![]() |
|
Plagegeister aller Art und deren Bekämpfung: Thema: ADWCleaner6.046 läuft durch beim Löschen hängt sich der PC auf - was kann die Ursache sein?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() Thema: ADWCleaner6.046 läuft durch beim Löschen hängt sich der PC auf - was kann die Ursache sein? Hallo Leute, bin neu hier; habe folgendes Problem: mein PC, Win. 10 Home wurde vor geraumer Zeit immer langsamer. Nach Durchlauf von einigen Virenprogrammen (Freeware) wurden auch Viren gefunden. Malwarebytes, ADWCleaner, ChicaLogic geprüft, mit den Programmen wird auch was gefunden aber leider, wenn es zum Löschen der Dateien kommt hängt sich mein PC komplett auf so, dass nur noch Reset möglich ist um aus dem Modus rauszukommen. Vor kurzem habe ich Norton gekauft und Komplettscan durchgeführt, PC ist wieder etwas schneller geworden, leider funktioniert das Löschen der dubiosen Dateien nach dem Suchlauf mit den oben erwähnten Programmen auch nicht, so als würde hier irgend was die Löschung blockieren. Bitte um Hilfe Hier mein File: Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 27-04-2017 durchgeführt von Julien (Administrator) auf HOMEPC (28-04-2017 17:10:54) Gestartet von C:\Users\Julien\Downloads Geladene Profile: Julien (Verfügbare Profile: Julien & Administrator) Platform: Windows 10 Home Version 1703 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Edge) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AdminService.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfemms.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Symantec Corporation) C:\Program Files\Norton Security\Engine\22.9.1.12\NS.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Atheros) C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe (ChicaLogic) C:\Program Files (x86)\ChicaLogic\ChicaPC-Shield\cpcsscheduler.exe (ChicaLogic) C:\Program Files (x86)\ChicaLogic\ChicaPC-Shield\cpcsservice.exe (Microsoft Corporation) C:\Windows\System32\SecurityHealthService.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (ChicaLogic) C:\Program Files (x86)\ChicaLogic\ChicaPC-Shield\cpcsgui.exe (Symantec Corporation) C:\Program Files\Norton Security\Engine\22.9.1.12\NS.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.14.662.0_x64__kzf8qxf38zg5c\SkypeHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe (Atheros Communications) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\ActivateDesktop.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Qualcomm Atheros) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtTray.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registry (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8512760 2015-08-04] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-08-04] (Realtek Semiconductor) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1796056 2014-08-19] (NVIDIA Corporation) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-04-30] (Intel Corporation) HKLM\...\Run: [BtPreLoad] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtPreLoad.exe [64640 2012-12-28] () HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2017-01-19] (Apple Inc.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [102928 2012-10-23] (CyberLink Corp.) HKLM-x32\...\Run: [Nikon Message Center 2] => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [570880 2013-12-27] (Nikon Corporation) HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [129664 2012-12-28] (Atheros Communications) HKU\S-1-5-21-836797742-737356516-1884966141-1001\...\Run: [Amazon Music] => C:\Users\Julien\AppData\Local\Amazon Music\Amazon Music Helper.exe [6277952 2014-12-08] () HKU\S-1-5-21-836797742-737356516-1884966141-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31682144 2015-03-25] (Skype Technologies S.A.) HKU\S-1-5-21-836797742-737356516-1884966141-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9532120 2017-04-11] (Piriform Ltd) ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton Security\Engine\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton Security\Engine\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton Security\Engine\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation) ShellIconOverlayIdentifiers: [DBARFileBackuped] -> {831cebdd-6baf-4432-be76-9e0989c14aef} => C:\WINDOWS\system32\mscoree.dll [2017-03-18] (Microsoft Corporation) ShellIconOverlayIdentifiers: [DBARFileNotBackuped] -> {275e4fd7-21ef-45cf-a836-832e5d2cc1b3} => C:\WINDOWS\system32\mscoree.dll [2017-03-18] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton Security\Engine32\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton Security\Engine32\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton Security\Engine32\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{e64359d6-d010-4166-882f-51061b3710e5}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{e84bf977-7d9d-48af-922b-627d2ba5065c}: [DhcpNameServer] 10.72.0.72 10.72.0.73 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-836797742-737356516-1884966141-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.de/?gws_rd=ssl SearchScopes: HKU\S-1-5-21-836797742-737356516-1884966141-1001 -> DefaultScope {2DD994EE-4BBD-4450-B1FE-9411B76D18E7} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-836797742-737356516-1884966141-1001 -> OldSearch URL = SearchScopes: HKU\S-1-5-21-836797742-737356516-1884966141-1001 -> {2DD994EE-4BBD-4450-B1FE-9411B76D18E7} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-836797742-737356516-1884966141-1001 -> {6CCAD392-DAA4-4E63-B9DF-389D743FF85D} URL = BHO: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security\Engine\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation) BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll [2012-12-28] (Qualcomm Atheros Commnucations) BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH) BHO-x32: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security\Engine32\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation) BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security\Engine\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security\Engine32\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2015-05-13] (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2015-05-13] (McAfee, Inc.) FireFox: ======== FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.9.1.12\coFFAddon FF Extension: (Norton Security Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.9.1.12\coFFAddon [2017-04-20] FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.9.1.12\coFFAddon FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2015-07-22] [ist nicht signiert] FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-05-13] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-01-24] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-01-24] (Intel Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-05-13] () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-29] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-29] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-21] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-21] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default [2017-04-25] CHR Extension: (Google Präsentationen) - C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-04-21] CHR Extension: (Google Docs) - C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-04-21] CHR Extension: (Google Drive) - C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-21] CHR Extension: (YouTube) - C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-21] CHR Extension: (Norton Security Toolbar) - C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2017-04-21] CHR Extension: (Google Tabellen) - C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-04-21] CHR Extension: (Google Docs Offline) - C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-04-21] CHR Extension: (Norton Identity Safe) - C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2017-04-21] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-21] CHR Extension: (Google Mail) - C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-21] CHR Extension: (Chrome Media Router) - C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-21] CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Security\Engine\22.9.1.12\Exts\Chrome.crx [2017-04-20] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Security\Engine\22.9.1.12\Exts\Chrome.crx [2017-04-20] CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.) R2 AtherosSvc; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe [226944 2012-12-28] (Qualcomm Atheros Commnucations) [Datei ist nicht signiert] R2 CPCSScheduler; C:\Program Files (x86)\ChicaLogic\ChicaPC-Shield\cpcsscheduler.exe [418376 2013-04-04] (ChicaLogic) R2 CPCSService; C:\Program Files (x86)\ChicaLogic\ChicaPC-Shield\cpcsservice.exe [701512 2013-04-04] (ChicaLogic) R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-04-19] (Digital Wave Ltd.) S4 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-30] (Intel Corporation) R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [Datei ist nicht signiert] R2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [Datei ist nicht signiert] S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129336 2013-01-31] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [167736 2013-01-31] (Intel Corporation) R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [754280 2015-05-13] (McAfee, Inc.) S4 McAWFwk; C:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334760 2012-12-21] (McAfee, Inc.) S4 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.5.495.0\McCSPServiceHost.exe [207344 2015-06-04] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.) S4 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.) S4 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [609592 2015-05-05] (McAfee, Inc.) S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.) S4 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.) S4 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.) R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-06-29] (McAfee, Inc.) R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [373704 2015-07-06] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [254792 2015-06-29] (McAfee, Inc.) S4 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.) R2 NS; C:\Program Files\Norton Security\Engine\22.9.1.12\NS.exe [326160 2017-03-16] (Symantec Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-12-29] (NVIDIA Corporation) R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-25] () R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [312056 2015-08-04] (Realtek Semiconductor) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10883824 2017-03-17] (TeamViewer GmbH) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation) S3 wlpasvc; C:\WINDOWS\System32\lpasvc.dll [1295360 2017-03-18] (Microsoft Corporation) R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe [81536 2012-12-26] (Atheros) [Datei ist nicht signiert] ===================== Treiber (Nicht auf der Ausnahmeliste) ====================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R1 BHDrvx64; C:\Program Files\Norton Security\NortonData\22.9.1.12\Definitions\BASHDefs\20170424.001\BHDrvx64.sys [1831064 2017-04-17] (Symantec Corporation) R3 BTATH_LWFLT; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-28] (Qualcomm Atheros) R1 ccSet_NS; C:\WINDOWS\system32\drivers\NSx64\1609010.00C\ccSetx64.sys [174240 2017-03-16] (Symantec Corporation) R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [77536 2015-07-02] (McAfee, Inc.) R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R3 CPCSProtector; C:\WINDOWS\system32\drivers\cpcs.sys [25928 2013-04-04] (ChicaLogic) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [497304 2017-04-06] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [156824 2017-04-06] (Symantec Corporation) S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [198448 2015-04-27] (McAfee, Inc.) S3 iaLPSS2i_GPIO2_BXT_P; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [85504 2017-03-18] (Intel Corporation) S3 iaLPSS2i_I2C_BXT_P; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [168448 2017-03-18] (Intel Corporation) R1 IDSVia64; C:\Program Files\Norton Security\NortonData\22.9.1.12\Definitions\IPSDefs\20170426.001\IDSvia64.sys [1036440 2017-04-27] (Symantec Corporation) R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [412440 2015-07-02] (McAfee, Inc.) R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [347800 2015-07-02] (McAfee, Inc.) R0 mfedisk; C:\WINDOWS\System32\DRIVERS\mfedisk.sys [101872 2015-02-17] (McAfee, Inc.) S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [80920 2015-07-02] (McAfee, Inc.) R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [496888 2015-07-02] (McAfee, Inc.) R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [875928 2015-07-02] (McAfee, Inc.) R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [483240 2015-03-26] (McAfee, Inc.) S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [100720 2015-03-26] (McAfee, Inc.) R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [344704 2015-07-02] (McAfee, Inc.) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_desktop_ref4wu.inf_amd64_39d8ca1ac617325e\nvlddmkm.sys [14199224 2017-01-04] (NVIDIA Corporation) S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] () R3 SRTSP; C:\WINDOWS\system32\drivers\NSx64\1609010.00C\SRTSP64.SYS [770200 2017-03-16] (Symantec Corporation) R1 SRTSPX; C:\WINDOWS\system32\drivers\NSx64\1609010.00C\SRTSPX64.SYS [49312 2017-03-16] (Symantec Corporation) R0 SymEFASI; C:\WINDOWS\System32\drivers\NSx64\1609010.00C\SYMEFASI64.SYS [1716896 2017-03-16] (Symantec Corporation) S0 SymELAM; C:\WINDOWS\System32\drivers\NSx64\1609010.00C\SymELAM.sys [24616 2017-03-16] (Symantec Corporation) R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [102608 2017-04-20] (Symantec Corporation) R1 SymIRON; C:\WINDOWS\system32\drivers\NSx64\1609010.00C\Ironx64.SYS [291480 2017-03-16] (Symantec Corporation) R1 SymNetS; C:\WINDOWS\system32\drivers\NSx64\1609010.00C\SYMNETS.SYS [567512 2017-03-16] (Symantec Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) R3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [54344 2016-11-22] (Intel Corporation) S3 NAVENG; \??\C:\Program Files\Norton Security\NortonData\22.9.1.12\Definitions\SDSDefs\20170420.002\NAVENG.SYS [X] S3 NAVEX15; \??\C:\Program Files\Norton Security\NortonData\22.9.1.12\Definitions\SDSDefs\20170420.002\NAVEX15.SYS [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) NETSVCx32: TokenBroker -> C:\Windows\SysWOW64\TokenBroker.dll (Microsoft Corporation) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-04-28 17:10 - 2017-04-28 17:11 - 00026198 _____ C:\Users\Julien\Downloads\FRST.txt 2017-04-28 17:10 - 2017-04-28 17:10 - 02427392 _____ (Farbar) C:\Users\Julien\Downloads\FRST64.exe 2017-04-28 17:10 - 2017-04-28 17:10 - 00000000 ____D C:\FRST 2017-04-28 16:54 - 2017-04-28 16:54 - 03144880 _____ (Avira Operations GmbH & Co. KG) C:\Users\Julien\Downloads\avira_registry_cleaner_de.exe 2017-04-28 16:52 - 2017-04-28 16:52 - 00000000 ___HD C:\OneDriveTemp 2017-04-28 16:42 - 2017-04-28 16:42 - 00000000 ___RD C:\Users\Julien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2017-04-27 19:23 - 2017-04-27 19:23 - 00000640 _____ C:\Users\Julien\Desktop\LuPO-Schülerversion.lnk 2017-04-27 19:23 - 2017-04-27 19:23 - 00000640 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LuPO-Schülerversion.lnk 2017-04-27 19:23 - 2017-04-27 19:23 - 00000625 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LuPO-Lehrerversion.lnk 2017-04-27 19:23 - 2017-04-27 19:23 - 00000613 _____ C:\Users\Public\Desktop\LuPO-Lehrerversion.lnk 2017-04-27 19:23 - 2017-04-27 19:23 - 00000425 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LuPO-Versionshinweise.lnk 2017-04-27 19:23 - 2017-04-27 19:23 - 00000000 ____D C:\LuPO 2017-04-25 21:48 - 2017-04-25 21:48 - 04102600 _____ C:\Users\Julien\Downloads\adwcleaner_6.046.exe 2017-04-24 21:48 - 2017-04-24 21:48 - 00000868 _____ C:\Users\Julien\Downloads\FRITZ!Box_Fon_WLAN_7390_84.06.83_24.04.2017_21_48-diagnose.csv 2017-04-21 21:30 - 2017-04-21 21:30 - 00000000 ____D C:\Program Files\Adblock Plus for IE 2017-04-21 21:28 - 2017-04-21 21:28 - 01496584 _____ C:\Users\Julien\Downloads\adblockplusie-1.5 - CHIP-Installer.exe 2017-04-21 21:26 - 2017-04-21 21:26 - 00002854 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2017-04-21 21:26 - 2017-04-21 21:26 - 00002338 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-04-21 21:26 - 2017-04-21 21:26 - 00002326 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-04-21 21:26 - 2017-04-21 21:26 - 00000865 _____ C:\Users\Public\Desktop\CCleaner.lnk 2017-04-21 21:26 - 2017-04-21 21:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2017-04-21 21:26 - 2017-04-21 21:26 - 00000000 ____D C:\Program Files\CCleaner 2017-04-21 21:25 - 2017-04-21 21:30 - 00003628 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2017-04-21 21:25 - 2017-04-21 21:30 - 00003504 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2017-04-21 21:25 - 2017-04-21 21:29 - 00000000 ____D C:\Users\Julien\AppData\Local\Google 2017-04-21 21:25 - 2017-04-21 21:25 - 09390672 _____ (Piriform Ltd) C:\Users\Julien\Downloads\ccsetup529.exe 2017-04-20 20:36 - 2017-04-28 17:09 - 00000000 ____D C:\WINDOWS\System32\Tasks\Remediation 2017-04-20 20:29 - 2017-04-21 15:59 - 00000000 ____D C:\Users\Julien\AppData\Local\NPE 2017-04-20 20:28 - 2017-04-28 16:52 - 00000000 ____D C:\Users\Julien\AppData\Local\CrashDumps 2017-04-20 19:45 - 2017-04-28 16:52 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Security 2017-04-20 19:43 - 2017-04-20 19:43 - 00102608 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS 2017-04-20 19:43 - 2017-04-20 19:43 - 00008298 _____ C:\WINDOWS\system32\Drivers\SYMEVENT64x86.CAT 2017-04-20 19:43 - 2017-04-20 19:43 - 00003374 _____ C:\WINDOWS\System32\Tasks\Norton WSC Integration 2017-04-20 19:43 - 2017-04-20 19:43 - 00002208 _____ C:\Users\Public\Desktop\Norton Security.lnk 2017-04-20 19:43 - 2017-04-20 19:43 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared 2017-04-20 19:42 - 2017-04-20 19:43 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security 2017-04-20 19:42 - 2017-04-20 19:42 - 00000000 ____D C:\WINDOWS\system32\Drivers\NSx64 2017-04-20 19:42 - 2017-04-20 19:42 - 00000000 ____D C:\ProgramData\NortonInstaller 2017-04-20 19:42 - 2017-04-20 19:42 - 00000000 ____D C:\Program Files\Norton Security 2017-04-20 19:42 - 2017-04-20 19:42 - 00000000 ____D C:\Program Files (x86)\NortonInstaller 2017-04-20 19:39 - 2017-04-20 19:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-04-20 19:39 - 2017-04-20 19:39 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-04-20 19:39 - 2016-12-29 14:43 - 00133056 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe 2017-04-20 19:39 - 2016-09-09 20:25 - 00269600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2017-04-20 19:39 - 2016-09-09 20:25 - 00261920 _____ C:\WINDOWS\system32\vulkan-1.dll 2017-04-20 19:39 - 2016-09-09 20:25 - 00110880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2017-04-20 19:39 - 2016-09-09 20:24 - 00125216 _____ C:\WINDOWS\system32\vulkaninfo.exe 2017-04-20 19:37 - 2017-04-20 20:29 - 00000000 ____D C:\ProgramData\Norton 2017-04-20 19:37 - 2017-04-20 19:37 - 00000000 ____D C:\Users\Public\Downloads\Norton 2017-04-19 11:47 - 2017-04-19 11:47 - 00000597 _____ C:\Users\Julien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Laura Sicherung (2).lnk 2017-04-18 22:51 - 2017-04-18 22:51 - 00000000 ____D C:\Users\Julien\AppData\Local\DBG 2017-04-18 22:47 - 2017-04-19 10:56 - 00000000 ____D C:\Users\Julien\AppData\Local\MicrosoftEdge 2017-04-18 22:24 - 2017-04-18 22:25 - 00000000 ____D C:\Windows.old 2017-04-18 22:24 - 2017-04-18 22:24 - 23680512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 23675392 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 20505600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 19334144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 11869696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 08319392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-04-18 22:24 - 2017-04-18 22:24 - 08247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 06756920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 06296064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 05477088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 03672064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-04-18 22:24 - 2017-04-18 22:24 - 02957824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2017-04-18 22:24 - 2017-04-18 22:24 - 02444184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2017-04-18 22:24 - 2017-04-18 22:24 - 02085280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 01760264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 01657344 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 01605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 01604312 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 01518088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 01506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 01411640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 01323880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2017-04-18 22:24 - 2017-04-18 22:24 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 01024416 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2017-04-18 22:24 - 2017-04-18 22:24 - 00986592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00805376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2017-04-18 22:24 - 2017-04-18 22:24 - 00626520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2017-04-18 22:24 - 2017-04-18 22:24 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2017-04-18 22:24 - 2017-04-18 22:24 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2017-04-18 22:24 - 2017-04-18 22:24 - 00409504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2017-04-18 22:24 - 2017-04-18 22:24 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00205728 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2017-04-18 22:24 - 2017-04-18 22:24 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys 2017-04-18 22:24 - 2017-04-18 22:24 - 00032004 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin 2017-04-18 22:23 - 2017-04-18 22:23 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2017-04-18 22:23 - 2017-04-18 22:23 - 00388000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2017-04-18 22:22 - 2017-04-18 22:22 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2017-04-18 22:18 - 2017-04-18 22:18 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2017-04-18 22:18 - 2017-04-18 22:18 - 00000000 ____D C:\Program Files\Reference Assemblies 2017-04-18 22:18 - 2017-04-18 22:18 - 00000000 ____D C:\Program Files\MSBuild 2017-04-18 22:18 - 2017-04-18 22:18 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2017-04-18 22:18 - 2017-04-18 22:18 - 00000000 ____D C:\Program Files (x86)\MSBuild 2017-04-18 22:17 - 2017-02-10 12:26 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 2017-04-18 22:17 - 2017-02-10 12:26 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2017-04-18 22:17 - 2017-02-10 12:26 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2017-04-18 22:17 - 2017-02-10 12:21 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2017-04-18 22:17 - 2017-02-10 12:21 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2017-04-18 22:17 - 2017-02-10 12:21 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2017-04-18 22:15 - 2017-04-18 22:15 - 00003274 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2 2017-04-18 22:15 - 2017-04-18 22:15 - 00002426 _____ C:\Users\Julien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-04-18 22:12 - 2017-04-21 16:02 - 00000000 ____D C:\Users\Julien\AppData\Local\Comms 2017-04-18 22:12 - 2017-04-18 22:12 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2017-04-18 22:10 - 2017-04-18 22:11 - 00000000 ____D C:\Users\Julien\AppData\Local\ConnectedDevicesPlatform 2017-04-18 22:10 - 2017-04-18 22:10 - 00000020 ___SH C:\Users\Julien\ntuser.ini 2017-04-18 22:10 - 2017-04-18 22:10 - 00000000 ____D C:\Users\Julien\AppData\Local\TileDataLayer 2017-04-18 22:10 - 2017-04-18 22:10 - 00000000 ____D C:\Users\Julien\AppData\Local\Publishers 2017-04-18 21:53 - 2017-04-18 21:57 - 00011433 _____ C:\WINDOWS\diagwrn.xml 2017-04-18 21:53 - 2017-04-18 21:57 - 00011433 _____ C:\WINDOWS\diagerr.xml 2017-04-18 21:51 - 2017-04-28 16:41 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-04-18 21:51 - 2017-04-21 14:06 - 00003556 _____ C:\WINDOWS\System32\Tasks\PCDEventLauncher 2017-04-18 21:51 - 2017-04-18 21:51 - 00003662 _____ C:\WINDOWS\System32\Tasks\PCDoctorBackgroundMonitorTask 2017-04-18 21:51 - 2017-04-18 21:51 - 00003256 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2017-04-18 21:51 - 2017-04-18 21:51 - 00003080 _____ C:\WINDOWS\System32\Tasks\ReimageUpdater 2017-04-18 21:51 - 2017-04-18 21:51 - 00003072 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{C7D19CF0-E87B-43C3-8D3E-595AD8772A0A} 2017-04-18 21:51 - 2017-04-18 21:51 - 00002950 _____ C:\WINDOWS\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d 2017-04-18 21:51 - 2017-04-18 21:51 - 00002848 _____ C:\WINDOWS\System32\Tasks\SystemToolsDailyTest 2017-04-18 21:51 - 2017-04-18 21:51 - 00002808 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-836797742-737356516-1884966141-1001 2017-04-18 21:51 - 2017-04-18 21:51 - 00002702 _____ C:\WINDOWS\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon 2017-04-18 21:51 - 2017-04-18 21:51 - 00002350 _____ C:\WINDOWS\System32\Tasks\CLVDLauncher 2017-04-18 21:51 - 2017-04-18 21:51 - 00002350 _____ C:\WINDOWS\System32\Tasks\CLMLSvc_P2G8 2017-04-18 21:51 - 2017-04-18 21:51 - 00001836 _____ C:\WINDOWS\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance 2017-04-18 21:51 - 2017-04-18 21:51 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD 2017-04-18 21:51 - 2017-04-18 21:51 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee 2017-04-18 21:51 - 2017-04-18 21:51 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple 2017-04-18 21:48 - 2017-04-28 16:48 - 02197866 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-04-18 21:41 - 2017-04-18 21:41 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2017-04-18 21:39 - 2017-04-18 21:39 - 00000000 ____D C:\ProgramData\USOShared 2017-04-18 21:36 - 2017-04-18 21:36 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate 2017-04-18 21:35 - 2017-04-28 16:41 - 00000000 ____D C:\Users\Julien 2017-04-18 21:35 - 2017-04-20 20:18 - 00000000 ____D C:\Users\Administrator 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\Vorlagen 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\Startmenü 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\Netzwerkumgebung 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\Lokale Einstellungen 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\Eigene Dateien 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\Druckumgebung 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\Documents\Eigene Videos 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\Documents\Eigene Musik 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\Documents\Eigene Bilder 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\AppData\Local\Verlauf 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\AppData\Local\Anwendungsdaten 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Julien\Anwendungsdaten 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\Vorlagen 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\Startmenü 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\Netzwerkumgebung 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\Lokale Einstellungen 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\Eigene Dateien 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\Druckumgebung 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Videos 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Musik 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\Documents\Eigene Bilder 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Verlauf 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\AppData\Local\Anwendungsdaten 2017-04-18 21:35 - 2017-04-18 21:35 - 00000000 _SHDL C:\Users\Administrator\Anwendungsdaten 2017-04-18 21:31 - 2017-04-28 16:41 - 00000000 ____D C:\ProgramData\NVIDIA 2017-04-18 21:31 - 2017-04-20 19:39 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-04-18 21:31 - 2017-04-18 21:36 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2017-04-18 21:31 - 2017-04-18 21:36 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2017-04-18 21:31 - 2017-04-18 21:31 - 00463760 _____ C:\WINDOWS\system32\Drivers\rtwavesmapro.dat 2017-04-18 21:31 - 2017-04-18 21:31 - 00019501 _____ C:\WINDOWS\system32\Drivers\rtwavesmaprocap.dat 2017-04-18 21:31 - 2017-04-18 21:31 - 00000000 ____H C:\ProgramData\DP45977C.lfl 2017-04-18 21:31 - 2017-04-18 21:31 - 00000000 ____D C:\WINDOWS\system32\SRSLabs 2017-04-18 21:31 - 2017-04-18 21:31 - 00000000 ____D C:\Program Files\Common Files\logishrd 2017-04-18 21:31 - 2017-03-18 22:56 - 02233344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2017-04-18 21:31 - 2016-12-29 14:44 - 06386232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2017-04-18 21:31 - 2016-12-29 14:44 - 02477624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2017-04-18 21:31 - 2016-12-29 14:44 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2017-04-18 21:31 - 2016-12-29 14:44 - 00546752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2017-04-18 21:31 - 2016-12-29 14:44 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2017-04-18 21:31 - 2016-12-29 14:44 - 00083512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2017-04-18 21:31 - 2016-12-29 14:44 - 00069568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2017-04-18 21:31 - 2016-12-19 09:26 - 07651057 _____ C:\WINDOWS\system32\nvcoproc.bin 2017-04-18 21:30 - 2017-04-18 21:30 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2017-04-18 21:30 - 2017-04-18 21:30 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2017-04-18 21:30 - 2017-04-18 21:30 - 00000000 ____D C:\Program Files\Realtek 2017-04-18 21:30 - 2017-04-18 21:30 - 00000000 ____D C:\Program Files\Common Files\Atheros 2017-04-18 21:28 - 2017-04-28 16:37 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-04-18 21:28 - 2017-04-20 19:56 - 00275248 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-04-18 21:28 - 2017-04-18 21:28 - 00000000 ____D C:\WINDOWS\ServiceProfiles 2017-04-18 19:37 - 2017-04-21 21:30 - 00000000 ___DC C:\WINDOWS\Panther 2017-04-18 19:37 - 2017-04-18 20:26 - 00000000 ___HD C:\$WINDOWS.~BT 2017-04-18 19:35 - 2017-04-18 19:37 - 00000036 _____ C:\WINDOWS\progress.ini 2017-04-18 18:53 - 2017-04-18 22:09 - 00000000 ___HD C:\$GetCurrent 2017-04-18 18:52 - 2017-04-18 22:10 - 00000000 ____D C:\Windows10Upgrade 2017-04-18 18:52 - 2017-04-18 18:52 - 00000704 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10-Upgrade-Assistent.lnk 2017-04-18 18:52 - 2017-04-18 18:52 - 00000692 _____ C:\Users\Julien\Desktop\Windows 10-Upgrade-Assistent.lnk 2017-04-16 13:37 - 2017-04-18 21:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ChicaLogic 2017-04-16 13:37 - 2017-04-16 13:37 - 00000000 ____D C:\Users\Julien\AppData\Roaming\ChicaLogic 2017-04-16 13:37 - 2017-04-16 13:37 - 00000000 ____D C:\ProgramData\ChicaLogic 2017-04-16 13:37 - 2017-04-16 13:37 - 00000000 ____D C:\Program Files (x86)\ChicaLogic 2017-04-16 13:37 - 2013-04-04 14:51 - 00025928 _____ (ChicaLogic) C:\WINDOWS\system32\Drivers\cpcs.sys 2017-04-16 13:35 - 2017-04-25 21:59 - 00000000 ____D C:\AdwCleaner 2017-04-16 12:31 - 2017-04-21 21:30 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2017-04-16 12:31 - 2017-04-16 12:38 - 00000985 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk 2017-04-16 12:31 - 2017-04-16 12:31 - 00000000 ____D C:\Users\Julien\AppData\Roaming\TeamViewer 2017-04-15 20:19 - 2017-04-16 09:09 - 00000000 ____D C:\ReimageUndo 2017-04-15 20:06 - 2017-04-16 14:00 - 00000140 _____ C:\WINDOWS\Reimage.ini 2017-04-15 20:06 - 2017-04-16 09:08 - 00000000 ____D C:\rei 2017-04-15 20:06 - 2017-04-15 20:07 - 00000000 ____D C:\Program Files\Reimage 2017-04-15 15:50 - 2016-08-22 18:33 - 00002090 _____ C:\Users\Julien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Madlens IPhone.lnk 2017-04-14 19:39 - 2017-04-14 19:39 - 00029195 _____ C:\ProgramData\agent.1492191576.bdinstall.bin 2017-04-14 17:31 - 2017-04-14 17:31 - 00047397 _____ C:\ProgramData\agent.1492183909.bdinstall.bin 2017-04-14 17:31 - 2017-04-14 17:31 - 00000000 ____D C:\ProgramData\Bitdefender Agent 2017-04-14 17:30 - 2017-04-14 17:30 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_avusbflt_01011.Wdf 2017-04-14 17:22 - 2017-04-14 17:22 - 01496584 _____ C:\Users\Julien\Downloads\AntiVir Avira Free Antivirus - CHIP-Installer.exe 2017-04-10 15:29 - 2017-04-24 19:40 - 00000000 ____D C:\Users\Julien\AppData\Roaming\Skype 2017-04-10 15:29 - 2017-04-18 21:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2017-04-10 15:29 - 2017-04-18 21:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2017-04-10 15:29 - 2017-04-10 15:29 - 00002715 _____ C:\Users\Public\Desktop\Skype.lnk 2017-04-10 15:29 - 2017-04-10 15:29 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-04-10 15:29 - 2017-04-10 15:29 - 00000000 ____D C:\Users\Julien\AppData\Local\Skype 2017-04-10 15:29 - 2017-04-10 15:29 - 00000000 ____D C:\ProgramData\Skype 2017-04-10 15:28 - 2017-04-14 17:27 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2017-04-10 15:25 - 2016-12-29 15:06 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat 2017-04-10 15:18 - 2014-11-08 04:03 - 00733696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll 2017-04-10 15:16 - 2017-02-22 16:35 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\centel.dll 2017-04-07 16:28 - 2017-04-07 16:28 - 00000000 ____D C:\Users\Julien\AppData\Local\ElevatedDiagnostics ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2017-04-28 16:52 - 2015-02-02 22:53 - 00000000 __RDO C:\Users\Julien\OneDrive 2017-04-28 16:48 - 2017-03-20 06:35 - 00988064 _____ C:\WINDOWS\system32\perfh007.dat 2017-04-28 16:48 - 2017-03-20 06:35 - 00215892 _____ C:\WINDOWS\system32\perfc007.dat 2017-04-28 16:45 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-04-27 20:32 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps 2017-04-25 21:59 - 2017-03-18 13:40 - 00008192 _____ C:\WINDOWS\system32\config\ELAM 2017-04-25 21:47 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF 2017-04-22 19:28 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\rescache 2017-04-22 18:53 - 2015-02-15 13:05 - 00000000 ____D C:\Users\Julien\AppData\Roaming\Audacity 2017-04-21 21:51 - 2017-03-18 13:40 - 01310720 _____ C:\WINDOWS\system32\config\BBI 2017-04-21 21:30 - 2015-02-02 20:36 - 00000000 ____D C:\Users\Julien\AppData\LocalLow\Adblock Plus for IE 2017-04-21 21:26 - 2015-01-30 23:22 - 00000000 ____D C:\Program Files (x86)\Google 2017-04-20 23:19 - 2016-12-29 16:23 - 00001473 _____ C:\Users\Public\Desktop\Free YouTube To MP3 Converter.lnk 2017-04-20 23:19 - 2016-12-29 16:21 - 00001410 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2017-04-20 23:19 - 2016-12-29 16:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2017-04-20 23:19 - 2016-12-29 16:20 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2017-04-20 22:50 - 2013-10-17 10:44 - 00000000 ____D C:\Program Files (x86)\Dell Wireless 2017-04-20 21:02 - 2016-12-29 16:23 - 00000000 ____D C:\ProgramData\DigitalWave.ApplicationUpdater_files 2017-04-20 20:36 - 2015-07-21 18:53 - 00000000 ____D C:\Program Files\Common Files\AV 2017-04-20 20:11 - 2015-08-14 21:46 - 00000000 ____D C:\ProgramData\Package Cache 2017-04-20 20:08 - 2015-01-30 20:24 - 00000000 ____D C:\Users\Julien\AppData\Local\Packages 2017-04-20 19:43 - 2017-03-18 23:03 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2017-04-20 19:40 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-04-20 19:39 - 2013-10-17 10:55 - 00000000 ____D C:\Temp 2017-04-19 10:46 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\appcompat 2017-04-18 22:27 - 2017-03-18 23:03 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2017-04-18 22:25 - 2017-03-18 23:06 - 00000000 ____D C:\WINDOWS\Setup 2017-04-18 22:18 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2017-04-18 22:18 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\MUI 2017-04-18 22:10 - 2013-11-03 11:24 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-04-18 21:58 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2017-04-18 21:58 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows NT 2017-04-18 21:57 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Registration 2017-04-18 21:52 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2017-04-18 21:51 - 2015-02-02 22:28 - 00023056 _____ C:\WINDOWS\system32\emptyregdb.dat 2017-04-18 21:49 - 2017-03-18 23:03 - 00000000 __RHD C:\Users\Public\Libraries 2017-04-18 21:48 - 2013-10-17 10:41 - 01849942 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI 2017-04-18 21:42 - 2017-03-03 16:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2017-04-18 21:42 - 2016-10-31 22:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2017-04-18 21:42 - 2016-09-07 22:09 - 00000000 ____D C:\Users\Julien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU 2017-04-18 21:42 - 2016-09-07 22:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU 2017-04-18 21:42 - 2016-08-05 11:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\freac - free audio converter 2017-04-18 21:42 - 2015-07-20 10:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FUJIdirekt 2017-04-18 21:42 - 2015-07-13 19:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nikon Message Center 2 2017-04-18 21:42 - 2015-07-13 19:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Capture NX 2 2017-04-18 21:42 - 2015-04-26 20:23 - 00000000 ____D C:\Users\Julien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\dreamboxEDIT 2017-04-18 21:42 - 2015-01-31 12:40 - 00000000 ____D C:\WINDOWS\system32\AutoUpdateLicense 2017-04-18 21:42 - 2015-01-30 23:18 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0 2017-04-18 21:42 - 2015-01-30 22:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2017-04-18 21:42 - 2015-01-30 20:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2017-04-18 21:42 - 2013-10-17 10:58 - 00000000 ____D C:\WINDOWS\de 2017-04-18 21:42 - 2013-10-17 10:50 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite 2017-04-18 21:42 - 2013-10-17 10:49 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Support Center 2017-04-18 21:42 - 2013-10-17 10:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell 2017-04-18 21:42 - 2013-10-17 10:41 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2017-04-18 21:39 - 2017-03-20 06:35 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\IME 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\spool 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\oobe 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\NDF 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\lv-LV 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\lt-LT 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\InputMethod 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\IME 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\et-EE 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\en-GB 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\USOPrivate 2017-04-18 21:39 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-04-18 21:39 - 2013-10-17 10:43 - 00000000 ____D C:\WINDOWS\SysWOW64\sda 2017-04-18 21:39 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared 2017-04-18 21:39 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared 2017-04-18 21:37 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\MediaViewer 2017-04-18 21:36 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\InputMethod 2017-04-18 21:36 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2017-04-18 21:36 - 2015-07-31 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2017-04-18 21:36 - 2015-01-30 20:24 - 00000000 ____D C:\ProgramData\PRICache 2017-04-18 21:36 - 2013-10-17 10:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HotSpot 2017-04-18 21:36 - 2013-10-17 10:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atheros Smart Net 2017-04-18 21:36 - 2013-10-17 10:44 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Program 2017-04-18 21:35 - 2013-10-17 11:13 - 00000000 ____D C:\Users\Administrator\AppData\Local\Packages 2017-04-18 21:35 - 2013-10-17 10:44 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2017-04-18 21:34 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2017-04-18 21:32 - 2017-03-20 06:37 - 00000000 ____D C:\WINDOWS\HoloShell 2017-04-18 21:32 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\PrintDialog 2017-04-18 21:32 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\MiracastView 2017-04-18 21:32 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2017-04-18 21:31 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Help 2017-04-15 19:46 - 2015-01-30 20:51 - 00001116 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2017-04-15 19:46 - 2015-01-30 20:51 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2017-04-15 16:39 - 2016-04-13 19:57 - 00103936 ___SH C:\Users\Julien\Downloads\Thumbs.db 2017-04-15 13:15 - 2014-08-29 21:21 - 00000200 _____ C:\Users\Julien\Desktop\YouTube.url 2017-04-14 19:40 - 2015-10-12 08:38 - 00000000 ____D C:\Users\Julien\AppData\Roaming\IrfanView 2017-04-14 17:31 - 2017-03-25 17:40 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-04-14 17:30 - 2015-01-30 21:21 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-04-14 17:28 - 2015-01-30 21:21 - 148601744 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-04-14 17:27 - 2015-02-03 21:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2017-04-10 15:31 - 2013-08-22 17:36 - 00000000 ___RD C:\WINDOWS\ToastData 2017-04-10 15:29 - 2013-11-03 11:46 - 00000000 ____D C:\Users\Julien\Documents\Bluetooth Folder 2017-04-10 15:10 - 2016-10-31 22:08 - 00000000 ____D C:\Users\Julien\AppData\Local\AvgSetupLog 2017-04-10 15:10 - 2016-10-31 22:08 - 00000000 ____D C:\ProgramData\Avg 2017-04-10 15:10 - 2016-10-31 22:08 - 00000000 ____D C:\Program Files (x86)\AVG 2017-04-10 15:10 - 2016-09-05 17:05 - 00000000 ___RD C:\Users\Julien\Dropbox 2017-04-10 15:05 - 2016-09-07 22:09 - 00000000 ____D C:\Users\Julien\AppData\Roaming\AVS4YOU 2017-04-08 13:27 - 2015-07-31 20:56 - 00035813 ____H C:\Users\Julien\AppData\Local\IconCache.db.backup 2017-04-03 18:56 - 2017-03-18 23:06 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-04-03 18:56 - 2017-03-18 23:06 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2015-07-13 19:27 - 2015-07-13 19:27 - 0000268 ___RH () C:\Users\Julien\AppData\Roaming\Conditionals 2015-07-13 19:27 - 2015-07-13 19:27 - 0000268 ___RH () C:\Users\Julien\AppData\Roaming\Configure Folder Actions 2017-04-14 17:31 - 2017-04-14 17:31 - 0047397 _____ () C:\ProgramData\agent.1492183909.bdinstall.bin 2017-04-14 19:39 - 2017-04-14 19:39 - 0029195 _____ () C:\ProgramData\agent.1492191576.bdinstall.bin 2015-07-13 19:27 - 2015-07-13 19:27 - 0000268 ___RH () C:\ProgramData\Contextual Menu Items 2015-07-13 19:27 - 2015-07-13 19:27 - 0000268 ___RH () C:\ProgramData\Core Data Application 2017-04-18 21:31 - 2017-04-18 21:31 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2015-07-13 19:25 - 2015-09-14 19:47 - 0000020 ____H () C:\ProgramData\PKP_DLbx.DAT 2015-07-13 19:27 - 2015-07-13 19:27 - 0000020 ____H () C:\ProgramData\PKP_DLck.DAT 2013-10-17 10:54 - 2013-10-17 10:54 - 0000119 _____ () C:\ProgramData\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}.log 2013-10-17 10:50 - 2013-10-17 10:51 - 0000106 _____ () C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log 2013-10-17 10:51 - 2013-10-17 10:53 - 0000111 _____ () C:\ProgramData\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}.log 2013-10-17 10:50 - 2013-10-17 10:50 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log 2013-10-17 10:53 - 2013-10-17 10:54 - 0000108 _____ () C:\ProgramData\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}.log ==================== Bamital & volsnap ====================== (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert C:\WINDOWS\explorer.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert C:\WINDOWS\system32\services.exe => Datei ist digital signiert C:\WINDOWS\system32\User32.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2017-04-18 21:28 ==================== Ende von FRST.txt Geändert von gregster (28.04.2017 um 18:44 Uhr) |
Themen zu Thema: ADWCleaner6.046 läuft durch beim Löschen hängt sich der PC auf - was kann die Ursache sein? |
dateien, durchgeführt, folge, folgendes, freeware, funktioniert, gekauft, home, hängt, komplett, leute, löschen, löschung, malwarebytes, modus, neu, norton, problem, programme, programmen, reset, scan, thema, virenprogramme, windowsapps, würde |