Ich habe alle Schritte wie angegeben befolgt.
Leider scheint das Problem weiterhin zu bestehen, zumindest auf Chrome werde ich noch immer auf Yahoo umgeleitet, obwohl er die entsprechende Adware gefunden und entfernt hatte... In Firefox scheint es behoben, hier wurde alles zurückgesetzt. Könnte es daran liegen, dass ich in Chrome mit meinem Google-Konto angemeldet bin? Ich hoffe, die Files geben Aufschluss. Mbam: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 28.11.2015
Suchlaufzeit: 01:53
Protokolldatei: mbam_suchlauf.txt
Administrator: Ja
Version: 2.2.0.1024
Malware-Datenbank: v2015.11.27.04
Rootkit-Datenbank: v2015.11.26.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Admin
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 397347
Abgelaufene Zeit: 30 Min., 31 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 6
PUP.Optional.Yontoo, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}, In Quarantäne, [1be5770c711a52e4f6fcdc427f830ff1],
PUP.Optional.Yontoo, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}, In Quarantäne, [1be5770c711a52e4f6fcdc427f830ff1],
PUP.Optional.BundleInstaller, HKLM\SOFTWARE\WOW6432NODE\VITTALIA\AxtanInstaller, In Quarantäne, [e917671cf992e74f8e8d5e1741c2da26],
PUP.Optional.Yontoo, HKU\S-1-5-21-251078781-3317619643-309151117-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BAE061C7-7A58-4E93-B036-AA11142C9619}, In Quarantäne, [e41c0182315ad46219b6ac0a0300817f],
PUP.Optional.Yontoo, HKU\S-1-5-21-251078781-3317619643-309151117-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\OLDSEARCH, In Quarantäne, [13ed6320e5a61c1abe11b7ffe22107f9],
PUP.Optional.Yontoo, HKU\S-1-5-21-251078781-3317619643-309151117-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CBE445E2-A0D0-4B5A-8044-825EAAD02B38}, In Quarantäne, [629e0a790d7e082efcd3aa0c14ef07f9],
Registrierungswerte: 5
PUP.Optional.Yontoo.ChrPRST, HKU\S-1-5-21-251078781-3317619643-309151117-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DoNotAskAgain, searchinterneat-a.akamaihd.net, In Quarantäne, [14ec20632962a492cf21e4d3cf34ab55]
PUP.Optional.Yontoo, HKU\S-1-5-21-251078781-3317619643-309151117-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BAE061C7-7A58-4E93-B036-AA11142C9619}|URL, hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ1aAF9CFAMVbQEPUw9cFQEbIxQAVQAXDAJFcg1eAApEE1NGeR9aFQQTSEcFME0FCFwEURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms}, In Quarantäne, [e41c0182315ad46219b6ac0a0300817f]
PUP.Optional.Yontoo.ChrPRST, HKU\S-1-5-21-251078781-3317619643-309151117-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DoNotAskAgain, searchinterneat-a.akamaihd.net, In Quarantäne, [8977691a24676dc9ab453087c24113ed]
PUP.Optional.Yontoo, HKU\S-1-5-21-251078781-3317619643-309151117-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\OldSearch|URL, hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ1aAF9CFAMVbQEPUw9cFQEbIxQAVQAXDAJFcg1eAApEE1NGeR9aFQQTSEcFME0FCFwEURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms}, In Quarantäne, [13ed6320e5a61c1abe11b7ffe22107f9]
PUP.Optional.Yontoo, HKU\S-1-5-21-251078781-3317619643-309151117-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CBE445E2-A0D0-4B5A-8044-825EAAD02B38}|URL, hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ1aAF9CFAMVbQEPUw9cFQEbIxQAVQAXDAJFcg1eAApEE1NGeR9aFQQTSEcFME0FCFwEURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms}, In Quarantäne, [629e0a790d7e082efcd3aa0c14ef07f9]
Registrierungsdaten: 3
PUP.Optional.Yontoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggXIlheUgxHFxgbdwsOTA1FGVYOeA0BBxRGRwcXJlgLVAsXRAwFIk0FA1ADB0VXfVBdFElXTwhwJVhKAlE8TkdGC1dXFg==, Gut: (www.google.com), Schlecht: (hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggXIlheUgxHFxgbdwsOTA1FGVYOeA0BBxRGRwcXJlgLVAsXRAwFIk0FA1ADB0VXfVBdFElXTwhwJVhKAlE8TkdGC1dXFg==),Ersetzt,[51afd2b1a8e3063013e6a7c4e123de22]
PUP.Optional.Yontoo, HKU\S-1-5-21-251078781-3317619643-309151117-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggXIlheUgxHFxgbdwsOTA1FGVYOeA0BBxRGRwcXJlgLVAsXRAwFIk0FA1ADB0VXfVBdFElXTwhwJVhKAlE8TkdGC1dXFg==, Gut: (www.google.com), Schlecht: (hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggXIlheUgxHFxgbdwsOTA1FGVYOeA0BBxRGRwcXJlgLVAsXRAwFIk0FA1ADB0VXfVBdFElXTwhwJVhKAlE8TkdGC1dXFg==),Ersetzt,[01ff8ef52368c571946a2d3e1ee659a7]
PUP.Optional.Yontoo, HKU\S-1-5-21-251078781-3317619643-309151117-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggXIlheUgxHFxgbdwsOTA1FGVYOeA0BBxRGRwcXJlgLVAsXRAwFIk0FA1ADB0VXfVBdFElXTwhwJVhKAlE8TkdGC1dXFg==, Gut: (www.google.com), Schlecht: (hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggXIlheUgxHFxgbdwsOTA1FGVYOeA0BBxRGRwcXJlgLVAsXRAwFIk0FA1ADB0VXfVBdFElXTwhwJVhKAlE8TkdGC1dXFg==),Ersetzt,[bd43542f167549ed817dd39828dc9e62]
Ordner: 0
(keine bösartigen Elemente erkannt)
Dateien: 12
PUP.Optional.Yontoo, C:\Users\Admin\AppData\Roaming\RPEng\829409BA32654075A906DC244F30DE18\setup.exe, In Quarantäne, [639d562d4447a195e2a7fa9e3ec3827e],
PUP.Optional.Yontoo, C:\Users\Admin\AppData\Local\Temp\~nsu.tmp\Au_.exe, In Quarantäne, [b14f236083084cea76131682e61b8d73],
PUP.Optional.Monetizer, C:\Users\Admin\AppData\Local\Temp\is-0BBVB.tmp\CBStub.exe, In Quarantäne, [e917e59e7e0d49edb3fdd60f99687888],
PUP.Optional.Yontoo.Gen, C:\Users\Jackie\AppData\Local\Temp\{D5105BCE-FA47-407D-9B54-77F109EBE32F}.xpi, In Quarantäne, [38c8ceb5ec9ffa3cff8b3ede16eb3ac6],
PUP.Optional.Yontoo.Gen, C:\Users\Jackie\AppData\Local\Temp\{A4463F29-2131-48D7-9CDB-3B944279B228}.xpi, In Quarantäne, [2bd596edfd8e49ed3654b369fb0608f8],
PUP.Optional.Yontoo, C:\Users\Jackie\AppData\Roaming\Mozilla\Firefox\Profiles\odxkmq1n.default\extensions\{4726aa1f-0890-46ef-b79b-d5798ba06db5}.xpi, In Quarantäne, [a858d4af573434024ae5b9dd9f631ae6],
PUP.Optional.Yontoo, C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences, Gut: ("session":{"restore_on_startup":4,"startup_urls":["https://www.malwarebytes.org/restorebrowser/"]}}), Schlecht: ("session":{"restore_on_startup":4,"restore_on_startup_migrated":true,"startup_urls":["hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggXIlheUgxHFxgbdwsOTA1FGVYOeA0BBxRGRwcXJlgLVAsXRAwFIk0FA1oDB0VXfV5bFElXTwhwJVhKAlE8TkdGC1dXFg=="],"urls_to_restore_on_startup":["hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggXIlheUgxHFxgbdwsOTA1FGVYOeA0BBxRGRwcXJlgLVAsXRAwFIk0FA1oDB0VXfV5bFElXTwhwJVhKAlE8TkdGC1dXFg=="]},"sync":{"remaining_rollback_tries":0}}), Ersetzt,[ba4698eba4e7e2549f9b9cfb54b06898]
PUP.Optional.Yontoo, C:\Users\Jackie\AppData\Roaming\Mozilla\Firefox\Profiles\odxkmq1n.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://searchinterneat-a.akamaihd.net/t?eq=U0EeFFhaR1oWHAFBIV8LVA9HDA0Ucg8VVQ1JQhgbdABeTA4XEwFFIQoNU18UGBNBNARaB0tXUUEeGGlxR1dMclBCMlpQLFYDRH5NL04=");), Ersetzt,[35cb22617714c5714499424e14f034cc]
PUP.Optional.Yontoo.ChrPRST, C:\Users\Jackie\AppData\Roaming\Mozilla\Firefox\Profiles\odxkmq1n.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ1aAF9CFAMVbQEPUw9cFQEbIxQAVQAXDAJFcg1eAApEE1NGeR9aFQQTR0cFME0FB18EURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms}");), Ersetzt,[37c9a2e10586ee484d95a4ec61a30ff1]
PUP.Optional.Yontoo, C:\Users\Jackie\AppData\Roaming\Mozilla\Firefox\Profiles\odxkmq1n.default\prefs.js, Gut: (browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Schlecht: (browser.startup.homepage", "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggXIlheUgxHFxgbdwsOTA1FGVYOeA0BBxRGRwcXJlgLVAsXRAwFIk0FA18DB0VXfWFoKB8fHGZGIUtbCXQeU1BoLlZP");), Ersetzt,[1de323609dee9d996bd5e4b3b74d8c74]
PUP.Optional.BDYahoo, C:\Users\Jackie\AppData\Roaming\Mozilla\Firefox\Profiles\odxkmq1n.default\searchplugins\default.xml, In Quarantäne, [7d830281c2c98ea8eaa1a6eed52f8977],
PUP.Optional.Yontoo, C:\Users\Jackie\AppData\Roaming\Mozilla\Firefox\Profiles\odxkmq1n.default\searchplugins\yahoo.xml, In Quarantäne, [b34d453ed6b586b0701c801444c0e41c],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) AdwCleaner: Code:
# AdwCleaner v5.022 - Bericht erstellt am 28/11/2015 um 02:40:16
# Aktualisiert am 22/11/2015 von Xplode
# Datenbank : 2015-11-22.2 [Server]
# Betriebssystem : Windows 8.1 (x64)
# Benutzername : Admin - VAIO
# Gestartet von : C:\Users\Jackie\Desktop\AdwCleaner_5.022.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum
***** [ Dienste ] *****
***** [ Ordner ] *****
[-] Ordner Gelöscht : C:\Users\Admin\AppData\Roaming\RPEng
[-] Ordner Gelöscht : C:\Users\Jackie\AppData\Roaming\dvdvideosoftiehelpers
***** [ Dateien ] *****
[-] Datei Gelöscht : C:\Users\Jackie\AppData\Roaming\Mozilla\Firefox\Profiles\odxkmq1n.default\foxydeal.sqlite
***** [ DLLs ] *****
***** [ Verknüpfungen ] *****
***** [ Aufgabenplanung ] *****
***** [ Registrierungsdatenbank ] *****
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Vittalia
***** [ Internetbrowser ] *****
[-] [C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider_Data] Gelöscht : hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ1aAF9CFAMVbQEPUw9cFQEbIxQAVQAXDAJFcg1eAApEE1NGeR9aFQQTQkcFME0FBloEURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms}
[-] [C:\Users\Jackie\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Gelöscht : searchinterneat-a.akamaihd.net
[-] [C:\Users\Jackie\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Gelöscht : hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggXIlheUgxHFxgbdwsOTA1FGVYOeA0BBxRGRwcXJlgLVAsXRAwFIk0FA1oDB0VXfV5bFElXTwhwJVhKAlE8TkdGC1dXFg==
[-] [C:\Users\Jackie\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider_Data] Gelöscht : hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ1aAF9CFAMVbQEPUw9cFQEbIxQAVQAXDAJFcg1eAApEE1NGeR9aFQQTQkcFME0FBloEURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms}
*************************
:: "Tracing" Schlüssel gelöscht
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Chrome Richtlinien gelöscht
########## EOF - \AdwCleaner\AdwCleaner[C1].txt - [2490 Bytes] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.1 (11.24.2015)
Operating System: Windows 8.1 x64
Ran by Admin (Administrator) on 28.11.2015 at 2:46:54,93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 1
Successfully deleted: C:\Users\Admin\AppData\Roaming\pdfforge (Folder)
Registry: 1
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.11.2015 at 2:51:49,23
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:27-11-2015
durchgeführt von Admin (Administrator) auf VAIO (28-11-2015 02:59:13)
Gestartet von C:\Users\Jackie\Desktop
Geladene Profile: Admin & Jackie (Verfügbare Profile: Admin & Jackie)
Platform: Windows 8.1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(BioWare) C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
() C:\Program Files\Sony\VAIO Care\listener.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1353432 2013-10-28] (Realtek Semiconductor)
HKLM\...\Run: [Bluetooth] => c:\Program Files\WIDCOMM\Bluetooth Software\bttray.exe [534232 2013-09-25] (Broadcom Corporation.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-03-30] (IvoSoft)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2465088 2014-11-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3928264 2015-05-27] (Synaptics Incorporated)
HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [2346008 2013-10-01] (Sony Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BDRegion] => c:\Program Files (x86)\Cyberlink\Shared files\brs.exe [178536 2013-10-09] (cyberlink)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7004376 2015-11-27] (AVAST Software)
HKLM\...\RunOnce: [MSPCLOCK] => rundll32.exe streamci,StreamingDeviceSetup {97ebaacc-95bd-11d0-a3ea-00a0c9223196},{53172480-4791-11D0-A5D6-28DB04C10000},{53172480-4791-11D0-A5D6-28DB04C10000}
HKLM\...\RunOnce: [MSPQM] => rundll32.exe streamci,StreamingDeviceSetup {DDF4358E-BB2C-11D0-A42F-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196}
HKLM\...\RunOnce: [MSKSSRV] => rundll32.exe streamci,StreamingDeviceSetup {96E080C7-143C-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196}
HKLM\...\RunOnce: [MSTEE.CxTransform] => rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},C:\Windows\inf\ksfilter.inf,MSTEE.Interf (Der Dateneintrag hat 11 mehr Zeichen).
HKLM\...\RunOnce: [MSTEE.Splitter] => rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},C:\Windows\inf\ksfilter.inf,MSTEE.Interf (Der Dateneintrag hat 11 mehr Zeichen).
HKLM\...\RunOnce: [WDM_DRMKAUD] => rundll32.exe streamci,StreamingDeviceSetup {EEC12DB6-AD9C-4168-8658-B03DAEF417FE},{ABD61E00-9350-47e2-A632-4438B90C6641},{FFBB6E3F-CCFE-4D84-90D9-421418B03A8E},C:\Windows\inf\WDMAUDIO.inf,WDM_DRMKAUD. (Der Dateneintrag hat 17 mehr Zeichen).
HKLM\...\RunOnce: [InstallSmbDrv] => C:\ProgramData\Synaptics\SmbDrv\dpinst.exe [1056968 2015-05-27] (Microsoft Corporation)
HKLM\...\RunOnce: [*Restore] => C:\Windows\System32\rstrui.exe [273920 2014-10-29] (Microsoft Corporation)
HKLM-x32\...\RunOnce: [20150107] => C:\Program Files\AVAST Software\Avast\setup\emupdate\c23160b4-2e85-4a87-951b-eae38d7b1ba1.exe [183232 2015-09-23] (AVAST Software)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2015-10-05] (Malwarebytes)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-251078781-3317619643-309151117-1002\...\RunOnce: [Report] => \AdwCleaner\AdwCleaner[C1].txt
HKU\S-1-5-21-251078781-3317619643-309151117-1003\...\Run: [Amazon Music] => C:\Users\Jackie\AppData\Local\Amazon Music\Amazon Music Helper.exe [5886784 2015-05-07] ()
HKU\S-1-5-21-251078781-3317619643-309151117-1003\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Jackie\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKU\S-1-5-21-251078781-3317619643-309151117-1003\...\Run: [Spotify Web Helper] => C:\Users\Jackie\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2344768 2015-11-17] (Spotify Ltd)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174856 2014-11-13] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156840 2014-11-13] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-11-27] (AVAST Software)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{5575E45E-985A-4038-9E34-3D07415FC8E6}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{6F0D5E33-B963-4225-8128-8AEB4CC265E2}: [DhcpNameServer] 127.0.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKU\S-1-5-21-251078781-3317619643-309151117-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://sony13.msn.com/?pc=SEJB
HKU\S-1-5-21-251078781-3317619643-309151117-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://vaioportal.sony.eu
HKU\S-1-5-21-251078781-3317619643-309151117-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://vaioportal.sony.eu
HKU\S-1-5-21-251078781-3317619643-309151117-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://sony13.msn.com/?pc=SEJB
HKU\S-1-5-21-251078781-3317619643-309151117-1003\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://vaioportal.sony.eu
SearchScopes: HKLM -> DefaultScope Wert fehlt
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope Wert fehlt
SearchScopes: HKU\S-1-5-21-251078781-3317619643-309151117-1002 -> DefaultScope {BAE061C7-7A58-4E93-B036-AA11142C9619} URL =
SearchScopes: HKU\S-1-5-21-251078781-3317619643-309151117-1002 -> {1AB7FB9C-C279-4B6F-87F2-CC46F40BF9E0} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-&_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-251078781-3317619643-309151117-1003 -> DefaultScope {CBE445E2-A0D0-4B5A-8044-825EAAD02B38} URL =
SearchScopes: HKU\S-1-5-21-251078781-3317619643-309151117-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-251078781-3317619643-309151117-1003 -> {344CAAFE-47F6-41A8-B699-74309BB7F0BF} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-&_nkw={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-12-28] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-11-27] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-12-28] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-11-27] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-12-28] (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-10] ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-12-28] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-10] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-18] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-18] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-12-28] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\Sony\MSS\3.0.318\npMcAfeeMss.dll [Keine Datei]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @sony.com/ReaderDesktop -> C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll [2013-06-25] (Sony Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-14] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-12-21] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-251078781-3317619643-309151117-1003: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Jackie\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-11-27]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-11-27]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.de/ig
CHR StartupUrls: Default -> "hxxps://www.malwarebytes.org/restorebrowser/"
CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-24]
CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-24]
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-25]
CHR Extension: (Google-Suche) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-25]
CHR Extension: (Google Docs Offline) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-25]
CHR Extension: (AdBlock) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-11-25]
CHR Extension: (Avast Online Security) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-25]
CHR Extension: (View Background Image) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\knnjokagadbonknppgkjgjpiolcijbmg [2014-04-04]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-25]
CHR Extension: (Universe) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\oecmlnmneeeeiccpcohlffnipjhngmdk [2014-09-19]
CHR Extension: (ScriptSafe) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiigbmnaadbkfbmpbfijlflahbdbdgdf [2014-08-07]
CHR Extension: (Google Mail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-25]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-11-27]
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AdobeActiveFileMonitor12.0; c:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe [181152 2013-09-25] (Adobe Systems Incorporated)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [174416 2015-11-27] (AVAST Software)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-10-28] (Broadcom Corporation.)
S2 CLKMSVC10_38F51D56; c:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [242024 2013-10-02] (CyberLink)
R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [382312 2015-11-17] (Digital Wave Ltd.)
R2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [377768 2013-05-29] (Intel Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-11-17] (NVIDIA Corporation)
R2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-18] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostServiceSony; C:\Program Files (x86)\Sony\MSS\3.0.318\McCHSvc.exe [235216 2013-02-11] (McAfee, Inc.)
S3 NetworkSupport; C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkSupport.exe [629336 2013-09-27] (Sony Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-11-17] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19821376 2014-11-17] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2099720 2015-11-27] (Electronic Arts)
R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [481304 2013-10-01] (Sony Corporation)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [266168 2013-05-29] (Intel Corporation)
S3 Sony SCSI Helper Service; C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [73728 2013-05-23] (Sony Corporation) [Datei ist nicht signiert]
S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [377768 2013-05-29] (Intel Corporation)
S3 VCFw; c:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [972000 2013-01-06] (Sony Corporation)
R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1369136 2013-09-25] (Sony Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S2 AdobeARMservice; "c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-11-27] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-11-27] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-11-27] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-11-27] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-27] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-27] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [154256 2015-11-27] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-11-27] (AVAST Software)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-10-28] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7488176 2013-12-28] (Broadcom Corporation)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2015-11-28] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-18] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20800 2014-11-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38216 2014-10-03] (NVIDIA Corporation)
R0 PxHlpa64; C:\Windows\System32\drivers\PxHlpa64.sys [56336 2013-07-19] (Corel Corporation)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [429272 2013-10-09] (Realsil Semiconductor Corporation)
R3 semav6thermal64ro; C:\Windows\system32\drivers\semav6thermal64ro.sys [13792 2013-12-28] ()
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-05-27] (Synaptics Incorporated)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-11-28 02:55 - 2015-11-28 02:55 - 00000000 ____D C:\Users\Jackie\Desktop\FRST-OlderVersion
2015-11-28 02:51 - 2015-11-28 02:55 - 00000748 _____ C:\Users\Admin\Desktop\JRT.txt
2015-11-28 02:38 - 2015-11-28 02:40 - 00000000 ____D C:\AdwCleaner
2015-11-28 02:37 - 2015-11-28 02:37 - 00008334 _____ C:\Users\Jackie\Desktop\mbam_suchlauf.txt
2015-11-28 02:36 - 2015-11-28 02:36 - 00000960 _____ C:\Users\Jackie\Desktop\mbam_schutzprotokoll.txt
2015-11-28 01:52 - 2015-11-28 01:53 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-28 01:52 - 2015-11-28 01:52 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-11-28 01:52 - 2015-11-28 01:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-11-28 01:52 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-11-28 01:52 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-11-28 01:52 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-11-28 01:45 - 2015-11-28 01:45 - 00001240 _____ C:\Users\Admin\Desktop\Revo Uninstaller.lnk
2015-11-28 01:45 - 2015-11-28 01:45 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2015-11-28 01:45 - 2015-11-28 01:45 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-11-28 01:43 - 2015-11-28 01:43 - 01733632 _____ C:\Users\Jackie\Desktop\AdwCleaner_5.022.exe
2015-11-28 01:43 - 2015-11-28 01:43 - 01599336 _____ (Malwarebytes) C:\Users\Jackie\Desktop\JRT.exe
2015-11-28 01:42 - 2015-11-28 01:42 - 22908888 _____ (Malwarebytes ) C:\Users\Jackie\Downloads\mbam-setup-2.2.0.1024.exe
2015-11-28 01:42 - 2015-11-28 01:42 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Jackie\Downloads\revosetup95.exe
2015-11-27 17:00 - 2015-11-27 17:00 - 00000000 ____D C:\Users\Jackie\AppData\Local\Steam
2015-11-27 16:07 - 2015-11-27 16:07 - 00386096 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-11-27 16:07 - 2015-11-27 16:07 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-11-27 10:34 - 2015-11-28 02:58 - 00036599 _____ C:\Users\Jackie\Desktop\Addition.txt
2015-11-25 21:14 - 2015-11-28 02:59 - 00023752 _____ C:\Users\Jackie\Desktop\FRST.txt
2015-11-25 21:11 - 2015-11-28 02:59 - 00000000 ____D C:\FRST
2015-11-25 21:01 - 2015-11-28 02:55 - 02349056 _____ (Farbar) C:\Users\Jackie\Desktop\FRST64.exe
2015-11-25 20:53 - 2015-11-25 20:53 - 00000720 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brackets.lnk
2015-11-25 20:53 - 2015-11-25 20:53 - 00000000 ____D C:\Users\Jackie\AppData\Roaming\Brackets
2015-11-25 20:53 - 2015-11-25 20:53 - 00000000 ____D C:\Program Files (x86)\Brackets
2015-11-25 20:43 - 2015-11-25 20:51 - 40275968 _____ C:\Users\Jackie\Downloads\Brackets.1.5.Extract.msi
2015-11-25 15:30 - 2015-11-25 15:30 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\Jackie\Downloads\sh-remover.exe
2015-11-20 21:52 - 2015-11-20 21:57 - 154340296 _____ C:\Users\Jackie\Downloads\SH3 - Preview.zip
2015-11-20 19:12 - 2015-11-20 19:12 - 00005975 _____ C:\Users\Jackie\AppData\Local\recently-used.xbel
2015-11-12 09:49 - 2015-11-03 01:23 - 00810488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-11-12 09:49 - 2015-11-03 01:23 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-11 19:23 - 2015-11-14 11:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-11 10:20 - 2015-10-13 16:59 - 00397224 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2015-11-11 10:20 - 2015-10-13 16:59 - 00340872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2015-11-11 10:20 - 2015-10-13 16:59 - 00137960 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-11 10:20 - 2015-10-13 16:59 - 00120376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-11-11 10:20 - 2015-10-13 16:59 - 00106952 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll
2015-11-11 10:20 - 2015-10-13 16:59 - 00091416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll
2015-11-11 10:20 - 2015-10-11 07:36 - 00561952 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-11-11 10:20 - 2015-10-11 07:36 - 00177496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-11-11 10:20 - 2015-10-10 19:40 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-11-11 10:20 - 2015-10-10 19:39 - 00401408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-11-11 10:20 - 2015-10-10 19:07 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-11-11 10:20 - 2015-10-10 18:33 - 01441280 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-11-11 10:20 - 2015-10-10 18:27 - 00432640 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-11 10:20 - 2015-10-10 18:11 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-11-11 10:20 - 2015-10-10 17:45 - 00359424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-11-11 10:19 - 2015-10-20 15:53 - 03705856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-11-11 10:19 - 2015-10-15 17:08 - 00990208 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-11 10:19 - 2015-10-15 16:46 - 00803328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-11-11 10:19 - 2015-10-15 00:02 - 07455064 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-11 10:19 - 2015-10-15 00:02 - 01659560 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-11-11 10:19 - 2015-10-15 00:02 - 01519592 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-11-11 10:19 - 2015-10-15 00:02 - 01487008 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-11-11 10:19 - 2015-10-15 00:02 - 01355848 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-11-11 10:19 - 2015-10-13 18:10 - 00559616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-11 10:19 - 2015-10-13 18:10 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-11 10:19 - 2015-09-29 13:24 - 00155480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys
2015-11-11 10:19 - 2015-09-12 14:47 - 00414559 _____ C:\Windows\system32\ApnDatabase.xml
2015-11-11 10:19 - 2015-09-04 20:24 - 00154112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
2015-11-11 10:19 - 2015-08-28 23:20 - 00183368 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe
2015-11-11 10:19 - 2015-08-20 21:45 - 01380048 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-11-11 10:19 - 2015-08-20 18:48 - 01096704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-11-11 10:18 - 2015-10-20 22:54 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-11-11 10:18 - 2015-10-20 15:36 - 02243072 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-11-11 10:18 - 2015-10-20 15:35 - 00891904 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-11-11 10:18 - 2015-10-20 15:34 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2015-11-11 10:18 - 2015-10-20 15:34 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-11-11 10:18 - 2015-10-20 15:34 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-11-11 10:18 - 2015-10-20 15:33 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-11-11 10:18 - 2015-10-20 15:14 - 00721920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-11-11 10:18 - 2015-10-20 15:13 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-11-11 10:18 - 2015-10-20 15:13 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-11-11 10:18 - 2015-10-20 15:13 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-11-11 10:18 - 2015-09-07 16:30 - 01091584 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-11-11 10:18 - 2014-11-05 02:41 - 00558080 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2015-11-11 10:18 - 2014-11-05 02:18 - 00507392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2015-11-11 10:17 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-11 10:17 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-11 10:17 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-11 10:17 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-11-11 10:17 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-11 10:17 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-11-11 10:17 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-11-11 10:17 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-11-11 10:17 - 2015-10-30 23:39 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-11-11 10:17 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-11-11 10:17 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-11-11 10:17 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-11 10:17 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-11 10:17 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-11 10:17 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-11-11 10:17 - 2015-10-30 23:14 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-11-11 10:17 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-11-11 10:17 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-11-11 10:17 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-11 10:17 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-11-11 10:17 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-11-11 10:17 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-11-11 10:17 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-11-11 10:17 - 2015-10-17 15:19 - 04176384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-11 10:17 - 2015-10-08 17:08 - 01083904 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2015-11-11 10:17 - 2015-09-07 17:22 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2015-11-11 10:17 - 2015-09-07 16:54 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2015-11-11 10:17 - 2015-08-10 19:15 - 00845312 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2015-11-11 10:17 - 2015-08-10 19:06 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2015-11-11 10:17 - 2015-08-10 18:49 - 00713216 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2015-11-11 10:17 - 2015-08-10 17:56 - 00272384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2015-11-11 10:17 - 2015-08-10 17:46 - 00561664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2015-11-11 10:17 - 2014-11-10 19:06 - 00136512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2015-10-29 22:27 - 2015-10-30 12:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-11-28 02:54 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\AppReadiness
2015-11-28 02:44 - 2014-04-05 00:35 - 00000000 ____D C:\Users\Jackie\AppData\Roaming\ClassicShell
2015-11-28 02:42 - 2014-04-04 17:24 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-28 02:41 - 2013-08-22 15:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-28 02:33 - 2013-08-22 14:36 - 00000000 ____D C:\Windows\Inf
2015-11-28 02:31 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\tracing
2015-11-28 02:21 - 2014-06-21 23:28 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-27 18:57 - 2014-04-05 18:04 - 00000000 ____D C:\Program Files (x86)\Steam
2015-11-27 18:57 - 2014-04-05 11:30 - 00000000 ____D C:\ProgramData\Origin
2015-11-27 16:45 - 2014-04-05 11:30 - 00000000 ____D C:\Program Files (x86)\Origin
2015-11-27 16:08 - 2014-04-04 17:37 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-11-27 16:07 - 2014-06-15 20:06 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-11-27 16:07 - 2014-04-04 17:37 - 01059656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-11-27 16:07 - 2014-04-04 17:37 - 00449992 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-11-27 16:07 - 2014-04-04 17:37 - 00273784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-11-27 16:07 - 2014-04-04 17:37 - 00154256 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-11-27 16:07 - 2014-04-04 17:37 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-11-27 16:07 - 2014-04-04 17:37 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-11-27 16:07 - 2014-04-04 17:37 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-11-27 16:07 - 2013-08-22 14:36 - 00000000 ____D C:\Windows
2015-11-27 15:27 - 2015-07-23 21:44 - 00000000 ____D C:\Users\Jackie\AppData\Roaming\Spotify
2015-11-27 15:22 - 2015-07-23 21:45 - 00000000 ____D C:\Users\Jackie\AppData\Local\Spotify
2015-11-27 14:26 - 2014-04-04 21:29 - 00000000 ___RD C:\Users\Jackie\Documents\Meine Dokumente
2015-11-25 21:29 - 2014-04-04 17:55 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-251078781-3317619643-309151117-1003
2015-11-25 16:32 - 2014-06-22 03:20 - 00000000 __SHD C:\Users\Jackie\AppData\LocalLow\EmieUserList
2015-11-25 16:32 - 2014-06-22 03:20 - 00000000 __SHD C:\Users\Jackie\AppData\LocalLow\EmieSiteList
2015-11-25 16:32 - 2014-06-22 03:20 - 00000000 __SHD C:\Users\Jackie\AppData\Local\EmieUserList
2015-11-25 16:32 - 2014-06-22 03:20 - 00000000 __SHD C:\Users\Jackie\AppData\Local\EmieSiteList
2015-11-25 15:31 - 2015-07-08 19:49 - 00000000 ____D C:\Program Files (x86)\FreeCodecPack
2015-11-25 15:31 - 2015-02-24 22:27 - 00000000 ____D C:\Users\Admin\AppData\Roaming\DVDVideoSoft
2015-11-24 23:50 - 2014-05-09 20:15 - 00000000 ____D C:\Users\Jackie\AppData\Roaming\DVDVideoSoft
2015-11-24 15:49 - 2013-12-28 16:29 - 00758496 _____ C:\Windows\system32\perfh007.dat
2015-11-24 15:49 - 2013-12-28 16:29 - 00155446 _____ C:\Windows\system32\perfc007.dat
2015-11-24 15:49 - 2013-09-13 22:06 - 01765716 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-22 23:56 - 2013-08-22 14:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-11-20 20:09 - 2014-07-07 13:17 - 00000000 ____D C:\Users\Jackie\.gimp-2.8
2015-11-20 18:24 - 2014-05-09 20:15 - 00000000 ____D C:\Users\Jackie\Documents\DVDVideoSoft
2015-11-14 23:58 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\rescache
2015-11-14 11:07 - 2014-04-04 23:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-12 09:48 - 2013-08-22 15:44 - 00573464 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-11 23:46 - 2013-08-22 16:36 - 00000000 ___RD C:\Windows\ToastData
2015-11-11 23:32 - 2014-04-04 17:25 - 00002155 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-11-11 18:26 - 2014-08-13 11:07 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-11 18:26 - 2013-08-22 16:20 - 00000000 ____D C:\Windows\CbsTemp
2015-11-11 18:21 - 2014-04-04 18:50 - 00000000 ____D C:\Windows\system32\MRT
2015-11-11 18:15 - 2014-04-04 18:50 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-11-10 20:21 - 2014-06-21 23:28 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-11-07 14:34 - 2014-07-07 13:39 - 00000000 ____D C:\Users\Jackie\AppData\Local\gtk-2.0
2015-11-06 13:06 - 2013-08-22 16:36 - 00000000 ___HD C:\Program Files\WindowsApps
2015-11-05 20:33 - 2014-05-09 17:15 - 00000000 ____D C:\Users\Jackie\AppData\Roaming\Skype
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2014-07-08 17:09 - 2009-08-21 19:45 - 0000175 _____ () C:\Program Files (x86)\AUTORUN.INF
2014-07-08 17:09 - 2009-08-21 19:45 - 0002582 _____ () C:\Program Files (x86)\README.HTM
2014-07-08 17:09 - 2009-08-25 10:28 - 0463152 _____ (Microsoft Corporation) C:\Program Files (x86)\SETUP.EXE
2013-12-28 08:05 - 2013-12-28 08:05 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Einige Dateien in TEMP:
====================
C:\Users\Admin\AppData\Local\Temp\COMAP.EXE
C:\Users\Admin\AppData\Local\Temp\sqlite3.dll
C:\Users\Jackie\AppData\Local\Temp\COMAP.EXE
C:\Users\Jackie\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Jackie\AppData\Local\Temp\tmd_34011176.exe
C:\Users\Jackie\AppData\Local\Temp\tmd_34017422.exe
C:\Users\Jackie\AppData\Local\Temp\tmp6633.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-11-18 12:24
==================== Ende von FRST.txt ============================ |