Teammalu | 03.03.2016 21:32 | eset log Code:
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internet# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=2229fb756fdea64a95ebafdf496d8f2f
# end=init
# utc_time=2016-03-03 05:46:30
# local_time=2016-03-03 06:46:30 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 28401
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=2229fb756fdea64a95ebafdf496d8f2f
# end=updated
# utc_time=2016-03-03 05:50:12
# local_time=2016-03-03 06:50:12 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=2229fb756fdea64a95ebafdf496d8f2f
# engine=28401
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-03-03 08:06:07
# local_time=2016-03-03 09:06:07 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=788 16777213 100 98 1950245 2074810 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 3775757 10806510 0 0
# scanned=289200
# found=10
# cleaned=0
# scan_time=8155
sh=EF317D8C323D3B44355F29B6B3958302CFB6B455 ft=1 fh=ea7bfd263cea1e3c vn="Variante von Win32/Adware.ConvertAd.AGD Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\35444335-1454867160-5438-4D39-B05ADAD90E2C\knsr277B.tmp.vir"
sh=ED5AC5AEC67BBE510C498CDDA6C1610FC12550E0 ft=1 fh=8fc02140b60e8229 vn="Variante von Win32/Adware.ConvertAd.AGD Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\35444335-1454867160-5438-4D39-B05ADAD90E2C\vnss81FB.tmp.vir"
sh=0DBC9314DE66C51FC865A85FD1F6EAEF0D244828 ft=1 fh=c71c001106d0d593 vn="Variante von Win32/Adware.CloudGuard.B Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\DNS Unlocker\ConsoleApplication1.dll.vir"
sh=C105DAF0A978672BA0E3668E55F3ED0ADEFBAE07 ft=1 fh=c71c0011292da1e8 vn="Variante von Win32/Adware.Adposhel.A Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\DNS Unlocker\DnsMonitoring.dll.vir"
sh=63AA770C5B78F96ABCC3F2D1F49A4F75788F6D10 ft=1 fh=e10365b81e22ab12 vn="Variante von Win32/Systweak.K evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\RCPUninstall.exe.vir"
sh=F378AF3725D4F8810F9A709CA871AD63BAC67EA0 ft=1 fh=bc56719f9c1c22ec vn="Variante von Win32/Systweak evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\RCP\RegCleanPro.exe.vir"
sh=C1515799C5063A5CAAD8CAB51725104041B7D5C1 ft=1 fh=bae9daf254c5bb84 vn="Variante von Win64/Systweak.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\WINDOWS\SysNative\roboot64.exe.vir"
sh=C31C40471EB9294743B4E89C8B93626A4EB8174F ft=1 fh=05ec11096a4e2e4e vn="Variante von Win64/Packed.Komodia.E verdächtige Datei" ac=I fn="C:\AdwCleaner\Quarantine\C\WINDOWS\SysNative\zcengine64.dll.vir"
sh=8D5ECBB71CB2BBDAC0657A6CD7CAB5F3FF9F1BD6 ft=1 fh=9ef1184901cdfddf vn="Variante von Generik.CWLHAFD Trojaner" ac=I fn="C:\alte Festplatten\Festplatte 1\PLATTE\T-Online\EMAIL4\Mail.exe"
sh=2DE50229B0B0A12BF5A2C2467711C78300A70598 ft=0 fh=0000000000000000 vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Michael\Michael Dell PC\banking2\FFSetup3.0.1.zip" Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 02.03.2016
Suchlaufzeit: 21:32
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.2.0.1024
Malware-Datenbank: v2016.03.02.05
Rootkit-Datenbank: v2016.02.27.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: kluch
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 379665
Abgelaufene Zeit: 23 Min., 7 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 40
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.DataContainer, In Quarantäne, [e81584fed7c2ee484ca44e1ae51f3fc1],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.DataContainer.1, In Quarantäne, [9469156d5247eb4bd41c6afe58ace020],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.DataController, In Quarantäne, [cb320f73900970c619d772f68c7853ad],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.DataController.1, In Quarantäne, [d52894ee6534a29428c8db8d2cd89070],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.DataTable, In Quarantäne, [30cd0e744a4fe551975974f4788cd12f],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.DataTable.1, In Quarantäne, [f904e0a26a2f7bbbfaf6aeba1ce86a96],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.DataTableFields, In Quarantäne, [59a4ee944f4afb3b7779511774904cb4],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.DataTableFields.1, In Quarantäne, [5ca1c2c01e7b2b0bd818a1c7ba4a5fa1],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.DataTableHolder, In Quarantäne, [738a4e34d0c9cf67f6faa8c0a262d52b],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.DataTableHolder.1, In Quarantäne, [6796730f9603280e14dc88e00afa3ec2],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.LSPLogic, In Quarantäne, [af4e1a684554d85ed41cc0a8d23209f7],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.LSPLogic.1, In Quarantäne, [4cb1eb97990022143bb5cb9dda2a1be5],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.ReadOnlyManager, In Quarantäne, [46b73c468c0dad89727efe6a06fe49b7],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.ReadOnlyManager.1, In Quarantäne, [13ea96ecd6c3fe38a947541435cf867a],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.WFPController, In Quarantäne, [916c5d257623290da64a0d5bfe067090],
PUP.Optional.Komodia, HKLM\SOFTWARE\CLASSES\zcengineLib.WFPController.1, In Quarantäne, [0af3b6ccdebbd95d31bf590fb64e6b95],
PUP.Optional.VBates, HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\4832D1BACA6156C53A74A472BE8678EAAABC8CBE, In Quarantäne, [e81586fc5c3d9c9a584ebdb63acae020],
PUP.Optional.YesSearches, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}, In Quarantäne, [a35aff8354453ef887a819ef2ad95aa6],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.DataContainer, In Quarantäne, [c03df48e6534ac8ad818beaadf257987],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.DataContainer.1, In Quarantäne, [ac513250b4e5122445ab3c2cb94bff01],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.DataController, In Quarantäne, [f10c7a080f8a85b1f3fdb2b6c4408b75],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.DataController.1, In Quarantäne, [9a63136f89101d19c0306efa2ed652ae],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.DataTable, In Quarantäne, [e617abd7dbbee551569acc9c010308f8],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.DataTable.1, In Quarantäne, [56a7136f5e3bf145f2fe03659c681be5],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.DataTableFields, In Quarantäne, [05f8057d9cfd62d49a56f96ff113b050],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.DataTableFields.1, In Quarantäne, [0eefacd6d6c36cca01ef54140ef650b0],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.DataTableHolder, In Quarantäne, [a35af58dafea66d0ce22f474db29926e],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.DataTableHolder.1, In Quarantäne, [4cb1e59d7f1a52e4648c27416c987b85],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.LSPLogic, In Quarantäne, [9469c9b9b9e059dd69874622d82c629e],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.LSPLogic.1, In Quarantäne, [0eefb9c9dfba40f68967036529db659b],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.ReadOnlyManager, In Quarantäne, [42bb5b2701988ea80ce44523d62e32ce],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.ReadOnlyManager.1, In Quarantäne, [8e6f7e048c0dbb7b6b85c6a23dc71ce4],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.WFPController, In Quarantäne, [39c4453d564361d5618fe2866c989b65],
PUP.Optional.Komodia, HKLM\SOFTWARE\WOW6432NODE\CLASSES\zcengineLib.WFPController.1, In Quarantäne, [fd005d25cfcafd39c729b7b16f955aa6],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\4832D1BACA6156C53A74A472BE8678EAAABC8CBE, In Quarantäne, [3bc292f0c2d771c5b5f1700320e4d12f],
PUP.Optional.YesSearches, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}, In Quarantäne, [609d9ae8d4c5fa3cf13ec54344bf0df3],
PUP.Optional.Shopperz.BrwsrFlsh, HKU\.DEFAULT\SOFTWARE\MICROSOFT\INTERNET EXPLORER\INTERNETREGISTRY\REGISTRY\USER\S-1-5-18\SOFTWARE\shopperz080220160607, In Quarantäne, [9865add5099061d53dabcc9ba95b956b],
PUP.Optional.Komodia, HKU\S-1-5-21-365323482-1659304263-2537558190-1001\SOFTWARE\INSTALLPATH\STATUS, In Quarantäne, [b7467d052f6a92a4c88a0c5de91b01ff],
PUP.Optional.YesSearches, HKU\S-1-5-21-365323482-1659304263-2537558190-1001\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}, In Quarantäne, [6b926c16772247ef5d9aeb8538cc51af],
PUP.Optional.VBates, HKU\S-1-5-21-365323482-1659304263-2537558190-1001_Classes\SOFTWARE\{390E710F-0CF2-422D-819F-D04816933201}, In Quarantäne, [7d807a08f9a09e9801c611645ea6926e],
Registrierungswerte: 18
PUP.Optional.Shopperz.BrwsrFlsh, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{984C487D-2AB4-4DFC-919E-0F53E15877D2}, C:\Program Files\shopperz080220160607\Firefox\{984C487D-2AB4-4DFC-919E-0F53E15877D2}.xpi, In Quarantäne, [b944e1a1960366d047b733afb74cc23e]
PUP.Optional.YesSearches, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|hp, hxxp://www.yessearches.com/?ts=AHEpB3YlB3AqBk..&v=20160202&uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&mode=ffsengext, In Quarantäne, [a35aff8354453ef887a819ef2ad95aa6]
PUP.Optional.YesSearches, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|tab, hxxp://www.yessearches.com/?ts=AHEpB3YlB3AqBk..&v=20160202&uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&mode=ffsengext, In Quarantäne, [36c71e64524765d1220d0701d42f55ab]
PUP.Optional.YesSearches, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|sp, hxxp://www.yessearches.com/chrome.php?uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&q={searchTerms}&ts=AHEpB3YlB3AqBk..&v=20160202&mode=ffsengext, In Quarantäne, [bc41542ea4f540f6002f18f023e0d030]
PUP.Optional.YesSearches, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|surl, hxxp://www.yessearches.com/chrome.php?uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&ts=AHEpB3YlB3AqBk..&v=20160202&mode=ffexttoolbar&q=, In Quarantäne, [5ca15d255148979fff30d434fa090bf5]
PUP.Optional.Shopperz.BrwsrFlsh, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{984C487D-2AB4-4DFC-919E-0F53E15877D2}, C:\Program Files\shopperz080220160607\Firefox\{984C487D-2AB4-4DFC-919E-0F53E15877D2}.xpi, In Quarantäne, [fa031270a3f65adc00fe8959689b1be5]
PUP.Optional.YesSearches, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|hp, hxxp://www.yessearches.com/?ts=AHEpB3YlB3AqBk..&v=20160202&uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&mode=ffsengext, In Quarantäne, [609d9ae8d4c5fa3cf13ec54344bf0df3]
PUP.Optional.YesSearches, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|tab, hxxp://www.yessearches.com/?ts=AHEpB3YlB3AqBk..&v=20160202&uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&mode=ffsengext, In Quarantäne, [24d9ec96a1f873c3f13e49bfb84b32ce]
PUP.Optional.YesSearches, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|sp, hxxp://www.yessearches.com/chrome.php?uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&q={searchTerms}&ts=AHEpB3YlB3AqBk..&v=20160202&mode=ffsengext, In Quarantäne, [916c6e149603a69075ba28e00201966a]
PUP.Optional.YesSearches, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|surl, hxxp://www.yessearches.com/chrome.php?uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&ts=AHEpB3YlB3AqBk..&v=20160202&mode=ffexttoolbar&q=, In Quarantäne, [ed10176bcdcc5bdbe34ce226d42f54ac]
PUP.Optional.MaxDriverUpdater, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{9780D7BE-5560-4435-B522-194ADB9969D8}, v2.25|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Max Driver Updater\maxdu.exe|Name=MaxDriverUpdater|, In Quarantäne, [47b61171c6d3f4428bfc5b1774903fc1]
PUP.Optional.Komodia, HKU\S-1-5-21-365323482-1659304263-2537558190-1001\SOFTWARE\INSTALLPATH\STATUS|FlowsurfCB, I, In Quarantäne, [b7467d052f6a92a4c88a0c5de91b01ff]
PUP.Optional.IEAudioAds, HKU\S-1-5-21-365323482-1659304263-2537558190-1001\SOFTWARE\INSTALLPATH\STATUS|NuvisionDataRemarketer, R, In Quarantäne, [7885612106930e2843dd936c57acdc24]
PUP.Optional.YesSearches, HKU\S-1-5-21-365323482-1659304263-2537558190-1001\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|hp, hxxp://www.yessearches.com/?ts=AHEpB3YlB3AqBk..&v=20160202&uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&mode=ffsengext, In Quarantäne, [6b926c16772247ef5d9aeb8538cc51af]
PUP.Optional.YesSearches, HKU\S-1-5-21-365323482-1659304263-2537558190-1001\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|tab, hxxp://www.yessearches.com/?ts=AHEpB3YlB3AqBk..&v=20160202&uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&mode=ffsengext, In Quarantäne, [ea13c5bd7128a88ea0570f611ce8ac54]
PUP.Optional.YesSearches, HKU\S-1-5-21-365323482-1659304263-2537558190-1001\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|sp, hxxp://www.yessearches.com/chrome.php?uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&q={searchTerms}&ts=AHEpB3YlB3AqBk..&v=20160202&mode=ffsengext, In Quarantäne, [837a2b57e1b83501ec0bd19fcb392ad6]
PUP.Optional.YesSearches, HKU\S-1-5-21-365323482-1659304263-2537558190-1001\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|surl, hxxp://www.yessearches.com/chrome.php?uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&ts=AHEpB3YlB3AqBk..&v=20160202&mode=ffexttoolbar&q=, In Quarantäne, [5aa3532f5049ca6cb4435e12c3411be5]
PUP.Optional.VBates, HKU\S-1-5-21-365323482-1659304263-2537558190-1001_Classes\SOFTWARE\{390E710F-0CF2-422D-819F-D04816933201}|Name, C:\Program Files\shopperz080220160607\Jitydi.exe, In Quarantäne, [7d807a08f9a09e9801c611645ea6926e]
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 1
Adware.LaSuperba, C:\uninst, In Quarantäne, [d22be49e3069f046fb4b919d6c99956b],
Dateien: 16
PUP.Optional.Amonetize.Gen, C:\ProgramData\f317a191-08d3-0\BITFF49.tmp, In Quarantäne, [6a93047e4b4e270f8098b9bbe321f30d],
PUP.Optional.Amonetize.Gen, C:\ProgramData\f317a191-1cd3-1\BITFEAC.tmp, In Quarantäne, [55a8e69ce5b448ee77a17afa36cef709],
Adware.LaSuperba, C:\uninst\uninstall.html, In Quarantäne, [d22be49e3069f046fb4b919d6c99956b],
PUP.Optional.MorePowerfulCleaner, C:\Users\kluch\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.searchengine.iconURL", "hxxp://download.mpc.am/mpc/www/mpc.ico");), Ersetzt,[47b6c3bf1f7a6ccafa5ac56aa85d8779]
PUP.Optional.MorePowerfulCleaner, C:\Users\kluch\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.searchengine.name", "MPC Safe Search ");), Ersetzt,[53aac1c1514858de04518da2ce37e31d]
PUP.Optional.YesSearches, C:\Users\kluch\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\DD1B66D4.xml, In Quarantäne, [708dec960990dd59664e3af4c243d42c],
PUP.Optional.YesSearches, C:\Users\kluch\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.searchengine.hp", "hxxp://www.yessearches.com/?ts=AHEpB3YlB3AqBk..&v=20160202&uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&mode=ffsengext");), Ersetzt,[a15c176b4d4c4cea6708c6698c7925db]
PUP.Optional.YesSearches, C:\Users\kluch\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js, Gut: (), Schlecht: (
user_pref("app.update.backgroundErrors", 1);
user_pref("app.update.enabled", false);
user_pref("app.update.lastUpdateTime.addon-background-update-timer", 1454876658);
user_pref("app.update.l), Ersetzt,[9e5faad85b3ea78f6e01200fdc29ab55]
PUP.Optional.YesSearches, C:\Users\kluch\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js, Gut: (), Schlecht: (
user_pref("accessibility.typeaheadfind", true);
user_pref("app.update.auto", false);
user_pref("app.update.backgroundErrors", 1);
user_pref("app.update.enabled", false);
user_pref("app.upda), Ersetzt,[c13c0a78a3f61b1b4e21cf60b154916f]
PUP.Optional.YesSearches, C:\Users\kluch\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.searchengine.hp", "hxxp://www.yessearches.com/?ts=AHEpB3YlB3AqBk..&v=20160202&uid=BB30AB1C443929D2A62EF2F900B54D71&ptid=sqr1&mode=ffsengext");), Ersetzt,[b647add5aaef91a517582c036a9b0af6]
PUP.Optional.YesSearches, C:\Users\kluch\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js, Gut: (), Schlecht: (ref("app.update.auto", false);
user_pref("app.update.backgroundErrors", 1);
user_pref("app.update.enabled", false);
user_pref("app.update.lastUpdateTime.addon-background-update-timer", 145487), Ersetzt,[14e9275b0f8aa096630c5fd09570d32d]
PUP.Optional.YesSearches, C:\Users\kluch\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js, Gut: (), Schlecht: (sit the URL about:config
*/
user_pref("accessibility.typeaheadfind", true);
user_pref("app.update.auto", false);
user_pref("app.update.backgroundErrors", 1);
user_pref("app.update.enabled), Ersetzt,[aa53037fa3f6181e0c635cd38b7a9b65]
PUP.Optional.YesSearches, C:\Users\kluch\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\searchplugins\DD1B66D4.xml, In Quarantäne, [de1f0d75049587af16ab8f9f9b6aa15f],
PUP.Optional.MorePowerfulCleaner, C:\Users\kluch\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.searchengine.iconURL", "hxxp://download.mpc.am/mpc/www/mpc.ico");), Ersetzt,[9b627c06cdccd95d3a1a40ef8f767e82]
PUP.Optional.MorePowerfulCleaner, C:\Users\kluch\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.searchengine.name", "MPC Safe Search ");), Ersetzt,[3ac3770b990038fe1b3a151a6e9728d8]
PUP.Optional.HijackHosts.Gen, C:\Windows\System32\suiw\cit\vhfa.dat, In Quarantäne, [e61709790c8d01351ceef1393bca2ed2],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Das zweite war auch auf dem Rechner? Frag bitte nicht, wo und wie ich das gefunden habe.
Gruß
Michael
FRST Logfile: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:17-02-2016
durchgeführt von SYSTEM auf MININT-SM46UF2 (03-03-2016 21:23:44)
Gestartet von D:\
Platform: Windows 10 Home Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11
Start-Modus: Recovery
Standard: ControlSet001 ACHTUNG!:=====> Wenn das System startfähig ist sollte FRST im normalen oder abgesicherten Modus ausgeführt werden, um ein vollständiges Ergebnis zu erhalten.
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8496344 2015-07-06] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3945656 2015-12-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [127528 2015-07-08] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [654088 2015-02-17] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-07-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HostManager] => C:\Program Files (x86)\Common Files\AOL\1450991226\ee\AOLSoftware.exe [41800 2010-03-08] (AOL Inc.)
HKLM-x32\...\Run: [IJNetworkScanUtility] => C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [206240 2010-08-23] (CANON INC.)
HKLM-x32\...\Run: [PowerDVD14Agent] => C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe [795336 2015-10-29] (CyberLink Corp.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139768 2016-02-08] (AVAST Software)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\kluch\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3014224 2016-02-04] (Valve Corporation)
HKU\kluch\...\Run: [SpybotPostWindows10UpgradeReInstall] => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
HKU\kluch\...\RunOnce: [Uninstall C:\Users\kluch\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\kluch\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64"
BootExecute: autocheck autochk * sdnclean64.exe
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S2 AdaptiveSleepService; c:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [138752 2015-07-06] ()
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-08] (AVAST Software)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2286848 2015-12-24] (Broadcom Corporation.)
S2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2787512 2015-12-22] (Microsoft Corporation)
S2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [349728 2015-06-25] (WildTangent)
S2 HPSupportSolutionsFrameworkService; c:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [25800 2015-09-28] (Hewlett-Packard Company)
S2 HPWMISVC; c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [608520 2015-02-17] (Hewlett-Packard Development Company, L.P.)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] ()
S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [294616 2015-07-06] (Realtek Semiconductor)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S2 SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [452456 2015-12-24] ()
S2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-12-24] (Synaptics Incorporated)
S2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [60432 2015-07-14] (Advanced Micro Devices, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 Amuuiis; "C:\Users\kluch\AppData\Roaming\IuceNuwm\Bosja.exe" -cms [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [18968 2015-07-14] (Advanced Micro Devices, INC.)
S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [101104 2015-07-14] (Advanced Micro Devices, Inc. )
S0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [73976 2015-07-14] (Advanced Micro Devices, Inc.)
S0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [277240 2015-07-14] (Advanced Micro Devices, Inc. )
S2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-08] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-02-08] (AVAST Software)
S1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-08] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-08] (AVAST Software)
S1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1065720 2016-02-08] (AVAST Software)
S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-08] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-08] (AVAST Software)
S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-10] (AVAST Software)
S3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-07-14] (Advanced Micro Devices)
S3 ATWPKT2; C:\WINDOWS\system32\drivers\ATWPKT264.SYS [34520 2014-02-25] (America Online)
S3 ATWPKT2; C:\WINDOWS\SysWOW64\drivers\ATWPKT264.SYS [34520 2014-02-25] (America Online)
S3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [177432 2015-12-01] (Broadcom Corporation.)
S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7551240 2015-11-24] (Broadcom Corporation)
S3 clwvd6; C:\Windows\system32\DRIVERS\clwvd6.sys [41400 2015-08-31] (CyberLink Corporation)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
S3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [301784 2015-06-10] (Realtek Semiconductor Corp.)
S3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-06-01] (Realtek )
S3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [402136 2015-06-10] (Realsil Semiconductor Corporation)
S3 SmbDrv; C:\Windows\system32\DRIVERS\Smb_driver_AMDASF.sys [42184 2015-12-24] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [33960 2015-07-13] (Synaptics Incorporated)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [214832 2015-12-08] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 WirelessButtonDriver64; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [30384 2015-06-23] (HP Inc.)
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-03-03 06:45 - 2016-03-03 06:45 - 00000000 ____D C:\Program Files (x86)\ESET
2016-03-02 21:29 - 2016-03-02 22:05 - 00192216 _____ (Malwarebytes) C:\Windows\System32\Drivers\MBAMSwissArmy.sys
2016-03-02 21:29 - 2016-03-02 21:29 - 00001178 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-02 21:29 - 2016-03-02 21:29 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-02 21:29 - 2016-03-02 21:29 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-02 21:29 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\System32\Drivers\mbamchameleon.sys
2016-03-02 21:29 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mwac.sys
2016-03-02 21:29 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\System32\Drivers\mbam.sys
2016-02-25 21:24 - 2016-02-25 21:24 - 00000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2016-02-25 21:22 - 2016-02-25 21:30 - 00361344 _____ C:\Windows\ntbtlog.txt
2016-02-25 20:38 - 2016-02-25 20:38 - 00277188 _____ C:\Windows\Minidump\022516-22046-01.dmp
2016-02-21 22:10 - 2016-02-21 22:10 - 00000000 ____H C:\Users\kluch\BITA052.tmp
2016-02-20 12:33 - 2016-02-20 12:50 - 00001344 _____ C:\Users\kluch\Desktop\Revo Uninstaller.lnk
2016-02-20 12:33 - 2016-02-20 12:33 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-02-19 09:54 - 2016-03-01 21:38 - 00000000 ____D C:\FRST
2016-02-17 21:37 - 2016-02-25 20:38 - 582401917 _____ C:\Windows\MEMORY.DMP
2016-02-17 21:37 - 2016-02-25 20:38 - 00000000 ____D C:\Windows\Minidump
2016-02-17 21:37 - 2016-02-17 21:38 - 00178388 _____ C:\Windows\Minidump\021716-28437-01.dmp
2016-02-14 19:15 - 2016-02-14 19:15 - 00000000 ____D C:\$SysReset
2016-02-12 22:28 - 2016-02-12 22:28 - 00000000 ____D C:\Quarantine
2016-02-12 22:04 - 2016-02-14 16:30 - 00000000 ____D C:\EEK
2016-02-11 20:19 - 2016-02-11 20:27 - 00000000 ____D C:\Users\kluch\Downloads\2016_02_11
2016-02-11 20:19 - 2016-02-11 20:19 - 00000000 ___HD C:\ProgramData\CanonIJScan
2016-02-09 21:54 - 2016-01-29 07:57 - 04502352 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-02-09 21:54 - 2016-01-29 07:33 - 04064320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2016-02-09 21:54 - 2016-01-27 07:15 - 01557776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-02-09 21:54 - 2016-01-27 07:15 - 01542816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-02-09 21:54 - 2016-01-27 07:01 - 07476064 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2016-02-09 21:54 - 2016-01-27 07:01 - 01997328 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2016-02-09 21:54 - 2016-01-27 07:01 - 01819720 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2016-02-09 21:54 - 2016-01-27 06:59 - 00304752 _____ (Microsoft Corporation) C:\Windows\System32\systemreset.exe
2016-02-09 21:54 - 2016-01-27 06:57 - 02919320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-02-09 21:54 - 2016-01-27 06:57 - 01824264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2016-02-09 21:54 - 2016-01-27 06:57 - 00820704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2016-02-09 21:54 - 2016-01-27 06:56 - 21124344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-02-09 21:54 - 2016-01-27 06:55 - 05242496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2016-02-09 21:54 - 2016-01-27 06:55 - 00081112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpenWith.exe
2016-02-09 21:54 - 2016-01-27 06:54 - 00295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-02-09 21:54 - 2016-01-27 06:46 - 02606824 _____ (Microsoft Corporation) C:\Windows\System32\combase.dll
2016-02-09 21:54 - 2016-01-27 06:46 - 01270072 _____ (Microsoft Corporation) C:\Windows\System32\WinTypes.dll
2016-02-09 21:54 - 2016-01-27 06:45 - 22564328 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll
2016-02-09 21:54 - 2016-01-27 06:45 - 06605544 _____ (Microsoft Corporation) C:\Windows\System32\windows.storage.dll
2016-02-09 21:54 - 2016-01-27 06:44 - 00604928 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2016-02-09 21:54 - 2016-01-27 06:44 - 00085320 _____ (Microsoft Corporation) C:\Windows\System32\OpenWith.exe
2016-02-09 21:54 - 2016-01-27 06:43 - 00359776 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2016-02-09 21:54 - 2016-01-27 06:37 - 01998176 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2016-02-09 21:54 - 2016-01-27 06:37 - 00576352 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms2.sys
2016-02-09 21:54 - 2016-01-27 06:21 - 00162816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-02-09 21:54 - 2016-01-27 06:15 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ztrace_maps.dll
2016-02-09 21:54 - 2016-01-27 06:13 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininetlui.dll
2016-02-09 21:54 - 2016-01-27 06:12 - 00045568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-02-09 21:54 - 2016-01-27 06:11 - 00118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-02-09 21:54 - 2016-01-27 06:10 - 22394368 _____ (Microsoft Corporation) C:\Windows\System32\edgehtml.dll
2016-02-09 21:54 - 2016-01-27 06:10 - 00099840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2016-02-09 21:54 - 2016-01-27 06:08 - 00299008 _____ (Microsoft Corporation) C:\Windows\System32\microsoft-windows-system-events.dll
2016-02-09 21:54 - 2016-01-27 06:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\ztrace_maps.dll
2016-02-09 21:54 - 2016-01-27 06:07 - 00203264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iassam.dll
2016-02-09 21:54 - 2016-01-27 06:05 - 19339776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-02-09 21:54 - 2016-01-27 06:05 - 18678272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2016-02-09 21:54 - 2016-01-27 06:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\System32\wininetlui.dll
2016-02-09 21:54 - 2016-01-27 06:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2016-02-09 21:54 - 2016-01-27 06:04 - 09918976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2016-02-09 21:54 - 2016-01-27 06:04 - 00147456 _____ (Microsoft Corporation) C:\Windows\System32\mtxoci.dll
2016-02-09 21:54 - 2016-01-27 06:03 - 00099328 _____ (Microsoft Corporation) C:\Windows\System32\ngckeyenum.dll
2016-02-09 21:54 - 2016-01-27 06:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\System32\hlink.dll
2016-02-09 21:54 - 2016-01-27 06:01 - 00792064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-02-09 21:54 - 2016-01-27 05:59 - 00258048 _____ (Microsoft Corporation) C:\Windows\System32\iassam.dll
2016-02-09 21:54 - 2016-01-27 05:58 - 11545088 _____ (Microsoft Corporation) C:\Windows\System32\twinui.dll
2016-02-09 21:54 - 2016-01-27 05:57 - 00764928 _____ (Microsoft Corporation) C:\Windows\System32\Chakradiag.dll
2016-02-09 21:54 - 2016-01-27 05:55 - 12125696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-02-09 21:54 - 2016-01-27 05:55 - 03666432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-02-09 21:54 - 2016-01-27 05:54 - 24603136 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2016-02-09 21:54 - 2016-01-27 05:52 - 00970752 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2016-02-09 21:54 - 2016-01-27 05:50 - 02230784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-02-09 21:54 - 2016-01-27 05:50 - 01504768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-02-09 21:54 - 2016-01-27 05:50 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxdav.sys
2016-02-09 21:54 - 2016-01-27 05:49 - 05662208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2016-02-09 21:54 - 2016-01-27 05:48 - 13382656 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2016-02-09 21:54 - 2016-01-27 05:44 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgbkend.dll
2016-02-09 21:54 - 2016-01-27 05:42 - 01387520 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2016-02-09 21:54 - 2016-01-27 05:41 - 03592704 _____ (Microsoft Corporation) C:\Windows\System32\win32kfull.sys
2016-02-09 21:54 - 2016-01-27 05:39 - 02275328 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2016-02-09 21:54 - 2016-01-27 05:38 - 07835648 _____ (Microsoft Corporation) C:\Windows\System32\Chakra.dll
2016-02-09 21:54 - 2016-01-27 05:38 - 01734656 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2016-02-09 21:54 - 2016-01-27 05:37 - 04894720 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2016-02-09 21:54 - 2016-01-27 05:36 - 02757120 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2016-02-09 21:54 - 2016-01-27 05:32 - 01087488 _____ (Microsoft Corporation) C:\Windows\System32\reseteng.dll
2016-02-09 21:54 - 2016-01-27 05:31 - 00079360 _____ (Microsoft Corporation) C:\Windows\System32\cfgbkend.dll
2016-02-09 21:30 - 2016-02-10 21:49 - 00000574 _____ C:\Windows\System32\.crusader
2016-02-09 21:11 - 2016-02-09 21:30 - 00000000 ____D C:\ProgramData\HitmanPro
2016-02-09 21:04 - 2016-02-14 21:50 - 00000547 _____ C:\Users\kluch\Desktop\JRT.txt
2016-02-09 20:14 - 2016-02-20 13:00 - 00000000 ____D C:\AdwCleaner
2016-02-09 20:14 - 2016-02-09 20:13 - 01508352 _____ C:\Users\kluch\Downloads\adwcleaner_5.032.exe
2016-02-09 20:02 - 2016-02-11 20:19 - 00000000 ____D C:\Users\kluch\AppData\Roaming\Canon
2016-02-09 19:27 - 2016-02-09 13:43 - 22908888 _____ (Malwarebytes ) C:\Users\kluch\Downloads\mbam-setup-2.2.0.1024.exe
2016-02-09 06:08 - 2016-02-08 08:14 - 00451073 ____R C:\Windows\System32\Drivers\etc\hosts.20160209-060856.backup
2016-02-08 09:57 - 2016-02-08 09:57 - 00000000 ____D C:\Windows\System32\suiw
2016-02-08 09:47 - 2016-02-19 09:47 - 00004280 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-02-08 09:47 - 2016-02-10 21:36 - 00287016 _____ (AVAST Software) C:\Windows\System32\Drivers\aswvmm.sys
2016-02-08 09:47 - 2016-02-08 09:47 - 00001974 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-02-08 09:47 - 2016-02-08 09:46 - 01065720 _____ (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2016-02-08 09:47 - 2016-02-08 09:46 - 00463744 _____ (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2016-02-08 09:47 - 2016-02-08 09:46 - 00165344 _____ (AVAST Software) C:\Windows\System32\Drivers\aswStm.sys
2016-02-08 09:47 - 2016-02-08 09:46 - 00107792 _____ (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2016-02-08 09:47 - 2016-02-08 09:46 - 00103064 _____ (AVAST Software) C:\Windows\System32\Drivers\aswRdr2.sys
2016-02-08 09:47 - 2016-02-08 09:46 - 00074544 _____ (AVAST Software) C:\Windows\System32\Drivers\aswRvrt.sys
2016-02-08 09:47 - 2016-02-08 09:46 - 00037656 _____ (AVAST Software) C:\Windows\System32\Drivers\aswHwid.sys
2016-02-08 09:46 - 2016-02-08 09:46 - 00398152 _____ (AVAST Software) C:\Windows\System32\aswBoot.exe
2016-02-08 09:46 - 2016-02-08 09:46 - 00052184 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-02-08 08:14 - 2016-02-07 18:43 - 00000967 _____ C:\Windows\System32\Drivers\etc\hosts.20160208-081459.backup
2016-02-08 08:07 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Users\Public\Desktop\Post Win10 Spybot-install.exe
2016-02-08 07:55 - 2016-02-14 16:49 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-02-08 07:55 - 2016-02-08 22:21 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-02-08 07:55 - 2016-02-08 07:55 - 00001455 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2016-02-08 07:55 - 2016-02-08 07:55 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2016-02-08 07:55 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\System32\sdnclean64.exe
2016-02-08 07:54 - 2016-02-14 21:20 - 00000008 __RSH C:\ProgramData\ntuser.pol
2016-02-08 07:52 - 2016-02-08 07:53 - 00000000 ____D C:\Users\kluch\AppData\Local\Tempfolder
2016-02-08 07:52 - 2016-02-08 07:52 - 00003420 _____ C:\Windows\System32\Tasks\Hittaem
2016-02-08 07:52 - 2016-02-08 07:52 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-02-08 07:52 - 2016-02-08 07:52 - 00000000 ____D C:\Users\kluch\AppData\Local\F727A298-4DB4-456A-AC54-A93EA5F8554D
2016-02-08 07:52 - 2016-02-08 07:52 - 00000000 ____D C:\Users\kluch\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-02-08 07:22 - 2016-02-08 09:45 - 201900432 _____ (AVAST Software) C:\Users\kluch\Downloads\avast_free2253_antivirus_setup.exe
2016-02-08 07:20 - 2016-02-08 07:54 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\kluch\Downloads\spybot-2.4.40.exe
2016-02-08 07:20 - 2016-02-08 07:21 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\kluch\Downloads\spybot-2.4.40 (1).exe
2016-02-07 21:08 - 2016-02-07 21:08 - 00187904 _____ C:\Windows\rsrcs.dll
2016-02-07 18:49 - 2016-03-02 21:57 - 00000000 ____D C:\ProgramData\f317a191-1cd3-1
2016-02-07 18:49 - 2016-03-02 21:57 - 00000000 ____D C:\ProgramData\f317a191-08d3-0
2016-02-07 18:49 - 2016-02-07 18:49 - 00022650 _____ C:\Windows\System32\Tasks\{7E0E0C47-7804-7D7D-0C11-7E7D0F0B110C}
2016-02-07 18:46 - 2016-02-07 18:43 - 00000967 _____ C:\Windows\System32\Drivers\etc\hp.bak
2016-02-07 18:43 - 2016-02-07 18:43 - 00000000 ____D C:\Users\kluch\AppData\Roaming\dlg
2016-02-07 14:11 - 2016-02-07 14:11 - 00000000 ____D C:\Program Files (x86)\Glarysoft
2016-02-07 12:07 - 2016-02-07 13:13 - 00000000 ____D C:\alte Festplatten
2016-02-07 10:52 - 2016-02-07 11:30 - 72859648 _____ C:\Users\kluch\Downloads\calibre-64bit-2.50.1.msi
2016-02-04 18:05 - 2016-02-04 18:06 - 00475350 _____ C:\Users\kluch\Downloads\Thermomix Rezeptwelt - Dinkel-Joghurt Brot - 2016-01-20 (4).pdf
2016-02-04 18:04 - 2016-02-04 18:05 - 00475349 _____ C:\Users\kluch\Downloads\Thermomix Rezeptwelt - Dinkel-Joghurt Brot - 2016-01-20 (3).pdf
2016-02-04 18:04 - 2016-02-04 18:04 - 00475353 _____ C:\Users\kluch\Downloads\Thermomix Rezeptwelt - Dinkel-Joghurt Brot - 2016-01-20 (2).pdf
2016-02-04 18:04 - 2016-02-04 18:04 - 00088669 _____ C:\Users\kluch\Downloads\Thermomix Rezeptwelt - Dinkel-Joghurt Brot - 2016-01-20.pdf
2016-02-04 18:04 - 2016-02-04 18:04 - 00088669 _____ C:\Users\kluch\Downloads\Thermomix Rezeptwelt - Dinkel-Joghurt Brot - 2016-01-20 (1).pdf
2016-02-04 15:51 - 2016-02-04 15:51 - 00000000 ____D C:\ProgramData\Cornelsen
2016-02-02 06:47 - 2015-08-31 08:26 - 00041400 _____ (CyberLink Corporation) C:\Windows\System32\Drivers\clwvd6.sys
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-03-03 21:22 - 2016-01-16 04:32 - 00065536 _____ C:\Windows\System32\spu_storage.bin
2016-03-03 21:22 - 2015-10-30 07:28 - 00524288 ___SH C:\Windows\System32\config\BBI
2016-03-03 21:21 - 2016-01-16 04:52 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-03-03 21:21 - 2015-11-24 09:29 - 02953019 _____ C:\Windows\SysWOW64\rootpa.e2e
2016-03-03 06:46 - 2015-12-24 21:03 - 00003992 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1450987433
2016-03-03 06:46 - 2015-12-24 21:03 - 00000000 ____D C:\Program Files (x86)\Opera
2016-03-02 22:09 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\AppReadiness
2016-03-02 21:58 - 2016-01-05 14:52 - 00000364 _____ C:\Windows\Tasks\HPCeeScheduleForkluch.job
2016-03-02 21:58 - 2015-10-30 08:24 - 00000000 ___RD C:\Windows\MiracastView
2016-03-02 21:57 - 2015-12-24 21:03 - 00001181 _____ C:\Users\Public\Desktop\Opera.lnk
2016-03-02 21:57 - 2015-12-24 19:59 - 00001931 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-03-02 21:32 - 2016-01-16 04:35 - 02003182 _____ C:\Windows\System32\PerfStringBackup.INI
2016-03-02 21:32 - 2015-10-30 19:35 - 00853752 _____ C:\Windows\System32\perfh007.dat
2016-03-02 21:32 - 2015-10-30 19:35 - 00187942 _____ C:\Windows\System32\perfc007.dat
2016-03-02 21:32 - 2015-10-30 08:21 - 00000000 ____D C:\Windows\INF
2016-03-02 21:31 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-02 21:30 - 2016-01-16 04:36 - 00000000 ____D C:\users\kluch
2016-03-02 21:30 - 2016-01-05 14:52 - 00003256 _____ C:\Windows\System32\Tasks\HPCeeScheduleForkluch
2016-02-23 22:07 - 2016-01-13 21:31 - 00000000 ____D C:\Users\kluch\AppData\LocalLow\Temp
2016-02-14 22:30 - 2015-12-24 21:16 - 00000000 ____D C:\Users\kluch\Documents\Calibre-Bibliothek
2016-02-10 09:56 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\rescache
2016-02-10 09:35 - 2015-10-30 08:11 - 00000000 ____D C:\Windows\CbsTemp
2016-02-10 09:19 - 2015-07-16 07:05 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-02-10 05:41 - 2015-10-30 19:44 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-10 00:16 - 2015-12-24 22:16 - 00000000 ____D C:\Windows\System32\MRT
2016-02-10 00:11 - 2015-12-24 22:16 - 146614896 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2016-02-09 19:41 - 2016-01-10 13:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-02-09 19:20 - 2015-12-24 22:24 - 00000000 ____D C:\Users\kluch\Documents\YouCam
2016-02-09 19:14 - 2015-11-24 09:35 - 00000000 ____D C:\ProgramData\mcafee
2016-02-09 19:13 - 2015-10-30 08:24 - 00000000 ___HD C:\Windows\ELAMBKUP
2016-02-09 19:13 - 2015-10-30 07:28 - 00032768 ___SH C:\Windows\System32\config\ELAM
2016-02-09 19:12 - 2015-12-25 14:20 - 00000000 ____D C:\Windows\System32\Tasks\McAfee
2016-02-09 19:11 - 2015-07-10 10:05 - 00000000 ____D C:\users\Default.migrated
2016-02-08 09:47 - 2015-12-25 12:07 - 00000000 ____D C:\Users\kluch\AppData\Roaming\AVAST Software
2016-02-08 09:46 - 2015-11-24 09:44 - 00000000 ____D C:\Program Files\AVAST Software
2016-02-08 09:45 - 2015-11-24 09:44 - 00000000 ____D C:\ProgramData\AVAST Software
2016-02-08 07:53 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2016-02-08 07:15 - 2015-10-30 08:24 - 00000000 ____D C:\Windows\System32\NDF
2016-02-08 06:49 - 2015-11-24 09:22 - 00000000 ____D C:\Program Files\Broadcom
2016-02-08 06:49 - 2015-07-13 17:28 - 00000000 ____D C:\SWSetup
2016-02-07 19:51 - 2016-01-16 04:26 - 00305232 _____ C:\Windows\System32\FNTCACHE.DAT
2016-02-07 19:48 - 2016-01-16 22:33 - 00000000 ____D C:\Program Files (x86)\Steam
2016-02-07 18:18 - 2015-12-24 19:44 - 00000000 ____D C:\Users\kluch\AppData\Local\Packages
2016-02-07 17:14 - 2015-12-25 12:12 - 00000000 ____D C:\Users\kluch\AppData\Roaming\vlc
2016-02-07 11:32 - 2015-12-24 21:15 - 00001006 _____ C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk
2016-02-07 11:32 - 2015-12-24 21:15 - 00000000 ____D C:\Program Files\Calibre2
2016-02-06 22:28 - 2015-11-24 09:49 - 00000000 ____D C:\Program Files\CyberLink
2016-02-06 22:24 - 2015-11-24 09:12 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-02-04 16:16 - 2016-01-19 20:16 - 00078730 _____ C:\Users\kluch\Downloads\dvr_fileconverter.zip
2016-02-03 20:05 - 2015-12-24 19:50 - 00000000 ___RD C:\Users\kluch\OneDrive
2016-02-03 20:01 - 2015-10-30 08:26 - 00828920 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-02-03 20:01 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-02-03 08:39 - 2015-11-24 09:26 - 00000000 ____D C:\Users\Public\Documents\CyberLink
2016-02-02 06:47 - 2015-11-24 09:16 - 00000000 ____D C:\ProgramData\SUPPORTDIR
2016-02-02 06:44 - 2015-11-24 09:16 - 00000000 ____D C:\ProgramData\Temp
2016-02-02 06:44 - 2015-11-24 09:16 - 00000000 ____D C:\Program Files (x86)\CyberLink
2016-02-02 06:33 - 2015-11-24 09:16 - 00000000 ____D C:\ProgramData\CyberLink
==================== Known DLLs (Nicht auf der Ausnahmeliste) =========================
[2015-10-30 08:17] - [2015-10-30 08:17] - 0442720 ____A (Microsoft Corporation) C:\Windows\System32\coml2.dll
[2015-10-30 08:18] - [2015-10-30 08:18] - 0358240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\coml2.dll
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\System32\winlogon.exe
[2016-01-16 10:51] - [2016-01-05 02:43] - 0584704 ____A (Microsoft Corporation) 7B24B823404D53DA4748F21AD2BF04C9
C:\Windows\System32\wininit.exe
[2015-10-30 08:17] - [2015-10-30 08:17] - 0290856 ____A (Microsoft Corporation) CAD491DD9EC00BB841EA407D9C498C4A
C:\Windows\explorer.exe
[2016-02-09 21:54] - [2016-01-29 07:57] - 4502352 ____A (Microsoft Corporation) 95D730526EF81792CD6848D8D10FAA1C
C:\Windows\SysWOW64\explorer.exe
[2016-02-09 21:54] - [2016-01-29 07:33] - 4064320 ____A (Microsoft Corporation) FCBCED2A237DCD7EF86CED551B731742
C:\Windows\System32\svchost.exe
[2015-10-30 08:17] - [2015-10-30 08:17] - 0043944 ____A (Microsoft Corporation) 8497852ED44AFF902D502015792D315D
C:\Windows\SysWOW64\svchost.exe
[2015-10-30 08:18] - [2015-10-30 08:18] - 0037256 ____A (Microsoft Corporation) 6A1212077C0559029CDFB9C39580C835
C:\Windows\System32\services.exe
[2016-01-28 07:15] - [2016-01-16 07:08] - 0440152 ____A (Microsoft Corporation) 6FF8248F3A9D69A095C7F3F42BC29CB2
C:\Windows\System32\User32.dll
[2016-01-16 04:17] - [2016-01-16 04:17] - 1399224 ____A (Microsoft Corporation) DD97EF0AE9224B8C1161736E033C03F1
C:\Windows\SysWOW64\User32.dll
[2016-01-16 04:17] - [2016-01-16 04:17] - 1337240 ____A (Microsoft Corporation) B8C4EFAA6AAED98E6B5AB57CAFA489B9
C:\Windows\System32\userinit.exe
[2015-10-30 08:17] - [2015-10-30 08:17] - 0030720 ____A (Microsoft Corporation) 8F3ECCB5DC878FA14887B43CD148CBA9
C:\Windows\SysWOW64\userinit.exe
[2015-10-30 08:18] - [2015-10-30 08:18] - 0026112 ____A (Microsoft Corporation) A878CF325C93723B5017642E6FDB80E8
C:\Windows\System32\rpcss.dll
[2015-10-30 08:17] - [2015-10-30 08:17] - 0904704 ____A (Microsoft Corporation) B339861C6A2A86FBCA67C2006B461473
C:\Windows\System32\dnsapi.dll
[2015-10-30 08:18] - [2015-10-30 08:18] - 0686984 ____A (Microsoft Corporation) E7B524818100B0FDE2B057C74B0C0DCD
C:\Windows\SysWOW64\dnsapi.dll
[2015-10-30 08:18] - [2015-10-30 08:18] - 0535088 ____A (Microsoft Corporation) 2796C0957F6F05A528DD64B8591371B6
C:\Windows\System32\Drivers\volsnap.sys
[2015-10-30 08:17] - [2015-10-30 08:17] - 0414560 ____A (Microsoft Corporation) E1F91A727A04C9F8199D04FF3BBBF63C
==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============
==================== Wiederherstellungspunkte =========================
Wiederherstellungspunkt Datum: 2016-03-03 09:28
Wiederherstellungspunkt Datum: 2016-03-03 09:28
==================== Speicherinformationen ===========================
Prozentuale Nutzung des RAM: 13%
Installierter physikalischer RAM: 7102.89 MB
Verfügbarer physikalischer RAM: 6123.66 MB
Summe virtueller Speicher: 7102.89 MB
Verfügbarer virtueller Speicher: 6155.08 MB
==================== Laufwerke ================================
Drive c: (Windows) (Fixed) (Total:914.83 GB) (Free:779.14 GB) NTFS
Drive d: (Intenso) (Removable) (Total:7.82 GB) (Free:7.45 GB) FAT32
Drive e: (RECOVERY) (Fixed) (Total:15.49 GB) (Free:1.84 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive g: () (Fixed) (Total:0.81 GB) (Free:0.34 GB) NTFS
Drive x: (Boot) (Fixed) (Total:0.5 GB) (Free:0.5 GB) NTFS
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 4F91BC2E)
Partition: GPT.
========================================================
Disk: 1 (Size: 7.8 GB) (Disk ID: 00000000)
Partition: GPT.
LastRegBack: 2016-03-01 21:25
==================== Ende von FRST.txt ============================ --- --- ---
[/CODE] |