danieljam | 03.12.2016 19:22 | AdwCleaner
AdwCleaner Logfile: Code:
# AdwCleaner v6.030 - Bericht erstellt am 17/11/2016 um 22:00:33
# Aktualisiert am 19/10/2016 von Malwarebytes
# Datenbank : 2016-10-18.1 [Lokal]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (X64)
# Benutzername : Yanik - YANIK-PC
# Gestartet von : C:\Users\Yanik\Desktop\Anti Vir\adwcleaner_6.030.exe
# Modus: Löschen
# Unterstützung : hxxps://www.malwarebytes.com/support
***** [ Dienste ] *****
***** [ Ordner ] *****
[-] Ordner gelöscht: C:\Users\Yanik\AppData\Local\globalUpdate
[-] Ordner gelöscht: C:\Users\Yanik\AppData\Roaming\goforfiles
[-] Ordner gelöscht: C:\Users\Yanik\AppData\Roaming\RPEng
[#] Ordner mit Neustart gelöscht: C:\Users\Yanik\AppData\Roaming\GoforFiles
[-] Ordner gelöscht: C:\ProgramData\apn
[#] Ordner mit Neustart gelöscht: C:\ProgramData\Application Data\apn
[-] Ordner gelöscht: C:\Users\Yanik\AppData\Local\Geckofx
***** [ Dateien ] *****
[-] Datei gelöscht: C:\user.js
[-] Datei gelöscht: C:\Users\Yanik\AppData\Roaming\Mozilla\Firefox\Profiles\wddldjwh.default-1385910868748\foxydeal.sqlite
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Verknüpfungen ] *****
[-] Verknüpfung desinfiziert: C:\Users\Yanik\Desktop\Anwendungen\RAGE.lnk
***** [ Aufgabenplanung ] *****
***** [ Registrierungsdatenbank ] *****
[-] Schlüssel gelöscht: HKLM\SOFTWARE\f13d413a-b4dd-45da-97e2-d8993ed31aa2
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\OpcMp4.OpcMp4Player
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\OpcMp4.OpcMp4Player.1
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\OpcMp4.OpcMp4Player
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\OpcMp4.OpcMp4Player.1
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
[-] Schlüssel gelöscht: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41564952-412D-5637-00A7-7A786E7484D7}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C4BEF720-313C-420A-ACF6-77DD95D8F553}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011431152}
[-] Schlüssel gelöscht: HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\AskPartnerNetwork
[-] Schlüssel gelöscht: HKU\S-1-5-21-3404717819-833408578-2882030763-1000\Software\GoforFiles
[-] Schlüssel gelöscht: HKU\S-1-5-21-3404717819-833408578-2882030763-1000\Software\InstalledBrowserExtensions
[-] Schlüssel gelöscht: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3404717819-833408578-2882030763-1000\Software\SweetIM
[-] Schlüssel gelöscht: HKU\S-1-5-21-3404717819-833408578-2882030763-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\GoforFiles
[-] Schlüssel gelöscht: HKU\S-1-5-21-3404717819-833408578-2882030763-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\InstalledBrowserExtensions
[-] Schlüssel gelöscht: HKU\S-1-5-21-3404717819-833408578-2882030763-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\WEDLMNGR
[-] Schlüssel gelöscht: HKU\S-1-5-21-3404717819-833408578-2882030763-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\GoforFiles
[-] Schlüssel gelöscht: HKU\S-1-5-21-3404717819-833408578-2882030763-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\InstalledBrowserExtensions
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\GoforFiles
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\InstalledBrowserExtensions
[-] Schlüssel gelöscht: HKU\.DEFAULT\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-18\Software\IB Updater
[-] Schlüssel gelöscht: HKLM\SOFTWARE\GoforFiles
[-] Schlüssel gelöscht: HKLM\SOFTWARE\InstalledBrowserExtensions
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3404717819-833408578-2882030763-1000\Software\SweetIM
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\GoforFiles
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\InstalledBrowserExtensions
[-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.bdliveupdate.oneclickctrl.9
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.bdliveupdate.update3webcontrol.3
***** [ Browser ] *****
*************************
:: "Tracing" Schlüssel gelöscht
:: Winsock Einstellungen zurückgesetzt
:: Proxy Einstellungen zurückgesetzt
:: TCP/IP Einstellungen zurückgesetzt
:: Firewall Einstellungen zurückgesetzt
:: IPSec Einstellungen zurückgesetzt
:: BITS Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [5369 Bytes] - [17/11/2016 22:00:33]
C:\AdwCleaner\AdwCleaner[R0].txt - [24517 Bytes] - [01/10/2013 15:59:36]
C:\AdwCleaner\AdwCleaner[R1].txt - [15697 Bytes] - [01/10/2013 16:02:06]
C:\AdwCleaner\AdwCleaner[S0].txt - [2080 Bytes] - [01/10/2013 16:00:54]
C:\AdwCleaner\AdwCleaner[S1].txt - [12904 Bytes] - [01/10/2013 16:02:25]
C:\AdwCleaner\AdwCleaner[S2].txt - [5557 Bytes] - [17/11/2016 21:59:20]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [5810 Bytes] ########## --- --- ---
[/CODE] Anti Root Kit Code:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2014.11.18.05
rootkit: v2014.11.12.01
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.18524
Yanik :: YANIK-PC [administrator]
17.11.2016 20:52:12
mbar-log-2016-11-17 (20-52-12).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 450338
Time elapsed: 57 minute(s), 44 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) Malwarebytes Anti Malware: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 17.11.2016
Suchlaufzeit: 20:12
Protokolldatei: Malwarebytes.txt
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2016.02.16.06
Rootkit-Datenbank: v2016.02.08.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Yanik
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 467123
Abgelaufene Zeit: 30 Min., 47 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 54
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\APPID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}, In Quarantäne, [01656001e1b86bcb50f1a10acb37758b],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}, In Quarantäne, [01656001e1b86bcb50f1a10acb37758b],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}, In Quarantäne, [01656001e1b86bcb50f1a10acb37758b],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\APPID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}, In Quarantäne, [8dd9a3be6732d6608bb9218af40ede22],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}, In Quarantäne, [8dd9a3be6732d6608bb9218af40ede22],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}, In Quarantäne, [8dd9a3be6732d6608bb9218af40ede22],
PUP.Optional.BonanzaDeals, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}, In Quarantäne, [372fe37e4851fe383ac7e2b8ec1639c7],
PUP.Optional.BonanzaDeals, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}, In Quarantäne, [372fe37e4851fe383ac7e2b8ec1639c7],
PUP.Optional.BonanzaDeals, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{33BAF587-9647-4281-A34F-F4830CDC1B9F}, In Quarantäne, [372fe27f7e1b12240af864369270817f],
PUP.Optional.BonanzaDeals, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4BEF720-313C-420A-ACF6-77DD95D8F553}, In Quarantäne, [d5915e039dfc93a3f4168c0e788a8a76],
PUP.Optional.BonanzaDeals, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C4BEF720-313C-420A-ACF6-77DD95D8F553}, In Quarantäne, [d5915e039dfc93a3f4168c0e788a8a76],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [4e18402149500f27de65e9c234cef20e],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [501668f99207ba7c3e0f802ba35f34cc],
PUP.Optional.CrossRider, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21501, In Quarantäne, [f96d0c558f0a64d2f474865860a337c9],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{14C8C076-A032-49C4-B474-35DCCBEF1C7A}, In Quarantäne, [84e24f12a9f0de58fe6c4a94d03352ae],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AB7E8926-AEDD-451F-A8A0-2839DCBE11AE}, In Quarantäne, [b7af91d03366dd59caa23ba3ab582fd1],
PUP.Optional.BonanzaDeals, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\BonanzaDealsLiveUpdateTaskMachineCore, In Quarantäne, [6105f46df8a14fe774458251e71c4eb2],
PUP.Optional.BonanzaDeals, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\BonanzaDealsLiveUpdateTaskMachineUA, In Quarantäne, [d492d58c12871f17f9c091423dc68c74],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\d59d601d-7389-4769-ab53-b322d00ce1c2-1, In Quarantäne, [dc8a9ac7a5f48da96effeaf4e91ae61a],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\d59d601d-7389-4769-ab53-b322d00ce1c2-11, In Quarantäne, [a9bd580975244aec4d207f5f0cf7649c],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\d59d601d-7389-4769-ab53-b322d00ce1c2-2, In Quarantäne, [da8c83de3861ad89b8b55589986b9967],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\d59d601d-7389-4769-ab53-b322d00ce1c2-3, In Quarantäne, [3432ff624a4fcb6b610cd60843c00ef2],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\d59d601d-7389-4769-ab53-b322d00ce1c2-4, In Quarantäne, [2d39471a6633a4923e2f45992ad9a060],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\d59d601d-7389-4769-ab53-b322d00ce1c2-5, In Quarantäne, [c1a5b7aa9cfdfc3a5518ffdf5ca7a759],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\d59d601d-7389-4769-ab53-b322d00ce1c2-5_user, In Quarantäne, [99cd7de489107abc2e3fb22cf211857b],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\d59d601d-7389-4769-ab53-b322d00ce1c2-6, In Quarantäne, [adb9aab75f3a4de9412c34aa7291b54b],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\d59d601d-7389-4769-ab53-b322d00ce1c2-7, In Quarantäne, [1c4afa67e1b874c2a2cbcf0fb3505aa6],
PUP.Optional.GoForFiles, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Go for FilesUpdate, In Quarantäne, [76f0501101987abcbb1f1cb2a45fc43c],
PUP.Optional.WeDownload, HKLM\SOFTWARE\WOW6432NODE\The weDownloads Manager+, In Quarantäne, [e38308597b1ec5716e336ea0d232817f],
PUP.Optional.WeDownload, HKLM\SOFTWARE\WOW6432NODE\The weDownloads Manager+-nv, In Quarantäne, [cb9b65fc8019b581683948c60afa3cc4],
PUP.Optional.FBPhotoZoom, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\mpieaakhacmfleokhjcjnpcnmnmpfkid, In Quarantäne, [1650ce93475265d15a26a241976ce31d],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\21501, In Quarantäne, [0264d78a9108d06669ff4d9193708c74],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{14C8C076-A032-49C4-B474-35DCCBEF1C7A}, In Quarantäne, [79edf76a5e3bdc5a0b5fa23c18eb1ae6],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110011431152}, In Quarantäne, [81e54f12adec13231753b826a3608e72],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AB7E8926-AEDD-451F-A8A0-2839DCBE11AE}, In Quarantäne, [e87e0958aeeb88ae82ea4d9191728d73],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, In Quarantäne, [fe680d5401988bab9944be28bb486b95],
PUP.Optional.GlobalUpdate, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, In Quarantäne, [d59199c85a3f0f272cb0aa3c45be34cc],
PUP.Optional.APNToolBar.Gen, HKU\S-1-5-18\SOFTWARE\AskPartnerNetwork, In Quarantäne, [89dd3031485139fd767359a3729034cc],
PUP.Optional.WeDownload, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\The weDownloads Manager+, In Quarantäne, [b7afd1904059f145fa9c49c50cf8d729],
PUP.Optional.WeDownLoadManager, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\WEDLMNGR, In Quarantäne, [96d0e9786d2c2214673efb1319eb48b8],
PUP.Optional.WeDownload, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\APPDATALOW\SOFTWARE\The weDownloads Manager+, In Quarantäne, [fc6a6ff2a8f1cc6a395dea245aaaff01],
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21501, In Quarantäne, [dd8994cd5643989e3f0f75683ec533cd],
PUP.Optional.WeDownload, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\weDownload, In Quarantäne, [194d2140eeab2d094157da349d672ad6],
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{14C8C076-A032-49C4-B474-35DCCBEF1C7A}, In Quarantäne, [3c2abea37a1fa88e80c936a82ad921df],
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{38796ADE-2C9A-46E4-8D85-93D17130D084}, In Quarantäne, [33330b5632675adc381305d9f60d37c9],
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{79311742-2865-4035-B487-B2405DC9A7AA}, In Quarantäne, [fd698dd46c2d93a3183222bc0bf8dd23],
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8790ED4E-7221-4D35-88FE-9BC24D52CFF0}, In Quarantäne, [7cead0913a5ffd39410abe208182d927],
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9A18C110-80F4-420D-B0CB-53DE633433A7}, In Quarantäne, [4026aab7b1e8e2546ae047979e65ce32],
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9BE81F06-E223-4F0B-80F5-8D7ABBBF5C4B}, In Quarantäne, [0165f170ebaef83ea3a7ecf2ff042cd4],
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A81977C1-C368-483C-B850-1BA8BB22C622}, In Quarantäne, [5412b9a8f2a713231932fee011f227d9],
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AB7E8926-AEDD-451F-A8A0-2839DCBE11AE}, In Quarantäne, [f670baa7d8c1c076f7549747798a7d83],
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BE96593E-40F6-499E-9DC7-3421636F372E}, In Quarantäne, [baac0958148546f0ba91fee06f94ff01],
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D56C8DCD-36A3-45C4-91E7-EE9837D220CB}, In Quarantäne, [9ccabca5abee40f65febe0fec043a15f],
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F5E78A12-7234-4C68-B154-A1B2E57D7466}, In Quarantäne, [fb6b154cf3a63ff701498d513cc7966a],
Registrierungswerte: 17
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{14c8c076-a032-49c4-b474-35dccbef1c7a}|AppName, The weDownloads Manager+-bg.exe, In Quarantäne, [84e24f12a9f0de58fe6c4a94d03352ae]
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ab7e8926-aedd-451f-a8a0-2839dcbe11ae}|AppName, The weDownloads Manager+-codedownloader.exe, In Quarantäne, [b7af91d03366dd59caa23ba3ab582fd1]
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{14c8c076-a032-49c4-b474-35dccbef1c7a}|AppName, The weDownloads Manager+-bg.exe, In Quarantäne, [79edf76a5e3bdc5a0b5fa23c18eb1ae6]
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110011431152}|AppName, CouponDropDown-bg.exe, In Quarantäne, [81e54f12adec13231753b826a3608e72]
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ab7e8926-aedd-451f-a8a0-2839dcbe11ae}|AppName, The weDownloads Manager+-codedownloader.exe, In Quarantäne, [e87e0958aeeb88ae82ea4d9191728d73]
PUP.Optional.FBPhotoZoom, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|fbphotozoom@installdaddy.com, C:\Program Files (x86)\fbphotozoom\fbphotozoom15.xpi, In Quarantäne, [b9ada9b86336a1950c75df0423e02cd4]
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{14c8c076-a032-49c4-b474-35dccbef1c7a}|AppName, The weDownloads Manager+-bg.exe, In Quarantäne, [3c2abea37a1fa88e80c936a82ad921df]
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{38796ADE-2C9A-46E4-8D85-93D17130D084}|AppName, d59d601d-7389-4769-ab53-b322d00ce1c2-2.exe-codedownloader.exe, In Quarantäne, [33330b5632675adc381305d9f60d37c9]
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{79311742-2865-4035-B487-B2405DC9A7AA}|AppName, d59d601d-7389-4769-ab53-b322d00ce1c2-2.exe-buttonutil.exe, In Quarantäne, [fd698dd46c2d93a3183222bc0bf8dd23]
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8790ED4E-7221-4D35-88FE-9BC24D52CFF0}|AppName, d59d601d-7389-4769-ab53-b322d00ce1c2-2.exe-codedownloader.exe, In Quarantäne, [7cead0913a5ffd39410abe208182d927]
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9A18C110-80F4-420D-B0CB-53DE633433A7}|AppName, d59d601d-7389-4769-ab53-b322d00ce1c2-2.exe-buttonutil.exe, In Quarantäne, [4026aab7b1e8e2546ae047979e65ce32]
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9BE81F06-E223-4F0B-80F5-8D7ABBBF5C4B}|AppName, d59d601d-7389-4769-ab53-b322d00ce1c2-2.exe-buttonutil.exe, In Quarantäne, [0165f170ebaef83ea3a7ecf2ff042cd4]
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A81977C1-C368-483C-B850-1BA8BB22C622}|AppName, d59d601d-7389-4769-ab53-b322d00ce1c2-2.exe-codedownloader.exe, In Quarantäne, [5412b9a8f2a713231932fee011f227d9]
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ab7e8926-aedd-451f-a8a0-2839dcbe11ae}|AppName, The weDownloads Manager+-codedownloader.exe, In Quarantäne, [f670baa7d8c1c076f7549747798a7d83]
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BE96593E-40F6-499E-9DC7-3421636F372E}|AppName, d59d601d-7389-4769-ab53-b322d00ce1c2-2.exe-codedownloader.exe, In Quarantäne, [baac0958148546f0ba91fee06f94ff01]
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D56C8DCD-36A3-45C4-91E7-EE9837D220CB}|AppName, d59d601d-7389-4769-ab53-b322d00ce1c2-2.exe-buttonutil.exe, In Quarantäne, [9ccabca5abee40f65febe0fec043a15f]
PUP.Optional.CrossRider, HKU\S-1-5-21-3404717819-833408578-2882030763-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F5E78A12-7234-4C68-B154-A1B2E57D7466}|AppName, d59d601d-7389-4769-ab53-b322d00ce1c2-2.exe-buttonutil.exe, In Quarantäne, [fb6b154cf3a63ff701498d513cc7966a]
Registrierungsdaten: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[5d09d28f8a0f270f845dfce98282df21]
Ordner: 1
PUP.Optional.APNToolBar.Gen, C:\ProgramData\APN\APN-Stub, In Quarantäne, [5214035ea2f70a2c0d99358bcc36f10f],
Dateien: 24
PUP.Optional.CrossRider, C:\Windows\System32\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-1, In Quarantäne, [580e73ee6e2b2115d4fb8c421ce77a86],
PUP.Optional.CrossRider, C:\Windows\System32\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-11, In Quarantäne, [baacc69b0f8a67cf1fb0e1ed59aa1fe1],
PUP.Optional.CrossRider, C:\Windows\System32\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-2, In Quarantäne, [87df65fc99005bdb9b34507eba49e917],
PUP.Optional.CrossRider, C:\Windows\System32\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-3, In Quarantäne, [74f27ee3f1a80e28517ee1ede12222de],
PUP.Optional.CrossRider, C:\Windows\System32\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-4, In Quarantäne, [4f17acb54d4c4ceaba154688e61db050],
PUP.Optional.CrossRider, C:\Windows\System32\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-5, In Quarantäne, [16502c358e0be3538b447757986bab55],
PUP.Optional.CrossRider, C:\Windows\System32\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-5_user, In Quarantäne, [cd99b8a9fa9f55e13c933896fe05ac54],
PUP.Optional.CrossRider, C:\Windows\System32\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-6, In Quarantäne, [92d4acb5f1a892a429a6606e51b2da26],
PUP.Optional.CrossRider, C:\Windows\System32\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-7, In Quarantäne, [9cca6bf6b2e76bcb1fb0fdd1d42fc33d],
PUP.Optional.CrossRider, C:\Windows\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-1.job, In Quarantäne, [4d199dc4188178be3c94bc128e75ab55],
PUP.Optional.CrossRider, C:\Windows\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-11.job, In Quarantäne, [ca9c8cd5d2c7310503cd00ce7d86a15f],
PUP.Optional.CrossRider, C:\Windows\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-2.job, In Quarantäne, [92d47fe2bfdab5815f71606e966d24dc],
PUP.Optional.CrossRider, C:\Windows\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-3.job, In Quarantäne, [a1c52f324d4ca096dbf57559ef14f40c],
PUP.Optional.CrossRider, C:\Windows\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-4.job, In Quarantäne, [73f30b56b5e47eb802ce85498a7911ef],
PUP.Optional.CrossRider, C:\Windows\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-5.job, In Quarantäne, [91d5f869ecad4cea10c0dbf32cd757a9],
PUP.Optional.CrossRider, C:\Windows\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-5_user.job, In Quarantäne, [ed79ef72871243f379571bb319ea6e92],
PUP.Optional.CrossRider, C:\Windows\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-6.job, In Quarantäne, [80e6cc9535646ec8b11f8f3f4cb7956b],
PUP.Optional.CrossRider, C:\Windows\Tasks\d59d601d-7389-4769-ab53-b322d00ce1c2-7.job, In Quarantäne, [c2a4ea77e1b864d2def265698281be42],
PUP.Optional.GoForFiles, C:\Windows\System32\Tasks\Go for FilesUpdate, In Quarantäne, [d98d550c5f3aba7c84546b635ea560a0],
PUP.Optional.BonanzaDeals, C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore, In Quarantäne, [f27496cbff9a32045f51b81b9b6816ea],
PUP.Optional.BonanzaDeals, C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA, In Quarantäne, [68fe88d9acedc175357b0bc8f50ed927],
PUP.Optional.BonanzaDeals, C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job, In Quarantäne, [5d09aeb3aced44f2ebc61db613f05aa6],
PUP.Optional.BonanzaDeals, C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job, In Quarantäne, [5016e879cecbc076565b03d060a313ed],
PUP.Optional.CrossRider, C:\Users\Yanik\AppData\Roaming\Mozilla\Firefox\Profiles\wddldjwh.default-1385910868748\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "148ac9c3ca2e8e8375223437e6a9a0fb");), Ersetzt,[62041c455e3bfd390c0ca76725e025db]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Junkware Removal Tool: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 7 Home Premium x64
Ran by Yanik (Administrator) on 17.11.2016 at 22:08:33,33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 21
Successfully deleted: C:\ProgramData\esellerate (Folder)
Successfully deleted: C:\Users\Yanik\AppData\Local\crashrpt (Folder)
Successfully deleted: C:\Users\Yanik\AppData\Roaming\getrighttogo (Folder)
Successfully deleted: C:\Users\Yanik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Yanik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\33ZMLJL8 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Yanik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Yanik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Yanik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Yanik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M87KH16K (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Yanik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NPP5G4S0 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Yanik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PRAH8PC1 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Yanik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YOVSS1SO (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\33ZMLJL8 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M87KH16K (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NPP5G4S0 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PRAH8PC1 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YOVSS1SO (Temporary Internet Files Folder)
Registry: 2
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A2D5EBA-F86D-4BD3-A177-019765996711} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A2D5EBA-F86D-4BD3-A177-019765996711} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17.11.2016 at 22:15:38,26
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ComboFix: Code:
Combofix Logfile:
Code:
ComboFix 16-11-13.01 - Yanik 18.11.2016 0:02.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8157.6096 [GMT 1:00]
ausgeführt von:: c:\users\Yanik\Desktop\ComboFix.exe
AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\program files (x86)\hl.exe
c:\program files (x86)\readme.txt
c:\program files (x86)\Update
c:\program files (x86)\Update\settings.ini
c:\program files (x86)\winrar.exe
c:\programdata\ntuser.pol
c:\programdata\ras_0oed.pad
c:\windows\msdownld.tmp
c:\windows\XSxS
.
.
((((((((((((((((((((((( Dateien erstellt von 2016-10-17 bis 2016-11-17 ))))))))))))))))))))))))))))))
.
.
2016-11-17 23:15 . 2016-11-17 23:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-11-17 22:24 . 2016-11-17 22:31 -------- d-----w- C:\FRST
2016-11-17 19:50 . 2016-11-17 22:33 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2016-11-17 19:11 . 2016-11-17 21:36 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-11-17 19:11 . 2016-11-17 22:33 109272 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2016-11-17 19:11 . 2016-11-17 19:11 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2016-11-17 19:11 . 2016-11-17 19:11 -------- d-----w- c:\programdata\Malwarebytes
2016-11-17 19:11 . 2016-03-10 13:09 64896 ----a-w- c:\windows\system32\drivers\mwac.sys
2016-11-17 19:11 . 2016-03-10 13:08 27008 ----a-w- c:\windows\system32\drivers\mbam.sys
2016-11-17 18:44 . 2015-07-16 19:12 856064 ----a-w- c:\windows\SysWow64\rdvidcrl.dll
2016-11-17 18:44 . 2015-07-16 19:12 53248 ----a-w- c:\windows\SysWow64\tsgqec.dll
2016-11-17 18:44 . 2015-07-16 19:11 62976 ----a-w- c:\windows\system32\tsgqec.dll
2016-11-17 18:44 . 2015-07-16 19:11 1057792 ----a-w- c:\windows\system32\rdvidcrl.dll
2016-11-17 18:44 . 2015-07-16 19:12 6131200 ----a-w- c:\windows\SysWow64\mstscax.dll
2016-11-17 18:44 . 2015-07-16 19:11 7077376 ----a-w- c:\windows\system32\mstscax.dll
2016-11-17 18:44 . 2015-07-11 13:15 429568 ----a-w- c:\windows\system32\wksprt.exe
2016-11-17 02:34 . 2016-11-17 02:34 -------- d-----w- c:\windows\Options
2016-11-17 02:34 . 2010-01-27 16:25 1584640 ----a-w- c:\windows\system32\drivers\athrx.sys
2016-11-17 02:34 . 2010-01-27 16:25 1584640 ----a-w- c:\windows\system32\athrx.sys
2016-11-17 00:48 . 2011-09-29 16:30 74272 ----a-w- c:\windows\system32\RtNicProp64.dll
2016-11-17 00:48 . 2011-09-29 16:30 646248 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2016-11-17 00:46 . 2011-09-16 14:12 32360 ----a-w- c:\windows\system32\drivers\RtVlan620.sys
2016-11-17 00:46 . 2011-06-15 20:11 48416 ----a-w- c:\windows\system32\drivers\RtTeam60.sys
2016-11-17 00:46 . 2011-06-15 20:11 32544 ----a-w- c:\windows\system32\drivers\RtNdPt60.sys
2016-11-16 21:08 . 2016-11-16 21:08 714448 ----a-w- c:\windows\is-TJBLS.exe
2016-11-16 21:08 . 2016-09-01 12:24 92688 ----a-w- c:\windows\system32\drivers\FocusriteUSBSwRoot.sys
2016-11-16 21:08 . 2016-11-17 00:22 -------- d-----w- c:\program files\FocusriteUSB
2016-11-15 15:45 . 2014-08-29 02:07 3179520 ----a-w- c:\windows\system32\rdpcorets.dll
2016-11-15 15:45 . 2014-05-08 09:32 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2016-11-14 15:16 . 2016-11-14 15:31 1013984 ----a-w- c:\windows\PE_File.dll
2016-11-14 15:15 . 2016-11-14 15:31 948448 ----a-w- c:\windows\PE_Rom.dll
2016-11-14 15:14 . 2016-11-16 17:09 -------- d-----w- c:\windows\SysWow64\RTCOM
2016-11-14 15:06 . 2006-02-07 14:44 65024 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2016-11-14 15:06 . 2006-02-07 14:40 204800 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2016-11-14 15:06 . 2006-02-07 14:40 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2016-11-14 15:06 . 2006-02-07 14:40 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2016-11-14 15:06 . 2005-11-13 22:19 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2016-11-14 15:06 . 2006-02-07 14:45 757760 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2016-11-14 15:06 . 2016-11-14 15:06 200836 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2016-11-14 15:06 . 2016-11-14 15:06 331908 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2016-11-14 14:56 . 2010-08-03 12:21 14464 ----a-w- c:\windows\SysWow64\drivers\AsUpIO.sys
2016-11-14 14:55 . 2008-12-02 19:05 184320 ----a-w- c:\windows\SysWow64\drivers\UpdateHelper.dll
2016-11-14 14:54 . 2008-01-04 12:34 11832 ------w- c:\windows\SysWow64\drivers\AsInsHelp64.sys
2016-11-14 14:54 . 2008-01-04 12:34 10216 ------w- c:\windows\SysWow64\drivers\AsInsHelp32.sys
2016-11-14 14:53 . 2016-11-14 15:51 -------- d-----w- c:\program files (x86)\ASUS
2016-11-14 14:53 . 2016-11-14 14:54 -------- d-----w- c:\programdata\ASUS
2016-11-14 14:53 . 2014-09-09 02:14 28672 ----a-w- c:\windows\SysWow64\AsIO.dll
2016-11-14 14:53 . 2014-09-09 02:14 15232 ----a-w- c:\windows\SysWow64\drivers\AsIO.sys
2016-11-14 14:45 . 2016-11-14 14:45 -------- d-----w- c:\windows\Intel_Chipset_XPVistaWin7_V9301019
2016-11-14 14:45 . 2016-11-14 14:45 16896 ----a-w- c:\windows\AsTaskSched.dll
2016-11-14 14:40 . 2016-11-14 14:40 -------- d-----w- c:\program files (x86)\ASM104xUSB3
2016-11-14 14:19 . 2013-10-02 04:51 3584 ----a-w- c:\windows\system32\drivers\de-DE\tsusbflt.sys.mui
2016-11-14 14:19 . 2013-10-02 01:10 44544 ----a-w- c:\windows\system32\TsUsbGDCoInstaller.dll
2016-11-14 14:19 . 2013-10-02 02:22 56832 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2016-11-14 14:19 . 2013-10-02 02:11 13824 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2016-11-14 14:19 . 2013-10-02 02:08 12800 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2016-11-14 14:19 . 2013-10-02 01:48 56832 ----a-w- c:\windows\system32\MsRdpWebAccess.dll
2016-11-14 14:19 . 2013-10-02 01:48 18944 ----a-w- c:\windows\system32\wksprtPS.dll
2016-11-14 14:19 . 2013-10-02 00:14 50176 ----a-w- c:\windows\SysWow64\MsRdpWebAccess.dll
2016-11-14 14:19 . 2013-10-02 00:14 17920 ----a-w- c:\windows\SysWow64\wksprtPS.dll
2016-11-14 14:19 . 2013-10-02 00:08 83968 ----a-w- c:\windows\system32\TSWbPrxy.exe
2016-11-14 14:19 . 2013-10-01 23:31 1147392 ----a-w- c:\windows\system32\mstsc.exe
2016-11-14 14:19 . 2013-10-01 22:34 1068544 ----a-w- c:\windows\SysWow64\mstsc.exe
2016-11-14 14:13 . 2012-08-23 14:13 243200 ----a-w- c:\windows\system32\rdpudd.dll
2016-11-14 14:13 . 2012-08-23 14:10 19456 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2016-11-14 14:13 . 2012-08-23 14:08 30208 ----a-w- c:\windows\system32\drivers\TsUsbGD.sys
2016-11-14 14:13 . 2012-08-23 11:12 192000 ----a-w- c:\windows\SysWow64\rdpendp_winip.dll
2016-11-14 14:13 . 2012-08-23 10:51 228864 ----a-w- c:\windows\system32\rdpendp_winip.dll
2016-11-14 14:11 . 2016-10-26 06:48 52248 ----a-w- c:\windows\system32\Spool\prtprocs\x64\us008pc.dll
2016-11-14 14:10 . 2016-11-14 14:10 -------- d-----w- c:\program files\Microsoft Silverlight
2016-11-14 14:10 . 2016-11-14 14:10 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2016-11-14 14:09 . 2015-08-05 17:56 22528 ----a-w- c:\windows\system32\icaapi.dll
2016-11-14 14:09 . 2015-08-05 17:06 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2016-11-14 14:05 . 2015-12-16 18:55 69120 ----a-w- c:\windows\system32\nlsbres.dll
2016-11-14 14:05 . 2015-12-16 18:53 7168 ----a-w- c:\windows\system32\kbdgeoqw.dll
2016-11-14 14:05 . 2015-12-16 18:53 7168 ----a-w- c:\windows\system32\KBDAZEL.DLL
2016-11-14 14:05 . 2015-12-16 18:53 7168 ----a-w- c:\windows\system32\KBDAZE.DLL
2016-11-14 14:05 . 2015-12-16 18:48 6656 ----a-w- c:\windows\SysWow64\kbdgeoqw.dll
2016-11-14 14:05 . 2015-12-16 18:48 6656 ----a-w- c:\windows\SysWow64\KBDAZEL.DLL
2016-11-14 14:05 . 2015-12-16 18:47 69120 ----a-w- c:\windows\SysWow64\nlsbres.dll
2016-11-13 01:58 . 2016-10-10 15:33 60416 ----a-w- c:\windows\system32\msobjs.dll
2016-11-13 01:58 . 2016-10-10 15:33 146432 ----a-w- c:\windows\system32\msaudite.dll
2016-11-13 01:58 . 2016-10-10 15:33 690688 ----a-w- c:\windows\system32\adtschema.dll
2016-11-13 01:58 . 2016-10-10 15:16 60416 ----a-w- c:\windows\SysWow64\msobjs.dll
2016-11-13 01:58 . 2016-10-10 15:16 146432 ----a-w- c:\windows\SysWow64\msaudite.dll
2016-11-13 01:58 . 2016-10-10 15:16 690688 ----a-w- c:\windows\SysWow64\adtschema.dll
2016-11-13 01:58 . 2016-10-07 14:50 2048 ----a-w- c:\windows\SysWow64\user.exe
2016-11-13 01:58 . 2016-08-22 16:19 1386496 ----a-w- c:\windows\system32\diagtrack.dll
2016-11-03 02:57 . 2016-11-03 04:40 -------- d-----w- c:\users\Yanik\AppData\Roaming\uTorrent
2016-11-01 06:30 . 2016-11-01 06:30 -------- d-----w- c:\program files (x86)\Tobias Erichsen
2016-11-01 06:30 . 2016-11-01 06:30 -------- d-----w- c:\program files\Tobias Erichsen
2016-11-01 06:08 . 2016-11-01 06:31 -------- d-----w- c:\program files (x86)\MIDIOX
2016-11-01 05:51 . 2016-11-16 17:10 -------- d-----w- c:\users\Yanik\AppData\Local\AutoTonic
2016-11-01 05:50 . 2016-11-01 05:50 -------- d-----w- c:\program files (x86)\AutoTonic
2016-10-26 06:49 . 2016-10-26 06:49 166776 ----a-w- c:\windows\system32\us008ci.exe
2016-10-26 06:48 . 2016-10-26 06:48 31256 ----a-w- c:\windows\system32\us008lm.dll
2016-10-26 06:48 . 2016-10-26 06:48 98320 ----a-w- c:\windows\system32\us008ci.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-11-13 01:42 . 2011-12-27 20:02 141011376 -c--a-w- c:\windows\system32\MRT.exe
2016-11-09 13:48 . 2012-04-24 06:26 796352 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2016-11-09 13:48 . 2011-10-15 16:47 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-10-28 20:17 . 2013-08-08 12:11 177432 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2016-10-26 15:29 . 2010-11-21 03:27 485032 ------w- c:\windows\system32\MpSigStub.exe
2016-10-13 14:39 . 2016-10-13 14:39 59528 ----a-w- c:\windows\system32\drivers\EpfwLWF.sys
2016-10-09 03:36 . 2016-10-09 03:37 31720 ----a-w- c:\windows\system32\drivers\avusbflt.sys
2016-10-09 03:36 . 2013-08-08 12:11 145536 ----a-w- c:\windows\system32\drivers\avipbb.sys
2016-10-07 15:12 . 2016-11-13 01:59 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2016-10-06 21:42 . 2016-11-15 15:35 12033040 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{159D8440-CE44-47D0-89A1-F2BD9C576E24}\mpengine.dll
2016-09-12 21:17 . 2016-10-12 15:02 77032 ----a-w- c:\windows\system32\CompatTelRunner.exe
2016-09-12 21:08 . 2016-10-12 15:02 1226752 ----a-w- c:\windows\system32\aeinv.dll
2016-09-12 21:08 . 2016-10-12 15:01 107520 ----a-w- c:\windows\system32\adsmsext.dll
2016-09-12 20:49 . 2016-10-12 15:01 76800 ----a-w- c:\windows\SysWow64\adsmsext.dll
2016-09-12 19:08 . 2016-10-12 15:01 1251328 ----a-w- c:\windows\SysWow64\DWrite.dll
2016-09-12 18:43 . 2016-10-12 15:01 1180160 ----a-w- c:\windows\system32\FntCache.dll
2016-09-12 18:43 . 2016-10-12 15:01 1648128 ----a-w- c:\windows\system32\DWrite.dll
2016-09-09 15:54 . 2016-10-12 15:02 586752 ----a-w- c:\windows\system32\generaltel.dll
2016-09-09 15:54 . 2016-10-12 15:02 314368 ----a-w- c:\windows\system32\invagent.dll
2016-09-09 15:54 . 2016-10-12 15:02 129024 ----a-w- c:\windows\system32\acmigration.dll
2016-09-09 15:54 . 2016-10-12 15:02 575488 ----a-w- c:\windows\system32\devinv.dll
2016-09-09 15:54 . 2016-10-12 15:02 273408 ----a-w- c:\windows\system32\centel.dll
2016-09-09 15:54 . 2016-10-12 15:02 224256 ----a-w- c:\windows\system32\aepic.dll
2016-09-09 15:54 . 2016-10-12 15:02 1629184 ----a-w- c:\windows\system32\appraiser.dll
2016-09-08 20:34 . 2016-10-12 15:01 263680 ----a-w- c:\windows\system32\WebClnt.dll
2016-09-08 20:34 . 2016-10-12 15:01 108544 ----a-w- c:\windows\system32\davclnt.dll
2016-09-08 20:34 . 2016-10-12 15:01 208896 ----a-w- c:\windows\SysWow64\WebClnt.dll
2016-09-08 20:34 . 2016-10-12 15:01 87040 ----a-w- c:\windows\SysWow64\davclnt.dll
2016-09-08 14:55 . 2016-10-12 15:01 142336 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2016-09-08 14:55 . 2016-10-12 15:01 106496 ----a-w- c:\windows\system32\drivers\dfsc.sys
2016-08-29 15:31 . 2016-10-12 14:56 14183424 ----a-w- c:\windows\system32\shell32.dll
2016-08-29 15:31 . 2016-10-12 14:56 1867776 ----a-w- c:\windows\system32\ExplorerFrame.dll
2016-08-29 15:31 . 2016-10-12 14:56 1941504 ----a-w- c:\windows\system32\authui.dll
2016-08-29 15:12 . 2016-10-12 14:56 1499648 ----a-w- c:\windows\SysWow64\ExplorerFrame.dll
2016-08-29 15:12 . 2016-10-12 14:56 1806848 ----a-w- c:\windows\SysWow64\authui.dll
2016-08-29 15:04 . 2016-10-12 14:56 3229696 ----a-w- c:\windows\explorer.exe
2016-08-29 14:55 . 2016-10-12 14:56 2972672 ----a-w- c:\windows\SysWow64\explorer.exe
2013-03-11 04:27 . 2015-02-02 00:27 70656 ----a-w- c:\program files (x86)\hwpatcher.dll
2012-06-14 16:35 . 2013-01-22 19:12 82944 ----a-w- c:\program files (x86)\Zip.SFX
2012-06-14 16:35 . 2013-01-22 19:12 76288 ----a-w- c:\program files (x86)\WinCon.SFX
2012-06-14 16:35 . 2013-01-22 19:12 140032 ----a-w- c:\program files (x86)\Default64.SFX
2012-06-14 16:35 . 2013-01-22 19:12 109824 ----a-w- c:\program files (x86)\Zip64.SFX
2012-06-14 16:35 . 2013-01-22 19:12 106448 ----a-w- c:\program files (x86)\WinCon64.SFX
2012-06-14 16:35 . 2013-01-22 19:12 102400 ----a-w- c:\program files (x86)\Default.SFX
2012-06-09 18:20 . 2013-01-21 14:43 196096 ----a-w- c:\program files (x86)\RarExt.dll
2012-06-09 18:20 . 2013-01-22 22:58 167936 ----a-w- c:\program files (x86)\RarExt32.dll
2012-06-09 18:19 . 2013-01-22 22:58 287744 ----a-w- c:\program files (x86)\UnRAR.exe
2012-06-09 18:19 . 2013-01-22 22:58 426496 ----a-w- c:\program files (x86)\Rar.exe
2012-05-05 04:40 . 2015-02-02 00:27 35 ----a-w- c:\program files (x86)\CS Dedicated Server GUI.bat
2012-04-30 08:41 . 2015-02-02 00:27 392704 ----a-w- c:\program files (x86)\steamclient.dll
2012-04-29 19:25 . 2015-02-02 00:27 77 ----a-w- c:\program files (x86)\Counter-Strike WaRzOnE.bat
2012-04-28 12:09 . 2015-02-02 00:27 147456 ----a-w- c:\program files (x86)\revSrvBrowser.dll
2012-04-08 12:16 . 2015-02-02 00:27 407336 ----a-w- c:\program files (x86)\hlds.exe
2012-03-04 18:25 . 2015-02-02 00:27 73 ----a-w- c:\program files (x86)\CS Dedicated Server CLI.bat
2012-03-04 18:04 . 2015-02-02 00:27 294496 ----a-w- c:\program files (x86)\crashhandler.dll
2012-02-22 10:15 . 2015-02-02 00:27 1668968 ----a-w- c:\program files (x86)\swds.dll
2011-06-10 20:58 . 2015-02-02 00:27 773968 ----a-w- c:\program files (x86)\msvcr100.dll
2011-03-16 13:09 . 2015-02-02 00:27 70144 ----a-w- c:\program files (x86)\steam_api_c.dll
2011-03-16 13:09 . 2015-02-02 00:27 67072 ----a-w- c:\program files (x86)\steam_api.dll
2011-03-16 13:09 . 2015-02-02 00:27 53248 ----a-w- c:\program files (x86)\voice_miles.dll
2011-03-16 13:09 . 2015-02-02 00:27 352256 ----a-w- c:\program files (x86)\vgui.dll
2011-03-16 13:09 . 2015-02-02 00:27 351744 ----a-w- c:\program files (x86)\Mss32.dll
2011-03-16 13:09 . 2015-02-02 00:27 344064 ----a-w- c:\program files (x86)\tier0.dll
2011-03-16 13:09 . 2015-02-02 00:27 340480 ----a-w- c:\program files (x86)\vstdlib.dll
2011-03-16 13:09 . 2015-02-02 00:27 245819 ----a-w- c:\program files (x86)\vgui2.dll
2011-03-16 13:09 . 2015-02-02 00:27 1672504 ----a-w- c:\program files (x86)\sw.dll
2011-03-16 13:09 . 2015-02-02 00:27 139264 ----a-w- c:\program files (x86)\voice_speex.dll
2011-03-16 13:09 . 2015-02-02 00:27 161792 ----a-w- c:\program files (x86)\Mssv29.asi
2011-03-16 13:09 . 2015-02-02 00:27 142848 ----a-w- c:\program files (x86)\Mssv12.asi
2011-03-16 13:09 . 2015-02-02 00:27 125952 ----a-w- c:\program files (x86)\Mp3dec.asi
2011-03-16 13:09 . 2015-02-02 00:27 90112 ----a-w- c:\program files (x86)\DemoPlayer.dll
2011-03-16 13:09 . 2015-02-02 00:27 69632 ----a-w- c:\program files (x86)\dbg.dll
2011-03-16 13:09 . 2015-02-02 00:27 258106 ----a-w- c:\program files (x86)\Core.dll
2011-03-16 13:09 . 2015-02-02 00:27 221184 ----a-w- c:\program files (x86)\hltv.exe
2011-03-16 13:09 . 2015-02-02 00:27 211456 ----a-w- c:\program files (x86)\a3dapi.dll
2011-03-16 13:09 . 2015-02-02 00:27 122974 ----a-w- c:\program files (x86)\FileSystem_Steam.dll
2011-03-08 11:25 . 2015-02-02 00:27 254012 ----a-w- c:\program files (x86)\proxy.dll
2011-03-08 11:25 . 2015-02-02 00:27 118872 ----a-w- c:\program files (x86)\FileSystem_Stdio.dll
2010-01-23 17:48 . 2015-02-02 00:27 1840440 ----a-w- c:\program files (x86)\hw.dll
2010-01-23 17:37 . 2015-02-02 00:27 2560 ----a-w- c:\program files (x86)\upatch.dll
2009-08-29 17:13 . 2015-02-02 00:27 402680 ----a-w- c:\program files (x86)\vstdlib_s.dll
2009-08-29 17:13 . 2015-02-02 00:27 3377648 ----a-w- c:\program files (x86)\steamclient_orig.dll
2009-08-29 17:13 . 2015-02-02 00:27 275704 ----a-w- c:\program files (x86)\tier0_s.dll
2009-08-29 17:12 . 2015-02-02 00:27 2888976 ----a-w- c:\program files (x86)\Steam_orig.dll
2009-05-17 07:38 . 2015-02-02 00:27 329728 ----a-w- c:\program files (x86)\Steam.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\users\Yanik\AppData\Local\Akamai\netsession_win.exe" [2015-09-10 4691384]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2011-10-03 393216]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2016-02-12 8641240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2016-10-28 916072]
"Avira SystrayStartTrigger"="c:\program files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe" [2016-08-19 60136]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R0 sptd;sptd; [x]
R2 AntiVirMailService;Avira Email-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe [x]
R2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
R2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;c:\program files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe;c:\program files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys;c:\windows\SYSNATIVE\Drivers\ssadadb.sys [x]
R3 camfilt2;camfilt2;c:\windows\system32\Drivers\camfilt2.sys;c:\windows\SYSNATIVE\Drivers\camfilt2.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 ffusb2audio;Focusrite USB 2.0 Audio Driver;c:\windows\system32\DRIVERS\ffusb2audio.sys;c:\windows\SYSNATIVE\DRIVERS\ffusb2audio.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x]
R3 hxctlflt;hxctlflt;c:\windows\system32\Drivers\hxctlflt.sys;c:\windows\SYSNATIVE\Drivers\hxctlflt.sys [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 libusb0;libusb-win32 - Kernel Driver 04/20/2012 0.0.0.0;c:\windows\system32\drivers\libusb0.sys;c:\windows\SYSNATIVE\drivers\libusb0.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtTeam60.sys;c:\windows\SYSNATIVE\DRIVERS\RtTeam60.sys [x]
R3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtVlan620.sys;c:\windows\SYSNATIVE\DRIVERS\RtVlan620.sys [x]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssadserd.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
R3 X6va003;X6va003;c:\users\Yanik\AppData\Local\Temp\00379B2.tmp;c:\users\Yanik\AppData\Local\Temp\00379B2.tmp [x]
R3 X6va005;X6va005;c:\users\Yanik\AppData\Local\Temp\005BEA4.tmp;c:\users\Yanik\AppData\Local\Temp\005BEA4.tmp [x]
R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys;SysWow64\drivers\AsUpIO.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.18\atkexComSvc.exe;c:\program files (x86)\ASUS\AXSP\1.00.18\atkexComSvc.exe [x]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.17\aaHMSvc.exe;c:\program files (x86)\ASUS\AAHM\1.00.17\aaHMSvc.exe [x]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [x]
S2 AsusFanControlService;AsusFanControlService;c:\program files (x86)\ASUS\AsusFanControlService\1.00.17\AsusFanControlService.exe;c:\program files (x86)\ASUS\AsusFanControlService\1.00.17\AsusFanControlService.exe [x]
S2 Avira.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 DigitalWave.Update.Service;Digital Wave Update Service;c:\program files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe;c:\program files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [x]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [x]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [x]
S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [x]
S2 PaceLicenseDServices;PACE License Services;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [x]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files (x86)\PDF Architect\HelperService.exe;c:\program files (x86)\PDF Architect\HelperService.exe [x]
S2 PDF Architect Service;PDF Architect Service;c:\program files (x86)\PDF Architect\ConversionService.exe;c:\program files (x86)\PDF Architect\ConversionService.exe [x]
S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys;c:\windows\SYSNATIVE\DRIVERS\RtNdPt60.sys [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 FocusriteUSBSwRoot;USB Audio Root;c:\windows\system32\DRIVERS\FocusriteUSBSwRoot.sys;c:\windows\SYSNATIVE\DRIVERS\FocusriteUSBSwRoot.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 teVirtualMIDI64;teVirtualMIDI - Virtual MIDI Driver x64;c:\windows\system32\DRIVERS\teVirtualMIDI64.sys;c:\windows\SYSNATIVE\DRIVERS\teVirtualMIDI64.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2016-11-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-24 13:48]
.
2016-11-17 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3404717819-833408578-2882030763-1000Core.job
- c:\users\Yanik\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-11-27 18:36]
.
2016-11-17 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3404717819-833408578-2882030763-1000UA.job
- c:\users\Yanik\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-11-27 18:36]
.
2016-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-15 15:40]
.
2016-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-15 15:40]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-12-13 13374568]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: Free YouTube Download - c:\users\Yanik\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~3\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Yanik\AppData\Roaming\Mozilla\Firefox\Profiles\wddldjwh.default-1385910868748\
FF - prefs.js: browser.startup.homepage - google.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
BHO-{41564952-412D-5637-00A7-7A786E7484D7} - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Native Instruments Absynth 5 - c:\programdata\{C2A88E6D-FA3D-462B-BDFF-A09B1EFA8FBE}\Absynth 5 Setup PC.exe
AddRemove-Native Instruments Alicias Keys - c:\programdata\{4A95D8FB-6FE5-4651-9C81-388A5F0CB306}\Alicias Keys Setup PC.exe
AddRemove-Native Instruments Balinese Gamelan - c:\programdata\{7B7672F5-5EA2-4D83-BC77-1AFCA8846266}\Balinese Gamelan Setup PC.exe
AddRemove-Native Instruments Battery 3 - c:\programdata\{E9CDB61C-771D-42BB-B441-4CA7622ACA52}\Battery 3 Setup PC.exe
AddRemove-Native Instruments Battery Library Importer for Maschine - c:\programdata\{D04E7E60-5F77-4E61-9CD4-7AEC5E15C525}\Battery Library Importer for Maschine Setup PC.exe
AddRemove-Native Instruments Berlin Concert Grand - c:\programdata\{68233086-CF7D-452D-8519-A7815257EC6B}\Berlin Concert Grand Setup PC.exe
AddRemove-Native Instruments Controller Editor - c:\programdata\{DCC412E7-393B-4016-91FB-9307F059AFB6}\Controller Editor Setup PC.exe
AddRemove-Native Instruments Evolve Mutations - c:\programdata\{4C01754A-32F9-4A34-8B9F-E06DD553B755}\Evolve Mutations Setup PC.exe
AddRemove-Native Instruments Evolve Mutations 2 - c:\programdata\{6B3E9A08-404E-4FBF-A80D-1E9DA9E75171}\Evolve Mutations 2 Setup PC.exe
AddRemove-Native Instruments FM8 - c:\programdata\{3006A797-CDFA-44FC-98EF-155579E2CDBF}\FM8 Setup PC.exe
AddRemove-Native Instruments George Duke Soul Treasures - c:\programdata\{8CD9955F-F554-4B5B-9EA3-370A45EF233C}\George Duke Soul Treasures Setup PC.exe
AddRemove-Native Instruments Guitar Rig 5 - c:\programdata\{1CEDDDD4-56D2-463F-BC4E-C5DFFD3533C9}\Guitar Rig 5 Setup PC.exe
AddRemove-O - c:\programdata\{B0CAD5CC-867E-473E-B55F-339F9635A45D}\Guitar Rig Mobile IO Setup PC.exe
AddRemove-Native Instruments Guitar Rig Mobile IO Driver - c:\programdata\{A088C926-8EF0-4CFF-A473-EB879919E63A}\Guitar Rig Mobile IO Driver Setup.exe
AddRemove-O - c:\programdata\{CB28D9D3-6B5D-4AFA-BA37-B4AFAAAF71B9}\Guitar Rig Session IO Setup PC.exe
AddRemove-Native Instruments Guitar Rig Session IO Driver - c:\programdata\{84BD2490-E07B-459A-85CD-649AABFCE52D}\Guitar Rig Session IO Driver Setup.exe
AddRemove-Native Instruments Komplete 8 Ultimate - c:\programdata\{D8A28F10-6563-43AC-A9A6-278CB7631D2B}\Komplete 8 Ultimate Setup PC.exe
AddRemove-Native Instruments Kontakt 5 - c:\programdata\{57623A97-E2F4-49B2-86D7-FA0915C77BED}\Kontakt 5 Setup PC.exe
AddRemove-Native Instruments Kontakt Factory Library - c:\programdata\{35B46D49-85E2-40EA-8EC6-43B281EDD8E7}\Kontakt Factory Library Setup PC.exe
AddRemove-Native Instruments Maschine Drum Selection - c:\programdata\{B7CF1107-3BD9-48BA-BC77-54B909022641}\Maschine Drum Selection Setup PC.exe
AddRemove-Native Instruments Massive - c:\programdata\{0EB7C0FC-5BF4-474E-B5F9-A6E991727B3E}\Massive Setup PC.exe
AddRemove-Native Instruments Monark - c:\programdata\{849C3EA7-6C44-4D64-BFD2-FC5AF841BE83}\Monark Setup PC.exe
AddRemove-Native Instruments New York Concert Grand - c:\programdata\{DFB8047B-FF22-438D-90BD-83E8B78F83D7}\New York Concert Grand Setup PC.exe
AddRemove-Native Instruments Rammfire - c:\programdata\{B0DF9098-245E-479F-A4ED-B5F91EA4948B}\Rammfire Setup PC.exe
AddRemove-Native Instruments Razor - c:\programdata\{B53633F4-53A8-4BAA-81BD-2830099F2459}\Razor Setup PC.exe
AddRemove-Native Instruments RC 24 - c:\programdata\{723368A4-89C4-4A3E-85AC-EDCD1335AFE2}\RC 24 Setup PC.exe
AddRemove-Native Instruments RC 48 - c:\programdata\{1985DF73-28BC-4F56-AC14-F13021B2A5AF}\RC 48 Setup PC.exe
AddRemove-Native Instruments Reaktor 5 - c:\programdata\{F92C204F-6C39-4D56-B100-EC929C871966}\Reaktor 5 Setup PC.exe
AddRemove-Native Instruments Reaktor Prism - c:\programdata\{DC597CF0-DB39-40C2-9F8C-CF9D0A386548}\Reaktor Prism Setup PC.exe
AddRemove-Native Instruments Reaktor Spark R2 - c:\programdata\{588D017F-D30B-4C08-8A10-1FEF7D039369}\Reaktor Spark R2 Setup PC.exe
AddRemove-Native Instruments Reflektor - c:\programdata\{0A583E76-A7A0-45F8-9386-AEE1E529A4DE}\Reflektor Setup PC.exe
AddRemove-Native Instruments Rig Kontrol 3 - c:\programdata\{5A23829C-A66E-47B0-AD50-21A3FFE6C325}\Rig Kontrol 3 Setup PC.exe
AddRemove-Native Instruments Rig Kontrol 3 Driver - c:\programdata\{E2CB91C4-F65B-43A3-AF20-333B2663A78A}\Rig Kontrol 3 Driver Setup.exe
AddRemove-Native Instruments Scarbee Funk Guitarist - c:\programdata\{589B734B-3C34-40B2-9EFD-8C2D12D479CE}\Scarbee Funk Guitarist Setup PC.exe
AddRemove-Native Instruments Scarbee Jay-Bass - c:\programdata\{624486AF-AD5B-4BB3-BEEE-A0D2D4D112DF}\Scarbee Jay-Bass Setup PC.exe
AddRemove-Native Instruments Scarbee MM-Bass - c:\programdata\{F2026C51-8509-47B4-816D-CCD2DB993FC1}\Scarbee MM-Bass Setup PC.exe
AddRemove-Native Instruments Scarbee MM-Bass Amped - c:\programdata\{B06671EB-304F-4BCB-A3C8-1D59B4FD236F}\Scarbee MM-Bass Amped Setup PC.exe
AddRemove-Native Instruments Scarbee Pre-Bass - c:\programdata\{7FC6C6B3-C2D5-4F17-BBEF-A11135E1A668}\Scarbee Pre-Bass Setup PC.exe
AddRemove-Native Instruments Scarbee Pre-Bass Amped - c:\programdata\{B8AB470F-A90B-4652-A8F5-160A08FD7411}\Scarbee Pre-Bass Amped Setup PC.exe
AddRemove-Native Instruments Scarbee Vintage Keys - c:\programdata\{AB38F02B-C891-457C-B8C8-DA9D96EFA317}\Scarbee Vintage Keys Setup PC.exe
AddRemove-Native Instruments Service Center - c:\programdata\{EB3B2B5B-0AEF-45F3-B397-76DE53F83140}\Service Center Setup PC.exe
AddRemove-Native Instruments Session Strings Pro - c:\programdata\{E13AD921-F7D5-4901-BF24-AC8BF60E1EB6}\Session Strings Pro Setup PC.exe
AddRemove-Native Instruments The Finger R2 - c:\programdata\{CA03436C-933D-4ADA-9E89-2C39CC03E904}\The Finger R2 Setup PC.exe
AddRemove-Native Instruments The Mouth - c:\programdata\{F299F641-E758-4AF2-AEE2-1FF1FA99E411}\The Mouth Setup PC.exe
AddRemove-Native Instruments Traktors 12 - c:\programdata\{3DFBC806-D62A-4312-81FF-5F343DDCB5DC}\Traktors 12 Setup PC.exe
AddRemove-Native Instruments Transient Master - c:\programdata\{6E467D89-1963-440B-84F9-852C8150E323}\Transient Master Setup PC.exe
AddRemove-Native Instruments Upright Piano - c:\programdata\{91377244-4B4E-4A81-9F72-FA41DECB3D8F}\Upright Piano Setup PC.exe
AddRemove-Native Instruments VC 160 - c:\programdata\{792288EF-B822-4482-B541-7ED490D444F7}\VC 160 Setup PC.exe
AddRemove-Native Instruments VC 2A - c:\programdata\{14F71F5E-7E38-4BE6-9307-DC81B8A419A5}\VC 2A Setup PC.exe
AddRemove-Native Instruments VC 76 - c:\programdata\{D49FD676-115D-4DF5-B976-28952EB09BEB}\VC 76 Setup PC.exe
AddRemove-Native Instruments Vienna Concert Grand - c:\programdata\{82B9F45C-9378-4B6C-B80A-338C197F3791}\Vienna Concert Grand Setup PC.exe
AddRemove-Native Instruments Vintage Organs - c:\programdata\{80A0A482-175E-4DE8-9D32-C8C8463D1362}\Vintage Organs Setup PC.exe
AddRemove-Native Instruments West Africa - c:\programdata\{F409EA92-6713-4D2D-AF88-0C51B1CF1D2A}\West Africa Setup PC.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-{01D57CF6-B5BC-4D03-AFF5-7960CFBD05A9} - c:\programdata\{1CEDDDD4-56D2-463F-BC4E-C5DFFD3533C9}\Guitar Rig 5 Setup PC.exe
AddRemove-{03DC1A7A-3F8D-40C1-ADD8-181BBB49F166} - c:\programdata\{723368A4-89C4-4A3E-85AC-EDCD1335AFE2}\RC 24 Setup PC.exe
AddRemove-{043EEF79-513F-4666-B340-B8556AB0EADC} - c:\programdata\{CCE3E562-124D-4D63-8AC7-EC849A579F07}\Studio Drummer Setup PC.exe
AddRemove-{079419C3-9DFC-4571-BAFC-CD79854C684E} - c:\programdata\{F409EA92-6713-4D2D-AF88-0C51B1CF1D2A}\West Africa Setup PC.exe
AddRemove-{0886900B-B2F3-452C-B580-60F1253F7F80} - c:\programdata\{DCC412E7-393B-4016-91FB-9307F059AFB6}\Controller Editor Setup PC.exe
AddRemove-{09BB8307-BD8F-4E92-9918-A4BAFD0638B3} - c:\programdata\{14F71F5E-7E38-4BE6-9307-DC81B8A419A5}\VC 2A Setup PC.exe
AddRemove-{0B8565BA-BAD5-4732-B122-5FD78EFC50A9} - c:\programdata\{EB3B2B5B-0AEF-45F3-B397-76DE53F83140}\Service Center Setup PC.exe
AddRemove-{0E086923-AAA3-4F98-A6E2-48B64CE27553} - c:\programdata\{F21A5765-AACF-4530-991E-CE1346273F96}\Reaktor Factory Selection Setup PC.exe
AddRemove-{1244CC88-97DF-4694-A720-6F073845DEE2} - c:\programdata\{35B46D49-85E2-40EA-8EC6-43B281EDD8E7}\Kontakt Factory Library Setup PC.exe
AddRemove-{14C1DD2C-D54E-464A-9588-C109E3E39EEF} - c:\programdata\{80A0A482-175E-4DE8-9D32-C8C8463D1362}\Vintage Organs Setup PC.exe
AddRemove-{16C964BA-7E2D-49EC-96D7-3A1497751660} - c:\programdata\{1985DF73-28BC-4F56-AC14-F13021B2A5AF}\RC 48 Setup PC.exe
AddRemove-{1745A39F-7F25-4ADA-8ADA-FD84A6301696} - c:\programdata\{D49FD676-115D-4DF5-B976-28952EB09BEB}\VC 76 Setup PC.exe
AddRemove-{1AE269AE-561D-4889-8A13-C1254ACBD025} - c:\programdata\{CD0D90ED-2704-4043-9651-E90B134DD7DD}\Abbey Road 80s Drums Setup PC.exe
AddRemove-{28327E39-F691-44D4-BDE5-9B5B251ADD63} - c:\programdata\{D8A28F10-6563-43AC-A9A6-278CB7631D2B}\Komplete 8 Ultimate Setup PC.exe
AddRemove-{2930FB47-6452-4476-BF16-D77F748646DB} - c:\programdata\{B0CAD5CC-867E-473E-B55F-339F9635A45D}\Guitar Rig Mobile IO Setup PC.exe
AddRemove-{2BBE23DB-F92C-4319-9179-7E79717EE9AC} - c:\programdata\{B459B207-EA55-45E4-939F-D5DBD19BA3B1}\Komplete 8 Players Setup PC.exe
AddRemove-{35DE6B98-31C9-4A01-AB64-20A3C71BE1D0} - c:\programdata\{0A583E76-A7A0-45F8-9386-AEE1E529A4DE}\Reflektor Setup PC.exe
AddRemove-{36ccb7d4-42c7-473e-b293-72e41a8ec766} - c:\programdata\{68233086-CF7D-452D-8519-A7815257EC6B}\Berlin Concert Grand Setup PC.exe
AddRemove-{371B17C3-9624-4583-A497-DF980313D851} - c:\programdata\{C2A88E6D-FA3D-462B-BDFF-A09B1EFA8FBE}\Absynth 5 Setup PC.exe
AddRemove-{434CC4CB-0183-4CDE-BE7F-00230BE26494} - c:\programdata\{F299F641-E758-4AF2-AEE2-1FF1FA99E411}\The Mouth Setup PC.exe
AddRemove-{491DF203-7B61-4F0E-BDCB-A1218C4DAFE9} - c:\programdata\{0EB7C0FC-5BF4-474E-B5F9-A6E991727B3E}\Massive Setup PC.exe
AddRemove-{4b98677f-ef75-4f71-8ef3-5603e3b0cbf7} - c:\programdata\{AB38F02B-C891-457C-B8C8-DA9D96EFA317}\Scarbee Vintage Keys Setup PC.exe
AddRemove-{5552453B-BB76-45E3-973D-F95E458ED780} - c:\programdata\{57623A97-E2F4-49B2-86D7-FA0915C77BED}\Kontakt 5 Setup PC.exe
AddRemove-{5B841301-3649-4891-BC10-7A66820397C9} - c:\programdata\{DC597CF0-DB39-40C2-9F8C-CF9D0A386548}\Reaktor Prism Setup PC.exe
AddRemove-{5D03CB59-6F91-4097-922C-9DCA057D2A76} - c:\programdata\{CA03436C-933D-4ADA-9E89-2C39CC03E904}\The Finger R2 Setup PC.exe
AddRemove-{5D1224E0-6777-4536-9D72-B0E151ED8C99} - c:\programdata\{D04E7E60-5F77-4E61-9CD4-7AEC5E15C525}\Battery Library Importer for Maschine Setup PC.exe
AddRemove-{5FC09265-8AAD-410D-B88D-EBAA41327056} - c:\programdata\{589B734B-3C34-40B2-9EFD-8C2D12D479CE}\Scarbee Funk Guitarist Setup PC.exe
AddRemove-{60BB45B2-E8E4-41C5-B69F-C6DC5D991DF5} - c:\programdata\{AA5037F8-9B97-456B-847E-A64FEB3E393C}\Abbey Road 60s Drums Setup PC.exe
AddRemove-{67e13682-a5ba-4f12-ac10-4b41eacb82da} - c:\programdata\{4A95D8FB-6FE5-4651-9C81-388A5F0CB306}\Alicias Keys Setup PC.exe
AddRemove-{6969a180-13e1-4393-8265-98d11903375c} - c:\programdata\{6B3E9A08-404E-4FBF-A80D-1E9DA9E75171}\Evolve Mutations 2 Setup PC.exe
AddRemove-{6BED4DFE-C527-463E-B93A-6F6848B74DD0} - c:\programdata\{E9CDB61C-771D-42BB-B441-4CA7622ACA52}\Battery 3 Setup PC.exe
AddRemove-{7930FB47-6452-4476-BF16-D77F748646DB} - c:\programdata\{CB28D9D3-6B5D-4AFA-BA37-B4AFAAAF71B9}\Guitar Rig Session IO Setup PC.exe
AddRemove-{835e9421-5f20-4491-9a75-baa7af1ea14d} - c:\programdata\{82B9F45C-9378-4B6C-B80A-338C197F3791}\Vienna Concert Grand Setup PC.exe
AddRemove-{8812511F-8D8C-49D3-A711-C9650B2F5566} - c:\programdata\{39F0D482-6A42-445B-B6E2-506945189709}\Guitar Rig Factory Selection for Maschine Setup PC.exe
AddRemove-{88E45461-E8D2-4BCA-BDEC-0405E6FB4817} - c:\programdata\{6E467D89-1963-440B-84F9-852C8150E323}\Transient Master Setup PC.exe
AddRemove-{8C04CE01-F7B8-4961-884B-6CE7EFFADCD4} - c:\programdata\{588D017F-D30B-4C08-8A10-1FEF7D039369}\Reaktor Spark R2 Setup PC.exe
AddRemove-{906E3E41-5259-4C3B-A5EB-3B7F63AFEDB5} - c:\programdata\{792288EF-B822-4482-B541-7ED490D444F7}\VC 160 Setup PC.exe
AddRemove-{9be187da-7d1c-4e8b-8b66-6132ca7697d8} - c:\programdata\{DFB8047B-FF22-438D-90BD-83E8B78F83D7}\New York Concert Grand Setup PC.exe
AddRemove-{9c1b2ca5-bf9c-4b3e-b5ac-49a9133896a3} - c:\programdata\{624486AF-AD5B-4BB3-BEEE-A0D2D4D112DF}\Scarbee Jay-Bass Setup PC.exe
AddRemove-{9D3BAEFB-5DDD-43D4-8BB2-D9989521F003} - c:\programdata\{B53633F4-53A8-4BAA-81BD-2830099F2459}\Razor Setup PC.exe
AddRemove-{a63e8179-0381-4b59-8876-0755be48eb6a} - c:\programdata\{F2026C51-8509-47B4-816D-CCD2DB993FC1}\Scarbee MM-Bass Setup PC.exe
AddRemove-{AA2F4574-FD46-4897-8791-CD6CCD80E882} - c:\programdata\{4C01754A-32F9-4A34-8B9F-E06DD553B755}\Evolve Mutations Setup PC.exe
AddRemove-{b0c719eb-4c55-4b54-b37a-38b6fcd7116c} - c:\programdata\{B06671EB-304F-4BCB-A3C8-1D59B4FD236F}\Scarbee MM-Bass Amped Setup PC.exe
AddRemove-{B0FC9E28-1CE6-4A40-BEF1-C6E6EDFCA070} - c:\programdata\{00E0164B-B182-4800-96DA-F8D39B3A7189}\Kontakt Factory Selection Setup PC.exe
AddRemove-{b125d937-9582-450d-951e-7b53bd94d16d} - c:\programdata\{7B7672F5-5EA2-4D83-BC77-1AFCA8846266}\Balinese Gamelan Setup PC.exe
AddRemove-{B2552FA6-86E3-410D-84AD-265C2242D410} - c:\programdata\{3006A797-CDFA-44FC-98EF-155579E2CDBF}\FM8 Setup PC.exe
AddRemove-{B962AD08-335F-46f7-A182-257D37672E5C} - c:\programdata\{5A23829C-A66E-47B0-AD50-21A3FFE6C325}\Rig Kontrol 3 Setup PC.exe
AddRemove-{C40C08A5-A7AF-43B2-BF93-7CF67719D194} - c:\programdata\{7FC6C6B3-C2D5-4F17-BBEF-A11135E1A668}\Scarbee Pre-Bass Setup PC.exe
AddRemove-{C9BCE8B9-2510-48D4-B93A-EA7BEA81D6E7} - c:\programdata\{3DFBC806-D62A-4312-81FF-5F343DDCB5DC}\Traktors 12 Setup PC.exe
AddRemove-{D597935A-5F0E-44F8-A028-A0EF9C647D95} - c:\programdata\{B0DF9098-245E-479F-A4ED-B5F91EA4948B}\Rammfire Setup PC.exe
AddRemove-{D69D39FC-DCC0-43F4-9524-043EE9F1C329} - c:\programdata\{69DF5CE1-2094-4539-A287-9DD19C7BD30B}\Abbey Road Modern Drums Setup PC.exe
AddRemove-{d8650fdb-9422-4a07-9f57-585c06d9d760} - c:\programdata\{91377244-4B4E-4A81-9F72-FA41DECB3D8F}\Upright Piano Setup PC.exe
AddRemove-{DDDE5B61-19BD-4F64-B14C-5F81DB56DF3E} - c:\programdata\{8CD9955F-F554-4B5B-9EA3-370A45EF233C}\George Duke Soul Treasures Setup PC.exe
AddRemove-{E1B6008F-26D8-47BF-B585-6518AFE73557} - c:\programdata\{B8AB470F-A90B-4652-A8F5-160A08FD7411}\Scarbee Pre-Bass Amped Setup PC.exe
AddRemove-{e72f86b6-d2cd-4ec8-a510-286eee52b446} - c:\programdata\{849C3EA7-6C44-4D64-BFD2-FC5AF841BE83}\Monark Setup PC.exe
AddRemove-{e90698e9-2c52-4079-aa1d-b341f0f5b036} - c:\programdata\{24EEDFDA-74B5-4E97-8334-5AEA44CD0095}\Abbey Road 70s Drums Setup PC.exe
AddRemove-{E9EA5F38-6299-45A1-9D23-F21729A19357} - c:\programdata\{F92C204F-6C39-4D56-B100-EC929C871966}\Reaktor 5 Setup PC.exe
AddRemove-{f62a8337-2009-40b7-af47-0a2a1371645c} - c:\programdata\{B7CF1107-3BD9-48BA-BC77-54B909022641}\Maschine Drum Selection Setup PC.exe
AddRemove-{FCD398EC-9A6C-478D-82AC-96AE6FEF585D} - c:\programdata\{E13AD921-F7D5-4901-BF24-AC8BF60E1EB6}\Session Strings Pro Setup PC.exe
AddRemove-{FF600C37-6328-4348-A67A-3F85D8039604} - c:\programdata\{9B069D1C-ECB9-4D1B-A782-7D5DDA2045D6}\Kore Player Setup PC.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\PaceLicenseDServices]
"ImagePath"="\"c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe\" -u https://activation.paceap.com/InitiateActivation"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va003]
"ImagePath"="\??\c:\users\Yanik\AppData\Local\Temp\00379B2.tmp"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va005]
"ImagePath"="\??\c:\users\Yanik\AppData\Local\Temp\005BEA4.tmp"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va011]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3404717819-833408578-2882030763-1000\Software\SecuROM\License information*]
"datasecu"=hex:0a,f3,b5,5e,00,02,56,57,bc,cc,93,b5,0a,a6,79,d7,b7,a0,1c,92,41,
10,78,8c,94,11,1a,4d,5a,7b,23,75,64,e4,b9,31,a5,79,c3,b8,15,28,3d,7f,36,c1,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_23_0_0_207_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_23_0_0_207_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:1d,7c,f0,7a,91,cc,89,27,bd,6a,3f,e8,55,fa,e1,00,b5,36,a9,30,38,
d5,9d,64,cf,8b,71,ae,72,db,21,83,1f,93,84,98,58,8d,9b,fe,41,33,ba,bb,66,c9,\
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_23_0_0_207_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_23_0_0_207_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_207.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.23"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_207.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_207.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_207.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:1d,7c,f0,7a,91,cc,89,27,bd,6a,3f,e8,55,fa,e1,00,b5,36,a9,30,38,
d5,9d,64,cf,8b,71,ae,72,db,21,83,1f,93,84,98,58,8d,9b,fe,41,33,ba,bb,66,c9,\
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Borland\InterBase\bin\ibguard.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files (x86)\TeamViewer\TeamViewer_Service.exe
c:\progra~2\COMMON~1\X10\Common\x10nets.exe
c:\program files (x86)\Borland\InterBase\bin\ibserver.exe
c:\program files (x86)\Avira\Launcher\Avira.Systray.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2016-11-18 00:25:55 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2016-11-17 23:25
.
Vor Suchlauf: 11 Verzeichnis(se), 53.361.090.560 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 77.446.348.800 Bytes frei
.
- - End Of File - - 929BDED514E0995B5432CDE737667F48 --- --- ---
A36C5E4F47E84449FF07ED3517B43A31 Security Check: Code:
Results of screen317's Security Check version 1.009
Windows 7 Service Pack 1 x64 (UAC is disabled!)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
Avira Antivirus
Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:`````````
Java version 32-bit out of Date!
Adobe Flash Player 23.0.0.207
Adobe Reader XI
Mozilla Firefox (49.0.2) ````````Process Check: objlist.exe by Laurent````````
ESET NOD32 Antivirus egui.exe
ESET NOD32 Antivirus ekrn.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
windows defender MpCmdRun.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` ESET Online Scanner: Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=5713d8457934f545b41273fd6dacc762
# end=init
# utc_time=2016-11-28 05:20:20
# local_time=2016-11-28 06:20:20 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 31559
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=5713d8457934f545b41273fd6dacc762
# end=updated
# utc_time=2016-11-28 05:31:54
# local_time=2016-11-28 06:31:54 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=5713d8457934f545b41273fd6dacc762
# engine=31559
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-11-28 09:31:12
# local_time=2016-11-28 10:31:12 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Avira Antivirus'
# compatibility_mode=1815 16777213 100 96 23170 3669163 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 103971 231998522 0 0
# scanned=805132
# found=7
# cleaned=7
# scan_time=14358
sh=928A536FBFF196495B90E4BD51B932485B84A099 ft=1 fh=748b6a41a833329e vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\Users\Yanik\AppData\Local\Temp\DMR\dmr_72.exe"
sh=4CAC22751E437CD246D7D2542BED599E7AD0F68F ft=0 fh=0000000000000000 vn="Variante von Win32/FusionCore.K evtl. unerwünschte Anwendung (gelöscht)" ac=C fn="C:\Users\Yanik\AppData\Local\Temp\HYDB07B.tmp.1479431993\HTA\install.1479431993.zip"
sh=189FAC2249A10A568D13A81F6449BFFFFDEAEFD2 ft=1 fh=2be0e2264a96be0a vn="Variante von Win32/FusionCore.K evtl. unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\Users\Yanik\AppData\Local\Temp\HYDB07B.tmp.1479431993\HTA\3rdparty\FS.dll"
sh=4CAC22751E437CD246D7D2542BED599E7AD0F68F ft=0 fh=0000000000000000 vn="Variante von Win32/FusionCore.K evtl. unerwünschte Anwendung (gelöscht)" ac=C fn="C:\Users\Yanik\AppData\Local\Temp\HYDEEA3.tmp.1479432009\HTA\install.1479432009.zip"
sh=189FAC2249A10A568D13A81F6449BFFFFDEAEFD2 ft=1 fh=2be0e2264a96be0a vn="Variante von Win32/FusionCore.K evtl. unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\Users\Yanik\AppData\Local\Temp\HYDEEA3.tmp.1479432009\HTA\3rdparty\FS.dll"
sh=DDD7E789E67132CF6C5D8169B2F46E3498FCA60F ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.C evtl. unerwünschte Anwendung (gelöscht)" ac=C fn="C:\Users\Yanik\AppData\Roaming\JZPUYQL"
sh=D8F12AD0482833348FCF5384CD2D03A9E6C22F99 ft=1 fh=5f1b9046662ae45b vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (Gesäubert durch Löschen)" ac=C fn="C:\Users\Yanik\Downloads\DelFix - CHIP-Installer.exe" So, das wars mit den Logs. ;-)
Die Logs stammen alle von damals, bevor ich ComboFix angewandt hatte.
Nur den ESET Online Scanner und SecurityCheck habe ich danach benutzt. |