|
Log-Analyse und Auswertung: akm trojaner ergebnisWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
22.09.2015, 15:21 | #1 |
| akm trojaner ergebnisCode:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x86) Version:15-09-2015 durchgeführt von michael (Administrator) auf MICHAEL-PC (22-09-2015 16:02:43) Gestartet von G:\ Geladene Profile: michael (Verfügbare Profile: michael & Michael & LogMeInRemoteUser & NeroMediaHomeUser.4) Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Safe Mode (minimal) Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9808488 2010-11-03] (Realtek Semiconductor) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [Agile1pAgent] => C:\Program Files\1Password 4\Agile1pAgent.exe [4859152 2015-08-11] (AgileBits) HKLM\...\Run: [LogMeIn GUI] => C:\Program Files\LogMeIn\x86\LogMeInSystray.exe [63048 2012-04-02] (LogMeIn, Inc.) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-09-15] (Apple Inc.) HKLM\...\Run: [VirtualCloneDrive] => C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG) HKLM\...\Run: [Nero MediaHome 4] => C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe [4891944 2009-06-23] (Nero AG) HKLM\...\Run: [TrayServer] => C:\Program Files\MAGIX\Video_deluxe_MX_Premium\TrayServer_de.exe [90112 2008-08-07] (MAGIX AG) HKLM\...\Run: [FrameManager] => C:\Program Files\Samsung\FrameManager\FrameManager.exe [512000 2008-10-23] (Samsung India Software Center) HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [433160 2015-09-04] (DivX, LLC) HKLM\...\Run: [WD Quick View] => C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe [5564784 2015-07-20] (Western Digital Technologies, Inc.) HKLM\...\Run: [CloneCDTray] => C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.) HKLM\...\Run: [Cloud Print Service Controller] => C:\Program Files\Software Devices LLC\Cloud Print for Windows\CloudPrintController.exe [782424 2013-06-10] (Software Devices LLC) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [SwitchBoard] => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM\...\Run: [AdobeCS6ServiceManager] => C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM\...\Run: [CompeGPSDev] => [X] HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation) HKLM\...\Run: [CitrixReceiver] => "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk" HKLM\...\Run: [ConnectionCenter] => C:\Program Files\Citrix\ICA Client\concentr.exe [407904 2014-11-27] (Citrix Systems, Inc.) HKLM\...\Run: [Redirector] => C:\Program Files\Citrix\ICA Client\redirector.exe [153952 2014-11-27] (Citrix Systems, Inc.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157456 2015-09-15] (Apple Inc.) HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861640 2015-06-27] (DivX, LLC) Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X] HKU\S-1-5-21-3390348399-1428350702-574305813-1141\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2015-04-26] (Apple Inc.) HKU\S-1-5-21-3390348399-1428350702-574305813-1141\...\Run: [Google Update] => C:\Users\michael.HHBKK\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-30] (Google Inc.) HKU\S-1-5-18\...\RunOnce: [iCloud] => C:\Program Files\Common Files\Apple\Internet Services\iCloud.exe [43816 2015-04-26] (Apple Inc.) ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-07-29] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-07-29] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-07-29] (Google) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PhraseExpress.lnk [2014-07-31] ShortcutTarget: PhraseExpress.lnk -> C:\Program Files\PhraseExpress\phraseexpress.exe (Bartels Media GmbH) Startup: C:\Users\michael.HHBKK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutoStarter.lnk [2015-09-22] ShortcutTarget: AutoStarter.lnk -> C:\Users\michael.HHBKK\AppData\Roaming\autostarter.exe () Startup: C:\Users\michael.HHBKK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-07-23] ShortcutTarget: Dropbox.lnk -> C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\michael.HHBKK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ja.lnk [2015-09-22] ShortcutTarget: ja.lnk -> C:\Users\michael.HHBKK\AppData\Roaming\loadit.exe () BootExecute: autocheck autochk * sdnclean.exe GroupPolicy: Beschränkung - Chrome <======= ACHTUNG CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Winsock: Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.) Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt Tcpip\..\Interfaces\{33AB95AC-F32C-4FFD-9290-6C54DB6047D8}: [DhcpNameServer] 172.20.10.1 Tcpip\..\Interfaces\{653742F4-1483-4726-9948-69E8D40CA368}: [DhcpNameServer] 208.67.222.222 208.67.220.220 Tcpip\..\Interfaces\{D830089B-C958-42C2-91A9-F0E02D0DC1A4}: [DhcpNameServer] 208.67.222.222 208.67.220.220 Tcpip\..\Interfaces\{D9FD32F7-2B98-454A-A28C-F88A6F33C637}: [DhcpNameServer] 194.48.139.254 194.48.124.200 Tcpip\..\Interfaces\{E4C624F7-A3F9-49FD-BADF-623617D382B1}: [NameServer] 192.168.20.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKU\S-1-5-21-3390348399-1428350702-574305813-1141\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3390348399-1428350702-574305813-1141 -> {5FDD748F-A9AF-41E2-8916-6065C6746457} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10871 BHO: 1Password -> {037C06D5-3893-49E8-9AC0-41F7524AFBF5} -> C:\Program Files\1Password 4\x86\Agile1pIE4.dll [2015-08-11] (AgileBits) BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-08-12] (Microsoft Corporation) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-08-31] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-31] (Oracle Corporation) Toolbar: HKLM - FindWide Toolbar - {EC5A86F7-7664-4D4E-B795-D45A57CB394B} - C:\Program Files\TNT2\2.0.0.1950\ietoolbar.dll Keine Datei Toolbar: HKU\S-1-5-21-3390348399-1428350702-574305813-1141 -> FindWide Toolbar - {EC5A86F7-7664-4D4E-B795-D45A57CB394B} - C:\Program Files\TNT2\2.0.0.1950\ietoolbar.dll Keine Datei Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-05-05] (Microsoft Corporation) Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll [2014-11-27] (Citrix Systems, Inc.) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\michael.HHBKK\AppData\Roaming\Mozilla\Firefox\Profiles\qnbczud8.default-1441737663340 FF Homepage: www.orf.at FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin: @Citrix.com/npican -> C:\Program Files\Citrix\ICA Client\npicaN.dll [2014-11-27] (Citrix Systems, Inc.) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2015-09-02] (DivX, LLC) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2013-07-03] (Foxit Corporation) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2013-07-03] (Foxit Corporation) FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2012-11-02] (GARMIN Corp.) FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Programme\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-31] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-31] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-05-19] (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3390348399-1428350702-574305813-1141: @citrixonline.com/appdetectorplugin -> C:\Users\michael.HHBKK\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-05-12] (Citrix Online) FF Plugin HKU\S-1-5-21-3390348399-1428350702-574305813-1141: @talk.google.com/GoogleTalkPlugin -> C:\Users\michael.HHBKK\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google) FF Plugin HKU\S-1-5-21-3390348399-1428350702-574305813-1141: @talk.google.com/O1DPlugin -> C:\Users\michael.HHBKK\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google) FF Plugin HKU\S-1-5-21-3390348399-1428350702-574305813-1141: @tools.google.com/Google Update;version=3 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.) FF Plugin HKU\S-1-5-21-3390348399-1428350702-574305813-1141: @tools.google.com/Google Update;version=9 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\CCMSDK.dll [2011-04-25] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\cgpcfg.dll [2011-04-25] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\CgpCore.dll [2011-04-25] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\confmgr.dll [2011-04-25] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\ctxlogging.dll [2011-04-25] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\ctxmui.dll [2011-04-25] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\icafile.dll [2011-04-25] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\icalogon.dll [2011-04-25] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np32dsw.dll [2004-09-09] (Macromedia, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPAdbESD.dll [2004-11-13] (Adobe Systems Incorporated) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npagent.dll [2007-03-22] () FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npicaN.dll [2011-04-25] () FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll [2006-12-12] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-05-19] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npOGAPlugin.dll [2009-08-03] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2015-06-29] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-08-27] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-08-27] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-08-27] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-08-27] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-08-27] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll [2011-03-22] (Nullsoft, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\sslsdk_b.dll [2011-04-25] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\TcpPServ.dll [2011-04-25] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Users\michael.HHBKK\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google) FF Plugin ProgramFiles/Appdata: C:\Users\michael.HHBKK\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google) FF Extension: 1Password - C:\Users\michael.HHBKK\AppData\Roaming\Mozilla\Firefox\Profiles\qnbczud8.default-1441737663340\Extensions\onepassword4@agilebits.com.xpi [2015-09-09] FF Extension: Google Translator for Firefox - C:\Users\michael.HHBKK\AppData\Roaming\Mozilla\Firefox\Profiles\qnbczud8.default-1441737663340\Extensions\translator@zoli.bod.xpi [2015-09-18] FF Extension: WhatsApp Panel - C:\Users\michael.HHBKK\AppData\Roaming\Mozilla\Firefox\Profiles\qnbczud8.default-1441737663340\Extensions\whatsapppanel@alejandrobrizuela.com.ar.xpi [2015-09-18] FF Extension: All-in-One Sidebar - C:\Users\michael.HHBKK\AppData\Roaming\Mozilla\Firefox\Profiles\qnbczud8.default-1441737663340\Extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi [2015-09-15] FF Extension: Password Exporter - C:\Users\michael.HHBKK\AppData\Roaming\Mozilla\Firefox\Profiles\qnbczud8.default-1441737663340\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi [2015-09-18] FF Extension: Adblock Plus - C:\Users\michael.HHBKK\AppData\Roaming\Mozilla\Firefox\Profiles\qnbczud8.default-1441737663340\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-09] FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-09-14] Chrome: ======= CHR Profile: C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Translate) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2014-12-22] CHR Extension: (Angry Birds) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2014-07-10] CHR Extension: (Google Docs) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-10] CHR Extension: (Google Drive) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-10] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-04] CHR Extension: (YouTube) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-10] CHR Extension: (Google Cast) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2014-07-13] CHR Extension: (Google Search) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-10] CHR Extension: (fjmhjjohhiehaoljianalpmfcceojaff) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjmhjjohhiehaoljianalpmfcceojaff [2015-03-09] CHR Extension: (AdBlock) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-07-10] CHR Extension: (1Password) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdmbinomkfhmgknkoicejolfdfjeajmk [2014-07-10] CHR Extension: (Google Wallet) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-10] CHR Extension: (Gmail) - C:\Users\michael.HHBKK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-10] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S2 Agile1Password; C:\Program Files\1Password\Agile1pService.exe [768784 2014-09-17] (AgileBits) S2 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) S2 Cloud Print Service; C:\Program Files\Software Devices LLC\Cloud Print for Windows\CloudPrintService.exe [336472 2013-06-10] (Software Devices LLC) S3 cphs; C:\Windows\system32\IntelCpHeciSvc.exe [290224 2015-06-01] (Intel Corporation) S2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) [Datei ist nicht signiert] S4 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [Datei ist nicht signiert] S2 FoxitCloudUpdateService; C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe [244392 2015-06-02] (Foxit Software Inc.) S4 FrameManager Service; C:\Program Files\Samsung\FrameManager\sam_service.exe [188416 2008-10-22] (Samsung India Software Center) [Datei ist nicht signiert] S2 KMService; C:\Windows\system32\srvany.exe [8192 2012-07-18] () [Datei ist nicht signiert] R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation) S4 NeroMediaHomeService.4; C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe [259368 2009-06-23] (Nero AG) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation) S2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2011-03-31] () [Datei ist nicht signiert] S2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.) S2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.) S2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.) S2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Datei ist nicht signiert] S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Datei ist nicht signiert] S2 WDBackup; C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2015-07-20] (Western Digital Technologies, Inc.) S2 WDDriveService; C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe [306552 2015-07-20] (Western Digital Technologies, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [97216 2008-01-02] (SlySoft, Inc.) R3 asmthub3; C:\Windows\System32\DRIVERS\asmthub3.sys [95720 2010-12-08] (ASMedia Technology Inc) R3 asmtxhci; C:\Windows\System32\DRIVERS\asmtxhci.sys [292840 2010-12-08] (ASMedia Technology Inc) S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [22528 2009-08-13] (CSR, plc) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-16] (SlySoft, Inc.) S1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [30616 2014-12-21] (Elaborate Bytes AG) S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [65896 2013-07-25] (FTDI Ltd.) S3 grmnusb; C:\Windows\System32\drivers\grmnusb.sys [15720 2012-04-18] (GARMIN Corp.) R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [41088 2010-10-19] (Intel Corporation) S3 miniusb; C:\Windows\System32\DRIVERS\sam_miniusb.sys [17336 2008-10-22] (Samsung India Software Center) S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation) S3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [1596208 2013-04-17] (Ralink Technology Corp.) S3 QCDonner; C:\Windows\System32\DRIVERS\LVCD.sys [474304 2004-04-26] (Logitech Inc.) S3 radpms; C:\Windows\System32\DRIVERS\radpms.sys [13408 2012-04-02] (LogMeIn, Inc.) S3 Ser2plx86; C:\Windows\System32\DRIVERS\ser2pl.sys [42752 2004-06-28] (Prolific Technology Inc.) S3 SIUSBXP; C:\Windows\System32\drivers\SiUSBXp.sys [14592 2009-11-03] (Silicon Laboratories) S3 SODI; C:\Windows\System32\DRIVERS\sam_miniport.sys [17976 2008-10-22] (Samsung India Software Center) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [320120 2014-01-16] (Duplex Secure Ltd.) S3 taphss; C:\Windows\System32\DRIVERS\taphss.sys [32768 2012-03-26] (AnchorFree Inc) S4 LMIRfsClientNP; kein ImagePath ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-09-22 16:02 - 2015-09-22 16:02 - 00000000 ____D C:\FRST 2015-09-22 15:19 - 2015-09-22 15:19 - 00000000 ____D C:\Windows\pss 2015-09-22 14:23 - 2015-09-22 15:49 - 00000043 _____ C:\Users\michael.HHBKK\AppData\Roaming\url.txt 2015-09-22 14:23 - 2015-09-22 14:24 - 00696694 _____ C:\Users\michael.HHBKK\AppData\Roaming\loadit.exe 2015-09-22 14:17 - 2015-09-18 08:06 - 103830659 _____ C:\Users\michael.HHBKK\AppData\Roaming\autostarter.exe 2015-09-21 09:41 - 2015-09-21 09:41 - 00417792 _____ C:\Users\michael.HHBKK\Downloads\DirectFromPC_Vue_3_00.exe 2015-09-21 08:19 - 2015-09-21 08:21 - 00000000 ___HD C:\$Windows.~BT 2015-09-19 15:42 - 2015-09-19 15:42 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk 2015-09-19 15:42 - 2015-09-19 15:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-09-19 15:41 - 2015-09-19 15:42 - 00000000 ____D C:\Program Files\iTunes 2015-09-19 15:41 - 2015-09-19 15:41 - 00000000 ____D C:\Program Files\iPod 2015-09-19 15:36 - 2015-09-19 15:36 - 00000000 ____D C:\Program Files\Bonjour 2015-09-19 15:33 - 2015-09-19 15:33 - 00000000 ____D C:\Program Files\Apple Software Update 2015-09-17 16:31 - 2015-09-17 16:31 - 00000000 ____D C:\Users\michael.HHBKK\Documents\My Data Files 2015-09-17 16:31 - 2015-09-17 16:31 - 00000000 ____D C:\Users\michael.HHBKK\AppData\Local\Wondershare 2015-09-17 16:31 - 2015-09-17 16:31 - 00000000 ____D C:\Program Files\Common Files\Wondershare 2015-09-17 16:30 - 2015-09-17 16:37 - 00000000 ____D C:\Program Files\Wondershare 2015-09-17 16:28 - 2015-09-17 16:30 - 25152664 _____ (Wondershare Software Co.,Ltd. ) C:\Users\michael.HHBKK\Downloads\data-recovery_full1018.exe 2015-09-16 13:09 - 2015-09-16 13:09 - 00001088 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390348399-1428350702-574305813-1141Core1d0f070238ba481.job 2015-09-15 07:50 - 2014-12-10 16:50 - 00000878 _____ C:\Windows\system32\Drivers\etc\hosts.20150915-075049.backup 2015-09-09 05:41 - 2015-08-18 03:14 - 00344168 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-09-09 05:41 - 2015-08-15 08:06 - 19856896 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-09-09 05:41 - 2015-08-15 07:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-09-09 05:41 - 2015-08-15 07:53 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-09-09 05:41 - 2015-08-15 07:40 - 00504832 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-09-09 05:41 - 2015-08-15 07:40 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-09-09 05:41 - 2015-08-15 07:39 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-09-09 05:41 - 2015-08-15 07:39 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-09-09 05:41 - 2015-08-15 07:38 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-09-09 05:41 - 2015-08-15 07:35 - 02279424 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-09-09 05:41 - 2015-08-15 07:33 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-09-09 05:41 - 2015-08-15 07:32 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-09-09 05:41 - 2015-08-15 07:30 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-09-09 05:41 - 2015-08-15 07:29 - 00665600 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-09-09 05:41 - 2015-08-15 07:29 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-09-09 05:41 - 2015-08-15 07:29 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-09-09 05:41 - 2015-08-15 07:29 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-09-09 05:41 - 2015-08-15 07:24 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-09-09 05:41 - 2015-08-15 07:21 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-09-09 05:41 - 2015-08-15 07:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-09-09 05:41 - 2015-08-15 07:14 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-09-09 05:41 - 2015-08-15 07:12 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-09-09 05:41 - 2015-08-15 07:11 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-09-09 05:41 - 2015-08-15 07:10 - 04520448 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-09-09 05:41 - 2015-08-15 07:04 - 12857344 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-09-09 05:41 - 2015-08-15 07:02 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-09-09 05:41 - 2015-08-15 07:02 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-09-09 05:41 - 2015-08-15 07:01 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-09-09 05:41 - 2015-08-15 07:01 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-09-09 05:41 - 2015-08-15 06:43 - 01951232 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-09-09 05:41 - 2015-08-15 06:39 - 01310720 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-09-09 05:41 - 2015-08-15 06:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-09-09 05:40 - 2015-09-02 04:48 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2015-09-09 05:40 - 2015-09-02 04:48 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-09-09 05:40 - 2015-09-02 04:48 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2015-09-09 05:40 - 2015-09-02 04:48 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2015-09-09 05:40 - 2015-09-02 03:36 - 02384896 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-09-09 05:40 - 2015-09-02 03:33 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-09-09 05:40 - 2015-08-27 19:58 - 01391104 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2015-09-09 05:40 - 2015-08-27 19:58 - 01241088 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2015-09-09 05:40 - 2015-08-27 19:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2015-09-09 05:40 - 2015-08-27 19:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2015-09-09 05:40 - 2015-08-05 19:41 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll 2015-09-09 05:40 - 2015-08-05 19:40 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2015-09-09 05:40 - 2015-08-05 19:40 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll 2015-09-09 05:40 - 2015-08-04 19:48 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2015-09-09 05:40 - 2015-08-04 19:47 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2015-09-09 05:40 - 2015-08-04 19:47 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2015-09-09 05:40 - 2015-08-04 19:46 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2015-09-09 05:40 - 2015-08-04 19:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2015-09-09 05:40 - 2015-08-04 18:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2015-09-09 05:39 - 2015-08-26 19:56 - 02953728 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-09-09 05:39 - 2015-08-26 19:56 - 02061824 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-09-09 05:39 - 2015-08-26 19:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-09-09 05:39 - 2015-08-26 19:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-09-09 05:39 - 2015-08-26 19:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-09-09 05:39 - 2015-08-26 19:56 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-09-09 05:39 - 2015-08-26 19:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-09-09 05:39 - 2015-08-26 19:55 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-09-09 05:39 - 2015-08-26 19:55 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-09-09 05:39 - 2015-08-26 19:55 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-09-09 05:39 - 2015-08-26 19:55 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-09-09 05:39 - 2015-07-22 19:57 - 03989952 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-09-09 05:39 - 2015-07-22 19:57 - 03934656 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-09-09 05:39 - 2015-07-22 19:57 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-09-09 05:39 - 2015-07-22 19:57 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-09-09 05:39 - 2015-07-22 19:54 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00937984 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-09-09 05:39 - 2015-07-22 19:53 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-09-09 05:39 - 2015-07-22 19:52 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-09-09 05:39 - 2015-07-22 19:52 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-09-09 05:39 - 2015-07-22 19:52 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-09-09 05:39 - 2015-07-22 19:52 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-09-09 05:39 - 2015-07-22 19:47 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-09-09 05:39 - 2015-07-22 19:46 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-09-09 05:39 - 2015-07-22 19:42 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-09-09 05:39 - 2015-07-22 19:42 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-09-09 05:39 - 2015-07-22 18:38 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2015-09-09 05:39 - 2015-07-22 18:34 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2015-09-09 05:39 - 2015-07-22 18:34 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-09-09 05:39 - 2015-07-22 18:33 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-09-09 05:39 - 2015-07-15 04:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2015-09-09 05:39 - 2015-07-09 19:42 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-09-09 05:39 - 2015-07-09 19:42 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll 2015-09-09 05:39 - 2015-06-25 11:48 - 00105408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2015-09-09 05:39 - 2015-06-25 11:44 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-09-09 05:39 - 2015-06-25 11:44 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2015-09-05 22:17 - 2015-09-05 22:17 - 00131072 _____ C:\Windows\Minidump\090515-25412-01.dmp 2015-09-03 09:33 - 2015-09-03 09:33 - 00001564 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix Receiver.lnk 2015-09-03 09:27 - 2015-09-03 09:27 - 00000000 ____D C:\Program Files\Common Files\Citrix 2015-09-03 09:02 - 2015-09-03 09:05 - 59525456 _____ (Citrix Systems, Inc.) C:\Users\michael.HHBKK\Downloads\CitrixReceiver_4.2.exe 2015-09-01 11:51 - 2015-09-01 11:51 - 00365576 _____ (DivX, LLC) C:\Windows\system32\DivXControlPanelApplet.cpl 2015-09-01 03:32 - 2015-09-01 03:32 - 00000000 ____D C:\Users\michael.HHBKK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-08-31 21:05 - 2015-08-31 21:05 - 00000000 __HDL C:\Users\michael.HHBKK\Dropbox 2015-08-31 21:04 - 2015-09-22 15:33 - 00000000 ___RD C:\Users\michael.HHBKK\Dropbox (BKK Harmony) 2015-08-31 21:04 - 2015-08-31 21:04 - 00001153 _____ C:\Users\michael.HHBKK\Desktop\Dropbox (BKK Harmony).lnk 2015-08-31 11:00 - 2015-08-31 11:00 - 00000000 ____D C:\Users\michael.HHBKK\AppData\Roaming\Sun 2015-08-31 11:00 - 2015-08-31 11:00 - 00000000 ____D C:\Users\michael.HHBKK\.oracle_jre_usage 2015-08-30 19:22 - 2015-09-16 13:09 - 00001088 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390348399-1428350702-574305813-1141Core1d0e34881bd571b.job 2015-08-27 22:25 - 2015-09-02 09:20 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-08-27 11:04 - 2015-08-27 11:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-09-22 16:01 - 2012-04-28 09:41 - 01812482 _____ C:\Windows\system32\PerfStringBackup.INI 2015-09-22 15:44 - 2012-04-28 09:39 - 01944285 _____ C:\Windows\WindowsUpdate.log 2015-09-22 15:38 - 2009-07-14 06:34 - 00029040 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-09-22 15:38 - 2009-07-14 06:34 - 00029040 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-09-22 15:33 - 2012-05-20 20:19 - 00000000 ___RD C:\Users\michael.HHBKK\Dropbox (Privat) 2015-09-22 15:33 - 2012-05-20 20:17 - 00000000 ____D C:\Users\michael.HHBKK\AppData\Roaming\Dropbox 2015-09-22 15:32 - 2014-01-22 19:45 - 00000974 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Client.lnk 2015-09-22 15:32 - 2014-01-22 19:45 - 00000958 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Control Panel.lnk 2015-09-22 15:31 - 2012-06-26 08:41 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-09-22 15:31 - 2012-05-18 13:23 - 00000112 _____ C:\Windows\system32\config\netlogon.ftl 2015-09-22 15:31 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-09-22 15:31 - 2009-07-14 06:39 - 00005517 _____ C:\Windows\setupact.log 2015-09-22 15:23 - 2015-08-13 11:40 - 00008192 _____ C:\Windows\system32\WDPABKP.dat 2015-09-22 15:05 - 2012-05-18 14:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-09-22 15:01 - 2012-06-26 08:41 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-09-22 14:19 - 2012-05-23 21:13 - 00000000 ____D C:\Users\michael.HHBKK\AppData\Roaming\UseNeXT 2015-09-22 09:06 - 2012-05-21 09:56 - 00000000 ____D C:\Users\michael.HHBKK\Documents\FinePrint files 2015-09-22 08:03 - 2012-05-21 08:16 - 00000000 ____D C:\ProgramData\LogMeIn 2015-09-22 08:02 - 2012-04-28 22:32 - 01120462 _____ C:\Windows\PFRO.log 2015-09-21 22:50 - 2014-07-31 19:11 - 00000000 ____D C:\Users\michael.HHBKK\Documents\PhraseExpress 2015-09-21 10:40 - 2012-08-30 21:20 - 00000000 ____D C:\Program Files\DivX 2015-09-21 10:40 - 2012-08-30 21:19 - 00000000 ____D C:\ProgramData\DivX 2015-09-21 10:39 - 2014-10-06 10:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2015-09-21 08:21 - 2012-04-28 10:26 - 00000000 ____D C:\Windows\Panther 2015-09-21 08:18 - 2012-05-21 08:16 - 00000000 ____D C:\Program Files\LogMeIn 2015-09-21 08:17 - 2012-05-21 08:17 - 00103296 _____ (LogMeIn, Inc.) C:\Windows\system32\LMIRfsClientNP.dll 2015-09-21 08:17 - 2012-05-21 08:17 - 00031592 _____ (LogMeIn, Inc.) C:\Windows\system32\LMIport.dll 2015-09-21 08:17 - 2012-05-21 08:16 - 00098152 _____ (LogMeIn, Inc.) C:\Windows\system32\LMIinit.dll 2015-09-19 15:41 - 2012-05-23 09:43 - 00000000 ____D C:\Program Files\Common Files\Apple 2015-09-19 15:33 - 2012-05-23 09:43 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2015-09-19 13:37 - 2013-11-11 20:50 - 00000000 ____D C:\Users\michael.HHBKK\Documents\Scan 2015-09-19 10:34 - 2012-05-24 09:24 - 00000000 ____D C:\Users\michael.HHBKK\AppData\Roaming\vlc 2015-09-19 10:32 - 2012-07-24 15:56 - 00020480 _____ C:\Users\michael.HHBKK\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-09-18 19:28 - 2012-05-21 09:56 - 00000000 ____D C:\Users\michael.HHBKK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FinePrint 2015-09-18 13:32 - 2015-03-11 12:31 - 00000000 ____D C:\Users\michael.HHBKK\AppData\Roaming\AgileBits 2015-09-17 16:47 - 2012-05-18 13:25 - 00000000 ____D C:\Users\michael.HHBKK 2015-09-17 16:41 - 2014-08-09 19:51 - 00000000 ____D C:\Program Files\Recuva 2015-09-15 07:45 - 2012-07-26 11:31 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2015-09-14 21:05 - 2013-01-06 14:50 - 00001814 _____ C:\Users\Public\Desktop\Free YouTube Downloader.lnk 2015-09-14 21:05 - 2012-06-26 15:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free YouTube Downloader 2015-09-14 21:05 - 2012-06-26 15:12 - 00000000 ____D C:\Program Files\Free YouTube Downloader 2015-09-11 03:04 - 2012-05-18 13:41 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-09-11 03:03 - 2012-12-11 15:55 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2015-09-10 05:11 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2015-09-10 04:22 - 2009-07-14 06:33 - 03945824 _____ C:\Windows\system32\FNTCACHE.DAT 2015-09-10 04:19 - 2009-07-14 10:57 - 00000000 ____D C:\Program Files\Windows Journal 2015-09-10 04:19 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2015-09-10 03:56 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2015-09-10 03:46 - 2009-07-14 04:04 - 00000633 _____ C:\Windows\win.ini 2015-09-10 03:27 - 2013-08-15 03:09 - 00000000 ____D C:\Windows\system32\MRT 2015-09-05 22:17 - 2013-06-13 22:12 - 00000000 ____D C:\Windows\Minidump 2015-09-05 22:17 - 2013-06-13 22:11 - 305252229 _____ C:\Windows\MEMORY.DMP 2015-09-03 09:34 - 2012-05-20 22:15 - 00000000 ____D C:\ProgramData\Citrix 2015-09-03 09:33 - 2012-05-20 22:15 - 00000000 ____D C:\Users\michael.HHBKK\AppData\Local\Citrix 2015-09-03 09:33 - 2012-05-20 22:14 - 00000000 ____D C:\Program Files\Citrix 2015-09-02 09:20 - 2012-05-18 13:19 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-08-31 21:02 - 2015-06-06 09:27 - 00520192 _____ C:\Users\michael.HHBKK\Desktop\Microsoft Access Datenbank (neu).accdb 2015-08-31 11:44 - 2013-10-18 09:13 - 00000000 ____D C:\ProgramData\Oracle 2015-08-31 11:02 - 2012-05-23 09:51 - 00000000 ____D C:\Program Files\Java 2015-08-31 11:01 - 2014-10-27 10:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-08-31 10:59 - 2014-10-27 10:05 - 00097888 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2015-08-30 19:22 - 2015-07-15 23:40 - 00001088 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390348399-1428350702-574305813-1141Core1d0bf46de533e29.job 2015-08-27 11:04 - 2012-05-23 09:44 - 00000000 ____D C:\Program Files\QuickTime 2015-08-26 18:36 - 2012-05-21 08:18 - 132039072 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-08-26 10:56 - 2012-05-21 08:16 - 00098152 _____ (LogMeIn, Inc.) C:\Windows\system32\LMIinit.dll.000.bak 2015-08-25 18:37 - 2012-05-27 09:49 - 00000000 ____D C:\Users\michael.HHBKK\AppData\Local\Apple Computer 2015-08-25 11:10 - 2014-07-05 13:14 - 00000000 ____D C:\Users\michael.HHBKK\AppData\Local\LogMeInIgnition ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2014-01-10 10:53 - 2014-01-10 10:53 - 0000012 _____ () C:\Users\michael.HHBKK\AppData\Roaming\010112.txt 2013-10-04 12:18 - 2013-10-11 10:41 - 0000093 _____ () C:\Users\michael.HHBKK\AppData\Roaming\ARCompanion.log 2015-09-22 14:17 - 2015-09-18 08:06 - 103830659 _____ () C:\Users\michael.HHBKK\AppData\Roaming\autostarter.exe 2012-12-11 15:53 - 2012-12-11 15:53 - 0226928 _____ () C:\Users\michael.HHBKK\AppData\Roaming\ff.xml 2015-09-22 14:23 - 2015-09-22 14:24 - 0696694 _____ () C:\Users\michael.HHBKK\AppData\Roaming\loadit.exe 2015-09-22 14:23 - 2015-09-22 15:49 - 0000043 _____ () C:\Users\michael.HHBKK\AppData\Roaming\url.txt 2012-07-24 15:56 - 2015-09-19 10:32 - 0020480 _____ () C:\Users\michael.HHBKK\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-05-24 09:17 - 2014-04-30 11:53 - 0007640 _____ () C:\Users\michael.HHBKK\AppData\Local\Resmon.ResmonCfg 2012-07-26 16:17 - 2015-07-21 13:31 - 0000166 ___SH () C:\ProgramData\.zreglib 2015-08-09 12:52 - 2015-08-09 12:52 - 0000006 __RSH () C:\ProgramData\6797b7a90edc0ac987ad3e86517e0f0218bb5afc 2012-06-26 15:12 - 2010-05-28 23:37 - 0015086 _____ () C:\ProgramData\Amazon.ico 2012-06-26 15:12 - 2010-07-20 12:53 - 0071926 _____ () C:\ProgramData\MercadoLivre.ico Einige Dateien in TEMP: ==================== C:\Users\Michael\AppData\Local\Temp\_is4D83.exe C:\Users\michael.HHBKK\AppData\Local\Temp\1Password-4.6.0.585.exe C:\Users\michael.HHBKK\AppData\Local\Temp\DivXSetup.exe C:\Users\michael.HHBKK\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpq4dcjv.dll C:\Users\michael.HHBKK\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmprpfkzn.dll C:\Users\michael.HHBKK\AppData\Local\Temp\em2xn2vz.exe C:\Users\michael.HHBKK\AppData\Local\Temp\Foxit Reader Updater.exe C:\Users\michael.HHBKK\AppData\Local\Temp\jre-8u60-windows-au.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-09-21 10:59 ==================== Ende vom FRST.txt ============================ |
22.09.2015, 15:27 | #2 |
/// the machine /// TB-Ausbilder | akm trojaner ergebnis hi,
__________________Addition.txt fehlt. Fehlerbeschreibung und Log mit Funden fehlt auch
__________________ |
22.09.2015, 15:56 | #3 |
| akm trojaner ergebnisCode:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x86) Version:15-09-2015 durchgeführt von michael (2015-09-22 16:04:22) Gestartet von G:\ Microsoft Windows 7 Professional Service Pack 1 (X86) (2012-04-28 07:39:30) Start-Modus: Safe Mode (minimal) ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3410191000-2188883831-428749532-500 - Administrator - Disabled) Gast (S-1-5-21-3410191000-2188883831-428749532-501 - Limited - Disabled) LogMeInRemoteUser (S-1-5-21-3410191000-2188883831-428749532-1001 - Administrator - Enabled) => C:\Users\LogMeInRemoteUser Michael (S-1-5-21-3410191000-2188883831-428749532-1000 - Administrator - Enabled) => C:\Users\Michael NeroMediaHomeUser.4 (S-1-5-21-3410191000-2188883831-428749532-1002 - Limited - Enabled) => C:\Users\NeroMediaHomeUser.4 ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A} AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) .print Client Windows (ICA) (HKLM\...\{7BDA669F-7154-4EDE-A426-BAD34EFF1702}) (Version: 8.0.113 - ThinPrint AG) 1Password 1.0.9.342 (HKLM\...\1Password_is1) (Version: 1.0 - AgileBits) 1Password 4.6.0.585 (HKLM\...\1Password4_is1) (Version: 4.0 - AgileBits) 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated) Adobe Creative Suite 6 Master Collection (HKLM\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated) Adobe CS6 Master Collection Patch 32bit (HKLM\...\Adobe CS6 Master Collection Patch 32bit) (Version: - ) Adobe Flash Player 18 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated) Adobe Help Manager (HKLM\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated) Adobe Reader XI (11.0.12) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated) Advertising Center (Version: 0.0.0.1 - Nero AG) Hidden AirPagesConfigurator Version 1.0.1 (HKLM\...\{752EF630-EE06-4C18-BB54-1A582B589CD1}_is1) (Version: 1.0.1 - Digifly Europe) AirTools Version 2.0.0RC2 (HKLM\...\{C833A81F-B85A-4599-BC8C-48A9A52BB14A}_is1) (Version: 2.0.0RC2 - Digifly Europe) AirUpdater Version 1.1.16 (HKLM\...\{98DAD382-928D-4C5C-8B22-74CFCB641D0E}_is1) (Version: 1.1.16 - Digifly Europe) AirZip FileSECURE Reader (HKLM\...\{FB3DA76D-77C2-45B3-8315-C0D9E4B70E01}) (Version: 4.3.177 - AirZip) AnyDVD (HKLM\...\AnyDVD) (Version: - SlySoft) Apple Application Support (32-Bit) (HKLM\...\{3540ADD5-822B-47FB-B1C2-CD7B2C8E9FEC}) (Version: 4.0.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{A75CA58D-DB9C-4D14-9428-E0C7B0F623DC}) (Version: 9.0.0.26 - Apple Inc.) Apple Software Update (HKLM\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.) Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.4.5.0 - Asmedia Technology) Bonjour (HKLM\...\{D168AAD0-6686-47C1-B599-CDD4888B9D1A}) (Version: 3.1.0.1 - Apple Inc.) Citrix Receiver (HKLM\...\CitrixOnlinePluginPackWeb) (Version: 14.2.0.10 - Citrix Systems, Inc.) CloneCD (HKLM\...\CloneCD) (Version: - SlySoft) CloneDVD2 (HKLM\...\CloneDVD2) (Version: 2.9.3.3 - Elaborate Bytes) Cloud Print for Windows (HKLM\...\{F9719FB4-C17E-4AF0-ABAB-700D7D9D4B00}) (Version: 1.6.6 - Software Devices LLC.) CompeGPS AIR 7.0.3 (HKLM\...\CompeGPS AIR_is1) (Version: - CompeGPS TEAM, S.L.) CompeGPS LAND 6.8.4 (HKLM\...\CompeGPS LAND_is1) (Version: - CompeGPS TEAM, S.L.) CompeGPS LAND 7.7.0 (HKLM\...\CompeGPS_is1) (Version: 7.7.0 - CompeGPS TEAM, S.L.) CompeGPSDownloader version 1.13 (HKLM\...\CompeGPSDownloader_is1) (Version: 1.13 - CompeGPS TEAM, S.L.) contive.PRO (HKLM\...\contive.PRO) (Version: - ) Contour Storyteller (HKLM\...\Contour Storyteller 3.3.3) (Version: 3.5.3 - Contour) Crystal Reports for Visual Studio (Version: 12.51.0.240 - SAP) Hidden D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden DivX-Setup (HKLM\...\DivX Setup) (Version: 2.7.0.93 - DivX, LLC) Dotfuscator Software Services - Community Edition (HKLM\...\{1AA5BD63-6614-44B2-88A7-605191EDB835}) (Version: 5.0.2500.0 - PreEmptive Solutions) Dropbox (HKU\S-1-5-21-3390348399-1428350702-574305813-1141\...\Dropbox) (Version: 3.8.8 - Dropbox, Inc.) edankTLL (HKU\S-1-5-21-3390348399-1428350702-574305813-1141\...\6245ed64e5be78ff) (Version: 1.0.0.0 - edankTLL) FinePrint (HKLM\...\FinePrint) (Version: 7.15 - FinePrint Software, LLC) Firebird SQL Server - MAGIX Edition (HKLM\...\{6C5F8503-55D2-4398-858C-362B7A7AF51C}) (Version: 2.1.31.0 - MAGIX AG) FormatFactory 3.0.1 (HKLM\...\FormatFactory) (Version: 3.0.1 - Free Time) Foxit Cloud (HKLM\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 3.5.116.602 - Foxit Software Inc.) Foxit Reader (HKLM\...\Foxit Reader_is1) (Version: 6.1.4.217 - Foxit Corporation) FrameManager (HKLM\...\{AF298732-1C3B-4BA2-81FD-1EAC6062ED95}) (Version: 3.00.0000 - Samsung) FrameManager (Version: 3.00.0000 - Samsung) Hidden Free YouTube Downloader 4.1.430 (HKLM\...\{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1) (Version: - HOW Inc.) Freizeitkarte_ALPS (Ausgabe 14.05) (HKLM\...\Freizeitkarte_ALPS) (Version: - ) Garmin BaseCamp (HKLM\...\{0D7C8884-192D-4E2D-A635-B282B3647E45}) (Version: 4.4.7 - Garmin Ltd or its subsidiaries) Garmin Communicator Plugin (HKLM\...\{647BB978-2876-487B-9B0E-FDB73F0EA4A2}) (Version: 4.0.4 - Garmin Ltd or its subsidiaries) Garmin MapInstall (HKLM\...\{5ED7CD44-1A33-4B36-BA09-0B55FE82AF95}) (Version: 4.0.3 - Garmin Ltd or its subsidiaries) Garmin MapSource (HKLM\...\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}) (Version: 6.16.3 - Garmin Ltd or its subsidiaries) Garmin TOPO Austria v3 (HKLM\...\{4B7C3B57-CBD5-49DA-BEA7-A915FA1643B4}) (Version: 3.0.0.0 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM\...\{E31435FE-F0B7-4A62-BE46-BD166A1EEFFB}) (Version: 2.3.1.1 - Garmin Ltd or its subsidiaries) Google Drive (HKLM\...\{12ADFB82-D5A3-43E4-B2F4-FCD9B690315B}) (Version: 1.24.9931.5480 - Google, Inc.) Google Earth (HKLM\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Talk Plugin (HKLM\...\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google) Google Update Helper (Version: 1.3.28.15 - Google Inc.) Hidden Google+ Auto Backup (HKU\S-1-5-21-3390348399-1428350702-574305813-1141\...\Google+ Auto Backup) (Version: 1.0.25.133 - Google, Inc.) Hard Disk Wipe Tool 2.35 build 1178 (HKLM\...\Hard Disk Wipe Tool_is1) (Version: - HDDGURU) HD Tune 2.55 (HKLM\...\HD Tune_is1) (Version: - EFD Software) hide.me VPN Version 1.0.7 (HKLM\...\{0E00BDA5-7998-4889-BE4B-39A4BBD2EDFB}_is1) (Version: 1.0.7 - eVenture Limited) Hotfix für Microsoft Team Foundation Server 2010-Objektmodell - DEU (KB2736182) (HKLM\...\{929F5BFC-60F0-34EC-A50B-2001AAC03D56}.KB2736182) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Team Foundation Server 2010-Objektmodell - DEU (KB2890573) (HKLM\...\{929F5BFC-60F0-34EC-A50B-2001AAC03D56}.KB2890573) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Professional - DEU (KB2529927) (HKLM\...\{CAD6AA29-9CA1-384D-8034-566261CFCC9B}.KB2529927) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Professional - DEU (KB2548139) (HKLM\...\{CAD6AA29-9CA1-384D-8034-566261CFCC9B}.KB2548139) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Professional - DEU (KB2549864) (HKLM\...\{CAD6AA29-9CA1-384D-8034-566261CFCC9B}.KB2549864) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Professional - DEU (KB2635973) (HKLM\...\{CAD6AA29-9CA1-384D-8034-566261CFCC9B}.KB2635973) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Professional - DEU (KB2736182) (HKLM\...\{CAD6AA29-9CA1-384D-8034-566261CFCC9B}.KB2736182) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Professional - DEU (KB2890573) (HKLM\...\{CAD6AA29-9CA1-384D-8034-566261CFCC9B}.KB2890573) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2010 Professional - DEU (KB3002340) (HKLM\...\{CAD6AA29-9CA1-384D-8034-566261CFCC9B}.KB3002340) (Version: 1 - Microsoft Corporation) HTC Driver Installer (HKLM\...\{6D6664A9-3342-4948-9B7E-034EFE366F0F}) (Version: 3.0.0.007 - HTC Corporation) iCloud (HKLM\...\{9A07AB4F-6B53-43E9-B7FC-7892E8C26BE3}) (Version: 4.1.1.53 - Apple Inc.) Intel(R) Management Engine Components (HKLM\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation) iTunes (HKLM\...\{9E9CFD9F-64D6-498F-8584-E5CD08BA60BE}) (Version: 12.3.0.44 - Apple Inc.) Java 8 Update 60 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation) JavaFX 2.1.1 (HKLM\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) join.me (HKU\S-1-5-21-3390348399-1428350702-574305813-1141\...\JoinMe) (Version: 1.20.0.503 - LogMeIn, Inc.) join.me.launcher (Version: 1.0.514.0 - LogMeIn, Inc.) Hidden LogMeIn (HKLM\...\{EE4CA5AF-4A55-418C-8CB8-74435814207B}) (Version: 4.1.2450 - LogMeIn, Inc.) MAGIX Screenshare (HKLM\...\{9E1C4D6B-4600-434D-8B88-1C5657D1FF74}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Speed burnR (MSI) (HKLM\...\{4C128290-346A-476F-B04A-15CFE3F96920}) (Version: 7.0.2.6 - MAGIX AG) MAGIX Video deluxe MX Premium (HKLM\...\MAGIX_MSI_Videodeluxe18_premium) (Version: 11.0.1.4 - MAGIX AG) MAGIX Video deluxe MX Premium (Version: 11.0.1.4 - MAGIX AG) Hidden MaxPunkte Ver. 6.5.x (HKLM\...\MaxPunkte_is1) (Version: - ) Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft ASP.NET MVC 2 - DEU (HKLM\...\{E4E9CBC9-1CF5-48E3-AF6F-1AB44A856346}) (Version: 2.0.50331.0 - Microsoft Corporation) Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools - DEU (HKLM\...\{31C3C6EA-E991-405F-A3AA-2C070CCCC47C}) (Version: 2.0.50331.0 - Microsoft Corporation) Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools (HKLM\...\{40416836-56CC-4C0E-A6AF-5C34BADCE483}) (Version: 2.0.50217.0 - Microsoft Corporation) Microsoft ASP.NET MVC 2 (HKLM\...\{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation) Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.1 Language Pack - DEU) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation) Microsoft Silverlight 3 SDK - Deutsch (HKLM\...\{91F54E1D-804A-46D8-A56C-53EA9C4B3177}) (Version: 3.0.40818.0 - Microsoft Corporation) Microsoft Silverlight 4 SDK - Deutsch (HKLM\...\{803910CC-3A39-45E3-A594-0D5512A60A86}) (Version: 4.0.50826.0 - Microsoft Corporation) Microsoft SkyDrive (HKU\S-1-5-21-3390348399-1428350702-574305813-1141\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation) Microsoft SQL Server 2008 (HKLM\...\Microsoft SQL Server 10 Release) (Version: - Microsoft Corporation) Microsoft SQL Server 2008 Browser (HKLM\...\{4AF2248C-B3DF-46FB-9596-87F5DB193689}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 Native Client (HKLM\...\{1C2B3CEA-482E-4453-B3E2-C9731337828A}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (HKLM\...\{E9089B6A-1FDE-47F3-8D29-175F5B7A0722}) (Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Transact-SQL-Sprachdienst (HKLM\...\{BB1E119E-CF4B-4183-910E-A8C2B379F2C6}) (Version: 10.50.1752.9 - Microsoft Corporation) Microsoft SQL Server 2008 R2-Datenebenenanwendungs-Framework (HKLM\...\{919E5477-D20B-4F64-AE8B-8199469F7817}) (Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server 2008 R2-Datenebenenanwendungs-Projekt (HKLM\...\{103A5E44-DD5B-46D5-AD1E-9DF2260CA023}) (Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 DEU (HKLM\...\{0125D081-30D0-4A97-82A8-C28D444B6256}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Database Publishing Wizard 1.4 (HKLM\...\{ACE28263-76A4-4BF5-B6F4-8BD719595969}) (Version: 10.1.2512.8 - Microsoft Corporation) Microsoft SQL Server System CLR Types (HKLM\...\{C668416A-9213-4058-B7F2-01A42D85559D}) (Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server VSS Writer (HKLM\...\{D074DC76-F6C9-440E-A1D0-1DE958417FDB}) (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft Sync Framework Runtime v1.0 SP1 (x86) de (HKLM\...\{DB0AF767-7CC7-4E4D-B6BE-A200F20A2FB1}) (Version: 1.0.3010.0 - Microsoft Corporation) Microsoft Sync Framework SDK v1.0 SP1 de (HKLM\...\{03A4C6A1-26E9-4DDB-81D9-B332E5BB10AD}) (Version: 1.0.3010.0 - Microsoft Corporation) Microsoft Sync Framework Services v1.0 SP1 (x86) de (HKLM\...\{EAF7B35C-DCBE-4032-9ABF-C35C43D07124}) (Version: 1.0.3010.0 - Microsoft Corporation) Microsoft Sync Services for ADO.NET v2.0 SP1 (x86) de (HKLM\...\{D6A6CFAD-CD86-482B-90D1-6FCC4E252ACD}) (Version: 2.0.3010.0 - Microsoft Corporation) Microsoft Team Foundation Server 2010-Objektmodell - DEU (HKLM\...\Microsoft Team Foundation Server 2010 Object Model - DEU) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (HKLM\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual F# 2.0 Runtime (HKLM\...\{85467CBC-7A39-33C9-8940-D72D9269B84F}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual F# 2.0 Runtime Language Pack - DEU (HKLM\...\{681F4E9F-34E0-36BD-BF2C-100554E403A5}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM\...\{616C6F39-4CE1-3434-A665-2F6A04C09A7F}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Professional - DEU (HKLM\...\Microsoft Visual Studio 2010 Professional - DEU) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual Studio 2010 Service Pack 1 (HKLM\...\Microsoft Visual Studio 2010 Service Pack 1) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio Macro Tools - DEU Language Pack (HKLM\...\Microsoft Visual Studio Macro Tools - DEU Language Pack) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual Studio Macro Tools (HKLM\...\Microsoft Visual Studio Macro Tools) (Version: 9.0.30729 - Microsoft Corporation) Mozilla Firefox 40.0.3 (x86 de) (HKLM\...\Mozilla Firefox 40.0.3 (x86 de)) (Version: 40.0.3 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 40.0.3.5716 - Mozilla) MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2721691) (HKLM\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Naviextras Toolbox (HKLM\...\Naviextras Toolbox) (Version: 3.18.3.412849 - NNG Llc.) Naviextras Toolbox Prerequesities (HKLM\...\{537575D6-3B96-474C-BD8F-DFF667363DBD}) (Version: 1.0.0 - NNG Llc.) Nero MediaHome 4 Essentials (HKLM\...\{a71473b2-24eb-4ece-9780-89cd6715d45f}) (Version: - Nero AG) Nvu 1.0 (HKLM\...\Nvu_is1) (Version: 1.0 - Thorsten Fritz) Online Plug-in (Version: 14.2.0.10 - Citrix Systems, Inc.) Hidden Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden PC Connectivity Solution (HKLM\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia) PC-Küche - Kochen mit Gewinn! (HKLM\...\{DD434FBF-171B-41CA-BCFC-841F97CD6CEE}_is1) (Version: PC-Küche - Kochen mit Gewinn! - Fenz-Software GmbH) PDF Settings CS6 (Version: 11.0 - Adobe Systems Incorporated) Hidden pdfFactory Pro (HKLM\...\pdfFactory Pro) (Version: 5.05 - FinePrint Software, LLC) PhotoScape (HKLM\...\PhotoScape) (Version: - ) PhraseExpress v10.5.8 (HKLM\...\PhraseExpress_is1) (Version: 10.5.8 - Bartels Media GmbH) Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.) PL-2303 USB-to-Serial (HKLM\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.3.0 - Prolific Technology INC) QuickTime 7 (HKLM\...\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.) Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.37.1229.2010 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6235 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.52 - Piriform) Self-Service Plug-in (Version: 4.2.0.2495 - Citrix Systems, Inc.) Hidden Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft) Service Pack 1 für SQL Server 2008 (KB 968369) (HKLM\...\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Sicherheitsupdate für Microsoft Visual Studio 2010 Professional - DEU (KB2645410) (HKLM\...\{CAD6AA29-9CA1-384D-8034-566261CFCC9B}.KB2645410) (Version: 1 - Microsoft Corporation) Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM\...\SLABCOMM&10C4&EA60) (Version: - ) Silicon Laboratories USBXpress Device (Driver Removal) (HKLM\...\SIUSBXP&10C4&EA61) (Version: - ) Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-3390348399-1428350702-574305813-1141\...\Spotify) (Version: 1.0.3.101.gbfa97dfe - Spotify AB) Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.) Sql Server Customer Experience Improvement Program (Version: 10.1.2531.0 - Microsoft Corporation) Hidden TeamViewer 9 (HKLM\...\TeamViewer 9) (Version: 9.0.41110 - TeamViewer) TeraCopy 2.1 (HKLM\...\TeraCopy_is1) (Version: - Code Sector Inc.) ThinPrint Cloud Printer Connector 1.0 (HKLM\...\{5BACB8AA-9255-4AC8-9FFC-578E860AB9E3}) (Version: 1.0.70 - Cortado AG) Unterstützungsdateien für Microsoft SQL Server 2008-Setup (HKLM\...\{9AA2D735-3375-42D4-9A61-3FFEF82599D6}) (Version: 10.1.2731.0 - Microsoft Corporation) Update for Skype for Business 2015 (KB2889853) 32-Bit Edition (HKLM\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{0C5B0539-7EDE-4297-947E-48890971B557}) (Version: - Microsoft) UseNeXT by Tangysoft (HKLM\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden VirtualCloneDrive (HKLM\...\VirtualCloneDrive) (Version: - Elaborate Bytes) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (HKLM\...\{CFCB8616-A5D1-4281-80E8-389F685BFAE2}) (Version: 4.0.8080.0 - Microsoft Corporation) VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN) VLTools 2011 version 1.0.0 (HKLM\...\{A6A7BDAC-1652-4589-827F-2F1CC4428430}_is1) (Version: 1.0.0 - Digifly Europe) WCF RIA Services V1.0 SP1 (HKLM\...\{D9E6001A-5DC3-4620-AF7A-80B6CD48645D}) (Version: 4.1.60114.0 - Microsoft Corporation) WD Quick View (HKLM\...\{847C1E81-8A3F-49BF-8FF0-189E56634656}) (Version: 2.4.12.1 - Western Digital Technologies, Inc.) WD SmartWare (HKLM\...\{3E58F4A2-D474-4476-9C2A-9ED2E9FF39C9}) (Version: 2.4.12.1 - Western Digital Technologies, Inc.) WD SmartWare Installer (HKLM\...\{979a4332-3eb0-4561-9f74-a4fb871cf2bd}) (Version: 2.4.12.1 - Western Digital Technologies, Inc.) Weather Display 10.37R Build 81 (HKLM\...\Weather Display_is1) (Version: - ) WeatherLink 5.9.2 (HKLM\...\{C7C88E00-129D-4A91-96A0-4338B41A6A48}) (Version: 5.9.2 - Davis Instruments Corp.) WeatherLink 6.0.0 (HKLM\...\{B985ED85-0666-4FF7-B8F6-D34E8BAB9FC9}) (Version: 6.0.0 - Davis Instruments Corp.) WeatherLink 6.0.2 (HKLM\...\{9026FBC7-84E7-44A5-BC2F-1F509DFA0314}) (Version: 6.0.2 - Davis Instruments Corp.) WeatherLink 6.0.3 (HKLM\...\{AEFAC1C0-6CDF-4289-A0B4-A61262FCA39A}) (Version: 6.0.3 - Davis Instruments Corp.) Web Deployment Tool (HKLM\...\{0F37D969-1260-419E-B308-EF7D29ABDE20}) (Version: 1.1.0618 - Microsoft Corporation) Wichtiges Update für Microsoft Visual Studio 2010 Professional - DEU (KB2938807) (HKLM\...\{CAD6AA29-9CA1-384D-8034-566261CFCC9B}.KB2938807) (Version: 1 - Microsoft Corporation) Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) WinRAR 4.11 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.25.5\psuser.dll Keine Datei CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{0FEB2313-F89B-4AC6-8153-84025604A06A}\InprocServer32 -> C:\Program Files\TNT2\TNT2UserPS.dll Keine Datei CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.27.5\psuser.dll Keine Datei CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.28.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.28.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\michael.HHBKK\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{39125640-8D80-11DC-A2FE-C5C455D89593}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Google Talk Plugin\googletalkax.dll (Google) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.28.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{554EBE31-AEC1-4E34-BCE3-606467760D88}\localserver32 -> "C:\Users\michael.HHBKK\AppData\Local\TNT2\2.0.0.1950\TNT2User.exe" Keine Datei CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.28.1\psuser.dll Keine Datei CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.28.13\psuser.dll Keine Datei CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\michael.HHBKK\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.24.15\psuser.dll Keine Datei CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\michael.HHBKK\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{AB9F4455-E591-4132-A386-0B91EAEDB96C}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Google Talk Plugin\o1dax.dll (Google) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\michael.HHBKK\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\michael.HHBKK\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.26.9\psuser.dll Keine Datei CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.25.11\psuser.dll Keine Datei CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll Keine Datei CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.28.15\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.28.15\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.28.15\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{EC5A86F7-7664-4D4E-B795-D45A57CB394B}\InprocServer32 -> C:\Program Files\TNT2\2.0.0.1950\ietoolbar.dll Keine Datei CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Google\Update\1.3.24.7\psuser.dll Keine Datei CustomCLSID: HKU\S-1-5-21-3390348399-1428350702-574305813-1141_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\michael.HHBKK\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.) ==================== Wiederherstellungspunkte ========================= ==================== Hosts Inhalt: ========================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:04 - 2015-09-15 07:50 - 00450825 ____R C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123fporn.info 127.0.0.1 www.123fporn.info 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123moviedownload.com Da befinden sich 1000 zusätzliche Einträge. ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {06BBBEA6-9C31-4058-8B78-4C0A7D5EDCA2} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2015-08-04] (Oracle Corporation) Task: {1D707D4D-F55F-4E60-8695-CABA5BF18825} - System32\Tasks\{4EE70FA4-0893-4AD7-8865-86313110A569} => pcalua.exe -a C:\Users\michael.HHBKK\Vario\Digifly\DIGIFLY_NEXTGEN_USB_Driver\Windows\PL2303_Prolific_DriverInstaller_v1417.exe -d C:\Users\michael.HHBKK\Vario\Digifly\DIGIFLY_NEXTGEN_USB_Driver\Windows Task: {1DB8FB05-90EC-4D1A-94F4-D42A83ED0CA3} - System32\Tasks\{E04E1F70-46FC-4261-88B9-7A2C4092B715} => pcalua.exe -a D:\setup.exe -d D:\ Task: {214800AD-D4A3-4925-8042-0B4CBDE1F4EE} - System32\Tasks\{F56D82BF-C8B9-48EC-8260-0AC4DFAF3BCA} => pcalua.exe -a E:\Programme\CompeGPS\unins000.exe -d E:\Programme\CompeGPS Task: {223A86DE-F524-4883-943F-5E8874327E0E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.) Task: {3A3AEFAF-0C04-4FF8-93AA-C482AE436389} - System32\Tasks\arp_flush => C:\Program Files\hide.me VPN\FlushArpCache.exe [2015-04-03] () Task: {3AC5F84F-5055-4167-B0BC-78DBBEE0E439} - System32\Tasks\{56F7DEBF-3819-4F3C-A18F-C1D72303F96C} => pcalua.exe -a "C:\Users\michael.HHBKK\Vario\Digifly\DIGIFLY_NEXTGEN_USB_Driver\DIGIFLY NEXTGEN-USB Driver\XP\Win_USB_Driver_Installer.exe" -d "C:\Users\michael.HHBKK\Vario\Digifly\DIGIFLY_NEXTGEN_USB_Driver\DIGIFLY NEXTGEN-USB Driver\XP" Task: {3B00FC58-8750-4219-81F5-6E1BF6C3E522} - System32\Tasks\Apple Diagnostics => C:\Program Files\Common Files\Apple\Internet Services\EReporter.exe [2015-04-26] (Apple Inc.) Task: {46FCAECF-CDB3-4330-A9E4-F495D08CAE2C} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {4F772E09-7A8F-4C0B-A418-6EDA66C74385} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {5B9EE364-6E31-4A1B-9233-2236294CCB1A} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {62EE64EA-BC22-41C1-97DB-A923DFF37C32} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.) Task: {7E2425E8-B831-4BE5-8A9B-B68BA437B502} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {7F854375-61B1-42BB-8F37-4F581000792E} - System32\Tasks\Microsoft\Windows\SyncCenter\S-1-5-21-3390348399-1428350702-574305813-1141\{750FDF10-2A26-11D1-A3EA-080036587F03}\Offlinedateien-Synchronisierungszeitplan 1 => C:\Windows\system32\mobsync.exe [2010-11-20] (Microsoft Corporation) Task: {7FB49A05-4292-4D71-B880-D562EA583E11} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.) Task: {9BCEBABC-3158-4C50-AA2E-2754FF521C37} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated) Task: {9E236B16-7327-4D30-98BB-67652D738F13} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {A8C1AE2C-B37B-4847-AB7D-4BD4C2E18A24} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.) Task: {AF8E4B0E-E562-4463-9157-7AF1017F2A7C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {B5523A1B-AEB4-422E-A843-C29173342E29} - System32\Tasks\Google Updater and Installer => C:\Users\michael.HHBKK\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {C6A60622-4017-40E1-A1FC-4046FA82C4D3} - System32\Tasks\DivX-Online-Aktualisierungsprogramm => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2015-06-27] (DivX, LLC) Task: {DC7015A3-1BAD-4195-9AF3-00EDC68F797C} - System32\Tasks\{DE373307-D43F-438E-BB33-ED9C9AC4EDA3} => pcalua.exe -a C:\Users\michael.HHBKK\Downloads\DirectFromPC_Vue_3_00.exe -d C:\Users\michael.HHBKK\Downloads Task: {DDD36B48-4A8A-49CD-B351-3247A5B68361} - System32\Tasks\{68A34CCA-DB86-4724-88DB-CC5AF3D6ADAE} => pcalua.exe -a C:\Users\michael.HHBKK\Downloads\SetupX.exe -d c:\progra~1\micros~2\office14 Task: {EEC48C9E-73E3-4311-8B08-E6C3C93D9087} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser Task: {FD72C31B-CB8B-4097-AC43-CD74816E85A6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3390348399-1428350702-574305813-1141Core1d0c1e8da05d7dc.job => C:\Users\michael.HHBKK\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390348399-1428350702-574305813-1141Core1cf8b5b7bf7a15d.job => C:\Users\michael.HHBKK\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390348399-1428350702-574305813-1141Core1cfea7da1b6f2c4.job => C:\Users\michael.HHBKK\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390348399-1428350702-574305813-1141Core1d0006ba480c3ed.job => C:\Users\michael.HHBKK\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390348399-1428350702-574305813-1141Core1d040812a6f03cd.job => C:\Users\michael.HHBKK\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390348399-1428350702-574305813-1141Core1d0922ca6f2ef9.job => C:\Users\michael.HHBKK\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390348399-1428350702-574305813-1141Core1d0bf46de533e29.job => C:\Users\michael.HHBKK\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390348399-1428350702-574305813-1141Core1d0e34881bd571b.job => C:\Users\michael.HHBKK\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390348399-1428350702-574305813-1141Core1d0f070238ba481.job => C:\Users\michael.HHBKK\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\TEMP:373E1720 AlternateDataStreams: C:\ProgramData\TEMP:A8ADE5D8 AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="1" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "UseAlternateShell"="1" ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com Da befinden sich 7867 mehr eingeschränkte Seiten. ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3390348399-1428350702-574305813-1141\Control Panel\Desktop\\Wallpaper -> C:\Users\michael.HHBKK\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: Datenträger ist nicht mit dem Internet verbunden. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\Services: FirebirdServerMAGIXInstance => 3 MSCONFIG\Services: FrameManager Service => 2 MSCONFIG\Services: NeroMediaHomeService.4 => 2 MSCONFIG\Services: ServiceLayer => 3 MSCONFIG\startupfolder: C:^Users^michael.HHBKK^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ja.lnk => C:\Windows\pss\ja.lnk.Startup ==================== FirewallRules (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{F475D713-6357-4688-90F2-ECA71AD15813}] => (Allow) C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{849645AE-CD20-4A03-B99A-E53BA8EDF520}] => (Allow) C:\Users\michael.HHBKK\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{A87A31FD-3012-469E-A926-FBAA278F2285}C:\protel\prot32.exe] => (Allow) C:\protel\prot32.exe FirewallRules: [UDP Query User{6F9B90C1-2BD1-424F-92CF-5C67A6FE4F50}C:\protel\prot32.exe] => (Allow) C:\protel\prot32.exe FirewallRules: [TCP Query User{93F0B8F7-0DB1-4482-9BC5-8BC59AA1439D}C:\users\michael.hhbkk\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\michael.hhbkk\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{38D328B3-638C-4B90-AFA7-F5583999638F}C:\users\michael.hhbkk\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\michael.hhbkk\appdata\roaming\spotify\spotify.exe FirewallRules: [{B0B11E39-33FD-49B5-8297-B6B64C4A335C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{5EE9891C-A780-49C4-8380-8BD5A2DD884E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{72D794C4-1AFD-4714-8E40-B6E8C3CB30A0}C:\program files\pc-küche - kochen mit gewinn!\kbk_gastro.exe] => (Allow) C:\program files\pc-küche - kochen mit gewinn!\kbk_gastro.exe FirewallRules: [UDP Query User{26E27095-5E6E-4AF0-882B-B74853598765}C:\program files\pc-küche - kochen mit gewinn!\kbk_gastro.exe] => (Allow) C:\program files\pc-küche - kochen mit gewinn!\kbk_gastro.exe FirewallRules: [TCP Query User{AD649A1D-8E74-4151-BE70-B5B42B45107F}C:\program files\mozilla firefox\plugin-container.exe] => (Allow) C:\program files\mozilla firefox\plugin-container.exe FirewallRules: [UDP Query User{3A558308-F6CC-4572-BFFA-F391B7C6F656}C:\program files\mozilla firefox\plugin-container.exe] => (Allow) C:\program files\mozilla firefox\plugin-container.exe FirewallRules: [TCP Query User{C3A3FC93-E518-4C9F-BA33-DCCFFB39F842}C:\program files\mozilla firefox\plugin-container.exe] => (Allow) C:\program files\mozilla firefox\plugin-container.exe FirewallRules: [UDP Query User{19377F42-7C68-4A52-8A8B-AFCAB99B99F9}C:\program files\mozilla firefox\plugin-container.exe] => (Allow) C:\program files\mozilla firefox\plugin-container.exe FirewallRules: [{A9CB7343-D924-45E9-A91E-6204D7048EDC}] => (Allow) C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe FirewallRules: [{E6C7FBED-5F60-4DF1-A3A7-4438AA404190}] => (Allow) C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe FirewallRules: [TCP Query User{955B00E1-2B3D-4988-B70C-B45DE9D269AC}C:\program files\pc-küche - kochen mit gewinn!\fernwartung.exe] => (Allow) C:\program files\pc-küche - kochen mit gewinn!\fernwartung.exe FirewallRules: [UDP Query User{2CCBA27E-C1E5-4E1F-9661-415FB2016C31}C:\program files\pc-küche - kochen mit gewinn!\fernwartung.exe] => (Allow) C:\program files\pc-küche - kochen mit gewinn!\fernwartung.exe FirewallRules: [{6D2D9BB5-D52D-4800-A9B9-BF16EFEE9772}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [TCP Query User{741190FF-90A8-4962-99E1-787BDA2E9EC8}\\harmsrv\wl\druckertreiber\ftp programm\ftpserv.exe] => (Allow) \\harmsrv\wl\druckertreiber\ftp programm\ftpserv.exe FirewallRules: [UDP Query User{8E129D60-236D-4AB4-95B1-3308397A58C9}\\harmsrv\wl\druckertreiber\ftp programm\ftpserv.exe] => (Allow) \\harmsrv\wl\druckertreiber\ftp programm\ftpserv.exe FirewallRules: [{241DED5D-6FEC-421C-91A5-C21A1B2BD01A}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{6EA03FB6-0284-4DE3-97F5-5DFDDE0BEE7C}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{BAFD0536-4CFF-4F02-AAD9-367119996E95}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{EE444EEE-7B2D-4AF2-9563-5C841F364995}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [TCP Query User{0E279456-8FD6-44CA-B638-F34DB941DB49}C:\users\michael.hhbkk\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\michael.hhbkk\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{C240C105-49D6-4F70-9AD2-8EA83C5AF200}C:\users\michael.hhbkk\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\michael.hhbkk\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{A7822B69-6DD5-4C66-876A-084467722A62}] => (Allow) C:\Users\michael.HHBKK\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{45BD5C7A-5C83-43D1-BBE1-19A2ACDE26D9}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [{0C733DE2-515D-4CE4-9AC8-8E12A91FD653}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe FirewallRules: [{14E5F82C-1277-486B-BD73-708BFDD13D02}] => (Allow) LPort=2869 FirewallRules: [{E4AD9802-5A7C-4C9F-A049-F81D9EDF0E91}] => (Allow) LPort=1900 FirewallRules: [TCP Query User{5373DBBC-3D9A-4251-B8B2-B627AF850707}C:\protel\prot32.exe] => (Block) C:\protel\prot32.exe FirewallRules: [UDP Query User{412653D2-88B8-43D4-B77B-B855FAC3A0B1}C:\protel\prot32.exe] => (Block) C:\protel\prot32.exe FirewallRules: [TCP Query User{9D28EE52-0715-4169-B4C6-71069BA4CF38}C:\users\michael.hhbkk\desktop\iphone\tinyumbrella-6.12.00.exe] => (Allow) C:\users\michael.hhbkk\desktop\iphone\tinyumbrella-6.12.00.exe FirewallRules: [UDP Query User{E2EF6BAC-8C4B-45D4-B668-00D0ED9165F0}C:\users\michael.hhbkk\desktop\iphone\tinyumbrella-6.12.00.exe] => (Allow) C:\users\michael.hhbkk\desktop\iphone\tinyumbrella-6.12.00.exe FirewallRules: [TCP Query User{CD200AA7-15E5-4825-B3D2-C3A34225BA8C}\\harmsrv\wl\druckertreiber\ftp programm\ftpserv.exe] => (Allow) \\harmsrv\wl\druckertreiber\ftp programm\ftpserv.exe FirewallRules: [UDP Query User{A8167896-3BB0-4E12-B891-2E8B75D1EEA6}\\harmsrv\wl\druckertreiber\ftp programm\ftpserv.exe] => (Allow) \\harmsrv\wl\druckertreiber\ftp programm\ftpserv.exe FirewallRules: [{23B46D7A-5F28-4CAC-BB8B-8FFDE65C20C7}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{82C8EDFA-1648-4234-9423-B32CC3F2D904}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{E9AE0E46-926A-4DB0-B000-63EAD6350248}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{B463D69A-0E96-4583-AE33-BD16F85239FB}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [TCP Query User{A1EADCF1-81A0-4BE0-B7D2-DDAD92EF3840}C:\users\michael.hhbkk\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\michael.hhbkk\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{7F49817C-B8E4-409D-8890-545015CE4EA2}C:\users\michael.hhbkk\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\michael.hhbkk\appdata\roaming\spotify\spotify.exe FirewallRules: [{96A0E5A9-CC7A-40F7-ABF8-780206461A20}] => (Allow) C:\Users\michael.HHBKK\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe FirewallRules: [{8994D22C-37C8-487A-A4BC-B7F365AB3793}] => (Allow) C:\Users\michael.HHBKK\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe FirewallRules: [TCP Query User{A45C26F4-E441-47D5-A702-141272652217}C:\users\michael.hhbkk\desktop\iphone\tinyumbrella-6.14.00(1).exe] => (Allow) C:\users\michael.hhbkk\desktop\iphone\tinyumbrella-6.14.00(1).exe FirewallRules: [UDP Query User{F8A2B393-E6E2-4032-87F6-B6C32A09CE2C}C:\users\michael.hhbkk\desktop\iphone\tinyumbrella-6.14.00(1).exe] => (Allow) C:\users\michael.hhbkk\desktop\iphone\tinyumbrella-6.14.00(1).exe FirewallRules: [TCP Query User{2F636FC8-1386-4DF6-A544-FB427CE059FA}C:\users\michael.hhbkk\desktop\iphone\tinyumbrella-7.00.00a.exe] => (Allow) C:\users\michael.hhbkk\desktop\iphone\tinyumbrella-7.00.00a.exe FirewallRules: [UDP Query User{69771D5C-6B43-4FFF-A0D1-E81132717029}C:\users\michael.hhbkk\desktop\iphone\tinyumbrella-7.00.00a.exe] => (Allow) C:\users\michael.hhbkk\desktop\iphone\tinyumbrella-7.00.00a.exe FirewallRules: [TCP Query User{54373991-544D-41B7-BC2F-176E21B14254}D:\easysetupassistant\archer c7\easysetupassistant.exe] => (Allow) D:\easysetupassistant\archer c7\easysetupassistant.exe FirewallRules: [UDP Query User{97050B7F-02B7-43D2-BA59-8E371AA0CFFD}D:\easysetupassistant\archer c7\easysetupassistant.exe] => (Allow) D:\easysetupassistant\archer c7\easysetupassistant.exe FirewallRules: [TCP Query User{6152ADA6-D83E-43AA-9EED-D54F83A3BF9E}D:\easysetupassistant\archer c7\easysetupassistant.exe] => (Allow) D:\easysetupassistant\archer c7\easysetupassistant.exe FirewallRules: [UDP Query User{FE9F166E-D212-48AF-A24C-6B69F959E83C}D:\easysetupassistant\archer c7\easysetupassistant.exe] => (Allow) D:\easysetupassistant\archer c7\easysetupassistant.exe FirewallRules: [TCP Query User{4AB477CE-DD0F-412C-B37F-14A87A55143D}C:\users\michael.hhbkk\appdata\local\logmein client\logmein client.exe] => (Allow) C:\users\michael.hhbkk\appdata\local\logmein client\logmein client.exe FirewallRules: [UDP Query User{850BC625-4043-4B19-92EF-2BFADBF44DA9}C:\users\michael.hhbkk\appdata\local\logmein client\logmein client.exe] => (Allow) C:\users\michael.hhbkk\appdata\local\logmein client\logmein client.exe FirewallRules: [TCP Query User{CA59DEAB-D3D8-451B-BF04-1826E047ABDB}C:\program files\logmein\ignition\lmiignition.exe] => (Allow) C:\program files\logmein\ignition\lmiignition.exe FirewallRules: [UDP Query User{033E666D-5F31-4E30-B152-1D191D8D6094}C:\program files\logmein\ignition\lmiignition.exe] => (Allow) C:\program files\logmein\ignition\lmiignition.exe FirewallRules: [{90203210-4310-4390-9C72-BCD040B720F4}] => (Block) C:\program files\logmein\ignition\lmiignition.exe FirewallRules: [{009F03C6-91C5-4753-B4F4-22DF9E19D77A}] => (Block) C:\program files\logmein\ignition\lmiignition.exe FirewallRules: [{28F8B02B-906B-429B-8E94-344817D5A19D}] => (Allow) C:\Program Files\PhraseExpress\PhraseExpress.exe FirewallRules: [{0149686C-F1D1-4C4F-AF30-8CE484146673}] => (Allow) C:\Program Files\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{3835F3DE-393B-4FF5-89E3-4DFDAD30C200}] => (Allow) C:\Program Files\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{30FF68B3-7BBC-4E23-BE76-D0813433B034}] => (Allow) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [{7D861E8E-4F56-4701-8F57-8C99033ACEDC}] => (Allow) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [{D882803B-879F-41FB-997F-DEF94AA7E381}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{6E90E44A-AF94-45BF-999A-A202B15D98D7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{251F0AAB-D489-432F-9209-B45090F0D484}] => (Allow) C:\Users\michael.HHBKK\AppData\Local\TNT2\2.0.0.1950\TNT2User.exe FirewallRules: [{35B76B1C-F5E6-4BD1-A293-FED4385F3D6C}] => (Allow) C:\Program Files\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{7B9B95D3-2241-4290-B8AC-D9E47944DD35}] => (Allow) C:\Program Files\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{6C089555-C787-4D34-BB47-7C1A74A5605C}] => (Allow) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [{68D6FB66-1D08-45EB-9545-76E25FA2FE4C}] => (Allow) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [TCP Query User{04904572-2ACA-4EAD-AFA4-DEDB2BC50EE7}C:\users\michael.hhbkk\appdata\local\temp\kmsnano\qemu-system-i386.exe] => (Allow) C:\users\michael.hhbkk\appdata\local\temp\kmsnano\qemu-system-i386.exe FirewallRules: [UDP Query User{F44B843C-185F-4680-80A2-FD098DE6B500}C:\users\michael.hhbkk\appdata\local\temp\kmsnano\qemu-system-i386.exe] => (Allow) C:\users\michael.hhbkk\appdata\local\temp\kmsnano\qemu-system-i386.exe FirewallRules: [{298A4440-A059-4181-8A0D-7EA8BD7A3476}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{EE8257A0-6738-4DC5-99F8-A51CEB19A269}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{8040600D-7913-488F-B7BF-F2A0ADCD57C4}] => (Allow) C:\Program Files\iTunes\iTunes.exe StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Security Processor Loader Driver Description: Security Processor Loader Driver Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: spldr Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (09/22/2015 08:13:48 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x80070422). Error: (09/21/2015 10:43:31 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: iTunes.exe, Version: 12.3.0.44, Zeitstempel: 0x55f8bb3b Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0xf2c010b2 ID des fehlerhaften Prozesses: 0x129c Startzeit der fehlerhaften Anwendung: 0xiTunes.exe0 Pfad der fehlerhaften Anwendung: iTunes.exe1 Pfad des fehlerhaften Moduls: iTunes.exe2 Berichtskennung: iTunes.exe3 Error: (09/21/2015 06:55:01 PM) (Source: Cloud Print Service) (EventID: 1) (User: ) Description: Jabber channel error: Unexpected disconnect. Error: (09/21/2015 06:53:38 PM) (Source: Cloud Print Service) (EventID: 1) (User: ) Description: Jabber channel error: Unexpected disconnect. Error: (09/21/2015 12:41:08 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: WeatherLink 6.0.3.exe, Version: 5.9.0.0, Zeitstempel: 0x50be7629 Name des fehlerhaften Moduls: WeatherLink 6.0.3.exe, Version: 5.9.0.0, Zeitstempel: 0x50be7629 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0010025e ID des fehlerhaften Prozesses: 0x1f1c Startzeit der fehlerhaften Anwendung: 0xWeatherLink 6.0.3.exe0 Pfad der fehlerhaften Anwendung: WeatherLink 6.0.3.exe1 Pfad des fehlerhaften Moduls: WeatherLink 6.0.3.exe2 Berichtskennung: WeatherLink 6.0.3.exe3 Error: (09/21/2015 11:06:59 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Beschreibung = Geplanter Prüfpunkt; Fehler = 0x80070422). Error: (09/21/2015 09:43:45 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: VueUpdater_3_0_original.exe, Version: 1.0.0.1, Zeitstempel: 0x4fa07657 Name des fehlerhaften Moduls: VueUpdater_3_0_original.exe, Version: 1.0.0.1, Zeitstempel: 0x4fa07657 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00002969 ID des fehlerhaften Prozesses: 0x1964 Startzeit der fehlerhaften Anwendung: 0xVueUpdater_3_0_original.exe0 Pfad der fehlerhaften Anwendung: VueUpdater_3_0_original.exe1 Pfad des fehlerhaften Moduls: VueUpdater_3_0_original.exe2 Berichtskennung: VueUpdater_3_0_original.exe3 Error: (09/21/2015 09:43:21 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: VueUpdater_3_0_original.exe, Version: 1.0.0.1, Zeitstempel: 0x4fa07657 Name des fehlerhaften Moduls: VueUpdater_3_0_original.exe, Version: 1.0.0.1, Zeitstempel: 0x4fa07657 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00002969 ID des fehlerhaften Prozesses: 0x10c8 Startzeit der fehlerhaften Anwendung: 0xVueUpdater_3_0_original.exe0 Pfad der fehlerhaften Anwendung: VueUpdater_3_0_original.exe1 Pfad des fehlerhaften Moduls: VueUpdater_3_0_original.exe2 Berichtskennung: VueUpdater_3_0_original.exe3 Error: (09/21/2015 09:39:17 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: WeatherLink 6.0.3.exe, Version: 5.9.0.0, Zeitstempel: 0x50be7629 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x04523083 ID des fehlerhaften Prozesses: 0x1ea4 Startzeit der fehlerhaften Anwendung: 0xWeatherLink 6.0.3.exe0 Pfad der fehlerhaften Anwendung: WeatherLink 6.0.3.exe1 Pfad des fehlerhaften Moduls: WeatherLink 6.0.3.exe2 Berichtskennung: WeatherLink 6.0.3.exe3 Error: (09/21/2015 08:19:07 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x80070422). Systemfehler: ============= Error: (09/22/2015 03:58:10 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "PnP-X-IP-Busenumerator" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (09/22/2015 03:58:10 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Cloud Print for Windows Service" ist vom Dienst "Druckwarteschlange" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (09/22/2015 03:56:10 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: AFD CSC DfsC discache ElbyCDIO MpFilter NetBIOS NetBT nsiproxy Psched rdbss spldr tdx vwififlt Wanarpv6 WfpLwf Error: (09/22/2015 03:56:10 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "NLA (Network Location Awareness)" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (09/22/2015 03:56:10 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "Microsoft Network Inspection System" ist vom Dienst "Microsoft Malware Protection Driver" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%31 Error: (09/22/2015 03:56:10 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "SQL Server (SQLEXPRESS)" ist vom Dienst "Anmeldedienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (09/22/2015 03:56:10 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "SMB 2.0-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (09/22/2015 03:56:10 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "SMB 1.x-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (09/22/2015 03:56:10 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "SMB-Miniredirector-Wrapper und -Modul" ist vom Dienst "Umgeleitetes Puffersubsystem" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%31 Error: (09/22/2015 03:56:10 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Der Dienst "IP-Hilfsdienst" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 ==================== Memory info =========================== Processor: Intel(R) Pentium(R) CPU G850 @ 2.90GHz Prozentuale Nutzung des RAM: 16% Installierter physikalischer RAM: 3299.14 MB Verfügbarer physikalischer RAM: 2741.13 MB Summe virtueller Speicher: 6596.59 MB Verfügbarer virtueller Speicher: 6082.05 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:101.6 GB) NTFS Drive e: () (Fixed) (Total:200.7 GB) (Free:52.22 GB) NTFS Drive f: (Volume) (Fixed) (Total:265.06 GB) (Free:229.82 GB) NTFS Drive g: () (Removable) (Total:3.94 GB) (Free:1.56 GB) FAT32 ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0FB60D76) Partition 1: (Active) - (Size=102 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: 13762A9F) Partition 1: (Active) - (Size=200.7 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=265.1 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows XP) (Size: 4 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=4 GB) - (Type=0B) ==================== Ende vom Addition.txt ============================ |
23.09.2015, 09:21 | #4 | |
/// the machine /// TB-Ausbilder | akm trojaner ergebnisZitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu akm trojaner ergebnis |
.dll, administrator, bonjour, defender, desktop, dnsapi.dll, explorer, flash player, google, homepage, iexplore.exe, mozilla, programme, prozesse, realtek, registry, scan, security, software, svchost.exe, system, temp, trojaner, usb, whatsapp, windows, winlogon.exe |