FRST Addition: Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-03-2017
durchgeführt von Ulla (04-04-2017 20:13:44)
Gestartet von C:\Users\Ulla\Desktop
Windows 10 Home Version 1607 (X64) (2016-09-25 07:55:42)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-1799405637-2938259579-1905707483-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1799405637-2938259579-1905707483-503 - Limited - Disabled)
Gast (S-1-5-21-1799405637-2938259579-1905707483-501 - Limited - Disabled)
Ulla (S-1-5-21-1799405637-2938259579-1905707483-1002 - Administrator - Enabled) => C:\Users\Ulla
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Avira Antivirus (Enabled - Up to date) {B3F630BD-538D-1B4A-14FA-14B63235278F}
AV: Kaspersky Free (Disabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Avira Antivirus (Enabled - Up to date) {0897D159-75B7-14C4-2E4A-2FC449B26D32}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Kaspersky Free (Disabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
ActivDriver x64 v5.9 (HKLM\...\{633EB44A-B19A-409E-8321-78B363553398}) (Version: 5.9.27 - Promethean)
ActivInspire Core Resources (DEU) v1 (HKLM-x32\...\{06C9F624-9F53-4C89-9720-1601A295769A}) (Version: 1.6.3 - Promethean)
ActivInspire Help (DEU) v1 (HKLM-x32\...\{B18A62F5-296F-4BC4-B8DD-A9FB16EE9106}) (Version: 1.6.3 - Promethean)
ActivInspire HWR Resources (DEU) v1 (HKLM-x32\...\{CB2158F5-B05D-41BF-B8F8-05A85695BA4E}) (Version: 1.7.1 - Promethean)
ActivInspire v2 (HKLM-x32\...\{7327AE03-C66E-410B-AD29-A7AA991FB3B4}) (Version: 2.8.66693 - Promethean)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.127 - Adobe Systems Incorporated)
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
AMD Catalyst Install Manager (HKLM\...\{654E38F8-81EE-3159-F215-D4BF3DC0441E}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.25.172 - Avira Operations GmbH & Co. KG)
Avira Connect (HKLM-x32\...\{0b46d918-af4f-4612-8076-5c0ae67cb2aa}) (Version: 1.2.81.41506 - Avira Operations GmbH & Co. KG)
Avira Connect (x32 Version: 1.2.81.41506 - Avira Operations GmbH & Co. KG) Hidden
Brother MFL-Pro Suite DCP-9022CDW (HKLM-x32\...\{E98A9C92-E767-475B-8BC6-8780A86DDC72}) (Version: 1.0.5.0 - Brother Industries, Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 5.28 - Piriform)
Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.22 - Cliqz.com)
CyberLink PowerDirector (Version: 9.0.0.5129 - CyberLink Corp.) Hidden
CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.7.0.0913 - CyberLink Corp.)
CyberLink PowerRecover (Version: 5.7.0.0913 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
Die Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.21.37.1020 - Electronic Arts Inc.)
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Fotogalerija (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Fotogalleri (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Fotogalleriet (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Fotoğraf Galerisi (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Fotótár (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galeria de Fotografias (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galeria fotografii (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 57.0.2987.133 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Photosmart 5520 series - Grundlegende Software für das Gerät (HKLM\...\{4F396B08-301D-4E53-A372-95A7E93ABD04}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Photosmart 5520 series Hilfe (HKLM-x32\...\{640A03B3-4E6B-4440-A350-E6A8D6348F12}) (Version: 27.0.0 - Hewlett Packard)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
Kaspersky Free (HKLM-x32\...\InstallWIX_{E27B1D7B-3B34-43A2-9FC0-9828D5DF46E2}) (Version: 17.0.0.611 - Лаборатория Касперского)
Kaspersky Free (x32 Version: 17.0.0.611 - Лаборатория Касперского) Hidden
LINE (HKLM-x32\...\LINE) (Version: 4.4.1.827 - LINE Corporation)
Malwarebytes Version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Medion Home Cinema 10 (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.)
Medion Home Cinema 10 (x32 Version: 10.2419 - CyberLink Corp.) Hidden
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50905.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{4fd02573-5f12-4ae4-8027-c63f8e1115af}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Nuance PaperPort 12 (HKLM-x32\...\{2A770862-7142-4C77-8117-F933E4110A3F}) (Version: 12.1.0006 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
OpenOffice 4.1.3 (HKLM-x32\...\{8D5FCC56-BB9F-4122-923C-71753F50F6F5}) (Version: 4.13.9783 - Apache Software Foundation)
OpenOffice Updater (HKU\S-1-5-21-1799405637-2938259579-1905707483-1002\...\OpenOffice Updater) (Version: 1.1.10 - OpenOffice)
OpenOffice Updater (HKU\S-1-5-21-1799405637-2938259579-1905707483-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04042017155829109\...\OpenOffice Updater) (Version: 1.1.10 - OpenOffice)
Origin (HKLM-x32\...\Origin) (Version: 9.4.21.2812 - Electronic Arts, Inc.)
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 14.00.0000 - Nuance Communications, Inc.)
Pelikan Egypt (HKLM-x32\...\Pelikan Egypt) (Version: - )
PhotoNow (x32 Version: 1.1.7717 - CyberLink Corp.) Hidden
Podstawowe programy Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Raccolta foto (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Scansoft PDF Professional (x32 Version: - ) Hidden
SchoolCraft Premium Content (HKLM-x32\...\{474EE743-9983-4765-9073-0143C3FEB0C4}_is1) (Version: 2016.2.2.230 - SchoolCraft GmbH)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.29 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.102 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-1799405637-2938259579-1905707483-1002\...\Spotify) (Version: 1.0.51.693.g6ea1e7f6 - Spotify AB)
Spotify (HKU\S-1-5-21-1799405637-2938259579-1905707483-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04042017155829109\...\Spotify) (Version: 1.0.51.693.g6ea1e7f6 - Spotify AB)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer)
Valokuvavalikoima (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Worksheet Crafter (HKLM-x32\...\{BA0ADF97-5ED4-415F-AA1B-1716582FF267}_is1) (Version: 2017.1.0.530 - SchoolCraft GmbH)
Συλλογή φωτογραφιών (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {0D2E6080-684D-47B7-A46D-0D6B30CC58E1} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Keine Datei <==== ACHTUNG
Task: {0ECB6CFB-0C05-41F5-B3E8-A5C75311321A} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-03-16] (Microsoft Corporation)
Task: {16C3A65C-22AA-49EA-A47E-A98785FD730D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {1FC8425D-57D8-4991-A937-7410CDD9578B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => %SystemRoot%\System32\AutoWorkplace.exe
Task: {361685ED-E4D4-497C-8F85-82A00248626C} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-03-21] (Adobe Systems Incorporated)
Task: {383976A5-4C89-429C-A902-A0DB5CF27BC4} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {4AA447AB-73F5-4030-A272-8E978D32AC0E} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {5AB9EB6E-E0E6-4403-A825-70DD3273B98A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {680C19D9-B340-42BA-AFC9-8BDB54A0F9B4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-04-03] (Google Inc.)
Task: {6A594B3C-D739-4E28-B760-F3B2F00593B8} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {778CF135-AE78-4C00-B149-EE999046C95C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-03-03] (Piriform Ltd)
Task: {7F6887D9-8187-4FF8-9616-6016EC820BBF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-04-03] (Google Inc.)
Task: {8337D830-DA61-4F7F-98F8-B0365294B728} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {9DF451D0-B910-4611-8981-2201AB093CFD} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {A3A9F515-3D9C-43DA-9C48-C18D89C626B3} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {B39FDDC0-AE38-4D50-B90C-D0ABCC9F6183} - \WPD\SqmUpload_S-1-5-21-1799405637-2938259579-1905707483-1002 -> Keine Datei <==== ACHTUNG
Task: {CBD25D40-12DF-4281-B218-C92F50C12477} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {CCD78865-CE3C-4E1B-A3A9-27C096627C7F} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {EEDC5C84-D0D9-46F1-9F7F-3154D60D194E} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
==================== Verknüpfungen =============================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MEDIONhome.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.medion.com
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Welcome.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.aldi-essen.de
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2015-11-04 16:43 - 2015-11-04 16:43 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2013-07-18 10:37 - 2010-08-19 18:43 - 00386344 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2017-04-03 23:20 - 2017-03-24 04:09 - 02271520 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-04-03 23:20 - 2017-03-24 04:10 - 02267600 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-03-14 23:22 - 2017-03-04 09:19 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2017-03-14 23:22 - 2017-03-04 09:19 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2017-03-14 23:22 - 2017-03-04 09:19 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-09-25 22:05 - 2016-09-25 22:05 - 00959168 _____ () C:\Users\Ulla\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2016-09-25 10:11 - 2016-09-25 10:11 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-03-14 23:21 - 2017-03-04 08:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-03-14 23:22 - 2017-03-04 08:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-03-14 23:22 - 2017-03-04 08:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-14 23:22 - 2017-03-04 08:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-03-14 23:22 - 2017-03-04 08:05 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-03-14 23:22 - 2017-03-04 08:05 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-03-14 23:22 - 2017-03-04 08:08 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2013-11-22 13:51 - 2013-11-22 13:51 - 00683872 _____ () C:\Program Files\Activ Software\ActivDriver\ActivMgr.exe
2013-11-22 13:51 - 2013-11-22 13:51 - 00523152 _____ () C:\Program Files\Activ Software\ActivDriver\FlashExtension\flashbridge-wrapper-crossplatform.exe
2015-11-04 16:43 - 2015-11-04 16:43 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2016-05-15 13:10 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2013-11-22 13:52 - 2013-11-22 13:52 - 00190824 _____ () C:\WINDOWS\libactivboardex.dll
2013-11-22 13:51 - 2013-11-22 13:51 - 00087392 _____ () C:\Program Files\Activ Software\ActivDriver\FlashExtension\activsdk2.dll
2013-11-22 13:51 - 2013-11-22 13:51 - 00341848 _____ () C:\Program Files\Activ Software\ActivDriver\FlashExtension\QtXml4.dll
2013-11-22 13:51 - 2013-11-22 13:51 - 07989592 _____ () C:\Program Files\Activ Software\ActivDriver\FlashExtension\QtGui4.dll
2013-11-22 13:51 - 2013-11-22 13:51 - 00691552 _____ () C:\Program Files\Activ Software\ActivDriver\FlashExtension\QtNetwork4.dll
2013-11-22 13:51 - 2013-11-22 13:51 - 02152792 _____ () C:\Program Files\Activ Software\ActivDriver\FlashExtension\QtCore4.dll
2013-11-22 13:51 - 2013-11-22 13:51 - 00388456 _____ () C:\Program Files\Activ Software\ActivDriver\FlashExtension\activsystem1.dll
2013-11-22 13:52 - 2013-11-22 13:52 - 00126296 _____ () C:\Program Files\Activ Software\ActivDriver\FlashExtension\plugins\imageformats\qjpeg4.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04042017155828905\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04042017155828999\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-1799405637-2938259579-1905707483-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Ulla\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
HKU\S-1-5-21-1799405637-2938259579-1905707483-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04042017155829109\Control Panel\Desktop\\Wallpaper -> C:\Users\Ulla\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
HKLM\...\StartupApproved\Run32: => "CLMLServer_For_P2G8"
HKLM\...\StartupApproved\Run32: => "CLVirtualDrive"
HKLM\...\StartupApproved\Run32: => "RemoteControl10"
HKLM\...\StartupApproved\Run32: => "BCSSync"
HKU\S-1-5-21-1799405637-2938259579-1905707483-1002\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1799405637-2938259579-1905707483-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04042017155829109\...\StartupApproved\Run: => "OneDrive"
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{11C47685-52C2-43CD-BF42-772CD8E297B2}C:\users\ulla\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ulla\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{9B3D7B50-CBE2-49C3-A099-0B2C1F5D0BBF}C:\users\ulla\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ulla\appdata\roaming\spotify\spotify.exe
FirewallRules: [{B91770FF-4D90-4DDD-AE0C-67F4BFABB4E0}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4_x64.exe
FirewallRules: [{16AAA18C-55CA-4968-84EB-7A5EA83065E9}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4_x64.exe
FirewallRules: [{94A8FA06-C1DD-4991-B7E6-DD544B894B72}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe
FirewallRules: [{F414A1CE-75BD-4632-A1D3-F9B05CDD985F}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe
FirewallRules: [UDP Query User{EED42B13-005F-453C-B307-48DAB436EBA6}C:\users\ulla\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ulla\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{8C7EDC6C-BF22-41F4-B823-4B266BD65FB8}C:\users\ulla\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ulla\appdata\roaming\spotify\spotify.exe
FirewallRules: [{709A53D2-13DE-4BC9-B6D8-C1B6BE580D03}] => (Allow) C:\Program Files\HP\HP Photosmart 5520 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{44AC64F7-F8E6-47E6-98A0-C06A4E56A5B0}] => (Allow) C:\Program Files\HP\HP Photosmart 5520 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{9E0A3657-F14F-4702-9124-4F9E6076D1D0}] => (Allow) C:\Program Files\HP\HP Photosmart 5520 series\Bin\DeviceSetup.exe
FirewallRules: [{B9AC56AB-B05A-4A1C-A359-764CEA2549BB}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{C4749DE7-AB5A-4634-B68C-07C236C49396}] => (Allow) LPort=2869
FirewallRules: [{75F0000B-6491-4361-A063-82E097F88067}] => (Allow) LPort=1900
FirewallRules: [{2995E60B-E1CA-4AA7-B52F-B27EEA6FA373}] => (Allow) C:\Program Files\CyberLink\PowerDirector\PDR9.EXE
FirewallRules: [{78F1B066-BDD2-4BE6-8F13-7C93207418DF}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{59D49AB0-C7B8-41F5-8197-17B01BD1BB5C}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{71285DA8-6842-471B-A502-CA4B24622F5D}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
FirewallRules: [{2F478039-E857-4718-8AE4-6705876A0E06}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe
FirewallRules: [TCP Query User{2669620E-10AF-413C-A7DF-A5DE0DEF0803}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [UDP Query User{5BD3A791-4AE7-4323-87D0-985467022CE5}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [TCP Query User{484C1D5B-8390-4589-A0E6-DAFE01351131}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{E352CF5B-BF9C-404C-8823-62EC49234198}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{D205CE1F-4831-4851-BD57-D6BDF6678AAA}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{46231D2D-F74E-4C54-91D5-BCBBCBEAE635}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{0E223204-0250-48C4-96A4-72025B062B4E}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{ABB6F15A-97C1-458B-B644-009F7D4C1915}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{1C01B806-A6C9-4803-93BF-F341F7F9FB8E}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{779A82B6-D5DD-48C2-BD27-00379EC658D5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{A5D3359D-AB78-4AC8-A35A-7E0FD9D0D360}] => (Allow) C:\Program Files (x86)\LINE\LINE.exe
FirewallRules: [{DEBA5C5C-1FFA-487A-8E11-E9B12097CFD3}] => (Allow) C:\Program Files (x86)\LINE\LINE.exe
FirewallRules: [{CE3239EC-D11A-44DE-92D8-D956C0DE5C4D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Wiederherstellungspunkte =========================
02-04-2017 21:35:14 Windows Update
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (04/04/2017 08:05:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: avguard.exe, Version: 15.0.25.170, Zeitstempel: 0x58c8088c
Name des fehlerhaften Moduls: avlode.dll, Version: 15.0.25.170, Zeitstempel: 0x58c8083c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000665d3
ID des fehlerhaften Prozesses: 0xaa0
Startzeit der fehlerhaften Anwendung: 0x01d2acc322034cd6
Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
Pfad des fehlerhaften Moduls: c:\program files (x86)\avira\antivir desktop\avlode.dll
Berichtskennung: d5049206-06a2-4858-bb34-e001d68cbf7e
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/03/2017 11:32:16 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Rory)
Description: Bei der Aktivierung der App „Microsoft.Windows.Photos_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (04/02/2017 09:35:27 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.
System Error:
Zugriff verweigert
.
Error: (04/02/2017 03:36:18 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Rory)
Description: Bei der Aktivierung der App „Microsoft.Windows.Photos_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (04/01/2017 02:39:17 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Rory)
Description: Das Paket „Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe+App“ wurde beendet, da das Anhalten zu lange dauerte.
Error: (03/31/2017 06:32:59 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: Die Open-Prozedur für den Dienst "BITS" in der DLL "C:\Windows\System32\bitsperf.dll" war nicht erfolgreich. Die Leistungsdaten für diesen Dienst sind nicht verfügbar. Die ersten vier Bytes (DWORD) des Datenbereichs enthalten den Fehlercode.
Error: (03/29/2017 09:04:56 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.
System Error:
Zugriff verweigert
.
Error: (03/29/2017 08:02:04 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: Die Open-Prozedur für den Dienst "BITS" in der DLL "C:\Windows\System32\bitsperf.dll" war nicht erfolgreich. Die Leistungsdaten für diesen Dienst sind nicht verfügbar. Die ersten vier Bytes (DWORD) des Datenbereichs enthalten den Fehlercode.
Error: (03/27/2017 08:35:30 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: Die Open-Prozedur für den Dienst "BITS" in der DLL "C:\Windows\System32\bitsperf.dll" war nicht erfolgreich. Die Leistungsdaten für diesen Dienst sind nicht verfügbar. Die ersten vier Bytes (DWORD) des Datenbereichs enthalten den Fehlercode.
Error: (03/26/2017 11:55:14 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: Die Open-Prozedur für den Dienst "BITS" in der DLL "C:\Windows\System32\bitsperf.dll" war nicht erfolgreich. Die Leistungsdaten für diesen Dienst sind nicht verfügbar. Die ersten vier Bytes (DWORD) des Datenbereichs enthalten den Fehlercode.
Systemfehler:
=============
Error: (04/04/2017 08:05:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (04/04/2017 08:00:03 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT)
Description: Der Server "{784E29F4-5EBE-4279-9948-1E8FE941646D}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (04/04/2017 07:57:03 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
und der APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/04/2017 12:01:39 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
und der APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/03/2017 11:52:05 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f020b fehlgeschlagen: Hewlett-Packard - Imaging - Null Print - HP Photosmart 5520 series
Error: (04/03/2017 11:46:15 PM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT)
Description: Der Server "{784E29F4-5EBE-4279-9948-1E8FE941646D}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error: (04/03/2017 11:43:13 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
und der APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/03/2017 11:42:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AODDriver4.3" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.
Error: (04/03/2017 11:42:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AODDriver4.2.0" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.
Error: (04/03/2017 11:40:35 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
und der APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
CodeIntegrity:
===================================
Date: 2017-04-03 23:44:57.010
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-03 23:44:57.006
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-03 23:44:56.997
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-03 23:44:56.933
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-04-03 23:44:56.696
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Speicherinformationen ===========================
Prozessor: AMD A8-6500 APU with Radeon(tm) HD Graphics
Prozentuale Nutzung des RAM: 59%
Installierter physikalischer RAM: 3286.55 MB
Verfügbarer physikalischer RAM: 1318.48 MB
Summe virtueller Speicher: 4950.55 MB
Verfügbarer virtueller Speicher: 2452.62 MB
==================== Laufwerke ================================
Drive c: (Boot) (Fixed) (Total:869.36 GB) (Free:777.96 GB) NTFS
Drive d: (Recover) (Fixed) (Total:60 GB) (Free:41.91 GB) NTFS
Drive g: () (Removable) (Total:1.84 GB) (Free:1.84 GB) FAT
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: B719B179)
Partition: GPT.
========================================================
Disk: 1 (Size: 1.8 GB) (Disk ID: 00000000)
Partition: GPT.
==================== Ende von Addition.txt ============================ und zum Abschluss tdskiller: Code:
20:50:21.0824 0x0834 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
20:50:21.0824 0x0834 UEFI system
20:50:24.0501 0x0834 ============================================================
20:50:24.0501 0x0834 Current date / time: 2017/04/04 20:50:24.0501
20:50:24.0501 0x0834 SystemInfo:
20:50:24.0501 0x0834
20:50:24.0501 0x0834 OS Version: 10.0.14393 ServicePack: 0.0
20:50:24.0501 0x0834 Product type: Workstation
20:50:24.0501 0x0834 ComputerName: RORY
20:50:24.0501 0x0834 UserName: Ulla
20:50:24.0501 0x0834 Windows directory: C:\WINDOWS
20:50:24.0501 0x0834 System windows directory: C:\WINDOWS
20:50:24.0501 0x0834 Running under WOW64
20:50:24.0501 0x0834 Processor architecture: Intel x64
20:50:24.0501 0x0834 Number of processors: 4
20:50:24.0501 0x0834 Page size: 0x1000
20:50:24.0501 0x0834 Boot type: Normal boot
20:50:24.0501 0x0834 CodeIntegrityOptions = 0x00000001
20:50:24.0501 0x0834 ============================================================
20:50:25.0454 0x0834 KLMD registered as C:\WINDOWS\system32\drivers\34523178.sys
20:50:25.0454 0x0834 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.953, osProperties = 0x19
20:50:25.0610 0x0834 System UUID: {3166F4BA-F095-E292-54EE-889CD6DB2ED9}
20:50:25.0985 0x0834 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:50:26.0001 0x0834 Drive \Device\Harddisk1\DR1 - Size: 0x75A00000 ( 1.84 Gb ), SectorSize: 0x200, Cylinders: 0xEF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
20:50:26.0017 0x0834 ============================================================
20:50:26.0017 0x0834 \Device\Harddisk0\DR0:
20:50:26.0017 0x0834 GPT partitions:
20:50:26.0017 0x0834 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {F7DBF4E2-9A8C-4F9A-AC7F-073D9DA460E3}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0xF9800
20:50:26.0017 0x0834 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {A7A4728C-25A1-48EC-A0BD-D146696FE02A}, Name: EFI system partition, StartLBA 0xFA000, BlocksNum 0x32000
20:50:26.0017 0x0834 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {5C7BC35A-6508-42C6-B37F-0E95ECA77420}, Name: Microsoft reserved partition, StartLBA 0x12C000, BlocksNum 0x40000
20:50:26.0017 0x0834 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {8D7F0CC6-879E-47F6-A767-0ED8FD3B0659}, UniqueGUID: {D62585CE-AA50-4DF7-ADBB-E1715DE305EC}, Name: Basic data partition, StartLBA 0x16C000, BlocksNum 0x200000
20:50:26.0017 0x0834 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {874CBC8A-39EC-4DE0-80B3-B6A033599044}, Name: Basic data partition, StartLBA 0x36C000, BlocksNum 0x6CAB9000
20:50:26.0017 0x0834 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {1BD7B842-AF4C-43D5-BFA9-BBEAC25B0DBB}, Name: , StartLBA 0x6CE25000, BlocksNum 0xE1000
20:50:26.0017 0x0834 \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {A5EBB69F-CB91-41F3-B74D-E3E43F29DBAF}, Name: Basic data partition, StartLBA 0x6CF06000, BlocksNum 0x7800000
20:50:26.0017 0x0834 MBR partitions:
20:50:26.0017 0x0834 \Device\Harddisk1\DR1:
20:50:26.0017 0x0834 MBR partitions:
20:50:26.0017 0x0834 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x6, StartLBA 0x87, BlocksNum 0x3ACF79
20:50:26.0017 0x0834 ============================================================
20:50:26.0032 0x0834 C: <-> \Device\Harddisk0\DR0\Partition5
20:50:26.0064 0x0834 D: <-> \Device\Harddisk0\DR0\Partition7
20:50:26.0064 0x0834 ============================================================
20:50:26.0064 0x0834 Initialize success
20:50:26.0064 0x0834 ============================================================
20:50:33.0402 0x124c ============================================================
20:50:33.0402 0x124c Scan started
20:50:33.0402 0x124c Mode: Manual; SigCheck; TDLFS;
20:50:33.0402 0x124c ============================================================
20:50:33.0402 0x124c KSN ping started
20:50:33.0669 0x124c KSN ping finished: true
20:50:36.0889 0x124c ================ Scan system memory ========================
20:50:36.0889 0x124c System memory - ok
20:50:36.0889 0x124c ================ Scan services =============================
20:50:36.0982 0x124c 1394ohci - ok
20:50:36.0982 0x124c 3ware - ok
20:50:36.0998 0x124c ACPI - ok
20:50:37.0014 0x124c AcpiDev - ok
20:50:37.0014 0x124c acpiex - ok
20:50:37.0014 0x124c acpipagr - ok
20:50:37.0045 0x124c AcpiPmi - ok
20:50:37.0045 0x124c acpitime - ok
20:50:37.0092 0x124c [ F2326408DE07AA2B4836DB374D04246B, BF4C09A1F8894343EB8FEC16DCFDE135ABDED12DE73C0A58EDA61509DD1B6EF2 ] ActivControl C:\Program Files\Activ Software\ActivDriver\ActivControlsvc.exe
20:50:37.0139 0x124c ActivControl - ok
20:50:37.0201 0x124c [ B932E0EE190778D840F1442DFC0F9612, 8780963F14D57279FDD585BE945ED40F24590D32676C7A9EF94002D38B8BA643 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:50:37.0217 0x124c AdobeARMservice - ok
20:50:37.0295 0x124c [ 7EB7A3B01751889C6459C51A74CC87FA, 088EF5CA10D439905822A3DFFEFD2D3416198F10EAAF8C235771CDB3DF86E82C ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
20:50:37.0357 0x124c AdobeFlashPlayerUpdateSvc - ok
20:50:37.0357 0x124c ADP80XX - ok
20:50:37.0373 0x124c AFD - ok
20:50:37.0389 0x124c ahcache - ok
20:50:37.0404 0x124c AJRouter - ok
20:50:37.0420 0x124c ALG - ok
20:50:37.0436 0x124c [ BBADD85854BFB5D43C60B7AC8EEA3DBA, 968C043ABEA46F5C79525863B3FE2681AC0FA4202036C9EFD20B408DECF407E2 ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
20:50:37.0451 0x124c AMD External Events Utility - ok
20:50:37.0495 0x124c [ DE51F5BB5C05D4C831ECB6E1A70E1B5E, 465834210ACE469481F75EDBB8532386029BD5277C41D084134E9E71B9BD8371 ] AMD FUEL Service C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
20:50:37.0526 0x124c AMD FUEL Service - ok
20:50:37.0542 0x124c AmdK8 - ok
20:50:37.0542 0x124c [ B28145E732EDEBBEDABC311DBA56D52A, 43745C17A3AC2A7A6FB0DBF1A2158C6B365198581E8E3B1F7E7E9EE9763A2735 ] amdkmafd C:\WINDOWS\system32\drivers\amdkmafd.sys
20:50:37.0573 0x124c amdkmafd - ok
20:50:37.0573 0x124c amdkmdag - ok
20:50:37.0604 0x124c [ 17BA5C907E14947574CBB788F4CEB85F, EAA3DBF436637C58666A91905E388287FC54334EBB2589A00727EB09AC4870E3 ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
20:50:37.0636 0x124c amdkmdap - ok
20:50:37.0651 0x124c AmdPPM - ok
20:50:37.0651 0x124c amdsata - ok
20:50:37.0651 0x124c amdsbs - ok
20:50:37.0651 0x124c amdxata - ok
20:50:37.0683 0x124c [ 0E6F9683928F99DF16E0E7924E4807D9, D236F8BCC233370E86F6A474F7576601E10AEC5923B9ED168FEF6303228F940E ] amd_sata C:\WINDOWS\system32\drivers\amd_sata.sys
20:50:37.0698 0x124c amd_sata - ok
20:50:37.0714 0x124c [ F9254DE6FA0A2782A4810726F2D677EF, C6FBDC24E48EE330D47C5A4726633207EE90B841D2A62900E1B2CDACAC7F2B58 ] amd_xata C:\WINDOWS\system32\drivers\amd_xata.sys
20:50:37.0729 0x124c amd_xata - ok
20:50:37.0792 0x124c [ E6CEE7C270AD1CAE17EA910C85211BAE, 1DEB7185CEDC5918C20353C13AA0398D739A318729700F057B13821FF0FF5C97 ] AntiVirMailService C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
20:50:37.0839 0x124c AntiVirMailService - ok
20:50:37.0870 0x124c [ 9658B76971381D9053E48E896256D5EB, 48C763BAF349E663D0E41657779BF5D1106A7C3E7F8C898185DC5D1998C0CDAF ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
20:50:37.0901 0x124c AntiVirSchedulerService - ok
20:50:37.0917 0x124c [ 9658B76971381D9053E48E896256D5EB, 48C763BAF349E663D0E41657779BF5D1106A7C3E7F8C898185DC5D1998C0CDAF ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
20:50:37.0933 0x124c AntiVirService - ok
20:50:37.0979 0x124c [ B62E24EEC8C4B6E8A173CAD069B5033A, 719F7C51D615591E70D549552AC66343526902007480278C0E56AA7E1F406F96 ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
20:50:38.0026 0x124c AntiVirWebService - ok
20:50:38.0058 0x124c [ C3D487827E48CC5EC17994FEC5BDFF87, 5FCEA3EEA583755D0C9F6005ED3032E9DFECB57F504DC67701AE7D2D2631C30E ] AODDriver4.2 C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
20:50:38.0058 0x124c AODDriver4.2 - ok
20:50:38.0073 0x124c [ C3D487827E48CC5EC17994FEC5BDFF87, 5FCEA3EEA583755D0C9F6005ED3032E9DFECB57F504DC67701AE7D2D2631C30E ] AODDriver4.2.0 C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
20:50:38.0073 0x124c AODDriver4.2.0 - ok
20:50:38.0089 0x124c [ C3D487827E48CC5EC17994FEC5BDFF87, 5FCEA3EEA583755D0C9F6005ED3032E9DFECB57F504DC67701AE7D2D2631C30E ] AODDriver4.3 C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
20:50:38.0089 0x124c AODDriver4.3 - ok
20:50:38.0104 0x124c AppID - ok
20:50:38.0120 0x124c AppIDSvc - ok
20:50:38.0120 0x124c Appinfo - ok
20:50:38.0136 0x124c applockerfltr - ok
20:50:38.0151 0x124c AppReadiness - ok
20:50:38.0151 0x124c AppXSvc - ok
20:50:38.0167 0x124c arcsas - ok
20:50:38.0167 0x124c AsyncMac - ok
20:50:38.0198 0x124c atapi - ok
20:50:38.0229 0x124c [ 0966FD5BAB1F9BE200875E9EED0A0A13, F4BE70C0581B51ED6DAE6412A5FF74AE310BF88DE89C5A5E5880BEED543B01D7 ] AtiHDAudioService C:\WINDOWS\system32\drivers\AtihdWT6.sys
20:50:38.0354 0x124c AtiHDAudioService - ok
20:50:38.0370 0x124c AudioEndpointBuilder - ok
20:50:38.0386 0x124c Audiosrv - ok
20:50:38.0401 0x124c [ 11F3AAFB5D279AFBCBB0AD9FF76A24F8, 06C5FA1BD64EB54691629363DD0771394F81E4EB216E489D5169395736E80D99 ] avgntflt C:\WINDOWS\system32\DRIVERS\avgntflt.sys
20:50:38.0417 0x124c avgntflt - ok
20:50:38.0433 0x124c [ F8520E88246641E51108922944FB34A6, 326DCB8114439FB1F75E9DB6E5F7818654FAAC4CD957B80DEE17B850676A737F ] avipbb C:\WINDOWS\system32\DRIVERS\avipbb.sys
20:50:38.0448 0x124c avipbb - ok
20:50:38.0479 0x124c [ AA46643E268120F3C70AADA7056CD0CC, 7660526029F219C466A2B52986A7F2F6A27793F89637983591E4803B18181E4A ] Avira.ServiceHost C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
20:50:38.0495 0x124c Avira.ServiceHost - ok
20:50:38.0511 0x124c [ 2CBA09A7983B1D39531B768BCED08C20, B40968DFE1A648CCB9260033E1EA57B5D496274A335B000354156B0DB740EDE0 ] avkmgr C:\WINDOWS\system32\DRIVERS\avkmgr.sys
20:50:38.0526 0x124c avkmgr - ok
20:50:38.0542 0x124c [ 8D18C6406FF8DC39028177E1E5675182, 44985DEE74F235567FB849350256F342BCE26EF66439D761FA3F6EDA22882092 ] avnetflt C:\WINDOWS\system32\DRIVERS\avnetflt.sys
20:50:38.0558 0x124c avnetflt - ok
20:50:38.0604 0x124c [ 03B45C52179E8DAE51A0F685C30D06D6, E06F066B4BFE5344BBF5749B9B8B8CFBA0C02920FD2B9C73BDDA7E34F1785DA7 ] AVP17.0.0 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\avp.exe
20:50:38.0620 0x124c AVP17.0.0 - ok
20:50:38.0667 0x124c AxInstSV - ok
20:50:38.0683 0x124c b06bdrv - ok
20:50:38.0683 0x124c BasicDisplay - ok
20:50:38.0683 0x124c BasicRender - ok
20:50:38.0698 0x124c bcmfn - ok
20:50:38.0698 0x124c bcmfn2 - ok
20:50:38.0698 0x124c BDESVC - ok
20:50:38.0714 0x124c Beep - ok
20:50:38.0729 0x124c BFE - ok
20:50:38.0729 0x124c BITS - ok
20:50:38.0745 0x124c bowser - ok
20:50:38.0761 0x124c BrokerInfrastructure - ok
20:50:38.0761 0x124c Browser - ok
20:50:38.0808 0x124c [ 0471D5669F18C50E552B2BC0CB15E7B3, 472F471FF9E5A1FDD5610BAC2F5E727AB284B7B5A71C4E515D549667F0B5EB86 ] BrYNSvc C:\Program Files (x86)\Browny02\BrYNSvc.exe
20:50:38.0870 0x124c BrYNSvc - detected UnsignedFile.Multi.Generic ( 1 )
20:50:39.0060 0x124c Detect skipped due to KSN trusted
20:50:39.0060 0x124c BrYNSvc - ok
20:50:39.0076 0x124c BthAvrcpTg - ok
20:50:39.0091 0x124c BthHFEnum - ok
20:50:39.0091 0x124c bthhfhid - ok
20:50:39.0107 0x124c BthHFSrv - ok
20:50:39.0107 0x124c BTHMODEM - ok
20:50:39.0122 0x124c bthserv - ok
20:50:39.0122 0x124c buttonconverter - ok
20:50:39.0122 0x124c CapImg - ok
20:50:39.0138 0x124c cdfs - ok
20:50:39.0154 0x124c CDPSvc - ok
20:50:39.0169 0x124c CDPUserSvc - ok
20:50:39.0185 0x124c cdrom - ok
20:50:39.0216 0x124c CertPropSvc - ok
20:50:39.0216 0x124c cht4iscsi - ok
20:50:39.0232 0x124c cht4vbd - ok
20:50:39.0232 0x124c circlass - ok
20:50:39.0247 0x124c CLFS - ok
20:50:39.0247 0x124c ClipSVC - ok
20:50:39.0247 0x124c clreg - ok
20:50:39.0294 0x124c [ 3E76A1547F2448BCEE3D2F4AE3931AB5, 31B41723FAA4210A86B1AE02D6C052BD8B738C4B89FB0177C1AE997D24BA5B8C ] CLVirtualDrive C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys
20:50:39.0294 0x124c CLVirtualDrive - ok
20:50:39.0310 0x124c CmBatt - ok
20:50:39.0357 0x124c [ B29A764A1E76473CD9D64C9438705C19, CD0497EB84DE60E1E491CA495AF981A8DFC4949BB373C1978CAF1BCF4321D30E ] cm_km C:\WINDOWS\system32\DRIVERS\cm_km.sys
20:50:39.0419 0x124c cm_km - ok
20:50:39.0451 0x124c CNG - ok
20:50:39.0451 0x124c cnghwassist - ok
20:50:39.0497 0x124c CompositeBus - ok
20:50:39.0497 0x124c COMSysApp - ok
20:50:39.0513 0x124c condrv - ok
20:50:39.0544 0x124c CoreMessagingRegistrar - ok
20:50:39.0560 0x124c CryptSvc - ok
20:50:39.0638 0x124c [ 9FF6436D65CD8C798691373E28FBFB3B, 7A9ACD14679FB82E71EF4C47E43DAD931EC4FD727A5656AF8A3CC3B95D67EB5B ] CyberLink PowerDVD 10 MS Monitor Service C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe
20:50:39.0654 0x124c CyberLink PowerDVD 10 MS Monitor Service - ok
20:50:39.0685 0x124c [ 06B5C625CB915E9A7A1F08A43E332FA1, 66F0BFE088B44ED3D36E62DC05200CD09F135FF63C447846C603D6246FABB9BE ] CyberLink PowerDVD 10 MS Service C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe
20:50:39.0701 0x124c CyberLink PowerDVD 10 MS Service - ok
20:50:39.0701 0x124c dam - ok
20:50:39.0716 0x124c DcomLaunch - ok
20:50:39.0732 0x124c DcpSvc - ok
20:50:39.0732 0x124c defragsvc - ok
20:50:39.0747 0x124c DeviceAssociationService - ok
20:50:39.0747 0x124c DeviceInstall - ok
20:50:39.0747 0x124c DevQueryBroker - ok
20:50:39.0763 0x124c Dfsc - ok
20:50:39.0794 0x124c [ 9593475FBC857A05D93BFF4FA7323C2B, D2A958AF5EFDC6136A6ABB7F8D5FE1F84C967E79BEA96C5BE3661A0145DEB907 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
20:50:39.0810 0x124c dg_ssudbus - ok
20:50:39.0826 0x124c Dhcp - ok
20:50:39.0857 0x124c diagnosticshub.standardcollector.service - ok
20:50:39.0888 0x124c DiagTrack - ok
20:50:39.0904 0x124c disk - ok
20:50:39.0919 0x124c DmEnrollmentSvc - ok
20:50:39.0919 0x124c dmvsc - ok
20:50:39.0935 0x124c dmwappushservice - ok
20:50:39.0935 0x124c Dnscache - ok
20:50:39.0951 0x124c dot3svc - ok
20:50:39.0951 0x124c DPS - ok
20:50:39.0966 0x124c drmkaud - ok
20:50:39.0966 0x124c DsmSvc - ok
20:50:39.0966 0x124c DsSvc - ok
20:50:39.0982 0x124c DXGKrnl - ok
20:50:39.0982 0x124c EapHost - ok
20:50:39.0982 0x124c ebdrv - ok
20:50:39.0997 0x124c EFS - ok
20:50:39.0997 0x124c EhStorClass - ok
20:50:40.0013 0x124c EhStorTcgDrv - ok
20:50:40.0029 0x124c embeddedmode - ok
20:50:40.0044 0x124c EntAppSvc - ok
20:50:40.0044 0x124c ErrDev - ok
20:50:40.0076 0x124c EventSystem - ok
20:50:40.0076 0x124c exfat - ok
20:50:40.0076 0x124c fastfat - ok
20:50:40.0091 0x124c Fax - ok
20:50:40.0091 0x124c fdc - ok
20:50:40.0107 0x124c fdPHost - ok
20:50:40.0107 0x124c FDResPub - ok
20:50:40.0122 0x124c fhsvc - ok
20:50:40.0138 0x124c FileCrypt - ok
20:50:40.0138 0x124c FileInfo - ok
20:50:40.0138 0x124c Filetrace - ok
20:50:40.0138 0x124c flpydisk - ok
20:50:40.0154 0x124c FltMgr - ok
20:50:40.0169 0x124c FontCache - ok
20:50:40.0247 0x124c FontCache3.0.0.0 - ok
20:50:40.0263 0x124c FrameServer - ok
20:50:40.0279 0x124c FsDepends - ok
20:50:40.0279 0x124c Fs_Rec - ok
20:50:40.0294 0x124c fvevol - ok
20:50:40.0294 0x124c gencounter - ok
20:50:40.0310 0x124c genericusbfn - ok
20:50:40.0310 0x124c GPIOClx0101 - ok
20:50:40.0325 0x124c gpsvc - ok
20:50:40.0341 0x124c GpuEnergyDrv - ok
20:50:40.0388 0x124c [ 2D8BBF6C7241AAD9EDE7708EBB7B43A4, 51AF8150C6CF738AF14F502E6BDAD1035773DD45980770E06393814B75259EF8 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:50:40.0404 0x124c gupdate - ok
20:50:40.0435 0x124c [ 2D8BBF6C7241AAD9EDE7708EBB7B43A4, 51AF8150C6CF738AF14F502E6BDAD1035773DD45980770E06393814B75259EF8 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:50:40.0435 0x124c gupdatem - ok
20:50:40.0450 0x124c HDAudBus - ok
20:50:40.0450 0x124c HidBatt - ok
20:50:40.0450 0x124c HidBth - ok
20:50:40.0450 0x124c hidi2c - ok
20:50:40.0466 0x124c hidinterrupt - ok
20:50:40.0466 0x124c HidIr - ok
20:50:40.0482 0x124c hidserv - ok
20:50:40.0513 0x124c HidUsb - ok
20:50:40.0513 0x124c HomeGroupListener - ok
20:50:40.0529 0x124c HomeGroupProvider - ok
20:50:40.0529 0x124c HpSAMD - ok
20:50:40.0560 0x124c HTTP - ok
20:50:40.0576 0x124c HvHost - ok
20:50:40.0607 0x124c hvservice - ok
20:50:40.0626 0x124c hwpolicy - ok
20:50:40.0626 0x124c hyperkbd - ok
20:50:40.0642 0x124c i8042prt - ok
20:50:40.0658 0x124c iagpio - ok
20:50:40.0658 0x124c iai2c - ok
20:50:40.0658 0x124c iaLPSS2i_GPIO2 - ok
20:50:40.0673 0x124c iaLPSS2i_I2C - ok
20:50:40.0673 0x124c iaLPSSi_GPIO - ok
20:50:40.0673 0x124c iaLPSSi_I2C - ok
20:50:40.0689 0x124c iaStorAV - ok
20:50:40.0689 0x124c iaStorV - ok
20:50:40.0689 0x124c ibbus - ok
20:50:40.0720 0x124c icssvc - ok
20:50:40.0720 0x124c IKEEXT - ok
20:50:40.0720 0x124c IndirectKmd - ok
20:50:40.0845 0x124c [ 622868E4BAE8FBCD22CB1A5901A2C824, C1A2264C0984DD16C83B663C9CE43E049E1356E32C5771C3ACE225F285699138 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
20:50:40.0970 0x124c IntcAzAudAddService - ok
20:50:40.0986 0x124c intelide - ok
20:50:40.0986 0x124c intelpep - ok
20:50:41.0001 0x124c intelppm - ok
20:50:41.0017 0x124c iorate - ok
20:50:41.0017 0x124c IpFilterDriver - ok
20:50:41.0048 0x124c iphlpsvc - ok
20:50:41.0064 0x124c IPMIDRV - ok
20:50:41.0064 0x124c IPNAT - ok
20:50:41.0064 0x124c irda - ok
20:50:41.0079 0x124c IRENUM - ok
20:50:41.0079 0x124c irmon - ok
20:50:41.0079 0x124c isapnp - ok
20:50:41.0079 0x124c iScsiPrt - ok
20:50:41.0095 0x124c kbdclass - ok
20:50:41.0095 0x124c kbdhid - ok
20:50:41.0119 0x124c kdnic - ok
20:50:41.0119 0x124c KeyIso - ok
20:50:41.0164 0x124c [ 97E3E8F35632EECD0ABD2DE6519A9666, ABE96FDEB1076E380D7FB4975C020B43ED4E821097EFC6AFE8C75D764167D6E8 ] kl1 C:\WINDOWS\system32\DRIVERS\kl1.sys
20:50:41.0180 0x124c kl1 - ok
20:50:41.0195 0x124c [ B01AD8DA034EE42D4C2282F77FDB03AE, 3FF55F3CEE4A0E5D559F04F5A639297EA0F36580720E94CF9DD56DEBF2E98F39 ] klbackupdisk C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys
20:50:41.0211 0x124c klbackupdisk - ok
20:50:41.0226 0x124c [ 10549B5BFD9A3DCF4FFA6287236FA959, 6BDFA335A8E3A69425CB23230660D3168CB82911ACB3AAAF85C19263511EAF51 ] klbackupflt C:\WINDOWS\system32\DRIVERS\klbackupflt.sys
20:50:41.0242 0x124c klbackupflt - ok
20:50:41.0242 0x124c [ 7DAA9047F50BF5A3F8C147719FC520AF, 0740387075AF46DB1E9AEE3B12C65A06EDFE58EADB8B562C36CB1FEFF9905C26 ] kldisk C:\WINDOWS\system32\DRIVERS\kldisk.sys
20:50:41.0258 0x124c kldisk - ok
20:50:41.0273 0x124c [ 5766A27C85EE813029831D125D2EFB45, BB5BAFD5A58E80C7F0B8D24121352E0386B3422FFC16B56F1D1B1C6A482AC9F0 ] klelam C:\WINDOWS\system32\DRIVERS\klelam.sys
20:50:41.0289 0x124c klelam - ok
20:50:41.0305 0x124c [ 2CBFFDD6325676C1DBD42C9F668B40EB, 07346840653D3D336D9CE7738DE7BCDD948EF23C22C105684E894C2D50655A64 ] klflt C:\WINDOWS\system32\DRIVERS\klflt.sys
20:50:41.0320 0x124c klflt - ok
20:50:41.0367 0x124c [ C2AED7EDBC43E8316513251C633FF546, F4C714DA34D65838065CAA0C54E8455FB52F0A1374F571900E1BFE42F144014D ] klhk C:\WINDOWS\System32\drivers\klhk.sys
20:50:41.0383 0x124c klhk - ok
20:50:41.0418 0x124c [ 9349AAE93762D6F23187E646D9BC00C9, 19B6BF974B7F2F52E27DF4229CAD6C289EA25DBFB714FACA82296CA0B08B1B09 ] KLIF C:\WINDOWS\system32\DRIVERS\klif.sys
20:50:41.0465 0x124c KLIF - ok
20:50:41.0481 0x124c [ 6357C533C30650361110DBAF59A25DF8, FA8CF6292CCBC7E23527D968E54CD773706CF091E35563B0CF9F8A1DF0B724B9 ] KLIM6 C:\WINDOWS\system32\DRIVERS\klim6.sys
20:50:41.0496 0x124c KLIM6 - ok
20:50:41.0512 0x124c [ 5480CC93737F48282552C84FA7EBA59B, B7D92424399B647132F6B9409FE75EAA310C984F796FC0B65BBE2EA180110968 ] klkbdflt C:\WINDOWS\system32\DRIVERS\klkbdflt.sys
20:50:41.0527 0x124c klkbdflt - ok
20:50:41.0543 0x124c [ FD47C92A63B6EADEA830BFA96C06EAEE, C15C39B6FA53CBD01A2F95243845C4B706B4229F8FFB75C7128819B9CEE5B2CB ] klmouflt C:\WINDOWS\system32\DRIVERS\klmouflt.sys
20:50:41.0559 0x124c klmouflt - ok
20:50:41.0574 0x124c [ 6B0C605591C892CBB683F63EA47822DC, E74C0A0501A1B4B56B417402108521F34DA6A23FCD1C05E4E524E41EBA0906FF ] klpd C:\WINDOWS\system32\DRIVERS\klpd.sys
20:50:41.0574 0x124c klpd - ok
20:50:41.0606 0x124c [ 66516A704F1D378E58B85D79633C103D, 54E3EB342D2FD17CF742A8ACADCA81A553216AA289955DD176A54D6414727DA5 ] klupd_klif_arkmon C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
20:50:41.0637 0x124c klupd_klif_arkmon - ok
20:50:41.0652 0x124c [ 34D207C9300529BE5E29267922483778, 6F2888A3E649B78477A568E8F8A2527493D9D0D1FD13822E5D90AE575D2041D2 ] klupd_klif_kimul C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
20:50:41.0668 0x124c klupd_klif_kimul - ok
20:50:41.0699 0x124c [ 55FC7F42A5AA55A265CE466227ABD0DE, AB72152F39460327D74DB693BFB36A93BC2D752653D3633BB7F439DC4B9AB081 ] klupd_klif_klark C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
20:50:41.0715 0x124c klupd_klif_klark - ok
20:50:41.0731 0x124c [ D7709E365C10F99DE58BB688C45358B7, C028FB885B7A4AFB98FD2B8EABF99E913F480891A9ED859FE5B4E077BDE8ACB5 ] klupd_klif_klbg C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
20:50:41.0746 0x124c klupd_klif_klbg - ok
20:50:41.0762 0x124c [ 8D7E0B5D4F843D39AA1F644B2578B0EE, C4A8E569A253738AA7B7CDE8D0E987954D1DA6BE6F32D962BD458CA5275A5D76 ] klupd_klif_mark C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
20:50:41.0778 0x124c klupd_klif_mark - ok
20:50:41.0824 0x124c [ D7F0B46844565E2ED68AC99AF0F4263F, AB419CBC29F96703237127AC4178A5365D4CCA010BAB1BD66D100D635E6E89B8 ] klvssbrigde64 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\x64\vssbridge64.exe
20:50:41.0840 0x124c klvssbrigde64 - ok
20:50:41.0871 0x124c [ 4C5305295B51BA72FC9C8CDAB32F95C3, 0E5850AC4CA14D971E7B04FED23CB2F6CEEE2796E905AADA0104677982ECD58A ] klwfp C:\WINDOWS\system32\DRIVERS\klwfp.sys
20:50:41.0902 0x124c klwfp - ok
20:50:41.0918 0x124c [ 4799405773BB400A2FF96663CF0EE4A2, F7650B80AC388675724D9A43D709FF9CCDE99374D7C5E3B900F61FC61D6816D2 ] Klwtp C:\WINDOWS\system32\DRIVERS\klwtp.sys
20:50:41.0934 0x124c Klwtp - ok
20:50:41.0965 0x124c [ 098D3EBDC599E05449A3BFB5BB519FE0, 00A02DE53312D4DF52E26E14E0E803255DF5AFAE95455EAE5A004F9E84C8B2F5 ] kneps C:\WINDOWS\system32\DRIVERS\kneps.sys
20:50:41.0996 0x124c kneps - ok
20:50:41.0996 0x124c KSecDD - ok
20:50:42.0012 0x124c KSecPkg - ok
20:50:42.0012 0x124c ksthunk - ok
20:50:42.0027 0x124c KtmRm - ok
20:50:42.0043 0x124c LanmanServer - ok
20:50:42.0043 0x124c LanmanWorkstation - ok
20:50:42.0059 0x124c lfsvc - ok
20:50:42.0059 0x124c LicenseManager - ok
20:50:42.0074 0x124c lltdio - ok
20:50:42.0090 0x124c lltdsvc - ok
20:50:42.0106 0x124c lmhosts - ok
20:50:42.0106 0x124c LSI_SAS - ok
20:50:42.0121 0x124c LSI_SAS2i - ok
20:50:42.0121 0x124c LSI_SAS3i - ok
20:50:42.0121 0x124c LSI_SSS - ok
20:50:42.0121 0x124c LSM - ok
20:50:42.0142 0x124c luafv - ok
20:50:42.0142 0x124c MapsBroker - ok
20:50:42.0361 0x124c [ 804E3246E3E73D4A936F2F4BCDC53A2D, BF1F9B4AC292238FA6EE541E325B220F311977F9D87D5BC7F90AD058FBF0B35A ] MBAMService C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
20:50:42.0501 0x124c MBAMService - ok
20:50:42.0517 0x124c megasas - ok
20:50:42.0533 0x124c megasas2i - ok
20:50:42.0548 0x124c megasr - ok
20:50:42.0548 0x124c MessagingService - ok
20:50:42.0580 0x124c Microsoft SharePoint Workspace Audit Service - ok
20:50:42.0580 0x124c mlx4_bus - ok
20:50:42.0580 0x124c MMCSS - ok
20:50:42.0595 0x124c Modem - ok
20:50:42.0595 0x124c monitor - ok
20:50:42.0611 0x124c mouclass - ok
20:50:42.0611 0x124c mouhid - ok
20:50:42.0611 0x124c mountmgr - ok
20:50:42.0611 0x124c mpsdrv - ok
20:50:42.0626 0x124c MpsSvc - ok
20:50:42.0642 0x124c MRxDAV - ok
20:50:42.0658 0x124c mrxsmb - ok
20:50:42.0673 0x124c mrxsmb10 - ok
20:50:42.0673 0x124c mrxsmb20 - ok
20:50:42.0700 0x124c MsBridge - ok
20:50:42.0700 0x124c MSDTC - ok
20:50:42.0711 0x124c Msfs - ok
20:50:42.0711 0x124c msgpiowin32 - ok
20:50:42.0727 0x124c mshidkmdf - ok
20:50:42.0727 0x124c mshidumdf - ok
20:50:42.0727 0x124c msisadrv - ok
20:50:42.0758 0x124c MSiSCSI - ok
20:50:42.0758 0x124c msiserver - ok
20:50:42.0773 0x124c MSKSSRV - ok
20:50:42.0773 0x124c MsLldp - ok
20:50:42.0773 0x124c MSPCLOCK - ok
20:50:42.0773 0x124c MSPQM - ok
20:50:42.0789 0x124c MsRPC - ok
20:50:42.0789 0x124c mssmbios - ok
20:50:42.0789 0x124c MSTEE - ok
20:50:42.0805 0x124c MTConfig - ok
20:50:42.0805 0x124c Mup - ok
20:50:42.0805 0x124c mvumis - ok
20:50:42.0820 0x124c NativeWifiP - ok
20:50:42.0820 0x124c NcaSvc - ok
20:50:42.0820 0x124c NcbService - ok
20:50:42.0836 0x124c NcdAutoSetup - ok
20:50:42.0836 0x124c ndfltr - ok
20:50:42.0836 0x124c NDIS - ok
20:50:42.0851 0x124c NdisCap - ok
20:50:42.0867 0x124c NdisImPlatform - ok
20:50:42.0867 0x124c NdisTapi - ok
20:50:42.0867 0x124c Ndisuio - ok
20:50:42.0867 0x124c NdisVirtualBus - ok
20:50:42.0883 0x124c NdisWan - ok
20:50:42.0883 0x124c ndiswanlegacy - ok
20:50:42.0883 0x124c ndproxy - ok
20:50:42.0883 0x124c Ndu - ok
20:50:42.0898 0x124c NetAdapterCx - ok
20:50:42.0898 0x124c NetBIOS - ok
20:50:42.0898 0x124c NetBT - ok
20:50:42.0914 0x124c Netlogon - ok
20:50:42.0930 0x124c Netman - ok
20:50:42.0930 0x124c netprofm - ok
20:50:42.0945 0x124c NetSetupSvc - ok
20:50:42.0977 0x124c NetTcpPortSharing - ok
20:50:42.0992 0x124c NgcCtnrSvc - ok
20:50:43.0008 0x124c NgcSvc - ok
20:50:43.0008 0x124c NlaSvc - ok
20:50:43.0008 0x124c Npfs - ok
20:50:43.0023 0x124c npsvctrig - ok
20:50:43.0023 0x124c nsi - ok
20:50:43.0023 0x124c nsiproxy - ok
20:50:43.0039 0x124c NTFS - ok
20:50:43.0039 0x124c Null - ok
20:50:43.0055 0x124c nvraid - ok
20:50:43.0055 0x124c nvstor - ok
20:50:43.0070 0x124c OneSyncSvc - ok
20:50:43.0164 0x124c [ 2906AF02B5D06B0EFCD32382F19B88DB, 52A57816017591AC18693095ED6877EC6187F01A1B075ECC0F7E8FA73543E9D0 ] Origin Client Service C:\Program Files (x86)\Origin\OriginClientService.exe
20:50:43.0211 0x124c Origin Client Service - ok
20:50:43.0242 0x124c [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:50:43.0258 0x124c ose - ok
20:50:43.0398 0x124c [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
20:50:43.0539 0x124c osppsvc - ok
20:50:43.0570 0x124c p2pimsvc - ok
20:50:43.0570 0x124c p2psvc - ok
20:50:43.0570 0x124c Parport - ok
20:50:43.0586 0x124c partmgr - ok
20:50:43.0617 0x124c PcaSvc - ok
20:50:43.0633 0x124c pci - ok
20:50:43.0648 0x124c pciide - ok
20:50:43.0648 0x124c pcmcia - ok
20:50:43.0648 0x124c pcw - ok
20:50:43.0664 0x124c pdc - ok
20:50:43.0711 0x124c [ 1EAE050F8CDC82B12C9F8C58DFB7567A, DE5B4839FCFDD09CA33D8ACB97635D805FAFED33C7F6DD119AE4D5EC17733B62 ] PDFProFiltSrvPP C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
20:50:43.0742 0x124c PDFProFiltSrvPP - ok
20:50:43.0758 0x124c PEAUTH - ok
20:50:43.0758 0x124c percsas2i - ok
20:50:43.0758 0x124c percsas3i - ok
20:50:43.0805 0x124c PerfHost - ok
20:50:43.0820 0x124c PhoneSvc - ok
20:50:43.0836 0x124c PimIndexMaintenanceSvc - ok
20:50:43.0851 0x124c pla - ok
20:50:43.0851 0x124c PlugPlay - ok
20:50:43.0867 0x124c PNRPAutoReg - ok
20:50:43.0867 0x124c PNRPsvc - ok
20:50:43.0883 0x124c PolicyAgent - ok
20:50:43.0883 0x124c Power - ok
20:50:43.0883 0x124c PptpMiniport - ok
20:50:44.0055 0x124c [ 77ABF70C71922873BC160933571B3F83, 7FCFBB4B42E7A92FCF11388CD5B600EA79A7C134F13A8A88CF8DCD3DB96C3F5A ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
20:50:44.0289 0x124c PrintNotify - ok
20:50:44.0305 0x124c Processor - ok
20:50:44.0320 0x124c ProfSvc - ok
20:50:44.0320 0x124c Psched - ok
20:50:44.0336 0x124c QWAVE - ok
20:50:44.0336 0x124c QWAVEdrv - ok
20:50:44.0336 0x124c RasAcd - ok
20:50:44.0367 0x124c RasAgileVpn - ok
20:50:44.0383 0x124c RasAuto - ok
20:50:44.0383 0x124c Rasl2tp - ok
20:50:44.0398 0x124c RasMan - ok
20:50:44.0398 0x124c RasPppoe - ok
20:50:44.0398 0x124c RasSstp - ok
20:50:44.0430 0x124c rdbss - ok
20:50:44.0477 0x124c rdpbus - ok
20:50:44.0477 0x124c RDPDR - ok
20:50:44.0508 0x124c RdpVideoMiniport - ok
20:50:44.0508 0x124c rdyboost - ok
20:50:44.0523 0x124c ReFSv1 - ok
20:50:44.0539 0x124c RemoteAccess - ok
20:50:44.0555 0x124c RemoteRegistry - ok
20:50:44.0570 0x124c RetailDemo - ok
20:50:44.0633 0x124c [ 0B169FE016039571ECC6DB70073F8979, B80663433919C3DE83A02E376E5B3020856C6E9E98B5773D316FD9C1C02C1417 ] RichVideo64 C:\Program Files\CyberLink\Shared files\RichVideo64.exe
20:50:44.0648 0x124c RichVideo64 - ok
20:50:44.0664 0x124c RmSvc - ok
20:50:44.0680 0x124c RpcEptMapper - ok
20:50:44.0680 0x124c RpcLocator - ok
20:50:44.0695 0x124c RpcSs - ok
20:50:44.0695 0x124c rspndr - ok
20:50:44.0711 0x124c rt640x64 - ok
20:50:44.0727 0x124c RtlWlanu_OldIC - ok
20:50:44.0727 0x124c s3cap - ok
20:50:44.0742 0x124c SamSs - ok
20:50:44.0758 0x124c sbp2port - ok
20:50:44.0773 0x124c SCardSvr - ok
20:50:44.0805 0x124c ScDeviceEnum - ok
20:50:44.0820 0x124c scfilter - ok
20:50:44.0820 0x124c Schedule - ok
20:50:44.0820 0x124c scmbus - ok
20:50:44.0836 0x124c scmdisk0101 - ok
20:50:44.0867 0x124c SCPolicySvc - ok
20:50:44.0867 0x124c sdbus - ok
20:50:44.0883 0x124c SDRSVC - ok
20:50:44.0898 0x124c sdstor - ok
20:50:44.0898 0x124c seclogon - ok
20:50:44.0898 0x124c SENS - ok
20:50:44.0919 0x124c SensorDataService - ok
20:50:44.0935 0x124c SensorService - ok
20:50:44.0935 0x124c SensrSvc - ok
20:50:44.0935 0x124c SerCx - ok
20:50:44.0950 0x124c SerCx2 - ok
20:50:44.0950 0x124c Serenum - ok
20:50:44.0950 0x124c Serial - ok
20:50:44.0966 0x124c sermouse - ok
20:50:44.0982 0x124c SessionEnv - ok
20:50:44.0997 0x124c sfloppy - ok
20:50:45.0013 0x124c SharedAccess - ok
20:50:45.0013 0x124c ShellHWDetection - ok
20:50:45.0028 0x124c shpamsvc - ok
20:50:45.0044 0x124c SiSRaid2 - ok
20:50:45.0044 0x124c SiSRaid4 - ok
20:50:45.0122 0x124c [ F3AAB7DF6408431C762D8721B68F46E4, 56ED764AA660955B8B06322703D086B3A52106625A83CCAF195B08BCBDEDA88F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
20:50:45.0153 0x124c SkypeUpdate - ok
20:50:45.0200 0x124c smphost - ok
20:50:45.0200 0x124c SmsRouter - ok
20:50:45.0216 0x124c SNMPTRAP - ok
20:50:45.0247 0x124c spaceport - ok
20:50:45.0247 0x124c SpbCx - ok
20:50:45.0263 0x124c Spooler - ok
20:50:45.0278 0x124c sppsvc - ok
20:50:45.0278 0x124c srv - ok
20:50:45.0294 0x124c srv2 - ok
20:50:45.0310 0x124c srvnet - ok
20:50:45.0310 0x124c SSDPSRV - ok
20:50:45.0325 0x124c SstpSvc - ok
20:50:45.0341 0x124c [ 592FF34A2FD6C6351B8A3AA76B2C0A9E, 152B7472DE531AC45492F562DD470B2CE33F1EEF13BC78F26046AE5ABF54E32F ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
20:50:45.0357 0x124c ssudmdm - ok
20:50:45.0388 0x124c StateRepository - ok
20:50:45.0388 0x124c stexstor - ok
20:50:45.0403 0x124c stisvc - ok
20:50:45.0403 0x124c storahci - ok
20:50:45.0403 0x124c storflt - ok
20:50:45.0419 0x124c stornvme - ok
20:50:45.0419 0x124c storqosflt - ok
20:50:45.0419 0x124c StorSvc - ok
20:50:45.0435 0x124c storufs - ok
20:50:45.0435 0x124c storvsc - ok
20:50:45.0435 0x124c svsvc - ok
20:50:45.0435 0x124c swenum - ok
20:50:45.0450 0x124c swprv - ok
20:50:45.0466 0x124c Synth3dVsc - ok
20:50:45.0466 0x124c SysMain - ok
20:50:45.0481 0x124c SystemEventsBroker - ok
20:50:45.0497 0x124c TabletInputService - ok
20:50:45.0497 0x124c TapiSrv - ok
20:50:45.0497 0x124c Tcpip - ok
20:50:45.0513 0x124c Tcpip6 - ok
20:50:45.0513 0x124c tcpipreg - ok
20:50:45.0528 0x124c tdx - ok
20:50:45.0700 0x124c [ 2AA61246A5B813C1B12BCCFAA6F23DD8, 74EE3DB839A0F4BC781294803281DB2248D013B8808FF05F2EE9597C14C6FEED ] TeamViewer C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
20:50:45.0888 0x124c TeamViewer - ok
20:50:45.0903 0x124c terminpt - ok
20:50:45.0903 0x124c TermService - ok
20:50:45.0919 0x124c Themes - ok
20:50:45.0935 0x124c TieringEngineService - ok
20:50:45.0950 0x124c tiledatamodelsvc - ok
20:50:45.0950 0x124c TimeBrokerSvc - ok
20:50:45.0966 0x124c TPM - ok
20:50:45.0966 0x124c TrkWks - ok
20:50:45.0997 0x124c TrustedInstaller - ok
20:50:46.0013 0x124c tsusbflt - ok
20:50:46.0013 0x124c TsUsbGD - ok
20:50:46.0013 0x124c tunnel - ok
20:50:46.0044 0x124c tzautoupdate - ok
20:50:46.0060 0x124c UASPStor - ok
20:50:46.0060 0x124c UcmCx0101 - ok
20:50:46.0060 0x124c UcmTcpciCx0101 - ok
20:50:46.0075 0x124c UcmUcsi - ok
20:50:46.0075 0x124c Ucx01000 - ok
20:50:46.0075 0x124c UdeCx - ok
20:50:46.0075 0x124c udfs - ok
20:50:46.0091 0x124c UEFI - ok
20:50:46.0091 0x124c Ufx01000 - ok
20:50:46.0091 0x124c UfxChipidea - ok
20:50:46.0106 0x124c ufxsynopsys - ok
20:50:46.0106 0x124c UI0Detect - ok
20:50:46.0122 0x124c umbus - ok
20:50:46.0122 0x124c UmPass - ok
20:50:46.0122 0x124c UmRdpService - ok
20:50:46.0138 0x124c UnistoreSvc - ok
20:50:46.0138 0x124c upnphost - ok
20:50:46.0138 0x124c UrsChipidea - ok
20:50:46.0153 0x124c UrsCx01000 - ok
20:50:46.0153 0x124c UrsSynopsys - ok
20:50:46.0153 0x124c usbccgp - ok
20:50:46.0153 0x124c usbcir - ok
20:50:46.0169 0x124c usbehci - ok
20:50:46.0185 0x124c [ 504901430B6E03B99EBB6BF26E0868C6, D00C0904B7008305DCA5D1E6FED153DD8875CAD14D80348E59F42A182FA7E832 ] usbfilter C:\WINDOWS\system32\DRIVERS\usbfilter.sys
20:50:46.0185 0x124c usbfilter - ok
20:50:46.0200 0x124c usbhub - ok
20:50:46.0200 0x124c USBHUB3 - ok
20:50:46.0200 0x124c usbohci - ok
20:50:46.0200 0x124c usbprint - ok
20:50:46.0232 0x124c [ 2EC7B2C8123236B1233A77281D378DF7, D97DB59C9CAE2B8B33C707E8CEA7A65BF88712842CC715D270F7432A99D21BB6 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:50:46.0325 0x124c usbscan - ok
20:50:46.0325 0x124c usbser - ok
20:50:46.0341 0x124c USBSTOR - ok
20:50:46.0341 0x124c usbuhci - ok
20:50:46.0341 0x124c USBXHCI - ok
20:50:46.0356 0x124c UserDataSvc - ok
20:50:46.0372 0x124c UserManager - ok
20:50:46.0372 0x124c UsoSvc - ok
20:50:46.0388 0x124c VaultSvc - ok
20:50:46.0388 0x124c vdrvroot - ok
20:50:46.0388 0x124c vds - ok
20:50:46.0403 0x124c VerifierExt - ok
20:50:46.0403 0x124c vhdmp - ok
20:50:46.0419 0x124c vhf - ok
20:50:46.0419 0x124c vmbus - ok
20:50:46.0419 0x124c VMBusHID - ok
20:50:46.0435 0x124c vmgid - ok
20:50:46.0435 0x124c vmicguestinterface - ok
20:50:46.0435 0x124c vmicheartbeat - ok
20:50:46.0450 0x124c vmickvpexchange - ok
20:50:46.0466 0x124c vmicrdv - ok
20:50:46.0466 0x124c vmicshutdown - ok
20:50:46.0466 0x124c vmictimesync - ok
20:50:46.0481 0x124c vmicvmsession - ok
20:50:46.0481 0x124c vmicvss - ok
20:50:46.0481 0x124c volmgr - ok
20:50:46.0497 0x124c volmgrx - ok
20:50:46.0497 0x124c volsnap - ok
20:50:46.0497 0x124c volume - ok
20:50:46.0513 0x124c vpci - ok
20:50:46.0513 0x124c vsmraid - ok
20:50:46.0513 0x124c VSS - ok
20:50:46.0528 0x124c VSTXRAID - ok
20:50:46.0528 0x124c vwifibus - ok
20:50:46.0528 0x124c vwififlt - ok
20:50:46.0544 0x124c vwifimp - ok
20:50:46.0544 0x124c W32Time - ok
20:50:46.0544 0x124c WacomPen - ok
20:50:46.0575 0x124c WalletService - ok
20:50:46.0575 0x124c wanarp - ok
20:50:46.0575 0x124c wanarpv6 - ok
20:50:46.0591 0x124c wbengine - ok
20:50:46.0606 0x124c WbioSrvc - ok
20:50:46.0622 0x124c wcifs - ok
20:50:46.0622 0x124c Wcmsvc - ok
20:50:46.0622 0x124c wcncsvc - ok
20:50:46.0638 0x124c wcnfs - ok
20:50:46.0638 0x124c WdBoot - ok
20:50:46.0638 0x124c Wdf01000 - ok
20:50:46.0653 0x124c WdFilter - ok
20:50:46.0653 0x124c WdiServiceHost - ok
20:50:46.0653 0x124c WdiSystemHost - ok
20:50:46.0669 0x124c wdiwifi - ok
20:50:46.0669 0x124c WdNisDrv - ok
20:50:46.0685 0x124c WdNisSvc - ok
20:50:46.0700 0x124c WebClient - ok
20:50:46.0700 0x124c Wecsvc - ok
20:50:46.0700 0x124c WEPHOSTSVC - ok
20:50:46.0716 0x124c wercplsupport - ok
20:50:46.0716 0x124c WerSvc - ok
20:50:46.0732 0x124c WFPLWFS - ok
20:50:46.0747 0x124c WiaRpc - ok
20:50:46.0747 0x124c WIMMount - ok
20:50:46.0747 0x124c WinDefend - ok
20:50:46.0778 0x124c WindowsTrustedRT - ok
20:50:46.0778 0x124c WindowsTrustedRTProxy - ok
20:50:46.0794 0x124c WinHttpAutoProxySvc - ok
20:50:46.0794 0x124c WinMad - ok
20:50:46.0841 0x124c Winmgmt - ok
20:50:46.0857 0x124c WinRM - ok
20:50:46.0872 0x124c WINUSB - ok
20:50:46.0872 0x124c WinVerbs - ok
20:50:46.0888 0x124c wisvc - ok
20:50:46.0903 0x124c WlanSvc - ok
20:50:46.0903 0x124c wlidsvc - ok
20:50:46.0919 0x124c WmiAcpi - ok
20:50:46.0919 0x124c wmiApSrv - ok
20:50:46.0950 0x124c WMPNetworkSvc - ok
20:50:46.0950 0x124c Wof - ok
20:50:46.0966 0x124c workfolderssvc - ok
20:50:46.0991 0x124c WPDBusEnum - ok
20:50:46.0991 0x124c WpdUpFltr - ok
20:50:46.0991 0x124c WpnService - ok
20:50:47.0007 0x124c WpnUserService - ok
20:50:47.0007 0x124c ws2ifsl - ok
20:50:47.0007 0x124c wscsvc - ok
20:50:47.0022 0x124c WSDPrintDevice - ok
20:50:47.0038 0x124c WSDScan - ok
20:50:47.0038 0x124c WSearch - ok
20:50:47.0054 0x124c wuauserv - ok
20:50:47.0054 0x124c WudfPf - ok
20:50:47.0069 0x124c WUDFRd - ok
20:50:47.0085 0x124c wudfsvc - ok
20:50:47.0085 0x124c WUDFWpdFs - ok
20:50:47.0101 0x124c WUDFWpdMtp - ok
20:50:47.0101 0x124c WwanSvc - ok
20:50:47.0101 0x124c XblAuthManager - ok
20:50:47.0125 0x124c XblGameSave - ok
20:50:47.0125 0x124c xboxgip - ok
20:50:47.0125 0x124c XboxNetApiSvc - ok
20:50:47.0154 0x124c xinputhid - ok
20:50:47.0154 0x124c ================ Scan global ===============================
20:50:47.0216 0x124c [ Global ] - ok
20:50:47.0216 0x124c ================ Scan MBR ==================================
20:50:47.0216 0x124c [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
20:50:47.0326 0x124c \Device\Harddisk0\DR0 - ok
20:50:47.0341 0x124c [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
20:50:47.0514 0x124c \Device\Harddisk1\DR1 - ok
20:50:47.0514 0x124c ================ Scan VBR ==================================
20:50:47.0530 0x124c [ 04040D125D17FCB721A43ED3ABBDC30B ] \Device\Harddisk0\DR0\Partition1
20:50:47.0530 0x124c \Device\Harddisk0\DR0\Partition1 - ok
20:50:47.0530 0x124c [ FA375C7F4C4C8F14192232896C97CB91 ] \Device\Harddisk0\DR0\Partition2
20:50:47.0530 0x124c \Device\Harddisk0\DR0\Partition2 - ok
20:50:47.0549 0x124c [ EFE09F71C47786BED45A6D3C2F9734E6 ] \Device\Harddisk0\DR0\Partition3
20:50:47.0550 0x124c \Device\Harddisk0\DR0\Partition3 - ok
20:50:47.0550 0x124c [ 8AA69EB6A512987FDBFB020B1B0AB607 ] \Device\Harddisk0\DR0\Partition4
20:50:47.0550 0x124c \Device\Harddisk0\DR0\Partition4 - ok
20:50:47.0565 0x124c [ 3541AD6EEC42D17E8C5734F63D7E1D6E ] \Device\Harddisk0\DR0\Partition5
20:50:47.0565 0x124c \Device\Harddisk0\DR0\Partition5 - ok
20:50:47.0581 0x124c [ 34BA6B8C68B4F69CE31F980351E695CB ] \Device\Harddisk0\DR0\Partition6
20:50:47.0581 0x124c \Device\Harddisk0\DR0\Partition6 - ok
20:50:47.0602 0x124c [ 94BA6B7C3E187D3348F7DA75F05578C1 ] \Device\Harddisk0\DR0\Partition7
20:50:47.0602 0x124c \Device\Harddisk0\DR0\Partition7 - ok
20:50:47.0602 0x124c [ 094724C84A0C7B881D059D14D1F9D17F ] \Device\Harddisk1\DR1\Partition1
20:50:47.0602 0x124c \Device\Harddisk1\DR1\Partition1 - ok
20:50:47.0602 0x124c ================ Scan generic autorun ======================
20:50:47.0992 0x124c [ 65E8545F1297CD83534C354A7BED1848, 19B3F3C17A335837454DC1851C6436D0BB2D8B1595AEB4DC71265FB20868B48F ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
20:50:48.0399 0x124c RTHDVCPL - ok
20:50:48.0414 0x124c Logitech Download Assistant - ok
20:50:48.0477 0x124c [ 1843EDBAAD135FFC743A8502EE9813FA, E40DB12ED7FB46C92E77B7ECCF8B4D5EF60060972C20E01A40DE96035B1993B5 ] C:\Program Files\Activ Software\ActivDriver\ActivMgr.exe
20:50:48.0493 0x124c ActivManager - ok
20:50:48.0649 0x124c [ A6A21A7D544675E98C040DA18904CF50, AACB578C297C7AC9FEBDAB4AD20235E5CFF6E3F260E76E6AE18D43DC57D69672 ] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe
20:50:48.0727 0x124c Malwarebytes TrayApp - ok
20:50:48.0805 0x124c [ 4C6AAABB264526A9C845A39AEBB79B69, B27F869E8B44CC5F1F9ADCA53AA848C16D706587ED9C7F995AE59BF9B0426523 ] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe
20:50:48.0821 0x124c StartCCC - ok
20:50:48.0883 0x124c [ EABAB863E4451B22CA44A4919E59D2B8, A74DD17FD171E794FF523D752438FDC330B246C21FD3D2FE8BCDD5B0395BF75D ] C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
20:50:48.0883 0x124c CLMLServer_For_P2G8 - ok
20:50:48.0914 0x124c [ 5961529D7D31C4D101190B35A600D7C8, 1848FA302F96F0F1F63A69DACB41C173B810672AC179DDCF75B9F5592DFDB7A5 ] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe
20:50:48.0930 0x124c CLVirtualDrive - ok
20:50:48.0961 0x124c [ 0966408A384E8B0FE57B0008E18D561C, 045AB5798CAFA7D27E7D02F780B3508EBF34C0991C8EF166A61CF869D9399B70 ] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
20:50:48.0977 0x124c RemoteControl10 - ok
20:50:49.0039 0x124c [ DBD8934E3909B60DA81A91BF53B76901, 29B061C5E05097394B8B9D7C6681783DB02735CE8AAD06BCC03C08617D778039 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
20:50:49.0071 0x124c avgnt - ok
20:50:49.0102 0x124c [ 187F4C75A89E3F412322C94526320074, D78FA7EF93C8C7B4326A5B6DB04A92ADD091DF00658FA8731D07C5D3BE29ED04 ] C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe
20:50:49.0102 0x124c BCSSync - ok
20:50:49.0149 0x124c [ 34D296AFC913E302953C70463EF09A48, BC413307CBC56C039EE8A05B51A56E14EF59678FBB33815AEB320078056C8CE7 ] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
20:50:49.0180 0x124c HP Software Update - ok
20:50:49.0227 0x124c OneDriveSetup - ok
20:50:49.0242 0x124c OneDriveSetup - ok
20:50:49.0336 0x124c [ 8F2EA5EE0695CCE2285D92C44108375C, 2C96A8E7E41E87C27B6A3325526F99A03333357EF2682C17A4892BE4A58D157E ] C:\Users\Ulla\AppData\Local\Microsoft\OneDrive\OneDrive.exe
20:50:49.0383 0x124c OneDrive - ok
20:50:49.0430 0x124c Skype - ok
20:50:49.0461 0x124c [ 6BF7676296D5359AFC135A5397000053, D31B9BCB856D6EFDEA27E4D4D341FF939BCBF0E8C97786B447C2074B3C68298E ] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
20:50:49.0524 0x124c ISUSPM - ok
20:50:49.0633 0x124c [ E9A2968052740D675A0FA9BE01DF861D, 76F27EAF70B6463216169122DF1731ECEA64437F5C9709E90F65603BDC2B541B ] C:\Users\Ulla\AppData\Roaming\Spotify\SpotifyWebHelper.exe
20:50:49.0680 0x124c Spotify Web Helper - ok
20:50:49.0852 0x124c [ EEEEF3C7728391B14AE64E3B4C27E418, 7D6A99918C1D83CDFB289E1EAAA54A56ECC7FA3294C06F7D77D5E2AE0A0C050F ] C:\Users\Ulla\AppData\Roaming\Spotify\Spotify.exe
20:50:50.0046 0x124c Spotify - ok
20:50:50.0093 0x124c [ 46996518AD75D97AD6427B42318936D5, F1609AF205464B7AC8251C4286F0D69A9C1BC745A4FB5D0B9149B12C4C5DCA99 ] C:\Users\Ulla\AppData\Roaming\OpenOffice Updater\Updater.exe
20:50:50.0124 0x124c OpenOffice Updater - ok
20:50:50.0502 0x124c [ 8D3D5BA1638778DE87503E5FEA68DC9F, D54C2B375A6F8A49BC53CAA3ED8A0EEBF53FD113BB47622F4AE6DA762D194FE7 ] C:\Program Files\CCleaner\CCleaner64.exe
20:50:50.0705 0x124c CCleaner Monitoring - ok
20:50:50.0721 0x124c Waiting for KSN requests completion. In queue: 80
20:50:51.0752 0x124c AV detected via SS2: Avira Antivirus, C:\Program Files (x86)\Avira\AntiVir Desktop\WindowsSecurityCenter.exe ( 15.0.25.170 ), 0x41000 ( enabled : updated )
20:50:51.0767 0x124c AV detected via SS2: Kaspersky Free, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\wmiav.exe ( 17.0.0.727 ), 0x40000 ( disabled : updated )
20:50:51.0799 0x124c AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
20:50:51.0799 0x124c AV detected via SS2: Malwarebytes, C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe ( 3.0.0.142 ), 0x60000 ( disabled : updated )
20:50:51.0846 0x124c Win FW state via NFP2: enabled ( trusted )
20:50:51.0986 0x124c ============================================================
20:50:51.0986 0x124c Scan finished
20:50:51.0986 0x124c ============================================================
20:50:51.0986 0x2104 Detected object count: 0
20:50:51.0986 0x2104 Actual detected object count: 0 Danke für deine Hilfe! |