ottojack | 11.10.2015 16:41 | hier ein frisches FRST logfile: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:11-10-2015 01
durchgeführt von admin (Administrator) auf PC (11-10-2015 17:38:19)
Gestartet von C:\Users\admin\Desktop
Geladene Profile: admin (Verfügbare Profile: admin)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(Prolific Technology Inc.) C:\Windows\SysWOW64\IoctlSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
() C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1793736 2015-05-19] (NVIDIA Corporation)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1427648 2015-08-07] (COMODO)
HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [114368 2015-07-01] (VMware, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKLM\...\RunOnce: [*EmptyTemp] => cmd /c rd /q/s C:\FRST\Temp
HKLM-x32\...\RunOnce: [{f255478c-ebfa-426d-a975-4a8d1f9432a4}] => C:\ProgramData\Package Cache\{f255478c-ebfa-426d-a975-4a8d1f9432a4}\vs_langpack.exe [1016624 2015-08-15] (Microsoft Corporation)
HKU\S-1-5-21-560193511-1957534509-1735208640-1001\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [152872 2015-05-19] (Nero AG)
HKU\S-1-5-21-560193511-1957534509-1735208640-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8322328 2015-06-24] (Piriform Ltd)
HKU\S-1-5-21-560193511-1957534509-1735208640-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [787592 2015-10-11] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-560193511-1957534509-1735208640-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4468056 2015-09-13] (Disc Soft Ltd)
HKU\S-1-5-21-560193511-1957534509-1735208640-1001\...\MountPoints2: E - E:\vs_professional.exe
HKU\S-1-5-21-560193511-1957534509-1735208640-1001\...\MountPoints2: {e0cb1ec8-5a55-11e5-a0fc-005056c00008} - E:\setup.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL Keine Datei
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL Keine Datei
Winsock: Catalog9 12 Keine Datei
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL Keine Datei
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL Keine Datei
Winsock: Catalog9-x64 12 Keine Datei
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{92F26E54-F45F-436B-AB09-400A4B3518BA}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKU\S-1-5-21-560193511-1957534509-1735208640-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-560193511-1957534509-1735208640-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-10-08] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-10-08] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-10-08] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-10-08] (Oracle Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\tjc4nckf.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-10-08] ()
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-10-08] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-10-08] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-10-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2015-07-23] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-10-08] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-10-08] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-07-19] (VideoLAN)
FF Extension: Kein Name - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\tjc4nckf.default\Extensions\trash [2015-10-07]
StartMenuInternet: FIREFOX.EXE - firefox.exe
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
"BFE" => Dienst konnte nicht entsperrt werden. <===== ACHTUNG
U2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5542472 2015-09-08] (COMODO)
U2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
U3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2015-07-21] (Microsoft Corporation)
U3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265792 2015-08-07] (COMODO)
U3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-09-13] (Disc Soft Ltd)
U3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2015-07-21] (Microsoft Corporation) [Datei ist nicht signiert]
U4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-09-15] (Malwarebytes Corporation)
U2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-09-15] (Malwarebytes Corporation)
U3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [275752 2015-05-19] (Nero AG)
U2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2015-05-19] (Prolific Technology Inc.) [Datei ist nicht signiert]
U2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [177800 2015-10-11] (Sandboxie Holdings, LLC)
U3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2015-07-21] (Microsoft Corporation) [Datei ist nicht signiert]
U2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [12732608 2015-07-01] ()
U3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2015-07-21] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
U1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [21184 2015-08-05] (COMODO)
U1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [806032 2015-08-05] (COMODO)
U1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45856 2015-08-05] (COMODO)
U3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-09-13] (Disc Soft Ltd)
U3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
U1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [105096 2015-08-05] (COMODO)
U3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [109272 2015-10-08] (Malwarebytes)
U3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-09-15] (Malwarebytes Corporation)
U3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-09-15] (Malwarebytes Corporation)
U3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
U3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2015-07-29] (NVIDIA Corporation)
U3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [191624 2015-09-21] (Sandboxie Holdings, LLC)
U0 sptd; C:\Windows\System32\Drivers\sptd.sys [381608 2015-09-13] (Duplex Secure Ltd.)
U2 VMparport; C:\Windows\system32\drivers\VMparport.sys [31936 2015-05-31] (VMware, Inc.)
U0 vsock; C:\Windows\System32\drivers\vsock.sys [76480 2015-05-21] (VMware, Inc.)
U2 vstor2-mntapi20-shared; C:\Windows\SysWow64\drivers\vstor2-mntapi20-shared.sys [33872 2013-08-28] (VMware, Inc.)
S5 BFE; <===== ACHTUNG: Gesperrter Dienst
U3 athr; system32\DRIVERS\athrx.sys [X]
U3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-10-11 17:37 - 2015-10-11 17:37 - 02195456 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2015-10-11 17:29 - 2015-10-11 17:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
2015-10-08 20:52 - 2015-10-09 20:59 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-10-08 08:44 - 2015-10-08 08:44 - 00000000 ____D C:\Users\admin\AppData\LocalLow\Temp
2015-10-08 01:01 - 2015-10-08 01:02 - 00006183 _____ C:\Users\admin\Desktop\FSS.txt
2015-10-08 00:51 - 2015-10-08 00:51 - 00003160 _____ C:\Windows\System32\Tasks\SidebarExecute
2015-10-08 00:19 - 2015-10-08 00:19 - 00000000 _____ C:\Windows\SysWOW64\REN722.tmp
2015-10-07 18:19 - 2015-10-08 00:18 - 00000000 ____D C:\Program Files\Java
2015-10-07 18:19 - 2015-10-08 00:16 - 00110688 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2015-10-07 18:19 - 2015-10-07 18:19 - 00000000 ____D C:\ProgramData\Sun
2015-10-07 18:18 - 2015-10-08 00:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-10-07 18:10 - 2015-10-07 18:10 - 00000000 _____ C:\Windows\SysWOW64\REND2E8.tmp
2015-10-07 17:49 - 2015-10-07 17:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-10-07 17:48 - 2015-10-07 17:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-10-07 17:48 - 2015-10-07 17:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-10-07 17:47 - 2015-10-07 17:47 - 00000000 ____D C:\Windows\SysWOW64\Adobe
2015-10-07 17:46 - 2015-10-10 18:47 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-10-07 17:46 - 2015-10-08 19:47 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-10-07 17:40 - 2015-10-07 17:40 - 00961192 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00883712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00064352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00062304 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-07 17:40 - 2015-10-07 17:40 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-10-07 14:32 - 2015-10-07 14:42 - 00001079 _____ C:\Users\admin\Desktop\Age of Empires II HD.lnk
2015-10-07 14:32 - 2015-10-07 14:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Age of Empires II HD
2015-10-07 14:30 - 2015-10-11 17:36 - 00000000 ____D C:\Program Files (x86)\Age of Empires II HD
2015-10-07 14:25 - 2015-10-07 14:25 - 04033440 _____ (Intel Corporation) C:\Windows\SysWOW64\libmmd.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 03477818 _____ (Red Hat) C:\Windows\SysWOW64\cygwin1.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 01260544 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Windows\SysWOW64\libeay32.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 01198049 _____ C:\Windows\unins001.exe
2015-10-07 14:25 - 2015-10-07 14:25 - 01070232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 01055676 _____ (Free Software Foundation) C:\Windows\SysWOW64\libiconv2.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 01054208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71u.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 01024000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 01017344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70u.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00935632 _____ (Microsoft Corporation) C:\Windows\system\vb40016.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00799568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdia100.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00722192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vb40032.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00660120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomct2.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00617896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00487424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp70.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00456008 _____ (AutoIt Team) C:\Windows\SysWOW64\autoitx3.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00445016 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00444328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshflxgd.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00416408 _____ (Microsoft Corporation ) C:\Windows\SysWOW64\comct332.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00398416 _____ (Microsoft Corporation) C:\Windows\system\vbrun300.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00356992 _____ (Microsoft Corporation) C:\Windows\system\vbrun200.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00344064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr70.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00295936 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Windows\SysWOW64\ssleay32.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00295936 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Windows\SysWOW64\libssl32.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00279192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdatgrd.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00271264 _____ C:\Windows\system\vbrun100.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00259736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msflxgrd.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00253080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdatlst.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00222360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tabctl32.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00219288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\richtx32.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00218776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dblist32.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00212112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mci32.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00210944 _____ C:\Windows\system\msvcrt10.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00179352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmask32.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00170920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comct232.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00163480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00162304 _____ C:\Windows\SysWOW64\libpng13.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00138752 _____ C:\Windows\SysWOW64\libpng15.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00131728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinet.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00131072 _____ (Sereby Corporation) C:\Windows\SysWOW64\AiORuntimes.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00130712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msstdfmt.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00127640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswinsck.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00119960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomm32.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\openal32.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00108696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msstkprp.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00107520 _____ C:\Windows\SysWOW64\zlib1.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00104088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\picclp32.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00103424 _____ (GNU <www.gnu.org>) C:\Windows\SysWOW64\libintl3.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl71.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl70.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00084624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysinfo.ocx
2015-10-07 14:25 - 2015-10-07 14:25 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71DEU.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71ITA.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71FRA.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71ESP.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70ITA.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70FRA.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70ESP.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70DEU.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71ENU.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70ENU.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00054784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvci70.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00053248 _____ (Adobe Systems, Incorporated) C:\Windows\system\plugin.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71KOR.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71JPN.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70KOR.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70JPN.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71CHT.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70CHT.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71CHS.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70CHS.dll
2015-10-07 14:25 - 2015-10-07 14:25 - 00010806 _____ C:\Windows\unins001.dat
2015-10-07 14:22 - 2015-10-07 14:24 - 00002793 _____ C:\Windows\unins000.dat
2015-10-07 14:22 - 2015-10-07 14:22 - 01199175 _____ C:\Windows\unins000.exe
2015-10-07 14:10 - 2015-10-07 14:44 - 00055419 _____ C:\Windows\DirectX.log
2015-10-07 13:34 - 2015-10-07 13:35 - 00080794 _____ C:\Users\admin\Desktop\Addition.txt
2015-10-07 13:33 - 2015-10-11 17:38 - 00013700 _____ C:\Users\admin\Desktop\FRST.txt
2015-09-23 03:28 - 2015-09-23 03:28 - 00000000 ____D C:\Program Files (x86)\Workflow Manager Tools
2015-09-23 03:27 - 2015-09-23 03:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Web Tools
2015-09-23 03:26 - 2015-09-23 03:26 - 00000000 ____D C:\ProgramData\NuGet
2015-09-23 03:26 - 2015-09-23 03:26 - 00000000 ____D C:\Program Files (x86)\NuGet
2015-09-19 19:56 - 2015-10-08 19:03 - 00000000 ____D C:\Users\admin\AppData\LocalLow\BitTorrent
2015-09-16 22:59 - 2015-09-16 22:59 - 00002105 _____ C:\Users\admin\Desktop\Gothic II spielen.lnk
2015-09-16 04:54 - 2015-09-16 04:54 - 00000000 ____D C:\Users\admin\AppData\Roaming\Zombi
2015-09-16 04:54 - 2015-09-16 04:54 - 00000000 ____D C:\Users\admin\AppData\Roaming\Zombi
2015-09-16 04:28 - 2015-09-16 04:30 - 00000000 ____D C:\Program Files (x86)\Zombies
2015-09-16 04:17 - 2015-09-16 04:17 - 00001140 _____ C:\Users\admin\Desktop\Zombi.lnk
2015-09-16 01:38 - 2015-09-16 01:38 - 00001294 _____ C:\Users\admin\Desktop\Continue installation .lnk
2015-09-14 20:50 - 2015-09-14 20:50 - 00000000 ___SD C:\ComboFix
2015-09-14 20:50 - 2015-09-14 20:50 - 00000000 ___SD C:\ComboFix
2015-09-14 20:48 - 2015-09-14 20:50 - 00000000 ____D C:\Qoobox
2015-09-14 20:48 - 2015-09-14 20:50 - 00000000 ____D C:\Qoobox
2015-09-14 20:48 - 2015-09-14 20:48 - 00000000 ____D C:\Windows\erdnt
2015-09-14 20:48 - 2015-09-14 20:48 - 00000000 ____D C:\Windows\erdnt
2015-09-13 23:53 - 2015-09-16 22:47 - 00000000 ____D C:\Users\admin\AppData\Local\8930
2015-09-13 23:53 - 2015-09-13 23:53 - 00000350 _____ C:\Windows\Tasks\AmiUpdXp.job
2015-09-13 23:35 - 2015-10-11 17:33 - 00002800 _____ C:\Windows\setupact.log
2015-09-13 23:35 - 2015-09-13 23:35 - 00000000 _____ C:\Windows\setuperr.log
2015-09-13 23:34 - 2015-10-09 20:59 - 00098112 _____ C:\Windows\PFRO.log
2015-09-13 23:12 - 2015-09-13 23:12 - 00000000 ____D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2015-09-13 23:10 - 2015-09-13 23:10 - 00000000 ____D C:\Users\admin\AppData\Local\Disc_Soft_Ltd
2015-09-13 23:01 - 2015-09-13 23:01 - 00381608 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys
2015-09-13 23:00 - 2015-09-13 23:00 - 00000000 ____D C:\Users\Public\Documents\Daemon Tools Images
2015-09-13 23:00 - 2015-09-13 23:00 - 00000000 ____D C:\Users\Public\Documents\Daemon Tools Images
2015-09-13 23:00 - 2015-09-13 23:00 - 00000000 ____D C:\ProgramData\Documents\Daemon Tools Images
2015-09-13 22:54 - 2015-09-13 22:58 - 00000000 ____D C:\Users\admin\AppData\Roaming\DAEMON Tools Lite
2015-09-13 22:54 - 2015-09-13 22:56 - 00000000 ____D C:\Program Files\DAEMON Tools Lite
2015-09-13 22:54 - 2015-09-13 22:55 - 00030264 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2015-09-13 22:54 - 2015-09-13 22:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2015-09-13 22:54 - 2015-09-13 22:54 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2015-09-13 22:48 - 2015-09-13 22:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IsoBuster
2015-09-13 22:48 - 2015-09-13 22:48 - 00000000 ____D C:\Program Files (x86)\IsoBuster
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-10-11 17:37 - 2015-06-24 03:15 - 01872302 _____ C:\Windows\system32\Drivers\fvstore.dat
2015-10-11 17:33 - 2015-06-24 01:08 - 00000000 ____D C:\ProgramData\VMware
2015-10-11 17:33 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-10-11 17:32 - 2015-06-24 01:52 - 01474832 _____ C:\Windows\system32\Drivers\sfi.dat
2015-10-11 17:32 - 2009-07-14 06:45 - 00037264 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-10-11 17:32 - 2009-07-14 06:45 - 00037264 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-10-11 17:29 - 2015-06-25 04:16 - 00000000 ____D C:\Users\admin\Desktop\Sachen
2015-10-11 17:19 - 2015-06-25 02:04 - 00001710 _____ C:\Windows\Sandboxie.ini
2015-10-09 21:03 - 2015-05-19 18:24 - 00000000 ___SD C:\Windows\system32\GWX
2015-10-09 00:00 - 2015-05-19 18:24 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-10-08 21:25 - 2015-09-03 22:20 - 00000000 ____D C:\Users\admin\AppData\Local\JDownloader 2.0
2015-10-08 20:52 - 2015-06-24 02:14 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-10-08 20:50 - 2015-06-24 02:14 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-10-08 19:47 - 2015-05-19 19:47 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-10-08 19:47 - 2015-05-19 19:47 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-08 19:03 - 2015-05-19 19:37 - 00000000 ____D C:\Users\admin\AppData\Roaming\BitTorrent
2015-10-08 08:27 - 2015-08-20 16:39 - 00000000 ____D C:\Users\admin\Downloads\DZ
2015-10-08 05:55 - 2015-05-23 18:32 - 00000000 ____D C:\Users\admin\AppData\Roaming\vlc
2015-10-08 03:57 - 2015-05-30 18:09 - 00000000 ____D C:\Program Files (x86)\Lee_
2015-10-08 02:35 - 2015-08-04 13:08 - 00000000 ____D C:\Tor Browser
2015-10-08 01:02 - 2011-04-12 09:43 - 00649288 _____ C:\Windows\system32\perfh007.dat
2015-10-08 01:02 - 2011-04-12 09:43 - 00132904 _____ C:\Windows\system32\perfc007.dat
2015-10-08 01:02 - 2009-07-14 07:13 - 01527502 _____ C:\Windows\system32\PerfStringBackup.INI
2015-10-08 00:59 - 2015-05-19 14:14 - 00059616 _____ C:\Users\admin\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-08 00:59 - 2015-05-19 14:14 - 00059616 _____ C:\Users\admin\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-08 00:58 - 2009-07-14 06:45 - 00270720 _____ C:\Windows\system32\FNTCACHE.DAT
2015-10-08 00:57 - 2015-05-19 13:21 - 00000000 ____D C:\Windows\CSC
2015-10-08 00:48 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-10-08 00:46 - 2009-07-14 04:34 - 00000439 _____ C:\Windows\win.ini
2015-10-08 00:22 - 2015-05-30 20:06 - 00000000 ____D C:\ProgramData\Oracle
2015-10-08 00:19 - 2015-05-30 21:01 - 00000000 ____D C:\Program Files (x86)\Java
2015-10-08 00:17 - 2015-05-30 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2015-10-07 23:30 - 2015-06-25 23:14 - 00000000 ____D C:\FRST
2015-10-07 18:09 - 2015-09-02 17:03 - 00000000 ____D C:\Users\admin\.oracle_jre_usage
2015-10-07 18:09 - 2015-09-02 17:03 - 00000000 ____D C:\Users\admin\.oracle_jre_usage
2015-10-07 17:47 - 2015-05-19 19:47 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2015-10-07 17:44 - 2015-07-21 16:18 - 00000000 ____D C:\ProgramData\Package Cache
2015-10-07 17:44 - 2015-07-21 16:18 - 00000000 ____D C:\ProgramData\Package Cache
2015-10-07 17:43 - 2013-10-08 14:27 - 00044696 _____ (Microsoft Corporation) C:\Windows\system32\mfc100jpn.dll
2015-10-07 17:40 - 2015-06-25 23:34 - 00400544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcamp140.dll
2015-10-07 16:58 - 2015-06-25 05:37 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-10-07 14:25 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
2015-10-07 14:23 - 2015-05-20 22:38 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2015-10-07 14:22 - 2015-05-20 22:38 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2015-10-07 13:11 - 2015-05-19 13:27 - 01156621 _____ C:\Windows\WindowsUpdate.log
2015-09-28 08:59 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-09-23 03:29 - 2015-07-21 16:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 12.0
2015-09-23 03:28 - 2015-07-21 16:22 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
2015-09-23 03:28 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\MSBuild
2015-09-23 03:27 - 2015-07-21 16:43 - 00000000 ____D C:\Program Files (x86)\Microsoft ASP.NET
2015-09-23 03:23 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-09-23 03:13 - 2015-05-19 18:50 - 01760532 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-09-23 02:51 - 2015-07-21 16:57 - 00000000 ____D C:\Users\admin\Documents\Visual Studio 2013
2015-09-21 20:15 - 2015-06-24 01:10 - 00000000 ____D C:\Users\admin\AppData\Roaming\VMware
2015-09-21 20:15 - 2015-06-24 01:10 - 00000000 ____D C:\Users\admin\AppData\Local\VMware
2015-09-21 19:12 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-09-18 18:16 - 2015-05-19 13:27 - 00000000 ____D C:\Users\admin
2015-09-16 22:58 - 2015-08-11 01:31 - 00002153 _____ C:\Users\admin\Desktop\Gothic II - Die Nacht des Raben.lnk
2015-09-16 00:23 - 2015-06-24 22:36 - 00000000 ____D C:\AdwCleaner
2015-09-16 00:11 - 2015-06-27 20:26 - 00001069 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MakeTorrent 2.lnk
2015-09-16 00:11 - 2015-05-19 21:32 - 00002699 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lumac.lnk
2015-09-16 00:11 - 2015-05-19 13:51 - 00001061 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-09-16 00:11 - 2012-03-14 13:15 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2015-09-16 00:11 - 2012-03-14 13:15 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2015-09-16 00:11 - 2009-07-14 07:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2015-09-16 00:11 - 2009-07-14 06:57 - 00001523 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-09-16 00:11 - 2009-07-14 06:57 - 00001304 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2015-09-16 00:11 - 2009-07-14 06:57 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2015-09-16 00:11 - 2009-07-14 06:54 - 00001210 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2015-09-16 00:11 - 2009-07-14 06:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2015-09-16 00:10 - 2015-08-04 13:09 - 00000823 _____ C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2015-09-16 00:10 - 2015-05-20 22:36 - 00001173 _____ C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Sims 4 by BuZeR.lnk
2015-09-16 00:10 - 2015-05-19 13:28 - 00001325 _____ C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-09-15 23:46 - 2015-06-24 02:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-15 23:46 - 2015-06-24 02:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-15 23:46 - 2015-06-24 02:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-15 23:46 - 2015-06-24 02:14 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-13 23:16 - 2015-09-02 11:05 - 00000000 ____D C:\Users\admin\AppData\Local\Ubisoft Game Launcher
2015-09-13 23:12 - 2015-09-02 11:05 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2015-09-11 18:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-09-11 16:46 - 2011-04-12 09:54 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-11 16:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2015-05-20 22:51 - 2015-06-05 16:58 - 0000001 _____ () C:\Users\admin\AppData\Roaming\update.dat
Einige Dateien in TEMP:
====================
C:\Users\admin\AppData\Local\Temp\SandboxieInstall.exe
C:\Users\admin\AppData\Local\Temp\CmdLineExt02.dll
C:\Users\admin\AppData\Local\Temp\SIntf16.dll
C:\Users\admin\AppData\Local\Temp\SIntf32.dll
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-10-02 10:20
==================== Ende von FRST.txt ============================ |