CrackyMF | 01.11.2015 16:52 | Danke für die Unterstützung. Hier die Logs.
Maleware: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 01.11.2015
Suchlaufzeit: 15:29
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.2.0.1024
Malware-Datenbank: v2015.11.01.03
Rootkit-Datenbank: v2015.10.28.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: pc
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 314822
Abgelaufene Zeit: 33 Min., 43 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 3
PUP.Optional.FaceMoods, HKU\S-1-5-21-4211159687-1543994603-830180300-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0D7562AE-8EF6-416d-A838-AB665251703A}, In Quarantäne, [5f7826520f7c6bcb9fecd74c82808f71],
PUP.Optional.OpenCandy, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\OpenCandyHelperRunOnce, Löschen bei Neustart, [3e99e0988308c076928d97e081821be5],
PUP.Optional.FaceMoods, HKU\S-1-5-18\SOFTWARE\facemoods.com, In Quarantäne, [bc1bb9bf96f5ac8ac7c37ee38b78dd23],
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 5
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\096EEF0FE0E04C9A8EAE967F57037EB1, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\OpenCandy_096EEF0FE0E04C9A8EAE967F57037EB1, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\OpenCandy_759D98B1E9F14170A177CEBCAB8F5C71, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\OpenCandy_A0C0E7F2B97840D6ABB11272A415A410, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
Dateien: 25
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\OpenCandy_759D98B1E9F14170A177CEBCAB8F5C71\DLMgr_3_1.6.44.exe, In Quarantäne, [b91e93e5286312240c4d58fbf60e46ba],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\OpenCandy_A0C0E7F2B97840D6ABB11272A415A410\LatestDLMgr.exe, In Quarantäne, [993e3543038891a5d980c88b8c7810f0],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\RHEng\5207B3E17F404C8BB35700F7DFAA59D2\du77h.exe, In Quarantäne, [f4e33b3d513a39fd1b9dff0540c16997],
PUP.Optional.WinYahoo, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\extensions\jid1-G80Ec8LLEbK5fQ@jetpack.xpi, In Quarantäne, [7166c4b4246758de0b98d4bb7b8815eb],
PUP.Optional.WinYahoo, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\searchplugins\yahoo-web.xml, In Quarantäne, [faddc7b1117abd79209b9b273bc843bd],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\096EEF0FE0E04C9A8EAE967F57037EB1\EBB77268-338F-4C6A-8590-AD88FED26F4A, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\096EEF0FE0E04C9A8EAE967F57037EB1\LinkuryInstaller.msi, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\096EEF0FE0E04C9A8EAE967F57037EB1\LinkuryInstaller_p1v5.exe, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\096EEF0FE0E04C9A8EAE967F57037EB1\OCBrowserHelper_1.0.2.72.dll, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\OpenCandy_759D98B1E9F14170A177CEBCAB8F5C71\registrybooster21.exe, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\OpenCandy_759D98B1E9F14170A177CEBCAB8F5C71\registrybooster21Wrapped.exe, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\OpenCandy_A0C0E7F2B97840D6ABB11272A415A410\2332.ico, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
PUP.Optional.OpenCandy, C:\Users\pc\AppData\Roaming\OpenCandy\OpenCandy_A0C0E7F2B97840D6ABB11272A415A410\LinkuryInstaller_p1v6.exe, In Quarantäne, [4a8da3d595f68da9c0d878c7d230ca36],
PUP.Optional.FaceMoods, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods._xpiupdate", true);), Ersetzt,[a0375325a5e63bfb0804134f48bc13ed]
PUP.Optional.FaceMoods, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js, Gut: (), Schlecht: (nces
/* Do not edit this file.
*
* If you ), Ersetzt,[74635c1cfe8d3cfaf6166cf62ed6d62a]
PUP.Optional.FaceMoods, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js, Gut: (), Schlecht: (rences
/* Do not edit this file.
*
* If you make ), Ersetzt,[1fb8f385177472c4d339a8babf4556aa]
PUP.Optional.FaceMoods, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js, Gut: (), Schlecht: (
/* Do not edit this file.
*
* If you make cha), Ersetzt,[1fb80a6e42499b9b39d3d78bc93ba25e]
PUP.Optional.FaceMoods, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js, Gut: (), Schlecht: (ces
/* Do not edit this file.
*
* If you make changes to this file w), Ersetzt,[10c74b2d800b6fc7bc504e14e61e659b]
PUP.Optional.FaceMoods, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js, Gut: (), Schlecht: (his file.
*
* If you make changes to this file whi), Ersetzt,[9c3b87f129628fa71cf0b4ae9b6917e9]
PUP.Optional.FaceMoods, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js, Gut: (), Schlecht: (s
/* Do not edit this file.
*
* If you make changes to), Ersetzt,[02d5d5a39af161d5f319d38ff113d22e]
PUP.Optional.FaceMoods, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js, Gut: (), Schlecht: ( Do not edit this file.
*
* If you make changes to this file while the a), Ersetzt,[cb0cdb9dcfbc5bdb000c91d1be4647b9]
PUP.Optional.FaceMoods, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js, Gut: (), Schlecht: (is file.
*
* If you make changes to this fi), Ersetzt,[4b8ca6d2d2b956e067a57de54fb545bb]
PUP.Optional.FaceMoods, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js, Gut: (), Schlecht: (ferences
/* Do not edit this file.
*
* If you ), Ersetzt,[ffd8f682e9a2f73ff21ac1a125dfdc24]
PUP.Optional.FaceMoods, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js, Gut: (), Schlecht: (es
/* Do not edit this file.
*
* If you make c), Ersetzt,[a730ceaae7a4e15565a73131a85c16ea]
PUP.Optional.WinYahoo, C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "resource://jid1-g80ec8llebk5fq-at-jetpack/newtab/data/newtab.html");), Ersetzt,[b7202d4bdab1b2844ff4e67d689c8b75]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) AwdCleaner: Code:
# AdwCleaner v5.015 - Bericht erstellt am 01/11/2015 um 15:32:51
# Aktualisiert am 26/10/2015 von Xplode
# Datenbank : 2015-10-29.1 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x86)
# Benutzername : pc - PC-PC
# Gestartet von : C:\Users\pc\Desktop\Adw\AdwCleaner_5.015.exe
# Option : Suchlauf
# Unterstützung : hxxp://toolslib.net/forum
***** [ Dienste ] *****
***** [ Ordner ] *****
Ordner Gefunden : C:\Program Files\AVG Secure Search
Ordner Gefunden : C:\Program Files\Common Files\AVG Secure Search
Ordner Gefunden : C:\ProgramData\AVG Secure Search
Ordner Gefunden : C:\ProgramData\AVG Security Toolbar
Ordner Gefunden : C:\Users\pc\AppData\Local\AVG Secure Search
Ordner Gefunden : C:\Users\pc\AppData\Local\OpenCandy
Ordner Gefunden : C:\Users\pc\AppData\Local\YSearchUtil
Ordner Gefunden : C:\Users\pc\AppData\LocalLow\AVG Secure Search
Ordner Gefunden : C:\Users\pc\AppData\Roaming\DesktopIconForAmazon
Ordner Gefunden : C:\Users\pc\AppData\Roaming\OpenCandy
Ordner Gefunden : C:\Users\pc\AppData\Roaming\Systweak
Ordner Gefunden : C:\Users\pc\AppData\Roaming\RHEng
Ordner Gefunden : C:\Windows\system32\config\systemprofile\AppData\Local\YSearchUtil
***** [ Dateien ] *****
Datei Gefunden : C:\Users\pc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\RegistryBooster.lnk
Datei Gefunden : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\user.js
***** [ DLLs ] *****
***** [ Verknüpfungen ] *****
***** [ Geplante Tasks ] *****
Task Gefunden : OpenCandyHelperRunOnce
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\driverscanner
Wert Gefunden : HKCU\Software\Mozilla\Firefox\Extensions [firejump@firejump.net]
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gefunden : HKU\.DEFAULT\Software\AVG Secure Search
Schlüssel Gefunden : HKU\.DEFAULT\Software\facemoods.com
Schlüssel Gefunden : HKCU\Software\Conduit
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : HKCU\Software\systweak
Schlüssel Gefunden : HKCU\Software\YahooPartnerToolbar
Schlüssel Gefunden : HKCU\Software\Reg\Clean
Schlüssel Gefunden : HKLM\SOFTWARE\Reg\Clean
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKU\S-1-5-21-4211159687-1543994603-830180300-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}
Schlüssel Gefunden : HKU\S-1-5-21-4211159687-1543994603-830180300-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKU\S-1-5-21-4211159687-1543994603-830180300-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}
Schlüssel Gefunden : HKU\S-1-5-21-4211159687-1543994603-830180300-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
***** [ Internetbrowser ] *****
[C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js] [Preference] Gefunden : user_pref("extensions.facemoods._xpiupdate", true);
[C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js] [Preference] Gefunden : user_pref("extensions.facemoods.aflt", "_#wbst");
[C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js] [Preference] Gefunden : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4");
[C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js] [Preference] Gefunden : user_pref("extensions.facemoods.first_time", false);
[C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js] [Preference] Gefunden : user_pref("extensions.facemoods.id", "_#287a1604aa7149f5acb4f879694c3acf");
[C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js] [Preference] Gefunden : user_pref("extensions.facemoods.instlDay", "_#15277");
[C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js] [Preference] Gefunden : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com");
[C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js] [Preference] Gefunden : user_pref("extensions.facemoods.sid", "_#287a1604aa7149f5acb4f879694c3acf");
[C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js] [Preference] Gefunden : user_pref("extensions.facemoods.uninst", true);
[C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js] [Preference] Gefunden : user_pref("extensions.facemoods.update", "_#v1.4.0");
[C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\prefs.js] [Preference] Gefunden : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5");
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [5718 Bytes] ########## Junkware: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 7 Home Premium x86
Ran by pc on 01.11.2015 at 16:23:34,71
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\Program Files\pluto tv
Successfully deleted: [Folder] C:\ProgramData\avg security toolbar
Successfully deleted: [Folder] C:\Users\pc\Appdata\Local\opencandy
Successfully deleted: [Folder] C:\Users\pc\Appdata\Local\plutotv
Successfully deleted: [Folder] C:\Users\pc\Appdata\Local\ysearchutil
Successfully deleted: [Folder] C:\Users\pc\AppData\Roaming\desktopiconforamazon
Successfully deleted: [Folder] C:\Users\pc\AppData\Roaming\systweak
~~~ FireFox
Successfully deleted: [File] C:\Users\pc\AppData\Roaming\mozilla\firefox\profiles\rvhwk7gc.default\user.js
Successfully deleted the following from C:\Users\pc\AppData\Roaming\mozilla\firefox\profiles\rvhwk7gc.default\prefs.js
user_pref(extensions.facemoods._xpiupdate, true);
user_pref(extensions.facemoods.aflt, _#wbst);
user_pref(extensions.facemoods.fcmdVrsn, 1.2.7.5.4);
user_pref(extensions.facemoods.first_time, false);
user_pref(extensions.facemoods.id, _#287a1604aa7149f5acb4f879694c3acf);
user_pref(extensions.facemoods.instlDay, _#15277);
user_pref(extensions.facemoods.prtnrId, _#facemoods.com);
user_pref(extensions.facemoods.sid, _#287a1604aa7149f5acb4f879694c3acf);
user_pref(extensions.facemoods.uninst, true);
user_pref(extensions.facemoods.update, _#v1.4.0);
user_pref(extensions.facemoods.vrsn, _#1.4.17.5);
user_pref(extensions.unitedinternet.email.runonceNewUsersShown, true);
Emptied folder: C:\Users\pc\AppData\Roaming\mozilla\firefox\profiles\rvhwk7gc.default\minidumps [182 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.11.2015 at 16:25:44,70
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x86) Version:31-10-2015
durchgeführt von pc (Administrator) auf PC-PC (01-11-2015 16:47:58)
Gestartet von C:\Users\pc\Desktop\FRST
Geladene Profile: pc (Verfügbare Profile: pc)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [782520 2015-09-25] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [433160 2015-09-04] (DivX, LLC)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [9605912 2014-10-14] (Logitech Inc.)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2015-06-16] (Apple Inc.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-29] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AMD AVT] => C:\Program Files\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861640 2015-06-26] (DivX, LLC)
HKLM\...\Run: [Avira SystrayStartTrigger] => C:\Program Files\Avira\Launcher\Avira.SystrayStartTrigger.exe [66320 2015-09-10] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKU\S-1-5-21-4211159687-1543994603-830180300-1000\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2015-06-16] (Apple Inc.)
HKU\S-1-5-21-4211159687-1543994603-830180300-1000\...\Run: [BingSvc] => C:\Users\pc\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-4211159687-1543994603-830180300-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6490904 2015-08-20] (Piriform Ltd)
BootExecute:
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
Tcpip\..\Interfaces\{99002492-41C1-4818-959F-1EEA871CC155}: [DhcpNameServer] 192.168.2.1 192.168.2.1
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
HKU\S-1-5-21-4211159687-1543994603-830180300-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-4211159687-1543994603-830180300-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://de.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
SearchScopes: HKU\S-1-5-21-4211159687-1543994603-830180300-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-4211159687-1543994603-830180300-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-4211159687-1543994603-830180300-1000 -> {A9244EFA-688F-4F73-A940-FC9CECFCF6F8} URL = hxxps://de.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-10-20] (Oracle Corporation)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17] (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-20] (Oracle Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_45-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_45-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_45-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Keine Datei
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default
FF NewTab: resource://jid1-g80ec8llebk5fq-at-jetpack/newtab/data/newtab.html
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Bing
FF Homepage: www.google.de
FF Keyword.URL: hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-19] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2010-05-05] (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2015-09-02] (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-20] (Oracle Corporation)
FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 -> C:\Program Files\Sony\Media Go\npmediago.dll [2010-09-14] (Sony Media Software and Services Inc)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-07-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-07-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-07-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-07-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-07-04] (Apple Inc.)
FF SearchPlugin: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\searchplugins\bing-.xml [2015-05-15]
FF SearchPlugin: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\searchplugins\youtube.xml [2010-07-24]
FF Extension: Bing Search - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\Extensions\bingsearch.full@microsoft.com [2015-05-14] [ist nicht signiert]
FF Extension: Adblock Plus - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-25]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-10-17] [ist nicht signiert]
FF HKU\S-1-5-21-4211159687-1543994603-830180300-1000\...\Firefox\Extensions: [firejump@firejump.net] - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\rvhwk7gc.default\extensions\firejump@firejump.net => nicht gefunden
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17]
CHR HKU\S-1-5-21-4211159687-1543994603-830180300-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2013-04-29] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [932912 2015-09-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [461672 2015-09-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [461672 2015-09-25] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1147720 2015-10-14] (Avira Operations GmbH & Co. KG)
S2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [5814392 2012-11-06] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [196664 2012-10-22] (AVG Technologies CZ, s.r.o.)
R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [240872 2015-09-10] (Avira Operations GmbH & Co. KG)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [Datei ist nicht signiert]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [45184 2012-03-05] (Advanced Micro Devices)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [179936 2012-10-22] (AVG Technologies CZ, s.r.o. )
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [55776 2012-10-15] (AVG Technologies CZ, s.r.o. )
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [19936 2012-09-21] (AVG Technologies CZ, s.r.o. )
S1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [159712 2012-10-02] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [177376 2012-09-21] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [93536 2012-10-05] (AVG Technologies CZ, s.r.o.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108448 2015-09-25] (Avira Operations GmbH & Co. KG)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [35552 2012-09-14] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [164832 2012-09-21] (AVG Technologies CZ, s.r.o.)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136728 2015-07-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-07] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [55912 2015-09-25] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [239168 2011-11-14] (DT Soft Ltd)
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36608 2010-06-14] () [Datei ist nicht signiert]
R3 LGBusEnum; C:\Windows\System32\drivers\LGBusEnum.sys [19720 2009-11-24] (Logitech Inc.)
S3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [39960 2013-05-30] (Logitech Inc.)
R3 LGVirHid; C:\Windows\System32\drivers\LGVirHid.sys [14856 2009-11-24] (Logitech Inc.)
R3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2Mon.sys [25752 2009-10-07] ()
S3 LVUSBSta; C:\Windows\System32\drivers\LVUSBSta.sys [41752 2007-10-12] (Logitech Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] ()
S3 PID_0928; C:\Windows\System32\DRIVERS\LV561AV.SYS [490776 2007-10-12] (Logitech Inc.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-06-10] (Avira Operations GmbH & Co. KG)
S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [98432 2010-04-27] (MCCI)
S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14848 2010-04-27] (MCCI Corporation)
S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [123648 2010-04-27] (MCCI Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\pc\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-11-01 16:25 - 2015-11-01 16:25 - 00002376 _____ C:\Users\pc\Desktop\JRT.txt
2015-11-01 16:23 - 2015-10-05 23:23 - 01801288 _____ (Malwarebytes) C:\Users\pc\Desktop\JRT.exe
2015-11-01 16:22 - 2015-11-01 16:22 - 00000000 ____D C:\Users\pc\Desktop\Junk
2015-11-01 16:21 - 2015-11-01 16:21 - 00007434 _____ C:\Users\pc\Desktop\mbam.txt
2015-11-01 15:32 - 2015-11-01 15:32 - 00000000 ____D C:\AdwCleaner
2015-11-01 15:30 - 2015-11-01 15:30 - 00000000 ____D C:\Users\pc\Desktop\Adw
2015-11-01 15:27 - 2015-11-01 16:19 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-01 15:26 - 2015-11-01 15:26 - 00001060 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-01 15:26 - 2015-11-01 15:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-01 15:26 - 2015-11-01 15:26 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-11-01 15:26 - 2015-10-05 09:50 - 00094936 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-11-01 15:26 - 2015-10-05 09:50 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-11-01 15:26 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-10-31 21:35 - 2015-10-31 21:35 - 00017360 _____ C:\ComboFix.txt
2015-10-31 21:19 - 2015-10-31 21:35 - 00000000 ____D C:\Qoobox
2015-10-31 21:19 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2015-10-31 21:19 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2015-10-31 21:19 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-10-31 21:19 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-10-31 21:19 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-10-31 21:19 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2015-10-31 21:19 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2015-10-31 21:19 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2015-10-31 21:18 - 2015-10-31 21:34 - 00000000 ____D C:\Windows\erdnt
2015-10-31 21:17 - 2015-10-31 21:17 - 05637361 ____R (Swearware) C:\Users\pc\Desktop\ComboFix.exe
2015-10-22 15:02 - 2015-11-01 16:17 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-10-22 15:00 - 2015-10-22 15:44 - 00000000 ____D C:\Users\pc\Desktop\mbar
2015-10-22 06:58 - 2015-11-01 16:47 - 00000000 ____D C:\FRST
2015-10-22 06:56 - 2015-11-01 16:46 - 00000000 ____D C:\Users\pc\Desktop\FRST
2015-10-22 06:21 - 2015-10-22 06:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-10-22 06:18 - 2015-11-01 15:24 - 00000000 ____D C:\Users\pc\Desktop\Malware
2015-10-20 21:04 - 2015-10-20 21:04 - 00000000 ____D C:\Program Files\Common Files\Java
2015-10-17 11:15 - 2015-10-19 21:42 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-10-16 12:22 - 2015-09-18 18:47 - 00023384 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-10-16 12:22 - 2015-09-18 18:44 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-10-16 12:22 - 2015-09-18 18:44 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-10-16 12:22 - 2015-09-18 18:44 - 00587776 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-10-16 12:22 - 2015-09-18 18:44 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-10-16 12:22 - 2015-09-18 18:44 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-10-16 12:22 - 2015-09-18 18:35 - 00999936 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-10-14 14:12 - 2015-10-01 18:50 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-10-14 14:12 - 2015-10-01 18:50 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-10-14 14:12 - 2015-10-01 18:50 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-10-14 14:12 - 2015-10-01 18:50 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-10-14 14:12 - 2015-10-01 18:50 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-10-14 14:12 - 2015-10-01 17:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-10-14 14:12 - 2015-09-29 04:05 - 03990976 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-10-14 14:12 - 2015-09-29 04:05 - 03936192 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-10-14 14:12 - 2015-09-29 04:02 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-10-14 14:12 - 2015-09-29 03:59 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-10-14 14:12 - 2015-09-29 03:59 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-10-14 14:12 - 2015-09-29 03:59 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-10-14 14:12 - 2015-09-29 03:59 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-10-14 14:12 - 2015-09-29 03:59 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-10-14 14:12 - 2015-09-29 03:59 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-10-14 14:12 - 2015-09-29 03:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-10-14 14:12 - 2015-09-29 03:58 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-10-14 14:12 - 2015-09-29 03:58 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-10-14 14:12 - 2015-09-29 03:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-10-14 14:12 - 2015-09-29 03:58 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-10-14 14:12 - 2015-09-29 03:58 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-10-14 14:12 - 2015-09-29 03:58 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-10-14 14:12 - 2015-09-29 03:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-10-14 14:12 - 2015-09-29 03:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-10-14 14:12 - 2015-09-29 03:49 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-10-14 14:12 - 2015-09-29 03:49 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-10-14 14:12 - 2015-09-29 02:43 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-10-14 14:12 - 2015-09-29 02:43 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-10-14 14:12 - 2015-09-29 02:43 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-10-14 14:12 - 2015-09-25 18:59 - 02955776 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-10-14 14:12 - 2015-09-25 18:59 - 02061824 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-10-14 14:12 - 2015-09-25 18:59 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-10-14 14:12 - 2015-09-25 18:59 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-10-14 14:12 - 2015-09-25 18:59 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-10-14 14:12 - 2015-09-25 18:59 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-10-14 14:12 - 2015-09-25 18:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-10-14 14:12 - 2015-09-25 18:58 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-10-14 14:12 - 2015-09-25 18:58 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-10-14 14:12 - 2015-09-25 18:58 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-10-14 14:12 - 2015-09-25 18:58 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-10-14 14:12 - 2015-09-18 19:58 - 00345688 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-10-14 14:12 - 2015-09-16 04:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-10-14 14:12 - 2015-09-16 04:32 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-10-14 14:12 - 2015-09-16 04:26 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-10-14 14:12 - 2015-09-16 04:26 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-10-14 14:12 - 2015-09-16 04:23 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-10-14 14:12 - 2015-09-16 04:23 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-10-14 14:12 - 2015-09-16 04:22 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-10-14 14:12 - 2015-09-16 04:18 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-10-14 14:12 - 2015-09-16 04:15 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-10-14 14:12 - 2015-09-16 04:10 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-10-14 14:12 - 2015-09-16 04:04 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-10-14 14:12 - 2015-09-16 03:56 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-10-14 14:12 - 2015-09-16 03:56 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-10-14 14:12 - 2015-09-16 03:55 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-10-14 14:12 - 2015-09-16 03:34 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-10-14 14:12 - 2015-09-16 03:32 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-10-14 14:12 - 2015-09-15 18:42 - 00139096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-10-14 14:12 - 2015-09-15 18:42 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-10-14 14:12 - 2015-09-15 18:36 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-10-14 14:12 - 2015-09-15 18:36 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-10-14 14:12 - 2015-09-15 18:36 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-10-14 14:12 - 2015-09-15 18:36 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-10-14 14:12 - 2015-09-15 18:36 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-10-14 14:12 - 2015-09-15 18:36 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-10-14 14:12 - 2015-09-15 18:35 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-10-14 14:12 - 2015-08-06 18:44 - 12875776 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-10-14 14:12 - 2015-08-06 18:44 - 01498624 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00901264 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00066400 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00022368 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-14 14:12 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-10-14 14:11 - 2015-09-16 04:58 - 20357632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-10-14 14:11 - 2015-09-16 04:45 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-10-14 14:11 - 2015-09-16 04:33 - 00504832 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-10-14 14:11 - 2015-09-16 04:33 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-10-14 14:11 - 2015-09-16 04:32 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-10-14 14:11 - 2015-09-16 04:31 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-10-14 14:11 - 2015-09-16 04:28 - 02279936 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-10-14 14:11 - 2015-09-16 04:24 - 00480256 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-10-14 14:11 - 2015-09-16 04:22 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-10-14 14:11 - 2015-09-16 04:07 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-10-14 14:11 - 2015-09-16 04:06 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-10-14 14:11 - 2015-09-16 04:05 - 04527616 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-10-14 14:11 - 2015-09-16 04:05 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-10-14 14:11 - 2015-09-16 03:58 - 12853760 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-10-14 14:11 - 2015-09-16 03:58 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-10-14 14:11 - 2015-09-16 03:55 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-10-14 14:11 - 2015-09-16 03:37 - 02011136 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-10-11 11:04 - 2015-10-11 11:04 - 04530560 _____ (InstallShield Software Corporation ) C:\Users\pc\Downloads\AVM_FRITZ_WLAN_Repeater_310_Assistent (1).exe
2015-10-11 11:03 - 2015-10-11 11:05 - 04530560 _____ (InstallShield Software Corporation ) C:\Users\pc\Downloads\AVM_FRITZ_WLAN_Repeater_310_Assistent.exe
2015-10-03 19:58 - 2015-10-03 19:58 - 00002687 _____ C:\Users\Public\Desktop\Skype.lnk
2015-10-03 19:58 - 2015-10-03 19:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-10-03 19:58 - 2015-10-03 19:58 - 00000000 ____D C:\Program Files\Common Files\Skype
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-11-01 16:44 - 2011-04-02 03:59 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-01 16:31 - 2009-07-14 05:34 - 00024192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-01 16:31 - 2009-07-14 05:34 - 00024192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-01 16:25 - 2012-04-08 03:34 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-01 16:21 - 2010-07-22 16:47 - 01634360 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-01 16:21 - 2010-07-22 16:39 - 02004594 _____ C:\Windows\WindowsUpdate.log
2015-11-01 16:17 - 2015-09-18 20:32 - 00003183 _____ C:\Windows\setupact.log
2015-11-01 16:17 - 2011-04-02 03:59 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-01 16:17 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-01 16:16 - 2015-09-18 20:32 - 00009596 _____ C:\Windows\PFRO.log
2015-11-01 16:16 - 2015-08-20 08:20 - 00000000 ____D C:\Windows\Minidump
2015-10-31 21:35 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Default
2015-10-31 21:35 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public
2015-10-31 21:31 - 2009-07-14 03:04 - 00000215 _____ C:\Windows\system.ini
2015-10-22 06:11 - 2012-10-26 23:44 - 00000000 ____D C:\Hijavckthis
2015-10-22 05:36 - 2012-05-05 12:04 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-10-22 02:09 - 2015-03-12 15:21 - 00000000 ____D C:\Users\pc\Desktop\BA Arbeit
2015-10-22 02:08 - 2014-09-23 22:49 - 00000000 ____D C:\Users\pc\AppData\Local\Battle.net
2015-10-21 22:28 - 2014-09-23 22:49 - 00000000 ____D C:\Program Files\Battle.net
2015-10-21 00:24 - 2010-07-24 14:41 - 00000000 ____D C:\Users\pc\AppData\Roaming\Skype
2015-10-20 21:04 - 2015-07-10 21:44 - 00000000 ____D C:\ProgramData\Oracle
2015-10-20 21:04 - 2015-07-10 21:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-10-20 21:03 - 2015-08-27 17:40 - 00000000 ____D C:\Users\pc\.oracle_jre_usage
2015-10-20 21:02 - 2015-07-10 21:45 - 00097888 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-10-20 21:02 - 2010-12-25 18:27 - 00000000 ____D C:\Program Files\Java
2015-10-20 19:36 - 2013-09-21 23:40 - 00000000 ____D C:\ATI Treiber
2015-10-20 18:14 - 2011-10-31 23:19 - 00484864 ___SH C:\Users\pc\Desktop\Thumbs.db
2015-10-20 16:38 - 2011-04-30 21:07 - 00000000 ____D C:\Users\pc\AppData\Local\CrashDumps
2015-10-20 01:25 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2015-10-19 10:25 - 2012-04-08 03:34 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-10-19 10:25 - 2011-05-13 23:30 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-10-16 12:37 - 2014-12-10 13:24 - 00000000 ____D C:\Windows\system32\appraiser
2015-10-16 12:37 - 2014-05-06 16:35 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-10-16 12:27 - 2013-04-25 10:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-10-14 18:20 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE
2015-10-14 15:02 - 2013-08-15 10:58 - 00000000 ____D C:\Windows\system32\MRT
2015-10-14 14:58 - 2010-07-24 17:58 - 141105520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-10-14 14:04 - 2015-09-02 09:17 - 00001096 _____ C:\Users\Public\Desktop\Avira Launcher.lnk
2015-10-14 14:04 - 2014-07-22 20:40 - 00000000 ____D C:\ProgramData\Package Cache
2015-10-14 14:04 - 2013-02-17 19:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-10-11 10:29 - 2015-04-05 01:12 - 00000000 ___SD C:\Windows\system32\GWX
2015-10-03 19:58 - 2010-07-24 14:40 - 00000000 ___RD C:\Program Files\Skype
2015-10-03 19:58 - 2010-07-24 14:40 - 00000000 ____D C:\ProgramData\Skype
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2012-05-19 19:12 - 2012-10-13 19:56 - 0000000 _____ () C:\Users\pc\AppData\Roaming\Enhance Timing
2012-05-19 19:00 - 2015-09-18 20:00 - 0000000 _____ () C:\Users\pc\AppData\Roaming\Machines
2013-09-01 01:26 - 2013-09-01 01:31 - 0005120 _____ () C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-01-21 22:06 - 2011-02-05 19:09 - 0001940 _____ () C:\Users\pc\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
2010-07-24 14:42 - 2010-07-24 14:42 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-09-18 20:00 - 2015-09-18 20:00 - 0000000 _____ () C:\ProgramData\MIDI Patch Names
2012-05-19 18:56 - 2015-09-18 20:00 - 0000000 ____H () C:\ProgramData\PKP_DLbx.DAT
2012-05-19 19:12 - 2012-10-13 19:56 - 0000000 ____H () C:\ProgramData\PKP_DLdu.DAT
Einige Dateien in TEMP:
====================
C:\Users\pc\AppData\Local\Temp\avgnt.exe
C:\Users\pc\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-10-31 23:08
==================== Ende vom FRST.txt ============================ |