Hallo!
Anbei erstmal die Logdatei vom AdwCleaner: Code:
# AdwCleaner v5.018 - Bericht erstellt am 06/11/2015 um 12:07:38
# Aktualisiert am 05/11/2015 von Xplode
# Datenbank : 2015-11-03.2 [Server]
# Betriebssystem : Windows 10 Pro (x64)
# Benutzername : Admin - PC
# Gestartet von : C:\Users\Admin\Downloads\AdwCleaner_5.018.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum
***** [ Dienste ] *****
***** [ Ordner ] *****
[-] Ordner Gelöscht : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcgcoifbkbphhjnekfkmohklfaimhikk
***** [ Dateien ] *****
[-] Datei Gelöscht : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jcgcoifbkbphhjnekfkmohklfaimhikk_0.localstorage
[-] Datei Gelöscht : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jcgcoifbkbphhjnekfkmohklfaimhikk_0.localstorage-journal
[-] Datei Gelöscht : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage
[-] Datei Gelöscht : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal
[-] Datei Gelöscht : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage
[-] Datei Gelöscht : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage-journal
***** [ DLLs ] *****
***** [ Verknüpfungen ] *****
***** [ Aufgabenplanung ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Internetbrowser ] *****
[-] [C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Gelöscht : jcgcoifbkbphhjnekfkmohklfaimhikk
*************************
:: "Tracing" Schlüssel gelöscht
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Chrome Richtlinien gelöscht
########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [1994 Bytes] ########## Die MBAM Logdatei: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 06.11.2015
Suchlaufzeit: 12:12
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.2.0.1024
Malware-Datenbank: v2015.11.06.03
Rootkit-Datenbank: v2015.11.04.02
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: Admin
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 368790
Abgelaufene Zeit: 14 Min., 32 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 11
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\temp_813a5cd0-04f6-4ddb-a269-e350a08d2cae-10_user, Löschen bei Neustart, [814acfabe8a342f461e7293add26f60a],
PUP.Optional.FasterSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\uhy3013, Löschen bei Neustart, [e3e83e3c0b80989edb1308c63fc49c64],
PUP.Optional.MyBrowser, HKLM\SOFTWARE\WOW6432NODE\MyBrowser, In Quarantäne, [5d6e7efc711acb6b4fa3d8c3ca3908f8],
PUP.Optional.SwiftSearch, HKLM\SOFTWARE\WOW6432NODE\SwiftSearch_1.10.0.25, In Quarantäne, [dcef86f4a4e7f1459750f19c1de64cb4],
PUP.Optional.CinemaPlus, HKU\S-1-5-18\SOFTWARE\CinemaPlus_1.3dV04.11-nv, In Quarantäne, [b21957230c7f3ef84c3c352753b04fb1],
PUP.Optional.CinemaPlus, HKU\S-1-5-18\SOFTWARE\CinemaPlus_1.3dV04.11-nv-ie, In Quarantäne, [ccffabcf7516c076078177e524df4cb4],
PUP.Optional.CinePlus, HKU\S-1-5-18\SOFTWARE\CinePlus-1.44V04.11-nv, In Quarantäne, [f7d4a3d777149b9b5e8f015b27dcc040],
PUP.Optional.CinePlus, HKU\S-1-5-18\SOFTWARE\CinePlus-1.44V04.11-nv-ie, In Quarantäne, [18b3a1d9f99242f46489510b3ec5847c],
PUP.Optional.CinemaPlus, HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\SOFTWARE\CinemaPlus_1.3dV04.11-nv-ie, In Quarantäne, [a9224238098292a41375500ccb38a957],
PUP.Optional.CinePlus, HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\SOFTWARE\CinePlus-1.44V04.11-nv-ie, In Quarantäne, [745793e7bfcc1e18e30a134904ff33cd],
PUP.Optional.MyBrowser, HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\SOFTWARE\MyBrowser, In Quarantäne, [3992dd9dbdce56e0c98ea4f8b2519070],
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 3
PUP.Optional.GlobalUpdate, C:\Users\Admin\AppData\Local\Temp\comh.360610, In Quarantäne, [d6f59ae04b40290d72edadb4aa5806fa],
PUP.Optional.GlobalUpdate, C:\Users\Admin\AppData\Local\Temp\comh.442473, In Quarantäne, [913a4e2c7813c76f17481b46748e2fd1],
PUP.Optional.MBot, C:\Program Files (x86)\mbot_de_014010136, In Quarantäne, [a9229ae0a4e773c315aee77ea75be719],
Dateien: 50
PUP.Optional.CrossRider, C:\Users\Admin\AppData\Roaming\28Arly8BQ3IUn.exe, In Quarantäne, [8e3dd2a8533857df7856e145ee1323dd],
PUP.Optional.CrossRider, C:\Users\Admin\AppData\Roaming\bSUwmicbiyVJJ5rnrs.exe, In Quarantäne, [ac1ff7839fec0b2bb8165fc7ee1304fc],
PUP.Optional.CrossBrowse, C:\Users\Admin\AppData\Local\Temp\225.exe, In Quarantäne, [5f6cec8e95f6ee48d7f578aeaf52d52b],
PUP.Optional.MyBrowser, C:\Users\Admin\AppData\Local\Temp\4156.exe, In Quarantäne, [52792852c6c500363b2b174ce81cc53b],
PUP.Optional.BonDon, C:\Users\Admin\AppData\Local\Temp\mytmpinstaller.exe, In Quarantäne, [1ead03778605c670ae6994b2b24f5aa6],
PUP.Optional.ConvertAd, C:\Users\Admin\AppData\Local\Temp\nsa22EC.tmp, In Quarantäne, [98334436b2d946f02c070ee51ce54eb2],
PUP.Optional.NoteUp, C:\Users\Admin\AppData\Local\Temp\nsl8B9B.tmp, In Quarantäne, [7a511466602b71c5a562b1a11ee3e917],
PUP.Optional.CrossRider, C:\Users\Admin\AppData\Local\Temp\9768.exe, In Quarantäne, [0cbf95e57318c670b5d36dfb40c48878],
PUP.Optional.Amonetize, C:\Users\Admin\AppData\Local\Temp\HarryPotterAndTheOrderOfThePhoenixGame__11652_il54233.exe, In Quarantäne, [b5166d0d33587eb8d3cce88ede23619f],
PUP.Optional.MyStartSearch.ShrtCln, C:\Users\Admin\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_76.exe, In Quarantäne, [75560d6d63280b2b82fcee7342c2d52b],
PUP.Optional.SwiftSearch, C:\Users\Admin\AppData\Local\Temp\is-1QRA7.tmp\465.exe, In Quarantäne, [04c7a4d65c2fcf67d19da6c36f9501ff],
PUP.Optional.Amonetize, C:\Users\Admin\AppData\Local\Temp\Rar$EXa0.430\HarryPotterAndTheOrderOfThePhoenixGame__11652_il54233.exe, In Quarantäne, [62698eec5239b086326d5a1c7190cc34],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.360610\globalupdate.exe, In Quarantäne, [517a710929620b2ba7263bb41de34db3],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.360610\globalupdateBroker.exe, In Quarantäne, [99327cfe4843c17537966a8524dc748c],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.360610\globalupdateCrashHandler.exe, In Quarantäne, [7f4c403a147739fdffce88678878af51],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.360610\globalupdateOnDemand.exe, In Quarantäne, [e8e34a30f99256e0f8d578773ac67987],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.360610\goopdate.dll, In Quarantäne, [d3f898e2e9a2dc5afdd0b73826dadc24],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.360610\goopdateres_en.dll, In Quarantäne, [85467dfd2566ee48af1e9956a06044bc],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.360610\npglobalupdateUpdate4.dll, In Quarantäne, [e8e391e9fe8d2d090cc10ee19d63eb15],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.360610\psmachine.dll, In Quarantäne, [5c6fc5b5216a94a2cd00cb242dd3dc24],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.360610\psuser.dll, In Quarantäne, [d9f213676526fd3915b815da9f615fa1],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.442473\globalupdate.exe, In Quarantäne, [993232487e0dcf67dfee707fef11a25e],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.442473\globalupdateBroker.exe, In Quarantäne, [62699edce2a93ff7438af7f82ad6cf31],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.442473\globalupdateCrashHandler.exe, In Quarantäne, [9f2cc4b6dbb077bf814c0be4c33dd22e],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.442473\globalupdateOnDemand.exe, In Quarantäne, [4784e8923556989ed3fa678808f8f808],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.442473\goopdate.dll, In Quarantäne, [b5162b4f6b20cb6b5c717d72887860a0],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.442473\goopdateres_en.dll, In Quarantäne, [01cabfbb7b102016e0ed509fc63a1ae6],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.442473\npglobalupdateUpdate4.dll, In Quarantäne, [dcef6812f5961e18e1ec757afd032cd4],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.442473\psmachine.dll, In Quarantäne, [39927208e9a29e9803ca5e9101ff738d],
PUP.Optional.ModGoog, C:\Users\Admin\AppData\Local\Temp\comh.442473\psuser.dll, In Quarantäne, [3a9196e4e8a3e353e2eb727d05fbe818],
PUP.Optional.EoRezo, C:\Users\Admin\AppData\Local\Temp\is-E6IQG.tmp\643.exe, In Quarantäne, [f2d9d2a87912e0569bcec85fe21f17e9],
PUP.Optional.EoRezo, C:\Users\Admin\AppData\Local\Temp\is-LQGHH.tmp\465.exe, In Quarantäne, [369517635c2fe6508bde0c1b778a40c0],
PUP.Optional.EoRezo, C:\Users\Admin\AppData\Local\Temp\is-LQGHH.tmp\package_SByoutube_installer_multilang.exe, In Quarantäne, [0cbfa6d4602bf343d693e83f1be6c937],
Adware.FakeAV, C:\Users\Admin\Downloads\Gimp_Downloader.exe, In Quarantäne, [597271095437da5c54a1cd73b74a7090],
PUP.Optional.ABengine, C:\Users\Admin\AppData\Local\Temp\lengine.ini.log, In Quarantäne, [725911696d1e23130fec99ba2bd842be],
PUP.Optional.ABengine, C:\Windows\Temp\lengine.ini.log, In Quarantäne, [15b6601aa3e8c571bc3f73e0966d669a],
PUP.Optional.Acengine, C:\Users\Admin\AppData\Local\Temp\acengine.log, In Quarantäne, [e4e765159dee30069372193bdb28e21e],
PUP.Optional.Acengine, C:\Windows\Temp\acengine.log, In Quarantäne, [408b1367a2e937ff0500df7526dd6a96],
PUP.Optional.CrossRider, C:\Windows\System32\Tasks\temp_813a5cd0-04f6-4ddb-a269-e350a08d2cae-10_user, In Quarantäne, [8f3c05753e4d221456a07be6d42fa65a],
PUP.Optional.CrossRider, C:\Windows\Tasks\temp_813a5cd0-04f6-4ddb-a269-e350a08d2cae-10_user.job, In Quarantäne, [98339cde206b53e3a94ef36e3bc821df],
PUP.Optional.Vitruvian, C:\Users\Admin\AppData\Local\Temp\vitruvian-installer-hardwareprofile-v0001, In Quarantäne, [5774acce0d7ea88eb56dcec546bdf20e],
PUP.Optional.Vitruvian, C:\Users\Admin\AppData\Local\Temp\vitruvian-installer-install-v0003, In Quarantäne, [00cb542617748ea872b06b281ae9d52b],
PUP.Optional.Vitruvian, C:\Users\Admin\AppData\Local\Temp\vitruvian-installer-processes-v0002, In Quarantäne, [6269a7d38b0059dd47db7e1538cb12ee],
PUP.Optional.Vitruvian, C:\Users\Admin\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001, In Quarantäne, [8d3ed6a4543740f64cd6761df70c2ad6],
PUP.Optional.Vitruvian, C:\Users\Admin\AppData\Local\Temp\vitruvian-installer-uninstall-v0002, In Quarantäne, [66653941b0dbd561e43ef2a12bd8c43c],
PUP.Optional.ReMarkit.PrxySvrRST, C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markit00.re-markit.co_0.localstorage, In Quarantäne, [329980fa4645eb4bffb1e9b862a107f9],
PUP.Optional.ReMarkit.PrxySvrRST, C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markit00.re-markit.co_0.localstorage-journal, In Quarantäne, [8c3f324814776acce4cceab7aa5922de],
PUP.Optional.FasterSearch, C:\Windows\System32\Tasks\uhy3013, In Quarantäne, [6a611f5b216a7eb8ea0266681ee52ed2],
PUP.Optional.GlobalUpdate, C:\Users\Admin\AppData\Local\Temp\comh.360610\globalupdateHelper.msi, In Quarantäne, [d6f59ae04b40290d72edadb4aa5806fa],
PUP.Optional.GlobalUpdate, C:\Users\Admin\AppData\Local\Temp\comh.442473\globalupdateHelper.msi, In Quarantäne, [913a4e2c7813c76f17481b46748e2fd1],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Die Logdatei vom JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 10 Pro x64
Ran by Admin on 06.11.2015 at 12:44:10,93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_A5B343D047FD8BD2F268B0EA0F8DBD7C
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\users\Public\Documents\guid
~~~ Chrome
[C:\Users\Admin\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Admin\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Admin\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Admin\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.11.2015 at 12:46:27,95
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und die beiden Logdateien vom FRST:
FRST: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:05-11-2015
durchgeführt von Admin (Administrator) auf PC (06-11-2015 12:50:47)
Gestartet von C:\Users\Admin\Desktop
Geladene Profile: Admin (Verfügbare Profile: Admin)
Platform: Windows 10 Pro (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Edge)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [XFast LAN] => C:\Program Files\ASRock\XFast LAN\cFosSpeed.exe [2009952 2013-05-31] (cFos Software GmbH)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169744 2015-09-12] (Apple Inc.)
HKLM-x32\...\Run: [XFastUSB] => C:\Program Files (x86)\XFastUSB\XFastUsb.exe [6311104 2014-12-15] (FNet Co., Ltd.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [RoccatKonePure] => C:\Program Files (x86)\ROCCAT\Kone Pure Mouse\KonePureMonitor.EXE [561152 2014-01-20] (ROCCAT GmbH)
HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\...\Run: [Spotify Web Helper] => C:\Users\Admin\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2021944 2015-06-17] (Spotify Ltd)
HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\...\Run: [Spotify] => C:\Users\Admin\AppData\Roaming\Spotify\Spotify.exe [7323192 2015-06-17] (Spotify Ltd)
HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8551848 2015-10-19] (Piriform Ltd)
HKU\S-1-5-18\...\RunOnce: [iCloud] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloud.exe [43816 2015-04-26] (Apple Inc.)
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk [2015-11-06]
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{947ba08f-6d7e-4686-b9ff-2806db41b1ff}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-09-29] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-25] (Google Inc.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-09-15] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-09-29] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-25] (Google Inc.)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-09-15] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-25] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-25] (Google Inc.)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-10-14] (Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-03] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-21] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-19] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
Chrome:
=======
CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-05]
CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Google-Suche) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (LoungeDestroyer) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2015-10-07]
CHR Extension: (Google Text & Tabellen Offline) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-03]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-25]
CHR Extension: (Google Mail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)
S2 ASRockIOMon; C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\IOMonitorSrv.exe [454656 2013-05-28] () [Datei ist nicht signiert]
S2 cFosSpeedS; C:\Program Files\ASRock\XFast LAN\spd.exe [652640 2013-05-31] (cFos Software GmbH)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [614624 2014-12-10] (Futuremark)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-03] (Intel Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [966336 2014-10-10] (@ByELDI) [Datei ist nicht signiert]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
S3 AsrDrv101; C:\Windows\SysWOW64\Drivers\AsrDrv101.sys [22280 2014-12-16] (ASRock Incorporation)
R0 AsrRamDisk; C:\Windows\System32\drivers\AsrRamDisk.sys [40200 2013-05-09] (ASRock Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [102912 2015-07-15] (Advanced Micro Devices)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2014-12-15] (FNet Co., Ltd.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2015-11-06] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation)
R3 sthid; C:\Windows\System32\drivers\sthid.sys [21216 2014-08-06] (Splashtop Inc.)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-11-06 12:50 - 2015-11-06 12:50 - 00000000 ____D C:\Users\Admin\Desktop\FRST-OlderVersion
2015-11-06 12:46 - 2015-11-06 12:46 - 00001283 _____ C:\Users\Admin\Desktop\JRT.txt
2015-11-06 12:43 - 2015-11-06 12:43 - 01798976 _____ (Malwarebytes) C:\Users\Admin\Desktop\JRT.exe
2015-11-06 12:43 - 2015-11-06 12:43 - 00010166 _____ C:\Users\Admin\Desktop\mbam.txt
2015-11-06 12:38 - 2015-11-06 12:38 - 00016148 _____ C:\WINDOWS\system32\PC_Admin_HistoryPrediction.bin
2015-11-06 12:12 - 2015-11-06 12:39 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-11-06 12:11 - 2015-11-06 12:37 - 00001169 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-06 12:11 - 2015-11-06 12:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-06 12:11 - 2015-11-06 12:11 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-11-06 12:11 - 2015-11-06 12:11 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-11-06 12:11 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-11-06 12:11 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-11-06 12:11 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-11-06 12:10 - 2015-11-06 12:11 - 22908888 _____ (Malwarebytes ) C:\Users\Admin\Downloads\mbam-setup-2.2.0.1024.exe
2015-11-06 12:09 - 2015-11-06 12:09 - 00002073 _____ C:\Users\Admin\Desktop\AdwCleaner[C3].txt
2015-11-06 12:08 - 2015-11-06 12:38 - 00014854 _____ C:\WINDOWS\PFRO.log
2015-11-06 12:05 - 2015-11-06 12:05 - 01713664 _____ C:\Users\Admin\Downloads\AdwCleaner_5.018.exe
2015-11-05 14:32 - 2015-11-06 12:51 - 00014435 _____ C:\Users\Admin\Desktop\FRST.txt
2015-11-05 14:31 - 2015-11-05 14:31 - 04404952 _____ (Kaspersky Lab ZAO) C:\Users\Admin\Desktop\tdsskiller.exe
2015-11-05 14:30 - 2015-11-06 12:50 - 02198528 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2015-11-05 14:30 - 2015-11-06 12:50 - 00000000 ____D C:\FRST
2015-11-05 14:13 - 2015-11-05 14:13 - 04944608 _____ (Advanced Micro Devices, Inc.) C:\Users\Admin\Downloads\autodetectutility.exe
2015-11-05 14:00 - 2015-11-05 14:00 - 00000000 ___HD C:\OneDriveTemp
2015-11-05 12:12 - 2015-11-05 12:12 - 01708032 _____ C:\Users\Admin\Downloads\adwcleaner_5.017 (3).exe
2015-11-04 17:15 - 2015-11-04 17:15 - 01708032 _____ C:\Users\Admin\Downloads\adwcleaner_5.017 (2).exe
2015-11-04 17:08 - 2015-11-06 12:07 - 00000000 ____D C:\AdwCleaner
2015-11-04 17:08 - 2015-11-04 17:08 - 01708032 _____ C:\Users\Admin\Downloads\adwcleaner_5.017 (1).exe
2015-11-04 16:49 - 2015-11-06 12:38 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-04 16:49 - 2015-11-04 16:49 - 00000000 ____D C:\$SysReset
2015-11-04 16:34 - 2015-11-06 12:37 - 00000901 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-11-04 16:34 - 2015-11-04 16:34 - 00002844 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2015-11-04 16:34 - 2015-11-04 16:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-11-04 16:34 - 2015-11-04 16:34 - 00000000 ____D C:\Program Files\CCleaner
2015-11-04 16:33 - 2015-11-04 16:34 - 05524624 _____ (Piriform Ltd) C:\Users\Admin\Downloads\ccsetup511_slim.exe
2015-11-04 16:14 - 2015-11-04 16:23 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2015-11-04 16:13 - 2015-11-04 16:13 - 00000000 ____D C:\WINDOWS\pss
2015-11-04 16:07 - 2015-11-04 16:07 - 00003380 _____ C:\WINDOWS\System32\Tasks\{6761BBC9-893A-456B-822C-C0DF98AE0062}
2015-11-04 15:21 - 2015-11-06 12:39 - 00001004 _____ C:\WINDOWS\Tasks\28Arly8BQ3IUn.job
2015-11-04 15:21 - 2015-11-04 15:21 - 00004136 _____ C:\WINDOWS\System32\Tasks\28Arly8BQ3IUn
2015-11-04 15:19 - 2015-11-06 12:39 - 00001014 _____ C:\WINDOWS\Tasks\bSUwmicbiyVJJ5rnrs.job
2015-11-04 15:19 - 2015-11-04 15:19 - 00004156 _____ C:\WINDOWS\System32\Tasks\bSUwmicbiyVJJ5rnrs
2015-11-04 15:17 - 2015-11-04 16:00 - 00000004 _____ C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-11-04 15:17 - 2013-08-22 14:25 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hp.bak
2015-11-04 15:16 - 2015-11-04 15:16 - 00000000 ____D C:\Users\Public\Documents\Baidu
2015-11-04 15:15 - 2015-11-04 15:39 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Opera Software
2015-11-04 15:15 - 2015-11-04 15:39 - 00000000 ____D C:\Users\Admin\AppData\Local\Opera Software
2015-11-04 15:12 - 2015-11-04 15:39 - 00000000 ____D C:\Program Files (x86)\Opera
2015-10-30 17:15 - 2015-10-30 17:15 - 00000000 ____D C:\ProgramData\ROCCAT
2015-10-30 17:15 - 2015-10-30 17:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ROCCAT
2015-10-30 17:14 - 2015-10-30 17:14 - 24907859 _____ C:\Users\Admin\Downloads\ROCCAT_Kone_Pure_DRV1.14_FW1.21.zip
2015-10-30 17:14 - 2015-10-30 17:14 - 00000000 ____D C:\Program Files (x86)\ROCCAT
2015-10-30 17:14 - 2014-01-20 10:53 - 73113600 _____ (ROCCAT GmbH) C:\Users\Admin\Desktop\KonePureOption.exe
2015-10-30 17:13 - 2015-10-28 00:38 - 21871616 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-30 17:13 - 2015-10-28 00:16 - 18801664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-30 17:13 - 2015-10-21 13:45 - 00541024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-10-30 17:13 - 2015-10-21 13:44 - 00459104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2015-10-30 17:13 - 2015-10-21 13:43 - 01392480 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-30 17:13 - 2015-10-21 13:39 - 03621248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-10-30 17:13 - 2015-10-21 13:00 - 24595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-30 17:13 - 2015-10-21 13:00 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-30 17:13 - 2015-10-21 12:59 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2015-10-30 17:13 - 2015-10-21 12:57 - 02418688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-30 17:13 - 2015-10-21 12:52 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-30 17:13 - 2015-10-21 12:50 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-10-30 17:13 - 2015-10-21 12:48 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-30 17:13 - 2015-10-21 12:47 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-10-30 17:13 - 2015-10-21 12:46 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-30 17:13 - 2015-10-21 12:46 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-10-30 17:13 - 2015-10-21 12:44 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-10-30 17:13 - 2015-10-21 12:44 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-30 17:13 - 2015-10-21 12:43 - 02675200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2015-10-30 17:13 - 2015-10-21 12:42 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-30 17:13 - 2015-10-21 12:41 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-30 17:13 - 2015-10-21 12:40 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2015-10-30 17:13 - 2015-10-21 12:38 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2015-10-30 17:13 - 2015-10-21 06:53 - 00961376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-30 17:13 - 2015-10-21 06:49 - 02878512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-10-30 17:13 - 2015-10-21 06:13 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-30 17:13 - 2015-10-21 06:11 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-30 17:13 - 2015-10-21 06:08 - 01918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-30 17:13 - 2015-10-21 06:05 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-10-30 17:13 - 2015-10-21 06:03 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-10-30 17:13 - 2015-10-21 06:03 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2015-10-30 17:13 - 2015-10-21 05:58 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2015-10-30 17:13 - 2015-10-21 05:58 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-30 17:13 - 2015-10-21 05:55 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2015-10-26 19:45 - 2015-10-26 19:45 - 00014336 _____ C:\Users\Admin\Downloads\wenn-2.xls
2015-10-26 19:38 - 2015-10-26 19:38 - 03135063 _____ C:\Users\Admin\Downloads\Pruefung_1_Jugendarbeitsschutzgesetz_.zip
2015-10-17 13:48 - 2015-10-10 08:12 - 00078528 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-17 13:48 - 2015-10-06 04:03 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-17 13:48 - 2015-10-06 03:46 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-17 13:48 - 2015-10-01 05:01 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-10-17 13:48 - 2015-10-01 05:01 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-10-17 13:48 - 2015-10-01 05:01 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-10-17 13:48 - 2015-10-01 05:01 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-10-17 13:48 - 2015-10-01 05:00 - 08020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-17 13:48 - 2015-10-01 04:03 - 00757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2015-10-17 13:48 - 2015-09-25 05:01 - 02573768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-10-17 13:48 - 2015-09-25 05:01 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-10-17 13:48 - 2015-09-25 04:56 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-10-17 13:48 - 2015-09-25 04:52 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-10-17 13:48 - 2015-09-25 04:33 - 01997336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-10-17 13:48 - 2015-09-25 04:26 - 20858360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-10-17 13:48 - 2015-09-25 04:11 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-17 13:48 - 2015-09-25 04:11 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-17 13:48 - 2015-09-25 04:09 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-10-17 13:48 - 2015-09-25 04:07 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-17 13:48 - 2015-09-25 04:04 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-10-17 13:48 - 2015-09-25 04:04 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-17 13:48 - 2015-09-25 04:03 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-17 13:48 - 2015-09-25 04:03 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-10-17 13:48 - 2015-09-25 04:02 - 07523840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-17 13:48 - 2015-09-25 04:02 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-10-17 13:48 - 2015-09-25 04:02 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-17 13:48 - 2015-09-25 04:01 - 04792320 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-17 13:48 - 2015-09-25 04:01 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-17 13:48 - 2015-09-25 04:00 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-17 13:48 - 2015-09-25 04:00 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-17 13:48 - 2015-09-25 04:00 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-17 13:48 - 2015-09-25 04:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-17 13:48 - 2015-09-25 03:59 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-17 13:48 - 2015-09-25 03:59 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-17 13:48 - 2015-09-25 03:59 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-17 13:48 - 2015-09-25 03:59 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-17 13:48 - 2015-09-25 03:59 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-17 13:48 - 2015-09-25 03:59 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-17 13:48 - 2015-09-25 03:58 - 01871360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-10-17 13:48 - 2015-09-25 03:47 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-17 13:48 - 2015-09-25 03:47 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-17 13:48 - 2015-09-25 03:38 - 03580416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-17 13:48 - 2015-09-25 03:38 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-10-17 13:48 - 2015-09-25 03:38 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-17 13:48 - 2015-09-25 03:38 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-10-17 13:48 - 2015-09-25 03:37 - 00766976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-10-17 13:48 - 2015-09-25 03:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-17 13:48 - 2015-09-25 03:37 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-17 13:48 - 2015-09-25 03:36 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-10-17 13:48 - 2015-09-25 03:36 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-17 13:48 - 2015-09-25 03:34 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-17 13:48 - 2015-09-25 03:34 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-17 13:48 - 2015-09-25 03:34 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-17 13:48 - 2015-09-25 03:34 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-17 13:48 - 2015-09-25 03:34 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-17 13:48 - 2015-09-25 03:33 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-17 13:48 - 2015-09-25 03:32 - 01594368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-10-17 13:48 - 2015-09-25 03:32 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-10-17 13:39 - 2015-11-04 16:28 - 00000000 ____D C:\Users\Admin\Desktop\Felgen
2015-10-17 13:36 - 2015-11-06 12:37 - 00001816 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-10-17 13:36 - 2015-10-17 13:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-10-17 13:35 - 2015-11-06 12:37 - 00002523 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-10-17 13:35 - 2015-10-17 13:36 - 00000000 ____D C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-10-17 13:35 - 2015-10-17 13:36 - 00000000 ____D C:\Program Files\iTunes
2015-10-17 13:35 - 2015-10-17 13:35 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple
2015-10-17 13:35 - 2015-10-17 13:35 - 00000000 ____D C:\Program Files\iPod
2015-10-17 13:35 - 2015-10-17 13:35 - 00000000 ____D C:\Program Files\Bonjour
2015-10-17 13:35 - 2015-10-17 13:35 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-10-17 13:35 - 2015-10-17 13:35 - 00000000 ____D C:\Program Files (x86)\Bonjour
2015-10-17 13:35 - 2015-10-17 13:35 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2015-10-17 13:30 - 2015-10-17 13:34 - 152447768 _____ (Apple Inc.) C:\Users\Admin\Downloads\iTunes6464Setup (1).exe
2015-10-12 18:13 - 2015-10-12 18:15 - 167601944 _____ (Apple Inc.) C:\Users\Admin\Downloads\iTunes6464Setup.exe
2015-10-12 17:20 - 2015-10-12 17:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2015-10-12 17:09 - 2015-10-12 17:19 - 71807792 _____ (Apple Inc.) C:\Users\Admin\Downloads\iCloudSetup.exe
2015-10-12 17:03 - 2015-10-12 17:24 - 1971067436 _____ C:\Users\Admin\Downloads\iPhone7,2_8.4.1_12H321_Restore.ipsw
2015-10-09 15:13 - 2015-10-09 15:13 - 00000000 ____D C:\Users\Admin\AppData\LocalLow\Hyper Hippo Productions Ltd_
2015-10-09 15:12 - 2015-10-09 15:12 - 00000222 _____ C:\Users\Admin\Desktop\AdVenture Capitalist.url
2015-10-08 16:47 - 2015-10-08 16:47 - 00000000 ____D C:\ProgramData\ATI
2015-10-07 18:54 - 2015-10-07 18:54 - 00062253 _____ C:\WINDOWS\SysWOW64\CCCInstall_201510071954276182.log
2015-10-07 18:54 - 2015-10-07 18:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-10-07 18:54 - 2015-10-07 18:54 - 00000000 ____D C:\Program Files\ATI Technologies
2015-10-07 18:53 - 2015-10-07 18:54 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2015-10-07 18:53 - 2015-10-07 18:53 - 00052907 _____ C:\WINDOWS\SysWOW64\CCCInstall_201510071953453509.log
2015-10-07 18:52 - 2015-10-07 18:52 - 47794160 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 39721456 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\amdocl.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 30776304 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atio6axx.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 27544560 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl12cl64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 25320432 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atioglxx.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 22327280 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\amdocl12cl.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 15725552 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticaldd64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 14310896 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticaldd.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 09355016 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 08009360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdva.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 07683096 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 07482560 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdag.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 06686192 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmantle64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 05216240 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmantle32.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 03471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
2015-10-07 18:52 - 2015-10-07 18:52 - 03437632 _____ C:\WINDOWS\system32\atiumd6a.cap
2015-10-07 18:52 - 2015-10-07 18:52 - 01196032 _____ C:\WINDOWS\system32\amdocl_as64.exe
2015-10-07 18:52 - 2015-10-07 18:52 - 01070592 _____ C:\WINDOWS\system32\amdocl_ld64.exe
2015-10-07 18:52 - 2015-10-07 18:52 - 01004032 _____ C:\WINDOWS\SysWOW64\amdocl_as32.exe
2015-10-07 18:52 - 2015-10-07 18:52 - 00935408 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00935408 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00833800 _____ C:\WINDOWS\system32\amdicdxx.dat
2015-10-07 18:52 - 2015-10-07 18:52 - 00807424 _____ C:\WINDOWS\SysWOW64\amdocl_ld32.exe
2015-10-07 18:52 - 2015-10-07 18:52 - 00662392 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
2015-10-07 18:52 - 2015-10-07 18:52 - 00662392 _____ C:\WINDOWS\system32\atiapfxx.blb
2015-10-07 18:52 - 2015-10-07 18:52 - 00631280 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00524272 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00471320 _____ C:\WINDOWS\system32\amdmiracast.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00375792 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiapfxx.exe
2015-10-07 18:52 - 2015-10-07 18:52 - 00341488 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODE.exe
2015-10-07 18:52 - 2015-10-07 18:52 - 00243696 _____ C:\WINDOWS\system32\clinfo.exe
2015-10-07 18:52 - 2015-10-07 18:52 - 00213488 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00199664 _____ (AMD) C:\WINDOWS\system32\atitmm64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00198640 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00177344 _____ C:\WINDOWS\system32\ativce03.dat
2015-10-07 18:52 - 2015-10-07 18:52 - 00175648 _____ C:\WINDOWS\system32\amde31a.dat
2015-10-07 18:52 - 2015-10-07 18:52 - 00168944 _____ C:\WINDOWS\system32\atieah64.exe
2015-10-07 18:52 - 2015-10-07 18:52 - 00165360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00152560 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2015-10-07 18:52 - 2015-10-07 18:52 - 00151936 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdhcp64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00150512 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00143344 _____ C:\WINDOWS\system32\amdhdl64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00138384 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdhcp32.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00136176 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00132080 _____ C:\WINDOWS\SysWOW64\amdhdl32.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00122352 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00117608 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00112368 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiu9pag.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00111600 _____ C:\WINDOWS\system32\hsa-thunk64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00111088 _____ C:\WINDOWS\SysWOW64\hsa-thunk.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00110320 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00103408 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00100816 _____ C:\WINDOWS\system32\ativce02.dat
2015-10-07 18:52 - 2015-10-07 18:52 - 00097776 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00096752 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00089584 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00088000 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00088000 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00083952 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6pxx.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00081168 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00081160 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00078320 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiglpxx.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00078320 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiglpxx.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00073712 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00071152 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalrt64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00068080 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00064496 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalcl64.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00060912 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalrt.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00059888 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODCLI.exe
2015-10-07 18:52 - 2015-10-07 18:52 - 00059376 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmmcl6.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00057840 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalcl.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00052208 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\ati2erec.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00048112 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmmcl.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00047664 _____ C:\WINDOWS\system32\kapp_ci.sbin
2015-10-07 18:52 - 2015-10-07 18:52 - 00043536 _____ C:\WINDOWS\system32\kapp_si.sbin
2015-10-07 18:52 - 2015-10-07 18:52 - 00038384 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00012784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
2015-10-07 18:52 - 2015-10-07 18:52 - 00012784 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-11-06 12:43 - 2015-08-05 21:51 - 01793546 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-06 12:43 - 2015-07-10 17:34 - 00772138 _____ C:\WINDOWS\system32\perfh007.dat
2015-11-06 12:43 - 2015-07-10 17:34 - 00154500 _____ C:\WINDOWS\system32\perfc007.dat
2015-11-06 12:39 - 2014-12-15 23:33 - 00001120 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-06 12:38 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-06 12:37 - 2015-09-08 18:22 - 00000971 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2015-11-06 12:37 - 2015-08-05 22:01 - 00002358 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-11-06 12:37 - 2015-08-05 21:45 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-11-06 12:37 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-11-06 12:37 - 2015-07-10 10:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-11-06 12:37 - 2015-05-24 23:54 - 00000925 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-11-06 12:37 - 2015-01-06 20:22 - 00001017 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2015-11-06 12:37 - 2014-12-31 19:28 - 00000973 _____ C:\Users\Public\Desktop\Steam.lnk
2015-11-06 12:37 - 2014-12-31 18:33 - 00001813 _____ C:\Users\Admin\Desktop\Spotify.lnk
2015-11-06 12:37 - 2014-12-31 18:33 - 00001799 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-11-06 12:37 - 2014-12-18 21:21 - 00002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-11-06 12:37 - 2014-12-15 23:33 - 00001321 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-11-06 12:23 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-11-06 12:19 - 2014-12-15 23:33 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-06 11:03 - 2014-12-31 19:28 - 00000000 ____D C:\Program Files (x86)\Steam
2015-11-05 20:20 - 2015-08-05 21:41 - 00000000 ____D C:\Users\Admin
2015-11-05 18:47 - 2015-01-06 20:23 - 00000000 ____D C:\Users\Admin\AppData\Roaming\TS3Client
2015-11-05 17:46 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\rescache
2015-11-05 14:57 - 2014-12-30 15:46 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-05 14:56 - 2014-12-30 19:00 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-11-05 14:05 - 2015-08-05 22:01 - 00000000 ___RD C:\Users\Admin\OneDrive
2015-11-04 17:09 - 2015-08-05 21:41 - 00000000 ___RD C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-11-04 17:09 - 2014-12-15 23:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-11-04 16:42 - 2015-08-05 22:33 - 00000000 ___DC C:\WINDOWS\Panther
2015-11-04 16:42 - 2014-12-30 23:19 - 00000000 ____D C:\Users\Admin\AppData\Local\CrashDumps
2015-11-04 16:09 - 2014-12-18 21:20 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-11-04 16:08 - 2014-12-15 22:53 - 00000000 ____D C:\Program Files\KMSpico
2015-11-04 15:46 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2015-11-04 15:39 - 2015-01-21 20:03 - 00000000 __SHD C:\Users\Admin\AppData\Local\EmieUserList
2015-11-04 15:39 - 2015-01-21 20:03 - 00000000 __SHD C:\Users\Admin\AppData\Local\EmieSiteList
2015-11-04 15:26 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-02 14:26 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-11-01 00:33 - 2015-01-05 18:20 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-10-30 17:14 - 2014-12-15 23:42 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-10-27 19:48 - 2014-12-31 18:33 - 00000000 ____D C:\Users\Admin\AppData\Local\Spotify
2015-10-27 19:48 - 2014-12-31 18:32 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Spotify
2015-10-26 20:55 - 2015-04-12 21:14 - 00000000 ____D C:\Users\Admin\Desktop\Mailin
2015-10-26 20:15 - 2013-08-22 14:25 - 00000167 _____ C:\WINDOWS\win.ini
2015-10-26 19:47 - 2014-12-15 22:56 - 00000000 ____D C:\Users\Admin\AppData\Local\Packages
2015-10-17 13:35 - 2015-04-10 06:25 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-10-17 13:34 - 2015-04-10 06:25 - 00000000 ____D C:\ProgramData\Apple
2015-10-16 04:10 - 2015-07-10 12:06 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-16 04:10 - 2015-07-10 12:06 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-12 18:13 - 2015-09-08 19:52 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2015-10-12 18:11 - 2014-12-30 17:39 - 00000000 ____D C:\Users\Admin\AppData\Local\Akamai
2015-10-12 17:47 - 2015-07-10 13:20 - 00348328 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-10-12 17:45 - 2015-07-10 17:44 - 00000000 ____D C:\Program Files\Windows Journal
2015-10-12 17:45 - 2015-07-10 12:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-12 17:45 - 2015-07-10 12:04 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-12 17:45 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-12 17:45 - 2015-07-10 12:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-12 17:45 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-12 17:45 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-12 17:45 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-12 17:45 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-09 15:12 - 2015-01-06 13:55 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-10-07 18:53 - 2015-07-30 15:44 - 00000000 ____D C:\Program Files (x86)\AMD
2015-10-07 18:53 - 2014-12-15 22:57 - 00000000 ____D C:\AMD
2015-10-07 18:52 - 2015-07-16 01:12 - 00162240 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiuxp64.dll
2015-10-07 18:52 - 2015-07-16 01:11 - 12088008 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atidxx64.dll
2015-10-07 18:52 - 2015-07-16 01:11 - 10211016 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atidxx32.dll
2015-10-07 18:52 - 2015-07-16 01:11 - 08982440 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd6a.dll
2015-10-07 18:52 - 2015-07-16 01:11 - 08864928 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd64.dll
2015-10-07 18:52 - 2015-07-16 01:11 - 01479808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2015-10-07 18:52 - 2015-07-16 01:11 - 01223552 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2015-10-07 18:52 - 2015-07-16 01:11 - 00143056 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiuxpag.dll
2015-10-07 18:52 - 2015-07-16 01:11 - 00130072 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiu9p64.dll
2015-10-07 18:52 - 2015-07-16 01:06 - 21648880 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmdag.sys
2015-10-07 18:52 - 2015-07-16 00:17 - 00683504 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2015-10-07 18:52 - 2015-07-16 00:17 - 00451056 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2015-10-07 18:52 - 2015-07-16 00:17 - 00255472 _____ (AMD) C:\WINDOWS\system32\atiesrxx.exe
2015-10-07 18:52 - 2015-07-16 00:13 - 01256432 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2015-10-07 18:52 - 2015-07-16 00:13 - 00674288 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmpag.sys
2015-10-07 18:52 - 2015-07-16 00:12 - 00874480 _____ (AMD) C:\WINDOWS\system32\coinst_15.20.dll
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2015-04-19 13:20 - 2015-04-19 13:20 - 0005872 _____ () C:\Users\Admin\AppData\Roaming\28Arly8BQ3IUn
2015-04-19 13:20 - 2015-04-19 13:20 - 0005872 _____ () C:\Users\Admin\AppData\Roaming\bSUwmicbiyVJJ5rnrs
2015-09-08 19:37 - 2015-09-08 19:37 - 0003225 _____ () C:\Users\Admin\AppData\Local\recently-used.xbel
Einige Dateien in TEMP:
====================
C:\Users\Admin\AppData\Local\Temp\8548.exe
C:\Users\Admin\AppData\Local\Temp\avgD177.exe
C:\Users\Admin\AppData\Local\Temp\InstallHelper.exe
C:\Users\Admin\AppData\Local\Temp\Opera_NI_stable.exe
C:\Users\Admin\AppData\Local\Temp\sqlite3.dll
C:\Users\Admin\AppData\Local\Temp\Uninstall.exe
C:\Users\Admin\AppData\Local\Temp\UninstallModule.exe
C:\Users\Admin\AppData\Local\Temp\VLX_Player.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-11-02 14:19
==================== Ende von FRST.txt ============================ Addition: Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:05-11-2015
durchgeführt von Admin (2015-11-06 12:51:40)
Gestartet von C:\Users\Admin\Desktop
Windows 10 Pro (X64) (2015-08-05 20:58:30)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Admin (S-1-5-21-3896126499-3315573620-1378135710-1001 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-3896126499-3315573620-1378135710-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3896126499-3315573620-1378135710-503 - Limited - Disabled)
Gast (S-1-5-21-3896126499-3315573620-1378135710-501 - Limited - Disabled)
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
3DMark (HKLM-x32\...\{7330098c-3669-4f39-9e82-4221d489db39}) (Version: 1.4.828.0 - Futuremark)
3DMark (Version: 1.4.828.0 - Futuremark) Hidden
Adobe Reader XI (11.0.13) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
AdVenture Capitalist (HKLM-x32\...\Steam App 346900) (Version: - Hyper Hippo Games)
Akamai NetSession Interface (HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\...\Akamai) (Version: - Akamai Technologies, Inc)
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
AMD Catalyst Install Manager (HKLM\...\{572C982F-95F5-0562-AE8F-8A9D7D024A88}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
APP Shop v1.0.13 (HKLM-x32\...\{90242E9B-BC60-46E3-8EE7-8E953F702280}_is1) (Version: 1.0.13 - ASRock Inc.)
Apple Application Support (32-Bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
ASRock App Charger v1.0.6 (HKLM\...\ASRock App Charger_is1) (Version: 1.0.6 - ASRock Inc.)
ASRock Restart to UEFI v1.0.3 (HKLM-x32\...\ASRock Restart to UEFI_is1) (Version: - )
ASRock XFast RAM v3.0.2 (HKLM\...\ASRock XFast RAM_is1) (Version: - ASRock Inc.)
A-Tuning v2.0.51.1 (HKLM-x32\...\A-Tuning_is1) (Version: 2.0.51.1 - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.11 - Piriform)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
Futuremark SystemInfo (HKLM-x32\...\{2FE4C157-30AD-47F3-9D93-D9A2AFF25D3F}) (Version: 4.33.485.0 - Futuremark)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 46.0.2490.80 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6904.2028 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
iCloud (HKLM\...\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{0EC7F9CC-4741-45AE-9F55-6E9343F726F5}) (Version: 1.1.0.36960 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel(R) Network Connections 18.5.54.0 (HKLM\...\PROSetDX) (Version: 18.5.54.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
iTunes (HKLM\...\{CEC7613B-E286-4A31-BEE3-3F7798488D9F}) (Version: 12.1.3.6 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version: - )
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
MyDriveConnect 4.0.2.2123 (HKLM-x32\...\MyDriveConnect) (Version: 4.0.2.2123 - TomTom)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
ROCCAT Kone Pure Mouse Driver (HKLM-x32\...\{4905245D-56E7-4176-BE68-962728B803D6}) (Version: - Roccat GmbH)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden
Splashtop Software Updater (HKLM-x32\...\Splashtop Software Updater) (Version: 1.5.6.15 - Splashtop Inc.)
Splashtop Streamer (HKLM-x32\...\{B7C5EA94-B96A-41F5-BE95-25D78B486678}) (Version: 2.6.2.4 - Splashtop Inc.)
Spotify (HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\...\Spotify) (Version: 1.0.6.80.g2a801a53 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Update for Skype for Business 2015 (KB2889853) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{CBCC2FD8-7DFE-4752-95B5-2E447C226F45}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3085581) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6BCC80EE-3B68-4110-8D47-23E04FB6D08D}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3085581) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6BCC80EE-3B68-4110-8D47-23E04FB6D08D}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3085581) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{6BCC80EE-3B68-4110-8D47-23E04FB6D08D}) (Version: - Microsoft)
VC_CRT_x64 (Version: 1.02.0000 - Intel Corporation) Hidden
Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WinRAR 5.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
XFast LAN v9.05 (HKLM\...\XFast LAN) (Version: 9.05 - cFos Software GmbH, Bonn)
XFastUSB (HKLM-x32\...\XFastUSB) (Version: 3.02.38 - ASRock Inc.)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-3896126499-3315573620-1378135710-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Admin\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation)
==================== Wiederherstellungspunkte =========================
17-10-2015 13:21:53 Removed iTunes
26-10-2015 19:59:23 Windows Update
02-11-2015 14:19:58 Windows Update
04-11-2015 15:33:50 Wiederherstellungsvorgang
06-11-2015 12:44:13 JRT Pre-Junkware Removal
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {0641E672-CA84-4606-B6D2-9F2BABE58BF5} - System32\Tasks\28Arly8BQ3IUn => C:\Users\Admin\AppData\Roaming\28Arly8BQ3IUn.exe <==== ACHTUNG
Task: {07181339-8E57-4CB5-BBFE-76170783B9DB} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {12FB6D15-B5C0-4B66-BF0C-21D82690E855} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {1780DAB3-4584-4FBD-92C9-8857F3886BA3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {18B3B3A2-AFFF-476E-BA62-AB75BE1E7871} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {314E7782-948E-4C4F-B24E-BC0CC4B34F09} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {35EB728D-F128-4075-B375-D45BF71FE8B2} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\BrowserChoice\browserchoice.exe
Task: {3A4FD38E-5C92-414E-9586-8C3CAA34B95C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {3E9757E4-DB07-4418-A44D-2721FDE15694} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {4D0FE605-48D7-41B3-AD75-AD266C4238D5} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Keine Datei <==== ACHTUNG
Task: {5769C702-F476-4F1D-8161-7F0B757132B2} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {6B883A1A-4B18-410C-B686-CE03876036BA} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {706560C9-EAA0-41D3-833A-15525024E0B5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)
Task: {80A4DADB-BA50-49B2-AA96-134B855D9DA2} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {829CE483-8082-49CD-A513-92A43A02E5FB} - System32\Tasks\{6761BBC9-893A-456B-822C-C0DF98AE0062} => pcalua.exe -a "C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\39.6.2171.95\Installer\setup.exe" -c --uninstall --system-level
Task: {91B7D1C5-C4A2-47A1-8301-8BB576FF708E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {A0AE8DD5-A88B-4716-868D-7DE54D6A193B} - \AutoKMS -> Keine Datei <==== ACHTUNG
Task: {ABDBD144-AC98-4BFB-A605-068E267D2877} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {AF2AD4F7-61F8-4A4D-80A1-EC7534DACF61} - System32\Tasks\bSUwmicbiyVJJ5rnrs => C:\Users\Admin\AppData\Roaming\bSUwmicbiyVJJ5rnrs.exe <==== ACHTUNG
Task: {B5D52175-0BF8-41EC-8DE9-7EA06BDD727D} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {C094DE92-8467-4C1A-BDA4-A77A51B90A69} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {CBA55D8E-91C9-42CD-83D1-CCEA95CCAD58} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {D9512478-B671-48F5-AB7D-4DFDF9C1B3D9} - \AutoPico Daily Restart -> Keine Datei <==== ACHTUNG
Task: {DA46E218-00C4-4B54-B5E0-5243E443B1D5} - \uhy3013 -> Keine Datei <==== ACHTUNG
Task: {ECA37C1B-4E7F-4781-B87B-E8B93639BBCB} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {F2497E2D-9818-4923-A176-F89FB32151E5} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-10-19] (Piriform Ltd)
Task: {F5E604C0-8A2B-485C-9605-9EC1FD317421} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {F69C0FCA-220E-4675-A1E1-DD67E0976A15} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\28Arly8BQ3IUn.job => C:\Users\Admin\AppData\Roaming\28Arly8BQ3IUn.exe <==== ACHTUNG
Task: C:\WINDOWS\Tasks\bSUwmicbiyVJJ5rnrs.job => C:\Users\Admin\AppData\Roaming\bSUwmicbiyVJJ5rnrs.exe <==== ACHTUNG
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2015-07-10 12:00 - 2015-07-10 12:00 - 00028160 _____ () C:\WINDOWS\SYSTEM32\efsext.dll
2015-08-05 22:30 - 2015-08-05 22:30 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-08-23 21:30 - 2015-08-11 10:14 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2015-10-01 09:14 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-01 09:14 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-10-19 21:00 - 2015-10-19 21:00 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2015-10-01 09:14 - 2015-09-17 06:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-10-01 09:14 - 2015-09-17 06:44 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-10-01 09:14 - 2015-09-17 06:42 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-10-01 09:14 - 2015-09-17 06:49 - 00884736 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2015-10-01 09:14 - 2015-09-17 06:42 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-10-01 09:14 - 2015-09-17 06:43 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-03-20 17:12 - 2015-03-20 17:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-03-20 17:12 - 2015-03-20 17:12 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-10-01 09:14 - 2015-09-17 06:43 - 00928768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RulesBackgroundTasks.dll
2014-12-15 23:45 - 2013-09-03 16:52 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Admin\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{8f613224-081d-4870-95b1-d3401a9c063b}.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\...\StartupApproved\Run: => "Akamai NetSession Interface"
HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-3896126499-3315573620-1378135710-1001\...\StartupApproved\Run: => "Spotify Web Helper"
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{AA2759FA-EDA9-49D9-8F1E-31DBB008545D}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{21668B50-B857-45A9-B645-E11ECDD0BA49}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{6CB59014-5555-42F1-8B13-C849BCCFE2D5}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{A3131C8E-696E-4F51-ACFD-B2AB59280978}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{FEE6B3AF-FAFD-4C1B-B25C-3D7B4B195124}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{B443DA33-A6A7-4033-956B-A93AC3CBC433}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E6CBFDB1-E319-4DB8-AFE5-A4934C2C92BB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6A8E79CC-2575-4BAE-8F1C-D7A7E2F46E1E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{8E7D9FDF-1879-4244-A2C6-EBC14CC669E7}] => (Allow) %USERPROFILE%\jagexcache\jagexlauncher\bin\JagexLauncher.exe
FirewallRules: [{35A1C72A-BDD3-483A-89A4-27F37D6F2DF0}] => (Allow) %USERPROFILE%\jagexcache\jagexlauncher\bin\JagexLauncher.exe
FirewallRules: [{B6240254-8695-4136-8688-496A32476A12}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{E7AD38FE-F37D-44CA-9649-1701BCC99048}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{B0CB35E9-5E30-4F33-B965-F50096A6FF89}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{D97329F3-5344-4F9A-ABBF-5E569CF1D363}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{CAEEFC92-F0A2-4DE5-A2E7-FFCAFF3B70D4}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{DA773FEA-CDF4-4FFB-818E-B255D4ABA4EF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{22A49953-B3ED-4BC6-8832-A1E30DE6E35D}] => (Block) C:\users\admin\appdata\roaming\spotify\spotify.exe
FirewallRules: [{C130419E-ACEF-4A16-B5CD-F7064DA07399}] => (Block) C:\users\admin\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{8F3963CA-4443-496D-B9E4-2A16E020A73E}C:\users\admin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\admin\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{C9892719-B171-4AE8-B087-57F263271C60}C:\users\admin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\admin\appdata\roaming\spotify\spotify.exe
FirewallRules: [{52E0F1D2-FD56-4E24-A22C-DE206D1494F7}] => (Allow) C:\Windows\AutoKMS\AutoKMS.exe
FirewallRules: [{7039608C-3BAF-4175-B1D5-9DB53104CE60}] => (Allow) C:\Windows\AutoKMS\AutoKMS.exe
FirewallRules: [{A6677B6E-9570-4D98-87FE-84B9780B452C}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{CD221F27-BA09-4A4E-BC94-50541EBCB868}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{85BC76F4-96B4-4164-A507-B85036C799E4}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{05E12DE1-3BF9-4600-BD77-0809E7D8C280}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [UDP Query User{6B3064D8-144A-4C73-834F-582573F693E1}C:\users\admin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\admin\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{4F97824E-B35A-4B0C-97A6-D3BAFD6E693B}C:\users\admin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\admin\appdata\local\akamai\netsession_win.exe
FirewallRules: [{ACFE8A12-C5A4-41FC-90A6-7D110C49FAEE}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{55CAAA0F-FBB7-462F-8A31-FCCBE685917A}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{046FF7F9-A214-4106-ADBB-6B8AD4D530E1}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{B26C67AD-595F-4798-8BA9-48A408D1A66A}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{0812631C-DFED-4D26-BAD8-38EC0D43A5F9}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{DD625CA9-74CC-4EF5-8787-672253D8102B}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{92F406C8-75D5-4ABC-B10E-2BCB8528AAD5}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{2E1B87E5-B37C-4C66-97F9-A7331EB138D4}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{20E5CF9D-CD2B-48EC-8529-99B170102939}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AdVenture Capitalist\adventure-capitalist.exe
FirewallRules: [{C1EF0CA2-2081-43FE-8B04-16DE223F8C15}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AdVenture Capitalist\adventure-capitalist.exe
FirewallRules: [{C20F43D5-69D4-45A1-AD1B-C744E89D4511}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7E097365-0904-432E-929B-8F1CD4D41E51}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1E925C46-62CE-4FA6-82B0-ABDF754998C5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{F8DCB71C-268A-4DB2-8339-FDB932450A7D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{DD491145-F36D-48BC-A4CF-458D412FE1DE}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{9E2BD5A0-E113-4596-8766-27355FE2915D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{E745B22D-7912-4168-B501-8A08C1F3C580}] => (Allow) C:\Program Files (x86)\Max Driver Updater\maxdu.exe
FirewallRules: [{93C38DE8-53A2-4A89-9205-B0807ACAA3F2}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
FirewallRules: [{279EF737-27B1-40C7-99AC-8EAD354171BD}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
FirewallRules: [{7886F932-3D5E-474B-9059-A0E18BD488B9}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\DataProxy.exe
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (11/06/2015 12:45:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: MicrosoftEdge.exe, Version: 11.0.10240.16566, Zeitstempel: 0x56277dbe
Name des fehlerhaften Moduls: CoreUIComponents.dll, Version: 0.0.0.0, Zeitstempel: 0x55fa4b76
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000060f73
ID des fehlerhaften Prozesses: 0x7e8
Startzeit der fehlerhaften Anwendung: 0xMicrosoftEdge.exe0
Pfad der fehlerhaften Anwendung: MicrosoftEdge.exe1
Pfad des fehlerhaften Moduls: MicrosoftEdge.exe2
Berichtskennung: MicrosoftEdge.exe3
Vollständiger Name des fehlerhaften Pakets: MicrosoftEdge.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge.exe5
Error: (11/06/2015 12:44:23 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll.
System Error:
Zugriff verweigert
.
Error: (11/05/2015 08:20:37 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (11/05/2015 01:57:18 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147024865. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (11/05/2015 01:57:18 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2147024865. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (11/05/2015 01:57:18 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC)
Description: Bei der Aktivierung der App „Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (11/04/2015 05:09:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: MicrosoftEdge.exe, Version: 11.0.10240.16566, Zeitstempel: 0x56277dbe
Name des fehlerhaften Moduls: CoreUIComponents.dll, Version: 0.0.0.0, Zeitstempel: 0x55fa4b76
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000060f73
ID des fehlerhaften Prozesses: 0x1f70
Startzeit der fehlerhaften Anwendung: 0xMicrosoftEdge.exe0
Pfad der fehlerhaften Anwendung: MicrosoftEdge.exe1
Pfad des fehlerhaften Moduls: MicrosoftEdge.exe2
Berichtskennung: MicrosoftEdge.exe3
Vollständiger Name des fehlerhaften Pakets: MicrosoftEdge.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MicrosoftEdge.exe5
Error: (11/04/2015 04:53:58 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: Unbekannter Fehler bei der Systemwiederherstellung: (Windows Update). Zusätzliche Informationen: 0x80070571.
Error: (11/04/2015 04:23:32 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC)
Description: Bei der Aktivierung der App „Microsoft.MicrosoftEdge_20.10240.16384.0_neutral__8wekyb3d8bbwe:MicrosoftEdge.AppX9zvsr9qeth9e9a03yr0g7rpdrcrwgn5r.mca“ ist folgender Fehler aufgetreten: -2144927149. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (11/04/2015 04:14:43 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC)
Description: Bei der Aktivierung der App „Microsoft.MicrosoftEdge_20.10240.16384.0_neutral__8wekyb3d8bbwe:MicrosoftEdge.AppX9zvsr9qeth9e9a03yr0g7rpdrcrwgn5r.mca“ ist folgender Fehler aufgetreten: -2144927149. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Systemfehler:
=============
Error: (11/06/2015 12:45:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Dynamic Application Loader Host Interface Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (11/06/2015 12:45:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) ME Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (11/06/2015 12:45:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "iPod-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (11/06/2015 12:45:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "cFosSpeed System Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (11/06/2015 12:45:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Intel(R) Capability Licensing Service Interface" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (11/06/2015 12:45:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Dienst "Bonjour"" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (11/06/2015 12:45:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Service KMSELDI" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (11/06/2015 12:44:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "MBAMService" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (11/06/2015 12:44:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "MBAMScheduler" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (11/06/2015 12:44:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) PROSet Monitoring Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
CodeIntegrity:
===================================
Date: 2015-11-06 12:29:17.082
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-11-05 12:39:36.174
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-10-26 20:03:56.406
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-09-28 17:52:15.924
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-09-24 22:29:45.054
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-09-15 19:40:31.474
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-08-29 12:12:37.860
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-08-05 23:10:52.350
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Speicherinformationen ===========================
Prozessor: Intel(R) Pentium(R) CPU G3420 @ 3.20GHz
Prozentuale Nutzung des RAM: 23%
Installierter physikalischer RAM: 8111.13 MB
Verfügbarer physikalischer RAM: 6176.89 MB
Summe virtueller Speicher: 9391.13 MB
Verfügbarer virtueller Speicher: 7412.32 MB
==================== Laufwerke ================================
Drive c: () (Fixed) (Total:243.36 GB) (Free:163.71 GB) NTFS
Drive d: (Volume) (Fixed) (Total:687.37 GB) (Free:687.19 GB) NTFS
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: C390FBE7)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=243.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=687.4 GB) - (Type=07 NTFS)
==================== Ende von Addition.txt ============================ |