|
Log-Analyse und Auswertung: Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
03.12.2015, 08:56 | #1 |
| Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? Hi, ich bin hin und wieder auf der Seite Schönerfernsehen.com unterwegs , erstmal schön und gut (wie man's nimmt ). Das Problem ist, ich bekomme seit ca. 3 Tagen ständig eine URL:Mal-Warnung von Avast sobald ich auf einen anderen Sender wechsle. URL: hxxp://sda.vidcore.tv/crossdomain.xml Infektion: URL:Mal Prozess: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Weder Avast noch Malwarebyte erkennen das bei einem Scan, trotzdem bekomme ich die Warnung von Avast sofort nach einem Senderwechsel. Ich habe nichts weiter versucht, vielleicht würde eine Firefox-Neuinstallation helfen. Danke schon mal im Voraus. |
03.12.2015, 10:57 | #2 |
/// the machine /// TB-Ausbilder | Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
04.12.2015, 02:12 | #3 |
| Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? Tut mir leid, eigentlich wollte ich den ersten Beitrag editieren und keinen neuen machen.
__________________FRST Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:01-12-2015 durchgeführt von Eldin (Administrator) auf ELDIN-PC (05-12-2015 01:55:59) Gestartet von C:\Users\Eldin\Desktop Geladene Profile: Eldin (Verfügbare Profile: Eldin & Gast) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Nenad Hrg SoftwareOK.de / SoftwareOK.com ) C:\Program Files (x86)\DesktopSchneeFree\DesktopSchneeFree.exe () C:\Program Files (x86)\KWorld Multimedia\HyperMediaCenter\DTVR\Scheduled.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Malwarebytes) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520 2015-10-12] (NVIDIA Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-16] (Apple Inc.) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-11-19] (Intel Corporation) HKLM-x32\...\Run: [Center Agent] => C:\Program Files (x86)\KWorld Multimedia\HyperMediaCenter\DTVR\Scheduled.exe [867840 2006-10-05] () HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-10-13] (Apple Inc.) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2013536 2014-05-10] (Wondershare) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6133520 2015-11-07] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\beKEY: HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\Run: [DS3 Tool] => C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe [110352 2011-01-01] (www.motioninjoy.com) HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8551848 2015-10-19] (Piriform Ltd) HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\Run: [DesktopSchneeFree] => C:\Program Files (x86)\DesktopSchneeFree\DesktopSchneeFree.exe [450048 2010-01-15] (Nenad Hrg SoftwareOK.de / SoftwareOK.com ) HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1763166945-3058576130-879148785-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\VIDEOWLP.SCR ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-10-09] (AVAST Software) CHR HKU\S-1-5-21-1763166945-3058576130-879148785-1001\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{43A4DED4-692B-4843-817C-860D7A0BD3E8}: [NameServer] 192.168.0.1,8.8.8.8 Tcpip\..\Interfaces\{43A4DED4-692B-4843-817C-860D7A0BD3E8}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1763166945-3058576130-879148785-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} HKU\S-1-5-21-1763166945-3058576130-879148785-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006 SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-1763166945-3058576130-879148785-1001 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-1763166945-3058576130-879148785-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-1763166945-3058576130-879148785-1001 -> {530F9655-665C-4D2E-905F-33F3AEBB9775} URL = SearchScopes: HKU\S-1-5-21-1763166945-3058576130-879148785-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2015-05-05] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-07] (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-05-05] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-07] (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Keine Datei Toolbar: HKLM - Kein Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Keine Datei Toolbar: HKU\S-1-5-21-1763166945-3058576130-879148785-1001 -> Kein Name - {FCA68881-E0E4-44CA-824D-2AF348BB5D3E} - Keine Datei StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537 FF DefaultSearchUrl: hxxps://www.google.com/search/?trackid=sp-006 FF SearchEngineOrder.1: Google (avast) FF SelectedSearchEngine: Yahoo! FF Homepage: hxxp://google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-12] () FF Plugin: @java.com/DTPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-05-05] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2015-05-05] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-12] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin HKU\S-1-5-21-1763166945-3058576130-879148785-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Eldin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-08] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-1763166945-3058576130-879148785-1001: bebomedia.com/OfferMosquitoIEHelper -> C:\Users\Eldin\AppData\Local\ext_offermosquito\npOfferMosquitoIEHelper.dll [Keine Datei] FF Plugin HKU\S-1-5-21-1763166945-3058576130-879148785-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [Keine Datei] FF user.js: detected! => C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\user.js [2015-06-22] FF SearchPlugin: C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\searchplugins\google-avast.xml [2015-02-24] FF Extension: Rikaichan Japanese-German Dictionary File - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\rikaichan-jpde@polarcloud.com [2015-08-20] FF Extension: Rikaichan Japanese-English Dictionary File - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\rikaichan-jpen@polarcloud.com [2015-08-20] FF Extension: Rikaichan - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\{0AA9101C-D3C1-4129-A9B7-D778C6A17F82} [2015-05-28] FF Extension: Black Youtube Theme - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\{2c93446d-612b-416d-9af0-b7355797b611}.xpi [2015-09-20] FF Extension: WOT - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-11-10] FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-10-09] [ist nicht signiert] FF Extension: ADB Helper - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\Extensions\adbhelper@mozilla.org [2015-11-13] FF Extension: MEGA - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\Extensions\firefox@mega.co.nz.xpi [2015-11-23] [ist nicht signiert] FF Extension: Valence - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\Extensions\fxdevtools-adapters@mozilla.org [2015-10-21] FF Extension: Adblock Plus - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-26] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR Profile: C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-22] CHR Extension: (Google Docs) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-22] CHR Extension: (Google Drive) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-18] CHR Extension: (YouTube) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-27] CHR Extension: (Google-Suche) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-27] CHR Extension: (Avast SafePrice) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-11-27] CHR Extension: (Google Tabellen) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-22] CHR Extension: (Google Docs Offline) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-27] CHR Extension: (Avast Online Security) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-27] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-29] CHR Extension: (Google Mail) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-22] CHR Profile: C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Docs) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-27] CHR Extension: (Google Drive) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-27] CHR Extension: (YouTube) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-27] CHR Extension: (Google-Suche) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-27] CHR Extension: (Avast SafePrice) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-11-27] CHR Extension: (Google Docs Offline) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-27] CHR Extension: (Avast Online Security) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-27] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-27] CHR Extension: (Google Mail) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-27] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-04-03] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-03] CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Eldin\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx <nicht gefunden> ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-10-09] (AVAST Software) R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4048280 2015-10-09] (Avast Software) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384 2015-10-12] (NVIDIA Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [Datei ist nicht signiert] R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696 2015-10-12] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568288 2015-10-12] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-05-18] () R2 PowerBiosServer; c:\Program Files (x86)\Hotkey\PowerBiosServer.exe [35328 2012-05-22] () [Datei ist nicht signiert] R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [490496 2012-07-23] () [Datei ist nicht signiert] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 Ak27x64; C:\Windows\System32\DRIVERS\Ak27x64.sys [3364720 2012-07-23] (Qualcomm Atheros, Inc.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-10-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-10-09] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-10-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-10-09] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-07] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-07] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-10-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-10-09] (AVAST Software) S3 ATHDFU; C:\Windows\System32\Drivers\AthDfu.sys [51872 2012-02-13] (Windows (R) Win 7 DDK provider) [Datei ist nicht signiert] R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [66928 2012-07-23] (Qualcomm Atheros, Inc.) S3 BTATH_BUS; C:\Windows\system32\drivers\btath_bus.sys [30368 2012-02-13] (Atheros) [Datei ist nicht signiert] S3 BTATH_RCP; C:\Windows\system32\drivers\btath_rcp.sys [280992 2012-02-13] (Atheros) [Datei ist nicht signiert] R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-05-16] (Disc Soft Ltd) S3 E100B; C:\Windows\System32\DRIVERS\efe5b32e.sys [192256 2009-06-10] (Intel Corporation) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28216 2012-11-19] (Intel Corporation) S3 lehidmini; C:\Windows\system32\drivers\leath_hid.sys [36128 2012-02-13] (Atheros) [Datei ist nicht signiert] R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2015-12-05] (Malwarebytes) R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [132656 2015-10-09] (AVAST Software) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20768 2015-10-12] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.) R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [274336 2015-10-09] (Avast Software) S3 BTATH_HCRP; \SystemRoot\system32\drivers\btath_hcrp.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-12-05 01:55 - 2015-12-05 01:56 - 00023283 _____ C:\Users\Eldin\Desktop\FRST.txt 2015-12-05 01:32 - 2015-12-05 01:55 - 00000000 ____D C:\FRST 2015-12-05 01:30 - 2015-12-05 01:30 - 02350080 _____ (Farbar) C:\Users\Eldin\Desktop\FRST64.exe 2015-12-05 01:20 - 2015-12-05 01:20 - 00001175 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-12-05 01:20 - 2015-12-05 01:20 - 00001163 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-12-05 01:20 - 2015-12-05 01:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-12-05 01:19 - 2015-12-05 01:19 - 00243976 _____ C:\Users\Eldin\Downloads\Firefox Setup Stub 42.0.exe 2015-12-03 22:14 - 2015-12-03 22:14 - 00001316 _____ C:\Users\Eldin\Desktop\Creativerse.lnk 2015-12-03 21:35 - 2015-12-03 21:35 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software 2015-12-03 21:35 - 2015-12-03 21:35 - 00000000 ____D C:\Program Files\Common Files\AV 2015-12-03 07:08 - 2015-12-05 01:25 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-12-03 07:08 - 2015-12-03 21:29 - 00001112 _____ C:\Users\Public\Desktop\Malwarebyte.lnk 2015-12-03 07:08 - 2015-12-03 07:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-12-03 07:08 - 2015-12-03 07:08 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-12-03 07:08 - 2015-12-03 07:08 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-12-03 07:08 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-12-03 07:08 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-12-03 07:08 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2015-12-01 04:10 - 2015-12-01 04:47 - 00000000 ____D C:\Program Files (x86)\iExplorer 2015-12-01 04:10 - 2015-12-01 04:10 - 00000000 ____D C:\Users\Eldin\AppData\Local\Macroplant_LLC 2015-11-30 18:43 - 2015-11-30 18:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft 2015-11-27 02:27 - 2015-11-27 02:27 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\iPadian 2015-11-27 02:26 - 2015-11-27 02:33 - 00000000 ____D C:\Users\Eldin\AppData\Local\MalwareProtectionLive 2015-11-13 19:30 - 2015-11-03 18:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-11-12 02:27 - 2015-12-03 21:29 - 00000516 _____ C:\Users\Eldin\Desktop\Project64 - Verknüpfung.lnk 2015-11-12 02:10 - 2015-12-03 21:29 - 00001717 _____ C:\Users\Public\Desktop\iTunes.lnk 2015-11-12 02:10 - 2015-11-12 02:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Windows\System32\Tasks\Apple 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Program Files\iPod 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Program Files\Bonjour 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Program Files (x86)\Bonjour 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2015-11-12 01:55 - 2015-12-03 21:29 - 00000830 _____ C:\Users\Public\Desktop\CCleaner.lnk 2015-11-12 01:55 - 2015-11-12 01:55 - 00002790 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2015-11-12 01:55 - 2015-11-12 01:55 - 00000000 ____D C:\Program Files\CCleaner 2015-11-11 17:31 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-11-11 17:31 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-11-11 17:31 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-11-11 17:31 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-11-11 17:31 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-11-11 17:31 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-11-11 17:31 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-11-11 17:31 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-11-11 17:31 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-11-11 17:31 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-11-11 17:31 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-11-11 17:31 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-11-11 17:31 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-11-11 17:31 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-11-11 17:31 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-11-11 17:31 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-11-11 17:31 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-11-11 17:31 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-11-11 17:31 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-11-11 17:31 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-11-11 17:31 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-11-11 17:31 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-11-11 17:31 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-11-11 17:31 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-11-11 17:31 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-11-11 17:31 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-11-11 17:31 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-11-11 17:31 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-11-11 17:31 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-11-11 17:31 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-11-11 17:31 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-11-11 17:31 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2015-11-11 17:31 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-11-11 17:31 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-11-11 17:31 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-11-11 17:31 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-11-11 17:31 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-11-11 17:31 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-11-11 17:31 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-11-11 17:31 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-11-11 17:31 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-11-11 17:31 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-11-11 17:31 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-11-11 17:31 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-11-11 17:31 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-11-11 17:31 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-11-11 17:31 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-11-11 17:31 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-11-11 17:31 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-11-11 17:31 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-11-11 17:31 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-11-11 17:31 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-11-11 17:31 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2015-11-11 17:31 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-11-11 17:31 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-11-11 17:31 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-11-11 17:31 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-11-11 17:31 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-11-11 17:31 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-11-11 17:31 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-11-11 17:31 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-11-11 17:31 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-11-11 17:31 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-11-11 17:31 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-11-11 17:31 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-11-11 17:31 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-11-11 17:31 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-11-11 17:31 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-11-11 17:31 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-11-11 17:31 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-11-11 17:31 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-11-11 17:31 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-11-11 17:31 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-11-11 17:30 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2015-11-11 17:30 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll 2015-11-11 17:30 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe 2015-11-11 17:30 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll 2015-11-11 17:30 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll 2015-11-11 17:30 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll 2015-11-11 17:30 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe 2015-11-11 17:30 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-11-11 17:30 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-11-11 17:30 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-11-11 17:30 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-11-11 17:30 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-11-11 17:30 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-11-11 17:30 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-11-11 17:30 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-11-11 17:30 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-11-11 17:30 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-11-11 17:30 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-11-11 17:30 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-11-11 17:30 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-11-11 17:30 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-11-11 17:30 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-11-11 17:30 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-11-11 17:30 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-11-11 17:30 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-11-11 17:30 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-11-11 17:30 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-11-11 17:30 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-11-11 17:30 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2015-11-11 17:30 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-11-11 17:30 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-11-11 17:30 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-11-11 17:30 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-11-11 17:30 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2015-11-11 17:30 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2015-11-11 17:30 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2015-11-11 17:30 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2015-11-11 17:30 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll 2015-11-11 17:30 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2015-11-11 17:30 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-11-11 17:30 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll 2015-11-11 17:30 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll 2015-11-08 22:58 - 2015-11-08 22:58 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\fltk.org 2015-11-07 17:54 - 2015-11-07 17:54 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\project64 1.6 2015-11-07 17:52 - 1999-01-28 10:20 - 13893632 _____ C:\Users\Eldin\Desktop\Mario Kart 64.v64 ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-12-05 01:45 - 2014-09-07 21:21 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-12-05 01:45 - 2014-05-30 18:19 - 00003930 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896} 2015-12-05 01:41 - 2012-09-19 13:46 - 00000000 ____D C:\Windows 2015-12-05 01:41 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2015-12-05 01:20 - 2014-04-18 17:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-12-05 01:19 - 2013-04-06 13:25 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-12-05 00:45 - 2014-09-07 21:21 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-12-05 00:40 - 2014-09-07 21:21 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-12-05 00:40 - 2014-09-07 21:21 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-12-05 00:03 - 2009-07-14 05:45 - 00027936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-12-05 00:03 - 2009-07-14 05:45 - 00027936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-12-03 21:36 - 2011-04-12 08:43 - 00700622 _____ C:\Windows\system32\perfh007.dat 2015-12-03 21:36 - 2011-04-12 08:43 - 00150228 _____ C:\Windows\system32\perfc007.dat 2015-12-03 21:36 - 2009-07-14 06:13 - 01623690 _____ C:\Windows\system32\PerfStringBackup.INI 2015-12-03 21:30 - 2015-03-04 03:20 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2015-12-03 21:29 - 2015-10-23 16:15 - 00001077 _____ C:\Users\Public\Desktop\XMedia Recode.lnk 2015-12-03 21:29 - 2015-09-10 06:02 - 00000843 _____ C:\Users\Eldin\Desktop\MGS 5 - TPP.lnk 2015-12-03 21:29 - 2015-09-08 21:01 - 00000516 _____ C:\Users\Public\Desktop\Steam.lnk 2015-12-03 21:29 - 2015-09-04 06:16 - 00002088 _____ C:\Users\Eldin\Desktop\Resident Evil 4.lnk 2015-12-03 21:29 - 2015-08-07 17:53 - 00001930 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-12-03 21:29 - 2015-06-20 16:00 - 00001309 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk 2015-12-03 21:29 - 2015-02-22 07:35 - 00001237 _____ C:\Users\Eldin\Desktop\TreeSize Free.lnk 2015-12-03 21:29 - 2014-11-14 01:20 - 00000742 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anki.lnk 2015-12-03 21:29 - 2014-09-08 01:59 - 00002238 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-12-03 21:29 - 2014-07-01 04:42 - 00000919 _____ C:\Users\Eldin\Desktop\Dolphin.lnk 2015-12-03 21:29 - 2014-06-05 00:29 - 00012268 _____ C:\Users\Eldin\Desktop\Windows Media Center.lnk 2015-12-03 21:29 - 2014-06-02 01:46 - 00001076 _____ C:\Users\Public\Desktop\VLC media player.lnk 2015-12-03 21:29 - 2014-05-30 18:13 - 00001395 _____ C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-12-03 21:29 - 2014-05-16 00:42 - 00001960 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk 2015-12-03 21:29 - 2013-11-02 16:41 - 00002005 _____ C:\Users\Public\Desktop\DesktopSchneeFree.lnk 2015-12-03 21:29 - 2013-09-06 19:55 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2015-12-03 21:29 - 2013-08-02 00:49 - 00001773 _____ C:\Users\Eldin\Desktop\Snes9x.lnk 2015-12-03 21:29 - 2013-07-12 00:17 - 00001208 _____ C:\Users\Eldin\Desktop\On-Screen Keyboard.lnk 2015-12-03 21:29 - 2013-06-08 17:23 - 00001422 _____ C:\Users\Public\Desktop\Fraps.lnk 2015-12-03 21:29 - 2013-05-20 20:31 - 00001930 _____ C:\Users\Public\Desktop\DS3 Tool.lnk 2015-12-03 21:29 - 2013-05-14 14:28 - 00002645 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Final Draft Tagger 2.lnk 2015-12-03 21:29 - 2013-04-29 13:01 - 00002076 _____ C:\Users\Eldin\Desktop\Snipping Tool.lnk 2015-12-03 21:29 - 2013-04-29 12:47 - 00002201 _____ C:\Users\Eldin\Desktop\Portrait Professional 11 Test.lnk 2015-12-03 21:29 - 2013-04-29 12:31 - 00002304 _____ C:\Users\Eldin\Desktop\Winamp.lnk 2015-12-03 21:29 - 2013-04-29 12:07 - 00001925 _____ C:\Users\Eldin\Desktop\Musik.lnk 2015-12-03 21:29 - 2013-04-06 12:01 - 00002144 _____ C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk 2015-12-03 21:29 - 2013-04-06 12:00 - 00002538 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk 2015-12-03 21:29 - 2013-04-06 12:00 - 00001494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk 2015-12-03 21:29 - 2013-04-06 12:00 - 00001378 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk 2015-12-03 21:29 - 2013-04-03 06:49 - 00002423 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk 2015-12-03 21:29 - 2013-03-14 15:54 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2015-12-03 21:29 - 2013-03-14 15:54 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2015-12-03 21:29 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-12-03 21:29 - 2009-07-14 06:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk 2015-12-03 21:29 - 2009-07-14 05:57 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2015-12-03 21:29 - 2009-07-14 05:57 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk 2015-12-03 21:29 - 2009-07-14 05:57 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk 2015-12-03 21:29 - 2009-07-14 05:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk 2015-12-03 21:29 - 2009-07-14 05:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk 2015-12-03 21:29 - 2009-07-14 05:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk 2015-12-03 21:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\security 2015-12-03 07:56 - 2013-05-17 19:32 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2015-12-03 07:56 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-12-03 07:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SchCache 2015-12-01 02:34 - 2014-11-09 05:50 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\.minecraft 2015-11-30 04:40 - 2014-06-02 02:53 - 00000000 ____D C:\Users\Eldin\Desktop\True.Det 2015-11-30 04:26 - 2014-06-02 01:47 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\vlc 2015-11-27 02:54 - 2013-04-06 17:41 - 00000000 ____D C:\Users\Eldin\AppData\Local\CrashDumps 2015-11-21 18:32 - 2014-02-09 10:49 - 00000000 ___RD C:\Users\Eldin\Desktop\ボール 2015-11-17 23:01 - 2013-08-02 00:48 - 00000000 ____D C:\Snes9x 2015-11-14 13:54 - 2009-07-14 05:45 - 00297656 _____ C:\Windows\system32\FNTCACHE.DAT 2015-11-14 03:01 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2015-11-12 02:10 - 2013-09-06 19:56 - 00000000 ____D C:\Program Files\iTunes 2015-11-12 02:09 - 2013-09-06 19:56 - 00000000 ____D C:\Program Files (x86)\iTunes 2015-11-12 02:09 - 2013-09-06 19:55 - 00000000 ____D C:\Program Files\Common Files\Apple 2015-11-12 02:06 - 2013-04-06 13:25 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-11-12 02:06 - 2013-04-06 13:25 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-11-12 02:06 - 2013-04-06 13:25 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-11-12 01:57 - 2013-04-24 10:39 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\PhotoScape 2015-11-11 19:10 - 2013-08-14 21:31 - 00000000 ____D C:\Windows\system32\MRT 2015-11-11 19:08 - 2013-04-08 00:45 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-11-11 19:03 - 2013-03-14 16:51 - 01597970 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2015-11-11 19:03 - 2011-04-12 08:55 - 00000000 ____D C:\Program Files\Windows Journal 2015-11-11 18:19 - 2013-05-14 15:19 - 04699336 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2015-11-07 01:24 - 2015-03-04 03:20 - 01059656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2015-11-07 01:24 - 2015-03-04 03:20 - 00449992 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2013-04-06 14:22 - 2013-04-06 12:00 - 0000916 _____ () C:\Program Files\Install CameraRecorder.lnk 2013-04-06 14:22 - 2013-04-06 14:22 - 0000355 _____ () C:\Program Files\KeepSafe - Verknüpfung.lnk 2013-04-06 14:22 - 2013-04-06 14:22 - 0002248 _____ () C:\Program Files\Qualcomm Atheros Killer Network Manager (2).lnk 2013-04-06 14:22 - 2013-04-03 06:55 - 0002248 _____ () C:\Program Files\Qualcomm Atheros Killer Network Manager.lnk 2015-04-11 18:16 - 2015-04-11 18:16 - 0407972 _____ () C:\Program Files\Wordpad_2009_RC1.zip 2014-02-26 02:17 - 2014-02-27 23:19 - 0000117 _____ () C:\Users\Eldin\AppData\Roaming\D2Info0 2014-02-26 02:17 - 2014-02-26 04:38 - 0000008 _____ () C:\Users\Eldin\AppData\Roaming\DofusAppId0_1 2014-02-26 02:17 - 2014-02-27 23:19 - 0000008 _____ () C:\Users\Eldin\AppData\Roaming\DofusAppId0_2 2014-02-26 02:57 - 2014-02-26 04:08 - 0000008 _____ () C:\Users\Eldin\AppData\Roaming\DofusAppId0_3 2013-12-28 21:39 - 2014-01-04 01:39 - 0000071 _____ () C:\Users\Eldin\AppData\Roaming\WB.CFG 2015-10-22 03:28 - 2015-10-22 03:28 - 0000000 ___SH () C:\Users\Eldin\AppData\Local\LumaEmu 2015-05-11 19:00 - 2015-05-11 19:00 - 0002073 _____ () C:\Users\Eldin\AppData\Local\recently-used.xbel 2013-04-06 13:01 - 2013-04-06 13:05 - 111691960 _____ () C:\ProgramData\avast_free_antivirus_setup.exe 2013-04-07 01:52 - 2013-04-07 01:54 - 0774648 _____ (Google Inc.) C:\ProgramData\ChromeSetup.exe 2014-04-22 06:59 - 2014-07-04 06:53 - 0028157 _____ () C:\ProgramData\dxdiag.txt 2013-05-14 14:26 - 2013-05-14 14:27 - 41230322 _____ () C:\ProgramData\finaldraft_802.zip 2013-04-06 13:15 - 2013-04-06 13:15 - 20904728 _____ (Mozilla) C:\ProgramData\Firefox Setup 20.0.exe 2013-04-07 13:00 - 2013-04-07 13:00 - 62405680 _____ (Anthropics Technology Ltd. ) C:\ProgramData\PortraitProfessionalTrialSetup_en_de_fr.exe 2013-04-09 21:46 - 2013-04-09 21:46 - 5693485 _____ (XMedia Recode ) C:\ProgramData\XMediaRecode3154_setup.exe Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\ProgramData\avast_free_antivirus_setup.exe C:\ProgramData\ChromeSetup.exe C:\ProgramData\Firefox Setup 20.0.exe C:\ProgramData\PortraitProfessionalTrialSetup_en_de_fr.exe C:\ProgramData\XMediaRecode3154_setup.exe C:\Users\Eldin\setup.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-11-22 06:56 ==================== Ende von FRST.txt ============================ Addition Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:01-12-2015 durchgeführt von Eldin (2015-12-05 01:56:18) Gestartet von C:\Users\Eldin\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2013-04-06 11:01:00) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1763166945-3058576130-879148785-500 - Administrator - Disabled) Eldin (S-1-5-21-1763166945-3058576130-879148785-1001 - Administrator - Enabled) => C:\Users\Eldin Gast (S-1-5-21-1763166945-3058576130-879148785-501 - Limited - Disabled) => C:\Users\Gast.Eldin-PC HomeGroupUser$ (S-1-5-21-1763166945-3058576130-879148785-1407 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) 7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 19.0.0.241 - Adobe Systems Incorporated) Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated) Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated) Anki (HKLM-x32\...\Anki) (Version: - ) Apple Application Support (32-Bit) (HKLM-x32\...\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.) Apple Application Support (64-Bit) (HKLM\...\{0DE0A178-AC7B-4650-806C-CF226DE03766}) (Version: 4.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.4.2233 - AVAST Software) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.11 - Piriform) Creativerse (HKLM-x32\...\Steam App 280790) (Version: - Playful Corporation) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) DesktopSchneeFree (HKLM-x32\...\DesktopSchneeFree) (Version: - ) EAX4 Unified Redist (HKLM-x32\...\{89661B04-C646-4412-B6D3-5E19F02F1F37}) (Version: 4.001 - Creative Labs) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Feature Update Service (YFD) (HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\YourFileDownloaderUpdater) (Version: 1.4.0 - ) <==== ACHTUNG Final Draft (HKLM-x32\...\{7C3C895B-AE02-4F30-8A6A-051D37A38DD0}) (Version: 8.0.2.118 - Final Draft, Inc.) Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.73 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden Hotkey 6.0058 (HKLM-x32\...\InstallShield_{164714B6-46BC-4649-9A30-A6ED32F03B5A}) (Version: 6.0058 - NoteBook) Hotkey 6.0058 (x32 Version: 6.0058 - NoteBook) Hidden HyperMediaCenter (HKLM-x32\...\{AE9C8073-B7CA-4BE3-BC3A-8797109343BE}) (Version: 1.0 - ) Intel(R) Driver Update Utility 2.0 (x32 Version: 2.0.0.29 - Intel) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.7.0.1013 - Intel Corporation) Intel® Driver Update Utility (HKLM-x32\...\{8409c4f7-2340-4933-a304-5d37db4fb48b}) (Version: 2.0.0.29 - Intel) iTunes (HKLM\...\{E690A491-702F-4DEC-9977-C015D1DBB57C}) (Version: 12.3.1.23 - Apple Inc.) Java 7 Update 80 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417080FF}) (Version: 7.0.800 - Oracle) Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden KWorld EM_USB Device Utilities (HKLM-x32\...\{55D8440D-6577-46DC-9571-8E5E3046AC11}) (Version: 3.0.0.0 - ) Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE (HKLM-x32\...\{F97E3841-CA9D-4964-9D64-26066241D26F}) (Version: 3.3.24.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{8FB1B528-E260-451E-9B55-E9152F94B80B}) (Version: 3.2.3.0 - Microsoft Corporation) Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation) Microsoft SkyDrive (HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\SkyDriveSetup.exe) (Version: 17.0.2006.0314 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Minecraft Version 1.8.4 (HKLM-x32\...\Minecraft_is1) (Version: 1.8.4 - Mojang) MotioninJoy ds3 driver version 0.6.0003 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.5.0001 - www.motioninjoy.com) Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 42.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0 - Mozilla) NVIDIA GeForce Experience 2.5.15.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.15.54 - NVIDIA Corporation) NVIDIA Grafiktreiber 358.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 358.50 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) OpenOffice.org 3.4.1 (HKLM-x32\...\{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}) (Version: 3.41.9593 - Apache Software Foundation) PhotoScape (HKLM-x32\...\PhotoScape) (Version: - ) PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) Portrait Professional 11.2 Test (HKLM-x32\...\PortraitProfessional11Trial_is1) (Version: 11.2 - Anthropics Technology Ltd.) Project64 1.6 (HKLM-x32\...\{9559F7CA-5E34-4237-A2D9-D856464AD727}) (Version: 1.6 - Project64) Qualcomm Atheros Killer Network Manager (HKLM-x32\...\InstallShield_{DF446558-ADF7-4884-9B2D-281979CCE71F}) (Version: 6.1.0.395 - Qualcomm Atheros) Qualcomm Atheros Killer Network Manager (Version: 6.1.0.395 - Qualcomm Atheros) Hidden Rapture3D 2.3.22 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6804 - Realtek Semiconductor Corp.) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.27015 - Realtek Semiconductor Corp.) Scrivener (HKLM-x32\...\Scrivener 1720) (Version: 1720 - Literature and Latte) SHIELD Streaming (Version: 4.1.500 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.5.15.54 - NVIDIA Corporation) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.4.0 - Synaptics Incorporated) TreeSize Free V3.3 (HKLM-x32\...\TreeSize Free_is1) (Version: 3.3 - JAM Software) Unity Web Player (HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Value Apps (x32 Version: 2.2.7.11 - Perion) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) VoiceOver Kit (HKLM-x32\...\{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}) (Version: 1.42.128.0 - Apple Inc.) Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) XMedia Recode Version 3.2.6.3 (HKLM-x32\...\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.2.6.3 - XMedia Recode) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Wiederherstellungspunkte ========================= 24-11-2015 17:56:31 Windows-Sicherung 27-11-2015 22:56:26 Windows Update 30-11-2015 03:23:18 Windows-Sicherung 03-12-2015 02:07:31 Windows Update ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {024141BA-1DA0-457D-9A1E-1D1D4CDFC308} - System32\Tasks\ValueAppsGUI => C:\Users\Eldin\AppData\Local\ValueApps\ValueAppsGUI.exe Task: {09835802-4A3F-4AF9-9D84-40909475BE69} - System32\Tasks\{64F19AC2-152D-463E-A9DB-817FE2FC73E0} => pcalua.exe -a "D:\Resident Evil 4\SetupTool.exe" -d "D:\Resident Evil 4" Task: {151BF93C-D8EE-4D5A-B552-8EE0654F5B5E} - System32\Tasks\{A569009C-F900-41B5-8BC3-E826F88B9778} => pcalua.exe -a C:\Users\Eldin\Desktop\RFG_Portal\Portal.exe -d C:\Users\Eldin\Desktop\RFG_Portal Task: {1CC82FEA-7F32-4749-A889-9F0D22A888C1} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1763166945-3058576130-879148785-1001 Task: {1D8A5EF8-F36F-42D1-8043-A235C022B952} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {24469E4E-8752-44E5-AC21-82152925BCBE} - System32\Tasks\{6D6BEB90-1B47-4B92-A512-3C7A79F5B280} => pcalua.exe -a "C:\Program Files (x86)\KWorld Multimedia\Uninstallation\QuickInstall.exe" -d "C:\Program Files (x86)\KWorld Multimedia\Uninstallation" Task: {2A09661D-15B7-46D4-B066-C3A8351B4B11} - \MySearchDial -> Keine Datei <==== ACHTUNG Task: {3A0C53B1-5867-42E4-B49C-2B8FADA3EBE5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.) Task: {3F4EC249-0ECF-4B57-9CA8-B82801D8845F} - System32\Tasks\FileAssociationManagerUpdater => C:\Program Files (x86)\FileAssociationManager\Updater.exe Task: {4235A71E-A2AF-4728-98B0-8E1B7EEE3295} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {5FBA8A8A-5D12-45AD-A9F4-D6DDDEE39A71} - System32\Tasks\{69977A5F-9A9C-4518-BA30-67E34B33DB12} => pcalua.exe -a C:\Users\Eldin\Downloads\jxpiinstall(1).exe -d C:\Users\Eldin\Downloads Task: {73CFD178-FA49-42F6-9F1E-0180F998F85E} - \Plus-HD-5.0-codedownloader -> Keine Datei <==== ACHTUNG Task: {7A8002CC-AFB0-423F-9D51-21D7DA5F646E} - \Plus-HD-5.0-updater -> Keine Datei <==== ACHTUNG Task: {7EB80EF4-608E-4FF1-A59B-0FE8409BA563} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-12] (Adobe Systems Incorporated) Task: {9F5CC07D-8B29-4DB7-9B5F-111DCBA29BF6} - \Advanced System Protector -> Keine Datei <==== ACHTUNG Task: {B13CF115-F013-4BE4-A51F-E814E066EFEF} - System32\Tasks\{9B4EF299-DE9E-460F-B45B-879166117861} => pcalua.exe -a C:\Users\Eldin\Downloads\jxpiinstall.exe -d C:\Users\Eldin\Downloads Task: {B5CC04F6-1997-4B84-AA12-9358D4A9BCCE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-10-19] (Piriform Ltd) Task: {C56EB804-93F4-42A3-94FC-E5F056AACEB0} - System32\Tasks\{AB6D510B-BBD6-4EED-8969-B599DC3AA41B} => pcalua.exe -a F:\DirectX9\dxsetup.exe -d F:\DirectX9 Task: {C6BDF701-0D95-429C-A0CF-1EC194675CBF} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2015-12-03] (AVAST Software) Task: {C8133448-A027-4978-AC1F-9F6BA7045434} - \Plus-HD-5.0-chromeinstaller -> Keine Datei <==== ACHTUNG Task: {CF2839E4-08C0-4336-BA89-09EA09CB682C} - System32\Tasks\{5489C3DB-368B-4185-AB2A-BF312B44539F} => pcalua.exe -a D:\RFG_Portal\Portal.exe -d D:\RFG_Portal Task: {CFE05FA4-0CE2-4F83-8849-57FBE124E70F} - \Plus-HD-5.0-firefoxinstaller -> Keine Datei <==== ACHTUNG Task: {DF8CA373-256D-4B8B-8969-66110F13470B} - \Plus-HD-5.0-enabler -> Keine Datei <==== ACHTUNG Task: {F7B51997-8451-4088-AA04-101CEE241E65} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-10-09] (AVAST Software) (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Verknüpfungen ============================= (Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.) ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2013-04-03 06:46 - 2015-10-03 03:49 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-01-20 22:35 - 2015-01-20 22:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-10-13 05:45 - 2015-10-13 05:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-02-02 19:36 - 2014-05-18 02:00 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2012-05-22 15:50 - 2012-05-22 15:50 - 00035328 _____ () c:\Program Files (x86)\Hotkey\PowerBiosServer.exe 2012-07-23 15:36 - 2012-07-23 15:36 - 00490496 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe 2011-05-09 19:46 - 2011-05-09 19:46 - 02760192 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\QtCore4.dll 2011-05-09 19:56 - 2011-05-09 19:56 - 09856000 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\QtGui4.dll 2011-05-09 19:47 - 2011-05-09 19:47 - 00416256 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\QtXml4.dll 2012-07-23 15:36 - 2012-07-23 15:36 - 00217600 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFCommon.dll 2011-05-10 11:32 - 2011-05-10 11:32 - 00731648 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\qwt5.dll 2011-05-09 19:48 - 2011-05-09 19:48 - 00990720 _____ () C:\Program Files\Qualcomm Atheros\Killer Network Manager\QtNetwork4.dll 2015-09-10 07:58 - 2015-10-03 06:06 - 00011896 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2013-04-06 17:40 - 2006-10-05 21:13 - 00867840 _____ () C:\Program Files (x86)\KWorld Multimedia\HyperMediaCenter\DTVR\Scheduled.exe 2015-10-19 21:00 - 2015-10-19 21:00 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2015-10-09 22:40 - 2015-10-09 22:40 - 00103376 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-10-09 22:40 - 2015-10-09 22:40 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-12-03 02:03 - 2015-12-03 02:03 - 02813440 _____ () C:\Program Files\AVAST Software\Avast\defs\15120201\algo.dll 2015-12-03 21:30 - 2015-12-03 21:30 - 02802176 _____ () C:\Program Files\AVAST Software\Avast\defs\15120301\algo.dll 2015-05-14 18:04 - 2015-10-12 04:05 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2013-10-22 00:12 - 2015-10-03 06:06 - 00012080 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll 2013-04-06 17:40 - 2003-09-10 18:42 - 00045056 _____ () C:\Program Files (x86)\KWorld Multimedia\HyperMediaCenter\DTVR\kwspnd.dll 2014-06-22 13:11 - 2014-05-10 19:33 - 00411136 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll 2014-06-22 13:11 - 2014-04-30 10:13 - 00137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll 2015-10-09 22:40 - 2015-10-09 22:40 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-01-23 16:19 - 2015-01-23 16:19 - 00016384 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\PSIClient\582f6038931a9b63060e663814d293d0\PSIClient.ni.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1763166945-3058576130-879148785-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 - 8.8.8.8 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: DesktopSchneeFree => "C:\Program Files (x86)\DesktopSchneeFree\DesktopSchneeFree.exe" -bg MSCONFIG\startupreg: DS3 Tool => C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe -mini MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\steam.exe" -silent MSCONFIG\startupreg: WinRoll => C:\Program Files (x86)\WinRoll\winroll.exe ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [TCP Query User{FCA961CB-5A67-442F-873B-FB218FB7BE4C}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe FirewallRules: [UDP Query User{C08927A8-8435-482E-8D39-5A555FDD443D}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe FirewallRules: [TCP Query User{0EEEA983-7998-4AAD-BEAE-00E1EF109331}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Block) C:\program files (x86)\mozilla firefox\plugin-container.exe FirewallRules: [UDP Query User{8E13F896-3B6C-4F3E-B1F9-6542E43C48A7}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Block) C:\program files (x86)\mozilla firefox\plugin-container.exe FirewallRules: [{0DF84993-5357-4F4F-894F-7A557380A22A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{0509E0E4-B767-454A-BE00-45CA669D0594}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{D62A3BF5-FA16-4616-83FE-8BD247FFF063}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{7A11941D-9988-4CE3-B7EE-9958516E1798}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{33A33451-F49B-4102-A57A-6FCC977B7AFC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{A04EFF29-64E5-46AD-A0D2-B37F8AD46A26}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{48B19B62-DB56-4737-BA22-AAD11EF64E86}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{5DEBB56B-0E4D-4F53-8D16-43AB51FE6697}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{30574D47-1AD4-4F4A-8324-0A9426BCB567}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{F17D5EE9-A861-4C60-A1D3-565926305FB7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{B6D8572E-5130-4685-B48A-E869522654AF}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{F08219E0-7B53-421D-A5F6-63789FC33C04}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{F9892FBA-3CB1-40B4-9D15-FB96EDBA899C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{F86EBE47-E32D-4E32-9CB7-CC2422814689}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{F14B901D-4FE0-48C9-A966-D2E28A56C50A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{E315E41D-0EE6-4246-9428-D7FB5BBB4430}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{19C17ED4-8153-49BB-9C00-D6718568D8BA}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{DA59EEF4-49D9-4655-8F6C-695E352D527D}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{697F431C-B176-4459-855D-E1B388D2B033}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{AEC05F9E-9988-4017-A177-F169AAC3F285}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{489ABBAC-44CC-4F88-81F3-79D7699BB915}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe FirewallRules: [{8462F07D-519F-4648-8715-162E78292315}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe FirewallRules: [{B25D1578-E8F7-49EE-912F-53BF076B3269}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [{8B6F9606-B798-45FD-82B7-FDBBFBCED505}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [{6453819E-9421-4167-A6AB-4524D8AC92AD}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{F526322F-F4E8-49DB-82FA-0B4569A94009}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{51201809-2A95-4C02-B977-0159AF9D1133}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{1FD219E5-D4AF-4F83-8B88-09A8E9341A23}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{277E2225-26CA-4C0E-B65C-13EB65E7A25C}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{5F042D5A-2AA6-42FB-B049-B4D54F85D95D}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{774D6ED9-5441-4514-A556-1A9898872D02}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{F73A0B79-7E84-42BF-BF80-0F84B9CAE93C}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{5EBC4172-4B66-4868-96EF-519ACEF7B751}] => (Allow) C:\Program Files\Internet Explorer\iexplore.exe FirewallRules: [{C254FDF7-6622-47F2-9EE4-E2F10BD5CFAD}] => (Allow) C:\Program Files\Internet Explorer\iexplore.exe FirewallRules: [{43EE182B-06D8-43B6-8D75-C7674D66F69B}] => (Allow) C:\Program Files\Internet Explorer\iexplore.exe FirewallRules: [{AA80BF19-ABEE-41A6-847E-881AD8DE1943}] => (Allow) C:\Program Files\Internet Explorer\iexplore.exe FirewallRules: [{234E7FCF-8ADE-49DA-8968-AB288BDC84A0}] => (Allow) C:\Program Files\Internet Explorer\iexplore.exe FirewallRules: [{C98DA54D-D2A4-4BBA-9993-A32A7E19E2F0}] => (Allow) C:\Program Files\Internet Explorer\iexplore.exe FirewallRules: [{F41D429D-68D9-4479-B9A1-85D01CF9B1ED}] => (Allow) C:\Program Files\AVAST Software\Avast\AvastUI.exe FirewallRules: [{B985718B-96F7-4990-8CE8-7A9516152FAF}] => (Allow) C:\Program Files\AVAST Software\Avast\AvastUI.exe FirewallRules: [{63BAF9B3-2158-430F-AC7B-4DBD6BBD7036}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{6F37B88A-7272-4156-BEBB-3CB3E70C029F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{E73A7CD2-10EA-44B8-BF56-FD8948B5FD31}] => (Allow) C:\Program Files\Internet Explorer\iexplore.exe FirewallRules: [{1E45E018-BD6F-4334-99EC-965835FDED6D}] => (Allow) C:\Program Files\Internet Explorer\iexplore.exe FirewallRules: [{C2E5CF72-1E82-44F4-8E43-C2EB0D83AC11}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{E9C73D2F-C81D-4EB9-9C33-EC76605FFB10}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{10BA43D3-C0FA-4843-B30C-4C54501A2A96}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{21838E28-2088-4078-B059-66269B9BC439}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [TCP Query User{3F1A333D-2412-4ED4-9029-C4CA51F5B050}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{0F3444D5-7541-4AA6-87E9-812E678A51B0}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{48D4E6C8-766E-4AB3-ABBE-1845E8D37DCA}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{D4347378-263D-486D-A383-F9E6224A43FF}] => (Allow) LPort=2869 FirewallRules: [{ABC4DE25-42FB-449C-B560-8C7FFB2F6109}] => (Allow) LPort=1900 FirewallRules: [{57866CF8-2992-4BF3-8686-FC837699C38E}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{3F1C4064-2442-48FD-B3D9-6AE8D9E47C55}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{F3474B00-5ACF-4BF7-875D-203765E413FD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{26993B45-897A-4AB3-A8C1-5853D1300C6E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{2D1C17D8-2B8C-4437-8D26-ECA7B3CC2F8D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{8534BD05-6ADF-4197-B227-7A335234122F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{45E9F946-139B-42BE-BBDE-7314502C5D5B}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{CAC08939-581C-492A-A3B8-D3E117DD39FC}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{14477D2E-4641-4393-B89D-91E30DD0690E}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{2209F907-D72B-4C68-9A18-053C7F95C266}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{333FEF3D-C26E-4FF7-A0FC-DD0521BE7D27}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{582FD223-EDC1-419A-A1B7-CFC1FDCEFB8F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{D8BFB99E-EB82-4EB3-A70A-E6BA3580BD40}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{45DE2BF6-D2C4-4E08-9B86-6554DD36C578}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{4DC294B9-59F8-4136-9841-022F53D675CA}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [TCP Query User{44808DF1-E5B0-44CC-86F7-28579B82ADE8}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{49B05736-03C6-433C-8E61-4694A2C20708}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [{58F258FA-1BFD-4B4E-826C-24BAD690E10E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{96FB3649-BD42-4AB6-AE26-7522F3E2C4C6}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{E23BEFFD-6640-45DC-8AE6-630065489025}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{FE30AB7F-241B-4389-A7ED-A07C088C6267}] => (Allow) D:\Steam\steamapps\common\Creativerse\Creativerse.exe FirewallRules: [{50EBEA0E-4F4F-4077-8A95-C235C6B7AFEB}] => (Allow) D:\Steam\steamapps\common\Creativerse\Creativerse.exe FirewallRules: [{46A6E396-8E4E-4EE6-B532-49D625F62EE9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{20909B2C-02AB-4A29-AE88-2FEE541E0170}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: Microsoft Virtual WiFi Miniport Adapter Description: Microsoft Virtual WiFi Miniport Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: vwifimp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (12/03/2015 09:29:16 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/03/2015 07:30:50 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/03/2015 07:29:52 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/03/2015 02:03:04 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/01/2015 11:06:49 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/01/2015 11:06:11 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm javaw.exe, Version 7.0.800.15 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1534 Startzeit: 01d12c82cf169f56 Endzeit: 287 Anwendungspfad: C:\Program Files\Java\jre7\bin\javaw.exe Berichts-ID: 68fbe1ba-9877-11e5-ba11-0090f5e38b48 Error: (12/01/2015 10:50:19 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/01/2015 07:39:50 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/01/2015 02:06:36 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/30/2015 06:40:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Systemfehler: ============= Error: (12/03/2015 04:23:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/03/2015 04:23:37 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht. Error: (11/30/2015 04:25:52 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 30.11.2015 um 04:24:07 unerwartet heruntergefahren. Error: (11/29/2015 07:18:54 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 29.11.2015 um 07:17:16 unerwartet heruntergefahren. Error: (11/28/2015 07:19:43 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (11/17/2015 11:49:48 PM) (Source: Schannel) (EventID: 4119) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung empfangen: 20. Error: (11/12/2015 00:19:40 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (11/12/2015 00:19:40 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535. Error: (11/12/2015 04:34:50 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (11/12/2015 01:48:04 AM) (Source: Application Popup) (EventID: 877) (User: ) Description: Fehler [DATABASE OPEN FAILED] beim Verarbeiten der Treiberdatenbank. ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i7-3630QM CPU @ 2.40GHz Prozentuale Nutzung des RAM: 29% Installierter physikalischer RAM: 8082.2 MB Verfügbarer physikalischer RAM: 5714.14 MB Summe virtueller Speicher: 16162.61 MB Verfügbarer virtueller Speicher: 13726.36 MB ==================== Laufwerke ================================ Drive c: (System) (Fixed) (Total:160 GB) (Free:18.2 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)] Drive d: (Data) (Fixed) (Total:305.76 GB) (Free:46.86 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 87E3C604) Partition 1: (Active) - (Size=160 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=305.8 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ |
05.12.2015, 09:47 | #4 |
/// the machine /// TB-Ausbilder | Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.12.2015, 00:36 | #5 |
| Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? AdwCleaner Code:
ATTFilter # AdwCleaner v5.023 - Bericht erstellt am 06/12/2015 um 01:02:16 # Aktualisiert am 30/11/2015 von Xplode # Datenbank : 2015-12-03.1 [Server] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64) # Benutzername : Eldin - ELDIN-PC # Gestartet von : C:\Users\Eldin\Desktop\AdwCleaner_5.023.exe # Option : Löschen # Unterstützung : hxxp://toolslib.net/forum ***** [ Dienste ] ***** ***** [ Ordner ] ***** [-] Ordner Gelöscht : C:\Program Files (x86)\FileAssociationManager [-] Ordner Gelöscht : C:\Program Files (x86)\globalUpdate [-] Ordner Gelöscht : C:\Program Files (x86)\GreenTree Applications [-] Ordner Gelöscht : C:\Program Files (x86)\SerialTrunc [-] Ordner Gelöscht : C:\Program Files (x86)\DriverToolkit [-] Ordner Gelöscht : C:\Program Files (x86)\sAvae net [!] Ordner Nicht Gelöscht : C:\Program Files (x86)\sAvae net [-] Ordner Gelöscht : C:\ProgramData\SecTaskMan [-] Ordner Gelöscht : C:\ProgramData\sAvae net [!] Ordner Nicht Gelöscht : C:\ProgramData\sAvae net [-] Ordner Gelöscht : C:\ProgramData\24dfea5097b4b183 [-] Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileParade bundle uninstaller [-] Ordner Gelöscht : C:\Users\Eldin\AppData\Local\globalUpdate [-] Ordner Gelöscht : C:\Users\Eldin\AppData\Local\Media Get LLC [-] Ordner Gelöscht : C:\Users\Eldin\AppData\Local\MediaGet2 [-] Ordner Gelöscht : C:\Users\Eldin\AppData\Local\DriverToolkit [-] Ordner Gelöscht : C:\Users\Eldin\AppData\Local\MalwareProtectionLive [-] Ordner Gelöscht : C:\Users\Eldin\AppData\Roaming\FileAssociationManager [-] Ordner Gelöscht : C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaGet2 ***** [ Dateien ] ***** [-] Datei Gelöscht : C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\invalidprefs.js [-] Datei Gelöscht : C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\user.js [-] Datei Gelöscht : C:\Windows\SysNative\ValueApps.ini [-] Datei Gelöscht : C:\Windows\SysWOW64\ValueApps.ini ***** [ DLLs ] ***** ***** [ Verknüpfungen ] ***** ***** [ Aufgabenplanung ] ***** [-] Aufgabenplanung Gelöscht : FileAssociationManagerUpdater [-] Aufgabenplanung Gelöscht : ValueAppsGUI ***** [ Registrierungsdatenbank ] ***** [-] Schlüssel Gelöscht : HKCU\Software\MozillaPlugins\bebomedia.com/OfferMosquitoIEHelper [-] Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9} [-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [Plus-HD-5.0-bg.exe] [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F} [-] Schlüssel Gelöscht : HKCU\Software\Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED0D2C81-7DB5-4599-B7C0-1033418B5672} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{ED721A76-8160-4DA0-A18E-7FD7C4574774} [-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{444785F1-DE89-4295-863A-D46C3A781394} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ED0D2C81-7DB5-4599-B7C0-1033418B5672} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{02F878DF-E2BE-4B85-8CB4-A0D2D4E2ED7F} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2AF343DD-3102-4F9D-AC95-DCA4C95382C7} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3137BC14-D8D7-4B67-8FFA-2E0B2E9D541B} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4CA2AC92-971B-47B1-ACB6-357B552155AC} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{52C5395B-1FCD-47FA-A834-FD830701C2D5} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5D3DCC39-9233-4330-94E9-DA92BE49CA1A} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{615FACDF-DADB-440D-AC91-8AAB0AE9E3AD} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{762D463B-C45A-456D-A80D-8689C297C91E} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7A6BE473-7960-44D0-BD54-D23DA76353DF} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{803F550E-BAAE-42BB-8917-64BA0006AB17} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8D5BC51D-C9D3-43B9-B728-B30677B7C7E8} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{991C9D8D-A789-4DB9-BDFC-5F33398B04BF} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A5ACC874-D943-483F-A2D1-14598D51F872} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B0474212-0D9D-4361-90B3-B89D1A44275D} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BFDE183A-C6FE-41D2-80F9-586C29210AC2} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D83C83BF-3EDD-4410-ADAB-5295116DD8C7} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DD260902-9420-4055-A956-9152EB4F3E6A} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EB1F9F3C-5526-4DAE-BD4B-3EAA7715DA9F} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F1912128-469A-4138-AA26-9699C15BB13E} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F68DC16C-9C2B-455B-8853-7E4D34BAA3F4} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FBA8498F-B3A0-4942-A2BF-E0CB7BC7E000} [-] Schlüssel Gelöscht : HKCU\Software\GlobalUpdate [-] Schlüssel Gelöscht : HKCU\Software\OCS [-] Schlüssel Gelöscht : HKCU\Software\foxydeal [-] Schlüssel Gelöscht : HKCU\Software\DriverTuner_Init [-] Schlüssel Gelöscht : HKCU\Software\DriverTuner [-] Schlüssel Gelöscht : HKCU\Software\Condut [-] Schlüssel Gelöscht : HKCU\Software\DriverToolkit [-] Schlüssel Gelöscht : HKCU\Software\AppDataLow\foxydeal [-] Schlüssel Gelöscht : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252} [-] Schlüssel Gelöscht : HKLM\SOFTWARE\ValueApps [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ValueApps [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613} [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5 [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375 [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964 [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467 [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7 [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18C9E3869A16248439FE3FF9EB02207A [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D8011310B2622942868A458964FFDC5 [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C63F7979DCC2154CB9591969A5CB89D [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6DD31E6C1A73B334383DF186676F4D20 [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB3204F747B20694B8D49EF92D8DC94B [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C81E33A400B6F814E90C7A3354E2A3A5 [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDBF68C5F16790341B7C6FD7C7F8E4FC [-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFA531D0F3A71504DA7AC6A11CE33739 ***** [ Internetbrowser ] ***** [-] [C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\prefs.js] [Preference] Gelöscht : user_pref("plugin.state.npconduitfirefoxplugin", 0); ************************* :: "Tracing" Schlüssel gelöscht :: Proxy Einstellungen zurückgesetzt :: Winsock Einstellungen zurückgesetzt :: Chrome Richtlinien gelöscht ########## EOF - C:\AdwCleaner\AdwCleaner[C10].txt - [12780 Bytes] ########## JRT Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.0.1 (11.24.2015) Operating System: Windows 7 Home Premium x64 Ran by Eldin (Administrator) on 06.12.2015 at 1:12:07,86 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 5 Successfully deleted: C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\{0AA9101C-D3C1-4129-A9B7-D778C6A17F82} (Folder) Successfully deleted: C:\Windows\SysWOW64\REN13AF.tmp (File) Successfully deleted: C:\Windows\SysWOW64\REN7203.tmp (File) Successfully deleted: C:\Windows\SysWOW64\REN7473.tmp (File) Successfully deleted: C:\Windows\SysWOW64\RENF5D3.tmp (File) Registry: 4 Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{FCA68881-E0E4-44CA-824D-2AF348BB5D3E} (Registry Value) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (Registry Key) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{530F9655-665C-4D2E-905F-33F3AEBB9775} (Registry Key) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 06.12.2015 at 1:14:27,23 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-12-2015 durchgeführt von Eldin (Administrator) auf ELDIN-PC (06-12-2015 01:17:17) Gestartet von C:\Users\Eldin\Desktop Geladene Profile: Eldin (Verfügbare Profile: Eldin & Gast) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor) HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2757424 2015-11-12] (NVIDIA Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-16] (Apple Inc.) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-11-19] (Intel Corporation) HKLM-x32\...\Run: [Center Agent] => C:\Program Files (x86)\KWorld Multimedia\HyperMediaCenter\DTVR\Scheduled.exe [867840 2006-10-05] () HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-10-13] (Apple Inc.) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2013536 2014-05-10] (Wondershare) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-05] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\beKEY: HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\Run: [DS3 Tool] => C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe [110352 2011-01-01] (www.motioninjoy.com) HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8551848 2015-10-19] (Piriform Ltd) HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\Run: [DesktopSchneeFree] => C:\Program Files (x86)\DesktopSchneeFree\DesktopSchneeFree.exe [450048 2010-01-15] (Nenad Hrg SoftwareOK.de / SoftwareOK.com ) HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1763166945-3058576130-879148785-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\VIDEOWLP.SCR AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [177600 2015-11-25] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [155792 2015-11-25] (NVIDIA Corporation) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-05] (AVAST Software) CHR HKU\S-1-5-21-1763166945-3058576130-879148785-1001\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{43A4DED4-692B-4843-817C-860D7A0BD3E8}: [NameServer] 192.168.0.1,8.8.8.8 Tcpip\..\Interfaces\{43A4DED4-692B-4843-817C-860D7A0BD3E8}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1763166945-3058576130-879148785-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} HKU\S-1-5-21-1763166945-3058576130-879148785-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006 SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-1763166945-3058576130-879148785-1001 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-1763166945-3058576130-879148785-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2015-05-05] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-12-05] (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-05-05] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-05] (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Keine Datei Toolbar: HKLM - Kein Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Keine Datei StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537 FF DefaultSearchUrl: hxxps://www.google.com/search/?trackid=sp-006 FF SearchEngineOrder.1: Google (avast) FF SelectedSearchEngine: Yahoo! FF Homepage: hxxp://google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-12] () FF Plugin: @java.com/DTPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-05-05] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2015-05-05] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-12] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin HKU\S-1-5-21-1763166945-3058576130-879148785-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Eldin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-08] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-1763166945-3058576130-879148785-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [Keine Datei] FF SearchPlugin: C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\searchplugins\google-avast.xml [2015-02-24] FF Extension: Rikaichan Japanese-German Dictionary File - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\rikaichan-jpde@polarcloud.com [2015-08-20] FF Extension: Rikaichan Japanese-English Dictionary File - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\rikaichan-jpen@polarcloud.com [2015-08-20] FF Extension: Black Youtube Theme - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\{2c93446d-612b-416d-9af0-b7355797b611}.xpi [2015-09-20] FF Extension: WOT - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-12-05] FF Extension: ADB Helper - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\Extensions\adbhelper@mozilla.org [2015-11-13] FF Extension: Kein Name - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\Extensions\firefox@mega.co.nz.xpi [2015-11-23] [ist nicht signiert] FF Extension: Valence - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\Extensions\fxdevtools-adapters@mozilla.org [2015-10-21] FF Extension: Adblock Plus - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-26] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-05] FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-12-05] Chrome: ======= CHR Profile: C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-22] CHR Extension: (Google Docs) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-22] CHR Extension: (Google Drive) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-18] CHR Extension: (YouTube) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-27] CHR Extension: (Google-Suche) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-27] CHR Extension: (Avast SafePrice) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-11-27] CHR Extension: (Google Tabellen) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-22] CHR Extension: (Google Docs Offline) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-27] CHR Extension: (Avast Online Security) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-27] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-29] CHR Extension: (Google Mail) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-22] CHR Profile: C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Docs) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-27] CHR Extension: (Google Drive) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-27] CHR Extension: (YouTube) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-27] CHR Extension: (Google-Suche) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-27] CHR Extension: (Avast SafePrice) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-11-27] CHR Extension: (Google Docs Offline) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-27] CHR Extension: (Avast Online Security) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-27] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-27] CHR Extension: (Google Mail) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-27] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-12-05] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-05] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-05] (AVAST Software) R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [5561368 2015-12-05] (Avast Software) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156400 2015-11-12] (NVIDIA Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [Datei ist nicht signiert] R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872688 2015-11-12] (NVIDIA Corporation) R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8133424 2015-11-12] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5915440 2015-11-12] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-05-18] () R2 PowerBiosServer; c:\Program Files (x86)\Hotkey\PowerBiosServer.exe [35328 2012-05-22] () [Datei ist nicht signiert] R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [490496 2012-07-23] () [Datei ist nicht signiert] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 Ak27x64; C:\Windows\System32\DRIVERS\Ak27x64.sys [3364720 2012-07-23] (Qualcomm Atheros, Inc.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-05] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-05] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-05] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-05] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-05] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [450504 2015-12-05] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-05] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-05] (AVAST Software) S3 ATHDFU; C:\Windows\System32\Drivers\AthDfu.sys [51872 2012-02-13] (Windows (R) Win 7 DDK provider) [Datei ist nicht signiert] R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [66928 2012-07-23] (Qualcomm Atheros, Inc.) S3 BTATH_BUS; C:\Windows\system32\drivers\btath_bus.sys [30368 2012-02-13] (Atheros) [Datei ist nicht signiert] S3 BTATH_RCP; C:\Windows\system32\drivers\btath_rcp.sys [280992 2012-02-13] (Atheros) [Datei ist nicht signiert] R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-05-16] (Disc Soft Ltd) S3 E100B; C:\Windows\System32\DRIVERS\efe5b32e.sys [192256 2009-06-10] (Intel Corporation) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28216 2012-11-19] (Intel Corporation) S3 lehidmini; C:\Windows\system32\drivers\leath_hid.sys [36128 2012-02-13] (Atheros) [Datei ist nicht signiert] S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2015-12-05] (Malwarebytes) R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [147088 2015-12-05] (AVAST Software) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19760 2015-11-12] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.) R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [310904 2015-12-05] (Avast Software) S3 BTATH_HCRP; \SystemRoot\system32\drivers\btath_hcrp.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-12-06 01:17 - 2015-12-06 01:17 - 00021908 _____ C:\Users\Eldin\Desktop\FRST.txt 2015-12-06 01:16 - 2015-12-06 01:16 - 02369024 _____ (Farbar) C:\Users\Eldin\Desktop\FRST64.exe 2015-12-06 01:14 - 2015-12-06 01:14 - 00001489 _____ C:\Users\Eldin\Desktop\JRT.txt 2015-12-06 01:07 - 2015-12-06 01:07 - 01599336 _____ (Malwarebytes) C:\Users\Eldin\Desktop\JRT.exe 2015-12-06 01:00 - 2015-12-06 01:02 - 00000000 ____D C:\AdwCleaner 2015-12-06 00:57 - 2015-12-06 00:57 - 01736704 _____ C:\Users\Eldin\Desktop\AdwCleaner_5.023.exe 2015-12-06 00:51 - 2015-12-06 00:51 - 00003262 _____ C:\Windows\System32\Tasks\{EF3EFEEC-4BDC-4BDD-B6F9-9483E635F06C} 2015-12-06 00:22 - 2015-12-06 00:22 - 00001280 _____ C:\Users\Eldin\Desktop\Revo Uninstaller.lnk 2015-12-06 00:22 - 2015-12-06 00:22 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller 2015-12-06 00:22 - 2015-12-06 00:22 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2015-12-06 00:20 - 2015-12-06 00:20 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Eldin\Desktop\revosetup95.exe 2015-12-05 06:18 - 2015-12-05 08:19 - 00002157 _____ C:\Users\Eldin\Desktop\Minecraft.lnk 2015-12-05 04:02 - 2015-12-05 04:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2015-12-05 03:59 - 2015-12-05 03:59 - 00386096 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2015-12-05 03:59 - 2015-12-05 03:59 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr 2015-12-05 02:35 - 2015-12-05 02:35 - 00000000 ____D C:\Windows\SysWOW64\NV 2015-12-05 02:35 - 2015-12-05 02:35 - 00000000 ____D C:\Windows\system32\NV 2015-12-05 02:33 - 2015-11-25 00:10 - 42913912 _____ C:\Windows\system32\nvcompiler.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 37882488 _____ C:\Windows\SysWOW64\nvcompiler.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 22310008 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 18363696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 17516040 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 16553568 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 15717672 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 15122296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 14835872 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 13527248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 12770752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 12034248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 11131184 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-12-05 02:33 - 2015-11-25 00:10 - 02870392 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 02490488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 01905272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435906.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 01564792 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435906.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00877360 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00861816 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00689272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00673912 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00501056 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00467912 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00422056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00413816 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00388024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00369272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00151184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00031352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys 2015-12-05 02:28 - 2015-11-12 19:37 - 00112712 _____ C:\Windows\system32\NvRtmpStreamer64.dll 2015-12-05 01:32 - 2015-12-06 01:17 - 00000000 ____D C:\FRST 2015-12-05 01:20 - 2015-12-05 01:20 - 00001175 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-12-05 01:20 - 2015-12-05 01:20 - 00001163 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-12-05 01:20 - 2015-12-05 01:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-12-05 01:19 - 2015-12-05 01:19 - 00243976 _____ C:\Users\Eldin\Downloads\Firefox Setup Stub 42.0.exe 2015-12-03 21:35 - 2015-12-03 21:35 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software 2015-12-03 21:35 - 2015-12-03 21:35 - 00000000 ____D C:\Program Files\Common Files\AV 2015-12-03 07:08 - 2015-12-05 08:18 - 00002032 _____ C:\Users\Public\Desktop\Malwarebyte.lnk 2015-12-03 07:08 - 2015-12-05 01:25 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-12-03 07:08 - 2015-12-03 07:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-12-03 07:08 - 2015-12-03 07:08 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-12-03 07:08 - 2015-12-03 07:08 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-12-03 07:08 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-12-03 07:08 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-12-03 07:08 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2015-12-01 04:10 - 2015-12-01 04:47 - 00000000 ____D C:\Program Files (x86)\iExplorer 2015-12-01 04:10 - 2015-12-01 04:10 - 00000000 ____D C:\Users\Eldin\AppData\Local\Macroplant_LLC 2015-11-30 18:43 - 2015-11-30 18:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft 2015-11-27 02:27 - 2015-11-27 02:27 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\iPadian 2015-11-13 19:30 - 2015-11-03 18:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-11-12 02:27 - 2015-12-03 21:29 - 00000516 _____ C:\Users\Eldin\Desktop\Project64 - Verknüpfung.lnk 2015-11-12 02:10 - 2015-12-03 21:29 - 00001717 _____ C:\Users\Public\Desktop\iTunes.lnk 2015-11-12 02:10 - 2015-11-12 02:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Windows\System32\Tasks\Apple 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Program Files\iPod 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Program Files\Bonjour 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Program Files (x86)\Bonjour 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2015-11-12 01:55 - 2015-12-03 21:29 - 00000830 _____ C:\Users\Public\Desktop\CCleaner.lnk 2015-11-12 01:55 - 2015-11-12 01:55 - 00002790 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2015-11-12 01:55 - 2015-11-12 01:55 - 00000000 ____D C:\Program Files\CCleaner 2015-11-11 17:31 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-11-11 17:31 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-11-11 17:31 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-11-11 17:31 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-11-11 17:31 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-11-11 17:31 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-11-11 17:31 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-11-11 17:31 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-11-11 17:31 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-11-11 17:31 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-11-11 17:31 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-11-11 17:31 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-11-11 17:31 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-11-11 17:31 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-11-11 17:31 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-11-11 17:31 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-11-11 17:31 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-11-11 17:31 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-11-11 17:31 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-11-11 17:31 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-11-11 17:31 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-11-11 17:31 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-11-11 17:31 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-11-11 17:31 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-11-11 17:31 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-11-11 17:31 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-11-11 17:31 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-11-11 17:31 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-11-11 17:31 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-11-11 17:31 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-11-11 17:31 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-11-11 17:31 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2015-11-11 17:31 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-11-11 17:31 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-11-11 17:31 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-11-11 17:31 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-11-11 17:31 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-11-11 17:31 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-11-11 17:31 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-11-11 17:31 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-11-11 17:31 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-11-11 17:31 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-11-11 17:31 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-11-11 17:31 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-11-11 17:31 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-11-11 17:31 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-11-11 17:31 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-11-11 17:31 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-11-11 17:31 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-11-11 17:31 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-11-11 17:31 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-11-11 17:31 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-11-11 17:31 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2015-11-11 17:31 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-11-11 17:31 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-11-11 17:31 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-11-11 17:31 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-11-11 17:31 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-11-11 17:31 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-11-11 17:31 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-11-11 17:31 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-11-11 17:31 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-11-11 17:31 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-11-11 17:31 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-11-11 17:31 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-11-11 17:31 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-11-11 17:31 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-11-11 17:31 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-11-11 17:31 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-11-11 17:31 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-11-11 17:31 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-11-11 17:31 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-11-11 17:31 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-11-11 17:31 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-11-11 17:30 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2015-11-11 17:30 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll 2015-11-11 17:30 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe 2015-11-11 17:30 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll 2015-11-11 17:30 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll 2015-11-11 17:30 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll 2015-11-11 17:30 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe 2015-11-11 17:30 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-11-11 17:30 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-11-11 17:30 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-11-11 17:30 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-11-11 17:30 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-11-11 17:30 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-11-11 17:30 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-11-11 17:30 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-11-11 17:30 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-11-11 17:30 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-11-11 17:30 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-11-11 17:30 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-11-11 17:30 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-11-11 17:30 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-11-11 17:30 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-11-11 17:30 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-11-11 17:30 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-11-11 17:30 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-11-11 17:30 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-11-11 17:30 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-11-11 17:30 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-11-11 17:30 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2015-11-11 17:30 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-11-11 17:30 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-11-11 17:30 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-11-11 17:30 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-11-11 17:30 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2015-11-11 17:30 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2015-11-11 17:30 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2015-11-11 17:30 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2015-11-11 17:30 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll 2015-11-11 17:30 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2015-11-11 17:30 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-11-11 17:30 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll 2015-11-11 17:30 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll 2015-11-08 22:58 - 2015-11-08 22:58 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\fltk.org 2015-11-07 17:54 - 2015-11-07 17:54 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\project64 1.6 ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-12-06 01:11 - 2009-07-14 05:45 - 00027936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-12-06 01:11 - 2009-07-14 05:45 - 00027936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-12-06 01:09 - 2011-04-12 08:43 - 00700622 _____ C:\Windows\system32\perfh007.dat 2015-12-06 01:09 - 2011-04-12 08:43 - 00150228 _____ C:\Windows\system32\perfc007.dat 2015-12-06 01:09 - 2009-07-14 06:13 - 01623690 _____ C:\Windows\system32\PerfStringBackup.INI 2015-12-06 01:09 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2015-12-06 01:05 - 2014-05-30 18:19 - 00003930 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896} 2015-12-06 01:03 - 2014-09-07 21:21 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-12-06 01:03 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-12-06 00:45 - 2014-09-07 21:21 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-12-06 00:19 - 2013-04-06 13:25 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-12-05 22:38 - 2014-11-10 03:09 - 00000000 ____D C:\Windows\SysWOW64\vbox 2015-12-05 22:38 - 2014-11-10 03:09 - 00000000 ____D C:\Windows\system32\vbox 2015-12-05 22:36 - 2015-03-04 03:20 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2015-12-05 08:19 - 2013-04-29 12:56 - 00000000 ____D C:\ProgramData\Icons 2015-12-05 07:13 - 2014-11-09 05:50 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\.minecraft 2015-12-05 06:13 - 2014-06-02 02:53 - 00000000 ____D C:\Users\Eldin\Desktop\True.Det 2015-12-05 04:02 - 2013-05-01 01:37 - 00000000 ____D C:\Program Files\7-Zip 2015-12-05 03:59 - 2015-07-22 02:09 - 00147088 _____ (AVAST Software) C:\Windows\system32\Drivers\ngvss.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 01055560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00450504 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00273784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00155304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys 2015-12-05 03:59 - 2012-09-19 13:46 - 00000000 ____D C:\Windows 2015-12-05 02:35 - 2013-04-06 17:41 - 00000000 ____D C:\Users\Eldin\AppData\Local\CrashDumps 2015-12-05 02:35 - 2013-04-03 06:46 - 00000000 ____D C:\ProgramData\NVIDIA 2015-12-05 02:28 - 2014-01-08 03:59 - 00000000 ____D C:\Users\Eldin\AppData\Local\NVIDIA Corporation 2015-12-05 01:20 - 2014-04-18 17:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-12-05 00:40 - 2014-09-07 21:21 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-12-05 00:40 - 2014-09-07 21:21 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-12-03 21:29 - 2015-10-23 16:15 - 00001077 _____ C:\Users\Public\Desktop\XMedia Recode.lnk 2015-12-03 21:29 - 2015-09-10 06:02 - 00000843 _____ C:\Users\Eldin\Desktop\MGS 5 - TPP.lnk 2015-12-03 21:29 - 2015-09-04 06:16 - 00002088 _____ C:\Users\Eldin\Desktop\Resident Evil 4.lnk 2015-12-03 21:29 - 2015-08-07 17:53 - 00001930 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-12-03 21:29 - 2015-06-20 16:00 - 00001309 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk 2015-12-03 21:29 - 2015-02-22 07:35 - 00001237 _____ C:\Users\Eldin\Desktop\TreeSize Free.lnk 2015-12-03 21:29 - 2014-11-14 01:20 - 00000742 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anki.lnk 2015-12-03 21:29 - 2014-09-08 01:59 - 00002238 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-12-03 21:29 - 2014-07-01 04:42 - 00000919 _____ C:\Users\Eldin\Desktop\Dolphin.lnk 2015-12-03 21:29 - 2014-06-05 00:29 - 00012268 _____ C:\Users\Eldin\Desktop\Windows Media Center.lnk 2015-12-03 21:29 - 2014-06-02 01:46 - 00001076 _____ C:\Users\Public\Desktop\VLC media player.lnk 2015-12-03 21:29 - 2014-05-30 18:13 - 00001395 _____ C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-12-03 21:29 - 2014-05-16 00:42 - 00001960 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk 2015-12-03 21:29 - 2013-11-02 16:41 - 00002005 _____ C:\Users\Public\Desktop\DesktopSchneeFree.lnk 2015-12-03 21:29 - 2013-09-06 19:55 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2015-12-03 21:29 - 2013-08-02 00:49 - 00001773 _____ C:\Users\Eldin\Desktop\Snes9x.lnk 2015-12-03 21:29 - 2013-07-12 00:17 - 00001208 _____ C:\Users\Eldin\Desktop\On-Screen Keyboard.lnk 2015-12-03 21:29 - 2013-06-08 17:23 - 00001422 _____ C:\Users\Public\Desktop\Fraps.lnk 2015-12-03 21:29 - 2013-05-20 20:31 - 00001930 _____ C:\Users\Public\Desktop\DS3 Tool.lnk 2015-12-03 21:29 - 2013-05-14 14:28 - 00002645 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Final Draft Tagger 2.lnk 2015-12-03 21:29 - 2013-04-29 13:01 - 00002076 _____ C:\Users\Eldin\Desktop\Snipping Tool.lnk 2015-12-03 21:29 - 2013-04-29 12:47 - 00002201 _____ C:\Users\Eldin\Desktop\Portrait Professional 11 Test.lnk 2015-12-03 21:29 - 2013-04-29 12:31 - 00002304 _____ C:\Users\Eldin\Desktop\Winamp.lnk 2015-12-03 21:29 - 2013-04-29 12:07 - 00001925 _____ C:\Users\Eldin\Desktop\Musik.lnk 2015-12-03 21:29 - 2013-04-06 12:01 - 00002144 _____ C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk 2015-12-03 21:29 - 2013-04-06 12:00 - 00002538 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk 2015-12-03 21:29 - 2013-04-06 12:00 - 00001494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk 2015-12-03 21:29 - 2013-04-06 12:00 - 00001378 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk 2015-12-03 21:29 - 2013-04-03 06:49 - 00002423 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk 2015-12-03 21:29 - 2013-03-14 15:54 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2015-12-03 21:29 - 2013-03-14 15:54 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2015-12-03 21:29 - 2009-07-14 06:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk 2015-12-03 21:29 - 2009-07-14 05:57 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2015-12-03 21:29 - 2009-07-14 05:57 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk 2015-12-03 21:29 - 2009-07-14 05:57 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk 2015-12-03 21:29 - 2009-07-14 05:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk 2015-12-03 21:29 - 2009-07-14 05:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk 2015-12-03 21:29 - 2009-07-14 05:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk 2015-12-03 21:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\security 2015-12-03 07:56 - 2013-05-17 19:32 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2015-12-03 07:56 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-12-03 07:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SchCache 2015-11-30 04:26 - 2014-06-02 01:47 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\vlc 2015-11-25 00:10 - 2015-09-10 07:58 - 03579696 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2015-11-25 00:10 - 2015-09-10 07:58 - 03159248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2015-11-25 00:10 - 2012-10-29 18:45 - 00177600 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2015-11-25 00:10 - 2012-10-29 18:45 - 00155792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2015-11-25 00:10 - 2012-10-29 18:45 - 00033607 _____ C:\Windows\system32\nvinfo.pb 2015-11-24 19:40 - 2013-04-03 06:46 - 06358648 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2015-11-24 19:40 - 2013-04-03 06:46 - 02983032 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2015-11-24 19:40 - 2013-04-03 06:46 - 02554488 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2015-11-24 19:40 - 2013-04-03 06:46 - 00938616 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2015-11-24 19:40 - 2013-04-03 06:46 - 00523384 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2015-11-24 19:40 - 2013-04-03 06:46 - 00385144 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2015-11-24 19:40 - 2013-04-03 06:46 - 00075056 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2015-11-24 19:40 - 2013-04-03 06:46 - 00062584 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2015-11-23 11:38 - 2013-04-03 06:46 - 06049858 _____ C:\Windows\system32\nvcoproc.bin 2015-11-21 18:32 - 2014-02-09 10:49 - 00000000 ___RD C:\Users\Eldin\Desktop\ボール 2015-11-17 23:01 - 2013-08-02 00:48 - 00000000 ____D C:\Snes9x 2015-11-14 13:54 - 2009-07-14 05:45 - 00297656 _____ C:\Windows\system32\FNTCACHE.DAT 2015-11-14 03:01 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2015-11-12 19:37 - 2014-09-07 21:52 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll 2015-11-12 19:37 - 2014-09-07 21:52 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll 2015-11-12 19:37 - 2013-12-09 01:34 - 01828160 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2015-11-12 19:37 - 2013-12-09 01:34 - 01509824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2015-11-12 02:10 - 2013-09-06 19:56 - 00000000 ____D C:\Program Files\iTunes 2015-11-12 02:09 - 2013-09-06 19:56 - 00000000 ____D C:\Program Files (x86)\iTunes 2015-11-12 02:09 - 2013-09-06 19:55 - 00000000 ____D C:\Program Files\Common Files\Apple 2015-11-12 02:06 - 2013-04-06 13:25 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-11-12 02:06 - 2013-04-06 13:25 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-11-12 02:06 - 2013-04-06 13:25 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-11-12 01:57 - 2013-04-24 10:39 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\PhotoScape 2015-11-11 19:10 - 2013-08-14 21:31 - 00000000 ____D C:\Windows\system32\MRT 2015-11-11 19:08 - 2013-04-08 00:45 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-11-11 19:03 - 2013-03-14 16:51 - 01597970 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2015-11-11 19:03 - 2011-04-12 08:55 - 00000000 ____D C:\Program Files\Windows Journal 2015-11-11 18:19 - 2013-05-14 15:19 - 04699336 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2013-04-06 14:22 - 2013-04-06 12:00 - 0000916 _____ () C:\Program Files\Install CameraRecorder.lnk 2013-04-06 14:22 - 2013-04-06 14:22 - 0000355 _____ () C:\Program Files\KeepSafe - Verknüpfung.lnk 2013-04-06 14:22 - 2013-04-06 14:22 - 0002248 _____ () C:\Program Files\Qualcomm Atheros Killer Network Manager (2).lnk 2013-04-06 14:22 - 2013-04-03 06:55 - 0002248 _____ () C:\Program Files\Qualcomm Atheros Killer Network Manager.lnk 2015-04-11 18:16 - 2015-04-11 18:16 - 0407972 _____ () C:\Program Files\Wordpad_2009_RC1.zip 2014-02-26 02:17 - 2014-02-27 23:19 - 0000117 _____ () C:\Users\Eldin\AppData\Roaming\D2Info0 2014-02-26 02:17 - 2014-02-26 04:38 - 0000008 _____ () C:\Users\Eldin\AppData\Roaming\DofusAppId0_1 2014-02-26 02:17 - 2014-02-27 23:19 - 0000008 _____ () C:\Users\Eldin\AppData\Roaming\DofusAppId0_2 2014-02-26 02:57 - 2014-02-26 04:08 - 0000008 _____ () C:\Users\Eldin\AppData\Roaming\DofusAppId0_3 2013-12-28 21:39 - 2014-01-04 01:39 - 0000071 _____ () C:\Users\Eldin\AppData\Roaming\WB.CFG 2015-10-22 03:28 - 2015-10-22 03:28 - 0000000 ___SH () C:\Users\Eldin\AppData\Local\LumaEmu 2015-05-11 19:00 - 2015-05-11 19:00 - 0002073 _____ () C:\Users\Eldin\AppData\Local\recently-used.xbel 2013-04-06 13:01 - 2013-04-06 13:05 - 111691960 _____ () C:\ProgramData\avast_free_antivirus_setup.exe 2013-04-07 01:52 - 2013-04-07 01:54 - 0774648 _____ (Google Inc.) C:\ProgramData\ChromeSetup.exe 2014-04-22 06:59 - 2014-07-04 06:53 - 0028157 _____ () C:\ProgramData\dxdiag.txt 2013-05-14 14:26 - 2013-05-14 14:27 - 41230322 _____ () C:\ProgramData\finaldraft_802.zip 2013-04-06 13:15 - 2013-04-06 13:15 - 20904728 _____ (Mozilla) C:\ProgramData\Firefox Setup 20.0.exe 2013-04-07 13:00 - 2013-04-07 13:00 - 62405680 _____ (Anthropics Technology Ltd. ) C:\ProgramData\PortraitProfessionalTrialSetup_en_de_fr.exe 2013-04-09 21:46 - 2013-04-09 21:46 - 5693485 _____ (XMedia Recode ) C:\ProgramData\XMediaRecode3154_setup.exe Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\ProgramData\avast_free_antivirus_setup.exe C:\ProgramData\ChromeSetup.exe C:\ProgramData\Firefox Setup 20.0.exe C:\ProgramData\PortraitProfessionalTrialSetup_en_de_fr.exe C:\ProgramData\XMediaRecode3154_setup.exe C:\Users\Eldin\setup.exe Einige Dateien in TEMP: ==================== C:\Users\Eldin\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-11-22 06:56 ==================== Ende von FRST.txt ============================ Geändert von Aeon (06.12.2015 um 01:31 Uhr) |
06.12.2015, 22:35 | #6 |
/// the machine /// TB-Ausbilder | Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm?ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? |
07.12.2015, 03:33 | #7 |
| Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? Die letzte Frage ob ich noch Probleme habe, hat mich zum schmunzeln gebracht. Ich bin mir nicht ganz sicher ob das so in Ordnung ist, wenn ich hier die ganze Zeit Codes poste die jeder mitlesen kann. Stichwort Datenschutzgesetze. Wenn man in fremde Threads nicht posten kann, dann sollte man auch die ganzen Codes nicht lesen können, meine Meinung. Tut mir leid wenn das nicht hier hin gehört aber ich mache mir nur etwas Sorgen. Zum Thema. Einem anderen user wurde hier im Forum gesagt dass wahrschinlich nur eine Seite geblockt wird und bei ihm nichts gefunden wurde. Könnte das nicht auch bei mir der Fall sein nach all den posts? Zumal ich die Mal-Warnung nur auf dieser Seite bekomme und das auch nur beim Senderwechsel. Was kann man aus all dem bisher schlussfolgern? |
08.12.2015, 07:20 | #8 |
/// the machine /// TB-Ausbilder | Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? Korrekt, ist gleich, aber bei Dir ist davon ab trotzdem ne Tonne an Adware auf dem Rechner gewesen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.12.2015, 20:48 | #9 |
| Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? Naja, ich bin kein Profi aber wenn ich 20 Programme durch den PC jagen muss um irgendwas aufzuspüren, dann weiß ich jetzt bescheid. ___________________________________________ ESET Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c0a21abbfb36434c82e32f5324f0abbd # end=init # utc_time=2015-12-09 08:39:25 # local_time=2015-12-09 09:39:25 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download Update Finalize Updated modules version: 27110 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c0a21abbfb36434c82e32f5324f0abbd # end=updated # utc_time=2015-12-09 08:43:44 # local_time=2015-12-09 09:43:44 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=c0a21abbfb36434c82e32f5324f0abbd # end=restart # utc_time=2015-12-09 10:22:30 # local_time=2015-12-09 11:22:30 (+0100, Mitteleuropäische Zeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 71 91 375751 24224509 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 0 201286400 0 0 # scanned=252777 # found=13 # cleaned=0 # scan_time=5925 sh=5B05032339C16B165950B4DE41272A1090AE3560 ft=1 fh=9ab4632cd8e08102 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\Temp\XMedia Recode.exe" sh=705636E6F6727192A76AF598BAD1BA197C3343CB ft=1 fh=dcaba59de91f2724 vn="Variante von Win32/InstalleRex.T evtl. unerwünschte Anwendung" ac=I fn="C:\ProgramData\InstallMate\{88171401-1825-4AEA-A801-500753F436F7}\Custom.dll" sh=705636E6F6727192A76AF598BAD1BA197C3343CB ft=1 fh=dcaba59de91f2724 vn="Variante von Win32/InstalleRex.T evtl. unerwünschte Anwendung" ac=I fn="C:\Users\All Users\InstallMate\{88171401-1825-4AEA-A801-500753F436F7}\Custom.dll" sh=B835518BF6F88265F956E4B048D08440B5CDE0F6 ft=1 fh=797d64834ee866e5 vn="Variante von Win32/AdkDLLWrapper.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Eldin\AppData\Roaming\BitTorrent\BitTorrent.exe" sh=245C5D6AA77DC06BDE45EF37AD6A1C1797831D53 ft=1 fh=14bf317c03f7dc7f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Eldin\Documents\eldin\DESKTO\SoftonicToolbar.exe" sh=4328BB17EFA3AC9078AA8F8FA59B0CB4C3D57067 ft=1 fh=dc14cd79dc9c52d5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Eldin\Downloads\CopyTrans Manager - CHIP-Installer.exe" sh=D9CD9E63434B5DCD74461229D8161838A10A006B ft=1 fh=d877b79b9cb680c8 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Eldin\Downloads\Demo Euro Truck Simulator 2 - CHIP-Installer(1).exe" sh=289AA398F5DFA44F2C88B35D9F478069DEB11108 ft=1 fh=4f2ea848fcac0625 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Eldin\Downloads\Everest Ultimate Edition - CHIP-Installer.exe" sh=250579FF0D3BB98BEF5C7DAA9CF940C0A3932A27 ft=1 fh=0bb1497c349ce07e vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Eldin\Downloads\Notepad - CHIP-Installer(1).exe" sh=25356577B51DC8CB3BFA282C191DB3A358068EC1 ft=1 fh=edf819d2140636d2 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Eldin\Downloads\Notepad - CHIP-Installer.exe" sh=C916B71AD8FE2ACEE7257240FA23FCF6250A8060 ft=1 fh=8341c6112b909af3 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Eldin\Downloads\VLC media player 32 Bit - CHIP-Installer.exe" sh=A91E7025FA449C247BCD54A02F7EB1DD63097D30 ft=1 fh=c15022604ff03155 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Eldin\Downloads\Wise Registry Cleaner - CHIP-Installer.exe" sh=207EBDA069A63CA48582BA02043583304DD45343 ft=1 fh=fcbb3f3bf093cf80 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Eldin\Downloads\Wordpad 2009 - CHIP-Installer(1).exe" Code:
ATTFilter Results of screen317's Security Check version 1.009 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 20.0.0.235 Mozilla Firefox (42.0) Google Chrome (46.0.2490.86) Google Chrome (47.0.2526.73) ````````Process Check: objlist.exe by Laurent```````` AVAST Software Avast AvastSvc.exe AVAST Software Avast ng vbox\AvastVBoxSVC.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-12-2015 durchgeführt von Eldin (Administrator) auf ELDIN-PC (09-12-2015 20:37:53) Gestartet von C:\Users\Eldin\Desktop Geladene Profile: Eldin (Verfügbare Profile: Eldin & Gast) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: FF) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe (Nenad Hrg SoftwareOK.de / SoftwareOK.com ) C:\Program Files (x86)\DesktopSchneeFree\DesktopSchneeFree.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE () C:\Program Files (x86)\KWorld Multimedia\HyperMediaCenter\DTVR\Scheduled.exe (Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor) HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2757424 2015-11-12] (NVIDIA Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-16] (Apple Inc.) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-11-19] (Intel Corporation) HKLM-x32\...\Run: [Center Agent] => C:\Program Files (x86)\KWorld Multimedia\HyperMediaCenter\DTVR\Scheduled.exe [867840 2006-10-05] () HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-10-13] (Apple Inc.) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2013536 2014-05-10] (Wondershare) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-05] (AVAST Software) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\beKEY: HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\Run: [DesktopSchneeFree] => C:\Program Files (x86)\DesktopSchneeFree\DesktopSchneeFree.exe [450048 2010-01-15] (Nenad Hrg SoftwareOK.de / SoftwareOK.com ) HKU\S-1-5-21-1763166945-3058576130-879148785-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1763166945-3058576130-879148785-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\VIDEOWLP.SCR AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [177600 2015-11-25] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [155792 2015-11-25] (NVIDIA Corporation) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-05] (AVAST Software) CHR HKU\S-1-5-21-1763166945-3058576130-879148785-1001\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{43A4DED4-692B-4843-817C-860D7A0BD3E8}: [NameServer] 192.168.0.1,8.8.8.8 Tcpip\..\Interfaces\{43A4DED4-692B-4843-817C-860D7A0BD3E8}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1763166945-3058576130-879148785-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} HKU\S-1-5-21-1763166945-3058576130-879148785-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006 SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-1763166945-3058576130-879148785-1001 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-1763166945-3058576130-879148785-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2015-05-05] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-12-05] (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-05-05] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-05] (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Keine Datei Toolbar: HKLM - Kein Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Keine Datei StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537 FF DefaultSearchUrl: hxxps://www.google.com/search/?trackid=sp-006 FF SearchEngineOrder.1: Google (avast) FF SelectedSearchEngine: Yahoo! FF Homepage: hxxp://google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll [2015-12-09] () FF Plugin: @java.com/DTPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-05-05] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2015-05-05] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-09] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin HKU\S-1-5-21-1763166945-3058576130-879148785-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Eldin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-08] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-1763166945-3058576130-879148785-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [Keine Datei] FF SearchPlugin: C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\searchplugins\google-avast.xml [2015-02-24] FF Extension: Rikaichan Japanese-German Dictionary File - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\rikaichan-jpde@polarcloud.com [2015-08-20] FF Extension: Rikaichan Japanese-English Dictionary File - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\rikaichan-jpen@polarcloud.com [2015-08-20] FF Extension: Black Youtube Theme - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\{2c93446d-612b-416d-9af0-b7355797b611}.xpi [2015-09-20] FF Extension: WOT - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-12-09] FF Extension: ADB Helper - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\Extensions\adbhelper@mozilla.org [2015-11-13] FF Extension: Kein Name - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\Extensions\firefox@mega.co.nz.xpi [2015-12-09] [ist nicht signiert] FF Extension: Valence - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\Extensions\fxdevtools-adapters@mozilla.org [2015-10-21] FF Extension: Adblock Plus - C:\Users\Eldin\AppData\Roaming\Mozilla\Firefox\Profiles\01he47lr.default-1406846418537\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-26] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-05] FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-12-05] Chrome: ======= CHR Profile: C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-22] CHR Extension: (Google Docs) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-22] CHR Extension: (Google Drive) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-18] CHR Extension: (YouTube) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-27] CHR Extension: (Google-Suche) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-27] CHR Extension: (Avast SafePrice) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-11-27] CHR Extension: (Google Tabellen) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-22] CHR Extension: (Google Docs Offline) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-27] CHR Extension: (Avast Online Security) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-27] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-29] CHR Extension: (Google Mail) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-22] CHR Profile: C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Docs) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-27] CHR Extension: (Google Drive) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-27] CHR Extension: (YouTube) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-27] CHR Extension: (Google-Suche) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-27] CHR Extension: (Avast SafePrice) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-11-27] CHR Extension: (Google Docs Offline) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-27] CHR Extension: (Avast Online Security) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-27] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-27] CHR Extension: (Google Mail) - C:\Users\Eldin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-27] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-12-05] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-05] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-05] (AVAST Software) R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [5561368 2015-12-05] (Avast Software) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156400 2015-11-12] (NVIDIA Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [Datei ist nicht signiert] R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872688 2015-11-12] (NVIDIA Corporation) R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8133424 2015-11-12] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5915440 2015-11-12] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-05-18] () R2 PowerBiosServer; c:\Program Files (x86)\Hotkey\PowerBiosServer.exe [35328 2012-05-22] () [Datei ist nicht signiert] R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [490496 2012-07-23] () [Datei ist nicht signiert] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R3 Ak27x64; C:\Windows\System32\DRIVERS\Ak27x64.sys [3364720 2012-07-23] (Qualcomm Atheros, Inc.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-05] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-05] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-05] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-05] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-05] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [450504 2015-12-05] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-05] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-05] (AVAST Software) S3 ATHDFU; C:\Windows\System32\Drivers\AthDfu.sys [51872 2012-02-13] (Windows (R) Win 7 DDK provider) [Datei ist nicht signiert] R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [66928 2012-07-23] (Qualcomm Atheros, Inc.) S3 BTATH_BUS; C:\Windows\system32\drivers\btath_bus.sys [30368 2012-02-13] (Atheros) [Datei ist nicht signiert] S3 BTATH_RCP; C:\Windows\system32\drivers\btath_rcp.sys [280992 2012-02-13] (Atheros) [Datei ist nicht signiert] R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-05-16] (Disc Soft Ltd) S3 E100B; C:\Windows\System32\DRIVERS\efe5b32e.sys [192256 2009-06-10] (Intel Corporation) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28216 2012-11-19] (Intel Corporation) S3 lehidmini; C:\Windows\system32\drivers\leath_hid.sys [36128 2012-02-13] (Atheros) [Datei ist nicht signiert] R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [147088 2015-12-05] (AVAST Software) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19760 2015-11-12] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.) R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [310904 2015-12-05] (Avast Software) S3 BTATH_HCRP; \SystemRoot\system32\drivers\btath_hcrp.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-12-09 20:37 - 2015-12-09 20:38 - 00022453 _____ C:\Users\Eldin\Desktop\FRST.txt 2015-12-09 20:36 - 2015-12-09 20:36 - 00000813 _____ C:\Users\Eldin\Desktop\checkup.txt 2015-12-09 09:39 - 2015-12-09 09:39 - 00000000 ____D C:\Program Files (x86)\ESET 2015-12-09 09:33 - 2015-12-09 09:33 - 00852720 _____ C:\Users\Eldin\Desktop\SecurityCheck.exe 2015-12-09 06:40 - 2015-12-09 06:40 - 02870984 _____ (ESET) C:\Users\Eldin\Desktop\esetsmartinstaller_deu.exe 2015-12-09 02:36 - 2015-11-20 19:54 - 03170304 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-12-09 02:36 - 2015-11-20 19:54 - 02609152 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-12-09 02:36 - 2015-11-20 19:54 - 00709632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-12-09 02:36 - 2015-11-20 19:54 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-12-09 02:36 - 2015-11-20 19:54 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-12-09 02:36 - 2015-11-20 19:54 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-12-09 02:36 - 2015-11-20 19:54 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-12-09 02:36 - 2015-11-20 19:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-12-09 02:36 - 2015-11-20 19:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-12-09 02:36 - 2015-11-20 19:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-12-09 02:36 - 2015-11-20 19:54 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-12-09 02:36 - 2015-11-20 19:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-12-09 02:36 - 2015-11-20 19:34 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-12-09 02:36 - 2015-11-20 19:34 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-12-09 02:36 - 2015-11-20 19:34 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-12-09 02:36 - 2015-11-20 19:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-12-09 02:36 - 2015-11-05 20:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2015-12-09 02:36 - 2015-11-05 20:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2015-12-09 02:36 - 2015-11-03 20:04 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2015-12-09 02:36 - 2015-11-03 19:56 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2015-12-09 02:36 - 2015-10-08 20:13 - 00419928 _____ C:\Windows\SysWOW64\locale.nls 2015-12-09 02:36 - 2015-10-08 19:52 - 00419928 _____ C:\Windows\system32\locale.nls 2015-12-09 02:35 - 2015-11-11 22:12 - 00387792 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-12-09 02:35 - 2015-11-11 21:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-12-09 02:35 - 2015-11-11 19:53 - 01735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2015-12-09 02:35 - 2015-11-11 19:53 - 00525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll 2015-12-09 02:35 - 2015-11-11 19:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll 2015-12-09 02:35 - 2015-11-11 19:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll 2015-12-09 02:35 - 2015-11-11 17:21 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-12-09 02:35 - 2015-11-11 17:00 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-12-09 02:35 - 2015-11-11 16:44 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-12-09 02:35 - 2015-11-11 16:44 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-12-09 02:35 - 2015-11-11 16:41 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-12-09 02:35 - 2015-11-11 16:12 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-12-09 02:35 - 2015-11-11 15:57 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-12-09 02:35 - 2015-11-10 19:55 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2015-12-09 02:35 - 2015-11-10 19:55 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2015-12-09 02:35 - 2015-11-10 19:55 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2015-12-09 02:35 - 2015-11-10 19:39 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2015-12-09 02:35 - 2015-11-10 19:37 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2015-12-09 02:35 - 2015-11-10 18:47 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-12-09 02:35 - 2015-11-10 01:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-12-09 02:35 - 2015-11-10 01:13 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-12-09 02:35 - 2015-11-10 01:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-12-09 02:35 - 2015-11-10 01:12 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-12-09 02:35 - 2015-11-10 01:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-12-09 02:35 - 2015-11-10 01:11 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-12-09 02:35 - 2015-11-10 01:08 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-12-09 02:35 - 2015-11-10 01:06 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-12-09 02:35 - 2015-11-10 01:06 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-12-09 02:35 - 2015-11-10 01:04 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-12-09 02:35 - 2015-11-10 01:03 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-12-09 02:35 - 2015-11-10 01:02 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-12-09 02:35 - 2015-11-10 01:02 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-12-09 02:35 - 2015-11-10 00:50 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-12-09 02:35 - 2015-11-10 00:47 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-12-09 02:35 - 2015-11-10 00:46 - 04514816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-12-09 02:35 - 2015-11-10 00:44 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2015-12-09 02:35 - 2015-11-10 00:37 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-12-09 02:35 - 2015-11-10 00:36 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-12-09 02:35 - 2015-11-10 00:36 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-12-09 02:35 - 2015-11-10 00:35 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-12-09 02:35 - 2015-11-10 00:17 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-12-09 02:35 - 2015-11-10 00:14 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-12-09 02:35 - 2015-11-10 00:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-12-09 02:35 - 2015-11-08 23:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-12-09 02:35 - 2015-11-08 23:32 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-12-09 02:35 - 2015-11-08 23:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-12-09 02:35 - 2015-11-08 23:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-12-09 02:35 - 2015-11-08 23:15 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-12-09 02:35 - 2015-11-08 23:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-12-09 02:35 - 2015-11-08 23:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-12-09 02:35 - 2015-11-08 23:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-12-09 02:35 - 2015-11-08 23:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-12-09 02:35 - 2015-11-08 23:06 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-12-09 02:35 - 2015-11-08 23:04 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-12-09 02:35 - 2015-11-08 23:02 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-12-09 02:35 - 2015-11-08 23:01 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-12-09 02:35 - 2015-11-08 23:01 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-12-09 02:35 - 2015-11-08 23:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-12-09 02:35 - 2015-11-08 23:01 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-12-09 02:35 - 2015-11-08 22:52 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-12-09 02:35 - 2015-11-08 22:48 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-12-09 02:35 - 2015-11-08 22:40 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-12-09 02:35 - 2015-11-08 22:35 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-12-09 02:35 - 2015-11-08 22:32 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-12-09 02:35 - 2015-11-08 22:29 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2015-12-09 02:35 - 2015-11-08 22:18 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-12-09 02:35 - 2015-11-08 22:15 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-12-09 02:35 - 2015-11-08 22:15 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-12-09 02:35 - 2015-11-08 22:14 - 14456832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-12-09 02:35 - 2015-11-08 22:14 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-12-09 02:35 - 2015-11-08 22:13 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-12-09 02:35 - 2015-11-08 21:53 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-12-09 02:35 - 2015-11-08 21:41 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-12-09 02:35 - 2015-11-08 21:30 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-12-09 02:35 - 2015-11-05 20:05 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll 2015-12-09 02:35 - 2015-11-05 20:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll 2015-12-09 02:35 - 2015-11-05 10:53 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2015-12-09 02:35 - 2015-10-09 00:22 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll 2015-12-09 02:35 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL 2015-12-09 02:35 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll 2015-12-09 02:35 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL 2015-12-09 02:35 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL 2015-12-09 02:35 - 2015-10-09 00:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll 2015-12-09 02:35 - 2015-10-09 00:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL 2015-12-09 02:35 - 2015-10-09 00:17 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll 2015-12-09 02:34 - 2015-11-03 20:04 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll 2015-12-09 02:34 - 2015-11-03 19:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll 2015-12-08 02:47 - 2015-12-08 02:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2015-12-08 02:47 - 2015-12-08 02:47 - 00000000 ____D C:\Program Files (x86)\QuickTime 2015-12-08 02:46 - 2015-12-08 02:46 - 00001035 _____ C:\Users\Public\Desktop\iExplorer.lnk 2015-12-08 02:46 - 2015-12-08 02:46 - 00000000 ____D C:\Users\Eldin\AppData\LocalLow\Apple Computer 2015-12-08 02:46 - 2015-12-08 02:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iExplorer 2015-12-06 03:50 - 2015-12-06 03:50 - 00000000 ____D C:\Users\Eldin\AppData\Local\BetterDS3 2015-12-06 03:49 - 2013-05-10 10:57 - 01661440 _____ (Slackerhome Productions) C:\Users\Eldin\Desktop\Better DS3.exe 2015-12-06 01:16 - 2015-12-06 01:16 - 02369024 _____ (Farbar) C:\Users\Eldin\Desktop\FRST64.exe 2015-12-06 01:07 - 2015-12-06 01:07 - 01599336 _____ (Malwarebytes) C:\Users\Eldin\Desktop\JRT.exe 2015-12-06 01:00 - 2015-12-06 01:24 - 00000000 ____D C:\AdwCleaner 2015-12-06 00:57 - 2015-12-06 00:57 - 01736704 _____ C:\Users\Eldin\Desktop\AdwCleaner_5.023.exe 2015-12-06 00:51 - 2015-12-06 00:51 - 00003262 _____ C:\Windows\System32\Tasks\{EF3EFEEC-4BDC-4BDD-B6F9-9483E635F06C} 2015-12-06 00:22 - 2015-12-06 00:22 - 00001280 _____ C:\Users\Eldin\Desktop\Revo Uninstaller.lnk 2015-12-06 00:22 - 2015-12-06 00:22 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller 2015-12-06 00:22 - 2015-12-06 00:22 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2015-12-05 06:18 - 2015-12-05 08:19 - 00002157 _____ C:\Users\Eldin\Desktop\Minecraft.lnk 2015-12-05 04:02 - 2015-12-05 04:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2015-12-05 03:59 - 2015-12-05 03:59 - 00386096 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2015-12-05 03:59 - 2015-12-05 03:59 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr 2015-12-05 02:35 - 2015-12-05 02:35 - 00000000 ____D C:\Windows\SysWOW64\NV 2015-12-05 02:35 - 2015-12-05 02:35 - 00000000 ____D C:\Windows\system32\NV 2015-12-05 02:33 - 2015-11-25 00:10 - 42913912 _____ C:\Windows\system32\nvcompiler.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 37882488 _____ C:\Windows\SysWOW64\nvcompiler.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 22310008 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 18363696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 17516040 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 16553568 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 15717672 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 15122296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 14835872 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 13527248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 12770752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 12034248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 11131184 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-12-05 02:33 - 2015-11-25 00:10 - 02870392 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 02490488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 01905272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435906.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 01564792 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435906.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00877360 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00861816 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00689272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00673912 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00501056 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00467912 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00422056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00413816 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00388024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00369272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00151184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2015-12-05 02:33 - 2015-11-25 00:10 - 00031352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys 2015-12-05 02:28 - 2015-11-12 19:37 - 00112712 _____ C:\Windows\system32\NvRtmpStreamer64.dll 2015-12-05 01:32 - 2015-12-09 20:37 - 00000000 ____D C:\FRST 2015-12-05 01:20 - 2015-12-05 01:20 - 00001175 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-12-05 01:20 - 2015-12-05 01:20 - 00001163 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-12-05 01:20 - 2015-12-05 01:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-12-05 01:19 - 2015-12-05 01:19 - 00243976 _____ C:\Users\Eldin\Downloads\Firefox Setup Stub 42.0.exe 2015-12-03 21:35 - 2015-12-03 21:35 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software 2015-12-03 21:35 - 2015-12-03 21:35 - 00000000 ____D C:\Program Files\Common Files\AV 2015-12-03 07:08 - 2015-12-06 01:34 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-12-03 07:08 - 2015-12-05 08:18 - 00002032 _____ C:\Users\Public\Desktop\Malwarebyte.lnk 2015-12-03 07:08 - 2015-12-03 07:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-12-03 07:08 - 2015-12-03 07:08 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-12-03 07:08 - 2015-12-03 07:08 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-12-03 07:08 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-12-03 07:08 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-12-03 07:08 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2015-12-01 04:10 - 2015-12-08 02:46 - 00000000 ____D C:\Program Files (x86)\iExplorer 2015-12-01 04:10 - 2015-12-01 04:10 - 00000000 ____D C:\Users\Eldin\AppData\Local\Macroplant_LLC 2015-11-30 18:43 - 2015-11-30 18:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft 2015-11-27 02:27 - 2015-11-27 02:27 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\iPadian 2015-11-12 02:27 - 2015-12-03 21:29 - 00000516 _____ C:\Users\Eldin\Desktop\Project64 - Verknüpfung.lnk 2015-11-12 02:10 - 2015-12-03 21:29 - 00001717 _____ C:\Users\Public\Desktop\iTunes.lnk 2015-11-12 02:10 - 2015-11-12 02:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Windows\System32\Tasks\Apple 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Program Files\iPod 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Program Files\Bonjour 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Program Files (x86)\Bonjour 2015-11-12 02:09 - 2015-11-12 02:09 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2015-11-12 01:55 - 2015-12-03 21:29 - 00000830 _____ C:\Users\Public\Desktop\CCleaner.lnk 2015-11-12 01:55 - 2015-11-12 01:55 - 00002790 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2015-11-12 01:55 - 2015-11-12 01:55 - 00000000 ____D C:\Program Files\CCleaner 2015-11-11 17:30 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2015-11-11 17:30 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll 2015-11-11 17:30 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe 2015-11-11 17:30 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll 2015-11-11 17:30 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll 2015-11-11 17:30 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll 2015-11-11 17:30 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe 2015-11-11 17:30 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-11-11 17:30 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-11-11 17:30 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-11-11 17:30 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-11-11 17:30 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-11-11 17:30 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-11-11 17:30 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-11-11 17:30 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-11-11 17:30 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-11-11 17:30 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-11-11 17:30 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-11-11 17:30 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-11-11 17:30 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-11-11 17:30 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-11-11 17:30 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-11-11 17:30 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-11-11 17:30 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-11-11 17:30 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-11-11 17:30 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-11-11 17:30 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-11-11 17:30 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-11-11 17:30 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-11-11 17:30 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-11-11 17:30 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-11-11 17:30 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2015-11-11 17:30 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-11-11 17:30 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-11-11 17:30 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-11-11 17:30 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-11-11 17:30 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-11-11 17:30 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2015-11-11 17:30 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2015-11-11 17:30 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2015-11-11 17:30 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2015-11-11 17:30 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll 2015-11-11 17:30 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2015-11-11 17:30 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-11-11 17:30 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll 2015-11-11 17:30 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-12-09 20:36 - 2009-07-14 05:45 - 00027936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-12-09 20:36 - 2009-07-14 05:45 - 00027936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-12-09 20:35 - 2011-04-12 08:43 - 00700622 _____ C:\Windows\system32\perfh007.dat 2015-12-09 20:35 - 2011-04-12 08:43 - 00150228 _____ C:\Windows\system32\perfc007.dat 2015-12-09 20:35 - 2009-07-14 06:13 - 01623690 _____ C:\Windows\system32\PerfStringBackup.INI 2015-12-09 20:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2015-12-09 20:31 - 2014-05-30 18:19 - 00003930 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896} 2015-12-09 20:28 - 2014-09-07 21:21 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-12-09 20:28 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-12-09 11:49 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2015-12-09 11:45 - 2014-09-07 21:21 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-12-09 11:39 - 2014-11-10 03:09 - 00000000 ____D C:\Windows\SysWOW64\vbox 2015-12-09 11:39 - 2014-11-10 03:09 - 00000000 ____D C:\Windows\system32\vbox 2015-12-09 11:23 - 2015-05-13 17:51 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2015-12-09 11:23 - 2015-05-13 17:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2015-12-09 11:23 - 2012-09-19 13:46 - 00000000 ____D C:\Windows 2015-12-09 11:23 - 2009-07-14 05:45 - 00297656 _____ C:\Windows\system32\FNTCACHE.DAT 2015-12-09 11:19 - 2013-04-06 13:25 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-12-09 05:19 - 2013-04-06 13:25 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-12-09 05:19 - 2013-04-06 13:25 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-12-09 05:19 - 2013-04-06 13:25 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-12-09 03:06 - 2015-05-13 17:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-12-09 03:04 - 2013-08-14 21:31 - 00000000 ____D C:\Windows\system32\MRT 2015-12-09 03:00 - 2013-04-08 00:45 - 140158008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-12-07 16:22 - 2015-03-04 03:20 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2015-12-06 21:53 - 2014-02-09 10:49 - 00000000 ___RD C:\Users\Eldin\Desktop\ボール 2015-12-06 04:26 - 2013-04-06 17:41 - 00000000 ____D C:\Users\Eldin\AppData\Local\CrashDumps 2015-12-06 02:26 - 2014-05-05 17:19 - 00000000 ____D C:\Users\Eldin\AppData\Local\ElevatedDiagnostics 2015-12-05 08:19 - 2013-04-29 12:56 - 00000000 ____D C:\ProgramData\Icons 2015-12-05 07:13 - 2014-11-09 05:50 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\.minecraft 2015-12-05 06:13 - 2014-06-02 02:53 - 00000000 ____D C:\Users\Eldin\Desktop\True.Det 2015-12-05 04:02 - 2013-05-01 01:37 - 00000000 ____D C:\Program Files\7-Zip 2015-12-05 03:59 - 2015-07-22 02:09 - 00147088 _____ (AVAST Software) C:\Windows\system32\Drivers\ngvss.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 01055560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00450504 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00273784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00155304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2015-12-05 03:59 - 2015-03-04 03:20 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys 2015-12-05 02:35 - 2013-04-03 06:46 - 00000000 ____D C:\ProgramData\NVIDIA 2015-12-05 02:28 - 2014-01-08 03:59 - 00000000 ____D C:\Users\Eldin\AppData\Local\NVIDIA Corporation 2015-12-05 01:20 - 2014-04-18 17:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-12-05 00:40 - 2014-09-07 21:21 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-12-05 00:40 - 2014-09-07 21:21 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-12-03 21:29 - 2015-10-23 16:15 - 00001077 _____ C:\Users\Public\Desktop\XMedia Recode.lnk 2015-12-03 21:29 - 2015-09-10 06:02 - 00000843 _____ C:\Users\Eldin\Desktop\MGS 5 - TPP.lnk 2015-12-03 21:29 - 2015-09-04 06:16 - 00002088 _____ C:\Users\Eldin\Desktop\Resident Evil 4.lnk 2015-12-03 21:29 - 2015-08-07 17:53 - 00001930 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-12-03 21:29 - 2015-06-20 16:00 - 00001309 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk 2015-12-03 21:29 - 2015-02-22 07:35 - 00001237 _____ C:\Users\Eldin\Desktop\TreeSize Free.lnk 2015-12-03 21:29 - 2014-11-14 01:20 - 00000742 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anki.lnk 2015-12-03 21:29 - 2014-09-08 01:59 - 00002238 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-12-03 21:29 - 2014-07-01 04:42 - 00000919 _____ C:\Users\Eldin\Desktop\Dolphin.lnk 2015-12-03 21:29 - 2014-06-05 00:29 - 00012268 _____ C:\Users\Eldin\Desktop\Windows Media Center.lnk 2015-12-03 21:29 - 2014-06-02 01:46 - 00001076 _____ C:\Users\Public\Desktop\VLC media player.lnk 2015-12-03 21:29 - 2014-05-30 18:13 - 00001395 _____ C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-12-03 21:29 - 2014-05-16 00:42 - 00001960 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk 2015-12-03 21:29 - 2013-11-02 16:41 - 00002005 _____ C:\Users\Public\Desktop\DesktopSchneeFree.lnk 2015-12-03 21:29 - 2013-09-06 19:55 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2015-12-03 21:29 - 2013-08-02 00:49 - 00001773 _____ C:\Users\Eldin\Desktop\Snes9x.lnk 2015-12-03 21:29 - 2013-07-12 00:17 - 00001208 _____ C:\Users\Eldin\Desktop\On-Screen Keyboard.lnk 2015-12-03 21:29 - 2013-06-08 17:23 - 00001422 _____ C:\Users\Public\Desktop\Fraps.lnk 2015-12-03 21:29 - 2013-05-14 14:28 - 00002645 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Final Draft Tagger 2.lnk 2015-12-03 21:29 - 2013-04-29 13:01 - 00002076 _____ C:\Users\Eldin\Desktop\Snipping Tool.lnk 2015-12-03 21:29 - 2013-04-29 12:47 - 00002201 _____ C:\Users\Eldin\Desktop\Portrait Professional 11 Test.lnk 2015-12-03 21:29 - 2013-04-29 12:31 - 00002304 _____ C:\Users\Eldin\Desktop\Winamp.lnk 2015-12-03 21:29 - 2013-04-29 12:07 - 00001925 _____ C:\Users\Eldin\Desktop\Musik.lnk 2015-12-03 21:29 - 2013-04-06 12:01 - 00002144 _____ C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk 2015-12-03 21:29 - 2013-04-06 12:00 - 00002538 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk 2015-12-03 21:29 - 2013-04-06 12:00 - 00001494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk 2015-12-03 21:29 - 2013-04-06 12:00 - 00001378 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk 2015-12-03 21:29 - 2013-04-03 06:49 - 00002423 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk 2015-12-03 21:29 - 2013-03-14 15:54 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2015-12-03 21:29 - 2013-03-14 15:54 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2015-12-03 21:29 - 2009-07-14 06:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk 2015-12-03 21:29 - 2009-07-14 05:57 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2015-12-03 21:29 - 2009-07-14 05:57 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk 2015-12-03 21:29 - 2009-07-14 05:57 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk 2015-12-03 21:29 - 2009-07-14 05:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk 2015-12-03 21:29 - 2009-07-14 05:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk 2015-12-03 21:29 - 2009-07-14 05:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk 2015-12-03 21:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\security 2015-12-03 07:56 - 2013-05-17 19:32 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2015-12-03 07:56 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-12-03 07:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SchCache 2015-11-30 04:26 - 2014-06-02 01:47 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\vlc 2015-11-25 00:10 - 2015-09-10 07:58 - 03579696 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2015-11-25 00:10 - 2015-09-10 07:58 - 03159248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2015-11-25 00:10 - 2012-10-29 18:45 - 00177600 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2015-11-25 00:10 - 2012-10-29 18:45 - 00155792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2015-11-25 00:10 - 2012-10-29 18:45 - 00033607 _____ C:\Windows\system32\nvinfo.pb 2015-11-24 19:40 - 2013-04-03 06:46 - 06358648 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2015-11-24 19:40 - 2013-04-03 06:46 - 02983032 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2015-11-24 19:40 - 2013-04-03 06:46 - 02554488 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2015-11-24 19:40 - 2013-04-03 06:46 - 00938616 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2015-11-24 19:40 - 2013-04-03 06:46 - 00523384 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2015-11-24 19:40 - 2013-04-03 06:46 - 00385144 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2015-11-24 19:40 - 2013-04-03 06:46 - 00075056 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2015-11-24 19:40 - 2013-04-03 06:46 - 00062584 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2015-11-23 11:38 - 2013-04-03 06:46 - 06049858 _____ C:\Windows\system32\nvcoproc.bin 2015-11-17 23:01 - 2013-08-02 00:48 - 00000000 ____D C:\Snes9x 2015-11-12 19:37 - 2014-09-07 21:52 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll 2015-11-12 19:37 - 2014-09-07 21:52 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll 2015-11-12 19:37 - 2013-12-09 01:34 - 01828160 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2015-11-12 19:37 - 2013-12-09 01:34 - 01509824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2015-11-12 02:10 - 2013-09-06 19:56 - 00000000 ____D C:\Program Files\iTunes 2015-11-12 02:09 - 2013-09-06 19:56 - 00000000 ____D C:\Program Files (x86)\iTunes 2015-11-12 02:09 - 2013-09-06 19:55 - 00000000 ____D C:\Program Files\Common Files\Apple 2015-11-12 01:57 - 2013-04-24 10:39 - 00000000 ____D C:\Users\Eldin\AppData\Roaming\PhotoScape 2015-11-11 19:03 - 2013-03-14 16:51 - 01597970 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2015-11-11 19:03 - 2011-04-12 08:55 - 00000000 ____D C:\Program Files\Windows Journal ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2013-04-06 14:22 - 2013-04-06 12:00 - 0000916 _____ () C:\Program Files\Install CameraRecorder.lnk 2013-04-06 14:22 - 2013-04-06 14:22 - 0000355 _____ () C:\Program Files\KeepSafe - Verknüpfung.lnk 2013-04-06 14:22 - 2013-04-06 14:22 - 0002248 _____ () C:\Program Files\Qualcomm Atheros Killer Network Manager (2).lnk 2013-04-06 14:22 - 2013-04-03 06:55 - 0002248 _____ () C:\Program Files\Qualcomm Atheros Killer Network Manager.lnk 2015-04-11 18:16 - 2015-04-11 18:16 - 0407972 _____ () C:\Program Files\Wordpad_2009_RC1.zip 2014-02-26 02:17 - 2014-02-27 23:19 - 0000117 _____ () C:\Users\Eldin\AppData\Roaming\D2Info0 2014-02-26 02:17 - 2014-02-26 04:38 - 0000008 _____ () C:\Users\Eldin\AppData\Roaming\DofusAppId0_1 2014-02-26 02:17 - 2014-02-27 23:19 - 0000008 _____ () C:\Users\Eldin\AppData\Roaming\DofusAppId0_2 2014-02-26 02:57 - 2014-02-26 04:08 - 0000008 _____ () C:\Users\Eldin\AppData\Roaming\DofusAppId0_3 2013-12-28 21:39 - 2014-01-04 01:39 - 0000071 _____ () C:\Users\Eldin\AppData\Roaming\WB.CFG 2015-10-22 03:28 - 2015-10-22 03:28 - 0000000 ___SH () C:\Users\Eldin\AppData\Local\LumaEmu 2015-05-11 19:00 - 2015-05-11 19:00 - 0002073 _____ () C:\Users\Eldin\AppData\Local\recently-used.xbel 2013-04-06 13:01 - 2013-04-06 13:05 - 111691960 _____ () C:\ProgramData\avast_free_antivirus_setup.exe 2013-04-07 01:52 - 2013-04-07 01:54 - 0774648 _____ (Google Inc.) C:\ProgramData\ChromeSetup.exe 2014-04-22 06:59 - 2014-07-04 06:53 - 0028157 _____ () C:\ProgramData\dxdiag.txt 2013-05-14 14:26 - 2013-05-14 14:27 - 41230322 _____ () C:\ProgramData\finaldraft_802.zip 2013-04-06 13:15 - 2013-04-06 13:15 - 20904728 _____ (Mozilla) C:\ProgramData\Firefox Setup 20.0.exe 2013-04-07 13:00 - 2013-04-07 13:00 - 62405680 _____ (Anthropics Technology Ltd. ) C:\ProgramData\PortraitProfessionalTrialSetup_en_de_fr.exe 2013-04-09 21:46 - 2013-04-09 21:46 - 5693485 _____ (XMedia Recode ) C:\ProgramData\XMediaRecode3154_setup.exe Dateien, die verschoben oder gelöscht werden sollten: ==================== C:\ProgramData\avast_free_antivirus_setup.exe C:\ProgramData\ChromeSetup.exe C:\ProgramData\Firefox Setup 20.0.exe C:\ProgramData\PortraitProfessionalTrialSetup_en_de_fr.exe C:\ProgramData\XMediaRecode3154_setup.exe C:\Users\Eldin\setup.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-12-09 11:40 ==================== Ende von FRST.txt ============================ |
10.12.2015, 14:05 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? Ich spring mal für schrauber ein. Man muss nicht 20 Tools ausführen nur um die Adware aufzuspüren. Wir können auch alles manuell. Nur wirst du dann irgendwann meckern weil das zuviel Aufwand ist und länger dauert als eins der speziellen Tools doppelzuklicken, die einen die meiste Arbeit abnehmen weil es automatisiert ist. In deinem Fall hätte adwCleaner allein gereich um auzuzeigen, was für ne dicke Tonne Adware du hast und wenn du dir jeden scheiß von softonic und chip.de in Form vom chip installer runterlädst ist das ja nun auch wirklich kein Wunder. FRST-Fix Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft! Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\ProgramData\InstallMate\{88171401-1825-4AEA-A801-500753F436F7} C:\Users\All Users\InstallMate\{88171401-1825-4AEA-A801-500753F436F7} C:\Users\Eldin\Documents\eldin\DESKTO\SoftonicToolbar.exe C:\Users\Eldin\Downloads\CopyTrans Manager - CHIP-Installer.exe C:\Users\Eldin\Downloads\Demo Euro Truck Simulator 2 - CHIP-Installer(1).exe C:\Users\Eldin\Downloads\Everest Ultimate Edition - CHIP-Installer.exe C:\Users\Eldin\Downloads\Notepad - CHIP-Installer(1).exe C:\Users\Eldin\Downloads\Notepad - CHIP-Installer.exe C:\Users\Eldin\Downloads\VLC media player 32 Bit - CHIP-Installer.exe C:\Users\Eldin\Downloads\Wise Registry Cleaner - CHIP-Installer.exe C:\Users\Eldin\Downloads\Wordpad 2009 - CHIP-Installer(1).exe emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
11.12.2015, 01:41 | #11 |
| Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? Ich glaube ich hätte jetzt doch wieder schrauber am Aparat. Muss ich mich jetzt von dir anmachen lassen? Ich weiß selbst das ich von Chip.de lieber nichts hätte laden sollen aber das kann man auch anders ausdrücken. AdwCleaner allein hätte gereich? Ach wirklich? CCleaner und Malwarebyte haben gar nichts ergeben aber das allround tool AdwCleaner hätte es sicher getan. Riiiiight. Mit deinem übergroßen Ego hat es dich wohl in den Fingern gejuckt hier zu antworten. Wenn du für schrauber "mal einspringen" willst, dann vielleicht in einem anderen thread, Herr Oberfeldwebel. Von meinem ursprünglichen "Problem" wurde ich inzwischen befreit und von "einer Tonne" malware wohl auch. Dafür Danke ich schrauber recht herzlich für seine Mühe und Geduld die er mit mir hatte. |
11.12.2015, 01:45 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? Was erzählst du hier für einen Dünnpfiff Schrauber hat keine Zeit und wir wurden gebeten für ihn einzuspringen. Aber du kannst ja auch lieber schlaue (peinliche?) Sprüche bringen statt das zu tun, was ein Helfer dir empfiehlt.
__________________ Logfiles bitte immer in CODE-Tags posten |
11.12.2015, 01:58 | #13 |
| Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? Ach so, du wolltest helfen? Na sieh mal einer an. Leider war das erst auf den 4. Blick zu erkennen. Schade. Was an meinem post peinlich ist, kann ich beim besten Willen nicht erkennen. Das nächste mal vielleicht einfach mal die einzelnen Arbeitsschritte posten anstatt erstmal den Klugscheißer hängen zu lassen. Bye. |
11.12.2015, 02:00 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? Biste besoffen? Scheint so. Ich hab nen Arbeitsschritt für dich gepostet. Aber du musst ja wie ein loser reagieren. Naja, dann nach viel Spaß mit dem CHIP-Installer
__________________ Logfiles bitte immer in CODE-Tags posten |
11.12.2015, 02:09 | #15 |
| Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? Wenn die Wahrheit weh tut, wird sich aus den letzten Schubladen bedient. Ich dachte hier dürfen nur Profis anderen helfen und keine 15 jährigen Kiddis. Hm, da habe ich mich wohl geirrt. Ja, der Kleine wollte helfen aber erstmal alles in die lauwarme Milch tunken und den "Großen" raushängen lassen. Nicht wirklich seriös wenn du mich fragst. Das war's jetzt aber wirklich für mich. Du kannst dich aber auch noch aus der lezten Schublade bedienen. Greif zu.. |
Themen zu Ständige URL:Mal Warnung von Avast beim Senderwechsel, Fehlalarm? |
.com, andere, anderen, avast, erkenne, erkennen, fehlalarm, files, firefox, malware, mozilla, nichts, problem, program, scan, seite, sobald, sofort, ständige, tagen, unterwegs, url:mal, versuch, versucht, virus, warnung, würde, zunge |