|
Log-Analyse und Auswertung: Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsamWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
22.01.2016, 00:22 | #1 |
| Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam Hey, ich habe schon des längeren das Problem, dass sich z.Bsp Google Chrome oder auch andere Anwendungen schließen mit der Meldung: " Programm xyz reagiert nicht mehr". Des Weiteren ist mein Computer schlagartig sehr langsam geworden. Daraufhin habe ich heute morgen einmal einen Scan mit Malwarebyte vollzogen. Dieser meldete mir über 80 Funde, welche mein Virenprogramm (BitDefender) nie gefunden hatte. Ich habe Malwarebyte die Funde dann in Quarantäne verschieben lassen, was die Situation nur verschlimmert hat. Seit dem Verschieben der Dateien, habe ich beim laden des Desktops (nach einem Neustart), immer fast eine Minute einen kompletten Blackscreen. Danach läd er nach und nach den Hintergrund, Applikationen etc... Außerdem ist der Computer seit dem Verschieben der Dateien nochmals langsamer geworden. Ich muss im Moment gute 10-20s warten bis er ein Programm oder Ordner öffnet. FRST Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:18-01-2016 durchgeführt von Basti (Administrator) auf BASTI-DESKTOP (21-01-2016 23:52:00) Gestartet von C:\Users\Basti\Downloads Geladene Profile: Basti (Verfügbare Profile: Basti & Zocken & DefaultAppPool) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\vsserv.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Dassault Systemes) C:\Program Files\Dassault Systemes\B21\win_b64\code\bin\CATSysDemon.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe () C:\Program Files (x86)\Droid4X\Droid4XService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe (SoftEther VPN Project at University of Tsukuba, Japan.) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe (GGS) C:\Users\Basti\AppData\Local\THORN\Thorn.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\updatesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (GGS) C:\Users\Basti\AppData\Local\THORN\ThornHelper.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\bdagent.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Mixesoft Project) C:\Users\Basti\AppData\Local\Mixesoft\AppNHost\appnhost.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxag.exe (Spotify Ltd) C:\Users\Basti\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\antispam32\bdwtxapps.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxcr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE (Echobit LLC) C:\Program Files\Echobit\Evolve\EvolveClient.exe (Echobit LLC) C:\Program Files\Echobit\Evolve\EvoSvc.exe (Echobit, LLC) C:\Program Files\Echobit\Evolve\Drivers\EvolveTracker_32.exe (Echobit, LLC) C:\Program Files\Echobit\Evolve\Drivers\EvolveTracker_64.exe (Echobit, LLC) C:\Program Files\Echobit\Evolve\EvolveUI.exe (Echobit, LLC) C:\Program Files\Echobit\Evolve\EvolveUI.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\odscanui.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2771576 2015-12-16] (NVIDIA Corporation) HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-15] (Logitech Inc.) HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2016\bdagent.exe [1720488 2016-01-12] (Bitdefender) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-04-29] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-04-29] (Adobe Systems Inc.) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-09-23] (Cisco Systems, Inc.) HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Run: [appnhost] => C:\Users\Basti\AppData\Local\Mixesoft\AppNHost\appnhost.exe [453176 2014-08-08] (Mixesoft Project) HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Run: [Bitdefender-Geldb�rse-Agent] => C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxag.exe [1423288 2016-01-12] (Bitdefender) HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Run: [Spotify Web Helper] => C:\Users\Basti\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2346096 2015-12-21] (Spotify Ltd) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BdBkpFolder [2016-01-12] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell Display Manager.lnk [2016-01-21] ShortcutTarget: Dell Display Manager.lnk -> C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe (EnTech Taiwan) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) ProxyServer: [S-1-5-21-1745305398-2489788369-3521438674-1002] => localhost:8080 Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{8A41A65B-D9F1-429C-8BC5-46D12DA767EE}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {CCC4110B-5AF8-466B-8DE4-1B9BB14979FC} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {CCC4110B-5AF8-466B-8DE4-1B9BB14979FC} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> DefaultScope {DF39FAF5-E2FF-4630-90A1-159FB1F73C0A} URL = hxxps://de.search.yahoo.com/search?fr=mcafee&type=C010DE91021D20141021&p={searchTerms} SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://www.google.com/search?q={searchTerms}&rlz=1I7ADRA_deDE485 SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {C6CE0053-87D1-4C2C-9DBF-738685826369} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=PF&o=15180&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=RX&apn_dtid=YYYYYYYYDE&apn_uid=8648a3b9-301b-40f6-b522-f94384361361&apn_sauid=6FAA0A15-3C93-40FB-B6E8-4D8CD5970E54 SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {CCC4110B-5AF8-466B-8DE4-1B9BB14979FC} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {DF39FAF5-E2FF-4630-90A1-159FB1F73C0A} URL = hxxps://de.search.yahoo.com/search?fr=mcafee&type=C010DE91021D20141021&p={searchTerms} BHO: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2016\pmbxie.dll [2016-01-12] (Bitdefender) BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-11-01] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-01] (Oracle Corporation) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22] (Hewlett-Packard Co.) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated) BHO-x32: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2016\Antispam32\pmbxie.dll [2016-01-12] (Bitdefender) BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.) BHO-x32: Winamp Toolbar Loader -> {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} -> C:\Program Files (x86)\Winamp Toolbar\winamptb.dll [2012-03-19] (AOL Inc.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-11-01] (Oracle Corporation) BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2015-10-29] (Perfect World Entertainment Inc) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13] (Microsoft Corporation) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-18] (Google Inc.) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-04-29] (Adobe Systems Incorporated) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-01] (Oracle Corporation) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-04-29] (Adobe Systems Incorporated) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22] (Hewlett-Packard Co.) Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.) Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2016\pmbxie.dll [2016-01-12] (Bitdefender) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.) Toolbar: HKLM-x32 - Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll [2012-03-19] (AOL Inc.) Toolbar: HKLM-x32 - Kein Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - Keine Datei Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-04-29] (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.) Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2016\Antispam32\pmbxie.dll [2016-01-12] (Bitdefender) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-18] (Google Inc.) Toolbar: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.) Toolbar: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> Kein Name - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - Keine Datei DPF: HKLM {BAD4FE2C-503B-45CC-88CD-4B0574057D11} hxxp://clients.futuremark.com/calico/systeminfodeploy/FMSI_v490.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 FF SearchEngineOrder.1: Sichere Suche FF SearchEngineOrder.3: Bing FF SelectedSearchEngine: Sichere Suche FF Homepage: www.google.de FF Session Restore: -> ist aktiviert. FF Keyword.URL: hxxps://de.search.yahoo.com/search?fr=mcafee&type=C110DE91021D20141021&p= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll [2016-01-20] () FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll [2014-09-01] (EA Digital Illusions CE AB) FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-01] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-01] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-20] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll [2013-04-03] (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-10-01] () FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll [2014-09-01] (EA Digital Illusions CE AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-01] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-01] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-12-16] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-12-16] (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [Keine Datei] FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2015-10-29] (Perfect World Entertainment Inc) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-04-29] (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems) FF Plugin HKU\S-1-5-21-1745305398-2489788369-3521438674-1002: @my.com/Games -> C:\Users\Basti\AppData\Local\MyComGames\NPMyComDetector.dll [2015-09-30] (My.com, Inc) FF Plugin HKU\S-1-5-21-1745305398-2489788369-3521438674-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Basti\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-08] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-1745305398-2489788369-3521438674-1002: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-01] () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdnu.dll [2009-07-07] (AOL LLC) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdnupdater2.dll [2009-07-07] (AOL LLC) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-30] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2011-12-09] (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\searchplugins\anonymouseorg-anonym-surfen.xml [2015-11-16] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\searchplugins\McSiteAdvisor.xml [2015-11-17] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\duckduckgo-ssl-javascript-free.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\google-de-ssl.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\google-encrypted-no-personalization.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick---deutsch.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick-ssl-pictures---deutsch.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick-ssl-pictures---english.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\leo-eng-ger.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\leo-esp-ale.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\leo-fra-all.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\metager2.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ssl-wikipedia-deutsch.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ssl-wikipedia-english.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\startpage-https---deutsch.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\startpage-https.xml [2013-06-25] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2015-10-29] FF Extension: Amazon-Icon - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\amazon-icon@giga.de [2013-12-28] [ist nicht signiert] FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-06-08] [ist nicht signiert] FF Extension: DownThemAll! - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-05-28] FF Extension: Updated Ad Blocker for Firefox 11+ - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}.xpi [2015-05-29] FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015-06-23] [ist nicht signiert] FF Extension: HTTPS-Everywhere - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\https-everywhere-eff@eff.org [2015-08-28] FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender 2016\\antispam32\bdwteff [2016-01-13] FF Extension: Bing Search Engine - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\bingsearch.full@microsoft.com [2015-03-12] [ist nicht signiert] FF Extension: Magic Actions for YouTube™ - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\jid0-UVAeBCfd34Kk5usS8A1CBiobvM8@jetpack.xpi [2015-07-30] FF Extension: SSL Version Control - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\jid1-ZM3BerwS6FsQAg@jetpack.xpi [2015-05-27] FF Extension: Adblock Plus - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-17] FF Extension: Amazon-Icon - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\amazon-icon@giga.de [2013-12-28] [ist nicht signiert] FF Extension: HTTPS-Everywhere - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\https-everywhere@eff.org [2013-07-12] [ist nicht signiert] FF Extension: Spartipps von SparPilot.com - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\sparpilot@sparpilot.com [2013-12-28] [ist nicht signiert] FF Extension: UnPlug - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\unplug@compunach.xpi [2013-05-15] [ist nicht signiert] FF Extension: JonDoFox - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{437be45a-4114-11dd-b9ab-71d256d89593}.xpi [2013-06-28] [ist nicht signiert] FF Extension: Cookie Monster - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{45d8ff86-d909-11db-9705-005056c00008} [2013-07-12] [ist nicht signiert] FF Extension: NoScript - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-07-20] [ist nicht signiert] FF Extension: Adblock Plus - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-05-15] [ist nicht signiert] FF Extension: ProfileSwitcher - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{fa8476cf-a98c-4e08-99b4-65a69cb4b7d4}.xpi [2013-06-25] [ist nicht signiert] FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06] FF HKLM\...\Firefox\Extensions: [bdwteffv20@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\\antispam32\bdwteff FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\bdtbext FF Extension: Bitdefender Antispam Toolbar - C:\Program Files\Bitdefender\Bitdefender 2016\bdtbext [2015-11-25] [ist nicht signiert] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-06-10] [ist nicht signiert] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF HKLM-x32\...\Firefox\Extensions: [bdwteffv20@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\\antispam32\bdwteff FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\bdtbext FF HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR Session Restore: Default -> ist aktiviert. CHR Profile: C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-27] CHR Extension: (Magic Actions for YouTube™) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2015-12-10] CHR Extension: (Google Docs) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-29] CHR Extension: (Google Drive) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21] CHR Extension: (YouTube) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29] CHR Extension: (Google-Suche) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (Bitdefender Wallet) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhhejlifdlcgcmogbggeomfodgklfaem [2015-12-13] CHR Extension: (Google Tabellen) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-27] CHR Extension: (Google Docs Offline) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18] CHR Extension: (Click&Clean) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2015-11-02] CHR Extension: (AdBlock) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-20] CHR Extension: (Google Maps) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-11-27] CHR Extension: (Amazon-Icon) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg [2015-09-27] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-27] CHR Extension: (YouTube Unblocker) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl [2015-12-07] [UpdateUrl: hxxp://www.unblocker.yt/addon/chrome/updates.xml] <==== ACHTUNG CHR Extension: (Click&Clean App) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2015-11-02] CHR Extension: (Google Mail) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-29] CHR HKLM-x32\...\Chrome\Extension: [dhhejlifdlcgcmogbggeomfodgklfaem] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Basti\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx [2013-12-28] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-10-29] (Perfect World Entertainment Inc) R2 BBDemon; C:\Program Files\Dassault Systemes\B21\win_b64\code\bin\CATSysDemon.exe [46592 2011-01-08] (Dassault Systemes) [Datei ist nicht signiert] S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1145216 2015-05-26] () R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation) R2 Droid4XService; C:\Program Files (x86)\Droid4X\Droid4XService.exe [261864 2015-06-03] () [Datei ist nicht signiert] R3 EvoSvc; C:\Program Files\Echobit\Evolve\EvoSvc.exe [1583488 2016-01-10] (Echobit LLC) S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1616440 2015-12-22] (GOG.com) S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7184440 2015-12-22] (GOG.com) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156216 2015-12-16] (NVIDIA Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert] R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-04-10] (Intel Corporation) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.) R2 LPDSVC; C:\Windows\system32\lpdsvc.dll [45568 2009-07-14] (Microsoft Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert] S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3806032 2015-10-13] (INCA Internet Co., Ltd.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-12-16] (NVIDIA Corporation) R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8185464 2015-12-16] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [6477432 2015-12-16] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-07] (Electronic Arts) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert] R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-30] () R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [857288 2015-11-09] (Bitdefender) S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.) R2 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [5250280 2015-12-29] (SoftEther VPN Project at University of Tsukuba, Japan.) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Datei ist nicht signiert] R2 Thorn; C:\Users\Basti\AppData\Local\THORN\Thorn.exe [56824 2015-10-01] (GGS) R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2016\updatesrv.exe [124488 2015-09-29] (Bitdefender) R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2016\vsserv.exe [1604080 2016-01-12] (Bitdefender) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1600512 2015-10-28] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [282000 2015-09-17] (BitDefender) R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [775424 2015-09-17] (BitDefender) R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2011-11-03] (Broadcom Corporation.) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107080 2012-10-29] (BitDefender LLC) R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [87912 2015-12-14] (BitDefender) S3 cpuz135; kein ImagePath R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-06-08] (DT Soft Ltd) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R3 EvolveVirtualAdapter; C:\Windows\System32\DRIVERS\evolve.sys [21656 2016-01-10] (Echobit, LLC) R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [160032 2015-04-29] (BitDefender LLC) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-11-29] (Intel Corporation) R0 ignis; C:\Windows\System32\DRIVERS\ignis.sys [271808 2015-10-22] (Bitdefender) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R1 LUMDriver; C:\Windows\system32\drivers\LUMDriver.sys [24848 2008-01-02] (IBM) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation) R3 Neo_VPN; C:\Windows\System32\DRIVERS\Neo_0024.sys [38432 2015-12-29] (SoftEther Corporation) S3 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-12-16] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-12-16] (NVIDIA Corporation) R2 trufos; C:\Windows\System32\DRIVERS\trufos.sys [477272 2015-06-02] (BitDefender S.R.L.) R3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2010-03-29] (Texas Instruments) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-03-12] (Cisco Systems, Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-01-21 23:52 - 2016-01-21 23:54 - 00044556 _____ C:\Users\Basti\Downloads\FRST.txt 2016-01-21 23:46 - 2016-01-21 23:52 - 00000000 ____D C:\FRST 2016-01-21 23:45 - 2016-01-21 23:46 - 02370560 _____ (Farbar) C:\Users\Basti\Downloads\FRST64.exe 2016-01-21 15:28 - 2016-01-21 15:28 - 02967888 _____ C:\Users\Basti\Desktop\Sebastian Schmitt.tif 2016-01-21 14:34 - 2016-01-21 14:34 - 00002243 _____ C:\Users\Public\Desktop\Blade & Soul.lnk 2016-01-21 14:20 - 2016-01-21 14:20 - 01611384 _____ (NCSOFT Corporation) C:\Users\Basti\Downloads\NC-LauncherSetup.exe 2016-01-21 12:15 - 2016-01-21 23:55 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-01-21 12:15 - 2016-01-21 13:14 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2016-01-21 12:15 - 2016-01-21 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2016-01-21 12:15 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-01-21 12:14 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2016-01-21 12:14 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2016-01-21 12:06 - 2016-01-21 12:15 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2016-01-21 12:06 - 2016-01-21 12:06 - 22908888 _____ (Malwarebytes ) C:\Users\Basti\Downloads\mbam-setup-2.2.0.1024.exe 2016-01-21 12:06 - 2016-01-21 12:06 - 22908888 _____ (Malwarebytes ) C:\Users\Basti\Downloads\mbam-setup-2.2.0.1024 (1).exe 2016-01-21 12:06 - 2016-01-21 12:06 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-01-20 11:02 - 2016-01-20 11:02 - 00006949 _____ C:\Users\Basti\Desktop\BnS.xml 2016-01-18 15:09 - 2016-01-18 15:10 - 00000000 ____D C:\Users\Basti\AppData\Local\CrashDumps 2016-01-18 10:42 - 2016-01-18 10:42 - 00038983 _____ C:\ComboFix.txt 2016-01-18 10:29 - 2016-01-21 14:11 - 00007668 _____ C:\bdlog.txt 2016-01-18 10:14 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2016-01-18 10:14 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2016-01-18 10:14 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2016-01-18 10:14 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2016-01-18 10:14 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2016-01-18 10:14 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2016-01-18 10:14 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2016-01-18 10:14 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2016-01-18 10:13 - 2016-01-18 10:42 - 00000000 ____D C:\Qoobox 2016-01-18 10:12 - 2016-01-18 10:40 - 00000000 ____D C:\Windows\erdnt 2016-01-18 10:12 - 2016-01-18 10:12 - 05649812 ____R (Swearware) C:\Users\Basti\Downloads\ComboFix.exe 2016-01-18 10:08 - 2016-01-18 10:08 - 00532480 _____ (Trend Micro Incorporated) C:\Users\Basti\Downloads\cwshredder.exe 2016-01-18 10:07 - 2016-01-18 10:07 - 00052461 _____ C:\Users\Basti\Downloads\delcwssk (2).zip 2016-01-18 10:06 - 2016-01-18 10:06 - 00052461 _____ C:\Users\Basti\Downloads\delcwssk (1).zip 2016-01-18 10:03 - 2016-01-18 10:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\Basti\Downloads\HijackThis.exe 2016-01-18 09:58 - 2016-01-18 09:58 - 00052461 _____ C:\Users\Basti\Downloads\delcwssk.zip 2016-01-18 09:48 - 2016-01-18 09:48 - 00388608 _____ (Trend Micro Inc.) C:\Users\Basti\Downloads\HijackThis_2.0.5.exe 2016-01-18 09:48 - 2016-01-18 09:48 - 00388608 _____ (Trend Micro Inc.) C:\Users\Basti\Downloads\HijackThis_2.0.5 (2).exe 2016-01-18 09:39 - 2016-01-18 09:39 - 00388608 _____ (Trend Micro Inc.) C:\Users\Basti\Downloads\HijackThis_2.0.5 (1).exe 2016-01-18 09:39 - 2016-01-18 09:39 - 00388608 _____ (Trend Micro Inc.) C:\Users\Basti\Downloads\_HijackThis_2.0.5.exe 2016-01-18 09:38 - 2016-01-18 09:38 - 00544173 _____ C:\Users\Basti\Downloads\HijackThis_Logfileauswertung_-_2014-02-05_16.22.13.zip 2016-01-17 23:28 - 2015-12-16 18:34 - 00111520 _____ C:\Windows\system32\NvRtmpStreamer64.dll 2016-01-17 23:23 - 2015-12-16 15:39 - 00103032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2016-01-17 23:22 - 2015-12-16 15:53 - 00523384 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2016-01-17 23:22 - 2015-12-16 15:53 - 00075056 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 42977072 _____ C:\Windows\system32\nvcompiler.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 37609080 _____ C:\Windows\SysWOW64\nvcompiler.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 31061624 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 24895792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 21122456 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 20663816 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 17561432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 17156968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 16981976 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 12334200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2016-01-17 23:16 - 2015-12-16 18:34 - 03168376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 02755704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 01915696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436143.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 01564976 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436143.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00938104 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00872056 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00734512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00681592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00502080 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00469144 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00423264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00416376 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00388560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00370808 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00205456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2016-01-17 23:16 - 2015-12-16 18:34 - 00175368 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00153392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00151184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00069416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00050472 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2016-01-17 23:16 - 2015-12-16 18:34 - 00039240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2016-01-17 23:12 - 2016-01-17 23:13 - 336974040 _____ (NVIDIA Corporation) C:\Users\Basti\Downloads\361.43-desktop-win8-win7-winvista-64bit-international-whql.exe 2016-01-17 23:07 - 2016-01-17 23:07 - 00003146 _____ C:\Windows\System32\Tasks\{2D1288DA-1D43-479F-8B4B-36F07394063D} 2016-01-17 23:03 - 2016-01-17 23:04 - 00584288 _____ (Oracle Corporation) C:\Users\Basti\Downloads\jxpiinstall(2).exe 2016-01-17 02:00 - 2016-01-17 02:00 - 01250844 _____ C:\Users\Basti\Downloads\ProcessExplorer161.zip 2016-01-14 23:46 - 2016-01-14 23:53 - 38572508 _____ C:\Users\Basti\Desktop\intro.avi 2016-01-14 23:29 - 2016-01-14 23:34 - 00576953 _____ C:\Users\Basti\Downloads\56981f3794d73.mp4 2016-01-14 21:23 - 2016-01-21 13:12 - 00000882 _____ C:\Users\Basti\Desktop\iFree Skype Recorder.lnk 2016-01-14 21:23 - 2016-01-14 21:41 - 00000000 ____D C:\Users\Basti\Documents\iFree Skype Recorder 2016-01-14 21:23 - 2016-01-14 21:24 - 00000000 ____D C:\Users\Basti\AppData\Roaming\iFree 2016-01-14 21:23 - 2016-01-14 21:23 - 01058568 _____ C:\Users\Basti\Downloads\iFreeRecorder.exe 2016-01-14 21:23 - 2016-01-14 21:23 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iFree Skype Recorder 2016-01-14 21:23 - 2016-01-14 21:23 - 00000000 ____D C:\Program Files (x86)\iFree Skype Recorder 2016-01-13 17:26 - 2016-01-13 17:26 - 01504376 _____ (Skype Technologies S.A.) C:\Users\Basti\Downloads\SkypeSetup.exe 2016-01-13 16:55 - 2016-01-13 16:55 - 00584288 _____ (Oracle Corporation) C:\Users\Basti\Downloads\chromeinstall-8u66 (1).exe 2016-01-13 16:49 - 2015-11-01 15:59 - 00110176 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-64.dll 2016-01-13 16:49 - 2015-11-01 15:52 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2016-01-13 16:47 - 2016-01-13 16:47 - 00584288 _____ (Oracle Corporation) C:\Users\Basti\Downloads\chromeinstall-8u66.exe 2016-01-13 10:19 - 2015-12-12 19:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-01-13 10:19 - 2015-12-12 19:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2016-01-13 10:19 - 2015-12-12 19:02 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2016-01-13 10:19 - 2015-12-12 18:37 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2016-01-13 10:19 - 2015-12-12 18:36 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2016-01-13 10:19 - 2015-12-12 18:30 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2016-01-13 10:19 - 2015-12-12 18:10 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2016-01-13 10:19 - 2015-12-11 19:57 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2016-01-13 10:19 - 2015-12-08 22:54 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2016-01-13 10:19 - 2015-12-08 22:54 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 01568768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 01325056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00902144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll 2016-01-13 10:19 - 2015-12-08 22:54 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00970240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00509952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax 2016-01-13 10:19 - 2015-12-08 22:53 - 00153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2016-01-13 10:19 - 2015-12-08 22:53 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2016-01-13 10:19 - 2015-12-08 22:53 - 00004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksuser.dll 2016-01-13 10:19 - 2015-12-08 22:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 01955328 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 01575424 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 01573888 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 01232896 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 01153024 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 01026048 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 01010688 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00978944 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00666112 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00624640 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00292352 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00224768 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2016-01-13 10:19 - 2015-12-08 20:07 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\ksuser.dll 2016-01-13 10:19 - 2015-12-08 20:06 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax 2016-01-13 10:19 - 2015-12-08 20:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2016-01-13 10:19 - 2015-12-08 20:04 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2016-01-13 10:19 - 2015-12-08 19:54 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2016-01-13 10:19 - 2015-12-08 19:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2016-01-13 10:19 - 2015-12-08 19:11 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys 2016-01-13 10:19 - 2015-12-08 18:58 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-01-13 10:19 - 2015-11-17 02:11 - 00025024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2016-01-13 10:19 - 2015-11-17 02:08 - 01381376 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2016-01-13 10:19 - 2015-11-17 02:08 - 00792064 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2016-01-13 10:19 - 2015-11-17 02:08 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2016-01-13 10:19 - 2015-11-17 02:08 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2016-01-13 10:19 - 2015-11-17 02:08 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2016-01-13 10:19 - 2015-11-16 21:17 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2016-01-13 10:19 - 2015-11-14 00:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll 2016-01-13 10:19 - 2015-11-14 00:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll 2016-01-13 10:19 - 2015-11-14 00:08 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe 2016-01-13 10:19 - 2015-11-13 23:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll 2016-01-13 10:19 - 2015-11-13 23:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll 2016-01-13 10:19 - 2015-11-13 23:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fixmapi.exe 2016-01-13 10:18 - 2015-12-30 20:08 - 05572544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-01-13 10:18 - 2015-12-30 20:08 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-01-13 10:18 - 2015-12-30 20:08 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-01-13 10:18 - 2015-12-30 20:05 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-01-13 10:18 - 2015-12-30 20:02 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2016-01-13 10:18 - 2015-12-30 20:02 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2016-01-13 10:18 - 2015-12-30 20:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2016-01-13 10:18 - 2015-12-30 20:02 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-01-13 10:18 - 2015-12-30 20:02 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-01-13 10:18 - 2015-12-30 20:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-01-13 10:18 - 2015-12-30 20:00 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2016-01-13 10:18 - 2015-12-30 19:59 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-01-13 10:18 - 2015-12-30 19:59 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-01-13 10:18 - 2015-12-30 19:59 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-01-13 10:18 - 2015-12-30 19:58 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-01-13 10:18 - 2015-12-30 19:58 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-01-13 10:18 - 2015-12-30 19:57 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2016-01-13 10:18 - 2015-12-30 19:57 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-01-13 10:18 - 2015-12-30 19:57 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-01-13 10:18 - 2015-12-30 19:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-01-13 10:18 - 2015-12-30 19:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2016-01-13 10:18 - 2015-12-30 19:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:47 - 03993536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2016-01-13 10:18 - 2015-12-30 19:47 - 03938240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2016-01-13 10:18 - 2015-12-30 19:44 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2016-01-13 10:18 - 2015-12-30 19:40 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-01-13 10:18 - 2015-12-30 19:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2016-01-13 10:18 - 2015-12-30 19:39 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-01-13 10:18 - 2015-12-30 19:39 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-01-13 10:18 - 2015-12-30 19:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2016-01-13 10:18 - 2015-12-30 19:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2016-01-13 10:18 - 2015-12-30 19:38 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-01-13 10:18 - 2015-12-30 19:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 18:57 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-01-13 10:18 - 2015-12-30 18:50 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2016-01-13 10:18 - 2015-12-30 18:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2016-01-13 10:18 - 2015-12-30 18:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2016-01-13 10:18 - 2015-12-30 18:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-01-13 10:18 - 2015-12-30 18:42 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-01-13 10:18 - 2015-12-30 18:42 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-01-13 10:18 - 2015-12-30 18:41 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-01-13 10:18 - 2015-12-30 18:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-01-13 10:18 - 2015-12-30 18:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2016-01-13 10:18 - 2015-12-30 18:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2016-01-13 10:18 - 2015-12-30 18:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2016-01-13 10:18 - 2015-12-30 18:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2016-01-13 10:18 - 2015-12-30 18:30 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2016-01-13 10:18 - 2015-12-30 18:30 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 18:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 18:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-01-13 10:18 - 2015-12-24 00:13 - 00387784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2016-01-13 10:18 - 2015-12-23 23:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2016-01-13 10:18 - 2015-12-12 19:54 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-01-13 10:18 - 2015-12-12 19:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2016-01-13 10:18 - 2015-12-12 19:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2016-01-13 10:18 - 2015-12-12 19:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2016-01-13 10:18 - 2015-12-12 19:15 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2016-01-13 10:18 - 2015-12-12 19:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2016-01-13 10:18 - 2015-12-12 19:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2016-01-13 10:18 - 2015-12-12 19:07 - 06051328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2016-01-13 10:18 - 2015-12-12 19:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2016-01-13 10:18 - 2015-12-12 19:07 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2016-01-13 10:18 - 2015-12-12 19:03 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2016-01-13 10:18 - 2015-12-12 19:02 - 20367360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-01-13 10:18 - 2015-12-12 19:02 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2016-01-13 10:18 - 2015-12-12 19:02 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2016-01-13 10:18 - 2015-12-12 19:02 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2016-01-13 10:18 - 2015-12-12 18:55 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2016-01-13 10:18 - 2015-12-12 18:51 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2016-01-13 10:18 - 2015-12-12 18:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2016-01-13 10:18 - 2015-12-12 18:44 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2016-01-13 10:18 - 2015-12-12 18:40 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2016-01-13 10:18 - 2015-12-12 18:39 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2016-01-13 10:18 - 2015-12-12 18:37 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2016-01-13 10:18 - 2015-12-12 18:37 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2016-01-13 10:18 - 2015-12-12 18:37 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2016-01-13 10:18 - 2015-12-12 18:36 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2016-01-13 10:18 - 2015-12-12 18:35 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2016-01-13 10:18 - 2015-12-12 18:33 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-01-13 10:18 - 2015-12-12 18:31 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2016-01-13 10:18 - 2015-12-12 18:28 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2016-01-13 10:18 - 2015-12-12 18:27 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2016-01-13 10:18 - 2015-12-12 18:27 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2016-01-13 10:18 - 2015-12-12 18:27 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2016-01-13 10:18 - 2015-12-12 18:25 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2016-01-13 10:18 - 2015-12-12 18:23 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2016-01-13 10:18 - 2015-12-12 18:22 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2016-01-13 10:18 - 2015-12-12 18:21 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2016-01-13 10:18 - 2015-12-12 18:20 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2016-01-13 10:18 - 2015-12-12 18:19 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2016-01-13 10:18 - 2015-12-12 18:18 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-01-13 10:18 - 2015-12-12 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2016-01-13 10:18 - 2015-12-12 18:12 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2016-01-13 10:18 - 2015-12-12 18:10 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2016-01-13 10:18 - 2015-12-12 18:09 - 04610560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2016-01-13 10:18 - 2015-12-12 18:08 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2016-01-13 10:18 - 2015-12-12 18:06 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2016-01-13 10:18 - 2015-12-12 18:02 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2016-01-13 10:18 - 2015-12-12 18:00 - 12856320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-01-13 10:18 - 2015-12-12 18:00 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2016-01-13 10:18 - 2015-12-12 18:00 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2016-01-13 10:18 - 2015-12-12 18:00 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2016-01-13 10:18 - 2015-12-12 17:54 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2016-01-13 10:18 - 2015-12-12 17:42 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2016-01-13 10:18 - 2015-12-12 17:41 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2016-01-13 10:18 - 2015-12-12 17:38 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2016-01-13 10:18 - 2015-12-12 17:36 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2016-01-13 10:18 - 2015-12-08 22:53 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2016-01-13 10:18 - 2015-12-08 22:52 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2016-01-13 10:18 - 2015-12-08 20:07 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2016-01-13 10:18 - 2015-12-08 20:07 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2016-01-12 22:35 - 2016-01-12 22:35 - 00000000 ____D C:\Users\Basti\AppData\Local\bdch 2016-01-12 22:35 - 2016-01-12 22:35 - 00000000 ____D C:\ProgramData\bdch 2016-01-12 22:23 - 2016-01-12 22:28 - 00000000 ____D C:\Users\Basti\Wichtig 2016-01-12 21:43 - 2016-01-12 21:43 - 00000684 ____H C:\bdr-cf01 2016-01-12 21:42 - 2016-01-12 21:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2016 2016-01-12 21:41 - 2016-01-12 21:43 - 00253404 ____H C:\bdr-ld01 2016-01-12 21:41 - 2016-01-12 21:43 - 00009216 ____H C:\bdr-ld01.mbr 2016-01-12 21:41 - 2015-10-22 14:02 - 00271808 _____ (Bitdefender) C:\Windows\system32\Drivers\ignis.sys 2016-01-12 21:41 - 2015-07-15 16:13 - 49737193 ____H C:\bdr-im01.gz 2016-01-12 21:41 - 2013-08-13 12:38 - 03271472 ____H C:\bdr-bz01 2016-01-12 21:40 - 2015-06-02 14:21 - 00477272 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys 2016-01-12 21:40 - 2015-04-29 13:32 - 00160032 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys 2016-01-12 21:37 - 2016-01-12 21:37 - 09736920 _____ C:\Users\Basti\Downloads\bitdefender_windows_2268285f-b17f-4c1f-972a-438e9cf16488.exe 2016-01-12 21:27 - 2016-01-12 21:27 - 09736920 _____ C:\Users\Basti\Downloads\bitdefender_windows_752fc001-db4f-4d5a-b26f-50072841116e.exe 2016-01-12 21:24 - 2016-01-12 21:24 - 00003414 _____ C:\Windows\System32\Tasks\Bitdefender Restart ProductCfg_F5C977342AD24B62922B89BDC5ABCCD2 2016-01-10 21:28 - 2016-01-21 13:14 - 00002020 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evolve.lnk 2016-01-10 21:28 - 2016-01-21 13:14 - 00002014 _____ C:\Users\Public\Desktop\Evolve.lnk 2016-01-10 21:28 - 2016-01-10 21:28 - 00021656 _____ (Echobit, LLC) C:\Windows\system32\Drivers\evolve.sys 2016-01-10 21:28 - 2016-01-10 21:28 - 00000000 ____D C:\Program Files\Echobit 2016-01-10 21:27 - 2016-01-10 21:27 - 03258328 _____ (Echobit LLC) C:\Users\Basti\Downloads\EvolveSetup.exe 2016-01-10 21:27 - 2016-01-10 21:27 - 00003140 _____ C:\Windows\System32\Tasks\{4FE8E9A0-83ED-441A-8CB2-539F94CDF074} 2016-01-10 21:27 - 2016-01-10 21:27 - 00000000 ____D C:\Users\Basti\AppData\Local\Echobit 2016-01-10 21:27 - 2016-01-10 21:27 - 00000000 ____D C:\ProgramData\Echobit 2016-01-10 13:57 - 2016-01-10 13:57 - 00000000 ____D C:\Program Files\Common Files\INCA Shared 2016-01-10 13:57 - 2015-10-13 14:32 - 03806032 _____ (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des 2016-01-10 13:57 - 2005-01-03 07:43 - 00004682 _____ (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\npptNT2.sys 2016-01-10 13:57 - 2003-07-18 22:17 - 00005174 _____ C:\Windows\SysWOW64\nppt9x.vxd 2016-01-10 12:28 - 2016-01-21 14:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCSOFT 2016-01-10 12:28 - 2016-01-21 14:34 - 00000000 ____D C:\Program Files (x86)\NCSOFT 2016-01-10 12:27 - 2016-01-21 14:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCWest 2016-01-10 12:27 - 2016-01-21 14:33 - 00000000 ____D C:\Program Files (x86)\NCWest 2016-01-10 12:26 - 2016-01-10 12:26 - 00003534 _____ C:\Users\Basti\Documents\cc_20160110_122618.reg 2016-01-10 12:26 - 2016-01-10 12:26 - 00000372 _____ C:\Users\Basti\Documents\cc_20160110_122633.reg 2016-01-10 12:25 - 2016-01-10 12:25 - 00254422 _____ C:\Users\Basti\Documents\cc_20160110_122546.reg 2016-01-10 12:03 - 2016-01-10 12:03 - 224976152 _____ (NC Interactive, LLC ) C:\Users\Basti\Downloads\BnS_Lite_Installer.exe 2016-01-09 11:57 - 2016-01-09 11:57 - 02026520 _____ (BitTorrent Inc.) C:\Users\Basti\Downloads\uTorrent (1).exe 2016-01-09 03:35 - 2016-01-10 14:02 - 00000000 ____D C:\Users\Basti\Documents\BnS 2016-01-08 20:16 - 2016-01-08 20:16 - 00000000 ____D C:\Users\Basti\AppData\Local\BNSUpdater 2016-01-08 18:54 - 2016-01-08 18:54 - 00000000 ____D C:\Users\Basti\Downloads\BnS 2016-01-08 18:47 - 2016-01-08 18:47 - 02026520 _____ (BitTorrent Inc.) C:\Users\Basti\Downloads\uTorrent.exe 2016-01-08 18:47 - 2016-01-08 18:47 - 00024161 _____ C:\Users\Basti\Downloads\playbns_client_2.torrent 2016-01-04 23:40 - 2016-01-04 23:40 - 00028578 _____ C:\Users\Basti\Downloads\malloc.exe 2016-01-04 23:40 - 2016-01-04 23:40 - 00001740 _____ C:\Users\Basti\Downloads\malloc.o 2016-01-04 23:39 - 2016-01-04 23:39 - 00002827 _____ C:\Users\Basti\Downloads\malloc.c 2016-01-04 22:15 - 2016-01-04 22:15 - 00000747 _____ C:\Users\Basti\Desktop\aufgabe5.c 2016-01-04 11:09 - 2016-01-04 11:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2016-01-04 00:00 - 2016-01-21 13:13 - 00000968 _____ C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\MinGW Installation Manager.lnk 2016-01-04 00:00 - 2016-01-04 00:16 - 00000000 ____D C:\MinGW 2016-01-03 23:59 - 2016-01-03 23:59 - 00086528 _____ (MinGW.org Project) C:\Users\Basti\Downloads\mingw-get-setup.exe 2016-01-03 23:52 - 2016-01-03 23:52 - 122655932 _____ C:\Users\Basti\Downloads\gcc-5.2.0.tar.gz 2016-01-03 12:00 - 2016-01-13 17:50 - 00000000 ____D C:\Users\Basti\AppData\Roaming\CodeBlocks 2016-01-03 11:59 - 2016-01-21 13:12 - 00001104 _____ C:\Users\Basti\Desktop\CodeBlocks.lnk 2016-01-03 11:59 - 2016-01-03 12:00 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CodeBlocks 2016-01-03 11:59 - 2016-01-03 12:00 - 00000000 ____D C:\Program Files (x86)\CodeBlocks 2016-01-03 11:59 - 2016-01-03 11:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeBlocks 2016-01-03 11:58 - 2016-01-03 11:59 - 102611063 _____ (The Code::Blocks Team) C:\Users\Basti\Downloads\codeblocks-13.12mingw-setup.exe 2015-12-29 00:23 - 2015-12-29 00:23 - 00038432 _____ (SoftEther Corporation) C:\Windows\system32\Drivers\Neo_0024.sys 2015-12-29 00:21 - 2016-01-21 13:14 - 00001980 _____ C:\Users\Public\Desktop\SoftEther VPN Client Manager.lnk 2015-12-29 00:21 - 2016-01-21 13:13 - 00001992 _____ C:\ProgramData\Microsoft\Windows\Start Menu\SoftEther VPN Client Manager.lnk 2015-12-29 00:21 - 2015-12-29 00:21 - 00144104 _____ (SoftEther VPN Project at University of Tsukuba, Japan.) C:\Windows\system32\vpncmd.exe 2015-12-29 00:21 - 2015-12-29 00:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftEther VPN Client 2015-12-29 00:20 - 2016-01-21 14:14 - 00000000 ____D C:\Program Files\SoftEther VPN Client 2015-12-29 00:19 - 2015-12-29 00:19 - 00000000 ____D C:\Users\Basti\Downloads\vpngate-client-2015.12.29-build-9599.134383 2015-12-29 00:17 - 2015-12-29 00:19 - 54298926 _____ C:\Users\Basti\Downloads\vpngate-client-2015.12.29-build-9599.134383.zip 2015-12-28 23:35 - 2015-12-29 00:57 - 00000000 ____D C:\Users\Basti\Documents\Black Desert 2015-12-28 23:30 - 2015-12-28 23:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Black Desert RU Patcher 2015-12-28 23:16 - 2015-12-28 23:16 - 00000000 __SHD C:\ProgramData\Info 2015-12-28 21:32 - 2016-01-21 14:13 - 00000000 ____D C:\Users\Basti\AppData\Local\THORN 2015-12-28 21:31 - 2016-01-08 15:56 - 00004296 _____ C:\Windows\System32\Tasks\GameNet 2015-12-28 21:31 - 2015-12-28 21:31 - 00000000 ____D C:\Users\Basti\AppData\Local\Vebanaul 2015-12-28 21:29 - 2015-12-28 21:29 - 00478768 _____ (Global Gamers Solutions Ltd. (c)) C:\Users\Basti\Downloads\PlayBlackDesert.exe 2015-12-28 21:24 - 2015-12-28 21:24 - 04363099 _____ C:\Users\Basti\Downloads\setup.exe ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-01-21 23:56 - 2012-05-27 12:25 - 00000000 ____D C:\Users\Basti\Documents\Outlook-Dateien 2016-01-21 23:50 - 2009-07-14 04:20 - 00000000 ____D C:\Windows 2016-01-21 23:41 - 2015-12-13 01:57 - 00000000 ____D C:\Program Files\Bitdefender Agent 2016-01-21 23:40 - 2012-06-06 20:18 - 00000000 ____D C:\Users\Basti\AppData\Local\LogMeIn Hamachi 2016-01-21 23:40 - 2012-05-26 17:00 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Skype 2016-01-21 23:27 - 2009-07-14 05:45 - 00032080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-01-21 23:27 - 2009-07-14 05:45 - 00032080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-01-21 23:15 - 2012-05-26 17:22 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-01-21 23:05 - 2012-05-27 00:38 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-01-21 22:15 - 2012-05-26 17:22 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-01-21 15:28 - 2013-11-03 23:54 - 02324992 ___SH C:\Users\Basti\Desktop\Thumbs.db 2016-01-21 14:34 - 2012-05-25 15:05 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-01-21 14:23 - 2015-04-17 22:24 - 00000546 ____H C:\Windows\Tasks\MATLAB R2015a Startup Accelerator.job 2016-01-21 14:13 - 2015-07-15 14:58 - 00000000 _____ C:\hsrv.txt 2016-01-21 14:13 - 2012-05-25 15:06 - 00000000 ____D C:\ProgramData\NVIDIA 2016-01-21 14:13 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-01-21 13:29 - 2015-11-27 18:06 - 00002353 _____ C:\Users\Basti\Desktop\Chrome App Launcher.lnk 2016-01-21 13:14 - 2015-12-13 02:12 - 00002129 _____ C:\Users\Public\Desktop\Bitdefender 2016.lnk 2016-01-21 13:14 - 2015-11-21 11:45 - 00001106 _____ C:\Users\Public\Desktop\LECTURNITY Player.lnk 2016-01-21 13:14 - 2015-11-02 11:42 - 00001160 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-01-21 13:14 - 2015-11-02 11:42 - 00001154 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-01-21 13:14 - 2015-09-27 14:20 - 00002178 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-01-21 13:14 - 2015-08-12 00:30 - 00002373 _____ C:\Users\Public\Desktop\TI-Nspire CX CAS Student Software.lnk 2016-01-21 13:14 - 2015-08-11 23:58 - 00002333 _____ C:\Users\Public\Desktop\TI-Nspire CAS Student Software.lnk 2016-01-21 13:14 - 2015-07-15 14:58 - 00000998 _____ C:\Users\Public\Desktop\Droid4X.lnk 2016-01-21 13:14 - 2015-07-14 23:38 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-01-21 13:14 - 2015-07-14 23:38 - 00002050 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2016-01-21 13:14 - 2015-06-20 11:50 - 00001094 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Content Viewer.lnk 2016-01-21 13:14 - 2015-06-06 15:54 - 00001202 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk 2016-01-21 13:14 - 2015-05-28 15:57 - 00001062 _____ C:\Users\Public\Desktop\GOG Galaxy.lnk 2016-01-21 13:14 - 2015-04-17 22:27 - 00001296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB R2015a.lnk 2016-01-21 13:14 - 2015-04-17 22:27 - 00001290 _____ C:\Users\Public\Desktop\MATLAB R2015a.lnk 2016-01-21 13:14 - 2015-02-21 13:07 - 00001166 _____ C:\Users\Public\Desktop\Dell Display Manager.lnk 2016-01-21 13:14 - 2015-01-23 17:18 - 00002029 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk 2016-01-21 13:14 - 2014-10-13 18:21 - 00000937 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk 2016-01-21 13:14 - 2014-10-09 14:36 - 00001243 _____ C:\Users\Public\Desktop\Battlefield 4.lnk 2016-01-21 13:14 - 2014-10-09 14:36 - 00001228 _____ C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk 2016-01-21 13:14 - 2014-07-02 22:48 - 00001998 _____ C:\Users\Public\Desktop\HP Photo Creations.lnk 2016-01-21 13:14 - 2014-07-02 22:43 - 00000960 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR-Registrierung.lnk 2016-01-21 13:14 - 2014-07-02 22:42 - 00002113 _____ C:\Users\Public\Desktop\HP Officejet 6700.lnk 2016-01-21 13:14 - 2013-11-20 21:36 - 00000918 _____ C:\Users\Public\Desktop\VLC media player.lnk 2016-01-21 13:14 - 2012-12-01 16:29 - 00002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk 2016-01-21 13:14 - 2012-12-01 16:29 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk 2016-01-21 13:14 - 2012-12-01 16:27 - 00001094 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk 2016-01-21 13:14 - 2012-12-01 16:24 - 00000994 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk 2016-01-21 13:14 - 2012-11-24 13:29 - 00000869 _____ C:\Users\Public\Desktop\CCleaner.lnk 2016-01-21 13:14 - 2012-11-20 16:01 - 00001878 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk 2016-01-21 13:14 - 2012-08-18 15:28 - 00002002 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk 2016-01-21 13:14 - 2012-08-18 15:28 - 00001946 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk 2016-01-21 13:14 - 2012-08-18 15:28 - 00001925 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk 2016-01-21 13:14 - 2012-07-30 11:51 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2016-01-21 13:14 - 2012-07-29 17:18 - 00001297 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inhaltsmanager-Assistent für PlayStation(R).lnk 2016-01-21 13:14 - 2012-06-26 19:04 - 00001914 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LOL Recorder.lnk 2016-01-21 13:14 - 2012-06-07 19:29 - 00001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk 2016-01-21 13:14 - 2011-06-29 12:22 - 00001455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk 2016-01-21 13:14 - 2011-06-29 12:22 - 00001371 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk 2016-01-21 13:14 - 2011-06-29 12:22 - 00001302 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk 2016-01-21 13:14 - 2011-06-29 12:21 - 00002483 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk 2016-01-21 13:14 - 2011-04-27 12:03 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2016-01-21 13:14 - 2011-04-27 12:03 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2016-01-21 13:14 - 2009-07-14 05:57 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-01-21 13:14 - 2009-07-14 05:57 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk 2016-01-21 13:14 - 2009-07-14 05:57 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk 2016-01-21 13:14 - 2009-07-14 05:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk 2016-01-21 13:14 - 2009-07-14 05:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk 2016-01-21 13:13 - 2013-12-14 11:41 - 00001804 _____ C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk 2016-01-21 13:13 - 2012-05-27 11:24 - 00001366 _____ C:\ProgramData\Microsoft\Windows\Start Menu\HP Solution Center.lnk 2016-01-21 13:13 - 2012-05-26 16:56 - 00001434 _____ C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-01-21 13:13 - 2009-07-14 06:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk 2016-01-21 13:13 - 2009-07-14 05:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk 2016-01-21 13:12 - 2015-11-01 15:43 - 00002137 _____ C:\Users\Basti\Desktop\Minecraft.lnk 2016-01-21 13:12 - 2015-09-30 16:40 - 00002029 _____ C:\Users\Basti\Desktop\My.com Game Center.lnk 2016-01-21 13:12 - 2015-08-25 21:01 - 00000833 _____ C:\Users\Basti\Desktop\lol.launcher.admin - Verknüpfung.lnk 2016-01-21 13:12 - 2015-06-17 14:20 - 00001085 _____ C:\Users\Basti\Desktop\Oracle VM VirtualBox.lnk 2016-01-21 13:12 - 2015-06-04 13:52 - 00001964 _____ C:\Users\Basti\Desktop\The Witcher® 3 - Wild Hunt.lnk 2016-01-21 13:12 - 2015-06-01 12:56 - 00001020 _____ C:\Users\Basti\Desktop\Fidelify.lnk 2016-01-21 13:12 - 2015-03-19 11:59 - 00001818 _____ C:\Users\Basti\Desktop\Spotify.lnk 2016-01-21 13:12 - 2014-06-08 17:13 - 00001900 _____ C:\Users\Basti\Desktop\Watch Dogs.lnk 2016-01-21 13:12 - 2014-05-24 11:30 - 00001886 _____ C:\Users\Basti\Desktop\CivilizationV_DX11.exe.lnk 2016-01-21 13:12 - 2014-05-24 00:12 - 00001011 _____ C:\Users\Basti\Desktop\Dark Souls II Black Armour Edition.lnk 2016-01-21 13:12 - 2014-05-23 20:12 - 00000628 _____ C:\Users\Basti\Desktop\Tropico 5.lnk 2016-01-21 13:12 - 2014-05-17 11:27 - 00002118 _____ C:\Users\Basti\Desktop\JDownloader 2.lnk 2016-01-21 13:12 - 2012-06-21 20:47 - 00001087 _____ C:\Users\Basti\Desktop\Basti.lnk 2016-01-21 13:12 - 2012-05-27 11:05 - 00000355 _____ C:\Users\Basti\Desktop\Computer.lnk 2016-01-21 13:09 - 2010-11-21 08:00 - 00000000 ____D C:\Windows\ShellNew 2016-01-21 13:07 - 2012-06-06 19:59 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2016-01-21 13:07 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2016-01-21 09:34 - 2012-05-26 17:23 - 00000000 ____D C:\Users\Basti\AppData\Local\Adobe 2016-01-20 10:05 - 2012-05-27 00:38 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-01-20 10:05 - 2012-05-27 00:38 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-01-20 10:05 - 2012-05-27 00:38 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-01-18 10:31 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2016-01-18 09:51 - 2015-08-02 16:20 - 00000000 ____D C:\Users\Basti\Desktop\Trainer 2016-01-18 00:53 - 2012-08-18 14:08 - 00007599 _____ C:\Users\Basti\AppData\Local\Resmon.ResmonCfg 2016-01-17 23:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2016-01-17 23:26 - 2012-09-11 20:18 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-01-17 23:23 - 2012-05-25 15:05 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-01-17 23:19 - 2012-05-25 15:05 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-01-17 23:08 - 2015-11-01 15:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit 2016-01-17 23:08 - 2015-01-31 18:37 - 00000000 ____D C:\Program Files (x86)\Java 2016-01-17 23:08 - 2013-10-07 22:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-01-17 23:07 - 2013-10-07 22:47 - 00000000 ____D C:\ProgramData\Oracle 2016-01-17 01:03 - 2013-12-14 11:41 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Spotify 2016-01-16 11:33 - 2013-12-14 11:41 - 00000000 ____D C:\Users\Basti\AppData\Local\Spotify 2016-01-14 23:53 - 2013-11-20 21:36 - 00000000 ____D C:\Users\Basti\AppData\Roaming\vlc 2016-01-14 12:39 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2016-01-14 10:57 - 2010-11-21 07:50 - 00737796 _____ C:\Windows\system32\perfh007.dat 2016-01-14 10:57 - 2010-11-21 07:50 - 00159894 _____ C:\Windows\system32\perfc007.dat 2016-01-14 10:57 - 2009-07-14 06:13 - 01710742 _____ C:\Windows\system32\PerfStringBackup.INI 2016-01-14 10:50 - 2009-07-14 05:45 - 05101656 _____ C:\Windows\system32\FNTCACHE.DAT 2016-01-14 10:46 - 2014-12-11 12:06 - 00000000 ____D C:\Windows\system32\appraiser 2016-01-14 10:46 - 2014-05-01 02:01 - 00000000 ___SD C:\Windows\system32\CompatTel 2016-01-14 10:42 - 2013-03-13 23:18 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2016-01-14 10:42 - 2013-03-13 23:18 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2016-01-14 02:32 - 2013-03-13 23:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2016-01-14 02:32 - 2012-05-27 11:15 - 00000000 ____D C:\ProgramData\Microsoft Help 2016-01-14 02:29 - 2013-07-21 22:37 - 00000000 ____D C:\Windows\system32\MRT 2016-01-14 02:05 - 2011-04-27 12:44 - 143671360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-01-14 01:58 - 2009-07-14 03:34 - 00000513 _____ C:\Windows\win.ini 2016-01-13 17:34 - 2012-06-09 15:23 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-01-13 17:34 - 2012-06-09 15:23 - 00000000 ____D C:\ProgramData\Skype 2016-01-13 16:50 - 2015-11-01 15:52 - 00000000 ____D C:\Users\Basti\.oracle_jre_usage 2016-01-12 22:23 - 2012-05-26 16:53 - 00000000 ____D C:\Users\Basti 2016-01-12 22:20 - 2015-12-13 02:08 - 00000000 ____D C:\ProgramData\Bitdefender 2016-01-12 22:10 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Offline Web Pages 2016-01-12 22:05 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Downloaded Program Files 2016-01-12 21:49 - 2015-09-30 16:38 - 00000000 ____D C:\Users\Basti\AppData\Local\MyComGames 2016-01-12 21:42 - 2015-12-13 02:11 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Bitdefender 2016-01-12 21:40 - 2015-12-13 02:07 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2016-01-12 15:22 - 2015-04-17 23:21 - 00000000 ____D C:\Users\Basti\Documents\MATLAB 2016-01-10 12:21 - 2012-11-24 14:09 - 00000000 ____D C:\Program Files (x86)\Steam 2016-01-10 12:21 - 2012-06-07 15:43 - 00000000 ____D C:\Users\Basti\AppData\Roaming\TS3Client 2016-01-10 12:20 - 2012-09-10 17:02 - 00000000 ____D C:\Windows\Minidump 2016-01-08 19:16 - 2013-02-02 19:00 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2016-01-04 11:09 - 2014-03-29 12:34 - 00000000 ____D C:\Users\Basti\AppData\Local\Skype 2016-01-04 02:53 - 2014-02-10 17:04 - 00000000 ____D C:\Users\Basti\AppData\Local\Battle.net 2016-01-04 00:56 - 2015-06-06 15:50 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm 2016-01-04 00:23 - 2013-10-17 14:45 - 00000000 ____D C:\Users\Basti\Uni 2016-01-03 14:04 - 2015-12-15 14:33 - 00000000 ____D C:\Users\Basti\Desktop\test 2015-12-30 11:58 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2015-12-28 22:49 - 2015-07-16 00:46 - 00000095 _____ C:\Users\Basti\Desktop\codes.txt 2015-12-24 13:21 - 2014-02-10 17:04 - 00000000 ____D C:\Program Files (x86)\Battle.net 2015-12-23 15:32 - 2015-05-28 21:19 - 00000000 ____D C:\Users\Basti\Documents\The Witcher 3 2015-12-22 12:01 - 2015-05-28 15:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com 2015-12-22 11:25 - 2015-05-28 15:57 - 00000000 ____D C:\Program Files (x86)\GalaxyClient ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2012-09-29 16:29 - 2013-02-12 19:50 - 0000064 _____ () C:\Program Files\MC.bat 2012-06-06 20:13 - 2012-05-11 18:11 - 0139783 _____ () C:\Program Files\MinecraftSP.jar 2012-11-08 05:39 - 2012-11-08 05:39 - 120115048 _____ () C:\Program Files (x86)\avira_antivirus_premium_en.exe 2012-07-14 15:28 - 2015-11-02 21:05 - 376347915 _____ () C:\Users\Basti\AppData\Roaming\.minecraft.rar 2013-02-07 19:16 - 2015-08-31 22:51 - 0000132 _____ () C:\Users\Basti\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen 2015-07-15 14:57 - 2015-07-15 15:00 - 0002380 _____ () C:\Users\Basti\AppData\Roaming\droid4xinstaller.log 2012-08-18 14:08 - 2016-01-18 00:53 - 0007599 _____ () C:\Users\Basti\AppData\Local\Resmon.ResmonCfg 2014-07-02 22:42 - 2014-07-02 22:42 - 0000057 _____ () C:\ProgramData\Ament.ini 2012-07-02 20:16 - 2012-07-02 20:16 - 0000252 _____ () C:\ProgramData\FastPics.log 2012-05-27 11:11 - 2012-06-10 15:42 - 0005000 _____ () C:\ProgramData\hpzinstall.log 2012-07-02 20:16 - 2013-03-01 18:36 - 0025200 _____ () C:\ProgramData\lxdw.log 2012-07-02 20:19 - 2012-07-02 20:24 - 0000537 _____ () C:\ProgramData\lxdwDiagnostics.log Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\Users\Basti\hamachi-2-ui.exe C:\Users\Basti\save.reg ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-01-19 09:35 ==================== Ende von FRST.txt ============================ Ich konnte die restlichen Log files (Addition, Malwarebyte Bericht) nicht einfügen, da die Nachricht sonst zu lang ist. Mfg Basti |
22.01.2016, 00:24 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam Hi und
__________________Logs bitte nicht anhängen, notfalls splitten und über mehrere Postings verteilt posten Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
22.01.2016, 00:55 | #3 |
| Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam Wollte nur nicht gleich nochmal ein post machen, da es ja irgendwo heißt, dass man in einem neu eröffneten Thema nicht gleich nochmal posten soll.
__________________Also Addition FRST Additions Logfile: Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-01-2016 durchgeführt von Basti (2016-01-21 23:57:51) Gestartet von C:\Users\Basti\Downloads Windows 7 Home Premium Service Pack 1 (X64) (2012-05-26 15:53:52) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1745305398-2489788369-3521438674-500 - Administrator - Disabled) Basti (S-1-5-21-1745305398-2489788369-3521438674-1002 - Administrator - Enabled) => C:\Users\Basti Gast (S-1-5-21-1745305398-2489788369-3521438674-501 - Limited - Enabled) Zocken (S-1-5-21-1745305398-2489788369-3521438674-1005 - Limited - Enabled) => C:\Users\Zocken ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Bitdefender Antivirus (Enabled - Out of date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D} AS: Bitdefender Spyware-Schutz (Enabled - Out of date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Bitdefender Firewall (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated) Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.14 - Adobe Systems) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated) Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated) Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.3 - Adobe Systems Incorporated) Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.286 - Adobe Systems Incorporated) Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.286 - Adobe Systems Incorporated) Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.) Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.) Adobe® Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 3.4.3 - Adobe Systems, Incorporated) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) AppNHost 1.0.5.1 (HKLM-x32\...\{A8CB86C7-CD4C-4C4F-AF6A-33D1CAC63562}) (Version: 1.0.5.1 - Mixesoft Project) Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.5510 - Perfect World Entertainment) Assassin's Creed (R) III (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.01 - Ubisoft) Audible Download Manager (HKLM-x32\...\AudibleDownloadManager) (Version: 6.6.0.15 - Audible, Inc.) avira_antivirus_premium_en 1.00 (HKLM-x32\...\avira_antivirus_premium_en 1.00) (Version: 1.00 - Avira) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.5.2.34169 - Electronic Arts) Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation) Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 20.0.23.1252 - Bitdefender) Bitdefender Total Security 2016 (HKLM\...\Bitdefender) (Version: 20.0.23.1252 - Bitdefender) bl (x32 Version: 1.0.0 - Your Company Name) Hidden Black Desert RU Patcher (HKLM-x32\...\{94381DF9-7266-459C-AF82-4D1458E1AFE7}) (Version: 1.00.0000 - Black Desert RU Patcher) Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.60.197 - NC Interactive, LLC) Blade & Soul (x32 Version: 1.0.60.197 - NC Interactive, LLC) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) BufferChm (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden C4600 (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.24 - Piriform) CD- und DVD-Sharing (HKLM-x32\...\{514FBEC8-E8CE-4F6F-A17F-2789E8DE8D69}) (Version: 1.0.1.4 - Apple Inc.) Cheat Engine 6.2 (HKLM-x32\...\Cheat Engine 6.2_is1) (Version: - Dark Byte) Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.11004 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.11004 - Cisco Systems, Inc.) Hidden CodeBlocks (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team) Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.4.0315 - DT Soft Ltd) Dark Souls II Black Armour Edition MULTI-2 1.0 (HKLM-x32\...\Dark Souls II Black Armour Edition MULTI-2 1.0) (Version: - ) Dassault Systemes Software B21 (HKLM\...\Dassault Systemes B21_0) (Version: - ) Dassault Systemes Software Prerequisites x86-x64 (HKLM\...\{CF1EB598-B424-436A-B15F-B763846BA970}) (Version: 8.1.3 - Dassault Systemes) Dassault Systemes Software VC9 Prerequisites x86-x64 (HKLM\...\{F2F2DEA7-36AB-4E13-907C-D8BDE775EF97}) (Version: 9.1.2 - Dassault Systemes) DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive) Dell Display Manager (HKLM-x32\...\{AC50C05D-9D57-40F5-B2EF-AC402F14312B}_is1) (Version: - EnTech Taiwan) Delta Chrome Toolbar (HKLM-x32\...\{177586E7-E42E-4F38-83D1-D15B4AF5B714}) (Version: 1.0.0.0 - DeltaInstaller) <==== ACHTUNG Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden DNDownloader version 1.2 (HKLM-x32\...\DNDownloader_is1) (Version: 1.2 - ) Download Updater (AOL LLC) (HKLM-x32\...\SoftwareUpdUtility) (Version: - ) <==== ACHTUNG Droid4X (HKLM-x32\...\Droid4X) (Version: 0.8.2 - Haiyu Dongxiang Co.,Ltd.) Dropbox (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Dropbox) (Version: 2.10.30 - Dropbox, Inc.) DVDFab 9.0.6.0 (21/08/2013) (HKLM-x32\...\DVDFab 9_is1) (Version: - Fengtao Software Inc.) EE-ZDE (HKLM-x32\...\{B49C924C-A651-4378-94F6-5D9BF44A959F}) (Version: - ) Empire Earth (HKLM-x32\...\{2447500B-22D7-47BD-9B13-1A927F43A267}) (Version: - ) eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden Evolve (HKLM\...\{670B1B49-9FD3-4827-9B41-471EFF580AA8}) (Version: 1.8.18 - Echobit, LLC) Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft) Fidelify (HKLM-x32\...\Fidelify) (Version: - ) Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Free YouTube to MP3 Converter version 3.11.34.1015 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.34.1015 - DVDVideoSoft Ltd.) Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.9.0 - Futuremark Corporation) Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Gameforge Live 1.0 "Legend" (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 1.1.1724 - Gameforge) GeoGebra 5 (HKLM-x32\...\GeoGebra 5) (Version: 5.0.53.0 - International GeoGebra Institute) GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.111 - Google Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden GPBaseService2 (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden GUILD WARS (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Guild Wars) (Version: - ) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP) HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP) HP Officejet 6700 - Grundlegende Software für das Gerät (HKLM\...\{9086D601-50B7-491D-A143-28193DADE36B}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Officejet 6700 Hilfe (HKLM-x32\...\{E1AE0CB7-1333-4728-8520-CB3F88A252B4}) (Version: 140.0.2.2 - Hewlett Packard) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.9572 - HP) HP Photosmart C4600 All-In-One Driver Software 14.0 Rel. 5 (HKLM\...\{1E1746EF-F5BF-4677-8F30-04FE399130DA}) (Version: 14.0 - HP) HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP) HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP) HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden hpPrintProjects (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden hpWLPGInstaller (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) iCloud (HKLM\...\{EAFB2AD8-D92B-464C-8D97-B9CB94703C4A}) (Version: 3.0.2.163 - Apple Inc.) iFree Skype Recorder 6.0.15 (HKLM-x32\...\iFree Skype Recorder) (Version: 6.0.15 - iFree Skype Recorder) ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!) Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{0DCD0704-E2AB-4e97-96A7-90F146BD8243}) (Version: 2.50.6733.38 - Sony Computer Entertainment Inc.) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.10.1464 - Intel Corporation) Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 16.6 - Intel) iTunes (HKLM\...\{A04DCB25-7040-4935-A30D-8E0A893ABF2D}) (Version: 11.1.2.32 - Apple Inc.) JAP (HKLM-x32\...\JAP) (Version: 00.18.001 - JAP-Team) Java 8 Update 65 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418065F0}) (Version: 8.0.650.17 - Oracle Corporation) Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation) Java SE Development Kit 8 Update 65 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180650}) (Version: 8.0.650.17 - Oracle Corporation) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games) LECTURNITY Player (HKLM-x32\...\{8624888C-A959-45A5-98F4-292E956325EA}) (Version: 4.5.0000 - imc AG) Logitech Gaming Software 8.53 (HKLM\...\Logitech Gaming Software) (Version: 8.53.154 - Logitech Inc.) Logitech SetPoint 6.65 (HKLM\...\sp6) (Version: 6.65.62 - Logitech) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.410 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.410 - LogMeIn, Inc.) Hidden LOLReplay (HKLM-x32\...\LOLReplay) (Version: 0.8.0.1 - www.leaguereplays.com) Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden MATLAB R2015a (HKLM\...\Matlab R2015a) (Version: 8.5 - MathWorks) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{3c3aafc8-d898-43ec-998f-965ffdae065a}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft) Minecraft1.6.2 (HKLM-x32\...\Minecraft1.6.2) (Version: - ) Mozilla Firefox 42.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) My.com Game Center (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\MyComGames) (Version: 3.146 - My.com B.V.) NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version: - NCSOFT) Need for Speed™ Most Wanted (HKLM-x32\...\{A48B9CD8-C2BA-4EC9-0081-7260D238C7CF}) (Version: - ) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.52.3 - Black Tree Gaming) NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.43 - NVIDIA Corporation) NVIDIA 3D Vision Video Player (HKLM-x32\...\{FE3B9518-9FF3-4D89-8A8D-E540C9CCAF3B}) (Version: 1.5.2 - NVIDIA Corporation) NVIDIA GeForce Experience 2.8.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.8.1.21 - NVIDIA Corporation) NVIDIA Grafiktreiber 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.43 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.3.6.4639 - Electronic Arts, Inc.) PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2-r4600) (Version: - ) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden PFConfig 1.0.296 (HKLM-x32\...\PFConfig) (Version: 1.0.296 - Portforward.com) Pflanzen gegen Zombies™ (HKLM-x32\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.) ph (x32 Version: 1.0.0 - Your Company Name) Hidden PS_AIO_05_C4600_Software_Min (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden PTC Mathcad Prime 3.0 (HKLM-x32\...\{C4AB999A-D981-4913-BA26-E4776B598E7D}) (Version: 3.0.0 - PTC) PTC Quality Agent (HKLM-x32\...\{5B7F8A19-AF71-4517-B49C-683AFC5B639C}) (Version: 2.0.0.0 - PTC) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) QuickTransfer (x32 Version: 140.0.98.000 - Hewlett-Packard) Hidden Revo Uninstaller 1.94 (HKLM-x32\...\Revo Uninstaller) (Version: 1.94 - VS Revo Group) Samsung New PC Studio (HKLM-x32\...\InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Samsung New PC Studio (x32 Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.650.0 - SAMSUNG Electronics Co., Ltd.) Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden Secure Download Manager (HKLM-x32\...\{531E35C7-B4E7-418C-A2CD-C1205D9C8AC9}) (Version: 3.1.20 - Kivuto Solutions Inc.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) SHIELD Streaming (Version: 4.1.0250 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.8.1.21 - NVIDIA Corporation) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP) Sid Meier's Civilization V (HKLM-x32\...\Sid Meier's Civilization V_is1) (Version: Sid Meier's Civilization V - ) skyforge_mycom (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\skyforge_mycom) (Version: 1.46 - My.com B.V.) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation) Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.103 - Skype Technologies S.A.) Sleeping Dogs Limited Edition (HKLM-x32\...\Sleeping Dogs™ UPDATE 1.5_is1) (Version: 1.5.0.0 - QfG) SleepTimer Ultimate 1.2 (HKLM-x32\...\{0EE56463-49B2-45E1-B74F-3E0139DBC986}_is1) (Version: - Christian Handorf) SmartWebPrinting (x32 Version: 140.0.186.000 - Hewlett-Packard) Hidden SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.19.9599 - SoftEther VPN Project) SolutionCenter (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden Space Engineers (HKLM-x32\...\Steam App 244850) (Version: - Keen Software House) Spotify (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Spotify) (Version: 1.0.20.94.g8f8543b3 - Spotify AB) Status (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.0.11.0 - GOG.com) The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\...\Free DLC program (16 DLC)_is1) (Version: 1.0.10.0 - GOG.com) TI-Nspire™ CAS Student Software (HKLM-x32\...\{F03A8756-7FCB-4DCD-9AC1-12C63A6075F1}) (Version: 3.9.0.463 - Texas Instruments Inc.) TI-Nspire™ CX CAS Student Software (HKLM-x32\...\{E994956D-8CA7-4091-BFF5-0C749470BA2E}) (Version: 4.0.0.235 - Texas Instruments Inc.) Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Tropico 5 (HKLM-x32\...\Tropico 5_is1) (Version: - ) Unity Web Player (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\UnityWebPlayer) (Version: 5.0.3f2 - Unity Technologies ApS) Uplay (HKLM-x32\...\Uplay) (Version: 4.3 - Ubisoft) VBA (3821b) (x32 Version: 6.01.00.1234 - Microsoft Corporation) Hidden VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN) WebReg (x32 Version: 140.0.212.017 - Hewlett-Packard) Hidden Winamp (HKLM-x32\...\Winamp) (Version: 5.623 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Winamp Toolbar (HKLM-x32\...\Winamp Toolbar) (Version: - ) <==== ACHTUNG Winamp Toolbar (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Winamp Toolbar) (Version: - ) <==== ACHTUNG Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinRAR 4.11 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH) Xilisoft iPod to PC Copy (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Xilisoft iPod to PC Copy) (Version: 5.4.0.20120709 - Xilisoft) XMedia Recode Version 3.1.1.6 (HKLM-x32\...\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.1.6 - XMedia Recode) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {03DA3B3E-4D58-494B-B245-DAD0A8DBDDBB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {153DADDB-4AF6-47D4-9A9D-67EC0B18A250} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-09-14] (Adobe Systems Incorporated) Task: {1B95DAB2-8C86-456F-A170-84602E3279E6} - System32\Tasks\Bitdefender Restart ProductCfg_F5C977342AD24B62922B89BDC5ABCCD2 => C:\Program Files\Bitdefender\Bitdefender 2016\ProductCfg.exe [2016-01-12] (Bitdefender) Task: {1BA04B1B-DE8A-4E45-ACDA-1A8BA907AFFA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-10-24] (Piriform Ltd) Task: {1F671263-2C93-4355-8954-D8A6E869F130} - System32\Tasks\{4B70D9A6-59CA-43A1-BDBB-B887E40A84D7} => Firefox.exe hxxp://ui.skype.com/ui/0/6.6.0.106/de/go/help.faq.installer?LastError=1618 Task: {2490A96E-2646-4481-8A6A-BBB935E89609} - System32\Tasks\{9342110C-473A-40B6-BA74-470DFD73271A} => pcalua.exe -a "C:\Program Files\NVIDIA Corporation\3D Emitter\nvUSBInst.exe" -d "C:\Program Files\NVIDIA Corporation\3D Emitter" Task: {293C18C3-B0F0-4881-947C-966DBAC8BD49} - System32\Tasks\{2D1288DA-1D43-479F-8B4B-36F07394063D} => pcalua.exe -a C:\Users\Basti\Downloads\jxpiinstall(2).exe -d C:\Users\Basti\Downloads Task: {3ACB3CBC-294D-4FA3-A2D0-3F121830A2F8} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2015-11-09] (Bitdefender) Task: {4BFE7F94-DA9B-405C-A8F1-276005CD48F2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-20] (Adobe Systems Incorporated) Task: {508DEA04-F80D-4D62-8C8D-BC6AC05F4FA3} - System32\Tasks\GameNet => C:\Program Files (x86)\QGNA\qGNA.exe Task: {531F9E18-C366-4AAA-9E20-8D05859A457C} - System32\Tasks\Installation App Launcher => C:\Program Files (x86) (x86)\Lexmark 7600 Series\ezprint.exe [2010-02-10] (Lexmark International Inc.) Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto Task: {5ED4D938-3805-450A-888D-B8DEE4C24A92} - System32\Tasks\{C9B77DE9-6A1C-4821-9150-5E9DEA822464} => pcalua.exe -a "C:\Users\Basti\Local Settings\Application Data\Bundled software uninstaller\biclient.exe" -c /initurl hxxp://bi.bisrv.com/:affid:/:sid:/:uid:? /affid uninstall /id uninstall /name "Bundled software uninstaller" Task: {6131115E-E342-4ED5-BA2E-274E03E3AD03} - System32\Tasks\MATLAB R2015a Startup Accelerator => C:\Program Files\MATLAB\R2015a\bin\win64\MATLABStartupAccelerator.exe [2014-12-29] () Task: {65774187-F822-4405-9366-4822D1B7BB56} - System32\Tasks\{4FE8E9A0-83ED-441A-8CB2-539F94CDF074} => pcalua.exe -a C:\Users\Basti\Downloads\EvolveSetup.exe -d C:\Users\Basti\Downloads Task: {6F3A25B2-F32B-4D54-90C7-DC55CE87C89F} - System32\Tasks\AdobeAAMUpdater-1.0-Basti-PC-Basti => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-05-25] (Adobe Systems Incorporated) Task: {8CA2239D-3265-4137-9474-7F68939B16D3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {A5B7212F-CF00-47BD-A6B8-6AFB1673C7FE} - System32\Tasks\{17AF4C96-0ABB-4915-ABBF-64D12E75ED44} => pcalua.exe -a H:\Adobe_Photoshop_CS5_Extended-AkamaiDLM.exe -d H:\ Task: {AA49A26C-34A3-4E6F-B51A-1597E039672E} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation) Task: {AD6C33B2-B2D5-4DB3-885B-F850B71E16F8} - \Dealply -> Keine Datei <==== ACHTUNG Task: {C09706A8-6289-4CBB-83AA-307E834C9348} - System32\Tasks\{F2F37F3E-65F3-4810-8851-E0B4B6BAEA81} => C:\Sierra\EE-ZDE\EE-AOC.exe [2002-08-21] () Task: {C3011503-2B45-43D6-8191-7E900C479FA0} - System32\Tasks\{D00EF0EA-619B-4134-97D6-7A640F11A328} => pcalua.exe -a "C:\Users\Basti\Downloads\FM13 Datensatz - Deutschland.exe" -d C:\Users\Basti\Downloads Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc Task: {DE3BBF04-CFC3-41EC-B711-791D41C3733B} - System32\Tasks\{7AE8198C-13CA-46CB-B46B-D22ECDC213E0} => pcalua.exe -a C:\Users\Basti\Downloads\forge-1.7.10-10.13.4.1448-1.7.10-installer-win.exe -d C:\Users\Basti\Downloads Task: {E88A55D5-4F57-41B6-BB0C-B0893DC08821} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Dealply.job.bak => C:\Users\Basti\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ACHTUNG Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\MATLAB R2015a Startup Accelerator.job => C:\Program Files\MATLAB\R2015a\bin\win64\MATLABStartupAccelerator.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) Shortcut: C:\Users\Basti\Spiele\MC-Server_start.bat - Verknüpfung.lnk -> C:\Users\Basti\Desktop\Neuer Ordner\Server_start.bat (Keine Datei) Shortcut: C:\Users\Basti\Spiele\MC.bat - Verknüpfung.lnk -> C:\Program Files\MC.bat () Shortcut: C:\Users\Basti\Spiele\Start NFS MW Mod Loader.bat - Verknüpfung.lnk -> C:\Program Files (x86)\EA GAMES\Need for Speed Most Wanted\Start NFS MW Mod Loader.bat () ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2016-01-12 21:42 - 2013-09-03 13:29 - 00101328 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\bdmetrics.dll 2016-01-21 17:30 - 2016-01-21 17:30 - 01119064 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttpbr.mdl 2016-01-21 17:30 - 2016-01-21 17:30 - 00794832 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttpdsp.mdl 2016-01-21 17:30 - 2016-01-21 17:30 - 03038112 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttpph.mdl 2016-01-21 17:30 - 2016-01-21 17:30 - 01648408 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttprbl.mdl 2012-09-11 20:19 - 2015-12-16 15:53 - 00126072 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-06-03 03:56 - 2015-06-03 03:56 - 00261864 _____ () C:\Program Files (x86)\Droid4X\Droid4XService.exe 2016-01-17 23:26 - 2015-12-16 18:34 - 00217720 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll 2012-06-08 14:13 - 2012-02-17 19:55 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll 2012-11-22 16:19 - 2013-10-30 19:53 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2014-02-11 19:21 - 2014-02-11 19:21 - 00860160 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-02-11 19:22 - 2014-02-11 19:22 - 01043968 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-02-11 19:21 - 2014-02-11 19:21 - 00052736 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2014-02-11 19:22 - 2014-02-11 19:22 - 00236032 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2015-09-23 18:43 - 2015-09-23 18:43 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2012-05-30 19:06 - 2012-05-30 19:06 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-05-30 19:06 - 2012-05-30 19:06 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2015-12-28 21:32 - 2015-04-24 16:40 - 00043520 _____ () C:\Users\Basti\AppData\Local\THORN\QtSolutions_Service-head.dll 2015-12-28 21:32 - 2014-08-28 10:36 - 00732160 _____ () C:\Users\Basti\AppData\Local\THORN\libGLESv2.dll 2015-12-28 21:32 - 2014-08-28 10:41 - 00856576 _____ () C:\Users\Basti\AppData\Local\THORN\platforms\qwindows.dll 2015-12-28 21:32 - 2014-08-28 10:36 - 00047104 _____ () C:\Users\Basti\AppData\Local\THORN\libEGL.dll 2016-01-17 23:26 - 2015-12-16 18:34 - 00011896 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-04-29 23:16 - 2015-04-29 23:16 - 00019968 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\acrotray.deu 2012-05-25 15:07 - 2012-03-28 21:18 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2016-01-14 11:16 - 2016-01-12 17:35 - 01590088 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libglesv2.dll 2016-01-14 11:16 - 2016-01-12 17:35 - 00087880 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libegl.dll 2015-12-21 13:52 - 2015-12-21 13:52 - 00932032 ____R () C:\Program Files (x86)\Skype\Phone\ssScreenVVS2.dll 2013-09-14 00:51 - 2013-09-14 00:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll 2013-09-14 00:50 - 2013-09-14 00:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf 2016-01-12 21:41 - 2013-09-03 13:29 - 00095088 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\antispam32\bdmetrics.dll 2015-04-29 23:15 - 2015-04-29 23:15 - 02897304 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\PDFMaker\Common\AdobePDFMakerX.dll 2015-04-29 23:16 - 2015-04-29 23:16 - 01446400 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\PDFMaker\AdobePDFMakerX.DEU 2015-11-11 02:42 - 2015-11-11 02:42 - 01045672 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 00189440 _____ () C:\Program Files\Echobit\Evolve\libidn.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 00047616 _____ () C:\Program Files\Echobit\Evolve\boost_thread-vc100-mt-1_46_1.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 00044032 _____ () C:\Program Files\Echobit\Evolve\boost_date_time-vc100-mt-1_46_1.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 00046592 _____ () C:\Program Files\Echobit\Evolve\boost_signals-vc100-mt-1_46_1.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 00135168 _____ () C:\Program Files\Echobit\Evolve\boost_filesystem-vc100-mt-1_46_1.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 00015360 _____ () C:\Program Files\Echobit\Evolve\boost_system-vc100-mt-1_46_1.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 00611328 _____ () C:\Program Files\Echobit\Evolve\boost_regex-vc100-mt-1_46_1.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 00321536 _____ () C:\Program Files\Echobit\Evolve\boost_program_options-vc100-mt-1_46_1.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 00086400 _____ () C:\Program Files\Echobit\Evolve\EvolveEasyHook_32.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 38599680 _____ () C:\Program Files\Echobit\Evolve\libcef.DLL 2016-01-10 21:28 - 2016-01-10 21:28 - 00710430 _____ () C:\Program Files\Echobit\Evolve\swscale-2-evo.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 00481201 _____ () C:\Program Files\Echobit\Evolve\avutil-51-evo.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 01166303 _____ () C:\Program Files\Echobit\Evolve\avformat-53-evo.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 05033711 _____ () C:\Program Files\Echobit\Evolve\avcodec-53-evo.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 38599680 _____ () C:\Program Files\Echobit\Evolve\libcef.dll 2016-01-10 21:28 - 2016-01-10 21:28 - 00874496 _____ () C:\Program Files\Echobit\Evolve\ffmpegsumo.dll 2012-03-09 16:26 - 2013-04-25 02:50 - 00108128 _____ () C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\zlib1.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\Users\Basti\.DS_Store:AFP_AfpInfo AlternateDataStreams: C:\Users\Basti\Desktop\.DS_Store:AFP_AfpInfo AlternateDataStreams: C:\Users\Basti\Downloads\.DS_Store:AFP_AfpInfo AlternateDataStreams: C:\Users\Basti\Downloads\361.43-desktop-win8-win7-winvista-64bit-international-whql.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\BnS_Lite_Installer.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\chromeinstall-8u66 (1).exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\chromeinstall-8u66.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\codeblocks-13.12mingw-setup.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\ComboFix.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\cwshredder.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\EvolveSetup.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\FRST64.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\HijackThis.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\HijackThis_2.0.5 (1).exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\HijackThis_2.0.5 (2).exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\HijackThis_2.0.5.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\iFreeRecorder.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\jxpiinstall(2).exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\mbam-setup-2.2.0.1024 (1).exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\mbam-setup-2.2.0.1024.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\mingw-get-setup.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\NC-LauncherSetup.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\PlayBlackDesert.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\setup.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\SkypeSetup.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\uTorrent (1).exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\uTorrent.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\_HijackThis_2.0.5.exe:BDU AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com Da befinden sich 7865 mehr Seiten. IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123simsen.com -> www.123simsen.com Da befinden sich 7863 mehr Seiten. ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 03:34 - 2016-01-21 23:13 - 00004098 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com 127.0.0.1 na2m-pr.licenses.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 ereg.wip4.adobe.com 127.0.0.1 wip.adobe.com 127.0.0.1 wip1.adobe.com 127.0.0.1 wip2.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 wip4.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 hl2rcv.adobe.com 127.0.0.1 adobeereg.com 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 3dns.adobe.com 127.0.0.1 3dns-1.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-4.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-1.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 adobe-dns-4.adobe.com127.0.0.1 www.007guard.com Da befinden sich 77 zusätzliche Einträge. ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist deaktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Inhaltsmanager-Assistent für PlayStation(R).lnk => C:\Windows\pss\Inhaltsmanager-Assistent für PlayStation(R).lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Basti^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Synchronizer => MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin MSCONFIG\startupreg: ApnUpdater => MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: AutoStartNPSAgent => C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe MSCONFIG\startupreg: CD- und DVD-Sharing => "C:\Program Files (x86)\CD- und DVD-Sharing\ODSAgent.exe" MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming MSCONFIG\startupreg: EzPrint => "C:\Program Files (x86) (x86)\Lexmark 7600 Series\ezprint.exe" MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start MSCONFIG\startupreg: LOLReplay Recorder => "C:\Program Files (x86)\LOLReplay\LOLRecorder.exe" -minimize MSCONFIG\startupreg: lxdwmon.exe => "C:\Program Files (x86) (x86)\Lexmark 7600 Series\lxdwmon.exe" MSCONFIG\startupreg: Pando Media Booster => MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{AEB0AA6D-6C50-4812-9625-67A55EFD53FF}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{B6C925FB-AAF5-426B-B3E4-AE312A3FA526}] => (Allow) LPort=2869 FirewallRules: [{B8A05455-93A9-4D81-8C81-D3F3517D953C}] => (Allow) LPort=1900 FirewallRules: [{E8294358-232A-45E3-8825-6CF312AFF0A3}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{FF42412D-60DF-4783-9856-A6786836D569}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe FirewallRules: [TCP Query User{8605D22C-C232-4D70-95DE-DF0204070B05}E:\skype\phone\skype.exe] => (Allow) E:\skype\phone\skype.exe FirewallRules: [UDP Query User{3E24806E-72F0-4CB2-85B5-52D76EA61D9D}E:\skype\phone\skype.exe] => (Allow) E:\skype\phone\skype.exe FirewallRules: [TCP Query User{66097FAD-DE6E-45FE-B4B5-494B7951E559}E:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) E:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [UDP Query User{E44AFAA1-C985-4D4D-98C4-D1F1222E8DEC}E:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) E:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [{50589B4A-7714-4736-A12C-F203A0404CBD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{7BEB5529-C91A-4153-8184-940217CA9A68}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{BA05C10F-C9BD-4AAF-8CA9-1FD195EDC8AD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{9CE0C97A-8FA5-4C78-8636-3CCBF4236105}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{43F4BE84-BDF6-4A56-B305-76266D5CE186}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe FirewallRules: [{944328E1-A43A-4626-AFB3-1B5EB8ED02AB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe FirewallRules: [{01296CE7-D3EA-4B41-80A9-2B1A6DB946AC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{A1DFC9B1-30E8-4236-BC1B-7C29FA788E56}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe FirewallRules: [{61452E45-4CE4-4DEC-BFBF-F8C65D483E7D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{35B97D4E-9D9B-42C9-ADFB-D6DE5CFDFD87}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{ACD23962-358A-4CF3-B3BE-C1859D1B3AC4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{9A6355D6-6CE8-4A0B-A848-6868982EB28C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{E5585DFB-2F3E-452B-974F-0659487E8AC3}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{37A64963-0E37-4E44-A6E5-544FC3B270B1}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe FirewallRules: [{EB61EA23-EE2E-4D8B-9A1B-2F888ECA97EA}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{4F20E937-3A3E-484E-AF41-BCBF8F6EF15A}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe FirewallRules: [{0FCC7DD0-110E-48F3-98D7-63537CE9D87C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C3BB32CF-7D2A-4B49-B0E6-C59A5363AFDB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E40CC70F-53F7-43AE-82A1-464181035FD8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{26EA374E-9D61-4AB5-BFEB-457A93CDB684}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{9D747C84-4B7C-4ABD-954F-808306C2E7DE}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{0FD22C5F-CEEC-452B-BB9B-F382C7DD3E7A}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{1316D1D9-190F-43A7-840B-E3DB02CAD839}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{F2AAF089-6789-4D58-86CA-8AF3A3014E3D}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{BF4BE5A0-D5B0-4CCE-AD02-C3926AF88D7F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{840BA19A-BE66-447C-8549-E61914FD6364}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{DA31F48E-4D65-448E-B0E5-F0F032D1A0C3}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe FirewallRules: [{405839C9-B746-4857-8BEF-9440A903A334}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe FirewallRules: [{7AFE82AF-470C-472B-9E42-73595DDB3C58}] => (Allow) LPort=7935 FirewallRules: [{834A5996-41C5-4FED-A7C7-29812EB211A6}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe FirewallRules: [{3F1637F3-3EA7-4C2D-A98A-756F2DBA7161}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe FirewallRules: [{F738565D-20E7-4107-B64A-A15741CD7DE5}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe FirewallRules: [{48144A4D-6B79-4058-9A48-20772876CB90}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe FirewallRules: [{CFE4DF24-5F00-49FB-A863-530E7E9E1505}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe FirewallRules: [{C19442D6-0261-4459-BD4F-6C8C4CC36C6E}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe FirewallRules: [{BDDB4C68-8452-43E0-B3EB-33E014E862F2}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3.exe FirewallRules: [{2B9602D7-E869-44EB-A586-73EAFF8A1523}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3.exe FirewallRules: [{8CA1C522-931E-45DF-A8B2-1496E2233AF9}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3_d3d11.exe FirewallRules: [{ED332F7D-C2B1-4A8E-A563-FB8F8ABD00B1}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3_d3d11.exe FirewallRules: [{706DA564-C0DD-4259-BE64-9504CA32903B}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Updater.exe FirewallRules: [{077438E0-8148-47F5-82EA-7A23153241E2}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Updater.exe FirewallRules: [{AFB4F4A8-A984-40B8-AC0A-A581DBC8D0AA}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Editor.exe FirewallRules: [{A7BBF6CC-173E-4F92-B1A5-91533FE68EBE}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Editor.exe FirewallRules: [{2525E825-F9A6-4F85-A5A8-E97D5C3A4FDA}] => (Allow) C:\Windows\SysWOW64\msiexec.exe FirewallRules: [{4AE9836A-57F4-4F10-9FE2-079DCE1A74C5}] => (Allow) C:\Windows\SysWOW64\msiexec.exe FirewallRules: [{782775DE-583A-4E84-BCDF-8766C9907708}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsasvr.exe FirewallRules: [{A6DE10C4-6169-4354-8A5F-1D6EF61C649A}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsasvr.exe FirewallRules: [{360EE568-4F95-4925-AD87-D0D8629D8E94}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsvsvr.exe FirewallRules: [{E834066F-C3C5-4C49-A039-7AE32F6BA807}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsvsvr.exe FirewallRules: [TCP Query User{56C7AB21-BCCD-4F5C-8D52-74B395884B9E}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Block) C:\program files (x86)\sony\content manager assistant\cma.exe FirewallRules: [UDP Query User{C47A71CD-4BB7-4FF9-BC0F-829EE83DFA87}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Block) C:\program files (x86)\sony\content manager assistant\cma.exe FirewallRules: [{27133C47-866D-499D-B8E0-62C8175B8D81}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe FirewallRules: [{FC824A4A-084E-4949-A0FE-00036DCD3AE0}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\ODSAgent.exe FirewallRules: [{2BF78D21-34D1-407F-BB1E-863E83E76E74}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\ODSAgent.exe FirewallRules: [{ED6FAA94-A8B5-45A3-9D07-B568068532D2}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\RemoteInstallMacOSX.exe FirewallRules: [{6A55489F-AC43-4B82-8B6F-10620D1D28BB}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\RemoteInstallMacOSX.exe FirewallRules: [{E744BA9D-77AC-4A44-B1CC-53F9C01E70F8}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{E7C457CF-0B0B-42A7-A0D2-F942BD081C8C}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{14972E55-7D37-4D27-AE30-652C230045BE}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{B9FBD964-5AD5-4909-B65A-DCB842B4B050}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [TCP Query User{FE2B4338-50A1-42E3-BC70-F33D927CCA59}C:\users\basti\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\basti\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{FC27B11D-372E-4D59-9F85-5B7E0630AD9C}C:\users\basti\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\basti\appdata\roaming\spotify\spotify.exe FirewallRules: [{77FEF5E3-A2C3-4AAF-B6F3-2944DB24AEB0}] => (Block) C:\users\basti\appdata\roaming\spotify\spotify.exe FirewallRules: [{3C5A270E-15A2-4014-84D7-4C2B82BFD115}] => (Block) C:\users\basti\appdata\roaming\spotify\spotify.exe FirewallRules: [{0BEC205D-E089-4F21-9A05-312B20B704F9}] => (Allow) E:\Dragon Nest Europe\DragonNest.exe FirewallRules: [{F2C2E9A0-14A3-46AB-B79D-0489399BAFF8}] => (Allow) E:\Dragon Nest Europe\DragonNest.exe FirewallRules: [TCP Query User{6B0C01E5-C627-4A7C-8E52-D90D5FA2D12F}C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe] => (Allow) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe FirewallRules: [UDP Query User{49CAF30B-96F6-46AF-87DC-7C846CEE1567}C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe] => (Allow) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe FirewallRules: [{DBB21750-4C66-4A32-BDE8-9BD9B599C09C}] => (Block) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe FirewallRules: [{E8872357-7E0F-4009-960C-A6CA99D08262}] => (Block) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe FirewallRules: [{D90E4B67-C6C8-4C6D-B779-95A0AF0549FB}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{01D550ED-529B-4EBD-A526-FF7C61C99B38}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{3AEC5918-0F0F-446C-814F-BED80BA8D615}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{A19FAE1B-8FC4-47A2-AF99-615CB1632989}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{E7C041D1-61AF-47DC-87FF-C4102F7E96AB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{29261903-A601-474E-B969-353B616287C2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{F3F0B184-0050-4CC7-A11F-2FF10347E4E1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{B75523F0-6DFC-4C2E-88DF-3A853D1A7A1E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{3BAF1F78-0DC1-4410-88A6-ACFE28FAADD8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{63076B8D-F269-449B-BF26-999899FB5637}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{092EAFF9-F1B8-492E-8A93-FCDED7F6F01A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{2FE6D278-7786-4902-A270-0562F93891F8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{5BF2665B-F8A2-448B-A8B1-166D603E24FF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [{589C5ED7-3E1B-4004-A20E-66EEB891C562}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [{C0F3EDDA-BD33-4854-B4D0-75DD8675C224}] => (Allow) C:\Program Files (x86)\Origin Games\Plants vs. Zombies\PlantsVsZombies.exe FirewallRules: [{6D26D78C-E034-449D-ADBE-E29E44D2F37A}] => (Allow) C:\Program Files (x86)\Origin Games\Plants vs. Zombies\PlantsVsZombies.exe FirewallRules: [{4442C690-D7E9-4B5F-A25E-521E36417F40}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{5D891812-49CD-43AE-B7EE-B27C96C7C7B2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [TCP Query User{91BF4BE0-EB25-44AD-ADB9-36F1E34B317B}C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe] => (Allow) C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe FirewallRules: [UDP Query User{A4A79727-54EA-44D0-948D-F9DFAEFDAF0F}C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe] => (Allow) C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe FirewallRules: [{68D3CDC7-D1F8-4273-842F-B17E7C4E86CF}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe FirewallRules: [{A4642A64-FFB6-42F5-9EF8-A3F257E61B1C}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe FirewallRules: [{C5272483-76CE-4BD8-8646-C6EC5F1CF1C6}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe FirewallRules: [{8B4C1C15-86C8-4AD4-B190-9C08CFFD95D9}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe FirewallRules: [{25ADDED9-C807-4172-90A1-C3AC964FE326}] => (Allow) %ProgramFiles% (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe FirewallRules: [{FA35EA0D-AF61-4537-97B0-E60A84D561B2}] => (Block) %USERPROFILE%\Downloads\Test\Watch.Dogs.Deluxe.Edition.Cracked-3DM\bin\watch_dogs.exe FirewallRules: [{5B1D4735-6FF7-4A19-A18C-5AF5E9D2714F}] => (Block) E:\Program Files (x86)\Tropico 5\Tropico5.exe FirewallRules: [{794319B8-A91B-4DD1-93BF-25E9DA084189}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\FaxApplications.exe FirewallRules: [{8C20186C-0132-442A-A451-0EA1015D8F23}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\DigitalWizards.exe FirewallRules: [{66CB480A-D5FC-4F94-AC12-477B0638B0DA}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\SendAFax.exe FirewallRules: [{CEFFC8B8-7E7F-4597-9668-0026E35B6E55}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\DeviceSetup.exe FirewallRules: [{359830D2-A868-402B-B585-B569FB7EB3C0}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicator.exe FirewallRules: [{5EBF68FE-225D-4A50-A647-5F055D3EFEDE}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{C82C70BC-BCA0-4975-B46C-17D9C4A9BEA5}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{CE760193-0C9F-4B96-AB09-26F0C191308E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{071BE61C-F3E5-49E7-A3A4-56EA1EB407CA}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4_x86.exe FirewallRules: [{D1797CFD-02F7-4544-9D54-7A0B951C5482}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4_x86.exe FirewallRules: [{7A5E1850-EC46-4F46-85DA-54540ACBDDB2}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe FirewallRules: [{996983E1-D0BE-4FCD-8BBA-E257667941C5}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe FirewallRules: [TCP Query User{B8D07668-448E-487F-969A-93BD616D78E5}C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe FirewallRules: [UDP Query User{662D666A-2E35-412E-A419-095CFC37F1C1}C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe FirewallRules: [{F2FC4E0B-76F9-4320-853A-51889938D513}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe FirewallRules: [{FDFA8CE5-7B10-4F85-911C-B56695D7EAE2}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe FirewallRules: [TCP Query User{5FC2F183-3E0D-440A-A0CD-69E7A331D073}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe FirewallRules: [UDP Query User{E8183AD0-A3B5-4509-A899-446F3BC09495}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe FirewallRules: [TCP Query User{041EF0F9-A7FE-4004-805D-A9BCE9B87258}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe FirewallRules: [UDP Query User{33544488-16F1-42C3-A81A-1C1511AF6668}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe FirewallRules: [{031849CA-EB99-4088-9CCB-4C258DD89942}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ_BE.exe FirewallRules: [{8E346669-071F-4C46-A819-6CD8A7CC5FEA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ_BE.exe FirewallRules: [{B1A7B880-0EB6-4823-9D86-9FFCF83A3F58}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{E58C066A-3E3D-42F8-BFA8-E9BAE65EB7E4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{B991969E-6CD9-460C-A810-EDD7ADA4E68B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{04971D38-5D33-4E01-B3BB-219E0093C7BA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{89F1D3EE-7834-42BC-9700-3D25BCBC56B3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{C3FAE89B-1D4E-4D46-8A61-50158D229C9A}C:\program files\matlab\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\r2015a\bin\win64\matlab.exe FirewallRules: [UDP Query User{AF96BE9C-1D63-45FA-A019-CBD69EC2ECFD}C:\program files\matlab\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\r2015a\bin\win64\matlab.exe FirewallRules: [{79EDEFCB-DED5-415A-A2D4-954E3A07B2BC}] => (Block) C:\program files\matlab\r2015a\bin\win64\matlab.exe FirewallRules: [{5D435D29-34E0-4F66-BC06-329AC4E22143}] => (Block) C:\program files\matlab\r2015a\bin\win64\matlab.exe FirewallRules: [TCP Query User{E16785C3-4F1F-43DB-8569-7DAA1BB4939E}C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [UDP Query User{F8F7CE09-1BD6-40C2-BD53-B90E1779DF9E}C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [{56E46A08-F7EC-4BCD-99E7-67C16D04072B}] => (Block) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [{BAE9B81F-B180-450C-AAC2-90F85855CDCF}] => (Block) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [TCP Query User{960BAFE7-B279-4687-9762-B617276B2508}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [UDP Query User{3DD91B0E-AD44-4ACC-A86F-E3FFDF965641}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [{1498F3EC-1538-4C3F-9EAA-03B8D867AF38}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [{91101AFB-5036-4D1E-9DE3-115D13D0A94C}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [TCP Query User{DB4711FF-7CE3-4C3F-A9E2-C814CAE24E25}C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe FirewallRules: [UDP Query User{2FCA9D68-E3E0-464D-B786-8D9728A834FD}C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe FirewallRules: [{6D6BEFEA-892A-461E-8E30-BC2DD8A8A9F1}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe FirewallRules: [{C30C8168-C7A9-411E-B51C-B21F3F9F16B2}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe FirewallRules: [TCP Query User{83036536-6209-4CB8-B628-DA794E18A8DE}C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe FirewallRules: [UDP Query User{A139B970-9425-43E7-BDB6-4E22B2345171}C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe FirewallRules: [{700BBAB0-6C40-4AF2-BA97-8C696AC63CB0}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe FirewallRules: [{F11DDB0B-43A6-49B1-B7D0-5A8066177317}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe FirewallRules: [TCP Query User{BB97726B-726D-4884-B231-36F1A90474C5}C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe FirewallRules: [UDP Query User{F0AFB84E-50C4-44F0-92F2-B67D99132739}C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe FirewallRules: [{00EB906D-649C-4861-8C9D-34882AA42F23}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe FirewallRules: [{8CA6EF79-B664-454D-B766-431FFD0DF4B7}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe FirewallRules: [{A6D6D585-8623-4CE1-BAAD-351E922FB928}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [{C2585F8A-885F-42B0-862D-ABAE50F00A1F}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe FirewallRules: [{BBFEFEDB-1230-42AF-A40A-7968C2540868}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe FirewallRules: [{077A8C17-D8B6-424C-8B93-106296089B81}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe FirewallRules: [{E873F7D5-09B2-46FE-9BB0-FC73E216E95C}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe FirewallRules: [TCP Query User{82994F2D-DF04-4504-9058-CD0ECF2CB746}C:\users\basti\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\basti\appdata\local\mycomgames\mycomgames.exe FirewallRules: [UDP Query User{7A4E61E8-A717-4843-BD4D-C110383BB73B}C:\users\basti\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\basti\appdata\local\mycomgames\mycomgames.exe FirewallRules: [TCP Query User{705B4041-A30C-4268-8F74-2563047066DB}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\javaw.exe FirewallRules: [UDP Query User{0C868E8E-EF56-47E5-9E9E-6416F680CADC}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\javaw.exe FirewallRules: [{A7EF31CF-8B85-49A0-AA01-137354F2D690}] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe FirewallRules: [{0A27EF24-7F72-4DA8-96AA-0602EE1512E5}] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe FirewallRules: [{6A3A3F01-F7A8-4478-BCE1-A786958317D4}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [{AF0213A2-AC56-4328-AC32-39E8FB0880D0}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe FirewallRules: [TCP Query User{7C58B92D-4076-4983-AF12-2E3D4EE31460}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe FirewallRules: [UDP Query User{43725424-2FA4-4C68-A7C6-AE4D1E43ABD4}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe FirewallRules: [{C5AE2AAD-ACB2-4E63-BC67-B6FA715C0461}] => (Block) C:\program files\java\jre1.8.0_65\bin\java.exe FirewallRules: [{50A441D2-4782-462D-AEDA-5999E5B5CED0}] => (Block) C:\program files\java\jre1.8.0_65\bin\java.exe FirewallRules: [{798DF15F-3FB2-4BF3-A2FC-DF8A03AECE4C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{C34618EC-DBF5-490C-AF1D-DF67C2E6D049}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{A4A0EC4B-C983-4968-9F2D-3302F4F92661}C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe] => (Allow) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe FirewallRules: [UDP Query User{A4AAC983-1616-4AB4-8AD2-3D6AFF5356D7}C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe] => (Allow) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe FirewallRules: [{06F93520-1969-4A3A-8192-EA0B59554B6E}] => (Block) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe FirewallRules: [{F423C64F-ED88-4412-9950-D47215E34DBB}] => (Block) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe FirewallRules: [{7773F1CF-7D07-444E-9F8C-D57EEBADC678}] => (Allow) C:\Users\Basti\Downloads\PlayBlackDesert.exe FirewallRules: [{A6016ED8-3344-4278-8690-1A83D5005216}] => (Allow) C:\Users\Basti\Downloads\PlayBlackDesert.exe FirewallRules: [{C52C2134-609E-4B7E-B36A-3EADD6F8A190}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd.exe FirewallRules: [{238E1164-63F1-46B6-AD8F-0CC27C8619BA}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe FirewallRules: [{C96E8D7E-8DE5-4FD3-85C1-CF41AE855BA6}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr.exe FirewallRules: [{22687CF4-7DE2-4EA1-8698-5586C8BA5CE2}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient.exe FirewallRules: [{E1DD1465-3FC5-4683-9970-D29CF3F37977}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe FirewallRules: [{A1F50892-915B-4F15-8E2B-23EC7CCCA0AE}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd_x64.exe FirewallRules: [TCP Query User{D47A2608-0668-439F-BD5D-3F91C39914AB}C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{F79027D7-71EA-4E9B-A204-126AE06D6F0B}C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe FirewallRules: [{25BF71AC-A7D7-455F-909D-072BE2A7890D}] => (Block) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe FirewallRules: [{56497540-DDF4-4F39-97B8-427A74C3F8EB}] => (Block) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe FirewallRules: [{C92E8A48-A808-4C74-8216-0AF4284CF939}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\PublicLauncher.exe FirewallRules: [{FFB5C658-D2AA-45C6-90F8-83CC5523B319}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\PublicLauncher.exe FirewallRules: [{9E2CB54A-70ED-4A4E-A8BD-F7E24A1E8A57}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\MQELDiagnostics.exe FirewallRules: [{00ED0974-C580-4FFD-A091-BA3BFBEC7AC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\MQELDiagnostics.exe FirewallRules: [TCP Query User{5197AE62-CE7D-4AA2-B80F-B5F444D5BFA7}C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe FirewallRules: [UDP Query User{A0DC3AE3-67CD-46C7-ABB1-F7B625700ACC}C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe FirewallRules: [{5C48AC52-2639-4854-A883-55938500DD89}] => (Block) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe FirewallRules: [{F39D5120-EA60-4023-8F52-E21E2020037B}] => (Block) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe FirewallRules: [{571F6C7C-2EFF-4F40-BB56-2654CCAFC1C2}] => (Allow) C:\Program Files\Echobit\Evolve\EvoSvc.exe FirewallRules: [{450EC6E1-77C0-43E2-9A68-1750427FB700}] => (Allow) C:\Program Files\Echobit\Evolve\EvolveClient.exe FirewallRules: [{3FFDEB63-D938-43B8-A52B-A79A42CE5867}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{7759388F-4EB9-47C8-905A-89153DD9989C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{90246421-2C2E-499B-A5B5-69F2DEB1E1F7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{DF9CE38A-4A6C-48B5-9157-3B60D3673EC7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{4EED09D9-F074-4E5F-8F6B-04CB10A69337}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{3DC9517A-F886-44F5-AF92-5EE0EF4B3B9A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe ==================== Wiederherstellungspunkte ========================= 21-01-2016 14:26:57 Entfernt Blade & Soul 21-01-2016 14:33:54 Installiert Blade & Soul ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (01/21/2016 02:28:47 PM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP) Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/21/2016 02:14:32 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/21/2016 01:25:41 PM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP) Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/21/2016 01:11:48 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/21/2016 10:45:54 AM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP) Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/21/2016 10:31:30 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/21/2016 09:38:26 AM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP) Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/21/2016 09:23:47 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/20/2016 09:46:05 AM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP) Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/20/2016 09:33:44 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Systemfehler: ============= Error: (01/21/2016 11:58:36 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10. Error: (01/21/2016 11:57:52 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10. Error: (01/21/2016 11:57:52 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10. Error: (01/21/2016 11:57:52 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10. Error: (01/21/2016 11:57:31 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10. Error: (01/21/2016 03:23:30 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10. Error: (01/21/2016 02:14:23 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (01/21/2016 01:48:09 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "Intelligenter Hintergrundübertragungsdienst" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147467243. Error: (01/21/2016 01:48:09 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16392) (User: NT-AUTORITÄT) Description: Fehler beim Starten des BITS-Dienstes. Fehler: 2147500053. Error: (01/21/2016 01:12:05 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) CodeIntegrity: =================================== Date: 2016-01-18 10:27:54.004 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-18 10:27:53.954 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-30 14:58:14.199 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.CP6452" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-30 14:58:14.135 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.CP6452" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-29 13:19:19.901 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.sA6316" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-29 13:19:19.826 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.sA6316" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-29 13:07:59.521 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.AF5708" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-29 13:07:59.460 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.AF5708" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-29 00:11:40.229 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.yT4184" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-29 00:11:40.169 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.yT4184" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz Prozentuale Nutzung des RAM: 74% Installierter physikalischer RAM: 8146.98 MB Verfügbarer physikalischer RAM: 2080.05 MB Summe virtueller Speicher: 14287.19 MB Verfügbarer virtueller Speicher: 6894.3 MB ==================== Laufwerke ================================ Drive c: (Win7HPx64) (Fixed) (Total:465.76 GB) (Free:38.61 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)] Drive d: (MUNZ_2012) (CDROM) (Total:0.03 GB) (Free:0 GB) CDFS Drive e: (SAMSUNG) (Fixed) (Total:931.28 GB) (Free:313.13 GB) FAT32 ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4E7DE8CA) Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: C3178030) Partition 1: (Active) - (Size=931.5 GB) - (Type=0C) ==================== Ende von Addition.txt ============================ Malwarebyte Code:
ATTFilter <?xml version="1.0" encoding="UTF-16" ?> <mbam-log> <header> <date>2016/01/21 12:15:47 +0100</date> <logfile>mbam-log-2016-01-21 (12-15-46).xml</logfile> <isadmin>yes</isadmin> </header> <engine> <version>2.2.0.1024</version> <malware-database>v2016.01.21.01</malware-database> <rootkit-database>v2016.01.20.01</rootkit-database> <license>free</license> <file-protection>disabled</file-protection> <web-protection>disabled</web-protection> <self-protection>disabled</self-protection> </engine> <system> <hostname>BASTI-DESKTOP</hostname> <ip>192.168.178.25, *****</ip> <osversion>Windows 7 Service Pack 1</osversion> <arch>x64</arch> <username>Basti</username> <filesys>NTFS</filesys> </system> <summary> <type>threat</type> <result>completed</result> <objects>538955</objects> <time>3017</time> <processes>0</processes> <modules>0</modules> <keys>9</keys> <values>2</values> <datas>0</datas> <folders>10</folders> <files>61</files> <sectors>0</sectors> </summary> <options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>disabled</rootkits> <deeprootkit>disabled</deeprootkit> <heuristics>enabled</heuristics> <pup>enabled</pup> <pum>enabled</pum> </options> <items> <key><path>HKLM\SOFTWARE\CLASSES\APPID\{608D3067-77E8-463D-9084-908966806826}</path><vendor>PUP.Optional.Incredibar</vendor><action>success</action><hash>e461a19bc2d744f21fa31577ab57bd43</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{608D3067-77E8-463D-9084-908966806826}</path><vendor>PUP.Optional.Incredibar</vendor><action>success</action><hash>e461a19bc2d744f21fa31577ab57bd43</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{608D3067-77E8-463D-9084-908966806826}</path><vendor>PUP.Optional.Incredibar</vendor><action>success</action><hash>e461a19bc2d744f21fa31577ab57bd43</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}</path><vendor>Adware.1ClickDownloader</vendor><action>success</action><hash>75d0f349e2b78caa219f85079072c838</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}</path><vendor>Adware.1ClickDownloader</vendor><action>success</action><hash>75d0f349e2b78caa219f85079072c838</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}</path><vendor>Adware.1ClickDownloader</vendor><action>success</action><hash>75d0f349e2b78caa219f85079072c838</hash></key> <key><path>HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Dealply</path><vendor>PUP.Optional.DealPly</vendor><action>delete-on-reboot</action><hash>e95c0c300099bc7a0c612c9134cfeb15</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\kekfoodhbhpjhjcdecjngamojfhknooc</path><vendor>PUP.Optional.Amonetize</vendor><action>success</action><hash>b68fff3d316866d030e3aa052ed5ca36</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110111491187}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>ab9a2517a1f880b6961bebd1c3403cc4</hash></key> <value><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110111491187}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>PC Speed Up Extension-bg.exe</valuedata><hash>ab9a2517a1f880b6961bebd1c3403cc4</hash></value> <value><path>HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS</path><valuename>ntfdsaftsfdfdxx@mozilla.org</valuename><vendor>PUP.Optional.Amonetize</vendor><action>success</action><valuedata>C:\Users\Basti\AppData\Roaming\iPumper\extension_firefox.xpi</valuedata><hash>370eac908d0cfc3a0115b4fbd92a847c</hash></value> <folder><path>C:\Users\Basti\AppData\Roaming\OpenCandy</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ac99023aa6f36dc95e48534662a042be</hash></folder> <folder><path>C:\Users\Basti\AppData\Roaming\OpenCandy\A190A5BDEE9949658EE7FF47A4B2FC35</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ac99023aa6f36dc95e48534662a042be</hash></folder> <folder><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></folder> <folder><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\components</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></folder> <folder><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></folder> <folder><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></folder> <folder><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></folder> <folder><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></folder> <folder><path>C:\Users\Basti\AppData\Roaming\Dealply</path><vendor>PUP.Optional.DealPly</vendor><action>success</action><hash>e56096a6930638fe7a2e555bb25044bc</hash></folder> <folder><path>C:\Users\Basti\AppData\Roaming\Dealply\UpdateProc</path><vendor>PUP.Optional.DealPly</vendor><action>success</action><hash>e56096a6930638fe7a2e555bb25044bc</hash></folder> <file><path>C:\Users\Basti\AppData\Roaming\OpenCandy\A190A5BDEE9949658EE7FF47A4B2FC35\LatestDLMgr.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>3f065ae2d2c786b078326dc854ad9a66</hash></file> <file><path>C:\Windows\hidcon.exe</path><vendor>Trojan.Agent.Drop</vendor><action>success</action><hash>d273ef4d4257c2742021cc7755adbb45</hash></file> <file><path>C:\Windows\System32\Tasks\Dealply</path><vendor>PUP.Optional.DealPly</vendor><action>success</action><hash>65e088b48118d75fb6a7c3fac53ea060</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\logs.dat</path><vendor>Backdoor.Bifrose.Trace</vendor><action>success</action><hash>01440a32445596a0b33fe0131de613ed</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\OpenCandy\A190A5BDEE9949658EE7FF47A4B2FC35\LinkuryYAHOO_RBCB_p3v3.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ac99023aa6f36dc95e48534662a042be</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\chrome.manifest</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\install.rdf</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\components\FFDisp.dll</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\delta.css</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\delta.xul</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\dpk.htm</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\hlprs.js</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\loader.xul</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\mtstart.js</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\serp.js</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\tmplt.js</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\arwDwn.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\closeo.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\help_16.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\home.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\icon_seperator.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\logo.PNG</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\privecy_16_hot.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\sign.jpg</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\specialoffer.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\tellafriend.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\uninstall.gif</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ae.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\bg.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ch.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\cn.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\cz.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\de.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\eg.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\en.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\es.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\fr.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\gr.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\he.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\il.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\it.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ja.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\jp.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\nl.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\no.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\pl.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\pt.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ro.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ru.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\sa.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\se.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\sv.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\tr.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ua.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\us.png</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF\manifest.mf</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF\zigbert.rsa</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF\zigbert.sf</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>1530cc70d1c80036e952e5b61de520e0</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Dealply\UpdateProc\config.dat</path><vendor>PUP.Optional.DealPly</vendor><action>success</action><hash>e56096a6930638fe7a2e555bb25044bc</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js</path><vendor>PUP.Optional.Babylon</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.newTab", true);</baddata><gooddata></gooddata><hash>90b58fad4b4e0531af323da4e420a35d</hash></file> <file><path>C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js</path><vendor>PUP.Optional.Babylon</vendor><action>replaced</action><baddata>rences /* Do not edit this file. * * If you make changes to this file while the application is running, * the changes will be overwritten wh</baddata><gooddata></gooddata><hash>3d08023ad7c289ad9a47fce5a2628a76</hash></file> </items> </mbam-log> |
22.01.2016, 09:11 | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsamZitat:
Lesestoff: Illegale Software: Cracks, Keygens und Co Bitte lesen => http://www.trojaner-board.de/95393-c...-software.html Es geht weiter wenn du alles Illegale entfernt hast. Bei wiederholten Crack/Keygen Verstößen behalte ich es mir vor, den Support einzustellen, d.h. Hilfe nur noch bei der Datensicherung und Neuinstallation des Betriebssystems.
__________________ Logfiles bitte immer in CODE-Tags posten |
22.01.2016, 09:59 | #5 |
| Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam Sry Des hab ich vergessen zu löschen. Werde sofort alles beseitigen wenn ich wieder zu Hause bin. Soll ich danach nochmal einen bestimmten Scan laufen lassen? |
22.01.2016, 10:58 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam Das Log von Malwarebytes richtig posten. Im TXT Format. XML kann doch keiner lesen.
__________________ --> Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam |
22.01.2016, 13:28 | #7 |
| Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam Code von Malwarebytes in TXT-form Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 21.01.2016 Suchlaufzeit: 12:15 Protokolldatei: malwarebytes.txt Administrator: Ja Version: 2.2.0.1024 Malware-Datenbank: v2016.01.21.01 Rootkit-Datenbank: v2016.01.20.01 Lizenz: Kostenlose Version Malware-Schutz: Deaktiviert Schutz vor bösartigen Websites: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Basti Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 538955 Abgelaufene Zeit: 50 Min., 17 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 9 PUP.Optional.Incredibar, HKLM\SOFTWARE\CLASSES\APPID\{608D3067-77E8-463D-9084-908966806826}, In Quarantäne, [e461a19bc2d744f21fa31577ab57bd43], PUP.Optional.Incredibar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{608D3067-77E8-463D-9084-908966806826}, In Quarantäne, [e461a19bc2d744f21fa31577ab57bd43], PUP.Optional.Incredibar, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{608D3067-77E8-463D-9084-908966806826}, In Quarantäne, [e461a19bc2d744f21fa31577ab57bd43], Adware.1ClickDownloader, HKLM\SOFTWARE\CLASSES\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}, In Quarantäne, [75d0f349e2b78caa219f85079072c838], Adware.1ClickDownloader, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}, In Quarantäne, [75d0f349e2b78caa219f85079072c838], Adware.1ClickDownloader, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}, In Quarantäne, [75d0f349e2b78caa219f85079072c838], PUP.Optional.DealPly, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Dealply, Löschen bei Neustart, [e95c0c300099bc7a0c612c9134cfeb15], PUP.Optional.Amonetize, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\kekfoodhbhpjhjcdecjngamojfhknooc, In Quarantäne, [b68fff3d316866d030e3aa052ed5ca36], PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110111491187}, In Quarantäne, [ab9a2517a1f880b6961bebd1c3403cc4], Registrierungswerte: 2 PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110111491187}|AppName, PC Speed Up Extension-bg.exe, In Quarantäne, [ab9a2517a1f880b6961bebd1c3403cc4] PUP.Optional.Amonetize, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|ntfdsaftsfdfdxx@mozilla.org, C:\Users\Basti\AppData\Roaming\iPumper\extension_firefox.xpi, In Quarantäne, [370eac908d0cfc3a0115b4fbd92a847c] Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 10 PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy, In Quarantäne, [ac99023aa6f36dc95e48534662a042be], PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\A190A5BDEE9949658EE7FF47A4B2FC35, In Quarantäne, [ac99023aa6f36dc95e48534662a042be], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\components, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.DealPly, C:\Users\Basti\AppData\Roaming\Dealply, In Quarantäne, [e56096a6930638fe7a2e555bb25044bc], PUP.Optional.DealPly, C:\Users\Basti\AppData\Roaming\Dealply\UpdateProc, In Quarantäne, [e56096a6930638fe7a2e555bb25044bc], Dateien: 61 PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\A190A5BDEE9949658EE7FF47A4B2FC35\LatestDLMgr.exe, In Quarantäne, [3f065ae2d2c786b078326dc854ad9a66], Trojan.Agent.Drop, C:\Windows\hidcon.exe, In Quarantäne, [d273ef4d4257c2742021cc7755adbb45], PUP.Optional.DealPly, C:\Windows\System32\Tasks\Dealply, In Quarantäne, [65e088b48118d75fb6a7c3fac53ea060], Backdoor.Bifrose.Trace, C:\Users\Basti\AppData\Roaming\logs.dat, In Quarantäne, [01440a32445596a0b33fe0131de613ed], PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\A190A5BDEE9949658EE7FF47A4B2FC35\LinkuryYAHOO_RBCB_p3v3.exe, In Quarantäne, [ac99023aa6f36dc95e48534662a042be], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\chrome.manifest, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\install.rdf, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\components\FFDisp.dll, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\delta.css, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\delta.xul, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\dpk.htm, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\hlprs.js, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\loader.xul, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\mtstart.js, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\serp.js, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\tmplt.js, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\arwDwn.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\closeo.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\help_16.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\home.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\icon_seperator.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\logo.PNG, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\privecy_16_hot.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\sign.jpg, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\specialoffer.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\tellafriend.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\uninstall.gif, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ae.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\bg.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ch.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\cn.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\cz.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\de.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\eg.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\en.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\es.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\fr.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\gr.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\he.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\il.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\it.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ja.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\jp.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\nl.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\no.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\pl.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\pt.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ro.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ru.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\sa.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\se.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\sv.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\tr.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\ua.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\content\imgs\flgs\us.png, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF\manifest.mf, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF\zigbert.rsa, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.Delta.ShrtCln, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\ffxtlbr@delta.com\META-INF\zigbert.sf, In Quarantäne, [1530cc70d1c80036e952e5b61de520e0], PUP.Optional.DealPly, C:\Users\Basti\AppData\Roaming\Dealply\UpdateProc\config.dat, In Quarantäne, [e56096a6930638fe7a2e555bb25044bc], PUP.Optional.Babylon, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.newTab", true);), Ersetzt,[90b58fad4b4e0531af323da4e420a35d] PUP.Optional.Babylon, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js, Gut: (), Schlecht: (rences /* Do not edit this file. * * If you make changes to this file while the application is running, * the changes will be overwritten wh), Ersetzt,[3d08023ad7c289ad9a47fce5a2628a76] Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) |
22.01.2016, 13:30 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam Adware/Junkware/Toolbars entfernen Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop! Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren! 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
22.01.2016, 17:45 | #9 |
| Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam AdwCleaner: Code:
ATTFilter # AdwCleaner v5.030 - Bericht erstellt am 22/01/2016 um 17:04:37 # Aktualisiert am 17/01/2016 von Xplode # Datenbank : 2016-01-19.2 [Server] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64) # Benutzername : Basti - BASTI-DESKTOP # Gestartet von : C:\Users\Basti\Desktop\AdwCleaner_5.030.exe # Option : Löschen # Unterstützung : hxxp://toolslib.net/forum ***** [ Dienste ] ***** ***** [ Ordner ] ***** [-] Ordner Gelöscht : C:\Program Files (x86)\Winamp Toolbar [-] Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\AskTB [-] Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB [-] Ordner Gelöscht : C:\Program Files (x86)\Common Files\Software Update Utility [-] Ordner Gelöscht : C:\ProgramData\Winamp Toolbar [-] Ordner Gelöscht : C:\Users\Basti\AppData\Local\Winamp Toolbar [-] Ordner Gelöscht : C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg [-] Ordner Gelöscht : C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl [-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Booster [-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\dvdvideosoftiehelpers [-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iPumper [-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\Extensions\staged\EFGLQA@78ETGYN-0W7FN789T87.COM [-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\Extensions\sparpilot@sparpilot.com [-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\staged\EFGLQA@78ETGYN-0W7FN789T87.COM [-] Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\sparpilot@sparpilot.com ***** [ Dateien ] ***** [-] Datei Gelöscht : C:\END [-] Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll [-] Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.xpt [-] Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll [-] Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.xpt [-] Datei Gelöscht : C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\npnkeeiehehhefofiekoflfedgehcdhl ***** [ DLLs ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** ***** [ Registrierungsdatenbank ] ***** [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\dnu.EXE [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\winamptbServer.exe [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B27D9527-3762-4D71-963D-FB7A94FDD678} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6EF4E91D-DDD5-4478-BCA7-DA04435934C0} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{841FD004-57A2-4B49-BBDB-5897394619DB} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B38D6EDE-390B-4620-8365-29E16459EBDA} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F20F11FD-203E-45A9-B7BB-AFC1B4FEA7A6} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FE178B09-C8AA-4734-804D-1849BCCA0C29} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{507591C2-2F4E-46A7-92D6-E6CFF82E5F26} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{538CD77C-BFDD-49B0-9562-77419CAB89D1} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} [-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} [-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} [-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} [-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A8C2644D-BF72-4A89-A88C-D85F565F2F46} [-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] [-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}] [-] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}] [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057} [-] Schlüssel Gelöscht : HKCU\Software\BI [-] Schlüssel Gelöscht : HKCU\Software\Escolade [-] Schlüssel Gelöscht : HKCU\Software\Headlight [-] Schlüssel Gelöscht : HKCU\Software\OCS [-] Schlüssel Gelöscht : HKCU\Software\Softonic [-] Schlüssel Gelöscht : HKCU\Software\Winamp Toolbar [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Winamp Toolbar [-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{177586E7-E42E-4F38-83D1-D15B4AF5B714} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Features\7E685771E24E83F4381D1DB5A45F7B41 [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\7E685771E24E83F4381D1DB5A45F7B41 [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7E685771E24E83F4381D1DB5A45F7B41 [-] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain] [-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C6CE0053-87D1-4C2C-9DBF-738685826369} ***** [ Internetbrowser ] ***** [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("browser.search.defaultengine", "Ask.com"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("browser.search.defaultenginename", "Ask.com"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("browser.search.order.1", "Ask.com"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("browser.search.selectedEngine", "Ask.com"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", ""); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.admin", false); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.aflt", "babsst"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.autoRvrt", "false"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.dfltLng", "en"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.excTlbr", false); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.id", "5005731d0000000000000008cae5fc52"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.instlDay", "15746"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.instlRef", "sst"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.newTab", false); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.prdct", "delta"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.prtnrId", "delta"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.rvrt", "false"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.smplGrp", "none"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.tlbrId", "base"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.tlbrSrchUrl", ""); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.vrsn", "1.8.10.0"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.10.014:55:22"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\prefs.js] [Preference] Gelöscht : user_pref("extensions.delta.vrsni", "1.8.10.0"); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\prefs.js] [Preference] Gelöscht : user_pref("pttl.menu-search-groups-tab", false); [-] [C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\prefs.js] [Preference] Gelöscht : user_pref("pttl.menu-search-groups-win", false); [-] [C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Gelöscht : bopakagnckmlgajfccecajhnimjiiedh [-] [C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Gelöscht : mkcedibhemacmilmkpndpkoidlnmgngg [-] [C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Gelöscht : npnkeeiehehhefofiekoflfedgehcdhl ************************* :: "Tracing" Schlüssel gelöscht :: Proxy Einstellungen zurückgesetzt :: Winsock Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [14981 Bytes] ########## JRT JRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.0.2 (01.06.2016) Operating System: Windows 7 Home Premium x64 Ran by Basti (Administrator) on 22.01.2016 at 17:14:57,44 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 24 Successfully deleted: C:\ProgramData\thunder network (Folder) Successfully deleted: C:\Users\Basti\AppData\Local\{2807B5C6-21F2-437F-A447-2CDE66EC162D} (Empty Folder) Successfully deleted: C:\Users\Basti\AppData\Local\{745065C1-17A7-4617-B5CB-FC6F610C1C53} (Empty Folder) Successfully deleted: C:\Users\Basti\AppData\Local\{7A9BA8C6-F356-4222-A711-3E1B243FEB9E} (Empty Folder) Successfully deleted: C:\Users\Basti\AppData\Local\{CA69364C-5368-4B53-BE56-648DBB42BBF1} (Empty Folder) Successfully deleted: C:\Users\Basti\AppData\Roaming\4930 (Folder) Successfully deleted: C:\Users\Basti\AppData\Roaming\getrighttogo (Folder) Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 - Kopie\extensions\staged (Folder) Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\bingsearch.full@microsoft.com\search.xml (File) Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\hxxps-everywhere-eff@eff.org\chrome\locale\ru@petr1708 (Folder) Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\hxxps-everywhere-eff@eff.org\chrome\locale\zh_CN.GB2312 (Folder) Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\staged (Folder) Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\extensions\staged (Folder) Successfully deleted: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\startpage-hxxps.xml (File) Successfully deleted: C:\Users\Public\thunder network (Folder) Successfully deleted: C:\Windows\wininit.ini (File) Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\34IRQKQM (Folder) Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\46070FJA (Folder) Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OJWNIVD8 (Folder) Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OY95ZJ7K (Folder) Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PMG458TI (Folder) Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SKP48RWE (Folder) Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YG3Y9O3X (Folder) Successfully deleted: C:\Users\Basti\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z43XJXW4 (Folder) Registry: 1 Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 22.01.2016 at 17:21:56,18 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
22.01.2016, 17:48 | #10 |
| Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam FRST Logfile: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:18-01-2016 durchgeführt von Basti (Administrator) auf BASTI-DESKTOP (22-01-2016 17:31:38) Gestartet von C:\Users\Basti\Desktop Geladene Profile: Basti (Verfügbare Profile: Basti & Zocken & DefaultAppPool) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\vsserv.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Dassault Systemes) C:\Program Files\Dassault Systemes\B21\win_b64\code\bin\CATSysDemon.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe () C:\Program Files (x86)\Droid4X\Droid4XService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe (SoftEther VPN Project at University of Tsukuba, Japan.) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe (GGS) C:\Users\Basti\AppData\Local\THORN\Thorn.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\updatesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (GGS) C:\Users\Basti\AppData\Local\THORN\ThornHelper.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\bdagent.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxag.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\antispam32\bdwtxapps.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxcr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2771576 2015-12-16] (NVIDIA Corporation) HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-15] (Logitech Inc.) HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2016\bdagent.exe [1720488 2016-01-12] (Bitdefender) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-04-29] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-04-29] (Adobe Systems Inc.) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [708496 2015-09-23] (Cisco Systems, Inc.) HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Run: [appnhost] => C:\Users\Basti\AppData\Local\Mixesoft\AppNHost\appnhost.exe [453176 2014-08-08] (Mixesoft Project) HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Run: [Bitdefender-Geldb�rse-Agent] => C:\Program Files\Bitdefender\Bitdefender 2016\bdwtxag.exe [1423288 2016-01-12] (Bitdefender) HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Run: [Spotify Web Helper] => C:\Users\Basti\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2346096 2015-12-21] (Spotify Ltd) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BdBkpFolder [2016-01-12] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell Display Manager.lnk [2016-01-21] ShortcutTarget: Dell Display Manager.lnk -> C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe (EnTech Taiwan) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{8A41A65B-D9F1-429C-8BC5-46D12DA767EE}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {CCC4110B-5AF8-466B-8DE4-1B9BB14979FC} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = SearchScopes: HKLM-x32 -> {CCC4110B-5AF8-466B-8DE4-1B9BB14979FC} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> DefaultScope {DF39FAF5-E2FF-4630-90A1-159FB1F73C0A} URL = hxxps://de.search.yahoo.com/search?fr=mcafee&type=C010DE91021D20141021&p={searchTerms} SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://www.google.com/search?q={searchTerms}&rlz=1I7ADRA_deDE485 SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {CCC4110B-5AF8-466B-8DE4-1B9BB14979FC} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> {DF39FAF5-E2FF-4630-90A1-159FB1F73C0A} URL = hxxps://de.search.yahoo.com/search?fr=mcafee&type=C010DE91021D20141021&p={searchTerms} BHO: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2016\pmbxie.dll [2016-01-12] (Bitdefender) BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-11-01] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-01] (Oracle Corporation) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22] (Hewlett-Packard Co.) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated) BHO-x32: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2016\Antispam32\pmbxie.dll [2016-01-12] (Bitdefender) BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-11-01] (Oracle Corporation) BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2015-10-29] (Perfect World Entertainment Inc) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13] (Microsoft Corporation) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-18] (Google Inc.) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-04-29] (Adobe Systems Incorporated) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-01] (Oracle Corporation) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-04-29] (Adobe Systems Incorporated) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22] (Hewlett-Packard Co.) Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.) Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2016\pmbxie.dll [2016-01-12] (Bitdefender) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-04-29] (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.) Toolbar: HKLM-x32 - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2016\Antispam32\pmbxie.dll [2016-01-12] (Bitdefender) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-18] (Google Inc.) Toolbar: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.) DPF: HKLM {BAD4FE2C-503B-45CC-88CD-4B0574057D11} hxxp://clients.futuremark.com/calico/systeminfodeploy/FMSI_v490.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157 FF SearchEngineOrder.1: Sichere Suche FF SearchEngineOrder.3: Bing FF SelectedSearchEngine: Sichere Suche FF Homepage: www.google.de FF Session Restore: -> ist aktiviert. FF Keyword.URL: hxxps://de.search.yahoo.com/search?fr=mcafee&type=C110DE91021D20141021&p= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll [2016-01-20] () FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll [2014-09-01] (EA Digital Illusions CE AB) FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-01] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-01] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-20] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll [2013-04-03] (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-10-01] () FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll [2014-09-01] (EA Digital Illusions CE AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-01] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-01] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-12-16] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-12-16] (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [Keine Datei] FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll [2015-10-29] (Perfect World Entertainment Inc) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-04-29] (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems) FF Plugin HKU\S-1-5-21-1745305398-2489788369-3521438674-1002: @my.com/Games -> C:\Users\Basti\AppData\Local\MyComGames\NPMyComDetector.dll [2015-09-30] (My.com, Inc) FF Plugin HKU\S-1-5-21-1745305398-2489788369-3521438674-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Basti\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-08] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-1745305398-2489788369-3521438674-1002: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-01] () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-30] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2011-12-09] (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\searchplugins\anonymouseorg-anonym-surfen.xml [2015-11-16] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\searchplugins\McSiteAdvisor.xml [2015-11-17] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\duckduckgo-ssl-javascript-free.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\google-de-ssl.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\google-encrypted-no-personalization.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick---deutsch.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick-ssl-pictures---deutsch.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick-ssl-pictures---english.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ixquick.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\leo-eng-ger.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\leo-esp-ale.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\leo-fra-all.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\metager2.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ssl-wikipedia-deutsch.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\ssl-wikipedia-english.xml [2013-06-25] FF SearchPlugin: C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\searchplugins\startpage-https---deutsch.xml [2013-06-25] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2015-10-29] FF Extension: Amazon-Icon - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\amazon-icon@giga.de [2013-12-28] [ist nicht signiert] FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-06-08] [ist nicht signiert] FF Extension: DownThemAll! - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-05-28] FF Extension: Updated Ad Blocker for Firefox 11+ - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}.xpi [2015-05-29] FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015-06-23] [ist nicht signiert] FF Extension: HTTPS-Everywhere - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\extensions\https-everywhere-eff@eff.org [2015-08-28] FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender 2016\\antispam32\bdwteff [2016-01-13] FF Extension: Bing Search Engine - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\bingsearch.full@microsoft.com [2016-01-22] [ist nicht signiert] FF Extension: Magic Actions for YouTube™ - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\jid0-UVAeBCfd34Kk5usS8A1CBiobvM8@jetpack.xpi [2015-07-30] FF Extension: SSL Version Control - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\jid1-ZM3BerwS6FsQAg@jetpack.xpi [2015-05-27] FF Extension: Adblock Plus - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\csf6zwti.default-1357585031157\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-17] FF Extension: Amazon-Icon - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\amazon-icon@giga.de [2013-12-28] [ist nicht signiert] FF Extension: HTTPS-Everywhere - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\https-everywhere@eff.org [2013-07-12] [ist nicht signiert] FF Extension: UnPlug - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\unplug@compunach.xpi [2013-05-15] [ist nicht signiert] FF Extension: JonDoFox - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{437be45a-4114-11dd-b9ab-71d256d89593}.xpi [2013-06-28] [ist nicht signiert] FF Extension: Cookie Monster - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{45d8ff86-d909-11db-9705-005056c00008} [2013-07-12] [ist nicht signiert] FF Extension: NoScript - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-07-20] [ist nicht signiert] FF Extension: Adblock Plus - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-05-15] [ist nicht signiert] FF Extension: ProfileSwitcher - C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\JonDoFox\Extensions\{fa8476cf-a98c-4e08-99b4-65a69cb4b7d4}.xpi [2013-06-25] [ist nicht signiert] FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06] FF HKLM\...\Firefox\Extensions: [bdwteffv20@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\\antispam32\bdwteff FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\bdtbext FF Extension: Bitdefender Antispam Toolbar - C:\Program Files\Bitdefender\Bitdefender 2016\bdtbext [2015-11-25] [ist nicht signiert] FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-06-10] [ist nicht signiert] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF HKLM-x32\...\Firefox\Extensions: [bdwteffv20@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\\antispam32\bdwteff FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\bdtbext FF HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR Session Restore: Default -> ist aktiviert. CHR Profile: C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-27] CHR Extension: (Magic Actions for YouTube™) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2015-12-10] CHR Extension: (Google Docs) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-29] CHR Extension: (Google Drive) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21] CHR Extension: (YouTube) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29] CHR Extension: (Google-Suche) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (Bitdefender Wallet) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhhejlifdlcgcmogbggeomfodgklfaem [2015-12-13] CHR Extension: (Google Tabellen) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-27] CHR Extension: (Google Docs Offline) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18] CHR Extension: (Click&Clean) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2015-11-02] CHR Extension: (AdBlock) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-20] CHR Extension: (Google Maps) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-11-27] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-27] CHR Extension: (Click&Clean App) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2015-11-02] CHR Extension: (Google Mail) - C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-29] CHR HKLM-x32\...\Chrome\Extension: [dhhejlifdlcgcmogbggeomfodgklfaem] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-10-29] (Perfect World Entertainment Inc) R2 BBDemon; C:\Program Files\Dassault Systemes\B21\win_b64\code\bin\CATSysDemon.exe [46592 2011-01-08] (Dassault Systemes) [Datei ist nicht signiert] S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1145216 2015-05-26] () R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation) R2 Droid4XService; C:\Program Files (x86)\Droid4X\Droid4XService.exe [261864 2015-06-03] () [Datei ist nicht signiert] S3 EvoSvc; C:\Program Files\Echobit\Evolve\EvoSvc.exe [1583488 2016-01-10] (Echobit LLC) S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1616440 2015-12-22] (GOG.com) S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7184440 2015-12-22] (GOG.com) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156216 2015-12-16] (NVIDIA Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert] R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-04-10] (Intel Corporation) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.) R2 LPDSVC; C:\Windows\system32\lpdsvc.dll [45568 2009-07-14] (Microsoft Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert] S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3806032 2015-10-13] (INCA Internet Co., Ltd.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-12-16] (NVIDIA Corporation) R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8185464 2015-12-16] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [6477432 2015-12-16] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-07] (Electronic Arts) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Datei ist nicht signiert] R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-30] () R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [857288 2015-11-09] (Bitdefender) S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.) R2 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [5250280 2015-12-29] (SoftEther VPN Project at University of Tsukuba, Japan.) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Datei ist nicht signiert] R2 Thorn; C:\Users\Basti\AppData\Local\THORN\Thorn.exe [56824 2015-10-01] (GGS) R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2016\updatesrv.exe [124488 2015-09-29] (Bitdefender) R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2016\vsserv.exe [1604080 2016-01-12] (Bitdefender) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1600512 2015-10-28] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [282000 2015-09-17] (BitDefender) R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [775424 2015-09-17] (BitDefender) R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2011-11-03] (Broadcom Corporation.) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107080 2012-10-29] (BitDefender LLC) R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [87912 2015-12-14] (BitDefender) S3 cpuz135; kein ImagePath R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-06-08] (DT Soft Ltd) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R3 EvolveVirtualAdapter; C:\Windows\System32\DRIVERS\evolve.sys [21656 2016-01-10] (Echobit, LLC) R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [160032 2015-04-29] (BitDefender LLC) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-11-29] (Intel Corporation) R0 ignis; C:\Windows\System32\DRIVERS\ignis.sys [271808 2015-10-22] (Bitdefender) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R1 LUMDriver; C:\Windows\system32\drivers\LUMDriver.sys [24848 2008-01-02] (IBM) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation) R3 Neo_VPN; C:\Windows\System32\DRIVERS\Neo_0024.sys [38432 2015-12-29] (SoftEther Corporation) S3 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-12-16] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-12-16] (NVIDIA Corporation) R2 trufos; C:\Windows\System32\DRIVERS\trufos.sys [477272 2015-06-02] (BitDefender S.R.L.) R3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2010-03-29] (Texas Instruments) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-03-12] (Cisco Systems, Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-01-22 17:31 - 2016-01-22 17:31 - 02370560 _____ (Farbar) C:\Users\Basti\Desktop\FRST64.exe 2016-01-22 17:31 - 2016-01-22 17:31 - 00040729 _____ C:\Users\Basti\Desktop\FRST.txt 2016-01-22 17:21 - 2016-01-22 17:21 - 00003521 _____ C:\Users\Basti\Desktop\JRT.txt 2016-01-22 17:13 - 2016-01-22 17:13 - 01600184 _____ (Malwarebytes) C:\Users\Basti\Desktop\JRT.exe 2016-01-22 13:41 - 2016-01-22 17:04 - 00000000 ____D C:\AdwCleaner 2016-01-22 13:35 - 2016-01-22 13:35 - 01505280 _____ C:\Users\Basti\Desktop\AdwCleaner_5.030.exe 2016-01-22 13:26 - 2016-01-22 13:26 - 00018340 _____ C:\Users\Basti\Desktop\malwarebytes.txt 2016-01-21 23:46 - 2016-01-22 17:31 - 00000000 ____D C:\FRST 2016-01-21 15:28 - 2016-01-21 15:28 - 02967888 _____ C:\Users\Basti\Desktop\Sebastian Schmitt.tif 2016-01-21 14:34 - 2016-01-21 14:34 - 00002243 _____ C:\Users\Public\Desktop\Blade & Soul.lnk 2016-01-21 14:20 - 2016-01-21 14:20 - 01611384 _____ (NCSOFT Corporation) C:\Users\Basti\Downloads\NC-LauncherSetup.exe 2016-01-21 12:15 - 2016-01-22 13:25 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-01-21 12:15 - 2016-01-21 13:14 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2016-01-21 12:15 - 2016-01-21 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2016-01-21 12:15 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-01-21 12:14 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2016-01-21 12:14 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2016-01-21 12:06 - 2016-01-21 12:15 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2016-01-21 12:06 - 2016-01-21 12:06 - 22908888 _____ (Malwarebytes ) C:\Users\Basti\Downloads\mbam-setup-2.2.0.1024 (1).exe 2016-01-21 12:06 - 2016-01-21 12:06 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-01-20 11:02 - 2016-01-20 11:02 - 00006949 _____ C:\Users\Basti\Desktop\BnS.xml 2016-01-18 15:09 - 2016-01-18 15:10 - 00000000 ____D C:\Users\Basti\AppData\Local\CrashDumps 2016-01-18 10:42 - 2016-01-18 10:42 - 00038983 _____ C:\ComboFix.txt 2016-01-18 10:29 - 2016-01-22 17:05 - 00008451 _____ C:\bdlog.txt 2016-01-18 10:14 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2016-01-18 10:14 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2016-01-18 10:14 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2016-01-18 10:14 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2016-01-18 10:14 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2016-01-18 10:14 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2016-01-18 10:14 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2016-01-18 10:14 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2016-01-18 10:13 - 2016-01-18 10:42 - 00000000 ____D C:\Qoobox 2016-01-18 10:12 - 2016-01-18 10:40 - 00000000 ____D C:\Windows\erdnt 2016-01-17 23:28 - 2015-12-16 18:34 - 00111520 _____ C:\Windows\system32\NvRtmpStreamer64.dll 2016-01-17 23:23 - 2015-12-16 15:39 - 00103032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2016-01-17 23:22 - 2015-12-16 15:53 - 00523384 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2016-01-17 23:22 - 2015-12-16 15:53 - 00075056 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 42977072 _____ C:\Windows\system32\nvcompiler.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 37609080 _____ C:\Windows\SysWOW64\nvcompiler.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 31061624 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 24895792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 21122456 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 20663816 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 17561432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 17156968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 16981976 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 12334200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2016-01-17 23:16 - 2015-12-16 18:34 - 03168376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 02755704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 01915696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436143.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 01564976 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436143.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00938104 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00872056 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00734512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00681592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00502080 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00469144 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00423264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00416376 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00388560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00370808 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00205456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2016-01-17 23:16 - 2015-12-16 18:34 - 00175368 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00153392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00151184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00069416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2016-01-17 23:16 - 2015-12-16 18:34 - 00050472 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2016-01-17 23:16 - 2015-12-16 18:34 - 00039240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2016-01-17 23:12 - 2016-01-17 23:13 - 336974040 _____ (NVIDIA Corporation) C:\Users\Basti\Downloads\361.43-desktop-win8-win7-winvista-64bit-international-whql.exe 2016-01-17 23:07 - 2016-01-17 23:07 - 00003146 _____ C:\Windows\System32\Tasks\{2D1288DA-1D43-479F-8B4B-36F07394063D} 2016-01-17 23:03 - 2016-01-17 23:04 - 00584288 _____ (Oracle Corporation) C:\Users\Basti\Downloads\jxpiinstall(2).exe 2016-01-14 23:46 - 2016-01-14 23:53 - 38572508 _____ C:\Users\Basti\Desktop\intro.avi 2016-01-14 23:29 - 2016-01-14 23:34 - 00576953 _____ C:\Users\Basti\Downloads\56981f3794d73.mp4 2016-01-14 21:23 - 2016-01-21 13:12 - 00000882 _____ C:\Users\Basti\Desktop\iFree Skype Recorder.lnk 2016-01-14 21:23 - 2016-01-14 21:41 - 00000000 ____D C:\Users\Basti\Documents\iFree Skype Recorder 2016-01-14 21:23 - 2016-01-14 21:24 - 00000000 ____D C:\Users\Basti\AppData\Roaming\iFree 2016-01-14 21:23 - 2016-01-14 21:23 - 01058568 _____ C:\Users\Basti\Downloads\iFreeRecorder.exe 2016-01-14 21:23 - 2016-01-14 21:23 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iFree Skype Recorder 2016-01-14 21:23 - 2016-01-14 21:23 - 00000000 ____D C:\Program Files (x86)\iFree Skype Recorder 2016-01-13 17:26 - 2016-01-13 17:26 - 01504376 _____ (Skype Technologies S.A.) C:\Users\Basti\Downloads\SkypeSetup.exe 2016-01-13 16:55 - 2016-01-13 16:55 - 00584288 _____ (Oracle Corporation) C:\Users\Basti\Downloads\chromeinstall-8u66 (1).exe 2016-01-13 16:49 - 2015-11-01 15:59 - 00110176 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-64.dll 2016-01-13 16:49 - 2015-11-01 15:52 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2016-01-13 16:47 - 2016-01-13 16:47 - 00584288 _____ (Oracle Corporation) C:\Users\Basti\Downloads\chromeinstall-8u66.exe 2016-01-13 10:19 - 2015-12-12 19:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-01-13 10:19 - 2015-12-12 19:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2016-01-13 10:19 - 2015-12-12 19:02 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2016-01-13 10:19 - 2015-12-12 18:37 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2016-01-13 10:19 - 2015-12-12 18:36 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2016-01-13 10:19 - 2015-12-12 18:30 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2016-01-13 10:19 - 2015-12-12 18:10 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2016-01-13 10:19 - 2015-12-11 19:57 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2016-01-13 10:19 - 2015-12-08 22:54 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2016-01-13 10:19 - 2015-12-08 22:54 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 01568768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 01325056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00902144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll 2016-01-13 10:19 - 2015-12-08 22:54 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL 2016-01-13 10:19 - 2015-12-08 22:54 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00970240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00509952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax 2016-01-13 10:19 - 2015-12-08 22:53 - 00153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL 2016-01-13 10:19 - 2015-12-08 22:53 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll 2016-01-13 10:19 - 2015-12-08 22:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2016-01-13 10:19 - 2015-12-08 22:53 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2016-01-13 10:19 - 2015-12-08 22:53 - 00004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksuser.dll 2016-01-13 10:19 - 2015-12-08 22:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 01955328 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 01575424 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 01573888 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 01232896 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 01153024 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 01026048 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 01010688 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00978944 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00666112 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00624640 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00292352 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00224768 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL 2016-01-13 10:19 - 2015-12-08 20:07 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll 2016-01-13 10:19 - 2015-12-08 20:07 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2016-01-13 10:19 - 2015-12-08 20:07 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\ksuser.dll 2016-01-13 10:19 - 2015-12-08 20:06 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax 2016-01-13 10:19 - 2015-12-08 20:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2016-01-13 10:19 - 2015-12-08 20:04 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2016-01-13 10:19 - 2015-12-08 19:54 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2016-01-13 10:19 - 2015-12-08 19:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2016-01-13 10:19 - 2015-12-08 19:11 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys 2016-01-13 10:19 - 2015-12-08 18:58 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-01-13 10:19 - 2015-11-17 02:11 - 00025024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2016-01-13 10:19 - 2015-11-17 02:08 - 01381376 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2016-01-13 10:19 - 2015-11-17 02:08 - 00792064 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2016-01-13 10:19 - 2015-11-17 02:08 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2016-01-13 10:19 - 2015-11-17 02:08 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2016-01-13 10:19 - 2015-11-17 02:08 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2016-01-13 10:19 - 2015-11-16 21:17 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2016-01-13 10:19 - 2015-11-14 00:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll 2016-01-13 10:19 - 2015-11-14 00:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll 2016-01-13 10:19 - 2015-11-14 00:08 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe 2016-01-13 10:19 - 2015-11-13 23:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll 2016-01-13 10:19 - 2015-11-13 23:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll 2016-01-13 10:19 - 2015-11-13 23:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fixmapi.exe 2016-01-13 10:18 - 2015-12-30 20:08 - 05572544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-01-13 10:18 - 2015-12-30 20:08 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-01-13 10:18 - 2015-12-30 20:08 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-01-13 10:18 - 2015-12-30 20:05 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-01-13 10:18 - 2015-12-30 20:02 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2016-01-13 10:18 - 2015-12-30 20:02 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2016-01-13 10:18 - 2015-12-30 20:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2016-01-13 10:18 - 2015-12-30 20:02 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-01-13 10:18 - 2015-12-30 20:02 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-01-13 10:18 - 2015-12-30 20:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-01-13 10:18 - 2015-12-30 20:01 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-01-13 10:18 - 2015-12-30 20:00 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2016-01-13 10:18 - 2015-12-30 19:59 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-01-13 10:18 - 2015-12-30 19:59 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-01-13 10:18 - 2015-12-30 19:59 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-01-13 10:18 - 2015-12-30 19:58 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-01-13 10:18 - 2015-12-30 19:58 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-01-13 10:18 - 2015-12-30 19:57 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2016-01-13 10:18 - 2015-12-30 19:57 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-01-13 10:18 - 2015-12-30 19:57 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-01-13 10:18 - 2015-12-30 19:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-01-13 10:18 - 2015-12-30 19:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2016-01-13 10:18 - 2015-12-30 19:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:47 - 03993536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2016-01-13 10:18 - 2015-12-30 19:47 - 03938240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2016-01-13 10:18 - 2015-12-30 19:44 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2016-01-13 10:18 - 2015-12-30 19:41 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2016-01-13 10:18 - 2015-12-30 19:40 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-01-13 10:18 - 2015-12-30 19:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2016-01-13 10:18 - 2015-12-30 19:39 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-01-13 10:18 - 2015-12-30 19:39 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-01-13 10:18 - 2015-12-30 19:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2016-01-13 10:18 - 2015-12-30 19:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2016-01-13 10:18 - 2015-12-30 19:38 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-01-13 10:18 - 2015-12-30 19:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 19:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 18:57 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-01-13 10:18 - 2015-12-30 18:50 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2016-01-13 10:18 - 2015-12-30 18:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2016-01-13 10:18 - 2015-12-30 18:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2016-01-13 10:18 - 2015-12-30 18:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-01-13 10:18 - 2015-12-30 18:42 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-01-13 10:18 - 2015-12-30 18:42 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-01-13 10:18 - 2015-12-30 18:41 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-01-13 10:18 - 2015-12-30 18:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-01-13 10:18 - 2015-12-30 18:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2016-01-13 10:18 - 2015-12-30 18:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2016-01-13 10:18 - 2015-12-30 18:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2016-01-13 10:18 - 2015-12-30 18:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2016-01-13 10:18 - 2015-12-30 18:30 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2016-01-13 10:18 - 2015-12-30 18:30 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 18:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 18:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-01-13 10:18 - 2015-12-30 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-01-13 10:18 - 2015-12-24 00:13 - 00387784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2016-01-13 10:18 - 2015-12-23 23:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2016-01-13 10:18 - 2015-12-12 19:54 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-01-13 10:18 - 2015-12-12 19:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2016-01-13 10:18 - 2015-12-12 19:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2016-01-13 10:18 - 2015-12-12 19:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2016-01-13 10:18 - 2015-12-12 19:15 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2016-01-13 10:18 - 2015-12-12 19:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2016-01-13 10:18 - 2015-12-12 19:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2016-01-13 10:18 - 2015-12-12 19:07 - 06051328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2016-01-13 10:18 - 2015-12-12 19:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2016-01-13 10:18 - 2015-12-12 19:07 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2016-01-13 10:18 - 2015-12-12 19:03 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2016-01-13 10:18 - 2015-12-12 19:02 - 20367360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-01-13 10:18 - 2015-12-12 19:02 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2016-01-13 10:18 - 2015-12-12 19:02 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2016-01-13 10:18 - 2015-12-12 19:02 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2016-01-13 10:18 - 2015-12-12 18:55 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2016-01-13 10:18 - 2015-12-12 18:51 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2016-01-13 10:18 - 2015-12-12 18:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2016-01-13 10:18 - 2015-12-12 18:44 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2016-01-13 10:18 - 2015-12-12 18:40 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2016-01-13 10:18 - 2015-12-12 18:39 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2016-01-13 10:18 - 2015-12-12 18:37 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2016-01-13 10:18 - 2015-12-12 18:37 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2016-01-13 10:18 - 2015-12-12 18:37 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2016-01-13 10:18 - 2015-12-12 18:36 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2016-01-13 10:18 - 2015-12-12 18:35 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2016-01-13 10:18 - 2015-12-12 18:33 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-01-13 10:18 - 2015-12-12 18:31 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2016-01-13 10:18 - 2015-12-12 18:28 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2016-01-13 10:18 - 2015-12-12 18:27 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2016-01-13 10:18 - 2015-12-12 18:27 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2016-01-13 10:18 - 2015-12-12 18:27 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2016-01-13 10:18 - 2015-12-12 18:25 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2016-01-13 10:18 - 2015-12-12 18:23 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2016-01-13 10:18 - 2015-12-12 18:22 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2016-01-13 10:18 - 2015-12-12 18:21 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2016-01-13 10:18 - 2015-12-12 18:20 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2016-01-13 10:18 - 2015-12-12 18:19 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2016-01-13 10:18 - 2015-12-12 18:18 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-01-13 10:18 - 2015-12-12 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2016-01-13 10:18 - 2015-12-12 18:12 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2016-01-13 10:18 - 2015-12-12 18:10 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2016-01-13 10:18 - 2015-12-12 18:09 - 04610560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2016-01-13 10:18 - 2015-12-12 18:08 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2016-01-13 10:18 - 2015-12-12 18:06 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2016-01-13 10:18 - 2015-12-12 18:02 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2016-01-13 10:18 - 2015-12-12 18:00 - 12856320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-01-13 10:18 - 2015-12-12 18:00 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2016-01-13 10:18 - 2015-12-12 18:00 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2016-01-13 10:18 - 2015-12-12 18:00 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2016-01-13 10:18 - 2015-12-12 17:54 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2016-01-13 10:18 - 2015-12-12 17:42 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2016-01-13 10:18 - 2015-12-12 17:41 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2016-01-13 10:18 - 2015-12-12 17:38 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2016-01-13 10:18 - 2015-12-12 17:36 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2016-01-13 10:18 - 2015-12-08 22:53 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2016-01-13 10:18 - 2015-12-08 22:52 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2016-01-13 10:18 - 2015-12-08 20:07 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2016-01-13 10:18 - 2015-12-08 20:07 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2016-01-12 22:35 - 2016-01-12 22:35 - 00000000 ____D C:\Users\Basti\AppData\Local\bdch 2016-01-12 22:35 - 2016-01-12 22:35 - 00000000 ____D C:\ProgramData\bdch 2016-01-12 22:23 - 2016-01-12 22:28 - 00000000 ____D C:\Users\Basti\Wichtig 2016-01-12 21:43 - 2016-01-12 21:43 - 00000684 ____H C:\bdr-cf01 2016-01-12 21:42 - 2016-01-12 21:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2016 2016-01-12 21:41 - 2016-01-12 21:43 - 00253404 ____H C:\bdr-ld01 2016-01-12 21:41 - 2016-01-12 21:43 - 00009216 ____H C:\bdr-ld01.mbr 2016-01-12 21:41 - 2015-10-22 14:02 - 00271808 _____ (Bitdefender) C:\Windows\system32\Drivers\ignis.sys 2016-01-12 21:41 - 2015-07-15 16:13 - 49737193 ____H C:\bdr-im01.gz 2016-01-12 21:41 - 2013-08-13 12:38 - 03271472 ____H C:\bdr-bz01 2016-01-12 21:40 - 2015-06-02 14:21 - 00477272 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys 2016-01-12 21:40 - 2015-04-29 13:32 - 00160032 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys 2016-01-12 21:37 - 2016-01-12 21:37 - 09736920 _____ C:\Users\Basti\Downloads\bitdefender_windows_2268285f-b17f-4c1f-972a-438e9cf16488.exe 2016-01-12 21:27 - 2016-01-12 21:27 - 09736920 _____ C:\Users\Basti\Downloads\bitdefender_windows_752fc001-db4f-4d5a-b26f-50072841116e.exe 2016-01-12 21:24 - 2016-01-12 21:24 - 00003414 _____ C:\Windows\System32\Tasks\Bitdefender Restart ProductCfg_F5C977342AD24B62922B89BDC5ABCCD2 2016-01-10 21:28 - 2016-01-21 13:14 - 00002020 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evolve.lnk 2016-01-10 21:28 - 2016-01-21 13:14 - 00002014 _____ C:\Users\Public\Desktop\Evolve.lnk 2016-01-10 21:28 - 2016-01-10 21:28 - 00021656 _____ (Echobit, LLC) C:\Windows\system32\Drivers\evolve.sys 2016-01-10 21:28 - 2016-01-10 21:28 - 00000000 ____D C:\Program Files\Echobit 2016-01-10 21:27 - 2016-01-10 21:27 - 03258328 _____ (Echobit LLC) C:\Users\Basti\Downloads\EvolveSetup.exe 2016-01-10 21:27 - 2016-01-10 21:27 - 00003140 _____ C:\Windows\System32\Tasks\{4FE8E9A0-83ED-441A-8CB2-539F94CDF074} 2016-01-10 21:27 - 2016-01-10 21:27 - 00000000 ____D C:\Users\Basti\AppData\Local\Echobit 2016-01-10 21:27 - 2016-01-10 21:27 - 00000000 ____D C:\ProgramData\Echobit 2016-01-10 13:57 - 2016-01-10 13:57 - 00000000 ____D C:\Program Files\Common Files\INCA Shared 2016-01-10 13:57 - 2015-10-13 14:32 - 03806032 _____ (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des 2016-01-10 13:57 - 2005-01-03 07:43 - 00004682 _____ (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\npptNT2.sys 2016-01-10 13:57 - 2003-07-18 22:17 - 00005174 _____ C:\Windows\SysWOW64\nppt9x.vxd 2016-01-10 12:28 - 2016-01-21 14:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCSOFT 2016-01-10 12:28 - 2016-01-21 14:34 - 00000000 ____D C:\Program Files (x86)\NCSOFT 2016-01-10 12:27 - 2016-01-21 14:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCWest 2016-01-10 12:27 - 2016-01-21 14:33 - 00000000 ____D C:\Program Files (x86)\NCWest 2016-01-10 12:26 - 2016-01-10 12:26 - 00003534 _____ C:\Users\Basti\Documents\cc_20160110_122618.reg 2016-01-10 12:26 - 2016-01-10 12:26 - 00000372 _____ C:\Users\Basti\Documents\cc_20160110_122633.reg 2016-01-10 12:25 - 2016-01-10 12:25 - 00254422 _____ C:\Users\Basti\Documents\cc_20160110_122546.reg 2016-01-10 12:03 - 2016-01-10 12:03 - 224976152 _____ (NC Interactive, LLC ) C:\Users\Basti\Downloads\BnS_Lite_Installer.exe 2016-01-09 03:35 - 2016-01-10 14:02 - 00000000 ____D C:\Users\Basti\Documents\BnS 2016-01-08 20:16 - 2016-01-08 20:16 - 00000000 ____D C:\Users\Basti\AppData\Local\BNSUpdater 2016-01-08 18:54 - 2016-01-08 18:54 - 00000000 ____D C:\Users\Basti\Downloads\BnS 2016-01-08 18:47 - 2016-01-08 18:47 - 00024161 _____ C:\Users\Basti\Downloads\playbns_client_2.torrent 2016-01-04 23:40 - 2016-01-04 23:40 - 00028578 _____ C:\Users\Basti\Downloads\malloc.exe 2016-01-04 23:40 - 2016-01-04 23:40 - 00001740 _____ C:\Users\Basti\Downloads\malloc.o 2016-01-04 23:39 - 2016-01-04 23:39 - 00002827 _____ C:\Users\Basti\Downloads\malloc.c 2016-01-04 22:15 - 2016-01-04 22:15 - 00000747 _____ C:\Users\Basti\Desktop\aufgabe5.c 2016-01-04 11:09 - 2016-01-04 11:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2016-01-04 00:00 - 2016-01-21 13:13 - 00000968 _____ C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\MinGW Installation Manager.lnk 2016-01-04 00:00 - 2016-01-04 00:16 - 00000000 ____D C:\MinGW 2016-01-03 23:59 - 2016-01-03 23:59 - 00086528 _____ (MinGW.org Project) C:\Users\Basti\Downloads\mingw-get-setup.exe 2016-01-03 23:52 - 2016-01-03 23:52 - 122655932 _____ C:\Users\Basti\Downloads\gcc-5.2.0.tar.gz 2016-01-03 12:00 - 2016-01-13 17:50 - 00000000 ____D C:\Users\Basti\AppData\Roaming\CodeBlocks 2016-01-03 11:59 - 2016-01-21 13:12 - 00001104 _____ C:\Users\Basti\Desktop\CodeBlocks.lnk 2016-01-03 11:59 - 2016-01-03 12:00 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CodeBlocks 2016-01-03 11:59 - 2016-01-03 12:00 - 00000000 ____D C:\Program Files (x86)\CodeBlocks 2016-01-03 11:59 - 2016-01-03 11:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeBlocks 2016-01-03 11:58 - 2016-01-03 11:59 - 102611063 _____ (The Code::Blocks Team) C:\Users\Basti\Downloads\codeblocks-13.12mingw-setup.exe 2015-12-29 00:23 - 2015-12-29 00:23 - 00038432 _____ (SoftEther Corporation) C:\Windows\system32\Drivers\Neo_0024.sys 2015-12-29 00:21 - 2016-01-21 13:14 - 00001980 _____ C:\Users\Public\Desktop\SoftEther VPN Client Manager.lnk 2015-12-29 00:21 - 2016-01-21 13:13 - 00001992 _____ C:\ProgramData\Microsoft\Windows\Start Menu\SoftEther VPN Client Manager.lnk 2015-12-29 00:21 - 2015-12-29 00:21 - 00144104 _____ (SoftEther VPN Project at University of Tsukuba, Japan.) C:\Windows\system32\vpncmd.exe 2015-12-29 00:21 - 2015-12-29 00:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftEther VPN Client 2015-12-29 00:20 - 2016-01-22 17:09 - 00000000 ____D C:\Program Files\SoftEther VPN Client 2015-12-29 00:19 - 2015-12-29 00:19 - 00000000 ____D C:\Users\Basti\Downloads\vpngate-client-2015.12.29-build-9599.134383 2015-12-29 00:17 - 2015-12-29 00:19 - 54298926 _____ C:\Users\Basti\Downloads\vpngate-client-2015.12.29-build-9599.134383.zip 2015-12-28 23:35 - 2015-12-29 00:57 - 00000000 ____D C:\Users\Basti\Documents\Black Desert 2015-12-28 23:30 - 2015-12-28 23:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Black Desert RU Patcher 2015-12-28 23:16 - 2015-12-28 23:16 - 00000000 __SHD C:\ProgramData\Info 2015-12-28 21:32 - 2016-01-22 17:09 - 00000000 ____D C:\Users\Basti\AppData\Local\THORN 2015-12-28 21:31 - 2016-01-08 15:56 - 00004296 _____ C:\Windows\System32\Tasks\GameNet 2015-12-28 21:31 - 2015-12-28 21:31 - 00000000 ____D C:\Users\Basti\AppData\Local\Vebanaul 2015-12-28 21:24 - 2015-12-28 21:24 - 04363099 _____ C:\Users\Basti\Downloads\setup.exe ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-01-22 17:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows 2016-01-22 17:19 - 2009-07-14 05:45 - 00032080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-01-22 17:19 - 2009-07-14 05:45 - 00032080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-01-22 17:16 - 2012-05-26 17:00 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Skype 2016-01-22 17:15 - 2015-04-17 22:24 - 00000546 ____H C:\Windows\Tasks\MATLAB R2015a Startup Accelerator.job 2016-01-22 17:15 - 2012-05-26 17:22 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-01-22 17:09 - 2015-12-13 01:57 - 00000000 ____D C:\Program Files\Bitdefender Agent 2016-01-22 17:09 - 2012-06-06 20:18 - 00000000 ____D C:\Users\Basti\AppData\Local\LogMeIn Hamachi 2016-01-22 17:08 - 2015-07-15 14:58 - 00000000 _____ C:\hsrv.txt 2016-01-22 17:08 - 2012-05-26 17:22 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-01-22 17:08 - 2012-05-25 15:06 - 00000000 ____D C:\ProgramData\NVIDIA 2016-01-22 17:08 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-01-22 17:05 - 2012-05-27 00:38 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-01-22 13:38 - 2012-12-09 22:22 - 00000000 ____D C:\Program Files (x86)\Ubisoft 2016-01-22 13:36 - 2012-05-25 15:05 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-01-22 13:36 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2016-01-22 13:07 - 2012-05-26 17:23 - 00000000 ____D C:\Users\Basti\AppData\Local\Adobe 2016-01-22 01:09 - 2012-05-27 12:25 - 00000000 ____D C:\Users\Basti\Documents\Outlook-Dateien 2016-01-21 15:28 - 2013-11-03 23:54 - 02324992 ___SH C:\Users\Basti\Desktop\Thumbs.db 2016-01-21 13:29 - 2015-11-27 18:06 - 00002353 _____ C:\Users\Basti\Desktop\Chrome App Launcher.lnk 2016-01-21 13:14 - 2015-12-13 02:12 - 00002129 _____ C:\Users\Public\Desktop\Bitdefender 2016.lnk 2016-01-21 13:14 - 2015-11-21 11:45 - 00001106 _____ C:\Users\Public\Desktop\LECTURNITY Player.lnk 2016-01-21 13:14 - 2015-11-02 11:42 - 00001160 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-01-21 13:14 - 2015-11-02 11:42 - 00001154 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-01-21 13:14 - 2015-09-27 14:20 - 00002178 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-01-21 13:14 - 2015-08-12 00:30 - 00002373 _____ C:\Users\Public\Desktop\TI-Nspire CX CAS Student Software.lnk 2016-01-21 13:14 - 2015-08-11 23:58 - 00002333 _____ C:\Users\Public\Desktop\TI-Nspire CAS Student Software.lnk 2016-01-21 13:14 - 2015-07-15 14:58 - 00000998 _____ C:\Users\Public\Desktop\Droid4X.lnk 2016-01-21 13:14 - 2015-07-14 23:38 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-01-21 13:14 - 2015-07-14 23:38 - 00002050 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2016-01-21 13:14 - 2015-06-20 11:50 - 00001094 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Content Viewer.lnk 2016-01-21 13:14 - 2015-06-06 15:54 - 00001202 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk 2016-01-21 13:14 - 2015-05-28 15:57 - 00001062 _____ C:\Users\Public\Desktop\GOG Galaxy.lnk 2016-01-21 13:14 - 2015-04-17 22:27 - 00001296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB R2015a.lnk 2016-01-21 13:14 - 2015-04-17 22:27 - 00001290 _____ C:\Users\Public\Desktop\MATLAB R2015a.lnk 2016-01-21 13:14 - 2015-02-21 13:07 - 00001166 _____ C:\Users\Public\Desktop\Dell Display Manager.lnk 2016-01-21 13:14 - 2015-01-23 17:18 - 00002029 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk 2016-01-21 13:14 - 2014-10-13 18:21 - 00000937 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk 2016-01-21 13:14 - 2014-10-09 14:36 - 00001243 _____ C:\Users\Public\Desktop\Battlefield 4.lnk 2016-01-21 13:14 - 2014-10-09 14:36 - 00001228 _____ C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk 2016-01-21 13:14 - 2014-07-02 22:48 - 00001998 _____ C:\Users\Public\Desktop\HP Photo Creations.lnk 2016-01-21 13:14 - 2014-07-02 22:43 - 00000960 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR-Registrierung.lnk 2016-01-21 13:14 - 2014-07-02 22:42 - 00002113 _____ C:\Users\Public\Desktop\HP Officejet 6700.lnk 2016-01-21 13:14 - 2013-11-20 21:36 - 00000918 _____ C:\Users\Public\Desktop\VLC media player.lnk 2016-01-21 13:14 - 2012-12-01 16:29 - 00002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk 2016-01-21 13:14 - 2012-12-01 16:29 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk 2016-01-21 13:14 - 2012-12-01 16:27 - 00001094 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk 2016-01-21 13:14 - 2012-12-01 16:24 - 00000994 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk 2016-01-21 13:14 - 2012-11-24 13:29 - 00000869 _____ C:\Users\Public\Desktop\CCleaner.lnk 2016-01-21 13:14 - 2012-11-20 16:01 - 00001878 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk 2016-01-21 13:14 - 2012-08-18 15:28 - 00002002 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk 2016-01-21 13:14 - 2012-08-18 15:28 - 00001946 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk 2016-01-21 13:14 - 2012-08-18 15:28 - 00001925 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk 2016-01-21 13:14 - 2012-07-30 11:51 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2016-01-21 13:14 - 2012-07-29 17:18 - 00001297 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inhaltsmanager-Assistent für PlayStation(R).lnk 2016-01-21 13:14 - 2012-06-26 19:04 - 00001914 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LOL Recorder.lnk 2016-01-21 13:14 - 2012-06-07 19:29 - 00001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk 2016-01-21 13:14 - 2011-06-29 12:22 - 00001455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk 2016-01-21 13:14 - 2011-06-29 12:22 - 00001371 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk 2016-01-21 13:14 - 2011-06-29 12:22 - 00001302 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk 2016-01-21 13:14 - 2011-06-29 12:21 - 00002483 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk 2016-01-21 13:14 - 2011-04-27 12:03 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2016-01-21 13:14 - 2011-04-27 12:03 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2016-01-21 13:14 - 2009-07-14 05:57 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-01-21 13:14 - 2009-07-14 05:57 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk 2016-01-21 13:14 - 2009-07-14 05:57 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk 2016-01-21 13:14 - 2009-07-14 05:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk 2016-01-21 13:14 - 2009-07-14 05:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk 2016-01-21 13:13 - 2013-12-14 11:41 - 00001804 _____ C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk 2016-01-21 13:13 - 2012-05-27 11:24 - 00001366 _____ C:\ProgramData\Microsoft\Windows\Start Menu\HP Solution Center.lnk 2016-01-21 13:13 - 2012-05-26 16:56 - 00001434 _____ C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-01-21 13:13 - 2009-07-14 06:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk 2016-01-21 13:13 - 2009-07-14 05:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk 2016-01-21 13:12 - 2015-11-01 15:43 - 00002137 _____ C:\Users\Basti\Desktop\Minecraft.lnk 2016-01-21 13:12 - 2015-09-30 16:40 - 00002029 _____ C:\Users\Basti\Desktop\My.com Game Center.lnk 2016-01-21 13:12 - 2015-08-25 21:01 - 00000833 _____ C:\Users\Basti\Desktop\lol.launcher.admin - Verknüpfung.lnk 2016-01-21 13:12 - 2015-06-17 14:20 - 00001085 _____ C:\Users\Basti\Desktop\Oracle VM VirtualBox.lnk 2016-01-21 13:12 - 2015-06-04 13:52 - 00001964 _____ C:\Users\Basti\Desktop\The Witcher® 3 - Wild Hunt.lnk 2016-01-21 13:12 - 2015-06-01 12:56 - 00001020 _____ C:\Users\Basti\Desktop\Fidelify.lnk 2016-01-21 13:12 - 2015-03-19 11:59 - 00001818 _____ C:\Users\Basti\Desktop\Spotify.lnk 2016-01-21 13:12 - 2014-05-24 11:30 - 00001886 _____ C:\Users\Basti\Desktop\CivilizationV_DX11.exe.lnk 2016-01-21 13:12 - 2014-05-17 11:27 - 00002118 _____ C:\Users\Basti\Desktop\JDownloader 2.lnk 2016-01-21 13:12 - 2012-06-21 20:47 - 00001087 _____ C:\Users\Basti\Desktop\Basti.lnk 2016-01-21 13:12 - 2012-05-27 11:05 - 00000355 _____ C:\Users\Basti\Desktop\Computer.lnk 2016-01-21 13:09 - 2010-11-21 08:00 - 00000000 ____D C:\Windows\ShellNew 2016-01-21 13:07 - 2012-06-06 19:59 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2016-01-20 10:05 - 2012-05-27 00:38 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-01-20 10:05 - 2012-05-27 00:38 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-01-20 10:05 - 2012-05-27 00:38 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-01-18 10:31 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2016-01-18 09:51 - 2015-08-02 16:20 - 00000000 ____D C:\Users\Basti\Desktop\Trainer 2016-01-18 00:53 - 2012-08-18 14:08 - 00007599 _____ C:\Users\Basti\AppData\Local\Resmon.ResmonCfg 2016-01-17 23:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2016-01-17 23:26 - 2012-09-11 20:18 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-01-17 23:23 - 2012-05-25 15:05 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-01-17 23:19 - 2012-05-25 15:05 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-01-17 23:08 - 2015-11-01 15:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit 2016-01-17 23:08 - 2015-01-31 18:37 - 00000000 ____D C:\Program Files (x86)\Java 2016-01-17 23:08 - 2013-10-07 22:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-01-17 23:07 - 2013-10-07 22:47 - 00000000 ____D C:\ProgramData\Oracle 2016-01-17 01:03 - 2013-12-14 11:41 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Spotify 2016-01-16 11:33 - 2013-12-14 11:41 - 00000000 ____D C:\Users\Basti\AppData\Local\Spotify 2016-01-14 23:53 - 2013-11-20 21:36 - 00000000 ____D C:\Users\Basti\AppData\Roaming\vlc 2016-01-14 12:39 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2016-01-14 10:57 - 2010-11-21 07:50 - 00737796 _____ C:\Windows\system32\perfh007.dat 2016-01-14 10:57 - 2010-11-21 07:50 - 00159894 _____ C:\Windows\system32\perfc007.dat 2016-01-14 10:57 - 2009-07-14 06:13 - 01710742 _____ C:\Windows\system32\PerfStringBackup.INI 2016-01-14 10:50 - 2009-07-14 05:45 - 05101656 _____ C:\Windows\system32\FNTCACHE.DAT 2016-01-14 10:46 - 2014-12-11 12:06 - 00000000 ____D C:\Windows\system32\appraiser 2016-01-14 10:46 - 2014-05-01 02:01 - 00000000 ___SD C:\Windows\system32\CompatTel 2016-01-14 10:42 - 2013-03-13 23:18 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2016-01-14 10:42 - 2013-03-13 23:18 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2016-01-14 02:32 - 2013-03-13 23:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2016-01-14 02:32 - 2012-05-27 11:15 - 00000000 ____D C:\ProgramData\Microsoft Help 2016-01-14 02:29 - 2013-07-21 22:37 - 00000000 ____D C:\Windows\system32\MRT 2016-01-14 02:05 - 2011-04-27 12:44 - 143671360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-01-14 01:58 - 2009-07-14 03:34 - 00000513 _____ C:\Windows\win.ini 2016-01-13 17:34 - 2012-06-09 15:23 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-01-13 17:34 - 2012-06-09 15:23 - 00000000 ____D C:\ProgramData\Skype 2016-01-13 16:50 - 2015-11-01 15:52 - 00000000 ____D C:\Users\Basti\.oracle_jre_usage 2016-01-12 22:23 - 2012-05-26 16:53 - 00000000 ____D C:\Users\Basti 2016-01-12 22:20 - 2015-12-13 02:08 - 00000000 ____D C:\ProgramData\Bitdefender 2016-01-12 22:10 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Offline Web Pages 2016-01-12 22:05 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Downloaded Program Files 2016-01-12 21:49 - 2015-09-30 16:38 - 00000000 ____D C:\Users\Basti\AppData\Local\MyComGames 2016-01-12 21:42 - 2015-12-13 02:11 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Bitdefender 2016-01-12 21:40 - 2015-12-13 02:07 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2016-01-12 15:22 - 2015-04-17 23:21 - 00000000 ____D C:\Users\Basti\Documents\MATLAB 2016-01-10 12:21 - 2012-11-24 14:09 - 00000000 ____D C:\Program Files (x86)\Steam 2016-01-10 12:21 - 2012-06-07 15:43 - 00000000 ____D C:\Users\Basti\AppData\Roaming\TS3Client 2016-01-10 12:20 - 2012-09-10 17:02 - 00000000 ____D C:\Windows\Minidump 2016-01-08 19:16 - 2013-02-02 19:00 - 00000000 ____D C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2016-01-04 11:09 - 2014-03-29 12:34 - 00000000 ____D C:\Users\Basti\AppData\Local\Skype 2016-01-04 02:53 - 2014-02-10 17:04 - 00000000 ____D C:\Users\Basti\AppData\Local\Battle.net 2016-01-04 00:56 - 2015-06-06 15:50 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm 2016-01-04 00:23 - 2013-10-17 14:45 - 00000000 ____D C:\Users\Basti\Uni 2016-01-03 14:04 - 2015-12-15 14:33 - 00000000 ____D C:\Users\Basti\Desktop\test 2015-12-30 11:58 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2015-12-28 22:49 - 2015-07-16 00:46 - 00000095 _____ C:\Users\Basti\Desktop\codes.txt 2015-12-24 13:21 - 2014-02-10 17:04 - 00000000 ____D C:\Program Files (x86)\Battle.net 2015-12-23 15:32 - 2015-05-28 21:19 - 00000000 ____D C:\Users\Basti\Documents\The Witcher 3 ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2012-09-29 16:29 - 2013-02-12 19:50 - 0000064 _____ () C:\Program Files\MC.bat 2012-06-06 20:13 - 2012-05-11 18:11 - 0139783 _____ () C:\Program Files\MinecraftSP.jar 2012-11-08 05:39 - 2012-11-08 05:39 - 120115048 _____ () C:\Program Files (x86)\avira_antivirus_premium_en.exe 2012-07-14 15:28 - 2015-11-02 21:05 - 376347915 _____ () C:\Users\Basti\AppData\Roaming\.minecraft.rar 2013-02-07 19:16 - 2015-08-31 22:51 - 0000132 _____ () C:\Users\Basti\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen 2015-07-15 14:57 - 2015-07-15 15:00 - 0002380 _____ () C:\Users\Basti\AppData\Roaming\droid4xinstaller.log 2012-08-18 14:08 - 2016-01-18 00:53 - 0007599 _____ () C:\Users\Basti\AppData\Local\Resmon.ResmonCfg 2014-07-02 22:42 - 2014-07-02 22:42 - 0000057 _____ () C:\ProgramData\Ament.ini 2012-07-02 20:16 - 2012-07-02 20:16 - 0000252 _____ () C:\ProgramData\FastPics.log 2012-05-27 11:11 - 2012-06-10 15:42 - 0005000 _____ () C:\ProgramData\hpzinstall.log 2012-07-02 20:16 - 2013-03-01 18:36 - 0025200 _____ () C:\ProgramData\lxdw.log 2012-07-02 20:19 - 2012-07-02 20:24 - 0000537 _____ () C:\ProgramData\lxdwDiagnostics.log Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\Users\Basti\hamachi-2-ui.exe C:\Users\Basti\save.reg Einige Dateien in TEMP: ==================== C:\Users\Basti\AppData\Local\Temp\sqlite3.dll C:\Users\Basti\AppData\Local\Temp\Uninstall.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-01-19 09:35 ==================== Ende von FRST.txt =========================== |
22.01.2016, 17:49 | #11 |
| Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam Addition Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-01-2016 durchgeführt von Basti (2016-01-22 17:31:55) Gestartet von C:\Users\Basti\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2012-05-26 15:53:52) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1745305398-2489788369-3521438674-500 - Administrator - Disabled) Basti (S-1-5-21-1745305398-2489788369-3521438674-1002 - Administrator - Enabled) => C:\Users\Basti Gast (S-1-5-21-1745305398-2489788369-3521438674-501 - Limited - Enabled) Zocken (S-1-5-21-1745305398-2489788369-3521438674-1005 - Limited - Enabled) => C:\Users\Zocken ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Bitdefender Antivirus (Enabled - Out of date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D} AS: Bitdefender Spyware-Schutz (Enabled - Out of date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Bitdefender Firewall (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated) Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.14 - Adobe Systems) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated) Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated) Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.3 - Adobe Systems Incorporated) Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.286 - Adobe Systems Incorporated) Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.286 - Adobe Systems Incorporated) Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.) Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.) Adobe® Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 3.4.3 - Adobe Systems, Incorporated) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) AppNHost 1.0.5.1 (HKLM-x32\...\{A8CB86C7-CD4C-4C4F-AF6A-33D1CAC63562}) (Version: 1.0.5.1 - Mixesoft Project) Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.5510 - Perfect World Entertainment) Audible Download Manager (HKLM-x32\...\AudibleDownloadManager) (Version: 6.6.0.15 - Audible, Inc.) avira_antivirus_premium_en 1.00 (HKLM-x32\...\avira_antivirus_premium_en 1.00) (Version: 1.00 - Avira) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.5.2.34169 - Electronic Arts) Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation) Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 20.0.23.1252 - Bitdefender) Bitdefender Total Security 2016 (HKLM\...\Bitdefender) (Version: 20.0.23.1252 - Bitdefender) bl (x32 Version: 1.0.0 - Your Company Name) Hidden Black Desert RU Patcher (HKLM-x32\...\{94381DF9-7266-459C-AF82-4D1458E1AFE7}) (Version: 1.00.0000 - Black Desert RU Patcher) Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.60.197 - NC Interactive, LLC) Blade & Soul (x32 Version: 1.0.60.197 - NC Interactive, LLC) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) BufferChm (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden C4600 (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.24 - Piriform) CD- und DVD-Sharing (HKLM-x32\...\{514FBEC8-E8CE-4F6F-A17F-2789E8DE8D69}) (Version: 1.0.1.4 - Apple Inc.) Cheat Engine 6.2 (HKLM-x32\...\Cheat Engine 6.2_is1) (Version: - Dark Byte) Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.11004 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.11004 - Cisco Systems, Inc.) Hidden CodeBlocks (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team) Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.4.0315 - DT Soft Ltd) Dark Souls II Black Armour Edition MULTI-2 1.0 (HKLM-x32\...\Dark Souls II Black Armour Edition MULTI-2 1.0) (Version: - ) Dassault Systemes Software B21 (HKLM\...\Dassault Systemes B21_0) (Version: - ) Dassault Systemes Software Prerequisites x86-x64 (HKLM\...\{CF1EB598-B424-436A-B15F-B763846BA970}) (Version: 8.1.3 - Dassault Systemes) Dassault Systemes Software VC9 Prerequisites x86-x64 (HKLM\...\{F2F2DEA7-36AB-4E13-907C-D8BDE775EF97}) (Version: 9.1.2 - Dassault Systemes) DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive) Dell Display Manager (HKLM-x32\...\{AC50C05D-9D57-40F5-B2EF-AC402F14312B}_is1) (Version: - EnTech Taiwan) Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden DNDownloader version 1.2 (HKLM-x32\...\DNDownloader_is1) (Version: 1.2 - ) Droid4X (HKLM-x32\...\Droid4X) (Version: 0.8.2 - Haiyu Dongxiang Co.,Ltd.) Dropbox (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Dropbox) (Version: 2.10.30 - Dropbox, Inc.) DVDFab 9.0.6.0 (21/08/2013) (HKLM-x32\...\DVDFab 9_is1) (Version: - Fengtao Software Inc.) EE-ZDE (HKLM-x32\...\{B49C924C-A651-4378-94F6-5D9BF44A959F}) (Version: - ) Empire Earth (HKLM-x32\...\{2447500B-22D7-47BD-9B13-1A927F43A267}) (Version: - ) eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden Evolve (HKLM\...\{670B1B49-9FD3-4827-9B41-471EFF580AA8}) (Version: 1.8.18 - Echobit, LLC) Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft) Fidelify (HKLM-x32\...\Fidelify) (Version: - ) Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Free YouTube to MP3 Converter version 3.11.34.1015 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.34.1015 - DVDVideoSoft Ltd.) Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.9.0 - Futuremark Corporation) Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Gameforge Live 1.0 "Legend" (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 1.1.1724 - Gameforge) GeoGebra 5 (HKLM-x32\...\GeoGebra 5) (Version: 5.0.53.0 - International GeoGebra Institute) GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.111 - Google Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden GPBaseService2 (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden GUILD WARS (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Guild Wars) (Version: - ) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP) HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP) HP Officejet 6700 - Grundlegende Software für das Gerät (HKLM\...\{9086D601-50B7-491D-A143-28193DADE36B}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Officejet 6700 Hilfe (HKLM-x32\...\{E1AE0CB7-1333-4728-8520-CB3F88A252B4}) (Version: 140.0.2.2 - Hewlett Packard) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.9572 - HP) HP Photosmart C4600 All-In-One Driver Software 14.0 Rel. 5 (HKLM\...\{1E1746EF-F5BF-4677-8F30-04FE399130DA}) (Version: 14.0 - HP) HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP) HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP) HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden hpPrintProjects (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden hpWLPGInstaller (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) iCloud (HKLM\...\{EAFB2AD8-D92B-464C-8D97-B9CB94703C4A}) (Version: 3.0.2.163 - Apple Inc.) iFree Skype Recorder 6.0.15 (HKLM-x32\...\iFree Skype Recorder) (Version: 6.0.15 - iFree Skype Recorder) ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!) Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{0DCD0704-E2AB-4e97-96A7-90F146BD8243}) (Version: 2.50.6733.38 - Sony Computer Entertainment Inc.) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.10.1464 - Intel Corporation) Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 16.6 - Intel) iTunes (HKLM\...\{A04DCB25-7040-4935-A30D-8E0A893ABF2D}) (Version: 11.1.2.32 - Apple Inc.) JAP (HKLM-x32\...\JAP) (Version: 00.18.001 - JAP-Team) Java 8 Update 65 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418065F0}) (Version: 8.0.650.17 - Oracle Corporation) Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation) Java SE Development Kit 8 Update 65 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180650}) (Version: 8.0.650.17 - Oracle Corporation) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games) LECTURNITY Player (HKLM-x32\...\{8624888C-A959-45A5-98F4-292E956325EA}) (Version: 4.5.0000 - imc AG) Logitech Gaming Software 8.53 (HKLM\...\Logitech Gaming Software) (Version: 8.53.154 - Logitech Inc.) Logitech SetPoint 6.65 (HKLM\...\sp6) (Version: 6.65.62 - Logitech) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.410 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.410 - LogMeIn, Inc.) Hidden LOLReplay (HKLM-x32\...\LOLReplay) (Version: 0.8.0.1 - www.leaguereplays.com) Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden MATLAB R2015a (HKLM\...\Matlab R2015a) (Version: 8.5 - MathWorks) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{3c3aafc8-d898-43ec-998f-965ffdae065a}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft) Minecraft1.6.2 (HKLM-x32\...\Minecraft1.6.2) (Version: - ) Mozilla Firefox 42.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) My.com Game Center (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\MyComGames) (Version: 3.146 - My.com B.V.) NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version: - NCSOFT) Need for Speed™ Most Wanted (HKLM-x32\...\{A48B9CD8-C2BA-4EC9-0081-7260D238C7CF}) (Version: - ) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.52.3 - Black Tree Gaming) NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.43 - NVIDIA Corporation) NVIDIA 3D Vision Video Player (HKLM-x32\...\{FE3B9518-9FF3-4D89-8A8D-E540C9CCAF3B}) (Version: 1.5.2 - NVIDIA Corporation) NVIDIA GeForce Experience 2.8.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.8.1.21 - NVIDIA Corporation) NVIDIA Grafiktreiber 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.43 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.3.6.4639 - Electronic Arts, Inc.) PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2-r4600) (Version: - ) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden PFConfig 1.0.296 (HKLM-x32\...\PFConfig) (Version: 1.0.296 - Portforward.com) Pflanzen gegen Zombies™ (HKLM-x32\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.) ph (x32 Version: 1.0.0 - Your Company Name) Hidden PS_AIO_05_C4600_Software_Min (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden PTC Mathcad Prime 3.0 (HKLM-x32\...\{C4AB999A-D981-4913-BA26-E4776B598E7D}) (Version: 3.0.0 - PTC) PTC Quality Agent (HKLM-x32\...\{5B7F8A19-AF71-4517-B49C-683AFC5B639C}) (Version: 2.0.0.0 - PTC) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) QuickTransfer (x32 Version: 140.0.98.000 - Hewlett-Packard) Hidden Revo Uninstaller 1.94 (HKLM-x32\...\Revo Uninstaller) (Version: 1.94 - VS Revo Group) Samsung New PC Studio (HKLM-x32\...\InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Samsung New PC Studio (x32 Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.650.0 - SAMSUNG Electronics Co., Ltd.) Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden Secure Download Manager (HKLM-x32\...\{531E35C7-B4E7-418C-A2CD-C1205D9C8AC9}) (Version: 3.1.20 - Kivuto Solutions Inc.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) SHIELD Streaming (Version: 4.1.0250 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.8.1.21 - NVIDIA Corporation) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP) Sid Meier's Civilization V (HKLM-x32\...\Sid Meier's Civilization V_is1) (Version: Sid Meier's Civilization V - ) skyforge_mycom (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\skyforge_mycom) (Version: 1.46 - My.com B.V.) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation) Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.103 - Skype Technologies S.A.) Sleeping Dogs Limited Edition (HKLM-x32\...\Sleeping Dogs™ UPDATE 1.5_is1) (Version: 1.5.0.0 - QfG) SleepTimer Ultimate 1.2 (HKLM-x32\...\{0EE56463-49B2-45E1-B74F-3E0139DBC986}_is1) (Version: - Christian Handorf) SmartWebPrinting (x32 Version: 140.0.186.000 - Hewlett-Packard) Hidden SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.19.9599 - SoftEther VPN Project) SolutionCenter (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden Space Engineers (HKLM-x32\...\Steam App 244850) (Version: - Keen Software House) Spotify (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Spotify) (Version: 1.0.20.94.g8f8543b3 - Spotify AB) Status (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.0.11.0 - GOG.com) The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\...\Free DLC program (16 DLC)_is1) (Version: 1.0.10.0 - GOG.com) TI-Nspire™ CAS Student Software (HKLM-x32\...\{F03A8756-7FCB-4DCD-9AC1-12C63A6075F1}) (Version: 3.9.0.463 - Texas Instruments Inc.) TI-Nspire™ CX CAS Student Software (HKLM-x32\...\{E994956D-8CA7-4091-BFF5-0C749470BA2E}) (Version: 4.0.0.235 - Texas Instruments Inc.) Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden Tropico 5 (HKLM-x32\...\Tropico 5_is1) (Version: - ) Unity Web Player (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\UnityWebPlayer) (Version: 5.0.3f2 - Unity Technologies ApS) Uplay (HKLM-x32\...\Uplay) (Version: 4.3 - Ubisoft) VBA (3821b) (x32 Version: 6.01.00.1234 - Microsoft Corporation) Hidden VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN) WebReg (x32 Version: 140.0.212.017 - Hewlett-Packard) Hidden Winamp (HKLM-x32\...\Winamp) (Version: 5.623 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinRAR 4.11 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH) Xilisoft iPod to PC Copy (HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\Xilisoft iPod to PC Copy) (Version: 5.4.0.20120709 - Xilisoft) XMedia Recode Version 3.1.1.6 (HKLM-x32\...\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.1.6 - XMedia Recode) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basti\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {03DA3B3E-4D58-494B-B245-DAD0A8DBDDBB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {153DADDB-4AF6-47D4-9A9D-67EC0B18A250} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-09-14] (Adobe Systems Incorporated) Task: {1B95DAB2-8C86-456F-A170-84602E3279E6} - System32\Tasks\Bitdefender Restart ProductCfg_F5C977342AD24B62922B89BDC5ABCCD2 => C:\Program Files\Bitdefender\Bitdefender 2016\ProductCfg.exe [2016-01-12] (Bitdefender) Task: {1BA04B1B-DE8A-4E45-ACDA-1A8BA907AFFA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-10-24] (Piriform Ltd) Task: {1F671263-2C93-4355-8954-D8A6E869F130} - System32\Tasks\{4B70D9A6-59CA-43A1-BDBB-B887E40A84D7} => Firefox.exe hxxp://ui.skype.com/ui/0/6.6.0.106/de/go/help.faq.installer?LastError=1618 Task: {2490A96E-2646-4481-8A6A-BBB935E89609} - System32\Tasks\{9342110C-473A-40B6-BA74-470DFD73271A} => pcalua.exe -a "C:\Program Files\NVIDIA Corporation\3D Emitter\nvUSBInst.exe" -d "C:\Program Files\NVIDIA Corporation\3D Emitter" Task: {293C18C3-B0F0-4881-947C-966DBAC8BD49} - System32\Tasks\{2D1288DA-1D43-479F-8B4B-36F07394063D} => pcalua.exe -a C:\Users\Basti\Downloads\jxpiinstall(2).exe -d C:\Users\Basti\Downloads Task: {3ACB3CBC-294D-4FA3-A2D0-3F121830A2F8} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2015-11-09] (Bitdefender) Task: {4BFE7F94-DA9B-405C-A8F1-276005CD48F2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-20] (Adobe Systems Incorporated) Task: {508DEA04-F80D-4D62-8C8D-BC6AC05F4FA3} - System32\Tasks\GameNet => C:\Program Files (x86)\QGNA\qGNA.exe Task: {531F9E18-C366-4AAA-9E20-8D05859A457C} - System32\Tasks\Installation App Launcher => C:\Program Files (x86) (x86)\Lexmark 7600 Series\ezprint.exe [2010-02-10] (Lexmark International Inc.) Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto Task: {5ED4D938-3805-450A-888D-B8DEE4C24A92} - System32\Tasks\{C9B77DE9-6A1C-4821-9150-5E9DEA822464} => pcalua.exe -a "C:\Users\Basti\Local Settings\Application Data\Bundled software uninstaller\biclient.exe" -c /initurl hxxp://bi.bisrv.com/:affid:/:sid:/:uid:? /affid uninstall /id uninstall /name "Bundled software uninstaller" Task: {6131115E-E342-4ED5-BA2E-274E03E3AD03} - System32\Tasks\MATLAB R2015a Startup Accelerator => C:\Program Files\MATLAB\R2015a\bin\win64\MATLABStartupAccelerator.exe [2014-12-29] () Task: {65774187-F822-4405-9366-4822D1B7BB56} - System32\Tasks\{4FE8E9A0-83ED-441A-8CB2-539F94CDF074} => pcalua.exe -a C:\Users\Basti\Downloads\EvolveSetup.exe -d C:\Users\Basti\Downloads Task: {6F3A25B2-F32B-4D54-90C7-DC55CE87C89F} - System32\Tasks\AdobeAAMUpdater-1.0-Basti-PC-Basti => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-05-25] (Adobe Systems Incorporated) Task: {822254E8-1508-4FDA-A2D3-1D5A491C3664} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation) Task: {8CA2239D-3265-4137-9474-7F68939B16D3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {8ECEC114-1088-4798-8437-7B8444048439} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation) Task: {A5B7212F-CF00-47BD-A6B8-6AFB1673C7FE} - System32\Tasks\{17AF4C96-0ABB-4915-ABBF-64D12E75ED44} => pcalua.exe -a H:\Adobe_Photoshop_CS5_Extended-AkamaiDLM.exe -d H:\ Task: {AD6C33B2-B2D5-4DB3-885B-F850B71E16F8} - \Dealply -> Keine Datei <==== ACHTUNG Task: {C09706A8-6289-4CBB-83AA-307E834C9348} - System32\Tasks\{F2F37F3E-65F3-4810-8851-E0B4B6BAEA81} => C:\Sierra\EE-ZDE\EE-AOC.exe [2002-08-21] () Task: {C3011503-2B45-43D6-8191-7E900C479FA0} - System32\Tasks\{D00EF0EA-619B-4134-97D6-7A640F11A328} => pcalua.exe -a "C:\Users\Basti\Downloads\FM13 Datensatz - Deutschland.exe" -d C:\Users\Basti\Downloads Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc Task: {DE3BBF04-CFC3-41EC-B711-791D41C3733B} - System32\Tasks\{7AE8198C-13CA-46CB-B46B-D22ECDC213E0} => pcalua.exe -a C:\Users\Basti\Downloads\forge-1.7.10-10.13.4.1448-1.7.10-installer-win.exe -d C:\Users\Basti\Downloads (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Dealply.job.bak => C:\Users\Basti\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ACHTUNG Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\MATLAB R2015a Startup Accelerator.job => C:\Program Files\MATLAB\R2015a\bin\win64\MATLABStartupAccelerator.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) Shortcut: C:\Users\Basti\Spiele\MC-Server_start.bat - Verknüpfung.lnk -> C:\Users\Basti\Desktop\Neuer Ordner\Server_start.bat (Keine Datei) Shortcut: C:\Users\Basti\Spiele\MC.bat - Verknüpfung.lnk -> C:\Program Files\MC.bat () Shortcut: C:\Users\Basti\Spiele\Start NFS MW Mod Loader.bat - Verknüpfung.lnk -> C:\Program Files (x86)\EA GAMES\Need for Speed Most Wanted\Start NFS MW Mod Loader.bat () ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2016-01-12 21:42 - 2013-09-03 13:29 - 00101328 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\bdmetrics.dll 2016-01-21 17:30 - 2016-01-21 17:30 - 01119064 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttpbr.mdl 2016-01-21 17:30 - 2016-01-21 17:30 - 00794832 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttpdsp.mdl 2016-01-21 17:30 - 2016-01-21 17:30 - 03038112 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttpph.mdl 2016-01-21 17:30 - 2016-01-21 17:30 - 01648408 _____ () C:\Program Files\Bitdefender\Bitdefender 2016\otengines_01751_004\ashttprbl.mdl 2015-06-03 03:56 - 2015-06-03 03:56 - 00261864 _____ () C:\Program Files (x86)\Droid4X\Droid4XService.exe 2012-06-08 14:13 - 2012-02-17 19:55 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll 2016-01-17 23:26 - 2015-12-16 18:34 - 00217720 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll 2012-11-22 16:19 - 2013-10-30 19:53 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2015-09-23 18:43 - 2015-09-23 18:43 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2012-05-30 19:06 - 2012-05-30 19:06 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-05-30 19:06 - 2012-05-30 19:06 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2015-12-28 21:32 - 2015-04-24 16:40 - 00043520 _____ () C:\Users\Basti\AppData\Local\THORN\QtSolutions_Service-head.dll 2015-12-28 21:32 - 2014-08-28 10:36 - 00732160 _____ () C:\Users\Basti\AppData\Local\THORN\libGLESv2.dll 2015-12-28 21:32 - 2014-08-28 10:41 - 00856576 _____ () C:\Users\Basti\AppData\Local\THORN\platforms\qwindows.dll 2015-12-28 21:32 - 2014-08-28 10:36 - 00047104 _____ () C:\Users\Basti\AppData\Local\THORN\libEGL.dll 2012-05-25 15:07 - 2012-03-28 21:18 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2015-12-21 13:52 - 2015-12-21 13:52 - 00932032 ____R () C:\Program Files (x86)\Skype\Phone\ssScreenVVS2.dll 2016-01-17 23:26 - 2015-12-16 18:34 - 00011896 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-01-14 11:16 - 2016-01-12 17:35 - 01590088 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libglesv2.dll 2016-01-14 11:16 - 2016-01-12 17:35 - 00087880 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libegl.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\Users\Basti\.DS_Store:AFP_AfpInfo AlternateDataStreams: C:\Users\Basti\Desktop\.DS_Store:AFP_AfpInfo AlternateDataStreams: C:\Users\Basti\Desktop\AdwCleaner_5.030.exe:BDU AlternateDataStreams: C:\Users\Basti\Desktop\FRST64.exe:BDU AlternateDataStreams: C:\Users\Basti\Desktop\JRT.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\.DS_Store:AFP_AfpInfo AlternateDataStreams: C:\Users\Basti\Downloads\361.43-desktop-win8-win7-winvista-64bit-international-whql.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\BnS_Lite_Installer.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\chromeinstall-8u66 (1).exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\chromeinstall-8u66.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\codeblocks-13.12mingw-setup.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\EvolveSetup.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\iFreeRecorder.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\jxpiinstall(2).exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\mbam-setup-2.2.0.1024 (1).exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\mingw-get-setup.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\NC-LauncherSetup.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\setup.exe:BDU AlternateDataStreams: C:\Users\Basti\Downloads\SkypeSetup.exe:BDU AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com Da befinden sich 7865 mehr Seiten. IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\...\123simsen.com -> www.123simsen.com Da befinden sich 7863 mehr Seiten. ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 03:34 - 2016-01-22 17:08 - 00004098 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com 127.0.0.1 na2m-pr.licenses.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 ereg.wip4.adobe.com 127.0.0.1 wip.adobe.com 127.0.0.1 wip1.adobe.com 127.0.0.1 wip2.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 wip4.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 hl2rcv.adobe.com 127.0.0.1 adobeereg.com 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 3dns.adobe.com 127.0.0.1 3dns-1.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-4.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-1.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 adobe-dns-4.adobe.com127.0.0.1 www.007guard.com Da befinden sich 77 zusätzliche Einträge. ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist deaktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Inhaltsmanager-Assistent für PlayStation(R).lnk => C:\Windows\pss\Inhaltsmanager-Assistent für PlayStation(R).lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Basti^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Synchronizer => MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin MSCONFIG\startupreg: ApnUpdater => MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: AutoStartNPSAgent => C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe MSCONFIG\startupreg: CD- und DVD-Sharing => "C:\Program Files (x86)\CD- und DVD-Sharing\ODSAgent.exe" MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming MSCONFIG\startupreg: EzPrint => "C:\Program Files (x86) (x86)\Lexmark 7600 Series\ezprint.exe" MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start MSCONFIG\startupreg: LOLReplay Recorder => "C:\Program Files (x86)\LOLReplay\LOLRecorder.exe" -minimize MSCONFIG\startupreg: lxdwmon.exe => "C:\Program Files (x86) (x86)\Lexmark 7600 Series\lxdwmon.exe" MSCONFIG\startupreg: Pando Media Booster => MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe MSCONFIG\startupreg: XboxStat => "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{AEB0AA6D-6C50-4812-9625-67A55EFD53FF}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{B6C925FB-AAF5-426B-B3E4-AE312A3FA526}] => (Allow) LPort=2869 FirewallRules: [{B8A05455-93A9-4D81-8C81-D3F3517D953C}] => (Allow) LPort=1900 FirewallRules: [{E8294358-232A-45E3-8825-6CF312AFF0A3}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{FF42412D-60DF-4783-9856-A6786836D569}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe FirewallRules: [TCP Query User{8605D22C-C232-4D70-95DE-DF0204070B05}E:\skype\phone\skype.exe] => (Allow) E:\skype\phone\skype.exe FirewallRules: [UDP Query User{3E24806E-72F0-4CB2-85B5-52D76EA61D9D}E:\skype\phone\skype.exe] => (Allow) E:\skype\phone\skype.exe FirewallRules: [TCP Query User{66097FAD-DE6E-45FE-B4B5-494B7951E559}E:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) E:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [UDP Query User{E44AFAA1-C985-4D4D-98C4-D1F1222E8DEC}E:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) E:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [{50589B4A-7714-4736-A12C-F203A0404CBD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{7BEB5529-C91A-4153-8184-940217CA9A68}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{BA05C10F-C9BD-4AAF-8CA9-1FD195EDC8AD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{9CE0C97A-8FA5-4C78-8636-3CCBF4236105}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{43F4BE84-BDF6-4A56-B305-76266D5CE186}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe FirewallRules: [{944328E1-A43A-4626-AFB3-1B5EB8ED02AB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe FirewallRules: [{01296CE7-D3EA-4B41-80A9-2B1A6DB946AC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{A1DFC9B1-30E8-4236-BC1B-7C29FA788E56}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe FirewallRules: [{61452E45-4CE4-4DEC-BFBF-F8C65D483E7D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{35B97D4E-9D9B-42C9-ADFB-D6DE5CFDFD87}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{ACD23962-358A-4CF3-B3BE-C1859D1B3AC4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{9A6355D6-6CE8-4A0B-A848-6868982EB28C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{E5585DFB-2F3E-452B-974F-0659487E8AC3}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{37A64963-0E37-4E44-A6E5-544FC3B270B1}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe FirewallRules: [{EB61EA23-EE2E-4D8B-9A1B-2F888ECA97EA}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{4F20E937-3A3E-484E-AF41-BCBF8F6EF15A}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe FirewallRules: [{0FCC7DD0-110E-48F3-98D7-63537CE9D87C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C3BB32CF-7D2A-4B49-B0E6-C59A5363AFDB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E40CC70F-53F7-43AE-82A1-464181035FD8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{26EA374E-9D61-4AB5-BFEB-457A93CDB684}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{9D747C84-4B7C-4ABD-954F-808306C2E7DE}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{0FD22C5F-CEEC-452B-BB9B-F382C7DD3E7A}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{1316D1D9-190F-43A7-840B-E3DB02CAD839}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{F2AAF089-6789-4D58-86CA-8AF3A3014E3D}] => (Allow) C:\Users\Basti\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{BF4BE5A0-D5B0-4CCE-AD02-C3926AF88D7F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{840BA19A-BE66-447C-8549-E61914FD6364}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{DA31F48E-4D65-448E-B0E5-F0F032D1A0C3}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe FirewallRules: [{405839C9-B746-4857-8BEF-9440A903A334}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe FirewallRules: [{7AFE82AF-470C-472B-9E42-73595DDB3C58}] => (Allow) LPort=7935 FirewallRules: [{834A5996-41C5-4FED-A7C7-29812EB211A6}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe FirewallRules: [{3F1637F3-3EA7-4C2D-A98A-756F2DBA7161}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3SP.exe FirewallRules: [{F738565D-20E7-4107-B64A-A15741CD7DE5}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe FirewallRules: [{48144A4D-6B79-4058-9A48-20772876CB90}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AC3MP.exe FirewallRules: [{CFE4DF24-5F00-49FB-A863-530E7E9E1505}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe FirewallRules: [{C19442D6-0261-4459-BD4F-6C8C4CC36C6E}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe FirewallRules: [{BDDB4C68-8452-43E0-B3EB-33E014E862F2}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3.exe FirewallRules: [{2B9602D7-E869-44EB-A586-73EAFF8A1523}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3.exe FirewallRules: [{8CA1C522-931E-45DF-A8B2-1496E2233AF9}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3_d3d11.exe FirewallRules: [{ED332F7D-C2B1-4A8E-A563-FB8F8ABD00B1}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3_d3d11.exe FirewallRules: [{706DA564-C0DD-4259-BE64-9504CA32903B}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Updater.exe FirewallRules: [{077438E0-8148-47F5-82EA-7A23153241E2}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Updater.exe FirewallRules: [{AFB4F4A8-A984-40B8-AC0A-A581DBC8D0AA}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Editor.exe FirewallRules: [{A7BBF6CC-173E-4F92-B1A5-91533FE68EBE}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Editor.exe FirewallRules: [{2525E825-F9A6-4F85-A5A8-E97D5C3A4FDA}] => (Allow) C:\Windows\SysWOW64\msiexec.exe FirewallRules: [{4AE9836A-57F4-4F10-9FE2-079DCE1A74C5}] => (Allow) C:\Windows\SysWOW64\msiexec.exe FirewallRules: [{782775DE-583A-4E84-BCDF-8766C9907708}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsasvr.exe FirewallRules: [{A6DE10C4-6169-4354-8A5F-1D6EF61C649A}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsasvr.exe FirewallRules: [{360EE568-4F95-4925-AD87-D0D8629D8E94}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsvsvr.exe FirewallRules: [{E834066F-C3C5-4C49-A039-7AE32F6BA807}] => (Allow) C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsvsvr.exe FirewallRules: [TCP Query User{56C7AB21-BCCD-4F5C-8D52-74B395884B9E}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Block) C:\program files (x86)\sony\content manager assistant\cma.exe FirewallRules: [UDP Query User{C47A71CD-4BB7-4FF9-BC0F-829EE83DFA87}C:\program files (x86)\sony\content manager assistant\cma.exe] => (Block) C:\program files (x86)\sony\content manager assistant\cma.exe FirewallRules: [{27133C47-866D-499D-B8E0-62C8175B8D81}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe FirewallRules: [{FC824A4A-084E-4949-A0FE-00036DCD3AE0}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\ODSAgent.exe FirewallRules: [{2BF78D21-34D1-407F-BB1E-863E83E76E74}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\ODSAgent.exe FirewallRules: [{ED6FAA94-A8B5-45A3-9D07-B568068532D2}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\RemoteInstallMacOSX.exe FirewallRules: [{6A55489F-AC43-4B82-8B6F-10620D1D28BB}] => (Allow) C:\Program Files (x86)\CD- und DVD-Sharing\RemoteInstallMacOSX.exe FirewallRules: [{E744BA9D-77AC-4A44-B1CC-53F9C01E70F8}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{E7C457CF-0B0B-42A7-A0D2-F942BD081C8C}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{14972E55-7D37-4D27-AE30-652C230045BE}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{B9FBD964-5AD5-4909-B65A-DCB842B4B050}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [TCP Query User{FE2B4338-50A1-42E3-BC70-F33D927CCA59}C:\users\basti\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\basti\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{FC27B11D-372E-4D59-9F85-5B7E0630AD9C}C:\users\basti\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\basti\appdata\roaming\spotify\spotify.exe FirewallRules: [{77FEF5E3-A2C3-4AAF-B6F3-2944DB24AEB0}] => (Block) C:\users\basti\appdata\roaming\spotify\spotify.exe FirewallRules: [{3C5A270E-15A2-4014-84D7-4C2B82BFD115}] => (Block) C:\users\basti\appdata\roaming\spotify\spotify.exe FirewallRules: [{0BEC205D-E089-4F21-9A05-312B20B704F9}] => (Allow) E:\Dragon Nest Europe\DragonNest.exe FirewallRules: [{F2C2E9A0-14A3-46AB-B79D-0489399BAFF8}] => (Allow) E:\Dragon Nest Europe\DragonNest.exe FirewallRules: [TCP Query User{6B0C01E5-C627-4A7C-8E52-D90D5FA2D12F}C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe] => (Allow) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe FirewallRules: [UDP Query User{49CAF30B-96F6-46AF-87DC-7C846CEE1567}C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe] => (Allow) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe FirewallRules: [{DBB21750-4C66-4A32-BDE8-9BD9B599C09C}] => (Block) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe FirewallRules: [{E8872357-7E0F-4009-960C-A6CA99D08262}] => (Block) C:\program files\dassault systemes\b21\win_b64\code\bin\cnext.exe FirewallRules: [{D90E4B67-C6C8-4C6D-B779-95A0AF0549FB}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{01D550ED-529B-4EBD-A526-FF7C61C99B38}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{3AEC5918-0F0F-446C-814F-BED80BA8D615}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{A19FAE1B-8FC4-47A2-AF99-615CB1632989}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{E7C041D1-61AF-47DC-87FF-C4102F7E96AB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{29261903-A601-474E-B969-353B616287C2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ.exe FirewallRules: [{F3F0B184-0050-4CC7-A11F-2FF10347E4E1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{B75523F0-6DFC-4C2E-88DF-3A853D1A7A1E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{3BAF1F78-0DC1-4410-88A6-ACFE28FAADD8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{63076B8D-F269-449B-BF26-999899FB5637}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{092EAFF9-F1B8-492E-8A93-FCDED7F6F01A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{2FE6D278-7786-4902-A270-0562F93891F8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{5BF2665B-F8A2-448B-A8B1-166D603E24FF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [{589C5ED7-3E1B-4004-A20E-66EEB891C562}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe FirewallRules: [{C0F3EDDA-BD33-4854-B4D0-75DD8675C224}] => (Allow) C:\Program Files (x86)\Origin Games\Plants vs. Zombies\PlantsVsZombies.exe FirewallRules: [{6D26D78C-E034-449D-ADBE-E29E44D2F37A}] => (Allow) C:\Program Files (x86)\Origin Games\Plants vs. Zombies\PlantsVsZombies.exe FirewallRules: [{4442C690-D7E9-4B5F-A25E-521E36417F40}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{5D891812-49CD-43AE-B7EE-B27C96C7C7B2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [TCP Query User{91BF4BE0-EB25-44AD-ADB9-36F1E34B317B}C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe] => (Allow) C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe FirewallRules: [UDP Query User{A4A79727-54EA-44D0-948D-F9DFAEFDAF0F}C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe] => (Allow) C:\users\basti\downloads\test\watch.dogs.deluxe.edition.cracked-3dm\bin\watch_dogs.exe FirewallRules: [{68D3CDC7-D1F8-4273-842F-B17E7C4E86CF}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe FirewallRules: [{A4642A64-FFB6-42F5-9EF8-A3F257E61B1C}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe FirewallRules: [{C5272483-76CE-4BD8-8646-C6EC5F1CF1C6}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe FirewallRules: [{8B4C1C15-86C8-4AD4-B190-9C08CFFD95D9}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe FirewallRules: [{25ADDED9-C807-4172-90A1-C3AC964FE326}] => (Allow) %ProgramFiles% (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe FirewallRules: [{794319B8-A91B-4DD1-93BF-25E9DA084189}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\FaxApplications.exe FirewallRules: [{8C20186C-0132-442A-A451-0EA1015D8F23}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\DigitalWizards.exe FirewallRules: [{66CB480A-D5FC-4F94-AC12-477B0638B0DA}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\SendAFax.exe FirewallRules: [{CEFFC8B8-7E7F-4597-9668-0026E35B6E55}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\DeviceSetup.exe FirewallRules: [{359830D2-A868-402B-B585-B569FB7EB3C0}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicator.exe FirewallRules: [{5EBF68FE-225D-4A50-A647-5F055D3EFEDE}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{C82C70BC-BCA0-4975-B46C-17D9C4A9BEA5}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{CE760193-0C9F-4B96-AB09-26F0C191308E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{071BE61C-F3E5-49E7-A3A4-56EA1EB407CA}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4_x86.exe FirewallRules: [{D1797CFD-02F7-4544-9D54-7A0B951C5482}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4_x86.exe FirewallRules: [{7A5E1850-EC46-4F46-85DA-54540ACBDDB2}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe FirewallRules: [{996983E1-D0BE-4FCD-8BBA-E257667941C5}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe FirewallRules: [TCP Query User{B8D07668-448E-487F-969A-93BD616D78E5}C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe FirewallRules: [UDP Query User{662D666A-2E35-412E-A419-095CFC37F1C1}C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe FirewallRules: [{F2FC4E0B-76F9-4320-853A-51889938D513}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe FirewallRules: [{FDFA8CE5-7B10-4F85-911C-B56695D7EAE2}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\ti-nspire cas student software.exe FirewallRules: [TCP Query User{5FC2F183-3E0D-440A-A0CD-69E7A331D073}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe FirewallRules: [UDP Query User{E8183AD0-A3B5-4509-A899-446F3BC09495}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcher.exe FirewallRules: [TCP Query User{041EF0F9-A7FE-4004-805D-A9BCE9B87258}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe FirewallRules: [UDP Query User{33544488-16F1-42C3-A81A-1C1511AF6668}E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe] => (Block) E:\program files (x86)\lolpbe\league of legends public beta\rads\projects\lol_patcher\releases\0.0.0.89\deploy\lolpatcherux.exe FirewallRules: [{031849CA-EB99-4088-9CCB-4C258DD89942}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ_BE.exe FirewallRules: [{8E346669-071F-4C46-A819-6CD8A7CC5FEA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ_BE.exe FirewallRules: [{B1A7B880-0EB6-4823-9D86-9FFCF83A3F58}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{E58C066A-3E3D-42F8-BFA8-E9BAE65EB7E4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{B991969E-6CD9-460C-A810-EDD7ADA4E68B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{04971D38-5D33-4E01-B3BB-219E0093C7BA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{89F1D3EE-7834-42BC-9700-3D25BCBC56B3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{C3FAE89B-1D4E-4D46-8A61-50158D229C9A}C:\program files\matlab\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\r2015a\bin\win64\matlab.exe FirewallRules: [UDP Query User{AF96BE9C-1D63-45FA-A019-CBD69EC2ECFD}C:\program files\matlab\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\r2015a\bin\win64\matlab.exe FirewallRules: [{79EDEFCB-DED5-415A-A2D4-954E3A07B2BC}] => (Block) C:\program files\matlab\r2015a\bin\win64\matlab.exe FirewallRules: [{5D435D29-34E0-4F66-BC06-329AC4E22143}] => (Block) C:\program files\matlab\r2015a\bin\win64\matlab.exe FirewallRules: [TCP Query User{E16785C3-4F1F-43DB-8569-7DAA1BB4939E}C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [UDP Query User{F8F7CE09-1BD6-40C2-BD53-B90E1779DF9E}C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [{56E46A08-F7EC-4BCD-99E7-67C16D04072B}] => (Block) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [{BAE9B81F-B180-450C-AAC2-90F85855CDCF}] => (Block) C:\users\basti\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe FirewallRules: [TCP Query User{960BAFE7-B279-4687-9762-B617276B2508}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [UDP Query User{3DD91B0E-AD44-4ACC-A86F-E3FFDF965641}C:\program files (x86)\droid4x\download\minithunderplatform.exe] => (Allow) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [{1498F3EC-1538-4C3F-9EAA-03B8D867AF38}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [{91101AFB-5036-4D1E-9DE3-115D13D0A94C}] => (Block) C:\program files (x86)\droid4x\download\minithunderplatform.exe FirewallRules: [TCP Query User{DB4711FF-7CE3-4C3F-A9E2-C814CAE24E25}C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe FirewallRules: [UDP Query User{2FCA9D68-E3E0-464D-B786-8D9728A834FD}C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe FirewallRules: [{6D6BEFEA-892A-461E-8E30-BC2DD8A8A9F1}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe FirewallRules: [{C30C8168-C7A9-411E-B51C-B21F3F9F16B2}] => (Block) C:\program files (x86)\ti education\ti-nspire cas student software\jre\bin\java.exe FirewallRules: [TCP Query User{83036536-6209-4CB8-B628-DA794E18A8DE}C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe FirewallRules: [UDP Query User{A139B970-9425-43E7-BDB6-4E22B2345171}C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe FirewallRules: [{700BBAB0-6C40-4AF2-BA97-8C696AC63CB0}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe FirewallRules: [{F11DDB0B-43A6-49B1-B7D0-5A8066177317}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\ti-nspire cx cas student software.exe FirewallRules: [TCP Query User{BB97726B-726D-4884-B231-36F1A90474C5}C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe FirewallRules: [UDP Query User{F0AFB84E-50C4-44F0-92F2-B67D99132739}C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe] => (Allow) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe FirewallRules: [{00EB906D-649C-4861-8C9D-34882AA42F23}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe FirewallRules: [{8CA6EF79-B664-454D-B766-431FFD0DF4B7}] => (Block) C:\program files (x86)\ti education\ti-nspire cx cas student software\jre\bin\java.exe FirewallRules: [{A6D6D585-8623-4CE1-BAAD-351E922FB928}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [{C2585F8A-885F-42B0-862D-ABAE50F00A1F}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe FirewallRules: [{BBFEFEDB-1230-42AF-A40A-7968C2540868}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe FirewallRules: [{077A8C17-D8B6-424C-8B93-106296089B81}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe FirewallRules: [{E873F7D5-09B2-46FE-9BB0-FC73E216E95C}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe FirewallRules: [TCP Query User{82994F2D-DF04-4504-9058-CD0ECF2CB746}C:\users\basti\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\basti\appdata\local\mycomgames\mycomgames.exe FirewallRules: [UDP Query User{7A4E61E8-A717-4843-BD4D-C110383BB73B}C:\users\basti\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\basti\appdata\local\mycomgames\mycomgames.exe FirewallRules: [TCP Query User{705B4041-A30C-4268-8F74-2563047066DB}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\javaw.exe FirewallRules: [UDP Query User{0C868E8E-EF56-47E5-9E9E-6416F680CADC}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\javaw.exe FirewallRules: [{A7EF31CF-8B85-49A0-AA01-137354F2D690}] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe FirewallRules: [{0A27EF24-7F72-4DA8-96AA-0602EE1512E5}] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe FirewallRules: [{6A3A3F01-F7A8-4478-BCE1-A786958317D4}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [{AF0213A2-AC56-4328-AC32-39E8FB0880D0}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe FirewallRules: [TCP Query User{7C58B92D-4076-4983-AF12-2E3D4EE31460}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe FirewallRules: [UDP Query User{43725424-2FA4-4C68-A7C6-AE4D1E43ABD4}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe FirewallRules: [{C5AE2AAD-ACB2-4E63-BC67-B6FA715C0461}] => (Block) C:\program files\java\jre1.8.0_65\bin\java.exe FirewallRules: [{50A441D2-4782-462D-AEDA-5999E5B5CED0}] => (Block) C:\program files\java\jre1.8.0_65\bin\java.exe FirewallRules: [{798DF15F-3FB2-4BF3-A2FC-DF8A03AECE4C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{C34618EC-DBF5-490C-AF1D-DF67C2E6D049}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{A4A0EC4B-C983-4968-9F2D-3302F4F92661}C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe] => (Allow) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe FirewallRules: [UDP Query User{A4AAC983-1616-4AB4-8AD2-3D6AFF5356D7}C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe] => (Allow) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe FirewallRules: [{06F93520-1969-4A3A-8192-EA0B59554B6E}] => (Block) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe FirewallRules: [{F423C64F-ED88-4412-9950-D47215E34DBB}] => (Block) C:\program files (x86)\lecturnity player\jre5\bin\javaw.exe FirewallRules: [{7773F1CF-7D07-444E-9F8C-D57EEBADC678}] => (Allow) C:\Users\Basti\Downloads\PlayBlackDesert.exe FirewallRules: [{A6016ED8-3344-4278-8690-1A83D5005216}] => (Allow) C:\Users\Basti\Downloads\PlayBlackDesert.exe FirewallRules: [{C52C2134-609E-4B7E-B36A-3EADD6F8A190}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd.exe FirewallRules: [{238E1164-63F1-46B6-AD8F-0CC27C8619BA}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe FirewallRules: [{C96E8D7E-8DE5-4FD3-85C1-CF41AE855BA6}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr.exe FirewallRules: [{22687CF4-7DE2-4EA1-8698-5586C8BA5CE2}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient.exe FirewallRules: [{E1DD1465-3FC5-4683-9970-D29CF3F37977}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe FirewallRules: [{A1F50892-915B-4F15-8E2B-23EC7CCCA0AE}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd_x64.exe FirewallRules: [TCP Query User{D47A2608-0668-439F-BD5D-3F91C39914AB}C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{F79027D7-71EA-4E9B-A204-126AE06D6F0B}C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe FirewallRules: [{25BF71AC-A7D7-455F-909D-072BE2A7890D}] => (Block) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe FirewallRules: [{56497540-DDF4-4F39-97B8-427A74C3F8EB}] => (Block) C:\program files (x86)\heroes of the storm\versions\base39709\heroesofthestorm_x64.exe FirewallRules: [{C92E8A48-A808-4C74-8216-0AF4284CF939}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\PublicLauncher.exe FirewallRules: [{FFB5C658-D2AA-45C6-90F8-83CC5523B319}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\PublicLauncher.exe FirewallRules: [{9E2CB54A-70ED-4A4E-A8BD-F7E24A1E8A57}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\MQELDiagnostics.exe FirewallRules: [{00ED0974-C580-4FFD-A091-BA3BFBEC7AC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Mighty Quest For Epic Loot\Launcher\MQELDiagnostics.exe FirewallRules: [TCP Query User{5197AE62-CE7D-4AA2-B80F-B5F444D5BFA7}C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe FirewallRules: [UDP Query User{A0DC3AE3-67CD-46C7-ABB1-F7B625700ACC}C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe FirewallRules: [{5C48AC52-2639-4854-A883-55938500DD89}] => (Block) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe FirewallRules: [{F39D5120-EA60-4023-8F52-E21E2020037B}] => (Block) C:\program files (x86)\2k games\sid meier's civilization v\civilizationv_dx11.exe FirewallRules: [{571F6C7C-2EFF-4F40-BB56-2654CCAFC1C2}] => (Allow) C:\Program Files\Echobit\Evolve\EvoSvc.exe FirewallRules: [{450EC6E1-77C0-43E2-9A68-1750427FB700}] => (Allow) C:\Program Files\Echobit\Evolve\EvolveClient.exe FirewallRules: [{3FFDEB63-D938-43B8-A52B-A79A42CE5867}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{7759388F-4EB9-47C8-905A-89153DD9989C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{90246421-2C2E-499B-A5B5-69F2DEB1E1F7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{DF9CE38A-4A6C-48B5-9157-3B60D3673EC7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{4EED09D9-F074-4E5F-8F6B-04CB10A69337}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{3DC9517A-F886-44F5-AF92-5EE0EF4B3B9A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe ==================== Wiederherstellungspunkte ========================= 21-01-2016 14:26:57 Entfernt Blade & Soul 21-01-2016 14:33:54 Installiert Blade & Soul 22-01-2016 17:15:03 JRT Pre-Junkware Removal ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (01/22/2016 05:24:00 PM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP) Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/22/2016 05:09:29 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/22/2016 01:31:22 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (01/22/2016 01:09:17 PM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP) Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/22/2016 12:56:39 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/22/2016 01:07:34 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Client.exe, Version 0.0.146.5585 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1abc Startzeit: 01d154a85317fdbe Endzeit: 73 Anwendungspfad: C:\Program Files (x86)\NCSOFT\BnS\bin\Client.exe Berichts-ID: 0e447086-c09c-11e5-ba16-0008cae5fc52 Error: (01/22/2016 01:00:19 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Client.exe, Version 0.0.146.5585 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1a70 Startzeit: 01d154a669c2ae21 Endzeit: 51 Anwendungspfad: C:\Program Files (x86)\NCSOFT\BnS\bin\Client.exe Berichts-ID: 0f2c1b30-c09b-11e5-ba16-0008cae5fc52 Error: (01/21/2016 02:28:47 PM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP) Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/21/2016 02:14:32 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/21/2016 01:25:41 PM) (Source: MsiInstaller) (EventID: 1024) (User: BASTI-DESKTOP) Description: Produkt: Adobe Acrobat Reader DC - Deutsch - Update "{AC76BA86-7AD7-0000-2550-AC0F0A4E5800}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Systemfehler: ============= Error: (01/22/2016 05:15:57 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "NVIDIA Display Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (01/22/2016 05:09:47 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (01/22/2016 05:05:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Apple Mobile Device" wurde aufgrund folgenden Fehlers nicht gestartet: %%109 Error: (01/22/2016 05:05:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Druckwarteschlange" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (01/22/2016 05:05:34 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: Der Dienst "Spooler" konnte sich nicht als "NT AUTHORITY\SYSTEM" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%50 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (01/22/2016 05:05:32 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\Windows\System32\bcmihvsrv64.dll Error: (01/22/2016 05:05:32 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\Windows\System32\bcmihvsrv64.dll Error: (01/22/2016 05:05:25 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\Windows\System32\bcmihvsrv64.dll Error: (01/22/2016 05:05:06 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (01/22/2016 05:04:37 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "BBUpdate" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. CodeIntegrity: =================================== Date: 2016-01-18 10:27:54.004 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2016-01-18 10:27:53.954 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-30 14:58:14.199 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.CP6452" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-30 14:58:14.135 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.CP6452" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-29 13:19:19.901 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.sA6316" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-29 13:19:19.826 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.sA6316" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-29 13:07:59.521 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.AF5708" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-29 13:07:59.460 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.AF5708" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-29 00:11:40.229 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.yT4184" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-12-29 00:11:40.169 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Basti\AppData\Local\Temp\GameNet.yT4184" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz Prozentuale Nutzung des RAM: 55% Installierter physikalischer RAM: 8146.98 MB Verfügbarer physikalischer RAM: 3621.87 MB Summe virtueller Speicher: 14287.19 MB Verfügbarer virtueller Speicher: 8793.6 MB ==================== Laufwerke ================================ Drive c: (Win7HPx64) (Fixed) (Total:465.76 GB) (Free:54.55 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)] Drive d: (MUNZ_2012) (CDROM) (Total:0.03 GB) (Free:0 GB) CDFS Drive e: (SAMSUNG) (Fixed) (Total:931.28 GB) (Free:313.13 GB) FAT32 ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4E7DE8CA) Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: C3178030) Partition 1: (Active) - (Size=931.5 GB) - (Type=0C) ==================== Ende von Addition.txt ============================ |
22.01.2016, 18:25 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam FRST-Fix Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft! Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Task: {AD6C33B2-B2D5-4DB3-885B-F850B71E16F8} - \Dealply -> Keine Datei <==== ACHTUNG HKLM-x32\...\Run: [] => [X] Task: C:\Windows\Tasks\Dealply.job.bak => C:\Users\Basti\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ACHTUNG HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG C:\Users\Basti\hamachi-2-ui.exe C:\Users\Basti\save.reg emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
22.01.2016, 18:44 | #13 |
| Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam Fixlog Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-01-2016 durchgeführt von Basti (2016-01-22 18:32:58) Run:1 Gestartet von C:\Users\Basti\Desktop Geladene Profile: Basti (Verfügbare Profile: Basti & Zocken & DefaultAppPool) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** Task: {AD6C33B2-B2D5-4DB3-885B-F850B71E16F8} - \Dealply -> Keine Datei <==== ACHTUNG HKLM-x32\...\Run: [] => [X] Task: C:\Windows\Tasks\Dealply.job.bak => C:\Users\Basti\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ACHTUNG HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG C:\Users\Basti\hamachi-2-ui.exe C:\Users\Basti\save.reg emptytemp: ***************** "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AD6C33B2-B2D5-4DB3-885B-F850B71E16F8}" => Schlüssel erfolgreich entfernt "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AD6C33B2-B2D5-4DB3-885B-F850B71E16F8}" => Schlüssel erfolgreich entfernt HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dealply => Schlüssel nicht gefunden. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wert erfolgreich entfernt C:\Windows\Tasks\Dealply.job.bak => erfolgreich verschoben "HKU\S-1-5-21-1745305398-2489788369-3521438674-1002\SOFTWARE\Policies\Microsoft\Internet Explorer" => Schlüssel erfolgreich entfernt C:\Users\Basti\hamachi-2-ui.exe => erfolgreich verschoben C:\Users\Basti\save.reg => erfolgreich verschoben EmptyTemp: => 20.3 GB temporäre Dateien entfernt. Das System musste neu gestartet werden. ==== Ende von Fixlog 18:34:55 ==== |
22.01.2016, 18:47 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam Okay, dann Kontrollscans mit (1) MBAM, (2) ESET und (3) SecurityCheck bitte: 1. Schritt: MBAM Downloade Dir bitte Malwarebytes Anti-Malware
2. Schritt: ESET ESET Online Scanner
3. Schritt: SecurityCheck Downloade Dir bitte SecurityCheck und:
__________________ Logfiles bitte immer in CODE-Tags posten |
23.01.2016, 11:14 | #15 |
| Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam MBAM Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 22.01.2016 Suchlaufzeit: 18:48 Protokolldatei: mbam.txt Administrator: Ja Version: 2.2.0.1024 Malware-Datenbank: v2016.01.22.07 Rootkit-Datenbank: v2016.01.20.01 Lizenz: Kostenlose Version Malware-Schutz: Deaktiviert Schutz vor bösartigen Websites: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Basti Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 538103 Abgelaufene Zeit: 46 Min., 34 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 0 (keine bösartigen Elemente erkannt) Registrierungswerte: 0 (keine bösartigen Elemente erkannt) Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Dateien: 0 (keine bösartigen Elemente erkannt) Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=90def005ca238c4d82c0cf0aa042f148 # end=init # utc_time=2016-01-22 07:04:38 # local_time=2016-01-22 08:04:38 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download esets_scanner_update returned -1 esets_gle=41221 Update Finalize Updated modules version: 0 Old modules - leave modules Update Init Update Download Update Init Update Download Update Finalize Updated modules version: 27771 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=90def005ca238c4d82c0cf0aa042f148 # end=updated # utc_time=2016-01-22 07:11:42 # local_time=2016-01-22 08:11:42 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=90def005ca238c4d82c0cf0aa042f148 # engine=27771 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2016-01-22 07:27:11 # local_time=2016-01-22 08:27:11 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Bitdefender Antivirus' # compatibility_mode=2067 16777213 50 88 1348 150803496 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 2687906 205120681 0 0 # scanned=4342 # found=1 # cleaned=0 # scan_time=929 sh=8992F72873D09212597E582A16F8D9BC60E6A22A ft=1 fh=e21391a34e842ffc vn="Win32/Toolbar.Conduit.S evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir" ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=90def005ca238c4d82c0cf0aa042f148 # end=init # utc_time=2016-01-22 07:32:14 # local_time=2016-01-22 08:32:14 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download esets_scanner_update returned -1 esets_gle=53251 Update Finalize Updated modules version: 27771 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=90def005ca238c4d82c0cf0aa042f148 # end=updated # utc_time=2016-01-22 07:32:40 # local_time=2016-01-22 08:32:40 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=90def005ca238c4d82c0cf0aa042f148 # engine=27771 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2016-01-23 05:17:10 # local_time=2016-01-23 06:17:10 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Bitdefender Antivirus' # compatibility_mode=2067 16777213 50 88 35096 150838895 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 2723305 205156080 0 0 # scanned=1227807 # found=12 # cleaned=0 # scan_time=35070 sh=8992F72873D09212597E582A16F8D9BC60E6A22A ft=1 fh=e21391a34e842ffc vn="Win32/Toolbar.Conduit.S evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir" sh=D0557816EC4DE99AF7D0CF003B8586A18BD97034 ft=1 fh=73d51bed1f67e8af vn="Win32/Spy.Zbot.YW Trojaner" ac=I fn="C:\ProgramData\NVIDIA\Updatus\Packages\00003367\dao.15411892.exe" sh=D0557816EC4DE99AF7D0CF003B8586A18BD97034 ft=1 fh=73d51bed1f67e8af vn="Win32/Spy.Zbot.YW Trojaner" ac=I fn="C:\Users\All Users\NVIDIA\Updatus\Packages\00003367\dao.15411892.exe" sh=6E31A6D60056AE0AA43DC0EF2501E0A83FF0C782 ft=1 fh=ec910ffbdbda110c vn="Variante von Win32/Toolbar.Conduit.AI evtl. unerwünschte Anwendung" ac=I fn="E:\Program Files (x86)\DVDVideoSoft\TB\ConduitInstaller.exe" sh=359D977D432E4F90FE627B2717144AE873990AC4 ft=1 fh=63c7b0ee3e7f229d vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="E:\Program Files (x86)\DVDVideoSoft\TB\DVDVideoSoftTB.exe" sh=D94D95A9DC6EA1645BA959FE28C59B6F48B4C9CB ft=0 fh=0000000000000000 vn="HTML/Iframe.B Trojaner" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-06-21 223358\Backup files 2.zip" sh=659937DC23FB9B389B79495FA8F4C0A3065921CF ft=0 fh=0000000000000000 vn="Win32/Vittalia.A evtl. unerwünschte Anwendung" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-06-21 223358\Backup files 5.zip" sh=8A92C925A45E2F657502EDCC7545204B7077E7FF ft=0 fh=0000000000000000 vn="Variante von Win32/Adware.Coupons.AA Anwendung" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-06-21 223358\Backup files 15.zip" sh=023A624441CECD326D021F426FE7103E2B55671D ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.S evtl. unerwünschte Anwendung" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-07-28 181346\Backup files 15.zip" sh=A69C740E036FC438EF9A54B5BEEEC1CCEBA82DA2 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-09-13 223221\Backup files 7.zip" sh=12AFD48E07E4EBB65057C85307CD7D78C23DB150 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-09-13 223221\Backup files 353.zip" sh=36DB8ECB21889CA25B7543CE6B749CB57254A073 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="E:\BASTI-PC\Backup Set 2012-06-21 223358\Backup Files 2012-09-13 223221\Backup files 721.zip" Code:
ATTFilter Results of screen317's Security Check version 1.009 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Bitdefender Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java 8 Update 65 Java version 32-bit out of Date! Adobe Flash Player 20.0.0.286 Mozilla Firefox (42.0) Google Chrome (47.0.2526.106) Google Chrome (47.0.2526.111) ````````Process Check: objlist.exe by Laurent```````` Bitdefender Bitdefender 2016 vsserv.exe Bitdefender Agent ProductAgentService.exe Bitdefender Bitdefender 2016 updatesrv.exe Bitdefender Bitdefender 2016 bdagent.exe Bitdefender Bitdefender 2016 bdwtxag.exe Bitdefender Bitdefender 2016 Antispam32 bdwtxapps.exe Bitdefender Bitdefender 2016 downloader.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
Themen zu Windows Explorer keine Rückmeldung, nach scan mit Malwarebyte und 80 Funden Computer extrem langsam |
antivirus, avira, bonjour, combofix, computer, dnsapi.dll, flash player, google, hijack, home, homepage, installation, keine rückmeldung, langsam, launch, mozilla, officejet, problem, programm, prozesse, registry, rundll, scan, services.exe, software, system, usb, virenfunde, windows |