Here we go:
MBAM: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 16.09.2015
Suchlaufzeit: 19:45
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.09.16.04
Rootkit-Datenbank: v2015.08.16.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Tim
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 327547
Abgelaufene Zeit: 5 Min., 30 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 5
PUP.Optional.Software.Updater, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SystemStoreService, In Quarantäne, [b6de0828296201359e0106c16f95d729],
PUP.Optional.Widdit, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [e5af0729bdce181ef57afbc7d52fb44c],
PUP.Optional.APNToolBar.Gen, HKU\S-1-5-18\SOFTWARE\AskPartnerNetwork, In Quarantäne, [f4a06dc3bccf23131066c26ba95a5ca4],
PUP.Optional.WeDownLoadManager, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\WEDLMNGR, In Quarantäne, [cfc5fa369cef62d461d9ac160afac23e],
PUP.Optional.Widdit, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [643032fe4249d066f17b5b673bc904fc],
Registrierungswerte: 6
PUP.Optional.SearchCertified, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Bar, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, In Quarantäne, [296b3bf58b00cd6901902c8646be9868]
PUP.Optional.Widdit, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|SuggestionsURL_JSON, hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=46364&gid=1&dbCode=1&command={searchTerms}, In Quarantäne, [e5af0729bdce181ef57afbc7d52fb44c]
PUP.Optional.CertifiedToolBar.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), hxxp://search.certified-toolbar.com?si=46364&st=bs&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=%s, In Quarantäne, [e7ad42eedbb0979f194e3d03e61db14f]
PUP.Optional.CertifiedToolBar.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|(Default), hxxp://search.certified-toolbar.com?si=46364&st=bs&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=%s, In Quarantäne, [5440131dc9c2ed49e97f0b35dd262ed2]
PUP.Optional.SearchCertified, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Bar, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, In Quarantäne, [abe99d93c6c5280e5e3206acdd2757a9]
PUP.Optional.Widdit, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|SuggestionsURL_JSON, hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=46364&gid=1&dbCode=1&command={searchTerms}, In Quarantäne, [643032fe4249d066f17b5b673bc904fc]
Registrierungsdaten: 28
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B),Ersetzt,[60340d237e0d5fd748bcff6c14f18977]
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Default_Page_URL, hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B),Ersetzt,[8b096cc42a613df94cb86209d62f9c64]
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[eca8cc64fa918fa755af28439e67eb15]
PUP.Optional.CertifiedToolBar.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Start Page, hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B, Gut: (www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B),Ersetzt,[ccc82b05dab164d270d6451e5ea7a65a]
Hijack.SearchPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Start Page, hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B),Ersetzt,[0a8a6bc5f59694a25aab6803b74e51af]
PUP.Optional.CertifiedToolBar.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Start Default_Page_URL, hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B, Gut: (www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B),Ersetzt,[cbc986aac6c57abc7acc283b64a14fb1]
Hijack.SearchPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Start Default_Page_URL, hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B),Ersetzt,[484c61cfc7c4c07632d36efd23e201ff]
PUP.Optional.CertifiedToolBar.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[c7cd85ab662553e3fb4b2b384bba7789]
Hijack.SearchPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[6b29e34d73180d2904013b3006ff7d83]
PUP.Optional.CertifiedToolBar.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Bar, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[088c969ac9c24ee890b64e1581847888]
Hijack.SearchPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Bar, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[7e16fe32a3e80b2bbb4a3e2d788d8a76]
PUP.Optional.CertifiedToolBar.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Page, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[c5cf49e74d3e2f078bbb570c759004fc]
Hijack.SearchPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Page, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[f4a00e2232597eb815f0f2792fd68e72]
Hijack.StartPage, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B),Ersetzt,[bfd520104744a294e41f84e709fc34cc]
Hijack.StartPage, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Default_Page_URL, hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B),Ersetzt,[cfc517194e3d36000ef513588a7b1fe1]
Hijack.StartPage, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[0c882907becd02347c87551632d36e92]
PUP.Optional.CertifiedToolBar.ShrtCln, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Start Page, hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B, Gut: (www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B),Ersetzt,[d4c043ed83081026ff46e97ac24339c7]
Hijack.SearchPage, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Start Page, hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B),Ersetzt,[613369c7bbd02c0ae12576f55ea7d729]
PUP.Optional.CertifiedToolBar.ShrtCln, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Start Default_Page_URL, hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B, Gut: (www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B),Ersetzt,[f2a273bd2566aa8c1d28c0a3cb3a1de3]
Hijack.SearchPage, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Start Default_Page_URL, hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B),Ersetzt,[2173cf613259db5bb94d70fbc73ef60a]
PUP.Optional.CertifiedToolBar.ShrtCln, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[b7ddbb7590fb4beb1a2bd09364a1b947]
Hijack.SearchPage, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[454fc26e0784f4420105df8ca362649c]
PUP.Optional.CertifiedToolBar.ShrtCln, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Bar, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[dbb9cb65c8c391a546ffb3b0f70e2ad6]
Hijack.SearchPage, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Bar, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[0a8a4ae6deada393e0264922a560ae52]
PUP.Optional.CertifiedToolBar.ShrtCln, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Page, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[f79dcd634b40f343a89d5d06b64f738d]
Hijack.SearchPage, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Page, hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=),Ersetzt,[fb997bb590fbed495aac6506ff06c23e]
PUP.Optional.SearchCertifiedTB, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), hxxp://search.certified-toolbar.com?si=46364&st=bs&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=%s, Gut: (www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=bs&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=%s),Ersetzt,[4f453af6612a1323a579006fe12436ca]
PUP.Optional.SearchCertifiedTB, HKU\S-1-5-21-831909047-1497575709-4132674677-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|(Default), hxxp://search.certified-toolbar.com?si=46364&st=bs&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=%s, Gut: (www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=46364&st=bs&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=%s),Ersetzt,[1b7998984546290dc7582946cf367d83]
Ordner: 6
PUP.Optional.DownloadGuide, C:\Users\Tim\AppData\Local\DownloadGuide, In Quarantäne, [9bf962ceb3d82214bed56031fe060cf4],
PUP.Optional.DownloadGuide, C:\Users\Tim\AppData\Local\DownloadGuide\Offers, In Quarantäne, [9bf962ceb3d82214bed56031fe060cf4],
PUP.Optional.Software.Updater, C:\Program Files\SoftwareUpdater, In Quarantäne, [b6de0828296201359e0106c16f95d729],
PUP.Optional.APNToolBar.Gen, C:\ProgramData\APN\APN-Stub, In Quarantäne, [ddb7ce62c9c2a4927d4f738b788a5ca4],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.PriceAlarm, C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab, In Quarantäne, [2f6571bf4348dd59e9b6f32a8d769b65],
Dateien: 38
PUP.Soft32Downloader, C:\Users\Tim\Downloads\pokerstove setup.exe, In Quarantäne, [d2c249e7f39873c3c1231ec3ff0102fe],
PUP.Optional.APNToolBar, C:\Users\Tim\Downloads\SopCast.zip, In Quarantäne, [4b49141cf7943bfb1ca2991f46bb4eb2],
PUP.Optional.CrossRider, C:\Users\Tim\AppData\Local\DownloadGuide\Offers\plushd.exe, In Quarantäne, [286c2a06414a60d6dd6c98588c74c33d],
PUP.Optional.DownloadGuide, C:\Users\Tim\AppData\Local\DownloadGuide\amazon.ico, In Quarantäne, [9bf962ceb3d82214bed56031fe060cf4],
PUP.Optional.DownloadGuide, C:\Users\Tim\AppData\Local\DownloadGuide\free-driver-scout.exe, In Quarantäne, [9bf962ceb3d82214bed56031fe060cf4],
PUP.Optional.DownloadGuide, C:\Users\Tim\AppData\Local\DownloadGuide\Offers\foxydeal.exe, In Quarantäne, [9bf962ceb3d82214bed56031fe060cf4],
PUP.Optional.DownloadGuide, C:\Users\Tim\AppData\Local\DownloadGuide\Offers\pricealarm.exe, In Quarantäne, [9bf962ceb3d82214bed56031fe060cf4],
PUP.Optional.SearchCertifiedTB, C:\Program Files\Mozilla Firefox\searchplugins\Web Search.xml, In Quarantäne, [fc9870c036554bebeca9684ab94b54ac],
PUP.Optional.WebSearch, C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\KB086tPA.default\searchplugins\Web Search.xml, In Quarantäne, [f59f6cc46c1f80b6f8bdf3cee123b14f],
PUP.Optional.Software.Updater, C:\Program Files\SoftwareUpdater\SystemStore.exe, In Quarantäne, [b6de0828296201359e0106c16f95d729],
PUP.Optional.Software.Updater, C:\Program Files\SoftwareUpdater\config, In Quarantäne, [b6de0828296201359e0106c16f95d729],
PUP.Optional.Software.Updater, C:\Program Files\SoftwareUpdater\Maintenance.exe, In Quarantäne, [b6de0828296201359e0106c16f95d729],
PUP.Optional.Software.Updater, C:\Program Files\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe, In Quarantäne, [b6de0828296201359e0106c16f95d729],
PUP.Optional.Software.Updater, C:\Program Files\SoftwareUpdater\SoftwareUpdater.dll, In Quarantäne, [b6de0828296201359e0106c16f95d729],
PUP.Optional.Software.Updater, C:\Program Files\SoftwareUpdater\SoftwareUpdater.Ui.exe, In Quarantäne, [b6de0828296201359e0106c16f95d729],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\contact.png, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\default_logo.png, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\default_search_button.png, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\default_search_provider12.png, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\default_search_provider16.png, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\default_seperator.ico, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\help.png, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\home.png, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\refresh.png, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\settings.dat, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\shrink.png, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\stbcfg.bin, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.HomeTab, C:\Users\Tim\AppData\LocalLow\HomeTab\upgrade.png, In Quarantäne, [fc98f53bfa9101350e53a17321e2e818],
PUP.Optional.PriceAlarm, C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.html, In Quarantäne, [2f6571bf4348dd59e9b6f32a8d769b65],
PUP.Optional.PriceAlarm, C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.js, In Quarantäne, [2f6571bf4348dd59e9b6f32a8d769b65],
PUP.Optional.PriceAlarm, C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\fire.js, In Quarantäne, [2f6571bf4348dd59e9b6f32a8d769b65],
PUP.Optional.PriceAlarm, C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\manifest.json, In Quarantäne, [2f6571bf4348dd59e9b6f32a8d769b65],
PUP.Optional.PriceAlarm, C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\refire.js, In Quarantäne, [2f6571bf4348dd59e9b6f32a8d769b65],
PUP.Optional.CertifiedTB.ShrtCln, C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://search.certified-toolbar.com?si=46364&st=newtab&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B");), Ersetzt,[e1b3969a2b602f0770828123aa5ba15f]
PUP.Optional.CertifiedTB.ShrtCln, C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=");), Ersetzt,[2173fa36dbb066d018db911346bf4cb4]
PUP.Optional.CertifiedTB.ShrtCln, C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\KB086tPA.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://search.certified-toolbar.com?si=46364&st=newtab&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B");), Ersetzt,[5c38c36d2764f343df13eaba996c6a96]
PUP.Optional.CertifiedTB.ShrtCln, C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\KB086tPA.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=");), Ersetzt,[a8ec31ff5c2fbb7b92611f85bd484bb5]
PUP.Optional.CertifiedTB.ShrtCln, C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\KB086tPA.default\prefs.js, Gut: (browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Schlecht: (browser.startup.homepage", "hxxp://search.certified-toolbar.com), Ersetzt,[4450a18f64272f07d7c0f2b95ca9f30d]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end)
AdwC: Code:
# AdwCleaner v5.007 - Bericht erstellt am 16/09/2015 um 19:57:29
# Aktualisiert am 08/09/2015 von Xplode
# Datenbank : 2015-09-15.1 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x86)
# Benutzername : Tim - TIM-PC
# Gestartet von : C:\Users\Tim\Desktop\AdwCleaner_5.007.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum
***** [ Dienste ] *****
***** [ Ordner ] *****
[-] Ordner Gelöscht : C:\Program Files\ParetoLogic
[-] Ordner Gelöscht : C:\Program Files\Common Files\ParetoLogic
[-] Ordner Gelöscht : C:\ProgramData\apn
[-] Ordner Gelöscht : C:\ProgramData\ParetoLogic
[-] Ordner Gelöscht : C:\ProgramData\{1C6FDDD8-FC9E-4C12-9FA5-1AAD377097B3}
[-] Ordner Gelöscht : C:\Users\Tim\AppData\Local\Software_Updater
[-] Ordner Gelöscht : C:\Users\Tim\AppData\Local\SoftwareUpdater
[-] Ordner Gelöscht : C:\Users\Tim\AppData\LocalLow\SimplyTech
[-] Ordner Gelöscht : C:\Users\Tim\AppData\Roaming\DriverCure
[-] Ordner Gelöscht : C:\Users\Tim\AppData\Roaming\ParetoLogic
[-] Ordner Gelöscht : C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ParetoLogic
***** [ Dateien ] *****
[-] Datei Gelöscht : C:\Users\Tim\Desktop\ParetoLogic PC Health Advisor.lnk
***** [ Verknüpfungen ] *****
***** [ Geplante Tasks ] *****
[-] Task Gelöscht : FreeDriverScout
[-] Task Gelöscht : paretologic registration3
[-] Task Gelöscht : paretologic update version3
[-] Task Gelöscht : PC Health Advisor
[-] Task Gelöscht : PC Health Advisor Defrag
[-] Task Gelöscht : Software Updater
[-] Task Gelöscht : Software Updater Ui
[-] Task Gelöscht : ParetoLogic Update Version3 Startup Task
***** [ Registrierungsdatenbank ] *****
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\uus3url-pl
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
[-] Schlüssel Gelöscht : HKCU\Software\OCS
[-] Schlüssel Gelöscht : HKCU\Software\ParetoLogic
[-] Schlüssel Gelöscht : HKCU\Software\foxydeal
[-] Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\simplytech
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\ParetoLogic
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3CBF3EBB-235D-4c29-A68B-2BB1F428586E}
[!] Schlüssel Nicht Gelöscht : HKU\S-1-5-21-831909047-1497575709-4132674677-1000\Software\AppDataLow\Software\simplytech
[-] Daten Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
***** [ Internetbrowser ] *****
[-] [C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\prefs.js] [Preference] Gelöscht : user_pref("browser.newtab.url", "hxxp://search.certified-toolbar.com?si=46364&st=newtab&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B");
[-] [C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\prefs.js] [Preference] Gelöscht : user_pref("browser.search.defaultengine", "Web Search");
[-] [C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\prefs.js] [Preference] Gelöscht : user_pref("browser.search.order.1", "Web Search");
[-] [C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\prefs.js] [Preference] Gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
[-] [C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\prefs.js] [Preference] Gelöscht : user_pref("extensions.fvd_single.__surfcanyon_disable_time", "1");
[-] [C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\prefs.js] [Preference] Gelöscht : user_pref("extensions.fvd_single.seopack.b_surfcanyon", true);
[-] [C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\prefs.js] [Preference] Gelöscht : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1375026143756.000005&tguid=46364-3869-1375026143756-3C8B48A8EAB55DA7E03D70F6FD14D78B&q=");
[-] [C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\KB086tPA.default\prefs.js] [Preference] Gelöscht : user_pref("browser.search.defaultenginename", "Web Search");
[-] [C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\KB086tPA.default\prefs.js] [Preference] Gelöscht : user_pref("browser.search.defaultengine", "Web Search");
[-] [C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\KB086tPA.default\prefs.js] [Preference] Gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
[-] [C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\KB086tPA.default\prefs.js] [Preference] Gelöscht : user_pref("browser.search.order.1", "Web Search");
*************************
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4961 Bytes] ##########
JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.2 (09.14.2015:1)
OS: Windows 7 Home Premium x86
Ran by Tim on 16.09.2015 at 20:00:43,99
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Tim\AppData\Roaming\mozilla\firefox\profiles\6rhc2ovr.default-1380013996825\extensions\staged
Emptied folder: C:\Users\Tim\AppData\Roaming\mozilla\firefox\profiles\6rhc2ovr.default-1380013996825\minidumps [75 files]
~~~ Chrome
[C:\Users\Tim\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Tim\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Tim\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Tim\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.09.2015 at 20:02:03,46
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x86) Version:15-09-2015
durchgeführt von Tim (Administrator) auf TIM-PC (16-09-2015 20:02:55)
Gestartet von C:\Users\Tim\Downloads
Geladene Profile: Tim (Verfügbare Profile: Tim)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [CheckNDISPortF0acA7] => C:\Program Files\Hostless Modem\o2 Surfstick\CheckNDISPort_df.exe [419072 2013-05-10] ()
HKLM\...\Run: [CancelAutoPlay_df] => C:\Program Files\Hostless Modem\o2 Surfstick\CancelAutoPlay_df.exe [446720 2013-05-10] ()
HKLM\...\Run: [StartCCC] => C:\Program Files\AMD\ATI.ACE\Core-Static\x86\CLIStart.exe [748744 2015-08-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Avira SystrayStartTrigger] => C:\Program Files\Avira\Launcher\Avira.SystrayStartTrigger.exe [66936 2015-08-13] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [782008 2015-08-26] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-831909047-1497575709-4132674677-1000\...\Run: [F.lux] => C:\Users\Tim\AppData\Local\FluxSoftware\Flux\flux.exe [1016712 2013-10-16] (Flux Software LLC)
HKU\S-1-5-21-831909047-1497575709-4132674677-1000\...\Run: [Steam] => C:\Program Files\Steam\steam.exe [2889408 2015-04-14] (Valve Corporation)
HKU\S-1-5-21-831909047-1497575709-4132674677-1000\...\Run: [Spotify Web Helper] => C:\Users\Tim\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2025016 2015-09-16] (Spotify Ltd)
HKU\S-1-5-21-831909047-1497575709-4132674677-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [53735968 2015-08-07] (Skype Technologies S.A.)
HKU\S-1-5-21-831909047-1497575709-4132674677-1000\...\Run: [Spotify] => C:\Users\Tim\AppData\Roaming\Spotify\Spotify.exe [7571000 2015-09-16] (Spotify Ltd)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-07-30] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2013-11-15]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2013-07-28]
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{409745DA-2080-4AB3-88BA-39DE7927F265}: [DhcpNameServer] 192.168.0.1 192.168.0.1
Tcpip\..\Interfaces\{E8F5B5D7-5506-4428-A28E-52E9CC25B615}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-831909047-1497575709-4132674677-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-831909047-1497575709-4132674677-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-831909047-1497575709-4132674677-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-20] (Oracle Corporation)
BHO: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\Windows\system32\mscoree.dll [2010-11-05] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-20] (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-13] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-20] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2014-02-06] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2013-06-07] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-831909047-1497575709-4132674677-1000: ubisoft.com/uplaypc -> C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll Keine Datei
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np32dsw.dll [2003-02-11] (Macromedia, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\Extensions\artur.dubovoy@gmail.com [2015-09-16]
FF Extension: YouTube Center - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\Extensions\jid1-cwbvBTE216jjpg@jetpack.xpi [2014-04-02]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2014-02-19]
FF Extension: Adblock Plus - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\6rhc2ovr.default-1380013996825\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-06]
Chrome:
=======
CHR Profile: C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [276992 2015-08-04] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [887128 2015-08-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [461672 2015-08-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [461672 2015-08-26] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1213072 2015-08-26] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [228104 2015-08-13] (Avira Operations GmbH & Co. KG)
S3 jswpsapi; C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\WPS\jswpsapi.exe [954368 2013-03-12] (Wireless) [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe [235696 2015-07-31] (McAfee, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S3 GenericMount Helper Service; "C:\Program Files\Norton Ghost\Shared\Drivers\GenericMountHelper.exe" [X]
S3 SymSnapService; "C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe" [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\i386\AODDriver2.sys [50400 2014-02-11] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-08-26] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-08-26] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-22] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-10] (Avira Operations GmbH & Co. KG)
S3 GenericMount; C:\Windows\System32\DRIVERS\GenericMount.sys [57840 2010-02-12] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
R0 RRamdisk; C:\Windows\System32\DRIVERS\rramdisk.sys [12288 2008-11-12] (gavotte) [Datei ist nicht signiert]
R3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [801896 2011-04-08] (Realtek Semiconductor Corporation )
S3 amdiox86; system32\DRIVERS\amdiox86.sys [X]
S3 AODDriver4.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [X]
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Tim\AppData\Local\Temp\catchme.sys [X]
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015x\WNt600x86\Sandra.sys [X]
U2 V2iMount; kein ImagePath
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-09-16 20:02 - 2015-09-16 20:02 - 00001432 _____ C:\Users\Tim\Desktop\JRT.txt
2015-09-16 20:02 - 2015-09-16 20:02 - 00000000 ____D C:\Users\Tim\Downloads\FRST-OlderVersion
2015-09-16 19:56 - 2015-09-16 19:57 - 00000000 ____D C:\AdwCleaner
2015-09-16 19:50 - 2015-09-16 19:50 - 01798976 _____ (Malwarebytes) C:\Users\Tim\Desktop\JRT.exe
2015-09-16 19:49 - 2015-09-16 19:49 - 01660416 _____ C:\Users\Tim\Desktop\AdwCleaner_5.007.exe
2015-09-16 19:44 - 2015-09-16 19:53 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-16 19:44 - 2015-09-16 19:51 - 00001054 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-16 19:44 - 2015-09-16 19:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-16 19:44 - 2015-09-16 19:44 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-09-16 19:44 - 2015-06-18 08:41 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-09-16 19:44 - 2015-06-18 08:41 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-16 19:44 - 2015-06-18 08:41 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-16 19:43 - 2015-09-16 19:44 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Tim\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-14 19:18 - 2015-09-14 19:18 - 00018258 _____ C:\ComboFix.txt
2015-09-14 19:11 - 2015-09-14 19:18 - 00000000 ____D C:\ComboFix
2015-09-14 19:10 - 2015-09-14 19:18 - 00000000 ____D C:\Qoobox
2015-09-14 19:10 - 2015-09-14 19:17 - 00000000 ____D C:\Windows\erdnt
2015-09-14 19:10 - 2015-09-14 19:10 - 05635119 ____R (Swearware) C:\Users\Tim\Downloads\ComboFix.exe
2015-09-14 19:10 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2015-09-14 19:10 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2015-09-14 19:10 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-09-14 19:10 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-09-14 19:10 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-09-14 19:10 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2015-09-14 19:10 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2015-09-14 19:10 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2015-09-14 19:08 - 2015-09-16 19:51 - 00001222 _____ C:\Users\Tim\Desktop\Revo Uninstaller.lnk
2015-09-14 19:08 - 2015-09-14 19:08 - 00000000 ____D C:\Program Files\VS Revo Group
2015-09-14 19:07 - 2015-09-14 19:07 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Tim\Downloads\revosetup95.exe
2015-09-14 18:26 - 2015-09-16 20:02 - 00000000 ____D C:\Users\Tim\Desktop\Neuer Ordner (2)
2015-09-14 18:18 - 2015-09-16 20:02 - 00012202 _____ C:\Users\Tim\Downloads\FRST.txt
2015-09-14 18:18 - 2015-09-16 20:02 - 00000000 ____D C:\FRST
2015-09-14 18:18 - 2015-09-14 18:18 - 00380416 _____ C:\Users\Tim\Downloads\Gmer-19357.exe
2015-09-14 18:18 - 2015-09-14 18:18 - 00035586 _____ C:\Users\Tim\Downloads\Addition.txt
2015-09-14 18:17 - 2015-09-16 20:02 - 01695232 _____ (Farbar) C:\Users\Tim\Downloads\FRST.exe
2015-09-14 18:16 - 2015-09-14 18:16 - 00000000 _____ C:\Users\Tim\defogger_reenable
2015-09-14 18:15 - 2015-09-14 18:15 - 00050477 _____ C:\Users\Tim\Downloads\Defogger.exe
2015-09-14 18:12 - 2015-09-14 18:12 - 00008610 _____ C:\Users\Tim\Desktop\bluescreen.txt
2015-09-13 19:23 - 2015-09-14 18:36 - 00000951 _____ C:\Users\Tim\Downloads\BlueScreenView.cfg
2015-09-13 19:22 - 2015-09-13 19:22 - 01097176 _____ (Avira Operations GmbH & Co. KG) C:\Users\Tim\Downloads\avira_registry_cleaner_de.exe
2015-09-13 19:18 - 2015-01-29 10:11 - 00061024 _____ (NirSoft) C:\Users\Tim\Downloads\BlueScreenView.exe
2015-09-13 19:18 - 2015-01-29 10:11 - 00018488 _____ C:\Users\Tim\Downloads\BlueScreenView.chm
2015-09-13 19:17 - 2015-09-13 19:17 - 01162528 _____ C:\Users\Tim\Downloads\BlueScreenView - CHIP-Installer.exe
2015-09-13 19:17 - 2015-09-13 19:17 - 00067310 _____ C:\Users\Tim\Downloads\bluescreenview_v1.55.zip
2015-09-13 19:12 - 2015-09-13 19:12 - 05813872 _____ (ParetoLogic Inc.) C:\Users\Tim\Desktop\ParetoLogic PC Health Advisor_de.exe
2015-09-13 19:08 - 2015-09-13 19:08 - 00143592 _____ C:\Windows\Minidump\091315-13665-01.dmp
2015-09-13 18:47 - 2015-09-13 18:47 - 00143592 _____ C:\Windows\Minidump\091315-23696-01.dmp
2015-09-13 17:21 - 2015-09-13 17:21 - 00143592 _____ C:\Windows\Minidump\091315-13525-01.dmp
2015-09-08 22:27 - 2015-08-18 03:14 - 00344168 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-09-08 22:27 - 2015-08-15 08:06 - 19856896 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-09-08 22:27 - 2015-08-15 07:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-09-08 22:27 - 2015-08-15 07:53 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-09-08 22:27 - 2015-08-15 07:40 - 00504832 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-09-08 22:27 - 2015-08-15 07:40 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-09-08 22:27 - 2015-08-15 07:39 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-09-08 22:27 - 2015-08-15 07:39 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-09-08 22:27 - 2015-08-15 07:38 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-09-08 22:27 - 2015-08-15 07:35 - 02279424 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-09-08 22:27 - 2015-08-15 07:33 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-09-08 22:27 - 2015-08-15 07:32 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-09-08 22:27 - 2015-08-15 07:30 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-09-08 22:27 - 2015-08-15 07:29 - 00665600 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-09-08 22:27 - 2015-08-15 07:29 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-09-08 22:27 - 2015-08-15 07:29 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-09-08 22:27 - 2015-08-15 07:29 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-09-08 22:27 - 2015-08-15 07:24 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-09-08 22:27 - 2015-08-15 07:21 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-09-08 22:27 - 2015-08-15 07:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-09-08 22:27 - 2015-08-15 07:14 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-09-08 22:27 - 2015-08-15 07:12 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-09-08 22:27 - 2015-08-15 07:11 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-09-08 22:27 - 2015-08-15 07:10 - 04520448 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-09-08 22:27 - 2015-08-15 07:04 - 12857344 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-09-08 22:27 - 2015-08-15 07:02 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-09-08 22:27 - 2015-08-15 07:02 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-09-08 22:27 - 2015-08-15 07:01 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-09-08 22:27 - 2015-08-15 07:01 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-09-08 22:27 - 2015-08-15 06:43 - 01951232 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-09-08 22:27 - 2015-08-15 06:39 - 01310720 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-09-08 22:27 - 2015-08-15 06:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-09-08 22:25 - 2015-09-02 04:48 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-09-08 22:25 - 2015-09-02 04:48 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-08 22:25 - 2015-09-02 04:48 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-09-08 22:25 - 2015-09-02 04:48 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-09-08 22:25 - 2015-09-02 03:36 - 02384896 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-09-08 22:25 - 2015-09-02 03:33 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-08 22:25 - 2015-08-27 19:58 - 01391104 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-09-08 22:25 - 2015-08-27 19:58 - 01241088 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-09-08 22:25 - 2015-08-27 19:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-09-08 22:25 - 2015-08-27 19:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-09-08 22:25 - 2015-08-05 19:41 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-08 22:25 - 2015-08-05 19:40 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-09-08 22:25 - 2015-08-05 19:40 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-09-08 22:25 - 2015-08-04 19:48 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-09-08 22:25 - 2015-08-04 19:47 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-09-08 22:25 - 2015-08-04 19:47 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-09-08 22:25 - 2015-08-04 19:46 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-09-08 22:25 - 2015-08-04 19:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-09-08 22:25 - 2015-08-04 18:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-09-08 22:25 - 2015-07-22 19:57 - 03989952 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-09-08 22:25 - 2015-07-22 19:57 - 03934656 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-09-08 22:25 - 2015-07-22 19:57 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-09-08 22:25 - 2015-07-22 19:57 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-09-08 22:25 - 2015-07-22 19:54 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00937984 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-09-08 22:25 - 2015-07-22 19:53 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-09-08 22:25 - 2015-07-22 19:52 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-09-08 22:25 - 2015-07-22 19:52 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-09-08 22:25 - 2015-07-22 19:52 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-09-08 22:25 - 2015-07-22 19:52 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-09-08 22:25 - 2015-07-22 19:47 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-09-08 22:25 - 2015-07-22 19:46 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-09-08 22:25 - 2015-07-22 19:42 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-09-08 22:25 - 2015-07-22 19:42 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-09-08 22:25 - 2015-07-22 18:38 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-09-08 22:25 - 2015-07-22 18:34 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-09-08 22:25 - 2015-07-22 18:34 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-09-08 22:25 - 2015-07-22 18:33 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-09-08 22:25 - 2015-07-09 19:42 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-09-08 22:25 - 2015-07-09 19:42 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-09-08 22:20 - 2015-08-26 19:56 - 02953728 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-09-08 22:20 - 2015-08-26 19:56 - 02061824 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-09-08 22:20 - 2015-08-26 19:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-09-08 22:20 - 2015-08-26 19:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-09-08 22:20 - 2015-08-26 19:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-09-08 22:20 - 2015-08-26 19:56 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-09-08 22:20 - 2015-08-26 19:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-09-08 22:20 - 2015-08-26 19:55 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-09-08 22:20 - 2015-08-26 19:55 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-09-08 22:20 - 2015-08-26 19:55 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-09-08 22:20 - 2015-08-26 19:55 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-09-08 22:20 - 2015-07-15 04:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-09-08 22:20 - 2015-06-25 11:48 - 00105408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-09-08 22:20 - 2015-06-25 11:44 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-09-08 22:20 - 2015-06-25 11:44 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-09-04 15:29 - 2015-09-04 15:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2015-09-04 15:29 - 2015-09-04 15:29 - 00000000 ____D C:\Program Files\McAfee Security Scan
2015-08-30 10:06 - 2015-08-30 10:06 - 00000000 ___RD C:\Program Files\Skype
2015-08-30 10:06 - 2015-08-30 10:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-30 10:06 - 2015-08-30 10:06 - 00000000 ____D C:\Program Files\Common Files\Skype
2015-08-28 19:23 - 2015-09-14 19:09 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-08-26 00:26 - 2015-08-26 00:26 - 00000000 ____D C:\ProgramData\ATI
2015-08-26 00:17 - 2015-08-30 11:01 - 00000000 ____D C:\Program Files\Raptr
2015-08-26 00:17 - 2015-08-26 00:17 - 00057073 _____ C:\Windows\system32\CCCInstall_201508260017018074.log
2015-08-26 00:16 - 2015-08-26 00:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-09-16 20:00 - 2009-07-14 06:34 - 00062976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-16 20:00 - 2009-07-14 06:34 - 00062976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-16 19:59 - 2015-08-13 16:36 - 00000000 ____D C:\Users\Tim\AppData\Local\Spotify
2015-09-16 19:59 - 2015-08-13 16:33 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Spotify
2015-09-16 19:59 - 2015-01-16 21:06 - 00000000 ____D C:\Program Files\Steam
2015-09-16 19:59 - 2013-07-28 17:59 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Skype
2015-09-16 19:58 - 2015-07-18 19:23 - 00005815 _____ C:\Windows\setupact.log
2015-09-16 19:58 - 2013-07-31 19:02 - 00619192 _____ C:\Windows\PFRO.log
2015-09-16 19:58 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-16 19:57 - 2013-07-28 16:22 - 01619284 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-16 19:57 - 2013-07-28 16:19 - 01845560 _____ C:\Windows\WindowsUpdate.log
2015-09-16 19:51 - 2015-08-13 16:36 - 00001793 _____ C:\Users\Tim\Desktop\Spotify.lnk
2015-09-16 19:51 - 2015-08-13 16:36 - 00001779 _____ C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-09-16 19:51 - 2015-06-08 19:11 - 00001035 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2015-09-16 19:51 - 2015-03-20 18:20 - 00001848 _____ C:\Users\Public\Desktop\o2 Surfstick.lnk
2015-09-16 19:51 - 2015-02-07 16:08 - 00000949 _____ C:\Users\Tim\Desktop\SopCast.lnk
2015-09-16 19:51 - 2015-01-23 17:10 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-09-16 19:51 - 2015-01-17 15:15 - 00001016 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2015-09-16 19:51 - 2015-01-16 21:06 - 00000915 _____ C:\Users\Public\Desktop\Steam.lnk
2015-09-16 19:51 - 2014-04-29 16:19 - 00002039 _____ C:\Users\Tim\Desktop\Universal Replayer.lnk
2015-09-16 19:51 - 2014-03-30 17:21 - 00001889 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2015-09-16 19:51 - 2014-03-30 17:21 - 00001833 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2015-09-16 19:51 - 2014-02-27 22:41 - 00002681 _____ C:\Users\Public\Desktop\Skype.lnk
2015-09-16 19:51 - 2013-11-27 17:30 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-09-16 19:51 - 2013-11-27 17:30 - 00001983 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-09-16 19:51 - 2013-11-19 16:04 - 00002211 _____ C:\Users\Public\Desktop\PokerStrategy.com Equilab.lnk
2015-09-16 19:51 - 2013-11-15 15:46 - 00001961 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2015-09-16 19:51 - 2013-09-23 22:50 - 00001068 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2015-09-16 19:51 - 2013-07-28 18:26 - 00001993 _____ C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\888poker.lnk
2015-09-16 19:51 - 2013-07-28 18:26 - 00001969 _____ C:\Users\Tim\Desktop\888poker.lnk
2015-09-16 19:51 - 2013-07-28 18:09 - 00001018 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-09-16 19:51 - 2013-07-28 17:56 - 00001048 _____ C:\ProgramData\Microsoft\Windows\Start Menu\PokerStars.fr.lnk
2015-09-16 19:51 - 2013-07-28 17:56 - 00001048 _____ C:\ProgramData\Microsoft\Windows\Start Menu\PokerStars.eu.lnk
2015-09-16 19:51 - 2013-07-28 17:56 - 00001036 _____ C:\Users\Public\Desktop\PokerStars.fr.lnk
2015-09-16 19:51 - 2013-07-28 17:56 - 00001036 _____ C:\Users\Public\Desktop\PokerStars.eu.lnk
2015-09-16 19:51 - 2013-07-28 17:28 - 00001105 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-09-16 19:51 - 2013-07-28 17:28 - 00001099 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-09-16 19:51 - 2013-07-28 17:08 - 00002207 _____ C:\Users\Public\Desktop\TP-LINK Wireless Configuration Utility.lnk
2015-09-16 19:51 - 2013-07-28 16:19 - 00001409 _____ C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-09-16 19:51 - 2013-07-28 16:16 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2015-09-16 19:51 - 2013-07-28 16:16 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2015-09-16 19:51 - 2009-07-14 06:46 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2015-09-16 19:51 - 2009-07-14 06:42 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
2015-09-16 19:51 - 2009-07-14 06:42 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2015-09-16 19:51 - 2009-07-14 06:42 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2015-09-16 19:51 - 2009-07-14 06:42 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2015-09-16 19:51 - 2009-07-14 06:37 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2015-09-16 19:44 - 2013-08-19 12:33 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-16 17:20 - 2013-07-28 17:46 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-14 19:18 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Default
2015-09-14 19:18 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2015-09-14 19:17 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2015-09-14 18:16 - 2013-07-28 16:19 - 00000000 ____D C:\Users\Tim
2015-09-14 18:14 - 2013-08-19 12:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-09-13 21:38 - 2013-08-19 12:38 - 00000000 ____D C:\Program Files\Avira
2015-09-13 19:08 - 2013-08-01 19:32 - 00000000 ____D C:\Windows\Minidump
2015-09-13 18:54 - 2014-10-21 12:26 - 00000000 ____D C:\Program Files\SleepTimer Ultimate
2015-09-13 14:20 - 2014-12-13 14:08 - 00000000 ____D C:\Users\Tim\Desktop\Auszüge
2015-09-09 20:17 - 2013-09-23 10:32 - 00000000 ____D C:\ProgramData\Package Cache
2015-09-09 20:12 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-09-09 20:05 - 2009-07-14 06:33 - 00287288 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-09 20:04 - 2009-07-14 10:56 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-09 20:04 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2015-09-08 23:14 - 2013-08-14 23:16 - 00000000 ____D C:\Windows\system32\MRT
2015-09-07 19:18 - 2013-07-28 17:56 - 00000000 ____D C:\Users\Tim\AppData\Local\PokerStars.EU
2015-09-01 18:18 - 2014-01-13 19:30 - 00000000 ____D C:\Users\Tim\Desktop\phonoElit
2015-09-01 17:59 - 2013-07-28 17:56 - 00000000 ____D C:\Program Files\PokerStars.EU
2015-08-30 10:06 - 2013-07-28 17:59 - 00000000 ____D C:\ProgramData\Skype
2015-08-29 06:20 - 2013-07-28 17:28 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-08-26 23:52 - 2013-08-19 12:39 - 00136728 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-08-26 23:52 - 2013-08-19 12:39 - 00108448 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-08-26 18:36 - 2013-08-11 10:19 - 132039072 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-26 00:16 - 2013-07-28 16:38 - 00000000 ____D C:\Program Files\AMD
2015-08-26 00:16 - 2013-07-28 16:28 - 00000000 ____D C:\ProgramData\AMD
2015-08-26 00:14 - 2013-09-23 10:31 - 00000000 ____D C:\AMD
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2015-06-08 19:59 - 2015-06-08 19:59 - 0001943 _____ () C:\Users\Tim\AppData\Local\recently-used.xbel
2014-10-13 18:03 - 2014-10-13 18:03 - 0000017 _____ () C:\Users\Tim\AppData\Local\resmon.resmoncfg
Einige Dateien in TEMP:
====================
C:\Users\Tim\AppData\Local\temp\avgnt.exe
C:\Users\Tim\AppData\Local\temp\sqlite3.dll
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-09-13 14:46
==================== Ende vom FRST.txt ============================ |