Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert?

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 06.12.2015, 22:06   #1
zeVra
 
Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert? - Beitrag

Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert?



Hallo Trojaner-Board! Ich hoffe ihr könnt mir bei meinem Problem helfen.
Seit einiger Zeit, ich bin mir nicht ganz sicher seit wann, hängen sich die Programme auf meinem PC ständig auf. Wirklich ständig. Selbst wenn ich nur einen Dateinamen auf dem Desktop ändere, hängt er sich auf; keine Rückmeldung. Dies passiert auch in anderen Programmen (Explorer, Adobe Premiere Pro CC 2015, Adobe Photoshop CC 2014, Firefox, etc.).
Dies war früher nicht so.

Danke im Voraus!
PC Specs: nVidia GeForce 650 2GB, 8GB Ram, AMD FX- 6300 Six Core Prozessor (3.5 GHZ)
Windows 10 Pro, 64 Bit
Habe meinen Nachnamen überall durch **** ersetzt!

Farbar Recovery Scan Tool FRST.txt
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-12-2015
durchgeführt von Nico (Administrator) auf NICO (06-12-2015 21:51:48)
Gestartet von C:\Users\Nico ****\Downloads
Geladene Profile: Nico (Verfügbare Profile: Nico)
Platform: Windows 10 Pro (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(American Megatrends Inc.) C:\Program Files\AMI\DuOS\AndServMgr.exe
() C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\47.0.2526.18\remoting_host.exe
() C:\Program Files (x86)\freeSSHd\FreeSSHDService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\47.0.2526.18\remoting_host.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Flux Software LLC) C:\Users\Nico ****\AppData\Local\FluxSoftware\Flux\flux.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.3.0.0\Lightshot.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DiscSoftBusService.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Microsoft Corporation) C:\Windows\System32\wimserv.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Program Files (x86)\Bethesda Studios\Fallout 4\Mod Manager\Fallout4ModManager.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\7badfbd5-1b99-4a1a-88f8-a4e455fb9de3.com


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8497368 2015-08-14] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520 2015-10-12] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-07-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2303152 2015-07-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2109952 2014-10-07] (Dominik Reichl)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [917112 2015-10-08] (BlueStack Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKLM\...\Policies\Explorer: [AllowLegacyWebView] 1
HKLM\...\Policies\Explorer: [AllowUnhashedWebView] 1
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8551848 2015-10-19] (Piriform Ltd)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [KeePass Password Safe 2] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2109952 2014-10-07] (Dominik Reichl)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [BitTorrent] => C:\Users\Nico ****\AppData\Roaming\BitTorrent\BitTorrent.exe [1977192 2015-10-17] (BitTorrent Inc.)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3761424 2014-11-10] (Disc Soft Ltd)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22790776 2015-11-04] (Google)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [48138880 2015-10-14] (Skype Technologies S.A.)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [f.lux] => C:\Users\Nico ****\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [MinerGateGui] => C:\Program Files\MinerGate\minergate.exe [16197632 2015-11-10] ()
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7935904 2015-12-02] (SUPERAntiSpyware)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\RunOnce: [Uninstall C:\Users\Nico ****\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Nico ****\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\RunOnce: [Uninstall C:\Users\Nico ****\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Nico ****\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Policies\Explorer: [NofolderOptions] 0
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000
IFEO\utilman.exe: [Debugger] cmd.exe
SSODL-x32: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} -  Keine Datei
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-07-22] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-07-22] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-07-22] ()
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  Keine Datei
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  Keine Datei
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  Keine Datei
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  Keine Datei
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  Keine Datei
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  Keine Datei
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  Keine Datei
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  Keine Datei
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2015-11-06]
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2015-11-06]
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2014-11-08]
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\chrome - Verknüpfung.lnk [2015-08-11]
ShortcutTarget: chrome - Verknüpfung.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Startup: C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EventGhost.lnk [2015-08-07]
ShortcutTarget: EventGhost.lnk -> C:\Program Files (x86)\EventGhost\EventGhost.exe (EventGhost Project)
BootExecute: autocheck autochk * SmartDefragBootTime.exe
CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{4bc30ba3-ec84-4364-8edf-d69cb2e1bb61}: [NameServer] 192.168.2.1
Tcpip\..\Interfaces\{4bc30ba3-ec84-4364-8edf-d69cb2e1bb61}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{74966d45-470b-4b0f-b3db-885a0046fb25}: [DhcpNameServer] 8.8.8.8

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://de.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
SearchScopes: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/search?q={SearchTerms}&fr=ntg
SearchScopes: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = 
SearchScopes: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001 -> {F90EF9FE-D59B-44BB-8929-A440EE26CC05} URL = hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
SearchScopes: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/search?q={SearchTerms}&fr=ntg
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-10-20] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-11-02] (Oracle Corporation)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-11-06] (LastPass)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-02] (Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-10-20] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-11-02] (Oracle Corporation)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-11-06] (LastPass)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-13] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-02] (Oracle Corporation)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-11-06] (LastPass)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-11-06] (LastPass)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-11] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-02] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-02] (Oracle Corporation)
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-11-06] (LastPass)
FF Plugin: @unity3d.com/UnityPlayer64,version=1.0 -> C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll [2015-02-18] (Unity Technologies ApS)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2013-11-12] (VideoLAN)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-07-23] (Adobe Systems)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC)
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-02] (Oracle Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-11-06] (LastPass)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-01-10] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-11-14] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-11-14] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [Keine Datei]
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Nico ****\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2014-03-10] (Raidcall)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-07-23] (Adobe Systems)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin HKU\S-1-5-21-2171699750-2845458332-3438301781-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Nico ****\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-08] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2171699750-2845458332-3438301781-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [Keine Datei]
FF Plugin HKU\S-1-5-21-2171699750-2845458332-3438301781-1001: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-01-31] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-01-31] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-01-31] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-01-31] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-01-31] (Apple Inc.)
FF SearchPlugin: C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\searchplugins\youtube-videosuche.xml [2015-10-03]
FF Extension: Modify Headers - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}.xpi [2015-11-06]
FF Extension: Greasemonkey - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2015-11-30]
FF Extension: LastPass - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\extensions\support@lastpass.com [2015-12-03]
FF Extension: Fox To Phone - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\extensions\sendtophone@martinezdelizarrondo.com.xpi [2015-12-05]
FF Extension: Kein Name - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\firefox@betterttv.net.xpi [2015-10-18] [ist nicht signiert]
FF Extension: YouTube mp3 - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\info@youtube-mp3.org.xpi [2015-09-26]
FF Extension: Kein Name - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\MediaSniffer@hiyoko.info.xpi [2015-12-05] [ist nicht signiert]
FF Extension: YouTube Unblocker - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\youtubeunblocker@unblocker.yt [2015-12-03]
FF Extension: ZIPUpdaterFree - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\{45a2694b-7a8d-4e31-aaab-81087fdf2756}.xpi [2015-12-05] [ist nicht signiert]
FF Extension: Video DownloadHelper - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-10-30]
FF Extension: Adblock Plus - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-25]
FF Extension: HTML5 Extension - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\{eeba6b96-d5c8-4dd8-8ff7-105b1bbb45c2}.xpi [2015-12-01] [ist nicht signiert]

Chrome: 
=======
CHR NewTab: Default -> "chrome-extension://bhloflhklmhfpedakmangadcdofhnnoh/index.html"
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR DefaultSuggestURL: Default -> hxxps://de.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Profile: C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Heartbeat) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aailiojlhjbichheofhdpcongebcgcgm [2015-12-05]
CHR Extension: (Google Präsentationen) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-20]
CHR Extension: (Google Docs) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-21]
CHR Extension: (Google Drive) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (Earth View from Google Earth) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhloflhklmhfpedakmangadcdofhnnoh [2015-12-05]
CHR Extension: (YouTube) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Adblock Plus) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-11-29]
CHR Extension: (Google-Suche) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Tampermonkey) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2015-11-29]
CHR Extension: (ARC Welder) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\emfinbmielocnlhgmfkkmkngdoccbadn [2015-12-06]
CHR Extension: (Google Tabellen) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-20]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2015-11-05]
CHR Extension: (Google Docs Offline) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-29]
CHR Extension: (AutoRemote) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\hglmpnnkhfjpnoheioijdpleijlmfcfb [2015-11-29]
CHR Extension: (Google Notizen – Notizen & Listen) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2015-11-29]
CHR Extension: (VideoHunter+) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpiikdgdgibmpnfhkopjaamphpmdgfhm [2015-09-10]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2015-09-01]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2015-08-20]
CHR Extension: (Tampermonkey) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfaihdlpglflfgpfjcifdjdjcckigekc [2015-12-06]
CHR Extension: (Keepa - Amazon Price Tracker) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\neebplgakaahbhdphmkckjjcegoiijjo [2015-11-29]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-20]
CHR Extension: (Google Chrome to Phone Extension) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco [2015-12-05]
CHR Extension: (Google Mail) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-21]
CHR Extension: (__MSG_extName__) - C:\Users\Nico ****\Documents\ARCWELDER\Hack%20Ex%20-%20Simulator_1.1.4_apk-dl.com.apk_export_oUBJK [2015-10-26]
CHR Extension: (__MSG_extName__) - C:\Users\Nico ****\Documents\ARCWELDER\Hack%20Ex%20-%20Simulator_1.1.4_apk-dl.com.apk_export_oUBJK [2015-10-26]
CHR Extension: (__MSG_extName__) - C:\Users\Nico ****\Documents\ARCWELDER\Hack%20Ex%20-%20Simulator_1.1.4_apk-dl.com.apk_export_wUfLB [2015-10-26]
CHR Extension: (__MSG_extName__) - C:\Users\Nico ****\Documents\ARCWELDER\Hack%20Ex%20-%20Simulator_1.1.4_apk-dl.com.apk_export_wUfLB [2015-10-26]
CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [njabjmhinndphfnbjehdalkphpdmepli] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [npdicihegicnhaangkdmcgbjceoemeoo] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 AndServMgr; C:\Program Files\AMI\DuOS\AndServMgr.exe [82384 2015-08-06] (American Megatrends Inc.)
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [437880 2015-10-08] (BlueStack Systems, Inc.)
S2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [417400 2015-10-08] (BlueStack Systems, Inc.)
S2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [855672 2015-10-08] (BlueStack Systems, Inc.)
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\47.0.2526.18\remoting_host.exe [69448 2015-10-14] (Google Inc.)
R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [216576 2014-11-25] () [Datei ist nicht signiert]
R3 Disc Soft Bus Service; C:\Program Files (x86)\DAEMON Tools Pro\DiscSoftBusService.exe [2216208 2014-11-10] (Disc Soft Ltd)
S2 Droid4XService; C:\Program Files (x86)\Droid4X\Droid4XService.exe [261864 2015-06-03] () [Datei ist nicht signiert]
S2 Ds3Service; C:\Program Files\Scarlet.Crush Productions\bin\ScpService.exe [388352 2013-05-05] (Scarlet.Crush Productions)
R2 FreeSSHDService; C:\Program Files (x86)\freeSSHd\FreeSSHDService.exe [1513072 2015-02-02] ()
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384 2015-10-12] (NVIDIA Corporation)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-08-07] (IObit)
S2 Mobizen plugin; C:\Program Files (x86)\RSUPPORT\MobizenService\MobizenService.exe [3353360 2015-08-14] ( Rsupport Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696 2015-10-12] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568288 2015-10-12] (NVIDIA Corporation)
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [24576 2013-11-03] (The OpenVPN Project) [Datei ist nicht signiert]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-08] (Electronic Arts)
S2 Remotr Service; C:\Program Files (x86)\Remotr\RemotrService.exe [181328 2015-11-16] (RemoteMyApp sp. z o.o.)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [242936 2015-11-06] (RaMMicHaeL)
S2 UnsignedThemes; C:\Windows\unsignedthemes.exe [13824 2013-09-23] (The Within Network, LLC) [Datei ist nicht signiert]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [672024 2015-02-26] (Wacom Technology, Corp.)

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [11944 2015-05-24] (Advanced Micro Devices Inc.)
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2015-09-01] (Google Inc)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [146040 2015-10-08] (BlueStack Systems)
S3 cxbu0x64; C:\Windows\system32\DRIVERS\cxbu0x64.sys [147576 2015-09-05] (HID Global Corporation)
S3 dtscsibus; C:\Windows\system32\DRIVERS\dtscsibus.sys [29864 2015-06-04] (Disc Soft Ltd)
R1 DuoVMDrv; C:\Windows\system32\DRIVERS\DuoVMDrv.sys [239536 2015-07-31] (American Megatrends Inc.)
S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [44296 2015-03-30] (LogMeIn Inc.)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-05-24] (REALiX(tm))
S3 LcUvcUpper; C:\Windows\system32\DRIVERS\LcUvcUpper.sys [34408 2013-09-27] (Microsoft Corporation)
R3 ManyCam; C:\Windows\system32\DRIVERS\mcvidrv_x64.sys [34304 2012-01-11] (ManyCam LLC)
R3 mcaudrv_simple; C:\Windows\system32\drivers\mcaudrv_x64.sys [28160 2012-02-22] (ManyCam LLC)
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] ()
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20768 2015-10-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
S3 qcusbser; C:\Windows\system32\DRIVERS\qcusbser.sys [242688 2015-08-14] (QUALCOMM Incorporated)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek                                            )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-05] (Scarlet.Crush Productions)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S2 uxstyle; C:\Windows\system32\Drivers\uxstyle.sys [31440 2013-09-23] (The Within Network, LLC)
R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-10-15] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [146584 2015-10-15] (Oracle Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 pxldqpod; C:\Users\Nico ****\AppData\Local\Temp\pxldqpod.sys [56496 2015-12-06] (GMER) [Datei ist nicht signiert]
S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-12-06 21:51 - 2015-12-06 21:52 - 00036961 _____ C:\Users\Nico ****\Downloads\FRST.txt
2015-12-06 21:47 - 2015-12-06 21:51 - 00000000 ____D C:\FRST
2015-12-06 21:47 - 2015-12-06 21:47 - 02369024 _____ (Farbar) C:\Users\Nico ****\Downloads\FRST64.exe
2015-12-06 21:34 - 2015-12-06 21:34 - 00380416 _____ C:\Users\Nico ****\Downloads\Gmer-19357.exe
2015-12-06 21:34 - 2015-12-06 21:34 - 00050477 _____ C:\Users\Nico ****\Downloads\Defogger.exe
2015-12-06 21:04 - 2015-12-06 21:04 - 00016148 _____ C:\WINDOWS\system32\NICO_Nico_HistoryPrediction.bin
2015-12-06 18:52 - 2015-12-06 18:52 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\SUPERAntiSpyware.com
2015-12-06 18:51 - 2015-12-06 21:31 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-12-06 18:51 - 2015-12-06 18:51 - 00001849 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-12-06 18:51 - 2015-12-06 18:51 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2015-12-06 18:51 - 2015-12-06 18:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-12-06 18:49 - 2015-12-06 18:50 - 24088304 _____ (SUPERAntiSpyware) C:\Users\Nico ****\Downloads\SUPERAntiSpyware.exe
2015-12-06 18:14 - 2015-12-06 18:14 - 00000000 _____ C:\Users\Nico ****\Desktop\Telegraph.apk
2015-12-06 18:09 - 2015-12-06 18:21 - 00000000 ____D C:\Users\Nico ****\Desktop\Zeitungen
2015-12-06 16:11 - 2015-12-06 16:11 - 00011793 _____ C:\Users\Nico ****\Downloads\ic_directions_bike_black_24dp.zip
2015-12-06 16:05 - 2015-12-06 16:05 - 00007253 _____ C:\Users\Nico ****\Downloads\ic_announcement_black_24dp.zip
2015-12-06 13:28 - 2015-12-06 13:28 - 00000000 ____D C:\Users\Nico ****\AppData\Local\minergate
2015-12-06 13:28 - 2015-12-06 13:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MinerGate
2015-12-06 13:28 - 2015-12-06 13:28 - 00000000 ____D C:\Program Files\MinerGate
2015-12-06 13:22 - 2015-12-06 13:22 - 10782967 _____ C:\Users\Nico ****\Downloads\MinerGate-5.06-win64.exe
2015-12-06 11:38 - 2015-12-06 11:38 - 00011226 _____ C:\Users\Nico ****\Downloads\ic_whatshot_black_24dp.zip
2015-12-05 23:31 - 2015-12-05 23:31 - 00023040 _____ () C:\Users\Nico ****\Desktop\FO4FaceRipper.exe
2015-12-05 23:31 - 2015-12-05 23:31 - 00008771 _____ C:\Users\Nico ****\Downloads\Save Face Ripper-3878-7.7z
2015-12-05 23:29 - 2015-12-05 23:40 - 00000000 ____D C:\Users\Nico ****\Desktop\BIGBOSS éu2.0
2015-12-05 22:29 - 2015-12-05 22:29 - 05401798 _____ C:\Users\Nico ****\Downloads\Skyrim Audio Converter 1_0_2-8303-1-0-2.7z
2015-12-05 19:16 - 2015-12-05 19:16 - 00000022 _____ C:\WINDOWS\S.dirmngr
2015-12-05 17:09 - 2015-12-05 17:09 - 02903735 _____ C:\Users\Nico ****\Downloads\BIGBOSS V2.0-4118-2-0.zip
2015-12-05 15:44 - 2015-12-05 15:44 - 00011536 _____ C:\Users\Nico ****\Downloads\ic_stars_black_24dp.zip
2015-12-05 15:31 - 2015-12-05 15:31 - 00006824 _____ C:\Users\Nico ****\Downloads\ic_movie_black_24dp.zip
2015-12-05 15:27 - 2015-12-05 15:27 - 00009653 _____ C:\Users\Nico ****\Downloads\ic_local_mall_black_24dp.zip
2015-12-05 15:23 - 2015-12-05 15:23 - 02615253 _____ C:\Users\Nico ****\Downloads\9396-44434-1-PB.pdf
2015-12-05 15:22 - 2015-12-05 15:22 - 02192671 _____ C:\Users\Nico ****\Downloads\Fallout4Translator-215-0-8.zip
2015-12-05 15:06 - 2015-12-05 15:06 - 00007935 _____ C:\Users\Nico ****\Downloads\ic_video_library_black_24dp.zip
2015-12-05 14:52 - 2015-12-05 14:53 - 00006575 _____ C:\Users\Nico ****\Downloads\ic_games_black_24dp.zip
2015-12-05 14:43 - 2015-12-05 14:43 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-12-05 14:43 - 2015-12-05 14:43 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2015-12-05 14:34 - 2015-12-05 14:34 - 41904448 _____ (Apple Inc.) C:\Users\Nico ****\Downloads\QuickTimeInstaller.exe
2015-12-05 11:56 - 2015-12-05 11:56 - 01240761 _____ C:\Users\Nico ****\Downloads\Longer Distance PipBoy and Spotlights (With Optional PipBoyShadows)-1790--5.rar
2015-12-04 23:54 - 2015-12-04 23:54 - 00096140 _____ C:\Users\Nico ****\Downloads\special-elite.zip
2015-12-04 23:52 - 2015-12-04 23:52 - 00075028 _____ C:\Users\Nico ****\Downloads\kingthings_trypewriter.zip
2015-12-04 23:21 - 2015-12-04 23:21 - 00007136 _____ C:\Users\Nico ****\Downloads\Save Face Ripper-3878-6.7z
2015-12-04 23:09 - 2015-12-04 23:09 - 01392248 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-1-7-222.zip
2015-12-04 23:08 - 2015-11-13 14:54 - 03431117 _____ C:\Users\Nico ****\Desktop\Save3_1A910BF0_57616C746572_Vault111Cryo_000049_20151113135408_1_2.fos
2015-12-04 23:05 - 2015-12-04 23:05 - 01193192 _____ C:\Users\Nico ****\Downloads\W.W. Heisenberg-348-1-1.rar
2015-12-04 20:29 - 2015-12-04 20:30 - 01143808 _____ (PainteR) C:\Users\Nico ****\Downloads\adobe.snr.patch-painter.exe
2015-12-04 20:14 - 2015-12-04 20:14 - 00201085 _____ C:\Users\Nico ****\Downloads\my_underwood.zip
2015-12-04 20:13 - 2015-12-04 20:13 - 00033086 _____ C:\Users\Nico ****\Downloads\remingtoned_type.zip
2015-12-04 20:07 - 2015-12-04 20:07 - 00989291 _____ C:\Users\Nico ****\Downloads\traveling_typewriter(1).zip
2015-12-04 20:00 - 2015-12-04 20:00 - 00029241 _____ C:\Users\Nico ****\Downloads\Slabo_27px.zip
2015-12-04 14:48 - 2015-12-04 14:48 - 00008219 _____ C:\Users\Nico ****\Downloads\ic_thumb_down_black_24dp.zip
2015-12-04 14:48 - 2015-12-04 14:48 - 00008094 _____ C:\Users\Nico ****\Downloads\ic_thumb_up_black_24dp.zip
2015-12-04 14:26 - 2015-12-04 14:26 - 01075821 _____ C:\Users\Nico ****\Downloads\Roboto(1).zip
2015-12-04 14:23 - 2015-12-04 14:23 - 01379427 _____ C:\Users\Nico ****\Downloads\roboto.zip
2015-12-04 14:04 - 2015-12-06 18:53 - 00000000 ____D C:\Users\Nico ****\Desktop\Krasse Zeitung
2015-12-03 15:45 - 2015-12-03 15:45 - 00002541 _____ C:\Users\Nico ****\Downloads\Fallout 4 Place in Red v1.7.zip-1267-1-7.zip
2015-12-03 15:45 - 2015-11-23 01:50 - 00017654 _____ C:\Users\Nico ****\Desktop\Fallout 4 Place in Red v1.7.ct
2015-12-03 14:12 - 2015-12-06 14:31 - 00000000 ____D C:\WINDOWS\Panther
2015-12-02 22:09 - 2015-12-02 22:09 - 01371366 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-1-5-2060.zip
2015-12-02 14:30 - 2015-12-02 14:30 - 00934931 _____ C:\Users\Nico ****\Downloads\Settlement Raid Mod 1.7-2995-1-7.zip
2015-12-01 19:02 - 2015-11-30 18:30 - 05621885 _____ C:\Users\Nico ****\Desktop\fo4facetransfer.exe
2015-12-01 19:00 - 2015-12-01 19:01 - 05560961 _____ C:\Users\Nico ****\Downloads\Fallout 4 Face Transfer-3597-0-1.zip
2015-11-30 21:03 - 2015-11-30 21:03 - 01671338 _____ C:\Users\Nico ****\Downloads\Gorgeous Vaultgirl (Vault Exit Version)-193-1-02.zip
2015-11-30 20:52 - 2015-11-30 20:52 - 01666048 _____ (WJ&AF Company) C:\Users\Nico ****\Desktop\F4SGE.exe
2015-11-30 20:50 - 2015-11-30 20:50 - 01355166 _____ C:\Users\Nico ****\Downloads\Gorgeous Vaultgirl-193-1-01(1).zip
2015-11-30 20:50 - 2015-11-30 20:50 - 01301129 _____ C:\Users\Nico ****\Downloads\F4SGE.0v1b6-838-alfa.7z
2015-11-30 19:31 - 2015-11-30 19:31 - 03081746 _____ C:\Users\Nico ****\Downloads\AutoHotkey112209_Install.exe
2015-11-30 19:31 - 2015-11-30 19:31 - 01358686 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-1-3-1793.zip
2015-11-30 19:17 - 2015-11-30 19:18 - 02190640 _____ C:\Users\Nico ****\Downloads\Fallout4Translator-215-0-7b.zip
2015-11-30 15:48 - 2015-11-30 15:50 - 01355166 _____ C:\Users\Nico ****\Downloads\Gorgeous Vaultgirl-193-1-01.zip
2015-11-29 18:00 - 2015-11-29 18:02 - 00000017 _____ C:\Users\Nico ****\Desktop\Telegraph (.apk
2015-11-29 10:42 - 2015-11-29 10:42 - 01482475 _____ C:\Users\Nico ****\Downloads\Fallout 4 Mod Manager-495-1-0-30(1).zip
2015-11-28 15:36 - 2015-11-28 15:36 - 01919162 _____ C:\Users\Nico ****\Downloads\Fallout4_EnglishSTRINGS-215-0-1.7z
2015-11-28 15:16 - 2015-11-28 15:16 - 15422436 _____ C:\Users\Nico ****\Downloads\Fallout4_STRINGS_Misc-215-0-1.7z
2015-11-28 14:59 - 2015-11-28 14:59 - 02732887 _____ C:\Users\Nico ****\Downloads\FO4Edit 3.1.3-2737-EXP.7z
2015-11-28 14:57 - 2015-11-30 14:19 - 00000000 ____D C:\Users\Nico ****\Desktop\FO4Edit
2015-11-27 22:02 - 2015-11-27 22:02 - 00031097 _____ C:\Users\Nico ****\Downloads\Who Are You v1.2-2377-1-2.7z
2015-11-27 21:27 - 2015-11-27 21:27 - 02722183 _____ C:\Users\Nico ****\Downloads\TES5Edit_211115a.7z
2015-11-27 21:20 - 2015-11-27 21:20 - 00309595 _____ C:\Users\Nico ****\Downloads\Settler Renaming-2017-1-7-2.zip
2015-11-26 14:28 - 2015-11-26 14:28 - 00000000 ____D C:\Users\Nico ****\AppData\Local\ElevatedDiagnostics
2015-11-26 14:01 - 2015-11-26 14:03 - 01482475 _____ C:\Users\Nico ****\Downloads\Fallout 4 Mod Manager-495-1-0-30.zip
2015-11-25 17:13 - 2015-11-25 17:13 - 02189078 _____ C:\Users\Nico ****\Downloads\Fallout4Translator-215-0-7a.zip
2015-11-25 14:26 - 2015-11-25 14:28 - 54666380 _____ C:\Users\Nico ****\Downloads\EBT v007-212-0-07.7z
2015-11-24 20:32 - 2015-11-24 20:33 - 01478096 _____ C:\Users\Nico ****\Downloads\Fallout 4 Mod Manager-495-1-0-27.zip
2015-11-24 19:16 - 2015-11-24 19:17 - 01229444 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-1-1-180.zip
2015-11-24 19:13 - 2015-11-10 20:11 - 63446952 _____ C:\Users\Nico ****\Desktop\setup-1.bin
2015-11-24 19:13 - 2015-11-10 20:11 - 03672661 _____ ( ) C:\Users\Nico ****\Desktop\setup.exe
2015-11-24 18:39 - 2015-11-24 18:39 - 00192475 _____ C:\Users\Nico ****\Downloads\f4se_0_01_01.7z
2015-11-24 18:34 - 2015-11-24 18:34 - 01478075 _____ C:\Users\Nico ****\Downloads\Fallout 4 Mod Manager-495-1-0-26.zip
2015-11-23 22:28 - 2015-11-23 22:28 - 00026079 _____ C:\Users\Nico ****\Downloads\glowingbobbleheads-1888-1-0.zip
2015-11-23 22:23 - 2015-11-23 22:24 - 00024354 _____ C:\Users\Nico ****\Downloads\Settlement Supplies Expanded-1145-1-92.rar
2015-11-23 19:38 - 2015-11-23 19:38 - 00000421 _____ C:\Users\Nico ****\Downloads\Faster Terminal Displays (5x) FO4Edit Version-937-2-0.zip
2015-11-23 14:30 - 2015-11-23 14:30 - 01130794 _____ C:\Users\Nico ****\Downloads\Black Gasmask-567-0-1.rar
2015-11-23 14:27 - 2015-11-23 14:27 - 00001457 _____ C:\Users\Nico ****\Downloads\VOT - Increased VATS Range-2173-1-0.zip
2015-11-23 14:20 - 2015-11-23 14:20 - 00022919 _____ C:\Users\Nico ****\Downloads\More Armor Slots 1.2.3 German Translation-745-1-2-3.zip
2015-11-23 14:10 - 2015-11-23 14:11 - 00720598 _____ C:\Users\Nico ****\Downloads\Improved Map with Visible Roads - Darker Version-1215-1-1.zip
2015-11-22 17:35 - 2015-11-22 17:35 - 00002696 _____ C:\Users\Nico ****\Downloads\Summon Companions v0.1-1096-0-1.rar
2015-11-22 11:07 - 2015-11-22 11:07 - 00001006 _____ C:\Users\Nico ****\Downloads\Main file-1951-1-0.7z
2015-11-21 22:51 - 2015-11-21 22:51 - 02187907 _____ C:\Users\Nico ****\Downloads\Fallout4Translator-215-0-5b.zip
2015-11-21 22:39 - 2015-11-21 22:39 - 01526040 _____ C:\Users\Nico ****\Downloads\1k - bottles label overhaul v0.3-1500-0-3.zip
2015-11-21 22:38 - 2015-11-21 22:38 - 00083626 _____ C:\Users\Nico ****\Downloads\ETSGlowingMagsNMMVersion-1728-1-0.zip
2015-11-21 22:34 - 2015-11-21 22:34 - 00657334 _____ C:\Users\Nico ****\Downloads\Better Inventory (German)-1074-1-0.zip
2015-11-21 22:27 - 2015-11-21 22:27 - 00000510 _____ C:\Users\Nico ****\Downloads\Higher Settlement Budget v1.2-818-1-2.7z
2015-11-21 22:22 - 2015-11-21 22:22 - 00028527 _____ C:\Users\Nico ****\Downloads\Settlement Supplies Expanded-1145-1-8.rar
2015-11-21 22:18 - 2015-11-21 22:18 - 06191014 _____ C:\Users\Nico ****\Downloads\(Deutsche) Full Dialogue Interface - German translation-1235-Beta3.zip
2015-11-21 22:04 - 2015-11-21 22:04 - 00178402 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-853151c225ffcfb605973844082e6efc.pdf
2015-11-21 22:04 - 2015-11-21 22:04 - 00178402 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-853151c225ffcfb605973844082e6efc(1).pdf
2015-11-21 22:03 - 2015-11-21 22:03 - 00150742 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-03cfe7ca141459de7d8a9eb67760132a.pdf
2015-11-21 22:03 - 2015-11-21 22:03 - 00150742 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-03cfe7ca141459de7d8a9eb67760132a(5).pdf
2015-11-21 22:03 - 2015-11-21 22:03 - 00150742 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-03cfe7ca141459de7d8a9eb67760132a(3).pdf
2015-11-21 22:03 - 2015-11-21 22:03 - 00150742 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-03cfe7ca141459de7d8a9eb67760132a(2).pdf
2015-11-21 21:58 - 2015-11-21 21:59 - 00153214 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-283258d897f1fbd53b403ad53727dbbd.pdf
2015-11-20 19:02 - 2015-11-20 19:02 - 00002210 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2015-11-20 19:02 - 2015-11-14 07:12 - 00102520 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2015-11-20 19:01 - 2015-11-20 19:02 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2015-11-20 19:00 - 2015-11-16 04:54 - 42913912 _____ C:\WINDOWS\system32\nvcompiler.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 37881976 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 22345848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 18390832 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 16561320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 15839200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 14844112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 13533608 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 12040952 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 02876536 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 02496632 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 01905456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435900.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 01564792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435900.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 01016544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00877688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00861816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00823232 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00689784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00674096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00539464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00503416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00501056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00446584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00445400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00422752 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00413816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00369456 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00177600 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00155792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00151184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00039240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2015-11-19 19:15 - 2015-11-19 19:15 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Fallout4ModManager
2015-11-17 18:38 - 2015-11-17 18:38 - 00001533 _____ C:\Users\Nico ****\Downloads\Default Carry Weight-214-1-4.rar
2015-11-17 18:38 - 2015-11-12 03:26 - 00000140 _____ C:\Users\Nico ****\Desktop\CarryWeight500.esp
2015-11-17 18:34 - 2015-11-17 18:36 - 00630571 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-0-4-3351.zip
2015-11-16 17:10 - 2015-11-16 17:10 - 05577782 _____ C:\Users\Nico ****\Downloads\Updated High res pre-war money re-texture-309-2(1).zip
2015-11-16 16:19 - 2015-11-16 16:19 - 04680510 _____ C:\Users\Nico ****\Downloads\Jesters Ammo Retex Fixed-345-2-0.rar
2015-11-16 08:31 - 2015-11-16 08:31 - 00003972 _____ C:\Users\Nico ****\Downloads\Configurable Fusion Core Drain 1.5-325-1-5(1).zip
2015-11-15 23:37 - 2015-11-15 23:37 - 00318938 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-0-3-3050(1).7z
2015-11-15 23:32 - 2015-11-24 19:17 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Bilago
2015-11-15 23:31 - 2015-11-15 23:31 - 00318938 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-0-3-3050.7z
2015-11-15 21:32 - 2015-11-15 21:32 - 05577782 _____ C:\Users\Nico ****\Downloads\Updated High res pre-war money re-texture-309-2.zip
2015-11-15 21:28 - 2015-11-13 02:54 - 00000614 _____ C:\Users\Nico ****\Desktop\50% Fusion Core Drain.esp
2015-11-15 14:35 - 2015-11-15 14:36 - 38734984 _____ C:\Users\Nico ****\Downloads\FTO Pip-Boy 2K-449-1-0.rar
2015-11-15 14:35 - 2015-11-15 14:35 - 00003972 _____ C:\Users\Nico ****\Downloads\Configurable Fusion Core Drain 1.5-325-1-5.zip
2015-11-15 10:54 - 2015-11-15 10:54 - 00003864 _____ C:\Users\Nico ****\Downloads\ENBoost 0.281-332-281.zip
2015-11-15 10:51 - 2015-11-19 19:15 - 00000155 _____ C:\Users\Nico ****\Desktop\modorder.txt
2015-11-15 10:50 - 2015-11-15 10:50 - 00000000 ____D C:\Users\Nico ****\AppData\Local\FO4_PluginsManager
2015-11-15 10:49 - 2015-11-15 10:49 - 00183634 _____ C:\Users\Nico ****\Downloads\Plugins Manager 1.2-487-1-2.zip
2015-11-15 10:45 - 2015-11-15 10:45 - 00000996 _____ C:\Users\Nico ****\Downloads\Bonus Carry Weight-214-1-2.rar
2015-11-15 10:41 - 2015-11-15 10:41 - 15830769 _____ C:\Users\Nico ****\Downloads\EBT v002-212-0-02.7z
2015-11-14 22:54 - 2015-11-28 15:04 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Fallout4
2015-11-14 21:47 - 2015-11-14 21:50 - 00000000 ____D C:\WINDOWS\SysWOW64\directx
2015-11-14 21:46 - 2015-11-14 21:46 - 00001036 _____ C:\Users\Public\Desktop\Play Fallout 4.lnk
2015-11-14 21:46 - 2015-11-14 21:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bethesda Studios
2015-11-14 20:57 - 2015-11-14 20:57 - 00000000 ____D C:\Program Files (x86)\Bethesda Studios
2015-11-13 17:00 - 2015-12-04 20:10 - 00000000 ____D C:\Users\Nico ****\Desktop\LeoDaBOSS
2015-11-13 16:59 - 2015-11-13 16:59 - 00000000 ____D C:\Users\Nico ****\Downloads\Leo Da VInci
2015-11-13 16:45 - 2015-11-14 23:56 - 00000355 _____ C:\Users\Nico ****\Desktop\Neues Textdokument (6).txt
2015-11-12 19:06 - 2015-11-12 19:06 - 512522753 _____ C:\Users\Nico ****\Downloads\IGG-The.Escapists.The.Walking.Dead.rar
2015-11-11 19:44 - 2015-11-11 19:44 - 00000000 ____D C:\Users\Nico ****\AppData\LocalLow\BitTorrent
2015-11-11 19:42 - 2015-11-12 18:29 - 00000000 ____D C:\Users\Nico ****\Documents\The Escapists
2015-11-11 19:40 - 2015-11-03 22:12 - 00000000 ____D C:\Users\Nico ****\Desktop\IGG-The.Escapists.v1.23.Incl.4.DLCs
2015-11-11 19:36 - 2015-11-11 19:36 - 93030375 _____ C:\Users\Nico ****\Downloads\IGG-The.Escapists.v1.23.Incl.4.DLCs.rar
2015-11-11 16:52 - 2015-11-05 06:15 - 08020832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-11-11 16:52 - 2015-11-05 06:15 - 00541024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-11-11 16:52 - 2015-11-05 06:14 - 00459104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2015-11-11 16:52 - 2015-11-05 06:13 - 00577888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2015-11-11 16:52 - 2015-11-05 06:11 - 01392480 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-11-11 16:52 - 2015-11-05 06:06 - 03621248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-11-11 16:52 - 2015-11-05 06:06 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-11-11 16:52 - 2015-11-05 06:01 - 00607408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-11-11 16:52 - 2015-11-05 05:56 - 01083072 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-11-11 16:52 - 2015-11-05 05:56 - 00116064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2015-11-11 16:52 - 2015-11-05 05:56 - 00025280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-11-11 16:52 - 2015-11-05 05:30 - 00961376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-11-11 16:52 - 2015-11-05 05:24 - 02878512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-11-11 16:52 - 2015-11-05 05:23 - 00762888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-11-11 16:52 - 2015-11-05 05:23 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2015-11-11 16:52 - 2015-11-05 05:20 - 21873664 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-11-11 16:52 - 2015-11-05 05:18 - 24597504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-11-11 16:52 - 2015-11-05 05:18 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-11-11 16:52 - 2015-11-05 05:18 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-11-11 16:52 - 2015-11-05 05:17 - 02418688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-11-11 16:52 - 2015-11-05 05:12 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
2015-11-11 16:52 - 2015-11-05 05:11 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-11-11 16:52 - 2015-11-05 05:10 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-11-11 16:52 - 2015-11-05 05:10 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-11-11 16:52 - 2015-11-05 05:07 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-11 16:52 - 2015-11-05 05:06 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-11-11 16:52 - 2015-11-05 05:05 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-11-11 16:52 - 2015-11-05 05:05 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-11-11 16:52 - 2015-11-05 05:03 - 02180608 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-11-11 16:52 - 2015-11-05 05:03 - 01015808 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-11-11 16:52 - 2015-11-05 05:01 - 00949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-11-11 16:52 - 2015-11-05 05:01 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-11-11 16:52 - 2015-11-05 05:01 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-11-11 16:52 - 2015-11-05 04:59 - 03587072 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-11-11 16:52 - 2015-11-05 04:59 - 02675200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2015-11-11 16:52 - 2015-11-05 04:58 - 01383936 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-11-11 16:52 - 2015-11-05 04:58 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-11 16:52 - 2015-11-05 04:56 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-11-11 16:52 - 2015-11-05 04:55 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2015-11-11 16:52 - 2015-11-05 04:54 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2015-11-11 16:52 - 2015-11-05 04:47 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-11-11 16:52 - 2015-11-05 04:42 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-11-11 16:52 - 2015-11-05 04:40 - 01918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-11-11 16:52 - 2015-11-05 04:35 - 18803712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-11-11 16:52 - 2015-11-05 04:35 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-11-11 16:52 - 2015-11-05 04:34 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2015-11-11 16:52 - 2015-11-05 04:33 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-11-11 16:52 - 2015-11-05 04:33 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-11-11 16:52 - 2015-11-05 04:30 - 00767488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-11-11 16:52 - 2015-11-05 04:28 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-11-11 16:52 - 2015-11-05 04:27 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2015-11-11 16:52 - 2015-11-05 04:27 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-11-11 16:52 - 2015-11-05 04:23 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2015-11-08 20:25 - 2015-11-08 20:25 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Crisis_Point_Extinction
2015-11-08 16:20 - 2015-11-08 16:20 - 17164524 _____ C:\Users\Nico ****\Downloads\Crisis Point - v.13.zip
2015-11-08 16:20 - 2015-11-08 16:20 - 00000000 ____D C:\Users\Nico ****\Desktop\crisis point
2015-11-08 13:45 - 2015-11-08 13:45 - 00003930 _____ C:\Users\Nico ****\Desktop\500 50+ ID's.txt
2015-11-08 13:11 - 2015-11-08 13:46 - 00000113 _____ C:\Users\Nico ****\Desktop\8h Cascade.txt
2015-11-08 13:04 - 2015-11-08 13:04 - 00000660 _____ C:\Users\Nico ****\Desktop\accounts.txt
2015-11-07 18:33 - 2015-12-06 18:21 - 00000000 ____D C:\Users\Nico ****\Desktop\KAROÜBERRASCHUNG
2015-11-07 12:22 - 2015-11-07 12:27 - 223137808 _____ C:\Users\Nico ****\Downloads\Slim_mini_gapps.ALPHA.6.0.build.0.x-20151106.zip
2015-11-07 10:48 - 2015-11-07 10:48 - 06762072 _____ (Piriform Ltd) C:\Users\Nico ****\Downloads\ccsetup511.exe
2015-11-07 10:42 - 2015-11-07 10:42 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\LastPass
2015-11-06 22:49 - 2015-11-06 22:50 - 55334400 _____ C:\Users\Nico ****\Downloads\FontPack11009_XtdAlf_Lang.msi
2015-11-06 22:46 - 2015-11-06 22:46 - 03963591 _____ C:\Users\Nico ****\Downloads\Nico****.pdf
2015-11-06 22:40 - 2015-11-06 22:40 - 00001149 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
2015-11-06 22:40 - 2015-11-06 22:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2015-11-06 22:40 - 2015-10-15 15:49 - 00964928 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxDrv.sys
2015-11-06 22:40 - 2015-10-15 15:49 - 00138904 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxUSBMon.sys
2015-11-06 22:35 - 2015-11-06 22:38 - 117095112 _____ (Oracle Corporation) C:\Users\Nico ****\Downloads\VirtualBox-5.0.8-103449-Win.exe
2015-11-06 22:28 - 2015-11-06 22:45 - 571322368 _____ C:\Users\Nico ****\Downloads\xpsp3_5512.080413-2113_usa_x86fre_spcd.iso
2015-11-06 18:56 - 2015-12-06 20:41 - 00000000 ____D C:\Users\Nico ****\AppData\LocalLow\LastPass
2015-11-06 18:56 - 2015-11-06 18:56 - 00001158 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk
2015-11-06 18:56 - 2015-11-06 18:56 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
2015-11-06 18:56 - 2015-11-06 18:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastPass
2015-11-06 18:54 - 2015-11-06 18:55 - 20320792 _____ (LastPass) C:\Users\Nico ****\Downloads\lastpass_x64(1).exe

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-12-06 21:47 - 2015-07-10 10:05 - 00000000 ____D C:\Windows
2015-12-06 21:43 - 2014-06-08 15:00 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-12-06 21:08 - 2014-10-13 21:02 - 00000000 ____D C:\LazyPressing
2015-12-06 21:00 - 2014-08-08 18:04 - 00001128 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-06 20:52 - 2014-03-31 18:07 - 00000412 _____ C:\WINDOWS\Tasks\update-sys.job
2015-12-06 19:56 - 2014-03-31 18:07 - 00000412 _____ C:\WINDOWS\Tasks\update-S-1-5-21-2171699750-2845458332-3438301781-1001.job
2015-12-06 18:59 - 2014-01-15 01:01 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\Audacity
2015-12-06 18:41 - 2015-05-30 14:39 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-12-06 18:23 - 2014-01-11 18:49 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\OBS
2015-12-06 16:28 - 2015-08-16 13:41 - 00004150 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{482FA375-426E-4AE5-812B-617B25429D8D}
2015-12-06 15:42 - 2013-12-24 22:14 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\Skype
2015-12-06 14:23 - 2015-10-30 20:28 - 00000000 ___HD C:\$WINDOWS.~BT
2015-12-05 21:02 - 2015-08-19 22:08 - 00002252 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-05 19:17 - 2014-08-08 18:04 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-05 19:16 - 2015-11-05 21:14 - 00000000 _____ C:\hsrv.txt
2015-12-05 19:16 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-12-05 19:16 - 2013-11-29 00:25 - 00000000 ____D C:\ProgramData\NVIDIA
2015-12-05 19:15 - 2015-07-10 10:05 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2015-12-05 19:14 - 2014-10-04 19:11 - 00000000 ____D C:\Program Files (x86)\Steam
2015-12-05 18:58 - 2015-07-10 13:20 - 04344080 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-12-05 18:58 - 2013-11-29 21:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-12-05 14:43 - 2015-01-31 13:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-12-05 14:43 - 2014-03-23 12:53 - 00000000 ____D C:\ProgramData\Apple Computer
2015-12-05 14:43 - 2014-03-23 12:52 - 00000000 ____D C:\ProgramData\Apple
2015-12-05 14:43 - 2014-02-19 19:03 - 00000000 ____D C:\Program Files (x86)\QuickTime
2015-12-05 14:42 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-05 13:14 - 2014-08-16 14:38 - 00007593 _____ C:\Users\Nico ****\AppData\Local\Resmon.ResmonCfg
2015-12-05 00:55 - 2014-08-08 18:04 - 00004186 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-05 00:55 - 2014-08-08 18:04 - 00003954 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-04 20:42 - 2014-03-16 19:02 - 00000000 ____D C:\Users\Nico ****\Documents\Adobe
2015-12-04 15:44 - 2015-10-18 04:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-12-04 14:01 - 2015-07-10 12:04 - 00000000 ___HD C:\Program Files\WindowsApps
2015-12-03 20:43 - 2015-08-16 12:41 - 00000000 ____D C:\Users\Nico ****
2015-12-02 14:17 - 2013-11-29 21:45 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Adobe
2015-12-01 14:15 - 2015-05-24 08:23 - 00000000 ____D C:\ProgramData\ProductData
2015-11-29 17:40 - 2014-03-27 19:36 - 00000000 ____D C:\Users\Nico ****\AppData\Local\fabi.me
2015-11-26 13:58 - 2015-08-09 22:14 - 00000000 ___RD C:\Users\Nico ****\Google Drive
2015-11-26 13:57 - 2015-08-09 22:12 - 00002115 _____ C:\Users\Public\Desktop\Google Slides.lnk
2015-11-26 13:57 - 2015-08-09 22:12 - 00002113 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2015-11-26 13:57 - 2015-08-09 22:12 - 00002103 _____ C:\Users\Public\Desktop\Google Docs.lnk
2015-11-26 13:57 - 2015-08-09 22:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-11-24 20:41 - 2014-04-25 01:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Process Hacker 2
2015-11-24 20:41 - 2014-04-25 01:18 - 00000000 ____D C:\Program Files\Process Hacker 2
2015-11-24 20:30 - 2015-08-19 13:16 - 00003632 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2015-11-20 19:02 - 2015-07-10 12:02 - 00000000 ____D C:\WINDOWS\INF
2015-11-20 19:02 - 2014-03-13 20:03 - 00000000 ____D C:\temp
2015-11-20 19:02 - 2013-11-29 22:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-11-20 19:02 - 2013-11-29 00:24 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-11-19 15:05 - 2015-09-27 00:02 - 00000000 ____D C:\Users\Nico ****\.VirtualBox
2015-11-19 15:04 - 2014-01-24 21:00 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\BitTorrent
2015-11-18 13:57 - 2015-07-16 12:16 - 00001142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remotr Streamer.lnk
2015-11-18 13:57 - 2015-07-16 12:16 - 00000000 ____D C:\Program Files (x86)\Remotr
2015-11-17 18:32 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-11-17 07:27 - 2015-08-16 14:03 - 11228816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2015-11-16 04:54 - 2015-08-16 14:03 - 18487360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2015-11-16 04:54 - 2015-08-16 14:03 - 15933400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2015-11-16 04:54 - 2015-08-16 14:03 - 12870192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2015-11-16 04:54 - 2015-08-16 14:03 - 03540544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2015-11-16 04:54 - 2015-08-16 14:03 - 03126800 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2015-11-16 04:54 - 2015-08-16 14:03 - 00034494 _____ C:\WINDOWS\system32\nvinfo.pb
2015-11-16 04:54 - 2015-06-29 08:52 - 01572496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2015-11-16 04:54 - 2015-06-29 08:52 - 00205456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2015-11-16 04:54 - 2013-11-29 00:24 - 00112944 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2015-11-16 04:54 - 2013-11-29 00:24 - 00105080 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2015-11-14 23:47 - 2014-03-28 17:25 - 00000000 ____D C:\Users\Nico ****\AppData\Local\JDownloader v2.0
2015-11-14 23:06 - 2015-10-10 14:02 - 00000000 ____D C:\Users\Nico ****\Desktop\Filme
2015-11-14 22:54 - 2014-03-30 14:29 - 00000000 ____D C:\Users\Nico ****\Documents\My Games
2015-11-14 21:49 - 2014-05-24 07:54 - 00000000 ___HD C:\WINDOWS\msdownld.tmp
2015-11-14 15:54 - 2015-04-19 20:07 - 00000080 _____ C:\Users\Nico ****\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦
2015-11-14 14:11 - 2015-10-24 16:38 - 00000000 ____D C:\Aptana Stuido
2015-11-14 11:01 - 2014-10-04 19:29 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-11-14 07:20 - 2013-11-29 00:25 - 06358648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-11-14 07:20 - 2013-11-29 00:25 - 02983216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2015-11-14 07:20 - 2013-11-29 00:25 - 02554488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-11-14 07:20 - 2013-11-29 00:25 - 00938616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-11-14 07:20 - 2013-11-29 00:25 - 00062584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-11-14 07:20 - 2013-11-29 00:24 - 00385144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-11-14 00:20 - 2014-04-14 17:53 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Battle.net
2015-11-13 19:25 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\rescache
2015-11-13 18:40 - 2014-12-14 14:00 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-11-13 16:42 - 2015-08-16 13:05 - 01790124 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-13 16:42 - 2015-07-10 17:34 - 00771100 _____ C:\WINDOWS\system32\perfh007.dat
2015-11-13 16:42 - 2015-07-10 17:34 - 00153964 _____ C:\WINDOWS\system32\perfc007.dat
2015-11-12 21:41 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-12 15:36 - 2013-11-29 23:02 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-11-12 15:35 - 2013-11-29 23:01 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-12 15:23 - 2013-11-29 21:12 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-11-12 15:14 - 2013-11-29 21:12 - 145617392 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-11-12 15:13 - 2013-08-22 14:25 - 00000167 _____ C:\WINDOWS\win.ini
2015-11-11 19:44 - 2015-04-16 20:14 - 00000000 ____D C:\Users\Nico ****\Desktop\GTA
2015-11-11 16:43 - 2014-06-08 15:00 - 00003870 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-11-09 14:22 - 2015-07-16 12:16 - 00000000 ____D C:\ProgramData\Remotr
2015-11-08 22:37 - 2014-09-16 19:04 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Genymobile
2015-11-08 13:38 - 2015-10-28 15:17 - 00000185 _____ C:\Users\Nico ****\Desktop\Spamips.txt
2015-11-08 00:25 - 2014-06-29 12:45 - 00000000 ___RD C:\Users\Nico ****\Creative Cloud Files
2015-11-07 18:32 - 2014-01-11 18:49 - 00000000 ____D C:\Program Files\OBS
2015-11-07 10:56 - 2015-09-10 15:33 - 00000000 ____D C:\Program Files (x86)\WinPcap
2015-11-07 10:56 - 2015-01-04 19:59 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\Wireshark
2015-11-07 10:56 - 2014-12-16 13:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2015-11-07 10:56 - 2014-08-01 21:28 - 00000000 ____D C:\Users\Nico ****\AppData\Local\paint.net
2015-11-07 10:56 - 2014-05-24 12:48 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\Thunderbird
2015-11-07 10:56 - 2013-11-29 23:01 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Microsoft Help
2015-11-07 10:50 - 2014-12-26 01:23 - 00003014 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-11-07 10:45 - 2015-01-15 15:51 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\KeePass
2015-11-06 19:00 - 2015-03-14 17:42 - 00003454 _____ C:\Users\Nico ****\Documents\daten.kdbx
2015-11-06 18:57 - 2015-11-02 14:50 - 00000000 ____D C:\Program Files (x86)\LastPass

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2015-11-06 18:57 - 2015-11-06 18:57 - 20320792 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2014-02-23 16:22 - 2014-02-23 16:22 - 1213440 _____ () C:\Users\Nico ****\AppData\Roaming\21390.exe
2014-02-23 16:21 - 2014-02-23 16:21 - 1213440 _____ () C:\Users\Nico ****\AppData\Roaming\55d77.exe
2014-03-17 17:12 - 2014-05-31 19:13 - 0000132 _____ () C:\Users\Nico ****\AppData\Roaming\Adobe IllExport-Filter CC - Voreinstellungen
2014-04-21 15:14 - 2014-04-21 16:05 - 0000132 _____ () C:\Users\Nico ****\AppData\Roaming\Adobe PNG Format CS5 Prefs
2014-01-15 01:17 - 2014-06-29 09:55 - 0000132 _____ () C:\Users\Nico ****\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen
2014-08-07 18:56 - 2015-08-10 09:10 - 0000034 _____ () C:\Users\Nico ****\AppData\Roaming\AdobeWLCMCache.dat
2014-02-23 16:21 - 2014-09-03 16:32 - 0000152 _____ () C:\Users\Nico ****\AppData\Roaming\config.ini
2015-11-05 21:07 - 2015-11-05 21:16 - 0002732 _____ () C:\Users\Nico ****\AppData\Roaming\droid4xinstaller.log
2015-08-08 10:35 - 2015-08-08 10:35 - 0000000 _____ () C:\Users\Nico ****\AppData\Roaming\Stardockfences_debug_snapshot.dat
2015-06-24 13:04 - 2015-06-23 18:55 - 0178176 _____ () C:\Users\Nico ****\AppData\Roaming\TMP01.txt
2014-04-28 00:38 - 2014-08-26 17:04 - 0001839 _____ () C:\Users\Nico ****\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2014-01-11 19:56 - 2014-01-12 16:24 - 0005632 _____ () C:\Users\Nico ****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-02-20 17:08 - 2015-02-20 17:09 - 0000026 _____ () C:\Users\Nico ****\AppData\Local\isoworkshop.ini
2015-03-14 20:50 - 2015-03-14 20:50 - 0000000 ___SH () C:\Users\Nico ****\AppData\Local\LumaEmu
2014-08-16 14:38 - 2015-12-05 13:14 - 0007593 _____ () C:\Users\Nico ****\AppData\Local\Resmon.ResmonCfg
2014-03-31 18:07 - 2014-03-31 18:07 - 0000003 _____ () C:\Users\Nico ****\AppData\Local\updater.log
2014-03-31 18:07 - 2015-10-03 10:56 - 0000424 _____ () C:\Users\Nico ****\AppData\Local\UserProducts.xml
2014-10-23 19:54 - 2014-10-23 19:54 - 0314151 _____ () C:\ProgramData\1414090333.bdinstall.bin
2015-08-16 12:37 - 2015-08-16 12:37 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-05-10 11:06 - 2014-03-11 11:06 - 0000032 ____R () C:\ProgramData\hash.dat
2014-03-16 03:42 - 2015-05-13 18:38 - 0000213 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\ProgramData\hash.dat


Einige Dateien in TEMP:
====================
C:\Users\Nico ****\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Nico ****\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Nico ****\AppData\Local\Temp\nvStInst.exe
C:\Users\Nico ****\AppData\Local\Temp\processhacker-2.36-setup.exe


Einige mit null Byte Größe Dateien/Ordner:
==========================
C:\Windows\System32\BDSandBoxUH.dll
C:\Windows\System32\BDSandBoxUISkin.dll
C:\Windows\System32\BDSandBoxUISkin32.dll

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2015-12-04 17:11

==================== Ende von FRST.txt ============================
         
Die Addition.txt ist zu groß um sie hier einzufügen! Was soll ich tun?

Alt 06.12.2015, 22:39   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert? - Standard

Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert?



hi,

Log aufteilen und mehrere Posts benutzen.
__________________

__________________

Alt 06.12.2015, 22:49   #3
zeVra
 
Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert? - Standard

Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert?



So, hier nochmal die FRST.txt vom Desktop gestartet
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-12-2015
durchgeführt von Nico (Administrator) auf NICO (06-12-2015 22:45:19)
Gestartet von C:\Users\Nico ****\Desktop
Geladene Profile: Nico (Verfügbare Profile: Nico)
Platform: Windows 10 Pro (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(American Megatrends Inc.) C:\Program Files\AMI\DuOS\AndServMgr.exe
() C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\47.0.2526.18\remoting_host.exe
() C:\Program Files (x86)\freeSSHd\FreeSSHDService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\47.0.2526.18\remoting_host.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Flux Software LLC) C:\Users\Nico ****\AppData\Local\FluxSoftware\Flux\flux.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.3.0.0\Lightshot.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DiscSoftBusService.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Microsoft Corporation) C:\Windows\System32\wimserv.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Program Files (x86)\Bethesda Studios\Fallout 4\Mod Manager\Fallout4ModManager.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\7badfbd5-1b99-4a1a-88f8-a4e455fb9de3.com
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Don HO don.h@free.fr) C:\Program Files (x86)\Notepad++\notepad++.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8497368 2015-08-14] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520 2015-10-12] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-07-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2303152 2015-07-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2109952 2014-10-07] (Dominik Reichl)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [917112 2015-10-08] (BlueStack Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKLM\...\Policies\Explorer: [AllowLegacyWebView] 1
HKLM\...\Policies\Explorer: [AllowUnhashedWebView] 1
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8551848 2015-10-19] (Piriform Ltd)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [KeePass Password Safe 2] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2109952 2014-10-07] (Dominik Reichl)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [BitTorrent] => C:\Users\Nico ****\AppData\Roaming\BitTorrent\BitTorrent.exe [1977192 2015-10-17] (BitTorrent Inc.)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3761424 2014-11-10] (Disc Soft Ltd)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22790776 2015-11-04] (Google)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [48138880 2015-10-14] (Skype Technologies S.A.)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [f.lux] => C:\Users\Nico ****\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [MinerGateGui] => C:\Program Files\MinerGate\minergate.exe [16197632 2015-11-10] ()
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7935904 2015-12-02] (SUPERAntiSpyware)
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\RunOnce: [Uninstall C:\Users\Nico ****\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Nico ****\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\RunOnce: [Uninstall C:\Users\Nico ****\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Nico ****\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Policies\Explorer: [NofolderOptions] 0
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000
IFEO\utilman.exe: [Debugger] cmd.exe
SSODL-x32: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} -  Keine Datei
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-07-22] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-07-22] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-07-22] ()
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  Keine Datei
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  Keine Datei
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  Keine Datei
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  Keine Datei
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  Keine Datei
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  Keine Datei
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  Keine Datei
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} =>  Keine Datei
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} =>  Keine Datei
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2015-11-06]
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2015-11-06]
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2014-11-08]
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\chrome - Verknüpfung.lnk [2015-08-11]
ShortcutTarget: chrome - Verknüpfung.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Startup: C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EventGhost.lnk [2015-08-07]
ShortcutTarget: EventGhost.lnk -> C:\Program Files (x86)\EventGhost\EventGhost.exe (EventGhost Project)
BootExecute: autocheck autochk * SmartDefragBootTime.exe
CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{4bc30ba3-ec84-4364-8edf-d69cb2e1bb61}: [NameServer] 192.168.2.1
Tcpip\..\Interfaces\{4bc30ba3-ec84-4364-8edf-d69cb2e1bb61}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{74966d45-470b-4b0f-b3db-885a0046fb25}: [DhcpNameServer] 8.8.8.8

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://de.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
SearchScopes: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/search?q={SearchTerms}&fr=ntg
SearchScopes: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = 
SearchScopes: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001 -> {F90EF9FE-D59B-44BB-8929-A440EE26CC05} URL = hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
SearchScopes: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/search?q={SearchTerms}&fr=ntg
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-10-20] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-11-02] (Oracle Corporation)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-11-06] (LastPass)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-13] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-02] (Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-10-20] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-11-02] (Oracle Corporation)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-11-06] (LastPass)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-13] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-02] (Oracle Corporation)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-11-06] (LastPass)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-11-06] (LastPass)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-11] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-02] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-02] (Oracle Corporation)
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-11-06] (LastPass)
FF Plugin: @unity3d.com/UnityPlayer64,version=1.0 -> C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll [2015-02-18] (Unity Technologies ApS)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2013-11-12] (VideoLAN)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-07-23] (Adobe Systems)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC)
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-02] (Oracle Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-11-06] (LastPass)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-01-10] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-11-14] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-11-14] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [Keine Datei]
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Nico ****\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2014-03-10] (Raidcall)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-07-23] (Adobe Systems)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin HKU\S-1-5-21-2171699750-2845458332-3438301781-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Nico ****\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-08] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2171699750-2845458332-3438301781-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [Keine Datei]
FF Plugin HKU\S-1-5-21-2171699750-2845458332-3438301781-1001: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-01-31] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-01-31] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-01-31] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-01-31] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-01-31] (Apple Inc.)
FF SearchPlugin: C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\searchplugins\youtube-videosuche.xml [2015-10-03]
FF Extension: Modify Headers - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}.xpi [2015-11-06]
FF Extension: Greasemonkey - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2015-11-30]
FF Extension: LastPass - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\extensions\support@lastpass.com [2015-12-03]
FF Extension: Fox To Phone - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\extensions\sendtophone@martinezdelizarrondo.com.xpi [2015-12-05]
FF Extension: Kein Name - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\firefox@betterttv.net.xpi [2015-10-18] [ist nicht signiert]
FF Extension: YouTube mp3 - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\info@youtube-mp3.org.xpi [2015-09-26]
FF Extension: Kein Name - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\MediaSniffer@hiyoko.info.xpi [2015-12-05] [ist nicht signiert]
FF Extension: YouTube Unblocker - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\youtubeunblocker@unblocker.yt [2015-12-03]
FF Extension: ZIPUpdaterFree - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\{45a2694b-7a8d-4e31-aaab-81087fdf2756}.xpi [2015-12-05] [ist nicht signiert]
FF Extension: Video DownloadHelper - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-10-30]
FF Extension: Adblock Plus - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-25]
FF Extension: HTML5 Extension - C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\Extensions\{eeba6b96-d5c8-4dd8-8ff7-105b1bbb45c2}.xpi [2015-12-01] [ist nicht signiert]

Chrome: 
=======
CHR NewTab: Default -> "chrome-extension://bhloflhklmhfpedakmangadcdofhnnoh/index.html"
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR DefaultSuggestURL: Default -> hxxps://de.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Profile: C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Heartbeat) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aailiojlhjbichheofhdpcongebcgcgm [2015-12-05]
CHR Extension: (Google Präsentationen) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-20]
CHR Extension: (Google Docs) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-21]
CHR Extension: (Google Drive) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (Earth View from Google Earth) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhloflhklmhfpedakmangadcdofhnnoh [2015-12-05]
CHR Extension: (YouTube) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Adblock Plus) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-11-29]
CHR Extension: (Google-Suche) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Tampermonkey) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2015-11-29]
CHR Extension: (ARC Welder) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\emfinbmielocnlhgmfkkmkngdoccbadn [2015-12-06]
CHR Extension: (Google Tabellen) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-20]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2015-11-05]
CHR Extension: (Google Docs Offline) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-29]
CHR Extension: (AutoRemote) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\hglmpnnkhfjpnoheioijdpleijlmfcfb [2015-11-29]
CHR Extension: (Google Notizen – Notizen & Listen) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2015-11-29]
CHR Extension: (VideoHunter+) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpiikdgdgibmpnfhkopjaamphpmdgfhm [2015-09-10]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2015-09-01]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2015-08-20]
CHR Extension: (Tampermonkey) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfaihdlpglflfgpfjcifdjdjcckigekc [2015-12-06]
CHR Extension: (Keepa - Amazon Price Tracker) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\neebplgakaahbhdphmkckjjcegoiijjo [2015-11-29]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-20]
CHR Extension: (Google Chrome to Phone Extension) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco [2015-12-05]
CHR Extension: (Google Mail) - C:\Users\Nico ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-21]
CHR Extension: (__MSG_extName__) - C:\Users\Nico ****\Documents\ARCWELDER\Hack%20Ex%20-%20Simulator_1.1.4_apk-dl.com.apk_export_oUBJK [2015-10-26]
CHR Extension: (__MSG_extName__) - C:\Users\Nico ****\Documents\ARCWELDER\Hack%20Ex%20-%20Simulator_1.1.4_apk-dl.com.apk_export_oUBJK [2015-10-26]
CHR Extension: (__MSG_extName__) - C:\Users\Nico ****\Documents\ARCWELDER\Hack%20Ex%20-%20Simulator_1.1.4_apk-dl.com.apk_export_wUfLB [2015-10-26]
CHR Extension: (__MSG_extName__) - C:\Users\Nico ****\Documents\ARCWELDER\Hack%20Ex%20-%20Simulator_1.1.4_apk-dl.com.apk_export_wUfLB [2015-10-26]
CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [njabjmhinndphfnbjehdalkphpdmepli] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [npdicihegicnhaangkdmcgbjceoemeoo] - hxxps://clients2.google.com/service/update2/crx

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 AndServMgr; C:\Program Files\AMI\DuOS\AndServMgr.exe [82384 2015-08-06] (American Megatrends Inc.)
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [437880 2015-10-08] (BlueStack Systems, Inc.)
S2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [417400 2015-10-08] (BlueStack Systems, Inc.)
S2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [855672 2015-10-08] (BlueStack Systems, Inc.)
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\47.0.2526.18\remoting_host.exe [69448 2015-10-14] (Google Inc.)
R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [216576 2014-11-25] () [Datei ist nicht signiert]
R3 Disc Soft Bus Service; C:\Program Files (x86)\DAEMON Tools Pro\DiscSoftBusService.exe [2216208 2014-11-10] (Disc Soft Ltd)
S2 Droid4XService; C:\Program Files (x86)\Droid4X\Droid4XService.exe [261864 2015-06-03] () [Datei ist nicht signiert]
S2 Ds3Service; C:\Program Files\Scarlet.Crush Productions\bin\ScpService.exe [388352 2013-05-05] (Scarlet.Crush Productions)
R2 FreeSSHDService; C:\Program Files (x86)\freeSSHd\FreeSSHDService.exe [1513072 2015-02-02] ()
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384 2015-10-12] (NVIDIA Corporation)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-08-07] (IObit)
S2 Mobizen plugin; C:\Program Files (x86)\RSUPPORT\MobizenService\MobizenService.exe [3353360 2015-08-14] ( Rsupport Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696 2015-10-12] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568288 2015-10-12] (NVIDIA Corporation)
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [24576 2013-11-03] (The OpenVPN Project) [Datei ist nicht signiert]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-08] (Electronic Arts)
S2 Remotr Service; C:\Program Files (x86)\Remotr\RemotrService.exe [181328 2015-11-16] (RemoteMyApp sp. z o.o.)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [242936 2015-11-06] (RaMMicHaeL)
S2 UnsignedThemes; C:\Windows\unsignedthemes.exe [13824 2013-09-23] (The Within Network, LLC) [Datei ist nicht signiert]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [672024 2015-02-26] (Wacom Technology, Corp.)

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 amdide64; C:\Windows\System32\drivers\amdide64.sys [11944 2015-05-24] (Advanced Micro Devices Inc.)
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2015-09-01] (Google Inc)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [146040 2015-10-08] (BlueStack Systems)
S3 cxbu0x64; C:\Windows\system32\DRIVERS\cxbu0x64.sys [147576 2015-09-05] (HID Global Corporation)
S3 dtscsibus; C:\Windows\system32\DRIVERS\dtscsibus.sys [29864 2015-06-04] (Disc Soft Ltd)
R1 DuoVMDrv; C:\Windows\system32\DRIVERS\DuoVMDrv.sys [239536 2015-07-31] (American Megatrends Inc.)
S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [44296 2015-03-30] (LogMeIn Inc.)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-05-24] (REALiX(tm))
S3 LcUvcUpper; C:\Windows\system32\DRIVERS\LcUvcUpper.sys [34408 2013-09-27] (Microsoft Corporation)
R3 ManyCam; C:\Windows\system32\DRIVERS\mcvidrv_x64.sys [34304 2012-01-11] (ManyCam LLC)
R3 mcaudrv_simple; C:\Windows\system32\drivers\mcaudrv_x64.sys [28160 2012-02-22] (ManyCam LLC)
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] ()
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20768 2015-10-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
S3 qcusbser; C:\Windows\system32\DRIVERS\qcusbser.sys [242688 2015-08-14] (QUALCOMM Incorporated)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek                                            )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-05] (Scarlet.Crush Productions)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S2 uxstyle; C:\Windows\system32\Drivers\uxstyle.sys [31440 2013-09-23] (The Within Network, LLC)
R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-10-15] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [146584 2015-10-15] (Oracle Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 pxldqpod; C:\Users\Nico ****\AppData\Local\Temp\pxldqpod.sys [56496 2015-12-06] (GMER) [Datei ist nicht signiert]
S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-12-06 22:45 - 2015-12-06 22:46 - 00037159 _____ C:\Users\Nico ****\Desktop\FRST.txt
2015-12-06 21:53 - 2015-12-06 22:01 - 00079911 _____ C:\Users\Nico ****\Downloads\Addition.txt
2015-12-06 21:51 - 2015-12-06 22:02 - 00080115 _____ C:\Users\Nico ****\Downloads\FRST.txt
2015-12-06 21:47 - 2015-12-06 22:45 - 00000000 ____D C:\FRST
2015-12-06 21:47 - 2015-12-06 21:47 - 02369024 _____ (Farbar) C:\Users\Nico ****\Desktop\FRST64.exe
2015-12-06 21:34 - 2015-12-06 21:34 - 00380416 _____ C:\Users\Nico ****\Downloads\Gmer-19357.exe
2015-12-06 21:34 - 2015-12-06 21:34 - 00050477 _____ C:\Users\Nico ****\Downloads\Defogger.exe
2015-12-06 21:04 - 2015-12-06 21:04 - 00016148 _____ C:\WINDOWS\system32\NICO_Nico_HistoryPrediction.bin
2015-12-06 18:52 - 2015-12-06 18:52 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\SUPERAntiSpyware.com
2015-12-06 18:51 - 2015-12-06 21:31 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-12-06 18:51 - 2015-12-06 18:51 - 00001849 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-12-06 18:51 - 2015-12-06 18:51 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2015-12-06 18:51 - 2015-12-06 18:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-12-06 18:49 - 2015-12-06 18:50 - 24088304 _____ (SUPERAntiSpyware) C:\Users\Nico ****\Downloads\SUPERAntiSpyware.exe
2015-12-06 18:14 - 2015-12-06 18:14 - 00000000 _____ C:\Users\Nico ****\Desktop\Telegraph.apk
2015-12-06 18:09 - 2015-12-06 18:21 - 00000000 ____D C:\Users\Nico ****\Desktop\Zeitungen
2015-12-06 16:11 - 2015-12-06 16:11 - 00011793 _____ C:\Users\Nico ****\Downloads\ic_directions_bike_black_24dp.zip
2015-12-06 16:05 - 2015-12-06 16:05 - 00007253 _____ C:\Users\Nico ****\Downloads\ic_announcement_black_24dp.zip
2015-12-06 13:28 - 2015-12-06 13:28 - 00000000 ____D C:\Users\Nico ****\AppData\Local\minergate
2015-12-06 13:28 - 2015-12-06 13:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MinerGate
2015-12-06 13:28 - 2015-12-06 13:28 - 00000000 ____D C:\Program Files\MinerGate
2015-12-06 13:22 - 2015-12-06 13:22 - 10782967 _____ C:\Users\Nico ****\Downloads\MinerGate-5.06-win64.exe
2015-12-06 11:38 - 2015-12-06 11:38 - 00011226 _____ C:\Users\Nico ****\Downloads\ic_whatshot_black_24dp.zip
2015-12-05 23:31 - 2015-12-05 23:31 - 00023040 _____ () C:\Users\Nico ****\Desktop\FO4FaceRipper.exe
2015-12-05 23:31 - 2015-12-05 23:31 - 00008771 _____ C:\Users\Nico ****\Downloads\Save Face Ripper-3878-7.7z
2015-12-05 23:29 - 2015-12-05 23:40 - 00000000 ____D C:\Users\Nico ****\Desktop\BIGBOSS éu2.0
2015-12-05 22:29 - 2015-12-05 22:29 - 05401798 _____ C:\Users\Nico ****\Downloads\Skyrim Audio Converter 1_0_2-8303-1-0-2.7z
2015-12-05 19:16 - 2015-12-05 19:16 - 00000022 _____ C:\WINDOWS\S.dirmngr
2015-12-05 17:09 - 2015-12-05 17:09 - 02903735 _____ C:\Users\Nico ****\Downloads\BIGBOSS V2.0-4118-2-0.zip
2015-12-05 15:44 - 2015-12-05 15:44 - 00011536 _____ C:\Users\Nico ****\Downloads\ic_stars_black_24dp.zip
2015-12-05 15:31 - 2015-12-05 15:31 - 00006824 _____ C:\Users\Nico ****\Downloads\ic_movie_black_24dp.zip
2015-12-05 15:27 - 2015-12-05 15:27 - 00009653 _____ C:\Users\Nico ****\Downloads\ic_local_mall_black_24dp.zip
2015-12-05 15:23 - 2015-12-05 15:23 - 02615253 _____ C:\Users\Nico ****\Downloads\9396-44434-1-PB.pdf
2015-12-05 15:22 - 2015-12-05 15:22 - 02192671 _____ C:\Users\Nico ****\Downloads\Fallout4Translator-215-0-8.zip
2015-12-05 15:06 - 2015-12-05 15:06 - 00007935 _____ C:\Users\Nico ****\Downloads\ic_video_library_black_24dp.zip
2015-12-05 14:52 - 2015-12-05 14:53 - 00006575 _____ C:\Users\Nico ****\Downloads\ic_games_black_24dp.zip
2015-12-05 14:43 - 2015-12-05 14:43 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-12-05 14:43 - 2015-12-05 14:43 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2015-12-05 14:34 - 2015-12-05 14:34 - 41904448 _____ (Apple Inc.) C:\Users\Nico ****\Downloads\QuickTimeInstaller.exe
2015-12-05 11:56 - 2015-12-05 11:56 - 01240761 _____ C:\Users\Nico ****\Downloads\Longer Distance PipBoy and Spotlights (With Optional PipBoyShadows)-1790--5.rar
2015-12-04 23:54 - 2015-12-04 23:54 - 00096140 _____ C:\Users\Nico ****\Downloads\special-elite.zip
2015-12-04 23:52 - 2015-12-04 23:52 - 00075028 _____ C:\Users\Nico ****\Downloads\kingthings_trypewriter.zip
2015-12-04 23:21 - 2015-12-04 23:21 - 00007136 _____ C:\Users\Nico ****\Downloads\Save Face Ripper-3878-6.7z
2015-12-04 23:09 - 2015-12-04 23:09 - 01392248 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-1-7-222.zip
2015-12-04 23:08 - 2015-11-13 14:54 - 03431117 _____ C:\Users\Nico ****\Desktop\Save3_1A910BF0_57616C746572_Vault111Cryo_000049_20151113135408_1_2.fos
2015-12-04 23:05 - 2015-12-04 23:05 - 01193192 _____ C:\Users\Nico ****\Downloads\W.W. Heisenberg-348-1-1.rar
2015-12-04 20:29 - 2015-12-04 20:30 - 01143808 _____ (PainteR) C:\Users\Nico ****\Downloads\adobe.snr.patch-painter.exe
2015-12-04 20:14 - 2015-12-04 20:14 - 00201085 _____ C:\Users\Nico ****\Downloads\my_underwood.zip
2015-12-04 20:13 - 2015-12-04 20:13 - 00033086 _____ C:\Users\Nico ****\Downloads\remingtoned_type.zip
2015-12-04 20:07 - 2015-12-04 20:07 - 00989291 _____ C:\Users\Nico ****\Downloads\traveling_typewriter(1).zip
2015-12-04 20:00 - 2015-12-04 20:00 - 00029241 _____ C:\Users\Nico ****\Downloads\Slabo_27px.zip
2015-12-04 14:48 - 2015-12-04 14:48 - 00008219 _____ C:\Users\Nico ****\Downloads\ic_thumb_down_black_24dp.zip
2015-12-04 14:48 - 2015-12-04 14:48 - 00008094 _____ C:\Users\Nico ****\Downloads\ic_thumb_up_black_24dp.zip
2015-12-04 14:26 - 2015-12-04 14:26 - 01075821 _____ C:\Users\Nico ****\Downloads\Roboto(1).zip
2015-12-04 14:23 - 2015-12-04 14:23 - 01379427 _____ C:\Users\Nico ****\Downloads\roboto.zip
2015-12-04 14:04 - 2015-12-06 18:53 - 00000000 ____D C:\Users\Nico ****\Desktop\Krasse Zeitung
2015-12-03 15:45 - 2015-12-03 15:45 - 00002541 _____ C:\Users\Nico ****\Downloads\Fallout 4 Place in Red v1.7.zip-1267-1-7.zip
2015-12-03 15:45 - 2015-11-23 01:50 - 00017654 _____ C:\Users\Nico ****\Desktop\Fallout 4 Place in Red v1.7.ct
2015-12-03 14:12 - 2015-12-06 14:31 - 00000000 ____D C:\WINDOWS\Panther
2015-12-02 22:09 - 2015-12-02 22:09 - 01371366 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-1-5-2060.zip
2015-12-02 14:30 - 2015-12-02 14:30 - 00934931 _____ C:\Users\Nico ****\Downloads\Settlement Raid Mod 1.7-2995-1-7.zip
2015-12-01 19:02 - 2015-11-30 18:30 - 05621885 _____ C:\Users\Nico ****\Desktop\fo4facetransfer.exe
2015-12-01 19:00 - 2015-12-01 19:01 - 05560961 _____ C:\Users\Nico ****\Downloads\Fallout 4 Face Transfer-3597-0-1.zip
2015-11-30 21:03 - 2015-11-30 21:03 - 01671338 _____ C:\Users\Nico ****\Downloads\Gorgeous Vaultgirl (Vault Exit Version)-193-1-02.zip
2015-11-30 20:52 - 2015-11-30 20:52 - 01666048 _____ (WJ&AF Company) C:\Users\Nico ****\Desktop\F4SGE.exe
2015-11-30 20:50 - 2015-11-30 20:50 - 01355166 _____ C:\Users\Nico ****\Downloads\Gorgeous Vaultgirl-193-1-01(1).zip
2015-11-30 20:50 - 2015-11-30 20:50 - 01301129 _____ C:\Users\Nico ****\Downloads\F4SGE.0v1b6-838-alfa.7z
2015-11-30 19:31 - 2015-11-30 19:31 - 03081746 _____ C:\Users\Nico ****\Downloads\AutoHotkey112209_Install.exe
2015-11-30 19:31 - 2015-11-30 19:31 - 01358686 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-1-3-1793.zip
2015-11-30 19:17 - 2015-11-30 19:18 - 02190640 _____ C:\Users\Nico ****\Downloads\Fallout4Translator-215-0-7b.zip
2015-11-30 15:48 - 2015-11-30 15:50 - 01355166 _____ C:\Users\Nico ****\Downloads\Gorgeous Vaultgirl-193-1-01.zip
2015-11-29 10:42 - 2015-11-29 10:42 - 01482475 _____ C:\Users\Nico ****\Downloads\Fallout 4 Mod Manager-495-1-0-30(1).zip
2015-11-28 15:36 - 2015-11-28 15:36 - 01919162 _____ C:\Users\Nico ****\Downloads\Fallout4_EnglishSTRINGS-215-0-1.7z
2015-11-28 15:16 - 2015-11-28 15:16 - 15422436 _____ C:\Users\Nico ****\Downloads\Fallout4_STRINGS_Misc-215-0-1.7z
2015-11-28 14:59 - 2015-11-28 14:59 - 02732887 _____ C:\Users\Nico ****\Downloads\FO4Edit 3.1.3-2737-EXP.7z
2015-11-28 14:57 - 2015-11-30 14:19 - 00000000 ____D C:\Users\Nico ****\Desktop\FO4Edit
2015-11-27 22:02 - 2015-11-27 22:02 - 00031097 _____ C:\Users\Nico ****\Downloads\Who Are You v1.2-2377-1-2.7z
2015-11-27 21:27 - 2015-11-27 21:27 - 02722183 _____ C:\Users\Nico ****\Downloads\TES5Edit_211115a.7z
2015-11-27 21:20 - 2015-11-27 21:20 - 00309595 _____ C:\Users\Nico ****\Downloads\Settler Renaming-2017-1-7-2.zip
2015-11-26 14:28 - 2015-11-26 14:28 - 00000000 ____D C:\Users\Nico ****\AppData\Local\ElevatedDiagnostics
2015-11-26 14:01 - 2015-11-26 14:03 - 01482475 _____ C:\Users\Nico ****\Downloads\Fallout 4 Mod Manager-495-1-0-30.zip
2015-11-25 17:13 - 2015-11-25 17:13 - 02189078 _____ C:\Users\Nico ****\Downloads\Fallout4Translator-215-0-7a.zip
2015-11-25 14:26 - 2015-11-25 14:28 - 54666380 _____ C:\Users\Nico ****\Downloads\EBT v007-212-0-07.7z
2015-11-24 20:32 - 2015-11-24 20:33 - 01478096 _____ C:\Users\Nico ****\Downloads\Fallout 4 Mod Manager-495-1-0-27.zip
2015-11-24 19:16 - 2015-11-24 19:17 - 01229444 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-1-1-180.zip
2015-11-24 19:13 - 2015-11-10 20:11 - 63446952 _____ C:\Users\Nico ****\Desktop\setup-1.bin
2015-11-24 19:13 - 2015-11-10 20:11 - 03672661 _____ ( ) C:\Users\Nico ****\Desktop\setup.exe
2015-11-24 18:39 - 2015-11-24 18:39 - 00192475 _____ C:\Users\Nico ****\Downloads\f4se_0_01_01.7z
2015-11-24 18:34 - 2015-11-24 18:34 - 01478075 _____ C:\Users\Nico ****\Downloads\Fallout 4 Mod Manager-495-1-0-26.zip
2015-11-23 22:28 - 2015-11-23 22:28 - 00026079 _____ C:\Users\Nico ****\Downloads\glowingbobbleheads-1888-1-0.zip
2015-11-23 22:23 - 2015-11-23 22:24 - 00024354 _____ C:\Users\Nico ****\Downloads\Settlement Supplies Expanded-1145-1-92.rar
2015-11-23 19:38 - 2015-11-23 19:38 - 00000421 _____ C:\Users\Nico ****\Downloads\Faster Terminal Displays (5x) FO4Edit Version-937-2-0.zip
2015-11-23 14:30 - 2015-11-23 14:30 - 01130794 _____ C:\Users\Nico ****\Downloads\Black Gasmask-567-0-1.rar
2015-11-23 14:27 - 2015-11-23 14:27 - 00001457 _____ C:\Users\Nico ****\Downloads\VOT - Increased VATS Range-2173-1-0.zip
2015-11-23 14:20 - 2015-11-23 14:20 - 00022919 _____ C:\Users\Nico ****\Downloads\More Armor Slots 1.2.3 German Translation-745-1-2-3.zip
2015-11-23 14:10 - 2015-11-23 14:11 - 00720598 _____ C:\Users\Nico ****\Downloads\Improved Map with Visible Roads - Darker Version-1215-1-1.zip
2015-11-22 17:35 - 2015-11-22 17:35 - 00002696 _____ C:\Users\Nico ****\Downloads\Summon Companions v0.1-1096-0-1.rar
2015-11-22 11:07 - 2015-11-22 11:07 - 00001006 _____ C:\Users\Nico ****\Downloads\Main file-1951-1-0.7z
2015-11-21 22:51 - 2015-11-21 22:51 - 02187907 _____ C:\Users\Nico ****\Downloads\Fallout4Translator-215-0-5b.zip
2015-11-21 22:39 - 2015-11-21 22:39 - 01526040 _____ C:\Users\Nico ****\Downloads\1k - bottles label overhaul v0.3-1500-0-3.zip
2015-11-21 22:38 - 2015-11-21 22:38 - 00083626 _____ C:\Users\Nico ****\Downloads\ETSGlowingMagsNMMVersion-1728-1-0.zip
2015-11-21 22:34 - 2015-11-21 22:34 - 00657334 _____ C:\Users\Nico ****\Downloads\Better Inventory (German)-1074-1-0.zip
2015-11-21 22:27 - 2015-11-21 22:27 - 00000510 _____ C:\Users\Nico ****\Downloads\Higher Settlement Budget v1.2-818-1-2.7z
2015-11-21 22:22 - 2015-11-21 22:22 - 00028527 _____ C:\Users\Nico ****\Downloads\Settlement Supplies Expanded-1145-1-8.rar
2015-11-21 22:18 - 2015-11-21 22:18 - 06191014 _____ C:\Users\Nico ****\Downloads\(Deutsche) Full Dialogue Interface - German translation-1235-Beta3.zip
2015-11-21 22:04 - 2015-11-21 22:04 - 00178402 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-853151c225ffcfb605973844082e6efc.pdf
2015-11-21 22:04 - 2015-11-21 22:04 - 00178402 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-853151c225ffcfb605973844082e6efc(1).pdf
2015-11-21 22:03 - 2015-11-21 22:03 - 00150742 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-03cfe7ca141459de7d8a9eb67760132a.pdf
2015-11-21 22:03 - 2015-11-21 22:03 - 00150742 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-03cfe7ca141459de7d8a9eb67760132a(5).pdf
2015-11-21 22:03 - 2015-11-21 22:03 - 00150742 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-03cfe7ca141459de7d8a9eb67760132a(3).pdf
2015-11-21 22:03 - 2015-11-21 22:03 - 00150742 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-03cfe7ca141459de7d8a9eb67760132a(2).pdf
2015-11-21 21:58 - 2015-11-21 21:59 - 00153214 _____ C:\Users\Nico ****\Downloads\ROSSMANN-Coupon-283258d897f1fbd53b403ad53727dbbd.pdf
2015-11-20 19:02 - 2015-11-20 19:02 - 00002210 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2015-11-20 19:02 - 2015-11-14 07:12 - 00102520 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2015-11-20 19:01 - 2015-11-20 19:02 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2015-11-20 19:00 - 2015-11-16 04:54 - 42913912 _____ C:\WINDOWS\system32\nvcompiler.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 37881976 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 22345848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 18390832 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 16561320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 15839200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 14844112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 13533608 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 12040952 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 02876536 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 02496632 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 01905456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435900.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 01564792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435900.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 01016544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00877688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00861816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00823232 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00689784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00674096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00539464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00503416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00501056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00446584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00445400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00422752 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00413816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00369456 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00177600 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00155792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00151184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2015-11-20 19:00 - 2015-11-16 04:54 - 00039240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2015-11-19 19:15 - 2015-11-19 19:15 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Fallout4ModManager
2015-11-17 18:38 - 2015-11-17 18:38 - 00001533 _____ C:\Users\Nico ****\Downloads\Default Carry Weight-214-1-4.rar
2015-11-17 18:38 - 2015-11-12 03:26 - 00000140 _____ C:\Users\Nico ****\Desktop\CarryWeight500.esp
2015-11-17 18:34 - 2015-11-17 18:36 - 00630571 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-0-4-3351.zip
2015-11-16 17:10 - 2015-11-16 17:10 - 05577782 _____ C:\Users\Nico ****\Downloads\Updated High res pre-war money re-texture-309-2(1).zip
2015-11-16 16:19 - 2015-11-16 16:19 - 04680510 _____ C:\Users\Nico ****\Downloads\Jesters Ammo Retex Fixed-345-2-0.rar
2015-11-16 08:31 - 2015-11-16 08:31 - 00003972 _____ C:\Users\Nico ****\Downloads\Configurable Fusion Core Drain 1.5-325-1-5(1).zip
2015-11-15 23:37 - 2015-11-15 23:37 - 00318938 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-0-3-3050(1).7z
2015-11-15 23:32 - 2015-11-24 19:17 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Bilago
2015-11-15 23:31 - 2015-11-15 23:31 - 00318938 _____ C:\Users\Nico ****\Downloads\Fallout 4 Configuration Tool-102-1-0-3-3050.7z
2015-11-15 21:32 - 2015-11-15 21:32 - 05577782 _____ C:\Users\Nico ****\Downloads\Updated High res pre-war money re-texture-309-2.zip
2015-11-15 21:28 - 2015-11-13 02:54 - 00000614 _____ C:\Users\Nico ****\Desktop\50% Fusion Core Drain.esp
2015-11-15 14:35 - 2015-11-15 14:36 - 38734984 _____ C:\Users\Nico ****\Downloads\FTO Pip-Boy 2K-449-1-0.rar
2015-11-15 14:35 - 2015-11-15 14:35 - 00003972 _____ C:\Users\Nico ****\Downloads\Configurable Fusion Core Drain 1.5-325-1-5.zip
2015-11-15 10:54 - 2015-11-15 10:54 - 00003864 _____ C:\Users\Nico ****\Downloads\ENBoost 0.281-332-281.zip
2015-11-15 10:51 - 2015-11-19 19:15 - 00000155 _____ C:\Users\Nico ****\Desktop\modorder.txt
2015-11-15 10:50 - 2015-11-15 10:50 - 00000000 ____D C:\Users\Nico ****\AppData\Local\FO4_PluginsManager
2015-11-15 10:49 - 2015-11-15 10:49 - 00183634 _____ C:\Users\Nico ****\Downloads\Plugins Manager 1.2-487-1-2.zip
2015-11-15 10:45 - 2015-11-15 10:45 - 00000996 _____ C:\Users\Nico ****\Downloads\Bonus Carry Weight-214-1-2.rar
2015-11-15 10:41 - 2015-11-15 10:41 - 15830769 _____ C:\Users\Nico ****\Downloads\EBT v002-212-0-02.7z
2015-11-14 22:54 - 2015-11-28 15:04 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Fallout4
2015-11-14 21:47 - 2015-11-14 21:50 - 00000000 ____D C:\WINDOWS\SysWOW64\directx
2015-11-14 21:46 - 2015-11-14 21:46 - 00001036 _____ C:\Users\Public\Desktop\Play Fallout 4.lnk
2015-11-14 21:46 - 2015-11-14 21:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bethesda Studios
2015-11-14 20:57 - 2015-11-14 20:57 - 00000000 ____D C:\Program Files (x86)\Bethesda Studios
2015-11-13 17:00 - 2015-12-04 20:10 - 00000000 ____D C:\Users\Nico ****\Desktop\LeoDaBOSS
2015-11-13 16:59 - 2015-11-13 16:59 - 00000000 ____D C:\Users\Nico ****\Downloads\Leo Da VInci
2015-11-13 16:45 - 2015-11-14 23:56 - 00000355 _____ C:\Users\Nico ****\Desktop\Neues Textdokument (6).txt
2015-11-12 19:06 - 2015-11-12 19:06 - 512522753 _____ C:\Users\Nico ****\Downloads\IGG-The.Escapists.The.Walking.Dead.rar
2015-11-11 19:44 - 2015-11-11 19:44 - 00000000 ____D C:\Users\Nico ****\AppData\LocalLow\BitTorrent
2015-11-11 19:42 - 2015-11-12 18:29 - 00000000 ____D C:\Users\Nico ****\Documents\The Escapists
2015-11-11 19:36 - 2015-11-11 19:36 - 93030375 _____ C:\Users\Nico ****\Downloads\IGG-The.Escapists.v1.23.Incl.4.DLCs.rar
2015-11-11 16:52 - 2015-11-05 06:15 - 08020832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-11-11 16:52 - 2015-11-05 06:15 - 00541024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-11-11 16:52 - 2015-11-05 06:14 - 00459104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2015-11-11 16:52 - 2015-11-05 06:13 - 00577888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2015-11-11 16:52 - 2015-11-05 06:11 - 01392480 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-11-11 16:52 - 2015-11-05 06:06 - 03621248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-11-11 16:52 - 2015-11-05 06:06 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-11-11 16:52 - 2015-11-05 06:01 - 00607408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-11-11 16:52 - 2015-11-05 05:56 - 01083072 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-11-11 16:52 - 2015-11-05 05:56 - 00116064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2015-11-11 16:52 - 2015-11-05 05:56 - 00025280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-11-11 16:52 - 2015-11-05 05:30 - 00961376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-11-11 16:52 - 2015-11-05 05:24 - 02878512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-11-11 16:52 - 2015-11-05 05:23 - 00762888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-11-11 16:52 - 2015-11-05 05:23 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2015-11-11 16:52 - 2015-11-05 05:20 - 21873664 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-11-11 16:52 - 2015-11-05 05:18 - 24597504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-11-11 16:52 - 2015-11-05 05:18 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-11-11 16:52 - 2015-11-05 05:18 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-11-11 16:52 - 2015-11-05 05:17 - 02418688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-11-11 16:52 - 2015-11-05 05:12 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
2015-11-11 16:52 - 2015-11-05 05:11 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-11-11 16:52 - 2015-11-05 05:10 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-11-11 16:52 - 2015-11-05 05:10 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-11-11 16:52 - 2015-11-05 05:07 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-11 16:52 - 2015-11-05 05:06 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-11-11 16:52 - 2015-11-05 05:05 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-11-11 16:52 - 2015-11-05 05:05 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-11-11 16:52 - 2015-11-05 05:03 - 02180608 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-11-11 16:52 - 2015-11-05 05:03 - 01015808 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-11-11 16:52 - 2015-11-05 05:01 - 00949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-11-11 16:52 - 2015-11-05 05:01 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-11-11 16:52 - 2015-11-05 05:01 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-11-11 16:52 - 2015-11-05 04:59 - 03587072 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-11-11 16:52 - 2015-11-05 04:59 - 02675200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2015-11-11 16:52 - 2015-11-05 04:58 - 01383936 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-11-11 16:52 - 2015-11-05 04:58 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-11 16:52 - 2015-11-05 04:56 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-11-11 16:52 - 2015-11-05 04:55 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2015-11-11 16:52 - 2015-11-05 04:54 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2015-11-11 16:52 - 2015-11-05 04:47 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-11-11 16:52 - 2015-11-05 04:42 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-11-11 16:52 - 2015-11-05 04:40 - 01918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-11-11 16:52 - 2015-11-05 04:35 - 18803712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-11-11 16:52 - 2015-11-05 04:35 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-11-11 16:52 - 2015-11-05 04:34 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2015-11-11 16:52 - 2015-11-05 04:33 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-11-11 16:52 - 2015-11-05 04:33 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-11-11 16:52 - 2015-11-05 04:30 - 00767488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-11-11 16:52 - 2015-11-05 04:28 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-11-11 16:52 - 2015-11-05 04:27 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2015-11-11 16:52 - 2015-11-05 04:27 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-11-11 16:52 - 2015-11-05 04:23 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2015-11-08 20:25 - 2015-11-08 20:25 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Crisis_Point_Extinction
2015-11-08 16:20 - 2015-11-08 16:20 - 17164524 _____ C:\Users\Nico ****\Downloads\Crisis Point - v.13.zip
2015-11-08 16:20 - 2015-11-08 16:20 - 00000000 ____D C:\Users\Nico ****\Desktop\crisis point
2015-11-08 13:45 - 2015-11-08 13:45 - 00003930 _____ C:\Users\Nico ****\Desktop\500 50+ ID's.txt
2015-11-08 13:11 - 2015-11-08 13:46 - 00000113 _____ C:\Users\Nico ****\Desktop\8h Cascade.txt
2015-11-08 13:04 - 2015-11-08 13:04 - 00000660 _____ C:\Users\Nico ****\Desktop\accounts.txt
2015-11-07 18:33 - 2015-12-06 18:21 - 00000000 ____D C:\Users\Nico ****\Desktop\KAROÜBERRASCHUNG
2015-11-07 12:22 - 2015-11-07 12:27 - 223137808 _____ C:\Users\Nico ****\Downloads\Slim_mini_gapps.ALPHA.6.0.build.0.x-20151106.zip
2015-11-07 10:48 - 2015-11-07 10:48 - 06762072 _____ (Piriform Ltd) C:\Users\Nico ****\Downloads\ccsetup511.exe
2015-11-07 10:42 - 2015-11-07 10:42 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\LastPass
2015-11-06 22:49 - 2015-11-06 22:50 - 55334400 _____ C:\Users\Nico ****\Downloads\FontPack11009_XtdAlf_Lang.msi
2015-11-06 22:46 - 2015-11-06 22:46 - 03963591 _____ C:\Users\Nico ****\Downloads\Nico****.pdf
2015-11-06 22:40 - 2015-11-06 22:40 - 00001149 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
2015-11-06 22:40 - 2015-11-06 22:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2015-11-06 22:40 - 2015-10-15 15:49 - 00964928 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxDrv.sys
2015-11-06 22:40 - 2015-10-15 15:49 - 00138904 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxUSBMon.sys
2015-11-06 22:35 - 2015-11-06 22:38 - 117095112 _____ (Oracle Corporation) C:\Users\Nico ****\Downloads\VirtualBox-5.0.8-103449-Win.exe
2015-11-06 22:28 - 2015-11-06 22:45 - 571322368 _____ C:\Users\Nico ****\Downloads\xpsp3_5512.080413-2113_usa_x86fre_spcd.iso
2015-11-06 18:56 - 2015-12-06 20:41 - 00000000 ____D C:\Users\Nico ****\AppData\LocalLow\LastPass
2015-11-06 18:56 - 2015-11-06 18:56 - 00001158 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk
2015-11-06 18:56 - 2015-11-06 18:56 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
2015-11-06 18:56 - 2015-11-06 18:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastPass
2015-11-06 18:54 - 2015-11-06 18:55 - 20320792 _____ (LastPass) C:\Users\Nico ****\Downloads\lastpass_x64(1).exe

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-12-06 22:43 - 2014-06-08 15:00 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-12-06 22:00 - 2014-08-08 18:04 - 00001128 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-06 21:55 - 2015-07-10 10:05 - 00000000 ____D C:\Windows
2015-12-06 21:08 - 2014-10-13 21:02 - 00000000 ____D C:\LazyPressing
2015-12-06 20:52 - 2014-03-31 18:07 - 00000412 _____ C:\WINDOWS\Tasks\update-sys.job
2015-12-06 19:56 - 2014-03-31 18:07 - 00000412 _____ C:\WINDOWS\Tasks\update-S-1-5-21-2171699750-2845458332-3438301781-1001.job
2015-12-06 18:59 - 2014-01-15 01:01 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\Audacity
2015-12-06 18:41 - 2015-05-30 14:39 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-12-06 18:23 - 2014-01-11 18:49 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\OBS
2015-12-06 16:28 - 2015-08-16 13:41 - 00004150 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{482FA375-426E-4AE5-812B-617B25429D8D}
2015-12-06 15:42 - 2013-12-24 22:14 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\Skype
2015-12-06 14:23 - 2015-10-30 20:28 - 00000000 ___HD C:\$WINDOWS.~BT
2015-12-05 21:02 - 2015-08-19 22:08 - 00002252 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-05 19:17 - 2014-08-08 18:04 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-05 19:16 - 2015-11-05 21:14 - 00000000 _____ C:\hsrv.txt
2015-12-05 19:16 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-12-05 19:16 - 2013-11-29 00:25 - 00000000 ____D C:\ProgramData\NVIDIA
2015-12-05 19:15 - 2015-07-10 10:05 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2015-12-05 19:14 - 2014-10-04 19:11 - 00000000 ____D C:\Program Files (x86)\Steam
2015-12-05 18:58 - 2015-07-10 13:20 - 04344080 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-12-05 18:58 - 2013-11-29 21:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-12-05 14:43 - 2015-01-31 13:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-12-05 14:43 - 2014-03-23 12:53 - 00000000 ____D C:\ProgramData\Apple Computer
2015-12-05 14:43 - 2014-03-23 12:52 - 00000000 ____D C:\ProgramData\Apple
2015-12-05 14:43 - 2014-02-19 19:03 - 00000000 ____D C:\Program Files (x86)\QuickTime
2015-12-05 14:42 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-05 13:14 - 2014-08-16 14:38 - 00007593 _____ C:\Users\Nico ****\AppData\Local\Resmon.ResmonCfg
2015-12-05 00:55 - 2014-08-08 18:04 - 00004186 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-05 00:55 - 2014-08-08 18:04 - 00003954 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-04 20:42 - 2014-03-16 19:02 - 00000000 ____D C:\Users\Nico ****\Documents\Adobe
2015-12-04 15:44 - 2015-10-18 04:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-12-04 14:01 - 2015-07-10 12:04 - 00000000 ___HD C:\Program Files\WindowsApps
2015-12-03 20:43 - 2015-08-16 12:41 - 00000000 ____D C:\Users\Nico ****
2015-12-02 14:17 - 2013-11-29 21:45 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Adobe
2015-12-01 14:15 - 2015-05-24 08:23 - 00000000 ____D C:\ProgramData\ProductData
2015-11-29 17:40 - 2014-03-27 19:36 - 00000000 ____D C:\Users\Nico ****\AppData\Local\fabi.me
2015-11-26 13:58 - 2015-08-09 22:14 - 00000000 ___RD C:\Users\Nico ****\Google Drive
2015-11-26 13:57 - 2015-08-09 22:12 - 00002115 _____ C:\Users\Public\Desktop\Google Slides.lnk
2015-11-26 13:57 - 2015-08-09 22:12 - 00002113 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2015-11-26 13:57 - 2015-08-09 22:12 - 00002103 _____ C:\Users\Public\Desktop\Google Docs.lnk
2015-11-26 13:57 - 2015-08-09 22:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-11-24 20:41 - 2014-04-25 01:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Process Hacker 2
2015-11-24 20:41 - 2014-04-25 01:18 - 00000000 ____D C:\Program Files\Process Hacker 2
2015-11-24 20:30 - 2015-08-19 13:16 - 00003632 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2015-11-20 19:02 - 2015-07-10 12:02 - 00000000 ____D C:\WINDOWS\INF
2015-11-20 19:02 - 2014-03-13 20:03 - 00000000 ____D C:\temp
2015-11-20 19:02 - 2013-11-29 22:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-11-20 19:02 - 2013-11-29 00:24 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-11-19 15:05 - 2015-09-27 00:02 - 00000000 ____D C:\Users\Nico ****\.VirtualBox
2015-11-19 15:04 - 2014-01-24 21:00 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\BitTorrent
2015-11-18 13:57 - 2015-07-16 12:16 - 00001142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remotr Streamer.lnk
2015-11-18 13:57 - 2015-07-16 12:16 - 00000000 ____D C:\Program Files (x86)\Remotr
2015-11-17 18:32 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-11-17 07:27 - 2015-08-16 14:03 - 11228816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2015-11-16 04:54 - 2015-08-16 14:03 - 18487360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2015-11-16 04:54 - 2015-08-16 14:03 - 15933400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2015-11-16 04:54 - 2015-08-16 14:03 - 12870192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2015-11-16 04:54 - 2015-08-16 14:03 - 03540544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2015-11-16 04:54 - 2015-08-16 14:03 - 03126800 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2015-11-16 04:54 - 2015-08-16 14:03 - 00034494 _____ C:\WINDOWS\system32\nvinfo.pb
2015-11-16 04:54 - 2015-06-29 08:52 - 01572496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2015-11-16 04:54 - 2015-06-29 08:52 - 00205456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2015-11-16 04:54 - 2013-11-29 00:24 - 00112944 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2015-11-16 04:54 - 2013-11-29 00:24 - 00105080 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2015-11-14 23:47 - 2014-03-28 17:25 - 00000000 ____D C:\Users\Nico ****\AppData\Local\JDownloader v2.0
2015-11-14 23:06 - 2015-10-10 14:02 - 00000000 ____D C:\Users\Nico ****\Desktop\Filme
2015-11-14 22:54 - 2014-03-30 14:29 - 00000000 ____D C:\Users\Nico ****\Documents\My Games
2015-11-14 21:49 - 2014-05-24 07:54 - 00000000 ___HD C:\WINDOWS\msdownld.tmp
2015-11-14 15:54 - 2015-04-19 20:07 - 00000080 _____ C:\Users\Nico ****\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦
2015-11-14 14:11 - 2015-10-24 16:38 - 00000000 ____D C:\Aptana Stuido
2015-11-14 11:01 - 2014-10-04 19:29 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-11-14 07:20 - 2013-11-29 00:25 - 06358648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-11-14 07:20 - 2013-11-29 00:25 - 02983216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2015-11-14 07:20 - 2013-11-29 00:25 - 02554488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-11-14 07:20 - 2013-11-29 00:25 - 00938616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-11-14 07:20 - 2013-11-29 00:25 - 00062584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-11-14 07:20 - 2013-11-29 00:24 - 00385144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-11-14 00:20 - 2014-04-14 17:53 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Battle.net
2015-11-13 19:25 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\rescache
2015-11-13 18:40 - 2014-12-14 14:00 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-11-13 16:42 - 2015-08-16 13:05 - 01790124 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-13 16:42 - 2015-07-10 17:34 - 00771100 _____ C:\WINDOWS\system32\perfh007.dat
2015-11-13 16:42 - 2015-07-10 17:34 - 00153964 _____ C:\WINDOWS\system32\perfc007.dat
2015-11-12 21:41 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-12 15:36 - 2013-11-29 23:02 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-11-12 15:35 - 2013-11-29 23:01 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-12 15:23 - 2013-11-29 21:12 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-11-12 15:14 - 2013-11-29 21:12 - 145617392 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-11-12 15:13 - 2013-08-22 14:25 - 00000167 _____ C:\WINDOWS\win.ini
2015-11-11 19:44 - 2015-04-16 20:14 - 00000000 ____D C:\Users\Nico ****\Desktop\GTA
2015-11-11 16:43 - 2014-06-08 15:00 - 00003870 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-11-09 14:22 - 2015-07-16 12:16 - 00000000 ____D C:\ProgramData\Remotr
2015-11-08 22:37 - 2014-09-16 19:04 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Genymobile
2015-11-08 13:38 - 2015-10-28 15:17 - 00000185 _____ C:\Users\Nico ****\Desktop\Spamips.txt
2015-11-08 00:25 - 2014-06-29 12:45 - 00000000 ___RD C:\Users\Nico ****\Creative Cloud Files
2015-11-07 18:32 - 2014-01-11 18:49 - 00000000 ____D C:\Program Files\OBS
2015-11-07 10:56 - 2015-09-10 15:33 - 00000000 ____D C:\Program Files (x86)\WinPcap
2015-11-07 10:56 - 2015-01-04 19:59 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\Wireshark
2015-11-07 10:56 - 2014-12-16 13:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2015-11-07 10:56 - 2014-08-01 21:28 - 00000000 ____D C:\Users\Nico ****\AppData\Local\paint.net
2015-11-07 10:56 - 2014-05-24 12:48 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\Thunderbird
2015-11-07 10:56 - 2013-11-29 23:01 - 00000000 ____D C:\Users\Nico ****\AppData\Local\Microsoft Help
2015-11-07 10:50 - 2014-12-26 01:23 - 00003014 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-11-07 10:45 - 2015-01-15 15:51 - 00000000 ____D C:\Users\Nico ****\AppData\Roaming\KeePass
2015-11-06 19:00 - 2015-03-14 17:42 - 00003454 _____ C:\Users\Nico ****\Documents\daten.kdbx
2015-11-06 18:57 - 2015-11-02 14:50 - 00000000 ____D C:\Program Files (x86)\LastPass

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2015-11-06 18:57 - 2015-11-06 18:57 - 20320792 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2014-02-23 16:22 - 2014-02-23 16:22 - 1213440 _____ () C:\Users\Nico ****\AppData\Roaming\21390.exe
2014-02-23 16:21 - 2014-02-23 16:21 - 1213440 _____ () C:\Users\Nico ****\AppData\Roaming\55d77.exe
2014-03-17 17:12 - 2014-05-31 19:13 - 0000132 _____ () C:\Users\Nico ****\AppData\Roaming\Adobe IllExport-Filter CC - Voreinstellungen
2014-04-21 15:14 - 2014-04-21 16:05 - 0000132 _____ () C:\Users\Nico ****\AppData\Roaming\Adobe PNG Format CS5 Prefs
2014-01-15 01:17 - 2014-06-29 09:55 - 0000132 _____ () C:\Users\Nico ****\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen
2014-08-07 18:56 - 2015-08-10 09:10 - 0000034 _____ () C:\Users\Nico ****\AppData\Roaming\AdobeWLCMCache.dat
2014-02-23 16:21 - 2014-09-03 16:32 - 0000152 _____ () C:\Users\Nico ****\AppData\Roaming\config.ini
2015-11-05 21:07 - 2015-11-05 21:16 - 0002732 _____ () C:\Users\Nico ****\AppData\Roaming\droid4xinstaller.log
2015-08-08 10:35 - 2015-08-08 10:35 - 0000000 _____ () C:\Users\Nico ****\AppData\Roaming\Stardockfences_debug_snapshot.dat
2015-06-24 13:04 - 2015-06-23 18:55 - 0178176 _____ () C:\Users\Nico ****\AppData\Roaming\TMP01.txt
2014-04-28 00:38 - 2014-08-26 17:04 - 0001839 _____ () C:\Users\Nico ****\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2014-01-11 19:56 - 2014-01-12 16:24 - 0005632 _____ () C:\Users\Nico ****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-02-20 17:08 - 2015-02-20 17:09 - 0000026 _____ () C:\Users\Nico ****\AppData\Local\isoworkshop.ini
2015-03-14 20:50 - 2015-03-14 20:50 - 0000000 ___SH () C:\Users\Nico ****\AppData\Local\LumaEmu
2014-08-16 14:38 - 2015-12-05 13:14 - 0007593 _____ () C:\Users\Nico ****\AppData\Local\Resmon.ResmonCfg
2014-03-31 18:07 - 2014-03-31 18:07 - 0000003 _____ () C:\Users\Nico ****\AppData\Local\updater.log
2014-03-31 18:07 - 2015-10-03 10:56 - 0000424 _____ () C:\Users\Nico ****\AppData\Local\UserProducts.xml
2014-10-23 19:54 - 2014-10-23 19:54 - 0314151 _____ () C:\ProgramData\1414090333.bdinstall.bin
2015-08-16 12:37 - 2015-08-16 12:37 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-05-10 11:06 - 2014-03-11 11:06 - 0000032 ____R () C:\ProgramData\hash.dat
2014-03-16 03:42 - 2015-05-13 18:38 - 0000213 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\ProgramData\hash.dat


Einige Dateien in TEMP:
====================
C:\Users\Nico ****\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Nico ****\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Nico ****\AppData\Local\Temp\nvStInst.exe
C:\Users\Nico ****\AppData\Local\Temp\processhacker-2.36-setup.exe


Einige mit null Byte Größe Dateien/Ordner:
==========================
C:\Windows\System32\BDSandBoxUH.dll
C:\Windows\System32\BDSandBoxUISkin.dll
C:\Windows\System32\BDSandBoxUISkin32.dll

==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2015-12-04 17:11

==================== Ende von FRST.txt ============================
         
__________________

Alt 06.12.2015, 22:51   #4
zeVra
 
Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert? - Standard

Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert?



Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-12-2015
durchgeführt von Nico (2015-12-06 22:46:52)
Gestartet von C:\Users\Nico ****\Desktop
Windows 10 Pro (X64) (2015-08-16 12:15:01)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-2171699750-2845458332-3438301781-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2171699750-2845458332-3438301781-503 - Limited - Disabled)
Gast (S-1-5-21-2171699750-2845458332-3438301781-501 - Limited - Disabled)
Nico (S-1-5-21-2171699750-2845458332-3438301781-1001 - Administrator - Enabled) => C:\Users\Nico ****
PaiNkiiT (S-1-5-21-2171699750-2845458332-3438301781-1007 - Limited - Enabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

µTorrent (HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\uTorrent) (Version: 3.4.3.40760 - BitTorrent Inc.)
4K Stogram 1.9 (HKLM-x32\...\4K Stogram_is1) (Version: 1.9.4.944 - Open Media LLC)
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version:  - )
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Action! (HKLM-x32\...\Mirillis Action!) (Version: 1.18.0 - Mirillis)
Adobe After Effects CC 2015 (HKLM-x32\...\{147EC100-14BE-45EF-AB42-35BAEE7D02F0}) (Version: 13.5.1 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 19.0.0.213 - Adobe Systems Incorporated)
Adobe Bridge CC (64 Bit) (HKLM-x32\...\{359F8007-6486-429C-A8C5-D67F6897C88C}) (Version: 6.0 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.2.0.129 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Professional CC 2015 (HKLM-x32\...\{31390329-FFF0-11E4-85AD-AF2C4143F080}) (Version: 15.0 - Adobe Systems Incorporated)
Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.1.1 - Adobe Systems Incorporated)
Adobe Media Encoder CC 2015 (HKLM-x32\...\{0FAC7130-BEC5-47A5-8813-1D339B8326ED}) (Version: 9.0.1 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0.1 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2014 (HKLM-x32\...\{07BE616F-9E42-4C90-AF4F-0F32A5B088E7}) (Version: 8.2.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.13) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
AdVenture Capitalist (HKLM-x32\...\Steam App 346900) (Version:  - Hyper Hippo Games)
Aeria Ignite (HKLM-x32\...\Aeria Ignite 1.13.3296) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (HKLM-x32\...\Aeria Ignite) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (x32 Version: 1.13.3296 - Aeria Games & Entertainment) Hidden
Akamai NetSession Interface (HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Android SDK Tools (HKLM-x32\...\Android SDK Tools) (Version: 1.16 - Google Inc.)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Aptana Studio (HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Aptana Studio 3.6.0) (Version: 3.6.0 - Appcelerator)
Aptana Studio (x32 Version: 3.6.0 - Appcelerator) Hidden
Audacity 2.0.6 (HKLM-x32\...\Audacity_is1) (Version: 2.0.6 - Audacity Team)
Auslogics DiskDefrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 4.5.5.0 - Auslogics Labs Pty Ltd)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bitcoin Core (64-bit) (HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Bitcoin Core (64-bit)) (Version: 0.10.2 - Bitcoin Core project)
BitTorrent (HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\BitTorrent) (Version: 7.9.5.41203 - BitTorrent Inc.)
BlueStacks App Player (HKLM-x32\...\{D7E3588F-25E6-4A93-8B1C-596F7951CA38}) (Version: 0.10.7.5601 - BlueStack Systems, Inc.)
Call of Duty: Black Ops II - Zombies (HKLM-x32\...\Steam App 212910) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.11 - Piriform)
Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version:  - Cheat Engine)
Chrome Remote Desktop Host (HKLM-x32\...\{CDF9E1C8-4B97-4F8B-A848-7DD0E8BEB89F}) (Version: 47.0.2526.18 - Google Inc.)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
Clicker Heroes (HKLM-x32\...\Steam App 363970) (Version:  - )
ClipGrab 3.5.1 (HKLM-x32\...\{8A1033B0-EF33-4FB5-97A1-C47A7DCDD7E6}_is1) (Version:  - Philipp Schmieder Medien)
Color Suite v11.0.4 (HKLM-x32\...\{99487911-8011-42BC-B594-8B02BFD32B1D}_is1) (Version: 11.0.4 - Red Giant, LLC)
CPUID CPU-Z 1.74 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Curse (HKLM-x32\...\{1F2611FB-6F69-4AA8-BECD-243BD8CB45F3}) (Version: 6.0.0.0 - Curse)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Pro (HKLM-x32\...\DAEMON Tools Pro) (Version: 6.0.0.0444 - Disc Soft Ltd)
DarkComet RAT Remover version 1.0 (HKLM-x32\...\DarkComet RAT Remover_is1) (Version: 1.0 - Phrozen ® Software 2012.)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.64 - DivX, LLC)
Don't Starve (HKLM-x32\...\Steam App 219740) (Version:  - Klei Entertainment)
Driver (HKLM-x32\...\{C9A7E6A6-110D-4DBC-A8E2-F634613B5A8C}_is1) (Version:  - TCL Commumication Technology Holdings Limited)
Driver Booster 2.3 (HKLM-x32\...\Driver Booster_is1) (Version: 2.3 - IObit)
Droid4X (HKLM-x32\...\Droid4X) (Version: 0.8.5 - Haiyu Dongxiang Co.,Ltd.)
DuOS (HKLM\...\{8CE9E5DD-D523-44F2-8DE7-0439310EA984}) (Version: 2.0.3.7527 - American Megatrends Inc.)
EventGhost 0.4.1.r1700 (HKLM-x32\...\EventGhost_is1) (Version: 0.4.1.r1700 - EventGhost Project)
Exact Audio Copy 1.1 (HKLM-x32\...\Exact Audio Copy) (Version: 1.1 - Andre Wiethoff)
Extended Asian Language font pack for Adobe Reader XI (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-A00000000049}) (Version: 11.0.09 - Adobe Systems Incorporated)
f.lux (HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\Flux) (Version:  - )
Fallout 4 German Language Pack (HKLM-x32\...\Fallout 4 German Language Pack_is1) (Version:  - )
Fallout 4 version 1.0.0 (HKLM-x32\...\Fallout 4_is1) (Version: 1.0.0 - Bethesda Studios)
File Shredder 2.5 (HKLM\...\File Shredder_is1) (Version:  - Pow Tools)
Findus4 (HKLM-x32\...\Findus4) (Version:  - )
Font Validator (HKLM-x32\...\{330A929A-F800-4457-9706-DF19224D9770}) (Version: 1.0.0 - Microsoft)
Fotogalerie (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Freemake Video Converter Version 4.1.5 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.5 - Ellora Assets Corporation)
freeSSHd 1.3.1 (HKLM-x32\...\70DBC326-7505-4913-A0C1-C6BD87C1859D_is1) (Version:  - Kresimir Petric)
Gamepad 3 TURBO (HKLM-x32\...\{FEC7CD2E-2BB5-40C3-9592-078F64677E6C}) (Version: 1.00.0000 - GASIA)
Genymotion version 2.5.4 (HKLM\...\{6D180286-D4DF-40EF-9227-923B9C07C08A}_is1) (Version: 2.5.4 - Genymobile)
Gif Recorder (HKLM-x32\...\{149895C0-6D91-4670-8BDC-BCB848EAFE3E}) (Version: 3.1 - AGORA Software BV)
Git version 1.8.4-preview20130916 (HKLM-x32\...\Git_is1) (Version: 1.8.4-preview20130916 - The Git Development Community)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.73 - Google Inc.)
Google Drive (HKLM-x32\...\{1C3D2F92-D25E-4D98-B810-3F3B0857BF26}) (Version: 1.26.0707.2863 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
Gpg4win (2.2.3) (HKLM-x32\...\GPG4Win) (Version: 2.2.3 - The Gpg4win Project)
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto IV (x32 Version: 1.0.0011.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto V (HKLM-x32\...\{E01FA564-2094-4833-8F2F-1FFEC6AFCC46}) (Version: "1.00.0000" - Rockstar Games)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Hotfix für Microsoft Visual Basic 2010 Express - DEU (KB2635973) (HKLM-x32\...\{CCAC7E52-ECCE-3C4D-B1BE-BC2ACF1C1C0E}.KB2635973) (Version: 1 - Microsoft Corporation)
Intel Android Device USB driver (HKLM\...\Intel Android Device USB driver) (Version: 1.10.0 - Intel)
ISO Workshop 5.8 (HKLM-x32\...\ISO Workshop_is1) (Version:  - Glorylogic)
Java 8 Update 65 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Java SE Development Kit 7 Update 79 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170790}) (Version: 1.7.0.790 - Oracle)
Java SE Development Kit 8 Update 60 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180600}) (Version: 8.0.600.27 - Oracle Corporation)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
KC Softwares Zer0 (HKLM-x32\...\KC Softwares Zer0_is1) (Version:  - KC Softwares)
KeePass Password Safe 2.28 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.28 - Dominik Reichl)
KMSpico v9.1.0.20131125 (Beta) (HKLM\...\KMSpico_is1) (Version: 9.1.0.20131125 - )
Kung Fury Street Rage version 1.0 (HKLM-x32\...\{9AD03FB9-CFCF-4526-9C47-F1EE11513E38}_is1) (Version: 1.0 - )
LADSPA_plugins-win-0.4.15 (HKLM-x32\...\LADSPA_plugins-win_is1) (Version:  - Audacity Team)
Lagarith Lossless Codec (1.3.27) (HKLM-x32\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version:  - )
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
LastPass (Nur deinstallieren) (HKLM-x32\...\LastPass) (Version:  - LastPass)
Launcher for Skype (HKLM-x32\...\{82799854-39DF-4EC3-8778-918CE0C81A3F}_is1) (Version: 1.6.8 - binaerkombinat)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
LEGO MINDSTORMS NXT - (Deutsch) Sprachenpaket (HKLM-x32\...\{4614C36E-AABF-42AD-9419-0B8051547B96}) (Version: 2.0.100.0 - The LEGO Group)
LEGO MINDSTORMS NXT Driver for x64 (HKLM\...\{74E85F31-573F-45BF-8939-4D2BCDCC2083}) (Version: 1.17.770 - LEGO)
LEGO MINDSTORMS NXT Migration Package (HKLM-x32\...\{6C1D47CC-682C-4673-8CA8-DEE659628599}) (Version: 1.2.8.0 - LEGO)
LEGO MINDSTORMS NXT Software v2.0 (HKLM-x32\...\{5B7EDCF8-E6AD-4E99-972C-34BF1F07B349}) (Version: 2.0.114.0 - LEGO)
Lightshot-5.3.0.0 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.3.0.0 - Skillbrains)
LINE (HKLM-x32\...\LINE) (Version: 4.2.1.678 - LINE Corporation)
LOOT (HKLM-x32\...\LOOT) (Version: 0.7.0 - LOOT Development Team)
Macromedia Extension Manager (HKLM-x32\...\{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}) (Version: 1.7.240 - Macromedia, Inc.)
Macromedia Flash 8 Video Encoder (HKLM-x32\...\{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}) (Version: 1.00.0000 - Macromedia)
Macromedia Flash Player 8 Plugin (HKLM-x32\...\{91057632-CA70-413C-B628-2D3CDBBB906B}) (Version: 8.0.22.0 - Macromedia)
Magic Bullet PhotoLooks (HKLM-x32\...\Magic Bullet PhotoLooks) (Version:  - )
Magic Bullet Suite 64-bit (HKLM-x32\...\InstallShield_{26055432-339E-4776-803B-F22240B91864}) (Version: 11.1.2 - Red Giant Software)
Magic Bullet Suite 64-bit (HKLM-x32\...\InstallShield_{E7676EF4-3896-4B7E-B030-1356EEC477CE}) (Version: 11.4.4 - Red Giant)
Magic Bullet Suite 64-bit (Version: 11.1.2 - Red Giant Software) Hidden
Magic Bullet Suite 64-bit (Version: 11.4.4 - Red Giant) Hidden
Magic ISO Maker v5.5 (build 0281) (HKLM-x32\...\Magic ISO Maker v5.5 (build 0281)) (Version:  - )
ManyCam 3.0.80 (remove only) (HKLM-x32\...\ManyCam) (Version: 3.0.80 - ManyCam LLC)
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 1.0 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.0 Language Pack - DEU) (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation)
Microsoft Help Viewer 1.1 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.1 Language Pack - DEU) (Version: 1.1.40219 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{E9089B6A-1FDE-47F3-8D29-175F5B7A0722}) (Version: 10.50.1750.9 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{0125D081-30D0-4A97-82A8-C28D444B6256}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 DEU (HKLM\...\{C3EAE456-7E7A-451F-80EF-F34C7A13C558}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{C668416A-9213-4058-B7F2-01A42D85559D}) (Version: 10.50.1750.9 - Microsoft Corporation)
Microsoft Visual Basic 2010 Express - DEU (HKLM-x32\...\Microsoft Visual Basic 2010 Express - DEU) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Runtime - 10.0.40219 (HKLM\...\{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\...\{616C6F39-4CE1-3434-A665-2F6A04C09A7F}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU (HKLM\...\{3C983A67-DFB2-3D3D-AD9E-CA1A5A09FD18}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Service Pack 1 (HKLM-x32\...\Microsoft Visual Studio 2010 Service Pack 1) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
MinerGate (HKLM-x32\...\MinerGate) (Version: 5.06 - Minergate Inc)
mIRC (HKLM-x32\...\mIRC) (Version: 7.38 - mIRC Co. Ltd.)
MK LOL (HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\MK LOL) (Version:  - )
Mobizen (HKLM-x32\...\{BA0D3A44-BCEE-4C8B-BCD4-F7F1E64F41E3}) (Version: 2.17.0.1 - RSUPPORT)
MotioninJoy Gamepad tool 0.7.1001 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.1001 - www.motioninjoy.com)
Mouse and Keyboard Recorder 3.2.0.8 (HKLM-x32\...\{3408E5D6-4925-4496-AB67-AB8643C3685C}_is1) (Version:  - Robot-Soft.com, Inc.)
Movie Maker (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Mozilla Firefox 42.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
Mozilla Thunderbird 31.7.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.7.0 (x86 de)) (Version: 31.7.0 - Mozilla)
Mp3tag v2.71 (HKLM-x32\...\Mp3tag) (Version: v2.71 - Florian Heidenreich)
Node.js (HKLM-x32\...\{2D41A012-35EE-4724-AE8E-E592EDD9F89D}) (Version: 0.10.13 - Joyent, Inc. and other Node contributors)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.7.4 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 359.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 359.00 - NVIDIA Corporation)
NVIDIA DDS Utilities (HKLM-x32\...\{64963F0E-03F2-4B59-8D1B-1806545E7092}) (Version: 1.0 - )
NVIDIA GeForce Experience 2.5.15.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.15.54 - NVIDIA Corporation)
NVIDIA Grafiktreiber 359.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 359.00 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
NVIDIA Miracast Virtueller Ton 353.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 353.30 - NVIDIA Corporation)
NVIDIA Photoshop Plug-ins 64 bit (HKLM-x32\...\{5E386C5B-CDE7-435A-B5C9-EC73A1B0553A}) (Version: 8.50 - )
NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Oddworld Strangers Wrath HD (HKLM-x32\...\Oddworld Strangers Wrath HD_is1) (Version: 2.0.0.0 - )
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
OpenIV (HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\OpenIV) (Version: 2.6.4.642 - .black/OpenIV Team)
OpenVPN 2.3.2-I200 (uac/max_config build) (HKLM-x32\...\OpenVPN) (Version: 2.3.2-I200 - )
Oracle VM VirtualBox 5.0.8 (HKLM\...\{C1B8ECDB-4DB0-47ED-B9CE-61638F876B0F}) (Version: 5.0.8 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.7.2.53208 - Electronic Arts, Inc.)
osu! (HKLM-x32\...\{01b234a2-bdf1-4f8f-ad9a-b06d31f0de0c}) (Version: latest - ppy Pty Ltd)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Paint the Town Red (HKLM-x32\...\Steam App 337320) (Version:  - South East Games)
paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC)
Pamela RME 2.0 (HKLM-x32\...\MoodEditor) (Version: 2.0 - Scendix Software-Vertriebsges. mbH)
PAYDAY: The Heist (HKLM-x32\...\Steam App 24240) (Version:  - OVERKILL Software)
Pixel Fodder (HKLM-x32\...\air.com.wacha.pixelfodder) (Version: 0.8.142 - UNKNOWN)
Pixel Fodder (x32 Version: 0.8.142 - UNKNOWN) Hidden
Process Hacker 2.36 (r6153) (HKLM\...\Process_Hacker2_is1) (Version: 2.36.0.6153 - wj32)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickSFV (Remove only) (HKLM\...\QuickSFV) (Version:  - )
QuickTime (HKLM-x32\...\QuickTime) (Version:  - )
QuickTime 7 (HKLM-x32\...\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.)
RaidCall (HKLM-x32\...\RaidCall) (Version: 7.3.4-1.0.12889.86 - raidcall.com)
RAIDXpert (x32 Version: 3.2.1540.5 - AMD) Hidden
RAYEVEIL (HKLM-x32\...\RAYEVEIL) (Version:  - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7553 - Realtek Semiconductor Corp.)
Red Giant Link (HKLM-x32\...\{10F82E5B-B611-4C65-8F29-666A9EC5680A}_is1) (Version: 1.7.26.0 - Red Giant, LLC)
Remotr version 1.1.1183 (HKLM-x32\...\Remotr_is1) (Version: 1.1.1183 - RemoteMyApp sp. z o.o.)
Resource Hacker Version 3.6.0 (HKLM-x32\...\ResourceHacker_is1) (Version:  - )
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.6.8 - Rockstar Games)
Ruby 2.2.3-p173-x64 (HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\{A98E44F8-6401-400F-830E-B1A2919C22BD}_is1) (Version: 2.2.3-p173 - RubyInstaller Team)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.33.0 - SAMSUNG Electronics Co., Ltd.)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version:  - Microsoft)
SHIELD Streaming (Version: 4.1.500 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.5.15.54 - NVIDIA Corporation) Hidden
Shutdown Timer (HKLM\...\{0B1BBEE3-C10D-44BE-A6BE-EEC867315F87}) (Version: 3.3.4 - Sinvise Systems)
Skype™ 7.13 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.13.101 - Skype Technologies S.A.)
Smart Defrag 4 (HKLM-x32\...\Smart Defrag 4_is1) (Version: 4.2 - IObit)
Soundcloud Playlist Downloader (HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\35cf6f8efa605d1f) (Version: 1.0.0.36 - Soundcloud Playlist Downloader)
Speccy (HKLM\...\Speccy) (Version: 1.28 - Piriform)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
STAR WARS™ Battlefront™ Beta (HKLM-x32\...\{8A863B64-C9BE-4203-9ED7-92981CF690D3}) (Version: 1.0.3.51560 - Electronic Arts)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Super Hexagon (HKLM-x32\...\Super Hexagon_is1) (Version: 1.0 - compiled by testncrash)
Super Meat Boy (HKLM-x32\...\Steam App 40800) (Version:  - Team Meat)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1210 - SUPERAntiSpyware.com)
Surgeon Simulator (HKLM-x32\...\Steam App 233720) (Version:  - Bossa Studios)
System Requirements Lab (HKLM-x32\...\{0F659036-14C7-4622-9505-35A0DC93526A}) (Version: 6.1.3.0 - Husdawg, LLC)
System Requirements Lab Detection (HKLM-x32\...\{CDC8CF38-98EF-4716-9C1E-49FFD6F6538A}) (Version: 6.1.6.0 - Husdawg, LLC)
TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - )
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Telegram Desktop Version 0.7.6 (HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 0.7.6 - Telegram Messenger LLP)
The Binding of Isaac: Rebirth (HKLM-x32\...\Steam App 250900) (Version:  - Nicalis, Inc.)
The Sims 4 (HKLM-x32\...\The Sims 4_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, ProZorg_tm)
The Sims 4 Spa Day Addon Pack with Bonus (HKLM-x32\...\VGhlU2ltczQ=_is1) (Version: 1 - )
TI Connect™ (HKLM-x32\...\{D06BA64C-4447-49B4-B99D-E85BEA9E1035}) (Version: 4.0.0.218 - Texas Instruments Inc.)
Time Stopper (HKLM-x32\...\Time Stopper4.0) (Version: 4.0 - DilSoft)
Tom Clancy's Splinter Cell® Blacklist™ (HKLM-x32\...\{A6356F2F-D3E1-4D83-9AA2-72871DD0C298}) (Version: 1.01 - Ubisoft)
TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation)
TS3 Overlay (HKLM\...\TS3 Overlay) (Version: v3.0.16 - Rohrbacher Development)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Unchecky v0.4.1 (HKLM-x32\...\Unchecky) (Version: 0.4.1 - RaMMicHaeL)
Unity Web Player (HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\UnityWebPlayer) (Version: 5.0.3f2 - Unity Technologies ApS)
Unity Web Player (x64) (All users) (HKLM\...\UnityWebPlayer) (Version: 4.6.3f1 - Unity Technologies ApS)
Universal Adb Driver (HKLM-x32\...\{99687796-138F-4919-B96F-30A951C74473}) (Version: 1.0.2 - ClockworkMod)
Universal Adb Driver (HKLM-x32\...\{D9C4202E-6D51-4B06-A8F1-22316E654BCA}) (Version: 1.0.0 - ClockworkMod)
Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb)
Update for Skype for Business 2015 (KB2889853) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{0C5B0539-7EDE-4297-947E-48890971B557}) (Version:  - Microsoft)
USB Vibration Joystick (HKLM-x32\...\{4999B2F1-3E74-409A-B8B5-E94448AA9EA6}) (Version: 2007.08.17 - )
UxStyle (HKLM-x32\...\{05560347-3a9b-4644-a8ed-8b64cc947189}) (Version: 0.2.3.0 - The Within Network, LLC)
UxStyle (Version: 0.2.3.0 - The Within Network, LLC) Hidden
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Vegas Pro 13.0 (64-bit) (HKLM\...\{386F5740-091D-11E4-B13E-F04DA23A5C58}) (Version: 13.0.373 - Sony)
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{CFCB8616-A5D1-4281-80E8-389F685BFAE2}) (Version: 4.0.8080.0 - Microsoft Corporation)
VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN)
VPNAutoconnect (HKLM-x32\...\{8E557F21-99AE-440D-8058-CD8CB3302E13}) (Version: 1.15 - globalip)
Wacom Tablett (HKLM\...\Wacom Tablet Driver) (Version: 6.3.11-4 - Wacom Technology Corp.)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
Windows Driver Package - Texas Instruments Inc. (SilvrLnk) USB  (06/11/2009 1.0.0.0) (HKLM\...\EC3E466026556D3EB760B01C4772277614354E11) (Version: 06/11/2009 1.0.0.0 - Texas Instruments Inc.)
Windows Driver Package - Texas Instruments Inc. (TIEHDUSB) USB  (09/02/2009 1.0.0.1) (HKLM\...\7511B29C86C398B4D11A0B0E4176CAD68D1B7057) (Version: 09/02/2009 1.0.0.1 - Texas Instruments Inc.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3522.0110 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.11 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-E9AA2CEB5EC4}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => Keine Datei
CustomCLSID: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001_Classes\CLSID\{ca586c80-7c84-4b88-8537-726724df6929}\InprocServer32 -> C:\Program Files (x86)\Git\git-cheetah\git_shell_ext64.dll ()
CustomCLSID: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)

==================== Wiederherstellungspunkte =========================

17-11-2015 18:53:17 Windows Update
25-11-2015 16:52:40 Geplanter Prüfpunkt
04-12-2015 17:34:28 Geplanter Prüfpunkt

==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2013-08-22 14:25 - 2015-12-05 19:16 - 00005884 ___RA C:\WINDOWS\system32\Drivers\etc\hosts

‣潃祰楲桧⁴挨
㤱㌹㈭〰‹楍牣獯景⁴潃灲മ⌊਍‣桔獩椠⁳⁡慳灭敬䠠协協映汩⁥獵摥戠⁹楍牣獯景⁴䍔⽐偉映牯圠湩潤獷മ⌊਍‣桔獩映汩⁥潣瑮楡獮琠敨洠灡楰杮⁳景䤠⁐摡牤獥敳⁳潴栠獯⁴慮敭⹳䔠捡൨⌊攠瑮祲猠潨汵⁤敢欠灥⁴湯愠湩楤楶畤污氠湩⹥吠敨䤠⁐摡牤獥⁳桳畯摬਍‣敢瀠慬散⁤湩琠敨映物瑳挠汯浵潦汬睯摥戠⁹桴⁥潣牲獥潰摮湩⁧潨瑳渠浡⹥਍‣桔⁥偉愠摤敲獳愠摮琠敨栠獯⁴慮敭猠潨汵⁤敢猠灥牡瑡摥戠⁹瑡氠慥瑳漠敮਍‣灳捡⹥਍ണ⌊䄠摤瑩潩慮汬ⱹ挠浯敭瑮⁳猨捵⁨獡琠敨敳
慭⁹敢椠獮牥整⁤湯椠摮癩摩慵൬⌊氠湩獥漠⁲潦汬睯湩⁧桴⁥慭档湩⁥慮敭搠湥瑯摥戠⁹⁡⌧‧祳扭汯മ⌊਍‣潆⁲硥浡汰㩥਍ണ⌊†††〱⸲㐵㤮⸴㜹††爠楨潮愮浣⹥潣††††⌠猠畯捲⁥敳癲牥਍‣†††㠳㈮⸵㌶ㄮ‰††⹸捡敭挮浯†††††††‣⁸汣敩瑮栠獯൴ഊ⌊氠捯污潨瑳渠浡⁥敲潳畬楴湯椠⁳慨摮敬⁤楷桴湩䐠华椠獴汥⹦਍ण㈱⸷⸰⸰‱†††潬慣桬獯൴⌊㨉ㄺ††††††氠捯污潨瑳਍㈱⸷⸰⸰‱†††††††††桴獩楬敮歳灩慳祮浥瑰汹湩獥਍㈱⸷⸰⸰‱†††††††††業楲汬獩挮浯਍㈱⸷⸰⸰‱†††††††††睷⹷業楲汬獩挮浯਍㈱⸷⸰⸰‱†††††††††敳睲牥⸲慰慫猭牥楶散挮浯਍㈱⸷⸰⸰‱†††††††††獮㠳ㄶ㤱漮桶渮瑥਍㈱⸷⸰⸰‱†††††††††業楲汬獩瀮൬
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ਍                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ਍                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ਍਍‣湵档捥祫扟来湩਍‣桔獥⁥畲敬⁳敷敲愠摤摥戠⁹桴⁥湕档捥祫瀠潲牧浡椠牯敤⁲潴戠潬正愠癤牥楴楳杮猠景睴牡⁥潭畤敬൳《〮〮〮〠〮〮〮⌠映硩映牯琠慲散潲瑵⁥湡⁤敮獴慴⁴楤灳慬⁹湡浯污൹《〮〮〮琠慲正湩⹧灯湥慣摮⹹潣⹭㍳愮慭潺慮獷挮浯਍⸰⸰⸰‰敭楤⹡灯湥慣摮⹹潣൭《〮〮〮挠湤漮数据湡祤挮浯਍⸰⸰⸰‰牴捡楫杮漮数据湡祤挮浯਍⸰⸰⸰‰灡⹩灯湥慣摮⹹潣൭《〮〮〮愠楰爮捥浯敭摮摥睳挮浯਍⸰⸰⸰‰湩瑳污敬⹲敢瑴牥湩瑳污敬⹲潣൭《〮〮〮椠獮慴汬牥昮汩扥汵摬杯挮浯਍⸰⸰⸰‰㍤硯湴砱戳搸椷挮潬摵牦湯⹴敮൴《〮〮〮椠湮⹯楢牳⹶潣൭《〮〮〮渠楳⹳楢牳⹶潣൭《〮〮〮挠湤昮汩㉥敤歳潴⹰潣൭《〮〮〮挠湤朮慯整獡捴捡⹨獵਍⸰⸰⸰‰摣⹮畧瑴獡慴摴⹫獵਍⸰⸰⸰‰摣⹮湩歳湩敭楤⹡潣൭《〮〮〮挠湤椮獮慴漮扩湵汤獥⸲潣൭《〮〮〮挠湤椮獮慴瀮慬批祲整挮浯਍⸰⸰⸰‰摣⹮汬杯瑥慦瑳慣档甮൳《〮〮〮挠湤洮湯楴牥⹡潣൭《〮〮〮挠湤洮摳湷摬挮浯਍⸰⸰⸰‰摣⹮祭捰慢正灵挮浯਍⸰⸰⸰‰摣⹮灰潤湷潬摡挮浯਍⸰⸰⸰‰摣⹮楲散瑡慥瑳慣档甮൳《〮〮〮挠湤献票灡瑯瑡⹯獵਍⸰⸰⸰‰摣⹮潳楬扭⹡潣൭《〮〮〮挠湤琮瑵㑯捰挮浯਍⸰⸰⸰‰摣⹮灡牰畯摮戮穩਍⸰⸰⸰‰摣⹮楢獧数摥牰⹯潣൭《〮〮〮挠湤戮獩摰挮浯਍⸰⸰⸰‰摣⹮楢牳⹶潣൭《〮〮〮挠湤挮湤灤挮浯਍⸰⸰⸰‰摣⹮潤湷潬摡献敷瑥慰正⹳潣൭《〮〮〮挠湤搮摰睯汮慯⹤潣൭《〮〮〮挠湤瘮獩慵扬敥渮瑥਍‣湵档捥祫敟摮਍

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {155D2CBF-19B9-45FE-A64B-DDD7D45044E8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-10-19] (Piriform Ltd)
Task: {1F9D8035-C4BD-4309-9C8B-539E628F4C12} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {2E1F992E-342D-45BB-BDEA-0BB7ABA9322A} - System32\Tasks\CreateExplorerShellUnelevatedTask => /NOUACCHECK
Task: {4401EBFD-C7EB-44D8-AD2F-DE1280417945} - System32\Tasks\update-S-1-5-21-2171699750-2845458332-3438301781-1001 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-03-25] ()
Task: {49C1974F-81CE-4216-8838-3A5858324650} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {64D6726A-175C-4C98-8693-28B3C19FC4A8} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-03-25] ()
Task: {6E9D64CD-BC01-426E-9D20-CD5EDD6A917A} - System32\Tasks\{5D291DEA-B995-40B4-82EC-3018701CAE30} => pcalua.exe -a "C:\Users\Nico ****\Desktop\11.11\New Summoners Rift Installer.exe" -d "C:\Users\Nico ****\Desktop\11.11"
Task: {7D12D71C-2C0E-43AB-99C6-ADE4A991A8AF} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {8F1AA1C4-7515-4B44-86E3-3C581DCFC2CA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {91EB7D30-D869-4FEF-BAE6-F98793E669CA} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {92AC1171-D973-4027-99E7-A7FB63697D17} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {97304B9F-C609-4201-8486-7ABE6197C3A0} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\BrowserChoice\browserchoice.exe
Task: {9948FED4-63F4-44FE-B528-65421E66262B} - System32\Tasks\AdobeAAMUpdater-1.0-Nico-Nico **** => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-07-22] (Adobe Systems Incorporated)
Task: {99E07EA8-7290-4585-96ED-774E7F07DE25} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-11-12] (Microsoft Corporation)
Task: {A293A213-F453-4473-9BFC-BC99A43B1B6C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {D0962C95-8A5C-44CD-B2B8-8D346A5DDD83} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {D3FA8B4A-C813-496B-8648-5949BA29DC4E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {D7001DD1-7B33-4A49-BCA7-09558B1C4338} - System32\Tasks\{C2B1A770-ECEA-4D7A-8B22-10B58383F8D6} => pcalua.exe -a E:\ZToolBar.exe -d E:\
Task: {DB6F5C2A-5108-417B-BB86-99C781ECE322} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {E33D0EA5-9F68-455A-93C2-6CB76D12C114} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {E9FA8485-1D57-4E5E-95EE-BE644234A21B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-11] (Adobe Systems Incorporated)
Task: {EDA45236-7C9F-4BC4-9C64-A6CE2B5B73BA} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {F55B3C8A-5D55-4524-9487-B3ECE9072ADC} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe
Task: {FC53B995-9CF7-490C-B3C0-5AB1F8E7FE9F} - System32\Tasks\AdobeAAMUpdater-1.0-Nico-Nico => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-07-22] (Adobe Systems Incorporated)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\update-S-1-5-21-2171699750-2845458332-3438301781-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\WINDOWS\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

Shortcut: C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ruby 2.2.3-p173-x64\Interactive Ruby.lnk -> C:\Ruby22-x64\bin\irb.bat () <==== ACHTUNG

ShortcutWithArgument: C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ruby 2.2.3-p173-x64\Start Command Prompt with Ruby.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /E:ON /K C:\Ruby22-x64\bin\setrbvars.bat <==== ACHTUNG
ShortcutWithArgument: C:\Users\Nico ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Node.js\Node.js command prompt.lnk -> C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) -> /k "C:\Program Files (x86)\nodejs\nodevars.bat" <==== ACHTUNG

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2015-08-16 14:46 - 2015-07-15 03:04 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2013-11-29 00:24 - 2015-11-14 07:20 - 00116528 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-11-25 20:25 - 2014-11-25 20:25 - 00216576 _____ () C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
2015-09-18 23:39 - 2015-02-02 00:05 - 01513072 _____ () C:\Program Files (x86)\freeSSHd\FreeSSHDService.exe
2015-10-01 18:59 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-04 14:00 - 2015-12-04 14:00 - 00012800 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2015-12-04 14:00 - 2015-12-04 14:00 - 11526656 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2015-11-20 13:54 - 2015-11-20 13:55 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2015-10-01 18:59 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-07-22 00:02 - 2015-07-22 00:02 - 00803488 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2015-10-24 16:39 - 2013-09-16 11:15 - 00718377 _____ () C:\Program Files (x86)\Git\git-cheetah\git_shell_ext64.dll
2010-07-15 05:44 - 2010-07-15 05:44 - 00020032 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll
2015-10-10 14:45 - 2012-03-31 23:06 - 02689536 _____ () C:\Program Files\File Shredder\fsshell.dll
2014-05-12 10:49 - 2014-05-12 10:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2015-10-01 18:59 - 2015-09-17 06:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-10-01 18:59 - 2015-09-17 06:44 - 06569472 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-10-01 18:58 - 2015-09-17 06:42 - 00471040 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-10-01 18:58 - 2015-09-17 06:42 - 01808384 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-10-01 18:59 - 2015-09-17 06:43 - 02274816 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-10 12:00 - 2015-07-10 17:43 - 00210432 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
2015-11-29 10:42 - 2015-12-04 15:45 - 00984576 _____ () C:\Program Files (x86)\Bethesda Studios\Fallout 4\Mod Manager\Fallout4ModManager.exe
2014-11-25 20:11 - 2014-11-25 20:11 - 00221184 _____ () C:\Program Files (x86)\GNU\GnuPG\libksba-8.dll
2014-11-25 20:10 - 2014-11-25 20:10 - 00070144 _____ () C:\Program Files (x86)\GNU\GnuPG\libassuan-0.dll
2014-11-25 19:57 - 2014-11-25 19:57 - 00050176 _____ () C:\Program Files (x86)\GNU\GnuPG\libw32pth-0.dll
2014-11-25 20:13 - 2014-11-25 20:13 - 00742912 _____ () C:\Program Files (x86)\GNU\GnuPG\libgcrypt-20.dll
2014-11-25 20:05 - 2014-11-25 20:05 - 00038400 _____ () C:\Program Files (x86)\GNU\GnuPG\libgpg-error-0.dll
2015-04-02 12:53 - 2015-10-12 04:05 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-06-04 11:26 - 2015-06-04 11:26 - 00002048 _____ () C:\Program Files (x86)\DAEMON Tools Pro\MSIMG32.dll
2015-12-03 14:48 - 2015-12-03 14:48 - 01020928 _____ () C:\Users\Nico ****\AppData\Roaming\Mozilla\Firefox\Profiles\vdjrujq7.default-1443220686031\extensions\support@lastpass.com\platform\WINNT_x86-msvc\components\lpxpcom.dll
2011-07-18 22:07 - 2011-07-18 22:07 - 00014336 _____ () C:\Program Files (x86)\Notepad++\plugins\NppExport.dll
2014-01-07 00:42 - 2015-08-22 11:18 - 02873856 _____ () C:\Program Files (x86)\Notepad++\plugins\NppFTP.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)

AlternateDataStreams: C:\WINDOWS\SysWOW64\zlib.dll:DocumentSummaryInformation
AlternateDataStreams: C:\WINDOWS\SysWOW64\zlib.dll:SummaryInformation
AlternateDataStreams: C:\WINDOWS\SysWOW64\zlib.dll:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)

HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\Software\Classes\.exe:  =>  <===== ACHTUNG

==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\aeriagames.com -> hxxps://aeriagames.com
IE trusted site: HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\aeriagames.com -> hxxp://aeriagames.com

==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKLM\...\StartupApproved\StartupFolder: => "Curse.lnk"
HKLM\...\StartupApproved\StartupFolder: => "phase-6 Reminder.lnk"
HKLM\...\StartupApproved\StartupFolder: => "Install LastPass IE RunOnce.lnk"
HKLM\...\StartupApproved\StartupFolder: => "Install LastPass FF RunOnce.lnk"
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "StartIsBackTR"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "RaidCall"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "DivXMediaServer"
HKLM\...\StartupApproved\Run32: => "DivXUpdate"
HKLM\...\StartupApproved\Run32: => "AdobeAAMUpdater-1.0"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\StartupFolder: => "Curse.lnk"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\StartupFolder: => "An OneNote senden.lnk"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\StartupFolder: => "REFOG Free Keylogger.lnk"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\StartupFolder: => "REFOG Free Keylogger (2).lnk"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\StartupFolder: => "Stardock ObjectDock.lnk"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\StartupFolder: => "MEGAsync.lnk"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\StartupFolder: => "EventGhost.lnk"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\StartupFolder: => "chrome - Verknüpfung.lnk"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "Overwolf"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "MKLOL"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "Akamai NetSession Interface"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "SUPERAntiSpyware"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "Dxtory Update Checker 2.0"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "BitTorrent"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "upnpupdate"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_7BEA7ECD44ECFD70AAFE47C026C2BE54"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "MarioMMOinstaller"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "MK LOL"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "KeePass Password Safe 2"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "RocketDock"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "Speed AutoClicker"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "XLaunchpad"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "xwidget"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "DAEMON Tools Pro Agent"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "AdobeBridge"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "GoogleDriveSync"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2171699750-2845458332-3438301781-1001\...\StartupApproved\Run: => "Lync"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{70C000B8-017B-427D-B3C8-5C2C0532F630}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{92F9BC71-AB9B-49D4-80F3-731E825168D8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{AAD8CB77-A29B-407A-8786-AADB8E4CAEC0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{D7DA62F2-4171-478D-948A-84623E55FAA9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{37168914-FCE7-46D1-A1D4-C4BFAFB3EA5C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{EAE09E80-1C4C-4D53-A4B1-ADC60725B6B9}] => (Allow) C:\Program Files (x86)\Remotr\RemotrServer.exe
FirewallRules: [{F108203B-3D88-4028-8B4F-8CA4FCAEDAD1}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{3B0C0937-79C1-4C9A-9672-64AEB9C7DF09}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{70F89F74-58E5-4FFF-A7E8-A080BF23C984}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{FEA77FBA-CFCA-4799-B52D-02790F46B552}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{A0BD45B1-4083-4EFF-8AE0-846022FA2C00}] => (Block) C:\Program Files (x86)\Mirillis\Action!\Action.exe
FirewallRules: [{EFE74695-8408-4A42-A717-23434408D832}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{13828DB4-7A7A-4700-A1C1-D3D4A48602A0}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{A9FB2B0C-321E-472C-A80D-439311C948A1}] => (Allow) LPort=1688
FirewallRules: [{26A0726B-04C6-418F-AEBC-02C191C14B56}] => (Allow) C:\Users\Nico ****\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{769E9EBD-C923-4AB4-8BD2-E6103AA2C1E4}] => (Allow) C:\Users\Nico ****\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{294EC8F2-E6C4-4A9C-9FB7-F399043174AF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{915557CB-3634-4034-9A2C-15199590F066}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{0642AFC9-6C75-4D57-B456-6E2E39CE435D}] => (Allow) D:\Games\Diablo III\Diablo III.exe
FirewallRules: [{C74BE60C-C9D0-4F05-8760-FE4BA7453F4B}] => (Allow) D:\Games\Diablo III\Diablo III.exe
FirewallRules: [{37C5C06E-D034-484C-89D4-9389F33204F5}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{E5A7C89C-6F8A-4E22-919A-0B35D2DD56C2}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{E30F0958-C2F2-47DA-B87C-8AD4CFDD4642}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{884981CC-A104-455D-9D03-800A3E2A9503}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{48E852C0-5F1B-4F16-ADE2-A520930E2DF4}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{83FFF097-6A0A-4040-A475-A9DC8791EB07}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{CFAE6329-AC71-4744-9994-5E85F0C33AC8}] => (Allow) D:\SteamLibrary\SteamApps\common\Super Meat Boy\SuperMeatBoy.exe
FirewallRules: [{2A48F735-5900-4C12-B851-EE5022FFCDD1}] => (Allow) D:\SteamLibrary\SteamApps\common\Super Meat Boy\SuperMeatBoy.exe
FirewallRules: [{8E996172-8A07-4823-AA2B-71C2A0FF8E8C}] => (Block) D:\SteamLibrary\SteamApps\common\The Binding of Isaac Rebirth\isaac-ng.exe
FirewallRules: [{5831E4E0-2C23-4B28-B7A4-5DAFA5C0F3C6}] => (Allow) D:\SteamLibrary\SteamApps\common\PAYDAY The Heist\payday_win32_release.exe
FirewallRules: [{B109BCFE-70EE-4F3A-8AB3-F215A800C8FD}] => (Allow) D:\SteamLibrary\SteamApps\common\PAYDAY The Heist\payday_win32_release.exe
FirewallRules: [{EBE711FB-1FC3-4152-B067-B4044BEAFA95}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{8F243922-AA5C-4874-B67C-C0E3C72A5975}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{429E5E40-9415-4ED9-B5AA-E7FD2FDDD792}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{ED8C8F1F-3350-4533-B40E-C62C94CE1F9A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{2F09EC8D-ED60-42BF-903E-FF49B771DA27}] => (Block) C:\program files (x86)\mirc\mirc.exe
FirewallRules: [{96D2ADD8-1184-4AA4-A2EC-E019EA40190B}] => (Block) C:\program files (x86)\mirc\mirc.exe
FirewallRules: [UDP Query User{9E96AF4C-39BD-4648-B6C6-32FA292A3B16}C:\program files (x86)\mirc\mirc.exe] => (Allow) C:\program files (x86)\mirc\mirc.exe
FirewallRules: [TCP Query User{14F33AA1-EDE0-4100-9434-D197275380A1}C:\program files (x86)\mirc\mirc.exe] => (Allow) C:\program files (x86)\mirc\mirc.exe
FirewallRules: [{E31219F8-A54A-4062-8A4C-C7261263BDFA}] => (Allow) LPort=65535
FirewallRules: [{FBDA8073-9CE7-42A5-AC69-8DBF147E5E9B}] => (Allow) LPort=3659
FirewallRules: [{24EE83D0-B6B3-4254-ACFD-70AA8A0B3F18}] => (Block) C:\users\nico ****\appdata\local\jdownloader v2.0\jdownloader2.exe
FirewallRules: [{D069DD78-C312-466F-A138-17BF2E85BD8F}] => (Block) C:\users\nico ****\appdata\local\jdownloader v2.0\jdownloader2.exe
FirewallRules: [UDP Query User{278CB397-779D-4EFB-8547-C3F0DEE63A4A}C:\users\nico ****\appdata\local\jdownloader v2.0\jdownloader2.exe] => (Allow) C:\users\nico ****\appdata\local\jdownloader v2.0\jdownloader2.exe
FirewallRules: [TCP Query User{F76456A2-EF61-43F5-BFF4-B066D82EBDED}C:\users\nico ****\appdata\local\jdownloader v2.0\jdownloader2.exe] => (Allow) C:\users\nico ****\appdata\local\jdownloader v2.0\jdownloader2.exe
FirewallRules: [{50E54D2A-A7CD-4554-A106-536D660411F8}] => (Block) C:\program files\adobe\adobe premiere pro cc 2014\adobe premiere pro.exe
FirewallRules: [{EABE79BB-0A56-4C60-969D-29751738BB3A}] => (Block) C:\program files\adobe\adobe premiere pro cc 2014\adobe premiere pro.exe
FirewallRules: [UDP Query User{7F258DFA-80BB-495D-AA35-92B5B96669DB}C:\program files\adobe\adobe premiere pro cc 2014\adobe premiere pro.exe] => (Allow) C:\program files\adobe\adobe premiere pro cc 2014\adobe premiere pro.exe
FirewallRules: [TCP Query User{2710E63E-5CAC-4EDE-B17D-BB8B1893679E}C:\program files\adobe\adobe premiere pro cc 2014\adobe premiere pro.exe] => (Allow) C:\program files\adobe\adobe premiere pro cc 2014\adobe premiere pro.exe
FirewallRules: [{A853458D-F152-4BE4-866D-E0B1E0A551FC}] => (Block) R:\far cry 3 blood dragon\bin\fc3_blooddragon.exe
FirewallRules: [{F18A34AA-E96F-49F1-98D3-0B99852E5F04}] => (Block) R:\far cry 3 blood dragon\bin\fc3_blooddragon.exe
FirewallRules: [UDP Query User{1002A3FC-8B6E-471A-A966-8B41DDBEBEA7}R:\far cry 3 blood dragon\bin\fc3_blooddragon.exe] => (Block) R:\far cry 3 blood dragon\bin\fc3_blooddragon.exe
FirewallRules: [TCP Query User{440A1324-A141-467C-A4AC-32E359358D8E}R:\far cry 3 blood dragon\bin\fc3_blooddragon.exe] => (Block) R:\far cry 3 blood dragon\bin\fc3_blooddragon.exe
FirewallRules: [{1F7A2E48-FE2C-4A91-B022-C1580E3FDED7}] => (Block) R:\darkcomet5.2\darkcomet.exe
FirewallRules: [{8B2EFA11-B276-4CEA-9064-BFE9FDA5A9E6}] => (Block) R:\darkcomet5.2\darkcomet.exe
FirewallRules: [UDP Query User{0E1917E4-C72E-46D3-8AD0-026E6DA7C362}R:\darkcomet5.2\darkcomet.exe] => (Block) R:\darkcomet5.2\darkcomet.exe
FirewallRules: [TCP Query User{E31C3A99-AA79-4DCE-BDD1-0A307B76874B}R:\darkcomet5.2\darkcomet.exe] => (Block) R:\darkcomet5.2\darkcomet.exe
FirewallRules: [{6AC2B1C8-8201-45FF-959E-360374733102}] => (Block) C:\users\nico ****\appdata\local\akamai\netsession_win.exe
FirewallRules: [{ED01493E-50F8-4569-95B5-1B5029464296}] => (Block) C:\users\nico ****\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{2AD2EAE6-07F8-4349-9C7C-B6F6A07499FD}C:\users\nico ****\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\nico ****\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{DA8554D4-97B1-422D-B475-EFFD73803E26}C:\users\nico ****\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\nico ****\appdata\local\akamai\netsession_win.exe
FirewallRules: [{955A15D4-279A-4F38-933E-DDA83A7BD7DB}] => (Allow) LPort=1900
FirewallRules: [{BBAE0B4E-CF49-447C-8ADB-AEE2007DA479}] => (Allow) LPort=2869
FirewallRules: [{082EC82E-EB7B-48A5-981F-6D7ED6850341}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{A642F3D0-F932-4AFF-9383-DFF5667820B6}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{43C66AD1-36C5-4F4A-9C56-18F68F990BD1}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [UDP Query User{E51B163F-1A16-403B-8AD2-DF3AF12CB21F}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{B494C1B2-4526-48B9-860F-EAFB4117CCE7}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{E19F1BDB-13CF-4197-924A-21DC614A5726}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{E38AE524-546B-4248-811A-F564AB16DB99}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{D465879C-D574-4106-A7FF-7D594E767505}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{92AA20AC-F4B3-4A68-8167-1A476664CCAC}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{FF0139D5-C8CC-4B61-A02B-31BE4132C626}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{8F91A4C8-AA14-481E-B2A2-CA5A31F257D5}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{159D2D20-8456-4F20-BC0F-58F5A753F054}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{73321DEA-4D1D-42DC-BD24-0A6AC02A8C27}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [TCP Query User{194E668D-6D05-4D40-B1B4-B530600BFA5F}D:\games\grand theft auto v\gta5.exe] => (Allow) D:\games\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{F2902179-752E-431F-9BED-464FEC45D783}D:\games\grand theft auto v\gta5.exe] => (Allow) D:\games\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{9707745C-A2AF-491C-8339-A668D375BFCA}C:\program files (x86)\eventghost\eventghost.exe] => (Allow) C:\program files (x86)\eventghost\eventghost.exe
FirewallRules: [UDP Query User{5AADFE45-53FA-4651-A160-657CACA2F441}C:\program files (x86)\eventghost\eventghost.exe] => (Allow) C:\program files (x86)\eventghost\eventghost.exe
FirewallRules: [TCP Query User{D7C091AE-E646-4452-B437-2926AA09E2E6}C:\program files\sony\vegas pro 13.0\vegas130.exe] => (Allow) C:\program files\sony\vegas pro 13.0\vegas130.exe
FirewallRules: [UDP Query User{847BAB50-C8C4-4E28-9C0B-CEB72FB0BC76}C:\program files\sony\vegas pro 13.0\vegas130.exe] => (Allow) C:\program files\sony\vegas pro 13.0\vegas130.exe
FirewallRules: [{36AC274E-7336-4ADC-BC1C-E9407E9077B3}] => (Allow) C:\Program Files\AMI\DuOS\DuOS.exe
FirewallRules: [{ABBF05BF-8358-4557-8255-E89C5C08EB18}] => (Allow) C:\Program Files\AMI\DuOS\DuOS.exe
FirewallRules: [{38D98D2A-E0DD-4230-9970-5621C690F85C}] => (Allow) C:\Program Files\AMI\DuOS\Ubusd.exe
FirewallRules: [{C4522EAC-3AD3-4225-898E-2D616B409200}] => (Allow) C:\Program Files\AMI\DuOS\Ubusd.exe
FirewallRules: [{82DCF781-2F7B-4BC8-9A82-B9C58802649A}] => (Allow) C:\Program Files\AMI\DuOS\Dsync.exe
FirewallRules: [{355D971B-0CDE-4E2D-BE0F-4052417844CE}] => (Allow) C:\Program Files\AMI\DuOS\Dsync.exe
FirewallRules: [{B88EED64-D78F-450C-BCC6-BF11D93A853C}] => (Allow) C:\Program Files\AMI\DuOS\SysEvent.exe
FirewallRules: [{AFA55E47-B0C0-4FD9-B495-FBA246C7F0B8}] => (Allow) C:\Program Files\AMI\DuOS\SysEvent.exe
FirewallRules: [{738C08EF-98D9-4F0F-B9C0-16CF54B8E793}] => (Allow) C:\Program Files\AMI\DuOS\locationservice.exe
FirewallRules: [{A02F2F23-3A7B-4CCF-9D5D-32492E9B91BF}] => (Allow) C:\Program Files\AMI\DuOS\locationservice.exe
FirewallRules: [{6A780CC1-D46B-429C-98DC-2916967C88B9}] => (Allow) C:\Program Files\AMI\DuOS\SensorService.exe
FirewallRules: [{97564757-0816-4EB1-9BCF-F947AA9D040B}] => (Allow) C:\Program Files\AMI\DuOS\SensorService.exe
FirewallRules: [{7CD27248-8C6F-4135-954E-9EF56EE9378A}] => (Allow) C:\Program Files\AMI\DuOS\..\DuoVM\DuoVMHeadless.exe
FirewallRules: [{6879288C-096B-4CAC-A398-9351121AA7CF}] => (Allow) C:\Program Files\AMI\DuOS\..\DuoVM\DuoVMHeadless.exe
FirewallRules: [TCP Query User{8CBBD471-6656-4C5B-8753-E2D64780F219}D:\games\diablo iii\diablo iii.exe] => (Allow) D:\games\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{9A8D96E2-9409-440A-86AF-7CCA5E49C0A5}D:\games\diablo iii\diablo iii.exe] => (Allow) D:\games\diablo iii\diablo iii.exe
FirewallRules: [{EE81BA08-CD30-4912-B48B-0E64DB9875C9}] => (Allow) C:\Program Files (x86)\Origin Games\STAR WARS Battlefront Beta\starwarsbattlefront.exe
FirewallRules: [{20ED971C-3DE8-4484-83C8-A2A90614A9C5}] => (Allow) C:\Program Files (x86)\Origin Games\STAR WARS Battlefront Beta\starwarsbattlefront.exe
FirewallRules: [TCP Query User{41D0892F-3E75-47AF-9409-4C0B6A676EF2}C:\aptana stuido\aptanastudio3.exe] => (Allow) C:\aptana stuido\aptanastudio3.exe
FirewallRules: [UDP Query User{D4068FD3-681B-48EB-ADB6-D168DF4AA4C5}C:\aptana stuido\aptanastudio3.exe] => (Allow) C:\aptana stuido\aptanastudio3.exe
FirewallRules: [{147E697D-5978-4A20-9833-4AD4E9717D25}] => (Block) C:\aptana stuido\aptanastudio3.exe
FirewallRules: [{88FCA53E-4D06-4753-86A2-8600C63A9351}] => (Block) C:\aptana stuido\aptanastudio3.exe
FirewallRules: [TCP Query User{91DB0B17-D952-4EAF-9118-AA168B201500}C:\ruby22-x64\bin\ruby.exe] => (Allow) C:\ruby22-x64\bin\ruby.exe
FirewallRules: [UDP Query User{20B66ABB-AFC0-4A37-B7A2-026A7D56E2DD}C:\ruby22-x64\bin\ruby.exe] => (Allow) C:\ruby22-x64\bin\ruby.exe
FirewallRules: [{024F5D6E-C894-44B1-931F-2CFBD954135D}] => (Block) C:\ruby22-x64\bin\ruby.exe
FirewallRules: [{2565E08A-8A76-4151-A751-DD4D73D2D8D7}] => (Block) C:\ruby22-x64\bin\ruby.exe
FirewallRules: [{BCFBECF1-0B83-4DA8-8532-DE566151383A}] => (Allow) C:\Program Files (x86)\LINE\LINE.exe
FirewallRules: [{A4450775-4C7B-480D-89C3-878BC4966770}] => (Allow) C:\Program Files (x86)\LINE\LINE.exe
FirewallRules: [{93E1A885-1F85-4671-BDD5-9021D4DB2563}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\47.0.2526.18\remoting_host.exe
FirewallRules: [TCP Query User{EEE7A079-926A-44DC-AA28-323C1EAB04CF}C:\users\nico ****\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\nico ****\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [UDP Query User{057231E3-5715-4306-88FA-BABCADD354CE}C:\users\nico ****\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe] => (Allow) C:\users\nico ****\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{D6A00814-4380-4FFA-A525-FB576413503B}] => (Block) C:\users\nico ****\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe
FirewallRules: [{58568672-4F87-4871-938E-D74004C7DAEE}] => (Allow) D:\SteamLibrary\SteamApps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{D0BB0600-BA14-45DC-BC36-53B998230427}] => (Allow) D:\SteamLibrary\SteamApps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{6D12EAEC-BCE8-4E08-9D93-01135C06EF5E}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe
FirewallRules: [{2E12ADF2-814F-4643-BF00-E1442F16FAB9}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe
FirewallRules: [{6A668BC7-A281-4E84-8E47-ECEFCCA41865}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe
FirewallRules: [{4202E712-E1BC-44D3-A9D5-50E2E726C14B}] => (Allow) D:\SteamLibrary\SteamApps\common\Paint the Town Red\PaintTheTownRed.exe
FirewallRules: [{A24CB130-D1FC-444E-B3AB-95E4FF43C4EC}] => (Allow) D:\SteamLibrary\SteamApps\common\Paint the Town Red\PaintTheTownRed.exe
FirewallRules: [{0E21B804-883C-4185-A1C3-FADF7FB476E2}] => (Allow) D:\SteamLibrary\SteamApps\common\Surgeon Simulator 2013\ss2013.exe
FirewallRules: [{145F6196-59CD-4955-A7A2-631AD63E6A4B}] => (Allow) D:\SteamLibrary\SteamApps\common\Surgeon Simulator 2013\ss2013.exe
FirewallRules: [TCP Query User{7C067AD6-F7BC-4834-BDFC-D4F2901DAE0F}C:\program files (x86)\bethesda studios\fallout 4\fallout4.exe] => (Allow) C:\program files (x86)\bethesda studios\fallout 4\fallout4.exe
FirewallRules: [UDP Query User{93CF6872-4C7B-44FB-9EC5-AFD4BE97B9EA}C:\program files (x86)\bethesda studios\fallout 4\fallout4.exe] => (Allow) C:\program files (x86)\bethesda studios\fallout 4\fallout4.exe
FirewallRules: [{9753F2C3-5ADA-4A29-A228-0C191630DF40}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5EE079FF-2F1B-4AE3-B9F4-C852316F0C9A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{63C5D1EC-21FC-4CF4-ADB0-40320EDC1321}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{7CD6B759-8B44-473E-8323-BB61CD34EF20}] => (Allow) D:\SteamLibrary\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{846CCD85-BF91-4FD2-B57C-C5409736DB30}] => (Allow) D:\SteamLibrary\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{0991197A-EF8C-4DC7-8CD8-BE0685B8DE8C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (12/06/2015 09:42:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Gmer-19357.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: Gmer-19357.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x2bf4
Startzeit der fehlerhaften Anwendung: 0xGmer-19357.exe0
Pfad der fehlerhaften Anwendung: Gmer-19357.exe1
Pfad des fehlerhaften Moduls: Gmer-19357.exe2
Berichtskennung: Gmer-19357.exe3
Vollständiger Name des fehlerhaften Pakets: Gmer-19357.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Gmer-19357.exe5

Error: (12/06/2015 06:43:54 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Nico)
Description: Das Paket „Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy+ppleae38af2e007f4358a809ac99a64a67c1“ wurde beendet, da das Anhalten zu lange dauerte.

Error: (12/06/2015 06:43:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Nico)
Description: Das Paket „Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy+CortanaUI“ wurde beendet, da das Anhalten zu lange dauerte.

Error: (12/06/2015 02:11:57 PM) (Source: MsiInstaller) (EventID: 10005) (User: NT-AUTORITÄT)
Description: Product: LEGO MINDSTORMS NXT Driver for x64 -- Internal Error 2705. Directory

Error: (12/06/2015 02:11:52 PM) (Source: MsiInstaller) (EventID: 11606) (User: NT-AUTORITÄT)
Description: Product: Adobe AIR -- Error 1606. Could not access network location (computed).

Error: (12/06/2015 02:11:52 PM) (Source: MsiInstaller) (EventID: 11606) (User: NT-AUTORITÄT)
Description: Product: Adobe AIR -- Error 1606. Could not access network location (computed).

Error: (12/05/2015 07:14:39 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Nico)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (12/05/2015 07:05:49 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Nico)
Description: Bei der Aktivierung der App „Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy!App“ ist folgender Fehler aufgetreten: -2147023170. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (12/05/2015 07:05:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: ShellExperienceHost.exe, Version: 10.0.10240.16515, Zeitstempel: 0x55fa599a
Name des fehlerhaften Moduls: Windows.UI.Xaml.dll, Version: 10.0.10240.16548, Zeitstempel: 0x56133a14
Ausnahmecode: 0xc000027b
Fehleroffset: 0x00000000004aee7f
ID des fehlerhaften Prozesses: 0x970
Startzeit der fehlerhaften Anwendung: 0xShellExperienceHost.exe0
Pfad der fehlerhaften Anwendung: ShellExperienceHost.exe1
Pfad des fehlerhaften Moduls: ShellExperienceHost.exe2
Berichtskennung: ShellExperienceHost.exe3
Vollständiger Name des fehlerhaften Pakets: ShellExperienceHost.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ShellExperienceHost.exe5

Error: (12/05/2015 07:05:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm explorer.exe, Version 10.0.10240.16431 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 13e0

Startzeit: 01d12f86ac39e34c

Beendigungszeit: 0

Anwendungspfad: C:\Windows\explorer.exe

Berichts-ID: cde741ce-9b7a-11e5-8423-60a44c52a5a2

Vollständiger Name des fehlerhaften Pakets: 

Auf das fehlerhafte Paket bezogene Anwendungs-ID:


Systemfehler:
=============
Error: (12/06/2015 10:47:43 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.

Error: (12/06/2015 10:47:35 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.

Error: (12/06/2015 10:47:26 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.

Error: (12/06/2015 10:47:18 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.

Error: (12/06/2015 10:47:09 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.

Error: (12/06/2015 10:47:01 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.

Error: (12/06/2015 10:46:09 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.

Error: (12/06/2015 10:46:01 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.

Error: (12/06/2015 10:45:53 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.

Error: (12/06/2015 10:45:45 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.


CodeIntegrity:
===================================
  Date: 2015-12-06 17:14:31.321
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-12-04 17:13:26.105
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-12-03 18:29:14.704
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-12-02 19:35:57.960
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-12-01 17:24:40.728
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-11-30 16:36:43.073
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-11-29 19:36:22.251
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-11-28 17:26:48.589
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-11-27 20:13:27.749
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-11-26 18:35:20.361
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Speicherinformationen =========================== 

Prozessor: AMD FX(tm)-6300 Six-Core Processor 
Prozentuale Nutzung des RAM: 70%
Installierter physikalischer RAM: 8174.11 MB
Verfügbarer physikalischer RAM: 2417.03 MB
Summe virtueller Speicher: 16300.11 MB
Verfügbarer virtueller Speicher: 9799.46 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:465.42 GB) (Free:20.47 GB) NTFS
Drive d: () (Fixed) (Total:450.75 GB) (Free:303.92 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A5783D9F)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450.8 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=15 GB) - (Type=OF Extended)

==================== Ende von Addition.txt ============================
         

Alt 07.12.2015, 20:03   #5
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert? - Standard

Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert?



hi,

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 07.12.2015, 23:19   #6
zeVra
 
Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert? - Standard

Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert?



Code:
ATTFilter
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org

Database version:
  main:    v2015.12.07.05
  rootkit: v2015.12.07.01

Windows 10 x64 NTFS
Internet Explorer 11.0.10240.16590
Nico :: NICO [administrator]

07.12.2015 22:13:30
mbar-log-2015-12-07 (22-13-30).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 409306
Time elapsed: 39 minute(s), 37 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\Users\Nico ****\AppData\Roaming\dclogs (Trojan.StolenData) -> Delete on reboot. [59e8257d0e7d2c0a6461c41730d30df3]

Files Detected: 8
C:\Users\Nico ****\Desktop\DWS_Lite.exe (Trojan.Dropper.MSIL) -> Delete on reboot. [ba87891912794cea7a73baad7988d32d]
C:\Program Files\KMSpico\KMSELDI.exe (HackTool.IdleKMS) -> Delete on reboot. [360befb3216abf776aba5fb2758d2dd3]
C:\Users\Nico ****\AppData\Local\Temp\Rar$DRa0.496\DWS_Lite.exe (Trojan.Dropper.MSIL) -> Delete on reboot. [4100356d513ad75fbd30501781801ee2]
C:\Users\Nico ****\Downloads\Vegas pro 13 Patch (TheSubber10).exe (RiskWare.FilePatcher) -> Delete on reboot. [69d8f7ab39527cbae354d7970100f907]
C:\Users\Nico ****\Downloads\adobe.snr.patch-painter.exe (RiskWare.Tool.HCK) -> Delete on reboot. [74cd99096823a690a20e36d1e31e7e82]
C:\Users\Nico ****\AppData\Roaming\21390.exe (Rogue.Agent.Gen) -> Delete on reboot. [db66079ba1ea5adcfc2bd4fe1de5bb45]
C:\Users\Nico ****\AppData\Roaming\dclogs\2015-04-24-6.dc (Trojan.StolenData) -> Delete on reboot. [59e8257d0e7d2c0a6461c41730d30df3]
C:\Users\Nico ****\AppData\Roaming\dclogs\2015-04-25-7.dc (Trojan.StolenData) -> Delete on reboot. [59e8257d0e7d2c0a6461c41730d30df3]

Physical Sectors Detected: 0
(No malicious items detected)

(end)
         

Alt 10.12.2015, 20:38   #7
deeprybka
/// TB-Ausbilder
/// Anleitungs-Guru
 
Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert? - Standard

Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert?



Dann entferne jetzt mal bitte die gecrackte Software, sonst gehts hier nicht weiter...
__________________
Gruß
deeprybka

Lob, Kritik, Wünsche?

Spende fürs trojaner-board?
_______________________________________________
„Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer

Antwort

Themen zu Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert?
bluestacks, ccsetup, converter, defender, desktop, dnsapi.dll, firefox, flash player, format, google, helper, hängen, hängt, install.exe, mozilla, mp3, npdicihegicnhaangkdmcgbjceoemeoo, onedrive, problem, prozesse, prozessor, realtek, registry, rundll, scan, services.exe, software, svchost.exe, system, updates, windows, windowsapps




Ähnliche Themen: Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert?


  1. System ist seit einiger Zeit unendlich langsam, Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 08.04.2015 (9)
  2. Seit einiger Zeit ist der Arbeitspeicher komplett belegt.
    Alles rund um Windows - 06.11.2014 (8)
  3. Windows 7: PC bootet seit einiger Zeit sehr langsam
    Alles rund um Windows - 29.10.2014 (21)
  4. Windows-7 64bit Anwendungs Programme starten nicht mehr nach einiger Zeit
    Log-Analyse und Auswertung - 16.10.2014 (21)
  5. Windows 8.1 - seit einiger Zeit sehr langsame Downloadgeschwindigkeit (Upload i.O)
    Log-Analyse und Auswertung - 03.04.2014 (9)
  6. Seit einiger Zeit haengt sich der Laptop
    Plagegeister aller Art und deren Bekämpfung - 08.02.2013 (3)
  7. Schwache Internetverbindung seit einiger Zeit
    Alles rund um Windows - 07.10.2012 (3)
  8. Internet seit einiger Zeit sehr langsam
    Log-Analyse und Auswertung - 04.07.2012 (11)
  9. Avira meldet seit einiger Zeit den Fund TR/ATRAPS.GEN
    Log-Analyse und Auswertung - 30.04.2012 (20)
  10. MSN meldet sich seit einiger zeit automatisch ab
    Alles rund um Windows - 07.09.2010 (5)
  11. Logitech M305 seit einiger Zeit furchtbar langsam
    Netzwerk und Hardware - 25.05.2010 (1)
  12. Laptop seit einiger Zeit sehr langsam! - Keine Rückmeldung
    Log-Analyse und Auswertung - 20.11.2009 (0)
  13. Laptop seit einiger Zeit sehr langsam! :(
    Log-Analyse und Auswertung - 26.10.2009 (1)
  14. Rechner und Internet seit einiger Zeit sehr langsam
    Log-Analyse und Auswertung - 13.02.2009 (12)
  15. Seit Trojanerwarnung blockieren Browser nach einiger Zeit...
    Log-Analyse und Auswertung - 04.11.2008 (13)
  16. Pc läuft seit einiger zeit langsamer
    Log-Analyse und Auswertung - 16.03.2008 (5)
  17. Kaspersky seit einiger zeit probs mit updaten
    Antiviren-, Firewall- und andere Schutzprogramme - 11.06.2005 (4)

Zum Thema Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert? - Hallo Trojaner-Board! Ich hoffe ihr könnt mir bei meinem Problem helfen. Seit einiger Zeit, ich bin mir nicht ganz sicher seit wann, hängen sich die Programme auf meinem PC ständig - Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert?...
Archiv
Du betrachtest: Windows 10: Programme hängen sich seit einiger Zeit auf. Infiziert? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.