StefanBee | 29.12.2015 22:23 | AttentionUninstallerLog: Code:
29.12.2015 22:21:35: Deinstallation gestartet...
29.12.2015 22:21:35: DNSBlock ist nicht installiert.
29.12.2015 22:21:35: Beliebige Taste zum Beenden drücken... AHHHHHHH! Habe danach mit MBAM weitergemacht wie beschrieben, Neustart - OK, jetzt fährt der Rechner nicht mehr hoch, ich komme nicht mal mehr zum Bios.
gelöst, die usb festplatte war der fehler.
Hier das LogProtokoll von mbam: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 29.12.2015
Suchlaufzeit: 22:35
Protokolldatei: MbamLog.txt
Administrator: Ja
Version: 2.2.0.1024
Malware-Datenbank: v2015.12.29.06
Rootkit-Datenbank: v2015.12.26.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: StefanMaster
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 334673
Abgelaufene Zeit: 5 Min., 16 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.DNSBlock.BrwsrFlsh, C:\Windows\System32\DnsBlockUpdateSvc.exe, 1604, Löschen bei Neustart, [9d3df0bae7a4f046fcb1eca35aa9738d]
PUP.Optional.DNSBlock.BrwsrFlsh, C:\Program Files (x86)\DnsBlock\DnsBlockTray.exe, 4408, Löschen bei Neustart, [45958327f69551e5b5dce1a724de07f9]
Module: 22
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [bd1d8d1db6d5c5714d2453a58083b947],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [bd1d8d1db6d5c5714d2453a58083b947],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [bd1d8d1db6d5c5714d2453a58083b947],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [bd1d8d1db6d5c5714d2453a58083b947],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [bd1d8d1db6d5c5714d2453a58083b947],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [bd1d8d1db6d5c5714d2453a58083b947],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [bd1d8d1db6d5c5714d2453a58083b947],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [bd1d8d1db6d5c5714d2453a58083b947],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [bd1d8d1db6d5c5714d2453a58083b947],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [bd1d8d1db6d5c5714d2453a58083b947],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [bd1d8d1db6d5c5714d2453a58083b947],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [30aa2e7c88031f17fc76b24656ada25e],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [30aa2e7c88031f17fc76b24656ada25e],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [30aa2e7c88031f17fc76b24656ada25e],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [30aa2e7c88031f17fc76b24656ada25e],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [30aa2e7c88031f17fc76b24656ada25e],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [30aa2e7c88031f17fc76b24656ada25e],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [30aa2e7c88031f17fc76b24656ada25e],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [30aa2e7c88031f17fc76b24656ada25e],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [30aa2e7c88031f17fc76b24656ada25e],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [30aa2e7c88031f17fc76b24656ada25e],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [30aa2e7c88031f17fc76b24656ada25e],
Registrierungsschlüssel: 24
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\TYPELIB\{E7BF74EE-9106-4113-B216-2F980BA29141}, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\INTERFACE\{F2DB3739-77FB-41EB-9ED3-ABF34DF2DBF7}, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F2DB3739-77FB-41EB-9ED3-ABF34DF2DBF7}, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F2DB3739-77FB-41EB-9ED3-ABF34DF2DBF7}, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E7BF74EE-9106-4113-B216-2F980BA29141}, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{E7BF74EE-9106-4113-B216-2F980BA29141}, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\DPBHO.DownloadProtect.1, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\DPBHO.DownloadProtect, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DPBHO.DownloadProtect, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\WOW6432NODE\DPBHO.DownloadProtect, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DPBHO.DownloadProtect.1, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\WOW6432NODE\DPBHO.DownloadProtect.1, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}\INPROCSERVER32, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DNSBlock.BrwsrFlsh, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7b5da7f5-de7d-4e00-b330-a2e08e460095}, In Quarantäne, [dcfeb8f24249fc3a157ecc5fe31ec838],
PUP.Optional.DNSBlock.BrwsrFlsh, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DnsBlockUpdateSvc, In Quarantäne, [9d3df0bae7a4f046fcb1eca35aa9738d],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\APPID\DPBHO.DLL, In Quarantäne, [eeecb0fad9b263d3991bf32110f47b85],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\DPBHO.DLL, In Quarantäne, [fae06d3d6724e056e7cdaf65a95ba25e],
PUP.Optional.DownloadProtect, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\DPBHO.DLL, In Quarantäne, [2fab5c4ee1aa7fb7faba49cbf3118c74],
PUP.Optional.ProductSetup, HKU\S-1-5-21-3629519260-1712515466-884136675-1000\SOFTWARE\PRODUCTSETUP, In Quarantäne, [c614e1c9612af5413c7dd8e532d127d9],
Registrierungswerte: 3
PUP.Optional.DownloadProtectExtension, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{A4C578AF-D382-4300-B2D9-47622168EAB2}, C:\Windows\Installer\{BA3BCA6D-F399-40BB-BCAF-85DE0FBC53A4}\{A4C578AF-D382-4300-B2D9-47622168EAB2}.xpi, In Quarantäne, [31a94c5e4d3ecd694bb0dbc7df24cd33]
PUP.Optional.ProductSetup, HKU\S-1-5-21-3629519260-1712515466-884136675-1000\SOFTWARE\PRODUCTSETUP|tb, 0B1H1G2O0K2Z1K1R1L, In Quarantäne, [c614e1c9612af5413c7dd8e532d127d9]
PUP.Optional.DNSBlock.BrwsrFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|DnsBlock, C:\Program Files (x86)\DnsBlock\DnsBlockTray.exe, In Quarantäne, [45958327f69551e5b5dce1a724de07f9]
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 9
PUP.Optional.DownloadProtect, C:\Windows\Installer\{3343F16E-894B-43DB-B125-0BA0D6386268}, In Quarantäne, [e8f23e6cacdf87afecfb346eaa591fe1],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{91953761-C1B7-45E3-B8BC-A0771281948A}, In Quarantäne, [5b7fa4069fec023493545a486b98ff01],
PUP.Optional.DownloadProtect.ChrPRST, C:\Windows\Installer\{BA3BCA6D-F399-40BB-BCAF-85DE0FBC53A4}, In Quarantäne, [cf0b1793e4a70a2cfa887e9ac73d0df3],
PUP.Optional.DNSBlock.BrwsrFlsh, C:\Users\StefanMaster\AppData\Local\DnsBlock, In Quarantäne, [dcfe9c0e3457ac8af7992d5ba55d7c84],
PUP.Optional.DNSBlock.BrwsrFlsh, C:\Program Files (x86)\DnsBlock, Löschen bei Neustart, [45958327f69551e5b5dce1a724de07f9],
PUP.Optional.DownloadProtect, C:\Program Files (x86)\{4DDBE744-AD11-4503-B6B1-FF93E387C603}, In Quarantäne, [02d800aaa3e860d625bcf5ce57ad926e],
PUP.Optional.DownloadProtect, C:\Program Files (x86)\{C2055949-FF93-4FD9-9A6B-A437F176CE32}, In Quarantäne, [3c9ef7b3692249edf4ed8c37e222fd03],
PUP.Optional.DownloadProtect, C:\Program Files\{4CBFAE47-062E-4801-AF5A-7C126DA73E3C}, In Quarantäne, [f2e83c6e0f7c46f08859e9dabc48a15f],
PUP.Optional.DownloadProtect, C:\Program Files\{D820A730-249A-4247-BDD0-2C0159FB02C2}, In Quarantäne, [f5e505a5721941f5ac357b4804007c84],
Dateien: 26
PUP.Optional.DownloadProtect, C:\Program Files\{D820A730-249A-4247-BDD0-2C0159FB02C2}\{B1F73882-D123-4BE3-9586-D717F4976994}.bin, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DownloadProtect, C:\Program Files (x86)\{C2055949-FF93-4FD9-9A6B-A437F176CE32}\{C72FB27D-6BAA-4355-8DDF-423C8895FDAC}.bin, In Quarantäne, [eded6c3e63282511812fb97358a8e41c],
PUP.Optional.DNSBlock.BrwsrFlsh, C:\Program Files (x86)\DnsBlock\uninst.exe, In Quarantäne, [dcfeb8f24249fc3a157ecc5fe31ec838],
PUP.Optional.DownloadProtect, C:\Program Files (x86)\{4DDBE744-AD11-4503-B6B1-FF93E387C603}\{21CC02C4-9EAC-4C05-ACB3-33E2503EA1DC}.bin, In Quarantäne, [9d3df6b4f893092d951b989432ce48b8],
PUP.Optional.DNSBlock.BrwsrFlsh, C:\Users\StefanMaster\AppData\Local\Temp\setup.exe, In Quarantäne, [1ac0a2081d6e51e592010d1eae53bf41],
PUP.Optional.DNSBlock.BrwsrFlsh, C:\Windows\System32\DnsBlockUpdateSvc.exe, Löschen bei Neustart, [9d3df0bae7a4f046fcb1eca35aa9738d],
PUP.Optional.DNSBlocker.BrwsrFlsh, C:\Windows\System32\dns.block, Löschen bei Neustart, [8e4cacfe0487d75fb4fde9a6ea19c43c],
PUP.Optional.DNSBlocker.BrwsrFlsh, C:\Windows\SysWOW64\dns.block, In Quarantäne, [d802dbcfeaa150e6832e335c5ba8c739],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{3343F16E-894B-43DB-B125-0BA0D6386268}\chlohneijdbkadbhlefhabfdljmbdgokgrx, In Quarantäne, [e8f23e6cacdf87afecfb346eaa591fe1],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{3343F16E-894B-43DB-B125-0BA0D6386268}\xhlohneijdbkadbhlefhabfdljmbdgokgml, In Quarantäne, [e8f23e6cacdf87afecfb346eaa591fe1],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{91953761-C1B7-45E3-B8BC-A0771281948A}\cioncpikonbeicnohmocnedpbpaifmpnirx, In Quarantäne, [5b7fa4069fec023493545a486b98ff01],
PUP.Optional.DownloadProtect, C:\Windows\Installer\{91953761-C1B7-45E3-B8BC-A0771281948A}\xioncpikonbeicnohmocnedpbpaifmpniml, In Quarantäne, [5b7fa4069fec023493545a486b98ff01],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockA.dll, Löschen bei Neustart, [bd1d8d1db6d5c5714d2453a58083b947],
PUP.Optional.Winsock.WnskRST, C:\Windows\SysWOW64\DnsBlockA.dll, Löschen bei Neustart, [7d5d03a7c1cac175323f6a8e946f4ab6],
PUP.Optional.Winsock.WnskRST, C:\Windows\System32\DnsBlockB.dll, Löschen bei Neustart, [30aa2e7c88031f17fc76b24656ada25e],
PUP.Optional.Winsock.WnskRST, C:\Windows\SysWOW64\DnsBlockB.dll, Löschen bei Neustart, [d901b4f6a7e42016a7cbbc3c3fc41ae6],
PUP.Optional.DownloadProtect.ChrPRST, C:\Windows\Installer\{BA3BCA6D-F399-40BB-BCAF-85DE0FBC53A4}\{A4C578AF-D382-4300-B2D9-47622168EAB2}.xpi, In Quarantäne, [cf0b1793e4a70a2cfa887e9ac73d0df3],
PUP.Optional.DNSBlock.BrwsrFlsh, C:\Program Files (x86)\DnsBlock\DnsBlockTray.exe, Löschen bei Neustart, [45958327f69551e5b5dce1a724de07f9],
PUP.Optional.DownloadProtect, C:\Program Files (x86)\{4DDBE744-AD11-4503-B6B1-FF93E387C603}\config.json, In Quarantäne, [02d800aaa3e860d625bcf5ce57ad926e],
PUP.Optional.DownloadProtect, C:\Program Files (x86)\{4DDBE744-AD11-4503-B6B1-FF93E387C603}\def.bin, In Quarantäne, [02d800aaa3e860d625bcf5ce57ad926e],
PUP.Optional.DownloadProtect, C:\Program Files (x86)\{C2055949-FF93-4FD9-9A6B-A437F176CE32}\config.json, In Quarantäne, [3c9ef7b3692249edf4ed8c37e222fd03],
PUP.Optional.DownloadProtect, C:\Program Files (x86)\{C2055949-FF93-4FD9-9A6B-A437F176CE32}\def.bin, In Quarantäne, [3c9ef7b3692249edf4ed8c37e222fd03],
PUP.Optional.DownloadProtect, C:\Program Files\{4CBFAE47-062E-4801-AF5A-7C126DA73E3C}\config.json, In Quarantäne, [f2e83c6e0f7c46f08859e9dabc48a15f],
PUP.Optional.DownloadProtect, C:\Program Files\{4CBFAE47-062E-4801-AF5A-7C126DA73E3C}\def.bin, In Quarantäne, [f2e83c6e0f7c46f08859e9dabc48a15f],
PUP.Optional.DownloadProtect, C:\Program Files\{D820A730-249A-4247-BDD0-2C0159FB02C2}\config.json, In Quarantäne, [f5e505a5721941f5ac357b4804007c84],
PUP.Optional.DownloadProtect, C:\Program Files\{D820A730-249A-4247-BDD0-2C0159FB02C2}\def.bin, In Quarantäne, [f5e505a5721941f5ac357b4804007c84],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Und das ADWCleaner-Log: Code:
# AdwCleaner v5.026 - Bericht erstellt am 29/12/2015 um 23:06:47
# Aktualisiert am 21/12/2015 von Xplode
# Datenbank : 2015-12-29.1 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : StefanMaster - STEFANMASTER-PC
# Gestartet von : C:\Users\StefanMaster\Desktop\AdwCleaner_5.026.exe
# Option : Löschen
# Unterstützung : hxxp://toolslib.net/forum
***** [ Dienste ] *****
***** [ Ordner ] *****
[-] Ordner Gelöscht : C:\ProgramData\simplitec
[-] Ordner Gelöscht : C:\Users\StefanMaster\AppData\Roaming\dvdvideosoftiehelpers
***** [ Dateien ] *****
[-] Datei Gelöscht : C:\Users\StefanMaster\AppData\Roaming\Mozilla\Firefox\Profiles\6uoy3t60.default\user.js
***** [ DLLs ] *****
***** [ Verknüpfungen ] *****
***** [ Aufgabenplanung ] *****
***** [ Registrierungsdatenbank ] *****
[-] Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{b64d9b05-48e1-4ceb-bf58-e0643994e900}]
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1C6F51F8-BCE6-4702-8952-6A8233359FBC}
[-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}]
[-] Schlüssel Gelöscht : HKCU\Software\OCS
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\simplitec
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\World of Warcraft Beta
***** [ Internetbrowser ] *****
*************************
:: "Tracing" Schlüssel gelöscht
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
:: Chrome Richtlinien gelöscht
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1618 Bytes] ########## ======
Und hier abschließend das neue Frst64-Log: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:29-12-2015
durchgeführt von StefanMaster (Administrator) auf STEFANMASTER-PC (29-12-2015 23:11:49)
Gestartet von C:\Users\StefanMaster\Desktop
Geladene Profile: StefanMaster (Verfügbare Profile: StefanMaster)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Steganos Software GmbH) C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\MSITrigger\VGA Boost\VGA Boost.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
() C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(NVIDIA Corporation) C:\Users\StefanMaster\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7191768 2013-06-27] (Realtek Semiconductor)
HKLM\...\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2771576 2015-12-09] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [11877656 2014-09-16] (Logitech Inc.)
HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2012-11-29] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [506864 2013-03-08] (MSI)
HKU\S-1-5-21-3629519260-1712515466-884136675-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8551848 2015-10-19] (Piriform Ltd)
HKU\S-1-5-21-3629519260-1712515466-884136675-1000\...\MountPoints2: {63030a41-8192-11e5-9950-806e6f6e6963} - D:\
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\iSCTsysTray.lnk [2014-03-15]
ShortcutTarget: iSCTsysTray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2014-06-02]
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{7411487A-FF21-481E-AB53-BF27FF30E042}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{50E340AE-DD64-4698-A93D-A28A569B831C}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
BHO: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\x64\IEExt\ie_plugin.dll [2014-11-20] (Kaspersky Lab ZAO)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-12-12] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-12-12] (Microsoft Corporation)
BHO: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\x64\IEExt\ie_plugin.dll [2014-11-20] (Kaspersky Lab ZAO)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-12-12] (Microsoft Corporation)
BHO: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\x64\IEExt\ie_plugin.dll [2014-11-20] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll [2014-11-20] (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-12-12] (Microsoft Corporation)
BHO-x32: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll [2014-11-20] (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll [2014-11-20] (Kaspersky Lab ZAO)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\StefanMaster\AppData\Roaming\Mozilla\Firefox\Profiles\6uoy3t60.default
FF Homepage: hxxps://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2015-12-29] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-29] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-05-17] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-05-17] (Intel Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker_6418E0D362104DADA084DC312DFA8ABC -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com [2014-11-20] ()
FF Plugin-x32: @kaspersky.com/online_banking_69A4E213815F42BD863D889007201D82 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com [2014-11-20] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com [2014-11-20] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-04-12] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-12-16] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-12-16] (NVIDIA Corporation)
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com [2014-11-20] [ist nicht signiert]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com [2014-11-20] [ist nicht signiert]
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com [2014-11-20] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker_6418E0D362104DADA084DC312DFA8ABC@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [online_banking_69A4E213815F42BD863D889007201D82@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Profile: C:\Users\StefanMaster\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\StefanMaster\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-01]
CHR Extension: (Google Docs) - C:\Users\StefanMaster\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-01]
CHR Extension: (Google Drive) - C:\Users\StefanMaster\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-01]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\StefanMaster\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-01]
CHR Extension: (YouTube) - C:\Users\StefanMaster\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-01]
CHR Extension: (Google-Suche) - C:\Users\StefanMaster\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-01]
CHR Extension: (Kaspersky Protection) - C:\Users\StefanMaster\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-01-01]
CHR Extension: (Google Tabellen) - C:\Users\StefanMaster\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-01]
CHR Extension: (Google Wallet) - C:\Users\StefanMaster\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-01]
CHR Extension: (Google Mail) - C:\Users\StefanMaster\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-01]
CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AVP15.0.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe [234520 2014-08-30] (Kaspersky Lab ZAO)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2802360 2015-11-24] (Microsoft Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156216 2015-12-09] (NVIDIA Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [180200 2013-02-13] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-17] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161264 2013-02-20] (MSI)
R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [29728 2013-05-28] (MICRO-STAR INTERNATIONAL CO., LTD.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-12-09] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8185464 2015-12-09] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [6477432 2015-12-09] (NVIDIA Corporation)
R2 OkayFreedom VPN Starter Service; C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe [330168 2015-04-14] (Steganos Software GmbH)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2015-10-17] ()
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [344576 2013-12-09] (Qualcomm Atheros) [Datei ist nicht signiert]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49048 2012-07-18] (Asmedia Technology)
R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [80080 2013-11-08] (Qualcomm Atheros, Inc.)
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [238288 2013-01-14] (Kaspersky Lab UK Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21048 2013-02-13] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21048 2013-02-13] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-02-13] ()
R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [468576 2014-03-31] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [46144 2014-07-02] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [150536 2014-11-20] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [246456 2014-08-12] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [819896 2015-03-12] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [30304 2014-02-25] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [28768 2014-03-28] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-08-08] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55872 2014-06-05] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [77512 2014-11-20] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [179776 2014-07-09] (Kaspersky Lab ZAO)
R3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.)
S3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [41752 2013-05-30] (Logitech Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-12-09] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
R3 VBAudioVACMME; C:\Windows\System32\DRIVERS\vbaudio_cable64_win7.sys [41192 2015-09-28] (Windows (R) Win 7 DDK provider)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2015-12-29] ()
S3 ALSysIO; \??\C:\Users\STEFAN~1\AppData\Local\Temp\ALSysIO64.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-12-29 23:11 - 2015-12-29 23:11 - 00020019 _____ C:\Users\StefanMaster\Desktop\FRST.txt
2015-12-29 23:11 - 2015-12-29 21:31 - 02370560 _____ (Farbar) C:\Users\StefanMaster\Desktop\FRST64.exe
2015-12-29 23:05 - 2015-12-29 23:06 - 00000000 ____D C:\AdwCleaner
2015-12-29 23:02 - 2015-12-29 23:02 - 01743360 _____ C:\Users\StefanMaster\Desktop\AdwCleaner_5.026.exe
2015-12-29 23:00 - 2015-12-29 23:00 - 00013688 _____ C:\Users\StefanMaster\Desktop\MbamLog.txt
2015-12-29 22:34 - 2015-12-29 22:58 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-12-29 22:34 - 2015-12-29 22:34 - 00001102 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-29 22:34 - 2015-12-29 22:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-12-29 22:34 - 2015-12-29 22:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-29 22:34 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-12-29 22:34 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-12-29 22:34 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-12-29 22:21 - 2015-12-29 22:24 - 00000166 _____ C:\Users\StefanMaster\Desktop\AttentionUninstallerLog.txt
2015-12-29 22:20 - 2015-12-29 22:20 - 00000088 _____ C:\Users\StefanMaster\Desktop\UnList.txt
2015-12-29 22:18 - 2015-12-29 22:18 - 03443652 _____ (Igor Pavlov) C:\Users\StefanMaster\Desktop\AttentionUninstaller64.exe
2015-12-29 22:11 - 2015-12-29 22:11 - 00001264 _____ C:\Users\StefanMaster\Desktop\Revo Uninstaller.lnk
2015-12-29 22:11 - 2015-12-29 22:11 - 00000000 ____D C:\Users\StefanMaster\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2015-12-29 22:11 - 2015-12-29 22:11 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-12-29 22:08 - 2015-12-29 22:08 - 04727984 _____ (Kaspersky Lab ZAO) C:\Users\StefanMaster\Desktop\tdsskiller.exe
2015-12-29 22:08 - 2015-12-29 22:07 - 16563352 _____ (Malwarebytes Corp.) C:\Users\StefanMaster\Desktop\mbar-1.09.3.1001.exe
2015-12-29 21:32 - 2015-12-29 23:11 - 00000000 ____D C:\FRST
2015-12-29 20:39 - 2015-12-29 20:39 - 00262144 _____ C:\Windows\system32\config\elam
2015-12-29 19:24 - 2015-12-29 23:07 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2015-12-29 19:22 - 2015-12-29 23:06 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-12-28 22:56 - 2015-12-28 22:56 - 00077084 _____ C:\Users\StefanMaster\AppData\Local\recently-used.xbel
2015-12-23 12:36 - 2015-12-24 08:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-12-21 21:48 - 2015-12-16 15:53 - 00523384 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2015-12-21 21:48 - 2015-12-16 15:53 - 00075056 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2015-12-21 21:48 - 2015-12-16 15:39 - 00103032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-12-21 21:47 - 2015-12-16 18:34 - 42977072 _____ C:\Windows\system32\nvcompiler.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 37609080 _____ C:\Windows\SysWOW64\nvcompiler.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 31061624 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 24895792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 21122456 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 20663816 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 17561432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 17156968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 16981976 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 12334200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-12-21 21:47 - 2015-12-16 18:34 - 03168376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 02755704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 01915696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436143.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 01564976 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436143.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00938104 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00872056 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00734512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00681592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00502080 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00469144 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00423264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00416376 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00388560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00370808 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00175368 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00153392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00151184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-12-21 21:47 - 2015-12-16 18:34 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-12-19 09:03 - 2015-12-19 09:03 - 00000000 _____ C:\Users\StefanMaster\Desktop\Neues Textdokument (2).txt
2015-12-18 15:03 - 2015-12-18 15:03 - 00075483 _____ C:\Users\StefanMaster\Documents\Buchstaben.xcf
2015-12-09 18:38 - 2015-11-20 19:54 - 03170304 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-12-09 18:38 - 2015-11-20 19:54 - 02609152 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-12-09 18:38 - 2015-11-20 19:54 - 00709632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-12-09 18:38 - 2015-11-20 19:54 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-12-09 18:38 - 2015-11-20 19:54 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-12-09 18:38 - 2015-11-20 19:54 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-12-09 18:38 - 2015-11-20 19:54 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-12-09 18:38 - 2015-11-20 19:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-12-09 18:38 - 2015-11-20 19:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-12-09 18:38 - 2015-11-20 19:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-12-09 18:38 - 2015-11-20 19:54 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-12-09 18:38 - 2015-11-20 19:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-12-09 18:38 - 2015-11-20 19:34 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-12-09 18:38 - 2015-11-20 19:34 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-12-09 18:38 - 2015-11-20 19:34 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-12-09 18:38 - 2015-11-20 19:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-12-09 18:38 - 2015-11-11 22:12 - 00387792 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-12-09 18:38 - 2015-11-11 21:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-12-09 18:38 - 2015-11-11 19:53 - 01735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2015-12-09 18:38 - 2015-11-11 19:53 - 00525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2015-12-09 18:38 - 2015-11-11 19:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2015-12-09 18:38 - 2015-11-11 19:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
2015-12-09 18:38 - 2015-11-11 17:21 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-12-09 18:38 - 2015-11-11 17:00 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-12-09 18:38 - 2015-11-11 16:44 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-12-09 18:38 - 2015-11-11 16:44 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-12-09 18:38 - 2015-11-11 16:41 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-12-09 18:38 - 2015-11-11 16:12 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-12-09 18:38 - 2015-11-11 15:57 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-12-09 18:38 - 2015-11-10 19:55 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-12-09 18:38 - 2015-11-10 19:55 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-12-09 18:38 - 2015-11-10 19:55 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2015-12-09 18:38 - 2015-11-10 19:39 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-12-09 18:38 - 2015-11-10 19:37 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2015-12-09 18:38 - 2015-11-10 18:47 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-12-09 18:38 - 2015-11-10 01:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-12-09 18:38 - 2015-11-10 01:13 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-12-09 18:38 - 2015-11-10 01:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-12-09 18:38 - 2015-11-10 01:12 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-12-09 18:38 - 2015-11-10 01:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-12-09 18:38 - 2015-11-10 01:11 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-12-09 18:38 - 2015-11-10 01:08 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-12-09 18:38 - 2015-11-10 01:06 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-12-09 18:38 - 2015-11-10 01:06 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-12-09 18:38 - 2015-11-10 01:04 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-12-09 18:38 - 2015-11-10 01:03 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-12-09 18:38 - 2015-11-10 01:02 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-12-09 18:38 - 2015-11-10 01:02 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-12-09 18:38 - 2015-11-10 00:50 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-12-09 18:38 - 2015-11-10 00:47 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-12-09 18:38 - 2015-11-10 00:46 - 04514816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-12-09 18:38 - 2015-11-10 00:44 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-12-09 18:38 - 2015-11-10 00:37 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-12-09 18:38 - 2015-11-10 00:36 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-12-09 18:38 - 2015-11-10 00:36 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-12-09 18:38 - 2015-11-10 00:35 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-12-09 18:38 - 2015-11-10 00:17 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-12-09 18:38 - 2015-11-10 00:14 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-12-09 18:38 - 2015-11-10 00:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-12-09 18:38 - 2015-11-08 23:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-12-09 18:38 - 2015-11-08 23:32 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-12-09 18:38 - 2015-11-08 23:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-12-09 18:38 - 2015-11-08 23:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-12-09 18:38 - 2015-11-08 23:15 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-12-09 18:38 - 2015-11-08 23:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-12-09 18:38 - 2015-11-08 23:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-12-09 18:38 - 2015-11-08 23:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-12-09 18:38 - 2015-11-08 23:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-12-09 18:38 - 2015-11-08 23:06 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-12-09 18:38 - 2015-11-08 23:04 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-12-09 18:38 - 2015-11-08 23:02 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-12-09 18:38 - 2015-11-08 23:01 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-12-09 18:38 - 2015-11-08 23:01 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-12-09 18:38 - 2015-11-08 23:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-12-09 18:38 - 2015-11-08 23:01 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-12-09 18:38 - 2015-11-08 22:52 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-12-09 18:38 - 2015-11-08 22:48 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-12-09 18:38 - 2015-11-08 22:40 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-12-09 18:38 - 2015-11-08 22:35 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-12-09 18:38 - 2015-11-08 22:32 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-12-09 18:38 - 2015-11-08 22:29 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-12-09 18:38 - 2015-11-08 22:18 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-12-09 18:38 - 2015-11-08 22:15 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-12-09 18:38 - 2015-11-08 22:15 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-12-09 18:38 - 2015-11-08 22:14 - 14456832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-12-09 18:38 - 2015-11-08 22:14 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-12-09 18:38 - 2015-11-08 22:13 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-12-09 18:38 - 2015-11-08 21:53 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-12-09 18:38 - 2015-11-08 21:41 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-12-09 18:38 - 2015-11-08 21:30 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-12-09 18:38 - 2015-11-05 20:05 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll
2015-12-09 18:38 - 2015-11-05 20:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll
2015-12-09 18:38 - 2015-11-05 20:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-12-09 18:38 - 2015-11-05 20:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-12-09 18:38 - 2015-11-05 10:53 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2015-12-09 18:38 - 2015-11-03 20:04 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2015-12-09 18:38 - 2015-11-03 20:04 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
2015-12-09 18:38 - 2015-11-03 19:56 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2015-12-09 18:38 - 2015-11-03 19:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll
2015-12-09 18:38 - 2015-10-09 00:22 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2015-12-09 18:38 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL
2015-12-09 18:38 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll
2015-12-09 18:38 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL
2015-12-09 18:38 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL
2015-12-09 18:38 - 2015-10-09 00:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll
2015-12-09 18:38 - 2015-10-09 00:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL
2015-12-09 18:38 - 2015-10-09 00:17 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2015-12-09 18:38 - 2015-10-08 20:13 - 00419928 _____ C:\Windows\SysWOW64\locale.nls
2015-12-09 18:38 - 2015-10-08 19:52 - 00419928 _____ C:\Windows\system32\locale.nls
2015-12-05 09:59 - 2015-12-29 18:45 - 00023258 _____ C:\Users\StefanMaster\Desktop\ForumURL.xlsx
2015-12-01 18:34 - 2015-11-25 00:10 - 01905272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435906.dll
2015-12-01 18:34 - 2015-11-25 00:10 - 01564792 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435906.dll
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-12-29 23:07 - 2014-03-15 19:03 - 00000000 ____D C:\ProgramData\NVIDIA
2015-12-29 23:07 - 2014-03-15 16:28 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-12-29 23:07 - 2014-03-15 16:24 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2015-12-29 23:07 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-29 23:05 - 2009-07-14 05:45 - 00029136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-29 23:05 - 2009-07-14 05:45 - 00029136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-29 23:03 - 2011-04-12 08:43 - 00699416 _____ C:\Windows\system32\perfh007.dat
2015-12-29 23:03 - 2011-04-12 08:43 - 00149556 _____ C:\Windows\system32\perfc007.dat
2015-12-29 23:03 - 2009-07-14 06:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-29 23:03 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2015-12-29 22:56 - 2014-10-16 20:50 - 00000000 ____D C:\Windows\ELAMBKUP
2015-12-29 22:31 - 2014-11-16 08:02 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-29 21:32 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
2015-12-29 20:38 - 2015-01-01 09:42 - 00000000 ____D C:\Users\StefanMaster\AppData\Roaming\Audacity
2015-12-29 20:33 - 2015-09-26 08:41 - 00000000 ____D C:\Users\StefanMaster\.gimp-2.8
2015-12-29 20:18 - 2014-03-15 19:32 - 00000000 ____D C:\Users\StefanMaster\AppData\Local\Battle.net
2015-12-29 18:31 - 2014-11-16 08:02 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-12-29 18:31 - 2014-03-15 19:16 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-12-29 18:31 - 2014-03-15 19:16 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-12-28 22:56 - 2015-09-26 08:43 - 00000000 ____D C:\Users\StefanMaster\AppData\Local\gtk-2.0
2015-12-27 18:20 - 2014-03-15 16:00 - 00000000 ____D C:\Users\StefanMaster
2015-12-24 08:21 - 2014-03-29 15:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-12-23 13:45 - 2014-03-15 19:19 - 00000000 ____D C:\Users\StefanMaster\AppData\Local\CrashDumps
2015-12-22 23:03 - 2009-07-14 05:45 - 00447696 _____ C:\Windows\system32\FNTCACHE.DAT
2015-12-22 20:00 - 2014-03-15 16:29 - 00121064 _____ C:\Users\StefanMaster\AppData\Local\GDIPFONTCACHEV1.DAT
2015-12-21 21:48 - 2014-03-15 19:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-12-21 21:48 - 2014-03-15 19:02 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-12-21 21:48 - 2014-03-15 19:02 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-12-21 21:47 - 2015-01-01 23:06 - 00000000 __SHD C:\Users\StefanMaster\AppData\Local\EmieBrowserModeList
2015-12-21 21:47 - 2014-09-27 09:44 - 00000000 __SHD C:\Users\StefanMaster\AppData\Local\EmieUserList
2015-12-21 21:47 - 2014-09-27 09:44 - 00000000 __SHD C:\Users\StefanMaster\AppData\Local\EmieSiteList
2015-12-18 19:34 - 2015-04-04 08:23 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-12-18 19:34 - 2015-04-04 08:23 - 00000000 ___SD C:\Windows\system32\GWX
2015-12-16 19:07 - 2015-08-01 14:07 - 00000000 ____D C:\Users\StefanMaster\Documents\MAGIX_MusicEditor
2015-12-16 18:34 - 2015-11-10 12:38 - 16286888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-12-16 18:34 - 2014-11-01 16:52 - 03211760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-12-16 18:34 - 2014-03-15 19:02 - 18716176 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-12-16 18:34 - 2014-03-15 19:02 - 14005408 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-12-16 18:34 - 2014-03-15 19:02 - 03637352 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-12-16 18:34 - 2014-03-15 19:02 - 00034848 _____ C:\Windows\system32\nvinfo.pb
2015-12-16 15:53 - 2014-03-15 19:03 - 06359672 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-12-16 15:53 - 2014-03-15 19:03 - 02985080 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-12-16 15:53 - 2014-03-15 19:03 - 02554488 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-12-16 15:53 - 2014-03-15 19:03 - 01256240 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-12-16 15:53 - 2014-03-15 19:03 - 00385328 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-12-16 15:53 - 2014-03-15 19:03 - 00062768 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-12-16 15:49 - 2014-03-15 19:03 - 06090019 _____ C:\Windows\system32\nvcoproc.bin
2015-12-12 04:37 - 2014-03-15 17:13 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2015-12-12 04:36 - 2014-03-15 17:11 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-12-11 17:09 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2015-12-09 22:14 - 2014-03-18 16:19 - 00000000 ____D C:\Windows\system32\MRT
2015-12-09 22:12 - 2014-03-18 16:19 - 140158008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-12-09 02:51 - 2015-11-21 08:41 - 00111520 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2015-12-09 02:51 - 2014-06-03 04:23 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-12-09 02:51 - 2014-06-03 04:23 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-12-09 02:51 - 2014-03-15 19:03 - 01846016 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-12-09 02:51 - 2014-03-15 19:03 - 01530240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-12-03 20:40 - 2015-11-12 16:34 - 00001591 _____ C:\Users\StefanMaster\Desktop\Kanalwerbung.txt
2015-12-02 13:18 - 2010-11-21 04:27 - 00301728 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2015-01-01 09:40 - 2015-01-01 09:41 - 22892794 _____ (Audacity Team ) C:\Program Files\audacity-win-2.0.6.exe
2015-01-20 22:40 - 2015-01-20 22:40 - 1689384 _____ (techPowerUp (www.techpowerup.com)) C:\Program Files\GPU-Z.0.8.0.exe
2015-04-18 21:04 - 2015-04-18 21:04 - 0064217 _____ () C:\Users\StefanMaster\AppData\Local\2B763BC1_stp.CIS
2015-04-18 21:04 - 2015-04-18 21:06 - 0000289 _____ () C:\Users\StefanMaster\AppData\Local\2B763BC1_stp.CIS.part
2015-04-18 21:04 - 2015-04-18 21:04 - 21666107 _____ () C:\Users\StefanMaster\AppData\Local\58C8488A_stp.CIS
2015-04-18 21:04 - 2015-04-18 21:07 - 0000512 _____ () C:\Users\StefanMaster\AppData\Local\58C8488A_stp.CIS.part
2015-04-18 21:07 - 2015-04-18 21:07 - 0064217 _____ () C:\Users\StefanMaster\AppData\Local\59ED2468_stp.CIS
2015-04-18 21:07 - 2015-04-18 21:07 - 0000289 _____ () C:\Users\StefanMaster\AppData\Local\59ED2468_stp.CIS.part
2015-04-18 21:02 - 2015-04-18 21:02 - 0385602 _____ () C:\Users\StefanMaster\AppData\Local\5D515C96_stp.CIS
2015-04-18 21:02 - 2015-04-18 21:06 - 0000220 _____ () C:\Users\StefanMaster\AppData\Local\5D515C96_stp.CIS.part
2014-06-02 12:52 - 2014-06-02 12:52 - 0000000 _____ () C:\Users\StefanMaster\AppData\Local\Driver_LOM_8161Present.flag
2014-03-15 16:12 - 2014-06-02 12:42 - 0000690 _____ () C:\Users\StefanMaster\AppData\Local\killertool.log
2015-12-28 22:56 - 2015-12-28 22:56 - 0077084 _____ () C:\Users\StefanMaster\AppData\Local\recently-used.xbel
Einige Dateien in TEMP:
====================
C:\Users\StefanMaster\AppData\Local\Temp\AttUninst64.exe
C:\Users\StefanMaster\AppData\Local\Temp\drm_dialogs.dll
C:\Users\StefanMaster\AppData\Local\Temp\drm_dyndata_7340014.dll
C:\Users\StefanMaster\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\StefanMaster\AppData\Local\Temp\nvSCPAPISvr.exe
C:\Users\StefanMaster\AppData\Local\Temp\nvStInst.exe
C:\Users\StefanMaster\AppData\Local\Temp\sqlite3.dll
C:\Users\StefanMaster\AppData\Local\Temp\tmd_34011066.exe
C:\Users\StefanMaster\AppData\Local\Temp\tmd_34011513.exe
C:\Users\StefanMaster\AppData\Local\Temp\tmd_34012792.exe
C:\Users\StefanMaster\AppData\Local\Temp\tmd_34013784.exe
C:\Users\StefanMaster\AppData\Local\Temp\tmd_34015719.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-12-21 18:55
==================== Ende von FRST.txt ============================ |