OhSchreck! | 22.02.2017 21:49 | Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 22-02-2017 01
durchgeführt von Thomas Keune (Administrator) auf THOMASKEUNE-PC (22-02-2017 21:40:10)
Gestartet von C:\Users\Thomas Keune\Desktop
Geladene Profile: Thomas Keune (Verfügbare Profile: Thomas Keune)
Platform: Windows 10 Home Version 1607 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
(Microsoft) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe
(REINER SCT) C:\Windows\SysWOW64\cjpcsc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
() C:\Program Files (x86)\TVG\OnlineUpdate\OnlineUpdateSvc.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
() C:\Program Files (x86)\Music Recorder\Music Recorder 2016\AudialsNotifier.exe
(Oracle Corporation) C:\Program Files\Java\jre1.8.0_121\bin\javaw.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2start.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.693_none_42ff55c9655f38bf\TiWorker.exe
==================== Registry (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [emsisoft anti-malware] => c:\program files\emsisoft anti-malware\a2guard.exe [8154184 2017-02-06] (Emsisoft Ltd)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-10-14] (Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [%RunKey%] => C:\Program Files (x86)\FRITZ!vox\FRITZ!vox.exe [1515520 2007-07-26] (AVM Berlin)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2014-03-18] (shbox.de)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4127488 2015-06-16] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048 2011-09-16] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-4016997756-889063991-563976297-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\Music Recorder\Music Recorder 2016\AudialsNotifier.exe [4535192 2016-07-01] ()
HKU\S-1-5-21-4016997756-889063991-563976297-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9292504 2016-12-21] (Piriform Ltd)
HKU\S-1-5-21-4016997756-889063991-563976297-1000\...\RunOnce: [Uninstall C:\Users\Thomas Keune\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Thomas Keune\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64"
HKU\S-1-5-21-4016997756-889063991-563976297-1000\...\Policies\system: [DisableLockWorkstation] 0
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-12-13] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-12-13] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-12-13] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-12-13] (SugarSync, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => -> Keine Datei
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Das Telefonbuch Browserlösung.lnk [2016-01-13]
ShortcutTarget: Das Telefonbuch Browserlösung.lnk -> C:\Program Files (x86)\TVG\DasTelefonbuch Deutschland\http_tfd.exe (TVG Telefon-und Verzeichnisverlag GmbH & Co. KG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FriFax32 - Verknüpfung.lnk [2012-04-15]
ShortcutTarget: FriFax32 - Verknüpfung.lnk -> C:\Program Files (x86)\FRITZ!\FriFax32.exe (AVM Berlin)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\JFritz.lnk [2017-01-04]
ShortcutTarget: JFritz.lnk -> C:\Program Files (x86)\JFritz2\jfritz.exe ()
Startup: C:\Users\Thomas Keune\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jfritz.jar - Verknüpfung.lnk [2017-01-17]
ShortcutTarget: jfritz.jar - Verknüpfung.lnk -> C:\Program Files (x86)\JFritz2\jfritz.jar ()
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
ProxyEnable: [S-1-5-21-4016997756-889063991-563976297-1000] => Proxy ist aktiviert.
ProxyServer: [S-1-5-21-4016997756-889063991-563976297-1000] => http=127.0.0.1:8082;https=127.0.0.1:8082
Winsock: Catalog5-x64 07 C:\Program Files\Bonjour\mdnsNSP.dll => Keine Datei
Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{5d1d9579-e842-492c-88e3-58021255ae65}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{d7841ead-ff00-46b7-9c07-9808ea9293f2}: [DhcpNameServer] 192.168.178.1
ManualProxies: 1http=127.0.0.1:8082;https=127.0.0.1:8082
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKU\S-1-5-21-4016997756-889063991-563976297-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-4016997756-889063991-563976297-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-4016997756-889063991-563976297-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-4016997756-889063991-563976297-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-02-14] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-14] (Oracle Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2010-05-28] (Hewlett-Packard Co.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-02-14] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-14] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2010-05-28] (Hewlett-Packard Co.)
Toolbar: HKLM-x32 - Recorder Toolbar - {120A8821-2BEE-4C29-BCDA-62C577781992} - C:\Program Files (x86)\MedienTeam66\MP3 Recorder for YouTube\IEPlugin.dll [2011-12-29] (MedienTeam66)
Toolbar: HKLM-x32 - NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files (x86)\Xi\NetXfer\NXToolBar.dll [2010-11-07] (Xi)
Toolbar: HKU\S-1-5-21-4016997756-889063991-563976297-1000 -> Kein Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Keine Datei
DPF: HKLM-x32 {39ED5386-A900-4D6C-B564-20BFDE5402CF} hxxp://www.medion.com/de/service/download/MEDION_Treibersuche.ocx
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
FireFox:
========
FF ProfilePath: C:\Users\Thomas Keune\AppData\Roaming\Mozilla\Firefox\Profiles\1t3lmzvm.default-1486818187624 [2017-02-22]
FF Homepage: Mozilla\Firefox\Profiles\1t3lmzvm.default-1486818187624 -> google.de/
FF NetworkProxy: Mozilla\Firefox\Profiles\1t3lmzvm.default-1486818187624 -> type", 4
FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\Thomas Keune\AppData\Roaming\Mozilla\Firefox\Profiles\1t3lmzvm.default-1486818187624\features\{db31db75-02c4-4c1f-8046-7897fc843a9b}\disableSHA1rollout@mozilla.org.xpi [2017-02-19]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru => nicht gefunden
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru => nicht gefunden
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru => nicht gefunden
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-03-09] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox
FF Extension: (Freemake Video Downloader Plugin) - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox [2014-03-13] [ist nicht signiert]
FF HKU\S-1-5-21-4016997756-889063991-563976297-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKU\S-1-5-21-4016997756-889063991-563976297-1000\...\Firefox\Extensions: [mail@shopping-preise.de] - C:\Users\Thomas Keune\AppData\Roaming\Mozilla\Firefox\Profiles\mic35z32.default\extensions\mail@shopping-preise.de => nicht gefunden
FF HKU\S-1-5-21-4016997756-889063991-563976297-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: (McAfee Security Scan Plus) - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] [ist nicht signiert]
FF HKU\S-1-5-21-4016997756-889063991-563976297-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Thomas Keune\AppData\Roaming\Mozilla\Firefox\Profiles\zxjx6lop.default-1409585167823\extensions\cliqz@cliqz.com => nicht gefunden
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-28] ()
FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-14] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-02-14] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [Keine Datei]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [Keine Datei]
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [Keine Datei]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-28] ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Windows\system32\C2MP\npdivx32.dll [Keine Datei]
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-02-14] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-01-20] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-01-20] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [9483200 2017-02-06] (Emsisoft Ltd)
S2 chip1click; C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe [91136 2016-10-27] (Chip Digital GmbH) [Datei ist nicht signiert]
R2 cjpcsc; C:\Windows\SysWOW64\cjpcsc.exe [514128 2012-03-19] (REINER SCT)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [41576 2016-10-24] (Dropbox, Inc.)
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [8704 2011-11-17] (Microsoft) [Datei ist nicht signiert]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [Datei ist nicht signiert]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [50688 2012-02-08] (Hewlett-Packard) [Datei ist nicht signiert]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-01-20] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-01-20] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [464440 2017-01-20] (NVIDIA Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-12] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2017-01-20] (NVIDIA Corporation)
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1716264 2014-04-17] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-04-17] (pdfforge GmbH)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [66048 2012-02-08] (Hewlett-Packard) [Datei ist nicht signiert]
R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [Datei ist nicht signiert]
R2 TVGOnlineUpdateSvc; C:\Program Files (x86)\TVG\OnlineUpdate\OnlineUpdateSvc.exe [401256 2015-02-09] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
S2 DigitalWave.Update.Service; "C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe" [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 cjusb; C:\Windows\system32\DRIVERS\cjusb.sys [34672 2011-03-29] (REINER SCT)
R1 epp; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp.sys [124552 2016-11-23] (Emsisoft Ltd)
R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [39248 2012-06-09] (Paragon Software Group)
R1 HssDRV6; C:\Windows\system32\DRIVERS\hssdrv6.sys [46280 2013-02-22] (AnchorFree Inc.)
S3 IAMTVE; C:\Windows\system32\drivers\IAMTVE.sys [43416 2010-12-17] (Intel Corporation)
R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [109272 2015-10-05] (Malwarebytes)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-02-22] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
R1 MpKslbbc0000f; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74504CD3-497A-413E-A67D-A4F5BFD4D598}\MpKslbbc0000f.sys [44928 2017-02-22] (Microsoft Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvmoi.inf_amd64_bab0214c8bd45ad2\nvlddmkm.sys [14427064 2017-01-21] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2017-01-20] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [46016 2017-01-20] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [57792 2017-01-20] (NVIDIA Corporation)
R3 taphss6; C:\Windows\System32\drivers\taphss6.sys [42184 2013-01-20] (Anchorfree Inc.)
R1 UimBus; C:\Windows\System32\drivers\uimx64.sys [90960 2012-06-09] (Windows (R) 2000 DDK provider)
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [633296 2012-06-09] (Paragon)
R1 Uim_VIM; C:\Windows\System32\Drivers\uim_vimx64.sys [389968 2012-06-09] (Paragon)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
U3 aspnet_state; kein ImagePath
S3 cpuz139; \??\C:\Users\THOMAS~1\AppData\Local\Temp\cpuz139\cpuz139_x64.sys [X] <==== ACHTUNG
S3 dbx; system32\DRIVERS\dbx.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-02-22 21:39 - 2017-02-22 21:39 - 02423296 _____ (Farbar) C:\Users\Thomas Keune\Desktop\FRST64.exe
2017-02-22 21:33 - 2017-02-22 21:33 - 00000000 ____D C:\Users\Thomas Keune\AppData\Local\CrashRpt
2017-02-22 11:07 - 2017-02-22 11:07 - 00000000 ____D C:\Users\Thomas Keune\Downloads\Notfall_DVD_10_Free
2017-02-22 08:32 - 2017-02-22 11:12 - 00000000 ____D C:\KVRT_Data
2017-02-22 08:25 - 2017-02-22 08:32 - 109283160 _____ (Kaspersky Lab ZAO) C:\Users\Thomas Keune\Downloads\KVRT.exe
2017-02-22 08:21 - 2017-02-22 08:40 - 1310308696 _____ C:\Users\Thomas Keune\Downloads\Notfall_DVD_10_Free.zip
2017-02-22 07:08 - 2017-02-22 07:08 - 00006046 _____ C:\Users\Thomas Keune\Documents\cc_20170222_070843.reg
2017-02-21 21:52 - 2017-02-21 21:53 - 106623920 _____ (Microsoft Corporation) C:\Users\Thomas Keune\Downloads\msoloc2010-kb2956076-fullfile-x86-glb.exe
2017-02-21 21:48 - 2017-02-21 21:49 - 01405520 _____ (Microsoft Corporation) C:\Users\Thomas Keune\Downloads\exppdf2010-kb3055047-fullfile-x86-glb.exe
2017-02-21 20:20 - 2017-02-21 20:21 - 00848064 _____ (IDG Magazine Media GmbH ) C:\Users\Thomas Keune\Downloads\pcwFixWindowsUpdate.exe
2017-02-21 06:17 - 2017-02-21 06:17 - 00000000 ____D C:\Users\Thomas Keune\Documents\Virensuche
2017-02-21 06:01 - 2017-02-21 06:15 - 00086974 _____ C:\TDSSKiller.3.1.0.12_21.02.2017_06.01.19_log.txt
2017-02-20 23:15 - 2017-02-20 23:21 - 00087644 _____ C:\TDSSKiller.3.1.0.12_20.02.2017_23.15.34_log.txt
2017-02-20 21:24 - 2017-02-21 06:30 - 148750096 _____ (Microsoft Corporation) C:\Users\Thomas Keune\Downloads\msert(1).exe
2017-02-20 18:12 - 2017-02-21 05:53 - 00000000 ____D C:\Users\Thomas Keune\AppData\Local\ESET
2017-02-20 18:11 - 2017-02-20 18:12 - 06776960 _____ (ESET spol. s r.o.) C:\Users\Thomas Keune\Downloads\ESETOnlineScanner_DEU.exe
2017-02-20 18:09 - 2017-02-20 18:09 - 00054620 _____ C:\Users\Thomas Keune\Documents\cc_20170220_180907.reg
2017-02-20 17:53 - 2017-02-20 17:53 - 00000000 ____D C:\Program Files (x86)\ESET
2017-02-20 17:32 - 2017-02-20 17:52 - 02870984 _____ (ESET) C:\Users\Thomas Keune\Downloads\esetsmartinstaller_deu.exe
2017-02-20 17:10 - 2017-02-22 11:50 - 00000632 _____ C:\Users\Thomas Keune\Desktop\JRT.txt
2017-02-20 17:01 - 2017-02-20 17:04 - 01663040 _____ (Malwarebytes) C:\Users\Thomas Keune\Downloads\JRT.exe
2017-02-20 16:41 - 2017-02-22 11:35 - 00000000 ____D C:\AdwCleaner
2017-02-20 16:40 - 2017-02-20 16:41 - 04015056 _____ C:\Users\Thomas Keune\Downloads\AdwCleaner_6.043.exe
2017-02-20 16:07 - 2017-02-20 16:07 - 00000000 ____D C:\Users\Thomas Keune\Desktop\FRST-OlderVersion
2017-02-20 09:23 - 2017-02-22 21:11 - 00000000 ____D C:\Windows\Microsoft Antimalware
2017-02-20 09:02 - 2017-02-20 09:04 - 47683808 _____ (Microsoft Corporation) C:\Users\Thomas Keune\Downloads\Windows-KB890830-x64-V5.44.exe
2017-02-16 08:33 - 2017-02-16 08:49 - 00087426 _____ C:\TDSSKiller.3.1.0.12_16.02.2017_08.33.24_log.txt
2017-02-15 16:36 - 2017-02-15 16:41 - 00087434 _____ C:\TDSSKiller.3.1.0.12_15.02.2017_16.36.49_log.txt
2017-02-15 16:32 - 2017-02-15 16:35 - 00010384 _____ C:\TDSSKiller.3.1.0.12_15.02.2017_16.32.33_log.txt
2017-02-15 15:12 - 2017-02-15 16:32 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Thomas Keune\Desktop\tdsskiller.exe
2017-02-15 15:12 - 2017-02-15 15:13 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Thomas Keune\Desktop\mbar-1.09.3.1001.exe
2017-02-15 09:25 - 2017-02-15 09:25 - 00000000 ____D C:\Users\Thomas Keune\AppData\Local\Chromium
2017-02-15 09:23 - 2017-01-20 19:39 - 00156608 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2017-02-15 09:23 - 2017-01-20 19:39 - 00124352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2017-02-15 09:23 - 2017-01-20 19:39 - 00057792 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2017-02-15 09:23 - 2017-01-20 14:36 - 00001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2017-02-15 08:36 - 2017-02-15 10:52 - 253966464 _____ C:\Users\Thomas Keune\Downloads\avira_antivirus_de-de.exe
2017-02-15 08:34 - 2017-02-15 08:34 - 02983904 _____ (Avira Operations GmbH & Co. KG) C:\Users\Thomas Keune\Downloads\avira_registry_cleaner_de(2).exe
2017-02-15 08:33 - 2017-02-15 12:24 - 02983904 _____ (Avira Operations GmbH & Co. KG) C:\Users\Thomas Keune\Downloads\avira_registry_cleaner_de(1).exe
2017-02-14 22:24 - 2017-02-14 22:24 - 00681536 _____ (O&O Software GmbH) C:\Users\Thomas Keune\Downloads\OOSU10.exe
2017-02-14 21:02 - 2017-02-20 16:13 - 00084452 _____ C:\Users\Thomas Keune\Desktop\Addition.txt
2017-02-14 20:59 - 2017-02-22 21:42 - 00028141 _____ C:\Users\Thomas Keune\Desktop\FRST.txt
2017-02-14 20:58 - 2017-02-22 21:40 - 00000000 ____D C:\FRST
2017-02-14 17:49 - 2017-02-14 18:16 - 00000000 ____D C:\ProgramData\Emsisoft
2017-02-14 17:49 - 2017-02-14 17:49 - 00000901 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2017-02-14 17:48 - 2017-02-22 21:33 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2017-02-14 17:45 - 2017-02-14 17:48 - 242868632 _____ (Emsisoft Ltd. ) C:\Users\Thomas Keune\Downloads\EmsisoftAntiMalwareSetup(1).exe
2017-02-14 17:32 - 2017-02-14 17:32 - 00108673 _____ C:\Users\Thomas Keune\Desktop\EmsiClean_2017.02.14_17.32.26.txt
2017-02-14 17:31 - 2017-02-14 17:31 - 00641240 _____ (Emsisoft Ltd) C:\Users\Thomas Keune\Desktop\emsiclean.exe
2017-02-14 16:51 - 2017-02-14 16:51 - 00000000 __SHD C:\found.001
2017-02-14 15:38 - 2017-02-14 16:00 - 242868632 _____ (Emsisoft Ltd. ) C:\Users\Thomas Keune\Downloads\EmsisoftAntiMalwareSetup.exe
2017-02-14 10:31 - 2017-02-14 10:31 - 04713984 _____ (Geza Kovacs) C:\Users\Thomas Keune\Downloads\unetbootin-windows-625.exe
2017-02-14 10:07 - 2017-02-20 16:49 - 00000000 ____D C:\ProgramData\Lavasoft
2017-02-14 10:07 - 2017-02-14 10:15 - 702468096 _____ C:\Users\Thomas Keune\Downloads\rescue916-system.iso
2017-02-14 09:35 - 2017-02-14 09:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2017-02-14 09:31 - 2017-02-14 09:31 - 00000000 __RHD C:\MSOCache
2017-02-14 08:55 - 2017-02-15 09:24 - 00003884 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-02-14 08:55 - 2017-02-15 09:23 - 00003894 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-02-14 08:55 - 2017-02-15 09:23 - 00003866 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-02-14 08:55 - 2017-02-15 09:23 - 00003858 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-02-14 08:55 - 2017-02-15 09:23 - 00003696 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-02-14 08:55 - 2017-02-15 09:23 - 00003654 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-02-14 08:54 - 2017-02-14 08:54 - 00002170 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2017-02-14 08:54 - 2017-01-20 15:07 - 00134080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2017-02-14 08:53 - 2017-02-14 08:53 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-02-14 08:53 - 2017-01-20 17:38 - 00514616 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2017-02-14 08:53 - 2017-01-20 17:38 - 00420408 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2017-02-14 08:53 - 2017-01-20 16:13 - 00548800 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2017-02-14 08:53 - 2017-01-20 16:13 - 00083512 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2017-02-14 08:53 - 2017-01-20 15:07 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
2017-02-14 08:53 - 2016-12-16 01:33 - 00273696 _____ C:\Windows\SysWOW64\vulkan-1.dll
2017-02-14 08:53 - 2016-12-16 01:33 - 00266528 _____ C:\Windows\system32\vulkan-1.dll
2017-02-14 08:53 - 2016-12-16 01:33 - 00111392 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2017-02-14 08:53 - 2016-12-16 01:32 - 00125728 _____ C:\Windows\system32\vulkaninfo.exe
2017-02-14 08:50 - 2017-01-24 01:00 - 00047664 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 40192056 _____ C:\Windows\system32\nvcompiler.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 35272760 _____ C:\Windows\SysWOW64\nvcompiler.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 34974656 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 28239928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 19008576 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 14677272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 11123936 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 11019192 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 09308896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 08990584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 04079032 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 03597640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 03167288 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 02715072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 01985080 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437849.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 01591352 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437849.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 01051584 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 00988608 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 00960568 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 00909760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 00687224 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 00576192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2017-02-14 08:50 - 2017-01-20 17:38 - 00000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2017-02-14 08:50 - 2017-01-20 17:38 - 00000669 _____ C:\Windows\system32\nv-vk64.json
2017-02-14 08:46 - 2017-02-14 09:01 - 04581024 _____ (Avira Operations GmbH & Co. KG) C:\Users\Thomas Keune\Downloads\avira_de_isec0_58a2b5e13e36d__wsd.exe
2017-02-14 08:34 - 2017-02-14 08:34 - 00097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2017-02-14 08:33 - 2017-02-14 08:46 - 398382600 _____ (NVIDIA Corporation) C:\Users\Thomas Keune\Downloads\378.49-desktop-win10-64bit-international-whql.exe
2017-02-14 08:27 - 2017-02-14 08:28 - 00739392 _____ (Oracle Corporation) C:\Users\Thomas Keune\Downloads\JavaSetup8u121.exe
2017-02-14 08:24 - 2017-02-14 08:23 - 00110144 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-64.dll
2017-02-14 08:21 - 2017-02-14 08:21 - 01181390 _____ C:\Users\Thomas Keune\Documents\cc_20170214_082136.reg
2017-02-13 22:43 - 2017-02-14 08:54 - 00000000 ____D C:\Windows\LastGood
2017-02-13 21:53 - 2017-02-13 21:53 - 01201256 _____ (Adobe Systems Incorporated) C:\Users\Thomas Keune\Downloads\flashplayer24au_ha_install(1).exe
2017-02-13 21:52 - 2017-02-13 22:11 - 00000000 ____D C:\Windows\LastGood.Tmp
2017-02-13 21:19 - 2017-02-13 21:27 - 00000000 ____D C:\Users\Thomas Keune\Downloads\CHIP_Update_Pack_Windows_10_64_Bit_Jan
2017-02-13 20:21 - 2017-02-13 21:19 - 160718565 _____ C:\Users\Thomas Keune\Downloads\CHIP_Update_Pack_Windows_10_64_Bit_Jan.zip
2017-02-13 16:14 - 2017-02-13 16:14 - 00000000 ____D C:\$WINDOWS.~BT
2017-02-13 13:33 - 2017-02-13 13:33 - 00000000 ___HD C:\$SysReset
2017-02-10 08:41 - 2017-02-15 09:23 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-02-03 18:55 - 2017-02-03 19:24 - 63184896 _____ C:\Users\Thomas Keune\Downloads\calibre-2.78.0.msi
2017-02-03 14:58 - 2017-02-03 14:58 - 00035784 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\tap0901.sys
2017-02-03 09:06 - 2017-02-03 09:06 - 00000000 ____D C:\Users\Thomas Keune\Downloads\MediathekView-13.0.1
2017-02-03 09:05 - 2017-02-03 09:05 - 27674457 _____ C:\Users\Thomas Keune\Downloads\MediathekView-13.0.1.zip
2017-01-31 21:15 - 2017-01-31 21:15 - 00082348 _____ C:\Users\Thomas Keune\Downloads\CheapTickets.de - E-ticket CDE-3125487.zip
2017-01-31 21:15 - 2017-01-31 21:15 - 00042295 _____ C:\Users\Thomas Keune\Downloads\CheapTickets.de - Bestätigung Ihrer Reservierung CDE-3125487.zip
2017-01-31 21:11 - 2017-01-31 21:11 - 00050990 _____ C:\Users\Thomas Keune\Downloads\JP793, FRA-TIA, 17NOV16, 08_55, GTB59, S13A, Mobile Boarding Pass.zip
2017-01-28 11:16 - 2016-12-21 08:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2017-01-28 11:16 - 2016-12-21 05:44 - 00120320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2017-01-26 11:31 - 2017-01-26 11:31 - 01995824 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437667.dll
2017-01-26 11:31 - 2017-01-26 11:31 - 01600048 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437667.dll
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-02-22 21:40 - 2016-10-14 03:32 - 00000000 ____D C:\ProgramData\NVIDIA
2017-02-22 21:37 - 2016-11-07 11:48 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-22 21:36 - 2016-11-22 15:29 - 00000000 ____D C:\Users\Thomas Keune\AppData\LocalLow\Mozilla
2017-02-22 21:33 - 2012-04-15 16:43 - 00000000 ____D C:\Users\Thomas Keune\AppData\Roaming\JFritz
2017-02-22 21:33 - 2011-12-29 14:27 - 00000000 ____D C:\Users\Thomas Keune\AppData\Local\FreePDF_XP
2017-02-22 21:32 - 2014-10-25 13:22 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-02-22 21:29 - 2016-10-14 04:07 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-02-22 21:29 - 2016-10-14 03:29 - 00000000 ____D C:\Windows\system32\SleepStudy
2017-02-22 21:15 - 2016-07-16 12:45 - 00000000 ____D C:\Windows\INF
2017-02-22 12:02 - 2016-07-16 07:04 - 01310720 _____ C:\Windows\system32\config\BBI
2017-02-22 07:04 - 2016-10-21 15:11 - 00000000 ____D C:\Windows\Minidump
2017-02-22 07:04 - 2016-07-16 12:47 - 00000000 ____D C:\Windows\LiveKernelReports
2017-02-21 20:54 - 2016-07-16 12:47 - 00000000 ____D C:\Windows\system32\NDF
2017-02-21 18:37 - 2011-12-24 10:35 - 00000000 ____D C:\Users\Thomas Keune\AppData\Local\FRITZ!
2017-02-21 06:53 - 2015-02-14 12:52 - 00000000 ____D C:\Users\Thomas Keune\Documents\Visaanträge
2017-02-21 05:59 - 2014-01-14 06:59 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-02-21 05:55 - 2016-07-16 12:47 - 00000000 ____D C:\Windows\AppReadiness
2017-02-21 05:52 - 2014-05-30 08:36 - 00000000 ____D C:\Windows\PixArt
2017-02-20 23:05 - 2011-12-27 09:00 - 00000000 ____D C:\Users\Thomas Keune\AppData\Roaming\DVDVideoSoft
2017-02-20 22:27 - 2011-12-25 13:19 - 00000000 ____D C:\Users\Thomas Keune\Documents\Calibre Library
2017-02-20 19:49 - 2016-09-20 20:02 - 00000000 ____D C:\Users\Thomas Keune\Documents\Scheidung-Alida
2017-02-20 18:03 - 2013-04-07 09:21 - 00000000 ____D C:\Users\Thomas Keune\AppData\Local\CrashDumps
2017-02-20 16:33 - 2014-01-14 06:58 - 00000000 ____D C:\Users\Thomas Keune\Desktop\mbar
2017-02-20 09:38 - 2011-03-14 15:08 - 135657872 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-02-19 21:24 - 2016-12-13 20:18 - 00000000 ____D C:\Users\Thomas Keune\Documents\Sicherung VR-Networld
2017-02-19 21:24 - 2011-12-23 20:07 - 00000000 ____D C:\Users\Public\Documents\VR-NetWorld
2017-02-19 20:00 - 2016-01-02 06:52 - 00000000 ____D C:\Users\Thomas Keune\Documents\Bestellungen
2017-02-19 19:10 - 2016-11-09 01:17 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-15 13:44 - 2016-11-06 18:29 - 00000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2017-02-15 13:34 - 2016-03-13 16:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-02-15 13:34 - 2015-12-30 11:31 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-15 13:34 - 2014-11-01 17:24 - 00000000 ____D C:\Users\Thomas Keune\AppData\Roaming\Avira
2017-02-15 11:59 - 2016-07-16 07:04 - 00032768 _____ C:\Windows\system32\config\ELAM
2017-02-15 11:58 - 2014-01-13 06:43 - 00000000 ____D C:\Windows\pss
2017-02-15 09:27 - 2016-07-16 23:51 - 01275756 _____ C:\Windows\system32\perfh007.dat
2017-02-15 09:27 - 2016-07-16 23:51 - 00321052 _____ C:\Windows\system32\perfc007.dat
2017-02-15 09:27 - 2016-01-06 20:25 - 02965156 _____ C:\Windows\system32\PerfStringBackup.INI
2017-02-15 09:26 - 2015-03-22 15:30 - 00000000 ____D C:\Users\Thomas Keune\AppData\Local\NVIDIA
2017-02-15 09:25 - 2016-10-14 03:31 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-02-15 09:25 - 2015-03-22 15:31 - 00000000 ____D C:\Users\Thomas Keune\AppData\Local\NVIDIA Corporation
2017-02-15 09:25 - 2015-03-22 15:30 - 00001449 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2017-02-15 09:23 - 2016-10-14 03:31 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-02-15 07:49 - 2016-03-22 11:41 - 00000424 _____ C:\Users\Thomas Keune\Desktop\Dieser PC - Verknüpfung.lnk
2017-02-15 07:20 - 2012-10-06 15:01 - 00000000 ____D C:\Users\Thomas Keune\MEDION NAS TOOL
2017-02-14 17:49 - 2013-08-19 14:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2017-02-14 17:16 - 2016-10-14 03:38 - 00000000 ____D C:\Users\Thomas Keune
2017-02-14 14:33 - 2016-07-14 20:03 - 00000000 ____D C:\Users\Thomas Keune\Documents\alida@keune.info
2017-02-14 09:45 - 2016-10-14 03:29 - 00399824 _____ C:\Windows\system32\FNTCACHE.DAT
2017-02-14 08:54 - 2015-03-22 15:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-02-14 08:43 - 2016-04-09 17:44 - 04734128 _____ (Avira Operations GmbH & Co. KG) C:\Users\Thomas Keune\Downloads\avira_de_avpn0_570931d1a801d__ws.exe
2017-02-14 08:42 - 2016-04-15 07:21 - 04734128 _____ (Avira Operations GmbH & Co. KG) C:\Users\Thomas Keune\Downloads\avira_de_ispm0_3017605605_6e4tda59yy4v1w5mn34a_wd.exe
2017-02-14 08:42 - 2014-10-23 14:38 - 168004048 _____ C:\Users\Thomas Keune\Downloads\avira_antivirus_pro_de.exe
2017-02-14 08:37 - 2013-12-18 09:58 - 00000000 ____D C:\ProgramData\Oracle
2017-02-14 08:34 - 2013-12-18 09:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-02-14 08:33 - 2011-12-25 22:15 - 00000000 ____D C:\Program Files (x86)\Java
2017-02-14 08:23 - 2016-11-06 20:55 - 00000000 ____D C:\Program Files\Java
2017-02-14 08:23 - 2016-02-04 16:09 - 00110144 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2017-02-13 23:02 - 2016-11-06 16:44 - 04479640 _____ (Avira Operations GmbH & Co. KG) C:\Users\Thomas Keune\Downloads\avira_de_asu60_581f4fd2262c1__ws.exe
2017-02-13 23:01 - 2016-11-06 19:19 - 04479640 _____ (Avira Operations GmbH & Co. KG) C:\Users\Thomas Keune\Downloads\avira_de_issudl_581f4fd2262c1__wsd.exe
2017-02-13 22:40 - 2016-04-15 07:29 - 00000000 ____D C:\Users\Thomas Keune\AppData\Local\Avira
2017-02-13 21:30 - 2011-12-26 10:12 - 00000000 ____D C:\Users\Thomas Keune\AppData\Local\ElevatedDiagnostics
2017-02-13 21:29 - 2016-11-08 20:35 - 00000006 _____ C:\ScrubRetValFile.txt
2017-02-13 21:16 - 2015-10-30 19:44 - 00000000 ____D C:\Windows\ShellNew
2017-02-13 16:14 - 2016-10-14 04:26 - 00000000 ___DC C:\Windows\Panther
2017-02-13 16:08 - 2016-10-14 04:09 - 00001908 _____ C:\Windows\diagwrn.xml
2017-02-13 16:08 - 2016-10-14 04:09 - 00001908 _____ C:\Windows\diagerr.xml
2017-02-13 16:04 - 2016-07-16 12:36 - 00000000 ____D C:\Windows\CbsTemp
2017-02-13 13:46 - 2016-11-22 17:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2017-02-13 13:46 - 2012-05-04 03:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-02-12 19:56 - 2016-10-14 03:38 - 00000000 ____D C:\Users\DefaultAppPool
2017-02-12 19:51 - 2016-07-16 12:47 - 00000000 ____D C:\Windows\registration
2017-02-12 18:28 - 2011-12-26 13:36 - 00000000 ____D C:\Users\Thomas Keune\Desktop\Briefe
2017-02-11 14:32 - 2016-12-01 08:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-02-11 14:03 - 2013-05-19 13:08 - 00000000 ____D C:\Users\Thomas Keune\Desktop\Alte Firefox-Daten
2017-02-10 18:42 - 2016-11-06 10:53 - 00000000 ____D C:\Users\Thomas Keune\Downloads\Musik
2017-02-03 19:59 - 2012-01-21 12:20 - 00000000 ____D C:\Users\Thomas Keune\Documents\Briefe
2017-02-03 19:26 - 2016-11-14 08:37 - 00000000 ____D C:\Program Files (x86)\Calibre2
2017-02-03 19:26 - 2015-07-03 06:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management
2017-02-03 19:26 - 2014-01-18 10:33 - 00000993 _____ C:\Users\Public\Desktop\calibre - E-book management.lnk
2017-02-03 09:07 - 2014-02-17 09:42 - 00000000 ____D C:\Users\Thomas Keune\.mediathek3
2017-01-31 20:02 - 2016-11-06 10:44 - 00000935 _____ C:\Users\Thomas Keune\Desktop\Video Downloader Ultimate.lnk
2017-01-31 20:02 - 2016-11-06 10:44 - 00000000 _____ C:\Users\Thomas Keune\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Video Downloader Ultimate.lnk
2017-01-24 01:00 - 2015-04-16 19:03 - 00217528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2017-01-24 01:00 - 2015-04-16 07:19 - 01600056 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2014-01-26 19:41 - 2015-12-30 11:29 - 0000000 _____ () C:\Users\Thomas Keune\AppData\Roaming\Basic Synth
2012-04-15 16:43 - 2013-01-14 10:51 - 0000000 _____ () C:\Users\Thomas Keune\AppData\Roaming\JFritz.lock
2012-01-26 12:08 - 2012-01-26 12:08 - 0033134 _____ () C:\Users\Thomas Keune\AppData\Roaming\UserTile.png
2014-10-26 17:51 - 2017-01-02 14:58 - 0003584 _____ () C:\Users\Thomas Keune\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-11-22 13:03 - 2015-11-22 13:03 - 0000036 _____ () C:\Users\Thomas Keune\AppData\Local\housecall.guid.cache
2017-01-02 23:01 - 2017-01-02 23:01 - 0000600 _____ () C:\Users\Thomas Keune\AppData\Local\PUTTY.RND
2015-04-27 12:44 - 2015-04-27 12:44 - 0002065 _____ () C:\Users\Thomas Keune\AppData\Local\recently-used.xbel
2012-10-11 08:33 - 2016-05-10 05:58 - 0000040 ___SH () C:\ProgramData\.zreglib
2013-02-25 18:01 - 2013-02-25 18:01 - 0000057 _____ () C:\ProgramData\Ament.ini
2016-10-14 03:32 - 2016-10-14 03:32 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2012-01-22 12:40 - 2016-11-07 07:42 - 0006058 _____ () C:\ProgramData\hpzinstall.log
2014-01-26 19:41 - 2015-12-30 11:29 - 0000000 ____H () C:\ProgramData\PKP_DLeo.DAT
2014-01-26 19:42 - 2015-12-30 11:28 - 0000000 ____H () C:\ProgramData\PKP_DLes.DAT
2014-01-26 19:42 - 2016-11-08 19:52 - 0000000 ____H () C:\ProgramData\PKP_DLet.DAT
2014-01-26 19:42 - 2016-11-08 19:52 - 0000000 ____H () C:\ProgramData\PKP_DLev.DAT
ZeroAccess:
C:\Users\Thomas Keune\AppData\Local\13d278f4
Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Users\Thomas Keune\fritzDummy.reg
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2017-02-15 08:07
==================== Ende von FRST.txt ============================ |