Ach, ist das herrlich, den Browser zu öffnen und nicht von Müll begrüßt zu werden :applaus: Code:
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 20-09-2016
durchgeführt von HP (20-09-2016 21:48:26) Run:1
Gestartet von C:\Users\HP\Desktop
Geladene Profile: HP & UpdatusUser (Verfügbare Profile: HP & UpdatusUser)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
start
CloseProcesses:
SearchScopes: HKU\S-1-5-21-3930845653-3837040866-4171826123-1004 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
Toolbar: HKLM-x32 - Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Keine Datei
FF Plugin HKU\S-1-5-21-3930845653-3837040866-4171826123-1001: @mail.ru/GameCenter -> C:\Users\HP\AppData\Local\Mail.Ru\GameCenter\NPDetector.dll [Keine Datei]
FF Extension: (Kein Name) - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha38\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta351\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha256\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha2543\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha4549\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home8521\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release1179\ff [nicht gefunden]
CHR HKLM-x32\...\Chrome\Extension: [ffffoobpkbfcfibdgopmebhlghaiiamk] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha38\ch\WebexpEnhancedV1alpha38.crx <nicht gefunden>
C:\Program Files (x86)\WebexpEnhancedV1
C:\Users\HP\AppData\Local\Kabeghtjerpoing
C:\Users\HP\Desktop\Die Installation von keygen - Free Download fortsetzen.lnk
C:\Program Files (x86)\Qotachcoerduk
C:\Users\HP\AppData\Local\clucadomqenayfehuent
C:\Users\HP\Downloads\*CHIP-Installer.exe
Unlock: C:\WINDOWS\system32\Drivers\etc\hosts
C:\WINDOWS\system32\Drivers\etc\hosts
Task: {710F6622-7749-4122-80E5-BC696171976F} - System32\Tasks\ExtFixer13197 => C:\windows\TEMP\41844_updater.exe <==== ACHTUNG
Task: {9ABBC3D1-DB15-4BAB-9397-BAE1EE87DAF1} - System32\Tasks\ExtFixer2078 => C:\windows\TEMP\41844_updater.exe <==== ACHTUNG
Task: {C463C7B7-3AAB-4778-8630-C3D74C672124} - System32\Tasks\{731C0D96-12CF-47EF-B0BF-E54A152EB958} => pcalua.exe -a "C:\Program Files (x86)\Cinema-Plus-1.2\Uninstall.exe" -c /fcp=1
Task: {DE278E01-1E60-465E-A5CB-E857CDF8F5D2} - \Perotainghernerry System -> Keine Datei <==== ACHTUNG
Task: C:\WINDOWS\Tasks\ExtFixer13197.job => C:\windows\TEMP\41844_updater.exeq/url='hxxp:/xml.localxpath.net/apps/cr/1060-4030_ElectroLyrics.exe <==== ACHTUNG
Task: C:\WINDOWS\Tasks\ExtFixer2078.job => C:\windows\TEMP\41844_updater.exep/url='hxxp:/xml.localxpath.net/apps/cr/1060-4030_ElectroLyrics.exe <==== ACHTUNG
AlternateDataStreams: C:\ProgramData\Temp:373E1720 [120]
AlternateDataStreams: C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Mail.Ru.website:TASKICON_0refresh-2076883145 [2686]
AlternateDataStreams: C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Mail.Ru.website:TASKICON_1write-1878237577 [2686]
AlternateDataStreams: C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Mail.Ru.website:TASKICON_2adress_book2-609010338 [2686]
CMD: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32" /v fst_de_19 /f
CMD: dir "%ProgramFiles%"
CMD: dir "%ProgramFiles(x86)%"
CMD: dir "%ProgramData%"
CMD: dir "%Appdata%"
CMD: dir "%LocalAppdata%"
Hosts:
RemoveProxy:
CMD: ipconfig /flushdns
CMD: netsh winsock reset
EmptyTemp:
end
*****************
Prozess erfolgreich geschlossen.
"HKU\S-1-5-21-3930845653-3837040866-4171826123-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => Schlüssel erfolgreich entfernt
HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => Schlüssel nicht gefunden.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Wert erfolgreich entfernt
HKCR\Wow6432Node\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Schlüssel nicht gefunden.
"HKU\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\MozillaPlugins\@mail.ru/GameCenter" => Schlüssel erfolgreich entfernt
C:\Users\HP\AppData\Local\Mail.Ru\GameCenter\NPDetector.dll => nicht gefunden.
C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff => nicht gefunden.
FF Extension: (Kein Name) - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff [nicht gefunden] => nicht gefunden
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha38\ff => nicht gefunden.
FF Extension: (Kein Name) - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha38\ff [nicht gefunden] => nicht gefunden
C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta351\ff => nicht gefunden.
FF Extension: (Kein Name) - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta351\ff [nicht gefunden] => nicht gefunden
C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha256\ff => nicht gefunden.
FF Extension: (Kein Name) - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha256\ff [nicht gefunden] => nicht gefunden
C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha2543\ff => nicht gefunden.
FF Extension: (Kein Name) - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha2543\ff [nicht gefunden] => nicht gefunden
C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha4549\ff => nicht gefunden.
FF Extension: (Kein Name) - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha4549\ff [nicht gefunden] => nicht gefunden
C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home8521\ff => nicht gefunden.
FF Extension: (Kein Name) - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home8521\ff [nicht gefunden] => nicht gefunden
C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release1179\ff => nicht gefunden.
FF Extension: (Kein Name) - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release1179\ff [nicht gefunden] => nicht gefunden
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ffffoobpkbfcfibdgopmebhlghaiiamk" => Schlüssel erfolgreich entfernt
"C:\Program Files (x86)\WebexpEnhancedV1" => nicht gefunden.
C:\Users\HP\AppData\Local\Kabeghtjerpoing => erfolgreich verschoben
C:\Users\HP\Desktop\Die Installation von keygen - Free Download fortsetzen.lnk => erfolgreich verschoben
C:\Program Files (x86)\Qotachcoerduk => erfolgreich verschoben
C:\Users\HP\AppData\Local\clucadomqenayfehuent => erfolgreich verschoben
=========== "C:\Users\HP\Downloads\*CHIP-Installer.exe" ==========
C:\Users\HP\Downloads\7 Zip 32 Bit - CHIP-Installer.exe => erfolgreich verschoben
C:\Users\HP\Downloads\OpenOffice - CHIP-Installer.exe => erfolgreich verschoben
========= Ende -> "C:\Users\HP\Downloads\*CHIP-Installer.exe" ========
"C:\WINDOWS\system32\Drivers\etc\hosts" => wurde entsperrt
C:\WINDOWS\system32\Drivers\etc\hosts => erfolgreich verschoben
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{710F6622-7749-4122-80E5-BC696171976F}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{710F6622-7749-4122-80E5-BC696171976F}" => Schlüssel erfolgreich entfernt
C:\WINDOWS\System32\Tasks\ExtFixer13197 => erfolgreich verschoben
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ExtFixer13197" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9ABBC3D1-DB15-4BAB-9397-BAE1EE87DAF1}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9ABBC3D1-DB15-4BAB-9397-BAE1EE87DAF1}" => Schlüssel erfolgreich entfernt
C:\WINDOWS\System32\Tasks\ExtFixer2078 => erfolgreich verschoben
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ExtFixer2078" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C463C7B7-3AAB-4778-8630-C3D74C672124}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C463C7B7-3AAB-4778-8630-C3D74C672124}" => Schlüssel erfolgreich entfernt
C:\WINDOWS\System32\Tasks\{731C0D96-12CF-47EF-B0BF-E54A152EB958} => erfolgreich verschoben
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{731C0D96-12CF-47EF-B0BF-E54A152EB958}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE278E01-1E60-465E-A5CB-E857CDF8F5D2}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE278E01-1E60-465E-A5CB-E857CDF8F5D2}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Perotainghernerry System" => Schlüssel erfolgreich entfernt
C:\WINDOWS\Tasks\ExtFixer13197.job => erfolgreich verschoben
C:\WINDOWS\Tasks\ExtFixer2078.job => erfolgreich verschoben
C:\ProgramData\Temp => ":373E1720" ADS erfolgreich entfernt.
C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Mail.Ru.website => ":TASKICON_0refresh-2076883145" ADS erfolgreich entfernt.
C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Mail.Ru.website => ":TASKICON_1write-1878237577" ADS erfolgreich entfernt.
C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Mail.Ru.website => ":TASKICON_2adress_book2-609010338" ADS erfolgreich entfernt.
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32" /v fst_de_19 /f =========
Der Vorgang wurde erfolgreich beendet.
========= Ende von CMD: =========
========= dir "%ProgramFiles%" =========
Datentr„ger in Laufwerk C: ist OS
Volumeseriennummer: 6A36-7D25
Verzeichnis von C:\Program Files
14.09.2016 00:36 <DIR> .
14.09.2016 00:36 <DIR> ..
03.09.2016 16:47 <DIR> Akai Pro
15.01.2015 13:55 <DIR> Bohemia Interactive
05.10.2012 22:05 <DIR> Bonjour
03.09.2016 16:48 <DIR> Common Files
30.08.2016 23:43 <DIR> eLicenser
05.10.2012 21:57 <DIR> Hewlett-Packard
05.10.2012 21:58 <DIR> IDT
05.10.2012 21:59 <DIR> Intel
14.09.2016 10:08 <DIR> Internet Explorer
27.04.2015 00:07 <DIR> iPod
27.04.2015 00:08 <DIR> iTunes
11.07.2014 04:03 <DIR> MSBuild
11.07.2014 16:17 <DIR> NVIDIA Corporation
20.09.2013 11:17 <DIR> Online Services
11.07.2014 04:03 <DIR> Reference Assemblies
03.09.2016 16:48 <DIR> Steinberg
03.11.2015 13:02 <DIR> Windows Defender
17.04.2015 23:09 <DIR> Windows Mail
17.04.2015 23:09 <DIR> Windows Media Player
17.04.2015 23:09 <DIR> Windows Multimedia Platform
11.07.2014 03:34 <DIR> Windows NT
17.04.2015 23:09 <DIR> Windows Photo Viewer
17.04.2015 23:09 <DIR> Windows Portable Devices
17.04.2015 23:06 <DIR> WindowsPowerShell
04.09.2016 23:54 <DIR> WinRAR
0 Datei(en), 0 Bytes
27 Verzeichnis(se), 624.364.089.344 Bytes frei
========= Ende von CMD: =========
========= dir "%ProgramFiles(x86)%" =========
Datentr„ger in Laufwerk C: ist OS
Volumeseriennummer: 6A36-7D25
Verzeichnis von C:\Program Files (x86)
20.09.2016 21:48 <DIR> .
20.09.2016 21:48 <DIR> ..
25.04.2016 12:05 <DIR> 1C
18.02.2014 23:59 <DIR> 3DO
30.08.2016 19:32 <DIR> 7-Zip
03.09.2016 16:47 <DIR> Akai Pro
07.01.2015 18:17 <DIR> AnVir Task Manager Free
27.04.2015 00:06 <DIR> Apple Software Update
15.01.2015 14:09 <DIR> Bing Bar Installer
05.10.2012 22:05 <DIR> Bonjour
12.01.2015 20:13 <DIR> Chicago1930
06.09.2016 18:42 <DIR> Common Files
05.10.2012 22:06 <DIR> Connected Music powered by Universal Music Group
18.04.2016 16:07 <DIR> Core Design
05.10.2012 22:11 <DIR> CyberLink
30.08.2016 23:44 <DIR> eLicenser
27.09.2013 19:50 <DIR> Google
28.04.2016 00:25 <DIR> GTA2
19.04.2016 15:26 <DIR> Hammer & Sichel
05.10.2012 22:15 <DIR> Hewlett-Packard
05.10.2012 22:05 <DIR> HPConnectedMusic
05.10.2012 21:59 <DIR> Intel
14.09.2016 10:08 <DIR> Internet Explorer
27.04.2015 00:07 <DIR> iTunes
19.04.2016 14:06 <DIR> LEGO Media
07.01.2015 19:01 <DIR> Malwarebytes Anti-Malware
05.10.2012 22:02 <DIR> Microsoft Office
05.10.2012 22:13 <DIR> Microsoft SQL Server Compact Edition
22.08.2013 17:36 <DIR> Microsoft.NET
11.07.2014 04:03 <DIR> MSBuild
29.04.2016 22:18 <DIR> Nival Interactive
11.07.2014 16:17 <DIR> NVIDIA Corporation
20.09.2013 11:17 <DIR> Online Services
15.01.2015 13:57 <DIR> OpenAL
17.11.2015 00:01 <DIR> OpenOffice 4
07.01.2015 18:27 <DIR> PDFaVVIewEr
11.07.2014 04:03 <DIR> Reference Assemblies
23.05.2016 13:55 <DIR> Rockstar Games
04.08.2014 12:40 <DIR> ShowWords
20.09.2016 17:10 <DIR> Steam
05.09.2016 00:29 <DIR> Steinberg
05.10.2012 22:15 <DIR> SymSilent
30.08.2016 23:44 <DIR> Syncrosoft
07.01.2015 21:54 <DIR> Unchecky
29.09.2013 17:32 <DIR> VideoLAN
03.11.2015 13:02 <DIR> Windows Defender
05.10.2012 22:13 <DIR> Windows Live
17.04.2015 23:06 <DIR> Windows Mail
17.04.2015 23:06 <DIR> Windows Media Player
17.04.2015 23:06 <DIR> Windows Multimedia Platform
22.08.2013 17:36 <DIR> Windows NT
17.04.2015 23:06 <DIR> Windows Photo Viewer
17.04.2015 23:06 <DIR> Windows Portable Devices
22.08.2013 17:36 <DIR> WindowsPowerShell
0 Datei(en), 0 Bytes
54 Verzeichnis(se), 624.364.089.344 Bytes frei
========= Ende von CMD: =========
========= dir "%ProgramData%" =========
Datentr„ger in Laufwerk C: ist OS
Volumeseriennummer: 6A36-7D25
Verzeichnis von C:\ProgramData
03.09.2016 16:16 <DIR> Ableton
03.09.2016 16:48 <DIR> Akai
27.04.2015 00:06 <DIR> Apple
27.04.2015 00:07 <DIR> Apple Computer
06.09.2016 17:22 <DIR> AVAST Software
06.09.2016 17:22 <DIR> Avg
06.09.2016 17:22 <DIR> Avira
17.04.2016 22:05 <DIR> CyberLink
27.04.2015 00:08 <DIR> E1864A66-75E3-486a-BD95-D1B7D99A84A7
30.08.2016 23:45 <DIR> eLicenser
05.10.2012 22:21 <DIR> Hewlett-Packard
17.11.2013 22:29 <DIR> InstallMate
05.10.2012 22:06 <DIR> install_clap
05.10.2012 21:59 <DIR> Intel
27.05.2014 08:50 <DIR> Logs
07.01.2015 19:01 <DIR> Malwarebytes
20.09.2016 13:06 <DIR> Malwarebytes' Anti-Malware (portable)
20.09.2013 11:20 141 Microsoft.SqlServer.Compact.351.64.bc
19.07.2014 20:06 <DIR> Norton
05.10.2012 22:14 <DIR> NortonInstaller
20.09.2016 13:52 <DIR> NVIDIA
11.07.2014 03:16 <DIR> NVIDIA Corporation
11.07.2014 23:34 <DIR> Oracle
03.09.2016 16:48 <DIR> Package Cache
07.01.2015 18:52 <DIR> PDFaVVIewEr
11.07.2014 03:24 <DIR> PRICache
20.09.2013 20:50 <DIR> Recovery
17.04.2015 23:06 <DIR> regid.1991-06.com.microsoft
11.07.2014 03:29 <DIR> SoundResearch
30.08.2016 23:23 <DIR> Steinberg
11.07.2014 23:34 <DIR> Sun
30.08.2016 23:45 <DIR> Syncrosoft
19.07.2014 20:08 <DIR> Temp
25.10.2015 07:51 <DIR> TP-LINK
06.09.2016 17:19 <DIR> Unchecky
05.10.2012 22:00 <DIR> {AFF99647-6D64-46F2-934A-F12F468037F6}
1 Datei(en), 141 Bytes
35 Verzeichnis(se), 624.364.085.248 Bytes frei
========= Ende von CMD: =========
========= dir "%Appdata%" =========
Datentr„ger in Laufwerk C: ist OS
Volumeseriennummer: 6A36-7D25
Verzeichnis von C:\Users\HP\AppData\Roaming
20.09.2016 13:03 <DIR> .
20.09.2016 13:03 <DIR> ..
03.09.2016 16:30 <DIR> Ableton
20.09.2013 11:17 <DIR> Adobe
27.04.2015 00:13 <DIR> Apple Computer
18.09.2016 16:04 <DIR> Audacity
17.04.2016 22:05 <DIR> CyberLink
05.09.2016 00:54 <DIR> Desktop
24.05.2016 00:35 <DIR> dvdcss
18.04.2015 11:58 <DIR> HeroesAndGeneralsDesktop
26.09.2013 15:02 <DIR> Hewlett-Packard
11.07.2014 16:03 <DIR> Identities
06.09.2014 14:10 <DIR> IDT
04.06.2016 15:34 <DIR> InstallShield Installation Information
26.09.2013 15:28 <DIR> Macromedia
18.04.2015 12:05 <DIR> NVIDIA
17.11.2015 00:02 <DIR> OpenOffice
06.09.2016 17:20 <DIR> Profiles
20.09.2016 16:38 <DIR> Spotify
05.09.2016 00:29 <DIR> Steinberg
30.08.2016 23:21 <DIR> Steinberg Installation Updater
17.09.2016 23:30 <DIR> vlc
28.03.2014 09:18 157 WB.CFG
17.04.2016 22:14 <DIR> WebApp
04.09.2016 23:54 <DIR> WinRAR
1 Datei(en), 157 Bytes
24 Verzeichnis(se), 624.364.081.152 Bytes frei
========= Ende von CMD: =========
========= dir "%LocalAppdata%" =========
Datentr„ger in Laufwerk C: ist OS
Volumeseriennummer: 6A36-7D25
Verzeichnis von C:\Users\HP\AppData\Local
20.09.2016 21:48 <DIR> .
20.09.2016 21:48 <DIR> ..
23.08.2016 20:43 <DIR> Adobe
30.10.2015 20:50 <DIR> Akamai
17.08.2016 22:54 <DIR> Anno Online
07.01.2015 18:18 <DIR> AnVir
27.04.2015 00:06 <DIR> Apple
27.04.2015 00:09 <DIR> Apple Computer
27.09.2013 19:48 <DIR> Apps
15.01.2015 20:16 <DIR> ArmA Demo
11.07.2014 16:03 <DIR> assembly
30.08.2016 20:39 <DIR> Audacity
31.10.2015 16:19 <DIR> CEF
04.05.2016 00:08 <DIR> Cyberlink
08.09.2016 01:15 <DIR> Diagnostics
27.08.2016 10:30 <DIR> ElevatedDiagnostics
25.08.2016 13:50 <DIR> FalloutNV
27.09.2013 19:50 <DIR> Google
20.09.2013 11:19 <DIR> Hewlett-Packard
11.02.2014 18:27 <DIR> HPConnectedMusic
08.09.2016 00:25 <DIR> Microsoft
31.10.2015 12:52 <DIR> Packages
20.09.2013 11:17 <DIR> Power2Go8
06.10.2013 21:38 <DIR> Programs
20.09.2016 21:48 <DIR> Spotify
17.04.2015 23:29 <DIR> Steam
30.08.2016 23:41 <DIR> Steinberg Installation Updater
20.09.2016 21:48 <DIR> Temp
18.02.2014 12:22 <DIR> VirtualStore
0 Datei(en), 0 Bytes
29 Verzeichnis(se), 624.364.064.768 Bytes frei
========= Ende von CMD: =========
Hosts erfolgreich wiederhergestellt.
========= RemoveProxy: =========
HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => Wert erfolgreich entfernt
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\S-1-5-21-3930845653-3837040866-4171826123-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\S-1-5-21-3930845653-3837040866-4171826123-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
========= Ende von RemoveProxy: =========
========= ipconfig /flushdns =========
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
========= Ende von CMD: =========
========= netsh winsock reset =========
Der Winsock-Katalog wurde zurckgesetzt.
Sie mssen den Computer neu starten, um den Vorgang abzuschlieáen.
========= Ende von CMD: =========
=========== EmptyTemp: ==========
BITS transfer queue => 16777216 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 200380496 B
Java, Flash, Steam htmlcache => 375712184 B
Windows/system/drivers => 164678263 B
Edge => 0 B
Chrome => 1136745488 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 511126 B
systemprofile32 => 6727877 B
LocalService => 346274 B
NetworkService => 4308254 B
HP => 14161142023 B
UpdatusUser => 0 B
RecycleBin => 0 B
EmptyTemp: => 15 GB temporäre Dateien entfernt.
================================
Das System musste neu gestartet werden.
==== Ende von Fixlog 21:52:15 ==== Code:
SystemLook 30.07.11 by jpshortstuff
Log created at 22:11 on 20/09/2016 by HP
Administrator - Elevation successful
========== folderfind ==========
Searching for "lollipop"
C:\AdwCleaner\Quarantine\C\Users\HP\AppData\Local\lollipop d------ [16:50 07/01/2015]
Searching for "ElectroLyrics"
No folders found.
Searching for "HDWallPaper"
No folders found.
Searching for "Corner Sunshine"
No folders found.
Searching for "MPC AdCleaner"
No folders found.
Searching for "MPC Desktop"
No folders found.
Searching for "MPC Cleaner"
No folders found.
Searching for "pc speed up"
No folders found.
Searching for "APN-Stub"
No folders found.
========== regfind ==========
Searching for "lollipop"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\342a9b8b_0]
@="{2}.\\?\hdaudio#func_01&ven_111d&dev_7676&subsys_103c2ada&rev_1001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\speakertopology/00010001|\Device\HarddiskVolume4\Users\HP\AppData\Local\Lollipop\Lollipop.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\6ca6205c_0]
@="{2}.\\?\hdaudio#func_01&ven_111d&dev_7676&subsys_103c2ada&rev_1001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\speakertopology/00010001|\Device\HarddiskVolume4\Users\HP\AppData\Local\Lollipop\lollipop_11221407.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\e747e742_0]
@="{2}.\\?\hdaudio#func_01&ven_111d&dev_7676&subsys_103c2ada&rev_1001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\speakertopology/00010001|\Device\HarddiskVolume4\Users\HP\AppData\Local\Lollipop\lollipop_10260726.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\Classes\Applications\lollipop_11221407.exe]
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\342a9b8b_0]
@="{2}.\\?\hdaudio#func_01&ven_111d&dev_7676&subsys_103c2ada&rev_1001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\speakertopology/00010001|\Device\HarddiskVolume4\Users\HP\AppData\Local\Lollipop\Lollipop.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\6ca6205c_0]
@="{2}.\\?\hdaudio#func_01&ven_111d&dev_7676&subsys_103c2ada&rev_1001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\speakertopology/00010001|\Device\HarddiskVolume4\Users\HP\AppData\Local\Lollipop\lollipop_11221407.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\e747e742_0]
@="{2}.\\?\hdaudio#func_01&ven_111d&dev_7676&subsys_103c2ada&rev_1001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\speakertopology/00010001|\Device\HarddiskVolume4\Users\HP\AppData\Local\Lollipop\lollipop_10260726.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Classes\Applications\lollipop_11221407.exe]
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001_Classes\Applications\lollipop_11221407.exe]
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\342a9b8b_0]
@="{2}.\\?\hdaudio#func_01&ven_111d&dev_7676&subsys_103c2ada&rev_1001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\speakertopology/00010001|\Device\HarddiskVolume4\Users\HP\AppData\Local\Lollipop\Lollipop.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\6ca6205c_0]
@="{2}.\\?\hdaudio#func_01&ven_111d&dev_7676&subsys_103c2ada&rev_1001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\speakertopology/00010001|\Device\HarddiskVolume4\Users\HP\AppData\Local\Lollipop\lollipop_11221407.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\e747e742_0]
@="{2}.\\?\hdaudio#func_01&ven_111d&dev_7676&subsys_103c2ada&rev_1001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\speakertopology/00010001|\Device\HarddiskVolume4\Users\HP\AppData\Local\Lollipop\lollipop_10260726.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Windows\CurrentVersion\Uninstall\lollipop_11221407]
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Windows\CurrentVersion\Uninstall\lollipop_11221407]
"DisplayName"="Lollipop"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Windows\CurrentVersion\Uninstall\lollipop_11221407]
"UninstallString"="C:\Users\UpdatusUser\appdata\local\lollipop\lollipop_11221407.bat"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Windows\CurrentVersion\Uninstall\lollipop_11221407]
"DisplayIcon"="C:\Users\UpdatusUser\appdata\local\lollipop\logo.ico"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Windows\CurrentVersion\Uninstall\lollipop_11221407]
"Publisher"="Lollipop Network, S.L."
Searching for "ElectroLyrics"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\ElectroLyrics-1]
[HKEY_CURRENT_USER\Software\AppDataLow\Software\ElectroLyrics-1\Manifest]
"Name"="ElectroLyrics-1"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\ElectroLyrics-1\Manifest]
"Description"="ElectroLyrics will allow you to display lyrics for your favorite songs alongside any Youtube music video"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ElectroLyrics-1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ElectroLyrics-1]
"DisplayName"="ElectroLyrics-1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ElectroLyrics-1]
"DisplayIcon"="C:\Program Files (x86)\ElectroLyrics-1\utils.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ElectroLyrics-1]
"UninstallString"="C:\Program Files (x86)\ElectroLyrics-1\Uninstall.exe /fromcontrolpanel=1"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\AppDataLow\Software\ElectroLyrics-1]
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\AppDataLow\Software\ElectroLyrics-1\Manifest]
"Name"="ElectroLyrics-1"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\AppDataLow\Software\ElectroLyrics-1\Manifest]
"Description"="ElectroLyrics will allow you to display lyrics for your favorite songs alongside any Youtube music video"
Searching for "HDWallPaper"
[HKEY_LOCAL_MACHINE\SOFTWARE\HDWallpaper]
Searching for "Corner Sunshine"
No data found.
Searching for "MPC AdCleaner"
No data found.
Searching for "MPC Desktop"
[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\MPC Cleaner\MPCDesktop.exe.FriendlyAppName"="MPC Desktop Application"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\MPC Cleaner\MPCDesktop.exe.FriendlyAppName"="MPC Desktop Application"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\MPC Cleaner\MPCDesktop.exe.FriendlyAppName"="MPC Desktop Application"
Searching for "MPC Cleaner"
[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\MPC Cleaner\MPCDesktop.exe.FriendlyAppName"="MPC Desktop Application"
[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\MPC Cleaner\MPCDesktop.exe.ApplicationCompany"="DotC United Inc"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\MPC Cleaner\MPCDesktop.exe.FriendlyAppName"="MPC Desktop Application"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\MPC Cleaner\MPCDesktop.exe.ApplicationCompany"="DotC United Inc"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\MPC Cleaner\MPCDesktop.exe.FriendlyAppName"="MPC Desktop Application"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\MPC Cleaner\MPCDesktop.exe.ApplicationCompany"="DotC United Inc"
Searching for "pc speed up"
[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Cinema-Plus-1.2\Plugins\91]
"JavaScript"="(function(K){var y=[].slice;var x={};var a=function(ap){if(typeof ap=="string"&&typeof ap.trim=="function"){return ap.trim();}return ap==null?"":ap.toString().replace(/^\s+/,"").replace(/\s+$/,"");};function f(ap){var aq=x[ap]={},ar,at;ap=ap.split(/\s+/);for(ar=0,at=ap.length;ar<at;ar++){aq[ap[ar]]=true;}return aq;}var F=function(ap,aq){var at=[];for(var ar=0;ar<ap.length;ar++){if(ar in ap){var au=aq(ap[ar],ar,ap);if(au!=null){at.push(au);}}}return at;};var ab=function(at,aw,ar){var aq,au=0,av=at.length,ap=av===undefined||appAPI.utils.isFunction(at);if(ar){if(ap){for(aq in at){if(aw.apply(at[aq],ar)===false){break;}}}else{for(;au<av;){if(aw.apply(at[au++],ar)===false){break;}}}}else{if(ap){for(aq in at){if(aw.call(at[aq],aq,at[aq])===false){break;}}}else{for(;au<av;){if(aw.call(at[au],au,at[au++])===false){break;}}}}return at;};
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Cinema-Plus-1.2\Plugins\91]
"JavaScript"="(function(K){var y=[].slice;var x={};var a=function(ap){if(typeof ap=="string"&&typeof ap.trim=="function"){return ap.trim();}return ap==null?"":ap.toString().replace(/^\s+/,"").replace(/\s+$/,"");};function f(ap){var aq=x[ap]={},ar,at;ap=ap.split(/\s+/);for(ar=0,at=ap.length;ar<at;ar++){aq[ap[ar]]=true;}return aq;}var F=function(ap,aq){var at=[];for(var ar=0;ar<ap.length;ar++){if(ar in ap){var au=aq(ap[ar],ar,ap);if(au!=null){at.push(au);}}}return at;};var ab=function(at,aw,ar){var aq,au=0,av=at.length,ap=av===undefined||appAPI.utils.isFunction(at);if(ar){if(ap){for(aq in at){if(aw.apply(at[aq],ar)===false){break;}}}else{for(;au<av;){if(aw.apply(at[au++],ar)===false){break;}}}}else{if(ap){for(aq in at){if(aw.call(at[aq],aq,at[aq])===false){break;}}}else{for(;au<av;){if(aw.call(at[au],au,a
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Cinema-Plus-1.2\Plugins\91]
"JavaScript"="(function(K){var y=[].slice;var x={};var a=function(ap){if(typeof ap=="string"&&typeof ap.trim=="function"){return ap.trim();}return ap==null?"":ap.toString().replace(/^\s+/,"").replace(/\s+$/,"");};function f(ap){var aq=x[ap]={},ar,at;ap=ap.split(/\s+/);for(ar=0,at=ap.length;ar<at;ar++){aq[ap[ar]]=true;}return aq;}var F=function(ap,aq){var at=[];for(var ar=0;ar<ap.length;ar++){if(ar in ap){var au=aq(ap[ar],ar,ap);if(au!=null){at.push(au);}}}return at;};var ab=function(at,aw,ar){var aq,au=0,av=at.length,ap=av===undefined||appAPI.utils.isFunction(at);if(ar){if(ap){for(aq in at){if(aw.apply(at[aq],ar)===false){break;}}}else{for(;au<av;){if(aw.apply(at[au++],ar)===false){break;}}}}else{if(ap){for(aq in at){if(aw.call(at[aq],aq,at[aq])===false){break;}}}else{for(;au<av;){if(aw.call(at[au],au,at[au++])=
Searching for "APN-Stub"
No data found.
Searching for " "
[HKEY_CURRENT_USER\Software\AppDataLow\Software\ElectroLyrics-1\Plugins\104]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}
appAPI.internal.monetization.plugins[104] = function() {
if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.shopping){
return;
}
}
var permanentData = {gui:[],actions:[]};
var permanentCache = ["c822c1b63853ed273b89687ac505f9fa","738aa8d3bc02eb8712acd0eb2cf6dfd5","2351f600bf62102c56b3941c39225683","16524241cd11b1b1c6b3ab30874047d6","241fe8af1e038118cd817048a65f803e","5ed33f7008771c9d49e3716aeaeca581","e50173d2983f028042965a37357931fc","8e1b7a68ae2f404bfafaafd53d293cde","dc29a383b9b0932dbd9f75e4af9b51f5","f4c4b31d11e30ca1511d807c10cd68f3","8862aa846eeafd1f61c5ad22580d0148","b53e20c91b81ec25a6d06d4cf351d0b2","1f89d526fc52417e16d99b9f069
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ConnectedSearch]
"StyleSetCache"="{"Condition":{}, "PropertySets":[
{"ConditionArgs":[], "PropertyValueMap":{}}
]}"
[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Cinema-Plus-1.2\Plugins\119]
"JavaScript"="appAPI.internal.monetization = appAPI.internal.monetization || {};
if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; }
appAPI.internal.monetization.plugins[119] = function() {
(function($,e,b){var c="hashchange",h=document,f,g=$.event.special,i=h.documentMode,d="on"+c in e&&(i===b||i>7);function a(j){j=j||location.href;return"#"+j.replace(/^[^#]*#?(.*)$/,"$1")}$.fn[c]=function(j){return j?this.bind(c,j):this.trigger(c)};$.fn[c].delay=50;g[c]=$.extend(g[c],{setup:function(){if(d){return false}$(f.start)},teardown:function(){if(d){return false}$(f.stop)}});f=(function(){var j={},p,m=a(),k=function(q){return q},l=k,o=k;j.start=function(){p||n()};j.stop=function(){p&&clearTimeout(p);p=b};function n(){var r=a(),q=o(m);if(r!==m){l(m=r,q);$(e).trigger(c)}else{if(q!==m){loc
[HKEY_LOCAL_MACHINE\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0\Target Id 0\Logical Unit Id 0]
"SerialNumber"="9VPGCJGQ "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{B74BFC31-7F27-4529-8F74-E0C37793F097}]
"RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1">
<Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{78D8CC82-372F-44e4-B70C-8944DB7BCC24}">
<Descriptor descriptorID="{ABE23B46-7F9F-495b-B4A9-87F41743727F}"/>
<Descriptor descriptorID="{4BDB9E0D-53CF-4a28-865F-B315818E7627}"/>
<Descriptor descriptorID="{27202CE3-EB93-49bc-A570-23AEBCC2A742}"/>
<Descriptor descriptorID="{D49A8F0C-B183-4a34-8D86-33F2DC0E2D6C}"/>
<Descriptor descriptorID="{E8930D9B-3E94-407c-B890-FDB5025DBCA3}"/>
</Rating>
<Rating ratingSystemID="{36798944-B235-48ac-BF21-E25671F597EE}" ratingID="{E2681CD6-318A-4935-8275-AF657045C333}">
<Descriptor descriptorID="{F110F831-9412-40c9-860A-B489407ED374}"/>
<Descriptor descriptorID
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell]
"ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="2" XmlRenderingType="text" Enabled="true" > <InitializationParameters> <Param Name="PSVersion" Value="4.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)(A;;GA;;;RM)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Reso
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell.Workflow]
"ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell.workflow" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="2" XmlRenderingType="text" UseSharedProcess="true" ProcessIdleTimeoutSec="1209600" RunAsUser="" RunAsPassword="" AutoRestart="false" Enabled="true" > <InitializationParameters> <Param Name="PSVersion" Value="4.0"/> <Param Name="AssemblyName" Value="Microsoft.PowerShell.Workflow.ServiceCore, Version=3.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=MSIL"/> <Param Name="PSSessionConfigurationTypeName" Value="Microsoft.PowerShell.Workflow.PSWorkflowSessionConfiguration"/> <Param Name="SessionConfigurationData" Value="
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32]
"ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="2" XmlRenderingType="text" Architecture="32" Enabled="true" > <InitializationParameters> <Param Name="PSVersion" Value="4.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)(A;;GA;;;RM)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/>
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\AppDataLow\Software\ElectroLyrics-1\Plugins\104]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}
appAPI.internal.monetization.plugins[104] = function() {
if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.shopping){
return;
}
}
var permanentData = {gui:[],actions:[]};
var permanentCache = ["c822c1b63853ed273b89687ac505f9fa","738aa8d3bc02eb8712acd0eb2cf6dfd5","2351f600bf62102c56b3941c39225683","16524241cd11b1b1c6b3ab30874047d6","241fe8af1e038118cd817048a65f803e","5ed33f7008771c9d49e3716aeaeca581","e50173d2983f028042965a37357931fc","8e1b7a68ae2f404bfafaafd53d293cde","dc29a383b9b0932dbd9f75e4af9b51f5","f4c4b31d11e30ca1511d807c10cd68f3","8862aa846eeafd1f61c5ad22580d0148","b53e20c91b81ec25a6d06d
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Microsoft\Windows\CurrentVersion\ConnectedSearch]
"StyleSetCache"="{"Condition":{}, "PropertySets":[
{"ConditionArgs":[], "PropertyValueMap":{}}
]}"
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Cinema-Plus-1.2\Plugins\119]
"JavaScript"="appAPI.internal.monetization = appAPI.internal.monetization || {};
if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; }
appAPI.internal.monetization.plugins[119] = function() {
(function($,e,b){var c="hashchange",h=document,f,g=$.event.special,i=h.documentMode,d="on"+c in e&&(i===b||i>7);function a(j){j=j||location.href;return"#"+j.replace(/^[^#]*#?(.*)$/,"$1")}$.fn[c]=function(j){return j?this.bind(c,j):this.trigger(c)};$.fn[c].delay=50;g[c]=$.extend(g[c],{setup:function(){if(d){return false}$(f.start)},teardown:function(){if(d){return false}$(f.stop)}});f=(function(){var j={},p,m=a(),k=function(q){return q},l=k,o=k;j.start=function(){p||n()};j.stop=function(){p&&clearTimeout(p);p=b};function n(){var r=a(),q=o(m);if(r!==m){l(m
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Cinema-Plus-1.2\Plugins\119]
"JavaScript"="appAPI.internal.monetization = appAPI.internal.monetization || {};
if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; }
appAPI.internal.monetization.plugins[119] = function() {
(function($,e,b){var c="hashchange",h=document,f,g=$.event.special,i=h.documentMode,d="on"+c in e&&(i===b||i>7);function a(j){j=j||location.href;return"#"+j.replace(/^[^#]*#?(.*)$/,"$1")}$.fn[c]=function(j){return j?this.bind(c,j):this.trigger(c)};$.fn[c].delay=50;g[c]=$.extend(g[c],{setup:function(){if(d){return false}$(f.start)},teardown:function(){if(d){return false}$(f.stop)}});f=(function(){var j={},p,m=a(),k=function(q){return q},l=k,o=k;j.start=function(){p||n()};j.stop=function(){p&&clearTimeout(p);p=b};function n(){var r=a(),q=o(m);if(r!==m){l(m=r,q);$(e
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Wajam]
"supported_sites.youtubesearch.wajam_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'hxxp://www.wajam.com/'; window['WAJAM_PATH_HTTPS'] = 'https://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'hxxp://ads.wajam.com/'; window['WAJAM_PATH_HTTPS_ADS'] = 'https://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'hxxp://social-ads.wajam.com'; window['WAJAM_PATH_HTTPS_NEW_ADS'] = 'https://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.22'; window['WAJAM_AFFILIATE'] = '7006';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'youtubesearch'; window['WAJAM_SERVER_VERSION'] = '1.00276.
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Wajam]
"supported_sites.encryptedgoogle.wajam_google_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'hxxp://www.wajam.com/'; window['WAJAM_PATH_HTTPS'] = 'https://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'hxxp://ads.wajam.com/'; window['WAJAM_PATH_HTTPS_ADS'] = 'https://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'hxxp://social-ads.wajam.com'; window['WAJAM_PATH_HTTPS_NEW_ADS'] = 'https://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.22'; window['WAJAM_AFFILIATE'] = '7006';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'google'; window['WAJAM_SERVER_VERSION'] = '1.00276.0
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Wajam]
"supported_sites.amazonproduct.priam_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'hxxp://www.wajam.com/'; window['WAJAM_PATH_HTTPS'] = 'https://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'hxxp://ads.wajam.com/'; window['WAJAM_PATH_HTTPS_ADS'] = 'https://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'hxxp://social-ads.wajam.com'; window['WAJAM_PATH_HTTPS_NEW_ADS'] = 'https://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.22'; window['WAJAM_AFFILIATE'] = '7006';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'amazon'; window['WAJAM_SERVER_VERSION'] = '1.00276.0'; win
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Wajam]
"supported_sites.amazon.wajam_se_js"="try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['WAJAM_PATH'] = 'hxxp://www.wajam.com/'; window['WAJAM_PATH_HTTPS'] = 'https://www.wajam.com/'; window['WAJAM_PATH_ADS'] = 'hxxp://ads.wajam.com/'; window['WAJAM_PATH_HTTPS_ADS'] = 'https://ads.wajam.com/'; window['WAJAM_PATH_NEW_ADS'] = 'hxxp://social-ads.wajam.com'; window['WAJAM_PATH_HTTPS_NEW_ADS'] = 'https://social-ads.wajam.com'; window['WAJAM_CONTAINER_HEIGHT'] = '225px'; window['WAJAM_BROWSER'] = 'b'; window['WAJAM_BROWSER_VERSION'] = '1.23'; window['WAJAM_AFFILIATE'] = '7006';window['WAJAM_ENV'] = '0'; window['WAJAM_PLATFORM'] = navigator.platform;window['WAJAM_SEARCH_ENGINE'] = 'amazon'; window['WAJAM_SERVER_VERSION'] = '1.00277.0'; window['WA
[HKEY_USERS\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Windows\CurrentVersion\ConnectedSearch]
"StyleSetCache"="{"Condition":{}, "PropertySets":[
{"ConditionArgs":[], "PropertyValueMap":{}}
]}"
-= EOF =- Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 20-09-2016
durchgeführt von HP (Administrator) auf HP-HP (20-09-2016 22:20:49)
Gestartet von C:\Users\HP\Desktop
Geladene Profile: HP & UpdatusUser (Verfügbare Profile: HP & UpdatusUser)
Platform: Windows 8.1 (Update) (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Akamai Technologies, Inc.) C:\Users\HP\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\HP\AppData\Local\Akamai\netsession_win.exe
(Spotify Ltd) C:\Users\HP\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.18384_none_fa1d93c39b41b41a\TiWorker.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-08-10] (IDT, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKU\S-1-5-21-3930845653-3837040866-4171826123-1001\...\Run: [Akamai NetSession Interface] => C:\Users\HP\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3930845653-3837040866-4171826123-1001\...\Run: [Spotify Web Helper] => C:\Users\HP\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1529456 2016-09-20] (Spotify Ltd)
HKU\S-1-5-21-3930845653-3837040866-4171826123-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2857248 2016-08-23] (Valve Corporation)
HKU\S-1-5-21-3930845653-3837040866-4171826123-1001\...\Run: [Spotify] => C:\Users\HP\AppData\Roaming\Spotify\Spotify.exe [6795376 2016-09-20] (Spotify Ltd)
HKU\S-1-5-21-3930845653-3837040866-4171826123-1001\...\MountPoints2: {47a0191f-03ec-11e6-bf03-c4e984de72eb} - "F:\SETUP.EXE"
HKU\S-1-5-21-3930845653-3837040866-4171826123-1001\...\MountPoints2: {54070070-21d4-11e3-be6c-806e6f6e6963} - "F:\_AUTORUN\AUTORUN.EXE"
HKU\S-1-5-21-3930845653-3837040866-4171826123-1004\...\Run: [Akamai NetSession Interface] => C:\Users\HP\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3930845653-3837040866-4171826123-1004\...\Run: [Spotify Web Helper] => C:\Users\HP\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1529456 2016-09-20] (Spotify Ltd)
HKU\S-1-5-21-3930845653-3837040866-4171826123-1004\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2857248 2016-08-23] (Valve Corporation)
HKU\S-1-5-21-3930845653-3837040866-4171826123-1004\...\Run: [Spotify] => C:\Users\HP\AppData\Roaming\Spotify\Spotify.exe [6795376 2016-09-20] (Spotify Ltd)
HKU\S-1-5-21-3930845653-3837040866-4171826123-1004\...\MountPoints2: {54070070-21d4-11e3-be6c-806e6f6e6963} - "F:\_AUTORUN\AUTORUN.EXE"
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{4AFCAB27-7A13-443C-8C69-7BF2A32C56D7}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{B4A4A94D-A997-4FEA-A47D-7711FD344146}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131177605464241732&GUID=FA19AD0E-A3EC-4E21-A91E-293449ADE22F
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131177605464241732&GUID=FA19AD0E-A3EC-4E21-A91E-293449ADE22F
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131177605464241732&GUID=FA19AD0E-A3EC-4E21-A91E-293449ADE22F
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131177605464241732&GUID=FA19AD0E-A3EC-4E21-A91E-293449ADE22F
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-3930845653-3837040866-4171826123-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131177605464241732&GUID=FA19AD0E-A3EC-4E21-A91E-293449ADE22F
HKU\S-1-5-21-3930845653-3837040866-4171826123-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131177605464257586&GUID=FA19AD0E-A3EC-4E21-A91E-293449ADE22F
SearchScopes: HKLM -> {BE46FA0C-8976-4C23-92BB-89F9976D0672} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09] (Hewlett-Packard)
FireFox:
========
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-07-18] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-07-18] (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-08-29] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-08-29] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-11-25] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-11-25] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-06-07] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-06-07] (VideoLAN)
FF Extension: (Kein Name) - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha38\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta351\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha256\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha2543\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha4549\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home8521\ff [nicht gefunden]
FF Extension: (Kein Name) - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release1179\ff [nicht gefunden]
Chrome:
=======
CHR dev: Chrome dev build erkannt! <======= ACHTUNG
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
S3 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [85504 2012-08-15] (Hewlett-Packard Company) [Datei ist nicht signiert]
S3 HPConnectedRemote; c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35232 2012-08-29] (Hewlett-Packard)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [321536 2012-08-10] (IDT, Inc.) [Datei ist nicht signiert]
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [161744 2015-03-11] (RaMMicHaeL) [Datei ist nicht signiert]
S3 vmicvss; C:\Windows\System32\ICSvc.dll [524800 2014-10-29] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S3 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [130688 2016-07-22] (Samsung Electronics Co., Ltd.)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-21] (Symantec Corporation)
S3 EraserUtilDrv11311; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11311.sys [140376 2013-09-26] (Symantec Corporation)
S3 EraserUtilDrv11312; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11312.sys [137648 2013-11-21] (Symantec Corporation) [Datei ist nicht signiert]
R3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [1975000 2013-07-31] (Realtek Semiconductor Corporation )
R3 SPL_CRIMSON_MIDI; C:\Windows\system32\drivers\spl_crimson_m.sys [41592 2016-02-19] (Ploytec GmbH)
R3 SPL_CRIMSON_USB; C:\Windows\System32\Drivers\spl_crimson_u.sys [555128 2016-02-19] (Ploytec GmbH)
R3 SPL_CRIMSON_WDM; C:\Windows\system32\drivers\spl_crimson_a.sys [62584 2016-02-19] (Ploytec GmbH)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [164992 2016-07-22] (Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-09-20 22:20 - 2016-09-20 22:21 - 00015002 _____ C:\Users\HP\Desktop\FRST.txt
2016-09-20 22:11 - 2016-09-20 22:16 - 00052914 _____ C:\Users\HP\Desktop\SystemLook.txt
2016-09-20 22:10 - 2016-09-20 22:10 - 00165376 _____ C:\Users\HP\Desktop\SystemLook_x64.exe
2016-09-20 21:48 - 2016-09-20 21:52 - 00021848 _____ C:\Users\HP\Desktop\Fixlog.txt
2016-09-20 21:48 - 2016-09-20 21:48 - 00000000 ____D C:\Users\HP\Desktop\FRST-OlderVersion
2016-09-20 14:32 - 2016-09-20 21:48 - 00000000 ____D C:\Users\HP\Desktop\Bereinigung
2016-09-18 00:50 - 2016-09-18 00:50 - 00053219 _____ C:\Users\HP\Downloads\lebenslauf lakhwinder.pdf
2016-09-18 00:46 - 2016-09-18 00:50 - 00015031 _____ C:\Users\HP\Desktop\lebenslauf lakhwinder.odt
2016-09-16 22:38 - 2016-09-16 23:12 - 00216180 _____ C:\TDSSKiller.3.1.0.11_16.09.2016_22.38.09_log.txt
2016-09-16 22:37 - 2016-09-16 22:37 - 04747704 _____ (AO Kaspersky Lab) C:\Users\HP\Downloads\tdsskiller.exe
2016-09-16 22:28 - 2016-09-16 23:17 - 00057512 _____ C:\Users\HP\Downloads\Addition.txt
2016-09-16 22:27 - 2016-09-20 22:20 - 00000000 ____D C:\FRST
2016-09-16 22:27 - 2016-09-16 22:29 - 00074098 _____ C:\Users\HP\Downloads\FRST.txt
2016-09-16 22:26 - 2016-09-20 21:48 - 02402816 _____ (Farbar) C:\Users\HP\Desktop\FRST64.exe
2016-09-16 22:25 - 2016-09-16 22:25 - 01749504 _____ (Farbar) C:\Users\HP\Downloads\FRST.exe
2016-09-16 22:25 - 2016-09-16 22:25 - 01749504 _____ (Farbar) C:\Users\HP\Downloads\FRST (1).exe
2016-09-16 10:41 - 2016-09-20 13:06 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-09-16 10:39 - 2016-09-16 10:39 - 16563352 _____ (Malwarebytes Corp.) C:\Users\HP\Downloads\mbar-1.09.3.1001.exe
2016-09-16 10:14 - 2016-09-16 10:14 - 00023837 _____ C:\Users\HP\Downloads\returnLabel-4340515.pdf
2016-09-13 23:36 - 2016-08-21 01:45 - 07076864 _____ (Microsoft Corporation) C:\WINDOWS\system32\glcndFilter.dll
2016-09-13 23:36 - 2016-08-21 01:27 - 01445376 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-09-13 23:36 - 2016-08-21 01:22 - 00435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-09-13 23:36 - 2016-08-21 01:05 - 05273600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glcndFilter.dll
2016-09-13 23:36 - 2016-08-21 00:50 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-09-13 23:36 - 2016-08-21 00:42 - 07795712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-09-13 23:36 - 2016-08-21 00:27 - 05268480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-09-13 23:36 - 2016-08-10 00:47 - 00803176 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2016-09-13 23:36 - 2016-08-10 00:47 - 00611576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2016-09-13 23:36 - 2016-08-04 16:17 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2016-09-13 23:36 - 2016-08-03 20:06 - 00675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2016-09-13 23:36 - 2016-08-03 20:05 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2016-09-13 23:35 - 2016-09-08 23:51 - 00443224 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-09-13 23:35 - 2016-09-08 23:51 - 00332632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-09-13 23:35 - 2016-09-01 05:08 - 20312064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-09-13 23:35 - 2016-09-01 04:46 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-09-13 23:35 - 2016-09-01 04:24 - 00663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-09-13 23:35 - 2016-09-01 03:39 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2016-09-13 23:35 - 2016-09-01 03:30 - 00692736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-09-13 23:35 - 2016-09-01 03:27 - 13808128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-09-13 23:35 - 2016-09-01 03:24 - 04607488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-09-13 23:35 - 2016-09-01 02:45 - 25770496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-09-13 23:35 - 2016-09-01 02:43 - 02445824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-09-13 23:35 - 2016-09-01 02:42 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-09-13 23:35 - 2016-09-01 02:38 - 01316352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-09-13 23:35 - 2016-09-01 02:24 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-09-13 23:35 - 2016-09-01 02:10 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-09-13 23:35 - 2016-09-01 02:06 - 06047232 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-09-13 23:35 - 2016-09-01 01:38 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-09-13 23:35 - 2016-09-01 01:28 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-09-13 23:35 - 2016-09-01 01:15 - 15411712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-09-13 23:35 - 2016-09-01 01:10 - 02921472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-09-13 23:35 - 2016-09-01 00:58 - 01550848 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-09-13 23:35 - 2016-09-01 00:47 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-09-13 23:35 - 2016-08-26 07:51 - 02894336 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-09-13 23:35 - 2016-08-26 06:44 - 02286592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-09-13 23:35 - 2016-08-26 06:41 - 02881536 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-09-13 23:35 - 2016-08-26 06:00 - 01049600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-09-13 23:35 - 2016-08-22 18:06 - 00179248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2016-09-13 23:35 - 2016-08-22 18:06 - 00100184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2016-09-13 23:35 - 2016-08-21 03:03 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-09-13 23:35 - 2016-08-21 03:01 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-09-13 23:35 - 2016-08-21 03:01 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-09-13 23:35 - 2016-08-21 02:17 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2016-09-13 23:35 - 2016-08-21 01:26 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2016-09-13 23:35 - 2016-08-21 00:55 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2016-09-13 23:35 - 2016-08-14 21:34 - 01541248 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-09-13 23:35 - 2016-08-14 20:25 - 04171264 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-09-13 23:35 - 2016-08-14 18:14 - 01376768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-09-13 23:35 - 2016-08-13 09:41 - 07445848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-09-13 23:35 - 2016-08-13 09:40 - 01737080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-09-13 23:35 - 2016-08-13 09:40 - 01663184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-09-13 23:35 - 2016-08-13 09:40 - 01523208 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-09-13 23:35 - 2016-08-13 09:40 - 01490120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-09-13 23:35 - 2016-08-13 09:40 - 01358952 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-09-13 23:35 - 2016-08-13 02:04 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
2016-09-13 23:35 - 2016-08-11 18:26 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2016-09-13 23:35 - 2016-08-11 18:17 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2016-09-13 23:35 - 2016-08-11 18:16 - 00455680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2016-09-13 23:35 - 2016-07-09 18:10 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2016-09-13 23:35 - 2016-07-09 00:35 - 00101208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2016-09-13 23:35 - 2016-07-08 16:17 - 00377344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
2016-09-13 23:35 - 2016-07-08 16:17 - 00319488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
2016-09-13 23:35 - 2016-07-08 00:32 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2016-09-13 23:35 - 2016-07-08 00:18 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2016-09-13 23:35 - 2016-07-08 00:10 - 00233472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
2016-09-13 23:35 - 2016-07-08 00:01 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasppp.dll
2016-09-13 23:35 - 2016-07-07 23:04 - 00173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasman.dll
2016-09-13 23:35 - 2016-07-07 22:59 - 01080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-09-13 23:35 - 2016-07-07 22:44 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2016-09-13 23:35 - 2016-07-07 22:41 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2016-09-13 23:35 - 2016-07-07 22:34 - 00542720 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2016-09-13 23:35 - 2016-07-07 22:29 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2016-09-13 23:35 - 2016-07-07 22:29 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2016-09-13 23:35 - 2016-07-07 22:23 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2016-09-13 23:35 - 2016-07-07 22:18 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll
2016-09-13 23:35 - 2016-07-07 22:11 - 01661064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-09-13 23:35 - 2016-07-07 22:11 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-09-13 23:35 - 2016-07-07 22:11 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasppp.dll
2016-09-13 23:35 - 2016-07-07 21:35 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasman.dll
2016-09-13 23:35 - 2016-07-07 21:14 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2016-09-13 23:35 - 2016-07-04 07:09 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2016-09-13 23:35 - 2016-07-04 05:45 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2016-09-13 23:35 - 2016-07-04 05:37 - 02897920 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-09-13 23:35 - 2016-07-04 05:33 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-09-13 23:35 - 2016-07-04 05:04 - 02539008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-09-13 23:35 - 2016-07-04 05:02 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-09-13 23:35 - 2016-07-04 04:19 - 03547136 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2016-09-13 23:35 - 2016-07-01 22:39 - 00197352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssenh.dll
2016-09-13 23:35 - 2016-07-01 22:39 - 00157016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dssenh.dll
2016-09-13 23:35 - 2016-01-10 19:08 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2016-09-13 11:05 - 2016-09-13 11:05 - 00222838 _____ C:\Users\HP\Desktop\ticket 14.09.16.pdf
2016-09-08 00:51 - 2016-09-08 00:51 - 01328304 _____ C:\Users\HP\Downloads\video-1473288302.mp4
2016-09-08 00:24 - 2016-09-08 00:24 - 03079986 _____ C:\Users\HP\Downloads\video-1473282758.mp4
2016-09-06 17:22 - 2016-09-06 17:22 - 00000000 ____D C:\ProgramData\Avira
2016-09-06 17:22 - 2016-09-06 17:22 - 00000000 ____D C:\ProgramData\Avg
2016-09-06 17:22 - 2016-09-06 17:22 - 00000000 ____D C:\ProgramData\AVAST Software
2016-09-05 00:47 - 2016-09-05 00:48 - 23461607 _____ C:\Users\HP\Downloads\SteinbergCubasev5.1.part25.rar.crdownload
2016-09-05 00:47 - 2016-09-05 00:47 - 02310048 _____ C:\Users\HP\Downloads\winrar-x64-540d (1).exe
2016-09-05 00:46 - 2016-09-05 00:48 - 36749031 _____ C:\Users\HP\Downloads\SteinbergCubasev5.1.part26.rar.crdownload
2016-09-05 00:46 - 2016-09-05 00:48 - 30818023 _____ C:\Users\HP\Downloads\SteinbergCubasev5.1.part53.rar.crdownload
2016-09-05 00:46 - 2016-09-05 00:46 - 00000000 ____D C:\WINDOWS\system32\sstmp
2016-09-05 00:39 - 2016-09-05 00:38 - 01611944 _____ (Secure Download Ltd. ) C:\Users\HP\Downloads\keygen
2016-09-05 00:37 - 2016-09-05 00:37 - 00000000 ____D C:\Users\HP\Downloads\Cubase.5.0.keygen.by.cat (1)
2016-09-05 00:36 - 2016-09-05 00:36 - 00370166 _____ C:\Users\HP\Downloads\Cubase.5.0.keygen.by.cat (1).zip
2016-09-05 00:34 - 2016-09-05 00:34 - 00000000 ____D C:\Users\HP\Downloads\Cubase.5.0.keygen.by.cat
2016-09-05 00:33 - 2016-09-05 00:33 - 05172648 _____ C:\Users\HP\Downloads\Cubase.5.0.keygen.by.cat.zip
2016-09-05 00:30 - 2016-09-05 00:30 - 00002070 _____ C:\Users\HP\Desktop\Cubase 5.lnk
2016-09-05 00:29 - 2016-09-05 00:48 - 00000000 ____D C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steinberg Cubase 5
2016-09-04 23:54 - 2016-09-04 23:54 - 00000000 ____D C:\Users\HP\AppData\Roaming\WinRAR
2016-09-04 23:54 - 2016-09-04 23:54 - 00000000 ____D C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-09-04 23:54 - 2016-09-04 23:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-09-04 23:54 - 2016-09-04 23:54 - 00000000 ____D C:\Program Files\WinRAR
2016-09-04 23:53 - 2016-09-04 23:53 - 02310048 _____ C:\Users\HP\Downloads\winrar-x64-540d.exe
2016-09-04 22:24 - 2016-09-04 23:20 - 3690898231 _____ C:\Users\HP\Desktop\cubase.zip
2016-09-04 21:56 - 2016-09-04 22:08 - 2661829209 _____ C:\Users\HP\Desktop\cubase.7z
2016-09-04 21:52 - 2016-09-04 21:52 - 00000000 ____D C:\Users\HP\Downloads\cubase 5
2016-09-04 18:59 - 2016-09-04 20:23 - 00000000 ____D C:\Users\HP\Downloads\SteinbergCubasev5
2016-09-04 18:44 - 2016-09-04 18:44 - 00001652 _____ C:\Users\HP\Desktop\JDownloader 2.lnk
2016-09-04 18:44 - 2016-09-04 18:44 - 00000000 ____D C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader
2016-09-04 18:42 - 2016-09-04 20:23 - 00000000 ____D C:\Users\HP\Desktop\JDownloader
2016-09-04 18:39 - 2016-09-04 18:39 - 00076504 _____ (AppWork GmbH) C:\Users\HP\Downloads\WebInstaller_adfree_2016_1.exe
2016-09-04 18:39 - 2016-09-04 18:39 - 00076504 _____ (AppWork GmbH) C:\Users\HP\Downloads\WebInstaller_adfree_2016_1 (1).exe
2016-09-04 18:07 - 2016-09-05 00:08 - 00000000 ____D C:\Users\HP\Desktop\cubase
2016-09-04 16:48 - 2016-09-04 16:48 - 00609217 ____T C:\Users\HP\Downloads\Don't Leave - Free Boom Bap Hip Hop Instrumental Beat (Prod By Outspoken & Yung Castello) (320 kbps).mp3.asd
2016-09-04 08:48 - 2016-09-04 08:48 - 00127537 _____ C:\Users\HP\Downloads\uebersicht-vorkurs-2014-100.pdf
2016-09-04 00:07 - 2016-09-04 00:07 - 00782252 ____T C:\Users\HP\Downloads\Afro_cuban_jazz_suite_for_ellington_[mp3take].mp3.asd
2016-09-03 23:30 - 2016-09-08 00:14 - 00000000 ___RD C:\Users\HP\Desktop\first drumpack Project
2016-09-03 17:06 - 2016-09-03 17:06 - 00000000 ____D C:\Users\HP\Downloads\Elements-Of-UK-Dance
2016-09-03 16:48 - 2016-09-03 17:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Akai
2016-09-03 16:48 - 2016-09-03 16:48 - 00001045 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC Essentials.lnk
2016-09-03 16:48 - 2016-09-03 16:48 - 00000000 ____D C:\ProgramData\Akai
2016-09-03 16:48 - 2016-09-03 16:48 - 00000000 ____D C:\Program Files\Common Files\Avid
2016-09-03 16:47 - 2016-09-03 16:47 - 00000000 ____D C:\Program Files\Akai Pro
2016-09-03 16:47 - 2016-09-03 16:47 - 00000000 ____D C:\Program Files (x86)\Akai Pro
2016-09-03 16:45 - 2016-09-03 16:45 - 00000000 ____D C:\Users\HP\Downloads\Update-MPC-Essentials-1.8.2-WIN
2016-09-03 16:38 - 2016-09-03 17:00 - 443053927 _____ C:\Users\HP\Downloads\Elements-Of-UK-Dance.zip
2016-09-03 16:37 - 2016-09-03 19:40 - 2919535507 _____ C:\Users\HP\Downloads\BigBangDrums2.zip
2016-09-03 16:37 - 2016-09-03 19:23 - 1490752945 _____ C:\Users\HP\Downloads\BigBang2.5.zip
2016-09-03 16:37 - 2016-09-03 16:45 - 136513144 _____ C:\Users\HP\Downloads\Update-MPC-Essentials-1.8.2-WIN.zip
2016-09-03 16:30 - 2016-09-03 17:07 - 975151220 _____ C:\Users\HP\Downloads\ableton_live_lite_9.6.2_64 (1).zip
2016-09-03 16:25 - 2016-09-03 17:00 - 00000000 ____D C:\Users\HP\Documents\Ableton
2016-09-03 16:22 - 2016-09-03 16:48 - 00000000 ____D C:\ProgramData\Package Cache
2016-09-03 16:21 - 2016-09-03 16:30 - 00000000 ____D C:\Users\HP\AppData\Roaming\Ableton
2016-09-03 16:16 - 2016-09-03 16:16 - 00000887 _____ C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ableton Live 9 Lite.lnk
2016-09-03 16:16 - 2016-09-03 16:16 - 00000000 ____D C:\ProgramData\Ableton
2016-09-03 16:13 - 2016-09-03 16:13 - 00000000 ____D C:\Users\HP\Downloads\ableton_live_lite_9.6.2_64
2016-09-03 16:01 - 2016-09-03 16:13 - 975151220 _____ C:\Users\HP\Downloads\ableton_live_lite_9.6.2_64.zip
2016-09-03 13:44 - 2016-09-03 13:44 - 00274725 _____ C:\Users\HP\Desktop\Ying And Yang by P_Beats.htm
2016-09-03 13:44 - 2016-09-03 13:44 - 00000000 ____D C:\Users\HP\Desktop\Ying And Yang by P_Beats_files
2016-08-30 23:51 - 2016-09-18 23:37 - 00000000 ____D C:\Users\HP\Documents\Cubase LE AI Elements Projects
2016-08-30 23:50 - 2016-08-30 23:50 - 00000000 ____D C:\Users\HP\Documents\VST3 Presets
2016-08-30 23:50 - 2016-08-30 23:50 - 00000000 ____D C:\Users\HP\Documents\Steinberg
2016-08-30 23:45 - 2016-09-05 00:29 - 00000000 ____D C:\Program Files (x86)\Steinberg
2016-08-30 23:45 - 2016-08-30 23:45 - 00002892 _____ () C:\WINDOWS\SysWOW64\audcon.sys
2016-08-30 23:45 - 2016-08-30 23:45 - 00002333 _____ C:\Users\HP\Desktop\Cubase LE AI Elements 8.lnk
2016-08-30 23:45 - 2016-08-30 23:45 - 00000000 ____D C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steinberg Cubase LE AI Elements 8 32bit
2016-08-30 23:45 - 2016-08-30 23:45 - 00000000 ____D C:\ProgramData\Syncrosoft
2016-08-30 23:44 - 2016-08-30 23:44 - 00000049 _____ C:\WINDOWS\SysWOW64\SYNSOPOS.exe.cfg
2016-08-30 23:44 - 2016-08-30 23:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eLicenser
2016-08-30 23:44 - 2016-08-30 23:44 - 00000000 ____D C:\Program Files (x86)\Syncrosoft
2016-08-30 23:44 - 2011-12-14 21:21 - 00086016 _____ C:\WINDOWS\SysWOW64\SYNSOPOS.exe
2016-08-30 23:43 - 2016-08-30 23:45 - 00000000 ____D C:\ProgramData\eLicenser
2016-08-30 23:43 - 2016-08-30 23:44 - 00000000 ____D C:\Program Files (x86)\eLicenser
2016-08-30 23:43 - 2016-08-30 23:43 - 00000000 ____D C:\Program Files\eLicenser
2016-08-30 23:43 - 2012-12-07 17:48 - 01714176 _____ (Steinberg Media Technologies GmbH) C:\WINDOWS\system32\SYNSOACC.dll
2016-08-30 23:43 - 2012-12-07 17:48 - 01277952 _____ (Steinberg Media Technologies GmbH) C:\WINDOWS\SysWOW64\SYNSOACC.dll
2016-08-30 23:23 - 2016-08-30 23:23 - 00000000 ____D C:\ProgramData\Steinberg
2016-08-30 23:23 - 2016-08-30 23:23 - 00000000 ____D C:\Program Files\Common Files\Steinberg
2016-08-30 23:21 - 2016-08-30 23:41 - 00000000 ____D C:\Users\HP\AppData\Local\Steinberg Installation Updater
2016-08-30 23:21 - 2016-08-30 23:21 - 00000000 ____D C:\Users\HP\AppData\Roaming\Steinberg Installation Updater
2016-08-30 23:11 - 2016-08-30 23:11 - 00000000 ____D C:\Users\HP\Downloads\Cubase_Elements_8_Trial_Installer_windows
2016-08-30 23:07 - 2016-09-05 00:29 - 00000000 ____D C:\Users\HP\AppData\Roaming\Steinberg
2016-08-30 23:07 - 2016-09-03 16:48 - 00000000 ____D C:\Program Files\Steinberg
2016-08-30 23:07 - 2016-09-03 16:21 - 00000000 ____D C:\Program Files\Common Files\Propellerhead Software
2016-08-30 23:07 - 2016-08-30 23:07 - 00002215 _____ C:\Users\HP\Desktop\Cubase LE AI Elements 8 64bit.lnk
2016-08-30 23:07 - 2016-08-30 23:07 - 00000000 ____D C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steinberg Cubase LE AI Elements 8 64bit
2016-08-30 22:25 - 2016-08-30 23:05 - 2772390032 _____ C:\Users\HP\Downloads\Cubase_Elements_8_Trial_Installer_windows.zip
2016-08-30 20:39 - 2016-09-18 16:04 - 00000000 ____D C:\Users\HP\AppData\Roaming\Audacity
2016-08-30 20:39 - 2016-08-30 20:39 - 00000000 ____D C:\Users\HP\Downloads\audacity-win-2.1.2
2016-08-30 20:39 - 2016-08-30 20:39 - 00000000 ____D C:\Users\HP\AppData\Local\Audacity
2016-08-30 20:38 - 2016-08-30 20:38 - 10921409 _____ C:\Users\HP\Downloads\audacity-win-2.1.2.zip
2016-08-30 19:36 - 2016-08-30 20:03 - 00000000 ____D C:\WINDOWS\usb-audio.deSPLCrimson
2016-08-30 19:36 - 2016-02-19 20:56 - 00555128 _____ (Ploytec GmbH) C:\WINDOWS\system32\Drivers\spl_crimson_u.sys
2016-08-30 19:36 - 2016-02-19 20:56 - 00062584 _____ (Ploytec GmbH) C:\WINDOWS\system32\Drivers\spl_crimson_a.sys
2016-08-30 19:36 - 2016-02-19 20:56 - 00041592 _____ (Ploytec GmbH) C:\WINDOWS\system32\Drivers\spl_crimson_m.sys
2016-08-30 19:35 - 2016-02-23 10:52 - 02175274 _____ C:\Users\HP\Downloads\SPL_Crimson_2.9.86.25.zip
2016-08-30 19:32 - 2016-08-30 19:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-08-30 19:32 - 2016-08-30 19:32 - 00000000 ____D C:\Program Files (x86)\7-Zip
2016-08-30 19:25 - 2016-08-30 19:25 - 02220493 _____ C:\Users\HP\Downloads\SPL_Crimson2.9.86.25_web.zip
2016-08-30 18:59 - 2016-08-30 19:00 - 00000000 ____D C:\Users\HP\Desktop\games
2016-08-30 18:56 - 2016-09-03 14:32 - 00000000 ____D C:\Users\HP\Desktop\bilder
2016-08-25 13:50 - 2016-08-25 13:50 - 00000000 ____D C:\Users\HP\Documents\My Games
2016-08-25 13:50 - 2016-08-25 13:50 - 00000000 ____D C:\Users\HP\AppData\Local\FalloutNV
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-09-20 22:17 - 2012-07-26 09:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-09-20 22:10 - 2014-07-14 18:15 - 11175936 ___SH C:\Users\HP\Downloads\Thumbs.db
2016-09-20 22:07 - 2015-04-17 22:33 - 00000000 ____D C:\Program Files (x86)\Steam
2016-09-20 22:07 - 2014-10-20 19:15 - 00000000 ____D C:\Users\HP\AppData\Local\Spotify
2016-09-20 22:07 - 2014-10-20 19:13 - 00000000 ____D C:\Users\HP\AppData\Roaming\Spotify
2016-09-20 22:07 - 2014-07-19 20:11 - 00000000 ___RD C:\Users\HP\OneDrive
2016-09-20 22:07 - 2014-07-14 15:04 - 00987648 ___SH C:\Users\HP\Desktop\Thumbs.db
2016-09-20 21:59 - 2014-03-18 12:03 - 01980998 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-09-20 21:59 - 2014-03-18 11:25 - 00841326 _____ C:\WINDOWS\system32\perfh007.dat
2016-09-20 21:59 - 2014-03-18 11:25 - 00191558 _____ C:\WINDOWS\system32\perfc007.dat
2016-09-20 21:59 - 2013-08-22 15:36 - 00000000 ____D C:\WINDOWS\Inf
2016-09-20 21:53 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-09-20 21:53 - 2012-10-05 21:55 - 00000000 ____D C:\ProgramData\NVIDIA
2016-09-20 21:50 - 2014-05-21 13:07 - 00000000 ____D C:\Users\HP\AppData\LocalLow\Temp
2016-09-20 13:52 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-09-20 13:52 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-09-20 13:51 - 2016-08-20 04:34 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-09-20 13:39 - 2013-09-20 11:33 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3930845653-3837040866-4171826123-1001
2016-09-20 13:19 - 2015-01-07 19:02 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-09-20 13:18 - 2015-01-07 19:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-09-20 13:05 - 2015-01-07 18:46 - 00000000 ____D C:\AdwCleaner
2016-09-20 13:04 - 2013-09-27 19:50 - 00001304 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-09-18 02:27 - 2016-08-20 04:34 - 00000946 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-09-17 23:30 - 2013-09-30 15:54 - 00000000 ____D C:\Users\HP\AppData\Roaming\vlc
2016-09-16 18:52 - 2012-10-05 22:13 - 00000000 ____D C:\WINDOWS\en
2016-09-14 10:38 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2016-09-14 10:24 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-09-14 10:24 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-09-14 10:13 - 2013-08-22 16:44 - 00377408 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-09-14 10:08 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2016-09-14 10:08 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\setup
2016-09-14 00:47 - 2013-09-27 16:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-09-14 00:37 - 2013-09-27 16:00 - 144199024 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-09-13 17:51 - 2016-08-20 04:34 - 00003898 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2016-09-13 17:51 - 2016-08-20 04:34 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-09-13 17:51 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-09-13 17:51 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-09-12 08:49 - 2014-07-11 16:17 - 00000000 ____D C:\Users\UpdatusUser
2016-09-12 08:47 - 2014-07-11 03:21 - 00000000 ____D C:\Users\HP
2016-09-08 01:15 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-09-07 03:11 - 2016-07-27 11:13 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-09-07 03:11 - 2016-07-27 11:13 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-09-06 17:19 - 2015-01-07 21:54 - 00000000 ____D C:\ProgramData\Unchecky
2016-09-02 12:33 - 2016-04-01 12:31 - 00000000 ____D C:\Users\HP\Desktop\mzzk
2016-08-27 10:30 - 2013-10-06 14:56 - 00000000 ____D C:\Users\HP\AppData\Local\ElevatedDiagnostics
2016-08-25 13:21 - 2015-04-17 23:33 - 00000000 ____D C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-08-23 20:43 - 2016-08-20 04:34 - 00000000 ____D C:\Users\HP\AppData\Local\Adobe
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2013-12-19 22:57 - 2014-03-28 09:18 - 0000157 _____ () C:\Users\HP\AppData\Roaming\WB.CFG
2013-09-20 11:20 - 2013-09-20 11:20 - 0000141 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2016-09-20 22:17
==================== Ende von FRST.txt ============================ |