Praefectus | 04.09.2015 19:23 | Ok, hier die mbam.txt: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 04.09.2015
Suchlaufzeit: 19:27
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.09.04.06
Rootkit-Datenbank: v2015.08.16.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Constantin
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 338908
Abgelaufene Zeit: 26 Min., 7 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 8
PUP.Optional.Downloader, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HQ Video Pro 3.1cV27.05, In Quarantäne, [ac3a3fec6c1fcc6a2ef53b7ff40d6e92],
PUP.Optional.BrowserApps, HKCU\SOFTWARE\BrowserV01.06-nv-ie, In Quarantäne, [c71fbb70038871c588d083fae71ded13],
PUP.Optional.CrossRider, HKCU\SOFTWARE\HQ Video Pro 3.1cV27.05, In Quarantäne, [20c68e9d7a11a88ef6ade99c3bc915eb],
PUP.Optional.CrossRider, HKCU\SOFTWARE\HQ Video Pro 3.1cV27.05-nv-ie, In Quarantäne, [08de5dce890204326d36bcc937cd8a76],
PUP.Optional.BrowserApps, HKLM\SOFTWARE\WOW6432NODE\BrowserV01.06-nv-ie, In Quarantäne, [8a5c72b9ec9fd3633c47daa320e40ff1],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\HQ Video Pro 3.1cV27.05, In Quarantäne, [38ae54d73a51f541668d7a0c9c688a76],
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\HQ Video Pro 3.1cV27.05-nv-ie, In Quarantäne, [16d0d655dbb03df9f300e2a461a325db],
PUP.Optional.CrossAd.Gen, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{9563BC59-9556-4805-8CD4-886781779D8D}, In Quarantäne, [20c619121b70350162f1efac2fd6768a],
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 10
PUP.Optional.CrossRider, C:\Program Files (x86)\HQ Video Pro 3.1cV27.05, In Quarantäne, [994d2902464561d5ebaee3a20df77888],
PUP.Optional.IOProtect, C:\Users\Constantin\AppData\Local\Temp\WIZZ, In Quarantäne, [a541f13a2a61fb3be4a410852fd5ab55],
PUP.Optional.WebBar, C:\Windows\System32\config\systemprofile\AppData\Local\WebBar, In Quarantäne, [8d59c962eaa1ac8ae2232297c242758b],
PUP.Optional.MaxDriverUpdater, C:\Users\Constantin\AppData\Local\Temp\MAXDriverUpdater, In Quarantäne, [a24439f2d0bb96a099cdb35c1ae96799],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Cooking Download\Component, In Quarantäne, [4d994ddeacdf75c182d18219d4311ee2],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Cooking Download, Löschen bei Neustart, [4d994ddeacdf75c182d18219d4311ee2],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Cooking Download\Bin, Löschen bei Neustart, [4d994ddeacdf75c182d18219d4311ee2],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart\Component, Löschen bei Neustart, [20c619121b70350162f1efac2fd6768a],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart, Löschen bei Neustart, [20c619121b70350162f1efac2fd6768a],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart\Bin, Löschen bei Neustart, [20c619121b70350162f1efac2fd6768a],
Dateien: 37
PUP.Optional.CrossRider, C:\Program Files (x86)\HQ Video Pro 3.1cV27.05\f41b1580-0ee1-4ded-9ddb-bb71138dff8d-1-6.exe, In Quarantäne, [b333b972d9b2e65081b87f151fe6c53b],
PUP.Optional.CrossRider, C:\Program Files (x86)\HQ Video Pro 3.1cV27.05\f41b1580-0ee1-4ded-9ddb-bb71138dff8d-1-7.exe, In Quarantäne, [fee87fac8efd1620d663375d0cf9a55b],
PUP.Optional.CrossRider, C:\Program Files (x86)\HQ Video Pro 3.1cV27.05\f41b1580-0ee1-4ded-9ddb-bb71138dff8d-11.exe, In Quarantäne, [ebfb2704088355e13009187c9f6608f8],
PUP.Optional.CrossRider, C:\Program Files (x86)\HQ Video Pro 3.1cV27.05\f41b1580-0ee1-4ded-9ddb-bb71138dff8d-5.exe, In Quarantäne, [95510e1d1378142240f9a2f20afba45c],
PUP.Optional.Downloader, C:\Program Files (x86)\HQ Video Pro 3.1cV27.05\Uninstall.exe, In Quarantäne, [ac3a3fec6c1fcc6a2ef53b7ff40d6e92],
PUP.Optional.CrossRider, C:\Program Files (x86)\HQ Video Pro 3.1cV27.05\bgNova.html, In Quarantäne, [994d2902464561d5ebaee3a20df77888],
PUP.Optional.CrossRider, C:\Program Files (x86)\HQ Video Pro 3.1cV27.05\1293297481.mxaddon, In Quarantäne, [994d2902464561d5ebaee3a20df77888],
PUP.Optional.CrossRider, C:\Program Files (x86)\HQ Video Pro 3.1cV27.05\f41b1580-0ee1-4ded-9ddb-bb71138dff8d.crx, In Quarantäne, [994d2902464561d5ebaee3a20df77888],
PUP.Optional.IOProtect, C:\Users\Constantin\AppData\Local\Temp\WIZZ\ioprotect_conf.xml, In Quarantäne, [a541f13a2a61fb3be4a410852fd5ab55],
PUP.Optional.PricePeep, C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage, Löschen bei Neustart, [00e66bc01c6f64d2982eb5f0d43050b0],
PUP.Optional.PricePeep, C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal, In Quarantäne, [db0b43e8c6c5e2544680b1f447bd1ce4],
PUP.Optional.ReMarkable, C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, Löschen bei Neustart, [2db9dd4e3f4ce056bc2fe4c332d217e9],
PUP.Optional.ReMarkable, C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, Löschen bei Neustart, [7c6a76b54c3f4ee8ae3d3671d72d9070],
PUP.Optional.SelectNGo, C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage, Löschen bei Neustart, [91552dfe216a9e98a7c8a903a262eb15],
PUP.Optional.SelectNGo, C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage-journal, Löschen bei Neustart, [5690c16ad8b3a0961d523577a85cbb45],
PUP.Optional.ShoppingGate, C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_inst.shoppingate.info_0.localstorage, Löschen bei Neustart, [e105c6654f3cab8b06592d805ea652ae],
PUP.Optional.ShoppingGate, C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_inst.shoppingate.info_0.localstorage-journal, Löschen bei Neustart, [ecfa12199af1b383f36c09a428dc34cc],
PUP.Optional.WebBar, C:\Windows\System32\config\systemprofile\AppData\Local\WebBar\wb.log, In Quarantäne, [8d59c962eaa1ac8ae2232297c242758b],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Cooking Download\Component\config.json, In Quarantäne, [4d994ddeacdf75c182d18219d4311ee2],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Cooking Download\Component\hello.js, In Quarantäne, [4d994ddeacdf75c182d18219d4311ee2],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Cooking Download\Component\manifest.json, In Quarantäne, [4d994ddeacdf75c182d18219d4311ee2],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Cooking Download\Component\scriptTagContext.js, In Quarantäne, [4d994ddeacdf75c182d18219d4311ee2],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Cooking Download\Component\tmp_bg.js, In Quarantäne, [4d994ddeacdf75c182d18219d4311ee2],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Cooking Download\Component\uconfig.json, In Quarantäne, [4d994ddeacdf75c182d18219d4311ee2],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Cooking Download\Bin\c.dat, In Quarantäne, [4d994ddeacdf75c182d18219d4311ee2],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Cooking Download\Bin\CookingDownload.dll, Löschen bei Neustart, [4d994ddeacdf75c182d18219d4311ee2],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Cooking Download\Bin\prtu.dll, In Quarantäne, [4d994ddeacdf75c182d18219d4311ee2],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart\Component\config.json, In Quarantäne, [20c619121b70350162f1efac2fd6768a],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart\Component\hello.js, In Quarantäne, [20c619121b70350162f1efac2fd6768a],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart\Component\log.html, Löschen bei Neustart, [20c619121b70350162f1efac2fd6768a],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart\Component\manifest.json, In Quarantäne, [20c619121b70350162f1efac2fd6768a],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart\Component\scriptTagContext.js, In Quarantäne, [20c619121b70350162f1efac2fd6768a],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart\Component\tmp_bg.js, In Quarantäne, [20c619121b70350162f1efac2fd6768a],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart\Component\uconfig.json, In Quarantäne, [20c619121b70350162f1efac2fd6768a],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart\Bin\c.dat, In Quarantäne, [20c619121b70350162f1efac2fd6768a],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart\Bin\FormMart.dll, Löschen bei Neustart, [20c619121b70350162f1efac2fd6768a],
PUP.Optional.CrossAd.Gen, C:\Users\Constantin\AppData\Local\Form Mart\Bin\fpwq.dll, Löschen bei Neustart, [20c619121b70350162f1efac2fd6768a],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Hier vom Adw: Code:
# AdwCleaner v5.005 - Bericht erstellt am 04/09/2015 um 20:03:23
# Aktualisiert am 31/08/2015 von Xplode
# Datenbank : 2015-08-31.2 [Server]
# Betriebssystem : Windows 8.1 (x64)
# Benutzername : Constantin - UROKAN
# Gestartet von : C:\Users\Constantin\Downloads\adwcleaner_5.005.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum
***** [ Dienste ] *****
***** [ Ordner ] *****
***** [ Dateien ] *****
***** [ Verknüpfungen ] *****
***** [ Geplante Tasks ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Internetbrowser ] *****
[-] [C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Gelöscht : homepage-web.com
[-] [C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Gelöscht : hxxp://homepage-web.com/?s=lenovo&m=start
*************************
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Chrome Richtlinien gelöscht
########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [1024 Bytes] ########## Hier vom jrt: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.0 (08.31.2015:1)
OS: Windows 8.1 x64
Ran by Constantin on 04.09.2015 at 20:09:05,25
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\WINDOWS\SysWOW64\ai_recyclebin
~~~ Chrome
[C:\Users\Constantin\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Constantin\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Constantin\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Constantin\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 04.09.2015 at 20:11:42,18
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und nochmal eins frisch aus der Presse vom FRST :) Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:31-08-2015
durchgeführt von Constantin (Administrator) auf UROKAN (04-09-2015 20:13:05)
Gestartet von C:\Users\Constantin\Downloads
Geladene Profile: Constantin (Verfügbare Profile: Constantin)
Platform: Windows 8.1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13662936 2013-10-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1368792 2013-11-13] (Realtek Semiconductor)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [216576 2014-03-10] (Realtek Semiconductor Corporation)
HKLM-x32\...\Run: [jmekey] => C:\WINDOWS\jmesoft\hotkey.exe [118784 2013-07-24] (Lenovo)
HKLM-x32\...\Run: [jmesoft] => C:\Windows\jmesoft\ServiceLoader.exe [28672 2011-08-16] ()
HKLM-x32\...\Run: [LVT] => C:\Program Files\Lenovo\LVT\LJYZ.exe [886112 2011-11-24] (Lenovo)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111824 2015-08-25] (AVAST Software)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1387610972-3622489449-1713692181-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [2892992 2015-06-04] (Valve Corporation)
HKU\S-1-5-21-1387610972-3622489449-1713692181-1002\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe [41200 2015-05-04] (Overwolf LTD)
HKU\S-1-5-21-1387610972-3622489449-1713692181-1002\...\Run: [Akamai NetSession Interface] => C:\Users\Constantin\AppData\Local\Akamai\netsession_win.exe [4691384 2015-07-23] (Akamai Technologies, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-14] (AVAST Software)
Startup: C:\Users\Constantin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2015-06-03] ()
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{8BC7C3A7-3368-4EDC-B31C-A14F0B73BB4E}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1387610972-3622489449-1713692181-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-1387610972-3622489449-1713692181-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKU\S-1-5-21-1387610972-3622489449-1713692181-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
HKU\S-1-5-21-1387610972-3622489449-1713692181-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> DefaultScope {720BBC57-EAD0-4CCC-8A8D-57E120A3DF9D} URL = hxxp://www.startseite24.net/?q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {720BBC57-EAD0-4CCC-8A8D-57E120A3DF9D} URL = hxxp://www.startseite24.net/?q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1387610972-3622489449-1713692181-1002 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1387610972-3622489449-1713692181-1002 -> {720BBC57-EAD0-4CCC-8A8D-57E120A3DF9D} URL = hxxp://www.startseite24.net/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1387610972-3622489449-1713692181-1002 -> {A30ECCEA-6C34-4EA7-ADE9-411385A63685} URL =
SearchScopes: HKU\S-1-5-21-1387610972-3622489449-1713692181-1002 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-14] (AVAST Software)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-14] (AVAST Software)
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-09-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-09-03] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-06-01]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.google.de/","https://www.google.com/?trackid=sp-006","hxxp://homepage-web.com/?s=lenovo&m=start"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-01]
CHR Extension: (Google Docs) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-01]
CHR Extension: (Google Drive) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-01]
CHR Extension: (YouTube) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-01]
CHR Extension: (GeoGebra) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2015-06-01]
CHR Extension: (Google Search) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-01]
CHR Extension: (Google Sheets) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-01]
CHR Extension: (Full Screen Weather) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkaebihfmbofclegkcfkkemepfehibg [2015-06-01]
CHR Extension: (Google Docs Offline) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-03]
CHR Extension: (Planetarium) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp [2015-06-01]
CHR Extension: (Avast Online Security) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-06-01]
CHR Extension: (wikiHow Survival Kit) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ickaeddjnhfofihhibhnjemlphjmnchl [2015-06-01]
CHR Extension: (theHunter) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jangaedeekciafhlanphhnalogmhefmo [2015-06-01]
CHR Extension: (Autodesk Homestyler) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2015-06-01]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-02]
CHR Extension: (Google Scholar Button) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldipcbpaocekfooobnbcddclnhejkcpn [2015-06-01]
CHR Extension: (Google Maps) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-06-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-01]
CHR Extension: (Universe) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\oecmlnmneeeeiccpcohlffnipjhngmdk [2015-09-03]
CHR Extension: (CogniFit Brain Fitness) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pckogiikkcdjefncaekfjbdkmlfniagf [2015-06-01]
CHR Extension: (Psykopaint) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil [2015-06-01]
CHR Extension: (Gmail) - C:\Users\Constantin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-01]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-06-01]
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-02] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-14] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109008 2015-08-14] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4047768 2015-08-14] (Avast Software)
S2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [92160 2014-03-12] () [Datei ist nicht signiert]
S2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-08-16] () [Datei ist nicht signiert]
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [559872 2014-08-06] (Lenovo)
S2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584632 2015-03-06] (LENOVO INCORPORATED.)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [272440 2015-03-09] (Lenovo)
S4 LSEDT; C:\Windows\System32\LSEDT.exe [32968 2015-06-03] (Lenovo)
S2 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [1844024 2014-08-01] (Maxthon)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [999152 2015-05-04] (Overwolf LTD)
S2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-11-04] (Advanced Micro Devices)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-14] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28144 2015-08-14] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-14] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [454016 2015-08-14] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-14] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048344 2015-08-14] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-08-14] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-14] (AVAST Software)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [115152 2015-08-14] (AVAST Software)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [559832 2014-02-26] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3347672 2014-03-13] (Realtek Semiconductor Corporation )
R3 SSMO4Filter; C:\Windows\system32\drivers\MO4Driver.sys [21504 2011-07-27] (Sagatek Co. Ltd.)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-08-14] (Avast Software)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
S3 xhunter1; \??\C:\WINDOWS\xhunter1.sys [X]
S3 xspirit; \??\C:\WINDOWS\xspirit.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-09-04 20:11 - 2015-09-04 20:11 - 00001145 _____ C:\Users\Constantin\Desktop\JRT.txt
2015-09-04 20:07 - 2015-09-04 20:07 - 01799392 _____ (Malwarebytes Corporation) C:\Users\Constantin\Desktop\JRT_7600.exe
2015-09-04 20:05 - 2015-09-04 20:05 - 00001103 _____ C:\Users\Constantin\Desktop\AdwCleaner[C3].txt
2015-09-04 20:00 - 2015-09-04 20:00 - 00009688 _____ C:\Users\Constantin\Desktop\mbam.txt
2015-09-04 19:56 - 2015-09-04 20:04 - 00014732 _____ C:\WINDOWS\PFRO.log
2015-09-04 19:26 - 2015-09-04 19:58 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-04 19:25 - 2015-09-04 19:25 - 00001129 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-04 19:25 - 2015-09-04 19:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-04 19:25 - 2015-09-04 19:25 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-04 19:25 - 2015-09-04 19:25 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-04 19:25 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-09-04 19:25 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-09-04 19:25 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-09-04 19:24 - 2015-09-04 19:25 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Constantin\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-04 19:19 - 2015-09-04 19:19 - 00001295 _____ C:\Users\Constantin\Desktop\Revo Uninstaller.lnk
2015-09-04 19:19 - 2015-09-04 19:19 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-09-04 19:18 - 2015-09-04 19:18 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Constantin\Downloads\revosetup95.exe
2015-09-03 19:29 - 2015-09-03 19:29 - 00030942 _____ C:\Users\Constantin\Downloads\Addition.txt
2015-09-03 19:27 - 2015-09-04 20:13 - 00018547 _____ C:\Users\Constantin\Downloads\FRST.txt
2015-09-03 19:27 - 2015-09-04 20:13 - 00000000 ____D C:\FRST
2015-09-03 19:26 - 2015-09-03 19:26 - 02188800 _____ (Farbar) C:\Users\Constantin\Downloads\FRST64.exe
2015-09-03 16:08 - 2015-09-03 16:15 - 149199966 _____ C:\Users\Constantin\Desktop\documents-export-2015-09-03 (5).zip
2015-09-03 15:58 - 2015-09-03 16:18 - 736148295 _____ C:\Users\Constantin\Desktop\documents-export-2015-09-03 (4).zip
2015-09-03 15:49 - 2015-09-03 15:55 - 307991580 _____ C:\Users\Constantin\Desktop\documents-export-2015-09-03 (3).zip
2015-09-03 15:42 - 2015-09-03 15:46 - 131987337 _____ C:\Users\Constantin\Desktop\documents-export-2015-09-03 (2).zip
2015-09-03 15:39 - 2015-09-03 15:45 - 234053238 _____ C:\Users\Constantin\Desktop\documents-export-2015-09-03 (1).zip
2015-09-03 15:32 - 2015-09-03 15:32 - 01893181 _____ C:\Users\Constantin\Desktop\documents-export-2015-09-03.zip
2015-09-03 15:11 - 2015-09-03 15:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-09-03 15:10 - 2015-09-04 20:06 - 00001128 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-03 15:10 - 2015-09-04 19:15 - 00001132 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-03 15:10 - 2015-09-03 15:10 - 00004104 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-03 15:10 - 2015-09-03 15:10 - 00003868 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-03 14:10 - 2015-09-03 14:10 - 04772888 _____ (Avira Operations GmbH & Co. KG) C:\Users\Constantin\Downloads\avira_de_av_55e838b070b70__ws1.exe
2015-09-01 22:58 - 2015-09-02 00:07 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-09-01 22:58 - 2015-09-01 23:06 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-09-01 22:58 - 2015-09-01 22:58 - 00001418 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-09-01 22:58 - 2015-09-01 22:58 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2015-09-01 22:58 - 2015-09-01 22:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-09-01 22:58 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe
2015-09-01 22:55 - 2015-09-01 22:56 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Constantin\Downloads\spybot-2.4.exe
2015-09-01 22:55 - 2015-09-01 22:55 - 13485202 _____ C:\Users\Constantin\Downloads\hitmanpro379.zip
2015-09-01 22:40 - 2015-09-01 22:40 - 02877952 _____ (Pokki) C:\Users\Constantin\Downloads\PokkiInstaller.exe
2015-09-01 22:40 - 2015-09-01 22:40 - 00825448 _____ (Pokki) C:\Users\Constantin\Downloads\Pokki_Start_MenuSetup.exe
2015-09-01 22:26 - 2015-09-01 22:26 - 01654272 _____ C:\Users\Constantin\Downloads\adwcleaner_5.005.exe
2015-08-30 21:32 - 2015-08-14 10:02 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-08-30 21:30 - 2015-08-30 21:30 - 00003086 _____ C:\WINDOWS\System32\Tasks\Form Mart
2015-08-30 21:20 - 2015-09-04 20:06 - 00690380 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-30 21:19 - 2015-09-04 20:04 - 00005281 _____ C:\WINDOWS\setupact.log
2015-08-30 21:19 - 2015-08-30 21:19 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-08-30 21:08 - 2015-09-04 20:03 - 00000000 ____D C:\AdwCleaner
2015-08-30 20:50 - 2015-08-30 20:54 - 00000272 _____ C:\Users\Constantin\Downloads\debug.log
2015-08-27 20:12 - 2015-08-27 20:12 - 00003114 _____ C:\WINDOWS\System32\Tasks\Cooking Download
2015-08-27 15:26 - 2015-08-27 15:26 - 03541664 _____ (Aeria Games & Entertainment) C:\Users\Constantin\Downloads\aeria_ignite_install.exe
2015-08-19 16:17 - 2015-08-11 03:20 - 25191936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-08-19 16:17 - 2015-08-11 02:20 - 19871232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-08-14 10:03 - 2015-08-14 10:02 - 00115152 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\ngvss.sys
2015-08-14 10:02 - 2015-08-14 10:02 - 00454016 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNdisFlt.sys
2015-08-14 10:02 - 2015-08-14 10:02 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-08-12 10:37 - 2015-07-30 16:04 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 10:37 - 2015-07-30 15:48 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 10:17 - 2015-07-19 03:58 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-08-12 10:17 - 2015-07-18 20:51 - 03704320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-08-12 10:17 - 2015-07-18 20:31 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-08-12 10:17 - 2015-07-18 20:31 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-08-12 10:17 - 2015-07-18 20:29 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-08-12 10:17 - 2015-07-18 20:12 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-08-12 10:17 - 2015-07-18 20:10 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-08-12 10:17 - 2015-07-18 20:09 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-08-12 10:16 - 2015-07-18 20:31 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-08-12 10:16 - 2015-07-18 20:29 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-08-12 10:16 - 2015-07-18 20:29 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-08-12 10:16 - 2015-07-18 20:28 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-08-12 10:16 - 2015-07-16 22:36 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-08-12 10:16 - 2015-07-16 22:36 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-08-12 10:16 - 2015-07-16 22:35 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-08-12 10:16 - 2015-07-16 22:26 - 05923328 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-08-12 10:16 - 2015-07-16 22:23 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-08-12 10:16 - 2015-07-16 22:21 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-08-12 10:16 - 2015-07-16 21:53 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-08-12 10:16 - 2015-07-16 21:51 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-08-12 10:16 - 2015-07-16 21:50 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2015-08-12 10:16 - 2015-07-16 21:45 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-08-12 10:16 - 2015-07-16 21:45 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-08-12 10:16 - 2015-07-16 21:41 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2015-08-12 10:16 - 2015-07-16 21:39 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-08-12 10:16 - 2015-07-16 21:38 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-08-12 10:16 - 2015-07-16 21:36 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-08-12 10:16 - 2015-07-16 21:34 - 14451200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-08-12 10:16 - 2015-07-16 21:32 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-08-12 10:16 - 2015-07-16 21:14 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-08-12 10:16 - 2015-07-16 21:13 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-08-12 10:16 - 2015-07-16 21:12 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-08-12 10:16 - 2015-07-16 21:12 - 02427904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-08-12 10:16 - 2015-07-16 21:10 - 12856832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-08-12 10:16 - 2015-07-16 21:06 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-08-12 10:16 - 2015-07-16 21:01 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-08-12 10:16 - 2015-07-16 20:52 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-08-12 10:16 - 2015-07-16 20:49 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-08-12 10:16 - 2015-07-16 20:42 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-08-12 10:16 - 2015-07-16 20:38 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-08-12 10:16 - 2015-07-16 20:37 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-08-12 10:16 - 2015-06-09 20:27 - 00411133 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-08-12 10:15 - 2015-07-29 16:37 - 01994752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-08-12 10:15 - 2015-07-29 16:30 - 01381888 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-08-12 10:15 - 2015-07-29 16:23 - 01559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-08-12 10:15 - 2015-07-29 01:24 - 00025776 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-08-12 10:15 - 2015-07-28 16:24 - 01148416 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-08-12 10:15 - 2015-07-28 16:24 - 01116160 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-08-12 10:15 - 2015-07-28 16:24 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-08-12 10:15 - 2015-07-28 16:24 - 00743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-08-12 10:15 - 2015-07-28 16:24 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-08-12 10:15 - 2015-07-28 16:24 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-08-12 10:15 - 2015-07-24 20:57 - 04177408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-08-12 10:15 - 2015-07-24 20:57 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-08-12 10:15 - 2015-07-24 20:52 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-08-12 10:15 - 2015-07-24 19:27 - 00301568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-08-12 10:15 - 2015-07-24 19:23 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-08-12 10:15 - 2015-07-16 02:29 - 07458648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-12 10:15 - 2015-07-16 02:29 - 01735000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-08-12 10:15 - 2015-07-16 02:29 - 00101720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-08-12 10:15 - 2015-07-16 02:28 - 01499920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-08-12 10:15 - 2015-07-14 23:59 - 01113944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-08-12 10:15 - 2015-07-14 23:59 - 00487256 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll
2015-08-12 10:15 - 2015-07-14 23:59 - 00393560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcfgx.dll
2015-08-12 10:15 - 2015-07-14 05:22 - 02529880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-08-12 10:15 - 2015-07-14 05:21 - 01901776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-08-12 10:15 - 2015-07-13 21:46 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
2015-08-12 10:15 - 2015-07-13 21:45 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2015-08-12 10:15 - 2015-07-10 20:19 - 01101824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2015-08-12 10:15 - 2015-07-10 19:54 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-08-12 10:15 - 2015-07-10 19:42 - 02345472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-08-12 10:15 - 2015-07-10 19:14 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll
2015-08-12 10:15 - 2015-07-10 19:13 - 07032320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2015-08-12 10:15 - 2015-07-10 18:47 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-08-12 10:15 - 2015-07-10 18:31 - 06213120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2015-08-12 10:15 - 2015-07-09 19:13 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-08-12 10:15 - 2015-07-09 19:13 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-08-12 10:15 - 2015-07-09 18:30 - 00212992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-08-12 10:15 - 2015-07-07 11:40 - 00270168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2015-08-12 10:15 - 2015-07-07 11:40 - 00114520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2015-08-12 10:15 - 2015-07-07 11:40 - 00044560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2015-08-12 10:15 - 2015-07-02 00:19 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll
2015-08-12 10:15 - 2015-07-02 00:16 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll
2015-08-12 10:15 - 2015-07-01 23:37 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll
2015-08-12 10:15 - 2015-07-01 23:35 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\davclnt.dll
2015-08-12 10:15 - 2015-06-12 19:03 - 18823680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-08-12 10:15 - 2015-06-12 18:36 - 15159296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-08-12 10:15 - 2015-06-11 22:12 - 02476376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-08-12 10:15 - 2015-06-11 22:12 - 00428888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-08-12 10:15 - 2015-05-12 02:24 - 00536920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-08-10 11:37 - 2015-08-10 11:37 - 00000000 ____D C:\Users\Constantin\AppData\Roaming\Wargaming.net
2015-08-10 11:19 - 2015-08-10 11:21 - 00000000 ____D C:\Users\Constantin\AppData\Local\Balance Image
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-09-04 20:12 - 2015-06-01 22:11 - 00000000 __RDO C:\Users\Constantin\OneDrive
2015-09-04 20:09 - 2015-06-01 20:04 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1387610972-3622489449-1713692181-1002
2015-09-04 20:05 - 2015-06-03 13:10 - 00000000 ____D C:\Users\Constantin\AppData\Local\Deployment
2015-09-04 20:04 - 2015-06-02 02:27 - 00135880 _____ (Lenovo) C:\WINDOWS\system32\wpbbin.exe
2015-09-04 20:04 - 2015-06-01 19:58 - 00372598 _____ C:\Users\Constantin\AppData\Local\BTServer.log
2015-09-04 20:04 - 2015-02-08 11:14 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2015-09-04 20:04 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-04 20:04 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-09-04 20:00 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-09-04 11:24 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-04 11:16 - 2015-06-01 20:05 - 00003942 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{A0C9C0E6-2AAC-4034-9A6B-FE9F398687C3}
2015-09-03 15:11 - 2015-06-01 20:10 - 00000000 ____D C:\Program Files (x86)\Google
2015-09-03 15:02 - 2015-06-01 19:58 - 00001028 _____ C:\Users\Constantin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-09-03 14:57 - 2015-02-08 11:13 - 00000000 ____D C:\ProgramData\Package Cache
2015-09-03 14:33 - 2015-02-08 20:00 - 00764340 _____ C:\WINDOWS\system32\perfh007.dat
2015-09-03 14:33 - 2015-02-08 20:00 - 00159160 _____ C:\WINDOWS\system32\perfc007.dat
2015-09-03 14:33 - 2014-03-18 11:53 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-01 22:39 - 2015-07-20 14:40 - 00000000 ____D C:\Users\Constantin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AeriaGames
2015-09-01 22:39 - 2015-07-20 13:43 - 00000000 ____D C:\AeriaGames
2015-09-01 22:17 - 2015-07-13 18:23 - 00000000 ____D C:\Users\Constantin\AppData\Roaming\Awesomium
2015-09-01 19:38 - 2015-06-01 20:36 - 00002192 _____ C:\Users\Constantin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk
2015-08-31 21:34 - 2015-06-01 20:38 - 00000000 ____D C:\Users\Constantin\AppData\Local\Battle.net
2015-08-31 20:09 - 2015-06-01 20:37 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-08-30 21:35 - 2015-02-08 11:31 - 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2015-08-30 21:35 - 2015-02-08 11:25 - 00000000 ____D C:\Program Files\Lenovo
2015-08-30 21:32 - 2015-06-01 20:22 - 00003924 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-08-30 21:30 - 2015-06-01 19:57 - 00000000 ____D C:\Users\Constantin
2015-08-30 21:29 - 2015-07-20 13:43 - 00000000 ____D C:\Users\Constantin\AppData\Local\Akamai
2015-08-30 21:29 - 2015-06-06 22:48 - 00000000 ___SD C:\WINDOWS\system32\GWX
2015-08-30 21:29 - 2015-06-01 20:38 - 00000000 ____D C:\Users\Constantin\AppData\Roaming\Battle.net
2015-08-30 21:29 - 2015-02-08 11:27 - 00000000 ____D C:\Program Files (x86)\Amazon
2015-08-30 21:25 - 2015-06-01 20:10 - 00000000 ____D C:\Users\Constantin\AppData\Local\Google
2015-08-30 21:25 - 2015-02-08 11:31 - 00000000 ____D C:\ProgramData\Lenovo
2015-08-30 21:25 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\registration
2015-08-30 20:59 - 2015-06-01 20:05 - 00000000 __SHD C:\Users\Constantin\AppData\Local\EmieUserList
2015-08-30 20:59 - 2015-06-01 20:05 - 00000000 __SHD C:\Users\Constantin\AppData\Local\EmieSiteList
2015-08-30 20:32 - 2015-07-10 14:30 - 00020480 ___SH C:\Users\Constantin\Downloads\Thumbs.db
2015-08-26 11:01 - 2015-06-01 20:36 - 00002347 _____ C:\Users\Constantin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2015-08-26 10:58 - 2015-06-01 20:36 - 00002653 _____ C:\Users\Constantin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo Web Start.lnk
2015-08-24 19:45 - 2015-06-09 20:35 - 00000000 ____D C:\Users\Constantin\Desktop\Seminararbeit
2015-08-19 16:17 - 2013-08-22 17:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-08-14 11:08 - 2015-06-01 20:22 - 00000000 ____D C:\WINDOWS\SysWOW64\vbox
2015-08-14 11:08 - 2015-06-01 20:22 - 00000000 ____D C:\WINDOWS\system32\vbox
2015-08-14 10:18 - 2015-06-29 12:35 - 00000000 ____D C:\WINDOWS\Minidump
2015-08-14 10:03 - 2015-06-01 20:22 - 01048344 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-08-14 10:02 - 2015-06-03 10:27 - 00028144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2015-08-14 10:02 - 2015-06-01 20:22 - 00447944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-08-14 10:02 - 2015-06-01 20:22 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-08-14 10:02 - 2015-06-01 20:22 - 00150672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-08-14 10:02 - 2015-06-01 20:22 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-08-14 10:02 - 2015-06-01 20:22 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-08-14 10:02 - 2015-06-01 20:22 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-08-14 10:02 - 2015-06-01 20:22 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-08-13 20:43 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2015-08-13 11:38 - 2013-08-22 16:44 - 00371584 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-08-12 22:28 - 2013-08-22 17:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-12 22:28 - 2013-08-22 17:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-12 22:28 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Windows Defender
2015-08-12 22:28 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-08-12 13:03 - 2015-06-28 12:30 - 00238592 ___SH C:\Users\Constantin\Desktop\Thumbs.db
2015-08-12 10:36 - 2015-06-06 20:40 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-08-12 10:32 - 2015-06-06 20:40 - 132483416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-12 10:31 - 2015-06-10 17:10 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-08-12 10:31 - 2015-06-06 22:48 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2015-08-12 10:31 - 2013-08-22 17:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 10:31 - 2013-08-22 17:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-08 15:55 - 2015-06-07 18:26 - 00794088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-08-08 15:55 - 2015-06-07 18:26 - 00179688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-07 11:38 - 2015-06-01 19:58 - 00000000 ____D C:\Users\Constantin\AppData\Local\Packages
2015-08-05 18:39 - 2015-06-09 20:35 - 00000000 ___RD C:\Users\Constantin\Documents\Müko
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Constantin\AppData\Roaming\gqhG0IiKuJp7cdOh1TD07YpNx
2015-06-01 19:58 - 2015-09-04 20:04 - 0372598 _____ () C:\Users\Constantin\AppData\Local\BTServer.log
2015-02-08 11:12 - 2015-02-08 11:12 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Einige Dateien in TEMP:
====================
C:\Users\Constantin\AppData\Local\Temp\0812265e81023a015467442aa03a79be.dll
C:\Users\Constantin\AppData\Local\Temp\bf42b6f18916a804f395bc5ca3f63664.dll
C:\Users\Constantin\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-08-30 14:25
==================== Ende von FRST.txt ============================ |