Code:
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 12-09-2016
durchgeführt von Alex (14-09-2016 17:09:10) Run:1
Gestartet von C:\Users\Alex\Desktop
Geladene Profile: Alex (Verfügbare Profile: Alex & Administrator & DefaultAppPool)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
start
CloseProcesses:
R2 JoropygrosakDebuger; C:\Program Files (x86)\Prerpetaincliiph\clhBuilder.dll [301568 2016-09-12] () [Datei ist nicht signiert]
Task: {3D26F772-E706-43C1-BB76-960259E909D5} - System32\Tasks\Joropygrosak Debuger => C:\Program Files (x86)\Prerpetaincliiph\keda.exe [2016-09-12] (CHENGDU YIWO Tech Development Co., Ltd)
C:\Program Files (x86)\Prerpetaincliiph
C:\WINDOWS\Joberphlusisp
C:\Users\Alex\AppData\Local\Sejoge
GroupPolicy: Beschränkung - Chrome <======= ACHTUNG
CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG
CMD: dir /B "%ProgramFiles%"
CMD: dir /B "%ProgramFiles(x86)%"
CMD: dir /B "%ProgramData%"
CMD: dir /B "%Appdata%"
CMD: dir /B "%LocalAppdata%"
RemoveProxy:
CMD: ipconfig /flushdns
CMD: netsh winsock reset
EmptyTemp:
end
*****************
Prozess erfolgreich geschlossen.
JoropygrosakDebuger => Dienst nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3D26F772-E706-43C1-BB76-960259E909D5}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D26F772-E706-43C1-BB76-960259E909D5}" => Schlüssel erfolgreich entfernt
C:\WINDOWS\System32\Tasks\Joropygrosak Debuger => nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Joropygrosak Debuger" => Schlüssel erfolgreich entfernt
C:\Program Files (x86)\Prerpetaincliiph => erfolgreich verschoben
C:\WINDOWS\Joberphlusisp => erfolgreich verschoben
C:\Users\Alex\AppData\Local\Sejoge => erfolgreich verschoben
"C:\WINDOWS\system32\GroupPolicy\Machine" => nicht gefunden.
HKLM\SOFTWARE\Policies\Google => Schlüssel nicht gefunden.
========= dir /B "%ProgramFiles%" =========
Adblock Plus for IE
Adobe
ATI
ATI Technologies
CMAK
Common Files
DVD Maker
FileZilla FTP Client
Highresolution Enterprises
HWiNFO64
Internet Explorer
Java
Logitech
Microsoft Mouse and Keyboard Center
Microsoft Office
Microsoft Silverlight
Mixxx
Mozilla Firefox
MSBuild
NVIDIA Corporation
Realtek
Reference Assemblies
Rockstar Games
TeamSpeak 3 Client
totalcmd
UeEi2
Unity
VS Revo Group
Windows Defender
Windows Journal
Windows Mail
Windows Media Player
Windows Multimedia Platform
Windows NT
Windows Photo Viewer
Windows Portable Devices
WinRAR
========= Ende von CMD: =========
========= dir /B "%ProgramFiles(x86)%" =========
AbiWord
Activation
Adobe
AIMP
AKVIS
Anvsoft
ASUS
Auslogics
Avidemux 2.6
Avira
AVS4YOU
Bandicam
BandiMPEG1
CDBurnerXP
CMAK
Common Files
D-Link
DAEMON Tools Lite
Disc Soft
DLLSuite
epson
ESET
FastSocial
Foxit Software
Freemake
Google
Internet Explorer
Java
Krita (x86)
LocksPro
Malwarebytes Anti-Malware
MegaDev
Microsoft
Microsoft ASP.NET
Microsoft Games for Windows - LIVE
Microsoft Office
Microsoft Silverlight
Microsoft Visual Studio
Microsoft Visual Studio 8
Microsoft Works
Microsoft.NET
Mozilla Maintenance Service
Mozilla Thunderbird
MP3Gain
MSBuild
NCH Software
Nesbox Companion
NVIDIA Corporation
OpenOffice.org 3
Origin
Overwolf
PhotoScape
PlayClaw 5
PMlabs
Realtek
Reference Assemblies
Rockstar Games
Sketch Drawer
Smart Application Controller
Sony
Steam
TeamViewer
TomTom International B.V
Total Video Converter
Tweaking.com
Ubisoft
Ultra Vision Video Converter
VideoLAN
VirtualDJ
VMware
VS Revo Group
Winamp
Windows Defender
Windows Mail
Windows Media Player
Windows Multimedia Platform
Windows NT
Windows Photo Viewer
Windows Portable Devices
Wise
========= Ende von CMD: =========
========= dir /B "%ProgramData%" =========
.mono
Adobe
Auslogics
AVAST Software
Avg
Avira
Becky Brogan 2
BlueStacksSetup
boost_interprocess
Canneverbe Limited
CannyGames
Codemasters
Comms
DAEMON Tools Lite
dbg
Dovetail Games
EA Core
eJay
Electronic Arts
EPSON
Far Mills
Forge of Games
Foxit ContentPlatform
Freemake
InstallShield
Licenses
Lionhead Studios
LittleGamesCompany
Logs
Malwarebytes
Malwarebytes' Anti-Malware (portable)
Microsoft Help
Microsoft OneDrive
Mozilla
MumboJumbo
Native Instruments
NCH Software
NVIDIA
NVIDIA Corporation
Oracle
Origin
Overwolf
Package Cache
Particles
PoBros
regid.1986-12.com.adobe
regid.1991-06.com.microsoft
RELOADED
Rockstar Games
SkidRow
Skype
SoftwareDistribution
Sony
Steam
Sun
TEMP
THQ
TuneUp Software
Ubisoft
Ultra Vision Video Converter
USOPrivate
USOShared
VMware
yelsi
========= Ende von CMD: =========
========= dir /B "%Appdata%" =========
.mono
AbiSuite
Activision
Adobe
AIMP
alsoft.ini
Andy
Anvate Games
Anvsoft
Argali
Artifex Mundi
ArtifexMundi
Aspyr Media
Atari
avidemux
Avira
AVS4YOU
Az-Art
BANDISOFT
Brave Giant
BraveGiant
Canneverbe Limited
cerasus.media
Colossal Order
com.nesbox.companion
DAEMON Tools Lite
de.rokapublish.launcher
Deep Shadows
DeltaBin
Desktop
DlinkViewCam
Doublefine
Dovetail Games
dvdcss
Eipix
EleFun Games
Elephant Games
EPSON
ESS
Feuerwache
FileZilla
FinewayStudios
Five-BN Games
Foxit Software
Frontier Developments
Frontwing
FUJIFILM
GameHouse
GHISLER
GrandMA Studios
Highresolution Enterprises
Identities
JanesZOO realore de
jhakonen.com
Kalypso Media
Keseling
krita
LestaStudio
Lionhead Studios
LittleGamesCompany
machines
Macromedia
Media Center Programs
Milestone
Mozilla
MumboJumbo
MyTransitGuide
NCH Software
NVIDIA
openal
OpenOffice.org
PhotoScape
PlayClaw5
PoBros
Profiles
ProMod
Promotion Software GmbH
RenPy
ShamanGS
Silverback Productions
Skype
Smart Application Controller
SpinTires
Steam
Sun
Sunward Games
TeamViewer
TheLastDream
Thunderbird
TomTom
TS3Client
ts3overlay
TuneUp Software
Ubisoft
Unity
uplay
Urchin
uTorrent
Vast Studios
vlc
VMware
Wargaming.net
Warner Bros. Interactive Entertainment
Winamp
WinRAR
Wise Care 365
Wise Force Deleter
WoodCutter2015
========= Ende von CMD: =========
========= dir /B "%LocalAppdata%" =========
ACCCx3_6_0_248
ACCCx3_6_0_248.zip
ActiveSync
Adobe
ali213GameLauncher
Apps
BlueStacks
CAPCOM
Caphyon
CEF
Colossal Order
Comms
CrashDumps
Daedalic Entertainment GmbH
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
DeadByDaylight
Diagnostics
Disc_Soft_Ltd
Downloaded Installations
ElevatedDiagnostics
EMU
file__0.localstorage
FishingGame
FlatOut Ultimate Carnage
fontconfig
FreemakeVideoConverter
Frontier Developments
fusioncache.dat
GHISLER
Ghostbusters
GHOSTBUSTERS (tm)
Google
GWX
id Software
JDownloader v2.0
Macromedia
Microsoft
Microsoft Help
MicrosoftEdge
Mixxx
Mozilla
MyComGames
NVIDIA
NVIDIA Corporation
Overwolf
Packages
PeerDistRepub
Programs
Publishers
resmon.resmoncfg
Rockstar Games
SKIDROW
Skype
SniperV2
speech
Sports Interactive
Steam
Temp
Thunderbird
TileDataLayer
TomTom
Ubisoft
Ubisoft Game Launcher
Unity
UnrealEngine
UWKProcess
Vedran_Budimir_Bajer
VirtualStore
WOS4 - New York
Zombie Army Trilogy
========= Ende von CMD: =========
========= RemoveProxy: =========
HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => Wert erfolgreich entfernt
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
========= Ende von RemoveProxy: =========
========= ipconfig /flushdns =========
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
========= Ende von CMD: =========
========= netsh winsock reset =========
Der Winsock-Katalog wurde zurckgesetzt.
Sie mssen den Computer neu starten, um den Vorgang abzuschlieáen.
========= Ende von CMD: =========
=========== EmptyTemp: ==========
BITS transfer queue => 35136 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 266451630 B
Java, Flash, Steam htmlcache => 38662463 B
Windows/system/drivers => 15003326 B
Edge => 68444011 B
Chrome => 483856881 B
Firefox => 337973523 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 2348 B
NetworkService => 197094 B
Alex => 293505883 B
Administrator => 0 B
DefaultAppPool => 0 B
RecycleBin => 0 B
EmptyTemp: => 1.4 GB temporäre Dateien entfernt.
================================
Das System musste neu gestartet werden.
==== Ende von Fixlog 17:11:39 ==== Code:
# AdwCleaner v6.010 - Bericht erstellt am 14/09/2016 um 16:13:52
# Aktualisiert am 12/08/2016 von ToolsLib
# Datenbank : 2016-09-13.1 [Server]
# Betriebssystem : Windows 10 Pro (X64)
# Benutzername : Alex - PEACHY
# Gestartet von : C:\Users\Alex\Desktop\AdwCleaner_6.010.exe
# Modus: Löschen
# Unterstützung : https://toolslib.net/forum
***** [ Dienste ] *****
***** [ Ordner ] *****
***** [ Dateien ] *****
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Verknüpfungen ] *****
***** [ Aufgabenplanung ] *****
***** [ Registrierungsdatenbank ] *****
[-] Schlüssel gelöscht: HKU\S-1-5-21-2927967124-101175508-2003510897-1000\Software\Classes\AppXrh6feys59dqfzsv9p3s9p6aep0hwtb23
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\Classes\AppXrh6feys59dqfzsv9p3s9p6aep0hwtb23
[-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\b`nl{y
[-] Schlüssel gelöscht: HKLM\SOFTWARE\b`nl{y
***** [ Browser ] *****
*************************
:: "Tracing" Schlüssel gelöscht
:: Winsock Einstellungen zurückgesetzt
:: "Prefetch" Dateien gelöscht
:: Proxy Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [4148 Bytes] - [06/09/2016 09:31:37]
C:\AdwCleaner\AdwCleaner[C2].txt - [2726 Bytes] - [06/09/2016 15:35:31]
C:\AdwCleaner\AdwCleaner[C3].txt - [3524 Bytes] - [12/09/2016 10:34:34]
C:\AdwCleaner\AdwCleaner[C4].txt - [1487 Bytes] - [14/09/2016 16:13:52]
C:\AdwCleaner\AdwCleaner[S0].txt - [4143 Bytes] - [06/09/2016 09:30:50]
C:\AdwCleaner\AdwCleaner[S1].txt - [2743 Bytes] - [06/09/2016 15:33:37]
C:\AdwCleaner\AdwCleaner[S2].txt - [1614 Bytes] - [07/09/2016 13:32:45]
C:\AdwCleaner\AdwCleaner[S3].txt - [3468 Bytes] - [12/09/2016 09:57:55]
C:\AdwCleaner\AdwCleaner[S4].txt - [3541 Bytes] - [12/09/2016 10:05:46]
C:\AdwCleaner\AdwCleaner[S5].txt - [2133 Bytes] - [14/09/2016 16:12:33]
########## EOF - C:\AdwCleaner\AdwCleaner[C4].txt - [1998 Bytes] ########## Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 14.09.2016
Suchlaufzeit: 16:23
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2016.09.14.07
Rootkit-Datenbank: v2016.08.15.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: Alex
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 420806
Abgelaufene Zeit: 16 Min., 26 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 1
PUP.Optional.Elex, C:\Program Files (x86)\Prerpetaincliiph\clhBuilder.dll, Löschen bei Neustart, [54bbe58d0e8cef47c822d61741c39070],
Registrierungsschlüssel: 4
PUP.Optional.HohoSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{3D26F772-E706-43C1-BB76-960259E909D5}, Löschen bei Neustart, [a86785edddbd0a2c5a7206c352b022de],
PUP.Optional.HohoSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Joropygrosak Debuger, Löschen bei Neustart, [a06f89e90298da5cf7d6993040c260a0],
PUP.Optional.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\JoropygrosakDebuger, In Quarantäne, [54bbe58d0e8cef47c822d61741c39070],
PUP.Optional.SystemHealer, HKU\S-1-5-21-2927967124-101175508-2003510897-500\SOFTWARE\SYSTEM HEALER, In Quarantäne, [4fc0bcb60496ec4a8a27e815e81ba45c],
Registrierungswerte: 2
PUP.Optional.HohoSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{3D26F772-E706-43C1-BB76-960259E909D5}|Path, \Joropygrosak Debuger, Löschen bei Neustart, [a86785edddbd0a2c5a7206c352b022de]
PUP.Optional.SystemHealer, HKU\S-1-5-21-2927967124-101175508-2003510897-500\SOFTWARE\SYSTEM HEALER|CartURL, 1, In Quarantäne, [4fc0bcb60496ec4a8a27e815e81ba45c]
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Dateien: 16
Trojan.AdLoad.CN, C:\Users\Alex\AppData\Local\Temp\237752750\ic-0.a62718415d79.exe, In Quarantäne, [5db2b4be3862d066c78283342ed6c040],
PUP.Optional.Amonetize, C:\Users\Alex\AppData\Local\Temp\237752750\Setup__2140_il1815.exe, In Quarantäne, [55ba2d45cdcd4de96899e07515ec669a],
PUP.Optional.HohoSearch, C:\Windows\System32\Tasks\Joropygrosak Debuger, In Quarantäne, [1af55a18e7b35ed8d8f29039a55d847c],
PUP.Optional.MorePowerfulCleaner, C:\Users\Alex\AppData\Roaming\Microsoft\Windows\SendTo\MPC Desktop.lnk, In Quarantäne, [d53aa5cd2d6d6ccabf28da24b84b9b65],
PUP.Optional.Elex, C:\Program Files\Mozilla Firefox\wtsapi32.dll, Löschen bei Neustart, [e12e4b274c4ec076a2ad5d6d857f4eb2],
PUP.Optional.Elex, C:\Program Files (x86)\Prerpetaincliiph\clhBuilder.dll, Löschen bei Neustart, [54bbe58d0e8cef47c822d61741c39070],
PUP.Optional.Amonetize, C:\Users\Alex\AppData\Local\Temp\amipixel.cfg, In Quarantäne, [31deff736337ae885b2998047490837d],
PUP.Optional.Trotux, C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\n4plk0l5.Alex\searchplugins\ezcclg65.xml, In Quarantäne, [ba559ad86a304ceaafcd5647030134cc],
PUP.Optional.Trotux, C:\Users\Alex\AppData\Roaming\Profiles\Prmertyckbock.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.trotux.com/?z=2e5bf6ff8db68eaf40997b5g5zfm0c1qcq0edmec2q&from=amz&uid=WDCXWD5000AAKS-00UU3A0_WD-WCAYU600309203092&type=hp");), Ersetzt,[de312c464d4d0d29498fa14bb05460a0]
PUP.Optional.Trotux, C:\Users\Alex\AppData\Roaming\Profiles\Prmertyckbock.default\prefs.js, Gut: (), Schlecht: ( 1473587134);
user_pref("app.update.lastUpdateTime.xpi-), Ersetzt,[957a7ff3792101352eaadf0da16306fa]
PUP.Optional.Trotux, C:\Users\Alex\AppData\Roaming\Profiles\Prmertyckbock.default\prefs.js, Gut: (), Schlecht: (s file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change t), Ersetzt,[ac63ec861a8086b0b02805e762a27b85]
PUP.Optional.Trotux, C:\Users\Alex\AppData\Roaming\Profiles\Prmertyckbock.default\prefs.js, Gut: (), Schlecht: (s running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
*/
user_pref("accessibility.typeaheadfin), Ersetzt,[d03f59193c5efa3caf295a92a75de020]
PUP.Optional.Trotux, C:\Users\Alex\AppData\Roaming\Profiles\Prmertyckbock.default\prefs.js, Gut: (), Schlecht: (nces, you can visit the URL about:config
*/
user_pref("accessibility.typeaheadfind", true);
user_pref("app.update.auto", false);
user_pref("app.update.enabled", false);
user_pref("app.update.lastU), Ersetzt,[8887046e8e0c57dfdbfd1fcdbe46b848]
PUP.Optional.Trotux, C:\Users\Alex\AppData\Roaming\Profiles\Prmertyckbock.default\prefs.js, Gut: (), Schlecht: (ges will be overwritten when the application exits.
), Ersetzt,[858aa6ccd9c154e26a6eb33933d1629e]
PUP.Optional.Trotux, C:\Users\Alex\AppData\Roaming\Profiles\Prmertyckbock.default\prefs.js, Gut: (), Schlecht: (ypeaheadfind", true);
user_pref("app.update.auto", false);
user_pref("app.update.enabled", false);
user_pref("app.update.lastUpdateTime.addon-background-update-timer", 147), Ersetzt,[cf40c9a93664c37328b0de0eca3a817f]
PUP.Optional.Trotux, C:\Users\Alex\AppData\Roaming\Profiles\Prmertyckbock.default\searchplugins\ezcclg65.xml, In Quarantäne, [60af96dc4d4d15219c39effdfe06a957],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.7 (07.03.2016)
Operating System: Windows 10 Pro x64
Ran by Alex (Administrator) on 14.09.2016 at 16:57:42,62
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 0
Registry: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14.09.2016 at 17:00:22,22
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 12-09-2016
durchgeführt von Alex (Administrator) auf PEACHY (14-09-2016 17:03:15)
Gestartet von C:\Users\Alex\Desktop
Geladene Profile: Alex (Verfügbare Profile: Alex & Administrator & DefaultAppPool)
Platform: Windows 10 Pro Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DiscSoftBusService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [XMouseButtonControl] => C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe [1075344 2014-12-08] (Highresolution Enterprises)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\nvspcap64.dll [1860120 2016-01-12] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2787264 2016-01-12] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-03-22] (Adobe Systems Incorporated)
HKLM\...\Run: [CmPCIaudio] => C:\WINDOWS\Syswow64\CMICNFG3.dll [8151040 2009-10-30] (C-Media Corporation)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: ["C:\Program Files (x86)\D-Link\D-ViewCam\MainConsole.EXE"] => "C:\Program Files (x86)\D-Link\D-ViewCam\MainConsole.EXE" RunWithWindows
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [60136 2016-08-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [55264 2016-03-10] (Malwarebytes)
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2857248 2016-08-23] (Valve Corporation)
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files (x86)\DAEMON Tools Lite\DTAgent.exe [4468056 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\...\Run: [EPSON SX125 Series] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIGGE.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\...\Run: [World of Tanks] => D:\Spiele\World_of_Tanks\WargamingGameUpdater.exe [3134728 2016-08-05] (Wargaming.net)
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\...\Run: [TomTomHOME.exe] => "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" -s
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\...\MountPoints2: H - "H:\AutoRun.exe"
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\...\MountPoints2: {0f748fbf-2152-11e5-8233-50465d90560b} - "N:\setup.exe"
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\...\MountPoints2: {75d42f49-1b0e-11e5-ac3c-50465d90560b} - "G:\setup.exe"
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\...\MountPoints2: {94b3fc27-1c9b-11e5-ac5a-50465d90560b} - "H:\setup.exe"
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\...\MountPoints2: {e3802153-18aa-11e5-ab60-50465d90560b} - "N:\setup.exe"
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{2a94d664-f07c-4e02-a516-4e233f0db8d2}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{faa03109-abab-40bf-9edb-fcd71145efd5}: [DhcpNameServer] 192.168.224.1
ManualProxies:
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\S-1-5-21-2927967124-101175508-2003510897-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/androidnews/
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll [2016-09-07] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-09-07] (Oracle Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2014-08-12] (Adblock Plus)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-09-07] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-09-07] (Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2014-08-12] (Adblock Plus)
Handler-x32: abs - {E00957BD-D0E1-4eb9-A025-7743FDC8B27B} - C:\Windows\system32\mscoree.dll [2015-10-30] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\n4plk0l5.Alex
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_162.dll [2016-09-13] ()
FF Plugin: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-09-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-09-07] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin: @unity3d.com/UnityPlayer64,version=1.0 -> C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll [2015-06-08] (Unity Technologies ApS)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2014-09-19] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_162.dll [2016-09-13] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2015-04-17] (Adobe Systems, Inc.)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [Keine Datei]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [Keine Datei]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [Keine Datei]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [Keine Datei]
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-09-07] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-09-07] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-01-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-01-23] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin HKU\S-1-5-21-2927967124-101175508-2003510897-1000: @my.com/Games -> C:\Users\Alex\AppData\Local\MyComGames\NPMyComDetector.dll [2016-02-03] (MY.COM B.V.)
FF Plugin HKU\S-1-5-21-2927967124-101175508-2003510897-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Alex\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-12] (Unity Technologies ApS)
FF Extension: (Firefox Hotfix) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\n4plk0l5.Alex\Extensions\firefox-hotfix@mozilla.org.xpi [2016-09-10]
FF Extension: (Adblock Plus) - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\n4plk0l5.Alex\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-08-14]
Chrome:
=======
CHR HomePage: ChromeDefaultData -> hxxp://www.google.de/
CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\ChromeDefaultData
CHR Extension: (Google Docs) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-09-12]
CHR Extension: (Fast Social for Google Chrome™) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\bkgibcbnbhhkelflcgappdalfbopghof [2016-09-12]
CHR Extension: (Avira Browserschutz) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-09-12]
CHR Extension: (AdBlock) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-09-12]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-09-12]
CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-12]
CHR Profile: C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-07-26]
CHR Extension: (Google Docs) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-07-26]
CHR Extension: (Google Drive) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-26]
CHR Extension: (Fast Social for Google Chrome™) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkgibcbnbhhkelflcgappdalfbopghof [2016-09-06]
CHR Extension: (YouTube) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-26]
CHR Extension: (Adblock Plus) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-08-23]
CHR Extension: (Google Tabellen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-07-26]
CHR Extension: (Myinstants Soundboard) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\fggacdedkdoacbemcilniodecinpfkgi [2016-08-30]
CHR Extension: (Avira Browserschutz) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-09-08]
CHR Extension: (Google Docs Offline) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-26]
CHR Extension: (AdBlock) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-08-24]
CHR Extension: (mydlink services plugin) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldibdoepbjbkkcbgndfljnphngpglhbb [2016-07-26]
CHR Extension: (Google Maps) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2016-07-26]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-07-26]
CHR Extension: (Mein Chrome-Design) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2016-07-26]
CHR Extension: (SEGA GENESIS / SEGA Mega Drive Emulator) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofnmgamcdbdieifheiiphnbbbcaofcbc [2016-07-26]
CHR Extension: (Emulador de Super Nintendo) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pffhngmcplldclknnkmkkecjlhhccmid [2016-07-26]
CHR Extension: (Google Mail) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-26]
CHR Extension: (RHS) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkaifndebjpbndephomibbjjbnokmfab [2016-09-06]
CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-29]
CHR Extension: (Audio Cutter) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\plimnkafgoiilijmlbnfoafihjjijbfp [2016-09-08]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [346928 2016-08-24] (Avira Operations GmbH & Co. KG)
S2 AviraPhantomVPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [253392 2016-08-26] (Avira Operations GmbH & Co. KG)
R3 Disc Soft Lite Bus Service; C:\Program Files (x86)\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [232208 2016-07-01] (EasyAntiCheat Ltd)
S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-12-03] (Freemake) [Datei ist nicht signiert]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-12] (NVIDIA Corporation)
S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-12] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-12] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-12] (NVIDIA Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1310448 2016-09-07] (Overwolf LTD)
S3 vmicvss; C:\Windows\System32\ICSvc.dll [511488 2015-10-30] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-07-01] (Microsoft Corporation)
S2 WiseBootAssistant; C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe [580144 2015-05-12] (WiseCleaner.com)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13368 2009-04-06] ()
R3 cmuda3; C:\Windows\system32\drivers\cmudax3.sys [1155072 2009-12-01] (C-Media Inc)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [130688 2016-07-22] (Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-06-22] (Disc Soft Ltd)
U0 gbtbsm; C:\Windows\System32\drivers\yxnutjg.sys [79064 2016-09-14] (Malwarebytes)
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [27552 2015-11-04] (REALiX(tm))
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-09-14] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek )
S3 Secdrv; C:\WINDOWS\SysWOW64\drivers\SECDRV.SYS [20128 2016-01-15] () [Datei ist nicht signiert]
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [221824 2016-04-25] (Samsung Electronics Co., Ltd.)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [221824 2016-04-25] (Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 WiseHDInfo; C:\Windows\WiseHDInfo64.dll [14800 2015-07-31] (wisecleaner.com)
R1 WiseUnlock; C:\WINDOWS\WiseUnlock64.sys [12240 2015-05-19] (WiseCleaner.com)
U3 idsvc; kein ImagePath
S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-09-14 17:03 - 2016-09-14 17:03 - 00022786 _____ C:\Users\Alex\Desktop\FRST.txt
2016-09-14 17:00 - 2016-09-14 17:00 - 00000545 _____ C:\Users\Alex\Desktop\JRT.txt
2016-09-14 16:56 - 2016-09-14 16:56 - 01610560 _____ (Malwarebytes) C:\Users\Alex\Desktop\JRT(1).exe
2016-09-14 16:55 - 2016-09-14 16:55 - 00005673 _____ C:\Users\Alex\Desktop\mbam.txt
2016-09-14 16:54 - 2016-09-14 16:54 - 00079064 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\yxnutjg.sys
2016-09-14 16:21 - 2016-09-14 16:21 - 00001131 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-09-14 16:20 - 2016-09-14 16:20 - 22851472 _____ (Malwarebytes ) C:\Users\Alex\Downloads\mbam-setup-2.2.1.1043.exe
2016-09-14 16:19 - 2016-09-14 16:19 - 00002084 _____ C:\Users\Alex\Desktop\AdwCleaner[C4].txt
2016-09-14 16:08 - 2016-09-14 16:08 - 00004542 _____ C:\Users\Alex\Desktop\14.09.16.txt
2016-09-14 14:54 - 2016-09-14 14:54 - 00000795 _____ C:\Users\Alex\Desktop\Fixlist.txt
2016-09-14 08:58 - 2016-09-14 08:58 - 00000000 ____D C:\Program Files (x86)\ESET
2016-09-13 21:14 - 2016-09-13 21:17 - 00059030 _____ C:\Users\Alex\Downloads\Addition.txt
2016-09-13 21:12 - 2016-09-14 17:03 - 00000000 ____D C:\FRST
2016-09-13 21:12 - 2016-09-13 21:17 - 00048192 _____ C:\Users\Alex\Downloads\FRST.txt
2016-09-13 21:12 - 2016-09-13 21:12 - 02398720 _____ (Farbar) C:\Users\Alex\Desktop\FRST64.exe
2016-09-13 21:10 - 2016-09-13 21:10 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Alex\Downloads\tdsskiller.exe
2016-09-13 21:04 - 2016-09-13 21:04 - 02870984 _____ (ESET) C:\Users\Alex\Downloads\esetsmartinstaller_deu.exe
2016-09-13 21:02 - 2016-09-13 21:02 - 00002296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-09-13 21:02 - 2016-09-13 21:02 - 00002284 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-09-13 21:00 - 2016-09-14 16:17 - 00001116 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-09-13 21:00 - 2016-09-14 16:05 - 00001120 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-09-13 21:00 - 2016-09-13 21:00 - 00004178 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-09-13 21:00 - 2016-09-13 21:00 - 00003946 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-09-13 20:47 - 2016-09-13 20:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-09-13 20:47 - 2016-09-13 20:47 - 00000000 ____D C:\Program Files\VS Revo Group
2016-09-13 20:14 - 2016-09-13 20:45 - 07093624 _____ (VS Revo Group ) C:\Users\Alex\Downloads\revosetup_2.0.exe
2016-09-13 20:13 - 2016-09-13 20:15 - 01610560 _____ (Malwarebytes) C:\Users\Alex\Downloads\JRT.exe
2016-09-12 08:13 - 2016-09-12 08:13 - 00000046 _____ C:\WINDOWS\Joberphlusisp
2016-09-12 08:13 - 2016-09-12 08:13 - 00000000 ____D C:\ProgramData\Avg
2016-09-12 08:13 - 2016-09-12 08:13 - 00000000 ____D C:\ProgramData\AVAST Software
2016-09-12 08:12 - 2016-09-12 10:35 - 00000000 ____D C:\Program Files (x86)\Prerpetaincliiph
2016-09-12 08:12 - 2016-09-12 09:55 - 00000000 ____D C:\Users\Alex\AppData\Local\Sejoge
2016-09-12 08:10 - 2016-09-12 10:35 - 00000000 ____D C:\Users\Alex\AppData\Roaming\MyTransitGuide
2016-09-12 08:08 - 2016-09-12 08:08 - 01208320 _____ C:\Users\Alex\Downloads\fernbus_simulator_conspir4cy_crackrar.img
2016-09-11 22:59 - 2016-09-11 22:59 - 00000000 ____D C:\Users\Alex\Documents\The.Task
2016-09-11 22:28 - 2016-09-11 22:28 - 00000000 ____D C:\Users\Alex\AppData\LocalLow\uTorrent
2016-09-11 21:34 - 2016-09-11 21:34 - 00016719 _____ C:\Users\Alex\Downloads\Fernbus_Simulator_2016.torrent
2016-09-11 19:42 - 2016-09-11 19:44 - 109132576 _____ C:\Users\Alex\Downloads\LMFAO_-_Sorry_For_Party_Rocking-2011-MOD.rar
2016-09-10 09:42 - 2016-09-10 09:42 - 01793045 _____ C:\Users\Alex\Downloads\187096_12.rar
2016-09-10 09:32 - 2016-09-10 09:32 - 03557465 _____ C:\Users\Alex\Downloads\FIFA 15 Latest Squads file by Mark.rar
2016-09-08 22:27 - 2016-09-08 22:27 - 00001032 _____ C:\Users\Alex\Desktop\fifa15.exe - Verknüpfung.lnk
2016-09-08 21:29 - 2016-09-08 21:33 - 00000000 ____D C:\Users\Alex\Documents\FIFA 15
2016-09-08 18:54 - 2016-09-08 18:54 - 00026052 ____N C:\Users\Alex\Downloads\88340998f9d272bb5a71c5b978fb316b42cc1347.dlc
2016-09-08 16:46 - 2016-09-08 16:46 - 00000000 ____D C:\Users\Alex\Documents\Soundaufnahmen
2016-09-07 22:17 - 2016-09-12 08:13 - 00000000 ____D C:\ProgramData\Avira
2016-09-07 22:17 - 2016-09-07 22:17 - 04446224 _____ (Avira Operations GmbH & Co. KG) C:\Users\Alex\Downloads\avira_de_avpn0_57d075bcae606__def.exe
2016-09-07 22:17 - 2016-09-07 22:17 - 00001085 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira Phantom VPN.lnk
2016-09-07 22:17 - 2016-09-07 22:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2016-09-07 21:03 - 2016-09-07 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atari
2016-09-07 20:28 - 2016-09-07 20:28 - 00014357 _____ C:\Users\Alex\Downloads\RollerCoaster.Tycoon.World.Early.Access.torrent
2016-09-07 20:26 - 2016-09-07 20:35 - 566719036 _____ C:\Users\Alex\Downloads\Rcsrtycnpltn.rar
2016-09-07 20:21 - 2016-09-07 20:21 - 00003342 _____ C:\WINDOWS\System32\Tasks\{F823577C-328F-42E1-82E8-273F76E8E0F2}
2016-09-07 14:31 - 2016-09-07 14:31 - 86921726 _____ C:\Users\Alex\Downloads\LStThViC.rar
2016-09-07 14:30 - 2016-09-08 16:45 - 00000000 ____D C:\Users\Alex\Desktop\Lindsey Stirling
2016-09-07 14:30 - 2016-09-07 14:30 - 137263509 _____ C:\Users\Alex\Downloads\%2FLindsey_Stirling-Lindsey_Stirling-%28Deluxe_Edition%29-2013-C4.zip
2016-09-07 14:29 - 2016-09-07 14:32 - 118347516 _____ C:\Users\Alex\Downloads\Lindsey_Stirling-Brave_Enough-%28Limited_Deluxe_Edition%29-2016-C4.rar
2016-09-07 14:29 - 2016-09-07 14:30 - 111660182 _____ C:\Users\Alex\Downloads\Lindsey_Stirling-Shatter_Me-%28Deluxe_Edition%29-2014-C4.rar
2016-09-07 14:26 - 2016-09-07 14:25 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-64.dll
2016-09-07 14:24 - 2016-09-07 14:24 - 01196752 _____ (Adobe Systems Incorporated) C:\Users\Alex\Downloads\flashplayer22_xa_install.exe
2016-09-07 13:09 - 2016-09-07 13:13 - 01028096 ____N C:\Users\Alex\Downloads\Fernbus Simulator Free.img
2016-09-06 13:11 - 2016-09-06 13:11 - 00594944 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Alex\Downloads\libeay32.dll
2016-09-06 13:11 - 2016-09-06 13:11 - 00152576 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Alex\Downloads\ssleay32.dll
2016-09-06 13:10 - 2016-09-14 16:13 - 00000008 __RSH C:\ProgramData\ntuser.pol
2016-09-06 13:10 - 2016-09-06 13:10 - 00002173 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Моzillа Firеfох.lnk
2016-09-06 13:10 - 2016-09-06 13:10 - 00002171 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk
2016-09-06 13:10 - 2016-09-06 13:10 - 00000000 ____D C:\Program Files (x86)\FastSocial
2016-09-06 13:08 - 2016-09-06 13:08 - 00000381 _____ C:\Users\Alex\Downloads\FF16 TOR.txt
2016-09-06 08:34 - 2016-09-14 16:13 - 00000000 ____D C:\AdwCleaner
2016-09-06 08:34 - 2016-09-06 08:34 - 03826240 _____ C:\Users\Alex\Desktop\AdwCleaner_6.010.exe
2016-09-05 09:57 - 2016-09-05 09:57 - 01144832 _____ C:\Users\Alex\Downloads\Crack Setup.img
2016-09-02 20:44 - 2016-09-02 20:44 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Promotion Software GmbH
2016-09-02 20:39 - 2016-09-02 20:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deep Silver
2016-08-31 15:26 - 2016-08-31 15:26 - 00134808 _____ (Atomix Productions) C:\Users\Alex\Downloads\install_ddjergopads (1).exe
2016-08-30 20:28 - 2016-08-30 20:28 - 00000553 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autobahn Police Simulator.lnk
2016-08-30 20:24 - 2016-08-30 20:24 - 00000580 _____ C:\Users\Alex\Downloads\windowsmediaplayer (2).asx
2016-08-30 13:45 - 2016-08-30 13:46 - 00000000 ____D C:\Program Files (x86)\MP3Gain
2016-08-30 13:45 - 2016-08-30 13:45 - 01474568 _____ C:\Users\Alex\Downloads\MP3Gain - CHIP-Installer (1).exe
2016-08-30 13:45 - 2016-08-30 13:45 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3Gain
2016-08-30 13:42 - 2016-08-30 13:42 - 01474568 _____ C:\Users\Alex\Downloads\wxMP3Gain - CHIP-Installer.exe
2016-08-30 11:43 - 2016-08-30 11:43 - 01474568 _____ C:\Users\Alex\Downloads\MP3Gain - CHIP-Installer.exe
2016-08-30 09:52 - 2005-05-17 15:39 - 00349265 _____ C:\Users\Alex\Desktop\tvtotalnippelboard.swf
2016-08-30 09:50 - 2016-08-30 09:52 - 395414331 _____ () C:\Users\Alex\Downloads\GLP - Soundboard Setup.exe
2016-08-30 09:48 - 2016-08-30 09:48 - 01474568 _____ C:\Users\Alex\Downloads\Stefan Raabs TV Total Nippelboard - CHIP-Installer.exe
2016-08-29 21:18 - 2016-08-29 21:18 - 00134808 _____ (Atomix Productions) C:\Users\Alex\Downloads\install_ddjergopads.exe
2016-08-29 21:15 - 2016-08-29 21:16 - 02000360 _____ (Atomix Productions) C:\Users\Alex\Downloads\install_blacksheephd.exe
2016-08-29 20:53 - 2016-08-29 20:55 - 04411520 _____ (Atomix Productions) C:\Users\Alex\Downloads\install_x96byzanard.exe
2016-08-29 20:47 - 2016-08-29 20:56 - 03227864 _____ (Atomix Productions) C:\Users\Alex\Downloads\install_pioneerxdjrxbyzaik.exe
2016-08-29 10:28 - 2009-10-30 04:39 - 08151040 ____N (C-Media Corporation) C:\WINDOWS\SysWOW64\CMICNFG3.dll
2016-08-29 10:28 - 2009-04-02 10:59 - 00143360 ____N C:\WINDOWS\SysWOW64\VmixP6.dll
2016-08-29 10:28 - 2008-07-23 12:59 - 00389120 ____N () C:\WINDOWS\system32\CMICNFG3.cpl
2016-08-29 10:28 - 2006-09-13 20:21 - 00200704 ____N (C-Media) C:\WINDOWS\SysWOW64\CMPaOxy.dll
2016-08-29 10:27 - 2016-08-29 10:28 - 00000188 _____ C:\WINDOWS\Cmicnfg3.ini.cfl
2016-08-29 10:27 - 2016-08-29 10:27 - 00792576 ____N C:\WINDOWS\system32\Cmeaupci.exe
2016-08-29 10:27 - 2016-08-29 10:27 - 00000183 _____ C:\WINDOWS\Cmicnfg3.ini.imi
2016-08-29 10:27 - 2016-08-29 10:27 - 00000130 _____ C:\WINDOWS\system\Dlap.pfx
2016-08-29 10:27 - 2016-08-29 10:27 - 00000122 _____ C:\WINDOWS\system\Cmicnfg3.ini
2016-08-29 10:27 - 2016-08-29 10:27 - 00000000 ____D C:\Users\Alex\Desktop\PCI-8738-091211-7.12.8.1740(W7-RC-01)
2016-08-29 10:27 - 2009-12-11 05:28 - 00002754 ____N C:\WINDOWS\cmudax3.ini
2016-08-29 10:27 - 2009-12-01 05:31 - 01155072 _____ (C-Media Inc) C:\WINDOWS\system32\Drivers\cmudax3.sys
2016-08-29 10:27 - 2009-08-19 10:00 - 00359424 ____N C:\WINDOWS\system32\CmiInstallResAll64.dll
2016-08-29 10:27 - 2008-10-15 09:41 - 00002123 ____N C:\WINDOWS\Cmicnfg3.ini.cfg
2016-08-29 10:27 - 2007-11-04 19:30 - 01144983 ____N C:\WINDOWS\SysWOW64\KB936225x64.msu
2016-08-29 10:27 - 2007-02-26 14:30 - 00036864 _____ (C-Media Electronics Ins.) C:\WINDOWS\system32\cmudax3.dll
2016-08-29 10:27 - 2006-10-05 23:45 - 00524768 _____ (Microsoft Corporation) C:\WINDOWS\difxapi.dll
2016-08-28 20:36 - 2016-08-28 20:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
2016-08-28 20:36 - 2016-08-28 20:36 - 00000000 __HDC C:\ProgramData\{90D8CE90-3E6B-4034-A281-BC9F19B60A5B}
2016-08-28 20:36 - 2016-08-28 20:36 - 00000000 __HDC C:\ProgramData\{42DEBD12-9D09-4B77-B434-2EF604E45D3D}
2016-08-28 20:36 - 2016-08-28 20:36 - 00000000 ____D C:\ProgramData\Native Instruments
2016-08-28 20:36 - 2016-08-28 20:36 - 00000000 ____D C:\Program Files\Common Files\Native Instruments
2016-08-28 20:32 - 2016-08-28 20:33 - 244782432 _____ (Native Instruments ) C:\Users\Alex\Downloads\Traktor 2 2.10.3 Setup PC.exe
2016-08-28 20:32 - 2016-08-28 20:32 - 00000000 __HDC C:\ProgramData\{EB9C1D32-304E-4E8E-8D44-C4102A190A39}
2016-08-28 20:32 - 2016-08-28 20:32 - 00000000 ____D C:\Backup
2016-08-28 20:28 - 2016-08-28 20:28 - 00000000 ____D C:\Users\Alex\Desktop\DJ
2016-08-28 18:15 - 2016-09-13 15:38 - 00000000 ____D C:\Program Files (x86)\VirtualDJ
2016-08-28 18:15 - 2016-08-31 15:01 - 00000000 ____D C:\Users\Alex\Documents\VirtualDJ
2016-08-28 18:15 - 2016-08-28 18:15 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
2016-08-28 18:14 - 2016-08-28 18:15 - 38203392 _____ C:\Users\Alex\Downloads\install_virtualdj_pc_v8.2.3343.msi
2016-08-28 17:52 - 2016-08-28 20:28 - 00000000 ____D C:\Users\Alex\AppData\Local\Mixxx
2016-08-28 17:48 - 2016-08-28 17:48 - 25035393 _____ C:\Users\Alex\Downloads\mixxx-2.0.0-win64.exe
2016-08-28 17:48 - 2016-08-28 17:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mixxx
2016-08-28 17:48 - 2016-08-28 17:48 - 00000000 ____D C:\Program Files\Mixxx
2016-08-28 17:41 - 2016-08-28 18:02 - 00000000 ____D C:\WINDOWS\System32\Tasks\NCH Software
2016-08-28 17:41 - 2016-08-28 17:41 - 00001123 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zulu DJ-Software.lnk
2016-08-28 17:41 - 2016-08-28 17:41 - 00000000 ____D C:\ProgramData\NCH Software
2016-08-28 17:41 - 2016-08-28 17:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Produktpalette
2016-08-28 17:41 - 2016-08-28 17:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audioverwandte Programme
2016-08-28 17:41 - 2016-08-28 17:41 - 00000000 ____D C:\Program Files (x86)\NCH Software
2016-08-28 17:40 - 2016-08-28 17:40 - 00974560 _____ (NCH Software) C:\Users\Alex\Downloads\zulusetup.exe
2016-08-28 17:40 - 2016-08-28 17:40 - 00000000 ____D C:\Users\Alex\AppData\Roaming\NCH Software
2016-08-28 17:03 - 2016-08-28 17:03 - 38302328 _____ (Atomix Productions) C:\Users\Alex\Downloads\install_virtualdj_home_v7.4.6.exe
2016-08-27 15:10 - 2016-08-27 15:10 - 02929520 _____ (Odem Mortis ) C:\Users\Alex\Downloads\OMC_ModPack_Installer.exe
2016-08-26 15:21 - 2016-08-26 15:21 - 01106840 _____ (Unity Technologies ApS) C:\Users\Alex\Downloads\UnityWebPlayer64.exe
2016-08-26 14:25 - 2016-08-26 14:25 - 00035784 _____ (The OpenVPN Project) C:\WINDOWS\system32\Drivers\tap0901.sys
2016-08-25 21:58 - 2016-08-25 21:58 - 00000000 ____D C:\Users\Alex\Documents\Ghosthunters
2016-08-25 21:12 - 2016-08-25 21:12 - 00000580 _____ C:\Users\Alex\Downloads\windowsmediaplayer (1).asx
2016-08-23 22:19 - 2016-08-23 22:19 - 00000000 ____D C:\Users\Alex\Documents\Die Unfassbaren 2
2016-08-23 21:09 - 2016-08-23 21:09 - 00000000 ____D C:\Users\Alex\Documents\Die.wilden.Kerle.6.Die.Legende.lebt
2016-08-22 18:36 - 2016-08-22 18:36 - 00001187 _____ C:\Users\Alex\Desktop\Dynamo Dresden v RB Leipzig - DFB Pokal 1 Runde 2016_17_08.lnk
2016-08-22 18:25 - 2016-08-22 18:25 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Aspyr Media
2016-08-22 17:53 - 2016-08-22 17:53 - 00000744 _____ C:\Users\Public\Desktop\Layers of Fear - Masterpiece Edition.lnk
2016-08-22 17:52 - 2016-08-22 17:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bloober Team SA
2016-08-20 15:42 - 2016-09-12 08:10 - 00000000 ____D C:\Users\Alex\Desktop\Musik
2016-08-18 21:09 - 2016-08-18 21:09 - 00003320 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task
2016-08-16 20:19 - 2016-08-16 20:19 - 00610769 _____ C:\Users\Alex\Downloads\depends22_x86.zip
2016-08-16 20:05 - 2016-08-16 20:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TomTom
2016-08-16 20:05 - 2016-08-16 20:05 - 00000000 ____D C:\Users\Alex\Documents\TomTom
2016-08-16 20:05 - 2016-08-16 20:05 - 00000000 ____D C:\Users\Alex\AppData\Roaming\TomTom
2016-08-16 20:05 - 2016-08-16 20:05 - 00000000 ____D C:\Users\Alex\AppData\Local\TomTom
2016-08-16 20:03 - 2016-08-16 20:03 - 29403160 _____ C:\Users\Alex\Downloads\TomTomHOME2winlatest.exe
2016-08-16 20:00 - 2016-08-16 20:00 - 37565768 _____ (TomTom International B.V.) C:\Users\Alex\Downloads\InstallMyDriveConnect.exe
2016-08-16 20:00 - 2016-08-16 20:00 - 00000000 ____D C:\Program Files (x86)\TomTom International B.V
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-09-14 16:55 - 2015-03-30 17:38 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-09-14 16:54 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\addins
2016-09-14 16:22 - 2016-07-20 12:07 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-09-14 16:21 - 2016-07-21 17:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-09-14 16:21 - 2016-07-21 17:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-09-14 16:18 - 2015-05-04 14:56 - 00000000 ____D C:\Program Files (x86)\Steam
2016-09-14 16:17 - 2015-07-31 20:20 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Wise Care 365
2016-09-14 16:15 - 2015-12-22 17:05 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-09-14 16:15 - 2015-12-22 16:39 - 00000000 ____D C:\ProgramData\NVIDIA
2016-09-14 16:14 - 2016-07-20 12:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-09-14 16:14 - 2015-10-30 08:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2016-09-14 14:40 - 2015-08-06 17:26 - 00004150 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{9976B872-EBCD-4E3B-A512-199270B5525F}
2016-09-14 12:27 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-09-14 11:58 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-09-14 08:29 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-09-13 21:22 - 2015-08-04 20:05 - 00000000 ____D C:\Users\Alex\Desktop\Sonstiges
2016-09-13 21:02 - 2014-12-31 21:03 - 00000000 ____D C:\Program Files (x86)\Google
2016-09-13 20:50 - 2016-07-25 15:29 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-09-13 20:11 - 2015-04-01 12:15 - 00000000 ____D C:\Program Files (x86)\Overwolf
2016-09-13 11:55 - 2016-03-24 18:55 - 06502080 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2016-09-13 11:55 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-09-13 11:55 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-09-13 08:34 - 2015-07-31 20:20 - 00002127 _____ C:\Users\Public\Desktop\Wise Care 365.lnk
2016-09-12 10:35 - 2015-10-30 09:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-09-12 10:29 - 2014-12-31 21:46 - 00000000 ____D C:\Users\Alex\AppData\Roaming\vlc
2016-09-12 08:12 - 2016-07-25 12:45 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-09-12 01:15 - 2015-01-04 22:19 - 00000000 ____D C:\Users\Alex\AppData\Roaming\uTorrent
2016-09-12 01:15 - 2015-01-02 16:17 - 00000000 ____D C:\Users\Alex\AppData\Local\JDownloader v2.0
2016-09-11 23:20 - 2015-12-22 16:42 - 02113470 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-09-11 23:20 - 2015-10-30 20:35 - 00898170 _____ C:\WINDOWS\system32\perfh007.dat
2016-09-11 23:20 - 2015-10-30 20:35 - 00201656 _____ C:\WINDOWS\system32\perfc007.dat
2016-09-11 23:20 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-09-11 22:43 - 2015-07-03 15:08 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2016-09-11 22:42 - 2015-07-03 15:19 - 00000000 ____D C:\Program Files\Rockstar Games
2016-09-09 22:07 - 2015-12-22 16:43 - 00000000 ____D C:\Users\Alex
2016-09-08 22:27 - 2015-01-02 20:33 - 00000000 ____D C:\Users\Alex\Documents\My Games
2016-09-08 13:14 - 2015-10-01 21:05 - 00000000 ____D C:\Users\Alex\AppData\Local\MyComGames
2016-09-08 12:28 - 2015-01-01 12:08 - 00000000 ____D C:\Users\Alex\Desktop\Spiele
2016-09-08 12:00 - 2015-08-21 10:33 - 00000000 ____D C:\Users\Alex\AppData\Local\CrashDumps
2016-09-07 22:17 - 2014-12-31 21:29 - 00000000 ____D C:\ProgramData\Package Cache
2016-09-07 22:17 - 2014-12-31 21:27 - 00000000 ____D C:\Program Files (x86)\Avira
2016-09-07 20:20 - 2015-01-03 13:40 - 00000000 ____D C:\Users\Alex\AppData\Local\ElevatedDiagnostics
2016-09-07 14:33 - 2015-03-30 20:16 - 00000000 ____D C:\ProgramData\Oracle
2016-09-07 14:26 - 2015-09-13 09:21 - 00000000 ____D C:\Users\Alex\.oracle_jre_usage
2016-09-07 14:26 - 2015-06-17 14:50 - 00000000 ____D C:\Program Files (x86)\Java
2016-09-07 14:26 - 2015-03-30 17:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-09-07 14:25 - 2016-02-19 14:31 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-09-07 14:25 - 2015-06-17 14:51 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2016-09-07 14:25 - 2015-06-17 14:51 - 00000000 ____D C:\Program Files\Java
2016-09-07 14:24 - 2015-01-01 21:08 - 00000000 ____D C:\Users\Alex\AppData\Local\Adobe
2016-09-07 13:07 - 2014-12-31 20:52 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-09-06 13:09 - 2016-07-26 21:31 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps
2016-09-04 19:09 - 2015-01-31 12:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-09-02 09:12 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-08-29 16:38 - 2015-02-01 10:39 - 00000000 ____D C:\ProgramData\Ultra Vision Video Converter
2016-08-29 10:29 - 2016-01-17 10:33 - 00387176 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-08-29 10:27 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\System
2016-08-27 15:56 - 2015-09-03 19:56 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\OMC ModPack
2016-08-27 15:10 - 2015-09-03 18:58 - 00000000 ____D C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\OMC ModPack Client
2016-08-27 13:19 - 2015-11-10 14:32 - 00000000 ____D C:\Users\Alex\AppData\Local\UnrealEngine
2016-08-27 09:24 - 2015-05-14 17:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ravenscourt
2016-08-22 18:55 - 2016-01-31 10:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Square Enix
2016-08-21 09:21 - 2015-08-17 19:42 - 00000000 ___RD C:\Users\Alex\Desktop\Bildbearbeitung
2016-08-20 15:21 - 2015-02-26 12:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2016-08-18 21:09 - 2015-08-04 19:56 - 00002416 _____ C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-08-18 21:09 - 2015-08-04 19:56 - 00000000 ___RD C:\Users\Alex\OneDrive
2016-08-16 20:03 - 2015-11-27 21:53 - 00000000 ____D C:\Users\Alex\AppData\Local\Downloaded Installations
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2015-11-15 18:22 - 2015-11-15 10:52 - 0012879 _____ () C:\Users\Alex\AppData\Roaming\alsoft.ini
2016-06-02 10:48 - 2016-06-02 10:49 - 266040255 _____ () C:\Users\Alex\AppData\Local\ACCCx3_6_0_248.zip
2015-04-10 15:38 - 2015-04-10 15:38 - 0004608 _____ () C:\Users\Alex\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-04 18:01 - 2015-07-04 18:02 - 0003072 _____ () C:\Users\Alex\AppData\Local\file__0.localstorage
2015-07-24 20:25 - 2015-07-24 20:25 - 0000092 _____ () C:\Users\Alex\AppData\Local\fusioncache.dat
2015-11-18 12:41 - 2015-11-18 12:41 - 0000017 _____ () C:\Users\Alex\AppData\Local\resmon.resmoncfg
2015-12-22 16:38 - 2015-12-22 16:38 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Einige Dateien in TEMP:
====================
C:\Users\Alex\AppData\Local\Temp\jre-8u101-windows-au.exe
C:\Users\Alex\AppData\Local\Temp\libeay32.dll
C:\Users\Alex\AppData\Local\Temp\msvcr120.dll
C:\Users\Alex\AppData\Local\Temp\proxy_vole4506188439364049303.dll
C:\Users\Alex\AppData\Local\Temp\sqlite3.dll
C:\Users\Alex\AppData\Local\Temp\VirtualDJ New Version.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2016-09-07 17:36
==================== Ende von FRST.txt ============================ |