|
Plagegeister aller Art und deren Bekämpfung: Download Protect und ich kann es nicht entfernenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
23.04.2016, 20:38 | #1 |
| Download Protect und ich kann es nicht entfernen Hallo Team vom Trojaner Board, ich habe mir Download Protect eingefangen. Habe mir Mailwarebytes Anti Mailware runtergeladen und Bedrohungssuchlauf gestartet. Alles enfernt (136 Bedrohungen insgesamt ), eine Logdatei erstellt (die poste ich ich gleich). Und jetzt brauche ich dringend eure Hilfe wie ich weiter verfahren muss (bitte bitte einen Schritt nach dem anderen, denn ich bin leider Voll-Laie...). Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 23.04.2016 Suchlaufzeit: 21:02 Protokolldatei: mbamlog.txt Administrator: Ja Version: 2.2.1.1043 Malware-Datenbank: v2016.04.23.05 Rootkit-Datenbank: v2016.04.17.01 Lizenz: Kostenlose Version Malware-Schutz: Deaktiviert Schutz vor bösartigen Websites: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 10 CPU: x64 Dateisystem: NTFS Benutzer: Admin Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 421692 Abgelaufene Zeit: 10 Min., 41 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 0 (keine bösartigen Elemente erkannt) Registrierungswerte: 0 (keine bösartigen Elemente erkannt) Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Dateien: 0 (keine bösartigen Elemente erkannt) Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) |
23.04.2016, 20:56 | #2 |
/// TB-Ausbilder | Download Protect und ich kann es nicht entfernenMein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags: So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Danke für deine Mitarbeit! Wenn es wirklich nur DownloadProtect ist... dann keine Sorge, das bekommen wir weg... Wo ist die Logdatei von MBAM mit den Funden??? Die leere Logdatei (ohne Funde) bringt mir nichts.... Bitte die richtige Logdatei nachreichen!!! Zur ersten Analyse bitte FRST und TDSS-Killer ausführen: Schritt 1 Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Schritt 2 Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
Bitte poste mit deiner nächsten Antwort
|
23.04.2016, 21:33 | #3 |
| Download Protect und ich kann es nicht entfernen Wo finde ich die ausführliche log-Datei?
__________________Mehr steht da nicht drin...... <?xml version="1.0" encoding="UTF-8"?> -<logs> <record toVersion="2016.4.17.1" name="Rootkit Database" last_modified_tag="672da04b-3b58-4980-9eee-e928b74ba8a9" fromVersion="2016.2.8.1" systemname="ADMIN-PC" username="SYSTEM" type="Update" source="Manual" datetime="2016-04-23T21:02:34.670185+02:00" LoggingEventType="1" severity="debug"/> <record toVersion="2016.4.19.1" name="Remediation Database" last_modified_tag="64408583-3efd-44d4-b485-f3760dc5313f" fromVersion="2016.2.12.1" systemname="ADMIN-PC" username="SYSTEM" type="Update" source="Manual" datetime="2016-04-23T21:02:34.705186+02:00" LoggingEventType="1" severity="debug"/> <record toVersion="2016.4.22.6" name="Domain Database" last_modified_tag="012aff4a-4b53-455a-b220-6bfa17996dd6" fromVersion="2016.2.16.8" systemname="ADMIN-PC" username="SYSTEM" type="Update" source="Manual" datetime="2016-04-23T21:02:34.905202+02:00" LoggingEventType="1" severity="debug"/> <record toVersion="2016.4.23.5" name="Malware Database" last_modified_tag="51c4877a-4455-4bb8-9816-afc3f7fec1a8" fromVersion="2016.2.16.6" systemname="ADMIN-PC" username="SYSTEM" type="Update" source="Manual" datetime="2016-04-23T21:02:36.574973+02:00" LoggingEventType="1" severity="debug"/> <record toVersion="2016.4.7.1" name="IP Database" last_modified_tag="ce74a7f0-9c36-47bc-b1ff-cb204d3e2c3e" fromVersion="2016.2.8.1" systemname="ADMIN-PC" username="SYSTEM" type="Update" source="Manual" datetime="2016-04-23T21:02:38.296231+02:00" LoggingEventType="1" severity="debug"/> <record last_modified_tag="8c82cc49-0cb8-4980-89f4-3011cc1c805e" systemname="ADMIN-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-04-23T21:02:38.336241+02:00" LoggingEventType="2" severity="debug" subtype="Refresh" result="Starting"/> <record last_modified_tag="a2f1d8ee-088d-4026-b5ef-f79e373aef78" systemname="ADMIN-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-04-23T21:02:45.273733+02:00" LoggingEventType="2" severity="debug" subtype="Refresh" result="Success"/> <record last_modified_tag="33e2066d-8456-45ef-a29c-57c8fba4978c" systemname="ADMIN-PC" username="SYSTEM" type="Scan" source="Manual" datetime="2016-04-23T21:31:58.563176+02:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="136" malwaredetections="0" duration="641" starttime="2016-04-23T21:02:38+02:00" scantype="threat"/> <record last_modified_tag="43c87666-4700-422b-b98c-ab54d9ec10be" systemname="ADMIN-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-04-23T21:32:12.225680+02:00" LoggingEventType="2" severity="debug" subtype="Malware Protection" result="Stopping"/> <record last_modified_tag="f954f718-052d-4304-a6a8-31b11be05a88" systemname="ADMIN-PC" username="SYSTEM" type="Protection" source="Protection" datetime="2016-04-23T21:32:13.171089+02:00" LoggingEventType="2" severity="debug" subtype="Malware Protection" result="Stopped"/> </logs> Hier die FRST.txt Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:18-04-2016 durchgeführt von Admin (Administrator) auf ADMIN-PC (23-04-2016 22:27:20) Gestartet von C:\Users\Admin\Desktop Geladene Profile: Admin (Verfügbare Profile: Admin & DefaultAppPool) Platform: Windows 10 Pro Version 1511 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (HP) C:\Windows\System32\HPSIsvc.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe () C:\Windows\System32\DnsBlockUpdateSvc.exe (HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (Plays.tv, LLC) C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (AppEx Networks Corporation) C:\Program Files\AMD Quick Stream\AMDQuickStream.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (Plays.tv, LLC) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe (Raptr Inc.) C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_ep64.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11821160 2011-05-09] (Realtek Semiconductor) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7390608 2016-04-23] (AVAST Software) HKLM-x32\...\Run: [PlaysTV] => C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe [71440 2016-04-05] (Plays.tv, LLC) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-04] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \mbamdor.exe [55264 2016-03-10] (Malwarebytes) HKU\S-1-5-21-540040400-2712554345-721507239-1000\...\Run: [AppEx Accelerator UI] => C:\Program Files\AMD Quick Stream\AMDQuickStream.exe [488640 2015-04-06] (AppEx Networks Corporation) HKU\S-1-5-21-540040400-2712554345-721507239-1000\...\RunOnce: [Uninstall C:\Users\Admin\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Admin\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64" ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-04-23] (AVAST Software) GroupPolicy: Beschränkung - Chrome <======= ACHTUNG CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <======= ACHTUNG (Beschränkung - ProxySettings) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 Tcpip\..\Interfaces\{40dc614c-2940-457d-87e1-132bb1ca5eec}: [DhcpNameServer] 192.168.2.1 192.168.2.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-540040400-2712554345-721507239-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} HKU\S-1-5-21-540040400-2712554345-721507239-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/?hl=de&gl=de HKU\S-1-5-21-540040400-2712554345-721507239-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://de.yahoo.com/?fr=hp-avast&type=avastbcl SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} SearchScopes: HKLM -> {373ED870-32D5-4ACA-8DB2-BC97C8E6CA84} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM-x32 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} SearchScopes: HKU\S-1-5-21-540040400-2712554345-721507239-1000 -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} SearchScopes: HKU\S-1-5-21-540040400-2712554345-721507239-1000 -> {373ED870-32D5-4ACA-8DB2-BC97C8E6CA84} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKU\S-1-5-21-540040400-2712554345-721507239-1000 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxp://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-23] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-23] (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Keine Datei Toolbar: HKLM - Kein Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Keine Datei Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\qp14xmqh.default FF NewTab: about:newtab FF DefaultSearchEngine: Google (avast) FF DefaultSearchUrl: hxxps://www.google.com/search?trackid=sp-006 FF SearchEngineOrder.1: Google (avast) FF SelectedSearchEngine: Google (avast) FF SelectedSearchEngine: google FF Homepage: hxxps://www.google.com/?trackid=sp-006 FF Keyword.URL: hxxps://www.google.com/search?trackid=sp-006 FF Keyword.URL: hxxp://www.google.de/search?hl=de&gl=de&lr=&ie=utf-8&oe=utf-8&meta=lr=lang_de&q= FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-20] (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.4.1 -> C:\WINDOWS\SysWOW64\npDeployJava1.dll [2012-04-04] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-23] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.) FF user.js: detected! => C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\qp14xmqh.default\user.js [2016-04-23] FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-12-18] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\qp14xmqh.default\searchplugins\google-avast.xml [2015-12-31] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-04-23] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-04-23] StartMenuInternet: FirefoxPortable - C:\Program Files (x86)\FirefoxPortable\FirefoxPortable.exe hxxp://www.yoursites123.com/?type=sc&ts=1449646655&z=b5b4df291f82c289678daf8g0z4z1t4q7z8q8qfw3g&from=ient07021&uid=ST3320820AS_9QF0Y1RHXXXX9QF0Y1RH Chrome: ======= CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-05] CHR Extension: (Google Präsentationen) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-05] CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-05] CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-05] CHR Extension: (Google-Suche) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-05] CHR Extension: (Kein Name) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\doigeogcjmkkmmekoldcljaipjhoohph [2016-04-23] CHR Extension: (Google Präsentationen) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-05] CHR Extension: (Google Präsentationen) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-20] CHR Extension: (Kein Name) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaommicacjonigcnpagdcjonanodceme [2016-04-23] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-05] CHR Extension: (Google Präsentationen) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\npdicihegicnhaangkdmcgbjceoemeoo [2015-12-05] CHR Extension: (Google Mail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-05] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-04-23] CHR HKLM-x32\...\Chrome\Extension: [npdicihegicnhaangkdmcgbjceoemeoo] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert] R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-04-23] (AVAST Software) R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [145920 2011-01-21] (HP) [Datei ist nicht signiert] R2 HPSIService; C:\Windows\system32\HPSIsvc.exe [124536 2012-12-25] (HP) [Datei ist nicht signiert] R2 PlaysService; C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe [32528 2016-04-05] (Plays.tv, LLC) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [31992 2015-06-03] (Advanced Micro Devices, Inc.) R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices) R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [229056 2015-04-03] (AppEx Networks Corporation) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-04-23] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-04-23] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-04-23] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-04-23] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-04-23] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-04-23] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [465792 2016-04-23] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [166432 2016-04-23] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287528 2016-04-23] (AVAST Software) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [111120 2016-03-01] (Advanced Micro Devices) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-04-23] (Malwarebytes) S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [29168 2016-01-20] (Marvell Semiconductor, Inc.) U0 nduvjyw; C:\Windows\System32\drivers\dsmrhitk.sys [79064 2016-04-23] (Malwarebytes) R3 NmPar; C:\Windows\system32\DRIVERS\NmPar.sys [95744 2010-01-12] (Windows (R) Codename Longhorn DDK provider) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek ) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) U3 idsvc; kein ImagePath ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-04-23 22:27 - 2016-04-23 22:27 - 00017464 _____ C:\Users\Admin\Desktop\FRST.txt 2016-04-23 22:26 - 2016-04-23 22:27 - 00000000 ____D C:\FRST 2016-04-23 22:26 - 2016-04-23 22:26 - 02375680 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe 2016-04-23 22:23 - 2016-04-23 22:25 - 01726464 _____ (Farbar) C:\Users\Admin\Desktop\FRST.exe 2016-04-23 22:18 - 2016-04-23 22:18 - 00001077 _____ C:\Users\Admin\Desktop\mbam.txt 2016-04-23 21:31 - 2016-04-23 21:31 - 00079064 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\dsmrhitk.sys 2016-04-23 21:02 - 2016-04-23 21:02 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-04-23 21:01 - 2016-04-23 21:31 - 00001165 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2016-04-23 21:01 - 2016-04-23 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2016-04-23 21:01 - 2016-04-23 21:01 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2016-04-23 21:01 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2016-04-23 21:01 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2016-04-23 21:01 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2016-04-23 21:00 - 2016-04-23 21:00 - 22851472 _____ (Malwarebytes ) C:\Users\Admin\Downloads\mbam-setup-2.2.1.1043.exe 2016-04-23 18:47 - 2016-04-23 18:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlaysTV 2016-04-23 18:39 - 2016-04-23 00:46 - 00268352 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe 2016-04-23 18:39 - 2012-04-04 18:47 - 00772504 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\npDeployJava1.dll 2016-04-23 18:39 - 2012-04-04 18:47 - 00687504 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\deployJava1.dll 2016-04-23 18:20 - 2016-04-23 18:20 - 00004296 _____ C:\WINDOWS\System32\Tasks\AMD Updater 2016-04-23 18:19 - 2016-04-23 18:19 - 00000000 ____D C:\WINDOWS\LastGood.Tmp 2016-04-23 18:00 - 2016-04-23 18:00 - 00398152 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2016-04-23 18:00 - 2016-04-23 18:00 - 00052184 _____ (AVAST Software) C:\WINDOWS\avastSS.scr 2016-04-13 12:16 - 2016-04-23 18:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-04-13 00:38 - 2016-03-29 12:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-04-13 00:38 - 2016-03-29 07:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-04-13 00:38 - 2016-03-29 07:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-04-13 00:38 - 2016-03-29 07:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-04-13 00:37 - 2016-04-02 06:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2016-04-13 00:37 - 2016-04-02 06:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2016-04-13 00:37 - 2016-04-02 06:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2016-04-13 00:37 - 2016-04-02 05:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll 2016-04-13 00:37 - 2016-04-02 05:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll 2016-04-13 00:37 - 2016-04-02 05:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll 2016-04-13 00:37 - 2016-04-02 05:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-04-13 00:37 - 2016-04-02 05:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2016-04-13 00:37 - 2016-04-02 05:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2016-04-13 00:37 - 2016-04-02 05:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-04-13 00:37 - 2016-04-02 05:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-04-13 00:37 - 2016-04-02 05:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-04-13 00:37 - 2016-04-02 05:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-04-13 00:37 - 2016-04-02 05:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-04-13 00:37 - 2016-03-29 12:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2016-04-13 00:37 - 2016-03-29 12:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2016-04-13 00:37 - 2016-03-29 12:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-04-13 00:37 - 2016-03-29 12:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2016-04-13 00:37 - 2016-03-29 12:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2016-04-13 00:37 - 2016-03-29 12:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2016-04-13 00:37 - 2016-03-29 12:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll 2016-04-13 00:37 - 2016-03-29 12:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll 2016-04-13 00:37 - 2016-03-29 12:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2016-04-13 00:37 - 2016-03-29 12:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2016-04-13 00:37 - 2016-03-29 12:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2016-04-13 00:37 - 2016-03-29 11:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2016-04-13 00:37 - 2016-03-29 11:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-04-13 00:37 - 2016-03-29 11:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll 2016-04-13 00:37 - 2016-03-29 11:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll 2016-04-13 00:37 - 2016-03-29 11:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys 2016-04-13 00:37 - 2016-03-29 11:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2016-04-13 00:37 - 2016-03-29 11:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2016-04-13 00:37 - 2016-03-29 11:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-04-13 00:37 - 2016-03-29 11:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2016-04-13 00:37 - 2016-03-29 11:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe 2016-04-13 00:37 - 2016-03-29 10:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll 2016-04-13 00:37 - 2016-03-29 10:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2016-04-13 00:37 - 2016-03-29 10:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe 2016-04-13 00:37 - 2016-03-29 10:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2016-04-13 00:37 - 2016-03-29 10:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys 2016-04-13 00:37 - 2016-03-29 10:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2016-04-13 00:37 - 2016-03-29 10:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2016-04-13 00:37 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll 2016-04-13 00:37 - 2016-03-29 10:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2016-04-13 00:37 - 2016-03-29 09:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll 2016-04-13 00:37 - 2016-03-29 09:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll 2016-04-13 00:37 - 2016-03-29 09:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll 2016-04-13 00:37 - 2016-03-29 09:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2016-04-13 00:37 - 2016-03-29 09:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-04-13 00:37 - 2016-03-29 09:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-04-13 00:37 - 2016-03-29 09:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll 2016-04-13 00:37 - 2016-03-29 09:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-04-13 00:37 - 2016-03-29 09:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2016-04-13 00:37 - 2016-03-29 09:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2016-04-13 00:37 - 2016-03-29 09:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2016-04-13 00:37 - 2016-03-29 09:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-04-13 00:37 - 2016-03-29 09:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll 2016-04-13 00:37 - 2016-03-29 09:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2016-04-13 00:37 - 2016-03-29 09:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2016-04-13 00:37 - 2016-03-29 09:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll 2016-04-13 00:37 - 2016-03-29 09:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll 2016-04-13 00:37 - 2016-03-29 09:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2016-04-13 00:37 - 2016-03-29 09:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll 2016-04-13 00:37 - 2016-03-29 09:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-04-13 00:37 - 2016-03-29 09:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2016-04-13 00:37 - 2016-03-29 09:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll 2016-04-13 00:37 - 2016-03-29 09:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-04-13 00:37 - 2016-03-29 09:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2016-04-13 00:37 - 2016-03-29 09:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2016-04-13 00:37 - 2016-03-29 09:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2016-04-13 00:37 - 2016-03-29 09:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-04-13 00:37 - 2016-03-29 09:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2016-04-13 00:37 - 2016-03-29 09:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll 2016-04-13 00:37 - 2016-03-29 09:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-04-13 00:37 - 2016-03-29 09:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2016-04-13 00:37 - 2016-03-29 09:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-04-13 00:37 - 2016-03-29 09:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-04-13 00:37 - 2016-03-29 09:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll 2016-04-13 00:37 - 2016-03-29 09:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll 2016-04-13 00:37 - 2016-03-29 09:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll 2016-04-13 00:37 - 2016-03-29 09:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2016-04-13 00:37 - 2016-03-29 09:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll 2016-04-13 00:37 - 2016-03-29 09:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2016-04-13 00:37 - 2016-03-29 09:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2016-04-13 00:37 - 2016-03-29 09:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys 2016-04-13 00:37 - 2016-03-29 09:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2016-04-13 00:37 - 2016-03-29 09:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll 2016-04-13 00:37 - 2016-03-29 09:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2016-04-13 00:37 - 2016-03-29 08:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2016-04-13 00:37 - 2016-03-29 08:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-04-13 00:37 - 2016-03-29 08:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll 2016-04-13 00:37 - 2016-03-29 08:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll 2016-04-13 00:37 - 2016-03-29 08:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-04-13 00:37 - 2016-03-29 08:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2016-04-13 00:37 - 2016-03-29 08:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll 2016-04-13 00:37 - 2016-03-29 08:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-04-13 00:37 - 2016-03-29 08:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll 2016-04-13 00:37 - 2016-03-29 08:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll 2016-04-13 00:37 - 2016-03-29 08:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2016-04-13 00:37 - 2016-03-29 08:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll 2016-04-13 00:37 - 2016-03-29 08:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll 2016-04-13 00:37 - 2016-03-29 08:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2016-04-13 00:37 - 2016-03-29 08:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2016-04-13 00:37 - 2016-03-29 08:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-04-13 00:37 - 2016-03-29 08:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll 2016-04-13 00:37 - 2016-03-29 08:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-04-13 00:37 - 2016-03-29 08:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2016-04-13 00:37 - 2016-03-29 08:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2016-04-13 00:37 - 2016-03-29 08:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-04-13 00:37 - 2016-03-29 08:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll 2016-04-13 00:37 - 2016-03-29 08:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-04-13 00:37 - 2016-03-29 08:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2016-04-13 00:37 - 2016-03-29 08:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2016-04-13 00:37 - 2016-03-29 08:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-04-13 00:37 - 2016-03-29 08:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-04-13 00:37 - 2016-03-29 08:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2016-04-13 00:37 - 2016-03-29 08:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2016-04-13 00:37 - 2016-03-29 08:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll 2016-04-13 00:37 - 2016-03-29 08:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2016-04-13 00:37 - 2016-03-29 08:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2016-04-13 00:37 - 2016-03-29 08:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll 2016-04-13 00:37 - 2016-03-29 08:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-04-13 00:37 - 2016-03-29 08:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll 2016-04-13 00:37 - 2016-03-29 08:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2016-04-13 00:37 - 2016-03-29 08:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-04-13 00:37 - 2016-03-29 08:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-04-13 00:37 - 2016-03-29 08:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll 2016-04-13 00:37 - 2016-03-29 08:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll 2016-04-13 00:37 - 2016-03-29 08:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2016-04-13 00:37 - 2016-03-29 08:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-04-13 00:37 - 2016-03-29 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-04-13 00:37 - 2016-03-29 08:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-04-13 00:37 - 2016-03-29 08:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-04-13 00:37 - 2016-03-29 08:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll 2016-04-13 00:37 - 2016-03-29 08:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2016-04-13 00:37 - 2016-03-29 08:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll 2016-04-13 00:37 - 2016-03-29 08:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-04-13 00:37 - 2016-03-29 08:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-04-13 00:37 - 2016-03-29 07:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-04-13 00:37 - 2016-03-29 07:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-04-13 00:37 - 2016-03-29 07:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-04-13 00:37 - 2016-03-29 07:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-04-13 00:37 - 2016-03-29 07:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll 2016-04-13 00:37 - 2016-03-29 07:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll 2016-04-13 00:37 - 2016-03-29 07:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-04-13 00:37 - 2016-03-29 07:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll 2016-04-13 00:37 - 2016-03-29 07:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-04-13 00:37 - 2016-03-29 07:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-04-13 00:37 - 2016-03-29 07:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-04-13 00:37 - 2016-03-29 07:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-04-13 00:37 - 2016-03-29 07:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-04-13 00:37 - 2016-03-29 07:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll 2016-04-13 00:37 - 2016-03-29 07:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-04-13 00:37 - 2016-03-29 07:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-04-13 00:37 - 2016-03-29 07:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll 2016-04-13 00:37 - 2016-03-29 07:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll 2016-04-13 00:36 - 2016-04-02 06:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll 2016-04-13 00:36 - 2016-04-02 05:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2016-04-13 00:36 - 2016-04-02 05:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll 2016-04-13 00:36 - 2016-04-02 05:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll 2016-04-13 00:36 - 2016-04-02 05:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll 2016-04-13 00:36 - 2016-04-02 05:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll 2016-04-13 00:36 - 2016-04-02 05:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2016-04-13 00:36 - 2016-04-02 05:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2016-04-13 00:36 - 2016-04-02 05:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2016-04-13 00:36 - 2016-03-29 12:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2016-04-13 00:36 - 2016-03-29 11:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll 2016-04-13 00:36 - 2016-03-29 11:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll 2016-04-13 00:36 - 2016-03-29 11:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2016-04-13 00:36 - 2016-03-29 11:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-04-13 00:36 - 2016-03-29 11:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe 2016-04-13 00:36 - 2016-03-29 11:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll 2016-04-13 00:36 - 2016-03-29 11:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll 2016-04-13 00:36 - 2016-03-29 11:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll 2016-04-13 00:36 - 2016-03-29 10:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll 2016-04-13 00:36 - 2016-03-29 10:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll 2016-04-13 00:36 - 2016-03-29 10:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll 2016-04-13 00:36 - 2016-03-29 10:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll 2016-04-13 00:36 - 2016-03-29 10:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll 2016-04-13 00:36 - 2016-03-29 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll 2016-04-13 00:36 - 2016-03-29 10:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys 2016-04-13 00:36 - 2016-03-29 10:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll 2016-04-13 00:36 - 2016-03-29 10:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2016-04-13 00:36 - 2016-03-29 10:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll 2016-04-13 00:36 - 2016-03-29 10:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll 2016-04-13 00:36 - 2016-03-29 10:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2016-04-13 00:36 - 2016-03-29 10:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll 2016-04-13 00:36 - 2016-03-29 10:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2016-04-13 00:36 - 2016-03-29 10:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe 2016-04-13 00:36 - 2016-03-29 10:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll 2016-04-13 00:36 - 2016-03-29 10:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll 2016-04-13 00:36 - 2016-03-29 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe 2016-04-13 00:36 - 2016-03-29 09:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll 2016-04-13 00:36 - 2016-03-29 09:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2016-04-13 00:36 - 2016-03-29 09:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-04-13 00:36 - 2016-03-29 09:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll 2016-04-13 00:36 - 2016-03-29 09:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-04-13 00:36 - 2016-03-29 09:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll 2016-04-13 00:36 - 2016-03-29 09:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-04-13 00:36 - 2016-03-29 09:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys 2016-04-13 00:36 - 2016-03-29 09:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll 2016-04-13 00:36 - 2016-03-29 09:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll 2016-04-13 00:36 - 2016-03-29 09:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll 2016-04-13 00:36 - 2016-03-29 09:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe 2016-04-13 00:36 - 2016-03-29 09:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll 2016-04-13 00:36 - 2016-03-29 09:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll 2016-04-13 00:36 - 2016-03-29 09:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-04-13 00:36 - 2016-03-29 09:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll 2016-04-13 00:36 - 2016-03-29 09:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll 2016-04-13 00:36 - 2016-03-29 09:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2016-04-13 00:36 - 2016-03-29 09:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-04-13 00:36 - 2016-03-29 09:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll 2016-04-13 00:36 - 2016-03-29 09:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll 2016-04-13 00:36 - 2016-03-29 09:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 2016-04-13 00:36 - 2016-03-29 09:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll 2016-04-13 00:36 - 2016-03-29 09:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll 2016-04-13 00:36 - 2016-03-29 09:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2016-04-13 00:36 - 2016-03-29 09:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys 2016-04-13 00:36 - 2016-03-29 09:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll 2016-04-13 00:36 - 2016-03-29 09:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll 2016-04-13 00:36 - 2016-03-29 09:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-04-13 00:36 - 2016-03-29 09:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-04-13 00:36 - 2016-03-29 09:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll 2016-04-13 00:36 - 2016-03-29 09:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll 2016-04-13 00:36 - 2016-03-29 09:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys 2016-04-13 00:36 - 2016-03-29 09:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-04-13 00:36 - 2016-03-29 09:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll 2016-04-13 00:36 - 2016-03-29 09:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll 2016-04-13 00:36 - 2016-03-29 09:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2016-04-13 00:36 - 2016-03-29 09:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll 2016-04-13 00:36 - 2016-03-29 09:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll 2016-04-13 00:36 - 2016-03-29 09:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2016-04-13 00:36 - 2016-03-29 09:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll 2016-04-13 00:36 - 2016-03-29 09:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2016-04-13 00:36 - 2016-03-29 09:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-04-13 00:36 - 2016-03-29 09:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll 2016-04-13 00:36 - 2016-03-29 09:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-04-13 00:36 - 2016-03-29 09:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll 2016-04-13 00:36 - 2016-03-29 09:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-04-13 00:36 - 2016-03-29 09:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll 2016-04-13 00:36 - 2016-03-29 09:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2016-04-13 00:36 - 2016-03-29 09:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll 2016-04-13 00:36 - 2016-03-29 09:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe 2016-04-13 00:36 - 2016-03-29 09:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll 2016-04-13 00:36 - 2016-03-29 09:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll 2016-04-13 00:36 - 2016-03-29 09:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll 2016-04-13 00:36 - 2016-03-29 09:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll 2016-04-13 00:36 - 2016-03-29 09:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll 2016-04-13 00:36 - 2016-03-29 09:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2016-04-13 00:36 - 2016-03-29 08:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2016-04-13 00:36 - 2016-03-29 08:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe 2016-04-13 00:36 - 2016-03-29 08:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll 2016-04-13 00:36 - 2016-03-29 08:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll 2016-04-13 00:36 - 2016-03-29 08:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll 2016-04-13 00:36 - 2016-03-29 08:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2016-04-13 00:36 - 2016-03-29 08:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll 2016-04-13 00:36 - 2016-03-29 08:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-04-13 00:36 - 2016-03-29 08:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll 2016-04-13 00:36 - 2016-03-29 08:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll 2016-04-13 00:36 - 2016-03-29 08:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2016-04-13 00:36 - 2016-03-29 08:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-04-13 00:36 - 2016-03-29 08:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-04-13 00:36 - 2016-03-29 08:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll 2016-04-13 00:36 - 2016-03-29 08:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll 2016-04-13 00:36 - 2016-03-29 08:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll 2016-04-13 00:36 - 2016-03-29 08:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2016-04-13 00:36 - 2016-03-29 08:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll 2016-04-13 00:36 - 2016-03-29 08:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-04-13 00:36 - 2016-03-29 08:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll 2016-04-13 00:36 - 2016-03-29 08:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2016-04-13 00:36 - 2016-03-29 08:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll 2016-04-13 00:36 - 2016-03-29 08:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2016-04-13 00:36 - 2016-03-29 08:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll 2016-04-13 00:36 - 2016-03-29 08:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL 2016-04-13 00:36 - 2016-03-29 08:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-04-13 00:36 - 2016-03-29 07:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll 2016-04-13 00:36 - 2016-03-29 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll 2016-04-13 00:36 - 2016-03-29 07:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL 2016-04-13 00:36 - 2016-03-29 07:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL 2016-04-13 00:36 - 2016-03-29 07:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL 2016-04-13 00:36 - 2016-03-29 07:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll 2016-03-29 13:03 - 2016-03-29 13:03 - 00003670 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-roland.unterweger@t-online.de 2016-03-29 13:01 - 2016-03-29 13:03 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2016-03-29 12:56 - 2016-04-23 21:31 - 00001596 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.lnk 2016-03-29 12:56 - 2016-04-23 21:31 - 00001070 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk 2016-03-29 12:56 - 2016-03-29 12:56 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2016-03-29 12:56 - 2016-03-29 12:56 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2016-03-29 12:51 - 2016-04-23 21:31 - 00001908 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Elements 9.lnk 2016-03-29 12:51 - 2016-04-23 21:31 - 00001890 _____ C:\Users\Public\Desktop\Adobe Photoshop Elements 9.lnk 2016-03-29 12:51 - 2010-03-19 03:00 - 00055856 ____N (Sonic Solutions) C:\WINDOWS\system32\Drivers\PxHlpa64.sys 2016-03-29 12:51 - 2009-10-20 03:00 - 00010224 ____N (Sonic Solutions) C:\WINDOWS\system32\Drivers\cdralw2k.sys 2016-03-29 12:51 - 2009-10-20 03:00 - 00010224 ____N (Sonic Solutions) C:\WINDOWS\system32\Drivers\cdr4_xp.sys ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2016-04-23 21:45 - 2015-02-17 15:53 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-04-23 21:35 - 2012-05-13 11:50 - 00001136 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-04-23 21:35 - 2012-05-13 11:50 - 00001132 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-04-23 21:31 - 2016-03-23 08:06 - 00001222 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk 2016-04-23 21:31 - 2016-03-23 08:06 - 00001204 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk 2016-04-23 21:31 - 2016-02-04 06:19 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-04-23 21:31 - 2016-02-04 06:03 - 00000000 ___DC C:\WINDOWS\Panther 2016-04-23 21:31 - 2016-01-18 11:23 - 00002162 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2015.lnk 2016-04-23 21:31 - 2016-01-07 14:50 - 00002636 _____ C:\Users\Public\Desktop\Skype.lnk 2016-04-23 21:31 - 2015-12-31 03:45 - 00002023 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk 2016-04-23 21:31 - 2015-12-31 03:45 - 00002005 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2016-04-23 21:31 - 2015-12-19 23:24 - 00001213 _____ C:\Users\Public\Desktop\LibreOffice 5.0.lnk 2016-04-23 21:31 - 2015-12-16 11:48 - 00002264 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-04-23 21:31 - 2015-12-16 11:48 - 00002246 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-04-23 21:31 - 2015-12-13 17:08 - 00002421 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-04-23 21:31 - 2015-12-13 17:05 - 00001047 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk 2016-04-23 21:31 - 2015-12-11 11:13 - 00002116 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk 2016-04-23 21:31 - 2015-12-11 10:00 - 00000572 _____ C:\Users\Public\Desktop\Winamp.lnk 2016-04-23 21:31 - 2015-12-06 13:15 - 00000820 _____ C:\Users\Public\Desktop\CCleaner.lnk 2016-04-23 21:31 - 2015-11-22 16:45 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-04-23 21:31 - 2015-11-22 16:45 - 00002001 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2016-04-23 21:31 - 2015-05-12 15:53 - 00001033 _____ C:\Users\Public\Desktop\PDF24 Creator.lnk 2016-04-23 21:31 - 2015-02-07 11:44 - 00002003 _____ C:\Users\Public\Desktop\ViewNX 2.lnk 2016-04-23 21:31 - 2014-12-30 17:18 - 00002049 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2014.lnk 2016-04-23 21:31 - 2014-11-14 23:58 - 00000954 _____ C:\Users\Public\Desktop\VLC media player.lnk 2016-04-23 21:31 - 2014-11-14 23:57 - 00001184 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk 2016-04-23 21:31 - 2014-06-24 13:59 - 00001055 _____ C:\Users\Admin\Desktop\DC-12 - Verknüpfung.lnk 2016-04-23 21:31 - 2014-01-29 11:59 - 00001866 _____ C:\Users\Public\Desktop\EPSON Smart Panel.lnk 2016-04-23 21:31 - 2013-12-31 13:22 - 00002049 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2013.lnk 2016-04-23 21:31 - 2013-11-14 22:20 - 00000924 _____ C:\Users\Public\Desktop\EPSON Scan.lnk 2016-04-23 21:31 - 2013-11-14 17:30 - 00001141 _____ C:\Users\Public\Desktop\Presto! BizCard 4.1.lnk 2016-04-23 21:31 - 2013-04-13 14:22 - 00001119 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-04-23 21:31 - 2013-04-13 14:22 - 00001101 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-04-23 21:31 - 2013-03-01 20:12 - 00001214 _____ C:\Users\Public\Desktop\BlazePhoto 2.0.1.lnk 2016-04-23 21:31 - 2013-02-13 12:18 - 00001862 _____ C:\Users\Public\Desktop\PDF24 Editor.lnk 2016-04-23 21:31 - 2013-02-13 12:18 - 00001013 _____ C:\Users\Public\Desktop\PDF24 Fax.lnk 2016-04-23 21:31 - 2012-10-06 16:09 - 00002087 _____ C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2012.lnk 2016-04-23 21:31 - 2012-10-06 14:09 - 00002033 _____ C:\Users\Public\Desktop\WISO Sparbuch 2010.lnk 2016-04-23 21:31 - 2012-09-05 16:05 - 00001958 _____ C:\Users\Admin\Desktop\P3170P Referenzhandbuch.lnk 2016-04-23 21:31 - 2012-09-05 16:04 - 00002092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 6.0 Professional.lnk 2016-04-23 18:47 - 2016-03-14 11:56 - 00000000 ____D C:\Program Files (x86)\Raptr Inc 2016-04-23 18:45 - 2011-10-11 17:06 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-04-23 18:41 - 2016-03-14 11:58 - 00004154 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{C8BD1A00-4BC1-4FCE-BCF1-FD980F22A11F} 2016-04-23 18:40 - 2016-02-04 06:12 - 02086168 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-04-23 18:40 - 2015-12-13 17:03 - 00000000 ____D C:\Users\Admin\AppData\Local\Packages 2016-04-23 18:40 - 2015-10-30 20:35 - 00888008 _____ C:\WINDOWS\system32\perfh007.dat 2016-04-23 18:40 - 2015-10-30 20:35 - 00197092 _____ C:\WINDOWS\system32\perfc007.dat 2016-04-23 18:40 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-04-23 18:40 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-04-23 18:40 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF 2016-04-23 18:39 - 2014-07-21 12:07 - 00000000 ____D C:\Program Files (x86)\Java 2016-04-23 18:39 - 2014-01-26 20:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-04-23 18:35 - 2016-03-14 11:57 - 00000000 ____D C:\Users\Admin\AppData\Roaming\PlaysTV 2016-04-23 18:35 - 2015-12-31 03:45 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update 2016-04-23 18:35 - 2015-12-03 12:55 - 00000728 __RSH C:\ProgramData\ntuser.pol 2016-04-23 18:33 - 2016-02-04 06:27 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-04-23 18:22 - 2015-10-30 08:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2016-04-23 18:19 - 2016-02-04 06:08 - 00000000 ____D C:\Program Files\AMD 2016-04-23 18:17 - 2015-12-13 16:36 - 00000000 ____D C:\AMD 2016-04-23 18:03 - 2016-03-23 08:06 - 00003186 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1458713193 2016-04-23 18:02 - 2012-05-05 18:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-04-23 18:01 - 2015-12-31 03:45 - 00287528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys 2016-04-23 18:00 - 2016-03-23 08:06 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2016-04-23 18:00 - 2015-12-31 03:45 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2016-04-23 18:00 - 2015-12-31 03:45 - 00465792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2016-04-23 18:00 - 2015-12-31 03:45 - 00166432 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys 2016-04-23 18:00 - 2015-12-31 03:45 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2016-04-23 18:00 - 2015-12-31 03:45 - 00103064 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2016-04-23 18:00 - 2015-12-31 03:45 - 00074544 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2016-04-23 18:00 - 2015-12-31 03:45 - 00037656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys 2016-04-23 00:47 - 2014-08-12 10:51 - 00000000 ____D C:\Users\Admin\AppData\Local\Adobe 2016-04-23 00:47 - 2012-05-07 18:40 - 00000000 ____D C:\ProgramData\Adobe 2016-04-23 00:47 - 2012-05-07 18:40 - 00000000 ____D C:\Program Files (x86)\Adobe 2016-04-23 00:47 - 2012-05-05 16:59 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Adobe 2016-04-23 00:46 - 2015-09-02 13:47 - 00000000 ____D C:\Users\Admin\.oracle_jre_usage 2016-04-23 00:46 - 2014-07-21 12:07 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-04-22 02:13 - 2012-10-12 18:03 - 00000000 ____D C:\Users\Admin\AppData\Roaming\vlc 2016-04-22 02:12 - 2015-06-24 14:27 - 00000000 ____D C:\Users\Admin\AppData\Roaming\dvdcss 2016-04-21 06:42 - 2016-02-04 06:13 - 00000000 ____D C:\Users\Admin 2016-04-21 06:42 - 2011-10-11 17:01 - 00000000 ____D C:\Users\Admin\AppData\Local\VirtualStore 2016-04-19 20:29 - 2014-01-26 20:04 - 00000000 ____D C:\ProgramData\Oracle 2016-04-18 05:34 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache 2016-04-13 17:32 - 2016-02-04 06:04 - 00264360 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-04-13 15:31 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-04-13 15:31 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-04-13 15:31 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2016-04-13 15:31 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-04-13 12:00 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-04-13 11:58 - 2013-08-15 03:01 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-04-13 11:53 - 2011-10-11 17:33 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-04-06 20:32 - 2015-10-30 09:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-04-06 20:32 - 2015-10-30 09:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-04-06 08:59 - 2015-12-06 13:44 - 00000000 ____D C:\externe Festplatte 2016-04-06 08:59 - 2006-12-01 11:50 - 00000000 ____D C:\alte eigene Dateien 2016-04-04 08:11 - 2013-04-14 18:05 - 00000000 ____D C:\Users\Admin\Documents\Mama+Papa 2016-03-29 13:12 - 2015-10-30 09:17 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe 2016-03-29 13:12 - 2015-10-30 09:17 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe 2016-03-29 13:12 - 2015-10-30 09:17 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe 2016-03-29 13:12 - 2015-10-30 09:17 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll 2016-03-29 13:12 - 2015-10-30 09:17 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-02-07 11:43 - 2015-02-07 11:43 - 0000268 ___RH () C:\Users\Admin\AppData\Roaming\Analog Swirl 2014-08-30 11:48 - 2014-08-30 11:48 - 0000038 _____ () C:\Users\Admin\AppData\Roaming\DVAP.set 2015-02-07 11:44 - 2015-02-07 11:44 - 0000268 ___RH () C:\Users\Admin\AppData\Roaming\libiconv 2015-02-07 11:44 - 2015-02-07 11:44 - 0000268 ___RH () C:\Users\Admin\AppData\Roaming\manual 2015-02-07 11:44 - 2015-02-07 11:44 - 0000268 ___RH () C:\Users\Admin\AppData\Roaming\programs 2015-02-07 14:57 - 2015-02-07 14:57 - 0003584 _____ () C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-04-20 22:22 - 2016-01-06 22:26 - 0007610 _____ () C:\Users\Admin\AppData\Local\Resmon.ResmonCfg 2015-02-07 11:44 - 2015-02-07 11:44 - 0000268 ___RH () C:\ProgramData\Abstract 2015-02-07 11:44 - 2015-02-07 11:44 - 0000268 ___RH () C:\ProgramData\AccountTypes 2015-02-07 11:44 - 2015-02-07 11:44 - 0000268 ___RH () C:\ProgramData\Action 2015-02-07 11:43 - 2015-02-07 11:43 - 0000268 ___RH () C:\ProgramData\Application 2015-02-07 11:43 - 2015-02-07 11:43 - 0000020 ____H () C:\ProgramData\PKP_DLeo.DAT 2015-02-07 11:44 - 2015-05-12 13:34 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT 2015-02-07 11:44 - 2015-11-09 16:20 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT 2015-02-07 11:44 - 2015-02-07 13:58 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT 2015-12-02 12:39 - 2015-12-09 09:38 - 0000074 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\Users\Admin\escanex.dll C:\Users\Admin\Setup.exe C:\Users\Admin\SkypeSetup.exe C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat Einige Dateien in TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\-uxyrrkd.dll C:\Users\Admin\AppData\Local\Temp\4wr4myxi.dll C:\Users\Admin\AppData\Local\Temp\a8kt3kca.dll C:\Users\Admin\AppData\Local\Temp\jre-8u77-windows-au.exe C:\Users\Admin\AppData\Local\Temp\playstv_patch.exe C:\Users\Admin\AppData\Local\Temp\raptrpatch.exe C:\Users\Admin\AppData\Local\Temp\raptr_stub.exe C:\Users\Admin\AppData\Local\Temp\tmp43D4.exe C:\Users\Admin\AppData\Local\Temp\tmpEDC.exe C:\Users\Admin\AppData\Local\Temp\zmuvh9tq.dll ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2016-04-21 02:34 ==================== Ende von FRST.txt ============================ Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:18-04-2016 durchgeführt von Admin (2016-04-23 22:28:34) Gestartet von C:\Users\Admin\Desktop Windows 10 Pro Version 1511 (X64) (2016-02-04 04:31:44) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Admin (S-1-5-21-540040400-2712554345-721507239-1000 - Administrator - Enabled) => C:\Users\Admin Administrator (S-1-5-21-540040400-2712554345-721507239-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-540040400-2712554345-721507239-503 - Limited - Disabled) Gast (S-1-5-21-540040400-2712554345-721507239-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-540040400-2712554345-721507239-1036 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) ABBYY FineReader 6.0 (HKLM-x32\...\{AF600F7B-67A7-48D9-BA3B-0FF97F35F970}) (Version: 6.0.759.29421 - ABBYY Software House) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.010.20060 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 21.0.0.198 - Adobe Systems Incorporated) Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.2.1.650 - Adobe Systems Incorporated) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated) Adobe Photoshop Elements 9 (HKLM-x32\...\Adobe Photoshop Elements 9) (Version: 9.0 - Adobe Systems Incorporated) AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) AMD Install Manager (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.4 - Advanced Micro Devices, Inc.) AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 4.0.0.0 - AppEx Networks) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.2.2261 - AVAST Software) BlazePhoto 2.0.1 (HKLM-x32\...\BlazePhoto 2.0.1_is1) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform) Cradle of Egypt (HKLM-x32\...\{2C02C8E3-CF3B-44BE-98C8-12A16EAF2713}_is1) (Version: - cerasus.media GmbH) Cradle of Rome 2 (HKLM-x32\...\{E60E8119-F64A-436B-8449-4FF87FC97350}_is1) (Version: - cerasus.media GmbH) Digital Camera Driver (HKLM-x32\...\Digital Camera Driver) (Version: - ) DVAPTray (HKLM-x32\...\{30D1B542-44E0-44F0-8A31-2A101CB626B5}) (Version: 2.3.2.31 - ) Elements 9 Organizer (x32 Version: 9.0 - Ihr Firmenname) Hidden Elements STI Installer (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden EPSON Copy Utility (HKLM-x32\...\{B69CC1A5-0404-11D6-ABCB-005004C21D30}) (Version: - ) EPSON Photo Print (HKLM-x32\...\{D379964B-685C-44D5-AE46-C953A9FEEA14}) (Version: - ) EPSON Scan (HKLM-x32\...\{0E0131B2-CF18-40D9-A331-60A3746C1204}) (Version: - ) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - ) EPSON Smart Panel (HKLM-x32\...\{6C11D561-620B-47DA-A693-4C597F3CDF40}) (Version: - ) Etron USB3.0 Host Controller (x32 Version: 0.101 - Etron Technology) Hidden ffdshow v1.1.3425 [2010-05-08] (HKLM-x32\...\ffdshow_is1) (Version: 1.1.3425.0 - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.) Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden HP LaserJet Professional CP1020 Series (HKLM\...\HP LaserJet Professional CP1020 Series) (Version: - ) HPLJUT (x32 Version: 1.00.0012 - HP) Hidden hppcp1025LaserJetService (HKLM-x32\...\{F31BF057-0D5E-485E-ADFD-560314A27912}) (Version: 1.00.0000 - Hewlett-Packard) hppLaserJetService (x32 Version: 007.015.00635 - Hewlett-Packard) Hidden Internet-TV für Windows Media Center (HKLM-x32\...\{9D318C86-AF4C-409F-A6AC-7183FF4CF424}) (Version: 4.2.2.0 - Microsoft Corporation) JAP (HKLM-x32\...\JAP) (Version: 00.18.001 - JAP-Team) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation) LibreOffice 5.0.3.2 (HKLM-x32\...\{D61E7AA0-0380-49B9-8DDD-7685E2306176}) (Version: 5.0.3.2 - The Document Foundation) Malwarebytes Anti-Malware Version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation) Mozilla Firefox 45.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 45.0.2 (x86 de)) (Version: 45.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.0.2.5941 - Mozilla) Namenslexikon (HKLM-x32\...\{4213F602-C9BB-48E2-B22F-3069C77EA605}_is1) (Version: 1.03 - YORAKO) NEF Codec (HKLM-x32\...\{D6506521-0959-4FA3-875F-E2E28830B0D2}) (Version: 1.27.0 - Nikon Corporation) Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon) Nikon Movie Editor (HKLM-x32\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.6.0 - Nikon) P3170P Referenzhandbuch (HKLM-x32\...\P3170P Referenzhandbuch) (Version: - ) PDF24 Creator 6.9.2 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Picture Control Utility x64 (HKLM\...\{11953C65-BB4E-4CA4-B0F0-2600A4B20040}) (Version: 1.4.7 - Nikon) PlaysTV (HKLM-x32\...\PlaysTV) (Version: 1.9.2-r111395-release - Plays.tv, LLC) Presto! BizCard 4.1 (Deutsch Version) (HKLM-x32\...\Uninstall Presto! BizCard 4.1 Ger) (Version: - ) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.38.113.2011 - Realtek) Realtek HDMI Audio Driver for ATI (HKLM-x32\...\{5449FB4F-1802-4D5B-A6D8-087DB1142147}) (Version: 6.0.1.6358 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6368 - Realtek Semiconductor Corp.) SafeZone Stable 1.48.2066.98 (x32 Version: 1.48.2066.98 - Avast Software) Hidden Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.) Startfenster (HKLM\...\Startfenster) (Version: - Startfenster) sysTPL (HKLM-x32\...\{4B74BC31-B353-4B8F-8CBE-DAB4FF326FF1}) (Version: 1.0.0 - Tlapia) <==== ACHTUNG ViewNX 2 (HKLM\...\{635BE602-BB9C-4C59-8CC5-93F9366E8A21}) (Version: 2.6.0 - Nikon) VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN) Wappenlexikon (HKLM-x32\...\Wappenlexikon) (Version: - ) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) Windows Media Center Add-in for Silverlight (HKLM-x32\...\{0EDBEB2B-7C8D-42E6-8312-0F84394A3223}) (Version: 4.7.3.0 - Microsoft Corporation) WISO Sparbuch 2010 (HKLM-x32\...\{46B70DEB-97B3-4E38-B746-EC16905E6A8F}) (Version: 17.00.6531 - Buhl Data Service GmbH) WISO Steuer-Sparbuch 2012 (HKLM-x32\...\{0CC1DAFB-40C8-4903-953D-471E541477C7}) (Version: 19.00.7303 - Buhl Data Service GmbH) WISO Steuer-Sparbuch 2013 (HKLM-x32\...\{D6CC2FAF-F827-4091-96A1-D32CC9B69C79}) (Version: 20.00.8137 - Buhl Data Service GmbH) WISO Steuer-Sparbuch 2014 (HKLM-x32\...\{AB70F5F9-AB44-411B-8310-5800EFDDA9EA}) (Version: 21.00.8480 - Buhl Data Service GmbH) WISO Steuer-Sparbuch 2015 (HKLM-x32\...\{EE6D8704-9D48-4FC3-A691-218D677C9F6C}) (Version: 22.00.8811 - Buhl Data Service GmbH) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-540040400-2712554345-721507239-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Admin\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation) ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {0B93DBD5-6F8A-4D1A-85D3-AB7B28E965CD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG Task: {14A0FCD7-1211-4BC8-9508-01B46CFF139E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated) Task: {18215BEF-A48D-4042-BFA4-C193C61E22D3} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG Task: {31367CE2-964C-4D90-93F7-EC6AA9FA3BD5} - System32\Tasks\avastBCLRestartS-1-5-21-540040400-2712554345-721507239-1000 => Firefox.exe Task: {323B5FC9-9DBA-45F8-B9A1-1B29BF87584D} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe Task: {329B659C-46E3-4003-9387-1A7EA5B1049A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-02] (Google Inc.) Task: {38416CA7-C264-4EDF-A162-38989005F689} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated) Task: {3E4D4157-B4CC-48BD-84D9-26E67110DCAD} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe Task: {412D63E9-7C48-4A13-A87C-7B72AB7B6995} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {46E8995C-BE9F-44AB-A094-7D150B3C22B8} - System32\Tasks\{0A5C81BD-E072-4D32-9DC6-512D69ABAA60} => Firefox.exe Task: {49285C46-088C-48A6-A93B-C4D411D2E9C8} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe Task: {4D345952-2C2E-4258-AC31-FA28DCAFC2B9} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe Task: {4DF417C0-13FE-4486-89C6-D14E2EDE1121} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG Task: {5463E111-6B9E-499F-9778-B545A2CFACF5} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe Task: {59CE1FFF-FF46-4174-BF1E-DA13CC3C812E} - System32\Tasks\{0F353B07-F163-4F6E-BE21-A4CFA1474839} => pcalua.exe -a C:\Users\Admin\Babylon\Utils\uninstbb.exe Task: {5AFF7F51-B4E5-4419-A58E-7DAECC25F994} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-02] (Google Inc.) Task: {5FADD56C-32BB-4AE6-8FC1-A97E4B267C90} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe Task: {65C1619E-8BBD-4698-8B08-6D5AB9411132} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe Task: {690F310B-9764-408B-834E-9EFEF9AEB403} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG Task: {6C323A28-9728-4B00-8737-C5619CB7BA85} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG Task: {725CE5BF-0C8A-44BF-A2E0-934F047F506A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-11-16] (Piriform Ltd) Task: {72FE48C8-4BF0-43EF-AE98-F4AF45CBBEF6} - System32\Tasks\{92EE3F88-280B-4749-9FCE-FAAD8FA734E1} => pcalua.exe -a "E:\Dokumente und Einstellungen\B. Unterweger-Bahr\Eigene Dateien\Ogame\japsetup12005.exe" -d "E:\Dokumente und Einstellungen\B. Unterweger-Bahr\Eigene Dateien\Ogame" Task: {7835F280-93BB-4F19-8AFD-76CB3713EDF6} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe Task: {8149B6A4-C2E4-44D4-8F0F-65FE7AA09A96} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {818E319A-10AC-456E-9E72-733086CC6F7C} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {823CABB1-72FD-4378-83AC-2A36DAADEA35} - System32\Tasks\{5CA77C06-D226-4007-ADB2-83D635592E9D} => E:\externe Festplatte\NauticTools\NauticTools\NauticTools.exe Task: {846EEFA0-1E47-4712-8827-3AD7DCE0BB5F} - System32\Tasks\HPLJCustParticipation => C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [2010-09-22] (Hewlett Packard) Task: {8655E296-5694-4099-9987-DC50B5440399} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-roland.unterweger@t-online.de => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-07-29] (Adobe Systems Incorporated) Task: {8CBA512E-8152-405D-AF7A-E9D832353B43} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG Task: {8CD4BDA6-09D7-489E-8E8D-D67F25FADFA1} - System32\Tasks\{3F922B6D-5D44-4BC4-86FE-2C459674C9F1} => pcalua.exe -a D:\EPSETUP.EXE -d D:\ Task: {90FC0D4C-C708-4C92-B856-47417505A6E6} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe Task: {92DCC69E-047D-4F95-B87B-F4E32E05285F} - System32\Tasks\{69EFE8EE-279E-469F-8DBD-C46822EF2531} => pcalua.exe -a "E:\Dokumente und Einstellungen\Roland Unterweger\NTools120.exe" -d "E:\Dokumente und Einstellungen\Roland Unterweger" Task: {934267CA-D0A3-4809-AEB4-9C31F44E2C02} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-04-23] (AVAST Software) Task: {94497B7A-9B65-4774-881D-2A3E465BF742} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {99EB08DD-077D-4214-BA2D-2F2318E563B7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG Task: {9AFFF787-52F5-4FEC-8861-0A252D036235} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe Task: {A39569E6-390D-4101-82F6-557866C555A3} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation) Task: {AEBF74A6-1D5E-461C-8834-FEF37D6BA5CF} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe Task: {AF757109-C1EA-493F-8142-7C554353CDD0} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe Task: {B8B4B42C-70A2-4A2A-B708-58A47F6D2868} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe Task: {BB4523D4-694F-4399-A309-4ED7198CDA56} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe Task: {C26FCE77-0012-4AD0-936F-D745C75AAB07} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG Task: {C506603D-7BE3-42C0-90ED-9C2C82E3D063} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe Task: {C712DC19-F803-43A7-AE88-AC246AC91617} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG Task: {C9919D4B-875B-4C0B-811E-B0E013B79F40} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {CA482785-6CB5-438F-BCCF-329DBC7C53F7} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe Task: {CF3121B4-AD77-4074-AF1B-7B57561280A9} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe Task: {D5E242E1-41AD-431A-BFF1-9E87F9662C25} - System32\Tasks\SafeZone scheduled Autoupdate 1458713193 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-03-30] (Avast Software) Task: {DBCC69D3-726B-4B42-B02E-FEBBA83D11F0} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe [2016-03-21] (Advanced Micro Devices, Inc.) Task: {DD1B8740-8A46-463A-ABAF-73A5EB07B809} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {E882533B-F5B8-403B-A209-CBE0D1140633} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG Task: {EFEE1C3B-05EF-4DC1-812C-6CD92D116E95} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe Task: {FD1C9DD5-8209-43CF-95A8-08CC8DCA1E11} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-01-20 02:53 - 2016-01-20 02:53 - 00137712 _____ () C:\WINDOWS\System32\HPCP1020LM.DLL 2015-08-04 01:25 - 2015-08-04 01:25 - 00214528 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll 2014-02-11 08:08 - 2014-02-11 08:08 - 00817152 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Device.dll 2014-02-11 08:08 - 2014-02-11 08:08 - 03650560 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Platform.dll 2015-12-02 12:39 - 2015-12-02 12:41 - 00149024 ____N () C:\Windows\system32\DnsBlockUpdateSvc.exe 2016-04-13 00:38 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-04-13 00:38 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-04-13 00:37 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-04-19 00:57 - 2016-04-19 00:57 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-02-04 05:58 - 2016-02-04 05:58 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-04-13 00:36 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2015-08-04 01:25 - 2015-08-04 01:25 - 00102400 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2016-04-13 00:37 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-04-13 00:37 - 2016-04-02 05:00 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2016-04-13 00:37 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-04-13 00:37 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-04-23 18:00 - 2016-04-23 18:00 - 00123344 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2016-04-23 18:00 - 2016-04-23 18:00 - 00135816 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-04-23 12:33 - 2016-04-23 12:33 - 02890240 _____ () C:\Program Files\AVAST Software\Avast\defs\16042300\algo.dll 2016-04-23 18:00 - 2016-04-23 18:00 - 00478144 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2015-11-24 22:48 - 2015-11-24 22:48 - 00028160 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\servicemanager.pyd 2015-11-24 22:46 - 2015-11-24 22:46 - 00110592 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\pywintypes26.dll 2015-11-24 22:48 - 2015-11-24 22:48 - 00041472 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32service.pyd 2015-11-24 22:48 - 2015-11-24 22:48 - 00096256 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32api.pyd 2015-11-24 22:43 - 2015-11-24 22:43 - 00356864 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\_hashlib.pyd 2015-11-24 22:48 - 2015-11-24 22:48 - 00017920 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32event.pyd 2015-11-24 22:48 - 2015-11-24 22:48 - 00019968 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32evtlog.pyd 2015-11-24 22:48 - 2015-11-24 22:48 - 00036352 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32process.pyd 2015-11-24 22:43 - 2015-11-24 22:43 - 00043008 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\_socket.pyd 2015-11-24 22:43 - 2015-11-24 22:43 - 00805376 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\_ssl.pyd 2015-11-24 22:43 - 2015-11-24 22:43 - 00087040 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\_ctypes.pyd 2015-11-24 22:46 - 2015-11-24 22:46 - 00354304 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\pythoncom26.dll 2015-11-24 22:48 - 2015-11-24 22:48 - 00167936 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32gui.pyd 2015-11-24 22:47 - 2015-11-24 22:47 - 01980928 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtGui.pyd 2015-12-07 22:57 - 2015-12-07 22:57 - 00077824 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\sip.pyd 2015-11-24 22:47 - 2015-11-24 22:47 - 01862144 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtCore.pyd 2015-11-24 22:47 - 2015-11-24 22:47 - 00516608 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtNetwork.pyd 2015-11-24 22:47 - 2015-11-24 22:47 - 04060160 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtWidgets.pyd 2015-11-24 22:43 - 2015-11-24 22:43 - 00010240 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\select.pyd 2016-04-19 00:57 - 2016-04-19 00:57 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-04-19 00:57 - 2016-04-19 00:57 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2015-12-31 03:45 - 2015-12-31 03:45 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-11-24 22:43 - 2015-11-24 22:43 - 00044544 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\_sqlite3.pyd 2015-11-24 22:43 - 2015-11-24 22:43 - 00387072 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\sqlite3.dll 2015-10-21 22:29 - 2015-10-21 22:29 - 00113171 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\libvlc.dll 2015-10-21 22:29 - 2015-10-21 22:29 - 02396691 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\libvlccore.dll 2015-11-24 22:48 - 2015-11-24 22:48 - 00111104 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32file.pyd 2015-11-24 22:47 - 2015-11-24 22:47 - 00216064 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtWebKitWidgets.pyd 2015-11-24 22:47 - 2015-11-24 22:47 - 00118784 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtWebKit.pyd 2015-11-24 22:47 - 2015-11-24 22:47 - 00199680 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtPrintSupport.pyd 2015-11-24 22:47 - 2015-11-24 22:47 - 00263168 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32com.shell.shell.pyd 2015-11-24 22:43 - 2015-11-24 22:43 - 00583680 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\unicodedata.pyd 2015-10-21 22:29 - 2015-10-21 22:29 - 00027667 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\plugins\audio_output\libdirectsound_plugin.dll 2015-10-21 22:29 - 2015-10-21 22:29 - 00031251 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\plugins\audio_output\libwaveout_plugin.dll 2015-10-21 22:29 - 2015-10-21 22:29 - 00066579 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\plugins\video_output\libdirectdraw_plugin.dll 2016-04-05 15:49 - 2016-04-05 15:49 - 02618120 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\ltc_host_ex.DLL ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\WINDOWS\system32\DnsBlockUpdateSvc.exe:IID [16] ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-540040400-2712554345-721507239-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Admin\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{cf1bb013-68d3-47a6-9f17-ad0dd1859df8}.JPG DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\Services: bthserv => 3 MSCONFIG\Services: TeamViewer8 => 2 MSCONFIG\Services: WMPNetworkSvc => 2 MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR MSCONFIG\startupreg: Nikon Message Center 2 => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s MSCONFIG\startupreg: PDFPrint => C:\Program Files (x86)\PDF24\pdf24.exe MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808 FirewallRules: [UDP Query User{E35CEE82-0A36-4C11-887C-E32D3FAB3CD3}C:\winamp\winamp.exe] => (Allow) C:\winamp\winamp.exe FirewallRules: [TCP Query User{F1C5CA4A-21DF-4FE5-ABEA-909A9ECB5FAE}C:\winamp\winamp.exe] => (Allow) C:\winamp\winamp.exe FirewallRules: [{8AE0FBC9-29BC-4BC6-9F6D-A2A3F4562D59}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{981C183F-32C2-44EE-BC76-89F1106933FC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{D99992E6-7CE5-4587-8605-D5D292613026}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{30A58B5E-5C0C-44DF-A036-CF68A56CCF6A}C:\winamp\winamp.exe] => (Block) C:\winamp\winamp.exe FirewallRules: [UDP Query User{21B02176-0505-4C46-B522-C9ABDA2515F5}C:\winamp\winamp.exe] => (Block) C:\winamp\winamp.exe FirewallRules: [{18627A34-7F6A-4BC2-BEE6-6FCDCFAECCF3}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{0B52CE7E-250E-4511-956F-6B1E8BB3E050}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{942E3EA5-1653-4D49-A093-55D6EE10BC6D}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{3C744211-175A-4563-B3D6-EC2C92573FDD}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{F67A11F0-757B-45FB-8D5F-9A52588792E3}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [{E451CEF5-F8BF-4259-86F8-61C83B2E6363}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [{B01C274B-C193-4368-9E37-7C2C4A68B97A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Wiederherstellungspunkte ========================= 09-04-2016 03:00:09 Windows-Sicherung 13-04-2016 00:38:30 Windows Update 16-04-2016 03:00:09 Windows-Sicherung 19-04-2016 22:34:13 Windows Update 23-04-2016 18:37:23 Removed Java 8 Update 77 ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (04/23/2016 06:38:10 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (04/23/2016 06:22:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 10.0.10586.0, Zeitstempel: 0x5632d7ba Name des fehlerhaften Moduls: ESENT.dll, Version: 10.0.10586.212, Zeitstempel: 0x56fa1686 Ausnahmecode: 0xc0000602 Fehleroffset: 0x000000000022885f ID des fehlerhaften Prozesses: 0xa00 Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0 Pfad der fehlerhaften Anwendung: svchost.exe1 Pfad des fehlerhaften Moduls: svchost.exe2 Berichtskennung: svchost.exe3 Vollständiger Name des fehlerhaften Pakets: svchost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe5 Error: (04/23/2016 06:22:25 PM) (Source: ESENT) (EventID: 908) (User: ) Description: svchost (2560) Der Prozess wird aufgrund eines nicht behebbaren Fehlers beendet: PV: 10.0.10586.0 SV: 10.0.10586.0 GLE: 0 ERR: -1054(tm.cxx:1630): dllentry.cxx(103) (ESENT[10.0.10586.0] RETAIL RTM MBCS) Error: (04/19/2016 10:34:31 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (04/19/2016 06:58:41 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (04/17/2016 09:37:31 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (04/16/2016 05:09:15 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (04/16/2016 03:00:28 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (04/14/2016 04:26:40 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (04/13/2016 08:13:01 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ADMIN-PC) Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Systemfehler: ============= Error: (04/23/2016 06:39:41 PM) (Source: DCOM) (EventID: 10016) (User: ADMIN-PC) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-540040400-2712554345-721507239-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (04/23/2016 06:39:41 PM) (Source: DCOM) (EventID: 10016) (User: ADMIN-PC) Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Admin-PCAdminS-1-5-21-540040400-2712554345-721507239-1000LocalHost (unter Verwendung von LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (04/23/2016 06:38:17 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Übermittlungsoptimierung" wurde nicht richtig gestartet. Error: (04/23/2016 06:33:38 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "NetTcpActivator" ist vom Dienst "NetTcpPortSharing" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (04/23/2016 06:22:27 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "StateRepository-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/23/2016 06:22:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Synchronisierungshost_35271 erreicht. Error: (04/23/2016 06:22:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Benutzerdatenspeicher _35271 erreicht. Error: (04/23/2016 06:22:13 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenzugriff_35271" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/23/2016 06:22:13 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Benutzerdatenspeicher _35271" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/23/2016 06:22:13 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Kontaktdaten_35271" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. CodeIntegrity: =================================== Date: 2016-04-14 21:10:13.654 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-04-13 17:34:52.428 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-04-13 14:25:25.684 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-29 13:24:31.352 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-29 13:06:06.327 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-24 23:47:59.960 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-15 03:02:33.078 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-14 10:48:43.779 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-12 04:33:11.349 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-04 13:18:38.445 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Speicherinformationen =========================== Prozessor: AMD A8-3870 APU with Radeon(tm) HD Graphics Prozentuale Nutzung des RAM: 54% Installierter physikalischer RAM: 3581.35 MB Verfügbarer physikalischer RAM: 1634.46 MB Summe virtueller Speicher: 7165.35 MB Verfügbarer virtueller Speicher: 4530.82 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:930.54 GB) (Free:726.61 GB) NTFS Drive d: (EREDV891) (CDROM) (Total:7.32 GB) (Free:0 GB) UDF Drive e: (Alte Bootplatte) (Fixed) (Total:285.28 GB) (Free:205.75 GB) NTFS Drive f: (RECOVER) (Fixed) (Total:12.8 GB) (Free:7.93 GB) FAT32 ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (Size: 298.1 GB) (Disk ID: 947C947C) Partition 1: (Active) - (Size=285.3 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=12.8 GB) - (Type=OF Extended) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: D2863A1C) Partition 1: (Active) - (Size=95 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=930.5 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ==================== Ende von Addition.txt ============================ |
23.04.2016, 21:47 | #4 |
| Download Protect und ich kann es nicht entfernen 22:45:01.0877 0x0778 TDSS rootkit removing tool 3.1.0.9 Dec 11 2015 22:49:12 22:45:06.0351 0x0778 ============================================================ 22:45:06.0351 0x0778 Current date / time: 2016/04/23 22:45:06.0351 22:45:06.0351 0x0778 SystemInfo: 22:45:06.0351 0x0778 22:45:06.0351 0x0778 OS Version: 10.0.10586 ServicePack: 0.0 22:45:06.0351 0x0778 Product type: Workstation 22:45:06.0351 0x0778 ComputerName: ADMIN-PC 22:45:06.0351 0x0778 UserName: Admin 22:45:06.0351 0x0778 Windows directory: C:\WINDOWS 22:45:06.0351 0x0778 System windows directory: C:\WINDOWS 22:45:06.0351 0x0778 Running under WOW64 22:45:06.0351 0x0778 Processor architecture: Intel x64 22:45:06.0351 0x0778 Number of processors: 4 22:45:06.0351 0x0778 Page size: 0x1000 22:45:06.0351 0x0778 Boot type: Normal boot 22:45:06.0351 0x0778 ============================================================ 22:45:06.0377 0x0778 KLMD registered as C:\WINDOWS\system32\drivers\88357116.sys 22:45:06.0631 0x0778 System UUID: {2C92D9CA-174C-3C14-5C32-D8FD424A7CDF} 22:45:07.0098 0x0778 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:45:07.0120 0x0778 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:45:07.0125 0x0778 ============================================================ 22:45:07.0125 0x0778 \Device\Harddisk1\DR1: 22:45:07.0130 0x0778 MBR partitions: 22:45:07.0130 0x0778 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x2F800 22:45:07.0130 0x0778 \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x30000, BlocksNum 0x74514800 22:45:07.0130 0x0778 \Device\Harddisk0\DR0: 22:45:07.0136 0x0778 MBR partitions: 22:45:07.0136 0x0778 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x23A8F9FA 22:45:07.0157 0x0778 \Device\Harddisk0\DR0\Partition2: MBR, Type 0xB, StartLBA 0x23A8FA78, BlocksNum 0x199DC49 22:45:07.0157 0x0778 ============================================================ 22:45:07.0186 0x0778 C: <-> \Device\Harddisk1\DR1\Partition2 22:45:07.0215 0x0778 E: <-> \Device\Harddisk0\DR0\Partition1 22:45:07.0215 0x0778 F: <-> \Device\Harddisk0\DR0\Partition2 22:45:07.0215 0x0778 ============================================================ 22:45:07.0216 0x0778 Initialize success 22:45:07.0216 0x0778 ============================================================ 22:46:11.0294 0x1dd4 ============================================================ 22:46:11.0294 0x1dd4 Scan started 22:46:11.0294 0x1dd4 Mode: Manual; SigCheck; TDLFS; 22:46:11.0294 0x1dd4 ============================================================ 22:46:11.0294 0x1dd4 KSN ping started 22:46:13.0679 0x1dd4 KSN ping finished: true 22:46:14.0347 0x1dd4 ================ Scan system memory ======================== 22:46:14.0347 0x1dd4 System memory - ok 22:46:14.0347 0x1dd4 ================ Scan services ============================= 22:46:14.0519 0x1dd4 1394ohci - ok 22:46:14.0529 0x1dd4 3ware - ok 22:46:14.0549 0x1dd4 ACPI - ok 22:46:14.0558 0x1dd4 acpiex - ok 22:46:14.0566 0x1dd4 acpipagr - ok 22:46:14.0575 0x1dd4 AcpiPmi - ok 22:46:14.0580 0x1dd4 acpitime - ok 22:46:14.0680 0x1dd4 [ C004F38974F4D321B4C20A240E1175C0, FCCABDF4397AC56D5AE794584384039BAFD3B67FD47C56F4F9491C9175C60763 ] AdobeActiveFileMonitor9.0 C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe 22:46:14.0757 0x1dd4 AdobeActiveFileMonitor9.0 - ok 22:46:14.0847 0x1dd4 [ F2CEEE9ABBCEF207ACB103215AC28BC2, F8F8B8AF6317926D7AC0CA2CA23628B2C69327A2792D58D3328443C5ED9514E9 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 22:46:14.0870 0x1dd4 AdobeARMservice - ok 22:46:14.0980 0x1dd4 [ 28FFB14117CCEDD7D2F124596AA9B785, 8FC482C6444C904B5536979B3354597FD714634EC7372B464118C42AA9DCB58A ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 22:46:15.0015 0x1dd4 AdobeFlashPlayerUpdateSvc - ok 22:46:15.0025 0x1dd4 ADP80XX - ok 22:46:15.0044 0x1dd4 AFD - ok 22:46:15.0049 0x1dd4 agp440 - ok 22:46:15.0057 0x1dd4 ahcache - ok 22:46:15.0081 0x1dd4 AJRouter - ok 22:46:15.0095 0x1dd4 ALG - ok 22:46:15.0175 0x1dd4 [ B12D8F8A42080B955D027EE56F5BD1C3, AA4763AF1D77F7F1FF3BFEC5B800E7E38F954C1488B19ED645B04FEC4D771A1C ] AMD FUEL Service C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe 22:46:15.0220 0x1dd4 AMD FUEL Service - detected UnsignedFile.Multi.Generic ( 1 ) 22:46:17.0553 0x1dd4 Detect skipped due to KSN trusted 22:46:17.0553 0x1dd4 AMD FUEL Service - ok 22:46:17.0568 0x1dd4 AmdK8 - ok 22:46:17.0620 0x1dd4 [ BE258C17CFD09F4210602105432E784A, FD38B50785206D6E5EADE65396030E18C8B9D993D7225057B0C24F3256BCE2E3 ] amdkmafd C:\WINDOWS\system32\drivers\amdkmafd.sys 22:46:17.0710 0x1dd4 amdkmafd - ok 22:46:17.0730 0x1dd4 amdkmdag - ok 22:46:17.0766 0x1dd4 [ AD96CC96B6A0CEE8910A13679426C970, 18005892C57CF8F3B2F09C3DDEC10612EC9B1C14BB057196AAE209D2703FF06E ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys 22:46:17.0798 0x1dd4 amdkmdap - ok 22:46:17.0800 0x1dd4 AmdPPM - ok 22:46:17.0805 0x1dd4 amdsata - ok 22:46:17.0810 0x1dd4 amdsbs - ok 22:46:17.0815 0x1dd4 amdxata - ok 22:46:17.0848 0x1dd4 [ F9D46B6B322708BD5AFCC8767EBDC901, BD4872A62516D8326D43FD37A8BECEBADB80C51CD79506FD8A2013358710F774 ] amd_sata C:\WINDOWS\system32\drivers\amd_sata.sys 22:46:17.0877 0x1dd4 amd_sata - ok 22:46:17.0882 0x1dd4 [ 329CC9C7E20DEEBCD4CD10816193EF14, FA217536D56EA0BFC783FC29919F529A9AF8E0F7B2A49AA452B218BC6F1E0366 ] amd_xata C:\WINDOWS\system32\drivers\amd_xata.sys 22:46:17.0900 0x1dd4 amd_xata - ok 22:46:17.0905 0x1dd4 [ C3D487827E48CC5EC17994FEC5BDFF87, 5FCEA3EEA583755D0C9F6005ED3032E9DFECB57F504DC67701AE7D2D2631C30E ] AODDriver4.3 C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys 22:46:17.0940 0x1dd4 AODDriver4.3 - ok 22:46:17.0955 0x1dd4 AppHostSvc - ok 22:46:17.0974 0x1dd4 AppID - ok 22:46:17.0977 0x1dd4 AppIDSvc - ok 22:46:17.0983 0x1dd4 Appinfo - ok 22:46:17.0991 0x1dd4 AppMgmt - ok 22:46:17.0997 0x1dd4 AppReadiness - ok 22:46:18.0015 0x1dd4 AppXSvc - ok 22:46:18.0040 0x1dd4 [ CF6E96336D3B247AB48F28CC570B83D8, B606BE7A2127E8FD3C7DFFEE844EFC8ABCBD08FE48384692B7B5928970AD54E3 ] APXACC C:\WINDOWS\system32\DRIVERS\appexDrv.sys 22:46:18.0065 0x1dd4 APXACC - ok 22:46:18.0070 0x1dd4 arcsas - ok 22:46:18.0151 0x1dd4 aspnet_state - ok 22:46:18.0187 0x1dd4 [ E5328558BE05B811182D59F4089B714B, 4BE87689ED5BFA574BAD227E336E351C27A9BF592EE84DC9B95C8BA57D1D2353 ] aswHwid C:\WINDOWS\system32\drivers\aswHwid.sys 22:46:18.0220 0x1dd4 aswHwid - ok 22:46:18.0252 0x1dd4 [ EEB944CD13080499C1EF5D767528CA5A, 7C10FE6021FF7A2F9DFEE03C194FEE6059887D3B0B5DA9776B0465215A322FDC ] aswKbd C:\WINDOWS\system32\drivers\aswKbd.sys 22:46:18.0277 0x1dd4 aswKbd - ok 22:46:18.0305 0x1dd4 [ A273F835D2AE124272C3BFE466AB2429, 2D2CE3C55D58609BF5BAA1CE7F4511CB71D6C9060CECAD447AB18867516F8356 ] aswMonFlt C:\WINDOWS\system32\drivers\aswMonFlt.sys 22:46:18.0330 0x1dd4 aswMonFlt - ok 22:46:18.0350 0x1dd4 [ FF306A66730CA45FEF817941AC9F1084, D9D1BBF8EEA3B7C845447DE74BA27B6748DD670272C27520E58580FBE6F35105 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr2.sys 22:46:18.0375 0x1dd4 aswRdr - ok 22:46:18.0380 0x1dd4 [ 0E83A1C5E193D91A0FE921A744EA2DFC, FD189EAB85485B80440DEEB7F31C880B03A802CCCCC7F9A4DAFC84F4EA1DA036 ] aswRvrt C:\WINDOWS\system32\drivers\aswRvrt.sys 22:46:18.0416 0x1dd4 aswRvrt - ok 22:46:18.0471 0x1dd4 [ 7160A228193B2EC718D369C281294AAD, 5397BD2180F0BD1F6CF857C43B4E04BF478DE5846B9627B91231D1D52A43FA23 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys 22:46:18.0531 0x1dd4 aswSnx - ok 22:46:18.0594 0x1dd4 [ 856ACBBDAEA6D9713C549E719BB6CFCB, 9B2F874AD10CBB9890B2C64ABD584D687D818F79591894C776325950A483426D ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys 22:46:18.0656 0x1dd4 aswSP - ok 22:46:18.0736 0x1dd4 [ 5C2B44C00B9550710B8418A5CF4AB18B, 1888A27F9F705855EF355246C7A4E0C0DB9AFEC9715EE6FB4FDE002C63EA5D3F ] aswStm C:\WINDOWS\system32\drivers\aswStm.sys 22:46:18.0776 0x1dd4 aswStm - ok 22:46:18.0826 0x1dd4 [ E460CE13920CF1D88E4967543FB4592C, 284498B2A0C6032A686F41151CABCBB01903EDE4E6D808EB28E3DF284EDE114F ] aswVmm C:\WINDOWS\system32\drivers\aswVmm.sys 22:46:18.0851 0x1dd4 aswVmm - ok 22:46:18.0861 0x1dd4 AsyncMac - ok 22:46:18.0866 0x1dd4 atapi - ok 22:46:18.0888 0x1dd4 [ 2A38B5218A7BE3CE0E0B3D92E3844782, 2B0799EF6E5A5EE65AC91E394F6C0EDE95067BB96567FD25DA0C003F9FB7E84E ] AtiHDAudioService C:\WINDOWS\system32\drivers\AtihdWT6.sys 22:46:18.0911 0x1dd4 AtiHDAudioService - ok 22:46:18.0941 0x1dd4 AudioEndpointBuilder - ok 22:46:18.0946 0x1dd4 Audiosrv - ok 22:46:19.0016 0x1dd4 [ A6F08BF95CC9A5D581532E320EBC95B5, 5A07ABC8857446344E7BC8C7F2246512758A1E7176CFE1516BE68431C9D7DAD3 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe 22:46:19.0046 0x1dd4 avast! Antivirus - ok 22:46:19.0051 0x1dd4 AxInstSV - ok 22:46:19.0056 0x1dd4 b06bdrv - ok 22:46:19.0061 0x1dd4 BasicDisplay - ok 22:46:19.0066 0x1dd4 BasicRender - ok 22:46:19.0076 0x1dd4 bcmfn - ok 22:46:19.0081 0x1dd4 bcmfn2 - ok 22:46:19.0097 0x1dd4 BDESVC - ok 22:46:19.0111 0x1dd4 Beep - ok 22:46:19.0126 0x1dd4 BFE - ok 22:46:19.0141 0x1dd4 BITS - ok 22:46:19.0146 0x1dd4 bowser - ok 22:46:19.0151 0x1dd4 BrokerInfrastructure - ok 22:46:19.0156 0x1dd4 Browser - ok 22:46:19.0166 0x1dd4 BthAvrcpTg - ok 22:46:19.0171 0x1dd4 BthHFEnum - ok 22:46:19.0176 0x1dd4 bthhfhid - ok 22:46:19.0198 0x1dd4 BthHFSrv - ok 22:46:19.0201 0x1dd4 BTHMODEM - ok 22:46:19.0206 0x1dd4 bthserv - ok 22:46:19.0216 0x1dd4 buttonconverter - ok 22:46:19.0226 0x1dd4 CapImg - ok 22:46:19.0231 0x1dd4 cdfs - ok 22:46:19.0236 0x1dd4 CDPSvc - ok 22:46:19.0241 0x1dd4 cdrom - ok 22:46:19.0246 0x1dd4 CertPropSvc - ok 22:46:19.0256 0x1dd4 circlass - ok 22:46:19.0261 0x1dd4 CLFS - ok 22:46:19.0266 0x1dd4 ClipSVC - ok 22:46:19.0281 0x1dd4 CmBatt - ok 22:46:19.0290 0x1dd4 CNG - ok 22:46:19.0296 0x1dd4 cnghwassist - ok 22:46:19.0357 0x1dd4 CompositeBus - ok 22:46:19.0372 0x1dd4 COMSysApp - ok 22:46:19.0398 0x1dd4 condrv - ok 22:46:19.0406 0x1dd4 CoreMessagingRegistrar - ok 22:46:19.0436 0x1dd4 CryptSvc - ok 22:46:19.0436 0x1dd4 CSC - ok 22:46:19.0446 0x1dd4 CscService - ok 22:46:19.0451 0x1dd4 dam - ok 22:46:19.0461 0x1dd4 DcomLaunch - ok 22:46:19.0466 0x1dd4 DcpSvc - ok 22:46:19.0471 0x1dd4 defragsvc - ok 22:46:19.0476 0x1dd4 DeviceAssociationService - ok 22:46:19.0481 0x1dd4 DeviceInstall - ok 22:46:19.0488 0x1dd4 DevQueryBroker - ok 22:46:19.0495 0x1dd4 Dfsc - ok 22:46:19.0501 0x1dd4 Dhcp - ok 22:46:19.0521 0x1dd4 diagnosticshub.standardcollector.service - ok 22:46:19.0536 0x1dd4 DiagTrack - ok 22:46:19.0541 0x1dd4 disk - ok 22:46:19.0561 0x1dd4 DmEnrollmentSvc - ok 22:46:19.0566 0x1dd4 dmvsc - ok 22:46:19.0571 0x1dd4 dmwappushservice - ok 22:46:19.0576 0x1dd4 Dnscache - ok 22:46:19.0587 0x1dd4 dot3svc - ok 22:46:19.0592 0x1dd4 DPS - ok 22:46:19.0615 0x1dd4 drmkaud - ok 22:46:19.0620 0x1dd4 DsmSvc - ok 22:46:19.0635 0x1dd4 DsSvc - ok 22:46:19.0650 0x1dd4 DXGKrnl - ok 22:46:19.0655 0x1dd4 Eaphost - ok 22:46:19.0660 0x1dd4 ebdrv - ok 22:46:19.0665 0x1dd4 EFS - ok 22:46:19.0670 0x1dd4 EhStorClass - ok 22:46:19.0675 0x1dd4 EhStorTcgDrv - ok 22:46:19.0690 0x1dd4 embeddedmode - ok 22:46:19.0697 0x1dd4 EntAppSvc - ok 22:46:19.0703 0x1dd4 ErrDev - ok 22:46:19.0710 0x1dd4 EventSystem - ok 22:46:19.0715 0x1dd4 exfat - ok 22:46:19.0720 0x1dd4 fastfat - ok 22:46:19.0725 0x1dd4 Fax - ok 22:46:19.0735 0x1dd4 fdc - ok 22:46:19.0740 0x1dd4 fdPHost - ok 22:46:19.0745 0x1dd4 FDResPub - ok 22:46:19.0750 0x1dd4 fhsvc - ok 22:46:19.0755 0x1dd4 FileCrypt - ok 22:46:19.0760 0x1dd4 FileInfo - ok 22:46:19.0765 0x1dd4 Filetrace - ok 22:46:19.0770 0x1dd4 flpydisk - ok 22:46:19.0775 0x1dd4 FltMgr - ok 22:46:19.0780 0x1dd4 FontCache - ok 22:46:19.0835 0x1dd4 FontCache3.0.0.0 - ok 22:46:19.0855 0x1dd4 FsDepends - ok 22:46:19.0870 0x1dd4 Fs_Rec - ok 22:46:19.0885 0x1dd4 fvevol - ok 22:46:19.0890 0x1dd4 gagp30kx - ok 22:46:19.0902 0x1dd4 gencounter - ok 22:46:19.0909 0x1dd4 genericusbfn - ok 22:46:19.0915 0x1dd4 GPIOClx0101 - ok 22:46:19.0920 0x1dd4 gpsvc - ok 22:46:19.0930 0x1dd4 GpuEnergyDrv - ok 22:46:20.0011 0x1dd4 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:46:20.0041 0x1dd4 gupdate - ok 22:46:20.0046 0x1dd4 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:46:20.0061 0x1dd4 gupdatem - ok 22:46:20.0071 0x1dd4 HDAudBus - ok 22:46:20.0076 0x1dd4 HidBatt - ok 22:46:20.0081 0x1dd4 HidBth - ok 22:46:20.0086 0x1dd4 hidi2c - ok 22:46:20.0091 0x1dd4 hidinterrupt - ok 22:46:20.0098 0x1dd4 HidIr - ok 22:46:20.0103 0x1dd4 hidserv - ok 22:46:20.0108 0x1dd4 HidUsb - ok 22:46:20.0126 0x1dd4 HomeGroupListener - ok 22:46:20.0136 0x1dd4 HomeGroupProvider - ok 22:46:20.0196 0x1dd4 [ CC1A58B54BCFFF376C3901BC8BEC1E22, CE40C382DC4F49B19F261DE0B8B989CCCC3A952B9B3A051D1A54E0B966BD0677 ] HP LaserJet Service C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe 22:46:20.0210 0x1dd4 HP LaserJet Service - detected UnsignedFile.Multi.Generic ( 1 ) 22:46:22.0569 0x1dd4 Detect skipped due to KSN trusted 22:46:22.0569 0x1dd4 HP LaserJet Service - ok 22:46:22.0579 0x1dd4 HpSAMD - ok 22:46:22.0624 0x1dd4 [ D26D7D9D6B2B447BDC35ACE9ADBBE7E1, 7CFCF14CFCBF62AF5182A07642840BC78815360CA5143DBB7614F259021F2A17 ] HPSIService C:\Windows\system32\HPSIsvc.exe 22:46:22.0669 0x1dd4 HPSIService - detected UnsignedFile.Multi.Generic ( 1 ) 22:46:25.0120 0x0ecc Object required for P2P: [ E5328558BE05B811182D59F4089B714B ] aswHwid 22:46:25.0154 0x1dd4 Detect skipped due to KSN trusted 22:46:25.0154 0x1dd4 HPSIService - ok 22:46:25.0174 0x1dd4 HTTP - ok 22:46:25.0189 0x1dd4 hwpolicy - ok 22:46:25.0194 0x1dd4 hyperkbd - ok 22:46:25.0199 0x1dd4 i8042prt - ok 22:46:25.0204 0x1dd4 iai2c - ok 22:46:25.0209 0x1dd4 iaLPSS2i_I2C - ok 22:46:25.0219 0x1dd4 iaLPSSi_GPIO - ok 22:46:25.0224 0x1dd4 iaLPSSi_I2C - ok 22:46:25.0229 0x1dd4 iaStorAV - ok 22:46:25.0234 0x1dd4 iaStorV - ok 22:46:25.0239 0x1dd4 ibbus - ok 22:46:25.0259 0x1dd4 icssvc - ok 22:46:25.0269 0x1dd4 IEEtwCollectorService - ok 22:46:25.0274 0x1dd4 IKEEXT - ok 22:46:25.0369 0x1dd4 [ 8F6ED52134EBB4CE2953EC37C9275497, 5381A9CBB0C05F447E6DCD18EAF195A6CDC934A04792C8865814A46E5B883308 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys 22:46:25.0439 0x1dd4 IntcAzAudAddService - ok 22:46:25.0449 0x1dd4 intelide - ok 22:46:25.0454 0x1dd4 intelpep - ok 22:46:25.0459 0x1dd4 intelppm - ok 22:46:25.0464 0x1dd4 IoQos - ok 22:46:25.0469 0x1dd4 IpFilterDriver - ok 22:46:25.0484 0x1dd4 iphlpsvc - ok 22:46:25.0489 0x1dd4 IPMIDRV - ok 22:46:25.0494 0x1dd4 IPNAT - ok 22:46:25.0499 0x1dd4 IRENUM - ok 22:46:25.0504 0x1dd4 isapnp - ok 22:46:25.0509 0x1dd4 iScsiPrt - ok 22:46:25.0514 0x1dd4 kbdclass - ok 22:46:25.0519 0x1dd4 kbdhid - ok 22:46:25.0524 0x1dd4 kdnic - ok 22:46:25.0529 0x1dd4 KeyIso - ok 22:46:25.0534 0x1dd4 KSecDD - ok 22:46:25.0550 0x1dd4 KSecPkg - ok 22:46:25.0554 0x1dd4 ksthunk - ok 22:46:25.0570 0x1dd4 KtmRm - ok 22:46:25.0575 0x1dd4 LanmanServer - ok 22:46:25.0580 0x1dd4 LanmanWorkstation - ok 22:46:25.0590 0x1dd4 lfsvc - ok 22:46:25.0595 0x1dd4 LicenseManager - ok 22:46:25.0600 0x1dd4 lltdio - ok 22:46:25.0605 0x1dd4 lltdsvc - ok 22:46:25.0610 0x1dd4 lmhosts - ok 22:46:25.0620 0x1dd4 LSI_SAS - ok 22:46:25.0625 0x1dd4 LSI_SAS2i - ok 22:46:25.0630 0x1dd4 LSI_SAS3i - ok 22:46:25.0635 0x1dd4 LSI_SSS - ok 22:46:25.0640 0x1dd4 LSM - ok 22:46:25.0646 0x1dd4 luafv - ok 22:46:25.0651 0x1dd4 MapsBroker - ok 22:46:25.0685 0x1dd4 [ 78488AF2AB2111D67B3C4044707A519B, 7AA71B9C4C7949A1A21F60EF7CCEDE0079794990696B60557B5DC86F4D47223A ] MBAMSwissArmy C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys 22:46:25.0725 0x1dd4 MBAMSwissArmy - ok 22:46:25.0730 0x1dd4 megasas - ok 22:46:25.0735 0x1dd4 megasr - ok 22:46:25.0740 0x1dd4 MessagingService - ok 22:46:25.0784 0x1dd4 mf - ok 22:46:25.0794 0x1dd4 mlx4_bus - ok 22:46:25.0799 0x1dd4 MMCSS - ok 22:46:25.0804 0x1dd4 Modem - ok 22:46:25.0809 0x1dd4 monitor - ok 22:46:25.0814 0x1dd4 mouclass - ok 22:46:25.0819 0x1dd4 mouhid - ok 22:46:25.0824 0x1dd4 mountmgr - ok 22:46:25.0865 0x1dd4 [ 63282F5EB7E5BFB58FD1EC93C6ADB457, 25096C4AE319E854153C75DCEC0A67A63F6B05FDD0B49D4D373724B3BF55D665 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 22:46:25.0875 0x1dd4 MozillaMaintenance - ok 22:46:25.0880 0x1dd4 mpsdrv - ok 22:46:25.0903 0x1dd4 MpsSvc - ok 22:46:25.0913 0x1dd4 MQAC - ok 22:46:25.0927 0x1dd4 MRxDAV - ok 22:46:25.0937 0x1dd4 mrxsmb - ok 22:46:25.0951 0x1dd4 mrxsmb10 - ok 22:46:25.0956 0x1dd4 mrxsmb20 - ok 22:46:25.0959 0x1dd4 MsBridge - ok 22:46:25.0965 0x1dd4 MSDTC - ok 22:46:25.0975 0x1dd4 Msfs - ok 22:46:25.0980 0x1dd4 msgpiowin32 - ok 22:46:26.0030 0x1dd4 mshidkmdf - ok 22:46:26.0035 0x1dd4 mshidumdf - ok 22:46:26.0040 0x1dd4 msisadrv - ok 22:46:26.0046 0x1dd4 MSiSCSI - ok 22:46:26.0052 0x1dd4 msiserver - ok 22:46:26.0057 0x1dd4 MSKSSRV - ok 22:46:26.0059 0x1dd4 MsLldp - ok 22:46:26.0079 0x1dd4 MSMQ - ok 22:46:26.0084 0x1dd4 MSPCLOCK - ok 22:46:26.0089 0x1dd4 MSPQM - ok 22:46:26.0094 0x1dd4 MsRPC - ok 22:46:26.0104 0x1dd4 mssmbios - ok 22:46:26.0109 0x1dd4 MSTEE - ok 22:46:26.0114 0x1dd4 MTConfig - ok 22:46:26.0119 0x1dd4 Mup - ok 22:46:26.0124 0x1dd4 mvumis - ok 22:46:26.0159 0x1dd4 [ AE4C156F78251158AE01CA4F1377F0E8, A72458303D4A46A18C080220791E88DE5B6C0EB726533FB57BBD0C7D56B7093E ] mvusbews C:\WINDOWS\System32\Drivers\mvusbews.sys 22:46:26.0185 0x1dd4 mvusbews - ok 22:46:26.0190 0x1dd4 NativeWifiP - ok 22:46:26.0217 0x1dd4 NcaSvc - ok 22:46:26.0222 0x1dd4 NcbService - ok 22:46:26.0227 0x1dd4 NcdAutoSetup - ok 22:46:26.0232 0x1dd4 ndfltr - ok 22:46:26.0242 0x1dd4 NDIS - ok 22:46:26.0248 0x1dd4 NdisCap - ok 22:46:26.0253 0x1dd4 NdisImPlatform - ok 22:46:26.0259 0x1dd4 NdisTapi - ok 22:46:26.0265 0x1dd4 Ndisuio - ok 22:46:26.0270 0x1dd4 NdisVirtualBus - ok 22:46:26.0275 0x1dd4 NdisWan - ok 22:46:26.0280 0x1dd4 ndiswanlegacy - ok 22:46:26.0285 0x1dd4 ndproxy - ok 22:46:26.0290 0x1dd4 Ndu - ok 22:46:26.0325 0x1dd4 [ 8C17F3795DAE9A0ECDE4B3A3B0740E5F, 65807F2EEB7E60E1A7EFB4AEC9BB20C7121E8754E9001616DF919E5EA8B7C541 ] nduvjyw C:\WINDOWS\system32\drivers\dsmrhitk.sys 22:46:26.0348 0x1dd4 nduvjyw - ok 22:46:26.0353 0x1dd4 NetBIOS - ok 22:46:26.0359 0x1dd4 NetBT - ok 22:46:26.0365 0x1dd4 Netlogon - ok 22:46:26.0370 0x1dd4 Netman - ok 22:46:26.0396 0x1dd4 NetMsmqActivator - ok 22:46:26.0402 0x1dd4 NetPipeActivator - ok 22:46:26.0407 0x1dd4 netprofm - ok 22:46:26.0418 0x1dd4 NetSetupSvc - ok 22:46:26.0418 0x1dd4 NetTcpActivator - ok 22:46:26.0423 0x1dd4 NetTcpPortSharing - ok 22:46:26.0433 0x1dd4 NgcCtnrSvc - ok 22:46:26.0438 0x1dd4 NgcSvc - ok 22:46:26.0443 0x1dd4 NlaSvc - ok 22:46:26.0460 0x1dd4 [ 2F48AB72B6D554A41817020171DC53D6, 1A38EB92C47A3481E27BE91DDC525952A8B01C0D2B7327116C5F78703A75105A ] NmPar C:\WINDOWS\system32\DRIVERS\NmPar.sys 22:46:26.0498 0x1dd4 NmPar - ok 22:46:26.0503 0x1dd4 Npfs - ok 22:46:26.0508 0x1dd4 npsvctrig - ok 22:46:26.0513 0x1dd4 nsi - ok 22:46:26.0518 0x1dd4 nsiproxy - ok 22:46:26.0538 0x1dd4 NTFS - ok 22:46:26.0543 0x1dd4 Null - ok 22:46:26.0553 0x1dd4 nvraid - ok 22:46:26.0558 0x1dd4 nvstor - ok 22:46:26.0560 0x1dd4 nv_agp - ok 22:46:26.0580 0x1dd4 OneSyncSvc - ok 22:46:26.0610 0x1dd4 p2pimsvc - ok 22:46:26.0615 0x1dd4 p2psvc - ok 22:46:26.0651 0x1dd4 Parport - ok 22:46:26.0655 0x1dd4 partmgr - ok 22:46:26.0660 0x1dd4 PcaSvc - ok 22:46:26.0665 0x1dd4 pci - ok 22:46:26.0670 0x1dd4 pciide - ok 22:46:26.0675 0x1dd4 pcmcia - ok 22:46:26.0680 0x1dd4 pcw - ok 22:46:26.0685 0x1dd4 pdc - ok 22:46:26.0695 0x1dd4 PEAUTH - ok 22:46:26.0710 0x1dd4 PeerDistSvc - ok 22:46:26.0715 0x1dd4 percsas2i - ok 22:46:26.0720 0x1dd4 percsas3i - ok 22:46:26.0785 0x1dd4 PerfHost - ok 22:46:26.0805 0x1dd4 PhoneSvc - ok 22:46:26.0825 0x1dd4 PimIndexMaintenanceSvc - ok 22:46:26.0852 0x1dd4 pla - ok 22:46:26.0906 0x1dd4 [ 9B6D836FD84C34C9E751D0888A367625, 4DC5FC3B8813A19CD64C1B470272C1392BA56A7DCA7514F483C95A7022C8E17C ] PlaysService C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe 22:46:26.0921 0x1dd4 PlaysService - ok 22:46:26.0921 0x1dd4 PlugPlay - ok 22:46:26.0926 0x1dd4 PNRPAutoReg - ok 22:46:26.0931 0x1dd4 PNRPsvc - ok 22:46:26.0941 0x1dd4 PolicyAgent - ok 22:46:26.0950 0x1dd4 Power - ok 22:46:26.0955 0x1dd4 PptpMiniport - ok 22:46:27.0080 0x1dd4 [ 959F94AD1255BC749884EDDD14EC29C4, 2CD6DA9778EA36FA0B4080F6DB1C634712238E014E47546403CD3CDB35A1DCA8 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll 22:46:27.0210 0x1dd4 PrintNotify - ok 22:46:27.0220 0x1dd4 Processor - ok 22:46:27.0225 0x1dd4 ProfSvc - ok 22:46:27.0230 0x1dd4 Psched - ok 22:46:27.0265 0x1dd4 [ 87B04878A6D59D6C79251DC960C674C1, 3EB8DB0624E646F0A65D0381408D35CF9FDC5ABFC30DF6431F4070A8EB68447C ] PxHlpa64 C:\WINDOWS\system32\Drivers\PxHlpa64.sys 22:46:27.0285 0x1dd4 PxHlpa64 - ok 22:46:27.0290 0x1dd4 QWAVE - ok 22:46:27.0300 0x1dd4 QWAVEdrv - ok 22:46:27.0305 0x1dd4 RasAcd - ok 22:46:27.0310 0x1dd4 RasAgileVpn - ok 22:46:27.0330 0x1dd4 RasAuto - ok 22:46:27.0340 0x1dd4 Rasl2tp - ok 22:46:27.0345 0x1dd4 RasMan - ok 22:46:27.0350 0x1dd4 RasPppoe - ok 22:46:27.0356 0x1dd4 RasSstp - ok 22:46:27.0360 0x1dd4 rdbss - ok 22:46:27.0370 0x1dd4 rdpbus - ok 22:46:27.0375 0x1dd4 RDPDR - ok 22:46:27.0385 0x1dd4 RdpVideoMiniport - ok 22:46:27.0390 0x1dd4 rdyboost - ok 22:46:27.0395 0x1dd4 ReFSv1 - ok 22:46:27.0435 0x1dd4 RemoteAccess - ok 22:46:27.0440 0x1dd4 RemoteRegistry - ok 22:46:27.0458 0x1dd4 RetailDemo - ok 22:46:27.0460 0x1dd4 RpcEptMapper - ok 22:46:27.0465 0x1dd4 RpcLocator - ok 22:46:27.0470 0x1dd4 RpcSs - ok 22:46:27.0475 0x1dd4 rspndr - ok 22:46:27.0480 0x1dd4 rt640x64 - ok 22:46:27.0485 0x1dd4 s3cap - ok 22:46:27.0495 0x1dd4 SamSs - ok 22:46:27.0500 0x1dd4 sbp2port - ok 22:46:27.0505 0x1dd4 SCardSvr - ok 22:46:27.0510 0x1dd4 ScDeviceEnum - ok 22:46:27.0515 0x1dd4 scfilter - ok 22:46:27.0520 0x1dd4 Schedule - ok 22:46:27.0525 0x1dd4 SCPolicySvc - ok 22:46:27.0530 0x1dd4 sdbus - ok 22:46:27.0535 0x1dd4 SDRSVC - ok 22:46:27.0553 0x1dd4 sdstor - ok 22:46:27.0557 0x1dd4 seclogon - ok 22:46:27.0560 0x1dd4 SENS - ok 22:46:27.0565 0x1dd4 SensorDataService - ok 22:46:27.0585 0x1dd4 SensorService - ok 22:46:27.0585 0x1dd4 SensrSvc - ok 22:46:27.0595 0x1dd4 SerCx - ok 22:46:27.0600 0x1dd4 SerCx2 - ok 22:46:27.0600 0x0ecc Object send P2P result: true 22:46:27.0600 0x0ecc Object required for P2P: [ 7160A228193B2EC718D369C281294AAD ] aswSnx 22:46:27.0615 0x1dd4 Serenum - ok 22:46:27.0630 0x1dd4 Serial - ok 22:46:27.0635 0x1dd4 sermouse - ok 22:46:27.0650 0x1dd4 SessionEnv - ok 22:46:27.0660 0x1dd4 sfloppy - ok 22:46:27.0660 0x1dd4 SharedAccess - ok 22:46:27.0690 0x1dd4 ShellHWDetection - ok 22:46:27.0695 0x1dd4 SiSRaid2 - ok 22:46:27.0700 0x1dd4 SiSRaid4 - ok 22:46:27.0740 0x1dd4 [ 52F7E8603E888E3DB0A8B3D1804098E9, 4E23DC9442C0C14AAE7146DACBB0B39743F1FFAA463EE7069CCDF866AD27BD77 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 22:46:27.0760 0x1dd4 SkypeUpdate - ok 22:46:27.0765 0x1dd4 smphost - ok 22:46:27.0770 0x1dd4 SmsRouter - ok 22:46:27.0785 0x1dd4 SNMPTRAP - ok 22:46:27.0790 0x1dd4 spaceport - ok 22:46:27.0795 0x1dd4 SpbCx - ok 22:46:27.0800 0x1dd4 Spooler - ok 22:46:27.0805 0x1dd4 sppsvc - ok 22:46:27.0810 0x1dd4 srv - ok 22:46:27.0815 0x1dd4 srv2 - ok 22:46:27.0820 0x1dd4 srvnet - ok 22:46:27.0825 0x1dd4 SSDPSRV - ok 22:46:27.0830 0x1dd4 SstpSvc - ok 22:46:27.0852 0x1dd4 StateRepository - ok 22:46:27.0856 0x1dd4 stexstor - ok 22:46:27.0865 0x1dd4 stisvc - ok 22:46:27.0870 0x1dd4 storahci - ok 22:46:27.0875 0x1dd4 storflt - ok 22:46:27.0880 0x1dd4 stornvme - ok 22:46:27.0885 0x1dd4 storqosflt - ok 22:46:27.0890 0x1dd4 StorSvc - ok 22:46:27.0895 0x1dd4 storufs - ok 22:46:27.0900 0x1dd4 storvsc - ok 22:46:27.0905 0x1dd4 svsvc - ok 22:46:27.0910 0x1dd4 swenum - ok 22:46:27.0915 0x1dd4 swprv - ok 22:46:27.0935 0x1dd4 Synth3dVsc - ok 22:46:27.0940 0x1dd4 SysMain - ok 22:46:27.0965 0x1dd4 SystemEventsBroker - ok 22:46:27.0997 0x1dd4 TabletInputService - ok 22:46:28.0002 0x1dd4 TapiSrv - ok 22:46:28.0017 0x1dd4 Tcpip - ok 22:46:28.0022 0x1dd4 Tcpip6 - ok 22:46:28.0032 0x1dd4 tcpipreg - ok 22:46:28.0060 0x1dd4 tdx - ok 22:46:28.0060 0x1dd4 terminpt - ok 22:46:28.0065 0x1dd4 TermService - ok 22:46:28.0070 0x1dd4 Themes - ok 22:46:28.0075 0x1dd4 TieringEngineService - ok 22:46:28.0138 0x1dd4 tiledatamodelsvc - ok 22:46:28.0151 0x1dd4 TimeBroker - ok 22:46:28.0160 0x1dd4 TPM - ok 22:46:28.0170 0x1dd4 TrkWks - ok 22:46:28.0200 0x1dd4 TrustedInstaller - ok 22:46:28.0205 0x1dd4 tsusbflt - ok 22:46:28.0215 0x1dd4 TsUsbGD - ok 22:46:28.0220 0x1dd4 tunnel - ok 22:46:28.0261 0x1dd4 tzautoupdate - ok 22:46:28.0266 0x1dd4 uagp35 - ok 22:46:28.0271 0x1dd4 UASPStor - ok 22:46:28.0276 0x1dd4 UcmCx0101 - ok 22:46:28.0281 0x1dd4 UcmUcsi - ok 22:46:28.0286 0x1dd4 Ucx01000 - ok 22:46:28.0291 0x1dd4 UdeCx - ok 22:46:28.0296 0x1dd4 udfs - ok 22:46:28.0301 0x1dd4 UEFI - ok 22:46:28.0306 0x1dd4 Ufx01000 - ok 22:46:28.0311 0x1dd4 UfxChipidea - ok 22:46:28.0316 0x1dd4 ufxsynopsys - ok 22:46:28.0331 0x1dd4 UI0Detect - ok 22:46:28.0336 0x1dd4 uliagpkx - ok 22:46:28.0341 0x1dd4 umbus - ok 22:46:28.0346 0x1dd4 UmPass - ok 22:46:28.0352 0x1dd4 UmRdpService - ok 22:46:28.0370 0x1dd4 UnistoreSvc - ok 22:46:28.0390 0x1dd4 upnphost - ok 22:46:28.0395 0x1dd4 UrsChipidea - ok 22:46:28.0400 0x1dd4 UrsCx01000 - ok 22:46:28.0405 0x1dd4 UrsSynopsys - ok 22:46:28.0410 0x1dd4 usbccgp - ok 22:46:28.0415 0x1dd4 usbcir - ok 22:46:28.0420 0x1dd4 usbehci - ok 22:46:28.0425 0x1dd4 usbhub - ok 22:46:28.0430 0x1dd4 USBHUB3 - ok 22:46:28.0435 0x1dd4 usbohci - ok 22:46:28.0445 0x1dd4 usbprint - ok 22:46:28.0471 0x1dd4 [ D67B6A4A6FB99D29444C2DBA2B636799, 62BC778D60593B2AB0DA13C4DB3EA5971895AE09DA06E8AB2D03973C940C890C ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 22:46:28.0501 0x1dd4 usbscan - ok 22:46:28.0520 0x1dd4 usbser - ok 22:46:28.0525 0x1dd4 USBSTOR - ok 22:46:28.0530 0x1dd4 usbuhci - ok 22:46:28.0535 0x1dd4 USBXHCI - ok 22:46:28.0552 0x1dd4 UserDataSvc - ok 22:46:28.0596 0x1dd4 UserManager - ok 22:46:28.0601 0x1dd4 UsoSvc - ok 22:46:28.0606 0x1dd4 VaultSvc - ok 22:46:28.0611 0x1dd4 vdrvroot - ok 22:46:28.0616 0x1dd4 vds - ok 22:46:28.0621 0x1dd4 VerifierExt - ok 22:46:28.0631 0x1dd4 vhdmp - ok 22:46:28.0636 0x1dd4 vhf - ok 22:46:28.0641 0x1dd4 vmbus - ok 22:46:28.0647 0x1dd4 VMBusHID - ok 22:46:28.0666 0x1dd4 vmicguestinterface - ok 22:46:28.0671 0x1dd4 vmicheartbeat - ok 22:46:28.0676 0x1dd4 vmickvpexchange - ok 22:46:28.0681 0x1dd4 vmicrdv - ok 22:46:28.0686 0x1dd4 vmicshutdown - ok 22:46:28.0691 0x1dd4 vmictimesync - ok 22:46:28.0696 0x1dd4 vmicvmsession - ok 22:46:28.0701 0x1dd4 vmicvss - ok 22:46:28.0706 0x1dd4 volmgr - ok 22:46:28.0716 0x1dd4 volmgrx - ok 22:46:28.0721 0x1dd4 volsnap - ok 22:46:28.0726 0x1dd4 vpci - ok 22:46:28.0731 0x1dd4 vsmraid - ok 22:46:28.0736 0x1dd4 VSS - ok 22:46:28.0741 0x1dd4 VSTXRAID - ok 22:46:28.0747 0x1dd4 vwifibus - ok 22:46:28.0752 0x1dd4 vwififlt - ok 22:46:28.0757 0x1dd4 W32Time - ok 22:46:28.0776 0x1dd4 w3logsvc - ok 22:46:28.0796 0x1dd4 W3SVC - ok 22:46:28.0801 0x1dd4 WacomPen - ok 22:46:28.0806 0x1dd4 WalletService - ok 22:46:28.0811 0x1dd4 wanarp - ok 22:46:28.0816 0x1dd4 wanarpv6 - ok 22:46:28.0821 0x1dd4 WAS - ok 22:46:28.0831 0x1dd4 wbengine - ok 22:46:28.0836 0x1dd4 WbioSrvc - ok 22:46:28.0841 0x1dd4 Wcmsvc - ok 22:46:28.0846 0x1dd4 wcncsvc - ok 22:46:28.0851 0x1dd4 WcsPlugInService - ok 22:46:28.0857 0x1dd4 WdBoot - ok 22:46:28.0860 0x1dd4 Wdf01000 - ok 22:46:28.0866 0x1dd4 WdFilter - ok 22:46:28.0871 0x1dd4 WdiServiceHost - ok 22:46:28.0876 0x1dd4 WdiSystemHost - ok 22:46:28.0881 0x1dd4 wdiwifi - ok 22:46:28.0886 0x1dd4 WdNisDrv - ok 22:46:28.0916 0x1dd4 WdNisSvc - ok 22:46:28.0921 0x1dd4 WebClient - ok 22:46:28.0926 0x1dd4 Wecsvc - ok 22:46:28.0931 0x1dd4 WEPHOSTSVC - ok 22:46:28.0936 0x1dd4 wercplsupport - ok 22:46:28.0941 0x1dd4 WerSvc - ok 22:46:28.0948 0x1dd4 WFPLWFS - ok 22:46:28.0953 0x1dd4 WiaRpc - ok 22:46:28.0958 0x1dd4 WIMMount - ok 22:46:28.0961 0x1dd4 WinDefend - ok 22:46:28.0971 0x1dd4 WindowsTrustedRT - ok 22:46:28.0976 0x1dd4 WindowsTrustedRTProxy - ok 22:46:28.0981 0x1dd4 WinHttpAutoProxySvc - ok 22:46:28.0986 0x1dd4 WinMad - ok 22:46:29.0006 0x1dd4 Winmgmt - ok 22:46:29.0021 0x1dd4 WinRM - ok 22:46:29.0031 0x1dd4 WINUSB - ok 22:46:29.0036 0x1dd4 WinVerbs - ok 22:46:29.0041 0x1dd4 WlanSvc - ok 22:46:29.0050 0x1dd4 wlidsvc - ok 22:46:29.0056 0x1dd4 WmiAcpi - ok 22:46:29.0061 0x1dd4 wmiApSrv - ok 22:46:29.0081 0x1dd4 WMPNetworkSvc - ok 22:46:29.0096 0x1dd4 [ 2A9650FCC696DB28E45EA8B33B99B8E6, FBEBC6C05D50F578C6EEE0A7285EBE1DEADB08DD21FA3232630FD8D5A68FC3FB ] Wof C:\WINDOWS\system32\drivers\Wof.sys 22:46:29.0126 0x1dd4 Wof - ok 22:46:29.0150 0x1dd4 workfolderssvc - ok 22:46:29.0155 0x1dd4 wpcfltr - ok 22:46:29.0161 0x1dd4 WPDBusEnum - ok 22:46:29.0166 0x1dd4 WpdUpFltr - ok 22:46:29.0171 0x1dd4 WpnService - ok 22:46:29.0176 0x1dd4 ws2ifsl - ok 22:46:29.0181 0x1dd4 wscsvc - ok 22:46:29.0186 0x1dd4 WSearch - ok 22:46:29.0196 0x1dd4 WSService - ok 22:46:29.0201 0x1dd4 wuauserv - ok 22:46:29.0206 0x1dd4 WudfPf - ok 22:46:29.0211 0x1dd4 WUDFRd - ok 22:46:29.0216 0x1dd4 wudfsvc - ok 22:46:29.0221 0x1dd4 WUDFWpdMtp - ok 22:46:29.0226 0x1dd4 WwanSvc - ok 22:46:29.0231 0x1dd4 XblAuthManager - ok 22:46:29.0236 0x1dd4 XblGameSave - ok 22:46:29.0241 0x1dd4 xboxgip - ok 22:46:29.0254 0x1dd4 XboxNetApiSvc - ok 22:46:29.0271 0x1dd4 xinputhid - ok 22:46:29.0271 0x1dd4 ================ Scan global =============================== 22:46:29.0301 0x1dd4 [ Global ] - ok 22:46:29.0306 0x1dd4 ================ Scan MBR ================================== 22:46:29.0321 0x1dd4 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1 22:46:29.0659 0x1dd4 \Device\Harddisk1\DR1 - ok 22:46:29.0676 0x1dd4 [ 72B8CE41AF0DE751C946802B3ED844B4 ] \Device\Harddisk0\DR0 22:46:29.0941 0x1dd4 \Device\Harddisk0\DR0 - ok 22:46:29.0941 0x1dd4 ================ Scan VBR ================================== 22:46:29.0949 0x1dd4 [ 0CCB758B89B99A79D9D4B54EA2BD0B3A ] \Device\Harddisk1\DR1\Partition1 22:46:29.0996 0x1dd4 \Device\Harddisk1\DR1\Partition1 - ok 22:46:30.0006 0x1dd4 [ DF5975FEE59530314E405D7DDBF879FB ] \Device\Harddisk1\DR1\Partition2 22:46:30.0050 0x1dd4 \Device\Harddisk1\DR1\Partition2 - ok 22:46:30.0055 0x1dd4 [ 930809843C2C3F700044D41D1536394F ] \Device\Harddisk0\DR0\Partition1 22:46:30.0057 0x1dd4 \Device\Harddisk0\DR0\Partition1 - ok 22:46:30.0061 0x1dd4 [ 36DF3921F8CAB4FCB718D856046BB8E5 ] \Device\Harddisk0\DR0\Partition2 22:46:30.0061 0x1dd4 \Device\Harddisk0\DR0\Partition2 - ok 22:46:30.0066 0x1dd4 ================ Scan generic autorun ====================== 22:46:30.0101 0x0ecc Object send P2P result: true 22:46:30.0101 0x0ecc Object required for P2P: [ 856ACBBDAEA6D9713C549E719BB6CFCB ] aswSP 22:46:30.0448 0x1dd4 [ 21C497180254D3CDCF9984FA19F6EBA8, 824495B97516B32A7B35C33162BCBA2D91F70A5C4F691BA74AB70EA0766D623C ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe 22:46:30.0691 0x1dd4 RtHDVCpl - ok 22:46:30.0858 0x1dd4 [ BB7481A1306823D1B6592263F1AB8DD7, 2D48A5DD217D81E99D134580721A1BC65EEFFB22FE9D2C03EAA3D9879F86A5D5 ] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe 22:46:30.0878 0x1dd4 AdobeAAMUpdater-1.0 - ok 22:46:31.0147 0x1dd4 [ 9C52D679C44539A7BB6694CA0166D84C, 685B79E1D7BD5DC2474FECBA7C431A57717403DEF957FC823888AE32F5060E6E ] C:\Program Files\AVAST Software\Avast\AvastUI.exe 22:46:31.0322 0x1dd4 AvastUI.exe - ok 22:46:31.0402 0x1dd4 [ 0D4BF3F447E9DA85F1A06027FE80E613, 3E8F3B281CA6597309C3E73731907EB368E472BAB573B50F010F573CE2919394 ] C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe 22:46:31.0427 0x1dd4 PlaysTV - ok 22:46:31.0512 0x1dd4 [ D5DDC3EC0BF960389E9A964D7CC8CC30, 02C06CF596B33B1883C371EA9B61B1EC41319EFF853A54864329129699534769 ] C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe 22:46:31.0532 0x1dd4 StartCCC - ok 22:46:31.0562 0x1dd4 [ 6513807FEE68E6C32E67437EE3FFB6C8, 2AB388BD68E984C38EAAF2D42DE918A64B42DA229627FC0B1A896A8AD60B5F91 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe 22:46:31.0582 0x1dd4 SunJavaUpdateSched - ok 22:46:31.0672 0x1dd4 [ 297C1BDCC26ADB339D4C0F0550E434D6, EFF4EC2543421BE537B1EDC8E88CFF7C529F3774F54BD9A71CCDB33EE9ED6370 ] C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \mbamdor.exe 22:46:31.0697 0x1dd4 Malwarebytes Anti-Malware (cleanup) - ok 22:46:31.0773 0x1dd4 OneDriveSetup - ok 22:46:31.0779 0x1dd4 OneDriveSetup - ok 22:46:31.0907 0x1dd4 [ 61F488AC3053DEB2AADB6A34DEBC8876, B5C5E0325F0FB4A37E80F08273B7483630F676C6342519564798CE7D1F121CB7 ] C:\Users\Admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe 22:46:31.0942 0x1dd4 OneDrive - ok 22:46:31.0994 0x1dd4 [ BDAE453D2EBCCDE40FC17F3094A43E29, B4642A62F78B3034D51ED8A60BD1353D269A62FCF14AF4FFA87DC7E02A6CC7A0 ] C:\Program Files\AMD Quick Stream\AMDQuickStream.exe 22:46:32.0034 0x1dd4 AppEx Accelerator UI - ok 22:46:32.0054 0x1dd4 Uninstall C:\Users\Admin\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64 - ok 22:46:32.0059 0x1dd4 OneDriveSetup - ok 22:46:32.0074 0x1dd4 WAB Migrate - ok 22:46:32.0075 0x1dd4 Waiting for KSN requests completion. In queue: 28 22:46:32.0615 0x0ecc Object send P2P result: true 22:46:32.0615 0x0ecc Object required for P2P: [ A6F08BF95CC9A5D581532E320EBC95B5 ] avast! Antivirus 22:46:33.0078 0x1dd4 Waiting for KSN requests completion. In queue: 24 22:46:34.0081 0x1dd4 Waiting for KSN requests completion. In queue: 24 22:46:34.0413 0x0df4 Object required for P2P: [ 63282F5EB7E5BFB58FD1EC93C6ADB457 ] MozillaMaintenance 22:46:35.0063 0x0ecc Object send P2P result: true 22:46:35.0083 0x1dd4 Waiting for KSN requests completion. In queue: 19 22:46:36.0086 0x1dd4 Waiting for KSN requests completion. In queue: 19 22:46:36.0878 0x0df4 Object send P2P result: true 22:46:36.0883 0x0df4 Object required for P2P: [ 9C52D679C44539A7BB6694CA0166D84C ] C:\Program Files\AVAST Software\Avast\AvastUI.exe 22:46:37.0087 0x1dd4 Waiting for KSN requests completion. In queue: 7 22:46:38.0090 0x1dd4 Waiting for KSN requests completion. In queue: 7 22:46:39.0091 0x1dd4 Waiting for KSN requests completion. In queue: 7 22:46:40.0091 0x1dd4 Waiting for KSN requests completion. In queue: 7 22:46:41.0092 0x1dd4 Waiting for KSN requests completion. In queue: 7 22:46:42.0096 0x1dd4 Waiting for KSN requests completion. In queue: 7 22:46:43.0100 0x1dd4 Waiting for KSN requests completion. In queue: 7 22:46:43.0329 0x0df4 Object send P2P result: true 22:46:44.0137 0x1dd4 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.9.10586.0 ), 0x60100 ( disabled : updated ) 22:46:44.0137 0x1dd4 AV detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 11.2.2732.0 ), 0x41000 ( enabled : updated ) 22:46:44.0147 0x1dd4 Win FW state via NFP2: enabled ( trusted ) 22:46:46.0529 0x1dd4 ============================================================ 22:46:46.0529 0x1dd4 Scan finished 22:46:46.0529 0x1dd4 ============================================================ 22:46:46.0552 0x0538 Detected object count: 0 22:46:46.0552 0x0538 Actual detected object count: 0 |
24.04.2016, 15:03 | #5 |
/// TB-Ausbilder | Download Protect und ich kann es nicht entfernen Servus, Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 4
Bitte poste mit deiner nächsten Antwort
|
27.04.2016, 15:54 | #6 |
/// TB-Ausbilder | Download Protect und ich kann es nicht entfernen Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen! |
Themen zu Download Protect und ich kann es nicht entfernen |
andere, anderen, anti, bedrohungen, board, brauche, download, download protect, dringend, enfernt, entferne, entfernen, erstell, erstellt, heulen, hilfe, logdatei, nicht, poste, protect, runtergeladen, schritt, troja, trojaner, trojaner board |