sucuk187 | 19.03.2017 13:57 | Hallo Matthias, vielen dank für deine schnelle Hilfe.
Ich habe über Nacht die den Windows Defender durchlaufen lassen und der hat auf jeden fall etwas gefunden leider kann ich nicht mehr einsehen was. Ich habe auf Löschen geklickt und dabei habe ich den Verlauf gelöscht.. Ich hoffe das ist nicht weiter schlimm.
Hier der TDSS-Killer Log Code:
13:44:46.0474 0x0440 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
13:44:50.0513 0x0440 ============================================================
13:44:50.0513 0x0440 Current date / time: 2017/03/19 13:44:50.0513
13:44:50.0513 0x0440 SystemInfo:
13:44:50.0543 0x0440
13:44:50.0543 0x0440 OS Version: 10.0.14393 ServicePack: 0.0
13:44:50.0543 0x0440 Product type: Workstation
13:44:50.0543 0x0440 ComputerName: SERGIOS-PC
13:44:50.0543 0x0440 UserName: Sergio
13:44:50.0543 0x0440 Windows directory: C:\WINDOWS
13:44:50.0543 0x0440 System windows directory: C:\WINDOWS
13:44:50.0543 0x0440 Running under WOW64
13:44:50.0543 0x0440 Processor architecture: Intel x64
13:44:50.0543 0x0440 Number of processors: 4
13:44:50.0543 0x0440 Page size: 0x1000
13:44:50.0543 0x0440 Boot type: Normal boot
13:44:50.0543 0x0440 CodeIntegrityOptions = 0x00000001
13:44:50.0543 0x0440 ============================================================
13:44:50.0913 0x0440 KLMD registered as C:\WINDOWS\system32\drivers\13766342.sys
13:44:50.0914 0x0440 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.693, osProperties = 0x19
13:44:52.0059 0x0440 System UUID: {3B441CB5-699C-2BC2-2078-741C976A80E1}
13:44:53.0071 0x0440 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:44:53.0158 0x0440 Drive \Device\Harddisk1\DR1 - Size: 0x1DCF856000 ( 119.24 Gb ), SectorSize: 0x200, Cylinders: 0x3CCE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:44:53.0171 0x0440 Drive \Device\Harddisk2\DR2 - Size: 0x53D67B6000 ( 335.35 Gb ), SectorSize: 0x200, Cylinders: 0xAB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:44:53.0187 0x0440 ============================================================
13:44:53.0187 0x0440 \Device\Harddisk0\DR0:
13:44:53.0216 0x0440 MBR partitions:
13:44:53.0216 0x0440 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
13:44:53.0216 0x0440 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
13:44:53.0216 0x0440 \Device\Harddisk1\DR1:
13:44:53.0247 0x0440 MBR partitions:
13:44:53.0247 0x0440 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xC869DB3
13:44:53.0247 0x0440 \Device\Harddisk2\DR2:
13:44:53.0254 0x0440 MBR partitions:
13:44:53.0254 0x0440 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xC7FF800
13:44:53.0254 0x0440 \Device\Harddisk2\DR2\Partition2: MBR, Type 0x7, StartLBA 0xC800000, BlocksNum 0x13880000
13:44:53.0296 0x0440 ============================================================
13:44:53.0402 0x0440 C: <-> \Device\Harddisk1\DR1\Partition1
13:44:53.0557 0x0440 D: <-> \Device\Harddisk0\DR0\Partition1
13:44:53.0835 0x0440 E: <-> \Device\Harddisk0\DR0\Partition2
13:44:53.0869 0x0440 F: <-> \Device\Harddisk2\DR2\Partition2
13:44:53.0906 0x0440 H: <-> \Device\Harddisk2\DR2\Partition1
13:44:53.0906 0x0440 ============================================================
13:44:53.0906 0x0440 Initialize success
13:44:53.0906 0x0440 ============================================================
13:45:27.0517 0x26f4 ============================================================
13:45:27.0517 0x26f4 Scan started
13:45:27.0517 0x26f4 Mode: Manual; SigCheck; TDLFS;
13:45:27.0517 0x26f4 ============================================================
13:45:27.0517 0x26f4 KSN ping started
13:45:27.0583 0x26f4 KSN ping finished: true
13:45:30.0246 0x26f4 ================ Scan system memory ========================
13:45:30.0246 0x26f4 System memory - ok
13:45:30.0247 0x26f4 ================ Scan services =============================
13:45:30.0412 0x26f4 1394ohci - ok
13:45:30.0422 0x26f4 3ware - ok
13:45:30.0458 0x26f4 ACPI - ok
13:45:30.0478 0x26f4 AcpiDev - ok
13:45:30.0482 0x26f4 acpiex - ok
13:45:30.0495 0x26f4 acpipagr - ok
13:45:30.0544 0x26f4 AcpiPmi - ok
13:45:30.0554 0x26f4 acpitime - ok
13:45:30.0752 0x26f4 [ 52997B1282BDAFC4275874B8990F9BE3, CFC4CD1EA75ADFC94E0B5623DDBBE38FC72162217DBEDB07EF5243CE5EEBEA4E ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
13:45:30.0852 0x26f4 AdobeARMservice - ok
13:45:33.0661 0x26f4 [ 7EB7A3B01751889C6459C51A74CC87FA, 088EF5CA10D439905822A3DFFEFD2D3416198F10EAAF8C235771CDB3DF86E82C ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
13:45:33.0680 0x26f4 AdobeFlashPlayerUpdateSvc - ok
13:45:33.0723 0x26f4 ADP80XX - ok
13:45:33.0749 0x26f4 AFD - ok
13:45:33.0775 0x26f4 ahcache - ok
13:45:33.0808 0x26f4 AJRouter - ok
13:45:33.0841 0x26f4 ALG - ok
13:45:33.0957 0x26f4 [ D7A72B9BA6AB996DADB37BFCB0363D63, A223684978928B59D39DFB49F6658E0CF04ADD15AD8ACFCEC384DBD4D8C8CBCA ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
13:45:34.0075 0x26f4 AMD External Events Utility - ok
13:45:34.0411 0x26f4 [ B12D8F8A42080B955D027EE56F5BD1C3, AA4763AF1D77F7F1FF3BFEC5B800E7E38F954C1488B19ED645B04FEC4D771A1C ] AMD FUEL Service C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
13:45:34.0524 0x26f4 AMD FUEL Service - detected UnsignedFile.Multi.Generic ( 1 )
13:45:34.0610 0x26f4 Detect skipped due to KSN trusted
13:45:34.0610 0x26f4 AMD FUEL Service - ok
13:45:34.0633 0x26f4 AmdK8 - ok
13:45:34.0708 0x26f4 [ 83ADF64C5BEAC0A065D7D2811E9A79CA, C724DC6EC9CB0E93DC034054FFB79284E70502FA155EFF624E112243F6C8D8E8 ] amdkmafd C:\WINDOWS\system32\drivers\amdkmafd.sys
13:45:34.0733 0x26f4 amdkmafd - ok
13:45:34.0774 0x26f4 amdkmdag - ok
13:45:35.0004 0x26f4 [ C14D7E5F24381BC8F333C4EB77892400, 8B8EF49D2398AF39E36EFFE6D1E0489727D5612DEFA43C71E3C7E4C0650010A5 ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
13:45:35.0209 0x26f4 amdkmdap - ok
13:45:35.0237 0x26f4 AmdPPM - ok
13:45:35.0242 0x26f4 amdsata - ok
13:45:35.0261 0x26f4 amdsbs - ok
13:45:35.0265 0x26f4 amdxata - ok
13:45:35.0346 0x26f4 [ C3D487827E48CC5EC17994FEC5BDFF87, 5FCEA3EEA583755D0C9F6005ED3032E9DFECB57F504DC67701AE7D2D2631C30E ] AODDriver4.3 C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys
13:45:35.0435 0x26f4 AODDriver4.3 - ok
13:45:35.0463 0x26f4 AppID - ok
13:45:35.0500 0x26f4 AppIDSvc - ok
13:45:35.0522 0x26f4 Appinfo - ok
13:45:35.0750 0x26f4 [ 7D811EA7A2AAA49B0446D42CBC1CD338, AFECE5E44E48F756C7EB81D95C9237552AF8A9C02CBE756E0F3D3C6524DE49AD ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
13:45:35.0778 0x26f4 Apple Mobile Device Service - ok
13:45:35.0783 0x26f4 applockerfltr - ok
13:45:35.0790 0x26f4 AppMgmt - ok
13:45:35.0804 0x26f4 AppReadiness - ok
13:45:35.0852 0x26f4 AppVClient - ok
13:45:35.0885 0x26f4 AppvStrm - ok
13:45:35.0947 0x26f4 AppvVemgr - ok
13:45:35.0970 0x26f4 AppvVfs - ok
13:45:36.0028 0x26f4 AppXSvc - ok
13:45:36.0095 0x26f4 arcsas - ok
13:45:36.0101 0x26f4 AsyncMac - ok
13:45:36.0144 0x26f4 atapi - ok
13:45:36.0197 0x26f4 [ 4A90468E458443382578EF66CDB4A0FD, 7CEA0ADDC2916169ED9C925738A5A5F88F8ECF518855F659EB72B17CA10A8A6C ] AtiHDAudioService C:\WINDOWS\system32\drivers\AtihdWT6.sys
13:45:36.0400 0x26f4 AtiHDAudioService - ok
13:45:36.0445 0x26f4 AudioEndpointBuilder - ok
13:45:36.0491 0x26f4 Audiosrv - ok
13:45:36.0566 0x26f4 AxInstSV - ok
13:45:36.0594 0x26f4 b06bdrv - ok
13:45:36.0651 0x26f4 BasicDisplay - ok
13:45:36.0684 0x26f4 BasicRender - ok
13:45:36.0751 0x26f4 bcmfn - ok
13:45:36.0792 0x26f4 bcmfn2 - ok
13:45:36.0860 0x26f4 BDESVC - ok
13:45:36.0902 0x26f4 Beep - ok
13:45:36.0927 0x26f4 BFE - ok
13:45:36.0978 0x26f4 BITS - ok
13:45:37.0181 0x26f4 [ B5C2F92EE1106DFE7BB1CCE4D35B6037, E399C390687589194D8AAD385055F0CFA7D52AD9E837D8FF95008B8EB2B34E50 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
13:45:37.0369 0x26f4 Bonjour Service - ok
13:45:37.0399 0x26f4 bowser - ok
13:45:37.0441 0x26f4 BrokerInfrastructure - ok
13:45:37.0449 0x26f4 Browser - ok
13:45:37.0496 0x26f4 BthAvrcpTg - ok
13:45:37.0558 0x26f4 BthEnum - ok
13:45:37.0592 0x26f4 BthHFEnum - ok
13:45:37.0659 0x26f4 bthhfhid - ok
13:45:37.0726 0x26f4 BthHFSrv - ok
13:45:37.0751 0x26f4 BTHMODEM - ok
13:45:37.0778 0x26f4 BthPan - ok
13:45:37.0803 0x26f4 BTHPORT - ok
13:45:37.0837 0x26f4 bthserv - ok
13:45:37.0842 0x26f4 BTHUSB - ok
13:45:37.0871 0x26f4 buttonconverter - ok
13:45:37.0904 0x26f4 CapImg - ok
13:45:37.0938 0x26f4 cdfs - ok
13:45:37.0963 0x26f4 CDPSvc - ok
13:45:38.0021 0x26f4 CDPUserSvc - ok
13:45:38.0242 0x26f4 cdrom - ok
13:45:38.0346 0x26f4 CertPropSvc - ok
13:45:38.0521 0x26f4 [ 59B4AB79011957DD3B83F0C2E63741BD, 5DE68785D701DBA0F98452B7D5CC407BEECD51685F39516157733CED2EF2FA19 ] chip1click C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe
13:45:39.0245 0x26f4 chip1click - detected UnsignedFile.Multi.Generic ( 1 )
13:45:39.0552 0x26f4 Detect skipped due to KSN trusted
13:45:39.0552 0x26f4 chip1click - ok
13:45:39.0574 0x26f4 cht4iscsi - ok
13:45:39.0598 0x26f4 cht4vbd - ok
13:45:39.0645 0x26f4 circlass - ok
13:45:39.0650 0x26f4 CLFS - ok
13:45:39.0679 0x26f4 ClipSVC - ok
13:45:39.0691 0x26f4 clreg - ok
13:45:39.0724 0x26f4 CmBatt - ok
13:45:39.0749 0x26f4 CNG - ok
13:45:39.0754 0x26f4 cnghwassist - ok
13:45:41.0069 0x26f4 CompositeBus - ok
13:45:41.0074 0x26f4 COMSysApp - ok
13:45:41.0112 0x26f4 condrv - ok
13:45:41.0134 0x26f4 CoreMessagingRegistrar - ok
13:45:41.0143 0x26f4 CryptSvc - ok
13:45:41.0156 0x26f4 CSC - ok
13:45:41.0161 0x26f4 CscService - ok
13:45:41.0166 0x26f4 dam - ok
13:45:41.0172 0x26f4 DcomLaunch - ok
13:45:41.0177 0x26f4 DcpSvc - ok
13:45:41.0183 0x26f4 defragsvc - ok
13:45:41.0196 0x26f4 DeviceAssociationService - ok
13:45:41.0205 0x26f4 DeviceInstall - ok
13:45:41.0210 0x26f4 DevQueryBroker - ok
13:45:41.0227 0x26f4 Dfsc - ok
13:45:41.0268 0x26f4 [ 73BDD44A6088916964945886F9025409, 8E2ECC9AAEF3C6EBA2E61D25F657FDFCC72AB517CC4FD5FFF992E1F9EB942662 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
13:45:41.0281 0x26f4 dg_ssudbus - ok
13:45:41.0360 0x26f4 Dhcp - ok
13:45:41.0454 0x26f4 diagnosticshub.standardcollector.service - ok
13:45:41.0519 0x26f4 DiagTrack - ok
13:45:41.0562 0x26f4 disk - ok
13:45:41.0624 0x26f4 DmEnrollmentSvc - ok
13:45:41.0654 0x26f4 dmvsc - ok
13:45:41.0668 0x26f4 dmwappushservice - ok
13:45:41.0703 0x26f4 Dnscache - ok
13:45:41.0730 0x26f4 dot3svc - ok
13:45:41.0772 0x26f4 DPS - ok
13:45:41.0828 0x26f4 drmkaud - ok
13:45:41.0896 0x26f4 DsmSvc - ok
13:45:41.0908 0x26f4 DsSvc - ok
13:45:41.0932 0x26f4 DXGKrnl - ok
13:45:41.0965 0x26f4 EapHost - ok
13:45:41.0990 0x26f4 ebdrv - ok
13:45:42.0049 0x26f4 EFS - ok
13:45:42.0075 0x26f4 EhStorClass - ok
13:45:42.0142 0x26f4 EhStorTcgDrv - ok
13:45:42.0177 0x26f4 [ BE2902E13CA69383F449B6BF927844FB, F092785E305D8E1FE795AF98A7A7B7B4548A0D6687060568C9E078FFA8D65C1C ] ElbyCDIO C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
13:45:42.0187 0x26f4 ElbyCDIO - ok
13:45:42.0210 0x26f4 embeddedmode - ok
13:45:42.0259 0x26f4 EntAppSvc - ok
13:45:42.0284 0x26f4 ErrDev - ok
13:45:42.0310 0x26f4 EventSystem - ok
13:45:42.0343 0x26f4 exfat - ok
13:45:42.0368 0x26f4 fastfat - ok
13:45:42.0394 0x26f4 Fax - ok
13:45:42.0429 0x26f4 fdc - ok
13:45:42.0463 0x26f4 fdPHost - ok
13:45:42.0496 0x26f4 FDResPub - ok
13:45:42.0571 0x26f4 fhsvc - ok
13:45:42.0580 0x26f4 FileCrypt - ok
13:45:42.0605 0x26f4 FileInfo - ok
13:45:42.0615 0x26f4 Filetrace - ok
13:45:42.0632 0x26f4 flpydisk - ok
13:45:42.0644 0x26f4 FltMgr - ok
13:45:42.0649 0x26f4 FontCache - ok
13:45:42.0780 0x26f4 FontCache3.0.0.0 - ok
13:45:42.0838 0x26f4 FrameServer - ok
13:45:42.0843 0x26f4 FsDepends - ok
13:45:42.0848 0x26f4 Fs_Rec - ok
13:45:42.0861 0x26f4 fvevol - ok
13:45:42.0872 0x26f4 [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
13:45:42.0881 0x26f4 GEARAspiWDM - ok
13:45:42.0933 0x26f4 gencounter - ok
13:45:42.0995 0x26f4 genericusbfn - ok
13:45:43.0017 0x26f4 GPIOClx0101 - ok
13:45:43.0026 0x26f4 gpsvc - ok
13:45:43.0041 0x26f4 GpuEnergyDrv - ok
13:45:43.0064 0x26f4 [ 9932E254656DF50C514B8AE61EF12CCC, 502C06A9FE869CF65508155ABCD29640D5A0097FBF199DF0D61D9193D98C978B ] hcmon C:\WINDOWS\system32\drivers\hcmon.sys
13:45:43.0093 0x26f4 hcmon - ok
13:45:43.0103 0x26f4 HDAudBus - ok
13:45:43.0172 0x26f4 HidBatt - ok
13:45:43.0223 0x26f4 HidBth - ok
13:45:43.0239 0x26f4 hidi2c - ok
13:45:43.0243 0x26f4 hidinterrupt - ok
13:45:43.0257 0x26f4 HidIr - ok
13:45:43.0279 0x26f4 hidserv - ok
13:45:43.0325 0x26f4 HidUsb - ok
13:45:43.0366 0x26f4 HomeGroupListener - ok
13:45:43.0391 0x26f4 HomeGroupProvider - ok
13:45:43.0433 0x26f4 HpSAMD - ok
13:45:43.0488 0x26f4 [ F47CEC45FB85791D4AB237563AD0FA8F, 1035066D48BD179855BCA7F62EFA1B951E6E839D2E29E15A31844E18A126DD41 ] HTCAND64 C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys
13:45:43.0496 0x26f4 HTCAND64 - detected UnsignedFile.Multi.Generic ( 1 )
13:45:43.0555 0x26f4 Detect skipped due to KSN trusted
13:45:43.0555 0x26f4 HTCAND64 - ok
13:45:43.0621 0x26f4 [ 7C7C986776D00E575BFBDE5DCBDC615D, 4CF12851A5A45917C3A9139B19D79434F2038611B617F83A714506CC7A1A6C61 ] HtcVCom32 C:\WINDOWS\system32\DRIVERS\HtcVComV64.sys
13:45:43.0646 0x26f4 HtcVCom32 - detected UnsignedFile.Multi.Generic ( 1 )
13:45:43.0945 0x26f4 Detect skipped due to KSN trusted
13:45:43.0945 0x26f4 HtcVCom32 - ok
13:45:43.0963 0x26f4 HTTP - ok
13:45:44.0006 0x26f4 HvHost - ok
13:45:44.0072 0x26f4 hvservice - ok
13:45:44.0114 0x26f4 hwpolicy - ok
13:45:44.0139 0x26f4 hyperkbd - ok
13:45:44.0213 0x26f4 i8042prt - ok
13:45:44.0217 0x26f4 iagpio - ok
13:45:44.0277 0x26f4 iai2c - ok
13:45:44.0283 0x26f4 iaLPSS2i_GPIO2 - ok
13:45:44.0320 0x26f4 iaLPSS2i_I2C - ok
13:45:44.0325 0x26f4 iaLPSSi_GPIO - ok
13:45:44.0359 0x26f4 iaLPSSi_I2C - ok
13:45:44.0401 0x26f4 iaStorAV - ok
13:45:44.0406 0x26f4 iaStorV - ok
13:45:44.0435 0x26f4 ibbus - ok
13:45:44.0490 0x26f4 icssvc - ok
13:45:44.0526 0x26f4 IKEEXT - ok
13:45:44.0566 0x26f4 IndirectKmd - ok
13:45:45.0101 0x26f4 [ 622868E4BAE8FBCD22CB1A5901A2C824, C1A2264C0984DD16C83B663C9CE43E049E1356E32C5771C3ACE225F285699138 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
13:45:45.0208 0x26f4 IntcAzAudAddService - ok
13:45:45.0261 0x26f4 intelide - ok
13:45:45.0286 0x26f4 intelpep - ok
13:45:45.0312 0x26f4 intelppm - ok
13:45:45.0347 0x26f4 iorate - ok
13:45:45.0380 0x26f4 IpFilterDriver - ok
13:45:45.0432 0x26f4 iphlpsvc - ok
13:45:45.0436 0x26f4 IPMIDRV - ok
13:45:45.0440 0x26f4 IPNAT - ok
13:45:45.0777 0x26f4 [ 97C9EBB84A761D48DC17E0E6B913C164, D195A8410E1FEED1A0EE9C5F5AF6F5FC861284765A38D460D496CE1048501905 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
13:45:45.0836 0x26f4 iPod Service - ok
13:45:45.0841 0x26f4 irda - ok
13:45:45.0867 0x26f4 IRENUM - ok
13:45:45.0909 0x26f4 irmon - ok
13:45:45.0947 0x26f4 isapnp - ok
13:45:45.0987 0x26f4 iScsiPrt - ok
13:45:46.0054 0x26f4 [ BD5BF20EC242E003A2F570B8754A56D1, B4B3492222E98BF8E6EC453E727187FF4AA50A508D1E88A0CBBD5C46355AE492 ] ivusb C:\WINDOWS\System32\drivers\ivusb.sys
13:45:46.0076 0x26f4 ivusb - ok
13:45:46.0146 0x26f4 kbdclass - ok
13:45:46.0179 0x26f4 kbdhid - ok
13:45:46.0205 0x26f4 kdnic - ok
13:45:46.0209 0x26f4 KeyIso - ok
13:45:46.0238 0x26f4 KSecDD - ok
13:45:46.0280 0x26f4 KSecPkg - ok
13:45:46.0313 0x26f4 ksthunk - ok
13:45:46.0355 0x26f4 KtmRm - ok
13:45:46.0381 0x26f4 LanmanServer - ok
13:45:46.0414 0x26f4 LanmanWorkstation - ok
13:45:46.0448 0x26f4 lfsvc - ok
13:45:46.0490 0x26f4 LicenseManager - ok
13:45:46.0494 0x26f4 lltdio - ok
13:45:46.0508 0x26f4 lltdsvc - ok
13:45:46.0532 0x26f4 lmhosts - ok
13:45:46.0565 0x26f4 LSI_SAS - ok
13:45:46.0570 0x26f4 LSI_SAS2i - ok
13:45:46.0577 0x26f4 LSI_SAS3i - ok
13:45:46.0634 0x26f4 LSI_SSS - ok
13:45:46.0676 0x26f4 LSM - ok
13:45:46.0710 0x26f4 luafv - ok
13:45:46.0730 0x26f4 MapsBroker - ok
13:45:46.0785 0x26f4 megasas - ok
13:45:46.0868 0x26f4 megasas2i - ok
13:45:46.0882 0x26f4 megasr - ok
13:45:46.0915 0x26f4 MessagingService - ok
13:45:47.0045 0x26f4 mlx4_bus - ok
13:45:47.0055 0x26f4 MMCSS - ok
13:45:47.0083 0x26f4 Modem - ok
13:45:47.0129 0x26f4 monitor - ok
13:45:47.0179 0x26f4 mouclass - ok
13:45:47.0205 0x26f4 mouhid - ok
13:45:47.0209 0x26f4 mountmgr - ok
13:45:47.0481 0x26f4 [ 0DE2474F316C515482ABAD3B697F8714, 62862AE7432F5350068E96AD466093359C6CF444EB517AE6D09134FAF78C49F5 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
13:45:47.0494 0x26f4 MozillaMaintenance - ok
13:45:47.0516 0x26f4 mpsdrv - ok
13:45:47.0536 0x26f4 MpsSvc - ok
13:45:47.0604 0x26f4 MRxDAV - ok
13:45:47.0626 0x26f4 mrxsmb - ok
13:45:47.0667 0x26f4 mrxsmb10 - ok
13:45:47.0693 0x26f4 mrxsmb20 - ok
13:45:47.0739 0x26f4 MsBridge - ok
13:45:47.0793 0x26f4 MSDTC - ok
13:45:47.0801 0x26f4 Msfs - ok
13:45:47.0862 0x26f4 msgpiowin32 - ok
13:45:47.0896 0x26f4 mshidkmdf - ok
13:45:47.0921 0x26f4 mshidumdf - ok
13:45:47.0955 0x26f4 msisadrv - ok
13:45:47.0999 0x26f4 MSiSCSI - ok
13:45:48.0003 0x26f4 msiserver - ok
13:45:48.0008 0x26f4 MSKSSRV - ok
13:45:48.0012 0x26f4 MsLldp - ok
13:45:48.0017 0x26f4 MSPCLOCK - ok
13:45:48.0039 0x26f4 MSPQM - ok
13:45:48.0043 0x26f4 MsRPC - ok
13:45:48.0080 0x26f4 MsSecFlt - ok
13:45:48.0107 0x26f4 mssmbios - ok
13:45:48.0111 0x26f4 MSTEE - ok
13:45:48.0164 0x26f4 MTConfig - ok
13:45:48.0223 0x26f4 [ 640617B6E682A150C36BE39D78547F6C, 784F712E9DC3EEE81F07946BBA08AA2BEAC7B3961E430B75043645EF7ECA715C ] MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys
13:45:48.0232 0x26f4 MTsensor - ok
13:45:48.0236 0x26f4 Mup - ok
13:45:48.0249 0x26f4 mvumis - ok
13:45:48.0298 0x26f4 NativeWifiP - ok
13:45:48.0324 0x26f4 NcaSvc - ok
13:45:48.0373 0x26f4 NcbService - ok
13:45:48.0377 0x26f4 NcdAutoSetup - ok
13:45:48.0409 0x26f4 ndfltr - ok
13:45:48.0436 0x26f4 NDIS - ok
13:45:48.0469 0x26f4 NdisCap - ok
13:45:48.0545 0x26f4 NdisImPlatform - ok
13:45:48.0549 0x26f4 NdisTapi - ok
13:45:48.0586 0x26f4 Ndisuio - ok
13:45:48.0628 0x26f4 NdisVirtualBus - ok
13:45:48.0632 0x26f4 NdisWan - ok
13:45:48.0636 0x26f4 ndiswanlegacy - ok
13:45:48.0662 0x26f4 ndproxy - ok
13:45:48.0687 0x26f4 Ndu - ok
13:45:48.0737 0x26f4 NetAdapterCx - ok
13:45:48.0742 0x26f4 NetBIOS - ok
13:45:48.0748 0x26f4 NetBT - ok
13:45:48.0752 0x26f4 Netlogon - ok
13:45:48.0786 0x26f4 Netman - ok
13:45:48.0820 0x26f4 netprofm - ok
13:45:48.0864 0x26f4 NetSetupSvc - ok
13:45:49.0445 0x26f4 NetTcpPortSharing - ok
13:45:49.0519 0x26f4 NgcCtnrSvc - ok
13:45:49.0552 0x26f4 NgcSvc - ok
13:45:49.0585 0x26f4 NlaSvc - ok
13:45:49.0611 0x26f4 Npfs - ok
13:45:49.0673 0x26f4 npsvctrig - ok
13:45:49.0718 0x26f4 nsi - ok
13:45:49.0731 0x26f4 nsiproxy - ok
13:45:49.0778 0x26f4 NTFS - ok
13:45:49.0814 0x26f4 Null - ok
13:45:49.0880 0x26f4 nvraid - ok
13:45:49.0884 0x26f4 nvstor - ok
13:45:49.0939 0x26f4 OneSyncSvc - ok
13:45:50.0126 0x26f4 [ 11E0B35479C895888BA3D7F619DCFFF3, 6ED82C19898101EC00BD64A9F90595C3D20AD2D2902AA8765B740FB3B9312DDF ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:45:50.0142 0x26f4 ose64 - ok
13:45:50.0177 0x26f4 p2pimsvc - ok
13:45:50.0191 0x26f4 p2psvc - ok
13:45:50.0266 0x26f4 Parport - ok
13:45:50.0275 0x26f4 partmgr - ok
13:45:50.0318 0x26f4 PcaSvc - ok
13:45:50.0325 0x26f4 pci - ok
13:45:50.0371 0x26f4 pciide - ok
13:45:50.0407 0x26f4 pcmcia - ok
13:45:50.0411 0x26f4 pcw - ok
13:45:50.0428 0x26f4 pdc - ok
13:45:50.0469 0x26f4 PEAUTH - ok
13:45:50.0503 0x26f4 PeerDistSvc - ok
13:45:50.0570 0x26f4 percsas2i - ok
13:45:50.0574 0x26f4 percsas3i - ok
13:45:53.0296 0x26f4 PerfHost - ok
13:45:53.0317 0x26f4 PhoneSvc - ok
13:45:53.0333 0x26f4 PimIndexMaintenanceSvc - ok
13:45:53.0362 0x26f4 pla - ok
13:45:53.0381 0x26f4 PlugPlay - ok
13:45:53.0431 0x26f4 PNRPAutoReg - ok
13:45:53.0435 0x26f4 PNRPsvc - ok
13:45:53.0474 0x26f4 PolicyAgent - ok
13:45:53.0480 0x26f4 Power - ok
13:45:53.0516 0x26f4 PptpMiniport - ok
13:45:54.0877 0x26f4 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
13:45:55.0024 0x26f4 PrintNotify - ok
13:45:55.0071 0x26f4 Processor - ok
13:45:55.0129 0x26f4 ProfSvc - ok
13:45:55.0161 0x26f4 Psched - ok
13:45:55.0181 0x26f4 QWAVE - ok
13:45:55.0214 0x26f4 QWAVEdrv - ok
13:45:55.0239 0x26f4 RasAcd - ok
13:45:55.0306 0x26f4 RasAgileVpn - ok
13:45:55.0348 0x26f4 RasAuto - ok
13:45:55.0352 0x26f4 Rasl2tp - ok
13:45:55.0373 0x26f4 RasMan - ok
13:45:55.0377 0x26f4 RasPppoe - ok
13:45:55.0382 0x26f4 RasSstp - ok
13:45:55.0407 0x26f4 rdbss - ok
13:45:55.0488 0x26f4 rdpbus - ok
13:45:55.0492 0x26f4 RDPDR - ok
13:45:55.0551 0x26f4 RdpVideoMiniport - ok
13:45:55.0592 0x26f4 rdyboost - ok
13:45:55.0596 0x26f4 ReFSv1 - ok
13:45:55.0625 0x26f4 RemoteAccess - ok
13:45:55.0661 0x26f4 RemoteRegistry - ok
13:45:55.0691 0x26f4 RetailDemo - ok
13:45:55.0725 0x26f4 RFCOMM - ok
13:45:55.0743 0x26f4 RmSvc - ok
13:45:55.0768 0x26f4 RpcEptMapper - ok
13:45:55.0793 0x26f4 RpcLocator - ok
13:45:55.0819 0x26f4 RpcSs - ok
13:45:55.0852 0x26f4 rspndr - ok
13:45:55.0920 0x26f4 rt640x64 - ok
13:45:55.0928 0x26f4 RtlWlanu_OldIC - ok
13:45:55.0951 0x26f4 [ 0988FECD9D924F5B4855D049E68BAAD3, 788B379B01F26C7C46DF0D3E9E37F9964831AAFD0762DDD17345478A97ADE83D ] rzdaendpt C:\WINDOWS\System32\drivers\rzdaendpt.sys
13:45:55.0961 0x26f4 rzdaendpt - ok
13:45:56.0036 0x26f4 [ C2A49525F6CEEED97A1D9FC950AAF863, DAA57C1C446861C733D3BE668EB247E40CE3871EF8FA0BB91CEB074B7357E0D8 ] rzudd C:\WINDOWS\System32\drivers\rzudd.sys
13:45:56.0048 0x26f4 rzudd - ok
13:45:56.0058 0x26f4 [ 2AD977273D8B3F2169411E8AED7C8702, FCC3D579AFC9958C0CE3FB202061D36C66FC6803AFD7B99DBFC41412F9131E34 ] rzvkeyboard C:\WINDOWS\System32\drivers\rzvkeyboard.sys
13:45:56.0067 0x26f4 rzvkeyboard - ok
13:45:56.0081 0x26f4 s3cap - ok
13:45:56.0092 0x26f4 [ 476BAA3EEBE9DB94BF6BDFAF46747E5D, 6E8FB06225341989B88C1F554800724F5DFE16A359C3E019CA63D6C2FAA22F72 ] SaiK0728 C:\WINDOWS\system32\DRIVERS\SaiK0728.sys
13:45:56.0118 0x26f4 SaiK0728 - ok
13:45:56.0135 0x26f4 SamSs - ok
13:45:56.0202 0x26f4 [ 186151BC8CEE2CF3E942E81527AAFF1A, 33D68239D655054CE8822438E96D2648193419D8D94F979A4B67AF57BCEF6CBD ] SbieDrv C:\Program Files\Sandboxie\SbieDrv.sys
13:45:56.0315 0x26f4 SbieDrv - ok
13:45:56.0430 0x26f4 [ 12820DA4BB0079BBC709C7028A22BA63, C15EDCC83CC4931C871D04F09A6FC6199C9DCD4332CDF4C80D1E6E5A2AFD4DE1 ] SbieSvc C:\Program Files\Sandboxie\SbieSvc.exe
13:45:56.0495 0x26f4 SbieSvc - ok
13:45:56.0500 0x26f4 sbp2port - ok
13:45:56.0518 0x26f4 SCardSvr - ok
13:45:56.0523 0x26f4 ScDeviceEnum - ok
13:45:56.0541 0x26f4 scfilter - ok
13:45:56.0559 0x26f4 Schedule - ok
13:45:56.0626 0x26f4 scmbus - ok
13:45:56.0659 0x26f4 scmdisk0101 - ok
13:45:56.0734 0x26f4 SCPolicySvc - ok
13:45:56.0776 0x26f4 sdbus - ok
13:45:56.0817 0x26f4 SDRSVC - ok
13:45:56.0853 0x26f4 sdstor - ok
13:45:56.0886 0x26f4 seclogon - ok
13:45:56.0920 0x26f4 SENS - ok
13:45:57.0080 0x26f4 Sense - ok
13:45:57.0144 0x26f4 SensorDataService - ok
13:45:57.0174 0x26f4 SensorService - ok
13:45:57.0198 0x26f4 SensrSvc - ok
13:45:57.0203 0x26f4 SerCx - ok
13:45:57.0265 0x26f4 SerCx2 - ok
13:45:57.0306 0x26f4 Serenum - ok
13:45:57.0324 0x26f4 Serial - ok
13:45:57.0329 0x26f4 sermouse - ok
13:45:57.0382 0x26f4 SessionEnv - ok
13:45:57.0457 0x26f4 sfloppy - ok
13:45:57.0533 0x26f4 SharedAccess - ok
13:45:57.0615 0x26f4 ShellHWDetection - ok
13:45:57.0670 0x26f4 shpamsvc - ok
13:45:57.0683 0x26f4 SiSRaid2 - ok
13:45:57.0700 0x26f4 SiSRaid4 - ok
13:45:57.0802 0x26f4 [ 0B70786BD1062CD4C6B58E412B9C3E55, 60ED027642FFF97BFFA55AE3EFFCCBB6D6AD8196D35E9ED06F9AF431E3C0402A ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
13:45:57.0820 0x26f4 SkypeUpdate - ok
13:45:57.0870 0x26f4 smphost - ok
13:45:57.0897 0x26f4 SmsRouter - ok
13:45:57.0946 0x26f4 SNMPTRAP - ok
13:45:57.0948 0x26f4 Soda PDF Desktop - ok
13:45:57.0953 0x26f4 Soda PDF Desktop CrashHandler - ok
13:45:57.0957 0x26f4 Soda PDF Desktop Creator - ok
13:45:58.0021 0x26f4 spaceport - ok
13:45:58.0054 0x26f4 SpbCx - ok
13:46:00.0139 0x26f4 [ 0FFE35F0B0CD5A324BBE22F02569AE3B, F4EE803EEFDB4EAEEDB3024C3516F1F9A202C77F4870D6B74356BBDE32B3B560 ] speedfan C:\WINDOWS\SysWoW64\speedfan.sys
13:46:00.0174 0x26f4 speedfan - ok
13:46:00.0199 0x26f4 Spooler - ok
13:46:00.0223 0x26f4 sppsvc - ok
13:46:00.0231 0x26f4 srv - ok
13:46:00.0257 0x26f4 srv2 - ok
13:46:00.0282 0x26f4 srvnet - ok
13:46:00.0309 0x26f4 SSDPSRV - ok
13:46:00.0334 0x26f4 SstpSvc - ok
13:46:00.0416 0x26f4 [ 5252D7BC56E5E0ED715AEA8FE173A455, 1408B3E98B35A449434718777EE70595F0D306197A428279C6281D2F1953F259 ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
13:46:00.0429 0x26f4 ssudmdm - ok
13:46:00.0476 0x26f4 StateRepository - ok
13:46:00.0735 0x26f4 [ 5CBCEB3FF7C232ACC8891C8197BF3353, B1FE57C61E62B1FEC81B219551DAD68DC5DF17FC1603CDC0CBA097A3E687A027 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
13:46:00.0916 0x26f4 Steam Client Service - ok
13:46:00.0942 0x26f4 stexstor - ok
13:46:00.0975 0x26f4 stisvc - ok
13:46:01.0009 0x26f4 storahci - ok
13:46:01.0042 0x26f4 storflt - ok
13:46:01.0076 0x26f4 stornvme - ok
13:46:01.0109 0x26f4 storqosflt - ok
13:46:01.0127 0x26f4 StorSvc - ok
13:46:01.0143 0x26f4 storufs - ok
13:46:01.0161 0x26f4 storvsc - ok
13:46:01.0166 0x26f4 svsvc - ok
13:46:01.0226 0x26f4 swenum - ok
13:46:01.0230 0x26f4 swprv - ok
13:46:01.0246 0x26f4 Synth3dVsc - ok
13:46:01.0272 0x26f4 SysMain - ok
13:46:01.0315 0x26f4 SystemEventsBroker - ok
13:46:01.0348 0x26f4 TabletInputService - ok
13:46:01.0382 0x26f4 TapiSrv - ok
13:46:01.0416 0x26f4 Tcpip - ok
13:46:01.0420 0x26f4 Tcpip6 - ok
13:46:01.0426 0x26f4 tcpipreg - ok
13:46:01.0441 0x26f4 tdx - ok
13:46:01.0614 0x26f4 [ BDE17782D06393AFD522C4B0D1B7E1F5, 735ED2C0E7AA324FE7919ADCAEDE8321CB506F33E7A2C713EFB6B7694E3E8BEF ] Tenable Nessus C:\Program Files\Tenable\Nessus\nessus-service.exe
13:46:01.0638 0x26f4 Tenable Nessus - ok
13:46:01.0673 0x26f4 terminpt - ok
13:46:01.0698 0x26f4 TermService - ok
13:46:01.0739 0x26f4 Themes - ok
13:46:01.0790 0x26f4 TieringEngineService - ok
13:46:01.0832 0x26f4 tiledatamodelsvc - ok
13:46:01.0878 0x26f4 TimeBrokerSvc - ok
13:46:01.0917 0x26f4 TPM - ok
13:46:01.0942 0x26f4 TrkWks - ok
13:46:02.0057 0x26f4 TrustedInstaller - ok
13:46:02.0063 0x26f4 tsusbflt - ok
13:46:02.0081 0x26f4 TsUsbGD - ok
13:46:02.0085 0x26f4 tsusbhub - ok
13:46:02.0089 0x26f4 tunnel - ok
13:46:02.0135 0x26f4 tzautoupdate - ok
13:46:02.0203 0x26f4 UASPStor - ok
13:46:02.0208 0x26f4 UcmCx0101 - ok
13:46:02.0237 0x26f4 UcmTcpciCx0101 - ok
13:46:02.0262 0x26f4 UcmUcsi - ok
13:46:02.0266 0x26f4 Ucx01000 - ok
13:46:02.0295 0x26f4 UdeCx - ok
13:46:02.0299 0x26f4 udfs - ok
13:46:02.0329 0x26f4 UEFI - ok
13:46:02.0333 0x26f4 UevAgentDriver - ok
13:46:02.0362 0x26f4 UevAgentService - ok
13:46:02.0367 0x26f4 Ufx01000 - ok
13:46:02.0385 0x26f4 UfxChipidea - ok
13:46:02.0430 0x26f4 ufxsynopsys - ok
13:46:02.0469 0x26f4 UI0Detect - ok
13:46:02.0474 0x26f4 umbus - ok
13:46:02.0493 0x26f4 UmPass - ok
13:46:02.0523 0x26f4 UmRdpService - ok
13:46:02.0556 0x26f4 UnistoreSvc - ok
13:46:02.0583 0x26f4 upnphost - ok
13:46:02.0617 0x26f4 UrsChipidea - ok
13:46:02.0642 0x26f4 UrsCx01000 - ok
13:46:02.0646 0x26f4 UrsSynopsys - ok
13:46:02.0693 0x26f4 [ F957092C63CD71D85903CA0D8370F473, 4DEC2FC20329F248135DA24CB6694FD972DCCE8B1BBEA8D872FDE41939E96AAF ] USBAAPL64 C:\WINDOWS\System32\Drivers\usbaapl64.sys
13:46:02.0799 0x26f4 USBAAPL64 - ok
13:46:02.0813 0x26f4 usbccgp - ok
13:46:02.0844 0x26f4 usbcir - ok
13:46:02.0887 0x26f4 usbehci - ok
13:46:02.0891 0x26f4 usbhub - ok
13:46:02.0924 0x26f4 USBHUB3 - ok
13:46:02.0938 0x26f4 usbohci - ok
13:46:02.0962 0x26f4 usbprint - ok
13:46:03.0005 0x26f4 usbscan - ok
13:46:03.0013 0x26f4 usbser - ok
13:46:03.0053 0x26f4 USBSTOR - ok
13:46:03.0076 0x26f4 usbuhci - ok
13:46:03.0089 0x26f4 USBXHCI - ok
13:46:03.0124 0x26f4 UserDataSvc - ok
13:46:03.0149 0x26f4 UserManager - ok
13:46:03.0183 0x26f4 UsoSvc - ok
13:46:03.0250 0x26f4 VaultSvc - ok
13:46:03.0430 0x26f4 [ 0D9780E8495C84911491AE1603711E39, 4D9E1157CA84E0DE1A1BFB9A75576AA49B37BD02F780CC84012A79720B183F0F ] VBoxDrv C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys
13:46:03.0524 0x26f4 VBoxDrv - ok
13:46:03.0589 0x26f4 [ 45633D58D5DB28E5F210CF51588E537D, DF88F66E360535966557249127AC17EC11746F478DC73210526E2545422C77FF ] VBoxNetAdp C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys
13:46:03.0625 0x26f4 VBoxNetAdp - ok
13:46:03.0680 0x26f4 [ B802AC859F5BEF61FFB24F1513755106, 54A75B61946D7B8B4A61C15BE79D81E8D10B08D8BE4F6F02BB6A4DC0DF9A6B76 ] VBoxNetLwf C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys
13:46:03.0719 0x26f4 VBoxNetLwf - ok
13:46:03.0767 0x26f4 [ FEB686C223F7EA10B530108C81BB110B, 79AAAE2345694617F7A35068F0614E256B179A803C14639591B1DC796CB92F47 ] VBoxUSBMon C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys
13:46:03.0799 0x26f4 VBoxUSBMon - ok
13:46:03.0850 0x26f4 [ 3C8E2C591345F38149C69FE8E5DF8C90, 9F4BB9BDA09CB2E99A6A888B288F322AE5C460B5D124CD714C6F00FF5029144B ] VClone C:\WINDOWS\System32\drivers\VClone.sys
13:46:03.0866 0x26f4 VClone - ok
13:46:03.0871 0x26f4 vdrvroot - ok
13:46:03.0896 0x26f4 vds - ok
13:46:03.0924 0x26f4 VerifierExt - ok
13:46:03.0961 0x26f4 vhdmp - ok
13:46:03.0965 0x26f4 vhf - ok
13:46:04.0112 0x26f4 [ BD00A8CFB76E6BB0E89DB191E3712528, 870664951D908772454E30042E2CD464722DF7331AFAC016B0884EC375FEA5C3 ] VMAuthdService C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
13:46:04.0179 0x26f4 VMAuthdService - ok
13:46:04.0204 0x26f4 vmbus - ok
13:46:04.0223 0x26f4 VMBusHID - ok
13:46:04.0260 0x26f4 [ BE8E5E5D53ACF71D4E8E686B68C99B04, 4F30A360095FCB2627068FA6A65A951688058E8FDDF5CE895E2AE39500A413B1 ] vmci C:\WINDOWS\system32\drivers\vmci.sys
13:46:04.0290 0x26f4 vmci - ok
13:46:04.0314 0x26f4 vmgid - ok
13:46:04.0349 0x26f4 vmicguestinterface - ok
13:46:04.0353 0x26f4 vmicheartbeat - ok
13:46:04.0358 0x26f4 vmickvpexchange - ok
13:46:04.0390 0x26f4 vmicrdv - ok
13:46:04.0394 0x26f4 vmicshutdown - ok
13:46:04.0399 0x26f4 vmictimesync - ok
13:46:04.0403 0x26f4 vmicvmsession - ok
13:46:04.0408 0x26f4 vmicvss - ok
13:46:04.0457 0x26f4 [ 18AA5F4A3B1204AD00045EE5AD39BCDB, 0211A8E94F169A2A52CD39CD580293907EBE104E52038DC36B988DE1CA7F2392 ] VMnetAdapter C:\WINDOWS\system32\DRIVERS\vmnetadapter.sys
13:46:04.0504 0x26f4 VMnetAdapter - ok
13:46:04.0524 0x26f4 [ 04CD4347CD9E8C40F78AD51F7FF426D0, BCA3E593E118BCA30142B23CD1CBE6905442D31C3DEB4C71B06D721E601F7BD8 ] VMnetBridge C:\WINDOWS\system32\DRIVERS\vmnetbridge.sys
13:46:04.0636 0x26f4 VMnetBridge - ok
13:46:06.0211 0x26f4 [ 338CD01BD29805A93902B9237A39CAC5, AB667D0BD54FFCAA997F97755CE576E47D361EEA21E45B95DEA1E912693B4CE2 ] VMnetDHCP C:\WINDOWS\SYSWOW64\VMNETDHCP.EXE
13:46:06.0342 0x26f4 VMnetDHCP - ok
13:46:06.0381 0x26f4 [ 76C4CFAC694A581EA5C8DE89B6AEBD4B, B6D19529223BD20AA2A17D93A8F0D2D32369FDE4E8535F6D1191B065B0755EE4 ] VMnetuserif C:\WINDOWS\system32\drivers\vmnetuserif.sys
13:46:06.0426 0x26f4 VMnetuserif - ok
13:46:06.0450 0x26f4 [ 69741000F15F2F0CE85E5EE0DD3EB78A, 485C1D410ADDDFACF3518FDDAE0D23B972F270031805EDCB3D40B17F216641E1 ] vmusb C:\WINDOWS\System32\drivers\vmusb.sys
13:46:06.0533 0x26f4 vmusb - ok
13:46:06.0821 0x26f4 [ 9D88591D3B97D30234F5B965B8E0ABD6, 42ECDD6D789645242E4640F10C1FB91BF0C2B37CDE3CF864B8175EE3E05DB2DB ] VMUSBArbService C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
13:46:06.0870 0x26f4 VMUSBArbService - ok
13:46:06.0978 0x26f4 [ 2B2BB1F8BFEBE6B847FDB32F89EA2A3E, 743EBF3EF12067A77454B04559E266EFB306A454AF765A0821193C646A952F2E ] VMware NAT Service C:\WINDOWS\SYSWOW64\VMNAT.EXE
13:46:07.0138 0x26f4 VMware NAT Service - ok
13:46:07.0163 0x26f4 [ F6B89D7078138FE6E9C00CF311FFE517, 701A33BB32A0289B2878268A27A5F4D36167C126601D51DC6EEE1C109E990868 ] vmx86 C:\WINDOWS\system32\drivers\vmx86.sys
13:46:07.0191 0x26f4 vmx86 - ok
13:46:07.0240 0x26f4 volmgr - ok
13:46:07.0245 0x26f4 volmgrx - ok
13:46:07.0249 0x26f4 volsnap - ok
13:46:07.0279 0x26f4 volume - ok
13:46:07.0302 0x26f4 vpci - ok
13:46:07.0318 0x26f4 vsmraid - ok
13:46:07.0386 0x26f4 [ CB4D2E3C5E8BFA3CF6AFFF6DDC6CC70D, 32A891045AF36FEAC62373894B98ABDCEA437978BDE027169C22EBC2C72D586E ] vsock C:\WINDOWS\system32\drivers\vsock.sys
13:46:07.0448 0x26f4 vsock - ok
13:46:07.0454 0x26f4 VSS - ok
13:46:07.0482 0x26f4 VSTXRAID - ok
13:46:07.0503 0x26f4 vwifibus - ok
13:46:07.0508 0x26f4 vwififlt - ok
13:46:07.0513 0x26f4 vwifimp - ok
13:46:07.0536 0x26f4 W32Time - ok
13:46:07.0561 0x26f4 WacomPen - ok
13:46:07.0606 0x26f4 WalletService - ok
13:46:07.0629 0x26f4 wanarp - ok
13:46:07.0634 0x26f4 wanarpv6 - ok
13:46:07.0662 0x26f4 wbengine - ok
13:46:07.0712 0x26f4 WbioSrvc - ok
13:46:07.0728 0x26f4 wcifs - ok
13:46:07.0746 0x26f4 Wcmsvc - ok
13:46:07.0788 0x26f4 wcncsvc - ok
13:46:07.0802 0x26f4 wcnfs - ok
13:46:07.0839 0x26f4 WdBoot - ok
13:46:07.0845 0x26f4 Wdf01000 - ok
13:46:07.0850 0x26f4 WdFilter - ok
13:46:07.0865 0x26f4 WdiServiceHost - ok
13:46:07.0870 0x26f4 WdiSystemHost - ok
13:46:07.0907 0x26f4 wdiwifi - ok
13:46:07.0941 0x26f4 WdNisDrv - ok
13:46:07.0986 0x26f4 WdNisSvc - ok
13:46:08.0012 0x26f4 WebClient - ok
13:46:08.0025 0x26f4 Wecsvc - ok
13:46:08.0067 0x26f4 WEPHOSTSVC - ok
13:46:08.0125 0x26f4 wercplsupport - ok
13:46:08.0167 0x26f4 WerSvc - ok
13:46:08.0173 0x26f4 WFPLWFS - ok
13:46:08.0210 0x26f4 WiaRpc - ok
13:46:08.0223 0x26f4 WIMMount - ok
13:46:08.0226 0x26f4 WinDefend - ok
13:46:08.0280 0x26f4 WindowsTrustedRT - ok
13:46:08.0310 0x26f4 WindowsTrustedRTProxy - ok
13:46:08.0328 0x26f4 WinHttpAutoProxySvc - ok
13:46:08.0394 0x26f4 WinMad - ok
13:46:08.0487 0x26f4 Winmgmt - ok
13:46:08.0521 0x26f4 WinRM - ok
13:46:08.0581 0x26f4 WINUSB - ok
13:46:08.0596 0x26f4 WinVerbs - ok
13:46:08.0636 0x26f4 wisvc - ok
13:46:08.0691 0x26f4 WlanSvc - ok
13:46:08.0724 0x26f4 wlidsvc - ok
13:46:08.0729 0x26f4 WmiAcpi - ok
13:46:08.0757 0x26f4 wmiApSrv - ok
13:46:08.0761 0x26f4 WMPNetworkSvc - ok
13:46:08.0799 0x26f4 Wof - ok
13:46:08.0842 0x26f4 workfolderssvc - ok
13:46:08.0892 0x26f4 WPDBusEnum - ok
13:46:08.0936 0x26f4 WpdUpFltr - ok
13:46:08.0974 0x26f4 WpnService - ok
13:46:08.0996 0x26f4 WpnUserService - ok
13:46:09.0013 0x26f4 ws2ifsl - ok
13:46:09.0029 0x26f4 wscsvc - ok
13:46:09.0035 0x26f4 WSearch - ok
13:46:09.0071 0x26f4 wuauserv - ok
13:46:09.0105 0x26f4 WudfPf - ok
13:46:09.0115 0x26f4 WUDFRd - ok
13:46:09.0131 0x26f4 wudfsvc - ok
13:46:09.0136 0x26f4 WUDFWpdFs - ok
13:46:09.0141 0x26f4 WUDFWpdMtp - ok
13:46:09.0164 0x26f4 WwanSvc - ok
13:46:09.0189 0x26f4 XblAuthManager - ok
13:46:09.0224 0x26f4 XblGameSave - ok
13:46:09.0231 0x26f4 xboxgip - ok
13:46:09.0269 0x26f4 XboxNetApiSvc - ok
13:46:09.0308 0x26f4 xinputhid - ok
13:46:09.0352 0x26f4 xusb22 - ok
13:46:09.0352 0x26f4 ================ Scan global ===============================
13:46:09.0462 0x26f4 [ Global ] - ok
13:46:09.0487 0x26f4 ================ Scan MBR ==================================
13:46:09.0541 0x26f4 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
13:46:19.0064 0x26f4 \Device\Harddisk0\DR0 - ok
13:46:19.0078 0x26f4 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
13:46:20.0220 0x26f4 \Device\Harddisk1\DR1 - ok
13:46:20.0234 0x26f4 [ EA923EB0EC0060F1451E9AD7B5762CFE ] \Device\Harddisk2\DR2
13:46:20.0378 0x26f4 \Device\Harddisk2\DR2 - ok
13:46:20.0379 0x26f4 ================ Scan VBR ==================================
13:46:20.0410 0x26f4 [ 49584FC3CEF718E95383334BBE44A26C ] \Device\Harddisk0\DR0\Partition1
13:46:20.0444 0x26f4 \Device\Harddisk0\DR0\Partition1 - ok
13:46:20.0471 0x26f4 [ 9CC34D5839F14F91915221DC674E9829 ] \Device\Harddisk0\DR0\Partition2
13:46:20.0558 0x26f4 \Device\Harddisk0\DR0\Partition2 - ok
13:46:20.0566 0x26f4 [ 2342137B7D2E664AFD8F47ED92D9666C ] \Device\Harddisk1\DR1\Partition1
13:46:20.0589 0x26f4 \Device\Harddisk1\DR1\Partition1 - ok
13:46:20.0593 0x26f4 [ 46E119D11DD0764FF2F5BC8653170BAD ] \Device\Harddisk2\DR2\Partition1
13:46:20.0594 0x26f4 \Device\Harddisk2\DR2\Partition1 - ok
13:46:20.0632 0x26f4 [ 5866AC64B6DF731BD073909F7DF5C6FA ] \Device\Harddisk2\DR2\Partition2
13:46:20.0633 0x26f4 \Device\Harddisk2\DR2\Partition2 - ok
13:46:20.0634 0x26f4 ================ Scan generic autorun ======================
13:46:21.0231 0x26f4 [ 22EBD5AE3B3220D713E544D1D3AB3FEE, 9EF058B096DAA5C6242FBEB3DF509108180B1EB1EA252E63C437CF6C1B743BE0 ] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
13:46:21.0414 0x26f4 RTHDVCPL - ok
13:46:21.0941 0x26f4 [ 739D7E0025F5CE97309695D3081E3823, 46A4B51123992B2FA3DF51F80C3E9E7118C6CCB6A68B6EDA3585BF87208B7DFC ] C:\Program Files\AMD\CNext\CNext\cnext.exe
13:46:22.0163 0x26f4 StartCN - ok
13:46:22.0172 0x26f4 WindowsDefender - ok
13:46:22.0267 0x26f4 [ 64D89BDA981ECD2BC9B547E4210CA6E0, 403F685FBC8A71896F550476C3E3CAAC0D593F7CF25D4A2F61ED62D576E62F12 ] C:\Program Files\iTunes\iTunesHelper.exe
13:46:22.0318 0x26f4 iTunesHelper - ok
13:46:22.0428 0x26f4 [ 3BD79A1F6D2EA0FDDEA3F8914B2A6A0C, 332E6806EFF846A2E6D0DC04A70D3503855DABFA83E6EC27F37E2D9103E80E51 ] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
13:46:22.0437 0x26f4 VirtualCloneDrive - ok
13:46:22.0567 0x26f4 [ 6F59A10A04D5B76903118C38C15B629C, 766763C1E291178A2EEE66341BF1F59C30CA62A90E86CFD95408346991773A5D ] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
13:46:22.0895 0x26f4 Adobe ARM - ok
13:46:23.0073 0x26f4 [ 56831CF0D755103BB0E7EA141A4895D9, 496A4EA8F84C0A9E79E1267B16B10F60F737F79BECBEECE593416D79F03B1063 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
13:46:23.0255 0x26f4 SunJavaUpdateSched - ok
13:46:24.0553 0x26f4 OneDriveSetup - ok
13:46:24.0556 0x26f4 OneDriveSetup - ok
13:46:24.0945 0x26f4 [ F0B461FB820595E8BAF1161F55BE3E74, B8022060E7280DC568BFC230CA99D37C09092152D0CEE91B08401ACD725E82A2 ] C:\Users\Sergio\AppData\Roaming\Spotify\SpotifyWebHelper.exe
13:46:25.0204 0x26f4 Spotify Web Helper - ok
13:46:25.0545 0x26f4 [ FE9E6388A039441098EB09C070EA5049, 3888822AF992F3BE27E9F973E31EBEE5302901E4A8260A9A6CF6B2BB2A12D173 ] C:\Users\Sergio\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe
13:46:25.0566 0x26f4 Google Update - ok
13:46:26.0118 0x26f4 [ CD7DC286D2FDFACB965C3E10967B2199, 30FFB133E70D694BE6968E86E999C797EE7349DCC4E9ACFB338412C039374388 ] C:\Users\Sergio\AppData\Local\Microsoft\OneDrive\OneDrive.exe
13:46:26.0161 0x26f4 OneDrive - ok
13:46:26.0816 0x26f4 [ 44A9229022A519ED45294A1934C05EEC, 6DEF0DB5F9B50E9B0AFEE1CF50066BEB4FB7E15E2DC829A499509925660D6992 ] C:\Users\Sergio\AppData\Local\FluxSoftware\Flux\flux.exe
13:46:27.0109 0x26f4 f.lux - ok
13:46:28.0518 0x26f4 [ 8D3D5BA1638778DE87503E5FEA68DC9F, D54C2B375A6F8A49BC53CAA3ED8A0EEBF53FD113BB47622F4AE6DA762D194FE7 ] C:\Program Files\CCleaner\CCleaner64.exe
13:46:28.0830 0x26f4 CCleaner Monitoring - ok
13:46:29.0061 0x26f4 [ 1A2214CF882CE18EF513BF2A33907C51, C1E9349EA50A239F440F0353CEEE544322F2C7F731166B3256F68108F1448C1A ] C:\Program Files\Sandboxie\SbieCtrl.exe
13:46:29.0107 0x26f4 SandboxieControl - ok
13:46:29.0111 0x26f4 OneDriveSetup - ok
13:46:29.0172 0x26f4 WAB Migrate - ok
13:46:29.0173 0x26f4 Waiting for KSN requests completion. In queue: 12
13:46:30.0185 0x26f4 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x61100 ( enabled : updated )
13:46:30.0190 0x26f4 Win FW state via NFP2: enabled ( trusted )
13:46:30.0301 0x26f4 ============================================================
13:46:30.0301 0x26f4 Scan finished
13:46:30.0301 0x26f4 ============================================================
13:46:30.0311 0x1510 Detected object count: 0
13:46:30.0311 0x1510 Actual detected object count: 0
Hier die FRST.txt Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
durchgeführt von Sergio (Administrator) auf SERGIOS-PC (19-03-2017 13:51:53)
Gestartet von C:\Users\Sergio\Desktop
Geladene Profile: Sergio (Verfügbare Profile: Sergio & postgres)
Platform: Windows 10 Pro Version 1607 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Tenable Network Security, Inc) C:\Program Files\Tenable\Nessus\nessus-service.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(Tenable Network Security, Inc) C:\Program Files\Tenable\Nessus\nessusd.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cnext.exe
(Flux Software LLC) C:\Users\Sergio\AppData\Local\FluxSoftware\Flux\flux.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\Evernote.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Chip Digital GmbH) C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
() C:\Program Files (x86)\SpeedFan\speedfan.exe
() C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8008.42007.0_x64__8wekyb3d8bbwe\HxMail.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8008.42007.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\cnext.exe [4926664 2016-02-26] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2017-01-19] (Apple Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1160408 2016-12-17] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKU\AvGeneric_S-1-5-21-1478414814-3749218601-3539646535-1007\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2016-07-16] (Microsoft Corporation)
HKU\S-1-5-21-1478414814-3749218601-3539646535-1001\...\Run: [Spotify Web Helper] => C:\Users\Sergio\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1446000 2017-03-11] (Spotify Ltd)
HKU\S-1-5-21-1478414814-3749218601-3539646535-1001\...\Run: [Google Update] => C:\Users\Sergio\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-18] (Google Inc.)
HKU\S-1-5-21-1478414814-3749218601-3539646535-1001\...\Run: [f.lux] => C:\Users\Sergio\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-1478414814-3749218601-3539646535-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9364696 2017-03-03] (Piriform Ltd)
HKU\S-1-5-21-1478414814-3749218601-3539646535-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [799376 2016-12-14] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-1478414814-3749218601-3539646535-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-1478414814-3749218601-3539646535-1001\...\MountPoints2: {b52f257e-9541-11e6-82b3-485b39c9a198} - "K:\HiSuiteDownLoader.exe"
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Keine Datei
ShellIconOverlayIdentifiers: [00ExpanDriveExt1] -> {C955792B-31A0-4791-9DDE-0A9A57411C16} => -> Keine Datei
ShellIconOverlayIdentifiers: [00ExpanDriveExt2] -> {C955792C-31A0-4791-9DDE-0A9A57411C16} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [00ExpanDriveExt1] -> {C955792B-31A0-4791-9DDE-0A9A57411C16} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [00ExpanDriveExt2] -> {C955792C-31A0-4791-9DDE-0A9A57411C16} => -> Keine Datei
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Audible Download Manager.lnk [2015-05-07]
ShortcutTarget: Audible Download Manager.lnk -> C:\Program Files (x86)\Audible\Bin\AudibleDownloadHelper.exe (Keine Datei)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FocalFilterHelper.lnk [2016-02-26]
ShortcutTarget: FocalFilterHelper.lnk -> C:\Program Files (x86)\FocalFilter\FocalFilterHelper.exe (Microsoft)
Startup: C:\Users\Sergio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2015-08-09]
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Sergio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2016-04-20]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy\User: Beschränkung <======= ACHTUNG
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{65462354-7EE1-4401-902C-4D58B7DBDA87}: [DhcpNameServer] 7.254.254.254
Tcpip\..\Interfaces\{8c608b9e-9074-4d1b-b1db-702840d39f03}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{aa6288ab-a4c6-4734-8fa6-9d9b694d76cd}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131343881188462559&GUID=D7BDAEA9-5712-40E5-A2B9-98992E8B0FDB
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131343881188468475&GUID=D7BDAEA9-5712-40E5-A2B9-98992E8B0FDB
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1478414814-3749218601-3539646535-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\AvGeneric_S-1-5-21-1478414814-3749218601-3539646535-1007 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1478414814-3749218601-3539646535-1001 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-1478414814-3749218601-3539646535-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-03-18] (Oracle Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-18] (Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2016-10-31] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Sergio\AppData\Roaming\Mozilla\Firefox\Profiles\0fihcjle.default [2017-03-19]
FF NewTab: Mozilla\Firefox\Profiles\0fihcjle.default -> about:newtab
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\0fihcjle.default -> Google
FF DefaultSearchUrl: Mozilla\Firefox\Profiles\0fihcjle.default -> hxxps://www.google.com/search?bcutc=sp-006
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\0fihcjle.default -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\0fihcjle.default -> Google
FF Homepage: Mozilla\Firefox\Profiles\0fihcjle.default -> about:home
FF Keyword.URL: Mozilla\Firefox\Profiles\0fihcjle.default -> hxxps://www.google.com/search?bcutc=sp-006
FF Extension: (BeeLine Reader) - C:\Users\Sergio\AppData\Roaming\Mozilla\Firefox\Profiles\0fihcjle.default\Extensions\beelinereader-firefox@beelinereader.com.xpi [2016-03-08]
FF Extension: (FoxyProxy Standard) - C:\Users\Sergio\AppData\Roaming\Mozilla\Firefox\Profiles\0fihcjle.default\Extensions\foxyproxy@eric.h.jung [2017-02-07]
FF Extension: (convert2mp3.net YouTube2MP3 Converter) - C:\Users\Sergio\AppData\Roaming\Mozilla\Firefox\Profiles\0fihcjle.default\Extensions\info@convert2mp3.net.xpi [2016-12-15]
FF Extension: (pdf updater) - C:\Users\Sergio\AppData\Roaming\Mozilla\Firefox\Profiles\0fihcjle.default\Extensions\{34840d80-0446-4a42-83ce-5c0fa22cd4e3}.xpi [2016-05-18] [ist nicht signiert]
FF Extension: (NoScript) - C:\Users\Sergio\AppData\Roaming\Mozilla\Firefox\Profiles\0fihcjle.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-08-13]
FF Extension: (LeechBlock) - C:\Users\Sergio\AppData\Roaming\Mozilla\Firefox\Profiles\0fihcjle.default\Extensions\{a95d8332-e4b4-6e7f-98ac-20b733364387} [2017-01-22]
FF Extension: (Adblock Plus) - C:\Users\Sergio\AppData\Roaming\Mozilla\Firefox\Profiles\0fihcjle.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-24]
FF Extension: (DownThemAll!) - C:\Users\Sergio\AppData\Roaming\Mozilla\Firefox\Profiles\0fihcjle.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-04-15]
FF SearchPlugin: C:\Users\Sergio\AppData\Roaming\Mozilla\Firefox\Profiles\0fihcjle.default\searchplugins\google-avast.xml [2017-03-18]
FF HKLM\...\Firefox\Extensions: [soda_pdf_desktop_conv@sodapdf.com] - C:\Program Files\Soda PDF Desktop\resources\sodapdfdesktopfirefoxextension => nicht gefunden
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll [2017-03-18] ()
FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-18] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-03-18] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin-x32: Soda PDF Desktop -> C:\Program Files (x86)\Soda PDF Desktop\np-previewer.dll [Keine Datei]
FF Plugin HKU\S-1-5-21-1478414814-3749218601-3539646535-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Sergio\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin HKU\S-1-5-21-1478414814-3749218601-3539646535-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Sergio\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-07-19] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Sergio\AppData\Local\Google\Chrome\User Data\Default [2017-03-18]
CHR Extension: (Google Präsentationen) - C:\Users\Sergio\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-26]
CHR Extension: (Google Docs) - C:\Users\Sergio\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-26]
CHR Extension: (Google Drive) - C:\Users\Sergio\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-11]
CHR Extension: (YouTube) - C:\Users\Sergio\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-11]
CHR Extension: (Google-Suche) - C:\Users\Sergio\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-03-11]
CHR Extension: (Google Tabellen) - C:\Users\Sergio\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-26]
CHR Extension: (Google Docs Offline) - C:\Users\Sergio\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-21]
CHR Extension: (AMZ Seller Browser) - C:\Users\Sergio\AppData\Local\Google\Chrome\User Data\Default\Extensions\klgpelgeohjghmccooegimcfhanlnngc [2016-05-09]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Sergio\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-12]
CHR Extension: (Google Mail) - C:\Users\Sergio\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-01]
CHR Extension: (Chrome Media Router) - C:\Users\Sergio\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-11]
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 chip1click; C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe [91136 2016-10-27] (Chip Digital GmbH) [Datei ist nicht signiert]
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [197776 2016-12-14] (Sandboxie Holdings, LLC)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
R2 Tenable Nessus; C:\Program Files\Tenable\Nessus\nessus-service.exe [17376 2017-02-15] (Tenable Network Security, Inc)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
S3 Soda PDF Desktop; "C:\Program Files\Soda PDF Desktop\ws.exe" [X]
S3 Soda PDF Desktop CrashHandler; "C:\Program Files\Soda PDF Desktop\crash-handler-ws.exe" [X]
S2 Soda PDF Desktop Creator; "C:\Program Files\Soda PDF Desktop\creator-ws.exe" [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [23240 2016-02-26] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102400 2016-02-26] (Advanced Micro Devices)
S3 HTCAND64; C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (HTC, Corporation) [Datei ist nicht signiert]
S3 HtcVCom32; C:\WINDOWS\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated) [Datei ist nicht signiert]
R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] ()
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
S3 RtlWlanu_OldIC; C:\WINDOWS\System32\drivers\rtwlanu_oldIC.sys [3814400 2016-07-16] (Realtek Semiconductor Corporation )
S3 rzdaendpt; C:\WINDOWS\System32\drivers\rzdaendpt.sys [33448 2014-09-05] (Razer Inc)
S3 rzvkeyboard; C:\WINDOWS\System32\drivers\rzvkeyboard.sys [31912 2014-09-05] (Razer Inc)
S3 SaiK0728; C:\WINDOWS\system32\DRIVERS\SaiK0728.sys [129024 2008-01-21] (Saitek)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [205968 2016-12-14] (Sandboxie Holdings, LLC)
R1 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [131144 2017-01-16] (Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [205440 2017-01-16] (Oracle Corporation)
R0 vsock; C:\WINDOWS\System32\drivers\vsock.sys [73296 2013-10-08] (VMware, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
U3 DfSdkS; kein ImagePath
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-03-19 13:51 - 2017-03-19 13:52 - 00022199 _____ C:\Users\Sergio\Desktop\FRST.txt
2017-03-19 13:44 - 2017-03-19 13:49 - 00082710 _____ C:\TDSSKiller.3.1.0.12_19.03.2017_13.44.46_log.txt
2017-03-19 13:44 - 2017-03-19 13:44 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Sergio\Desktop\tdsskiller.exe
2017-03-19 11:34 - 2017-03-19 11:34 - 00000085 _____ C:\WINDOWS\wininit.ini
2017-03-19 11:34 - 2017-03-19 11:34 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2017-03-19 10:13 - 2017-03-18 23:42 - 00032088 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswCD5C.tmp
2017-03-19 10:13 - 2017-03-18 23:41 - 00548928 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswCE6B.tmp
2017-03-19 10:13 - 2017-03-18 23:41 - 00337592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswCE8B.tmp
2017-03-19 10:13 - 2017-03-18 23:41 - 00162528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswCEFA.tmp
2017-03-19 10:13 - 2017-03-18 23:41 - 00126600 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswCE4A.tmp
2017-03-19 10:13 - 2017-03-18 23:41 - 00100640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswCDBB.tmp
2017-03-19 10:13 - 2017-03-18 23:41 - 00075704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswCE5B.tmp
2017-03-19 10:13 - 2017-03-18 23:41 - 00038296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswCE39.tmp
2017-03-19 10:13 - 2017-03-18 23:40 - 00993608 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswCD8B.tmp
2017-03-19 10:13 - 2017-03-18 23:40 - 00334600 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswCC50.tmp
2017-03-19 10:13 - 2017-03-18 23:40 - 00309272 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswCC0F.tmp
2017-03-19 10:13 - 2017-03-18 23:40 - 00189768 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswCC30.tmp
2017-03-19 10:13 - 2017-03-18 23:40 - 00048528 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswCC70.tmp
2017-03-19 02:00 - 2017-03-19 02:00 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\QuickScan
2017-03-19 01:43 - 2017-03-19 13:51 - 00000000 ____D C:\FRST
2017-03-19 01:42 - 2017-03-19 01:42 - 02424832 _____ (Farbar) C:\Users\Sergio\Desktop\FRST64.exe
2017-03-19 01:12 - 2017-03-19 01:12 - 00000000 ____D C:\Users\Sergio\AppData\Local\AdAwareDesktop
2017-03-19 01:10 - 2017-03-19 01:10 - 00000000 ____D C:\Users\Sergio\AppData\Local\AdAwareUpdater
2017-03-19 01:10 - 2017-03-19 01:10 - 00000000 ____D C:\Program Files\Common Files\adaware
2017-03-19 01:07 - 2017-03-19 11:34 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-03-19 01:07 - 2017-03-19 11:34 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-03-19 01:05 - 2017-03-19 01:06 - 00001748 _____ C:\WINDOWS\Sandboxie.ini
2017-03-19 01:05 - 2017-03-19 01:04 - 00000955 _____ C:\Users\Sergio\Desktop\Sandboxed Web Browser.lnk
2017-03-19 01:04 - 2017-03-19 01:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
2017-03-19 01:04 - 2017-03-19 01:04 - 00000000 ____D C:\Program Files\Sandboxie
2017-03-19 01:02 - 2017-03-19 01:02 - 00000000 ___HD C:\$SysReset
2017-03-19 01:02 - 2017-03-19 01:02 - 00000000 ____D C:\WINDOWS\Panther
2017-03-19 00:06 - 2017-03-19 00:06 - 00217088 _____ C:\Users\postgres\NTUSER.rhk
2017-03-19 00:03 - 2017-03-19 00:03 - 00015836 _____ C:\Users\Sergio\Documents\cc_20170319_000336.reg
2017-03-18 23:51 - 2017-03-18 23:51 - 00001822 _____ C:\Users\Public\Desktop\iTunes.lnk
2017-03-18 23:51 - 2017-03-18 23:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2017-03-18 23:50 - 2017-03-18 23:51 - 00000000 ____D C:\Program Files\iTunes
2017-03-18 23:50 - 2017-03-18 23:50 - 00000000 ____D C:\Program Files\iPod
2017-03-18 23:49 - 2017-03-18 23:49 - 00000000 ____D C:\Program Files\Bonjour
2017-03-18 23:49 - 2017-03-18 23:49 - 00000000 ____D C:\Program Files (x86)\Bonjour
2017-03-18 23:42 - 2017-03-18 23:42 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\AVAST Software
2017-03-18 23:41 - 2017-03-18 23:41 - 00547904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys.148987690906204
2017-03-18 23:41 - 2017-03-18 23:41 - 00337592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys.148987691079606
2017-03-18 23:41 - 2017-03-18 23:41 - 00000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software
2017-03-18 23:41 - 2017-03-18 23:41 - 00000000 ____D C:\Program Files\Common Files\AV
2017-03-18 23:40 - 2017-03-18 23:42 - 00000000 ____D C:\Program Files\AVAST Software
2017-03-18 23:39 - 2017-03-19 10:14 - 00000000 ____D C:\ProgramData\AVAST Software
2017-03-18 23:01 - 2017-03-19 00:06 - 04333568 _____ C:\Users\Sergio\NTUSER.rhk
2017-03-18 23:01 - 2017-03-18 23:01 - 00004058 _____ C:\WINDOWS\System32\Tasks\Wise Registry Cleaner Schedule Task
2017-03-18 22:57 - 2017-03-18 22:57 - 00763016 _____ C:\Users\Sergio\Documents\cc_20170318_225706.reg
2017-03-18 22:55 - 2017-03-18 22:55 - 00001329 _____ C:\Users\Public\Desktop\Ashampoo WinOptimizer 2017.lnk
2017-03-18 22:55 - 2017-03-18 22:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2017-03-18 22:55 - 2017-03-18 22:55 - 00000000 ____D C:\ProgramData\Ashampoo
2017-03-18 22:55 - 2017-03-18 22:55 - 00000000 ____D C:\Program Files (x86)\Ashampoo
2017-03-18 22:55 - 2009-08-24 21:13 - 00034304 _____ (mst software GmbH, Germany) C:\WINDOWS\system32\DfSdkBt.exe
2017-03-18 22:53 - 2017-03-18 23:01 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\Wise Registry Cleaner
2017-03-18 22:53 - 2017-03-18 23:01 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\Wise Euask
2017-03-18 22:53 - 2017-03-18 22:53 - 00001304 _____ C:\Users\Public\Desktop\Wise Registry Cleaner.lnk
2017-03-18 22:53 - 2017-03-18 22:53 - 00000000 ____D C:\WINDOWS\System32\Tasks\WiseCleaner
2017-03-18 22:53 - 2017-03-18 22:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner
2017-03-18 22:53 - 2017-03-18 22:53 - 00000000 ____D C:\Program Files (x86)\Wise
2017-03-18 22:53 - 2017-03-18 22:53 - 00000000 ____D C:\Program Files (x86)\Chip Digital GmbH
2017-03-18 22:48 - 2017-03-18 22:48 - 00002862 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2017-03-18 22:48 - 2017-03-18 22:48 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-03-18 22:48 - 2017-03-18 22:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-03-18 22:48 - 2017-03-18 22:48 - 00000000 ____D C:\Program Files\CCleaner
2017-03-18 22:25 - 2016-06-05 07:42 - 00000000 ____D C:\Users\Sergio\Desktop\Python 3 - Intensivkurs Projekte erfolgreich realisieren By Mark Pilgrim
2017-03-18 21:48 - 2016-09-01 12:09 - 00000000 ____D C:\Users\Sergio\Desktop\Yael Adler - Haut nah. Alles über unser größtes Organ inkl. pdf
2017-03-18 21:47 - 2016-10-17 16:46 - 00000000 ____D C:\Users\Sergio\Desktop\Nadja Hermann - Fettlogik überwinden
2017-03-18 01:04 - 2017-03-17 21:06 - 00000000 ____D C:\Users\Sergio\Desktop\Gunter Dueck - Flachsinn_ Ich habe Hirn, ich will hier raus
2017-03-16 21:27 - 2016-11-24 02:24 - 00000000 ____D C:\Users\Sergio\Desktop\Haiyti - Nightliner (2016)
2017-03-13 20:44 - 2017-03-13 20:44 - 14966655 _____ C:\Users\Sergio\Desktop\3662536676.psychologie.der.maerchen.2017.by.www.lul.to.pdf
2017-03-12 12:29 - 2017-03-12 12:26 - 00074345 ____N C:\Users\Sergio\Desktop\11057856.pdf
2017-03-11 11:55 - 2017-03-11 11:55 - 00000000 ____D C:\Users\Sergio\AppData\Local\TeamSpeak 3
2017-03-11 11:55 - 2017-03-11 11:55 - 00000000 ____D C:\Users\Sergio\.TeamSpeak 3
2017-03-10 22:56 - 2017-03-10 22:56 - 00000000 ____D C:\Users\Sergio\PycharmProjects
2017-03-10 22:55 - 2017-03-10 22:55 - 00001078 _____ C:\Users\Sergio\Desktop\JetBrains PyCharm Community Edition 2016.3.2.lnk
2017-03-10 22:55 - 2017-03-10 22:55 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\JetBrains
2017-03-10 22:55 - 2017-03-10 22:55 - 00000000 ____D C:\Users\Sergio\.PyCharmCE2016.3
2017-03-10 22:54 - 2017-03-10 22:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JetBrains
2017-03-10 22:54 - 2017-03-10 22:54 - 00000000 ____D C:\Program Files (x86)\JetBrains
2017-03-09 16:03 - 2017-03-09 16:03 - 00002713 _____ C:\Users\Sergio\Desktop\IDLE (Python 3.6 64-bit).lnk
2017-03-09 16:03 - 2017-03-09 16:03 - 00001520 _____ C:\Users\Sergio\Desktop\Python 3.6 (64-bit).lnk
2017-03-09 15:59 - 2017-03-09 15:59 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.6
2017-03-09 15:59 - 2017-03-09 15:59 - 00000000 ____D C:\Users\Sergio\AppData\Local\Package Cache
2017-03-08 16:00 - 2017-03-08 16:00 - 06744873 ____R C:\Users\Sergio\Desktop\3658108576.ich.glaube.es.hackt.2016.4.auflage.by.www.lul.to.pdf
2017-03-06 19:08 - 2017-03-06 19:08 - 00004296 _____ C:\WINDOWS\System32\Tasks\AMD Updater
2017-03-06 19:07 - 2017-03-06 19:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings
2017-03-06 18:50 - 2017-03-06 18:50 - 00000000 ____D C:\Users\Sergio\.Plays.tv
2017-03-05 18:37 - 2017-01-01 17:08 - 00000000 ____D C:\Users\Sergio\Desktop\Tory Lanez - Chixtape 4 (DatPiff.com)
2017-03-05 18:27 - 2017-03-05 18:27 - 00000000 ____D C:\ProgramData\GeoComply
2017-03-04 21:04 - 2017-03-04 21:06 - 00000000 ____D C:\Users\Sergio\VirtualBox VMs
2017-03-04 20:55 - 2017-03-05 14:02 - 00000000 ____D C:\Users\Sergio\.VirtualBox
2017-03-04 20:55 - 2017-03-04 20:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2017-03-04 20:55 - 2017-03-04 20:55 - 00000000 ____D C:\Program Files\Oracle
2017-03-04 20:55 - 2017-01-16 17:38 - 00959720 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxDrv.sys
2017-03-04 20:55 - 2017-01-16 17:38 - 00149304 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxUSBMon.sys
2017-03-01 23:49 - 2017-03-17 23:57 - 00001024 _____ C:\.rnd
2017-03-01 23:49 - 2017-03-01 23:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tenable Network Security
2017-03-01 23:48 - 2017-03-01 23:48 - 00000000 ____D C:\ProgramData\Tenable
2017-03-01 23:48 - 2017-03-01 23:48 - 00000000 ____D C:\Program Files\Tenable
2017-02-28 21:46 - 2017-03-05 11:48 - 00000000 ____D C:\Users\Sergio\Desktop\Ethic Hacking
2017-02-28 21:33 - 2017-02-28 21:33 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\.maltego
2017-02-28 21:33 - 2017-02-28 21:33 - 00000000 ____D C:\ProgramData\Paterva
2017-02-28 21:33 - 2017-02-28 21:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paterva
2017-02-28 21:32 - 2017-02-28 21:32 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\Sun
2017-02-28 21:32 - 2017-02-28 21:32 - 00000000 ____D C:\Program Files (x86)\Paterva
2017-02-28 21:31 - 2017-03-18 23:51 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2017-02-28 21:31 - 2017-03-18 23:51 - 00000000 ____D C:\Program Files\Java
2017-02-27 22:16 - 2015-06-24 14:30 - 00064728 _____ (VMware, Inc.) C:\WINDOWS\system32\Drivers\vmx86.sys
2017-02-27 22:16 - 2013-10-08 18:21 - 00073296 _____ (VMware, Inc.) C:\WINDOWS\system32\Drivers\vsock.sys
2017-02-27 22:16 - 2013-10-08 18:21 - 00067664 _____ (VMware, Inc.) C:\WINDOWS\system32\vsocklib.dll
2017-02-27 22:16 - 2013-10-08 18:21 - 00063568 _____ (VMware, Inc.) C:\WINDOWS\SysWOW64\vsocklib.dll
2017-02-27 22:15 - 2015-06-24 14:30 - 00437976 _____ (VMware, Inc.) C:\WINDOWS\SysWOW64\vmnat.exe
2017-02-27 22:15 - 2015-06-24 14:30 - 00359128 _____ (VMware, Inc.) C:\WINDOWS\SysWOW64\vmnetdhcp.exe
2017-02-27 22:15 - 2015-06-24 14:27 - 00031448 _____ (VMware, Inc.) C:\WINDOWS\system32\Drivers\vmnetuserif.sys
2017-02-27 22:14 - 2017-02-27 22:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
2017-02-27 22:14 - 2017-02-27 22:14 - 00000000 ____D C:\Program Files\Common Files\VMware
2017-02-27 22:14 - 2017-02-27 22:14 - 00000000 ____D C:\Program Files (x86)\VMware
2017-02-27 22:14 - 2015-06-24 14:27 - 00931032 _____ (VMware, Inc.) C:\WINDOWS\system32\vnetlib64.dll
2017-02-27 22:14 - 2014-08-21 08:07 - 00054976 _____ (VMware, Inc.) C:\WINDOWS\system32\Drivers\hcmon.sys
2017-02-27 22:14 - 2014-08-21 08:06 - 00058048 _____ (VMware, Inc.) C:\WINDOWS\system32\Drivers\vmusb.sys
2017-02-27 22:11 - 2017-02-27 22:42 - 00000000 ____D C:\Users\Sergio\Documents\Virtual Machines
2017-02-27 19:48 - 2017-02-27 19:48 - 00000000 ____D C:\Users\Sergio\.idlerc
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-03-19 13:41 - 2016-09-29 20:02 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-19 11:34 - 2016-09-29 20:05 - 00000000 ____D C:\Users\Sergio
2017-03-19 11:34 - 2016-07-16 07:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-03-19 11:34 - 2015-06-02 19:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-03-19 03:10 - 2016-10-04 16:41 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2017-03-19 00:55 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-03-19 00:37 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-19 00:07 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-19 00:06 - 2016-09-29 20:05 - 00000000 ____D C:\Users\postgres
2017-03-18 23:52 - 2016-09-29 20:14 - 00004440 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-03-18 23:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-03-18 23:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-03-18 23:52 - 2014-10-27 17:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-03-18 23:52 - 2014-10-26 12:23 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-03-18 23:52 - 2014-10-26 12:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-03-18 23:52 - 2014-10-26 12:23 - 00000000 ____D C:\Program Files\WinRAR
2017-03-18 23:51 - 2014-10-26 12:41 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-03-18 23:50 - 2015-05-06 18:27 - 00000000 ____D C:\Program Files\Common Files\Apple
2017-03-18 23:49 - 2014-10-26 00:07 - 00001151 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-03-18 23:02 - 2015-03-10 17:03 - 00000000 ____D C:\Users\Sergio\AppData\LocalLow\Temp
2017-03-18 22:59 - 2014-10-26 12:50 - 00000000 ____D C:\Users\Sergio\AppData\Local\JDownloader v2.0
2017-03-18 22:55 - 2016-09-23 20:37 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\TS3Client
2017-03-18 22:55 - 2014-11-05 17:58 - 00000000 ____D C:\Program Files (x86)\Steam
2017-03-18 22:50 - 2014-10-26 10:16 - 00000000 ____D C:\Users\Sergio\AppData\Local\Razer
2017-03-18 22:50 - 2014-10-26 00:15 - 00000000 ____D C:\ProgramData\Razer
2017-03-18 22:50 - 2014-10-26 00:15 - 00000000 ____D C:\Program Files (x86)\Razer
2017-03-18 21:23 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-03-18 00:59 - 2014-10-27 09:42 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\vlc
2017-03-18 00:21 - 2014-10-29 14:39 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-03-18 00:19 - 2015-04-16 15:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-03-18 00:19 - 2014-10-29 14:39 - 138634176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-03-18 00:18 - 2015-04-16 15:08 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-03-18 00:18 - 2015-04-16 15:08 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-03-18 00:18 - 2014-10-26 12:31 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2017-03-18 00:15 - 2016-11-05 15:37 - 00000000 ____D C:\Users\Sergio\AppData\Local\ElevatedDiagnostics
2017-03-18 00:14 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-18 00:00 - 2016-07-16 23:51 - 01032822 _____ C:\WINDOWS\system32\perfh007.dat
2017-03-18 00:00 - 2016-07-16 23:51 - 00243530 _____ C:\WINDOWS\system32\perfc007.dat
2017-03-18 00:00 - 2015-08-09 20:57 - 02469750 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-17 23:52 - 2014-10-27 17:10 - 00000000 ____D C:\ProgramData\VMware
2017-03-17 23:51 - 2016-09-29 20:14 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-16 22:25 - 2016-07-16 07:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-03-16 21:23 - 2013-08-22 14:25 - 00000167 _____ C:\WINDOWS\win.ini
2017-03-14 19:22 - 2014-12-23 17:29 - 00000000 ____D C:\Users\Sergio\AppData\Local\Spotify
2017-03-13 20:27 - 2014-10-27 17:14 - 00000000 ____D C:\Users\Sergio\AppData\Local\VMware
2017-03-13 19:32 - 2014-12-23 17:28 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\Spotify
2017-03-13 19:07 - 2014-10-27 17:14 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\VMware
2017-03-11 14:19 - 2016-10-23 19:11 - 00000000 ____D C:\Users\Sergio\Documents\Soda PDF Files
2017-03-11 14:19 - 2016-10-23 19:11 - 00000000 ____D C:\Users\Sergio\AppData\Roaming\Soda PDF Desktop
2017-03-11 12:13 - 2014-12-13 14:35 - 00000000 ____D C:\Users\Sergio\AppData\Local\PokerStars.EU
2017-03-11 12:12 - 2014-12-13 14:34 - 00000000 ____D C:\Program Files (x86)\PokerStars.EU
2017-03-11 11:55 - 2016-09-23 20:37 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2017-03-10 06:17 - 2016-07-16 12:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-03-10 06:17 - 2016-07-16 12:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-03-06 19:07 - 2016-09-29 20:03 - 00000000 ____D C:\Program Files\AMD
2017-03-06 19:07 - 2015-05-19 18:55 - 00000000 ____D C:\Program Files (x86)\AMD
2017-03-06 19:07 - 2014-10-26 00:19 - 00000000 ____D C:\Users\Sergio\AppData\Local\AMD
2017-03-06 19:04 - 2014-10-26 00:14 - 00000000 ____D C:\AMD
2017-03-06 18:50 - 2016-09-29 20:03 - 00000000 ____D C:\ProgramData\Package Cache
2017-03-06 18:48 - 2016-09-29 20:03 - 00000000 ____D C:\ProgramData\AMD
2017-03-04 23:55 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-02-28 21:32 - 2016-02-14 18:43 - 00000000 ____D C:\Users\Sergio\.oracle_jre_usage
2017-02-27 22:14 - 2014-10-27 17:10 - 02053002 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2017-02-25 11:31 - 2014-10-25 23:53 - 00000000 ____D C:\Users\Sergio\AppData\Local\Packages
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2015-07-20 16:32 - 2015-07-20 16:32 - 0923401 _____ () C:\Program Files (x86)\WinDlg_124.zip
2015-07-12 10:02 - 2015-07-12 10:02 - 0000000 ___SH () C:\Users\Sergio\AppData\Local\LumaEmu
2016-07-03 18:51 - 2016-07-03 18:51 - 0000733 _____ () C:\Users\Sergio\AppData\Local\recently-used.xbel
2016-09-29 20:03 - 2016-09-29 20:03 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-07-06 20:11 - 2015-07-06 20:11 - 0005036 _____ () C:\ProgramData\flwjycbm.bab
Einige Dateien in TEMP:
====================
2017-03-19 03:10 - 2017-03-19 03:10 - 0192512 _____ () C:\Users\Sergio\AppData\Local\Temp\sfamcc00001.dll
2017-03-19 03:10 - 2017-03-19 03:10 - 0158720 _____ () C:\Users\Sergio\AppData\Local\Temp\sfareca00001.dll
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2017-03-18 21:07
==================== Ende von FRST.txt ============================ |