FRST (
Teil 2 ):
Code:
Alles auswählen Aufklappen ATTFilter
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-22 02:12 - 2009-07-14 05:45 - 00031296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-22 02:12 - 2009-07-14 05:45 - 00031296 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-22 02:08 - 2014-05-23 15:58 - 01729770 _____ () C:\Windows\WindowsUpdate.log
2015-01-22 02:03 - 2014-11-28 13:19 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-22 02:03 - 2010-11-21 04:47 - 00257038 _____ () C:\Windows\PFRO.log
2015-01-22 02:03 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-22 02:03 - 2009-07-14 05:51 - 00051732 _____ () C:\Windows\setupact.log
2015-01-22 01:41 - 2014-11-28 13:19 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-22 01:38 - 2014-05-23 16:16 - 00000000 ____D () C:\Windows\es
2015-01-21 23:59 - 2014-05-23 16:09 - 00000000 ____D () C:\ProgramData\Adobe
2015-01-21 03:27 - 2014-07-24 07:29 - 00058016 _____ () C:\Users\usuario\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-21 03:23 - 2009-07-14 05:45 - 00268184 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-20 16:14 - 2014-05-24 01:46 - 00703840 _____ () C:\Windows\system32\perfh00A.dat
2015-01-20 16:14 - 2014-05-24 01:46 - 00137806 _____ () C:\Windows\system32\perfc00A.dat
2015-01-20 16:14 - 2009-07-14 06:13 - 01555646 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-18 17:06 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2015-01-17 16:33 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2015-01-17 16:32 - 2014-07-24 07:29 - 00001408 _____ () C:\Users\usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-17 16:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-17 16:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2015-01-17 16:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-01-17 16:18 - 2010-11-21 08:17 - 00000000 ____D () C:\Program Files\Windows Journal
2015-01-17 16:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2015-01-17 16:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2015-01-17 16:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2015-01-17 16:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2015-01-17 16:16 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-01-17 16:16 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism
2015-01-17 13:54 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Defender
2015-01-17 13:54 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-01-17 09:46 - 2014-07-24 07:24 - 00000000 ____D () C:\Users\usuario
2015-01-17 09:42 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-01-17 09:42 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2015-01-17 09:42 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-01-17 09:41 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\winrm
2015-01-17 09:41 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\WCN
2015-01-17 09:41 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\sysprep
2015-01-17 09:41 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\slmgr
2015-01-17 09:41 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts
2015-01-17 09:41 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\winrm
2015-01-17 09:41 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\WCN
2015-01-17 09:41 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\slmgr
2015-01-17 09:41 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2015-01-17 09:41 - 2009-07-14 06:37 - 00000000 ____D () C:\Windows\DigitalLocker
2015-01-17 09:41 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-01-17 09:41 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\DVD Maker
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Setup
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\oobe
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\com
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sysprep
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Setup
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\oobe
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\MUI
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\migwiz
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\com
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\servicing
2015-01-17 09:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\IME
2015-01-16 10:38 - 2014-11-28 13:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-01-16 10:36 - 2014-11-28 13:19 - 00004098 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-01-16 10:36 - 2014-11-28 13:19 - 00003846 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-01-16 10:26 - 2014-07-24 07:26 - 00000528 _____ () C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2015-01-16 10:26 - 2014-07-24 07:26 - 00000466 _____ () C:\Windows\Tasks\SystemToolsDailyTest.job
2015-01-16 09:43 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-01-16 09:41 - 2014-05-23 16:06 - 00000000 ____D () C:\swshare
2015-01-15 19:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\TAPI
2015-01-15 19:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\sppui
2015-01-15 19:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\ras
2015-01-15 19:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\InstallShield
2015-01-15 19:51 - 2014-05-24 01:46 - 00000000 ____D () C:\Windows\SysWOW64\es
2015-01-15 19:51 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns
2015-01-15 19:51 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\AdvancedInstallers
2015-01-15 19:51 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sppui
2015-01-15 19:51 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\ras
2015-01-15 19:50 - 2014-05-24 01:46 - 00000000 ____D () C:\Windows\system32\es
2015-01-15 19:48 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-01-15 19:47 - 2009-07-14 04:20 - 00000000 __RSD () C:\Windows\Media
2015-01-15 19:45 - 2014-05-23 16:17 - 00000000 ____D () C:\Windows\delnis
2015-01-15 19:44 - 2014-07-24 07:24 - 00000000 ___RD () C:\Users\usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-15 19:44 - 2014-07-24 07:24 - 00000000 ___RD () C:\Users\usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-15 19:44 - 2011-02-15 10:42 - 00000000 ____D () C:\SWTOOLS
2015-01-15 19:44 - 2010-11-21 08:16 - 00000000 ___RD () C:\Users\Public\Recorded TV
2015-01-15 19:44 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\addins
2015-01-15 19:44 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-01-15 19:44 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-15 19:44 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-15 19:44 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-15 19:44 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-15 19:42 - 2014-05-23 16:16 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2015-01-15 19:42 - 2014-05-23 16:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetWaiting
2015-01-15 19:42 - 2014-05-23 16:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InterVideo WinDVD
2015-01-15 19:42 - 2014-05-23 16:01 - 00000000 ___HD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools
2015-01-15 19:42 - 2014-05-23 16:00 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-01-15 19:42 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-15 19:42 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Portable Devices
2015-01-15 19:42 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-15 19:42 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-15 19:41 - 2014-05-23 16:14 - 00000000 ____D () C:\Program Files (x86)\NetWaiting
2015-01-15 19:41 - 2014-05-23 16:08 - 00000000 ____D () C:\Program Files (x86)\Lenovo Registration
2015-01-15 19:41 - 2014-05-23 16:01 - 00000000 ____D () C:\Program Files (x86)\Lenovo
2015-01-15 19:40 - 2014-05-23 16:14 - 00000000 ____D () C:\Program Files (x86)\Digital Line Detect
2015-01-15 19:40 - 2014-05-23 16:00 - 00000000 ____D () C:\Program Files (x86)\Integrated Camera Driver
2015-01-15 19:39 - 2014-05-23 16:10 - 00000000 ____D () C:\Program Files\PC-Doctor
2015-01-15 19:39 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2015-01-15 18:57 - 2009-07-14 03:34 - 00000505 _____ () C:\Windows\win.ini
2015-01-15 18:28 - 2014-07-24 07:26 - 00003506 _____ () C:\Windows\System32\Tasks\SystemToolsDailyTest
2015-01-14 17:10 - 2014-07-24 07:26 - 00003448 _____ () C:\Windows\System32\Tasks\PCDEventLauncher
2015-01-10 13:45 - 2014-05-23 16:08 - 00134287 _____ () C:\Windows\DirectX.log
2015-01-10 13:38 - 2014-11-29 22:20 - 00000000 ____D () C:\Users\usuario\AppData\Local\Windows Live
2015-01-08 09:55 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-07 00:49 - 2014-12-02 16:49 - 00000000 ____D () C:\Users\usuario\AppData\Roaming\Spotify
2015-01-05 16:22 - 2014-12-02 17:06 - 00000000 ____D () C:\Users\usuario\AppData\Local\Spotify
2015-01-02 16:34 - 2014-07-24 07:26 - 00004246 _____ () C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask
2014-12-27 11:55 - 2014-12-06 09:26 - 00000000 ____D () C:\ProgramData\Norton
2014-12-23 20:21 - 2014-11-28 13:10 - 00000000 ____D () C:\Users\usuario\AppData\Roaming\Adobe
Some content of TEMP:
====================
C:\Users\usuario\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmppjvapu.dll
C:\Users\usuario\AppData\Local\Temp\Quarantine.exe
C:\Users\usuario\AppData\Local\Temp\ReimagePackage.exe
C:\Users\usuario\AppData\Local\Temp\SoftonicAssistant_v0-1-6.exe
C:\Users\usuario\AppData\Local\Temp\sqlite3.dll
C:\Users\usuario\AppData\Local\Temp\uttB929.tmp.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-15 21:22
==================== End Of Log ============================