Brettkopp | 28.02.2017 20:45 | Hi Matthias, danke für deine Hilfe. Hier sind die gewünschten Logs. MBAM Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 28.02.2017
Suchlaufzeit: 14:20
Protokolldatei: MBAM.txt
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2017.02.28.06
Rootkit-Datenbank: v2017.02.27.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Username
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 347044
Abgelaufene Zeit: 21 Min., 7 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 5
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\Downloads, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\Downloads\fc14996dfa99adfc7baae624196888c5, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\Downloads\fc14996dfa99adfc7baae624196888c5\380b14beb7cb44d132a4a89ce089ea87, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\Downloads\fc14996dfa99adfc7baae624196888c5\a8121016752761ffea4c707352975735, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Dateien: 28
PUP.Optional.Somoto, C:\Users\Username\AppData\Local\Temp\bitool.dll, In Quarantäne, [4313990f36722c0a6d6de591f70bd42c],
PUP.Optional.OpenCandy, C:\Users\Username\AppData\Local\Temp\DTLite4481-0347.exe, In Quarantäne, [d680f6b21197ce68cd94e6437c888977],
PUP.Optional.OpenCandy, C:\Users\Username\AppData\Local\Temp\DTLite4491-0356.exe, In Quarantäne, [76e0099f0f99fb3b80e143e6a55f6d93],
Adware.DealPly.Generic, C:\Users\Username\AppData\Local\Temp\ns7402FA9C\2B476673_stp\setup.exe, In Quarantäne, [d1856246eabeef47513b5e8cc0409070],
PUP.Optional.Babylon, C:\Users\Username\AppData\Local\Temp\is1070216317\128767833_stp\DeltaTB.exe, In Quarantäne, [a0b6c1e78a1e58de833b824629d88f71],
PUP.Optional.WebConnect, C:\Users\Username\AppData\Local\Temp\is1070216317\128767945_stp\WebConnect.exe, In Quarantäne, [6de9baee9315a393dfc0dc218c77857b],
PUP.Optional.SearchHijacker, C:\Users\Username\AppData\Local\Temp\is1201216051\4917F1FD_stp\June10_www.sweet-page.com.exe, In Quarantäne, [72e4bbed505893a3c9d1498228d93ec2],
PUP.Optional.SearchHijacker, C:\Users\Username\AppData\Local\Temp\is1901864539\4917F1FD_stp\June10_www.sweet-page.com.exe, In Quarantäne, [f95d5e4aaff9fb3bb7e33c8f7e83d030],
PUP.Optional.InstallCore, C:\Users\Username\AppData\Local\Temp\is961225091\MySearchDial.exe, In Quarantäne, [12445553adfb58de980fa5329968768a],
PUP.Optional.BestToolBars, C:\Users\Username\AppData\Local\Temp\_ir_sf_temp_0\freecorder.ie.exe, In Quarantäne, [36203f69d9cf70c67f46d7f1738e7b85],
PUP.Optional.DownloadSponsor, C:\Users\Username\Downloads\SpeedFan - CHIP-Installer.exe, In Quarantäne, [20366a3e7830d165d250e8c77789f20e],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\iufunzgtaoqzikud.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\dmr_72.exe, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\ivybfnlclegrktoc.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\ivzcamuzgiahzddj.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\jnmqwxywrbkgzsjy.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\noyderfeqtfkxbjv.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\phffdkfzcxbstxax.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\qmdovixnyaesxfsv.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\qsfxqutuomyxoehz.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\qxdbjwoztrhscchu.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\shjbrfccexjmjsku.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\ycoteajccabonipd.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\yfjzdnbnsgyxzzpa.dat, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\Downloads\fc14996dfa99adfc7baae624196888c5\380b14beb7cb44d132a4a89ce089ea87\fdminst395.exe, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
Adware.ChinAd, C:\Users\Username\AppData\Local\Temp\DMR\Downloads\fc14996dfa99adfc7baae624196888c5\a8121016752761ffea4c707352975735\foobar2000_v1.3.7.exe, In Quarantäne, [b6a045631197cb6b0b69a631c9389b65],
PUP.Optional.BundleInstaller, C:\Users\Username\AppData\Local\Temp\binsis142.xml, In Quarantäne, [4f0716923e6a51e59fccbd15946f42be],
PUP.Optional.BundleInstaller, C:\Users\Username\AppData\Local\Temp\binsischeck654.xml, In Quarantäne, [afa744648b1d280eb0bce0f257ac60a0],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) FRST: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 27-02-2017 01
durchgeführt von Username (Administrator) auf Username-PC (28-02-2017 19:48:05)
Gestartet von C:\Users\Username\Downloads
Geladene Profile: Username (Verfügbare Profile: Username)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Windows\Runservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
() D:\Programme\CoreTemp\Core Temp.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsAgent.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsClient.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Data Recorder\SDRService.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos System Protection\ssp.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(CyberGhost S.R.L) C:\Program Files\CyberGhost 6\CyberGhost.Service.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Disc Soft Ltd) D:\Programme\Daemon Tools Lite\DTLite.exe
(Sync and Share NRW ) D:\Programme\sciebo\sciebo.exe
(CyberGhost S.R.L.) C:\Program Files\CyberGhost 6\CyberGhost.exe
(Dropbox, Inc.) C:\Users\Username\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(The OpenVPN Project) C:\Program Files\CyberGhost 6\Data\OpenVPN\openvpn.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(EJIE Technology) D:\Programme\clover\clover.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Don HO don.h@free.fr) D:\Programme\Notepad++\notepad++.exe
==================== Registry (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [8027016 2016-09-16] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [JMB36X IDE Setup] => C:\Windows\RaidTool\xInsIDE.exe [43608 2000-01-01] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [1480168 2017-02-02] (Sophos Limited)
HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\Run: [DAEMON Tools Lite] => D:\Programme\Daemon Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\Run: [Dropbox Update] => C:\Users\Username\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-30] (Dropbox, Inc.)
HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\Run: [sciebo] => D:\Programme\sciebo\sciebo.exe [39619077 2016-10-06] (Sync and Share NRW )
HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 6\CyberGhost.exe [1223728 2017-02-06] (CyberGhost S.R.L.)
HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\MountPoints2: I - I:\setup.exe
HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\MountPoints2: {8a4cfe96-50ca-11e4-aed7-0025220fb9e5} - I:\setup.exe
HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\...\MountPoints2: {fa7931b5-1893-11e3-8ac7-0025220fb9e5} - I:\Install\Install.exe
ShellIconOverlayIdentifiers: [ OCError] -> {0960F090-F328-48A3-B746-276B1E3C3722} => d:\Programme\sciebo\shellext\OCOverlays_x64.dll [2016-08-23] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [ OCOK] -> {0960F092-F328-48A3-B746-276B1E3C3722} => d:\Programme\sciebo\shellext\OCOverlays_x64.dll [2016-08-23] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [ OCOKShared] -> {0960F093-F328-48A3-B746-276B1E3C3722} => d:\Programme\sciebo\shellext\OCOverlays_x64.dll [2016-08-23] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [ OCSync] -> {0960F094-F328-48A3-B746-276B1E3C3722} => d:\Programme\sciebo\shellext\OCOverlays_x64.dll [2016-08-23] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [ OCWarning] -> {0960F096-F328-48A3-B746-276B1E3C3722} => d:\Programme\sciebo\shellext\OCOverlays_x64.dll [2016-08-23] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => D:\Programme\Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2 (GFS Stub)] -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => D:\Programme\Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => D:\Programme\Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 3 (GFS Folder)] -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => D:\Programme\Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => D:\Programme\Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Username\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
Startup: C:\Users\Username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2017-02-27]
ShortcutTarget: Dropbox.lnk -> C:\Users\Username\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited)
Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited)
Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited)
Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited)
Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited)
Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited)
Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited)
Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited)
Winsock: Catalog9 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [139832 2016-12-01] (Sophos Limited)
Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited)
Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited)
Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited)
Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited)
Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited)
Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited)
Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited)
Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited)
Winsock: Catalog9-x64 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [198016 2016-12-01] (Sophos Limited)
Tcpip\Parameters: [DhcpNameServer] 185.156.172.178 185.93.180.131 83.143.245.42
Tcpip\..\Interfaces\{1864234F-DFB0-4F2E-8D6F-AE04B221BA35}: [NameServer] 185.156.172.178,185.93.180.131
Tcpip\..\Interfaces\{1864234F-DFB0-4F2E-8D6F-AE04B221BA35}: [DhcpNameServer] 185.156.172.178 185.93.180.131 83.143.245.42
Tcpip\..\Interfaces\{2521E38E-D27C-4323-9E3A-81AA7AEE3AD7}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{E1F97774-19F8-4258-812B-0606B2661549}: [NameServer] 185.156.172.178,185.93.180.131
Tcpip\..\Interfaces\{E1F97774-19F8-4258-812B-0606B2661549}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3719417004-2107331891-2675601930-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> D:\Programme\Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-09-27] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Programme\Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-27] (Oracle Corporation)
BHO: ExplorerWatcher Class -> {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} -> d:\programme\clover\TabHelper64.dll [2014-01-23] (EJIE Technology)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-27] (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-27] (Oracle Corporation)
Toolbar: HKLM - Kein Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - Keine Datei
Toolbar: HKLM-x32 - Kein Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - Keine Datei
Toolbar: HKU\S-1-5-21-3719417004-2107331891-2675601930-1000 -> Kein Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - Keine Datei
FireFox:
========
FF DefaultProfile: lklm8bap.default
FF ProfilePath: C:\Users\Username\AppData\Roaming\Mozilla\Firefox\Profiles\lklm8bap.default [2017-02-28]
FF Homepage: Mozilla\Firefox\Profiles\lklm8bap.default -> hxxp://www.google.com
FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\Username\AppData\Roaming\Mozilla\Firefox\Profiles\lklm8bap.default\features\{1bae0e8a-aee3-4449-bec4-8c2f1265f06b}\disableSHA1rollout@mozilla.org.xpi [2017-02-26]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-14] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> d:\programme\PDF X-Change Viewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-11-08] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-27] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-27] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> D:\PROGRA~1\Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 -> d:\programme\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> d:\programme\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> d:\programme\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> d:\programme\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [Keine Datei]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-14] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> d:\programme\PDF X-Change Viewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2013-11-08] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll [2014-04-10] (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-27] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-01-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3719417004-2107331891-2675601930-1000: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> d:\programme\PDF X-Change Viewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2013-11-08] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-3719417004-2107331891-2675601930-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Username\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-01-23] (Unity Technologies ApS)
StartMenuInternet: FIREFOX.EXE - D:\programme\Firefox\firefox.exe
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://search.disconnect.me/"
CHR Session Restore: Default -> ist aktiviert.
CHR Profile: C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default [2017-02-28]
CHR Extension: (Simple Blocker) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\akfbkbiialncppkngofjpglbbobjoeoe [2016-08-22]
CHR Extension: (Google Docs) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Google Drive) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Adblock Plus) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-12-01]
CHR Extension: (Google-Suche) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Google Docs Offline) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (Inoreader - RSS, News and Social Reader) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhglljfmpijadbpkalkclnhlncncdono [2015-03-30]
CHR Extension: (Disconnect Search) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmobfennjmjnkdbklhcnnfbhfibedgkk [2016-08-25]
CHR Extension: (WEB.DE MailCheck) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo [2017-01-13]
CHR Extension: (Disconnect) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo [2016-01-22]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-19]
CHR Extension: (Adult Blocker) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\onjjgbgnpbedmhbdoikhknhflbfkecjm [2017-02-25]
CHR Extension: (Google Mail) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR Extension: (Chrome Media Router) - C:\Users\Username\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-28]
CHR HKLM-x32\...\Chrome\Extension: [dhhejlifdlcgcmogbggeomfodgklfaem] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fabcmochhfpldjekobfaaggijgohadih] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1860616 2016-06-17] ()
R2 CG6Service; C:\Program Files\CyberGhost 6\CyberGhost.Service.exe [76848 2017-02-06] (CyberGhost S.R.L)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [242960 2016-06-05] (EasyAntiCheat Ltd)
R2 LicCtrlService; C:\Windows\runservice.exe [2560 2014-11-10] () [Datei ist nicht signiert]
S3 Microsoft SharePoint Workspace Audit Service; D:\programme\Office\Office14\GROOVE.EXE [50942144 2013-12-18] (Microsoft Corporation)
S3 Origin Client Service; D:\Spiele\Origin\OriginClientService.exe [2120712 2016-06-08] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-10] ()
R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [229672 2016-10-25] (Sophos Limited)
R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [200064 2016-10-25] (Sophos Limited)
S2 SkypeUpdate; D:\programme\Skype\Updater\Updater.exe [315496 2014-12-11] (Skype Technologies)
R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [780424 2017-02-02] (Sophos Limited)
R2 Sophos MCS Agent; C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsAgent.exe [1379856 2016-12-01] (Sophos Limited)
R2 Sophos MCS Client; C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsClient.exe [1805368 2016-12-01] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [360040 2016-09-13] (Sophos Limited)
R2 SophosDataRecorderService; C:\Program Files\Sophos\Sophos Data Recorder\SDRService.exe [996240 2016-12-01] (Sophos Limited)
R2 sophossps; C:\Program Files\Sophos\Sophos System Protection\ssp.exe [5366040 2016-12-01] (Sophos Limited)
R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3644368 2016-09-13] (Sophos Limited)
S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2121224 2016-09-13] (Sophos Limited)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-08-17] (Microsoft Corporation)
S2 AdobeARMservice; "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 AsrVDrive; C:\Windows\System32\DRIVERS\AsrVDrive.sys [23048 2011-01-26] (ASRock Inc.)
R3 DGUSBAP; C:\Windows\System32\DRIVERS\dgmbx2.sys [194864 2011-02-13] (Avid Technology, Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-10-10] (Disc Soft Ltd)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [49304 2014-12-29] (Visicom Media Inc.)
R3 MBX2DFU; C:\Windows\System32\DRIVERS\dgmbx2fu.sys [32944 2011-02-13] (Avid Technology, Inc.)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35992 2014-12-29] (Visicom Media Inc.)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S3 RT61; C:\Windows\System32\DRIVERS\rt61.sys [438784 2009-06-02] (Ralink Technology, Corp.)
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [201168 2016-09-13] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [38144 2016-09-13] (Sophos Limited)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [27904 2016-09-13] (Sophos Limited)
R0 Tpkd; C:\Windows\SysWow64\Drivers\Tpkd.sys [86528 2008-07-02] (PACE Anti-Piracy, Inc.) [Datei ist nicht signiert]
R3 ALSysIO; \??\C:\Users\Username\AppData\Local\Temp\ALSysIO64.sys [X] <==== ACHTUNG
S3 b06bdrv; \SystemRoot\system32\drivers\bxvbda.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
S0 ignis; system32\DRIVERS\ignis.sys [X]
U3 swmidi; kein ImagePath
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-02-28 19:48 - 2017-02-28 19:48 - 00032435 _____ C:\Users\Username\Downloads\FRST.txt
2017-02-28 19:47 - 2017-02-28 19:48 - 00000000 ____D C:\FRST
2017-02-28 19:47 - 2017-02-28 19:47 - 02423296 _____ (Farbar) C:\Users\Username\Downloads\FRST64.exe
2017-02-28 19:45 - 2017-02-28 19:46 - 00005913 _____ C:\Users\Username\Desktop\MBAM.txt
2017-02-28 15:56 - 2017-02-28 15:56 - 01496584 _____ C:\Users\Username\Downloads\Ad Aware Free Antivirus - CHIP-Installer.exe
2017-02-28 15:54 - 2017-02-28 15:54 - 03516080 _____ (Enigma Software Group USA, LLC.) C:\Users\Username\Downloads\sh-remover.exe
2017-02-28 15:03 - 2017-02-28 15:03 - 00006525 _____ C:\Users\Username\Desktop\JRT.txt
2017-02-28 15:00 - 2017-02-28 15:00 - 01663040 _____ (Malwarebytes) C:\Users\Username\Downloads\JRT.exe
2017-02-28 14:19 - 2017-02-28 19:44 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-02-28 14:18 - 2017-02-28 14:18 - 00000731 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2017-02-28 14:18 - 2017-02-28 14:18 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-02-28 14:18 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2017-02-28 14:18 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2017-02-28 14:18 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-02-28 14:17 - 2017-02-28 14:18 - 22851472 _____ (Malwarebytes ) C:\Users\Username\Downloads\mbam-setup-2.2.1.1043.exe
2017-02-28 13:03 - 2017-02-28 13:43 - 00000000 ____D C:\AdwCleaner
2017-02-28 13:00 - 2017-02-28 13:01 - 04015056 _____ C:\Users\Username\Downloads\adwcleaner_6.043.exe
2017-02-27 21:00 - 2017-02-27 21:00 - 00000000 ____D C:\Users\Username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-02-24 21:56 - 2017-02-24 21:56 - 00000000 ____D C:\Users\Username\Documents\BioshockHD
2017-02-24 21:56 - 2017-02-24 21:56 - 00000000 ____D C:\Users\Username\AppData\Roaming\BioshockHD
2017-02-17 21:33 - 2017-02-17 21:33 - 00000000 ____D C:\Users\Username\Documents\Avalanche Studios
2017-02-13 11:57 - 2016-10-25 21:15 - 00044304 _____ (Sophos Limited) C:\Windows\system32\SophosBootTasks.exe
2017-02-03 21:18 - 2017-02-03 21:18 - 00000000 ____D C:\Users\Username\AppData\LocalLow\U-Play online
2017-02-03 20:05 - 2017-02-03 20:05 - 00000000 ____D C:\Users\Public\Documents\Steam
2017-02-03 20:05 - 2017-02-03 20:05 - 00000000 ____D C:\Users\Username\Documents\U-Play online
2017-01-30 20:06 - 2017-01-30 20:06 - 00274896 _____ C:\Windows\Minidump\013017-39968-01.dmp
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-02-28 19:28 - 2014-01-16 20:08 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-02-28 18:55 - 2015-06-18 09:45 - 00001224 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3719417004-2107331891-2675601930-1000UA.job
2017-02-28 17:09 - 2016-12-02 23:41 - 00000000 ____D C:\Users\Username\AppData\LocalLow\Mozilla
2017-02-28 16:23 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-02-28 16:23 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-02-28 16:17 - 2013-09-08 16:33 - 00000000 ___RD C:\Users\Username\Dropbox
2017-02-28 16:15 - 2015-12-06 14:33 - 00000000 ____D C:\Users\Username\AppData\Local\sciebo
2017-02-28 16:15 - 2014-11-10 17:52 - 00000857 ___SH C:\Windows\SysWOW64\mmf.sys
2017-02-28 16:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-02-28 15:08 - 2016-12-05 14:44 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2017-02-28 14:46 - 2015-12-06 14:34 - 00000000 ____D C:\Users\Username\sciebo
2017-02-28 14:44 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\addins
2017-02-27 21:00 - 2013-09-08 16:31 - 00000000 ____D C:\Users\Username\AppData\Roaming\Dropbox
2017-02-27 20:55 - 2015-06-18 09:45 - 00001172 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3719417004-2107331891-2675601930-1000Core.job
2017-02-26 00:03 - 2013-09-08 16:48 - 00000000 ____D C:\Users\Username\AppData\Roaming\vlc
2017-02-23 00:36 - 2016-12-02 21:09 - 00000000 ____D C:\Users\Username\AppData\Roaming\discord
2017-02-18 23:21 - 2014-02-13 01:47 - 00000000 ____D C:\Users\Username\Desktop\Musik smart
2017-02-14 16:28 - 2014-01-16 20:08 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-02-14 16:28 - 2014-01-16 20:08 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-02-14 16:28 - 2014-01-16 20:08 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-02-14 16:28 - 2014-01-16 20:08 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-02-14 16:28 - 2014-01-16 20:07 - 00000000 ____D C:\Windows\system32\Macromed
2017-02-13 11:57 - 2016-12-01 20:28 - 00000000 ____D C:\ProgramData\Sophos
2017-02-02 00:35 - 2013-09-08 15:21 - 00002187 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-01-30 20:06 - 2014-05-14 22:20 - 762790477 _____ C:\Windows\MEMORY.DMP
2017-01-30 20:06 - 2014-05-14 22:20 - 00000000 ____D C:\Windows\Minidump
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2014-05-29 23:26 - 2013-09-21 11:42 - 0012005 _____ () C:\Users\Username\AppData\Roaming\alsoft.ini
2013-10-05 21:35 - 2017-01-26 18:56 - 0000016 _____ () C:\Users\Username\AppData\Roaming\msregsvv.dll
2006-12-11 18:13 - 2006-12-11 18:13 - 0097336 _____ (Un4seen Developments) C:\Users\Username\AppData\Local\bass.dll
2006-12-11 18:13 - 2006-12-11 18:13 - 0013872 _____ (Un4seen Developments) C:\Users\Username\AppData\Local\basscd.dll
2007-08-13 16:46 - 2007-08-13 16:46 - 0102912 _____ (Albert L Faber) C:\Users\Username\AppData\Local\CDRip.dll
2007-08-13 16:46 - 2007-08-13 16:46 - 0155136 _____ () C:\Users\Username\AppData\Local\lame_enc.dll
2007-01-18 20:09 - 2007-01-18 20:09 - 0623616 _____ (Ivan Bischof ©2003 - 2005) C:\Users\Username\AppData\Local\No23 Recorder.exe
2005-08-23 21:34 - 2005-08-23 21:34 - 0029184 _____ () C:\Users\Username\AppData\Local\no23xwrapper.dll
2006-10-26 00:06 - 2006-10-26 00:06 - 0015872 _____ () C:\Users\Username\AppData\Local\ogg.dll
2013-10-05 23:19 - 2016-05-08 13:24 - 0001475 _____ () C:\Users\Username\AppData\Local\RecConfig.xml
2006-10-26 00:06 - 2006-10-26 00:06 - 0143872 _____ () C:\Users\Username\AppData\Local\vorbis.dll
2006-10-26 00:06 - 2006-10-26 00:06 - 0064000 _____ () C:\Users\Username\AppData\Local\vorbisenc.dll
2006-10-26 00:06 - 2006-10-26 00:06 - 0019456 _____ () C:\Users\Username\AppData\Local\vorbisfile.dll
2016-09-20 21:21 - 2016-09-20 21:21 - 0026834 _____ () C:\ProgramData\agent.1474402891.bdinstall.bin
2016-12-01 09:30 - 2016-12-01 09:30 - 0028751 _____ () C:\ProgramData\agent.1480580983.bdinstall.bin
2013-10-05 21:35 - 2016-08-24 22:23 - 0000016 _____ () C:\ProgramData\autobk.inc
Einige Dateien in TEMP:
====================
2015-07-09 11:12 - 2015-07-09 11:13 - 250329200 _____ (AMD Inc.) C:\Users\Username\AppData\Local\Temp\amd-catalyst-15.7-without-dotnet45-win7-64bit.exe
2016-05-04 18:39 - 2016-05-04 18:39 - 1138176 _____ () C:\Users\Username\AppData\Local\Temp\AMDCleanupUtility.exe
2015-07-09 11:11 - 2014-12-05 13:43 - 6245888 _____ (Advanced Micro Devices, Inc.) C:\Users\Username\AppData\Local\Temp\AutoDetectUtilApp.exe
2016-05-04 18:39 - 2016-05-04 18:39 - 0232960 _____ () C:\Users\Username\AppData\Local\Temp\Cleanup.dll
2013-09-10 23:25 - 2013-09-10 23:25 - 0036864 _____ () C:\Users\Username\AppData\Local\Temp\CmdLineExt02.dll
2016-05-04 18:39 - 2016-05-04 18:39 - 0065536 _____ (Windows (R) Server 2003 DDK provider) C:\Users\Username\AppData\Local\Temp\ddu.exe
2016-05-04 18:39 - 2016-05-04 18:39 - 0414152 _____ (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\difxapi.dll
2015-12-11 10:23 - 2015-12-11 10:23 - 0071168 _____ () C:\Users\Username\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmptqjwjq.dll
2013-02-11 14:08 - 2013-02-11 14:08 - 18722816 _____ () C:\Users\Username\AppData\Local\Temp\dsp_ipp.dll
2016-05-13 14:21 - 2016-11-30 20:50 - 0692072 _____ (Disc Soft Ltd.) C:\Users\Username\AppData\Local\Temp\DTLiteInstaller.exe
2015-12-17 01:55 - 2015-12-17 01:55 - 0000000 _____ () C:\Users\Username\AppData\Local\Temp\GURA208.exe
2014-12-14 12:55 - 2014-12-14 12:55 - 0079736 _____ (AppWork GmbH) C:\Users\Username\AppData\Local\Temp\JDSetup130630317136337890.exe
2014-04-15 21:50 - 2014-04-15 21:50 - 0921512 _____ (Oracle Corporation) C:\Users\Username\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
2014-07-28 06:15 - 2014-07-28 06:15 - 0918440 _____ (Oracle Corporation) C:\Users\Username\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
2017-01-18 02:56 - 2017-01-18 02:56 - 0739904 _____ (Oracle Corporation) C:\Users\Username\AppData\Local\Temp\jre-8u121-windows-au.exe
2015-06-12 23:21 - 2015-06-12 23:21 - 0563808 _____ (Oracle Corporation) C:\Users\Username\AppData\Local\Temp\jre-8u51-windows-au.exe
2015-09-27 09:50 - 2015-09-27 09:50 - 0585824 _____ (Oracle Corporation) C:\Users\Username\AppData\Local\Temp\jre-8u60-windows-au.exe
2016-04-20 01:56 - 2016-04-20 01:56 - 0739904 _____ (Oracle Corporation) C:\Users\Username\AppData\Local\Temp\jre-8u91-windows-au.exe
2016-05-04 18:39 - 2016-05-04 18:39 - 0516096 _____ (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\msvcm80.dll
2016-05-04 18:39 - 2016-05-04 18:39 - 1061376 _____ (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\msvcp80.dll
2016-05-04 18:39 - 2016-05-04 18:39 - 0796672 _____ (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\msvcr80.dll
2014-06-04 17:42 - 2014-06-04 17:42 - 7643919 _____ () C:\Users\Username\AppData\Local\Temp\npp.6.6.3.Installer.exe
2014-06-27 12:20 - 2014-06-27 12:20 - 7674224 _____ () C:\Users\Username\AppData\Local\Temp\npp.6.6.7.Installer.exe
2010-03-17 11:28 - 2010-03-17 11:28 - 0174440 ____R (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\ose00000.exe
2013-07-25 15:00 - 2013-07-25 15:00 - 0174440 ____R (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\ose00001.exe
2013-07-25 15:00 - 2013-07-25 15:00 - 0174440 ____R (Microsoft Corporation) C:\Users\Username\AppData\Local\Temp\ose00002.exe
2013-10-11 20:06 - 2013-10-11 20:06 - 0010752 _____ () C:\Users\Username\AppData\Local\Temp\PlaySound.dll
2016-04-29 15:17 - 2005-04-02 14:39 - 0207360 ____N () C:\Users\Username\AppData\Local\Temp\proccheck.exe
2017-02-24 21:49 - 2017-02-24 21:49 - 0040448 ____N () C:\Users\Username\AppData\Local\Temp\proxy_vole6036383075944681149.dll
2016-05-04 18:49 - 2016-05-04 18:49 - 12955000 _____ (AMD Inc.) C:\Users\Username\AppData\Local\Temp\radeon-crimson-16.3.2-minimalsetup.exe
2016-02-03 22:28 - 2016-02-03 22:29 - 61022664 _____ () C:\Users\Username\AppData\Local\Temp\raptrpatch.exe
2016-02-03 22:28 - 2016-02-03 22:28 - 0221632 _____ () C:\Users\Username\AppData\Local\Temp\raptr_stub.exe
2016-12-16 17:34 - 2016-12-16 17:34 - 0192512 _____ () C:\Users\Username\AppData\Local\Temp\sfamcc00001.dll
2015-02-10 18:56 - 2015-02-10 18:56 - 0105984 _____ () C:\Users\Username\AppData\Local\Temp\sfextra.dll
2015-04-13 23:14 - 2010-01-05 14:20 - 0088576 _____ (SkinSharp Inc.) C:\Users\Username\AppData\Local\Temp\Skin.dll
2016-04-29 14:33 - 2005-11-01 01:48 - 6711633 ____N () C:\Users\Username\AppData\Local\Temp\syncrosoftlicensecontrolsetup.exe
2015-08-05 22:02 - 2015-08-05 22:04 - 250446120 _____ (AMD Inc.) C:\Users\Username\AppData\Local\Temp\tmp43E0.exe
2016-02-03 22:00 - 2016-02-03 22:06 - 263289648 _____ (AMD Inc.) C:\Users\Username\AppData\Local\Temp\tmpEEB4.exe
2014-01-13 21:09 - 2015-04-18 08:06 - 0064358 _____ () C:\Users\Username\AppData\Local\Temp\Uninstall.exe
2013-11-28 01:10 - 2013-11-28 01:11 - 23679700 _____ () C:\Users\Username\AppData\Local\Temp\vlc-2.1.1-win64.exe
2014-01-18 16:07 - 2014-01-18 16:07 - 23884615 _____ () C:\Users\Username\AppData\Local\Temp\vlc-2.1.2-win64.exe
2014-03-24 20:14 - 2014-03-24 20:14 - 25055851 _____ () C:\Users\Username\AppData\Local\Temp\vlc-2.1.4-win64.exe
2014-08-17 14:04 - 2014-08-17 14:04 - 25611537 _____ () C:\Users\Username\AppData\Local\Temp\vlc-2.1.5-win64.exe
2012-11-02 10:08 - 2012-11-02 10:08 - 0118784 _____ () C:\Users\Username\AppData\Local\Temp\xmlUpdater.exe
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2017-02-22 18:39
==================== Ende von FRST.txt ============================ |