FireFox:
========
FF ProfilePath: C:\Users\Neku\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF Homepage: hxxp://google.rs/
FF Session Restore: -> ist aktiviert.
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-07] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-07] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\TXE Components\IPT\npIntelWebAPIIPT.dll [2014-07-01] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\TXE Components\IPT\npIntelWebAPIUpdater.dll [2014-07-01] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-2253936156-139631062-2474235644-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Neku\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-01-22] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2253936156-139631062-2474235644-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Neku\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-01-22] (Unity Technologies ApS)
FF Extension: FireGestures - C:\Users\Neku\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\
[email protected] [2016-04-11]
FF Extension: MEGA - C:\Users\Neku\AppData\Roaming\Mozilla\Firefox\Profiles\6vqbyy8g.default\Extensions\
[email protected] [2016-04-05]
FF Extension: FireGestures - C:\Users\Neku\AppData\Roaming\Mozilla\Firefox\Profiles\6vqbyy8g.default\Extensions\
[email protected] [2016-04-08]
FF Extension: English (US) Language Pack - C:\Users\Neku\AppData\Roaming\Mozilla\Firefox\Profiles\6vqbyy8g.default\Extensions\
[email protected] [2016-03-20]
FF Extension: MEGA - C:\Users\Neku\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\
[email protected] [2016-04-11]
FF Extension: English (US) Language Pack - C:\Users\Neku\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\
[email protected] [2016-03-20]
FF HKLM\...\Firefox\Extensions: [
[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-02-14]
FF HKLM-x32\...\Firefox\Extensions: [
[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR Profile: C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-30]
CHR Extension: (Google Docs) - C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-31]
CHR Extension: (Google Drive) - C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-31]
CHR Extension: (YouTube) - C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-31]
CHR Extension: (Google Search) - C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-31]
CHR Extension: (Google Sheets) - C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-30]
CHR Extension: (Google Docs Offline) - C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-02]
CHR Extension: (Avast Online Security) - C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-04-09]
CHR Extension: (Kein Name) - C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2016-04-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Kein Name) - C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebgdicanjhnamfmdlmlbcnkgehkkmf [2016-04-10]
CHR Extension: (Gmail) - C:\Users\Neku\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-31]
CHR HKU\S-1-5-21-2253936156-139631062-2474235644-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2253936156-139631062-2474235644-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ooebgdicanjhnamfmdlmlbcnkgehkkmf] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2253936156-139631062-2474235644-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2253936156-139631062-2474235644-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ooebgdicanjhnamfmdlmlbcnkgehkkmf] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-02-11]
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 Amazon 1Button App Service; c:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe [451072 2016-01-11] (Amazon Inc.) [Datei ist nicht signiert]
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [323152 2015-05-29] (Windows (R) Win 7 DDK provider)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-11] (AVAST Software)
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [433688 2016-02-05] (BlueStack Systems, Inc.)
S3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [413208 2016-02-05] (BlueStack Systems, Inc.)
S3 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [859672 2016-02-05] (BlueStack Systems, Inc.)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2860760 2016-01-14] (Acer Incorporated)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1444544 2016-03-01] (Disc Soft Ltd)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573568 2015-05-14] (Acer Incorporated)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [135496 2016-04-09] (SurfRight B.V.)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [368552 2016-01-30] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [330240 2015-02-26] () [Datei ist nicht signiert]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-02-26] () [Datei ist nicht signiert]
R2 jhi_service; C:\Program Files (x86)\Intel\TXE Components\DAL\jhi_service.exe [174368 2015-04-21] (Intel Corporation)
S2 Kingsoft_WPS_UpdateService; C:\Program Files (x86)\Kingsoft\WPS Office\9.1.0.5113\wtoolex\wpsupdatesvr.exe [133480 2015-09-01] (Zhuhai Kingsoft Office Software Co.,Ltd)
R2 ManyCam Service; C:\ProgramData\ManyCam\Service\service.exe [77528 2015-12-15] (Visicom Media Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1286896 2016-04-05] (Overwolf LTD)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2016-03-22] ()
R2 PnkBstrB; C:\WINDOWS\SysWOW64\PnkBstrB.exe [189248 2016-03-22] ()
R3 QALSvc; C:\Program Files\Acer\Acer Quick Access\QALSvc.exe [398176 2015-07-09] (Acer Incorporated)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [450400 2015-07-09] (Acer Incorporated)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [187024 2016-02-26] (Sandboxie Holdings, LLC)
R2 SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [445240 2015-04-30] ()
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Datei ist nicht signiert]
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [251232 2015-09-14] (acer)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-11] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-11] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-11] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-09] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-23] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-11] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-11] (AVAST Software)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4301304 2015-05-17] (Qualcomm Atheros Communications, Inc.)
S2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [154680 2016-02-05] (BlueStack Systems)
S2 CamMask; C:\Windows\system32\DRIVERS\cmvcamdrv64.sys [954072 2013-12-23] ()
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2016-02-05] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2016-02-05] (Disc Soft Ltd)
R1 epp; C:\Users\Neku\Desktop\security\bin64\epp.sys [124080 2016-02-11] (Emsisoft Ltd)
R3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [49584 2016-04-19] ()
R3 iagpioe; C:\Windows\System32\drivers\iagpioe.sys [41984 2015-06-02] (Intel(R) Corporation)
S3 iauarte; C:\Windows\System32\drivers\iauarte.sys [112640 2015-06-02] (Intel(R) Corporation)
R3 igfxLP; C:\Windows\system32\DRIVERS\igdkmd64lp.sys [5759240 2016-01-30] (Intel Corporation)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21344 2015-07-09] (Acer Incorporated)
R3 ManyCam; C:\Windows\system32\DRIVERS\mcvidrv.sys [49272 2014-12-29] (Visicom Media Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-04-19] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
R3 mcaudrv_simple; C:\Windows\system32\drivers\mcaudrv_x64.sys [35960 2014-12-29] (Visicom Media Inc.)
U0 Partizan; C:\Windows\SysWOW64\drivers\Partizan.sys [40304 2016-04-09] (Greatis Software)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14688 2015-07-09] (Acer Incorporated)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek )
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [402136 2015-05-27] (Realsil Semiconductor Corporation)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [204944 2016-02-26] (Sandboxie Holdings, LLC)
R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [51368 2015-05-11] (Synaptics Incorporated)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [146232 2015-06-26] (Intel Corporation)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
R1 VBoxNetAdp; C:\Windows\System32\drivers\VBoxNetAdp6.sys [117768 2016-01-19] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [194976 2016-01-19] (Oracle Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 xhunter1; C:\Windows\xhunter1.sys [35880 2016-03-11] (Wellbia.com Co., Ltd.)
S3 X6va062; \??\C:\WINDOWS\SysWOW64\Drivers\X6va062 [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-04-19 16:50 - 2016-04-19 16:50 - 00031876 _____ C:\Users\Neku\Desktop\FRST.txt
2016-04-19 16:47 - 2016-04-19 16:47 - 00049584 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys
2016-04-18 16:42 - 2016-04-18 16:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2016-04-18 16:42 - 2016-04-18 16:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-04-18 16:40 - 2016-04-18 16:40 - 00000000 ____D C:\WINDOWS\PCHEALTH
2016-04-18 16:40 - 2016-04-18 16:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services
2016-04-18 16:40 - 2016-04-18 16:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Sync Framework
2016-04-18 16:40 - 2016-04-18 16:40 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-04-18 16:38 - 2016-04-18 16:38 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2016-04-18 16:36 - 2016-04-18 16:36 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2016-04-18 16:35 - 2016-04-18 16:35 - 00000000 __RHD C:\MSOCache
2016-04-18 16:35 - 2016-04-18 16:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2016-04-18 16:07 - 2016-04-18 16:07 - 00000000 ___RD C:\Sandbox
2016-04-18 16:04 - 2016-04-19 16:45 - 00001772 _____ C:\WINDOWS\Sandboxie.ini
2016-04-18 16:04 - 2016-04-18 16:02 - 00000941 _____ C:\Users\Neku\Desktop\Sandboxed Web Browser.lnk
2016-04-18 16:02 - 2016-04-18 16:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
2016-04-18 16:02 - 2016-04-18 16:02 - 00000000 ____D C:\Program Files\Sandboxie
2016-04-18 16:01 - 2016-04-18 16:01 - 08584848 _____ (Sandboxie Holdings, LLC) C:\Users\Neku\Downloads\SandboxieInstall.exe
2016-04-18 14:09 - 2016-04-18 14:20 - 785858560 _____ C:\Users\Neku\Downloads\_Getintopc.com_Microsoft_Office_Proffesional_Plus_2010.iso
2016-04-18 13:11 - 2016-04-18 13:11 - 00000000 ___HD C:\OneDriveTemp
2016-04-15 18:36 - 2016-04-15 18:37 - 03677760 _____ C:\Users\Neku\Desktop\AdwCleaner.exe
2016-04-12 14:46 - 2016-04-12 14:46 - 00000000 _____ C:\Users\Neku\Desktop\New Text Document.txt
2016-04-12 14:41 - 2016-04-15 19:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-04-12 14:30 - 2016-04-19 16:50 - 00000000 ____D C:\FRST
2016-04-12 14:16 - 2016-04-12 14:16 - 02375168 _____ (Farbar) C:\Users\Neku\Desktop\FRST64.exe
2016-04-11 17:07 - 2016-04-11 18:04 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-04-11 16:26 - 2016-04-11 16:26 - 03465280 _____ C:\Users\Neku\Desktop\adwcleaner_5.110.exe
2016-04-11 16:18 - 2016-04-11 16:18 - 00000000 ____D C:\Program Files (x86)\ESET
2016-04-11 15:40 - 2016-04-11 15:41 - 24003656 _____ C:\Users\Neku\Downloads\RogueKillerX64.exe
2016-04-10 17:30 - 2016-04-10 17:30 - 00000478 _____ C:\WINDOWS\system32\.crusader
2016-04-10 15:41 - 2016-04-10 15:41 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-04-10 15:21 - 2016-04-10 15:23 - 227630056 _____ C:\Users\Neku\Downloads\EmsisoftEmergencyKit.exe
2016-04-10 14:55 - 2015-12-09 05:39 - 00301728 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-10 14:41 - 2016-04-15 18:42 - 00000000 ____D C:\AdwCleaner
2016-04-10 14:05 - 2016-04-10 14:05 - 01610352 _____ (Malwarebytes) C:\Users\Neku\Desktop\JRT.exe
2016-04-10 13:23 - 2016-04-10 13:23 - 00007607 _____ C:\Users\Neku\AppData\Local\Resmon.ResmonCfg
2016-04-10 13:17 - 2016-04-15 13:59 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2016-04-10 13:16 - 2016-04-10 14:05 - 00000000 ____D C:\ProgramData\RogueKiller
2016-04-10 13:11 - 2016-04-19 16:47 - 00000000 ____D C:\Users\Neku\Desktop\security
2016-04-10 13:06 - 2016-04-10 13:06 - 00000000 ____D C:\Users\Neku\AppData\Local\VirtualStore
2016-04-10 13:05 - 2016-04-19 16:42 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-04-09 21:52 - 2016-04-18 13:08 - 00000252 _____ C:\WINDOWS\SysWOW64\PARTIZAN.TXT
2016-04-09 21:49 - 2016-04-09 21:49 - 00000000 ____D C:\@RestoreQuarantine
2016-04-09 20:38 - 2016-04-10 16:24 - 00000000 ____D C:\ProgramData\RegRun
2016-04-09 20:38 - 2016-04-09 20:38 - 00040304 _____ (Greatis Software) C:\WINDOWS\SysWOW64\Drivers\Partizan.sys
2016-04-09 20:38 - 2016-04-09 20:38 - 00000002 RSHOT C:\WINDOWS\winstart.bat
2016-04-09 20:38 - 2016-04-09 20:38 - 00000002 RSHOT C:\WINDOWS\SysWOW64\CONFIG.NT
2016-04-09 20:38 - 2016-04-09 20:38 - 00000002 RSHOT C:\WINDOWS\SysWOW64\AUTOEXEC.NT
2016-04-09 20:37 - 2016-04-18 13:14 - 00000000 ____D C:\Program Files (x86)\UnHackMe
2016-04-09 20:37 - 2016-04-10 16:32 - 00000000 ____D C:\Users\Public\Documents\regruninfo
2016-04-09 20:37 - 2016-04-10 16:26 - 00000000 ____D C:\Users\Neku\Documents\RegRun2
2016-04-09 20:37 - 2016-04-09 20:37 - 00003418 _____ C:\WINDOWS\System32\Tasks\UnHackMe Task Scheduler
2016-04-09 20:37 - 2016-04-09 20:37 - 00000000 ____D C:\Users\Neku\Downloads\unhackme
2016-04-09 20:37 - 2016-04-09 20:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnHackMe
2016-04-09 20:37 - 2016-04-05 15:17 - 00012808 _____ (Greatis Software, LLC.) C:\WINDOWS\SysWOW64\Drivers\UnHackMeDrv.sys
2016-04-09 20:37 - 2015-12-28 11:32 - 00049968 _____ (Greatis Software) C:\WINDOWS\system32\partizan.exe
2016-04-09 20:08 - 2016-04-09 20:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2016-04-09 20:08 - 2016-04-09 20:08 - 00000000 ____D C:\Program Files\HitmanPro
2016-04-09 20:07 - 2016-04-10 17:30 - 00000000 ____D C:\ProgramData\HitmanPro
2016-04-09 17:58 - 2016-04-09 17:58 - 00000000 ____D C:\Program Files\Common Files\AV
2016-04-09 17:52 - 2016-04-09 17:52 - 00000000 ____D C:\Users\Neku\Documents\ProcAlyzer Dumps
2016-04-09 17:50 - 2016-04-15 19:04 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-04-09 17:50 - 2016-04-12 14:19 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-04-09 17:50 - 2016-04-09 17:50 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2016-04-09 16:49 - 2016-04-09 16:50 - 00000000 ____D C:\ProgramData\Sophos
2016-04-09 16:48 - 2016-04-10 16:54 - 00002781 _____ C:\Users\Neku\Desktop\Sophos Virus Removal Tool.lnk
2016-04-09 16:48 - 2016-04-09 16:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2016-04-09 16:48 - 2016-04-09 16:48 - 00000000 ____D C:\Program Files (x86)\Sophos
2016-04-09 16:45 - 2016-04-09 16:47 - 147100624 _____ (Sophos Limited) C:\Users\Neku\Downloads\Sophos Virus Removal Tool.exe
2016-04-09 16:31 - 2016-04-09 16:31 - 00000000 ____D C:\NPE
2016-04-09 16:10 - 2016-04-09 16:10 - 00111288 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SMR501.SYS.bak
2016-04-09 16:09 - 2016-04-09 16:58 - 00000000 ____D C:\Users\Neku\AppData\Local\NPE
2016-04-09 16:09 - 2016-04-09 16:10 - 00000000 ____D C:\ProgramData\Norton
2016-04-09 16:09 - 2016-04-09 16:09 - 03088296 _____ (Symantec Corporation) C:\Users\Neku\Downloads\NPE.exe
2016-04-09 15:23 - 2016-04-09 15:23 - 00005120 _____ C:\Users\Neku\AppData\Roaming\GiftBag.db
2016-04-09 15:15 - 2016-04-09 15:16 - 00000000 ____D C:\Users\Neku\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-04-09 15:15 - 2016-04-09 15:15 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-04-08 20:13 - 2016-04-08 20:13 - 00105322 _____ C:\Users\Neku\Downloads\Arbeitsvertrag_Muster.pdf
2016-04-08 19:19 - 2016-04-19 16:45 - 00000000 ___RD C:\Users\Neku\Google Drive
2016-04-08 19:19 - 2016-04-10 16:54 - 00001769 _____ C:\Users\Neku\Desktop\Google Drive.lnk
2016-04-08 19:16 - 2016-04-08 19:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-04-08 19:02 - 2016-04-10 16:55 - 00001080 _____ C:\Users\Public\Desktop\Audacity.lnk
2016-04-08 19:02 - 2016-04-09 22:48 - 00001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2016-04-08 19:02 - 2016-04-08 19:02 - 00000000 ____D C:\Program Files (x86)\Audacity
2016-04-01 19:57 - 2016-04-01 19:57 - 00000000 ____D C:\Users\Neku\AppData\Roaming\SmartSteamEmu
2016-03-31 21:25 - 2016-03-31 21:35 - 00000000 ____D C:\WINDOWS\Minidump
2016-03-31 19:32 - 2016-03-31 19:32 - 00000000 ____D C:\Users\Neku\AppData\Roaming\inkscape
2016-03-29 18:09 - 2016-03-29 18:09 - 00000000 ____D C:\Users\Neku\AppData\LocalLow\SUPERHOT_Team
2016-03-29 18:09 - 2016-03-29 18:09 - 00000000 ____D C:\Users\Neku\AppData\Local\SUPERHOT_Sp_z_o.o
2016-03-29 17:52 - 2016-03-29 17:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERHOT [GOG.com]
2016-03-29 17:47 - 2016-03-29 17:47 - 00000000 ____D C:\Users\Neku\AppData\LocalLow\SUPERHOT Team
2016-03-28 15:01 - 2016-03-28 15:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6 (2015-10-21)
2016-03-27 14:39 - 2016-03-27 14:39 - 00000000 ____D C:\Users\Neku\AppData\Local\ShootoutInc
2016-03-26 18:35 - 2016-03-26 20:33 - 00000000 ____D C:\Users\Neku\AppData\Local\Soundnode
2016-03-23 23:40 - 2016-03-23 23:40 - 00000000 ____D C:\Users\Neku\Documents\Holotech
2016-03-23 21:18 - 2016-03-23 21:18 - 00000000 ____D C:\ProgramData\Intel Telemetry
2016-03-23 21:16 - 2016-03-23 21:17 - 00000000 ____D C:\WINDOWS\System32\Tasks\Intel
2016-03-23 21:15 - 2016-03-23 21:15 - 00000000 ____D C:\Program Files\Common Files\Intel
2016-03-23 18:00 - 2016-04-09 22:48 - 00001226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-03-23 18:00 - 2016-03-23 18:00 - 00003200 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1458748831
2016-03-23 17:59 - 2016-03-23 17:59 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2016-03-22 22:53 - 2016-03-22 22:53 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2016-03-22 22:53 - 2016-03-22 22:53 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUSB_01007.Wdf
2016-03-22 17:40 - 2016-03-22 17:40 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-03-22 17:40 - 2016-03-22 17:40 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2016-03-22 17:39 - 2016-03-22 17:39 - 00189248 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe
2016-03-22 17:39 - 2016-03-22 17:39 - 00189248 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2016-03-22 17:39 - 2016-03-22 17:39 - 00076888 _____ C:\WINDOWS\SysWOW64\PnkBstrA.exe
2016-03-22 17:39 - 2016-03-22 17:32 - 03130440 _____ C:\WINDOWS\SysWOW64\pbsvc_blr.exe
2016-03-21 23:49 - 2016-03-21 23:49 - 00000000 ____D C:\Users\Neku\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2016-03-21 23:43 - 2016-03-21 23:43 - 00000000 ____D C:\Users\Neku\AppData\Roaming\PACE Anti-Piracy
2016-03-21 23:43 - 2016-03-21 23:43 - 00000000 ____D C:\Users\Neku\AppData\Local\PACE Anti-Piracy
2016-03-21 23:43 - 2016-03-21 23:43 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
2016-03-21 21:06 - 2016-03-21 21:06 - 00000000 ____D C:\Program Files\Adobe
2016-03-21 21:01 - 2016-03-21 21:01 - 00000000 ____D C:\Program Files (x86)\Adobe Story
2016-03-21 21:00 - 2009-07-09 04:00 - 00055280 ____N (Sonic Solutions) C:\WINDOWS\system32\Drivers\PxHlpa64.sys
2016-03-21 21:00 - 2009-06-23 04:00 - 00010224 ____N (Sonic Solutions) C:\WINDOWS\system32\Drivers\cdralw2k.sys
2016-03-21 21:00 - 2009-06-23 04:00 - 00010224 ____N (Sonic Solutions) C:\WINDOWS\system32\Drivers\cdr4_xp.sys
2016-03-21 20:59 - 2016-03-21 20:59 - 00000000 ____D C:\Program Files (x86)\My Company Name
2016-03-21 20:56 - 2016-04-09 22:48 - 00001074 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2016-03-21 20:56 - 2016-03-21 21:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2016-03-21 20:56 - 2016-03-21 20:56 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2016-03-21 20:56 - 2016-03-21 20:56 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2016-03-21 20:50 - 2016-03-21 21:06 - 00000000 ____D C:\Ap
2016-03-20 19:18 - 2016-03-20 19:18 - 00000000 ____D C:\Users\Neku\Downloads\G7 Pics
2016-03-20 01:00 - 2016-04-09 21:40 - 00000000 ____D C:\WINDOWS\AutoKMS
2016-03-20 00:56 - 2016-03-20 00:56 - 00000000 ____D C:\ProgramData\Microsoft Toolkit
2016-03-20 00:37 - 2016-04-18 17:47 - 00000000 ____D C:\Users\Neku\AppData\Local\Microsoft Help
2016-03-20 00:36 - 2016-04-18 16:36 - 00000000 ____D C:\Program Files\Microsoft Office
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-04-19 16:51 - 2016-01-30 23:07 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-19 16:50 - 2016-02-03 17:38 - 00000000 ____D C:\wifidata
2016-04-19 16:43 - 2016-02-23 19:11 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-19 16:43 - 2016-01-30 21:23 - 00000000 ___RD C:\Users\Neku\OneDrive
2016-04-19 16:42 - 2016-01-30 21:44 - 00000934 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-19 16:42 - 2016-01-30 21:18 - 00000000 __SHD C:\Users\Neku\IntelGraphicsProfiles
2016-04-18 19:52 - 2016-01-30 22:56 - 00004168 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{E27DC3F2-9B4B-4B5B-8DBD-E97FA14A4DDE}
2016-04-18 19:38 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-18 19:31 - 2016-01-30 21:41 - 00000000 ____D C:\Users\Neku\AppData\Local\CrashDumps
2016-04-18 19:07 - 2016-01-30 21:44 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-18 18:12 - 2016-02-01 18:11 - 00000000 ____D C:\Program Files (x86)\Overwolf
2016-04-18 18:03 - 2016-03-15 15:07 - 00000000 ____D C:\Windows.old
2016-04-18 16:55 - 2016-01-30 21:21 - 00000000 ____D C:\Users\Neku\AppData\Local\clear.fi
2016-04-18 16:50 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-04-18 16:50 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-18 16:42 - 2015-10-30 20:44 - 00000000 ____D C:\WINDOWS\ShellNew
2016-04-18 16:41 - 2016-03-15 14:51 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-04-18 16:40 - 2015-09-01 20:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-04-18 16:37 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-04-18 16:36 - 2015-07-10 13:04 - 00000199 _____ C:\WINDOWS\win.ini
2016-04-18 15:56 - 2016-02-05 15:12 - 00000000 ____D C:\Users\Neku\AppData\Roaming\DAEMON Tools Lite
2016-04-18 15:16 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-04-18 14:05 - 2016-02-06 12:32 - 00000000 ___RD C:\Users\Neku\Desktop\Games
2016-04-18 13:08 - 2016-03-15 15:47 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-15 19:05 - 2015-10-30 08:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2016-04-15 19:04 - 2015-07-16 05:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-04-15 17:50 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-04-15 15:41 - 2016-01-30 21:18 - 00000000 ____D C:\Users\Neku\AppData\Local\Packages
2016-04-15 13:57 - 2016-02-06 12:30 - 00000000 ____D C:\Users\Neku\AppData\Local\MEGAsync
2016-04-11 17:06 - 2016-02-23 19:11 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-04-10 16:55 - 2016-03-15 17:33 - 00001051 _____ C:\Users\Neku\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optionale Features.lnk
2016-04-10 16:55 - 2016-03-08 18:41 - 00001862 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2016-04-10 16:55 - 2016-03-02 17:51 - 00001746 _____ C:\Users\Neku\AppData\Roaming\Microsoft\Windows\Start Menu\BlueStacks.lnk
2016-04-10 16:55 - 2016-02-22 16:38 - 00000911 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-04-10 16:55 - 2016-02-19 23:07 - 00002640 _____ C:\Users\Public\Desktop\Skype.lnk
2016-04-10 16:55 - 2016-02-03 20:42 - 00000545 _____ C:\Users\Neku\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
2016-04-10 16:55 - 2016-01-31 12:40 - 00002641 _____ C:\Users\Neku\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2016-04-10 16:55 - 2016-01-30 21:42 - 00002015 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-04-10 16:55 - 2016-01-30 21:23 - 00002384 _____ C:\Users\Neku\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-04-10 16:55 - 2016-01-30 21:21 - 00001333 _____ C:\Users\Neku\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD Audio-Manager.lnk
2016-04-10 16:54 - 2016-02-23 20:26 - 00000651 _____ C:\Users\Neku\Desktop\4K YouTube to MP3.lnk
2016-04-10 16:54 - 2016-02-23 20:25 - 00000679 _____ C:\Users\Neku\Desktop\4K Video Downloader.lnk
2016-04-10 16:54 - 2016-02-20 12:54 - 00000420 _____ C:\Users\Neku\Desktop\My Computer.lnk
2016-04-10 16:52 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\appcompat
2016-04-09 22:48 - 2016-03-15 15:35 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-04-09 22:48 - 2016-02-25 19:20 - 00000860 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk
2016-04-09 22:48 - 2016-02-25 19:19 - 00000805 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk
2016-04-09 22:48 - 2016-02-25 19:18 - 00000830 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
2016-04-09 22:48 - 2016-02-25 19:17 - 00000777 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk
2016-04-09 22:48 - 2016-02-25 19:12 - 00001560 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
2016-04-09 22:48 - 2016-02-25 19:12 - 00000925 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
2016-04-09 22:48 - 2016-02-06 14:03 - 00001023 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mocha for After Effects CS4.lnk
2016-04-09 22:48 - 2016-02-06 13:54 - 00000921 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects CS4.lnk
2016-04-09 22:48 - 2016-02-06 13:52 - 00001488 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS4.lnk
2016-04-09 22:48 - 2016-02-05 23:26 - 00000643 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sublime Text 3.lnk
2016-04-09 22:48 - 2016-01-30 21:45 - 00002149 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-09 22:48 - 2016-01-30 21:42 - 00002027 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2016-04-09 22:48 - 2015-07-16 05:33 - 00001946 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-04-09 22:48 - 2015-03-21 02:28 - 00003274 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\App Explorer.lnk
2016-04-09 22:46 - 2016-02-14 20:34 - 00000646 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Toribash.lnk
2016-04-09 17:57 - 2016-02-23 19:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-04-09 17:57 - 2016-02-23 19:11 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-04-09 17:03 - 2016-01-31 12:38 - 00000000 ____D C:\Users\Neku\AppData\Roaming\uTorrent
2016-04-09 16:58 - 2015-10-30 20:35 - 00781048 _____ C:\WINDOWS\system32\perfh007.dat
2016-04-09 16:58 - 2015-10-30 20:35 - 00159634 _____ C:\WINDOWS\system32\perfc007.dat
2016-04-09 16:58 - 2015-07-16 05:31 - 01799166 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-09 16:35 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-04-09 16:31 - 2016-03-15 15:12 - 05094600 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-09 16:09 - 2016-02-01 21:09 - 00000000 ____D C:\Users\Neku\AppData\Roaming\Skype
2016-04-09 16:02 - 2016-02-01 21:09 - 00000000 ____D C:\ProgramData\Skype
2016-04-09 16:01 - 2016-02-19 23:07 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-04-09 15:33 - 2015-09-01 21:29 - 00000000 ____D C:\ProgramData\Temp
2016-04-09 15:31 - 2016-02-23 18:33 - 00000306 __RSH C:\ProgramData\ntuser.pol
2016-04-09 15:20 - 2016-03-17 19:41 - 00000000 ____D C:\Program Files\Unlocker
2016-04-09 00:31 - 2016-03-15 15:23 - 00000000 ____D C:\Users\Neku
2016-04-08 19:53 - 2016-02-03 17:54 - 00000000 ___RD C:\Users\Neku\Desktop\Skola
2016-04-08 19:52 - 2016-01-30 21:41 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2016-04-08 19:16 - 2016-01-30 21:44 - 00000000 ____D C:\Users\Neku\AppData\Local\Google
2016-04-08 19:16 - 2016-01-30 21:44 - 00000000 ____D C:\Program Files (x86)\Google
2016-04-08 19:10 - 2016-02-11 20:45 - 00000000 ____D C:\Users\Neku\Desktop\Game Making
2016-04-08 19:09 - 2016-02-10 13:06 - 00000000 ____D C:\Users\Neku\AppData\Roaming\Audacity
2016-04-08 18:02 - 2016-01-30 21:27 - 00000000 ____D C:\Users\Neku\AppData\Local\MicrosoftEdge
2016-04-07 19:51 - 2016-01-30 23:07 - 00003870 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-04-05 18:55 - 2016-03-05 20:36 - 00000000 ____D C:\Users\Neku\Downloads\snes9x-1.53-x64
2016-04-05 17:35 - 2016-02-22 16:38 - 00000000 ____D C:\Program Files\CCleaner
2016-04-04 19:26 - 2016-02-01 18:11 - 00000000 ____D C:\Users\Neku\AppData\Roaming\TS3Client
2016-04-01 20:05 - 2016-03-08 17:40 - 00000000 ____D C:\Users\Neku\AppData\Local\Coin
2016-04-01 18:44 - 2015-09-01 20:46 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-31 13:57 - 2016-01-30 21:18 - 00000000 ____D C:\Users\Neku\AppData\Roaming\Adobe
2016-03-29 18:54 - 2016-01-30 22:49 - 00000000 ____D C:\ProgramData\Oracle
2016-03-29 18:50 - 2016-01-30 22:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-03-29 18:50 - 2016-01-30 22:49 - 00000000 ____D C:\Program Files (x86)\Java
2016-03-29 18:09 - 2016-01-30 22:50 - 00000000 ____D C:\Users\Neku\.oracle_jre_usage
2016-03-29 18:08 - 2016-01-30 22:49 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-03-29 13:25 - 2016-02-01 18:10 - 00000000 ____D C:\Users\Neku\AppData\Local\Overwolf
2016-03-26 20:40 - 2016-01-30 23:05 - 00000000 ____D C:\Users\Neku\AppData\Local\Adobe
2016-03-26 13:53 - 2016-03-18 16:47 - 00000000 ____D C:\Users\Neku\BrawlhallaReplays
2016-03-24 00:00 - 2016-02-03 15:57 - 00000000 ____D C:\Users\Neku\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-03-23 21:16 - 2015-09-01 20:53 - 00000000 ____D C:\Program Files (x86)\Intel
2016-03-23 21:15 - 2015-09-01 20:53 - 00000000 ____D C:\ProgramData\Intel
2016-03-23 17:59 - 2015-07-16 05:32 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-23 17:59 - 2015-07-16 05:32 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-23 17:31 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-22 21:03 - 2016-02-23 20:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download
2016-03-22 14:53 - 2016-01-30 23:30 - 00000000 ____D C:\Users\Neku\Documents\Sound recordings
2016-03-21 23:43 - 2015-08-24 02:56 - 00000000 ___HD C:\Users\Neku\AppData\Local\RsFnlcmdhR
2016-03-21 23:42 - 2016-02-06 14:02 - 00000000 ____D C:\Users\Neku\Documents\Adobe
2016-03-21 21:07 - 2016-02-25 19:20 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2016-03-21 21:06 - 2016-02-06 13:53 - 00000000 ____D C:\Program Files\Common Files\Adobe
2016-03-21 20:57 - 2016-02-06 13:54 - 00000000 ____D C:\ProgramData\Adobe
2016-03-21 20:56 - 2016-02-06 13:52 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-03-20 01:56 - 2015-10-30 09:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-03-20 01:49 - 2015-10-30 09:24 - 00000000 ____D C:\Program Files\Common Files\System
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2016-04-09 15:23 - 2016-04-09 15:23 - 0005120 _____ () C:\Users\Neku\AppData\Roaming\GiftBag.db
2016-02-02 14:46 - 2016-02-02 14:46 - 0000000 ___SH () C:\Users\Neku\AppData\Local\LumaEmu
2016-04-10 13:23 - 2016-04-10 13:23 - 0007607 _____ () C:\Users\Neku\AppData\Local\Resmon.ResmonCfg
2016-03-15 15:18 - 2016-03-15 15:18 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Einige Dateien in TEMP:
====================
C:\Users\Neku\AppData\Local\Temp\ose00000.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2016-04-15 15:58
==================== Ende von FRST.txt ============================