gegedownhill | 13.11.2017 17:16 | Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 12-11-2017 03
durchgeführt von Gerald (Administrator) auf NB-GERALD-VAIO (13-11-2017 17:10:49)
Gestartet von C:\Users\Gerald\Downloads
Geladene Profile: Gerald (Verfügbare Profile: Gerald & Administrator & DefaultAppPool)
Platform: Windows 10 Pro Version 1703 15063.674 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(AuthenTec, Inc) C:\Program Files\TrueSuite\TrueSuite.Service.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\nst.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security with Backup\Engine\22.11.0.41\nsbu.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
(Data Perceptions / PowerProgrammer) C:\Windows\SysWOW64\WebUpdateSvc4.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Intel Corporation) C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VAIOTM\VTSvc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Authentec Inc.) C:\Program Files\Protector Suite\upeksvr.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security with Backup\Engine\22.11.0.41\nsbu.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\nst.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel® Corporation) C:\Program Files\Intel\CCDashboard\bin\CCDashServer.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VAIOTM\VTUsr.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Suunto) C:\Users\Gerald\AppData\Local\Apps\2.0\V19JA2ZA.HMC\GTLZRWVL.B4J\move..tion_391e8feca7b0cf78_0001.0004_6f8afc924d2bed6c\Moveslink2.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Logitech, Inc.) C:\ProgramData\LogiShrd\LogiOptions\Software\Current\LogiOptionsMgr.exe
(Logitech) C:\ProgramData\LogiShrd\LogiOptions\Software\Current\LogiOverlay.exe
(Fieldston Software) C:\Program Files\Fieldston Software\gSyncit\gsyncit.updater.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.487.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(AuthenTec Inc.) C:\Program Files\TrueSuite\TrueSuite.TouchControl.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IntelMyWiFiDashboard] => C:\Program Files\Intel\CCDashboard\bin\CCDashServer.exe [5010224 2012-07-13] (Intel® Corporation)
HKLM\...\Run: [ClientAppLogon] => C:\Program Files\TrueSuite\TrueSuite.ClientAppLogonExe.exe [421192 2011-04-26] (AuthenTec, Inc.)
HKLM\...\Run: [ClientAppLogon32] => C:\Program Files\TrueSuite\x86\TrueSuite.ClientAppLogonExe.exe [308040 2011-04-26] (AuthenTec, Inc.)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [242552 2013-09-26] (Alps Electric Co., Ltd.)
HKLM\...\Run: [PSQLLauncher] => C:\Program Files\Protector Suite\launcher.exe [85352 2012-10-23] (Authentec Inc.)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3928264 2015-05-27] (Synaptics Incorporated)
HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [2125944 2017-09-12] (Logitech, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [60552 2011-09-20] (Sony Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567928 2017-11-01] (Dropbox, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (Authentec Inc.)
HKU\S-1-5-21-3129668604-1059548586-3889123814-1000\...\Run: [Moveslink2] => C:\Users\Gerald\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Suunto\Moveslink2.appref-ms -auto
HKU\S-1-5-21-3129668604-1059548586-3889123814-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [25621648 2017-10-09] (Google)
HKU\S-1-5-21-3129668604-1059548586-3889123814-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-08-09] (InstallShield Software Corporation)
HKU\S-1-5-21-3129668604-1059548586-3889123814-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10021040 2017-10-18] (Piriform Ltd)
HKU\S-1-5-21-3129668604-1059548586-3889123814-1000\...\Run: [HP Officejet Pro 8600 (NET)] => C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
AppInit_DLLs: acaptuser64.dll => C:\WINDOWS\system32\acaptuser64.dll [119160 2008-06-11] (Adobe Systems, Inc.)
Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll
ShellExecuteHooks-x32: Kein Name - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - -> Keine Datei
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{80ba1f05-e617-45aa-b45e-3e7d907defab}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{f567ba48-54ce-4147-8f14-5c5ca8b57356}: [DhcpNameServer] 192.168.178.2
Tcpip\..\Interfaces\{f9e8a0ca-f77d-4ff6-a5b7-45e35dab5852}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=de&pid=N360&pvid=21.6.0.32
HKU\S-1-5-21-3129668604-1059548586-3889123814-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://vaioportal.sony.eu
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3129668604-1059548586-3889123814-1000 -> {2D6BF222-1AC1-4E15-8118-C40D0FA4706B} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-Q112&_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-3129668604-1059548586-3889123814-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN11913&l=dis&prt=NSBU&chn=oem&geo=DE&ver=22.10.1.10&locale=de_DE&guid=09135CF2-1675-42D1-A40F-F0C6B9442892&doi=2016-09-01&gct=kwd&qsrc=2869
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2017-09-12] (Microsoft Corporation)
BHO: TrueSuite WebStore -> {5cb2b77d-c8ca-44db-af20-a7a4df462a12} -> C:\WINDOWS\system32\mscoree.dll [2017-03-18] (Microsoft Corporation)
BHO: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security with Backup\Engine\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation)
BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files\TrueSuite\TrueSuite.IEBHO.dll [2011-04-26] (AuthenTec Inc.)
BHO: Norton Identity Protection -> {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} -> C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.7.11.42\coIEPlg.dll [2015-03-05] (Symantec Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2017-08-24] (Microsoft Corporation)
BHO-x32: TrueSuite WebStore -> {5cb2b77d-c8ca-44db-af20-a7a4df462a12} -> C:\WINDOWS\system32\mscoree.dll [2017-03-18] (Microsoft Corporation)
BHO-x32: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security with Backup\Engine32\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation)
BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files\TrueSuite\x86\TrueSuite.IEBHO.dll [2011-04-26] (AuthenTec Inc.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: FRITZ!Box Addon BHO -> {C0C86BBE-9509-4296-8459-FDBFDAF4B673} -> C:\Program Files (x86)\FRITZ!Box\AddOn (IE)\FBoxIESplitButton.dll [2012-12-11] (AVM Berlin)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
Toolbar: HKLM - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.7.11.42\coIEPlg.dll [2015-03-05] (Symantec Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security with Backup\Engine\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security with Backup\Engine32\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-3129668604-1059548586-3889123814-1000 -> Kein Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Keine Datei
Toolbar: HKU\S-1-5-21-3129668604-1059548586-3889123814-1000 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security with Backup\Engine\22.11.0.41\coIEPlg.dll [2017-10-04] (Symantec Corporation)
DPF: HKLM-x32 {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.2.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2017-08-15] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: zkcxp0so.default-1482095535167-1509216313557
FF ProfilePath: C:\Users\Gerald\AppData\Roaming\Mozilla\Firefox\Profiles\zkcxp0so.default-1482095535167-1509216313557 [2017-11-13]
FF Homepage: Mozilla\Firefox\Profiles\zkcxp0so.default-1482095535167-1509216313557 -> hxxps://www.google.de
FF Extension: (Ghostery) - C:\Users\Gerald\AppData\Roaming\Mozilla\Firefox\Profiles\zkcxp0so.default-1482095535167-1509216313557\Extensions\firefox@ghostery.com.xpi [2017-10-31]
FF Extension: (Safe Browsing Version 4 (temporary add-on)) - C:\Users\Gerald\AppData\Roaming\Mozilla\Firefox\Profiles\zkcxp0so.default-1482095535167-1509216313557\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-10-31]
FF Extension: (TrueSuite Website Log On) - C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon_toolbar@truesuite.com [2017-10-10] [ist nicht signiert]
FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.5.0.124\coFFAddon
FF Extension: (Norton Security Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.5.0.124\coFFAddon [2017-07-19]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015-10-15] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.7.3.12\coFFPlgn => nicht gefunden
FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.5.0.124\coFFAddon
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2017-04-13] [ist nicht signiert]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-10-25] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [Keine Datei]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-10-25] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 -> C:\Program Files (x86)\Sony\Media Go\npmediago.dll [2011-08-02] (Sony Network Entertainment International LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-29] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-10] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-07-19] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2017-08-10] (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.de/
CHR StartupUrls: Default -> "hxxps://www.google.de/"
CHR DefaultSearchURL: Default -> hxxp://www.awesomehp.com/web/?type=ds&ts=1392380218&from=amt&uid=ST3160215SCE_5RX2BKEWXXXX5RX2BKEW&q={searchTerms}
CHR DefaultSearchKeyword: Default -> awesomehp
CHR Profile: C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default [2017-11-13]
CHR Extension: (Google Drive) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-30]
CHR Extension: (YouTube) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-27]
CHR Extension: (Google-Suche) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-30]
CHR Extension: (Tidy Sidebar) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgmacifhhpefamjmolpipkijcofcmbgp [2017-08-23]
CHR Extension: (Logitech Smooth Scrolling) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2017-04-21]
CHR Extension: (Adobe Acrobat) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-03]
CHR Extension: (Norton Home Page for Chrome) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejbdobdndcjhdmljipngpeoekdinlohe [2017-10-30]
CHR Extension: (Google Docs Offline) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-26]
CHR Extension: (Ghostery) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2017-10-30]
CHR Extension: (Norton Safe) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmgcfemagnogdodbambjhdcmfcpicngl [2017-10-30]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-23]
CHR Extension: (Click&Clean App) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2017-10-30]
CHR Extension: (Google Mail) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-26]
CHR Extension: (Chrome Media Router) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-03]
CHR Profile: C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherheitsstandard [2017-11-13] <==== ACHTUNG
CHR Extension: (Google Präsentationen) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherheitsstandard\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-25]
CHR Extension: (Google Drive) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherheitsstandard\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-25]
CHR Extension: (YouTube) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherheitsstandard\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-25]
CHR Extension: (Google-Suche) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherheitsstandard\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-25]
CHR Extension: (Google Tabellen) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherheitsstandard\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-25]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherheitsstandard\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-25]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherheitsstandard\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2015-08-25]
CHR Extension: (Ghostery) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherheitsstandard\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2015-08-25]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherheitsstandard\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-25]
CHR Extension: (Click&Clean App) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherheitsstandard\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2015-08-25]
CHR Extension: (Google Mail) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherheitsstandard\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-25]
CHR Profile: C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard [2017-11-13] <==== ACHTUNG
CHR Extension: (Google Präsentationen) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-23]
CHR Extension: (Google Drive) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-23]
CHR Extension: (YouTube) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-23]
CHR Extension: (Adblock Plus) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-08-23]
CHR Extension: (Google-Suche) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-23]
CHR Extension: (Google Tabellen) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-23]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-23]
CHR Extension: (Ghostery) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2015-08-23]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-23]
CHR Extension: (Adblock Pro) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2015-08-23]
CHR Extension: (Click&Clean App) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2015-08-23]
CHR Extension: (Google Mail) - C:\Users\Gerald\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-23]
CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security with Backup\Engine\22.11.0.41\Exts\Chrome.crx <nicht gefunden>
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3129668604-1059548586-3889123814-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security with Backup\Engine\22.11.0.41\Exts\Chrome.crx <nicht gefunden>
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-02-09] (SUPERAntiSpyware.com)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [283296 2013-09-13] (Intel Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51016 2017-11-01] (Dropbox, Inc.)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2012-09-11] (Macrovision Europe Ltd.) [Datei ist nicht signiert]
R2 FPLService; C:\Program Files\TrueSuite\TrueSuite.Service.exe [294216 2011-04-26] (AuthenTec, Inc)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [177376 2016-08-12] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes)
R2 NCO; C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\NST.exe [131144 2015-03-05] (Symantec Corporation)
R2 NSBU; C:\Program Files (x86)\Norton Security with Backup\Engine\22.11.0.41\NSBU.exe [326144 2017-10-04] (Symantec Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [Datei ist nicht signiert]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-20] (Microsoft Corporation)
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Datei ist nicht signiert]
R2 uCamMonitor; c:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.)
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [894624 2011-09-01] (Sony Corporation)
R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1656600 2016-03-31] (Sony Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
R2 WebUpdate4; C:\WINDOWS\SysWOW64\WebUpdateSvc4.exe [291088 2011-06-23] (Data Perceptions / PowerProgrammer)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S3 Apowersoft_AudioDevice; C:\WINDOWS\system32\drivers\Apowersoft_AudioDevice.sys [31920 2014-04-09] (Wondershare)
R3 ArcSoftKsUFilter; C:\WINDOWS\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R1 BHDrvx64; C:\Program Files (x86)\Norton Security with Backup\NortonData\22.5.0.124\Definitions\BASHDefs\20171108.001\BHDrvx64.sys [1872024 2017-10-11] (Symantec Corporation)
R1 ccSet_NSBU; C:\WINDOWS\system32\drivers\NSBUx64\160B000.029\ccSetx64.sys [187520 2017-10-04] (Symantec Corporation)
R1 ccSet_NST; C:\WINDOWS\system32\drivers\NSTx64\7DE070B0.02A\ccSetx64.sys [162392 2013-09-27] (Symantec Corporation)
S3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [146856 2013-06-04] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [21928 2013-06-04] (Windows (R) Win 7 DDK provider)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [508056 2017-10-19] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [158360 2017-10-19] (Symantec Corporation)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77440 2017-10-04] ()
S3 HtcVCom32; C:\WINDOWS\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated)
R3 i8042HDR; C:\WINDOWS\system32\DRIVERS\i8042HDR.sys [15920 2009-08-14] (Windows (R) Codename Longhorn DDK provider)
R1 IDSVia64; C:\Program Files (x86)\Norton Security with Backup\NortonData\22.5.0.124\Definitions\IPSDefs\20171110.003\IDSvia64.sys [1056920 2017-10-14] (Symantec Corporation)
S2 io.sys; C:\WINDOWS\SysWOW64\drivers\io.sys [5152 2017-11-05] () [Datei ist nicht signiert]
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [192952 2017-10-31] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [110016 2017-10-31] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [45504 2017-10-31] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [252232 2017-10-31] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [94144 2017-11-13] (Malwarebytes)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2013-09-30] ()
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1009120 2017-09-19] (Realtek )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-05-27] (Synaptics Incorporated)
R1 SRTSP; C:\WINDOWS\System32\Drivers\NSBUx64\160B000.029\SRTSP64.SYS [812704 2017-10-04] (Symantec Corporation)
R1 SRTSPX; C:\WINDOWS\system32\drivers\NSBUx64\160B000.029\SRTSPX64.SYS [49304 2017-10-04] (Symantec Corporation)
R0 SymEFASI; C:\WINDOWS\System32\drivers\NSBUx64\160B000.029\SYMEFASI64.SYS [1868416 2017-10-04] (Symantec Corporation)
S0 SymELAM; C:\WINDOWS\System32\drivers\NSBUx64\160B000.029\SymELAM.sys [24608 2017-10-04] (Symantec Corporation)
R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [102568 2017-07-18] (Symantec Corporation)
R1 SymIRON; C:\WINDOWS\system32\drivers\NSBUx64\160B000.029\Ironx64.SYS [301288 2017-10-04] (Symantec Corporation)
R1 SymNetS; C:\WINDOWS\System32\Drivers\NSBUx64\160B000.029\SYMNETS.SYS [566912 2017-10-04] (Symantec Corporation)
R3 taphss6; C:\WINDOWS\System32\drivers\taphss6.sys [42064 2017-03-21] (Anchorfree Inc.)
R3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [206744 2013-06-20] (Windows (R) Win 7 DDK provider)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [Datei ist nicht signiert]
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
U3 idsvc; kein ImagePath
S3 semav6thermal64ro; \??\C:\WINDOWS\system32\drivers\semav6thermal64ro.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-11-13 17:10 - 2017-11-13 17:11 - 000038616 _____ C:\Users\Gerald\Downloads\FRST.txt
2017-11-13 17:10 - 2017-11-13 17:10 - 000000000 ____D C:\FRST
2017-11-13 17:08 - 2017-11-13 17:08 - 002392576 _____ (Farbar) C:\Users\Gerald\Downloads\FRST64.exe
2017-11-12 19:30 - 2017-11-12 19:30 - 000000000 ____D C:\WINDOWS\System32\Tasks\Remediation
2017-11-12 09:27 - 2017-11-12 09:27 - 000000000 ___HD C:\OneDriveTemp
2017-11-11 19:02 - 2017-11-11 19:02 - 000088997 _____ C:\Users\Gerald\Downloads\9841016_2017_Nr.010_Kontoauszug_vom_03.11.2017_20171111070202.pdf
2017-11-11 19:00 - 2017-11-11 19:00 - 000092949 _____ C:\Users\Gerald\Downloads\51191008_2017_Nr.011_Kontoauszug_vom_10.11.2017_20171111070028.pdf
2017-11-08 19:54 - 2017-11-08 19:54 - 002196049 _____ C:\Users\Gerald\Downloads\Kaffeevollautomat_oeffnen_Jura_E_AEG_CaFamosa_Krups_Orchestro.pdf
2017-11-06 17:40 - 2017-11-06 17:40 - 000000000 ____D C:\Mars
2017-11-06 17:37 - 2017-11-06 17:39 - 000000000 ____D C:\Program Files (x86)\FireCapture_v2.4
2017-11-05 20:19 - 2017-11-05 21:03 - 000001116 _____ C:\Users\Gerald\Desktop\FireCapture.exe - Verknüpfung.lnk
2017-11-05 18:53 - 2017-11-05 19:09 - 000921654 _____ C:\Users\Gerald\Documents\Cratlerlet_Capture_0000.bmp
2017-11-05 18:53 - 2017-11-05 18:53 - 000921654 _____ C:\Users\Gerald\Documents\Cratlerlet_Capture_0002.bmp
2017-11-05 18:53 - 2017-11-05 18:53 - 000921654 _____ C:\Users\Gerald\Documents\Cratlerlet_Capture_0001.bmp
2017-11-05 16:54 - 2017-11-05 18:09 - 000005152 _____ C:\WINDOWS\SysWOW64\Drivers\io.sys
2017-11-05 16:36 - 2017-11-05 16:36 - 000000037 _____ C:\WINDOWS\Pictor.INI
2017-11-05 16:33 - 2017-11-05 16:33 - 000000000 ____D C:\pview
2017-11-05 16:32 - 2017-11-06 19:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Meade
2017-11-04 12:32 - 1998-04-24 00:00 - 000368912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbar332.dll
2017-11-02 19:06 - 2017-11-02 19:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-11-01 12:58 - 2017-11-01 12:58 - 000051016 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2017-11-01 12:58 - 2017-11-01 12:58 - 000045672 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2017-11-01 12:58 - 2017-11-01 12:58 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2017-11-01 12:58 - 2017-11-01 12:58 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2017-10-31 16:11 - 2017-10-31 16:18 - 000000000 ____D C:\AdwCleaner
2017-10-31 16:06 - 2017-10-31 16:06 - 000001955 _____ C:\Users\Gerald\Desktop\mbam.txt
2017-10-31 15:51 - 2017-11-13 17:09 - 000094144 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-10-31 15:51 - 2017-10-31 16:19 - 000110016 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-10-31 15:51 - 2017-10-31 15:51 - 000192952 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2017-10-31 15:50 - 2017-10-31 16:19 - 000252232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2017-10-31 15:50 - 2017-10-31 16:19 - 000045504 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-10-31 15:50 - 2017-10-31 15:50 - 000001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-10-31 15:50 - 2017-10-31 15:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-10-31 15:50 - 2017-10-31 15:50 - 000000000 ____D C:\ProgramData\MB2Migration
2017-10-31 15:50 - 2017-10-31 15:50 - 000000000 ____D C:\Program Files\Malwarebytes
2017-10-31 15:50 - 2017-10-04 13:15 - 000077440 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-10-31 10:20 - 2017-10-31 10:20 - 000074703 _____ C:\WINDOWS\SysWOW64\mfc45.dat
2017-10-31 10:20 - 2017-10-31 10:20 - 000002089 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care (Desktop).lnk
2017-10-31 10:20 - 2017-10-31 10:20 - 000000000 __RHD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care
2017-10-25 20:53 - 2017-10-25 20:53 - 000000000 ____D C:\Users\Gerald\AppData\Local\Wondershare
2017-10-25 20:53 - 2017-10-25 20:53 - 000000000 ____D C:\ProgramData\Wondershare
2017-10-25 20:50 - 2017-10-25 20:53 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2017-10-24 20:41 - 2017-10-24 20:41 - 000003938 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2017-10-20 22:03 - 2017-11-03 00:53 - 000000000 ____D C:\Users\Gerald\Documents\chloe
2017-10-18 20:37 - 2017-11-12 18:59 - 000000000 ____D C:\WINDOWS\System32\Tasks\Norton Security with Backup
2017-10-18 20:37 - 2017-10-18 20:37 - 000003412 _____ C:\WINDOWS\System32\Tasks\Norton WSC Integration
2017-10-15 16:56 - 2017-10-15 16:56 - 000000000 ____D C:\Users\Gerald\Desktop\Hintergrundbilder
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2017-11-13 17:08 - 2012-07-29 13:28 - 000000000 ____D C:\Users\Gerald\Documents\Outlook-Dateien
2017-11-13 17:07 - 2017-07-02 00:37 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-11-13 13:48 - 2016-11-18 12:55 - 000000000 ____D C:\Users\Gerald\AppData\LocalLow\Mozilla
2017-11-13 13:48 - 2012-07-29 15:08 - 000000000 ____D C:\Users\Gerald\AppData\Roaming\gSyncit
2017-11-13 13:47 - 2017-07-02 08:00 - 000000000 ____D C:\Users\Gerald\AppData\Local\Deployment
2017-11-13 13:47 - 2013-10-19 10:52 - 000000000 __RDO C:\Users\Gerald\SkyDrive
2017-11-12 19:37 - 2015-08-16 19:15 - 000000000 ____D C:\Users\Gerald\AppData\Local\Comms
2017-11-12 19:28 - 2017-03-18 22:03 - 000000000 ___HD C:\Program Files\WindowsApps
2017-11-12 19:28 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-11-12 00:58 - 2017-07-02 21:36 - 000004172 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{9EA01580-B932-48D1-B70E-74650E09984C}
2017-11-11 17:59 - 2017-03-18 21:51 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-11-09 18:05 - 2012-08-24 06:48 - 000000000 ____D C:\SCHULE
2017-11-09 11:32 - 2017-03-18 12:40 - 000008192 _____ C:\WINDOWS\system32\config\ELAM
2017-11-07 22:39 - 2017-07-27 09:13 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3129668604-1059548586-3889123814-1000
2017-11-07 22:39 - 2015-08-16 19:16 - 000002434 _____ C:\Users\Gerald\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-11-06 19:25 - 2017-03-18 22:01 - 000000000 ____D C:\WINDOWS\INF
2017-11-06 19:25 - 2012-05-06 11:24 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-11-06 19:22 - 2012-10-27 23:14 - 000000000 ____D C:\Users\Gerald\AppData\Local\Packages
2017-11-06 19:18 - 2017-08-26 00:54 - 000000000 ____D C:\Users\Gerald\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meade
2017-11-06 16:37 - 2014-01-28 23:29 - 000000000 ____D C:\Users\Gerald\Desktop\Htc Tool Kit
2017-11-06 16:37 - 2013-10-15 22:40 - 000000000 __SHD C:\Users\Gerald\AppData\Roaming\wyUpdate AU
2017-11-06 16:10 - 2012-07-29 18:27 - 000000000 ____D C:\Users\Gerald\AppData\Local\CrashDumps
2017-11-05 16:57 - 2012-09-28 21:58 - 000000000 ____D C:\Users\Gerald\AppData\Local\ElevatedDiagnostics
2017-11-05 13:01 - 2012-08-06 22:39 - 000000000 ____D C:\Users\Gerald\AppData\Roaming\vlc
2017-11-04 13:59 - 2017-07-28 18:24 - 000010270 _____ C:\Users\Gerald\Desktop\TV Abo.xlsx
2017-11-04 12:37 - 2017-08-26 00:55 - 000000031 _____ C:\WINDOWS\WebUpdateSvc4.INI
2017-11-03 23:45 - 2017-08-26 08:58 - 000001771 _____ C:\WINDOWS\AutostarSuite.ini
2017-11-03 23:42 - 2017-08-26 08:54 - 000001691 _____ C:\WINDOWS\AutostarIP.INI
2017-11-02 19:07 - 2015-10-16 20:12 - 000000000 ____D C:\Program Files (x86)\Dropbox
2017-11-02 15:26 - 2017-10-08 19:42 - 000000000 ____D C:\Users\Gerald\Desktop\emil
2017-10-31 16:25 - 2017-07-02 00:39 - 002772748 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-10-31 16:25 - 2017-03-20 05:41 - 001258154 _____ C:\WINDOWS\system32\perfh007.dat
2017-10-31 16:25 - 2017-03-20 05:41 - 000301160 _____ C:\WINDOWS\system32\perfc007.dat
2017-10-31 16:19 - 2017-07-02 00:49 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-10-31 16:18 - 2017-03-18 12:40 - 001835008 _____ C:\WINDOWS\system32\config\BBI
2017-10-31 16:18 - 2012-08-02 21:31 - 000000000 ____D C:\Users\Gerald\AppData\Roaming\Yahoo!
2017-10-31 16:02 - 2017-07-02 00:37 - 000441656 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-10-31 15:50 - 2015-07-25 08:42 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-10-31 10:23 - 2017-07-10 10:55 - 000000000 ____D C:\WINDOWS\System32\Tasks\Sony Corporation
2017-10-31 10:23 - 2012-07-23 17:15 - 000000000 ____D C:\Update
2017-10-31 10:20 - 2012-05-06 12:17 - 000000000 ____D C:\ProgramData\iolo
2017-10-31 10:19 - 2014-05-31 09:51 - 000000000 ____D C:\ProgramData\Sony
2017-10-31 10:19 - 2012-05-06 12:20 - 000000000 ____D C:\Program Files\Sony
2017-10-28 19:45 - 2017-09-30 09:07 - 000000000 ____D C:\Users\Gerald\Desktop\Alte Firefox-Daten
2017-10-28 18:35 - 2012-11-18 11:22 - 000000000 ____D C:\Users\Gerald\AppData\Local\NPE
2017-10-28 18:01 - 2017-08-26 00:35 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-10-28 18:01 - 2015-08-26 10:36 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-10-28 18:01 - 2013-12-22 12:54 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2017-10-28 18:00 - 2017-07-02 00:40 - 000000000 ____D C:\Users\Gerald
2017-10-25 21:07 - 2012-07-29 10:29 - 000000000 ____D C:\Users\Gerald\AppData\Roaming\DVDVideoSoft
2017-10-25 20:32 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-10-25 20:31 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-10-24 20:41 - 2013-02-21 07:45 - 000000000 ____D C:\Program Files\CCleaner
2017-10-21 15:46 - 2017-03-05 10:55 - 000000000 ____D C:\Users\Gerald\AppData\Roaming\WhatsApp
2017-10-18 21:02 - 2016-04-08 18:24 - 000000000 ____D C:\Program Files\Common Files\AV
2017-10-18 20:37 - 2016-07-03 21:36 - 000002536 _____ C:\Users\Public\Desktop\Norton Security with Backup.lnk
2017-10-18 20:37 - 2015-10-27 11:08 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security with Backup
2017-10-18 20:37 - 2015-10-27 11:08 - 000000000 ____D C:\WINDOWS\system32\Drivers\NSBUx64
2017-10-17 12:57 - 2017-03-05 10:55 - 000002291 _____ C:\Users\Gerald\Desktop\WhatsApp.lnk
2017-10-17 12:57 - 2017-03-05 10:55 - 000000000 ____D C:\Users\Gerald\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp
2017-10-17 12:57 - 2017-03-05 10:55 - 000000000 ____D C:\Users\Gerald\AppData\Local\WhatsApp
2017-10-17 12:56 - 2017-03-05 10:55 - 000000000 ____D C:\Users\Gerald\AppData\Local\SquirrelTemp
2017-10-17 00:15 - 2017-03-17 20:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2017-10-14 11:50 - 2017-10-01 08:52 - 000000000 ____D C:\Users\Gerald\Desktop\Synscan
2017-10-14 10:59 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\rescache
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2012-10-28 00:02 - 2012-10-28 00:02 - 000002717 _____ () C:\Users\Gerald\AppData\Local\IWDAudHelper.20121028.010248.txt
2015-05-05 07:21 - 2015-05-05 07:21 - 000002238 _____ () C:\Users\Gerald\AppData\Local\recently-used.xbel
2012-10-28 00:02 - 2012-10-28 00:03 - 000025871 _____ () C:\Users\Gerald\AppData\Local\WiDiSetupLog.20121028.010223.txt
2014-05-25 21:26 - 2014-05-25 21:29 - 000038009 _____ () C:\Users\Gerald\AppData\Local\WiDiSetupLog.20140525.222651.wdl
2013-04-16 22:01 - 2013-04-16 22:01 - 000000057 _____ () C:\ProgramData\Ament.ini
2017-07-02 00:38 - 2017-07-02 00:38 - 000000000 ____H () C:\ProgramData\DP45977C.lfl
2012-08-02 21:29 - 2013-04-16 21:39 - 000020581 _____ () C:\ProgramData\hpzinstall.log
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2017-11-03 00:59
==================== Ende von FRST.txt ============================ |