230-E993-447A-B8BC-B011BD1ABEA4}] => (Allow) D:\OriginGames\Plants vs. Zombies\PlantsVsZombies.exe FirewallRules: [{5476BAD2-AE20-42B2-BFC6-58B987D9EC81}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [{812E2119-243A-400E-B7FE-DEB6D62808AB}] => (Allow) D:\OriginGames\SimCity\SimCity\SimCity.exe FirewallRules: [{2C4E33E9-EDDF-4059-9790-647FCF83145D}] => (Allow) D:\OriginGames\SimCity\SimCity\SimCity.exe FirewallRules: [TCP Query User{60D69111-FE19-4415-B387-D97AE26AFD38}C:\program files\tmnationsforever\tmforever.exe] => (Block) C:\program files\tmnationsforever\tmforever.exe FirewallRules: [UDP Query User{F2DF262E-FF7C-484F-AA4E-63FF8880305C}C:\program files\tmnationsforever\tmforever.exe] => (Block) C:\program files\tmnationsforever\tmforever.exe FirewallRules: [{A3C3ECE5-F0B8-458B-BF51-A7F6BF8F5E0E}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{DAA3B140-1FED-47B5-9F25-FB8F35548A03}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{F14B2E24-FBC1-4546-BBB6-CCBF3E3C26CB}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe FirewallRules: [{1EBAA986-ABD7-469D-8126-C6A22AB47DCF}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe FirewallRules: [TCP Query User{DF57783D-CA97-4654-B267-AC96484B730F}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{695F1F23-F5F2-4E3A-93D3-C046C30B108D}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{18759B6E-98BA-4489-983D-ABCF93CE30A2}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{C48C23E4-CF37-4289-AC60-2FF3F377ACD4}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe FirewallRules: [{BAE39D93-BC07-4545-A838-D128E5D729B1}] => (Allow) C:\Users\Philipp\AppData\Local\Apps\2.0\AKHGTRNK.DG4\BWYE0CZZ.LL7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{BDC2FD03-237D-49E4-A6A2-8AE3211FB11A}] => (Allow) C:\Users\Philipp\AppData\Local\Apps\2.0\AKHGTRNK.DG4\BWYE0CZZ.LL7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{2A33F55E-5BBB-4A44-9852-D7FEA360081E}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{084ED6E8-0CDB-42C1-9716-21D9E1E099C3}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [TCP Query User{5A171416-5B5C-45E6-A06C-FD51ECCBBA01}C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe] => (Block) C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [UDP Query User{EC3DF4E2-12D4-4BEA-9E53-8BD42E933EE3}C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe] => (Block) C:\users\philipp\appdata\local\apps\2.0\akhgtrnk.dg4\bwye0czz.ll7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{B3F421E8-5795-4576-A04B-678154A5D42C}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{56B79544-76F5-4B6F-85BD-3CA9415A0BE3}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [TCP Query User{A674A672-4708-4C05-A7DD-7FC78F2ABAD6}C:\program files\unified remote\remoteserver.exe] => (Allow) C:\program files\unified remote\remoteserver.exe FirewallRules: [UDP Query User{C42108C2-C11D-4BCD-848F-C882C383AFF1}C:\program files\unified remote\remoteserver.exe] => (Allow) C:\program files\unified remote\remoteserver.exe FirewallRules: [{66918B97-AE64-444C-9DB6-5DB605AE12F7}] => (Allow) D:\OriginGames\Bejeweled 3\Bejeweled3.exe FirewallRules: [{4D93D20E-753C-494E-8FA6-F47CF535E417}] => (Allow) D:\OriginGames\Bejeweled 3\Bejeweled3.exe FirewallRules: [{100DFB51-03A7-409A-8436-B1ADEDE290A7}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{3D1CFBF6-1099-4721-A86E-438E12C875EA}] => (Allow) C:\Program Files\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{708B5EAF-95EC-428E-9AA3-7F8A3CC499D7}] => (Allow) D:\OriginGames\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe FirewallRules: [{252252F8-D1E0-473A-8A33-743C157FAAAB}] => (Allow) D:\OriginGames\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe FirewallRules: [{12369EEC-4B3E-4804-8395-3B1EE1D1F377}] => (Allow) C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{23965B5B-2D1F-4BC2-82F2-4E012CDB6110}] => (Allow) C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{8AD425C4-E4CD-4E0A-B470-71C0186D4419}] => (Allow) D:\OriginGames\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe FirewallRules: [{79468976-3ED7-4AAD-8CDF-CC32C20626C3}] => (Allow) D:\OriginGames\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe FirewallRules: [{98C0D637-E762-4100-8AF8-3E756C54A265}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe FirewallRules: [{533B5FB5-1CB8-4776-8F97-B9D35616A215}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe FirewallRules: [{D67CAA53-7942-4A91-8D54-03DE16AF77AA}] => (Allow) D:\Steam\SteamApps\common\ConSim2015\ConSim2015.exe FirewallRules: [{085EB9AF-D4B4-42D7-AA85-2FF13C776871}] => (Allow) D:\Steam\SteamApps\common\ConSim2015\ConSim2015.exe FirewallRules: [{13EC435C-D4A0-4045-9736-20D5C2A52E0F}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{766D54AC-FE82-4990-81C9-4B3E62FC1D8E}] => (Allow) C:\Users\Beamer\AppData\Local\Apps\2.0\L54C6PTC.C5D\OZVODBER.JQ7\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{8147F4AA-6FEE-48F5-A257-DADCA6B3D1F7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{B59D5117-8BF8-4401-A031-594855C5359E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{C3A2EE98-6FD7-4841-986B-5FF483452073}] => (Allow) D:\OriginGames\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [{7894DF2C-B685-420A-810A-505E1663461E}] => (Allow) D:\OriginGames\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [{AB875D33-F535-45C7-83AD-4542A38F0A9A}] => (Allow) D:\OriginGames\Syndicate (1993)\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [{C8819052-499D-4060-A2CB-63C85B7289F3}] => (Allow) D:\OriginGames\Syndicate (1993)\data\Game\DOSBox\LAUNCHER.exe FirewallRules: [TCP Query User{2405E39F-611A-4841-8667-B7FAB332ED13}D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{98A5CF53-9EE7-4592-86E6-5A255E971ED4}D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) D:\philipp scheffler\philipps sachen\minecraft\neue installation\runtime\jre-x32\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{42389642-E7E4-4FA7-99F0-D17483626C6F}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{546675B7-4D5D-41B0-A82B-3C2AE0AED9AE}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [{F4820325-C52D-4F14-B0C1-E2F40210A513}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft3077.tmp\fsetup.exe FirewallRules: [{F8A2199B-EA6F-43B4-BF29-FC040CE4901D}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft3077.tmp\fsetup.exe FirewallRules: [{0CB53765-513D-49DE-87C5-AECA2C3658C1}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pftAA65.tmp\fsetup.exe FirewallRules: [{C88A6BB6-DBFF-4572-AA49-2F5929892EA3}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pftAA65.tmp\fsetup.exe FirewallRules: [{13D83860-A9E7-48A7-A64E-3D805CB1B574}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft96D1.tmp\fsetup.exe FirewallRules: [{4DDF4814-C41E-4164-81FB-D9C60F8AD319}] => (Allow) C:\Users\Beamer\AppData\Local\Temp\pft96D1.tmp\fsetup.exe FirewallRules: [{7870E46B-69E5-4524-B2E7-ECEB9E6D710D}] => (Allow) C:\Program Files\iTunes\iTunes.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/19/2015 07:49:17 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/18/2015 04:34:58 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/17/2015 08:04:15 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: gimp-2.8.exe, Version: 2.8.14.0, Zeitstempel: 0x00000000 Name des fehlerhaften Moduls: libpixman-1-0.dll, Version: 0.0.0.0, Zeitstempel: 0x0072a5f0 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00084b3b ID des fehlerhaften Prozesses: 0x1338 Startzeit der fehlerhaften Anwendung: 0xgimp-2.8.exe0 Pfad der fehlerhaften Anwendung: gimp-2.8.exe1 Pfad des fehlerhaften Moduls: gimp-2.8.exe2 Berichtskennung: gimp-2.8.exe3 Error: (06/17/2015 06:29:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/17/2015 06:12:59 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/17/2015 01:38:25 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/16/2015 08:32:18 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 38.0.5.5623, Zeitstempel: 0x5563c49a Name des fehlerhaften Moduls: mozalloc.dll, Version: 38.0.5.5623, Zeitstempel: 0x5563b229 Ausnahmecode: 0x80000003 Fehleroffset: 0x00001aa1 ID des fehlerhaften Prozesses: 0x1264 Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Error: (06/16/2015 04:55:48 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {24c98460-576e-4efe-898a-0f7fbfad98d1} Error: (06/16/2015 03:35:57 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/16/2015 01:48:07 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15585 System errors: ============= Error: (06/19/2015 07:57:58 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "WMI-Leistungsadapter" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/19/2015 07:57:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "FABS - Helping agent for MAGIX media database" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/19/2015 07:57:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/19/2015 07:57:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Software Protection" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/19/2015 07:57:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Modules Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/19/2015 07:57:28 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "MBAMService" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/19/2015 07:57:28 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "MBAMScheduler" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/19/2015 07:57:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Adobe Acrobat Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/19/2015 07:57:26 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/19/2015 07:57:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "ASLDR Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Microsoft Office: ========================= Error: (06/19/2015 07:49:17 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/18/2015 04:34:58 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/17/2015 08:04:15 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: gimp-2.8.exe2.8.14.000000000libpixman-1-0.dll0.0.0.00072a5f0c000000500084b3b133801d0a9279a9e94e3D:\GIMP 2\bin\gimp-2.8.exeD:\GIMP 2\bin\libpixman-1-0.dll432e3355-151b-11e5-ac41-002618f9ca5d Error: (06/17/2015 06:29:30 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/17/2015 06:12:59 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/17/2015 01:38:25 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/16/2015 08:32:18 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe38.0.5.56235563c49amozalloc.dll38.0.5.56235563b2298000000300001aa1126401d0a85c270b00cdC:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dll03eedcfa-1456-11e5-9a84-002618f9ca5d Error: (06/16/2015 04:55:48 PM) (Source: VSS) (EventID: 8194) (User: ) Description: 0x80070005, Zugriff verweigert Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {24c98460-576e-4efe-898a-0f7fbfad98d1} Error: (06/16/2015 03:35:57 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/16/2015 01:48:07 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15585 ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T6500 @ 2.10GHz Percentage of memory in use: 43% Total physical RAM: 3071.27 MB Available physical RAM: 1744.06 MB Total Pagefile: 6140.86 MB Available Pagefile: 4361.31 MB Total Virtual: 3071.88 MB Available Virtual: 2927.84 MB ==================== Drives ================================ Drive c: (VistaOS) (Fixed) (Total:149.04 GB) (Free:31.61 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (DATA) (Fixed) (Total:137.33 GB) (Free:72.24 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 97646C29) Partition 1: (Not Active) - (Size=11.7 GB) - (Type=1C) Partition 2: (Active) - (Size=149 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=137.3 GB) - (Type=OF Extended) ==================== End of log ============================ --- --- --- |
20.06.2015, 12:13 | #13 |
/// the machine /// TB-Ausbilder | DHL Spam Mail -> Trojaner/Virus?ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.06.2015, 05:54 | #14 |
| DHL Spam Mail -> Trojaner/Virus? Ok, ESET: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c0c7fff54a27634f9d2006f27ed8248f # end=init # utc_time=2015-06-22 03:07:09 # local_time=2015-06-22 05:07:09 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c0c7fff54a27634f9d2006f27ed8248f # end=init # utc_time=2015-06-22 05:29:26 # local_time=2015-06-22 07:29:26 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c0c7fff54a27634f9d2006f27ed8248f # end=init # utc_time=2015-06-22 05:31:14 # local_time=2015-06-22 07:31:14 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download Update Finalize Updated modules version: 24446 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c0c7fff54a27634f9d2006f27ed8248f # end=updated # utc_time=2015-06-22 05:33:54 # local_time=2015-06-22 07:33:54 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=c0c7fff54a27634f9d2006f27ed8248f # engine=24446 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-06-23 12:37:48 # local_time=2015-06-23 02:37:48 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 209274 186651059 0 0 # scanned=432286 # found=10 # cleaned=0 # scan_time=25434 sh=3DC2837E9E894C9B971C4DAC9F27C43561C49738 ft=1 fh=f4e11a8294dd61e1 vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Beamer\Downloads\aTube_Catcher.exe" sh=4CDFFCF08191640A9E441DB241BFD5ABE063742B ft=1 fh=a9082013fbdd22a7 vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Jeffel\Downloads\aTube_Catcher_Setup.exe" sh=D48DFC2287A65BAF685CD674711BF2CD0A784ADB ft=1 fh=466a3dc1051aac66 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Manuel\Downloads\CTcontrol - CHIP-Installer.exe" sh=D0607EC2B0E991266F690760AE3C67E67ED29B75 ft=0 fh=0000000000000000 vn="Win32/WinloadSDA.C evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-04-25 121650\Backup files 1.zip" sh=6C46740394AD406A1D35EDDA92FA7B9C2607C267 ft=0 fh=0000000000000000 vn="Win32/FileScout.A evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-04-25 121650\Backup files 108.zip" sh=E27CEEBCE8F58480E7559E8A1AB70327CC60605F ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-04-25 121650\Backup files 111.zip" sh=681014B2F904CB93D37DD1691A11D65A67F86B08 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-04-25 121650\Backup files 124.zip" sh=F263C95C1DEA2C00F1A1096FD49334DACBADF053 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-04-25 121650\Backup files 98.zip" sh=1BBABDBD8C8F180AA3D2145384B77DE24C3F86F9 ft=0 fh=0000000000000000 vn="Variante von Win32/GetNow.D evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-11-29 223933\Backup files 39.zip" sh=D096D8035843F8307DDB86D02A31C11C47C2D271 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="G:\SCHEFFLER-PC\Backup Set 2014-04-25 121650\Backup Files 2014-11-29 223933\Backup files 43.zip" Code:
ATTFilter Results of screen317's Security Check version 1.002 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Antivirus Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` CCleaner Java version 32-bit out of Date! Adobe Flash Player 17.0.0.188 Adobe Reader XI Mozilla Firefox (38.0.5) ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
23.06.2015, 12:16 | #15 |
/// the machine /// TB-Ausbilder | DHL Spam Mail -> Trojaner/Virus? und der Rest?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu DHL Spam Mail -> Trojaner/Virus? |
avira, board, fehlalarme, frage, gefunde, klick, kurzem, mail, nicht mehr, pdf, quara, quarantäne, runter, spam, spam mail, spammail, suchlauf, troja, trojaner, trojaner board, trojaner/virus, vater, virus, woche, wochen |