BrainWasheD | 19.06.2017 22:06 | Hallo Matthias,
ich habe deine Schritte befolgt, hier sind die Logfiles:
TDSS: Code:
23:00:31.0730 6136 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
23:00:33.0505 6136 ============================================================
23:00:33.0505 6136 Current date / time: 2017/06/19 23:00:33.0505
23:00:33.0505 6136 SystemInfo:
23:00:33.0505 6136
23:00:33.0506 6136 OS Version: 6.2.9200 ServicePack: 0.0
23:00:33.0506 6136 Product type: Workstation
23:00:33.0506 6136 ComputerName: BRAINWASHED-PC
23:00:33.0506 6136 UserName: BrainWasheD
23:00:33.0506 6136 Windows directory: C:\WINDOWS
23:00:33.0506 6136 System windows directory: C:\WINDOWS
23:00:33.0506 6136 Running under WOW64
23:00:33.0506 6136 Processor architecture: Intel x64
23:00:33.0506 6136 Number of processors: 8
23:00:33.0506 6136 Page size: 0x1000
23:00:33.0506 6136 Boot type: Normal boot
23:00:33.0506 6136 ============================================================
23:00:33.0649 6136 Drive \Device\Harddisk0\DR0 - Size: 0x37E4896000 (223.57 Gb), SectorSize: 0x200, Cylinders: 0x7201, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
23:00:33.0649 6136 Drive \Device\Harddisk1\DR1 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
23:00:33.0654 6136 Drive \Device\Harddisk2\DR2 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
23:00:33.0677 6136 ============================================================
23:00:33.0677 6136 \Device\Harddisk0\DR0:
23:00:33.0677 6136 MBR partitions:
23:00:33.0677 6136 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1BF23000
23:00:33.0677 6136 \Device\Harddisk1\DR1:
23:00:33.0678 6136 MBR partitions:
23:00:33.0678 6136 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
23:00:33.0678 6136 \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xDE80800
23:00:33.0678 6136 \Device\Harddisk2\DR2:
23:00:33.0679 6136 GPT partitions:
23:00:33.0679 6136 \Device\Harddisk2\DR2\Partition1: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {5BC6AE9C-68CC-4EA4-9F0C-F658EB956BD4}, Name: Basic data partition, StartLBA 0x72800, BlocksNum 0x3D01E000
23:00:33.0679 6136 \Device\Harddisk2\DR2\Partition2: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {F3BBD056-75F7-4982-A762-77E43B3FC4C1}, Name: Basic data partition, StartLBA 0x3D090800, BlocksNum 0x37675800
23:00:33.0679 6136 MBR partitions:
23:00:33.0679 6136 ============================================================
23:00:33.0683 6136 C: <-> \Device\Harddisk1\DR1\Partition2
23:00:33.0704 6136 D: <-> \Device\Harddisk2\DR2\Partition1
23:00:33.0733 6136 E: <-> \Device\Harddisk2\DR2\Partition2
23:00:33.0734 6136 A: <-> \Device\Harddisk0\DR0\Partition1
23:00:33.0734 6136 ============================================================
23:00:33.0734 6136 Initialize success
23:00:33.0734 6136 ============================================================
23:00:38.0203 3724 ============================================================
23:00:38.0203 3724 Scan started
23:00:38.0203 3724 Mode: Manual; SigCheck; TDLFS;
23:00:38.0203 3724 ============================================================
23:00:38.0323 3724 ================ Scan system memory ========================
23:00:38.0323 3724 System memory - ok
23:00:38.0323 3724 ================ Scan services =============================
23:00:38.0384 3724 1394ohci - ok
23:00:38.0387 3724 3ware - ok
23:00:38.0390 3724 ACPI - ok
23:00:38.0392 3724 AcpiDev - ok
23:00:38.0395 3724 acpiex - ok
23:00:38.0397 3724 acpipagr - ok
23:00:38.0400 3724 AcpiPmi - ok
23:00:38.0403 3724 acpitime - ok
23:00:38.0408 3724 [ 8D6BA8E7676038A27FD4ECF12CC744B0 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
23:00:38.0440 3724 AdobeARMservice - ok
23:00:38.0446 3724 ADP80XX - ok
23:00:38.0450 3724 AFD - ok
23:00:38.0454 3724 ahcache - ok
23:00:38.0456 3724 AJRouter - ok
23:00:38.0459 3724 ALG - ok
23:00:38.0461 3724 AmdK8 - ok
23:00:38.0463 3724 AmdPPM - ok
23:00:38.0466 3724 amdsata - ok
23:00:38.0470 3724 amdsbs - ok
23:00:38.0473 3724 amdxata - ok
23:00:38.0475 3724 AppID - ok
23:00:38.0477 3724 AppIDSvc - ok
23:00:38.0480 3724 Appinfo - ok
23:00:38.0483 3724 applockerfltr - ok
23:00:38.0486 3724 AppReadiness - ok
23:00:38.0488 3724 AppXSvc - ok
23:00:38.0491 3724 arcsas - ok
23:00:38.0548 3724 [ A760C2AFBA1A71E0F7310A6E900CB0E4 ] aswbIDSAgent C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
23:00:38.0704 3724 aswbIDSAgent - ok
23:00:38.0715 3724 [ 0C19C91ED99964925FF8B05C23743AB1 ] aswbidsdriver C:\WINDOWS\system32\drivers\aswbidsdrivera.sys
23:00:38.0737 3724 aswbidsdriver - ok
23:00:38.0740 3724 [ 670839F4BA6D82F3035AADFE8274F02E ] aswbidsh C:\WINDOWS\system32\drivers\aswbidsha.sys
23:00:38.0757 3724 aswbidsh - ok
23:00:38.0766 3724 [ 5C561968CF601D76A98692DCC8CF74ED ] aswblog C:\WINDOWS\system32\drivers\aswbloga.sys
23:00:38.0786 3724 aswblog - ok
23:00:38.0790 3724 [ 335E5F19E7397A283B7ED20FE7B369EB ] aswbuniv C:\WINDOWS\system32\drivers\aswbuniva.sys
23:00:38.0803 3724 aswbuniv - ok
23:00:38.0806 3724 [ BA02CA77D989710F79FD662019C4DF94 ] aswHwid C:\WINDOWS\system32\drivers\aswHwid.sys
23:00:38.0822 3724 aswHwid - ok
23:00:38.0825 3724 [ 5E6FD2CB74138C6AF591779D2619BD6C ] aswKbd C:\WINDOWS\system32\drivers\aswKbd.sys
23:00:38.0839 3724 aswKbd - ok
23:00:38.0844 3724 [ 2B1490F2F1CC76C9C9B61CE63D6E7973 ] aswMonFlt C:\WINDOWS\system32\drivers\aswMonFlt.sys
23:00:38.0861 3724 aswMonFlt - ok
23:00:38.0866 3724 [ F26D1F761E14789743275FA5D258EAB8 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr2.sys
23:00:38.0882 3724 aswRdr - ok
23:00:38.0887 3724 [ C1007774450CFAB19D784D50C3410FC7 ] aswRvrt C:\WINDOWS\system32\drivers\aswRvrt.sys
23:00:38.0902 3724 aswRvrt - ok
23:00:38.0917 3724 [ EB1991686949400C51B8C21CE013621E ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
23:00:38.0961 3724 aswSnx - ok
23:00:38.0968 3724 [ 7A17BD26C74F5329CB1DF029AE4DD357 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
23:00:38.0999 3724 aswSP - ok
23:00:39.0003 3724 [ 2933CBC7643168E4288D443B4125941C ] aswStm C:\WINDOWS\system32\drivers\aswStm.sys
23:00:39.0014 3724 aswStm - ok
23:00:39.0023 3724 [ E76C21203E29F2DCC489EF585E0B1A38 ] aswVmm C:\WINDOWS\system32\drivers\aswVmm.sys
23:00:39.0046 3724 aswVmm - ok
23:00:39.0049 3724 AsyncMac - ok
23:00:39.0052 3724 atapi - ok
23:00:39.0055 3724 AudioEndpointBuilder - ok
23:00:39.0058 3724 Audiosrv - ok
23:00:39.0062 3724 [ D961A7C05A76302E782B1B0CF6546BA7 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
23:00:39.0075 3724 avast! Antivirus - ok
23:00:39.0079 3724 AxInstSV - ok
23:00:39.0081 3724 b06bdrv - ok
23:00:39.0084 3724 BasicDisplay - ok
23:00:39.0087 3724 BasicRender - ok
23:00:39.0090 3724 bcmfn2 - ok
23:00:39.0092 3724 BDESVC - ok
23:00:39.0094 3724 Suspicious service (Hidden): BEDaisy
23:00:39.0095 3724 BEDaisy ( HiddenService.Multi.Generic ) - warning
23:00:39.0095 3724 BEDaisy - detected HiddenService.Multi.Generic (1)
23:00:39.0098 3724 Beep - ok
23:00:39.0110 3724 [ 5EC0D7E4DBEB0D8CA45F01A3277D8D9B ] BEService C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
23:00:39.0148 3724 BEService - ok
23:00:39.0151 3724 BFE - ok
23:00:39.0154 3724 BitDefenderCOM - ok
23:00:39.0157 3724 BITS - ok
23:00:39.0159 3724 bowser - ok
23:00:39.0162 3724 BrokerInfrastructure - ok
23:00:39.0165 3724 Browser - ok
23:00:39.0168 3724 BthAvrcpTg - ok
23:00:39.0170 3724 BthHFEnum - ok
23:00:39.0172 3724 bthhfhid - ok
23:00:39.0175 3724 BthHFSrv - ok
23:00:39.0178 3724 BTHMODEM - ok
23:00:39.0181 3724 bthserv - ok
23:00:39.0183 3724 buttonconverter - ok
23:00:39.0187 3724 CAD - ok
23:00:39.0189 3724 CapImg - ok
23:00:39.0191 3724 cdfs - ok
23:00:39.0194 3724 CDPSvc - ok
23:00:39.0196 3724 CDPUserSvc - ok
23:00:39.0199 3724 Suspicious service (Hidden): CDPUserSvc_3f01d
23:00:39.0202 3724 cdrom - ok
23:00:39.0204 3724 CertPropSvc - ok
23:00:39.0207 3724 cht4iscsi - ok
23:00:39.0210 3724 cht4vbd - ok
23:00:39.0212 3724 circlass - ok
23:00:39.0215 3724 CldFlt - ok
23:00:39.0217 3724 CLFS - ok
23:00:39.0267 3724 [ C464783FB7BF3FF6FB620453B3B96A89 ] ClickToRunSvc C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
23:00:39.0363 3724 ClickToRunSvc - ok
23:00:39.0368 3724 ClipSVC - ok
23:00:39.0370 3724 clreg - ok
23:00:39.0377 3724 CmBatt - ok
23:00:39.0379 3724 CNG - ok
23:00:39.0382 3724 cnghwassist - ok
23:00:39.0412 3724 CompositeBus - ok
23:00:39.0414 3724 COMSysApp - ok
23:00:39.0417 3724 condrv - ok
23:00:39.0421 3724 CoreMessagingRegistrar - ok
23:00:39.0425 3724 CryptSvc - ok
23:00:39.0428 3724 dam - ok
23:00:39.0432 3724 DcomLaunch - ok
23:00:39.0434 3724 defragsvc - ok
23:00:39.0437 3724 DeviceAssociationService - ok
23:00:39.0439 3724 DeviceInstall - ok
23:00:39.0442 3724 DevicesFlowUserSvc - ok
23:00:39.0444 3724 Suspicious service (Hidden): DevicesFlowUserSvc_3f01d
23:00:39.0447 3724 DevQueryBroker - ok
23:00:39.0449 3724 Dfsc - ok
23:00:39.0453 3724 [ 9593475FBC857A05D93BFF4FA7323C2B ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
23:00:39.0472 3724 dg_ssudbus - ok
23:00:39.0474 3724 Dhcp - ok
23:00:39.0479 3724 diagnosticshub.standardcollector.service - ok
23:00:39.0482 3724 DiagTrack - ok
23:00:39.0484 3724 Disk - ok
23:00:39.0487 3724 DmEnrollmentSvc - ok
23:00:39.0490 3724 dmvsc - ok
23:00:39.0492 3724 dmwappushservice - ok
23:00:39.0495 3724 Dnscache - ok
23:00:39.0498 3724 dot3svc - ok
23:00:39.0500 3724 DPS - ok
23:00:39.0503 3724 drmkaud - ok
23:00:39.0505 3724 DsmSvc - ok
23:00:39.0508 3724 DsSvc - ok
23:00:39.0511 3724 DusmSvc - ok
23:00:39.0514 3724 DXGKrnl - ok
23:00:39.0516 3724 EapHost - ok
23:00:39.0518 3724 ebdrv - ok
23:00:39.0521 3724 EFS - ok
23:00:39.0523 3724 EhStorClass - ok
23:00:39.0525 3724 EhStorTcgDrv - ok
23:00:39.0528 3724 embeddedmode - ok
23:00:39.0531 3724 EntAppSvc - ok
23:00:39.0535 3724 [ 0E840AA66CAB02CBA9730C772BBE305B ] epp C:\EEK\bin64\epp.sys
23:00:39.0554 3724 epp - ok
23:00:39.0560 3724 [ D315FF43E23DF424ECEC2F6C930203E4 ] EpsonScanSvc C:\WINDOWS\system32\EscSvc64.exe
23:00:39.0574 3724 EpsonScanSvc - ok
23:00:39.0577 3724 [ 86032A47AD0105130FE7808C903E2086 ] EPSON_PM_RPCV4_06 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE
23:00:39.0588 3724 EPSON_PM_RPCV4_06 - ok
23:00:39.0591 3724 ErrDev - ok
23:00:39.0595 3724 EventSystem - ok
23:00:39.0598 3724 exfat - ok
23:00:39.0600 3724 fastfat - ok
23:00:39.0604 3724 Fax - ok
23:00:39.0607 3724 fdc - ok
23:00:39.0610 3724 fdPHost - ok
23:00:39.0612 3724 FDResPub - ok
23:00:39.0614 3724 fhsvc - ok
23:00:39.0617 3724 FileCrypt - ok
23:00:39.0619 3724 FileInfo - ok
23:00:39.0622 3724 Filetrace - ok
23:00:39.0625 3724 flpydisk - ok
23:00:39.0627 3724 FltMgr - ok
23:00:39.0630 3724 FontCache - ok
23:00:39.0634 3724 FontCache3.0.0.0 - ok
23:00:39.0638 3724 FrameServer - ok
23:00:39.0640 3724 FsDepends - ok
23:00:39.0643 3724 Fs_Rec - ok
23:00:39.0645 3724 fvevol - ok
23:00:39.0648 3724 gencounter - ok
23:00:39.0650 3724 genericusbfn - ok
23:00:39.0653 3724 GPIOClx0101 - ok
23:00:39.0657 3724 gpsvc - ok
23:00:39.0659 3724 GpuEnergyDrv - ok
23:00:39.0666 3724 [ 0545A3EB959CFA4790D267BFB8C1ACA4 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:00:39.0677 3724 gupdate - ok
23:00:39.0683 3724 [ 0545A3EB959CFA4790D267BFB8C1ACA4 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:00:39.0693 3724 gupdatem - ok
23:00:39.0696 3724 HdAudAddService - ok
23:00:39.0699 3724 HDAudBus - ok
23:00:39.0702 3724 HidBatt - ok
23:00:39.0705 3724 HidBth - ok
23:00:39.0708 3724 hidi2c - ok
23:00:39.0710 3724 hidinterrupt - ok
23:00:39.0712 3724 HidIr - ok
23:00:39.0715 3724 hidserv - ok
23:00:39.0717 3724 HidUsb - ok
23:00:39.0720 3724 HomeGroupListener - ok
23:00:39.0722 3724 HomeGroupProvider - ok
23:00:39.0725 3724 HpSAMD - ok
23:00:39.0727 3724 HTTP - ok
23:00:39.0729 3724 HvHost - ok
23:00:39.0732 3724 hvservice - ok
23:00:39.0734 3724 hwpolicy - ok
23:00:39.0737 3724 hyperkbd - ok
23:00:39.0741 3724 i8042prt - ok
23:00:39.0743 3724 iagpio - ok
23:00:39.0745 3724 iai2c - ok
23:00:39.0749 3724 iaLPSS2i_GPIO2 - ok
23:00:39.0751 3724 iaLPSS2i_GPIO2_BXT_P - ok
23:00:39.0754 3724 iaLPSS2i_I2C - ok
23:00:39.0756 3724 iaLPSS2i_I2C_BXT_P - ok
23:00:39.0760 3724 iaLPSSi_GPIO - ok
23:00:39.0762 3724 iaLPSSi_I2C - ok
23:00:39.0765 3724 iaStorAV - ok
23:00:39.0767 3724 iaStorV - ok
23:00:39.0770 3724 ibbus - ok
23:00:39.0772 3724 icssvc - ok
23:00:39.0776 3724 IKEEXT - ok
23:00:39.0778 3724 IndirectKmd - ok
23:00:39.0812 3724 [ 3A2D6740F51BE48C0FD01AD907329DEE ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
23:00:39.0909 3724 IntcAzAudAddService - ok
23:00:39.0913 3724 intelide - ok
23:00:39.0916 3724 intelpep - ok
23:00:39.0919 3724 intelppm - ok
23:00:39.0921 3724 iorate - ok
23:00:39.0924 3724 IpFilterDriver - ok
23:00:39.0926 3724 iphlpsvc - ok
23:00:39.0929 3724 IPMIDRV - ok
23:00:39.0931 3724 IPNAT - ok
23:00:39.0934 3724 IpxlatCfgSvc - ok
23:00:39.0938 3724 irda - ok
23:00:39.0940 3724 IRENUM - ok
23:00:39.0943 3724 irmon - ok
23:00:39.0946 3724 isapnp - ok
23:00:39.0948 3724 iScsiPrt - ok
23:00:39.0951 3724 kbdclass - ok
23:00:39.0954 3724 kbdhid - ok
23:00:39.0957 3724 kdnic - ok
23:00:39.0960 3724 KeyIso - ok
23:00:39.0962 3724 KSecDD - ok
23:00:39.0964 3724 KSecPkg - ok
23:00:39.0968 3724 ksthunk - ok
23:00:39.0970 3724 KtmRm - ok
23:00:39.0974 3724 [ 89C6518926FA2E7C1800964375DB67B5 ] ladfGSS C:\WINDOWS\system32\drivers\ladfGSS.sys
23:00:39.0983 3724 ladfGSS - ok
23:00:39.0986 3724 LanmanServer - ok
23:00:39.0988 3724 LanmanWorkstation - ok
23:00:39.0992 3724 lfsvc - ok
23:00:39.0995 3724 [ A6F294B38F3DFB67D6B6E1D1E60A402A ] LGBusEnum C:\WINDOWS\system32\drivers\LGBusEnum.sys
23:00:40.0010 3724 LGBusEnum - ok
23:00:40.0015 3724 [ 2D7F1C02B94D6F0F3E10107E5EA8E141 ] LGCoreTemp C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys
23:00:40.0029 3724 LGCoreTemp - ok
23:00:40.0032 3724 [ 2A9F60E6531F42B31874618743037719 ] LGJoyXlCore C:\WINDOWS\system32\drivers\LGJoyXlCore.sys
23:00:40.0047 3724 LGJoyXlCore - ok
23:00:40.0050 3724 [ FA59A7421049F5852C1182345A4B8C4F ] LGVirHid C:\WINDOWS\system32\drivers\LGVirHid.sys
23:00:40.0064 3724 LGVirHid - ok
23:00:40.0067 3724 LicenseManager - ok
23:00:40.0070 3724 lltdio - ok
23:00:40.0073 3724 lltdsvc - ok
23:00:40.0075 3724 lmhosts - ok
23:00:40.0079 3724 [ 409BCD64FCA0147614E6B0DD14C071FA ] LogiRegistryService C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
23:00:40.0091 3724 LogiRegistryService - ok
23:00:40.0095 3724 LSI_SAS - ok
23:00:40.0097 3724 LSI_SAS2i - ok
23:00:40.0101 3724 LSI_SAS3i - ok
23:00:40.0104 3724 LSI_SSS - ok
23:00:40.0107 3724 LSM - ok
23:00:40.0109 3724 luafv - ok
23:00:40.0112 3724 MapsBroker - ok
23:00:40.0115 3724 mausbhost - ok
23:00:40.0117 3724 mausbip - ok
23:00:40.0150 3724 [ D76E56108E6482905D3FAEA0649919E4 ] MBAMService C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
23:00:40.0245 3724 MBAMService - ok
23:00:40.0249 3724 megasas - ok
23:00:40.0252 3724 megasas2i - ok
23:00:40.0256 3724 megasr - ok
23:00:40.0260 3724 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
23:00:40.0275 3724 MEIx64 - ok
23:00:40.0278 3724 MessagingService - ok
23:00:40.0279 3724 Suspicious service (Hidden): MessagingService_3f01d
23:00:40.0282 3724 mlx4_bus - ok
23:00:40.0284 3724 MMCSS - ok
23:00:40.0287 3724 Modem - ok
23:00:40.0291 3724 monitor - ok
23:00:40.0294 3724 mouclass - ok
23:00:40.0297 3724 mouhid - ok
23:00:40.0299 3724 mountmgr - ok
23:00:40.0301 3724 mpsdrv - ok
23:00:40.0305 3724 MpsSvc - ok
23:00:40.0307 3724 MRxDAV - ok
23:00:40.0309 3724 mrxsmb - ok
23:00:40.0311 3724 mrxsmb10 - ok
23:00:40.0314 3724 mrxsmb20 - ok
23:00:40.0316 3724 MsBridge - ok
23:00:40.0319 3724 MSDTC - ok
23:00:40.0323 3724 Msfs - ok
23:00:40.0326 3724 msgpiowin32 - ok
23:00:40.0328 3724 mshidkmdf - ok
23:00:40.0330 3724 mshidumdf - ok
23:00:40.0332 3724 msisadrv - ok
23:00:40.0335 3724 MSiSCSI - ok
23:00:40.0338 3724 msiserver - ok
23:00:40.0340 3724 MSKSSRV - ok
23:00:40.0342 3724 MsLldp - ok
23:00:40.0345 3724 MSPCLOCK - ok
23:00:40.0347 3724 MSPQM - ok
23:00:40.0350 3724 MsRPC - ok
23:00:40.0355 3724 mssmbios - ok
23:00:40.0357 3724 MSTEE - ok
23:00:40.0360 3724 MTConfig - ok
23:00:40.0362 3724 Mup - ok
23:00:40.0364 3724 mvumis - ok
23:00:40.0376 3724 [ 9BD90C37FF23463CEAFC465A688B1E9F ] MyEpson Portal Service C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe
23:00:40.0399 3724 MyEpson Portal Service - ok
23:00:40.0403 3724 NativeWifiP - ok
23:00:40.0406 3724 NaturalAuthentication - ok
23:00:40.0408 3724 NcaSvc - ok
23:00:40.0410 3724 NcbService - ok
23:00:40.0413 3724 NcdAutoSetup - ok
23:00:40.0415 3724 ndfltr - ok
23:00:40.0417 3724 NDIS - ok
23:00:40.0420 3724 NdisCap - ok
23:00:40.0423 3724 NdisImPlatform - ok
23:00:40.0425 3724 NdisTapi - ok
23:00:40.0427 3724 Ndisuio - ok
23:00:40.0430 3724 NdisVirtualBus - ok
23:00:40.0432 3724 NdisWan - ok
23:00:40.0435 3724 ndiswanlegacy - ok
23:00:40.0437 3724 ndproxy - ok
23:00:40.0440 3724 Ndu - ok
23:00:40.0442 3724 NetAdapterCx - ok
23:00:40.0444 3724 NetBIOS - ok
23:00:40.0448 3724 NetBT - ok
23:00:40.0451 3724 Netlogon - ok
23:00:40.0454 3724 Netman - ok
23:00:40.0456 3724 netprofm - ok
23:00:40.0459 3724 NetSetupSvc - ok
23:00:40.0470 3724 NetTcpPortSharing - ok
23:00:40.0473 3724 netvsc - ok
23:00:40.0477 3724 NgcCtnrSvc - ok
23:00:40.0479 3724 NgcSvc - ok
23:00:40.0481 3724 NlaSvc - ok
23:00:40.0484 3724 Npfs - ok
23:00:40.0487 3724 npsvctrig - ok
23:00:40.0489 3724 nsi - ok
23:00:40.0492 3724 nsiproxy - ok
23:00:40.0495 3724 NTFS - ok
23:00:40.0499 3724 Null - ok
23:00:40.0509 3724 [ 934BF1FB1BE4A5BAE408EE860D82AEF0 ] NvContainerLocalSystem C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
23:00:40.0526 3724 NvContainerLocalSystem - ok
23:00:40.0536 3724 [ 934BF1FB1BE4A5BAE408EE860D82AEF0 ] NvContainerNetworkService C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
23:00:40.0552 3724 NvContainerNetworkService - ok
23:00:40.0556 3724 nvdimmn - ok
23:00:40.0561 3724 [ C27427C9D79DE00A01B9987B68485F60 ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
23:00:40.0573 3724 NVHDA - ok
23:00:40.0691 3724 [ 444B969DABB3F2D2176EF0BFAB42364F ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_a2b0acab06663645\nvlddmkm.sys
23:00:40.0980 3724 nvlddmkm - ok
23:00:40.0986 3724 nvraid - ok
23:00:40.0991 3724 nvstor - ok
23:00:40.0994 3724 [ FED2C4C15F3547D0B7E83AFA96B1FBB6 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
23:00:41.0008 3724 NvStreamKms - ok
23:00:41.0019 3724 [ 0B7BD772ED45111574E2736A5F358D79 ] NvTelemetryContainer C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
23:00:41.0033 3724 NvTelemetryContainer - ok
23:00:41.0037 3724 [ 0DF10036D38CD3B83307984ECFE61436 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
23:00:41.0051 3724 nvvad_WaveExtensible - ok
23:00:41.0055 3724 [ AECE653E7B9583938B1CF74B5B831CE3 ] nvvhci C:\WINDOWS\System32\drivers\nvvhci.sys
23:00:41.0065 3724 nvvhci - ok
23:00:41.0067 3724 OneSyncSvc - ok
23:00:41.0069 3724 Suspicious service (Hidden): OneSyncSvc_3f01d
23:00:41.0074 3724 [ 80D3AD0BC4300D3C3EB61C84CD2A2710 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
23:00:41.0086 3724 ose - ok
23:00:41.0105 3724 [ 1FA09B19F725F0A0EA41F99DE7A9B18B ] OverwolfUpdater C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
23:00:41.0143 3724 OverwolfUpdater - ok
23:00:41.0146 3724 p2pimsvc - ok
23:00:41.0150 3724 p2psvc - ok
23:00:41.0152 3724 Parport - ok
23:00:41.0155 3724 partmgr - ok
23:00:41.0157 3724 PcaSvc - ok
23:00:41.0160 3724 pci - ok
23:00:41.0162 3724 pciide - ok
23:00:41.0165 3724 pcmcia - ok
23:00:41.0167 3724 pcw - ok
23:00:41.0171 3724 pdc - ok
23:00:41.0174 3724 PEAUTH - ok
23:00:41.0176 3724 percsas2i - ok
23:00:41.0180 3724 percsas3i - ok
23:00:41.0205 3724 PerfHost - ok
23:00:41.0211 3724 PhoneSvc - ok
23:00:41.0214 3724 PimIndexMaintenanceSvc - ok
23:00:41.0215 3724 Suspicious service (Hidden): PimIndexMaintenanceSvc_3f01d
23:00:41.0218 3724 pla - ok
23:00:41.0221 3724 PlugPlay - ok
23:00:41.0223 3724 pmem - ok
23:00:41.0226 3724 PNRPAutoReg - ok
23:00:41.0228 3724 PNRPsvc - ok
23:00:41.0231 3724 PolicyAgent - ok
23:00:41.0236 3724 Power - ok
23:00:41.0238 3724 PptpMiniport - ok
23:00:41.0326 3724 [ 5404E7A968A26DF03793B6F68536594D ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
23:00:41.0387 3724 PrintNotify - ok
23:00:41.0392 3724 Processor - ok
23:00:41.0397 3724 ProfSvc - ok
23:00:41.0399 3724 Psched - ok
23:00:41.0402 3724 QWAVE - ok
23:00:41.0405 3724 QWAVEdrv - ok
23:00:41.0407 3724 RasAcd - ok
23:00:41.0410 3724 RasAgileVpn - ok
23:00:41.0413 3724 RasAuto - ok
23:00:41.0415 3724 Rasl2tp - ok
23:00:41.0420 3724 RasMan - ok
23:00:41.0422 3724 RasPppoe - ok
23:00:41.0425 3724 RasSstp - ok
23:00:41.0427 3724 rdbss - ok
23:00:41.0432 3724 rdpbus - ok
23:00:41.0434 3724 RDPDR - ok
23:00:41.0439 3724 RdpVideoMiniport - ok
23:00:41.0442 3724 rdyboost - ok
23:00:41.0445 3724 ReFS - ok
23:00:41.0447 3724 ReFSv1 - ok
23:00:41.0452 3724 RemoteAccess - ok
23:00:41.0454 3724 RemoteRegistry - ok
23:00:41.0457 3724 RetailDemo - ok
23:00:41.0461 3724 RmSvc - ok
23:00:41.0464 3724 RpcEptMapper - ok
23:00:41.0466 3724 RpcLocator - ok
23:00:41.0470 3724 RpcSs - ok
23:00:41.0473 3724 rspndr - ok
23:00:41.0487 3724 [ 5FC48CA9FFB9FB56ABA925A85BAB0272 ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys
23:00:41.0525 3724 rt640x64 - ok
23:00:41.0528 3724 s3cap - ok
23:00:41.0531 3724 SamSs - ok
23:00:41.0534 3724 sbp2port - ok
23:00:41.0538 3724 SCardSvr - ok
23:00:41.0540 3724 ScDeviceEnum - ok
23:00:41.0544 3724 scfilter - ok
23:00:41.0546 3724 Schedule - ok
23:00:41.0549 3724 scmbus - ok
23:00:41.0552 3724 SCPolicySvc - ok
23:00:41.0554 3724 sdbus - ok
23:00:41.0557 3724 SDFRd - ok
23:00:41.0560 3724 SDRSVC - ok
23:00:41.0563 3724 sdstor - ok
23:00:41.0565 3724 seclogon - ok
23:00:41.0569 3724 SecurityHealthService - ok
23:00:41.0571 3724 SEMgrSvc - ok
23:00:41.0576 3724 SENS - ok
23:00:41.0578 3724 SensorDataService - ok
23:00:41.0581 3724 SensorService - ok
23:00:41.0584 3724 SensrSvc - ok
23:00:41.0588 3724 SerCx - ok
23:00:41.0591 3724 SerCx2 - ok
23:00:41.0594 3724 Serenum - ok
23:00:41.0597 3724 Serial - ok
23:00:41.0600 3724 sermouse - ok
23:00:41.0606 3724 SessionEnv - ok
23:00:41.0612 3724 sfloppy - ok
23:00:41.0615 3724 SharedAccess - ok
23:00:41.0618 3724 ShellHWDetection - ok
23:00:41.0621 3724 shpamsvc - ok
23:00:41.0623 3724 SiSRaid2 - ok
23:00:41.0626 3724 SiSRaid4 - ok
23:00:41.0629 3724 smphost - ok
23:00:41.0633 3724 SmsRouter - ok
23:00:41.0639 3724 SNMPTRAP - ok
23:00:41.0642 3724 spaceport - ok
23:00:41.0644 3724 SpatialGraphFilter - ok
23:00:41.0647 3724 SpbCx - ok
23:00:41.0650 3724 spectrum - ok
23:00:41.0653 3724 Spooler - ok
23:00:41.0657 3724 sppsvc - ok
23:00:41.0659 3724 srv - ok
23:00:41.0663 3724 srv2 - ok
23:00:41.0666 3724 srvnet - ok
23:00:41.0669 3724 SSDPSRV - ok
23:00:41.0672 3724 SstpSvc - ok
23:00:41.0678 3724 [ 592FF34A2FD6C6351B8A3AA76B2C0A9E ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
23:00:41.0696 3724 ssudmdm - ok
23:00:41.0699 3724 StateRepository - ok
23:00:41.0713 3724 [ AC5DE2689B571942E08128D0EC771495 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
23:00:41.0752 3724 Steam Client Service - ok
23:00:41.0755 3724 stexstor - ok
23:00:41.0758 3724 stisvc - ok
23:00:41.0761 3724 storahci - ok
23:00:41.0764 3724 storflt - ok
23:00:41.0766 3724 stornvme - ok
23:00:41.0770 3724 storqosflt - ok
23:00:41.0773 3724 StorSvc - ok
23:00:41.0776 3724 storufs - ok
23:00:41.0779 3724 storvsc - ok
23:00:41.0782 3724 svsvc - ok
23:00:41.0784 3724 swenum - ok
23:00:41.0788 3724 swprv - ok
23:00:41.0792 3724 Synth3dVsc - ok
23:00:41.0795 3724 SysMain - ok
23:00:41.0798 3724 SystemEventsBroker - ok
23:00:41.0800 3724 TabletInputService - ok
23:00:41.0803 3724 TapiSrv - ok
23:00:41.0806 3724 Tcpip - ok
23:00:41.0808 3724 Tcpip6 - ok
23:00:41.0812 3724 tcpipreg - ok
23:00:41.0816 3724 tdx - ok
23:00:41.0819 3724 terminpt - ok
23:00:41.0822 3724 TermService - ok
23:00:41.0825 3724 Themes - ok
23:00:41.0828 3724 TieringEngineService - ok
23:00:41.0831 3724 tiledatamodelsvc - ok
23:00:41.0834 3724 TimeBrokerSvc - ok
23:00:41.0837 3724 TokenBroker - ok
23:00:41.0839 3724 TPM - ok
23:00:41.0842 3724 TrkWks - ok
23:00:41.0852 3724 [ B9E5E3CFD096A5D60F2F7061A6FBB67B ] Trufos C:\WINDOWS\system32\DRIVERS\Trufos.sys
23:00:41.0879 3724 Trufos - ok
23:00:41.0882 3724 TrustedInstaller - ok
23:00:41.0886 3724 TsUsbFlt - ok
23:00:41.0889 3724 TsUsbGD - ok
23:00:41.0891 3724 tunnel - ok
23:00:41.0895 3724 tzautoupdate - ok
23:00:41.0897 3724 UASPStor - ok
23:00:41.0900 3724 UcmCx0101 - ok
23:00:41.0903 3724 UcmTcpciCx0101 - ok
23:00:41.0907 3724 UcmUcsi - ok
23:00:41.0909 3724 Ucx01000 - ok
23:00:41.0912 3724 UdeCx - ok
23:00:41.0915 3724 udfs - ok
23:00:41.0918 3724 UEFI - ok
23:00:41.0922 3724 Ufx01000 - ok
23:00:41.0924 3724 UfxChipidea - ok
23:00:41.0929 3724 ufxsynopsys - ok
23:00:41.0935 3724 UI0Detect - ok
23:00:41.0937 3724 umbus - ok
23:00:41.0940 3724 UmPass - ok
23:00:41.0943 3724 UmRdpService - ok
23:00:41.0947 3724 UnistoreSvc - ok
23:00:41.0949 3724 Suspicious service (Hidden): UnistoreSvc_3f01d
23:00:41.0952 3724 upnphost - ok
23:00:41.0955 3724 UrsChipidea - ok
23:00:41.0958 3724 UrsCx01000 - ok
23:00:41.0960 3724 UrsSynopsys - ok
23:00:41.0964 3724 usbaudio - ok
23:00:41.0966 3724 usbccgp - ok
23:00:41.0969 3724 usbcir - ok
23:00:41.0972 3724 usbehci - ok
23:00:41.0976 3724 usbhub - ok
23:00:41.0979 3724 USBHUB3 - ok
23:00:41.0982 3724 usbohci - ok
23:00:41.0984 3724 usbprint - ok
23:00:41.0989 3724 [ 96B48485A7CC2C0A63C196A16403C5F3 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
23:00:42.0008 3724 usbscan - ok
23:00:42.0011 3724 usbser - ok
23:00:42.0014 3724 USBSTOR - ok
23:00:42.0017 3724 usbuhci - ok
23:00:42.0021 3724 USBXHCI - ok
23:00:42.0025 3724 UserDataSvc - ok
23:00:42.0027 3724 Suspicious service (Hidden): UserDataSvc_3f01d
23:00:42.0030 3724 UserManager - ok
23:00:42.0032 3724 UsoSvc - ok
23:00:42.0035 3724 VaultSvc - ok
23:00:42.0039 3724 vdrvroot - ok
23:00:42.0041 3724 vds - ok
23:00:42.0044 3724 VerifierExt - ok
23:00:42.0047 3724 vhdmp - ok
23:00:42.0050 3724 vhf - ok
23:00:42.0055 3724 vmbus - ok
23:00:42.0057 3724 VMBusHID - ok
23:00:42.0060 3724 vmgid - ok
23:00:42.0064 3724 vmicguestinterface - ok
23:00:42.0066 3724 vmicheartbeat - ok
23:00:42.0069 3724 vmickvpexchange - ok
23:00:42.0072 3724 vmicrdv - ok
23:00:42.0075 3724 vmicshutdown - ok
23:00:42.0078 3724 vmictimesync - ok
23:00:42.0081 3724 vmicvmsession - ok
23:00:42.0083 3724 vmicvss - ok
23:00:42.0087 3724 volmgr - ok
23:00:42.0090 3724 volmgrx - ok
23:00:42.0093 3724 volsnap - ok
23:00:42.0096 3724 volume - ok
23:00:42.0099 3724 vpci - ok
23:00:42.0102 3724 vsmraid - ok
23:00:42.0105 3724 VSS - ok
23:00:42.0108 3724 VSTXRAID - ok
23:00:42.0111 3724 vwifibus - ok
23:00:42.0114 3724 vwififlt - ok
23:00:42.0117 3724 W32Time - ok
23:00:42.0121 3724 WacomPen - ok
23:00:42.0125 3724 WalletService - ok
23:00:42.0127 3724 wanarp - ok
23:00:42.0130 3724 wanarpv6 - ok
23:00:42.0133 3724 wbengine - ok
23:00:42.0136 3724 WbioSrvc - ok
23:00:42.0140 3724 wcifs - ok
23:00:42.0143 3724 Wcmsvc - ok
23:00:42.0146 3724 wcncsvc - ok
23:00:42.0149 3724 wcnfs - ok
23:00:42.0154 3724 WdBoot - ok
23:00:42.0157 3724 Wdf01000 - ok
23:00:42.0161 3724 WdFilter - ok
23:00:42.0164 3724 WdiServiceHost - ok
23:00:42.0167 3724 WdiSystemHost - ok
23:00:42.0170 3724 wdiwifi - ok
23:00:42.0173 3724 WdNisDrv - ok
23:00:42.0175 3724 WdNisSvc - ok
23:00:42.0179 3724 WebClient - ok
23:00:42.0182 3724 Wecsvc - ok
23:00:42.0186 3724 WEPHOSTSVC - ok
23:00:42.0189 3724 wercplsupport - ok
23:00:42.0192 3724 WerSvc - ok
23:00:42.0195 3724 WFDSConMgrSvc - ok
23:00:42.0198 3724 WFPLWFS - ok
23:00:42.0201 3724 WiaRpc - ok
23:00:42.0205 3724 WIMMount - ok
23:00:42.0207 3724 WinDefend - ok
23:00:42.0214 3724 WindowsTrustedRT - ok
23:00:42.0217 3724 WindowsTrustedRTProxy - ok
23:00:42.0220 3724 WinHttpAutoProxySvc - ok
23:00:42.0223 3724 WinMad - ok
23:00:42.0232 3724 Winmgmt - ok
23:00:42.0235 3724 WinNat - ok
23:00:42.0238 3724 WinRM - ok
23:00:42.0244 3724 WINUSB - ok
23:00:42.0247 3724 WinVerbs - ok
23:00:42.0250 3724 wisvc - ok
23:00:42.0253 3724 WlanSvc - ok
23:00:42.0256 3724 wlidsvc - ok
23:00:42.0259 3724 wlpasvc - ok
23:00:42.0263 3724 WmiAcpi - ok
23:00:42.0267 3724 wmiApSrv - ok
23:00:42.0270 3724 WMPNetworkSvc - ok
23:00:42.0277 3724 [ 1AE1076034392218EE89D2744EC2A071 ] Wof C:\WINDOWS\system32\drivers\Wof.sys
23:00:42.0300 3724 Wof - ok
23:00:42.0305 3724 workfolderssvc - ok
23:00:42.0310 3724 WPDBusEnum - ok
23:00:42.0313 3724 WpdUpFltr - ok
23:00:42.0316 3724 WpnService - ok
23:00:42.0319 3724 WpnUserService - ok
23:00:42.0322 3724 Suspicious service (Hidden): WpnUserService_3f01d
23:00:42.0324 3724 ws2ifsl - ok
23:00:42.0328 3724 wscsvc - ok
23:00:42.0330 3724 WSearch - ok
23:00:42.0335 3724 wuauserv - ok
23:00:42.0339 3724 WudfPf - ok
23:00:42.0342 3724 WUDFRd - ok
23:00:42.0345 3724 wudfsvc - ok
23:00:42.0348 3724 WUDFWpdFs - ok
23:00:42.0351 3724 WUDFWpdMtp - ok
23:00:42.0354 3724 WwanSvc - ok
23:00:42.0358 3724 xbgm - ok
23:00:42.0361 3724 XblAuthManager - ok
23:00:42.0364 3724 XblGameSave - ok
23:00:42.0367 3724 xboxgip - ok
23:00:42.0370 3724 XboxGipSvc - ok
23:00:42.0373 3724 XboxNetApiSvc - ok
23:00:42.0376 3724 xinputhid - ok
23:00:42.0378 3724 ================ Scan global ===============================
23:00:42.0387 3724 [Global] - ok
23:00:42.0387 3724 ================ Scan MBR ==================================
23:00:42.0389 3724 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
23:00:42.0408 3724 \Device\Harddisk0\DR0 - ok
23:00:42.0410 3724 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
23:00:42.0472 3724 \Device\Harddisk1\DR1 - ok
23:00:42.0473 3724 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk2\DR2
23:00:42.0556 3724 \Device\Harddisk2\DR2 - ok
23:00:42.0556 3724 ================ Scan VBR ==================================
23:00:42.0558 3724 [ 1195C03E7DA255B6915431A60E4B1184 ] \Device\Harddisk0\DR0\Partition1
23:00:42.0559 3724 \Device\Harddisk0\DR0\Partition1 - ok
23:00:42.0561 3724 [ 506CBC4A9F285019A259E027A0DDF1BE ] \Device\Harddisk1\DR1\Partition1
23:00:42.0562 3724 \Device\Harddisk1\DR1\Partition1 - ok
23:00:42.0564 3724 [ 594A7BDBF1B78F87D4872DE2EA5996E9 ] \Device\Harddisk1\DR1\Partition2
23:00:42.0566 3724 \Device\Harddisk1\DR1\Partition2 - ok
23:00:42.0593 3724 [ 5BF1B60609D5BC337ADE74C6A37DF53B ] \Device\Harddisk2\DR2\Partition1
23:00:42.0594 3724 \Device\Harddisk2\DR2\Partition1 - ok
23:00:42.0614 3724 [ EE83130179050E9C0607F99DEB389C0E ] \Device\Harddisk2\DR2\Partition2
23:00:42.0615 3724 \Device\Harddisk2\DR2\Partition2 - ok
23:00:42.0615 3724 ============================================================
23:00:42.0615 3724 Scan finished
23:00:42.0615 3724 ============================================================
23:00:42.0621 13376 Detected object count: 1
23:00:42.0621 13376 Actual detected object count: 1
23:00:43.0820 13376 BEDaisy ( HiddenService.Multi.Generic ) - skipped by user
23:00:43.0820 13376 BEDaisy ( HiddenService.Multi.Generic ) - User select action: Skip Addition: Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 18-06-2017 01
durchgeführt von BrainWasheD (19-06-2017 22:47:32)
Gestartet von C:\Users\BrainWasheD\Desktop
Windows 10 Home Version 1703 (X64) (2017-05-20 17:35:03)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-1290209912-1044598962-369420843-500 - Administrator - Disabled)
BrainWasheD (S-1-5-21-1290209912-1044598962-369420843-1000 - Administrator - Enabled) => C:\Users\BrainWasheD
DefaultAccount (S-1-5-21-1290209912-1044598962-369420843-503 - Limited - Disabled)
Gast (S-1-5-21-1290209912-1044598962-369420843-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1290209912-1044598962-369420843-1002 - Limited - Enabled)
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Ansel (Version: 382.05 - NVIDIA Corporation) Hidden
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.4.5.0 - Asmedia Technology)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.4.2294 - AVAST Software)
Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
CCleaner (HKLM\...\CCleaner) (Version: 5.31 - Piriform)
Discord (HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.)
Epson Event Manager (HKLM-x32\...\{9F205E94-9E42-4486-A92A-DF3F6CB85444}) (Version: 3.10.0061 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
Epson Software Updater (HKLM-x32\...\{7BAC3F7A-B963-468E-982E-B5608A87408D}) (Version: 4.4.4 - SEIKO EPSON CORPORATION)
EPSON XP-630 Series Printer Uninstall (HKLM\...\EPSON XP-630 Series) (Version: - Seiko Epson Corporation)
EPSON-Handbücher (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.53.0.0 - Seiko Epson Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.104 - Google Inc.)
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
Guild Wars 2 (HKLM\...\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment)
League of Legends (HKLM-x32\...\League of Legends 4.2.1) (Version: 4.2.1 - Riot Games)
League of Legends (x32 Version: 4.2.1 - Riot Games) Hidden
Logitech Gaming Software 8.92 (HKLM\...\Logitech Gaming Software) (Version: 8.92.67 - Logitech Inc.)
Malwarebytes Version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
Microsoft Office 365 ProPlus - de-de (HKLM\...\O365ProPlusRetail - de-de) (Version: 16.0.8229.2041 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation)
MyEpson Portal (x32 Version: 1.1.2.2 - SEIKO EPSON CORPORATION) Hidden
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.3.3 - Notepad++ Team)
Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.4.1 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 382.05 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.6.0.74 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.6.0.74 - NVIDIA Corporation)
NVIDIA Grafiktreiber 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 382.05 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.26 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.17.0329 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0329 - NVIDIA Corporation)
NvNodejs (Version: 3.6.0.74 - NVIDIA Corporation) Hidden
NvTelemetry (Version: 2.4.10.0 - NVIDIA Corporation) Hidden
NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.8229.2041 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.8229.2041 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.8229.2041 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.8229.2041 - Microsoft Corporation) Hidden
Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.104.211.0 - Overwolf Ltd.)
Overwolf.Setup.VC100CRTx64.Dist (HKLM\...\{EC9D5554-6852-4A55-81BB-AC02C7A8CFED}) (Version: 1.0.0 - Overwolf)
Overwolf.Setup.VC100CRTx86.Dist (x32 Version: 1.0.0 - Overwolf) Hidden
PLAYERUNKNOWN'S BATTLEGROUNDS (HKLM\...\Steam App 578080) (Version: - Bluehole, Inc.)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.91.1119.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.)
SafeZone Stable 3.55.2393.596 (x32 Version: 3.55.2393.596 - Avast Software) Hidden
SHIELD Streaming (Version: 7.1.0370 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 3.6.0.74 - NVIDIA Corporation) Hidden
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamSpeak 3 Client (HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\TeamSpeak 3 Client) (Version: 3.1.4 - TeamSpeak Systems GmbH)
Twitch (HKLM-x32\...\{1F2611FB-6F69-4AA8-BECD-243BD8CB45F3}) (Version: 6.0.0.0 - Twitch Interactive, Inc.)
UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.)
Vulkan Run Time Libraries 1.0.42.1 (HKLM\...\VulkanRT1.0.42.1) (Version: 1.0.42.1 - LunarG, Inc.)
WinRAR 5.40 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-1290209912-1044598962-369420843-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\BrainWasheD\AppData\Local\Microsoft\OneDrive\17.3.6816.0313\amd64\FileSyncShell64.dll => Keine Datei
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {0EA1CF12-4D4E-4351-94B7-84115E3AB914} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-18] (Google Inc.)
Task: {18BD4184-9849-4FDB-9B2D-24D03803CE9D} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {197019C0-A39E-4251-AA72-360935C4A061} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-06-17] (Microsoft Corporation)
Task: {1B4E6278-16D4-45A6-8BDE-8BAA2F57111A} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-05-03] (NVIDIA Corporation)
Task: {2A01F3FF-934C-4158-998B-12E9A8BA31B2} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-05-20] (AVAST Software)
Task: {3BF8BA78-4AC9-4CB9-9335-A07B87708F74} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-06-17] (Microsoft Corporation)
Task: {420B7897-F154-4134-B3AE-149DECC6BAF7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {4D07E85B-84E3-41BF-B128-048A1B11ABD7} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-17] ()
Task: {4D092839-43B2-4855-AB19-8D6325F14541} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {5832288D-E503-4966-AF8E-965743410F82} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5A7E1579-B6EB-4F42-9120-BC6031D5793C} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5B4D641C-AF35-4B5B-8EDB-D191464EBBE8} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {61C6518D-C13B-4071-9836-2975C78C13FD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-06-13] (Piriform Ltd)
Task: {6F7AC86E-5FFA-4710-9A38-0BE5F3CB4539} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {7270ECB5-AEA9-489F-BA3C-BC230228194A} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {74D85C90-A46D-4914-B0DE-2B320BE872A4} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-05-03] (NVIDIA Corporation)
Task: {7CA44C16-4C06-4287-B3F5-C92E3853D309} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-05-20] (AVAST Software)
Task: {7E801DA2-CF04-4FED-BCA3-31CF6097C3C2} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-05-03] (NVIDIA Corporation)
Task: {7FB80D08-E1BE-4B3C-BDA4-6AA519217046} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-05-03] (NVIDIA Corporation)
Task: {925B5788-1503-42EF-BA35-28AAED84F0DD} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-17] ()
Task: {93A58816-DD3E-4BF6-9C17-F4D3BAC595AC} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-05-03] (NVIDIA Corporation)
Task: {95284773-EAF4-481E-B224-DB2BF54EDA8F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {957EF89D-E1CF-4C48-BEC4-14BB44D42D51} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-18] (Google Inc.)
Task: {96F95AF5-1C8C-4718-A36B-24E45D8224B4} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {9CC7B1AB-F5C2-46E8-AF00-3CA249EBFF9A} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {A150F5A9-E5F0-4935-BD77-219558415C65} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {A34D82D1-35D7-40D5-BFBD-1228C53033DF} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {A4D1A90D-EB59-4F32-94B7-FF32DB04EE43} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A664084A-B808-467F-AAE7-749AE16EAF62} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-09] (Microsoft Corporation)
Task: {A81ACE1F-61CB-4BC1-A7FA-8C924339B59A} - System32\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE [2013-11-22] (SEIKO EPSON CORPORATION)
Task: {B428955E-0F10-42B9-9BC2-C8E0D4A2E8CA} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {B74E1E8C-4791-48B9-AB80-C95F3E9408B5} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2017-06-06] (Overwolf LTD)
Task: {BE535D16-1CEE-4C7F-B997-0936C38FD171} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
Task: {BFCFEED0-3A42-43DE-9DB8-3EB9C8A3436B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {C0E93ABF-6B28-43AF-9233-8C6C60788FCE} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {C2F94150-B72D-4E77-AF25-E4B46736A963} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DE170156-FC9E-4655-9B93-0A1102B1FB76} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-05-03] (NVIDIA Corporation)
Task: {E3B079A5-9C71-41C8-B6DF-3EF03C091D3E} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-05-03] (NVIDIA Corporation)
Task: {E413BE20-6FCF-4881-9CF1-2A7117D6ED3A} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-06-17] (Microsoft Corporation)
Task: {E8B61091-544C-404C-8B07-6E8782293A49} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F43B762F-7560-433A-B5B4-784D6E925E58} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-05-03] (NVIDIA Corporation)
Task: {F848E963-1286-4D26-917B-4090052424C3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {FCA81C28-8677-43F7-B312-4732D381BE28} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-09] (Microsoft Corporation)
Task: {FCC70481-09E8-4295-9EA9-2E5D1007F50D} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\EPSON XP-630 Series Update {61C1FF77-ABA5-4555-868B-77F3A3B348E5}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE :/EXE:{61C1FF77-ABA5-4555-868B-77F3A3B348E5} /F:Update WORKGROUP\BRAINWASHED-PC$ ÄŠSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
==================== Verknüpfungen & WMI ========================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2017-05-20 19:44 - 2017-05-03 22:16 - 01267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-03-18 22:58 - 2017-03-18 22:58 - 00138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2017-03-18 22:59 - 2017-03-20 06:36 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-06-08 11:14 - 2017-06-08 11:14 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-06-08 11:14 - 2017-06-08 11:14 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-06-08 11:14 - 2017-06-08 11:14 - 43318784 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-06-08 11:14 - 2017-06-08 11:14 - 02427904 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\skypert.dll
2015-03-07 02:07 - 2015-03-07 02:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2017-04-06 01:05 - 2017-04-06 01:05 - 01096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2015-03-07 02:07 - 2015-03-07 02:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2017-04-06 01:05 - 2017-04-06 01:05 - 00241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2017-06-18 22:38 - 2017-06-15 09:29 - 03807064 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.104\libglesv2.dll
2017-06-18 22:38 - 2017-06-15 09:29 - 00100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.104\libegl.dll
2017-05-27 02:21 - 2017-05-27 02:21 - 01529320 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8839\Battle.net Helper.exe
2017-05-20 19:44 - 2017-05-03 22:16 - 01040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-05-20 18:24 - 2017-05-20 18:24 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-05-20 18:24 - 2017-05-20 18:24 - 00997896 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll
2017-05-20 18:24 - 2017-05-20 18:24 - 67717632 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-05-20 18:24 - 2017-05-20 18:24 - 00176992 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-05-20 18:24 - 2017-05-20 18:24 - 00223224 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-05-20 18:23 - 2017-05-20 18:23 - 00291824 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-05-20 19:44 - 2017-05-03 22:15 - 65708992 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll
2017-05-20 21:01 - 2017-05-17 03:54 - 00678176 _____ () D:\Program Files (x86)\Steam\SDL2.dll
2017-05-20 21:01 - 2016-09-01 03:02 - 04969248 _____ () D:\Program Files (x86)\Steam\v8.dll
2017-05-20 21:01 - 2017-06-08 07:42 - 02485536 _____ () D:\Program Files (x86)\Steam\video.dll
2017-05-20 21:01 - 2016-09-01 03:02 - 01563936 _____ () D:\Program Files (x86)\Steam\icui18n.dll
2017-05-20 21:01 - 2016-09-01 03:02 - 01195296 _____ () D:\Program Files (x86)\Steam\icuuc.dll
2017-05-20 21:01 - 2016-01-27 09:49 - 02549760 _____ () D:\Program Files (x86)\Steam\libavcodec-56.dll
2017-05-20 21:01 - 2016-01-27 09:49 - 00491008 _____ () D:\Program Files (x86)\Steam\libavformat-56.dll
2017-05-20 21:01 - 2016-01-27 09:49 - 00332800 _____ () D:\Program Files (x86)\Steam\libavresample-2.dll
2017-05-20 21:01 - 2016-01-27 09:49 - 00442880 _____ () D:\Program Files (x86)\Steam\libavutil-54.dll
2017-05-20 21:01 - 2016-01-27 09:49 - 00485888 _____ () D:\Program Files (x86)\Steam\libswscale-3.dll
2017-05-20 21:01 - 2017-06-08 07:42 - 00877856 _____ () D:\Program Files (x86)\Steam\bin\chromehtml.DLL
2017-05-20 21:01 - 2016-07-05 00:17 - 00266560 _____ () D:\Program Files (x86)\Steam\openvr_api.dll
2017-05-20 21:01 - 2017-01-04 15:28 - 01958912 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\ffmpeg.dll
2017-05-20 21:01 - 2017-05-20 21:01 - 01082880 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_voice\discord_voice.node
2017-05-20 21:01 - 2017-05-20 21:01 - 03750400 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_voice\libdiscord.dll
2017-05-20 21:01 - 2017-05-20 21:01 - 00914432 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_utils\discord_utils.node
2017-05-20 21:01 - 2017-05-20 21:01 - 01127424 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_toaster\discord_toaster.node
2017-05-20 21:02 - 2017-05-08 21:45 - 69516064 _____ () D:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
2017-06-08 14:55 - 2017-05-17 03:54 - 00678176 _____ () D:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
2017-05-20 21:01 - 2017-06-08 07:42 - 00385312 _____ () D:\Program Files (x86)\Steam\steam.dll
2017-05-27 02:21 - 2017-05-27 02:21 - 55758824 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8839\libcef.dll
2017-05-27 02:21 - 2017-05-27 02:21 - 00540336 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8839\ortp.dll
2017-05-27 02:21 - 2017-05-27 02:21 - 00133632 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8839\libEGL.dll
2017-05-27 02:21 - 2017-05-27 02:21 - 03384832 _____ () D:\Program Files (x86)\Blizzard App\Battle.net.8839\libGLESv2.dll
2017-05-20 21:01 - 2017-01-04 15:28 - 02278912 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\libglesv2.dll
2017-05-20 21:01 - 2017-01-04 15:28 - 00096768 _____ () C:\Users\BrainWasheD\AppData\Local\Discord\app-0.0.297\libegl.dll
2017-06-19 22:41 - 2017-06-19 22:41 - 00148992 _____ () \\?\C:\Users\BrainWasheD\AppData\Local\Temp\4D6.tmp.node
2017-05-20 21:01 - 2017-05-20 21:01 - 02658296 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_rpc\discord_rpc.node
2017-05-20 21:02 - 2017-05-20 21:02 - 02665976 _____ () \\?\C:\Users\BrainWasheD\AppData\Roaming\discord\0.0.297\modules\discord_contact_import\discord_contact_import.node
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
IE trusted site: HKU\S-1-5-21-1290209912-1044598962-369420843-1000\...\sharepoint.com -> hxxps://uniduesseldorf-files.sharepoint.com
==================== Hosts Inhalt: ==========================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2009-07-14 04:34 - 2017-06-18 02:58 - 00000969 _____ C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 hxxp://hosted.ap.org/dynamic/stories/L/LT_COLOMBIA_EXPLOSION?SITE=OHCIN&SECTION=HOME&TEMPLATE=DEFAULT
127.0.0.1 hxxp://hosted.ap.org
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-1290209912-1044598962-369420843-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\BrainWasheD\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 80.69.96.12 - 81.210.129.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [{87F5FF42-E6DD-4726-95E9-16739ECC7E30}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.596\SZBrowser.exe
FirewallRules: [{872189C6-BFD2-4B8B-96BE-0B46B96644F3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{B8B90C3A-5B14-488C-AF0F-D1617885C3B7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{C26FC00F-49AE-4D19-99C7-600F0478DE5E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{0D761F0A-BBB2-45AC-B7A4-D482C6DEB44B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{55CDFBBC-4E2A-4AEF-B3B1-DCFC7D9BAF85}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{0E3356F7-F228-4728-9E30-BE801CEA82CF}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [UDP Query User{1EF88E0A-7ACA-4DF1-9C90-B65F0AA1445A}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [{A3092E72-F609-4569-A434-CAB23FFFD283}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{52E242B6-D440-4CAD-A20C-9C233527808A}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{C64A3D05-997F-4A86-9259-386559B19FF4}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{AFD1EF63-594B-48BA-8E9E-D023CE536350}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{8C819F29-F37B-4144-9A59-8A5F5E71EA8A}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{0D25867A-6142-4002-9962-9CD7B1B7F4E4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{42229EC3-B520-47C7-83BB-FE6C632C0FCF}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{CC3CEC28-C196-4CD5-81FE-F01B597B1DC5}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{963131C2-051C-40C2-9D9B-0DC305839D3A}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [TCP Query User{F64ACAA9-9C9C-40A8-BB68-4A6B0368B519}A:\program files (x86)\overwatch\overwatch.exe] => (Allow) A:\program files (x86)\overwatch\overwatch.exe
FirewallRules: [UDP Query User{A4F420F1-BA4B-4233-B661-6CC140C9B529}A:\program files (x86)\overwatch\overwatch.exe] => (Allow) A:\program files (x86)\overwatch\overwatch.exe
FirewallRules: [TCP Query User{155E7B90-091A-478A-B97D-3A7485E295DD}A:\program files (x86)\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe] => (Allow) A:\program files (x86)\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{31E9F334-B532-4C13-92D2-7D1C496B3D14}A:\program files (x86)\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe] => (Allow) A:\program files (x86)\heroes of the storm\versions\base53548\heroesofthestorm_x64.exe
FirewallRules: [TCP Query User{51EFE651-26BE-4A31-A5A4-A2EC6E2B4CB4}A:\program files (x86)\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) A:\program files (x86)\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe
FirewallRules: [UDP Query User{FF09E575-090C-458D-B310-F628B9378142}A:\program files (x86)\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) A:\program files (x86)\steamlibrary\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe
FirewallRules: [{EAE34AD0-B88C-47A7-BD29-081717FA782C}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
FirewallRules: [{133124C8-C45C-4ED5-BDB8-4AFC92BF3C11}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
FirewallRules: [TCP Query User{87218B48-9D2E-4248-B98B-8A9D1CBCB1E2}A:\program files (x86)\heroes of the storm\versions\base53965\heroesofthestorm_x64.exe] => (Allow) A:\program files (x86)\heroes of the storm\versions\base53965\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{306540A7-53FE-4C88-B647-E8EC332FF4F6}A:\program files (x86)\heroes of the storm\versions\base53965\heroesofthestorm_x64.exe] => (Allow) A:\program files (x86)\heroes of the storm\versions\base53965\heroesofthestorm_x64.exe
FirewallRules: [TCP Query User{2384971D-B58C-4376-908D-B785C4406E02}A:\program files (x86)\heroes of the storm\versions\base54339\heroesofthestorm_x64.exe] => (Allow) A:\program files (x86)\heroes of the storm\versions\base54339\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{56FAF66C-996E-4481-A4EB-6A0541C4D719}A:\program files (x86)\heroes of the storm\versions\base54339\heroesofthestorm_x64.exe] => (Allow) A:\program files (x86)\heroes of the storm\versions\base54339\heroesofthestorm_x64.exe
FirewallRules: [{952936BB-C030-4D9E-A816-BBEE5A3F2EB7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{31C9BEE6-141A-4867-82E9-47746613D8AE}] => (Block) C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hosted.ap.org_0
FirewallRules: [{70B0E2F7-4E72-43B7-B9DA-9975BAD33385}] => (Block) C:\Users\BrainWasheD\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hosted.ap.org_0.localstorage-journal
==================== Wiederherstellungspunkte =========================
ACHTUNG: Systemwiederherstellung ist deaktiviert
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (06/19/2017 04:43:29 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/19/2017 02:38:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb
Name des fehlerhaften Moduls: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000006369f2
ID des fehlerhaften Prozesses: 0x1564
Startzeit der fehlerhaften Anwendung: 0x01d2e890df61f200
Pfad der fehlerhaften Anwendung: C:\Program Files\Logitech Gaming Software\LCore.exe
Pfad des fehlerhaften Moduls: C:\Program Files\Logitech Gaming Software\LCore.exe
Berichtskennung: d9f806dd-6a32-4ab4-8c07-96a419ac4200
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (06/19/2017 02:12:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AUDIODG.EXE, Version: 10.0.15063.0, Zeitstempel: 0x4247e346
Name des fehlerhaften Moduls: RenderAPO.dll, Version: 8.90.101.0, Zeitstempel: 0x584a1932
Ausnahmecode: 0xc0000409
Fehleroffset: 0x00000000000c93e7
ID des fehlerhaften Prozesses: 0x2fec
Startzeit der fehlerhaften Anwendung: 0x01d2e8838602c153
Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\AUDIODG.EXE
Pfad des fehlerhaften Moduls: C:\WINDOWS\system32\RenderAPO.dll
Berichtskennung: a64e6368-da15-461b-be26-1fece953fe2c
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (06/19/2017 01:22:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: TDSSKiller.exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000409
Fehleroffset: 0xae2ca030
ID des fehlerhaften Prozesses: 0x37a8
Startzeit der fehlerhaften Anwendung: 0x01d2e889c899d617
Pfad der fehlerhaften Anwendung: C:\Users\BRAINW~1\AppData\Local\Temp\Rar$EXa0.094\TDSSKiller.exe
Pfad des fehlerhaften Moduls: unknown
Berichtskennung: 4a7d28d3-39ab-48a6-ae36-a72fca7d377f
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (06/19/2017 01:22:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: tdsskiller (1).exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000409
Fehleroffset: 0xae2ca030
ID des fehlerhaften Prozesses: 0x1a74
Startzeit der fehlerhaften Anwendung: 0x01d2e889b1a52f70
Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Downloads\tdsskiller (1).exe
Pfad des fehlerhaften Moduls: unknown
Berichtskennung: 78777bab-34d4-4f08-a8f2-70d99e9fd9d2
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (06/19/2017 01:21:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: tdsskiller (1).exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000409
Fehleroffset: 0xae2ca030
ID des fehlerhaften Prozesses: 0x26b0
Startzeit der fehlerhaften Anwendung: 0x01d2e889a189150a
Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Downloads\tdsskiller (1).exe
Pfad des fehlerhaften Moduls: unknown
Berichtskennung: 447b1cbb-e56f-4c39-824c-f12ca2c57e09
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (06/19/2017 01:18:40 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: tdsskiller.exe, Version: 3.1.0.15, Zeitstempel: 0x566b123a
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000409
Fehleroffset: 0xae2ca030
ID des fehlerhaften Prozesses: 0x1f94
Startzeit der fehlerhaften Anwendung: 0x01d2e88938948a87
Pfad der fehlerhaften Anwendung: C:\Users\BrainWasheD\Downloads\tdsskiller.exe
Pfad des fehlerhaften Moduls: unknown
Berichtskennung: ddedb9af-99dd-491f-85de-35329c0bfae1
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (06/18/2017 11:31:38 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/18/2017 11:22:41 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Fehler in Manifest- oder Richtliniendatei "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" in Zeile 1.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (06/18/2017 10:51:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb
Name des fehlerhaften Moduls: LCore.exe, Version: 8.92.67.0, Zeitstempel: 0x58e574bb
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000006369f2
ID des fehlerhaften Prozesses: 0x650
Startzeit der fehlerhaften Anwendung: 0x01d2e87252f161d4
Pfad der fehlerhaften Anwendung: C:\Program Files\Logitech Gaming Software\LCore.exe
Pfad des fehlerhaften Moduls: C:\Program Files\Logitech Gaming Software\LCore.exe
Berichtskennung: d7cf5a99-5bea-4dd1-bf40-a2adac4d1fb2
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Systemfehler:
=============
Error: (06/19/2017 12:11:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "BitDefenderCOM" wurde aufgrund folgenden Fehlers nicht gestartet:
Das System kann die angegebene Datei nicht finden.
Error: (06/19/2017 12:11:29 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "HomeGroupListener" wurde mit dem folgenden dienstspezifischen Fehler beendet:
%%2147944153 = In der Endpunktzuordnung sind keine weiteren Endpunkte verfügbar.
Error: (06/19/2017 12:11:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet:
Die Anforderung wird nicht unterstützt.
Error: (06/18/2017 11:38:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "BitDefenderCOM" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/18/2017 11:31:23 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "HomeGroupListener" wurde mit dem folgenden dienstspezifischen Fehler beendet:
%%2147944153 = In der Endpunktzuordnung sind keine weiteren Endpunkte verfügbar.
Error: (06/18/2017 11:31:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "CldFlt" wurde aufgrund folgenden Fehlers nicht gestartet:
Die Anforderung wird nicht unterstützt.
Error: (06/18/2017 11:30:23 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (06/18/2017 11:30:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Steam Client Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/18/2017 11:30:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "NVIDIA NetworkService Container" wurde mit folgendem Fehler beendet:
Für einen allgemeinen Befehl wurde ein Ergebnis zurückgegeben, das auf einen Fehler hinweist.
Error: (06/18/2017 11:30:22 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Microsoft Office-Klick-und-Los-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
CodeIntegrity:
===================================
Date: 2017-06-18 22:36:46.693
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
Date: 2017-06-18 22:36:46.372
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
Date: 2017-06-18 22:36:46.197
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
Date: 2017-06-18 22:01:20.659
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
Date: 2017-06-18 22:01:20.652
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
Date: 2017-06-18 22:00:02.252
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
Date: 2017-06-18 22:00:02.244
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
Date: 2017-06-18 21:59:29.324
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
Date: 2017-06-18 21:59:29.317
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
Date: 2017-06-18 21:58:02.048
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
==================== Speicherinformationen ===========================
Prozessor: Intel(R) Core(TM) i7-2600K CPU @ 3.40GHz
Prozentuale Nutzung des RAM: 42%
Installierter physikalischer RAM: 8173.24 MB
Verfügbarer physikalischer RAM: 4715.89 MB
Summe virtueller Speicher: 16877.24 MB
Verfügbarer virtueller Speicher: 12610.84 MB
==================== Laufwerke ================================
Drive a: (Volume) (Fixed) (Total:223.57 GB) (Free:165.94 GB) NTFS
Drive c: () (Fixed) (Total:111.25 GB) (Free:70.25 GB) NTFS
Drive d: () (Fixed) (Total:488.06 GB) (Free:439.63 GB) NTFS
Drive e: (Volume) (Fixed) (Total:443.23 GB) (Free:403.34 GB) NTFS
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 1E55C42B)
Partition 1: (Not Active) - (Size=223.6 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: DBC5041D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
========================================================
Disk: 2 (Size: 931.5 GB) (Disk ID: C99F686A)
Partition: GPT.
==================== Ende von Addition.txt ============================ |