Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 07.10.2015 19:56, SYSTEM, MAX-PC, Protection, Malware Protection, Starting,
Protection, 07.10.2015 19:56, SYSTEM, MAX-PC, Protection, Malware Protection, Started,
Protection, 07.10.2015 19:56, SYSTEM, MAX-PC, Protection, Malicious Website Protection, Starting,
Protection, 07.10.2015 19:56, SYSTEM, MAX-PC, Protection, Malicious Website Protection, Started,
Error, 07.10.2015 19:57, SYSTEM, MAX-PC, Update, Bad md5 or size: akadomains, 11,
Error, 07.10.2015 19:57, SYSTEM, MAX-PC, Update, Bad md5 or size: akaips, 11,
Update, 07.10.2015 19:57, SYSTEM, MAX-PC, Manual, Rootkit Database, 2015.6.2.1, 2015.10.6.1,
Update, 07.10.2015 19:57, SYSTEM, MAX-PC, Manual, AKA Domain Database, 0.0.0.0, 2015.9.11.2,
Update, 07.10.2015 19:57, SYSTEM, MAX-PC, Manual, AKA IP Database, 0.0.0.0, 2015.9.11.2,
Update, 07.10.2015 19:57, SYSTEM, MAX-PC, Manual, Remediation Database, 2015.5.13.1, 2015.10.7.2,
Update, 07.10.2015 19:57, SYSTEM, MAX-PC, Manual, IP Database, 0.0.0.0, 2015.10.6.2,
Update, 07.10.2015 19:57, SYSTEM, MAX-PC, Manual, Domain Database, 0.0.0.0, 2015.10.7.1,
Update, 07.10.2015 19:57, SYSTEM, MAX-PC, Manual, Malware Database, 2015.6.3.3, 2015.10.7.5,
Protection, 07.10.2015 19:57, SYSTEM, MAX-PC, Protection, Refresh, Starting,
Protection, 07.10.2015 19:57, SYSTEM, MAX-PC, Protection, Malicious Website Protection, Stopping,
Protection, 07.10.2015 19:57, SYSTEM, MAX-PC, Protection, Malicious Website Protection, Stopped,
Protection, 07.10.2015 19:57, SYSTEM, MAX-PC, Protection, Refresh, Success,
Protection, 07.10.2015 19:57, SYSTEM, MAX-PC, Protection, Malicious Website Protection, Starting,
Protection, 07.10.2015 19:57, SYSTEM, MAX-PC, Protection, Malicious Website Protection, Started,
Detection, 07.10.2015 20:02, rieme_000, MAX-PC, Protection, Malware-Schutz, Datei, PUP.Optional.ZombieInvasion, C:\ProgramData\FNDJCjV\dat\PhvoINk.exe, Quarantine Failed, 303, Queued for removal on reboot, [68b91b39f794ab8bd967d0f48a77817f]
Detection, 07.10.2015 20:02, SYSTEM, MAX-PC, Protection, Malware-Schutz, Datei, PUP.Optional.ZombieInvasion, C:\ProgramData\FNDJCjV\dat\PhvoINk.exe, Quarantine Failed, 303, Queued for removal on reboot, [68b91b39f794ab8bd967d0f48a77817f]
Detection, 07.10.2015 20:02, SYSTEM, MAX-PC, Protection, Malware-Schutz, Datei, PUP.Optional.ZombieInvasion, C:\ProgramData\FNDJCjV\dat\PhvoINk.exe, Quarantine Failed, 303, Queued for removal on reboot, [68b91b39f794ab8bd967d0f48a77817f]
Detection, 07.10.2015 20:02, SYSTEM, MAX-PC, Protection, Malware-Schutz, Datei, PUP.Optional.ZombieInvasion, C:\ProgramData\FNDJCjV\dat\PhvoINk.exe, Quarantine Failed, 303, Queued for removal on reboot, [68b91b39f794ab8bd967d0f48a77817f]
Detection, 07.10.2015 20:31, SYSTEM, MAX-PC, Protection, Malware-Schutz, Datei, Adware.PullUpdate, C:\ProgramData\Nagnetoelxru\1.0.6.1\soiweiim.exe, Quarantine Failed, 5, Zugriff verweigert , [58c9e86c048769cd82f53f79a160de22]
Detection, 07.10.2015 20:31, SYSTEM, MAX-PC, Protection, Malware-Schutz, Datei, PUP.Optional.ZombieInvasion, C:\ProgramData\FNDJCjV\dat\PhvoINk.exe, Quarantine Failed, 303, Queued for removal on reboot, [68b91b39f794ab8bd967d0f48a77817f]
Detection, 07.10.2015 20:31, SYSTEM, MAX-PC, Protection, Malware-Schutz, Datei, PUP.Optional.ZombieInvasion, C:\ProgramData\FNDJCjV\dat\PhvoINk.exe, Quarantine Failed, 303, Queued for removal on reboot, [68b91b39f794ab8bd967d0f48a77817f]
Detection, 07.10.2015 20:31, rieme_000, MAX-PC, Protection, Malware-Schutz, Datei, PUP.Optional.ZombieInvasion, C:\ProgramData\FNDJCjV\dat\PhvoINk.exe, Quarantine Failed, 303, Queued for removal on reboot, [68b91b39f794ab8bd967d0f48a77817f]
Detection, 07.10.2015 20:31, SYSTEM, MAX-PC, Protection, Malware-Schutz, Datei, PUP.Optional.ZombieInvasion, C:\ProgramData\FNDJCjV\dat\PhvoINk.exe, Quarantine Failed, 303, Queued for removal on reboot, [68b91b39f794ab8bd967d0f48a77817f]
Detection, 07.10.2015 20:32, SYSTEM, MAX-PC, Protection, Malware-Schutz, Datei, PUP.Optional.ZombieInvasion, C:\ProgramData\FNDJCjV\dat\PhvoINk.exe, Quarantine Failed, 303, Queued for removal on reboot, [68b91b39f794ab8bd967d0f48a77817f]
Detection, 07.10.2015 20:32, SYSTEM, MAX-PC, Protection, Malware-Schutz, Datei, PUP.Optional.ZombieInvasion, C:\ProgramData\FNDJCjV\dat\PhvoINk.exe, Quarantine Failed, 303, Queued for removal on reboot, [68b91b39f794ab8bd967d0f48a77817f]
(end)
AdwCleaner Logfile: Code:
# AdwCleaner v5.011 - Bericht erstellt am 07/10/2015 um 20:36:50
# Aktualisiert am 07/10/2015 von Xplode
# Datenbank : 2015-10-07.1 [Server]
# Betriebssystem : Windows 10 Home (x64)
# Benutzername : rieme_000 - MAX-PC
# Gestartet von : C:\Users\rieme_000\Downloads\adwcleaner_5.011.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum
***** [ Dienste ] *****
***** [ Ordner ] *****
***** [ Dateien ] *****
***** [ DLLs ] *****
***** [ Verknüpfungen ] *****
***** [ Geplante Tasks ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Internetbrowser ] *****
[-] [C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Gelöscht : npdicihegicnhaangkdmcgbjceoemeoo
[-] [C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Gelöscht : hxxp://www.trovi.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M7C0C8B80-8EB5-4AD3-8417-FB4F5757339E&SearchSource=55&CUI=&UM=8&UP=SPD689CF20-3A2E-48F6-993E-9BC492973DB6&SSPV=
*************************
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Chrome Richtlinien gelöscht
########## EOF - C:\AdwCleaner\AdwCleaner[C10].txt - [1205 Bytes] ########## --- --- ---
JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 10 Home x64
Ran by rieme_000 on 07.10.2015 at 20:42:39,07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_DD8682E172E8E04CF1AF1782D0ACCD0A
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\ProgramData\t122078ed
Successfully deleted: [Folder] C:\WINDOWS\SysWOW64\ai_recyclebin
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\npdicihegicnhaangkdmcgbjceoemeoo
[C:\Users\rieme_000\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\rieme_000\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\rieme_000\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\rieme_000\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
npdicihegicnhaangkdmcgbjceoemeoo
]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 07.10.2015 at 20:45:16,67
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
FRST Logfile: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:04-10-2015
durchgeführt von rieme_000 (Administrator) auf MAX-PC (07-10-2015 20:48:51)
Gestartet von C:\Users\rieme_000\Downloads
Geladene Profile: rieme_000 (Verfügbare Profile: rieme_000 & Gast1 & Administrator)
Platform: Windows 10 Home (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Microsoft Corporation) C:\Windows\System32\Speech_OneCore\Common\SpeechRuntime.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16464_none_116100d161f6ab1d\TiWorker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2611112 2012-09-04] ()
HKLM\...\Run: [TSleepSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSleepSrv.exe [1548952 2012-08-05] (TOSHIBA Corporation)
HKLM\...\Run: [TODDMain] => C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe [213136 2012-08-05] ()
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [169896 2012-08-14] (TOSHIBA Corporation)
HKLM\...\Run: [SRS Premium Sound HD] => C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe [2170784 2012-08-20] (SRS Labs, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3946184 2015-08-05] (Synaptics Incorporated)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-08-02] (Intel Corporation)
HKLM-x32\...\Run: [TPUReg] => C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe [7148032 2012-10-31] (Pegatron Corporation)
HKLM-x32\...\Run: [TPUReg(x86)] => "C:\Program Files\TOSHIBA\Password Utility\TosPU.exe" /Retimes
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2015-04-28] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [36710768 2015-10-02] (Dropbox, Inc.)
HKLM-x32\...\Run: [StartCCC] => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [56080 2015-10-01] (Raptr, Inc)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-3965243783-3504363802-2312614661-1009\...\Run: [Spotify Web Helper] => C:\Users\rieme_000\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2025016 2015-09-18] (Spotify Ltd)
HKU\S-1-5-21-3965243783-3504363802-2312614661-1009\...\Run: [GoogleChromeAutoLaunch_DD8682E172E8E04CF1AF1782D0ACCD0A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944 2015-09-24] (Google Inc.)
HKU\S-1-5-21-3965243783-3504363802-2312614661-1009\...\MountPoints2: {9c27cb7c-53af-11e3-824f-806e6f6e6963} - "E:\Start.exe"
AppInit_DLLs: C:\ProgramData\SecurityUtility\SecurityUtility64.dll => Keine Datei
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-09-11] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-09-11] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-09-11] (Google)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-02] (Dropbox, Inc.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{00818810-2036-4f56-acb7-71b0d05c2fbc}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{f7c3245e-3162-4a46-a49c-4f0fa22b05cb}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
SearchScopes: HKU\S-1-5-21-3965243783-3504363802-2312614661-1009 -> {4A062F34-A2AE-4B30-B13E-C5DBB75DB58E} URL = hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-08-31] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-31] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-21] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-21] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-31] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-31] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [Keine Datei]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => nicht gefunden
Chrome:
=======
CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M7C0C8B80-8EB5-4AD3-8417-FB4F5757339E&SearchSource=55&CUI=&UM=8&UP=SPD689CF20-3A2E-48F6-993E-9BC492973DB6&SSPV=
CHR StartupUrls: Default -> "hxxp://facebook.com/"
CHR Profile: C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (ProxFlow) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2015-02-12]
CHR Extension: (Google Präsentationen) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-09]
CHR Extension: (Google Docs) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-09]
CHR Extension: (Google Drive) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-09]
CHR Extension: (Snapchat web) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbnfijjojffhhchgkgdffpnjnlakcldk [2015-06-25]
CHR Extension: (YouTube) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-09]
CHR Extension: (GMX MailCheck) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\camnampocfohlcgbajligmemmabnljcm [2015-10-06]
CHR Extension: (Adblock Plus) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-09-22]
CHR Extension: (Google-Suche) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-09]
CHR Extension: (Google Tabellen) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-09]
CHR Extension: (Google Text & Tabellen Offline) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-14]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-04]
CHR Extension: (Skype Click to Call) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-06-08]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-09]
CHR Extension: (Google Mail) - C:\Users\rieme_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-09]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
CHR HKLM-x32\...\Chrome\Extension: [ocbnpbkmjpgbdcgiflkgkpnkinifpgpj] - C:\Users\rieme_000\ChromeExtensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj\amazon-icon-2.crx [2015-02-01]
Opera:
=======
OPR StartupUrls: "hxxp://facebook.com/"],"urls_signature":"HGzQt9rhy878nKccbSjwMKQvwTU29KzYd3kRhV3tg+nhRetcy04lzVcdxJtD0CFJ"},"settings":{"privacy":{"drm_salt":"17DC66022EB9EC8135E3875349EE687C89281C611071C2306E72EA3D4BE07BB7"}},"speeddial":{"bookmarks_folder_guid":"6360FD27-4CFE-49BB-81B0-DACAE668DC1D","imported_to_bookmarks":true},"spellcheck":{"dictionaries":["de"],"dictionary":""},"sync":{"acknowledged_types":["Bookmarks","Preferences","Passwords","Autofill Profiles","Autofill","Themes","Typed URLs","Extensions","Search Engines","Sessions","Apps","Device Info","Articles","App List","WiFi Credentials","Tabs","Encryption keys"
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [134512 2015-07-02] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [134512 2015-07-02] (Dropbox, Inc.)
S2 GFNEXSrv; C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe [156672 2011-10-13] () [Datei ist nicht signiert]
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [Datei ist nicht signiert]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-05-15] (Electronic Arts)
S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [201360 2012-08-31] (Realtek Semiconductor)
S2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
S2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-08-05] (Synaptics Incorporated)
R3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [116088 2013-07-18] (Toshiba Europe GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [31992 2015-06-03] (Advanced Micro Devices, Inc.)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4325544 2015-06-28] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-07-22] (Advanced Micro Devices)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [237568 2015-07-10] (Microsoft Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-10-07] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R2 PEGAGFN; C:\Program Files (x86)\TOSHIBA\Password Utility\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek )
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-08-05] (Synaptics Incorporated)
S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [45448 2015-07-25] (Toshiba Corporation)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-10-07 20:49 - 2015-10-07 20:49 - 00001285 _____ C:\Users\rieme_000\Desktop\AdwCleaner[C10].txt
2015-10-07 20:47 - 2015-10-07 20:47 - 00001070 _____ C:\Users\rieme_000\Desktop\FRST64 - Shortcut.lnk
2015-10-07 20:45 - 2015-10-07 20:45 - 00001526 _____ C:\Users\rieme_000\Desktop\JRT.txt
2015-10-07 20:42 - 2015-10-05 23:26 - 01801288 _____ (Malwarebytes) C:\Users\rieme_000\Desktop\JRT.exe
2015-10-07 20:41 - 2015-10-07 20:41 - 00001162 _____ C:\Users\rieme_000\Desktop\adwcleaner_5.011 - Shortcut.lnk
2015-10-07 20:39 - 2015-10-07 20:39 - 00016148 _____ C:\WINDOWS\system32\MAX-PC_rieme_000_HistoryPrediction.bin
2015-10-07 20:34 - 2015-10-07 20:35 - 01681920 _____ C:\Users\rieme_000\Downloads\adwcleaner_5.011.exe
2015-10-07 20:33 - 2015-10-07 20:33 - 00004436 _____ C:\Users\rieme_000\Desktop\mbam.txt
2015-10-07 20:08 - 2015-10-07 20:42 - 01798976 _____ (Malwarebytes) C:\Users\rieme_000\Downloads\JRT.exe
2015-10-07 19:56 - 2015-10-07 20:39 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-10-07 19:56 - 2015-10-07 19:56 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\2F7940E3.sys
2015-10-07 19:55 - 2015-10-07 20:29 - 00001180 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-10-07 19:55 - 2015-10-07 19:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-10-07 19:55 - 2015-10-07 19:55 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-10-07 19:55 - 2015-10-07 19:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-10-07 19:55 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-10-07 19:55 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-10-07 19:55 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-10-07 19:53 - 2015-10-07 19:55 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\rieme_000\Downloads\mbam-setup-2.1.8.1057.exe
2015-10-06 21:11 - 2015-10-06 21:12 - 00040059 _____ C:\Users\rieme_000\Downloads\Addition.txt
2015-10-06 21:10 - 2015-10-07 20:48 - 00022652 _____ C:\Users\rieme_000\Downloads\FRST.txt
2015-10-06 21:10 - 2015-10-06 21:10 - 02193920 _____ (Farbar) C:\Users\rieme_000\Downloads\FRST64.exe
2015-10-04 20:11 - 2015-10-04 20:12 - 00544408 _____ C:\Users\rieme_000\Downloads\abc-stundenplan-1.10.0303-setup.exe
2015-10-04 20:08 - 2015-10-04 20:08 - 00000000 ____D C:\Users\rieme_000\AppData\Roaming\gp-Untis
2015-10-04 20:06 - 2015-10-04 20:09 - 00000000 ____D C:\Program Files (x86)\Untis
2015-10-04 20:06 - 2015-10-04 20:08 - 00000000 ____D C:\Users\rieme_000\Documents\Untis
2015-10-04 20:06 - 2015-10-04 20:06 - 00000000 ____D C:\Users\rieme_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Untis
2015-10-04 20:00 - 2015-10-04 20:06 - 68310655 _____ (Gruber & Petters) C:\Users\rieme_000\Downloads\SetupExpressDE.exe
2015-10-04 19:57 - 2015-10-04 19:57 - 00008584 _____ C:\Users\rieme_000\Downloads\Excel-Vorlage-_Stundenplan.zip
2015-10-03 05:54 - 2015-10-03 05:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-09-30 20:59 - 2015-10-07 20:48 - 00000000 ____D C:\FRST
2015-09-30 20:29 - 2015-09-30 20:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cornelsen
2015-09-30 20:27 - 2015-09-30 20:27 - 00000000 ____D C:\Program Files (x86)\Cornelsen
2015-09-30 20:27 - 2001-03-12 05:55 - 00303104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVCR70.DLL
2015-09-28 18:38 - 2015-09-28 18:38 - 00090800 _____ C:\Users\rieme_000\Documents\Bewerbung Kommissionierer.odt
2015-09-28 18:23 - 2015-09-28 18:23 - 00091041 _____ C:\Users\rieme_000\Documents\Berwerbung Müller.odt
2015-09-27 18:29 - 2015-09-27 18:29 - 00989664 _____ (McAfee, Inc.) C:\Users\rieme_000\Downloads\SecurityScan_Release_small.exe
2015-09-22 16:27 - 2015-10-07 20:36 - 00000000 ____D C:\AdwCleaner
2015-09-22 16:26 - 2015-09-22 16:27 - 01662976 _____ C:\Users\rieme_000\Downloads\adwcleaner_5.008.exe
2015-09-20 23:08 - 2015-09-20 23:08 - 00070200 _____ C:\Users\rieme_000\Downloads\TurnOffLCDv101.zip
2015-09-16 18:00 - 2015-09-16 18:00 - 00000000 ____D C:\Users\rieme_000\AppData\LocalLow\Temp
2015-09-16 17:48 - 2015-09-16 17:48 - 00000000 ___RD C:\Users\rieme_000\3D Objects
2015-09-16 17:44 - 2015-09-16 17:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.4
2015-09-16 17:42 - 2015-09-16 17:44 - 00000000 ____D C:\Program Files (x86)\LibreOffice 4
2015-09-16 17:34 - 2015-09-16 17:36 - 224563200 _____ C:\Users\rieme_000\Downloads\LibreOffice_4.4.5_Win_x86.msi
2015-09-14 19:10 - 2015-09-14 19:10 - 00000000 ____D C:\Users\rieme_000\AppData\Roaming\AMD
2015-09-10 01:24 - 2015-09-02 03:20 - 00077400 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-09-10 01:24 - 2015-09-02 02:25 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-09-10 01:24 - 2015-09-02 02:25 - 01382912 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-09-10 01:24 - 2015-08-27 08:36 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-10 01:24 - 2015-08-27 08:32 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-10 01:24 - 2015-08-27 08:04 - 21874688 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-09-10 01:24 - 2015-08-27 07:59 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-10 01:24 - 2015-08-27 07:55 - 24594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-09-10 01:24 - 2015-08-27 07:54 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-10 01:24 - 2015-08-27 07:54 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-10 01:24 - 2015-08-27 07:51 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-10 01:24 - 2015-08-27 07:51 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-10 01:24 - 2015-08-27 07:49 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-10 01:24 - 2015-08-27 07:47 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-10 01:24 - 2015-08-27 07:43 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-10 01:24 - 2015-08-27 07:43 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-10 01:24 - 2015-08-27 07:42 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-10 01:24 - 2015-08-27 07:42 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-09-10 01:24 - 2015-08-27 07:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-10 01:24 - 2015-08-27 07:42 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-10 01:24 - 2015-08-27 07:39 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-10 01:24 - 2015-08-27 07:23 - 19324416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-09-10 01:24 - 2015-08-27 07:23 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-10 01:24 - 2015-08-27 07:16 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-09-10 01:24 - 2015-08-27 07:16 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-10 01:24 - 2015-08-27 07:16 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-10 01:24 - 2015-08-27 07:12 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-10 01:24 - 2015-08-27 07:12 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-10 01:24 - 2015-08-27 07:11 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-10 01:24 - 2015-08-27 07:11 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-10 01:24 - 2015-08-27 07:09 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-10 01:24 - 2015-08-27 07:08 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-10-07 20:49 - 2013-10-13 01:20 - 00001132 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-07 20:43 - 2015-07-30 07:51 - 00000000 ____D C:\Users\rieme_000
2015-10-07 20:41 - 2015-08-29 17:11 - 00000000 ____D C:\Users\rieme_000\AppData\Roaming\Raptr
2015-10-07 20:41 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-07 20:41 - 2015-07-02 16:53 - 00000000 ___RD C:\Users\rieme_000\Dropbox
2015-10-07 20:41 - 2015-07-02 16:48 - 00000000 ____D C:\Users\rieme_000\AppData\Local\Dropbox
2015-10-07 20:40 - 2015-07-10 14:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-07 20:39 - 2015-07-10 14:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-07 20:39 - 2015-07-02 16:48 - 00001230 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2015-10-07 20:39 - 2013-10-13 01:20 - 00001128 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-07 20:38 - 2015-07-30 07:42 - 00025904 _____ C:\WINDOWS\PFRO.log
2015-10-07 20:38 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-07 20:38 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-10-07 20:38 - 2015-07-10 11:05 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2015-10-07 20:33 - 2015-07-30 08:11 - 01790124 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-07 20:33 - 2015-07-10 18:34 - 00772342 _____ C:\WINDOWS\system32\perfh007.dat
2015-10-07 20:33 - 2015-07-10 18:34 - 00154170 _____ C:\WINDOWS\system32\perfc007.dat
2015-10-07 20:29 - 2015-07-30 14:11 - 00001162 _____ C:\Users\rieme_000\Desktop\Windows Defender (2).lnk
2015-10-07 20:29 - 2015-07-30 14:00 - 00002418 _____ C:\Users\rieme_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-10-07 20:29 - 2015-07-30 08:00 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-10-07 20:29 - 2015-05-15 14:54 - 00001158 _____ C:\Users\rieme_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Origin.lnk
2015-10-07 20:29 - 2015-03-26 21:10 - 00001119 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-10-07 20:29 - 2015-03-26 21:10 - 00001092 _____ C:\Users\Public\Desktop\Opera.lnk
2015-10-07 20:29 - 2015-03-26 20:51 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-10-07 20:29 - 2015-03-19 19:02 - 00001032 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Netzmanager.lnk
2015-10-07 20:29 - 2015-03-04 22:23 - 00001255 _____ C:\Users\rieme_000\Desktop\Revo Uninstaller.lnk
2015-10-07 20:29 - 2015-03-03 17:45 - 00001511 _____ C:\Users\rieme_000\Desktop\Windows Media Player.lnk
2015-10-07 20:29 - 2014-10-07 22:27 - 00000295 _____ C:\Users\rieme_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Papierkorb.lnk
2015-10-07 20:29 - 2014-10-07 22:23 - 00002197 _____ C:\Users\Public\Desktop\Google Earth.lnk
2015-10-07 20:29 - 2014-10-07 21:27 - 00001881 _____ C:\Users\rieme_000\Desktop\Spotify.lnk
2015-10-07 20:29 - 2014-10-07 21:27 - 00001867 _____ C:\Users\rieme_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-10-07 20:29 - 2014-10-07 20:31 - 00000405 _____ C:\Users\rieme_000\Desktop\Control Panel.lnk
2015-10-07 20:29 - 2014-02-27 22:10 - 00002527 _____ C:\Users\Public\Desktop\Skype.lnk
2015-10-07 20:29 - 2012-11-13 19:50 - 00002423 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk
2015-10-07 20:21 - 2014-10-07 21:27 - 00000000 ____D C:\Users\rieme_000\AppData\Local\Spotify
2015-10-07 20:15 - 2014-10-07 21:26 - 00000000 ____D C:\Users\rieme_000\AppData\Roaming\Spotify
2015-10-07 20:01 - 2014-05-08 23:04 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-07 19:58 - 2015-07-02 16:48 - 00001234 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2015-10-07 19:53 - 2014-10-14 22:28 - 00004162 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{DB5A610A-9079-4116-9F7F-1802CB2A215F}
2015-10-07 19:50 - 2015-05-21 01:27 - 00003548 _____ C:\WINDOWS\System32\Tasks\Nagnetoelxru
2015-10-04 16:33 - 2014-10-07 20:31 - 00000000 ____D C:\Users\rieme_000\AppData\Local\Packages
2015-10-04 16:30 - 2015-08-29 17:11 - 00000000 ____D C:\Program Files (x86)\Raptr
2015-10-03 05:54 - 2015-07-02 16:48 - 00000000 ____D C:\Program Files (x86)\Dropbox
2015-10-02 06:50 - 2014-04-26 21:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-10-01 20:10 - 2015-08-29 18:54 - 00003958 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1427397041
2015-10-01 20:10 - 2014-12-28 00:49 - 00000000 ____D C:\Program Files (x86)\Opera
2015-09-30 21:04 - 2015-07-10 14:20 - 00392328 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-30 20:47 - 2015-07-10 12:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-29 21:40 - 2014-05-11 21:37 - 00000000 ____D C:\Users\rieme_000\Documents\Schule
2015-09-28 20:37 - 2015-07-30 13:54 - 00000000 ____D C:\Users\rieme_000\AppData\Local\Comms
2015-09-28 17:19 - 2015-07-30 13:54 - 00000000 ____D C:\Users\rieme_000\AppData\Local\Publishers
2015-09-22 16:50 - 2014-10-07 20:31 - 00000000 ____D C:\Users\rieme_000\AppData\Local\Google
2015-09-21 20:59 - 2015-07-10 18:46 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-21 20:59 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-09-20 23:10 - 2008-07-14 04:48 - 00087040 _____ (Redmond Pie) C:\Users\rieme_000\Desktop\Turn Off LCD.exe
2015-09-16 06:44 - 2013-10-13 01:20 - 00004190 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-16 06:44 - 2013-10-13 01:20 - 00003958 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-14 19:13 - 2012-11-13 19:46 - 00000000 ____D C:\ProgramData\Toshiba
2015-09-14 19:12 - 2015-02-01 22:36 - 00000000 ____D C:\Users\rieme_000\VirtualBox VMs
2015-09-14 19:10 - 2015-02-01 22:36 - 00000000 ____D C:\Users\rieme_000\.VirtualBox
2015-09-11 01:22 - 2013-07-26 21:17 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-10 01:33 - 2013-05-22 18:31 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-10 01:29 - 2012-07-26 07:26 - 00000301 _____ C:\WINDOWS\win.ini
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2015-02-01 22:34 - 2015-02-01 22:34 - 0740775 _____ () C:\ProgramData\AndyDrivers.zip
Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Users\Public\AlexaNSISPlugin.6776.dll
Einige Dateien in TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\PresentationCore.dll
C:\Users\Administrator\AppData\Local\Temp\PresentationFramework.dll
C:\Users\Administrator\AppData\Local\Temp\ReachFramework.dll
C:\Users\Administrator\AppData\Local\Temp\UIAutomationProvider.dll
C:\Users\Administrator\AppData\Local\Temp\UIAutomationTypes.dll
C:\Users\Administrator\AppData\Local\Temp\WindowsBase.dll
C:\Users\Administrator\AppData\Local\Temp\WindowsFormsIntegration.dll
C:\Users\rieme_000\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmppdsa8l.dll
C:\Users\rieme_000\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\rieme_000\AppData\Local\Temp\raptrpatch.exe
C:\Users\rieme_000\AppData\Local\Temp\raptr_stub.exe
C:\Users\rieme_000\AppData\Local\Temp\sqlite3.dll
C:\Users\rieme_000\AppData\Local\Temp\tmp6A68.exe
C:\Users\rieme_000\AppData\Local\Temp\ytb.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-10-05 00:06
==================== Ende von FRST.txt ============================ --- --- --- |