|
Plagegeister aller Art und deren Bekämpfung: __prosschiff@gmail.com_.cryptWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
03.09.2015, 17:09 | #1 |
| __prosschiff@gmail.com_.crypt Alle Dateien auf meinem PC wurde mit der Endung __prosschiff@gmail.com_.crypt erweitert. Damit funktioniert natürlich auch nichts mehr. Wie bringe ich diesen Plagegeist wieder los ? Danke Torsten.E |
03.09.2015, 17:44 | #2 |
/// the machine /// TB-Ausbilder | __prosschiff@gmail.com_.crypt hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
03.09.2015, 17:52 | #3 |
| FRSTCode:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x86) Version:31-08-2015 durchgeführt von Administrator (Administrator) auf SH-PC2 (03-09-2015 18:48:10) Gestartet von C:\Users\TEMP.SH-PC2.031\Desktop Geladene Profile: Administrator (Verfügbare Profile: Schwedenhaus & Administrator) Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (VMware, Inc.) C:\Program Files\VMware\VMware Tools\vmacthlp.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (CrypKey (Canada) Ltd.) C:\Windows\System32\Crypserv.exe (devolo AG) C:\Program Files\devolo\dlan\devolonetsvc.exe () C:\Users\Schwedenhaus\AppData\Roaming\Mikogo 4\M4-Service.exe (McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe (McAfee, Inc.) C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe (pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe (pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe () C:\Program Files\Cyberlink\Shared files\RichVideo.exe (McAfee, Inc.) C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe (Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\w32x86\3\NetFaxServer.exe (DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe () C:\Users\Schwedenhaus\AppData\Roaming\Mikogo 4\M4-Capture.exe () C:\Program Files\Twonky\TwonkyServer\twonkyproxy.exe (PacketVideo) C:\Program Files\Twonky\TwonkyServer\twonkystarter.exe (McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor Enterprise\saHookMain.exe () C:\Program Files\Twonky\TwonkyServer\twonkywebdav.exe (VMware, Inc.) C:\Program Files\VMware\VMware Tools\vmtoolsd.exe (VMware, Inc.) C:\Program Files\VMware\VMware vCenter Converter Standalone Agent\vmware-converter-a.exe (Evgeny Lachinov) C:\Program Files\Wild Media Server\wmssvc.exe () C:\Program Files\Twonky\TwonkyServer\twonkyserver.exe (Google Inc.) C:\Program Files\Google\Update\1.3.28.13\GoogleCrashHandler.exe (Logitech Inc.) C:\Program Files\Logitech\SetPoint\LBTWiz.exe (Axis Communications) C:\Program Files\Axis Communications\AXIS Camera Management 4\AcmService.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (VMware, Inc.) C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfeann.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe (Cortado AG) C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Cortado AG) C:\Program Files\VMware\VMware Tools\TPAutoConnect.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\LifeExp.exe () C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (VMware, Inc.) C:\Program Files\VMware\VMware Tools\vmtoolsd.exe (Logitech Inc.) C:\Program Files\Squeezebox\SqueezeTray.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe (Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\w32x86\3\NetFaxTray.exe (TechSmith Corporation) C:\Program Files\TechSmith\Snagit 12\Snagit32.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe (TechSmith Corporation) C:\Program Files\TechSmith\Snagit 12\SnagPriv.exe (TechSmith Corporation) C:\Program Files\TechSmith\Snagit 12\TscHelp.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9914984 2010-11-30] (Realtek Semiconductor) HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [55824 2009-06-17] (Logitech, Inc.) HKLM\...\Run: [JMB36X IDE Setup] => C:\Windows\RaidTool\xInsIDE.exe [43632 2010-08-20] () HKLM\...\Run: [TVEService] => C:\Program Files\CyberLink\TV Enhance\TVEService.exe [176128 2008-09-30] (CyberLink Corp.) HKLM\...\Run: [LifeCam] => C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM\...\Run: [MVS Splash] => C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe [480872 2012-11-13] () HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [350072 2012-03-09] () HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKLM\...\Run: [VMware User Process] => C:\Program Files\VMware\VMware Tools\vmtoolsd.exe [64704 2015-05-22] (VMware, Inc.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2009-07-20] (Logitech, Inc.) Winlogon\Notify\ScCertProp: wlnotify.dll [X] HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-18\...\Run: [EEDSpeedLauncher] => rundll32.exe C:\Windows\system32\eed_ec.dll,SpeedLauncher AppInit_DLLs: C:\Windows\system32\FileMonitor32.dll => C:\Windows\system32\FileMonitor32.dll [108544 2011-04-19] () ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-07-29] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-07-29] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-07-29] (Google) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => Keine Datei Startup: C:\Users\Administrator.IFTA-GMBH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Asset UPnP uMediaLibrary.lnk [2010-08-02] ShortcutTarget: Asset UPnP uMediaLibrary.lnk -> C:\Program Files\Illustrate\dBpoweramp\uMediaLibrary.exe (Keine Datei) Startup: C:\Users\Administrator.IFTA-GMBH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Asset UPnP.lnk [2010-08-02] ShortcutTarget: Asset UPnP.lnk -> C:\Program Files\Illustrate\dBpoweramp\Asset-uPNP.exe (Keine Datei) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Media Server-Taskleisten-Tool.lnk [2012-10-06] ShortcutTarget: Logitech Media Server-Taskleisten-Tool.lnk -> C:\Program Files\Squeezebox\SqueezeTray.exe (Logitech Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk [2010-07-14] ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Network PC Fax.lnk [2014-09-12] ShortcutTarget: Samsung Network PC Fax.lnk -> C:\Windows\System32\spool\drivers\w32x86\3\NetFaxTray.exe (Samsung Electronics Co., Ltd.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 12.lnk [2014-10-08] ShortcutTarget: Snagit 12.lnk -> C:\Program Files\TechSmith\Snagit 12\Snagit32.exe (TechSmith Corporation) Startup: C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk!___prosschiff@gmail.com_.crypt [2014-08-28] Startup: C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jAnrufmonitor 5.0.lnk!___prosschiff@gmail.com_.crypt [2015-01-21] Startup: C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lFIrshno.lnk [2015-08-30] ShortcutTarget: lFIrshno.lnk -> C:\Users\TEMP.SH-PC2.031\AppData\Local\{F5552CE3-9802-4CE0-9826-10C7A8A00F93}\aogaRrTd.exe (Keine Datei) Startup: C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lFIrshno.lnk!___prosschiff@gmail.com_.crypt [2015-08-30] Startup: C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\login.bat.lnk!___prosschiff@gmail.com_.crypt [2013-11-19] Startup: C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TwonkyManager.lnk!___prosschiff@gmail.com_.crypt [2012-11-18] GroupPolicyScripts: Gruppenrichtline erkannt <======= ACHTUNG GroupPolicyScripts\User: Gruppenrichtline erkannt <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..) Tcpip\..\Interfaces\{D5A1D48A-C98D-422F-A34E-91FC24A9F1D5}: [NameServer] 192.168.21.20 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Richtlinienbeschränkung <======= ACHTUNG HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Skype add-on (mastermind) -> {22BF413B-C6D2-4d91-82A9-A0F997BA588C} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04] (Skype Technologies S.A.) BHO: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files\PDF Architect\PDFIEHelper.dll [2013-04-08] (pdfforge GmbH) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-10-21] (Oracle Corporation) BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20140403131932.dll [2013-12-17] (McAfee, Inc.) BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll [2014-03-06] (McAfee, Inc.) BHO: AusweisApp 1.12.0.0 -> {C9EE92B7-EDD5-4ad9-8029-2EC6818E653A} -> C:\Program Files\AusweisApp\siqeCardClientIE32.ols [2014-04-11] (OpenLimit SignCubes AG) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-10-21] (Oracle Corporation) Toolbar: HKLM - Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - C:\PROGRA~1\Zend\ZENDST~2.0\toolbars\ZENDIE~1.DLL Keine Datei Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll [2014-03-06] (McAfee, Inc.) DPF: {89A32C64-6176-4D10-BCA3-10B0079818FA} hxxps://server2.ifta-gmbh.local:3443/webconsole/RIMWebComponents.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_43-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_43-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_43-windows-i586.cab Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll [2014-03-06] (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll [2014-03-06] (McAfee, Inc.) FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1203133.dll [2013-06-26] (Adobe Systems, Inc.) FF Plugin: @canon.com/MycameraPlugin -> C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll [2008-10-15] (CANON INC.) FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-10-21] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-10-21] (Oracle Corporation) FF Plugin: @mcafee.com/SAFFPlugin -> C:\Program Files\McAfee\SiteAdvisor Enterprise\NPMcFFPlg.dll [2014-03-06] (McAfee, Inc.) FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-12-23] (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [Keine Datei] FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2012-10-02] (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2012-10-02] (NVIDIA Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-30] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-30] (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN) FF Plugin: @vmware.com/vmrc,version=5.5.0.00000 -> C:\Program Files\Common Files\VMware\VMware Remote Console Plug-in 5.5\Firefox\np-vmware-vmrc.dll [2014-02-11] (VMware, Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2013-06-13] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2013-06-13] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2013-06-13] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2013-06-13] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2013-06-13] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npstrlnk.dll [2010-07-20] ( ) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll [2011-10-26] (Nullsoft, Inc.) FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA} [2015-03-14] FF Extension: McAfee SiteAdvisor Enterprise - C:\Program Files\Mozilla Firefox\distribution\bundles\{B7082FAA-CB62-4872-9106-E42DD88EDE45} [2015-03-14] FF HKLM\...\Firefox\Extensions: [{3c9761ad-a43d-4447-b924-f5d83cb48063}] - C:\Program Files\Zend\Zend Studio 10.5.0\toolbars\firefox FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-08-07] FF HKLM\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files\Common Files\McAfee\SystemCore FF Extension: McAfee ScriptScan for Firefox - C:\Program Files\Common Files\McAfee\SystemCore [2013-08-22] FF HKLM\...\Firefox\Extensions: [{4F3D26C8-9907-48ff-BC74-B8C572D317BF}] - C:\Program Files\AusweisApp\mozilla\eCardClientExt_FFxx_Win FF Extension: Kein Name - C:\Program Files\AusweisApp\mozilla\eCardClientExt_FFxx_Win [2014-08-25] FF HKLM\...\Firefox\Extensions: [{4F0963A3-1658-4fde-9585-23A25CC288BF}] - C:\Program Files\AusweisApp\mozilla\eCardClientPIn_FFxx_Win FF Extension: Kein Name - C:\Program Files\AusweisApp\mozilla\eCardClientPIn_FFxx_Win [2014-08-25] Chrome: ======= CHR Profile: C:\Users\TEMP.SH-PC2.031\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\TEMP.SH-PC2.031\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-03] CHR Extension: (Google Docs) - C:\Users\TEMP.SH-PC2.031\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-03] CHR Extension: (Google Drive) - C:\Users\TEMP.SH-PC2.031\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-09-03] CHR Extension: (YouTube) - C:\Users\TEMP.SH-PC2.031\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-03] CHR Extension: (Google Search) - C:\Users\TEMP.SH-PC2.031\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-09-03] CHR Extension: (Google Sheets) - C:\Users\TEMP.SH-PC2.031\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-03] CHR Extension: (McAfee SiteAdvisor Enterprise) - C:\Users\TEMP.SH-PC2.031\AppData\Local\Google\Chrome\User Data\Default\Extensions\feobgjncdknhelkhjpiejdbpliekmfaj [2015-09-03] CHR Extension: (Google Docs Offline) - C:\Users\TEMP.SH-PC2.031\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-03] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\TEMP.SH-PC2.031\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-09-03] CHR Extension: (Chrome Web Store Payments) - C:\Users\TEMP.SH-PC2.031\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-03] CHR Extension: (Gmail) - C:\Users\TEMP.SH-PC2.031\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-03] CHR HKLM\...\Chrome\Extension: [feobgjncdknhelkhjpiejdbpliekmfaj] - C:\Program Files\McAfee\SiteAdvisor Enterprise\McChPlg.crx [2014-03-06] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AXIS Camera Management; C:\Program Files\Axis Communications\AXIS Camera Management 4\AcmService.exe [17920 2013-09-05] (Axis Communications) [Datei ist nicht signiert] S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-03] (Microsoft Corporation) R2 Crypkey License; C:\Windows\system32\crypserv.exe [122880 2008-05-08] (CrypKey (Canada) Ltd.) [Datei ist nicht signiert] R2 DevoloNetworkService; C:\Program Files\devolo\dlan\devolonetsvc.exe [3128856 2012-02-28] (devolo AG) S3 ELIService; C:\Program Files\EventLog Inspector 3\ELIService.exe [2276976 2013-07-30] () S3 FirebirdServerDefaultIns_GDI3; C:\Program Files\Firebird\FB25_GDI_23053\bin\fbserver.exe [3735552 2011-01-13] (Firebird Project) [Datei ist nicht signiert] R2 M4-Service; C:\Users\Schwedenhaus\AppData\Roaming\Mikogo 4\M4-Service.exe [1008032 2012-07-18] () R2 McAfee SiteAdvisor Enterprise Service; C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe [161128 2014-03-06] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [204320 2013-12-17] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [169800 2013-12-17] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [174968 2013-12-17] (McAfee, Inc.) R2 myAgtSvc; C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [296400 2014-04-25] (McAfee, Inc.) S4 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2009-05-14] (Hewlett-Packard) [Datei ist nicht signiert] R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) S4 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2009-05-14] (Hewlett-Packard) [Datei ist nicht signiert] R2 RichVideo; C:\Program Files\Cyberlink\Shared files\RichVideo.exe [241734 2008-09-30] () [Datei ist nicht signiert] R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\w32x86\3\NetFaxServer.exe [378416 2013-02-05] (Samsung Electronics Co., Ltd.) R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.) S3 SXDS10; C:\Program Files\Common Files\soft Xpansion\SXDS10.exe [160768 2009-07-13] (soft Xpansion) [Datei ist nicht signiert] R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5611280 2015-08-07] (TeamViewer GmbH) R3 TPAutoConnSvc; C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe [382288 2015-05-22] (Cortado AG) S3 TPVCGateway; C:\Program Files\VMware\VMware Tools\TPVCGateway.exe [406864 2015-05-22] (Cortado AG) R2 TVECapSvc; C:\Program Files\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe [348255 2008-09-30] () [Datei ist nicht signiert] R2 TVESched; C:\Program Files\CyberLink\TV Enhance\Kernel\TV\TVESched.exe [118877 2008-09-30] () [Datei ist nicht signiert] R2 TwonkyProxy; C:\Program Files\Twonky\TwonkyServer\twonkyproxy.exe [545608 2012-07-09] () R2 TwonkyServer; C:\Program Files\Twonky\TwonkyServer\twonkystarter.exe [549704 2012-07-09] (PacketVideo) R2 TwonkyWebDav; C:\Program Files\Twonky\TwonkyServer\twonkywebdav.exe [271176 2012-07-09] () R2 VMUSBArbService; C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe [714832 2013-08-05] (VMware, Inc.) R2 VMware Physical Disk Helper Service; C:\Program Files\VMware\VMware Tools\vmacthlp.exe [411328 2015-05-22] (VMware, Inc.) R2 vmware-converter-agent; C:\Program Files\VMware\VMware vCenter Converter Standalone Agent\vmware-converter-a.exe [423576 2012-10-15] (VMware, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) R2 WmsService; C:\Program Files\Wild Media Server\wmssvc.exe [3082504 2010-12-30] (Evgeny Lachinov) R2 RumorServer; "C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe" /RunDLL=RumorServer.dll;ServiceHost [X] ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 ACEDRV07; C:\Windows\system32\drivers\ACEDRV07.sys [101376 2010-08-22] (Protect Software GmbH) [Datei ist nicht signiert] R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [105728 2013-08-07] (AVM Berlin) S3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [105728 2013-08-07] (AVM Berlin) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2010-10-22] (AVM Berlin) [Datei ist nicht signiert] S3 bmdrvr; C:\Windows\System32\drivers\bmdrvr.sys [54384 2011-03-15] (VMware, Inc.) R3 DLANS2C0; C:\Windows\System32\drivers\dvls2c6x.sys [99200 2009-05-08] (devolo AG) R3 DLANS2T0; C:\Windows\System32\drivers\dvls2t6x.sys [42624 2009-05-08] (devolo AG) S3 es1371; C:\Windows\System32\drivers\es1371mp.sys [40832 2002-06-03] (Creative Technology Ltd.) S3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [586752 2010-10-22] (AVM GmbH) [Datei ist nicht signiert] R2 hcmon; C:\Windows\system32\drivers\hcmon.sys [41936 2013-08-05] (VMware, Inc.) R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [104024 2010-08-20] (JMicron Technology Corp.) S3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [28560 2009-06-17] (Logitech, Inc.) S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [134472 2013-12-17] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [236480 2013-12-17] (McAfee, Inc.) R3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [66408 2013-12-17] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [365928 2013-12-17] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [573136 2013-12-17] (McAfee, Inc.) S1 mfenlfk; C:\Windows\System32\DRIVERS\mfenlfk.sys [64912 2012-02-22] (McAfee, Inc.) R3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [93144 2013-12-17] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [213872 2013-12-17] (McAfee, Inc.) S3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] () R1 NetworkX; C:\Windows\system32\ckldrv.sys [19584 2008-03-17] () [Datei ist nicht signiert] R2 NPF_devolo; C:\Windows\system32\drivers\npf_devolo.sys [35840 2012-01-31] (CACE Technologies) [Datei ist nicht signiert] R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [22184 2014-10-09] (Audials AG) S3 SCL01132; C:\Windows\System32\DRIVERS\SCL01132.sys [61824 2010-05-07] (SCM Microsystems Inc.) R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2013-04-10] (Samsung Electronics) [Datei ist nicht signiert] S3 ss_conn_usb_driver; C:\Windows\System32\Drivers\ss_conn_usb_driver.sys [23296 2014-10-13] (DEVGURU Co., LTD.) S3 StarOpen; C:\Windows\system32\Drivers\StarOpen.sys [7168 2009-11-12] () [Datei ist nicht signiert] R3 tbhsd; C:\Windows\System32\drivers\tbhsd.sys [39048 2014-10-09] (RapidSolution Software AG) R3 teamviewervpn; C:\Windows\System32\DRIVERS\teamviewervpn.sys [25088 2013-10-17] (TeamViewer GmbH) S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [44544 2012-09-28] (Apple, Inc.) [Datei ist nicht signiert] R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [83392 2011-10-01] (Acronis) R2 VMMEMCTL; C:\Program Files\Common Files\VMware\Drivers\memctl\vmmemctl.sys [18752 2015-05-22] (VMware, Inc.) R3 vmusbmouse; C:\Windows\System32\DRIVERS\vmusbmouse.sys [11928 2012-10-31] (VMware, Inc.) R0 vsock; C:\Windows\System32\drivers\vsock.sys [64704 2014-11-17] (VMware, Inc.) R2 vstor2-mntapi10-shared; C:\Windows\System32\drivers\vstor2-mntapi10-shared.sys [22768 2011-07-12] (VMware, Inc.) U3 mfeavfk01; kein ImagePath U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-09-03 18:48 - 2015-09-03 18:48 - 00028965 _____ C:\Users\TEMP.SH-PC2.031\Desktop\FRST.txt 2015-09-03 18:47 - 2015-09-03 18:48 - 00000000 ____D C:\FRST 2015-09-03 18:47 - 2015-09-03 18:47 - 01690624 _____ (Farbar) C:\Users\TEMP.SH-PC2.031\Desktop\FRST.exe 2015-09-03 18:47 - 2015-09-03 18:47 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\AppData\Roaming\Avanquest 2015-09-03 17:24 - 2015-09-03 17:24 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\Documents\Snagit 2015-09-03 17:24 - 2015-09-03 17:24 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\AppData\Local\TechSmith 2015-09-03 17:23 - 2015-09-03 18:46 - 00002153 _____ C:\Users\TEMP.SH-PC2.031\Desktop\Google Chrome.lnk 2015-09-03 17:23 - 2015-09-03 17:23 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\AppData\Roaming\Samsung 2015-09-03 17:23 - 2015-09-03 17:23 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\AppData\Roaming\McAfee 2015-09-03 17:23 - 2015-09-03 17:23 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\AppData\Roaming\Logitech 2015-09-03 17:23 - 2015-09-03 17:23 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\AppData\Local\TVEnhance 2015-09-03 17:23 - 2015-09-03 17:23 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\AppData\Local\RapidSolution 2015-09-03 17:22 - 2015-09-03 17:23 - 00159288 _____ C:\Users\TEMP.SH-PC2.031\AppData\Local\GDIPFONTCACHEV1.DAT 2015-09-03 17:22 - 2015-09-03 17:23 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\AppData\Local\Google 2015-09-03 17:22 - 2015-09-03 17:23 - 00000000 ____D C:\Users\TEMP.SH-PC2.031 2015-09-03 17:22 - 2015-09-03 17:22 - 00001381 _____ C:\Users\TEMP.SH-PC2.031\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-09-03 17:22 - 2015-09-03 17:22 - 00000020 ___SH C:\Users\TEMP.SH-PC2.031\ntuser.ini 2015-09-03 17:22 - 2015-09-03 17:22 - 00000000 _SHDL C:\Users\TEMP.SH-PC2.031\Startmenü 2015-09-03 17:22 - 2015-09-03 17:22 - 00000000 _SHDL C:\Users\TEMP.SH-PC2.031\Netzwerkumgebung 2015-09-03 17:22 - 2015-09-03 17:22 - 00000000 _SHDL C:\Users\TEMP.SH-PC2.031\Druckumgebung 2015-09-03 17:22 - 2015-09-03 17:22 - 00000000 _SHDL C:\Users\TEMP.SH-PC2.031\Documents\Eigene Musik 2015-09-03 17:22 - 2015-09-03 17:22 - 00000000 _SHDL C:\Users\TEMP.SH-PC2.031\Documents\Eigene Bilder 2015-09-03 17:22 - 2015-09-03 17:22 - 00000000 _SHDL C:\Users\TEMP.SH-PC2.031\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-09-03 17:22 - 2015-09-03 17:22 - 00000000 _SHDL C:\Users\TEMP.SH-PC2.031\AppData\Local\Verlauf 2015-09-03 17:22 - 2015-09-03 17:22 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\AppData\Roaming\Adobe 2015-09-03 17:22 - 2012-05-07 23:29 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\AppData\LocalGoogle 2015-09-03 17:22 - 2011-12-23 11:31 - 00000000 ___RD C:\Users\TEMP.SH-PC2.031\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-09-03 17:22 - 2011-12-23 11:31 - 00000000 ___RD C:\Users\TEMP.SH-PC2.031\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-09-03 17:22 - 2011-12-23 11:31 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\AppData\Roaming\Macromedia 2015-09-03 17:22 - 2011-12-23 11:31 - 00000000 ____D C:\Users\TEMP.SH-PC2.031\AppData\Local\Microsoft Help 2015-08-31 13:06 - 2015-08-31 13:27 - 00003403 _____ C:\Users\Schwedenhaus\Desktop\Google Chrome.lnk!___prosschiff@gmail.com_.crypt 2015-08-31 13:06 - 2015-08-31 13:06 - 00000000 ____D C:\Users\Schwedenhaus\Documents\CyberLink 2015-08-31 13:06 - 2015-08-31 13:06 - 00000000 ____D C:\updates 2015-08-28 09:08 - 2015-08-28 09:12 - 24327792 _____ C:\Users\Schwedenhaus\Desktop\bu_alphabet_GRUPPEN_FIRMEN_2015-08-27_18-04-02.xml!___prosschiff@gmail.com_.crypt 2015-08-25 22:09 - 2015-08-25 22:09 - 08838771 _____ C:\Users\Schwedenhaus\Downloads\Profildaten-spin-20150825.zip!___prosschiff@gmail.com_.crypt 2015-08-25 22:09 - 2015-08-25 22:09 - 08838771 _____ C:\Users\Schwedenhaus\Downloads\Profildaten-spin-20150825 (1).zip!___prosschiff@gmail.com_.crypt 2015-08-25 16:33 - 2015-08-25 16:33 - 00143350 _____ C:\Users\Schwedenhaus\Desktop\skype-konto.jpg!___prosschiff@gmail.com_.crypt 2015-08-25 16:25 - 2015-08-25 16:26 - 00128305 _____ C:\Users\Schwedenhaus\Desktop\carmen-skype.jpg!___prosschiff@gmail.com_.crypt 2015-08-25 16:23 - 2015-08-25 16:23 - 06550754 _____ C:\Users\Schwedenhaus\Desktop\SkypeWebPlugin.msi!___prosschiff@gmail.com_.crypt 2015-08-25 16:23 - 2015-08-25 16:23 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\SkypePlugin 2015-08-22 11:29 - 2015-08-22 11:29 - 00010459 _____ C:\Users\Schwedenhaus\Desktop\honda-de_garten_hrd_2015_L.pdf!___prosschiff@gmail.com_.crypt 2015-08-22 09:16 - 2015-08-22 09:16 - 01595180 _____ C:\Users\Schwedenhaus\Desktop\Toro-3388-580.pdf!___prosschiff@gmail.com_.crypt 2015-08-20 11:34 - 2015-08-20 11:34 - 00000000 ____D C:\Users\TEMP.SH-PC2.030\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-20 11:34 - 2015-08-20 11:34 - 00000000 ____D C:\Users\TEMP.SH-PC2.030 2015-08-20 09:33 - 2015-08-20 09:33 - 00000000 ____D C:\Users\TEMP.SH-PC2.029 2015-08-20 03:31 - 2015-08-20 03:31 - 00000000 ____D C:\Users\TEMP.SH-PC2.028 2015-08-20 03:00 - 2015-08-11 02:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-08-20 03:00 - 2015-08-11 02:20 - 19871232 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-08-18 18:01 - 2015-08-18 18:01 - 00062215 _____ C:\Users\Schwedenhaus\Downloads\pkeyuibx_v1.5.0.zip!___prosschiff@gmail.com_.crypt 2015-08-14 09:12 - 2015-08-14 09:12 - 00073103 _____ C:\Users\Schwedenhaus\Desktop\bu_alphabet_ALPH_Agraria_2015-08-14_09-11-21.pdf!___prosschiff@gmail.com_.crypt 2015-08-14 08:57 - 2015-08-14 08:57 - 00072877 _____ C:\Users\Schwedenhaus\Desktop\bu_alphabet_ALPH_Agraria_2015-08-14_08-53-02.pdf!___prosschiff@gmail.com_.crypt 2015-08-14 08:19 - 2015-08-30 01:35 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\xsl_Barsoi_20150813 2015-08-14 08:18 - 2015-08-14 08:18 - 00012935 _____ C:\Users\Schwedenhaus\Desktop\xsl_Barsoi_20150813.zip!___prosschiff@gmail.com_.crypt 2015-08-12 07:20 - 2015-08-30 01:59 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-08-12 03:01 - 2015-07-30 15:13 - 00103120 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-08-11 20:44 - 2015-07-30 19:57 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2015-08-11 20:44 - 2015-07-30 19:57 - 01251328 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2015-08-11 20:44 - 2015-07-30 19:57 - 00909824 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2015-08-11 20:44 - 2015-07-30 19:57 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2015-08-11 20:44 - 2015-07-30 19:57 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-08-11 20:44 - 2015-07-30 19:57 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2015-08-11 20:44 - 2015-07-30 19:57 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2015-08-11 20:44 - 2015-07-30 18:52 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-08-11 20:44 - 2015-07-30 18:49 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-08-11 20:44 - 2015-07-28 22:04 - 00015808 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2015-08-11 20:44 - 2015-07-28 22:00 - 00952832 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-08-11 20:44 - 2015-07-28 22:00 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-08-11 20:44 - 2015-07-28 22:00 - 00598528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-08-11 20:44 - 2015-07-28 22:00 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-08-11 20:44 - 2015-07-28 22:00 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-08-11 20:44 - 2015-07-28 22:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-08-11 20:44 - 2015-07-28 21:54 - 00934400 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-08-11 20:44 - 2015-07-21 02:12 - 00342736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-08-11 20:44 - 2015-07-20 19:56 - 02943488 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-08-11 20:44 - 2015-07-20 19:56 - 02061312 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-08-11 20:44 - 2015-07-20 19:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-08-11 20:44 - 2015-07-20 19:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-08-11 20:44 - 2015-07-20 19:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-08-11 20:44 - 2015-07-20 19:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-08-11 20:44 - 2015-07-20 19:56 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-08-11 20:44 - 2015-07-20 19:56 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-08-11 20:44 - 2015-07-20 19:56 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-08-11 20:44 - 2015-07-20 19:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-08-11 20:44 - 2015-07-20 19:56 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-08-11 20:44 - 2015-07-16 22:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-08-11 20:44 - 2015-07-16 21:51 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-08-11 20:44 - 2015-07-16 21:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-08-11 20:44 - 2015-07-16 21:50 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-08-11 20:44 - 2015-07-16 21:50 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-08-11 20:44 - 2015-07-16 21:49 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-08-11 20:44 - 2015-07-16 21:45 - 02279424 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-08-11 20:44 - 2015-07-16 21:43 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-08-11 20:44 - 2015-07-16 21:43 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-08-11 20:44 - 2015-07-16 21:41 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-08-11 20:44 - 2015-07-16 21:39 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-08-11 20:44 - 2015-07-16 21:39 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-08-11 20:44 - 2015-07-16 21:39 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-08-11 20:44 - 2015-07-16 21:38 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-08-11 20:44 - 2015-07-16 21:32 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-08-11 20:44 - 2015-07-16 21:29 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-08-11 20:44 - 2015-07-16 21:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-08-11 20:44 - 2015-07-16 21:20 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-08-11 20:44 - 2015-07-16 21:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-08-11 20:44 - 2015-07-16 21:17 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-08-11 20:44 - 2015-07-16 21:12 - 06131200 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2015-08-11 20:44 - 2015-07-16 21:12 - 04520448 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-08-11 20:44 - 2015-07-16 21:12 - 00856064 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2015-08-11 20:44 - 2015-07-16 21:12 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2015-08-11 20:44 - 2015-07-16 21:10 - 12856832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-08-11 20:44 - 2015-07-16 21:06 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-08-11 20:44 - 2015-07-16 21:06 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-08-11 20:44 - 2015-07-16 21:06 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-08-11 20:44 - 2015-07-16 21:05 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-08-11 20:44 - 2015-07-16 20:42 - 01951232 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-08-11 20:44 - 2015-07-16 20:38 - 01310720 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-08-11 20:44 - 2015-07-16 20:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-08-11 20:44 - 2015-07-16 17:14 - 00355840 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2015-08-11 20:44 - 2015-07-15 19:59 - 03989952 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-08-11 20:44 - 2015-07-15 19:59 - 03934656 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-08-11 20:44 - 2015-07-15 19:59 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-08-11 20:44 - 2015-07-15 19:59 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2015-08-11 20:44 - 2015-07-15 19:59 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-08-11 20:44 - 2015-07-15 19:56 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-08-11 20:44 - 2015-07-15 19:55 - 01159168 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll 2015-08-11 20:44 - 2015-07-15 19:55 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-08-11 20:44 - 2015-07-15 19:55 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-08-11 20:44 - 2015-07-15 19:55 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-08-11 20:44 - 2015-07-15 19:55 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-08-11 20:44 - 2015-07-15 19:55 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-08-11 20:44 - 2015-07-15 19:55 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-08-11 20:44 - 2015-07-15 19:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-08-11 20:44 - 2015-07-15 19:55 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-08-11 20:44 - 2015-07-15 19:54 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-08-11 20:44 - 2015-07-15 19:54 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-08-11 20:44 - 2015-07-15 19:54 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-08-11 20:44 - 2015-07-15 19:54 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-08-11 20:44 - 2015-07-15 19:54 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-08-11 20:44 - 2015-07-15 19:54 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-08-11 20:44 - 2015-07-15 19:54 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-08-11 20:44 - 2015-07-15 19:54 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-08-11 20:44 - 2015-07-15 19:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2015-08-11 20:44 - 2015-07-15 19:54 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-08-11 20:44 - 2015-07-15 19:54 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-08-11 20:44 - 2015-07-15 19:54 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2015-08-11 20:44 - 2015-07-15 19:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-08-11 20:44 - 2015-07-15 19:49 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-08-11 20:44 - 2015-07-15 19:48 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-08-11 20:44 - 2015-07-15 19:44 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-08-11 20:44 - 2015-07-15 19:44 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-08-11 20:44 - 2015-07-15 18:36 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2015-08-11 20:44 - 2015-07-15 18:36 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-08-11 20:44 - 2015-07-15 18:36 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-08-11 20:44 - 2015-07-09 19:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe 2015-08-11 20:44 - 2015-07-09 19:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\notepad.exe 2015-08-11 20:44 - 2015-07-01 22:30 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2015-08-11 20:44 - 2015-07-01 22:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2015-08-11 20:43 - 2015-07-15 04:55 - 01390592 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2015-08-11 20:43 - 2015-07-15 04:55 - 01241088 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2015-08-11 20:43 - 2015-07-15 04:55 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll 2015-08-11 20:43 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2015-08-11 20:43 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2015-08-11 20:43 - 2015-07-10 19:34 - 12875776 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-08-11 20:43 - 2015-05-09 20:09 - 00715200 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll 2015-08-11 15:45 - 2015-08-11 15:45 - 00231843 _____ C:\Users\Schwedenhaus\Desktop\john_deere_js63vc_.pdf!___prosschiff@gmail.com_.crypt 2015-08-11 14:06 - 2015-08-11 14:06 - 00003208 _____ C:\Users\Schwedenhaus\Downloads\plg_admin8_j16_0.9.2.zip!___prosschiff@gmail.com_.crypt ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-09-03 18:40 - 2013-08-06 10:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-09-03 18:25 - 2010-02-07 19:28 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-09-03 17:49 - 2012-05-19 19:44 - 00001172 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789433706-2975812997-1506108583-500UA.job 2015-09-03 17:31 - 2011-12-23 12:13 - 01630814 _____ C:\Windows\system32\PerfStringBackup.INI 2015-09-03 17:31 - 2009-07-14 06:34 - 00025328 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-09-03 17:31 - 2009-07-14 06:34 - 00025328 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-09-03 17:23 - 2011-12-23 10:49 - 00000000 ____D C:\Users\Administrator 2015-09-03 17:23 - 2009-07-14 06:46 - 00001515 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2015-09-03 17:23 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public 2015-09-03 17:23 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration 2015-09-03 17:22 - 2012-11-19 19:42 - 00000000 ____D C:\ProgramData\TwonkyServer 2015-09-03 17:22 - 2012-08-11 23:05 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Mikogo 4 2015-09-03 17:22 - 2011-12-24 09:56 - 00053940 _____ C:\Windows\error.log 2015-09-03 17:22 - 2011-12-24 09:55 - 71915329 _____ C:\Windows\setupact.log 2015-09-03 17:22 - 2011-12-24 09:54 - 00011961 _____ C:\Windows\errord.log 2015-09-03 17:22 - 2011-02-21 09:53 - 00000000 ____D C:\ProgramData\firebird 2015-09-03 17:22 - 2010-10-27 18:49 - 00000000 ____D C:\ProgramData\CyberLink 2015-09-03 17:22 - 2010-08-03 12:19 - 00000000 ____D C:\ProgramData\Wild Media Server 2015-09-03 17:22 - 2010-02-07 19:28 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-09-03 17:22 - 2009-11-21 17:33 - 00000000 ____D C:\ProgramData\NVIDIA 2015-09-03 17:22 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-09-03 17:21 - 2011-12-23 12:01 - 01436966 _____ C:\Windows\WindowsUpdate.log 2015-09-03 11:27 - 2010-07-26 21:50 - 00000000 ____D C:\Program Files\TeamViewer 2015-09-02 19:49 - 2012-05-19 19:44 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789433706-2975812997-1506108583-500Core.job 2015-09-02 17:05 - 2015-07-31 12:16 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\GWX 2015-09-02 16:37 - 2013-08-05 09:56 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\CrashDumps 2015-09-02 15:58 - 2010-10-27 19:10 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\TVEnhance 2015-09-02 07:04 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\system32\FxsTmp 2015-09-01 05:00 - 2014-04-24 12:11 - 00000000 ____D C:\ProgramData\regid.1995-08.com.techsmith 2015-08-31 14:51 - 2011-12-23 10:49 - 00000000 ____D C:\Users\Schwedenhaus 2015-08-31 13:28 - 2011-12-23 21:00 - 00160538 _____ C:\Users\Schwedenhaus\AppData\Local\GDIPFONTCACHEV1.DAT!___prosschiff@gmail.com_.crypt 2015-08-31 13:16 - 2009-07-14 06:41 - 00001528 ___SH C:\Users\Public\Documents\desktop.ini!___prosschiff@gmail.com_.crypt 2015-08-31 13:16 - 2009-07-14 06:41 - 00001424 ___SH C:\Users\Public\desktop.ini!___prosschiff@gmail.com_.crypt 2015-08-31 13:15 - 2011-12-24 00:08 - 00777516 ____H C:\Users\Schwedenhaus\AppData\Local\IconCache.db!___prosschiff@gmail.com_.crypt 2015-08-31 13:06 - 2011-12-23 20:58 - 00001270 ___SH C:\Users\Schwedenhaus\ntuser.ini!___prosschiff@gmail.com_.crypt 2015-08-31 02:00 - 2012-05-19 10:29 - 00000350 _____ C:\Windows\Tasks\Quark Updater.job 2015-08-31 01:06 - 2011-10-05 07:58 - 00000000 ____D C:\ProgramData\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A} 2015-08-30 04:31 - 2013-01-05 15:20 - 00000000 ____D C:\ProgramData\leawo 2015-08-30 03:11 - 2014-10-23 08:55 - 00000000 ____D C:\Utilities 2015-08-30 03:00 - 2015-06-20 10:50 - 00002502 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3086022667-2732812533-850181598-1000UA.job!___prosschiff@gmail.com_.crypt 2015-08-30 02:47 - 2012-10-22 20:42 - 00002206 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3086022667-2732812533-850181598-1000UA.job!___prosschiff@gmail.com_.crypt 2015-08-30 02:26 - 2013-06-13 18:59 - 00000000 ____D C:\Users\Schwedenhaus\wp 2015-08-30 02:26 - 2010-08-19 11:13 - 00000000 ____D C:\Users\Schwedenhaus\ssh 2015-08-30 02:26 - 2010-01-17 11:22 - 00000000 ____D C:\Users\Schwedenhaus\Tracing 2015-08-30 02:24 - 2012-01-20 16:55 - 00000000 ____D C:\Users\Schwedenhaus\ncftp 2015-08-30 02:22 - 2013-02-07 11:16 - 00000000 ____D C:\Users\Schwedenhaus\Joomla-ZIP 2015-08-30 02:17 - 2010-11-25 17:02 - 00000000 ____D C:\Users\Administrator\ssh 2015-08-30 02:17 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Libraries 2015-08-30 02:16 - 2014-09-22 20:21 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Web-Sniffer 2015-08-30 02:16 - 2014-01-09 12:45 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\WatchTVProEx 2015-08-30 02:16 - 2013-11-06 11:53 - 00000000 ____D C:\Users\Administrator\Desktop\mbar 2015-08-30 02:16 - 2012-11-19 19:42 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\TwonkyServer 2015-08-30 02:16 - 2011-06-21 15:30 - 00000000 ____D C:\Users\Administrator\Desktop\FW_RT_N56U_1014 2015-08-30 02:16 - 2011-04-15 15:55 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\VMware 2015-08-30 02:16 - 2011-03-26 16:45 - 00000000 ____D C:\Users\Administrator\Documents\Add-in Express 2015-08-30 02:16 - 2010-12-04 19:45 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\vlc 2015-08-30 02:16 - 2010-11-18 11:09 - 00000000 ____D C:\Users\Administrator\Documents\PhoenixRC 2015-08-30 02:16 - 2010-09-09 11:41 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\skypePM 2015-08-30 02:16 - 2010-09-09 11:40 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Skype 2015-08-30 02:16 - 2010-08-22 16:19 - 00000000 ____D C:\Users\Administrator\Documents\Snagit 2015-08-30 02:16 - 2010-08-17 10:51 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\WinRAR 2015-08-30 02:16 - 2010-08-17 09:47 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Subversion 2015-08-30 02:16 - 2010-08-05 18:51 - 00000000 ____D C:\Users\Administrator\Desktop\tsmuxer 2015-08-30 02:16 - 2010-08-04 12:53 - 00000000 ____D C:\Users\Administrator\Desktop\vobmerge-2.51 2015-08-30 02:16 - 2010-08-03 12:18 - 00000000 ____D C:\Users\Administrator\Documents\WMS.1_04_7 2015-08-30 02:16 - 2010-07-31 22:06 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Winamp 2015-08-30 02:16 - 2010-07-28 21:36 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\TeamViewer 2015-08-30 02:16 - 2010-07-11 16:09 - 00000000 ____D C:\Users\Administrator\ModuleStudio 2015-08-30 02:16 - 2010-05-08 13:12 - 00000000 ____D C:\Users\Administrator\Desktop\JavaRa115 2015-08-30 02:16 - 2009-12-30 15:17 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\ZoomBrowser EX 2015-08-30 02:15 - 2014-03-13 15:17 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\hbide 2015-08-30 02:15 - 2014-01-31 10:36 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Notepad++ 2015-08-30 02:15 - 2014-01-09 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\WinZip 2015-08-30 02:15 - 2014-01-09 13:06 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\IPTVClient 2015-08-30 02:15 - 2013-12-28 13:03 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\mRemoteNG 2015-08-30 02:15 - 2013-12-28 13:03 - 00000000 ____D C:\Users\Administrator\AppData\Local\mRemoteNG 2015-08-30 02:15 - 2013-01-05 15:16 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\com.leawo.imediago 2015-08-30 02:15 - 2012-05-28 12:15 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\it4vet 2015-08-30 02:15 - 2011-12-23 10:49 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-08-30 02:15 - 2011-12-23 10:49 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-30 02:15 - 2011-12-21 18:17 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cisco ASDM 2015-08-30 02:15 - 2011-12-17 13:20 - 00000000 ____D C:\Users\Administrator\AppData\Local\NPE 2015-08-30 02:15 - 2011-04-15 15:55 - 00000000 ____D C:\Users\Administrator\AppData\Local\VMware 2015-08-30 02:15 - 2011-02-23 16:00 - 00000000 ____D C:\Users\Administrator\AppData\Local\Windows Live 2015-08-30 02:15 - 2011-01-11 17:34 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ModuleStudio 2015-08-30 02:15 - 2010-12-04 16:27 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Softerra LDAP Browser 2.6 2015-08-30 02:15 - 2010-11-25 16:41 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\dvdcss 2015-08-30 02:15 - 2010-10-27 19:50 - 00000000 ____D C:\Users\Administrator\AppData\Local\TVEnhance 2015-08-30 02:15 - 2010-08-17 10:51 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-08-30 02:15 - 2010-08-03 00:09 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\foobar2000 2015-08-30 02:15 - 2010-08-01 16:48 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\albumart 2015-08-30 02:15 - 2010-08-01 11:18 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\AccurateRip 2015-08-30 02:15 - 2010-07-31 22:08 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2015-08-30 02:14 - 2010-08-03 11:22 - 00000000 ____D C:\Users\Administrator\AppData\Local\MediaMonkey 2015-08-30 02:13 - 2015-06-05 07:17 - 00000000 ____D C:\Users\Administrator\.ebookreader 2015-08-30 02:13 - 2014-12-16 22:40 - 00000000 __SHD C:\Users\Administrator\AppData\Local\EmieBrowserModeList 2015-08-30 02:13 - 2014-09-06 18:36 - 00000000 ____D C:\Users\Administrator\AppData\Local\Akamai 2015-08-30 02:13 - 2014-09-06 17:36 - 00000000 __SHD C:\Users\Administrator\AppData\Local\EmieUserList 2015-08-30 02:13 - 2014-09-06 17:36 - 00000000 __SHD C:\Users\Administrator\AppData\Local\EmieSiteList 2015-08-30 02:13 - 2014-07-18 14:15 - 00000000 ____D C:\Users\Administrator\.ZendStudio 2015-08-30 02:13 - 2014-07-07 14:21 - 00000000 ____D C:\Users\Administrator\.nbi 2015-08-30 02:13 - 2013-11-21 09:53 - 00000000 ____D C:\Users\Administrator\AppData\Local\CrashDumps 2015-08-30 02:13 - 2012-05-28 12:15 - 00000000 ____D C:\Users\Administrator\.it4vet 2015-08-30 02:13 - 2011-05-31 08:51 - 00000000 ____D C:\Temp 2015-08-30 02:09 - 2013-11-01 12:41 - 00000000 ____D C:\ProgramData\WinZip 2015-08-30 02:09 - 2013-09-17 14:24 - 00000000 ____D C:\ProgramData\WebEx 2015-08-30 02:09 - 2012-04-23 10:01 - 00000000 ____D C:\schrott 2015-08-30 02:09 - 2009-12-21 10:15 - 00000000 ____D C:\ProgramData\Vodafone 2015-08-30 02:08 - 2014-03-25 11:29 - 00000000 ____D C:\ProgramData\TEMP 2015-08-30 02:08 - 2014-03-08 12:23 - 00000000 ____D C:\ProgramData\VetStar-Bestellprogramm 2015-08-30 02:08 - 2012-08-13 12:11 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2015-08-30 02:08 - 2012-05-19 10:26 - 00000000 ____D C:\ProgramData\Quark 2015-08-30 02:08 - 2011-12-09 12:34 - 00000000 ____D C:\ProgramData\SPEXBOX 2015-08-30 02:07 - 2014-03-25 11:29 - 00000000 ____D C:\ProgramData\Licenses 2015-08-30 02:07 - 2010-11-12 21:54 - 00000000 ____D C:\ProgramData\Lexware 2015-08-30 02:07 - 2010-01-19 19:00 - 00000000 ____D C:\ProgramData\FLEXnet 2015-08-30 02:04 - 2014-08-11 19:22 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\UNZIP-FIRST-SOCIALIZE (2) 2015-08-30 02:04 - 2013-10-06 10:26 - 00000000 ___RD C:\Users\Schwedenhaus\Dropbox 2015-08-30 02:04 - 2013-03-13 10:51 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\WebShadow 2015-08-30 02:04 - 2012-05-02 15:59 - 00000000 ___RD C:\Users\Schwedenhaus\Google Drive 2015-08-30 02:04 - 2011-10-13 16:26 - 00000000 ____D C:\Users\Schwedenhaus\git 2015-08-30 02:03 - 2015-06-08 08:56 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\kindle-advanced-template 2015-08-30 02:03 - 2014-11-24 10:46 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\mod_vina_ticker_rss_UNZIP_FIRST 2015-08-30 02:03 - 2014-07-17 07:22 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\UNZIP-FIRST-JomSocial Professional (1) 2015-08-30 02:03 - 2014-07-09 18:38 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\pri_simple_quickstart_v2.1_j3 2015-08-30 02:03 - 2014-07-09 16:25 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\pri_simple_template_only_v2.2_j3_unzip 2015-08-30 02:03 - 2014-06-29 13:03 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\memtest86-iso 2015-08-30 02:03 - 2014-05-23 13:43 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\plg_simpledisqus_UNZIPFIRST 2015-08-30 02:02 - 2015-06-08 09:23 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\how_to_make_kindle_comics___children_s_books 2015-08-30 02:02 - 2015-04-22 12:31 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\Anhänge_2015422 2015-08-30 02:02 - 2015-02-04 15:52 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\chhange_files 2015-08-30 02:02 - 2014-11-22 16:45 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\iperf-2.0.5-2-win32 2015-08-30 02:02 - 2014-11-13 20:48 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\1810G-Software-P0212 2015-08-30 02:02 - 2014-09-12 16:40 - 00000000 ____D C:\Users\Schwedenhaus\Documents\Scan 2015-08-30 02:02 - 2014-08-26 08:09 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\com_rsblog_2.5-3.x (3) 2015-08-30 02:02 - 2014-07-31 13:21 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\fix 2015-08-30 02:02 - 2014-07-09 12:52 - 00000000 ____D C:\Users\Schwedenhaus\Downloads\com_virtuemart.2.9.8_extract_first 2015-08-30 02:02 - 2013-11-05 14:11 - 00000000 ____D C:\Users\Schwedenhaus\Documents\test 2015-08-30 02:02 - 2013-11-05 14:11 - 00000000 ____D C:\Users\Schwedenhaus\Documents\src 2015-08-30 02:02 - 2012-07-13 08:25 - 00000000 ____D C:\Users\Schwedenhaus\Documents\SoftMaker 2015-08-30 02:02 - 2011-04-27 15:28 - 00000000 ____D C:\Users\Schwedenhaus\Documents\OneNote-Notizbücher 2015-08-30 02:02 - 2010-08-21 16:19 - 00000000 ____D C:\Users\Schwedenhaus\Documents\Snagit 2015-08-30 02:01 - 2015-06-02 20:41 - 00000000 ____D C:\Users\Schwedenhaus\Documents\Calibre-Bibliothek 2015-08-30 02:01 - 2015-01-21 10:25 - 00000000 ____D C:\Users\Schwedenhaus\Documents\jAnrufmonitor 2015-08-30 02:01 - 2014-10-01 12:34 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Web-Sniffer 2015-08-30 02:01 - 2014-01-09 12:46 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\WatchTVProEx 2015-08-30 02:01 - 2013-11-19 10:27 - 00000000 ____D C:\Users\Schwedenhaus\Batch 2015-08-30 02:01 - 2013-11-05 14:11 - 00000000 ____D C:\Users\Schwedenhaus\Documents\lib 2015-08-30 02:01 - 2013-11-05 14:11 - 00000000 ____D C:\Users\Schwedenhaus\Documents\doc 2015-08-30 02:01 - 2013-11-05 14:11 - 00000000 ____D C:\Users\Schwedenhaus\Documents\demo 2015-08-30 02:01 - 2013-11-05 14:11 - 00000000 ____D C:\Users\Schwedenhaus\Documents\bin 2015-08-30 02:01 - 2013-11-01 12:41 - 00000000 ____D C:\Users\Schwedenhaus\Documents\Add-in Express 2015-08-30 02:01 - 2013-10-24 16:21 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Thunderbird 2015-08-30 02:01 - 2013-10-10 16:13 - 00000000 ____D C:\Users\Schwedenhaus\Documents\Inno Setup Examples Output 2015-08-30 02:01 - 2013-09-17 14:25 - 00000000 __SHD C:\Users\Schwedenhaus\Documents\cache 2015-08-30 02:01 - 2011-11-01 22:40 - 00000000 ____D C:\Users\Schwedenhaus\Documents\Decrypt Output 2015-08-30 02:01 - 2011-11-01 22:01 - 00000000 ____D C:\Users\Schwedenhaus\Documents\My Digital Editions 2015-08-30 02:01 - 2011-09-04 14:21 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\XnView 2015-08-30 02:01 - 2011-07-11 17:17 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\vlc 2015-08-30 02:01 - 2011-06-22 18:48 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Software Informer 2015-08-30 02:01 - 2011-04-15 17:53 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\VMware 2015-08-30 02:01 - 2010-09-12 09:34 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Stereoscopic Player CHIP Edition 2015-08-30 02:01 - 2010-08-24 15:59 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\WinRAR 2015-08-30 02:01 - 2010-08-02 23:20 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\PMS 2015-08-30 02:01 - 2010-07-31 23:28 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Winamp 2015-08-30 02:01 - 2010-07-27 09:14 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\TeamViewer 2015-08-30 02:01 - 2010-05-30 19:00 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Subversion 2015-08-30 02:01 - 2009-12-30 20:29 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\ZoomBrowser EX 2015-08-30 02:01 - 2009-12-02 11:23 - 00000000 ___SD C:\Users\Schwedenhaus\Documents\Meine Shapes 2015-08-30 02:01 - 2009-11-25 10:28 - 00000000 ____D C:\Users\Schwedenhaus\Documents\Fiddler2 2015-08-30 02:01 - 2009-11-22 21:11 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\skypePM 2015-08-30 02:01 - 2009-11-22 21:05 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Skype 2015-08-30 02:00 - 2014-02-06 09:05 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Notepad++ 2015-08-30 01:59 - 2015-01-21 10:25 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\jAnrufmonitor 5.0 2015-08-30 01:59 - 2014-07-07 14:29 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\NetBeans 2015-08-30 01:59 - 2014-03-13 15:01 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\hbide 2015-08-30 01:59 - 2014-03-13 14:24 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Harbour Project 3.0 2015-08-30 01:59 - 2014-01-10 09:11 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\mRemoteNG 2015-08-30 01:59 - 2014-01-09 13:13 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\IPTVClient 2015-08-30 01:59 - 2013-10-08 09:21 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub, Inc 2015-08-30 01:59 - 2013-10-08 09:21 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\GitHub 2015-08-30 01:59 - 2013-10-06 10:24 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Dropbox 2015-08-30 01:59 - 2013-09-30 08:20 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-08-30 01:59 - 2013-07-31 15:37 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Free Monitor for Google 2015-08-30 01:59 - 2013-05-13 18:24 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\mresreg 2015-08-30 01:59 - 2013-04-21 11:58 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Barsoi System 2015-08-30 01:59 - 2013-03-09 03:47 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook 2015-08-30 01:59 - 2013-02-13 20:23 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kplus Warenwirtschaft 2015-08-30 01:59 - 2012-12-10 15:16 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HHD Hex Editor Neo 2015-08-30 01:59 - 2012-07-06 22:18 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\iSpy 2015-08-30 01:59 - 2012-03-27 19:11 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\gtk-2.0 2015-08-30 01:59 - 2012-01-20 16:41 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\FileZilla 2015-08-30 01:59 - 2011-12-23 10:49 - 00000000 ___RD C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-08-30 01:59 - 2011-12-23 10:49 - 00000000 ___RD C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-30 01:59 - 2011-11-13 18:08 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2015-08-30 01:59 - 2011-07-29 15:46 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cisco ASDM 2015-08-30 01:59 - 2011-07-26 13:34 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cisco ASDM-IDM Launcher 2015-08-30 01:59 - 2011-03-17 17:12 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\MySQL 2015-08-30 01:59 - 2010-08-18 08:38 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\dvdcss 2015-08-30 01:59 - 2010-08-02 16:02 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\foobar2000 2015-08-30 01:59 - 2010-05-27 12:54 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Softerra LDAP Browser 2.6 2015-08-30 01:58 - 2015-06-02 20:41 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\calibre 2015-08-30 01:58 - 2013-01-05 15:25 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\com.leawo.imediago 2015-08-30 01:58 - 2011-08-25 11:32 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\com.oxygenxml 2015-08-30 01:51 - 2015-03-03 14:50 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\WinZip 2015-08-30 01:51 - 2012-01-11 03:10 - 00000000 __SHD C:\Users\Schwedenhaus\AppData\Local\{260ac5b2-4a2b-bcc4-06d5-f6e96ab7e2d5} 2015-08-30 01:51 - 2011-12-09 12:33 - 00000000 ____D C:\Program Files\SPEXClient 2015-08-30 01:51 - 2011-04-15 17:53 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\VMware 2015-08-30 01:51 - 2011-02-24 11:17 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\Windows Live 2015-08-30 01:51 - 2010-12-05 14:35 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\albumart 2015-08-30 01:51 - 2010-07-31 20:54 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Roaming\AccurateRip 2015-08-30 01:51 - 2009-11-21 14:35 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\VirtualStore 2015-08-30 01:50 - 2010-08-01 11:19 - 00000000 ____D C:\Program Files\REACT2 2015-08-30 01:49 - 2014-03-23 14:35 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\True BoxShot 2015-08-30 01:49 - 2010-06-08 16:42 - 00000000 ____D C:\Program Files\PixiePack Codec Pack 2015-08-30 01:49 - 2010-06-08 11:27 - 00000000 ____D C:\Program Files\Opera 2015-08-30 01:45 - 2012-03-20 00:19 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\Tango 2015-08-30 01:43 - 2015-06-05 07:16 - 00000000 ____D C:\Program Files\Icecream Ebook Reader 2015-08-30 01:42 - 2014-01-10 09:11 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\mRemoteNG 2015-08-30 01:42 - 2009-12-01 19:11 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\Microsoft Help 2015-08-30 01:41 - 2011-08-23 17:13 - 00000000 ____D C:\Program Files\Easy XML Editor 2015-08-30 01:40 - 2015-01-17 14:53 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\LogMeInIgnition 2015-08-30 01:40 - 2015-01-17 14:53 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\LogMeIn Client 2015-08-30 01:40 - 2011-12-15 16:02 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\gtk-2.0 2015-08-30 01:38 - 2013-10-08 09:21 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\GitHub 2015-08-30 01:37 - 2015-06-02 20:42 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\calibre-cache 2015-08-30 01:37 - 2015-01-21 10:25 - 00000000 ____D C:\jAnrufmonitor 2015-08-30 01:37 - 2014-03-13 14:23 - 00000000 ____D C:\hb30 2015-08-30 01:37 - 2012-01-04 12:47 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\DOSBox 2015-08-30 01:36 - 2010-12-07 18:57 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\Apple Computer 2015-08-30 01:35 - 2015-06-07 08:13 - 00000000 ____D C:\Users\Schwedenhaus\.kindle 2015-08-30 01:35 - 2015-02-07 13:48 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\XSLT-Test 2015-08-30 01:35 - 2014-08-30 16:20 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\torsten.egeler_add_gmail.com 2015-08-30 01:35 - 2013-11-26 19:40 - 00000000 ____D C:\Users\Schwedenhaus\.gimp-2.8 2015-08-30 01:35 - 2013-10-08 09:24 - 00000000 ____D C:\Users\Schwedenhaus\.ssh 2015-08-30 01:35 - 2013-08-07 16:48 - 00000000 ____D C:\Users\Schwedenhaus\5BCC634A58AD42F9B3C62EA52F81CF85.TMP 2015-08-30 01:35 - 2013-03-29 15:50 - 00000000 ____D C:\Users\Schwedenhaus\.ZendStudio 2015-08-30 01:35 - 2013-03-29 12:47 - 00000000 ____D C:\Users\Schwedenhaus\.zend 2015-08-30 01:35 - 2011-12-15 15:49 - 00000000 ____D C:\Users\Schwedenhaus\.zenmap 2015-08-30 01:35 - 2011-08-23 17:41 - 00000000 ____D C:\Users\Schwedenhaus\.xmldog 2015-08-30 01:34 - 2013-10-09 07:42 - 00000000 ____D C:\easyVETDemoversion 2015-08-30 01:34 - 2012-03-27 19:09 - 00000000 ____D C:\Users\Schwedenhaus\.gimp-2.6 2015-08-30 01:33 - 2015-04-15 17:10 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\PHPExcel-develop 2015-08-30 01:33 - 2014-01-31 10:15 - 00000000 ____D C:\bldat 2015-08-30 01:33 - 2013-04-23 16:23 - 00000000 ____D C:\bldat_sic 2015-08-30 01:33 - 2013-04-23 15:37 - 00000000 ____D C:\Datensicherung 2015-08-30 01:33 - 2012-08-03 09:01 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\mod_rsblog_tags 2015-08-30 01:33 - 2010-12-09 10:21 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\iWebKit5.04 2015-08-30 01:32 - 2015-01-07 09:41 - 00000000 ____D C:\barsoiliste 2015-08-30 01:32 - 2014-12-15 18:35 - 00000000 ____D C:\AdwCleaner 2015-08-30 01:32 - 2013-10-08 19:12 - 00000000 ____D C:\ARJ 2015-08-30 01:32 - 2012-06-25 09:39 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\haus 2015-08-30 01:25 - 2015-06-05 07:17 - 00000000 ____D C:\Users\Schwedenhaus\.ebookreader 2015-08-30 01:25 - 2014-07-28 15:51 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\greenville-2014 2015-08-30 01:25 - 2011-08-23 17:13 - 00000000 ____D C:\Users\Schwedenhaus\.easyxmleditor 2015-08-30 01:24 - 2015-02-04 15:51 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\chhange_files 2015-08-30 01:24 - 2014-11-25 19:05 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\Bilder für Präsentation 2015-08-30 01:24 - 2014-08-25 13:17 - 00000000 ____D C:\Users\Schwedenhaus\.ausweisapp 2015-08-30 01:24 - 2014-05-25 12:59 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\ccomment 2015-08-30 01:24 - 2013-10-10 16:25 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\barsoi-install 2015-08-30 01:24 - 2011-03-04 00:31 - 00000000 ____D C:\Users\Schwedenhaus\AppData\Local\{F5552CE3-9802-4CE0-9826-10C7A8A00F93} 2015-08-30 01:24 - 2010-08-24 15:59 - 00000000 ____D C:\Users\Schwedenhaus\Desktop\cssviewer-1.0.3-fx 2015-08-30 01:00 - 2015-06-20 10:50 - 00002450 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3086022667-2732812533-850181598-1000Core.job!___prosschiff@gmail.com_.crypt 2015-08-29 20:47 - 2012-10-22 20:42 - 00002184 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3086022667-2732812533-850181598-1000Core.job!___prosschiff@gmail.com_.crypt 2015-08-28 09:36 - 2009-11-21 14:54 - 00003600 ____H C:\Users\Schwedenhaus\Documents\Default.rdp!___prosschiff@gmail.com_.crypt 2015-08-27 16:47 - 2012-01-05 13:07 - 00001850 _____ C:\Users\Schwedenhaus\AppData\Local\PUTTY.RND!___prosschiff@gmail.com_.crypt 2015-08-20 03:18 - 2012-01-03 08:48 - 00962670 _____ C:\Windows\PFRO.log 2015-08-18 14:21 - 2012-05-02 15:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2015-08-17 13:24 - 2014-12-08 09:56 - 00012274 _____ C:\Windows\system32\TeamViewer10_Hooks.log 2015-08-17 13:24 - 2014-11-12 08:47 - 00000889 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2015-08-12 16:40 - 2012-05-02 12:51 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-08-12 16:40 - 2011-06-21 16:16 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-08-12 07:19 - 2011-12-23 21:00 - 00001588 ___SH C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini!___prosschiff@gmail.com_.crypt 2015-08-12 07:19 - 2009-11-21 14:36 - 00001652 ___SH C:\Users\Schwedenhaus\Documents\desktop.ini!___prosschiff@gmail.com_.crypt 2015-08-12 07:19 - 2009-11-21 14:36 - 00001532 ___SH C:\Users\Schwedenhaus\Downloads\desktop.ini!___prosschiff@gmail.com_.crypt 2015-08-12 07:19 - 2009-11-21 14:36 - 00001532 ___SH C:\Users\Schwedenhaus\Desktop\desktop.ini!___prosschiff@gmail.com_.crypt 2015-08-12 07:19 - 2009-11-21 14:36 - 00001424 ___SH C:\Users\Schwedenhaus\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini!___prosschiff@gmail.com_.crypt 2015-08-12 04:11 - 2013-12-12 05:10 - 00000000 ____D C:\Windows\rescache 2015-08-12 03:40 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2015-08-12 03:34 - 2009-07-14 06:33 - 03919080 _____ C:\Windows\system32\FNTCACHE.DAT 2015-08-12 03:33 - 2014-12-11 04:24 - 00000000 ____D C:\Windows\system32\appraiser 2015-08-12 03:33 - 2014-05-07 03:00 - 00000000 ___SD C:\Windows\system32\CompatTel 2015-08-12 03:33 - 2009-11-22 13:53 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2015-08-12 03:33 - 2009-07-14 10:47 - 00000000 ____D C:\Windows\system32\Drivers\de-DE 2015-08-12 03:33 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2015-08-12 03:17 - 2009-12-02 11:17 - 00000039 _____ C:\Windows\vbaddin.ini 2015-08-12 03:17 - 2009-11-24 13:09 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-08-12 03:16 - 2010-06-04 00:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-08-12 03:13 - 2013-07-13 03:01 - 00000000 ____D C:\Windows\system32\MRT 2015-08-12 03:04 - 2011-12-23 13:59 - 129304528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2012-11-19 19:41 - 2012-11-19 19:41 - 0000011 _____ () C:\ProgramData\.tv7 2012-11-19 19:41 - 2012-11-19 19:41 - 0001261 _____ () C:\ProgramData\.tv7!___prosschiff@gmail.com_.crypt Einige Dateien in TEMP: ==================== C:\Users\Administrator\AppData\Local\Temp\AQOle32.dll C:\Users\Administrator\AppData\Local\Temp\AQShell32.dll C:\Users\Administrator\AppData\Local\Temp\sqlite3.dll C:\Users\Schwedenhaus\AppData\Local\Temp\AQOle32.dll C:\Users\Schwedenhaus\AppData\Local\Temp\AQShell32.dll C:\Users\Schwedenhaus\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpaha7eg.dll C:\Users\Schwedenhaus\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpftkflc.dll C:\Users\Schwedenhaus\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpg5zo3o.dll C:\Users\Schwedenhaus\AppData\Local\Temp\sqlite3.dll C:\Users\Schwedenhaus\AppData\Local\Temp\swt-gdip-win32-3452.dll C:\Users\Schwedenhaus\AppData\Local\Temp\swt-win32-3452.dll C:\Users\TEMP.SH-PC2.031\AppData\Local\Temp\AQOle32.dll C:\Users\TEMP.SH-PC2.031\AppData\Local\Temp\AQShell32.dll ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-08-22 00:25 ==================== Ende vom FRST.txt ============================ |
03.09.2015, 17:53 | #4 |
| AdditionCode:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x86) Version:31-08-2015 durchgeführt von Administrator (2015-09-03 18:48:58) Gestartet von C:\Users\TEMP.SH-PC2.031\Desktop Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3086022667-2732812533-850181598-500 - Administrator - Enabled) => C:\Users\TEMP.SH-PC2.031 Gast (S-1-5-21-3086022667-2732812533-850181598-501 - Limited - Disabled) McAfeeMVSUser (S-1-5-21-3086022667-2732812533-850181598-1008 - Limited - Enabled) Schwedenhaus (S-1-5-21-3086022667-2732812533-850181598-1000 - Limited - Enabled) => C:\Users\Schwedenhaus UpdatusUser (S-1-5-21-3086022667-2732812533-850181598-1004 - Limited - Enabled) ZendUser (S-1-5-21-3086022667-2732812533-850181598-1007 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: McAfee® Security-as-a-Service (Disabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AS: McAfee® Security-as-a-Service (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: McAfee® Security-as-a-Service (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 32 Bit HP CIO Components Installer (Version: 4.1.1 - Hewlett-Packard) Hidden Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated) Adobe Digital Editions (HKLM\...\Digital Editions) (Version: - ) Adobe Download Assistant (HKLM\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.2 - Adobe Systems Incorporated) Adobe Flash Player 18 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated) Adobe Help Manager (HKLM\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM\...\Adobe Shockwave Player) (Version: 12.0.3.133 - Adobe Systems, Inc.) ASIO4ALL (HKLM\...\ASIO4ALL) (Version: 2.10 - Michael Tippach) Audials (HKLM\...\{09D4C640-29A0-46B1-861C-E4CE7D78C3FC}) (Version: 12.0.49004.400 - Audials AG) Audials (HKLM\...\{8E877E95-E7B8-4722-9490-732E9DBBA068}) (Version: 9.0.52604.400 - RapidSolution Software AG) Audials TV (HKLM\...\{24EE4523-711A-4BD1-95EA-F73A8A6950D3}) (Version: 1.3.10803.300 - RapidSolution Software AG) AudialsOne (HKLM\...\{30406D09-0004-4CFA-AB4C-12E30D40C960}) (Version: 4.2.13600.0 - RapidSolution Software AG) AusweisApp (HKLM\...\{BA6CDB7A-F5D7-4341-99E1-1FF0AAEAF1D8}) (Version: 1.13.0 - OpenLimit SignCubes AG) AXIS Camera Management 2.00 (HKLM\...\{89FB030B-05F9-4421-9D90-8FF2BBA70FE7}_is1) (Version: 2.00.031 - Axis Communications) AXIS Camera Management 4.00 (HKLM\...\{DB5112F7-9C59-4cc0-B10F-119FE07D38E8}_is1) (Version: 4.00.070 - Axis Communications AB) AXIS Media Control Embedded (HKLM\...\AXIS Media Control Embedded) (Version: - ) AXIS Media Control Embedded Installer (HKLM\...\{7DA53C94-5B97-4475-A14B-7BDB31D83C5D}) (Version: 5.9.90 - Axis Communications) BARSOI LISTE Version 1.3.1.1 (HKLM\...\barsoi_liste_preisliste_is1) (Version: 1.3.1.1 - ) Benutzerhandbuch anzeigen (HKLM\...\View User Guide) (Version: 3.60.02.0 - ) Bitvise SSH Client 4.62 (remove only) (HKLM\...\BvSshClient) (Version: - ) calibre (HKLM\...\{D28D6EE4-3319-49B7-BEE5-1D5B2AC3FF30}) (Version: 2.30.0 - Kovid Goyal) CANON iMAGE GATEWAY MyCamera Download Plugin (HKLM\...\MyCamera Download Plugin) (Version: 3.1.0.1 - Canon Inc.) CANON iMAGE GATEWAY Task for ZoomBrowser EX (HKLM\...\CANON iMAGE GATEWAY Task) (Version: 1.8.0.1 - Canon Inc.) Canon Internet Library for ZoomBrowser EX (HKLM\...\Canon Internet Library for ZoomBrowser EX) (Version: 1.7.0.1 - Canon Inc.) Canon MOV Decoder (HKLM\...\Canon MOV Decoder) (Version: 1.7.0.6 - Canon Inc.) Canon MOV Encoder (HKLM\...\Canon MOV Encoder) (Version: 1.5.0.3 - Canon Inc.) Canon MovieEdit Task for ZoomBrowser EX (HKLM\...\MovieEditTask) (Version: 3.6.0.5 - Canon Inc.) Canon Pro9500 Mark II series Benutzerregistrierung (HKLM\...\Canon Pro9500 Mark II series Benutzerregistrierung) (Version: - ) Canon RAW Codec (HKLM\...\Canon RAW Codec) (Version: 1.8.0.68 - Canon Inc.) Canon Utilities CameraWindow (HKLM\...\CameraWindowLauncher) (Version: 7.4.0.7 - Canon Inc.) Canon Utilities CameraWindow DC (HKLM\...\CameraWindowDC) (Version: 7.4.1.10 - Canon Inc.) Canon Utilities CameraWindow DC 8 (HKLM\...\CameraWindowDC8) (Version: 8.1.0.11 - Canon Inc.) Canon Utilities Digital Photo Professional 3.9 (HKLM\...\DPP) (Version: 3.9.2.0 - Canon Inc.) Canon Utilities EOS Capture 1.5 (HKLM\...\InstallShield_{589D17BB-C997-48C0-BCD2-CC8DC3375FE8}) (Version: 1.5 - Canon) Canon Utilities EOS Utility (HKLM\...\EOS Utility) (Version: 2.7.3.0 - Canon Inc.) Canon Utilities MyCamera (HKLM\...\MyCamera) (Version: 7.3.0.5 - Canon Inc.) Canon Utilities ZoomBrowser EX (HKLM\...\ZoomBrowser EX) (Version: 6.6.0.23 - Canon Inc.) Canon ZoomBrowser EX Memory Card Utility (HKLM\...\ZoomBrowser EX Memory Card Utility) (Version: 1.4.0.4 - Canon Inc.) catforDocs WDT-Bestellprogramm (HKLM\...\{E2B8FD92-DE62-4EC8-9DDE-11880715050A}) (Version: 6.0.9 - WDT) CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4291 - CDBurnerXP) CDDRV_Installer (Version: 4.60 - Logitech) Hidden Cidero UPnP Applications 1.5.3 (HKLM\...\Cidero UPnP Applications 1.5.3) (Version: - Cidero) Cisco ASDM-IDM Launcher (HKLM\...\{15B5EA64-525A-4146-A3E9-0A369E9575B9}) (Version: 1.5.49 - Cisco Systems, Inc.) Common Desktop Agent (Version: 1.62.0 - OEM) Hidden CyberLink TV Enhance (HKLM\...\{E4C891D6-6844-41B8-86E8-633CACCC644F}) (Version: 1.5.5730 - CyberLink Corp.) devolo dLAN Cockpit (HKLM\...\dlancockpit) (Version: 3.2.0.0 - devolo AG) devolo dLAN TV Sat (HKLM\...\dlanavdvbs) (Version: 1.1 - devolo AG) devolo dLAN-Konfigurationsassistent (HKLM\...\dlanconf) (Version: 20.0.0.0 - devolo AG) devolo Informer (HKLM\...\dslmon) (Version: 28.0.0.0 - devolo AG) dLAN Cockpit (Version: 3.2.28 - devolo AG) Hidden DVDFab 8.0.8.5 (19/03/2011) (HKLM\...\DVDFab 8_is1) (Version: - Fengtao Software Inc.) Easy Extract Icon v1.3.0 (HKLM\...\Easy Extract Icon_is1) (Version: 1.3.0 - Abacre, Inc.) Easy XML Editor 1.7 (HKLM\...\Easy XML Editor_is1) (Version: - hxxp://www.easy-xml-editor.de) Easy2Sync für Dateien 1.43 (HKLM\...\{EF327022-B623-4B6A-C41D-411720425583}_is1) (Version: 1.43 - ITSTH) EncFlac 1.1.2 (HKLM\...\EncFlac) (Version: 1.1.2 - Michael Facquet) EOS Capture 1.5 (Version: 1.5 - Canon) Hidden EOS USB WIA Driver (HKLM\...\EOS USB WIA Driver) (Version: 6.0.0.4 - ) erLT (Version: 1.20.0137 - Logitech, Inc.) Hidden EventLog Inspector 3 (HKLM\...\{5EB95582-E14F-4371-9FE4-5E74894C51BD}) (Version: 3.1.0 - SnmpSoft Company) Exact Audio Copy 1.0beta1 (HKLM\...\Exact Audio Copy) (Version: 1.0beta1 - Andre Wiethoff) Facebook Messenger 2.1.4814.0 (HKLM\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook) Feedanzeige für Windows SideShow (HKLM\...\{E4DA04B6-3EC4-4DFD-A14E-44959EF36D5B}) (Version: 1.0.7252.0 - Microsoft Corporation) Feedback Tool (HKLM\...\{13A5E785-5197-4EAD-8EE3-D660271E49BC}) (Version: 1.2.0 - Microsoft Corporation) ffdshow [rev 3154] [2009-12-09] (HKLM\...\ffdshow_is1) (Version: 1.0 - ) FileZilla Client 3.8.1 (HKLM\...\FileZilla Client) (Version: 3.8.1 - Tim Kosse) FLAC 1.2.1b (remove only) (HKLM\...\FLAC) (Version: 1.2.1b - Xiph.org) foobar2000 v1.1.1 (HKLM\...\foobar2000) (Version: 1.1.1 - Peter Pawlowski) Free Monitor for Google 2.5 (HKLM\...\Free Monitor for Google_is1) (Version: - CleverStat) GIMP 2.8.6 (HKLM\...\GIMP-2_is1) (Version: 2.8.6 - The GIMP Team) Google Chrome (HKLM\...\Google Chrome) (Version: 45.0.2454.85 - Google Inc.) Google Drive (HKLM\...\{12ADFB82-D5A3-43E4-B2F4-FCD9B690315B}) (Version: 1.24.9931.5480 - Google, Inc.) Google Earth Plug-in (HKLM\...\{57BB4801-61C8-4E74-9672-2160728A461E}) (Version: 7.1.5.1557 - Google) Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (Version: 1.3.28.13 - Google Inc.) Hidden Graphviz 2.28 (HKLM\...\{D437FFB6-5C49-4DAC-ABAE-33FF065FE7CC}) (Version: 2.28.0 - AT&T Research Labs) Icecream Ebook Reader Version 1.62 (HKLM\...\{B8C30F0F-1F23-49E1-A3ED-44DE17660EE2}_is1) (Version: 1.62 - Icecream Apps) ImgBurn (HKLM\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!) Inno Setup Version 5.5.3 (HKLM\...\Inno Setup 5_is1) (Version: 5.5.3 - jrsoftware.org) Internet-TV für Windows Media Center (HKLM\...\{9D318C86-AF4C-409F-A6AC-7183FF4CF424}) (Version: 4.2.2.0 - Microsoft Corporation) Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle) Java DB 10.5.3.0 (HKLM\...\{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}) (Version: 10.5.3.0 - Sun Microsystems, Inc) Java(TM) 6 Update 43 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216043FF}) (Version: 6.0.430 - Oracle) JMicron JMB36X Driver (HKLM\...\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.17.58.2 - JMicron Technology Corp.) KhalInstallWrapper (Version: 2.00.0000 - Logitech) Hidden Klever PumpKIN 2.7.3 (HKLM\...\PumpKIN) (Version: 2.7.3 - Klever Group) Logitech Harmony Remote Software 7 (HKLM\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech) Logitech Media Server 7.7.5 (HKLM\...\Logitech Media Server_is1) (Version: 7.7.5 - Logitech) Logitech SetPoint (HKLM\...\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}) (Version: 4.80 - Logitech) McAfee Browser Protection Service (HKLM\...\McAfeeBrowserProtection) (Version: 6.0.3.138 - McAfee, Inc.) <==== ACHTUNG McAfee Firewall Protection Service (HKLM\...\McAfee Managed Firewall) (Version: 6.0.3.138 - McAfee, Inc.) McAfee SiteAdvisor Enterprise (Version: 3.5.0.1204 - McAfee, Inc.) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft LifeCam (HKLM\...\{BD71B413-9FEE-49BB-A6D1-2C0BFB99BDFE}) (Version: 3.60.253.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISER) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Outlook Connector (HKLM\...\{95140000-007A-0407-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation) Microsoft Office Project 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{8446EB22-A746-46DC-B1BD-E0DFA1F3CDDA}) (Version: - Microsoft) Microsoft Office Project Professional 2007 (HKLM\...\PRJPROR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Visio 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-0051-0000-0000-0000000FF1CE}_VISPROR_{CE144BF4-4950-4CDB-A5F7-CCE1888F49CB}) (Version: - Microsoft) Microsoft Office Visio Professional 2007 (HKLM\...\VISPROR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{887868A2-D6DE-3255-AA92-AA0B5A59B874}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE) (Version: - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mozilla Firefox 36.0.1 (x86 de) (HKLM\...\Mozilla Firefox 36.0.1 (x86 de)) (Version: 36.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla) mRemoteNG (HKLM\...\mRemoteNG) (Version: 1.72.5065.32737 - Next Generation Software) MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MySQL Connector/ODBC 5.1 (HKLM\...\{6F206B58-E2F7-4A70-ACAC-8E0ABFBC62F6}) (Version: 5.1.8 - Oracle Corporation) Napster (HKLM\...\{BBBCAE4B-B416-4182-A6F2-438180894A81}) (Version: 4.6.4.0 - Napster) Napster Burn Engine (Version: 3.5.0000 - Ihr Firmenname) Hidden NcFTP (HKLM\...\{38795F08-1CAA-4674-85DF-A6CEE99F4BF8}) (Version: 3.2.4 - NcFTP Software) NetBeans IDE Build 201407040001 (HKLM\...\nbi-nb-base-8.0.1.0.201407040001) (Version: Build 201407040001 - NetBeans.org) Notepad++ (HKLM\...\Notepad++) (Version: 6.7.4 - Notepad++ Team) NVIDIA 3D Vision Treiber 306.97 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 306.97 - NVIDIA Corporation) NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5896 - NVIDIA Corporation) NVIDIA Grafiktreiber 306.97 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 306.97 - NVIDIA Corporation) O&O SafeErase Professional (HKLM\...\{9E2B696F-8366-428B-A76D-9FED6BE60963}) (Version: 7.0.211 - O&O Software GmbH) Orca (HKLM\...\{039694F1-2108-4B3E-8575-85C245210F94}) (Version: 5.0.7693.0000 - Microsoft Corporation) PDF Architect (HKLM\...\{064A929A-4DE8-40CF-A901-BD40C14E4D25}) (Version: 1.1.83.9982 - pdfforge GmbH) PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge) PixiePack Codec Pack (HKLM\...\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}) (Version: 1.1.1200.0 - None) PlayReady PC Runtime x86 (HKLM\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation) Poedit (HKLM\...\{68EB2C37-083A-4303-B5D8-41FA67E50B8F}_is1) (Version: 1.4.6 - Vaclav Slavik) PowerDesk 8 (HKLM\...\{5536DFDE-9A88-4E87-90B9-800F619B3E7D}) (Version: 8.4.5.0 - Ihr Firmenname) PuTTY version 0.63 (HKLM\...\PuTTY_is1) (Version: 0.63 - Simon Tatham) PVSonyDll (Version: 1.00.0001 - NVIDIA Corporation) Hidden QuickTime (HKLM\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6257 - Realtek Semiconductor Corp.) Revo Uninstaller 1.93 (HKLM\...\Revo Uninstaller) (Version: 1.93 - VS Revo Group) RMPrepUSB (HKLM\...\RMPrepUSB) (Version: - ) Safari (HKLM\...\{FA4C2D53-205F-4245-9717-F3761154824D}) (Version: 5.34.57.2 - Apple Inc.) Samsung C460 Series (HKLM\...\Samsung C460 Series) (Version: 1.04 (04.12.2013) - Samsung Electronics Co., Ltd.) Samsung CLP-360 Series (HKLM\...\Samsung CLP-360 Series) (Version: 1.04 (07.07.2012) - Samsung Electronics Co., Ltd.) Samsung Easy Document Creator (HKLM\...\Samsung Easy Document Creator) (Version: 1.05.61 (10.04.2013) - Samsung Electronics Co., Ltd.) Samsung Easy Printer Manager (HKLM\...\Samsung Easy Printer Manager) (Version: 1.03.23.00(03.05.2013) - Samsung Electronics Co., Ltd.) Samsung Easy Wireless Setup (HKLM\...\Easy Wireless Setup) (Version: 3.60.40.03 - Samsung Electronics Co., Ltd.) Samsung Network PC Fax (HKLM\...\Samsung Network PC Fax) (Version: 1.09.14 (05.02.2013) - Samsung Electronics Co., Ltd.) Samsung OCR Software (HKLM\...\Samsung OCR Software) (Version: 1.00.09 (11.03.2013) - Samsung Electronics Co., Ltd.) Samsung Printer Live Update (HKLM\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) Samsung Scan Process Machine (Version: 1.00.56.01 - Samsung Electronics Co., Ltd.) Hidden Samsung SideSync 3.0 (HKLM\...\Samsung SideSync) (Version: 3.1.4.827 - Samsung Electronics Co., Ltd.) SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.) Securepoint Imaging Tool 2.2 (HKLM\...\Securepoint Imaging Tool_is1) (Version: - Securepoint GmbH) Skype web features (HKLM\...\{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}) (Version: 1.0.3971 - Skype Technologies S.A.) Skype Web Plugin (HKLM\...\{F7C13D74-E0FD-4A76-896A-E8687769767D}) (Version: 7.5.0.127 - Skype Technologies S.A.) Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) Snagit 12 (HKLM\...\{affb3620-aa43-4653-a34d-19705d4e9f07}) (Version: 12.1.1.1747 - TechSmith Corporation) Snagit 12 (Version: 12.1.1 - TechSmith Corporation) Hidden SNS Upload for Easy Document Creator (HKLM\...\{B6B5F07C-88D5-49D3-A1A7-A6D4BC37DCCC}) (Version: 1.0.0 - Samsung Electronics Co.,Ltd) Softerra LDAP Browser (HKLM\...\{520049D8-7E67-4E71-BB3E-74FDB34810AD}) (Version: 2.6 - Softerra) SpeedCommander 15 (HKLM\...\SpeedCommander 15) (Version: 15.10.7400 - SWE Sven Ritter) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden System Requirements Lab (HKLM\...\SystemRequirementsLab) (Version: - ) TeamViewer 10 (HKLM\...\TeamViewer) (Version: 10.0.45862 - TeamViewer) True BoxShot 2.1.1 (HKLM\...\{4D8E57C6-E1F7-404D-8930-ED93D9116D0F}_is1) (Version: 2.1 - trueboxshot.com) Tunebite (HKLM\...\{44830BDA-93FC-4821-A30E-30A0265CB269}) (Version: 7.0.33920.2000 - RapidSolution Software AG) Twonky 7.0 (HKLM\...\TwonkyServer) (Version: 7.0.9.0 - PacketVideo) Twonky Windows Components (HKLM\...\{7CC673E7-5271-409D-B196-BB76DA60300B}) (Version: 3.0.4 - PacketVideo) TwonkyManager (HKLM\...\TwonkyManager) (Version: 3.0.4 (58) - PacketVideo) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-0051-0000-0000-0000000FF1CE}_VISPROR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISER_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISER_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISER_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISER_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Update Rollup 1 für Microsoft Dynamics CRM-E-Mail-Router (KB2466084) (HKLM\...\KB2466084_Router_1031) (Version: 5.0.9688.1045 - Microsoft Corporation) Visual Studio C++ 10.0 Runtime (HKLM\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.) VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN) VMware Tools (HKLM\...\{2CB578D8-1E54-4373-BF52-48604D3D66EC}) (Version: 9.9.3.2759765 - VMware, Inc.) VMware vCenter Converter Standalone Agent (HKLM\...\{B55FEFEC-8FCC-4A16-B3CB-41673BA5545B}) (Version: 5.0.1.875114 - VMware, Inc.) VMware vSphere CLI (HKLM\...\{E60422F6-23F5-446A-B26D-70FF3092BF84}) (Version: 4.1.0.1892 - VMware, Inc.) VMware vSphere Client 4.1 (HKLM\...\{A0B433B1-941D-46F5-AE59-286263534232}) (Version: 4.1.0.14766 - VMware, Inc.) VMware vSphere Client 5.5 (HKLM\...\{4CFB0494-2E96-4631-8364-538E2AA91324}) (Version: 5.5.0.3838 - VMware, Inc.) VNC Free Edition 4.1.3 (HKLM\...\RealVNC_is1) (Version: 4.1.3 - RealVNC Ltd.) WebM Media Foundation Components (HKLM\...\webmmf) (Version: 1.0.1.2 - WebM Project) Web-Sniffer version 1.0.0 (HKLM\...\{7E38AD2F-57D8-480C-9C2E-A6CDAFB262D6}_is1) (Version: 1.0.0 - Lingo4you) Wild Media Server (UPnP, DLNA, HTTP) (HKLM\...\WMS) (Version: 1.07 - Evgeny Lachinov) Winamp (HKLM\...\Winamp) (Version: 5.622 - Nullsoft, Inc) Windows Command Line Ftp 11.02.18 (HKLM\...\Windows Command Line Ftp_is1) (Version: - hxxp://software-download.name/windows-command-line-ftp/) Windows Installer Clean Up (HKLM\...\{121634B0-2F4A-11D3-ADA3-00C04F52DD53}) (Version: 2.05.00.0000 - Microsoft Corporation) Windows Media Center Add-in for Silverlight (HKLM\...\{0EDBEB2B-7C8D-42E6-8312-0F84394A3223}) (Version: 4.7.3.0 - Microsoft Corporation) Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) WinSCP 5.0.5 beta (HKLM\...\winscp3_is1) (Version: 5.0.5 beta - Martin Prikryl) WinZip 19.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E4}) (Version: 19.0.11293 - WinZip Computing, S.L. ) WinZip Command Line Support Add-On 4.0 (HKLM\...\WZCLINE) (Version: - WinZip Computing, S.L.) XnView 1.98.2 (HKLM\...\XnView_is1) (Version: 1.98.2 - Gougelet Pierre-e) Zend Studio 10.5.0 (HKLM\...\{A73D4BEE-2BBE-4285-BF6C-4B8C7C001370}) (Version: 10.5.0 - Zend Technologies Ltd.) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-3086022667-2732812533-850181598-500_Classes\CLSID\{11CD84A3-A5E0-43CB-B3DF-92C623C0E0E0}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3086022667-2732812533-850181598-500_Classes\CLSID\{22756E83-8EBC-4B16-A4A4-0AA73BE497B1}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3086022667-2732812533-850181598-500_Classes\CLSID\{2A235D7E-0358-40E2-B51A-DE22F8F5C50D}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3086022667-2732812533-850181598-500_Classes\CLSID\{56C94D6A-7370-4885-A04E-7097FE4E0BAF}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3086022667-2732812533-850181598-500_Classes\CLSID\{672CDBDB-0270-4EB9-83EC-216377522D21}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3086022667-2732812533-850181598-500_Classes\CLSID\{841BFDCA-6A9A-4EBC-BC7E-194AA5DCE428}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3086022667-2732812533-850181598-500_Classes\CLSID\{94330D48-EB33-49BB-87F1-AD8C0352C010}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3086022667-2732812533-850181598-500_Classes\CLSID\{F7CA46A9-ACA5-45A6-967E-03FF5A282D01}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) ==================== Wiederherstellungspunkte ========================= 01-09-2015 19:00:34 Windows-Sicherung 02-09-2015 19:00:30 Windows-Sicherung ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:04 - 2011-12-21 16:18 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {05FCE019-D88C-4510-996B-3D8E3E372D07} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3086022667-2732812533-850181598-1000UA => C:\Users\Schwedenhaus\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {1598612A-5DB9-4415-95D5-829EDB5D58A2} - System32\Tasks\{5D8034A9-EB49-4E85-BDEB-37DB0ADC075E} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files\Poedit\bin\poedit.exe" Task: {248F186E-A6FC-4A36-8907-1660282C536B} - System32\Tasks\{1695B2C7-3366-48CC-853B-8278A6922234} => C:\Program Files\RealVNC\VNC4\vncviewer.exe [2008-10-15] (RealVNC Ltd.) Task: {2732E673-72BE-4806-AB3E-0D9DD63025B5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {2D93D8B5-1023-4A88-857D-D07016231079} - System32\Tasks\{DC393B53-54B6-40DF-A194-4B80E910729F} => pcalua.exe -a "C:\Program Files\Nokia\Nokia PC Suite 7\ApplicationInstaller.exe" -d C:\Users\Administrator\Desktop -c "C:\Users\Administrator\Downloads\MOST-CE-0.5.1-install.jar" Task: {2FDA73EB-A2EB-4F10-A4F8-3451F346BC2F} - System32\Tasks\{2C41DA4F-0E96-4A56-A7AF-0C17D7BF8BB9} => C:\Users\Administrator\ModuleStudio\modulestudio.exe Task: {34D2DA8F-CC60-4A84-B084-BFD615377F41} - System32\Tasks\{ED9452A7-A3E3-4644-964A-3E8FE506E7B8} => pcalua.exe -a C:\Users\Administrator\Downloads\pictureviz.exe -d C:\Users\Administrator\Desktop Task: {384A7F14-490C-40C9-96D9-7D438CF56FE8} - System32\Tasks\{F353B12E-8D0C-4F22-95A9-D4CDEB5F26A0} => C:\Users\Schwedenhaus\Desktop\MOST-CE-0.5b-install-win.exe Task: {3CF70A20-B779-4584-9E67-E82099FD3BA6} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3086022667-2732812533-850181598-1000Core => C:\Users\Schwedenhaus\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: {4B19CADA-C573-4E55-9DCE-986B08F8F9C4} - System32\Tasks\{E3FBFDE2-2E70-41A2-9697-1CF8F0036AF3} => C:\Users\Schwedenhaus\Desktop\MOST-CE-0.5b-install-win.exe Task: {546246C0-5846-4B22-B54A-53D327B08A91} - System32\Tasks\{7643E3BE-C9FA-4AF3-9E4D-D3BA5BD4417E} => C:\Users\Schwedenhaus\Downloads\phoenixRC_25v_30d_BETA_update.exe Task: {5466CD8E-54F1-4E91-9860-310D1B11DCC3} - System32\Tasks\{8D42DC55-E32B-4167-8CF4-D3104ABD4208} => \\SERVER9\David\Clients\setup.exe Task: {56C07F61-5A83-4EC9-A517-CD85AF6DEB0C} - System32\Tasks\{B5B020D1-057C-4166-BE77-67D2305678D2} => pcalua.exe -a "C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SLTJ11QM\On2Share_-_UPnP_Control_Point[1].exe" -d C:\Windows\system32 Task: {58963E38-A9F7-45F5-A103-AD5F8E2BE871} - System32\Tasks\{A6DAA908-41A1-4146-B948-A9A9CA57E01E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.0.0.123/en/go/help.faq.installer?LastError=1603 Task: {5AADBA61-AD0D-455C-8746-91C36AAEBA27} - System32\Tasks\{A758251B-EE1F-46F3-A449-4B3767EA0A0F} => C:\Program Files\RealVNC\VNC4\vncviewer.exe [2008-10-15] (RealVNC Ltd.) Task: {63FB7D1F-339D-4E55-BCD6-3A2298CEDF4D} - System32\Tasks\{0FA8CE5B-2ED8-488F-8335-7DFE9A378A07} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.0.0.152/de/go/help.faq.installer?LastError=1603 Task: {66F6BA6E-0762-4A14-89E1-B010F77F9A2D} - System32\Tasks\{5D89F900-2018-43EE-B08D-B4A40111AC5E} => C:\Program Files\RealVNC\VNC4\vncviewer.exe [2008-10-15] (RealVNC Ltd.) Task: {70C60780-0698-4769-A4ED-E34ADEC6684B} - System32\Tasks\{70551C58-679D-4F30-9B66-A6F1D06CF5DB} => C:\Users\Schwedenhaus\Desktop\DPP372DE\DPP372DE.exe Task: {70FB63D2-8033-4169-B4D8-7E7C8C4C9063} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {74AA878E-C6D9-4BB1-B924-067C96E920CA} - System32\Tasks\{4EE4F75A-F93C-4556-9C76-104130C5748C} => C:\Users\Schwedenhaus\Downloads\phoenixRC_25v_30d_BETA_update.exe Task: {74F905FE-4658-458A-B0AE-58AF638264ED} - System32\Tasks\{092F6C6F-AEDD-489F-A768-B18459CE1C75} => C:\Program Files\Poedit\bin\poedit.exe [2010-03-22] (Vaclav Slavik) Task: {75BF2854-1204-4736-B85E-677AC3272397} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-789433706-2975812997-1506108583-500Core => C:\Users\Administrator.IFTA-GMBH\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-19] (Google Inc.) Task: {7F63C52E-5352-4A9C-A146-8F906753AD93} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3086022667-2732812533-850181598-1000UA => C:\Users\Schwedenhaus\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: {8244C8F5-7E9F-4483-B014-ED46E60588EB} - System32\Tasks\{79E5BD38-BE8E-44B8-BBA6-DF33015C9CD3} => pcalua.exe -a "C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BH9QP51\JavaSetup6u21[1].exe" -d C:\Users\Administrator\Desktop Task: {8A1345A2-A3E8-4CDD-BF76-9E4FCD277BBB} - System32\Tasks\{167C34F1-B86F-4990-A502-6C8CE59B5ACF} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.1.0.104/de/go/help.faq.installer?LastError=1603 Task: {8B2C2FC5-AC09-4AA2-861B-76E445892E0D} - System32\Tasks\{0CDFBCE9-EB6E-4323-BCBC-091FF5573295} => pcalua.exe -a C:\Users\Administrator\Desktop\TwonkyManagerSetup.exe -d C:\Users\Administrator\Desktop Task: {8CF7F506-B3E9-4E2E-AC1A-37D49E10B7F4} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser Task: {8E199DE9-B69A-4FCE-8F43-4D2D940281D5} - System32\Tasks\{5950864C-9595-4D2D-9E56-A2134441DA3F} => C:\Users\Schwedenhaus\Desktop\DPP372DE\DPP372DE.exe Task: {90A30DDC-05FE-4890-ABF3-E6BCA6A74C25} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-789433706-2975812997-1506108583-500UA => C:\Users\Administrator.IFTA-GMBH\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-19] (Google Inc.) Task: {912FEA57-00E2-4CBF-AAA7-124A1E7E31D2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {AAA65F33-2AB9-4636-98D0-5E388174B140} - System32\Tasks\{E45CD787-EB63-499C-9456-50EBE84BD850} => C:\Program Files\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.) Task: {AADF6235-B913-4C5A-B0A7-2829A0F8F82D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated) Task: {AB6CEE5D-360A-4F6C-9B40-E7872D073548} - System32\Tasks\Quark Updater => C:\Program Files\Quark\Quark Update\AutoUpdate.exe Task: {B240091D-9A85-4676-AB4D-D9170C71E94F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3086022667-2732812533-850181598-1000Core => C:\Users\Schwedenhaus\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {B2C5E1B6-1A02-4A30-93CE-88165BAC759E} - System32\Tasks\{1B3E7196-D7BB-4F38-9C0F-D1543A4DE15D} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files\Poedit\bin\poedit.exe" Task: {B72C831F-1703-4975-B57A-1B1C3BE88F5A} - System32\Tasks\{BE64A0F1-7B22-43BD-9904-3EEAFB3E5223} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.0.0.123/en/go/help.faq.installer?LastError=1603 Task: {C3414AE6-089F-4D34-8A7B-E2EF3865C1B3} - System32\Tasks\{E70297F9-2D5F-4FDE-83DB-EDE7234D3C33} => pcalua.exe -a "C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A1QLOXF1\Flac_Plugin_for_WA2[1].exe" -d C:\Users\Administrator\Desktop Task: {D920BDFA-32CC-4137-B403-B102BAB9FA7C} - System32\Tasks\{03DCE3BD-CA25-47AD-A93C-01F3FE12186B} => pcalua.exe -a C:\Users\Schwedenhaus\Desktop\MOST-CE-0.5b-install-win.exe -d C:\Users\Schwedenhaus\Desktop Task: {EB87B390-6630-4700-AC19-4E62BB569EA8} - System32\Tasks\{D28E6BC4-AB7F-4DDA-A454-2060FAFEF34A} => pcalua.exe -a "C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CW5F70BB\JavaSetup6u30.exe" -d C:\Users\Administrator\Desktop Task: {EFD0FD8A-9E26-4402-9396-B9F2A4291C22} - System32\Tasks\{1C91FAFF-5BFB-4F5A-8990-CAABABF8E7B5} => pcalua.exe -a "C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\STPO6V5R\pictureviz[1].exe" -d C:\Users\Administrator\Desktop Task: {F350B462-253C-4FC6-8FD7-89989BC4E4FD} - System32\Tasks\{4E5E77C9-4DD4-4779-A708-426754BCB866} => pcalua.exe -a "C:\Program Files\Bitvise Tunnelier\uninst.exe" -d "C:\Program Files\Bitvise Tunnelier" -c Tunnelier Task: {F8CFBCD6-8E5F-4861-A8C3-F50B8CE03207} - System32\Tasks\{95B327C3-3D32-45BA-B22D-A0A977B55F31} => C:\medi\MEDI.EXE Task: {FE164FB0-B9ED-4F72-ACD7-4D1074F1279B} - System32\Tasks\{AEA5F0AE-5B23-4D40-A76D-B5ECE8B2CDDF} => C:\Program Files\RealVNC\VNC4\vncviewer.exe [2008-10-15] (RealVNC Ltd.) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3086022667-2732812533-850181598-1000Core.job!___prosschiff@gmail.com_.crypt => 0Y \ ? 0m ct nV NC zD zj Hb U5 4r hK ? aV qW 48 YN ? q2 ot jS jl / VA ? WJ \ 5F zW 2M 81 wS 7 Sa 16m \ d9 Uz0f7 /W vk 36s lY6j qzv N6t /pb XWxQ z6t \ z0 zo Vnu BWk0 IE Oq x1 df Tn Qy 55 1u Ae /Y \ ? ?fu 3Uv iQ sW qsU Qs \ 1X BD 4bvU4 K0 Eq dB Pp \ LnE 8L _h ERT Fb L5 nb Eg UzY fL zRBS sO kD Sy 8P v1 \ DA ? oN 0T is ? RJ vKU rF md d_ lr xy CL \ Zj 03N M3 Sj \ Q_ Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3086022667-2732812533-850181598-1000UA.job!___prosschiff@gmail.com_.crypt => \ ? 2m ct nV NC zD zj Hb U5 /r uK ? zV qR 4J HN tt \ DX ? Kf / \/ zF Tj Dk2 ? wT C4 79 nY 7a mf AH \ Sz okO3 \ Y7j 9z_ W6 B46 /bb Wr X_xA 6j \ lz2 9o Jnf pA Ct W9g ta EM d0c / xW xS \ fKT ? vta 0q 1j Ok 5z Qy 55 1u Ae /Y \ ? ?fu 3Uv iQ sW qsU Qs \ 1X BD 4bvU4 K0 Eq dB Pp \ LnE 8L _h ERT Fb L5 nb Eg UzY fL zRBS sO kD Sy 8P v1 \ DA ? oN 0T is ? RJ vKU rF md d_ lr xy CL \ Zj 03N M3 Sj \ Q_ Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3086022667-2732812533-850181598-1000Core.job!___prosschiff@gmail.com_.crypt => 9P /8 \ ? ct nV NC zD zf Hs / 3r nK ?\ qU / / HN HM ? ft 9S Bj 3N BA G3 Qf / vbFi \ zW Lj ? D42 ? 7j uY Sa \ NH 16 \ 9j1 Sz4f sk 3ds wY0j 7zD YEx6h3 / 9r Qy 55 1u Ae /Y \ ? ?fu 3Uv iQ sW qsU Qs \ 1X BD 4bvU4 K0 Eq dB Pp \ LnE 8L _h ERT Fb L5 nb Eg UzY fL zRBS sO kD Sy 8P v1 \ DA ? oN 0T is ? RJ vKU rF md d_ lr xy CL \ Zj 03N M3 Sj \ Q_ Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3086022667-2732812533-850181598-1000UA.job!___prosschiff@gmail.com_.crypt => 0g \ ? 3m ct nV NC zD zf Hs / 5r jK ? 6m aV / HN _q jS ? aN PA ? Rf WJ ybBi \ \ zD Yj Df2 ?91 wT / eY 16 \ c9j1 Xz f7 mk 3ds ME qY zQ J6 Br6 / 3r / X6x Qy 55 1u Ae /Y \ ? ?fu 3Uv iQ sW qsU Qs \ 1X BD 4bvU4 K0 Eq dB Pp \ LnE 8L _h ERT Fb L5 nb Eg UzY fL zRBS sO kD Sy 8P v1 \ DA ? oN 0T is ? RJ vKU rF md d_ lr xy CL \ Zj 03N M3 Sj \ Q_ Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789433706-2975812997-1506108583-500Core.job => C:\Users\Administrator.IFTA-GMBH\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789433706-2975812997-1506108583-500UA.job => C:\Users\Administrator.IFTA-GMBH\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Quark Updater.job => C:\Program Files\Quark\Quark Update\AutoUpdate.exe ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2011-04-19 18:34 - 2011-04-19 18:34 - 00108544 _____ () C:\Windows\system32\FileMonitor32.dll 2012-11-18 14:22 - 2012-10-02 21:28 - 00079208 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll 2012-01-09 12:41 - 2012-01-09 12:41 - 00024064 _____ () C:\Windows\System32\sst6clm.dll 2012-11-01 12:18 - 2012-01-09 15:31 - 00024064 _____ () C:\Windows\System32\sst6ylm.dll 2014-08-05 12:16 - 2014-08-05 12:16 - 00024064 _____ () C:\Windows\System32\sst9clm.dll 2009-11-27 11:15 - 2005-04-29 09:19 - 00073728 _____ () C:\Windows\System32\IMGMSGMO.dll 2015-08-17 13:24 - 2015-07-07 11:48 - 00019216 _____ () C:\Windows\system32\spool\PRTPROCS\W32X86\TeamViewer_PrintProcessor.dll 2012-07-18 15:00 - 2012-07-18 15:00 - 01008032 _____ () C:\Users\Schwedenhaus\AppData\Roaming\Mikogo 4\M4-Service.exe 2010-10-27 19:09 - 2008-09-30 12:30 - 00241734 _____ () C:\Program Files\Cyberlink\Shared files\RichVideo.exe 2015-09-03 17:22 - 2015-09-03 17:22 - 01592208 _____ () C:\Users\Schwedenhaus\AppData\Roaming\Mikogo 4\M4-Capture.exe 2012-07-09 20:33 - 2012-07-09 20:33 - 00545608 _____ () C:\Program Files\Twonky\TwonkyServer\twonkyproxy.exe 2012-07-09 20:33 - 2012-07-09 20:33 - 00271176 _____ () C:\Program Files\Twonky\TwonkyServer\twonkywebdav.exe 2012-10-15 11:19 - 2012-10-15 11:19 - 00085656 _____ () C:\Program Files\VMware\VMware vCenter Converter Standalone Agent\mspack.dll 2012-10-15 11:17 - 2012-10-15 11:17 - 01234584 _____ () C:\Program Files\VMware\VMware vCenter Converter Standalone Agent\libxml2.dll 2010-04-08 20:11 - 2010-04-08 20:11 - 00061952 ____R () C:\Program Files\VMware\VMware vSphere CLI\Perl\bin\ZLIB1.dll 2010-08-03 12:19 - 2010-12-25 10:11 - 08268814 _____ () C:\Program Files\Wild Media Server\ffmpeg-1.dll 2012-07-09 20:36 - 2012-07-09 20:36 - 01672008 _____ () C:\Program Files\Twonky\TwonkyServer\TwonkyServer.exe 2012-07-09 20:36 - 2012-07-09 20:36 - 00176968 _____ () C:\Program Files\Twonky\TwonkyServer\wmdrmdll.dll 2011-04-19 18:29 - 2011-04-19 18:29 - 00011264 _____ () C:\Program Files\Avanquest\PowerDesk\mxcview.dll 2011-04-19 18:30 - 2011-04-19 18:30 - 00112640 _____ () C:\Program Files\Avanquest\PowerDesk\mxgview.dll 2010-08-17 10:50 - 2010-03-15 11:28 - 00141824 _____ () C:\Program Files\WinRAR\rarext.dll 2011-04-19 18:35 - 2011-04-19 18:35 - 00317952 _____ () C:\Program Files\Avanquest\PowerDesk\PDShExt.dll 2013-08-22 10:52 - 2012-11-13 04:28 - 00480872 _____ () C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe 2013-08-22 10:52 - 2012-11-13 04:28 - 00403048 _____ () C:\Program Files\McAfee\Managed VirusScan\DesktopUI\Win32RenderingEngine.dll 2013-12-18 13:53 - 2014-04-25 15:58 - 00199016 _____ () C:\Program Files\McAfee\Managed VirusScan\DesktopUI\BPTrayPlugin.dll 2012-03-09 09:58 - 2012-03-09 09:58 - 00350072 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe 2012-03-09 09:58 - 2012-03-09 09:58 - 00056696 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00028774 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00024679 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\c5cce8d16a1bd48692b421dcf46d3396\Util.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00032878 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00024701 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00028779 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00020601 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\4461f48e31bde5c56b31b973b773de09\List.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00118918 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00082048 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00020576 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00036964 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\f233f63b6654362865c7577442edb9e3\Win32.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00020590 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00082033 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00024676 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00061540 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\e56c61f7248672819579325af3387035\POSIX.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00094334 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\eb138ef0e4282611dbf485a302784646\LibYAML.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00053340 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00184414 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\bd5179a413bc0c4b82eedc22c6cab101\re.dll 2015-09-03 17:23 - 2015-09-03 17:23 - 00024701 ____R () C:\Users\TEMPSH~1.031\AppData\Local\Temp\pdk-Administrator-6256\93e7e3d6030f426844228042348210cf\Service.dll 2010-07-14 11:26 - 2009-07-20 12:27 - 00017936 _____ () C:\Program Files\Logitech\SetPoint\khalwrapper.dll 2014-06-01 11:08 - 2014-06-01 11:08 - 00035328 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll 2014-05-24 18:41 - 2014-05-24 18:41 - 00091648 _____ () C:\Program Files\FileZilla FTP Client\libgcc_s_sjlj-1.dll 2014-05-24 18:41 - 2014-05-24 18:41 - 00892416 _____ () C:\Program Files\FileZilla FTP Client\libstdc++-6.dll 2015-09-03 12:26 - 2015-08-28 02:17 - 01501512 _____ () C:\Program Files\Google\Chrome\Application\45.0.2454.85\libglesv2.dll 2015-09-03 12:26 - 2015-08-28 02:17 - 00081224 _____ () C:\Program Files\Google\Chrome\Application\45.0.2454.85\libegl.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\TEMP:E655E454 AlternateDataStreams: C:\Users\Public\DRM:احتضان AlternateDataStreams: C:\Users\Schwedenhaus\Documents\Publikation1.ppp!___prosschiff@gmail.com_.crypt:SummaryInformation AlternateDataStreams: C:\Users\Schwedenhaus\Documents\Publikation1.ppp!___prosschiff@gmail.com_.crypt:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\.DEFAULT\...\schwedenhaus.ag -> hxxps://crm.schwedenhaus.ag IE trusted site: HKU\.DEFAULT\...\schwedenhaus.at -> hxxp://www.schwedenhaus.at IE trusted site: HKU\.DEFAULT\...\schwedenhausshop.de -> hxxp://www.schwedenhausshop.de ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3086022667-2732812533-850181598-500\Control Panel\Desktop\\Wallpaper -> C:\Users\TEMP.SH-PC2.031\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.21.20 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist deaktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TwonkyServer.lnk => C:\Windows\pss\TwonkyServer.lnk.CommonStartup MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: AXIS Camera Management Service Control => "C:\Program Files\Axis Communications\AXIS Camera Management 4\AcmAdmin.exe" MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: Software Informer => "C:\Program Files\Software Informer\softinfo.exe" -autorun ==================== FirewallRules (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{651FA36E-50B5-4E0F-8FBB-A685C5BD77C8}] => (Allow) C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe FirewallRules: [{A75802D0-9F37-4594-902B-71BD9F3D5A24}] => (Allow) C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe FirewallRules: [{672CA58E-18DB-4D91-9286-88740D83E4CD}] => (Allow) C:\Users\Schwedenhaus\AppData\Local\Akamai\netsession_win.exe FirewallRules: [{C23F9382-5BAA-4932-AD96-B4CE8788785B}] => (Allow) C:\Users\Schwedenhaus\AppData\Local\Akamai\netsession_win.exe FirewallRules: [{F1BFE6FC-3FA2-448B-A593-A195609A7E6C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{EDB746AD-B8A7-4C04-A12B-6D6F7512DB3C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{6C6B9369-7E84-41A2-BDCE-500A3861B0AB}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{E610F3D3-FDB1-4C43-BBF3-6BBEDB853458}] => (Allow) LPort=9089 FirewallRules: [UDP Query User{93C460E5-FF61-47C7-A7A4-EF9FA8296213}C:\program files\winamp\winamp.exe] => (Block) C:\program files\winamp\winamp.exe FirewallRules: [TCP Query User{86642483-C281-4CCC-9B99-2EFC147B0011}C:\program files\winamp\winamp.exe] => (Block) C:\program files\winamp\winamp.exe FirewallRules: [{DF8548E4-6DE5-4306-9C8B-A535AD207125}] => (Allow) C:\Program Files\TwonkyMedia\MediaManager\TwonkyMediaManager.exe FirewallRules: [{299B4F7D-C911-4932-A6A1-6D393BB60BE5}] => (Allow) C:\Program Files\TwonkyMedia\MediaManager\TwonkyMediaManager.exe FirewallRules: [{B1AFA27D-A2F2-4414-A5A8-0370332A2DAB}] => (Allow) C:\Program Files\TwonkyMedia\twonkymediaserver.exe FirewallRules: [{B07FE14D-91C5-4B63-B590-0FAFD4D880D2}] => (Allow) C:\Program Files\TwonkyMedia\twonkymediaserverwatchdog.exe FirewallRules: [{D2B6AD58-C693-40A9-8599-DC9A1D73EF38}] => (Allow) C:\Program Files\TwonkyMedia\twonkymediaserver.exe FirewallRules: [{FA08C6B0-8C69-40DF-BC20-30E2201CF241}] => (Allow) C:\Program Files\TwonkyMedia\twonkymediaserverwatchdog.exe FirewallRules: [{4059BC24-6BF1-410F-B96F-AC442C0D6199}] => (Allow) C:\Program Files\Squeezebox\server\SqueezeSvr.exe FirewallRules: [{717C0501-E9F0-4AAD-AB51-E6348C27D2D9}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeTray.exe FirewallRules: [{73B0AF9F-07BB-4736-8C22-BA066D22056B}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeTray.exe FirewallRules: [{58852977-F4FF-4B0E-B040-A13975F180EA}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeExp.exe FirewallRules: [{6108496C-FF91-4D63-8017-B585F23F87DF}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeExp.exe FirewallRules: [{DFFC1AB8-525F-4ED2-BAF6-23E6926B33C1}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeEnC2.exe FirewallRules: [{35006241-0999-4BCB-84BD-60654AB57E27}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeEnC2.exe FirewallRules: [{9EB801E7-B8F8-48D2-8AA3-10811DD6B629}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeCam.exe FirewallRules: [{E87CF5A8-98B8-432E-A8AB-C53DC9A83100}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeCam.exe FirewallRules: [{BA547E23-F3BD-4F60-8850-2863AD626E4B}] => (Allow) svchost.exe FirewallRules: [{CA47882D-A8EE-4962-B4B8-1C996AF16322}] => (Allow) C:\Program Files\Squeezebox\server\SqueezeSvr.exe FirewallRules: [{28EEE312-9B25-4F18-BEB4-916E7E7E9712}] => (Allow) C:\Program Files\devolo\informer\devinf.exe FirewallRules: [{A3E857E5-850B-448C-AD94-893BF8C6E3FA}] => (Allow) C:\Program Files\devolo\informer\devinf.exe FirewallRules: [UDP Query User{B48E994F-41CE-4B2A-973A-FB8FF33C806F}C:\program files\axis communications\axis camera management\axiscameramanagement.exe] => (Allow) C:\program files\axis communications\axis camera management\axiscameramanagement.exe FirewallRules: [TCP Query User{4DC2ED17-4AA0-4CD9-AFD1-5FDE3767EB22}C:\program files\axis communications\axis camera management\axiscameramanagement.exe] => (Allow) C:\program files\axis communications\axis camera management\axiscameramanagement.exe FirewallRules: [{69CB04F4-40F1-41FD-85D7-76510C87CC99}] => (Allow) C:\Program Files\Skype\Plugin Manager\skypePM.exe FirewallRules: [{9DFB5F2A-1FB5-4BA3-BFBA-D1F11900BD12}] => (Allow) LPort=26125 FirewallRules: [{5760CE34-AB97-4BE5-85D1-D29CD3384DFE}] => (Allow) LPort=26125 FirewallRules: [{8C46228B-E191-4B74-8210-9F8BD91A7E00}] => (Allow) C:\Program Files\Illustrate\dBpoweramp\Asset-uPNP.exe FirewallRules: [{69300B5E-01A3-485B-A160-A9A3D3C3305C}] => (Allow) C:\Program Files\Illustrate\dBpoweramp\Asset-uPNP.exe FirewallRules: [UDP Query User{C940FFAF-0A99-405C-801A-417EF4A1FB84}C:\program files\java\jre6\bin\javaw.exe] => (Allow) C:\program files\java\jre6\bin\javaw.exe FirewallRules: [TCP Query User{7ED4F8A7-2ABF-47AC-A8A1-42CF239CA5A6}C:\program files\java\jre6\bin\javaw.exe] => (Allow) C:\program files\java\jre6\bin\javaw.exe FirewallRules: [UDP Query User{424AEDB9-0F5E-41D8-83A4-A0C35CD44319}C:\program files\twonkymedia\mediamanager\twonkymediamanager.exe] => (Allow) C:\program files\twonkymedia\mediamanager\twonkymediamanager.exe FirewallRules: [TCP Query User{26E1D685-37E4-49FF-96A9-26E9B10B4861}C:\program files\twonkymedia\mediamanager\twonkymediamanager.exe] => (Allow) C:\program files\twonkymedia\mediamanager\twonkymediamanager.exe FirewallRules: [{F89B9653-74C3-4D4B-8729-AAF81D189CC3}] => (Allow) C:\Program Files\Squeezebox\server\SqueezeSvr.exe FirewallRules: [UDP Query User{84445899-3E89-4D9B-A248-3AAE2DB45865}C:\windows\system32\ftp.exe] => (Allow) C:\windows\system32\ftp.exe FirewallRules: [TCP Query User{C18B2870-38E5-45DE-9C98-552739A6E523}C:\windows\system32\ftp.exe] => (Allow) C:\windows\system32\ftp.exe FirewallRules: [UDP Query User{FE7ACE32-95F2-42F9-8FAB-535F6C877211}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe FirewallRules: [TCP Query User{53A055D2-FB7D-4AB4-AB6B-C7C6EC2D4F4B}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe FirewallRules: [UDP Query User{776FCC1F-475E-4859-B7F3-1A4F83D4DF47}C:\windows\system32\java.exe] => (Allow) C:\windows\system32\java.exe FirewallRules: [TCP Query User{6866F105-4424-48F7-86B5-A8A51DA29900}C:\windows\system32\java.exe] => (Allow) C:\windows\system32\java.exe FirewallRules: [UDP Query User{91865C3B-C989-4F78-AAB5-D9C5CCE609E3}C:\program files\eclipse\eclipse.exe] => (Allow) C:\program files\eclipse\eclipse.exe FirewallRules: [TCP Query User{C926F747-ADD0-49B0-8BFB-348B49C28294}C:\program files\eclipse\eclipse.exe] => (Allow) C:\program files\eclipse\eclipse.exe FirewallRules: [{9CC65EF3-68AA-4235-8805-BABE46CDD668}] => (Allow) C:\Program Files\Opera\opera.exe FirewallRules: [{5E752A6D-9876-40FA-AEE5-A0AFFE57C01F}] => (Allow) C:\Program Files\Opera\opera.exe FirewallRules: [UDP Query User{66EF4416-BBAE-4746-8894-157B09CAD217}C:\program files\windows sidebar\sidebar.exe] => (Allow) C:\program files\windows sidebar\sidebar.exe FirewallRules: [TCP Query User{809C8067-F265-4454-8117-24CA5BD53CCA}C:\program files\windows sidebar\sidebar.exe] => (Allow) C:\program files\windows sidebar\sidebar.exe FirewallRules: [UDP Query User{16AF7CE7-C652-4EB1-8E0D-7130C6A4AF5A}C:\program files\rapidsolution\audialstv\bin\audialstv.exe] => (Allow) C:\program files\rapidsolution\audialstv\bin\audialstv.exe FirewallRules: [TCP Query User{94CBA034-2693-49DF-BA0A-3826D157C055}C:\program files\rapidsolution\audialstv\bin\audialstv.exe] => (Allow) C:\program files\rapidsolution\audialstv\bin\audialstv.exe FirewallRules: [UDP Query User{D04FAF35-4589-4887-A590-112F17E6F818}C:\program files\java\jre6\bin\java.exe] => (Allow) C:\program files\java\jre6\bin\java.exe FirewallRules: [TCP Query User{82038E8D-D8B4-4EB2-B758-9EEAD0185BF8}C:\program files\java\jre6\bin\java.exe] => (Allow) C:\program files\java\jre6\bin\java.exe FirewallRules: [UDP Query User{77038D5E-5FE1-4B27-8874-C61C2DF35E6D}C:\program files\rapidsolution\audialsone 4\audialsone.exe] => (Allow) C:\program files\rapidsolution\audialsone 4\audialsone.exe FirewallRules: [TCP Query User{57D78414-6E02-4520-AF9F-77E8E6C18F60}C:\program files\rapidsolution\audialsone 4\audialsone.exe] => (Allow) C:\program files\rapidsolution\audialsone 4\audialsone.exe FirewallRules: [UDP Query User{8AA6609A-AE7F-4C0D-AC76-E1D1E3661101}C:\program files\internet explorer\iexplore.exe] => (Block) C:\program files\internet explorer\iexplore.exe FirewallRules: [TCP Query User{5ADBE429-A654-4FE0-8A8D-79C8CF7D2499}C:\program files\internet explorer\iexplore.exe] => (Block) C:\program files\internet explorer\iexplore.exe FirewallRules: [{BD1134D5-F6C3-49E3-A8D4-0FCC4696C101}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe FirewallRules: [{ECF8554B-FB75-417D-B712-654C709B2B44}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe FirewallRules: [UDP Query User{C8F95DA0-5BC1-4D79-9BA5-ACEB1DB9CF0A}C:\program files\napster\napster.exe] => (Allow) C:\program files\napster\napster.exe FirewallRules: [TCP Query User{E603847F-6943-452F-92ED-E652F2D53087}C:\program files\napster\napster.exe] => (Allow) C:\program files\napster\napster.exe FirewallRules: [UDP Query User{9836AE2E-4584-49D8-AE2D-AF73C1D47593}C:\program files\napster\napster.exe] => (Block) C:\program files\napster\napster.exe FirewallRules: [TCP Query User{6F262F6D-15A4-4337-BC21-9B2C1B787385}C:\program files\napster\napster.exe] => (Block) C:\program files\napster\napster.exe FirewallRules: [{D494C9E5-6939-4746-AE50-02AA51B7E047}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeTray.exe FirewallRules: [{4505C516-2694-4243-A218-96DECC27E64D}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeTray.exe FirewallRules: [{D68E9888-B425-4E79-8A28-B16D6567F911}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeExp.exe FirewallRules: [{A5252505-433A-454C-A5DE-1785D5BFDF5A}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeExp.exe FirewallRules: [{5C10E488-E5CC-4C57-ACC4-BC66A7EA8EB6}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeEnC2.exe FirewallRules: [{DBC1C048-73E7-420C-B4F7-FAF38C67C08F}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeEnC2.exe FirewallRules: [{B942766A-D274-467E-B2F3-821283DD6977}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeCam.exe FirewallRules: [{BA5C7FBC-BD92-44A6-AFB7-509CF89C347E}] => (Allow) C:\Program Files\Microsoft LifeCam\LifeCam.exe FirewallRules: [{C57D0ED3-207A-4DFC-980A-985B067A670F}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [UDP Query User{58322ACC-C7F2-4295-B0E0-4CEEF700892E}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe FirewallRules: [TCP Query User{919025E6-53E7-44F6-99C2-A4BDFD709AE6}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe FirewallRules: [{FAD83C48-34BB-49EB-9D33-E113BD151794}] => (Allow) C:\Program Files\Lexmark\MarkVision Professional\MarkVision.exe FirewallRules: [{A1C8E33F-C769-4DCE-A056-D8258A860638}] => (Allow) C:\Program Files\Lexmark\MarkVision Professional\MarkVision.exe FirewallRules: [{E2DE9992-2F9E-481E-8B13-701BDE41A468}] => (Allow) C:\Program Files\Lexmark\MarkVision Professional\jre\bin\java.exe FirewallRules: [{FC7B7112-0E88-44F2-B19C-D31501F02443}] => (Allow) C:\Program Files\Lexmark\MarkVision Professional\jre\bin\java.exe FirewallRules: [{E38B52BF-5763-4C6A-995D-AFC0EE7D7EA3}] => (Allow) C:\Program Files\Lexmark\MarkVision Server\jre\bin\LexWebService.exe FirewallRules: [{C163F46D-F246-44B0-89CD-B528EE947F88}] => (Allow) C:\Program Files\Lexmark\MarkVision Server\jre\bin\LexWebService.exe FirewallRules: [{B17EEC4B-3D5D-4D60-A916-BAFA500D2CEC}] => (Allow) C:\Program Files\Tango\Tango.exe FirewallRules: [{68E9B624-BC85-4565-8640-8757AAB4728B}] => (Allow) C:\Program Files\Tango\Tango.exe FirewallRules: [{888875FC-9F1D-44F3-B885-C375DA482D45}] => (Allow) C:\Program Files\Squeezebox\server\SqueezeSvr.exe FirewallRules: [{1B175F80-5434-4B68-A9CD-A0847B107AEC}] => (Allow) C:\Program Files\devolo\dlan\devolonetsvc.exe FirewallRules: [{7F41BF51-A6D3-4055-AC7D-3107EED0A252}] => (Allow) C:\Program Files\devolo\dlan\devolonetsvc.exe FirewallRules: [{F022EE29-AB96-41AC-B845-74E4BE74B260}] => (Allow) C:\Program Files\Cyberlink\TV Enhance\TVEnhance.exe FirewallRules: [{F9F8C1B3-A412-47D3-8981-667CDE84A681}] => (Allow) C:\Program Files\Cyberlink\TV Enhance\TVEnhance.exe FirewallRules: [{5B42A046-9600-4393-9D1D-E93EC9FF19E1}] => (Allow) C:\Program Files\Cyberlink\TV Enhance\TVEnhance.exe FirewallRules: [{DDD51914-1005-4E19-BC77-F4988960F42C}] => (Allow) C:\Program Files\Cyberlink\TV Enhance\TVEnhance.exe FirewallRules: [{69F2E30D-A0FB-494A-8896-4A967E68908F}] => (Allow) C:\Program Files\Cyberlink\TV Enhance\TVEService.exe FirewallRules: [{E9053A87-55BB-4219-AF6B-8B2D06253BEB}] => (Allow) C:\Program Files\Cyberlink\TV Enhance\TVEService.exe FirewallRules: [{2C2658C3-526F-4361-8780-E526D4EBC68A}] => (Allow) C:\Program Files\Cyberlink\TV Enhance\TVEService.exe FirewallRules: [{F784521F-F85E-4EE4-A957-4A807DB03CF6}] => (Allow) C:\Program Files\Cyberlink\TV Enhance\TVEService.exe FirewallRules: [{38AFEF98-7FCB-4D46-89F7-3EF3A63A467B}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\IDS.Application.exe FirewallRules: [{A825F80C-1108-42D1-A81E-CC6E3A31A0F3}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\IDS.Application.exe FirewallRules: [{039C7FDC-D77A-4129-8CDF-2D307473D9EA}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{2542B7F4-0FBD-4BA5-8E04-E16F075D9989}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{5D84B95B-244D-4649-A603-7578FF08D4C1}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\IDSAlert.exe FirewallRules: [{43A17AA5-772F-4F96-A50D-9F3A1B2233F7}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\IDSAlert.exe FirewallRules: [{8349E402-42C7-4BAA-94CC-AABED5C66DEF}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe FirewallRules: [{7668BF12-D245-4965-BE32-2C97B628BDF0}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe FirewallRules: [{5945268E-EB45-4F1A-9022-6FBBE4A9D508}] => (Allow) LPort=51796 FirewallRules: [{084FC4A1-C9CE-46EC-8F70-E7A376BD4DCA}] => (Allow) C:\Program Files\Twonky\TwonkyServer\twonkystarter.exe FirewallRules: [{9741D666-FE98-4EC2-9D07-15BFAEEE9491}] => (Allow) C:\Program Files\Twonky\TwonkyServer\twonkystarter.exe FirewallRules: [{14955B2A-540B-4598-A5EC-3CDA0102FD61}] => (Allow) C:\Program Files\Twonky\TwonkyServer\twonkyserver.exe FirewallRules: [{6955D3A1-B1DD-4020-B36E-BEC514D1E99C}] => (Allow) C:\Program Files\Twonky\TwonkyServer\twonkyserver.exe FirewallRules: [{A64C4599-457C-4319-84BD-4F1BC8535380}] => (Allow) LPort=9089 FirewallRules: [{CD2CD370-F7B0-486C-844F-1FAABB04FC1C}] => (Allow) C:\Users\Schwedenhaus\AppData\Local\Apps\2.0\YHV6K7M5.MB0\7BKAYVL1.J58\frit..tion_1acae14e4778b8d2_0002.0003_7c9366a34786c7f9\fritzbox-usb-fernanschluss.exe FirewallRules: [{5AB23883-7C3C-43C6-9557-0B7FCCE2A95C}] => (Allow) C:\Users\Schwedenhaus\AppData\Local\Apps\2.0\YHV6K7M5.MB0\7BKAYVL1.J58\frit..tion_1acae14e4778b8d2_0002.0003_7c9366a34786c7f9\fritzbox-usb-fernanschluss.exe FirewallRules: [TCP Query User{BF952D8F-3B9E-414E-B49E-8176D714CD0E}C:\users\schwedenhaus\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\schwedenhaus\appdata\local\akamai\netsession_win.exe FirewallRules: [UDP Query User{FA15678F-F6C6-4D2E-8BC5-A90C9FD3D070}C:\users\schwedenhaus\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\schwedenhaus\appdata\local\akamai\netsession_win.exe FirewallRules: [{5383DCA1-3461-4D34-B564-E101561FB42C}] => (Allow) C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe FirewallRules: [{BA240795-21C2-4A62-B476-A905B820AAC6}] => (Allow) C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe FirewallRules: [{DBE8F04B-EA91-46E8-8678-36946224DF96}] => (Allow) C:\Program Files\Squeezebox\server\SqueezeSvr.exe FirewallRules: [{B207C977-A86B-484C-AF98-4AA000BF6C36}] => (Allow) C:\Users\Schwedenhaus\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{5313148C-F9BB-4E9B-8C3C-1E232F96D2AB}] => (Allow) C:\Users\Schwedenhaus\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{3E88EFA2-953D-4238-8F71-7E0EAD3082DE}] => (Allow) C:\Users\Schwedenhaus\AppData\Local\Apps\2.0\YHV6K7M5.MB0\7BKAYVL1.J58\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{5286308E-1E01-4077-B237-62B2147B1FC8}] => (Allow) C:\Users\Schwedenhaus\AppData\Local\Apps\2.0\YHV6K7M5.MB0\7BKAYVL1.J58\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{2922B205-D713-4B0A-8FF3-96FEAB6EF77E}] => (Allow) %SystemRoot%\ehome\ehrecvr.exe FirewallRules: [{E602AFBF-C5CD-4E3E-B182-8D0F624E626C}] => (Allow) D:\Setup.exe FirewallRules: [{DE22AE7C-1FF9-4CC1-A891-16BD45F08F3D}] => (Allow) C:\Windows\twain_32\Samsung\SLC460\ScanCDLM\ScanCDLM.exe FirewallRules: [{A4DEF7DB-D274-40BE-8179-32495436B2BD}] => (Allow) C:\Windows\twain_32\Samsung\SLC460\ScanCDLM\ScanCDLM.exe FirewallRules: [{0F2D1358-66E5-4371-B97D-3D165F5941BE}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\IDS.Application.exe FirewallRules: [{9657DC83-A9FD-4D90-8EBE-D7D7837F141F}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\IDS.Application.exe FirewallRules: [{77EFF80F-6324-433E-893A-CBD3AA409116}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{82B479A2-96D6-4B3A-BBA8-BF4D078F9070}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{7E6AADB3-F3DB-4361-B85C-AD26AA1FD02C}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\IDSAlert.exe FirewallRules: [{8622BB3A-EFD2-4F95-A053-FB19213FF47A}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\IDSAlert.exe FirewallRules: [{9EDDAC26-4AA9-47CF-B23C-0F94D728EA2C}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\uninstall.exe FirewallRules: [{A19BAE2C-48DD-4470-A849-D2907ADA7C90}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\uninstall.exe FirewallRules: [{E27AC231-71CE-4F9E-B32C-E10914F6C386}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe FirewallRules: [{A4217BBB-9610-4A17-9EED-0375700A662F}] => (Allow) C:\Program Files\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe FirewallRules: [{0B657AA4-4EA4-4087-A114-294D686E6EC5}] => (Allow) C:\Program Files\Samsung\Easy Document Creator\EDC.exe FirewallRules: [{39A34465-3174-45D0-815F-1DCBDFB848D6}] => (Allow) C:\Program Files\Samsung\Easy Document Creator\EDC.exe FirewallRules: [{5D6A9DC5-606F-4C0A-9C25-EB2A69CCBB95}] => (Allow) C:\Program Files\Audials\Audials 12\Audials.exe FirewallRules: [{AA91B1A4-3CD2-4A26-A889-2B7E480F9590}] => (Allow) LPort=12972 FirewallRules: [{DC96E6E1-7588-41DB-A8D9-D161E01E31D5}] => (Allow) LPort=14714 FirewallRules: [{70629B9C-7528-4140-A822-70BF33F0F442}] => (Allow) LPort=31931 FirewallRules: [{F705E7A4-8976-4196-822F-6D79A77C726C}] => (Allow) C:\Program Files\Samsung\SideSync3\SideSync3.exe FirewallRules: [{7E038986-F70B-44B3-A0EE-CB6A271111B4}] => (Allow) C:\Program Files\Samsung\SideSync3\SideSync3.exe FirewallRules: [{F459BE0D-9C94-4DDC-AA75-6C9FE3B97EC8}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe FirewallRules: [{55DF561F-5AA9-4ED6-8F52-706ED10C6950}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe FirewallRules: [{2D4280ED-C7DC-429F-B959-0699AB81ADE7}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe FirewallRules: [{4F6F75D9-F1C5-4F46-9557-9AE89FF8447E}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe FirewallRules: [{3D21F3D2-97F0-4B3E-88DA-857C8C64901F}] => (Allow) C:\Users\Schwedenhaus\AppData\Local\Apps\2.0\YHV6K7M5.MB0\7BKAYVL1.J58\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{34D6DDEE-143D-4C8F-A145-BF6867E2B7BB}] => (Allow) C:\Users\Schwedenhaus\AppData\Local\Apps\2.0\YHV6K7M5.MB0\7BKAYVL1.J58\frit..tion_1acae14e4778b8d2_0002.0003_6dcb4a48ddb2ee39\fritzbox-usb-fernanschluss.exe FirewallRules: [{AA3824D4-B874-4462-B44E-E68AAB30DE24}] => (Allow) LPort=49267 FirewallRules: [{262B82DD-70BA-4BFB-AFC6-70D3C3282EE6}] => (Allow) LPort=5000 FirewallRules: [{F6607716-2F69-4434-B827-B7C5CC6642EA}] => (Allow) C:\Program Files\Squeezebox\server\SqueezeSvr.exe FirewallRules: [{A3899D26-6C06-48C5-8F5C-18C48DE2973D}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{E0AF922C-B5BC-4C4A-960F-7B61570D7784}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{F79E9807-6A26-4CF1-B176-711113D1C9A0}] => (Allow) LPort=49302 FirewallRules: [{47D70C5F-5778-403E-AD87-3DE1CDF6BB9E}] => (Allow) LPort=5000 FirewallRules: [{C685D10F-AE74-4244-9680-8349BB44EE81}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe FirewallRules: [{9609CE9A-1ED7-447A-8BAB-10DFDF6F9B9B}] => (Allow) C:\Program Files\TeamViewer\TeamViewer.exe FirewallRules: [{2B024FB8-0155-4884-A9F7-85C8FDBDEDBF}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe FirewallRules: [{2AE67AAB-06AA-47B3-821E-76D8FDC39996}] => (Allow) C:\Program Files\TeamViewer\TeamViewer_Service.exe FirewallRules: [{089EC4C9-79EC-4358-85C6-9D5CA918B498}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe DomainProfile\AuthorizedApplications: [C:\Program Files\DeTeWe\TapiServer\etapisrv.exe] => Enabled:OpenCTI TapiServer DomainProfile\AuthorizedApplications: [C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7 StandardProfile\AuthorizedApplications: [C:\Program Files\DeTeWe\TapiServer\etapisrv.exe] => Enabled:OpenCTI TapiServer StandardProfile\AuthorizedApplications: [C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7 DomainProfile\GloballyOpenPorts: [10000:TCP] => Enabled:Logitech Media Server 10000 tcp (UI) DomainProfile\GloballyOpenPorts: [3483:TCP] => Enabled:Logitech Media Server 3483 tcp DomainProfile\GloballyOpenPorts: [3483:UDP] => Enabled:Logitech Media Server 3483 udp DomainProfile\GloballyOpenPorts: [8000:TCP] => Enabled:Logitech Media Server 8000 tcp (UI) DomainProfile\GloballyOpenPorts: [9001:TCP] => Enabled:Logitech Media Server 9001 tcp (UI) DomainProfile\GloballyOpenPorts: [9002:TCP] => Enabled:Logitech Media Server 9002 tcp (UI) DomainProfile\GloballyOpenPorts: [9003:TCP] => Enabled:Logitech Media Server 9003 tcp (UI) DomainProfile\GloballyOpenPorts: [9004:TCP] => Enabled:Logitech Media Server 9004 tcp (UI) DomainProfile\GloballyOpenPorts: [9005:TCP] => Enabled:Logitech Media Server 9005 tcp (UI) DomainProfile\GloballyOpenPorts: [9006:TCP] => Enabled:Logitech Media Server 9006 tcp (UI) DomainProfile\GloballyOpenPorts: [9007:TCP] => Enabled:Logitech Media Server 9007 tcp (UI) DomainProfile\GloballyOpenPorts: [9008:TCP] => Enabled:Logitech Media Server 9008 tcp (UI) DomainProfile\GloballyOpenPorts: [9009:TCP] => Enabled:Logitech Media Server 9009 tcp (UI) DomainProfile\GloballyOpenPorts: [9010:TCP] => Enabled:Logitech Media Server 9010 tcp (UI) DomainProfile\GloballyOpenPorts: [9090:TCP] => Enabled:Logitech Media Server 9090 tcp (UI) DomainProfile\GloballyOpenPorts: [9100:TCP] => Enabled:Logitech Media Server 9100 tcp (UI) StandardProfile\GloballyOpenPorts: [10000:TCP] => Enabled:Logitech Media Server 10000 tcp (UI) StandardProfile\GloballyOpenPorts: [3483:TCP] => Enabled:Logitech Media Server 3483 tcp StandardProfile\GloballyOpenPorts: [3483:UDP] => Enabled:Logitech Media Server 3483 udp StandardProfile\GloballyOpenPorts: [8000:TCP] => Enabled:Logitech Media Server 8000 tcp (UI) StandardProfile\GloballyOpenPorts: [9001:TCP] => Enabled:Logitech Media Server 9001 tcp (UI) StandardProfile\GloballyOpenPorts: [9002:TCP] => Enabled:Logitech Media Server 9002 tcp (UI) StandardProfile\GloballyOpenPorts: [9003:TCP] => Enabled:Logitech Media Server 9003 tcp (UI) StandardProfile\GloballyOpenPorts: [9004:TCP] => Enabled:Logitech Media Server 9004 tcp (UI) StandardProfile\GloballyOpenPorts: [9005:TCP] => Enabled:Logitech Media Server 9005 tcp (UI) StandardProfile\GloballyOpenPorts: [9006:TCP] => Enabled:Logitech Media Server 9006 tcp (UI) StandardProfile\GloballyOpenPorts: [9007:TCP] => Enabled:Logitech Media Server 9007 tcp (UI) StandardProfile\GloballyOpenPorts: [9008:TCP] => Enabled:Logitech Media Server 9008 tcp (UI) StandardProfile\GloballyOpenPorts: [9009:TCP] => Enabled:Logitech Media Server 9009 tcp (UI) StandardProfile\GloballyOpenPorts: [9010:TCP] => Enabled:Logitech Media Server 9010 tcp (UI) StandardProfile\GloballyOpenPorts: [9090:TCP] => Enabled:Logitech Media Server 9090 tcp (UI) StandardProfile\GloballyOpenPorts: [9100:TCP] => Enabled:Logitech Media Server 9100 tcp (UI) ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: FRITZ!WLAN USB Stick N #2 - RRNetCap Miniport Description: RRNetCap Miniport Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: RapidSolution Software AG Service: RRNetCapMP Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: FRITZ!WLAN USB Stick N - RRNetCap Miniport Description: RRNetCap Miniport Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: RapidSolution Software AG Service: RRNetCapMP Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Atheros L1 Gigabit Ethernet 10/100/1000Base-T Controller - RRNetCap Miniport Description: RRNetCap Miniport Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: RapidSolution Software AG Service: RRNetCapMP Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: WAN-Miniport (IP) - RRNetCap Miniport Description: RRNetCap Miniport Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: RapidSolution Software AG Service: RRNetCapMP Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: WAN-Miniport (Netzwerkmonitor) - RRNetCap Miniport Description: RRNetCap Miniport Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: RapidSolution Software AG Service: RRNetCapMP Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: WAN-Miniport (IPv6) - RRNetCap Miniport Description: RRNetCap Miniport Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: RapidSolution Software AG Service: RRNetCapMP Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: McAfee NDIS Light Filter Description: McAfee NDIS Light Filter Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: mfenlfk Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft-Adapter für Miniports virtueller WiFis - RRNetCap Miniport Description: RRNetCap Miniport Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: RapidSolution Software AG Service: RRNetCapMP Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Linksys AE1000 - RRNetCap Miniport Description: RRNetCap Miniport Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: RapidSolution Software AG Service: RRNetCapMP Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (09/03/2015 05:22:47 PM) (Source: wmssvc.exe) (EventID: 0) (User: ) Description: (10049) Bindung Socket Fehler: 169.254.129.185: 45357 Error: (09/03/2015 05:22:43 PM) (Source: wmssvc.exe) (EventID: 0) (User: ) Description: (10049) Bindung Socket Fehler: 169.254.245.16: 45357 Error: (09/03/2015 05:22:43 PM) (Source: wmssvc.exe) (EventID: 0) (User: ) Description: (10049) Bindung Socket Fehler: 169.254.129.185: 45357 Error: (09/03/2015 05:22:35 PM) (Source: wmssvc.exe) (EventID: 0) (User: ) Description: (10049) Bindung Socket Fehler: 169.254.129.185: 45357 Error: (09/03/2015 05:22:26 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1511) (User: SH-PC2) Description: Das lokale Benutzerprofil wurde nicht gefunden. Sie werden mit einem temporären Benutzerprofil angemeldet. Änderungen, die Sie am Benutzerprofil vornehmen, gehen bei der Abmeldung verloren. Error: (09/03/2015 05:22:26 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1515) (User: SH-PC2) Description: Dieses Benutzerprofil wurde gesichert. Bei der nächsten Anmeldung dieses Benutzers wird automatisch versucht, dieses gesicherte Profil zu verwenden. Error: (09/03/2015 05:19:47 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Explorer.EXE, Version 6.1.7601.17567 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: d60 Startzeit: 01d0e3dffa6364de Endzeit: 15 Anwendungspfad: C:\Windows\Explorer.EXE Berichts-ID: 27f4e2f0-524f-11e5-94e3-00505637a7f6 Error: (09/03/2015 09:13:10 AM) (Source: Winlogon) (EventID: 4005) (User: ) Description: Der Windows-Anmeldeprozess wurde unerwartet beendet. Error: (09/02/2015 08:48:11 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-3086022667-2732812533-850181598-500.bak)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig. . Vorgang: OnIdentify-Ereignis Generatordaten werden gesammelt Kontext: Ausführungskontext: Shadow Copy Optimization Writer Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Generatorname: Shadow Copy Optimization Writer Generatorinstanz-ID: {ef97b77f-bb38-4de5-b71c-8780e7c301f0} Error: (09/02/2015 08:34:05 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-3086022667-2732812533-850181598-500.bak)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig. . Vorgang: OnIdentify-Ereignis Generatordaten werden gesammelt Kontext: Ausführungskontext: Shadow Copy Optimization Writer Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Generatorname: Shadow Copy Optimization Writer Generatorinstanz-ID: {ef97b77f-bb38-4de5-b71c-8780e7c301f0} Systemfehler: ============= Error: (09/03/2015 06:50:19 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "TVEnhance Task Scheduler (TTS))" wurde unerwartet beendet. Dies ist bereits 7009 Mal passiert. Error: (09/03/2015 06:50:19 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "TVEnhance Background Capture Service (TBCS)" wurde unerwartet beendet. Dies ist bereits 7017 Mal passiert. Error: (09/03/2015 06:50:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "TVEnhance Task Scheduler (TTS))" wurde unerwartet beendet. Dies ist bereits 7008 Mal passiert. Error: (09/03/2015 06:50:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "TVEnhance Background Capture Service (TBCS)" wurde unerwartet beendet. Dies ist bereits 7016 Mal passiert. Error: (09/03/2015 06:50:17 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "TVEnhance Task Scheduler (TTS))" wurde unerwartet beendet. Dies ist bereits 7007 Mal passiert. Error: (09/03/2015 06:50:17 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "TVEnhance Background Capture Service (TBCS)" wurde unerwartet beendet. Dies ist bereits 7015 Mal passiert. Error: (09/03/2015 06:50:17 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "TVEnhance Task Scheduler (TTS))" wurde unerwartet beendet. Dies ist bereits 7006 Mal passiert. Error: (09/03/2015 06:50:17 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "TVEnhance Background Capture Service (TBCS)" wurde unerwartet beendet. Dies ist bereits 7014 Mal passiert. Error: (09/03/2015 06:50:16 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "TVEnhance Task Scheduler (TTS))" wurde unerwartet beendet. Dies ist bereits 7005 Mal passiert. Error: (09/03/2015 06:50:16 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "TVEnhance Background Capture Service (TBCS)" wurde unerwartet beendet. Dies ist bereits 7013 Mal passiert. Microsoft Office: ========================= Error: (11/18/2011 11:08:19 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3 seconds with 0 seconds of active time. This session ended with a crash. Error: (06/29/2011 07:57:44 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6557.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2 seconds with 0 seconds of active time. This session ended with a crash. Error: (06/29/2011 07:57:41 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 9 seconds with 0 seconds of active time. This session ended with a crash. Error: (05/20/2011 07:38:38 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 113 seconds with 60 seconds of active time. This session ended with a crash. Error: (04/07/2011 04:06:30 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4 seconds with 0 seconds of active time. This session ended with a crash. Error: (01/29/2010 03:51:16 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 9, Application Name: Microsoft Office Project, Application Version: 12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 90356 seconds with 17340 seconds of active time. This session ended with a crash. Error: (12/02/2009 10:06:11 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1248 seconds with 240 seconds of active time. This session ended with a crash. CodeIntegrity: =================================== Date: 2015-09-01 18:42:57.663 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codecp.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-09-01 17:47:53.794 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codecp.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-08-31 13:27:45.123 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codecp.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-08-31 13:24:13.099 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codecp.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-08-31 13:15:33.578 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codecp.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-08-31 13:05:49.581 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codecp.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-08-31 12:39:48.146 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codecp.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-08-31 11:39:28.320 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codecp.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-08-31 10:39:04.391 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codecp.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-08-31 09:38:49.750 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codecp.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3450 CPU @ 3.10GHz Prozentuale Nutzung des RAM: 65% Installierter physikalischer RAM: 3071.55 MB Verfügbarer physikalischer RAM: 1073.72 MB Summe virtueller Speicher: 6141.42 MB Verfügbarer virtueller Speicher: 4183.86 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:149.05 GB) (Free:24.39 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)] Drive d: (GSP1RMCPRFRER_DE_DVD) (CDROM) (Total:2.34 GB) (Free:0 GB) UDF ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 149.1 GB) (Disk ID: 5DA55353) Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS) ==================== Ende vom Addition.txt ============================ |
03.09.2015, 18:33 | #5 |
/// the machine /// TB-Ausbilder | __prosschiff@gmail.com_.crypt Wurden auch schon Dateien verschlüsselt? Denn die sind nicht mehr zu retten.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.09.2015, 18:37 | #6 |
| Ja die Dateien sind verschlüsselt Hmmm... das ist ja s.. blöd. Aber trotzdem muß das Plagegeist runter, damit mich mir wenigstens die Dateien (Dateinamen) sorglos ansehen kann um einiges nachkonstruieren zu können. Danke Torsten.E |
04.09.2015, 17:35 | #7 |
/// the machine /// TB-Ausbilder | __prosschiff@gmail.com_.crypt Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu __prosschiff@gmail.com_.crypt |
bringe, dateien, endung, funktionier, funktioniert, meinem, natürlich, nichts, plagegeist, prosschiff |