![]() |
|
Log-Analyse und Auswertung: Windows 7 3-4 Webseiten öffnen sich nach Opera startWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Windows 7 3-4 Webseiten öffnen sich nach Opera start Hallo Trojaner Board'ler, Als ich heute Mittag (18.01.2017) eine vermeintlich sichere Datei, die ich vor Wochen von einer vermeintlich sicheren Quelle/Seite, geladen habe, kam es zu massiven Problem mit meinem Opera-Browser auf dem Desktop kam plötzlich auch Werbung. Dieser öffnet sporadisch irgendwelche Werbeseiten (3-4 Seiten). Die vermeintlich sichere Datei war eine Demo-Version von Daemontools-Lite (ohne irgendwelche Cracks, Keygens etc.) Leider kann ich euch nicht mehr genau sagen um welche Seite es sich gehandelt hat. ![]() ![]() Direkt nach dem doppelklick auf die .exe schlug dierekt mein Avira an. Danach habe ich direkt kompletten System-Scan gestartet. Habe Bereits aus der Host-Datei 100 Einträge mit gleicher IP-Adresse entfernt. nach dem ist die Desktop Werbung verschwunden. Dummerweise hab ich das erste Logfile überschrieben. Alles was jetzt noch zu tun ist übersteigt meine Kompetenzen. Deswegen benötige ich eure Hilfe. Alle Schritte die bisher unternommen wurden: Scan mit Avira Scan mit Hijackthis Scan mit Malwarebytes Anti-Rootkit BETA 1.09.3.1001 Scan mit FRST Avira Logfile Code:
ATTFilter 18.01.2017, 10:54:50 [Real-Time Protection] Malware found The pattern of 'ADWARE/Adware.xbjke [adware]' detected in file 'C:\Program Files (x86)\OtherSearch\ziengine.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:50 [Real-Time Protection] Malware found The pattern of 'TR/Strictor.gccpn [trojan]' detected in file 'C:\Program Files (x86)\OtherSearch\updengine.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:50 [Real-Time Protection] Malware found The pattern of 'ADWARE/Adware.spdug [adware]' detected in file 'C:\Program Files (x86)\OtherSearch\zdengine.dll. Action performed: Move file to quarantine 18.01.2017, 10:54:50 [Real-Time Protection] Malware found The pattern of 'ADWARE/Adware.tphcr [adware]' detected in file 'C:\Program Files (x86)\OtherSearch\zdenginecert.dll. Action performed: Move file to quarantine 18.01.2017, 10:54:50 [Real-Time Protection] Malware found The pattern of 'ADWARE/Komodia.exmaw [adware]' detected in file 'C:\Program Files (x86)\OtherSearch\kke.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:23 [Real-Time Protection] Malware found The pattern of 'ADWARE/Agent.onczr [adware]' detected in file 'C:\Windows\c562f3940e043920f3565bdb0653e17a.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:21 [Real-Time Protection] Malware found The pattern of 'ADWARE/Agent.dtsqs [adware]' detected in file 'C:\Program Files\5f997e823c149616faed2a7953b94672\c562f3940e043920f3565bdb0653e17a.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:18 [Real-Time Protection] Malware found The pattern of 'TR/Symmi.npyqa [trojan]' detected in file 'C:\Program Files\5f997e823c149616faed2a7953b94672\cc3ef4cb9c0b487ee043ca733e1cda27.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:17 [Real-Time Protection] Malware found The pattern of 'TR/Symmi.npyqa [trojan]' detected in file 'C:\Program Files\5f997e823c149616faed2a7953b94672\cc3ef4cb9c0b487ee043ca733e1cda27.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:08 [Real-Time Protection] Malware found The pattern of 'ADWARE/Sokuxuan.qrdkg [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\00029727\51477.top.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:07 [Real-Time Protection] Malware found The pattern of 'ADWARE/Adware.fycvv [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\00029720\kpzip.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:07 [Real-Time Protection] Malware found The pattern of 'ADWARE/Agent.ufptv [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\00029724\service.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:07 [Real-Time Protection] Malware found The pattern of 'TR/Agent.bryzl [trojan]' detected in file 'C:\Users\Alex\AppData\Local\Temp\00029720\RandomDelJiheReg.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:07 [Real-Time Protection] Malware found The pattern of 'ADWARE/Yeabests.oibru [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\00029720\hp.exe. Action performed: Move file to quarantine 18.01.2017, 10:54:05 [Real-Time Protection] Malware found The pattern of 'ADWARE/Agent.totp [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\00029720\newAutoTime_51477.jpg. Action performed: Move file to quarantine 18.01.2017, 10:54:00 [Real-Time Protection] Malware found The pattern of 'ADWARE/Agent.sslj [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\OfferInstaller.exe. Action performed: Move file to quarantine 18.01.2017, 10:53:58 [Real-Time Protection] Malware found The pattern of 'ADWARE/ConvertAd.51270 [adware]' detected in file 'C:\Users\Alex\AppData\Local\00000000-1484736823-0000-0000-D8CB8A9BBEC6\Uninstall.exe. Action performed: Move file to quarantine 18.01.2017, 10:53:57 [Real-Time Protection] Malware found The pattern of 'ADWARE/Agent.3030016.8 [adware]' detected in file 'C:\Users\Alex\AppData\Local\Temp\fsd4DE2.exe. Action performed: Move file to quarantine 18.01.2017, 10:53:56 [Real-Time Protection] Malware found The pattern of 'ADWARE/Adware.letsk [adware]' detected in file 'C:\Program Files (x86)\OtherSearch\zdengine.exe. Action performed: Move file to quarantine 18.01.2017, 10:53:56 [Real-Time Protection] Malware found The pattern of 'ADWARE/Adware.jqayd [adware]' detected in file 'C:\Program Files (x86)\OtherSearch\ziengine.exe. Action performed: Move file to quarantine 18.01.2017, 10:53:55 [Real-Time Protection] Malware found The pattern of 'ADWARE/ConvertAd.A.1926 [adware]' detected in file 'C:\Users\Alex\AppData\Local\00000000-1484736823-0000-0000-D8CB8A9BBEC6\qnso4EAE.tmp. Action performed: Move file to quarantine HiJackThis Log Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.5 Scan saved at 15:44:02, on 18.01.2017 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.18525) FIREFOX: 50.1.0 (x86 de) Boot mode: Normal Running processes: C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe C:\Program Files (x86)\Thunder Master\THPanel.exe C:\Users\Alex\AppData\Local\Microsoft\OneDrive\OneDrive.exe C:\Users\Alex\AppData\Local\Temp\00029720\msiql.exe C:\Program Files (x86)\Blue Manager Suite\BMExplorer.exe C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe C:\Program Files (x86)\Avira\Antivirus\avgnt.exe C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe C:\Program Files (x86)\Dropbox\Client\Dropbox.exe C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe C:\Users\Alex\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe C:\Users\Alex\Desktop\HijackThis_2.0.5.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll O2 - BHO: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL O2 - BHO: AviraBrowserSafety.BrowserSafety - {c3c77255-42c0-499f-b664-6e981a0b1647} - mscoree.dll (file missing) O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll O4 - HKLM\..\Run: [Sound Blaster Cinema 2] "C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe" /r O4 - HKLM\..\Run: [Avira SystrayStartTrigger] "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min O4 - HKLM\..\Run: [Fast Boot] C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe O4 - HKLM\..\Run: [Super Charger] C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup O4 - HKLM\..\Run: [Command Center] C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe O4 - HKCU\..\Run: [THPanel] "C:\Program Files (x86)\Thunder Master\THPanel.exe" /A O4 - HKCU\..\Run: [STUISpeedLauncher] "C:\Program Files\Samsung\Stylish UI Pack\TouchBasedUI.exe" -speedlauncher -minVer:6.6.58.0 O4 - HKCU\..\Run: [OneDrive] "C:\Users\Alex\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background O4 - HKCU\..\Run: [DAEMON Tools Ultra Agent] "C:\Program Files\DAEMON Tools Ultra\DTAgent.exe" -autorun O4 - HKCU\..\Run: [msiql] C:\Users\Alex\AppData\Local\Temp\00029720\msiql.exe /RUNNING O4 - HKCU\..\Run: [ProxyGate] C:\Users\Alex\AppData\Roaming\ProxyGate\MainService.exe O4 - HKUS\S-1-5-18\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'Default user') O4 - Global Startup: Blue Manager Suite.lnk = C:\Program Files (x86)\Blue Manager Suite\BMExplorer.exe O4 - Global Startup: Killer Network Manager.lnk = C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105 O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000 O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O9 - Extra button: Avira Browser Safety - {d8f67242-b229-4065-95fa-391b077ed6ca} - mscoree.dll (file missing) O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL O23 - Service: 5f997e823c149616faed2a7953b94672 - Unknown owner - C:\Program Files\5f997e823c149616faed2a7953b94672\4be4ee7ec1a7db4d36fdb985186936b5.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe O23 - Service: Dropbox-Update-Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe O23 - Service: Dropbox-Update-Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe O23 - Service: DbxSvc - Unknown owner - C:\Windows\system32\DbxSvc.exe (file missing) O23 - Service: Digital Wave Update Service (DigitalWave.Update.Service) - Digital Wave Ltd. - C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe O23 - Service: Disc Soft Ultra Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe O23 - Service: GamingApp_Service - Micro-Star Int'l Co., Ltd. - C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe O23 - Service: GamingHotkey_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe O23 - Service: Google Update-Dienst (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Sentinel LDK License Manager (hasplms) - Unknown owner - C:\Windows\system32\hasplms.exe (file missing) O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - H:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Killer Service V2 - Rivet Networks - C:\Program Files\Killer Networking\Network Manager\KillerService.exe O23 - Service: Logitech Gaming Registry Service (LogiRegistryService) - Logitech Inc. - C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe O23 - Service: Autodesk Simulation Moldflow MITSI 2017 Job-Manager (mitsijm2017) - Autodesk, Inc. - E:\Program Files\Autodesk\Inventor 2017\Moldflow\bin\mitsijm.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: MSI Command Center Clock Service (MSIClock_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe O23 - Service: MSI Command Center Comm Service (MSICOMM_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\MSICommService.exe O23 - Service: MSI Command Center CPU Service (MSICPU_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe O23 - Service: MSI Command Center control Service (MSICTL_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe O23 - Service: MSI Command Center DDR Service (MSIDDR_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe O23 - Service: MSI Command Center SMBus Service (MSISMB_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe O23 - Service: MSI Command Center SuperIO Service (MSISuperIO_CC) - MSI - C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe O23 - Service: MSI_FastBoot - MSI - C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe O23 - Service: NVIDIA Wireless Controller Service - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Users\Alex\Origin\OriginWebHelperService.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Samsung Printer Dianostics Service - Unknown owner - C:\Windows\system32\\spdsvc.exe O23 - Service: Samsung UPD Utility Service (SamsungUPDUtilSvc) - Unknown owner - C:\Windows\SysWOW64\SecUPDUtilSvc.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: Survarium-Steam Update Service - Unknown owner - H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium_service.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 15744 bytes Malwarebytes Anti-Rootkit Log Code:
ATTFilter --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.3.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 11.0.9600.18524 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, E:\ DRIVE_FIXED, H:\ DRIVE_FIXED, I:\ DRIVE_FIXED, J:\ DRIVE_FIXED, K:\ DRIVE_FIXED, L:\ DRIVE_FIXED, M:\ DRIVE_FIXED, P:\ DRIVE_FIXED CPU speed: 4.400000 GHz Memory total: 8552493056, free: 5017292800 Downloaded database version: v2017.01.18.06 Downloaded database version: v2016.11.20.01 Downloaded database version: v2016.12.16.01 ======================================= Initializing... Driver version: 0.3.0.4 ------------ Kernel report ------------ 01/18/2017 15:57:31 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\ACPI.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\system32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\mpio.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\system32\drivers\intelide.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\system32\drivers\aliide.sys \SystemRoot\system32\drivers\amdide.sys \SystemRoot\system32\drivers\cmdide.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\system32\drivers\nvraid.sys \SystemRoot\system32\drivers\CLASSPNP.SYS \SystemRoot\system32\DRIVERS\pciide.sys \SystemRoot\system32\drivers\viaide.sys \SystemRoot\system32\drivers\iaStorV.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\drivers\lsi_sas.sys \SystemRoot\system32\drivers\storport.sys \SystemRoot\system32\drivers\msahci.sys \SystemRoot\system32\DRIVERS\amd_sata.sys \SystemRoot\system32\DRIVERS\amd_xata.sys \SystemRoot\system32\DRIVERS\dtlitescsibus.sys \SystemRoot\system32\DRIVERS\dtultrascsibus.sys \SystemRoot\system32\drivers\HpSAMD.sys \SystemRoot\system32\drivers\adp94xx.sys \SystemRoot\system32\drivers\adpahci.sys \SystemRoot\system32\drivers\adpu320.sys \SystemRoot\system32\drivers\amdsata.sys \SystemRoot\system32\drivers\amdsbs.sys \SystemRoot\system32\drivers\amdxata.sys \SystemRoot\system32\drivers\arc.sys \SystemRoot\system32\drivers\arcsas.sys \SystemRoot\system32\drivers\bxfcoe.sys \SystemRoot\system32\drivers\bxois.sys \SystemRoot\system32\drivers\elxstor.sys \SystemRoot\system32\drivers\iirsp.sys \SystemRoot\system32\drivers\lsi_fc.sys \SystemRoot\system32\drivers\lsi_sas2.sys \SystemRoot\system32\drivers\lsi_scsi.sys \SystemRoot\system32\drivers\megasas.sys \SystemRoot\system32\drivers\MegaSR.sys \SystemRoot\system32\drivers\nfrd960.sys \SystemRoot\system32\drivers\nvstor.sys \SystemRoot\system32\drivers\ql2300.sys \SystemRoot\system32\drivers\ql40xx.sys \SystemRoot\system32\drivers\SiSRaid2.sys \SystemRoot\system32\drivers\sisraid4.sys \SystemRoot\system32\drivers\stexstor.sys \SystemRoot\system32\drivers\vhdmp.sys \SystemRoot\system32\drivers\FLTMGR.SYS \SystemRoot\system32\drivers\FSDEPENDS.SYS \SystemRoot\system32\drivers\vsmraid.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\msrpc.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\system32\drivers\storvsc.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\drivers\vmstorfl.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\msiscsi.sys \SystemRoot\system32\drivers\TDI.SYS \SystemRoot\System32\drivers\hwpolicy.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\drivers\disk.sys \SystemRoot\System32\Drivers\BtHidBus.sys \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\system32\drivers\rdprefmp.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\drivers\afd.sys \??\C:\Windows\system32\drivers\d9eee9dfd1d1e926566fcb6f68590575.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\ws2ifsl.sys \SystemRoot\system32\DRIVERS\wfplwf.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\vwififlt.sys \SystemRoot\system32\DRIVERS\bflwfx64.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\serial.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\DRIVERS\termdd.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\system32\DRIVERS\mssmbios.sys \SystemRoot\System32\drivers\discache.sys \SystemRoot\system32\drivers\csc.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\blbdrive.sys \SystemRoot\system32\DRIVERS\avkmgr.sys \SystemRoot\system32\DRIVERS\avipbb.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\nvlddmkm.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\system32\DRIVERS\HDAudBus.sys \SystemRoot\system32\DRIVERS\xhcdrv.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\DRIVERS\usbfilter.sys \SystemRoot\system32\drivers\usbohci.sys \SystemRoot\system32\drivers\USBPORT.SYS \SystemRoot\system32\drivers\usbehci.sys \SystemRoot\system32\DRIVERS\serenum.sys \SystemRoot\system32\DRIVERS\e22w7x64.sys \SystemRoot\system32\DRIVERS\wmiacpi.sys \SystemRoot\system32\DRIVERS\amdppm.sys \SystemRoot\system32\DRIVERS\CompositeBus.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\rdpbus.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\DRIVERS\swenum.sys \SystemRoot\system32\DRIVERS\ks.sys \SystemRoot\system32\DRIVERS\amdiox64.sys \SystemRoot\system32\drivers\LGBusEnum.sys \SystemRoot\system32\drivers\LGJoyXlCore.sys \SystemRoot\system32\DRIVERS\umbus.sys \SystemRoot\system32\drivers\nvvad64v.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\system32\DRIVERS\dtultrausbbus.sys \SystemRoot\system32\drivers\I2cHkBurn.sys \SystemRoot\system32\DRIVERS\ViaHub3.sys \SystemRoot\system32\drivers\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\drivers\nvhda64v.sys \SystemRoot\system32\drivers\RTKVHD64.sys \SystemRoot\system32\drivers\MBfilt64.sys \SystemRoot\system32\DRIVERS\USBSTOR.SYS \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\system32\DRIVERS\monitor.sys \SystemRoot\system32\DRIVERS\usbccgp.sys \SystemRoot\system32\DRIVERS\hidusb.sys \SystemRoot\system32\DRIVERS\HIDCLASS.SYS \SystemRoot\system32\DRIVERS\HIDPARSE.SYS \SystemRoot\system32\DRIVERS\kbdhid.sys \SystemRoot\system32\DRIVERS\mouhid.sys \SystemRoot\system32\DRIVERS\LGSHidFilt.Sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_amd_sata.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\System32\ATMFD.DLL \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\DRIVERS\avgntflt.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \??\C:\Windows\system32\drivers\aksdf.sys \SystemRoot\System32\Drivers\fastfat.SYS \??\C:\Windows\system32\drivers\aksfridge.sys \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys \SystemRoot\system32\DRIVERS\avnetflt.sys \??\C:\Windows\system32\drivers\hardlock.sys \??\C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys \SystemRoot\system32\drivers\peauth.sys \??\C:\Windows\SysWOW64\speedfan.sys \SystemRoot\System32\DRIVERS\srvnet.sys \??\C:\Windows\system32\Drivers\SSPORT.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\SYSTEM32\DRIVERS\WibuKey64.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\drivers\LGVirHid.sys \??\C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys \??\C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys \??\C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\DRIVERS\WUDFRd.sys \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys \Windows\System32\ntdll.dll \Windows\System32\smss.exe \Windows\System32\apisetschema.dll \Windows\System32\autochk.exe ----------- End ----------- Done! Scan started Database versions: main: v2017.01.18.06 rootkit: v2016.11.20.01 <<<2>>> Physical Sector Size: 512 Drive: 1, DevicePointer: 0xfffffa8007675060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa8007675b20, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8007675060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa8006de0ac0, DeviceName: Unknown, DriverName: \Driver\amd_xata\ DevicePointer: 0xfffffa8007456060, DeviceName: \Device\000000a8\, DriverName: \Driver\amd_sata\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... Done! Physical Sector Size: 512 Drive: 0, DevicePointer: 0xfffffa8007674060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa8007674b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8007674060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa80074555f0, DeviceName: Unknown, DriverName: \Driver\amd_xata\ DevicePointer: 0xfffffa8007452630, DeviceName: \Device\000000a6\, DriverName: \Driver\amd_sata\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 Drive 0 Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: 6015DB08 Partition information: Partition 0 type is Dynamic (0x42) Partition is NOT ACTIVE. Partition starts at LBA: 63 Numsec = 1985 Partition is not bootable Partition 1 type is Dynamic (0x42) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 204800 Partition is bootable Partition file system is NTFS Partition 2 type is Dynamic (0x42) Partition is NOT ACTIVE. Partition starts at LBA: 206848 Numsec = 209715200 Partition is not bootable Partition file system is NTFS Partition 3 type is Dynamic (0x42) Partition is NOT ACTIVE. Partition starts at LBA: 209922048 Numsec = 1743601072 Partition is not bootable Partition file system is NTFS Disk Size: 1000204886016 bytes Sector size: 512 bytes Done! Drive 1 This is a System drive Scanning MBR on drive 1... Inspecting partition table: MBR Signature: 55AA Disk Signature: 619C2244 Partition information: Partition 0 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 2048 Numsec = 204800 Partition is bootable Partition file system is NTFS Partition 1 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 208896 Numsec = 204800 Partition is bootable Partition file system is NTFS Partition 2 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 413696 Numsec = 468443136 Partition is not bootable Partition file system is NTFS Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition is not bootable Disk Size: 240057409536 bytes Sector size: 512 bytes Done! Physical Sector Size: 512 Drive: 2, DevicePointer: 0xfffffa8008a77060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa8008a56580, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8008a77060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa8008a5a8c0, DeviceName: Unknown, DriverName: \Driver\usbfilter\ DevicePointer: 0xfffffa8008a4a5a0, DeviceName: \Device\000000c1\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 Drive 2 Scanning MBR on drive 2... Inspecting partition table: MBR Signature: 55AA Disk Signature: 57A43849 Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 2018699264 Partition is bootable Partition file system is NTFS Partition 1 type is Extended with LBA (0xf) Partition is NOT ACTIVE. Partition starts at LBA: 2018701312 Numsec = 839682048 Partition is not bootable Partition 2 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 2858383360 Numsec = 524288000 Partition is not bootable Partition file system is NTFS Partition 3 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 3382671360 Numsec = 524288000 Partition is not bootable Partition file system is NTFS Disk Size: 2000365289472 bytes Sector size: 512 bytes Done! Physical Sector Size: 0 Drive: 3, DevicePointer: 0xfffffa80094a3510, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa80094a6040, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa80094a3510, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa80094a1440, DeviceName: Unknown, DriverName: \Driver\usbfilter\ DevicePointer: 0xfffffa800949b720, DeviceName: \Device\000000ec\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Physical Sector Size: 0 Drive: 4, DevicePointer: 0xfffffa80094a8060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa80094a8b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa80094a8060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa80094a2040, DeviceName: Unknown, DriverName: \Driver\usbfilter\ DevicePointer: 0xfffffa800946c060, DeviceName: \Device\000000ed\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Physical Sector Size: 0 Drive: 5, DevicePointer: 0xfffffa80094a5060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa80094a5b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa80094a5060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa80094a2bf0, DeviceName: Unknown, DriverName: \Driver\usbfilter\ DevicePointer: 0xfffffa800949a530, DeviceName: \Device\000000ee\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Physical Sector Size: 0 Drive: 6, DevicePointer: 0xfffffa80094ab790, DeviceName: \Device\Harddisk6\DR6\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa80094aa040, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa80094ab790, DeviceName: \Device\Harddisk6\DR6\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa80094a27a0, DeviceName: Unknown, DriverName: \Driver\usbfilter\ DevicePointer: 0xfffffa800949cb60, DeviceName: \Device\000000ef\, DriverName: \Driver\USBSTOR\ ------------ End ---------- Infected: C:\Users\Alex\AppData\Local\Temp\00029720\msiql.exe --> [Adware.Agent] Infected: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|msiql --> [Adware.Agent] Infected: C:\Users\Alex\AppData\Local\Temp\00029720\msiql.exe --> [Adware.Agent] File C:\Windows\System32\drivers\d9eee9dfd1d1e926566fcb6f68590575.sys will be destroyed Infected: C:\Windows\System32\drivers\d9eee9dfd1d1e926566fcb6f68590575.sys --> [Adware.Wajam.Generic] Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\d9eee9dfd1d1e926566fcb6f68590575 --> [Adware.Wajam.Generic] Infected: C:\$Recycle.Bin\S-1-5-21-844601699-3614358154-429673199-1000\$RMG8ZNU.tmp\Un_A.exe --> [Adware.OptimizerEliteMax] Infected: C:\$Recycle.Bin\S-1-5-21-844601699-3614358154-429673199-1000\$R49C5J1\onesystemcare.exe --> [Adware.OptimizerEliteMax] Infected: C:\Users\Alex\Desktop\Camtasia Studio 9\camtasia 9 patch.exe --> [RiskWare.FilePatcher] Scan finished Creating System Restore point... Cleaning up... <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action reg.exe... Success! Executing an action cmd.exe... Success! Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action reg.exe Queuing an action cmd.exe Queuing an action cmd.exe Queuing an action cmd.exe Queuing an action cmd.exe Queuing an action cmd.exe Removal scheduling successful. System shutdown needed. System shutdown occurred ======================================= --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.09.3.1001 (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 11.0.9600.18524 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, E:\ DRIVE_FIXED, H:\ DRIVE_FIXED, I:\ DRIVE_FIXED, K:\ DRIVE_FIXED CPU speed: 4.400000 GHz Memory total: 8552493056, free: 5128929280 Downloaded database version: v2017.01.18.07 ======================================= Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-01-2017 durchgeführt von Alex (Administrator) auf ALEX-PC (18-01-2017 16:32:44) Gestartet von C:\Users\Alex\Desktop Geladene Profile: Alex (Verfügbare Profile: Alex) Platform: Windows 7 Ultimate Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Opera) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe (SafeNet Inc.) C:\Windows\System32\hasplms.exe (VIA Technologies, Inc.) C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Palit Microsystems Ltd.) C:\Program Files (x86)\Thunder Master\THPanel.exe (Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe (iAnywhere Solutions) C:\Program Files (x86)\Blue Manager Suite\BMExplorer.exe (Autodesk, Inc.) E:\Program Files\Autodesk\Inventor 2017\Moldflow\bin\mitsijm.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe (MSI) C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe (MSI) C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe (MSI) C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe (MSI) C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe (MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Micro-Star INT'L CO.,LTD.) C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe () C:\Windows\System32\PnkBstrA.exe () C:\Windows\SysWOW64\spdsvc.exe () C:\Windows\SysWOW64\SecUPDUtilSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE (Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.94\opera.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8801024 2016-04-22] (Realtek Semiconductor) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [15112312 2016-02-09] (Logitech Inc.) HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] () HKLM-x32\...\Run: [Sound Blaster Cinema 2] => C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe [1442304 2014-05-29] (Creative Technology Ltd) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [60136 2016-11-15] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [917576 2016-12-14] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Fast Boot] => C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [759120 2015-04-22] () HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1015808 2016-05-19] (MSI) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [26287016 2017-01-06] (Dropbox, Inc.) HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [835680 2016-06-14] (MSI) HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [THPanel] => C:\Program Files (x86)\Thunder Master\THPanel.exe [2197472 2015-07-22] (Palit Microsystems Ltd.) HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [STUISpeedLauncher] => C:\Program Files\Samsung\Stylish UI Pack\TouchBasedUI.exe [411136 2015-02-09] () HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [DAEMON Tools Ultra Agent] => C:\Program Files\DAEMON Tools Ultra\DTAgent.exe [4644184 2015-06-10] (Disc Soft Ltd) HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Run: [ProxyGate] => C:\Users\Alex\AppData\Roaming\ProxyGate\MainService.exe <===== ACHTUNG HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\Policies\Explorer: [] HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {2a7e694d-afe4-11e5-881f-806e6f6e6963} - F:\DVDSetup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {7edadcfb-b3ab-11e5-a6ff-d8cb8a9bbec6} - R:\SETUP.EXE HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {883137d3-5c7c-11e6-abd0-d8cb8a9bbec6} - G:\startme.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {97a0ae78-d7be-11e5-bf3f-d8cb8a9bbec6} - M:\Startme.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {b7167805-aff4-11e5-89b3-d8cb8a9bbec6} - Q:\SETUP.EXE HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {dddedf48-3336-11e6-9221-d8cb8a9bbec6} - D:\setup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\...\MountPoints2: {fd345007-2950-11e6-980e-d8cb8a9bbec6} - Y:\Setup.exe HKU\S-1-5-21-844601699-3614358154-429673199-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [477696 2010-11-21] (Microsoft Corporation) HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1283112 2016-02-02] (Autodesk, Inc.) HKU\S-1-5-18\...\Policies\system: [DisableLockWorkstation] 0 ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2016-02-07] (Autodesk, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Blue Manager Suite.lnk [2016-01-16] ShortcutTarget: Blue Manager Suite.lnk -> C:\Program Files (x86)\Blue Manager Suite\BMExplorer.exe (iAnywhere Solutions) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2016-06-08] ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Winsock: Catalog9-x64 01 C:\Windows\system32\zdengine64.dll Keine Datei Winsock: Catalog9-x64 02 C:\Windows\system32\zdengine64.dll Keine Datei Winsock: Catalog9-x64 03 C:\Windows\system32\zdengine64.dll Keine Datei Winsock: Catalog9-x64 04 C:\Windows\system32\zdengine64.dll Keine Datei Winsock: Catalog9-x64 15 C:\Windows\system32\zdengine64.dll Keine Datei Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{9A7D4DD5-00F4-4688-B953-DE9AFC70D7F4}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{F008894C-19EE-458C-AC0A-9ECCF55B239D}: [DhcpNameServer] 192.168.2.1 Internet Explorer: ================== SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-844601699-3614358154-429673199-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-11-05] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-05] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-05] (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-21] (Microsoft Corporation) BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\Windows\system32\mscoree.dll [2010-11-21] (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-10-11] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-05] (Oracle Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default [2017-01-13] FF Homepage: Mozilla\Firefox\Profiles\qiF99tHm.default -> hxxps://www.google.de FF Session Restore: Mozilla\Firefox\Profiles\qiF99tHm.default -> ist aktiviert. FF Extension: (Avira Browser Safety) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default\Extensions\abs@avira.com.xpi [2016-11-27] FF Extension: (Firefox Hotfix) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-09-03] FF Extension: (MEGA) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\qiF99tHm.default\Extensions\firefox@mega.co.nz.xpi [2017-01-12] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt => nicht gefunden FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-13] () FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-05] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-05] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-25] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-13] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2016-02-18] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-05] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-05] (Oracle Corporation) FF Plugin-x32: @lattice3d.com/XVL Player -> C:\Program Files\Lattice\Player3_x86\npxvlplay.dll [2015-02-23] (Lattice Technology Co.,Ltd.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-11] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-11] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-25] (Adobe Systems) Chrome: ======= CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default [2017-01-12] CHR Extension: (Google Präsentationen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-14] CHR Extension: (Google Docs) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-14] CHR Extension: (Google Drive) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-14] CHR Extension: (YouTube) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-14] CHR Extension: (Adobe Acrobat) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-12] CHR Extension: (Google Tabellen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-14] CHR Extension: (Avira Browserschutz) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-12-14] CHR Extension: (Google Docs Offline) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-14] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-14] CHR Extension: (Google Mail) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-14] CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-14] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (Adblock Plus) - C:\Users\Alex\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2016-10-28] ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S4 5f997e823c149616faed2a7953b94672; C:\Program Files\5f997e823c149616faed2a7953b94672\4be4ee7ec1a7db4d36fdb985186936b5.exe [39237120 2017-01-17] () [Datei ist nicht signiert] <==== ACHTUNG S4 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1295376 2016-07-01] (Autodesk Inc.) S4 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-25] (Adobe Systems Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2207960 2016-09-26] (Adobe Systems, Incorporated) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-05-04] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert] S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1089592 2016-12-14] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [476736 2016-12-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [476736 2016-12-14] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1490296 2016-12-14] (Avira Operations GmbH & Co. KG) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [350528 2016-11-24] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1447944 2016-12-12] () S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-25] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-25] (Dropbox, Inc.) R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51504 2017-01-06] (Dropbox, Inc.) R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [392168 2016-08-31] (Digital Wave Ltd.) R3 Disc Soft Ultra Bus Service; C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe [1345368 2015-06-10] (Disc Soft Ltd) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [249104 2016-11-11] (EasyAntiCheat Ltd) R2 GamingApp_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [39888 2016-05-19] (Micro-Star Int'l Co., Ltd.) R2 GamingHotkey_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2019792 2016-05-16] (Micro-Star INT'L CO., LTD.) R2 hasplms; C:\Windows\system32\hasplms.exe [4609928 2013-08-01] (SafeNet Inc.) S2 HiPatchService; H:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-12-09] (Hi-Rez Studios) [Datei ist nicht signiert] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [Datei ist nicht signiert] R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [454872 2016-01-28] (Rivet Networks) R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193144 2016-02-09] (Logitech Inc.) R2 mitsijm2017; E:\Program Files\Autodesk\Inventor 2017\Moldflow\bin\mitsijm.exe [967456 2015-08-04] (Autodesk, Inc.) S3 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [4163680 2016-09-09] (MSI) S3 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2204768 2016-09-29] (MSI) S3 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe [4162656 2016-09-29] (MSI) R2 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [2015328 2016-09-29] (MSI) R2 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2327648 2016-09-29] (MSI) S3 MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [2076768 2016-09-29] (MSI) S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [607160 2016-09-29] (MSI) R2 MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [105296 2015-06-04] (MSI) S4 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2248144 2016-04-28] (Micro-Star INT'L CO., LTD.) R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [163280 2015-05-18] (MSI) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation) R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-13] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2016-12-13] (NVIDIA Corporation) S4 Origin Client Service; C:\Users\Alex\Origin\OriginClientService.exe [2119688 2016-12-24] (Electronic Arts) S2 Origin Web Helper Service; C:\Users\Alex\Origin\OriginWebHelperService.exe [2180624 2016-12-24] (Electronic Arts) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2016-01-02] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2016-01-02] () S4 PSI_SVC_2_x64; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (arvato digital services llc) R2 Samsung Printer Dianostics Service; C:\Windows\SysWOW64\\spdsvc.exe [498488 2016-05-01] () R2 SamsungUPDUtilSvc; C:\Windows\SysWOW64\SecUPDUtilSvc.exe [143664 2016-06-06] () S4 SanDisk SSD Dashboard Service; C:\Program Files (x86)\SanDisk\SSD Dashboard\SanDiskSSDDashboardService.exe [373760 2016-06-24] (SanDisk) [Datei ist nicht signiert] S3 Survarium-Steam Update Service; H:\Program Files (x86)\Steam\steamapps\common\Survarium\game\binaries\x86\survarium_service.exe [97880 2016-11-14] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2011-11-13] (Advanced Micro Devices) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [176464 2016-12-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [148032 2016-12-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2015-12-03] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [79696 2016-05-11] (Avira Operations GmbH & Co. KG) S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation) R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [147528 2016-01-24] (Rivet Networks, LLC.) S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.) R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [25056 2011-12-21] (IVT Corporation.) S3 btiaa2dp; C:\Windows\System32\drivers\btiaa2dp.sys [82944 2008-09-16] (iAnywhere Solutions) S3 BTiAPan; C:\Windows\System32\DRIVERS\btiapan.sys [37888 2008-09-16] (iAnywhere Solutions) S3 btiarcp; C:\Windows\System32\DRIVERS\btiarcp.sys [10880 2008-07-30] (iAnywhere Solutions) S3 btiaspp; C:\Windows\System32\DRIVERS\btiaspp.sys [92160 2008-09-16] (iAnywhere Solutions) S3 BTIAUSB; C:\Windows\System32\DRIVERS\btiausb.sys [31744 2008-11-14] (iAnywhere Solutions) S3 BTPROT; C:\Windows\System32\DRIVERS\btprot.sys [517632 2008-11-14] (iAnywhere Solutions) R0 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation) R0 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation) R0 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-12-31] (Disc Soft Ltd) S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [46392 2015-12-31] (Disc Soft Ltd) R0 dtultrascsibus; C:\Windows\System32\DRIVERS\dtultrascsibus.sys [30264 2016-03-15] (Disc Soft Ltd) R3 dtultrausbbus; C:\Windows\System32\DRIVERS\dtultrausbbus.sys [47160 2016-03-15] (Disc Soft Ltd) S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc) R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [331328 2013-08-01] (SafeNet Inc.) R3 I2cHkBurn; C:\Windows\System32\drivers\I2cHkBurn.sys [41760 2015-07-27] (FINTEK Corp.) S3 iAnywhere_btAudio; C:\Windows\System32\drivers\btiasco.sys [25088 2008-07-30] (iAnywhere Solutions) S3 IvtAudioBusSrv; C:\Windows\System32\Drivers\IvtBtBus.sys [27256 2012-12-24] (IVT Corporation.) S3 IvtPanBusSrv; C:\Windows\System32\Drivers\btnetBus.sys [31480 2012-12-24] (IVT Corporation.) R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [125488 2015-03-18] (Qualcomm Atheros, Inc.) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) R3 LGJoyXlCore; C:\Windows\System32\drivers\LGJoyXlCore.sys [68384 2015-06-11] (Logitech Inc.) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [41752 2013-05-30] (Logitech Inc.) R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI) R3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [13368 2012-10-26] (MSI) R3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-13] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-12-13] (NVIDIA Corporation) S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [163644 2016-07-30] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Datei ist nicht signiert] R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [225792 2014-10-31] (VIA Technologies, Inc.) R2 WIBUKEY; C:\Windows\System32\DRIVERS\WibuKey64.sys [106760 2015-10-14] (WIBU-SYSTEMS AG) R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [305664 2014-10-31] (VIA Technologies, Inc.) S3 ALSysIO; \??\C:\Users\Alex\AppData\Local\Temp\ALSysIO64.sys [X] S3 BlueletAudio; system32\DRIVERS\blueletaudio.sys [X] S3 BT; system32\DRIVERS\btnetdrv.sys [X] S3 BTCOM; system32\DRIVERS\btcomport.sys [X] S3 Btcsrusb; System32\Drivers\btcusb.sys [X] S3 cpuz137; \??\C:\Users\Alex\AppData\Local\Temp\cpuz137\cpuz137_x64.sys [X] S3 cpuz138; \??\C:\Users\Alex\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] S3 dbx; system32\DRIVERS\dbx.sys [X] S3 IvtComBusSrv; System32\Drivers\btcombus.sys [X] S3 MSICDSetup; \??\F:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [X] S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] S3 xspirit; \??\C:\Windows\xspirit.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-18 16:32 - 2017-01-18 16:33 - 00035949 _____ C:\Users\Alex\Desktop\FRST.txt 2017-01-18 16:32 - 2017-01-18 16:32 - 00000000 ____D C:\FRST 2017-01-18 16:31 - 2017-01-18 16:31 - 02419200 _____ (Farbar) C:\Users\Alex\Desktop\FRST64.exe 2017-01-18 16:21 - 2017-01-18 16:21 - 00000000 ___HD C:\OneDriveTemp 2017-01-18 15:57 - 2017-01-18 16:21 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2017-01-18 15:55 - 2017-01-18 16:12 - 00000000 ____D C:\Users\Alex\Desktop\mbar 2017-01-18 15:54 - 2017-01-18 15:54 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Alex\Desktop\mbar-1.09.3.1001.exe 2017-01-18 15:48 - 2017-01-18 15:48 - 00000000 ____D C:\Users\Alex\Desktop\backups 2017-01-18 15:34 - 2017-01-18 15:34 - 00388608 _____ (Trend Micro Inc.) C:\Users\Alex\Desktop\HijackThis_2.0.5.exe 2017-01-18 11:07 - 2017-01-18 16:21 - 00000318 ____H C:\Windows\Tasks\MSIOSDx86_Host.job 2017-01-18 11:07 - 2017-01-18 16:21 - 00000318 ____H C:\Windows\Tasks\MSIOSDx64_Host.job 2017-01-18 11:07 - 2017-01-18 16:21 - 00000252 ____H C:\Windows\Tasks\MSISW_Host.job 2017-01-18 10:54 - 2017-01-18 10:55 - 00000000 ____D C:\Windows\system32\SSL 2017-01-18 10:54 - 2017-01-18 10:54 - 00000000 ____D C:\Users\Alex\AppData\Local\app 2017-01-18 10:54 - 2017-01-18 10:54 - 00000000 ____D C:\ProgramData\b1fa982f-78d5-0 2017-01-18 10:54 - 2017-01-18 10:54 - 00000000 ____D C:\ProgramData\b1fa982f-2e57-1 2017-01-18 10:54 - 2017-01-18 10:54 - 00000000 ____D C:\Program Files\5f997e823c149616faed2a7953b94672 2017-01-18 10:53 - 2017-01-18 11:05 - 00000000 ____D C:\Program Files (x86)\8c019856-45eb-468e-bf17-e8408cf047bf1484733219 2017-01-18 10:53 - 2017-01-18 10:53 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Note-UP 2017-01-18 10:53 - 2017-01-18 10:53 - 00000000 ____D C:\Users\Alex\AppData\Local\00000000-1484736823-0000-0000-D8CB8A9BBEC6 2017-01-18 10:53 - 2017-01-18 10:53 - 00000000 _____ C:\TOSTACK 2017-01-18 10:07 - 2017-01-18 10:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2017-01-18 10:06 - 2017-01-18 10:07 - 00000000 ____D C:\Users\Alex\AppData\Roaming\DVDVideoSoft 2017-01-18 10:04 - 2017-01-18 10:05 - 00000000 ____D C:\Users\Alex\Documents\psynetic-gifx 2017-01-18 10:04 - 2017-01-18 10:04 - 00000000 ____D C:\Users\Alex\AppData\Local\psynetic-imageconverter 2017-01-18 10:03 - 2017-01-18 10:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\psynetic 2017-01-13 12:28 - 2017-01-13 12:28 - 00000000 ____D C:\Users\Alex\Desktop\CINEBENCHR15.03 2017-01-12 22:36 - 2017-01-12 22:50 - 00000028 _____ C:\Users\Alex\Desktop\Neues Textdokument.txt 2017-01-12 08:37 - 2017-01-12 08:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-01-09 16:16 - 2017-01-09 16:22 - 04407342 _____ C:\Users\Alex\Desktop\Konstruktionselementkalkulation V4.0 inkl. Mittelabflußplan.xlsx 2017-01-08 20:53 - 2017-01-08 20:53 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-01-08 20:53 - 2016-12-11 19:23 - 00134712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2017-01-08 20:53 - 2016-09-09 19:25 - 00269600 _____ C:\Windows\SysWOW64\vulkan-1.dll 2017-01-08 20:53 - 2016-09-09 19:25 - 00261920 _____ C:\Windows\system32\vulkan-1.dll 2017-01-08 20:53 - 2016-09-09 19:25 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe 2017-01-08 20:53 - 2016-09-09 19:24 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe 2017-01-08 20:50 - 2016-12-12 03:37 - 40125496 _____ C:\Windows\system32\nvcompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 35222976 _____ C:\Windows\SysWOW64\nvcompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 34703416 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 28138432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 14073400 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2017-01-08 20:50 - 2016-12-12 03:37 - 10912744 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 10795312 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 10345696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 09151216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 08913328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 08753832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 03640376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 03206080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 01953336 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437633.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 01586744 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437633.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 01036224 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00975416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00944184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00896056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00683640 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00572888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00521096 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00438208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00435904 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00407248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00388544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00170688 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00153184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2017-01-08 20:50 - 2016-12-12 03:37 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2017-01-06 01:04 - 2017-01-06 01:04 - 00051504 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2017-01-04 00:21 - 2017-01-04 00:22 - 00000000 ____D C:\Program Files (x86)\OBS 2017-01-04 00:21 - 2017-01-04 00:21 - 00000935 _____ C:\Users\Alex\Desktop\Open Broadcaster Software.lnk 2017-01-04 00:21 - 2017-01-04 00:21 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2017-01-04 00:21 - 2017-01-04 00:21 - 00000000 ____D C:\Program Files\OBS 2017-01-03 12:12 - 2017-01-12 22:40 - 00000000 ____D C:\Users\Alex\Desktop\Gifs 2017-01-02 15:07 - 2017-01-02 15:07 - 00000000 ____D C:\Crash 2017-01-01 23:15 - 2017-01-02 15:06 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\Daybreak Game Company 2017-01-01 23:15 - 2017-01-01 23:15 - 00000000 ____D C:\Users\Alex\AppData\Local\SCE 2017-01-01 23:15 - 2017-01-01 23:15 - 00000000 ____D C:\Users\Alex\AppData\Local\Daybreak Game Company 2016-12-26 19:26 - 2016-12-26 19:26 - 00000000 ____D C:\Users\Alex\AppData\Local\TechSmith 2016-12-26 19:02 - 2017-01-18 16:21 - 00002938 _____ C:\ProgramData\NvTelemetryContainer.log 2016-12-26 19:02 - 2017-01-18 16:20 - 00004984 _____ C:\ProgramData\NvTelemetryContainer.log_backup1 2016-12-26 19:02 - 2016-12-26 19:02 - 00004236 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-12-13 00:36 - 00156096 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2016-12-26 19:02 - 2016-12-13 00:36 - 00123840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2016-12-26 19:02 - 2016-12-13 00:36 - 00046016 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2016-12-26 19:02 - 2016-12-12 15:36 - 00001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat 2016-12-25 17:44 - 2016-12-25 17:44 - 00000000 ____D C:\Users\Alex\AppData\Local\4A Games 2016-12-22 20:53 - 2016-12-22 20:53 - 00000000 ____D C:\Users\Alex\AppData\Local\HirezLauncherUI 2016-12-22 20:52 - 2016-12-22 21:01 - 00000000 ____D C:\ProgramData\Hi-Rez Studios 2016-12-22 20:52 - 2016-12-22 20:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios 2016-12-22 17:26 - 2016-12-22 17:26 - 00788918 _____ C:\Users\Alex\Desktop\Nachtragsmanagement_MB.pdf 2016-12-22 17:26 - 2016-12-22 17:26 - 00317552 _____ C:\Users\Alex\Desktop\1.Verfahrensbeschreibungen (1).pdf 2016-12-22 14:13 - 2016-12-22 14:13 - 04464334 _____ C:\Users\Alex\Desktop\Konstruktionselementkalkulation V1 für Ausbau.xlsx 2016-12-21 14:05 - 2016-12-22 14:45 - 00000000 ____D C:\Users\Alex\Desktop\Mittelabflußplan 2016-12-21 07:52 - 2016-12-21 07:52 - 00018407 _____ C:\Users\Alex\AppData\Local\recently-used.xbel 2016-12-20 17:02 - 2016-12-20 17:03 - 00000000 ____D C:\Users\Alex\AppData\Roaming\TeamViewer 2016-12-20 17:02 - 2016-12-20 17:02 - 12971088 _____ (TeamViewer GmbH) C:\Users\Alex\Desktop\TeamViewer_Setup_de.exe 2016-12-20 12:07 - 2017-01-18 09:48 - 00003018 _____ C:\Windows\System32\Tasks\MSIAfterburner ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-01-18 16:28 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-01-18 16:28 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-01-18 16:27 - 2016-01-05 19:15 - 00000000 ____D C:\Users\Alex\Documents\Outlook-Dateien 2017-01-18 16:24 - 2016-07-21 15:35 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2017-01-18 16:21 - 2016-03-25 12:05 - 00000000 ___RD C:\Users\Alex\Dropbox 2017-01-18 16:21 - 2016-01-06 21:03 - 00000000 ___RD C:\Users\Alex\OneDrive 2017-01-18 16:21 - 2016-01-05 13:46 - 00000000 ____D C:\Users\Alex\AppData\Local\CrashDumps 2017-01-18 16:21 - 2015-12-31 19:02 - 00000000 ____D C:\ProgramData\NVIDIA 2017-01-18 16:21 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2017-01-18 16:21 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-01-18 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\IME 2017-01-18 16:12 - 2008-05-09 16:08 - 00001891 _____ C:\Users\Alex\AppData\Local\bmarchive.bms 2017-01-18 15:57 - 2016-07-21 15:36 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-01-18 15:57 - 2016-07-21 15:35 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-01-18 11:19 - 2016-12-14 15:41 - 00002295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-01-18 11:07 - 2016-02-21 22:19 - 00000946 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2017-01-18 10:56 - 2016-05-21 18:00 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2017-01-18 10:55 - 2016-11-23 12:46 - 00000000 ____D C:\Users\Public\Documents\AdobeGC 2017-01-18 10:46 - 2016-11-23 11:43 - 00000000 ____D C:\Users\Alex\Documents\Camtasia Studio 2017-01-18 10:45 - 2016-03-25 11:59 - 00001210 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2017-01-18 10:17 - 2016-10-14 10:13 - 00719098 _____ C:\Windows\system32\perfh019.dat 2017-01-18 10:17 - 2016-10-14 10:13 - 00151344 _____ C:\Windows\system32\perfc019.dat 2017-01-18 10:17 - 2013-04-15 15:44 - 00702730 _____ C:\Windows\system32\perfh007.dat 2017-01-18 10:17 - 2013-04-15 15:44 - 00150314 _____ C:\Windows\system32\perfc007.dat 2017-01-18 10:17 - 2009-07-14 06:13 - 02498584 _____ C:\Windows\system32\PerfStringBackup.INI 2017-01-18 10:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2017-01-18 10:07 - 2016-11-20 19:00 - 00000000 ____D C:\Users\Alex\.gimp-2.8 2017-01-18 09:59 - 2016-02-21 22:17 - 00000000 ____D C:\Users\Alex\AppData\Local\Adobe 2017-01-18 09:56 - 2016-05-21 18:00 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-01-18 09:56 - 2016-02-21 22:19 - 00003936 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-01-18 09:56 - 2016-01-04 20:38 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-01-18 09:56 - 2016-01-04 20:38 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-01-18 09:56 - 2016-01-04 20:38 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-01-18 09:56 - 2016-01-04 20:38 - 00000000 ____D C:\Windows\system32\Macromed 2017-01-18 09:48 - 2016-11-23 10:04 - 00003490 _____ C:\Windows\System32\Tasks\AutoKMS 2017-01-18 09:48 - 2016-03-25 11:59 - 00001206 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2017-01-13 12:30 - 2016-02-18 19:38 - 00000000 ____D C:\Program Files (x86)\SpeedFan 2017-01-13 12:29 - 2016-01-04 12:16 - 00000000 ____D C:\Users\Alex\AppData\Roaming\MAXON 2017-01-13 12:18 - 2016-12-01 19:09 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\Mozilla 2017-01-13 03:57 - 2016-01-05 20:53 - 00000000 ____D C:\Users\Alex\AppData\Roaming\TS3Client 2017-01-12 18:36 - 2016-11-27 19:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-01-12 08:37 - 2016-02-20 15:08 - 00000000 ____D C:\Program Files (x86)\Dropbox 2017-01-11 21:10 - 2016-03-07 20:07 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-01-11 21:09 - 2016-03-07 20:07 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2017-01-10 16:14 - 2016-07-29 13:57 - 00000000 ____D C:\Users\Alex\AppData\Roaming\OBS 2017-01-08 20:54 - 2016-11-15 14:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-01-08 20:54 - 2016-03-18 15:26 - 00000000 ____D C:\Temp 2017-01-08 20:54 - 2015-12-31 19:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-01-04 13:34 - 2016-01-04 14:47 - 00000000 ___RD C:\Users\Alex\Desktop\Games 2017-01-04 12:19 - 2015-12-31 16:47 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2017-01-01 23:09 - 2016-01-01 16:51 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Origin 2017-01-01 23:09 - 2016-01-01 16:46 - 00000000 ____D C:\ProgramData\Origin 2016-12-29 10:30 - 2016-01-04 14:50 - 00000000 ___RD C:\Users\Alex\Desktop\MSI 2016-12-29 10:26 - 2016-06-13 10:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp 2016-12-29 10:26 - 2016-06-13 10:02 - 00000000 ____D C:\Program Files\Core Temp 2016-12-27 16:51 - 2016-11-14 17:01 - 00000000 ____D C:\Users\Alex\Documents\Survarium-Steam 2016-12-26 19:02 - 2016-11-15 14:23 - 00003832 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003828 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003828 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003820 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003644 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2016-11-15 14:23 - 00003584 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2016-12-26 19:02 - 2015-12-31 19:03 - 00000000 ____D C:\Users\Alex\AppData\Local\NVIDIA Corporation 2016-12-26 19:02 - 2015-12-31 19:01 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-12-26 19:02 - 2015-12-31 18:59 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-12-25 17:46 - 2016-12-07 09:16 - 00000000 ____D C:\Users\Alex\Documents\4A Games 2016-12-24 12:47 - 2016-07-02 20:29 - 00000000 ____D C:\Users\Alex\Origin 2016-12-24 12:41 - 2016-11-30 16:24 - 00000000 ____D C:\Users\Public\Documents\.forever 2016-12-24 12:34 - 2016-01-04 14:30 - 00000000 ____D C:\Users\Alex\Desktop\SBOT 2016-12-22 21:00 - 2015-12-31 14:23 - 00000000 ____D C:\Users\Alex\Documents\My Games 2016-12-22 20:52 - 2015-12-31 19:12 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-12-22 15:37 - 2015-12-31 20:42 - 00003866 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1451590946 2016-12-22 15:37 - 2015-12-31 20:41 - 00000000 ____D C:\Program Files (x86)\Opera 2016-12-20 16:50 - 2016-07-18 14:59 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Skype 2016-12-20 16:43 - 2016-07-18 16:25 - 00000384 ___RH C:\Windows\sosyambaess.lock 2016-12-20 15:01 - 2016-07-18 14:59 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-12-20 15:01 - 2016-07-18 14:59 - 00000000 ____D C:\ProgramData\Skype ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2016-02-06 14:46 - 2016-02-06 14:54 - 0000104 _____ () C:\Users\Alex\AppData\Roaming\mBot.ini 2008-05-09 16:08 - 2017-01-18 16:12 - 0001891 _____ () C:\Users\Alex\AppData\Local\bmarchive.bms 2008-05-09 16:08 - 2016-02-20 19:23 - 0000000 _____ () C:\Users\Alex\AppData\Local\bmarchive.bms~RF1a66bd5.TMP 2016-12-21 07:52 - 2016-12-21 07:52 - 0018407 _____ () C:\Users\Alex\AppData\Local\recently-used.xbel 2015-12-31 18:57 - 2016-01-05 15:11 - 0007605 _____ () C:\Users\Alex\AppData\Local\resmon.resmoncfg 2016-05-13 21:20 - 2016-05-13 21:20 - 0000000 _____ () C:\Users\Alex\AppData\Local\{AF97A572-54D0-441A-A283-15CC4BC2A136} 2016-01-04 16:28 - 2016-01-04 16:28 - 0000016 _____ () C:\ProgramData\mntemp 2016-12-26 19:02 - 2017-01-18 16:21 - 0002938 _____ () C:\ProgramData\NvTelemetryContainer.log 2016-12-26 19:02 - 2017-01-18 16:20 - 0004984 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1 ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-01-03 12:51 ==================== Ende von FRST.txt ============================ Grüße BauBau |
Themen zu Windows 7 3-4 Webseiten öffnen sich nach Opera start |
antivirus, avira, bho, desktop, flash player, google, helper, hijack, hkus\s-1-5-18, homepage, installation, internet, internet explorer, logfile, mozilla, nvcontainer, problem, prozesse, realtek, registry, senden, software, super, svchost.exe, trojaner, trojaner board, un_a.exe, usb, windows |