|
Log-Analyse und Auswertung: Plötzliche Systemabschaltung bei Windows 7 und BluescreenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
17.10.2015, 19:36 | #1 |
| Plötzliche Systemabschaltung bei Windows 7 und Bluescreen Liebes Trojaner-Board Team, seit gestern schaltet sich mein Laptop (Windows 7, 64bit Version) immer wieder spontan einfach ab und es erscheint ein Bluescreen. Darin werde ich aufgefordert sämtliche Anti-Viren-Programme zu deaktivieren, was mich dann doch etwas stutzig gemacht hat. Hier ein Screenshot des Bluescreens: Mit meinen beschränkten Kenntnissen bin ich allerdings dem Problem bisher nicht Herr geworden, weshalb ich mich nun hikfesuchend an euch wende. Die herkömmliche Suche mit Malwarebytes und avast haben keine Treffer ergeben: Code:
ATTFilter <?xml version="1.0" encoding="UTF-8" ?> <logs> <record severity="debug" LoggingEventType="4" datetime="2015-10-17T00:15:22.891913+02:00" source="Protection" type="Error" username="SYSTEM" systemname="ROBERTBERGMEIER" code="13" last_modified_tag="e04890af-9eab-4a02-b319-73c53ee1b7d6" message="IsLicensed"></record> <record severity="debug" LoggingEventType="2" datetime="2015-10-17T00:15:22.891913+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="ROBERTBERGMEIER" last_modified_tag="eb98c0bf-083f-4960-8343-e2ece270a4f2" result="Stopping" subtype="Malware Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2015-10-17T00:15:22.907513+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="ROBERTBERGMEIER" last_modified_tag="1febeb98-97ba-4398-9ddc-8361c6d58d58" result="Stopped" subtype="Malware Protection"></record> <record severity="debug" LoggingEventType="4" datetime="2015-10-17T12:23:15.593304+02:00" source="Protection" type="Error" username="SYSTEM" systemname="ROBERTBERGMEIER" code="13" last_modified_tag="71c28103-131b-4979-b469-d9ed780e991d" message="IsLicensed"></record> <record severity="debug" LoggingEventType="2" datetime="2015-10-17T12:23:15.608904+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="ROBERTBERGMEIER" last_modified_tag="2ddbb74a-51ed-45ed-9953-13b5ad250e4a" result="Stopping" subtype="Malware Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2015-10-17T12:23:15.608904+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="ROBERTBERGMEIER" last_modified_tag="cabc8e35-fa87-426c-a693-5d226bc0d738" result="Stopped" subtype="Malware Protection"></record> <record severity="debug" LoggingEventType="4" datetime="2015-10-17T18:47:09.247910+02:00" source="Protection" type="Error" username="SYSTEM" systemname="ROBERTBERGMEIER" code="13" last_modified_tag="e5dcd791-e4aa-40b8-9efa-091251f9ecd4" message="IsLicensed"></record> <record severity="debug" LoggingEventType="2" datetime="2015-10-17T18:47:09.279110+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="ROBERTBERGMEIER" last_modified_tag="f672644f-5ccb-43fa-be5c-fb72cd54359a" result="Stopping" subtype="Malware Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2015-10-17T18:47:09.279110+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="ROBERTBERGMEIER" last_modified_tag="a0325049-a60f-4e4b-84a7-5d6d3d756c05" result="Stopped" subtype="Malware Protection"></record> </logs> Geändert von student_25 (17.10.2015 um 19:50 Uhr) |
17.10.2015, 20:06 | #2 |
/// the machine /// TB-Ausbilder | Plötzliche Systemabschaltung bei Windows 7 und Bluescreen hi,
__________________Lade Dir bitte Bluescreenview und installiere es: BlueScreenView - Download - Filepony Öffnen und den aktuellsten Dump analysieren lassen (macht das Tool automatisch). Output hier posten. Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
17.10.2015, 21:16 | #3 |
| Plötzliche Systemabschaltung bei Windows 7 und Bluescreen Hier schon mal der erste FRST Log:
__________________Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:17-10-2015 durchgeführt von ***** (Administrator) auf ROBERTBERGMEIER (17-10-2015 19:01:57) Gestartet von C:\Users\*****\Downloads Geladene Profile: ***** (Verfügbare Profile: *****) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AMD) C:\Windows\System32\atiesrxx.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Sony Corporation) C:\Program Files\sony\Network Utility\NSUService.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio64.exe () C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Sony Corporation) C:\Program Files\sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Sony Corporation) C:\Program Files\sony\VAIO Update\VUAgent.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7938080 2009-08-21] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-08-21] (Realtek Semiconductor Corp.) HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.) HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [438784 2010-12-17] () HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-09-15] (Apple Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-04] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AML] => C:\Program Files (x86)\Sony\VAIO Launcher\AML.exe [1101824 2009-07-15] (Sony) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-09-15] (Apple Inc.) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1679360 2012-02-28] (Wondershare) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-06-29] (Avast Software s.r.o.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.) Winlogon\Notify\VESWinlogon-x32: VESWinlogon.dll [X] HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [163328 2010-11-20] (Microsoft Corporation) HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2015-04-26] (Apple Inc.) HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2015-04-26] (Apple Inc.) HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2015-04-26] (Apple Inc.) HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1403192 2015-09-11] (Garmin Ltd. or its subsidiaries) HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\...\Run: [Dropbox Update] => C:\Users\*****\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-19] (Dropbox, Inc.) HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [787592 2015-09-21] (Sandboxie Holdings, LLC) HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\...\MountPoints2: {c853dec7-15c7-11e1-8fcd-00214ffdb918} - F:\LaunchU3.exe -a HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1403192 2015-09-11] (Garmin Ltd. or its subsidiaries) ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-06-29] (Avast Software s.r.o.) ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk [2009-09-07] ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.) Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-12-12] ShortcutTarget: Dropbox.lnk -> C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{29F76615-0621-43A6-AC08-E8213911782C}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{5FF0D8E2-5A83-4659-B7A2-DE64FF7FF1A0}: [DhcpNameServer] 172.20.10.1 Tcpip\..\Interfaces\{A396AE63-6965-471D-A8D4-71CABCDFB551}: [DhcpNameServer] 141.78.7.250 141.78.7.200 141.78.7.168 141.78.99.101 Tcpip\..\Interfaces\{E3616415-BC78-42B0-A64D-8C624C27E4DA}: [DhcpNameServer] 141.78.7.168 141.78.7.200 141.78.7.250 Internet Explorer: ================== HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.web.de/ HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006 URLSearchHook: HKLM-x32 -> Standard = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = SearchScopes: HKLM -> {AFB4D376-D858-409B-A6E3-9B9D65BDDFF2} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta= SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SNYT SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-06-29] (Avast Software s.r.o.) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll => Keine Datei BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22] (Hewlett-Packard Co.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-08-02] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-06-29] (Avast Software s.r.o.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-02] (Oracle Corporation) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22] (Hewlett-Packard Co.) Toolbar: HKLM - Kein Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Keine Datei Toolbar: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000 -> Kein Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Keine Datei Toolbar: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000 -> Kein Name - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - Keine Datei DPF: HKLM-x32 {59136DB4-6CA3-4B40-8F2F-BBF84B6F1E91} hxxps://stream.web.de/mail/activex/mail_upload_11213.cab DPF: HKLM-x32 {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\mg2x8srg.default-1440969205059 FF DefaultSearchEngine: Google FF Homepage: hxxp://web.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll [2015-10-17] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-17] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-07-03] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-07-03] (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-02] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-02] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.) FF Plugin HKU\S-1-5-21-3049852783-3627140865-2715150416-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-02-18] (Ubisoft) FF Extension: WOT - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\mg2x8srg.default-1440969205059\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-08-30] FF Extension: Adblock Plus Pop-up Addon - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\mg2x8srg.default-1440969205059\Extensions\adblockpopups@jessehakanen.net.xpi [2015-08-30] FF Extension: Adblock Plus - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\mg2x8srg.default-1440969205059\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-08-30] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-02-26] [ist nicht signiert] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-09-07] [ist nicht signiert] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-04] [ist nicht signiert] FF HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR dev: Chrome dev build erkannt! <======= ACHTUNG CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-06-29] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-06-29] (Avast Software s.r.o.) S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2009-08-26] (Macrovision Europe Ltd.) [Datei ist nicht signiert] S3 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [762272 2015-09-11] (Garmin Ltd. or its subsidiaries) S2 gupdate1ca2fff8f11d930; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-30] (Google Inc.) R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [Datei ist nicht signiert] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [Datei ist nicht signiert] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [Datei ist nicht signiert] S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes) R2 NSUService; C:\Program Files\sony\Network Utility\NSUService.exe [361472 2009-06-11] (Sony Corporation) [Datei ist nicht signiert] S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-01] (Electronic Arts) S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [114688 2009-01-08] (Sony Corporation) [Datei ist nicht signiert] S3 Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-06-26] (Sonic Solutions) S2 Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-06-26] (Sonic Solutions) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [177800 2015-09-21] (Sandboxie Holdings, LLC) S3 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-07-27] (Sony Corporation) S3 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-07-27] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-07-23] (Sony Corporation) [Datei ist nicht signiert] R2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [642920 2009-07-22] (Sony Corporation) R3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-07-23] (Sony Corporation) R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1642544 2014-02-28] (Sony Corporation) R2 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [206336 2009-07-23] (Sony Corporation) [Datei ist nicht signiert] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 c2cautoupdatesvc; "C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service [X] S2 c2cpnrsvc; "C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service [X] ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2008-04-24] (ArcSoft, Inc.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-06-29] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-06-29] (Avast Software s.r.o.) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-06-29] (Avast Software s.r.o.) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-06-29] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-06-29] (Avast Software s.r.o.) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-06-29] (Avast Software s.r.o.) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-06-29] (Avast Software s.r.o.) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-06-29] () S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation) S3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [102600 2009-07-08] (McAfee, Inc.) R1 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [307400 2009-07-08] (McAfee, Inc.) S3 mferkdk; C:\Windows\System32\drivers\mferkdk.sys [40904 2009-07-08] (McAfee, Inc.) S3 mfesmfk; C:\Windows\System32\drivers\mfesmfk.sys [49480 2009-07-08] (McAfee, Inc.) R2 risdptsk; C:\Windows\System32\DRIVERS\risdsn64.sys [76288 2008-10-23] (REDC) S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [115240 2008-05-16] (MCCI Corporation) S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [19496 2008-05-16] (MCCI Corporation) S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [158760 2008-05-16] (MCCI Corporation) S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [137256 2008-05-16] (MCCI Corporation) S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [34344 2008-05-16] (MCCI Corporation) S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [136744 2008-05-16] (MCCI Corporation) S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [151592 2008-05-16] (MCCI Corporation) S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [116264 2008-05-27] (MCCI Corporation) S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [19496 2008-05-27] (MCCI Corporation) S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [159784 2008-05-27] (MCCI Corporation) S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [138792 2008-05-27] (MCCI Corporation) S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [34856 2008-05-27] (MCCI Corporation) S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [137768 2008-05-27] (MCCI Corporation) S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [153128 2008-05-27] (MCCI Corporation) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [191624 2015-09-21] (Sandboxie Holdings, LLC) R3 seehcri; C:\Windows\System32\DRIVERS\seehcri.sys [34032 2008-01-09] (Sony Ericsson Mobile Communications) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X] S1 flpusbxw; \??\C:\Windows\system32\drivers\flpusbxw.sys [X] S2 regi; \??\C:\Windows\system32\drivers\regi.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-10-17 19:01 - 2015-10-17 19:02 - 00030351 _____ C:\Users\*****\Downloads\FRST.txt 2015-10-17 19:01 - 2015-10-17 19:02 - 00000000 ____D C:\FRST 2015-10-17 19:01 - 2015-10-17 19:01 - 00000494 _____ C:\Users\*****\Downloads\defogger_disable.log 2015-10-17 19:01 - 2015-10-17 19:01 - 00000000 _____ C:\Users\*****\defogger_reenable 2015-10-17 19:00 - 2015-10-17 19:00 - 02196992 _____ (Farbar) C:\Users\*****\Downloads\FRST64.exe 2015-10-17 19:00 - 2015-10-17 19:00 - 00050477 _____ C:\Users\*****\Downloads\Defogger.exe 2015-10-17 18:39 - 2015-10-17 18:39 - 00278504 _____ C:\Windows\Minidump\101715-31855-01.dmp 2015-10-17 00:14 - 2015-10-17 00:15 - 00262144 _____ C:\Windows\Minidump\101715-44132-01.dmp 2015-10-16 19:58 - 2015-10-16 19:59 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-10-16 19:58 - 2015-10-16 19:58 - 00001106 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-10-16 19:58 - 2015-10-16 19:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-10-16 19:58 - 2015-10-16 19:58 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-10-16 19:58 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-10-16 19:58 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-10-16 19:58 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2015-10-16 17:21 - 2015-10-16 19:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-10-16 11:52 - 2015-10-17 18:39 - 666221477 _____ C:\Windows\MEMORY.DMP 2015-10-16 11:52 - 2015-10-16 11:52 - 00274136 _____ C:\Windows\Minidump\101615-35537-01.dmp 2015-10-15 15:13 - 2015-10-15 16:22 - 00000000 __SHD C:\Recovery 2015-10-15 13:36 - 2015-10-15 13:37 - 00000757 _____ C:\Windows\DtcInstall.log 2015-10-15 13:32 - 2015-10-15 13:33 - 00001559 _____ C:\Windows\comsetup.log 2015-10-15 11:42 - 2015-09-18 21:22 - 00025432 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2015-10-15 11:42 - 2015-09-18 21:19 - 01291264 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-10-15 11:42 - 2015-09-18 21:19 - 00766464 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-10-15 11:42 - 2015-09-18 21:19 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-10-15 11:42 - 2015-09-18 21:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-10-15 11:42 - 2015-09-18 21:19 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-10-15 11:42 - 2015-09-18 21:09 - 01163776 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-10-14 11:35 - 2015-09-25 20:07 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-10-14 11:35 - 2015-09-25 20:07 - 02607104 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-10-14 11:35 - 2015-09-25 20:07 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-10-14 11:35 - 2015-09-25 20:07 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-10-14 11:35 - 2015-09-25 20:07 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-10-14 11:35 - 2015-09-25 20:07 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-10-14 11:35 - 2015-09-25 20:07 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-10-14 11:35 - 2015-09-25 20:06 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-10-14 11:35 - 2015-09-25 20:06 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-10-14 11:35 - 2015-09-25 20:06 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-10-14 11:35 - 2015-09-25 20:06 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-10-14 11:35 - 2015-09-25 19:59 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-10-14 11:35 - 2015-09-25 19:59 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-10-14 11:35 - 2015-09-25 19:59 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-10-14 11:35 - 2015-09-25 19:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-10-14 11:35 - 2015-09-25 19:58 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-10-14 11:35 - 2015-08-06 20:04 - 14176768 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-10-14 11:35 - 2015-08-06 20:03 - 01866752 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2015-10-14 11:35 - 2015-08-06 19:44 - 12875776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2015-10-14 11:35 - 2015-08-06 19:44 - 01498624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2015-10-14 11:34 - 2015-09-18 21:31 - 00391784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-10-14 11:34 - 2015-09-18 20:58 - 00345688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-10-14 11:34 - 2015-09-16 06:48 - 25851904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-10-14 11:34 - 2015-09-16 06:36 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-10-14 11:34 - 2015-09-16 06:36 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-10-14 11:34 - 2015-09-16 06:22 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-10-14 11:34 - 2015-09-16 06:21 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-10-14 11:34 - 2015-09-16 06:21 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-10-14 11:34 - 2015-09-16 06:21 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-10-14 11:34 - 2015-09-16 06:21 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-10-14 11:34 - 2015-09-16 06:21 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-10-14 11:34 - 2015-09-16 06:14 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-10-14 11:34 - 2015-09-16 06:13 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-10-14 11:34 - 2015-09-16 06:10 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-10-14 11:34 - 2015-09-16 06:09 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-10-14 11:34 - 2015-09-16 06:08 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-10-14 11:34 - 2015-09-16 06:08 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-10-14 11:34 - 2015-09-16 06:08 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-10-14 11:34 - 2015-09-16 06:08 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-10-14 11:34 - 2015-09-16 06:01 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-10-14 11:34 - 2015-09-16 05:58 - 20357632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-10-14 11:34 - 2015-09-16 05:58 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-10-14 11:34 - 2015-09-16 05:50 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-10-14 11:34 - 2015-09-16 05:46 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-10-14 11:34 - 2015-09-16 05:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-10-14 11:34 - 2015-09-16 05:45 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-10-14 11:34 - 2015-09-16 05:43 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-10-14 11:34 - 2015-09-16 05:41 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2015-10-14 11:34 - 2015-09-16 05:33 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-10-14 11:34 - 2015-09-16 05:33 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-10-14 11:34 - 2015-09-16 05:32 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-10-14 11:34 - 2015-09-16 05:32 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-10-14 11:34 - 2015-09-16 05:31 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-10-14 11:34 - 2015-09-16 05:31 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-10-14 11:34 - 2015-09-16 05:29 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-10-14 11:34 - 2015-09-16 05:29 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-10-14 11:34 - 2015-09-16 05:28 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-10-14 11:34 - 2015-09-16 05:28 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-10-14 11:34 - 2015-09-16 05:26 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-10-14 11:34 - 2015-09-16 05:26 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-10-14 11:34 - 2015-09-16 05:26 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-10-14 11:34 - 2015-09-16 05:24 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-10-14 11:34 - 2015-09-16 05:23 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-10-14 11:34 - 2015-09-16 05:22 - 14458368 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-10-14 11:34 - 2015-09-16 05:22 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-10-14 11:34 - 2015-09-16 05:22 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-10-14 11:34 - 2015-09-16 05:15 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-10-14 11:34 - 2015-09-16 05:11 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-10-14 11:34 - 2015-09-16 05:10 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-10-14 11:34 - 2015-09-16 05:07 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-10-14 11:34 - 2015-09-16 05:06 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-10-14 11:34 - 2015-09-16 05:05 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-10-14 11:34 - 2015-09-16 05:05 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-10-14 11:34 - 2015-09-16 05:04 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2015-10-14 11:34 - 2015-09-16 04:59 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-10-14 11:34 - 2015-09-16 04:58 - 12853760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-10-14 11:34 - 2015-09-16 04:58 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-10-14 11:34 - 2015-09-16 04:56 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-10-14 11:34 - 2015-09-16 04:55 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-10-14 11:34 - 2015-09-16 04:55 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-10-14 11:34 - 2015-09-16 04:48 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-10-14 11:34 - 2015-09-16 04:37 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-10-14 11:34 - 2015-09-16 04:34 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-10-14 11:34 - 2015-09-16 04:32 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-10-14 11:33 - 2015-10-01 20:12 - 00706496 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2015-10-14 11:33 - 2015-10-01 20:10 - 00631384 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2015-10-14 11:33 - 2015-10-01 20:09 - 01729984 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-10-14 11:33 - 2015-10-01 20:07 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-10-14 11:33 - 2015-10-01 20:07 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-10-14 11:33 - 2015-10-01 20:07 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-10-14 11:33 - 2015-10-01 20:07 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 01166336 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00730112 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-10-14 11:33 - 2015-10-01 20:06 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-10-14 11:33 - 2015-10-01 20:06 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-10-14 11:33 - 2015-10-01 20:06 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-10-14 11:33 - 2015-10-01 20:05 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-10-14 11:33 - 2015-10-01 20:05 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2015-10-14 11:33 - 2015-10-01 20:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-10-14 11:33 - 2015-10-01 20:05 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2015-10-14 11:33 - 2015-10-01 20:02 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-10-14 11:33 - 2015-10-01 20:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-10-14 11:33 - 2015-10-01 19:43 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2015-10-14 11:33 - 2015-10-01 19:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2015-10-14 11:33 - 2015-10-01 18:47 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-10-14 11:33 - 2015-10-01 18:46 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2015-10-14 11:33 - 2015-10-01 18:46 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-10-14 11:33 - 2015-09-28 22:21 - 03996608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-10-14 11:33 - 2015-09-28 22:21 - 03940800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-10-14 11:33 - 2015-09-28 22:19 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-10-14 11:33 - 2015-09-28 22:17 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-10-14 11:33 - 2015-09-28 22:17 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2015-10-14 11:33 - 2015-09-28 22:17 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-10-14 11:33 - 2015-09-28 22:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-10-14 11:33 - 2015-09-28 22:17 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2015-10-14 11:33 - 2015-09-28 22:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-10-14 11:33 - 2015-09-28 22:17 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-10-14 11:33 - 2015-09-28 22:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2015-10-14 11:33 - 2015-09-28 22:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-10-14 11:33 - 2015-09-28 22:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-10-14 11:33 - 2015-09-28 22:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-10-14 11:33 - 2015-09-28 22:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-10-14 11:33 - 2015-09-28 22:15 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-10-14 11:33 - 2015-09-28 22:15 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2015-10-14 11:33 - 2015-09-28 22:15 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-10-14 11:33 - 2015-09-28 22:15 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-10-14 11:33 - 2015-09-28 22:11 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-10-14 11:33 - 2015-09-28 22:11 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 22:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 20:22 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-10-14 11:33 - 2015-09-28 18:35 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-10-14 11:33 - 2015-09-28 18:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-10-14 11:33 - 2015-09-28 18:33 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 18:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 18:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-10-14 11:33 - 2015-09-28 18:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-10-14 11:33 - 2015-09-16 01:45 - 00157016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-10-14 11:33 - 2015-09-16 01:45 - 00097112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-10-14 11:33 - 2015-09-16 01:37 - 01464832 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-10-14 11:33 - 2015-09-16 01:37 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-10-14 11:33 - 2015-09-16 01:37 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-10-14 11:33 - 2015-09-16 01:37 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-10-14 11:33 - 2015-09-16 01:37 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-10-14 11:33 - 2015-09-16 01:37 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-10-14 11:33 - 2015-09-16 01:37 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-10-14 11:33 - 2015-09-16 01:25 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-10-14 11:33 - 2015-09-16 01:25 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-10-14 11:33 - 2015-09-16 01:25 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-10-14 11:33 - 2015-09-16 01:21 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-10-14 11:33 - 2015-09-14 23:40 - 00634432 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2015-10-14 11:31 - 2015-07-18 15:08 - 00984448 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00901264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2015-10-14 11:31 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2015-10-05 19:22 - 2015-10-05 19:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie 2015-10-03 20:31 - 2015-10-03 20:31 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-09-22 13:14 - 2015-09-22 13:14 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk 2015-09-22 13:14 - 2015-09-22 13:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-09-22 13:13 - 2015-09-22 13:14 - 00000000 ____D C:\Program Files\iTunes 2015-09-22 13:13 - 2015-09-22 13:13 - 00000000 ____D C:\Program Files\iPod 2015-09-22 13:13 - 2015-09-22 13:13 - 00000000 ____D C:\Program Files (x86)\iTunes 2015-09-22 13:09 - 2015-09-22 13:09 - 00000000 ____D C:\Program Files\Bonjour 2015-09-22 13:09 - 2015-09-22 13:09 - 00000000 ____D C:\Program Files (x86)\Bonjour 2015-09-22 13:08 - 2015-09-22 13:08 - 00000000 ____D C:\Windows\System32\Tasks\Apple 2015-09-22 13:08 - 2015-09-22 13:08 - 00000000 ____D C:\Program Files (x86)\Apple Software Update ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-10-17 19:01 - 2010-05-31 18:37 - 00000000 ____D C:\Users\***** 2015-10-17 18:59 - 2010-05-31 18:32 - 00019120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-10-17 18:59 - 2010-05-31 18:32 - 00019120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-10-17 18:55 - 2015-03-01 14:52 - 01203363 _____ C:\Windows\WindowsUpdate.log 2015-10-17 18:54 - 2010-05-31 19:54 - 00004002 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F0487B1B-9B33-4806-BA3D-9F3C72DFBBEA} 2015-10-17 18:50 - 2013-07-10 21:06 - 00000000 ___RD C:\Users\*****\Dropbox 2015-10-17 18:49 - 2012-06-02 17:08 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox 2015-10-17 18:48 - 2014-09-26 11:45 - 00000000 ___RD C:\Users\*****\iCloudDrive 2015-10-17 18:47 - 2009-09-07 23:25 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-10-17 18:46 - 2015-08-30 17:07 - 00064335 _____ C:\Windows\setupact.log 2015-10-17 18:46 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-10-17 18:39 - 2012-08-08 18:02 - 00000000 ____D C:\Windows\Minidump 2015-10-17 18:25 - 2012-03-29 12:14 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-10-17 18:23 - 2009-09-07 23:25 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-10-17 18:18 - 2015-06-19 18:31 - 00001268 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3049852783-3627140865-2715150416-1000UA.job 2015-10-17 16:25 - 2012-03-29 12:14 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-10-17 16:25 - 2012-03-29 12:14 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-10-17 16:25 - 2012-03-14 15:04 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-10-17 12:41 - 2015-06-19 18:31 - 00001216 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3049852783-3627140865-2715150416-1000Core.job 2015-10-16 23:05 - 2014-02-03 12:20 - 00000000 ____D C:\Users\*****\Desktop\PNP 2015-10-16 22:54 - 2014-01-04 11:35 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2015-10-16 22:53 - 2014-01-05 15:56 - 00004232 _____ C:\Windows\Sandboxie.ini 2015-10-16 22:49 - 2015-08-31 12:27 - 00007228 _____ C:\Windows\PFRO.log 2015-10-16 22:49 - 2012-05-03 13:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-10-16 18:04 - 2015-01-31 14:05 - 00000000 ____D C:\ProgramData\Origin 2015-10-16 17:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2015-10-16 12:32 - 2013-07-11 12:46 - 00000000 ____D C:\Users\*****\AppData\Local\CrashDumps 2015-10-16 01:46 - 2014-12-10 19:13 - 00000000 ____D C:\Windows\system32\appraiser 2015-10-16 01:46 - 2014-05-06 14:28 - 00000000 ___SD C:\Windows\system32\CompatTel 2015-10-15 15:24 - 2015-09-10 08:42 - 00000000 ___HD C:\$Windows.~BT 2015-10-15 13:39 - 2009-03-20 19:44 - 00008192 __RSH C:\BOOTSECT.BAK 2015-10-15 13:32 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2015-10-15 13:27 - 2014-09-02 18:30 - 00010448 _____ C:\Windows\system32\lvcoinst.log 2015-10-15 13:26 - 2015-08-30 17:07 - 00000495 _____ C:\Windows\setuperr.log 2015-10-15 13:26 - 2010-05-31 16:54 - 00010368 _____ C:\Windows\diagerr.xml 2015-10-15 13:26 - 2010-05-31 16:54 - 00007605 _____ C:\Windows\diagwrn.xml 2015-10-15 13:25 - 2010-06-01 04:26 - 00000000 ____D C:\Windows\Panther 2015-10-14 12:24 - 2013-07-17 12:20 - 00000000 ____D C:\Windows\system32\MRT 2015-10-14 12:12 - 2010-06-11 20:05 - 143481208 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-10-14 12:09 - 2009-08-26 23:25 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-10-13 12:53 - 2010-10-09 20:34 - 00000000 ____D C:\Users\*****\AppData\Roaming\Skype 2015-10-13 12:17 - 2009-08-26 23:45 - 00000000 ____D C:\ProgramData\Skype 2015-10-12 12:13 - 2009-03-20 13:40 - 00000000 ____D C:\ProgramData\Sony Corporation 2015-10-11 16:43 - 2011-08-03 00:17 - 00000000 ____D C:\Users\*****\AppData\Roaming\DVDVideoSoft 2015-10-10 00:18 - 2009-08-25 04:49 - 00699920 _____ C:\Windows\system32\perfh007.dat 2015-10-10 00:18 - 2009-08-25 04:49 - 00150028 _____ C:\Windows\system32\perfc007.dat 2015-10-10 00:18 - 2009-07-14 07:13 - 01621684 _____ C:\Windows\system32\PerfStringBackup.INI 2015-10-09 15:42 - 2015-04-08 00:59 - 00000000 ___SD C:\Windows\system32\GWX 2015-10-09 12:15 - 2015-04-08 00:59 - 00000000 ___SD C:\Windows\SysWOW64\GWX 2015-10-06 09:49 - 2012-04-22 22:14 - 00000121 _____ C:\Users\Public\LMDebug.log 2015-10-01 16:46 - 2015-01-31 14:05 - 00000000 ____D C:\Program Files (x86)\Origin 2015-10-01 16:44 - 2015-05-03 14:18 - 00000000 ____D C:\ProgramData\Package Cache 2015-09-22 13:13 - 2009-09-07 12:08 - 00000000 ____D C:\Program Files\Common Files\Apple 2015-09-22 13:08 - 2014-01-24 13:58 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2015-09-17 13:18 - 2009-09-07 23:25 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-09-17 13:18 - 2009-09-07 23:25 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2013-07-10 18:02 - 2013-07-10 18:02 - 4249600 _____ () C:\Program Files (x86)\GUTAE83.tmp 2015-07-26 21:34 - 2015-07-26 21:34 - 0000079 _____ () C:\Program Files (x86)\prefs.js 2004-01-26 17:15 - 2004-01-26 17:15 - 0233472 ____R () C:\Users\*****\AppData\Roaming\MafiaSetup.exe 2015-07-04 16:29 - 2015-07-04 16:29 - 0000047 _____ () C:\Users\*****\AppData\Roaming\WB.CFG 2012-03-12 14:43 - 2015-04-22 12:06 - 0010184 _____ () C:\Users\*****\AppData\Roaming\wklnhst.dat 2010-09-30 16:12 - 2010-09-30 16:12 - 0006144 _____ () C:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2010-09-30 18:45 - 2011-08-08 22:22 - 0007670 _____ () C:\Users\*****\AppData\Local\resmon.resmoncfg 2011-08-01 00:59 - 2011-08-01 00:59 - 0000000 _____ () C:\Users\*****\AppData\Local\{5E1F1058-F5CC-43DE-8062-8C0048D07A70} 2011-08-01 00:54 - 2011-08-01 00:54 - 0000000 _____ () C:\Users\*****\AppData\Local\{F395BF1E-6823-442A-A729-AA6FFF203CA1} 2010-11-02 17:23 - 2010-11-02 17:23 - 0000004 _____ () C:\ProgramData\044317ca.tmp 2010-10-09 20:36 - 2010-10-09 20:36 - 0000056 ____H () C:\ProgramData\ezsidmv.dat Einige Dateien in TEMP: ==================== C:\Users\*****\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpsxi22h.dll C:\Users\*****\AppData\Local\Temp\EsgInstallerx64Stub.exe C:\Users\*****\AppData\Local\Temp\Foxit Reader Updater.exe C:\Users\*****\AppData\Local\Temp\jre-8u51-windows-au.exe C:\Users\*****\AppData\Local\Temp\SandboxieInstall.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-10-11 16:08 ==================== Ende von FRST.txt ============================ |
17.10.2015, 21:17 | #4 |
| Plötzliche Systemabschaltung bei Windows 7 und Bluescreen Und hier nun noch die Addition und der output von BlueScreenView: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:17-10-2015 durchgeführt von ***** (2015-10-17 19:03:05) Gestartet von C:\Users\*****\Downloads Windows 7 Home Premium Service Pack 1 (X64) (2010-05-31 17:51:30) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3049852783-3627140865-2715150416-500 - Administrator - Disabled) Gast (S-1-5-21-3049852783-3627140865-2715150416-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3049852783-3627140865-2715150416-1002 - Limited - Enabled) ***** (S-1-5-21-3049852783-3627140865-2715150416-1000 - Administrator - Enabled) => C:\Users\***** ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 64 Bit HP CIO Components Installer (Version: 2.2.5 - Hewlett-Packard) Hidden 7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov) Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.226 - Adobe Systems Incorporated) Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated) Adobe Premiere Elements 7.0 (HKLM-x32\...\PremElem70) (Version: 7.0.1 - Adobe Systems Incorporated) Adobe Premiere Elements 7.0 Templates (HKLM-x32\...\PremElem70Templates) (Version: 7.0.0 - Adobe Systems Incorporated) ANNO 1503 Königs- Edition (HKLM-x32\...\{DB833EF9-A198-49BE-970A-BD46F30BFBB4}) (Version: 3.05.042.00 - ) ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden Apple Application Support (32-Bit) (HKLM-x32\...\{3540ADD5-822B-47FB-B1C2-CD7B2C8E9FEC}) (Version: 4.0.2 - Apple Inc.) Apple Application Support (64-Bit) (HKLM\...\{C9C0FE2C-602E-49D7-8C42-5B9E8FF04798}) (Version: 4.0.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.) Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.) ArcSoft Magic-i Visual Effects 2 (HKLM-x32\...\{7BB90344-0647-468E-925A-7F69F7983421}) (Version: 2.0.1.39 - ArcSoft) ArcSoft WebCam Companion 2 (HKLM-x32\...\{9973498D-EA29-4A68-BE0B-C88D6E03E928}) (Version: - ArcSoft) ATI Catalyst Install Manager (HKLM\...\{A4BC24CB-F8C7-27FB-41D5-47A405031A41}) (Version: 3.0.732.0 - ATI Technologies, Inc.) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Bonjour-Druckdienste (HKLM\...\{4CE925AF-6519-4FEB-BEBD-DE2BFE2944EB}) (Version: 2.0.0.36 - Apple Inc.) BufferChm (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden C4400 (x32 Version: 100.0.206.000 - Ihr Firmenname) Hidden C4400_Help (x32 Version: 100.0.206.000 - Hewlett-Packard) Hidden Cards_Calendar_OrderGift_DoMorePlugout (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden ccc-core-static (x32 Version: 2009.0804.2223.38385 - Ihr Firmenname) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.28 - Piriform) CDDRV_Installer (Version: 4.60 - Logitech) Hidden Click to Disc (HKLM-x32\...\{68A69CFF-130D-4CDE-AB0E-7374ECB144C8}) (Version: 1.2.73.04270 - Sony Corporation) Click to Disc (x32 Version: 1.2.73.04270 - Sony Corporation) Hidden Click to Disc Editor (HKLM-x32\...\InstallShield_{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}) (Version: 2.0.02 - Sony Corporation) Click to Disc Editor (x32 Version: 2.0.02 - Sony Corporation) Hidden Common Desktop Agent (Version: 1.53.0 - OEM) Hidden Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Copy (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden CustomerResearchQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden Destination Component (x32 Version: 100.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 100.0.190.000 - Hewlett-Packard) Hidden DeviceManagementQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden Die Siedler II - Die nächste Generation (HKLM-x32\...\S2TNG) (Version: - ) Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts) Die Sims™ 3 Late Night (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.5.1 - Electronic Arts) Die Sims™ 3 Luxus-Accessoires (HKLM-x32\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.13.1 - Electronic Arts) Die Sims™ 3 Traumsuite-Accessoires (HKLM-x32\...\{08A25478-C5DD-4EA7-B168-3D687CA987FF}) (Version: 11.0.84 - Electronic Arts) DocProc (x32 Version: 10.0.0.0 - Hewlett-Packard) Hidden DocProcQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden Dolby Control Center (HKLM\...\{D035FBF6-FDEF-487D-89CA-6F9DD07B783F}) (Version: 1.2.0702 - Dolby) Dropbox (HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\...\Dropbox) (Version: 3.10.7 - Dropbox, Inc.) EAX Unified (HKLM-x32\...\EAX Unified) (Version: - ) Einstellungen für VAIO-Inhaltsüberwachung (HKLM-x32\...\{23825B69-36DF-4DAD-9CFD-118D11D80F16}) (Version: 2.4.0.06120 - Sony Corporation) Electronic Arts Product Registration (HKLM-x32\...\InstallShield_{D7D50E0C-27DD-4999-BC05-E026B580F93A}) (Version: 1.01.0000 - Electronic Arts) Electronic Arts Product Registration (x32 Version: 1.01.0000 - Electronic Arts) Hidden Elevated Installer (x32 Version: 4.1.8.0 - Garmin Ltd or its subsidiaries) Hidden erLT (x32 Version: 1.20.0137 - Logitech, Inc.) Hidden eSupportQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 6.1.2.1224 - Foxit Corporation) Free YouTube To MP3 Converter version 4.0.0.913 (HKLM-x32\...\Free YouTube To MP3 Converter_is1) (Version: 4.0.0.913 - DVDVideoSoft Ltd.) GameShadow (HKLM-x32\...\{D98C9637-93DA-44DB-B73A-B11A1192AB26}) (Version: 1.91.0000 - Aardwork Software Ltd) Garmin Express (HKLM-x32\...\{44d9dfc0-3a4a-4439-870f-f97550a9bc8d}) (Version: 4.1.8.0 - Garmin Ltd or its subsidiaries) Garmin Express (x32 Version: 4.1.8.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (x32 Version: 4.1.8.0 - Garmin Ltd or its subsidiaries) Hidden Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden GPBaseService (x32 Version: 100.0.187.000 - Hewlett-Packard) Hidden GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden Grand Theft Auto San Andreas (HKLM-x32\...\{086BADF8-9B1F-4E89-B207-2EDA520972D6}) (Version: 1.00.00001 - Rockstar Games) Harry Potter II (HKLM-x32\...\{7BF68B83-5057-4D4B-0093-28285EEB9EE3}) (Version: - ) Harry Potter SS1 (HKLM-x32\...\Harry Potter SS1) (Version: - ) Harry Potter und der Feuerkelch™ (HKLM-x32\...\{9799BD05-5F89-484C-008E-F50592F53440}) (Version: - ) HDAUDIO SoftV92 Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200) (Version: - ) HP Customer Participation Program 10.0 (HKLM\...\HPExtendedCapabilities) (Version: 10.0 - HP) HP Imaging Device Functions 10.0 (HKLM\...\HP Imaging Device Functions) (Version: 10.0 - HP) HP Photosmart C4400 All-In-One Driver Software 10.0 Rel .3 (HKLM\...\{FF1F4E8E-A833-4c4b-A14A-45D5B841B5D8}) (Version: 10.0 - HP) HP Photosmart Essential 2.5 (HKLM\...\HP Photosmart Essential) (Version: 2.5 - HP) HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Update (HKLM-x32\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden HPPhotoSmartPhotobookWebPack1 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden iCloud (HKLM\...\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.) iTunes (HKLM\...\{88509E20-3936-4D88-A1C0-B274C7BB5151}) (Version: 12.3.0.44 - Apple Inc.) Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation) JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) KhalInstallWrapper (Version: 2.00.0000 - Logitech) Hidden Landwirtschafts Simulator 2013 (HKLM-x32\...\FarmingSimulator2013DE_is1) (Version: 1.0 - GIANTS Software) Logitech SetPoint (HKLM-x32\...\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}) (Version: 4.80 - Logitech) Logitech Unifying-Software 2.10 (HKLM\...\Logitech Unifying) (Version: 2.10.37 - Logitech) Macromedia Shockwave Player (HKLM-x32\...\Macromedia Shockwave Player) (Version: - ) Mafia (HKLM-x32\...\Mafia) (Version: - ) Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) MarketResearch (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden Me&My VAIO (HKLM-x32\...\{76D7CCD6-8369-405C-B494-5F34FAE67249}) (Version: 1.2.0.14020 - Sony Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Works (HKLM-x32\...\{62F7DA7E-CCCB-439C-A760-00C3926E761F}) (Version: 9.7.0621 - Microsoft Corporation) Mozilla Firefox 41.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 41.0.2 (x86 de)) (Version: 41.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 41.0.2.5765 - Mozilla) Mozilla Thunderbird 31.3.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.3.0 (x86 de)) (Version: 31.3.0 - Mozilla) MSVCSetup (x32 Version: 1.00.0000 - HP) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Music Transfer (HKLM-x32\...\{CE2121C6-C94D-4A73-8EA4-6943F33EE335}) (Version: 1.3.01.13160 - Sony Corporation) OCR Software by I.R.I.S. 10.0 (HKLM\...\HPOCR) (Version: 10.0 - HP) OpenMG Secure Module 5.3.00 (HKLM-x32\...\InstallShield_{DEF97A70-C67D-41E1-837C-6462C97A6F65}) (Version: 5.3.00.13080 - Sony Corporation) OpenMG Secure Module 5.3.00 (x32 Version: 5.3.00.13080 - Sony Corporation) Hidden Origin (HKLM-x32\...\Origin) (Version: 9.0.14.2148 - Electronic Arts, Inc.) PanoStandAlone (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden Primo (x32 Version: 1.00.0000 - Your Company Name) Hidden PS_AIO_03_C4400_ProductContext (x32 Version: 100.0.215.000 - Hewlett-Packard) Hidden PS_AIO_03_C4400_Software (x32 Version: 100.0.206.000 - Hewlett-Packard) Hidden PS_AIO_03_C4400_Software_Min (x32 Version: 100.0.213.000 - Hewlett-Packard) Hidden PSSWCORE (x32 Version: 2.02.0000 - Hewlett-Packard) Hidden QuickTime 7 (HKLM-x32\...\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 2.77 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Roxio Easy Media Creator 10 LJ (HKLM-x32\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3 - Roxio) Runtime (x32 Version: 1.00.0000 - Your Company Name) Hidden Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.02.06.05 - Samsung Electronics Co., Ltd.) Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) Samsung Scan Assistant (HKLM-x32\...\Samsung Scan Assistant) (Version: 1.04.30.00 - Samsung Electronics Co., Ltd.) Samsung SCX-3400 Series (HKLM-x32\...\Samsung SCX-3400 Series) (Version: - Samsung Electronics Co., Ltd.) Sandboxie 5.04 (64-bit) (HKLM\...\Sandboxie) (Version: 5.04 - Sandboxie Holdings, LLC) Scan (x32 Version: 10.1.0.0 - Hewlett-Packard) Hidden Setting Utility Series (HKLM-x32\...\{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}) (Version: 5.0.0.08060 - Sony Corporation) Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 10.0 - HP) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation) Skype™ 7.12 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.12.101 - Skype Technologies S.A.) SmartSound Quicktracks for Premiere Elements (HKLM-x32\...\InstallShield_{F6234880-85BE-4DCB-8A45-1FF85A1A8552}) (Version: 3.11.3090 - SmartSound Software Inc) SmartSound Quicktracks for Premiere Elements (x32 Version: 3.11.3090 - SmartSound Software Inc) Hidden SmartWebPrinting (x32 Version: 140.0.186.000 - Hewlett-Packard) Hidden Software Info for Me&My VAIO (HKLM-x32\...\{69C8B1E3-2665-4A0F-B049-67746E5C4CE3}) (Version: 1.0.0.14020 - Sony Corporation) SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden SonicStage Mastering Studio (HKLM-x32\...\{6332AFF1-9D9A-429C-AA03-F82749FA4F49}) (Version: 2.6 - Sony Corporation) SonicStage Mastering Studio Plugins (HKLM-x32\...\{9C1C8A04-F8CA-4472-A92D-4288CE32DE86}) (Version: 2.5 - Sony Corporation) Sony Home Network Library (HKLM-x32\...\{D03D02D8-AB64-4785-A48E-5AA8B0FB8C14}) (Version: 2.0.0.07280 - Sony Corporation) Sony Home Network Library (x32 Version: 1.4.0.14050 - Sony Corporation) Hidden Sony Home Network Library (x32 Version: 2.0.0.07280 - Sony Corporation) Hidden Sony Picture Utility (HKLM-x32\...\{D5068583-D569-468B-9755-5FBF5848F46F}) (Version: 4.2.12.16210 - Sony Corporation) Spelling Dictionaries Support For Adobe Reader 9 (HKLM-x32\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated) Status (x32 Version: 100.0.175.000 - Hewlett-Packard) Hidden Stronghold (HKLM-x32\...\{C917BA70-28A3-4C74-B163-41FD8C8E1A5A}) (Version: - ) Stronghold Crusader (HKLM-x32\...\{8C3727F2-8E37-49E4-820C-03B1677F53B6}) (Version: - ) TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - ) Toolbox (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden Total Access Memo 2000 (HKLM-x32\...\Total Access Memo 2000) (Version: - ) TrayApp (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) UnloadSupport (x32 Version: 10.0.0 - Hewlett-Packard) Hidden Unterstützung für VAIO-Präsentation (HKLM-x32\...\{2018C019-30D9-4240-8C01-0865C10DCF5A}) (Version: 2.0.0.05270 - Sony Corporation) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VAIO Content Metadata Intelligent Analyzing Manager (HKLM-x32\...\{4882EBF5-CA37-4EF4-BCB8-9B0E78B907D0}) (Version: 3.6.1.12010 - Sony Corporation) VAIO Content Metadata Intelligent Analyzing Manager (x32 Version: 3.6.1.12010 - Sony Corporation) Hidden VAIO Content Metadata Manager Settings (HKLM-x32\...\{12D0BE8D-538C-4AB1-86DE-C540308F50DA}) (Version: 3.6.0.09240 - Sony Corporation) VAIO Content Metadata Manager Settings (x32 Version: 3.6.0.09240 - Sony Corporation) Hidden VAIO Content Metadata XML Interface Library (HKLM-x32\...\{291FB4BF-EEC7-4CF9-8469-F39ED1DBC4D8}) (Version: 3.6.0.09080 - Sony Corporation) VAIO Content Metadata XML Interface Library (x32 Version: 3.6.0.09080 - Sony Corporation) Hidden VAIO Content Monitoring Settings (x32 Version: 2.4.0.06120 - Sony Corporation) Hidden VAIO Control Center (HKLM-x32\...\{72042FA6-5609-489F-A8EA-3C2DD650F667}) (Version: 4.0.0.07280 - Sony Corporation) VAIO Data Restore Tool (HKLM-x32\...\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}) (Version: 1.1.01.06290 - Sony Corporation) VAIO DVD Menu Data Basic (HKLM-x32\...\{596BED91-A1D8-4DF1-8CD1-1C777F7588AC}) (Version: 1.0.00.08130 - Sony Corporation) VAIO Edit Components (x32 Version: 6.5 - Sony Corporation) Hidden VAIO Edit Components 6.5 (HKLM-x32\...\{B7C03E84-AF46-42F4-809D-D4127D9086D0}) (Version: 6.5 - Sony Corporation) VAIO Energie Verwaltung (HKLM-x32\...\{5F5867F0-2D23-4338-A206-01A76C823924}) (Version: 4.0.0.07060 - Sony Corporation) VAIO Entertainment Platform (HKLM-x32\...\{6B1F20F2-6321-4669-A58C-33DF8E7517FF}) (Version: 3.5.0.07240 - Sony Corporation) VAIO Entertainment Platform (x32 Version: 3.5.0.07240 - Sony Corporation) Hidden VAIO Event Service (HKLM-x32\...\{C7477742-DDB4-43E5-AC8D-0259E1E661B1}) (Version: 5.0.0.08040 - Sony Corporation) VAIO Launcher (HKLM-x32\...\{15D5C238-4C2E-4AEA-A66D-D6989A4C586B}) (Version: 3.0.0.07150 - Sony Corporation) VAIO Marketing Tools (HKLM-x32\...\MarketingTools) (Version: - Sony Corporation) VAIO Media plus (HKLM-x32\...\{8DE50158-80AA-4FF2-9E9F-0A7C46F71FCD}) (Version: 2.0.0.08180 - Sony Corporation) VAIO Media plus Opening Movie (HKLM-x32\...\{9238E8A4-BEBA-43A3-B926-769BDBF194C5}) (Version: 1.2.0.09100 - Sony Corporation) VAIO Movie Story (HKLM-x32\...\{B25563A0-41F4-4A81-A6C1-6DBC0911B1F3}) (Version: 1.5.00.06191 - Sony Corporation) VAIO Movie Story (x32 Version: 1.4.00.13080 - Sony Corporation) Hidden VAIO Movie Story 1.5 Upgrade (x32 Version: 1.5.00.06191 - Sony Corporation) Hidden VAIO Movie Story Template Data (HKLM-x32\...\{6FA8BA2C-052B-4072-B8E2-2302C268BE9E}) (Version: 1.5.00.06191 - Sony Corporation) VAIO MusicBox (HKLM-x32\...\{D613E659-6503-42A8-9617-4F599061EAD5}) (Version: 2.3.0.09250 - Sony Corporation) VAIO MusicBox Sample Music (HKLM-x32\...\{98FC7A64-774B-49B5-B046-4B4EBC053FA9}) (Version: 1.1.00.14140 - Sony Corporation) VAIO Smart Network (HKLM-x32\...\{3B659FAD-E772-44A3-B7E7-560FF084669F}) (Version: 2.3.0.20100 - Sony Corporation) VAIO Update (HKLM-x32\...\{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}) (Version: 7.0.1.02280 - Sony Corporation) VAIO Wallpaper Contents (HKLM-x32\...\{D60F97EC-EF06-4E1E-B0D1-C2CBABA62FA3}) (Version: 1.3.0.10310 - Sony Corporation) VD64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden VideoToolkit01 (x32 Version: 100.0.128.000 - Hewlett-Packard) Hidden Visitenkarten in 2 Minuten (HKLM-x32\...\Visitenkarten in 2 Minuten) (Version: - ) VU5x64 (Version: 1.1.0 - Sony Corporation ) Hidden VU5x86 (x32 Version: 1.1.0 - Sony Corporation ) Hidden WebReg (x32 Version: 100.0.170.000 - Hewlett-Packard) Hidden WIDCOMM Bluetooth Software (HKLM\...\{D239B547-8B20-4BDE-888D-C9CCA823FFD8}) (Version: 6.2.0.7600 - Broadcom Corporation) Windows-Treiberpaket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) WinDVD for VAIO (HKLM-x32\...\InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}) (Version: 8.0-B20.79 - InterVideo Inc.) WinDVD for VAIO (x32 Version: 8.0-B20.79 - InterVideo Inc.) Hidden ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000_Classes\CLSID\{9E385F0A-0BA2-430C-96AA-4399C5E40F6C}\localserver32 -> C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) ==================== Wiederherstellungspunkte ========================= 13-10-2015 11:58:24 Windows Update 14-10-2015 12:01:14 Windows Update 16-10-2015 01:45:17 Windows Update 16-10-2015 19:49:44 Revo Uninstaller's restore point - Malwarebytes Anti-Malware Version 2.1.8.1057 ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2006-11-02 14:34 - 2006-09-18 23:37 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {069AE859-FE04-468C-BC69-FABFFCF37409} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-02-19] (Piriform Ltd) Task: {0BEAB28C-98A9-4D9C-8E41-3779859D392C} - System32\Tasks\{D3C0AD5B-4E9C-4A44-9C9B-7CFD135C193D} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {1A3AB0E9-0B2B-4422-AE64-42DD42CF35B8} - System32\Tasks\{230854C8-766A-4687-8916-2881CB248159} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {28C3D238-7A3D-4B41-A344-59B88F8B013F} - System32\Tasks\Norton Identity Safe\Norton Error Analyzer => C:\Program Files (x86)\Norton Identity Safe\Engine\2013.1.0.32\SymErr.exe Task: {2AE2D97C-8325-460A-A153-7F40DC423B51} - System32\Tasks\{C7513D00-7C75-4CCF-BBDA-4627F554E60A} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {2C5E1FB2-223C-43FE-B65E-FB11BFEB0BF9} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2015-09-11] () Task: {2F8AEE26-8DB3-4A0B-A37C-529FDCDF35CA} - System32\Tasks\{24B5C033-614D-47C3-ACE3-16EBDDF8DA4B} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {30193EFB-5468-4F70-8A84-B445937D3C9B} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2014-02-28] (Sony Corporation) Task: {31D6047D-6883-433E-9998-750C5E210956} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => C:\Windows\system32\compattelrunner.exe [2015-09-18] (Microsoft Corporation) Task: {3AC4DE36-C776-4052-B025-955C2F9EE222} - System32\Tasks\{3EDC4025-A216-432D-8F0F-5703BC32DB78} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.1.0.112.259/en/abandoninstall?page=tsMain&installinfo=google-toolbar:notoffered;toolbarpresent,google-chrome:notoffered;alreadyoffered Task: {3BC6BC8B-3011-42A6-9FE4-586E83E46914} - System32\Tasks\{3379A8E9-B894-4DF3-A18A-BA93CECBA90C} => C:\Users\*****\Desktop\Stronghold Crusader Trainer.exe Task: {3E50141C-2C2A-45D2-8997-8EE2F4BCB15F} - System32\Tasks\{93A60D55-3662-4B4F-A947-3E12DA8F7EF5} => pcalua.exe -a "C:\Users\*****\Desktop\Rezepte\Dropbox\Gotteslob\GLDVD\Plus\install.exe" -d "C:\Users\*****\Desktop\Rezepte\Dropbox\Gotteslob\GLDVD\Plus" Task: {460A9ACE-12E9-4E2D-846D-5BC8D5A7CBF3} - System32\Tasks\{3DE77364-2CFA-4001-A80B-3C0AF76678DE} => pcalua.exe -a G:\setup.exe -d G:\ Task: {4A3E6E15-6588-4B00-A0E4-57B8A3A1B919} - System32\Tasks\{55576861-DFE5-4102-9FC3-01852D606A69} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {4BF4B887-4C89-4AFF-AE7B-86291F963948} - System32\Tasks\{BE816B65-6193-4C8F-AEBA-E2C93F600B35} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {533E955C-E13D-492B-BD77-85527CA4FB6E} - System32\Tasks\{9C48FBCA-48B9-40FC-A5F4-01910466C2B3} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {54F7496A-45B5-43D2-8039-A3FF9B38F106} - System32\Tasks\{98C0F80C-3EA8-4115-8ABA-23A83CC3B5E2} => C:\Program Files (x86)\Ubisoft\SilentHunterIII\sh3.exe Task: {56128A70-A9F8-449E-8249-FAF8F1413C52} - System32\Tasks\{9684D1CB-4BAB-456B-97B6-E728FD59F70A} => C:\Program Files (x86)\Ubisoft\SilentHunterIII\sh3.exe Task: {5E64E703-2F8B-4D81-AA37-563C1C846FEB} - System32\Tasks\{D93B4924-53AD-4CC3-BD86-68C50094F655} => msiexec.exe /package "C:\Users\*****\AppData\Local\Apple\Apple Software Update\iTunes64.msi" Task: {5E93E1DC-B47F-4F30-9482-F8B05DA5446F} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-06-08] (Oracle Corporation) Task: {62AB8464-70BA-45F4-83C9-2B42E44F77AE} - System32\Tasks\{767D1EE9-08BB-43AF-A9C1-268773B9556F} => C:\Users\*****\Desktop\Rezepte\Dropbox\Gotteslob\GLDVD\Gotteslob\setup.exe Task: {6FEE8BAC-FD41-4ED2-9687-B59C02C2F9BD} - System32\Tasks\{8FA6952B-E287-4E6B-A9C3-A959BF09625C} => C:\Program Files (x86)\THQ\Company of Heroes\RelicCOH.exe Task: {712C6861-2B14-4E72-92BA-22B6921FE2B7} - System32\Tasks\Microsoft\Windows\Wired\GatherWiredInfo => C:\Windows\system32\gatherWiredInfo.vbs Task: {740B1420-D0D0-4F66-A041-BBC0DD79DC97} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.) Task: {7A9EC2D6-76C2-4499-9D9F-31D29356C6F6} - System32\Tasks\{66C6BB2B-B676-446D-BB65-503925D9DC83} => pcalua.exe -a "C:\Users\*****\Downloads\stronghold_crusader\Crusader Trainer.exe" -d "C:\Users\*****\Downloads\stronghold_crusader" Task: {82E9A8DB-979C-4682-8B26-26276AF691AD} - System32\Tasks\{1EEDBEFA-4246-43A7-9408-F98329F9BF82} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {83DCDCE2-C9AA-4A4C-B51B-1431204CBA7F} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe Task: {8DB309C4-E5C9-4CF0-BFE6-E78D3BD1C115} - System32\Tasks\SONY\Me&My VAIO\Me&My VAIO => C:\Program Files (x86)\Sony\Me&My VAIO\QLGuide.exe [2009-02-02] (Sony Corporation) Task: {929B9FE0-2DB3-4E04-926A-1D804845D034} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2014-03-01] (Sony Corporation) Task: {92B2417B-08F2-4CF7-B596-DA5FE759C74C} - System32\Tasks\{3FFC1997-F0AC-436A-8CFA-6249895797F4} => pcalua.exe -a "C:\Users\*****\AppData\Local\Temp\Temp1_stronghold_crusader.zip\Crusader Trainer.exe" Task: {95CCE930-5DE0-4413-9FFA-6DAC1B3CEBFC} - System32\Tasks\{C0A1F536-B0F4-4AD7-9769-20FF06C3D5CD} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {99AACA85-7A13-4B95-8207-0B662413309C} - System32\Tasks\{0DB990F1-5216-4A03-9C9F-60FC939FED6B} => C:\Program Files (x86)\Ubisoft\SilentHunterIII\sh3.exe Task: {9CC6C36B-7288-422A-99A0-E110907B2E25} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {9F8ECAAB-46A6-4512-9899-150D4EBAEBF1} - System32\Tasks\{76207A20-4FDA-4A91-8B9C-CBF9731E3827} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {A0CBFA83-A1FC-437D-9F5F-59231CAB65AE} - System32\Tasks\{5CE057A3-7DF6-4D18-93CD-FD42E58FD9BE} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {A12C8BD5-627F-467A-A75C-0936BF35364C} - System32\Tasks\{B8418DC4-62C0-45AA-919A-219273D4562C} => pcalua.exe -a "C:\Users\*****\Downloads\OpenVPN-Client-fuer-Windows-2014-12-29-1101.exe" -d "C:\Users\*****\Downloads" Task: {A2AE9C5A-17A2-40EA-896E-55AB3F7B9A5A} - System32\Tasks\{84648C1E-CBC8-4527-8B4A-21EBAC5C6097} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {A8D5EBD3-14C0-4EB8-8AF0-6460501D0797} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-17] (Adobe Systems Incorporated) Task: {AA51FCDA-0D49-415A-9583-00F259DC9D3E} - System32\Tasks\{44167DFA-FE22-433A-B227-EB640AF01D52} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {B3368364-8F57-4AC8-A02E-C4FE53B7EF43} - System32\Tasks\{6422F11A-5E55-486A-8B20-96A45653F930} => C:\Program Files (x86)\iTunes\iTunes.exe Task: {BD1BB07B-E036-4EA5-A19C-879F628CCD7D} - System32\Tasks\{93FC9DEF-D361-4A41-A55A-D637DFB15B5A} => C:\Program Files (x86)\Ubisoft\SilentHunterIII\sh3.exe Task: {BD916FF2-BAB9-4954-9FFB-E9B0CFD6FA88} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-06-29] (Avast Software s.r.o.) Task: {C043BB06-1BC4-48E4-8821-9C1AA03F689E} - System32\Tasks\{E9123B78-2C15-4FED-86E6-42E05B1A5AA0} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-09-28] (Skype Technologies S.A.) Task: {CBA4AF02-7F13-4938-A99D-68467BA5C452} - System32\Tasks\{BDC4BBB4-040C-47D4-B27F-E730F449609E} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {CD988933-3A79-4F7F-BACC-2EDD6449352B} - System32\Tasks\Norton Identity Safe\Norton Error Processor => C:\Program Files (x86)\Norton Identity Safe\Engine\2013.1.0.32\SymErr.exe Task: {D94FECF2-4760-4FF0-8620-8EB6C88643E6} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3049852783-3627140865-2715150416-1000Core => C:\Users\*****\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-19] (Dropbox, Inc.) Task: {DBFA0E63-A5CF-4B61-8299-21CC5FC6CB5B} - System32\Tasks\{C7ED77D3-464C-43A8-BCC8-0E8C628BA2D0} => Firefox.exe hxxp://ui.skype.com/ui/0/5.8.0.158.259/en/abandoninstall?page=tsMain Task: {DC1582C7-C562-4C89-BA4D-CECC56A811DB} - System32\Tasks\{32FFD25F-948F-4B73-86E5-98E5C9571075} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe Task: {E27A5585-2DD9-4073-8384-D76F06DEB0B4} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3049852783-3627140865-2715150416-1000UA => C:\Users\*****\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-19] (Dropbox, Inc.) Task: {E6876E3E-64DF-42BA-9679-32C6C525F786} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs Task: {E9D782A4-6101-472F-93C2-DB8A4B49A78B} - System32\Tasks\{A2F1846E-1378-489A-BD5C-B5DA469CAF19} => Firefox.exe hxxp://ui.skype.com/ui/0/6.1.73.129.457/de/abandoninstall?page=tsMain Task: {F7E54F5A-E94D-44AD-91CD-107F71DE44E3} - System32\Tasks\{4FC180CA-97B3-474C-BBB3-A012D18DBC4B} => pcalua.exe -a "C:\Users\*****\Downloads\OpenVPN-Client-fuer-Windows-2014-12-29-1101(2).exe" -d "C:\Users\*****\Downloads" Task: {F9B29800-6CF9-4C6D-8E68-5783A5E7538A} - System32\Tasks\{51E146FE-D8CE-40CE-A61F-12C9B44F0A1D} => Firefox.exe hxxp://ui.skype.com/ui/0/6.1.73.129.457/de/abandoninstall?page=tsMain Task: {FF290DAE-FC1A-4175-8ED5-F897712EFDFF} - System32\Tasks\{254743F8-C34B-483F-87B7-07EDC25BC7C7} => C:\Users\*****\Desktop\GTA San Andreas Trainer.exe (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3049852783-3627140865-2715150416-1000Core.job => C:\Users\*****\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3049852783-3627140865-2715150416-1000UA.job => C:\Users\*****\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2011-05-02 08:10 - 2011-05-02 08:10 - 00034304 _____ () C:\Windows\System32\ssm1mlm.dll 2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-09-15 14:25 - 2015-09-15 14:25 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2010-12-17 18:13 - 2010-12-17 18:13 - 00438784 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe 2010-12-17 18:13 - 2010-12-17 18:13 - 00050688 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll 2009-09-07 12:34 - 2009-07-20 12:35 - 00018960 _____ () C:\Program Files\Logitech\SetPoint\khalwrapper.dll 2009-09-07 12:34 - 2009-07-20 04:00 - 00077824 _____ () C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe 2008-08-26 11:41 - 2008-08-26 11:41 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-06-01 16:12 - 2010-06-01 16:12 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2015-06-29 14:04 - 2015-06-29 14:04 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-06-29 14:04 - 2015-06-29 14:04 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-10-17 12:38 - 2015-10-17 12:38 - 02994032 _____ () C:\Program Files\AVAST Software\Avast\defs\15101700\algo.dll 2010-06-01 16:37 - 2009-08-04 08:58 - 00010752 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll 2010-06-01 16:37 - 2009-08-04 08:58 - 00009728 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSubPS.dll 2015-09-15 14:25 - 2015-09-15 14:25 - 01040144 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2015-06-29 14:04 - 2015-06-29 14:04 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\...\samsungsetup.com -> hxxp://www.samsungsetup.com ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3049852783-3627140865-2715150416-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\*****\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^*****^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupfolder: C:^Users^*****^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk => C:\Windows\pss\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk.Startup MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe MSCONFIG\startupreg: hpqSRMon => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe MSCONFIG\startupreg: icq => C:\Users\*****\AppData\Roaming\ICQM\icq.exe -CU MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background MSCONFIG\startupreg: Sony Ericsson PC Companion => "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{7CE413CA-7E36-485F-94C4-EEEADBF721C4}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{BC942849-620C-4D49-975B-44CC97A3115E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{AC9C1793-868F-4D38-8D0B-8AD2C54B5039}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{039B460D-47D4-4137-9512-575E24AF9790}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{72F0A1E8-E0EC-4C15-9588-725CB8B36EE2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{E02CD568-B4A8-4097-A1B7-9D637141B07F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe FirewallRules: [{64BAAE93-7437-475D-9484-2E6A72679F62}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe FirewallRules: [{FAB9F12B-D14A-4F7D-BF9B-CE0D3FCC767A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe FirewallRules: [{DBCA8504-C0F2-4FDF-9EF3-2A3C257B2F47}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe FirewallRules: [{0A150681-4AA3-44D6-94A5-9BD155014554}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{62A115A9-3212-4B34-BA07-849EEC31B876}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe FirewallRules: [{ABA3EB47-D6F9-48E8-8060-9AD3A221FA3E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{D66CAEF5-E3EB-4CA2-8123-5A0336B03516}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{8CA7DA6D-5974-441B-9D88-770E15694015}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{F7176B9A-DAB8-4D58-AE9E-B3E38B21B830}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\smart web printing\smartwebprintexe.exe FirewallRules: [{4131026B-C896-45A6-A769-DCC4431D22F7}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{ADBA3ABA-DFBB-4E44-B064-F026A8DE10BE}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{9F2968E1-AB5D-45FD-A3C0-EECC2AF2915B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{9359DC24-C6C9-4405-845E-57DC26A96EEF}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{0006212B-5B20-4A21-BABB-64061478D529}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{2B3055F7-F145-42CA-B983-88FB4ADA1BF8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{82D2614C-E0E2-4C05-BB69-5B8AB1769004}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{94564C67-4710-4110-919B-F4915DD6B49D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{3359600F-DD06-4BDD-B311-8B33502CC663}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{0082D90A-A28E-4CAE-807F-EC553FEE6378}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [UDP Query User{90EF2219-87BD-424E-925B-B079A8AF5408}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe FirewallRules: [TCP Query User{AC62C581-BC3D-47DF-A2BF-08DE0DCD9D6C}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe FirewallRules: [UDP Query User{3FE2459D-EC4F-4567-8456-E7F0703919CF}C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe] => (Allow) C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe FirewallRules: [TCP Query User{5D2C329C-DE66-4C20-8567-13BE3319FE4C}C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe] => (Allow) C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe FirewallRules: [TCP Query User{050F8F64-7391-4F5C-AA53-9509B988A54F}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe FirewallRules: [UDP Query User{C8F48609-A212-4D16-8B72-4513763EE28B}C:\program files (x86)\google\google earth\client\googleearth.exe] => (Allow) C:\program files (x86)\google\google earth\client\googleearth.exe FirewallRules: [{711B0FFF-7380-4621-B173-7E4A8A01C0E3}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{D8121DB5-F103-42B2-987B-F3928924086D}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{6F4EF800-026A-40AC-B79B-F2EFC5A23137}] => (Allow) C:\Windows\twain_32\Samsung\SCX3400\SCNSearch\USDAgent.exe FirewallRules: [{9CD3ADF9-E3DE-4B5A-A0E0-2AC9C3F8E323}] => (Allow) C:\Windows\twain_32\Samsung\SCX3400\SCNSearch\USDAgent.exe FirewallRules: [{D37E3C20-0A52-4EF7-B8DA-9857A0158AC3}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{4FAD1BC9-07C9-42D3-865F-380F174FCADE}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{EBCAB8AE-8EE2-4C3D-AFF2-7EEB422892DC}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDS.Application.exe FirewallRules: [{92106B60-4205-483B-A2B7-630C5855F828}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDS.Application.exe FirewallRules: [{6607AEF3-71B3-49C4-AD8D-1D8F9107C6F5}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{0AF3F75B-83A2-42BA-8FD0-D8E1CA448719}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{5120B305-5AA2-4C9D-99A9-6C97777DAF6A}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDSAlert.exe FirewallRules: [{C5A7376E-FF3E-42E2-AFCF-9E92D5F3AC69}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDSAlert.exe FirewallRules: [{C11B7B33-026F-4202-B827-6E785ADF96B5}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe FirewallRules: [{0E4915FA-3599-4CF0-99C5-9EE2A4AD5EE8}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe FirewallRules: [{BBAD3193-63D6-496B-957B-DBEC63348BFD}] => (Allow) C:\Program Files (x86)\Scan Assistant\USDAgent.exe FirewallRules: [{B55E8D8E-3C6E-41CA-AA3F-AB1AC41F7691}] => (Allow) C:\Program Files (x86)\Scan Assistant\USDAgent.exe FirewallRules: [{C70E45F7-3BA5-484C-84AE-D7A83BEB2168}] => (Allow) C:\Program Files\OpenVPN\bin\openvpn-gui.exe FirewallRules: [{4873C091-0909-4890-83AA-B82AEFA70CE0}] => (Allow) C:\Program Files\OpenVPN\bin\openvpn-gui.exe FirewallRules: [{0C4C09A9-85D2-463E-B931-92686901B72E}] => (Allow) C:\Program Files\OpenVPN\bin\openvpn-gui.exe FirewallRules: [{E4D9A675-C57D-4C5C-B21F-EAEB4309DF4D}] => (Allow) C:\Program Files\OpenVPN\bin\openvpn-gui.exe FirewallRules: [{11D980C7-EA70-47A4-B4C6-248AD18A329B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{74D1F835-83D5-4258-86B1-72F567EA293B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{11909FE2-E500-4782-A135-B892C66F4789}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe FirewallRules: [{F44C69E0-FF7F-48AA-B23C-278ADBD5290E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{3188133D-BE8E-4C9E-9856-2B03961C0CB9}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{D890BC11-F374-4FF0-BD9A-E2D28CC05AD5}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{BAE10E6E-44C6-4B28-AFA9-C8FB344563E6}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe FirewallRules: [{E3B5AB5D-6D0A-4876-A3B9-051237934B71}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe FirewallRules: [{DEE7E3B8-9496-4D0C-8031-08B4E39C5FD4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe FirewallRules: [{16758A5F-981C-4A03-9751-B8164C95745C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{CB4FE837-B6E8-44ED-81DE-688E7174DBA2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe FirewallRules: [{5B6257DD-2DA7-44FD-9274-9602D5C9D001}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{EC48054A-1BE6-4C29-9BBA-0DE78BDF20D6}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{2BEAE0E2-17CB-4A80-91B6-61833C85CF53}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [TCP Query User{E87587DF-5EAD-4F71-8032-98F847A5CBCF}C:\windows\syswow64\dpnsvr.exe] => (Block) C:\windows\syswow64\dpnsvr.exe FirewallRules: [UDP Query User{D56520A8-925B-4B25-9455-191DA8418AA7}C:\windows\syswow64\dpnsvr.exe] => (Block) C:\windows\syswow64\dpnsvr.exe FirewallRules: [TCP Query User{4F05DAE5-4D14-4457-998F-4ABAE5BFA481}C:\program files (x86)\battlestations midway\battlestationsmidway.exe] => (Allow) C:\program files (x86)\battlestations midway\battlestationsmidway.exe FirewallRules: [UDP Query User{AE4E8408-5FC0-49A9-B728-A2FE3236C81F}C:\program files (x86)\battlestations midway\battlestationsmidway.exe] => (Allow) C:\program files (x86)\battlestations midway\battlestationsmidway.exe FirewallRules: [TCP Query User{45F24054-9CA6-4939-AD9E-6ACF147EFDAA}C:\users\*****\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\*****\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{8374616C-231D-49AA-8D34-EA5906A69AE4}C:\users\*****\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\*****\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{C53BB7F6-9B9A-444C-BA24-4BE2A90BD858}] => (Allow) C:\Program Files (x86)\Landwirtschafts Simulator 2013\FarmingSimulator2013.exe FirewallRules: [{18ADE468-A379-447D-B7B3-07CED744DDF5}] => (Allow) C:\Program Files (x86)\Landwirtschafts Simulator 2013\FarmingSimulator2013.exe FirewallRules: [{13BD81F1-4F17-49B1-944C-3D22E4DFADFD}] => (Allow) C:\Program Files (x86)\Landwirtschafts Simulator 2013\x64\FarmingSimulator2013Game.exe FirewallRules: [{AB044846-AAB2-4DF8-948B-6F5DC9968E6F}] => (Allow) C:\Program Files (x86)\Landwirtschafts Simulator 2013\x64\FarmingSimulator2013Game.exe FirewallRules: [{F38D7D1C-0A9B-4088-92FB-FFEDBFA69B66}] => (Allow) C:\Program Files (x86)\Landwirtschafts Simulator 2013\x86\FarmingSimulator2013Game.exe FirewallRules: [{B9218744-852A-472E-BAE7-FCD9937122F9}] => (Allow) C:\Program Files (x86)\Landwirtschafts Simulator 2013\x86\FarmingSimulator2013Game.exe FirewallRules: [{70AE5DE3-B0E1-4A94-A3D4-71BE5596F85B}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{F00FFA42-E90F-45E6-838A-BC6C5E36B3F9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{D8549231-E606-4D12-85D5-1369BAAFF7D4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{86BE6AE7-4E51-4AF2-9160-50D6E7DA808A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{64A3CB55-CD9F-49BE-96A2-94FFBFBB4310}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{6C4D5BC7-2553-4C88-8B4C-3C538DEA2C10}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{17402379-316C-4582-8AD6-7F06D6E6C2CC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{55AA5428-F009-4440-A6F6-848895F46620}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (10/17/2015 06:49:35 PM) (Source: VzCdbSvc) (EventID: 7) (User: ) Description: Das Plug-In-Modul konnte nicht geladen werden. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5}) (Fehlercode = 0x80042019) Error: (10/17/2015 06:48:23 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/17/2015 06:40:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/17/2015 12:39:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 24 Error: (10/17/2015 12:39:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 23 Error: (10/17/2015 12:39:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 22 Error: (10/17/2015 12:39:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 21 Error: (10/17/2015 12:39:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 20 Error: (10/17/2015 12:39:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 19 Error: (10/17/2015 12:39:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 18 Systemfehler: ============= Error: (10/17/2015 06:49:27 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "HP CUE DeviceDiscovery Service" wurde nicht richtig gestartet. Error: (10/17/2015 06:47:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "VAIO Power Management" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (10/17/2015 06:47:38 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst VAIO Power Management erreicht. Error: (10/17/2015 06:47:05 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Roxio Upnp Server 10 erreicht. Error: (10/17/2015 06:47:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "regi" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (10/17/2015 06:47:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Skype Click to Call PNR Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (10/17/2015 06:47:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Skype Click to Call Updater" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (10/17/2015 06:46:40 PM) (Source: atikmdag) (EventID: 19468) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (10/17/2015 06:40:17 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (10/17/2015 06:40:17 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 CodeIntegrity: =================================== Date: 2010-02-25 14:52:34.242 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\lgscroll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-02-25 14:52:34.167 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\GameHook.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-02-25 14:52:34.089 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\lgscroll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-02-25 14:52:34.031 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\GameHook.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-02-25 14:52:33.974 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\lgscroll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-02-25 14:52:33.908 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\GameHook.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-02-25 14:52:33.831 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\lgscroll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-02-25 14:52:33.777 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\GameHook.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-02-25 14:52:33.548 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\lgscroll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2010-02-25 14:52:33.490 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Logitech\SetPoint\GameHook.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM)2 Duo CPU P8700 @ 2.53GHz Prozentuale Nutzung des RAM: 48% Installierter physikalischer RAM: 4063.02 MB Verfügbarer physikalischer RAM: 2100.3 MB Summe virtueller Speicher: 8124.23 MB Verfügbarer virtueller Speicher: 5937.93 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:451.63 GB) (Free:237.71 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)] ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 1FB5E489) Partition 1: (Not Active) - (Size=14.1 GB) - (Type=27) Partition 2: (Active) - (Size=451.6 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ Code:
ATTFilter Ntfs.sys Ntfs.sys+4211 fffff880`0121f000 fffff880`013c8000 0x001a9000 0x52e1be8a 24.01.2014 03:14:50 ntoskrnl.exe ntoskrnl.exe+9d727 fffff800`03a64000 fffff800`0404b000 0x005e7000 0x56097216 28.09.2015 19:00:06 Microsoft® Windows® Operating System NT Kernel & System 6.1.7601.23223 (win7sp1_ldr.150928-0600) Microsoft Corporation C:\Windows\system32\ntoskrnl.exe |
18.10.2015, 19:23 | #5 |
/// the machine /// TB-Ausbilder | Plötzliche Systemabschaltung bei Windows 7 und Bluescreen Bitte bei Bluescreenview genau wie hier beschrieben vorgehen: Windows Bluescreen Absturz analysieren und beheben - so geht's - Anleitungen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.10.2015, 19:39 | #6 |
| Plötzliche Systemabschaltung bei Windows 7 und Bluescreen Oh, entschuldige, mein Fehler... Hier nun die Logs von bluescreenview: Code:
ATTFilter ================================================== Dump File : 101815-33119-01.dmp Crash Time : 18.10.2015 00:39:27 Bug Check String : DRIVER_POWER_STATE_FAILURE Bug Check Code : 0x1000009f Parameter 1 : 00000000`00000004 Parameter 2 : 00000000`00000258 Parameter 3 : fffffa80`03d3b040 Parameter 4 : fffff800`00b9a4d0 Caused By Driver : WudfPf.sys Caused By Address : WudfPf.sys+6500 File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+7318a Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\101815-33119-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 454.616 Dump File Time : 18.10.2015 00:41:11 ================================================== ================================================== Dump File : 101715-31855-01.dmp Crash Time : 17.10.2015 18:35:48 Bug Check String : NTFS_FILE_SYSTEM Bug Check Code : 0x00000024 Parameter 1 : 00000000`001904fb Parameter 2 : fffff880`02fb6648 Parameter 3 : fffff880`02fb5ea0 Parameter 4 : fffff800`03b01727 Caused By Driver : Ntfs.sys Caused By Address : Ntfs.sys+4211 File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+702c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\101715-31855-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 278.504 Dump File Time : 17.10.2015 18:39:32 ================================================== ================================================== Dump File : 101715-44132-01.dmp Crash Time : 17.10.2015 00:13:35 Bug Check String : NTFS_FILE_SYSTEM Bug Check Code : 0x00000024 Parameter 1 : 00000000`001904fb Parameter 2 : fffff880`03595588 Parameter 3 : fffff880`03594de0 Parameter 4 : fffff800`03aab228 Caused By Driver : Ntfs.sys Caused By Address : Ntfs.sys+4211 File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+702c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\101715-44132-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 262.144 Dump File Time : 17.10.2015 00:15:02 ================================================== ================================================== Dump File : 101615-35537-01.dmp Crash Time : 16.10.2015 11:50:43 Bug Check String : NTFS_FILE_SYSTEM Bug Check Code : 0x00000024 Parameter 1 : 00000000`001904fb Parameter 2 : fffff880`0be79ae8 Parameter 3 : fffff880`0be79340 Parameter 4 : fffff800`03a81404 Caused By Driver : Ntfs.sys Caused By Address : Ntfs.sys+4211 File Description : Product Name : Company : File Version : Processor : x64 Crash Address : ntoskrnl.exe+702c0 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\101615-35537-01.dmp Processors Count : 2 Major Version : 15 Minor Version : 7601 Dump File Size : 274.136 Dump File Time : 16.10.2015 11:52:41 ================================================== |
19.10.2015, 19:27 | #7 |
/// the machine /// TB-Ausbilder | Plötzliche Systemabschaltung bei Windows 7 und Bluescreen Bitte Windows Repair laufen lassen: Windows reparieren - so geht's - Anleitungen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.10.2015, 21:59 | #8 |
| Plötzliche Systemabschaltung bei Windows 7 und Bluescreen Okay, Windows Repair habe ich nun ordnungsgemäß ausgeführt, Rechner neugestartet, etc. War's das jetzt? Vielen Dank für die bisherige Hilfe! |
20.10.2015, 20:38 | #9 |
/// the machine /// TB-Ausbilder | Plötzliche Systemabschaltung bei Windows 7 und Bluescreen Keine Ahnung, sag Du es mir. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.10.2015, 20:52 | #10 |
| Plötzliche Systemabschaltung bei Windows 7 und Bluescreen Bisher läuft alles fehlerfrei. Keine weitere Abschaltung mehr. Sieht also ganz gut aus. Sollte doch nochmal etwas sein, melde ich mich wieder... Also besten Dank für alles! |
21.10.2015, 19:16 | #11 |
/// the machine /// TB-Ausbilder | Plötzliche Systemabschaltung bei Windows 7 und Bluescreen Cleanup: (Die Reihenfolge ist hier entscheidend) Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken. Falls Combofix verwendet wurde: Combofix deinstallieren .
Alle Logs gepostet? Dann lade Dir bitte DelFix herunter.
Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst. Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen. Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...und/oder das Forum mit einer kleinen Spende unterstützen. Absicherung: Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen: Browser Java Flash-Player PDF-Reader Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren. Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen. Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig. Verwende ein Antivirusprogramm mit Echtzeitscanner und stets aktueller Signaturendatenbank. Meine Empfehlung: Emsisoft Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen. Optional: NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen. Malwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen. Lade Software von einem sauberen Portal wie . Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen. Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwarecleaner . Abschließend noch ein paar grundsätzliche Bemerkungen: Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems. Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Plötzliche Systemabschaltung bei Windows 7 und Bluescreen |
64bit, avast, bluescreen, bluescreens, code, deaktivieren, einfach, error, erscheint, gestern, laptop, malwarebytes, message, problem, protection, schaltet, screenshot, source, system, sämtliche, tan, troja, version, windows, windows 7 |