|
Plagegeister aller Art und deren Bekämpfung: Windows 7: C:/Trojan:Win32/Wysotot!InkWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
23.04.2014, 19:34 | #1 |
| Windows 7: C:/Trojan:Win32/Wysotot!Ink Hi, ich brauch Eure Hilfe, bitte, dies ist sozusagen ein Gemeinschafts'Pc, wir sind eine kleine private Einrichtung, wo der PC von 3 Verschiedenen Personen benutzt wird. Nun hab ich das "Glück" den PC nutzen zu wollen und bekomme Warnmeldungen von dem Antivirusprogramm, es gibt Spyware usw...ich soll den PC bereinigen und ständig öffnen sich irgendwelche Fenster, die ich gar nicht brauch. Desweiteren geht Mozilla Firefox nicht, als Standardbrowser, ist dieser eingestellt. Nun ist hier alternativ Google Chrome in Benutzung. Auch von Google Chrome, kommen hier Warnmeldungen der PC ist verseucht. Ich kenne Eure Webseite von einem gutem Freund und weiß, das ich es mit Euch hier wieder hin bekommen werden. Nur weil der Pc so verschieden benutzt wird, kann ich nicht genau sagen, woher hier der Trojaner oder ähnlich her ist, auch konnte ich bis jetzt keine weiteren Symtome feststellen. Keiner von den Personen die den Pc benutzen weiß natürlich was.... Im Microsoft Security Essentials Verlauf steht unter Quaratäne: Trojan:Win32/Wysotot!Ink Mehr kann ich erstmal Euch nicht sagen. Danke Euch schonmal vielmals. |
23.04.2014, 19:45 | #2 |
/// the machine /// TB-Ausbilder | Windows 7: C:/Trojan:Win32/Wysotot!Ink hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
23.04.2014, 22:52 | #3 |
| Windows 7: C:/Trojan:Win32/Wysotot!Ink C:/FRST.txt:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-04-2014 Ran by Pippifax (administrator) on PIPPIFAX-THINK on 23-04-2014 23:38:51 Running from C:\Users\Pippifax\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AuthenTec, Inc) C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe (Lenovo.) C:\Windows\system32\ibmpmsvc.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Cherished Technololgy LIMITED) C:\ProgramData\IePluginService\PluginService.exe (Taiwan Shui Mu Chih Ching Technology Limited.) C:\Program Files (x86)\WinZipper\winzipersvc.exe (Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe (Just Develop It) C:\Program Files (x86)\MyPC Backup\BackupStack.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe () C:\Program Files\003\buuoujqmrk64.exe (Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe (Lenovo Group Limited) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe () C:\Program Files (x86)\LPT\srpts.exe () C:\Program Files (x86)\Re-markit-soft\Re-markit157.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe (Samsung) C:\Program Files (x86)\Samsung Inkjet\AiO\Center\SPAiOHostService.exe (Samsung) C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPPrinterSDK.exe (Samsung Electronics Co., Ltd.) C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SAsrv.exe (Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe (Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe () C:\Program Files (x86)\RightSurf\updateRightSurf.exe () C:\Program Files (x86)\RightSurf\bin\utilRightSurf.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe (Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Intel Corporation) C:\Windows\system32\igfxext.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\TouchControl.exe () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Lenovo.) C:\Windows\System32\TpShocks.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Smartbar) C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxTray64.exe (MyPCBackup.com) C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe (Intel Corporation) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (Samsung) C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPStatusMonitor.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe () C:\Program Files (x86)\Re-markit-soft\Re-markit_wd.exe (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpressServer.exe () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Lrcnta.exe () C:\Program Files (x86)\RightSurf\bin\FilterApp_C64.exe () C:\Program Files (x86)\RightSurf\bin\RightSurf.BrowserAdapter.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Lenovo) C:\Program Files (x86)\Lenovo\message center plus\mcplaunch.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Conduit) C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Conduit) C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe (Conduit) C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [178960 2012-03-15] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11407120 2012-03-27] (Intel Corporation) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [564352 2012-03-01] (Conexant Systems, Inc.) HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] () HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1654400 2012-02-21] (Conexant Systems, Inc.) HKLM\...\Run: [TpShocks] => C:\Windows\system32\TpShocks.exe [382528 2012-02-25] (Lenovo.) HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [290160 2012-06-01] (Lenovo Group Limited) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [IntelPROSet] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4756240 2012-02-26] (Intel(R) Corporation) HKLM\...\Run: [] => [X] HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-03-07] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-04-13] (Intel Corporation) HKLM-x32\...\Run: [RotateImage] => C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.) HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [507744 2011-12-20] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [PWMTRV] => rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [1091376 2012-01-17] (Lenovo) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-13] (Lenovo, Inc.) HKLM-x32\...\Run: [IntelSBA] => C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\UI\IntelSmallBusinessAdvantage.exe [4243168 2012-04-23] (Intel Corporation) HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2008-12-24] (CyberLink) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePDRShortCut] => C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl8] => C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe [91432 2009-04-16] (CyberLink Corp.) HKLM-x32\...\Run: [PDVD8LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe [50472 2009-04-16] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePPShortCut] => C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2009-03-12] (CyberLink Corp.) HKLM-x32\...\Run: [BingDesktop] => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2249352 2013-06-27] (Microsoft Corp.) HKLM-x32\...\Run: [Conime] => %windir%\system32\conime.exe HKLM-x32\...\Run: [SPStatusMonitor] => C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPStatusMonitor.exe [2778016 2012-11-14] (Samsung) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3270821018-310773288-2480351254-1000\...\Run: [Browser Infrastructure Helper] => C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.exe [21536 2014-02-09] (Smartbar) HKU\S-1-5-21-3270821018-310773288-2480351254-1000\...\Run: [GoogleChromeAutoLaunch_2814A6EC815B16EF397FE9F43BF95EB7] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [841032 2014-04-02] (Google Inc.) HKU\S-1-5-21-3270821018-310773288-2480351254-1000\...\MountPoints2: {6f751c26-4664-11e2-bc78-806e6f6e6963} - Q:\LenovoQDrive.exe AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [1355552 2014-04-08] (Conduit) AppInit_DLLs-x32: c:\progra~2\searchprotect\searchprotect\bin\spvc32loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [1050912 2014-04-08] (Conduit) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Network PC Fax.lnk ShortcutTarget: Samsung Network PC Fax.lnk -> C:\Windows\System32\spool\drivers\x64\3\NetFaxTray64.exe (Samsung Electronics Co., Ltd.) Startup: C:\Users\Pippifax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com) Startup: C:\Users\Pippifax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: http=127.0.0.1:13828 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1391901139&from=cor&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?gd=&ctid=CT3323900&octid=EB_ORIGINAL_CTID&ISID=M865116B7-E3C5-41BC-959F-BE8033E23DE1&SearchSource=55&CUI=&UM=5&UP=SPE5B598BD-7664-4BF9-A569-42E851CA7503&SSPV= HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna0_ccKZ8Eu5STmGwuIPQf1aGviDWZStUkblTAO0jz8PCQEO19OZE-ToI8FGQzqXpwqreIKViF6lC9u0wnuZ7ZJbRaiVRGgcsZAM13CPitSi_SAwDOd4aNcA6MLZ3Fr9wA,,&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=ds&from=wpm0226&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19&ts=1393411269&type=default&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna0_ccKZ8Eu5STmGwuIPQf1aGviDWZStUkblTAO0jz8PCQEO19OZE-ToI8FGQzqXpwqreIKViF6lC9u0wnuZ7ZJbRaiVRGgcsZAM13CPitSi_SAwDOd4aNcA6MLZ3Fr9wA,,&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1391901139&from=cor&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1391901139&from=cor&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.sweet-page.com/?type=hp&ts=1391901139&from=cor&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1391901139&from=cor&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1391901139&from=cor&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1391901139&from=cor&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.sweet-page.com/?type=hp&ts=1391901139&from=cor&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1391901139&from=cor&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.sweet-page.com/?type=sc&ts=1391901139&from=cor&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1391901139&from=cor&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19&q={searchTerms} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1391901139&from=cor&uid=WDCXWD5000BPKT-08PK4T0_WD-WXD1E72YCH19YCH19&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna0_ccKZ8Eu5STmGwuIPQf1aGviDWZStUkblTAO0jz8PCQEO19OZE-ToI8FGQzqXpwqreIKViF6lC9u0wnuZ7ZJbRaiVRGgcsZAM13CPitSi_SAwDOd4aNcA6MLZ3Fr9wA,,&q={searchTerms} SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna0_ccKZ8Eu5STmGwuIPQf1aGviDWZStUkblTAO0jz8PCQEO19OZE-ToI8FGQzqXpwqreIKViF6lC9u0wnuZ7ZJbRaiVRGgcsZAM13CPitSi_SAwDOd4aNcA6MLZ3Fr9wA,,&q={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna0_ccKZ8Eu5STmGwuIPQf1aGviDWZStUkblTAO0jz8PCQEO19OZE-ToI8FGQzqXpwqreIKViF6lC9u0wnuZ7ZJbRaiVRGgcsZAM13CPitSi_SAwDOd4aNcA6MLZ3Fr9wA,,&q={searchTerms} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna0_ccKZ8Eu5STmGwuIPQf1aGviDWZStUkblTAO0jz8PCQEO19OZE-ToI8FGQzqXpwqreIKViF6lC9u0wnuZ7ZJbRaiVRGgcsZAM13CPitSi_SAwDOd4aNcA6MLZ3Fr9wA,,&q={searchTerms} BHO: MediaPlayerplus - {11111111-1111-1111-1111-110511421146} - C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-bho64.dll (Freeven) BHO: SmartbarInternetExplorerBHOEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\IEBHO.DLL (AuthenTec Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation) BHO-x32: 2rs3 - {10AD2C61-0898-4348-8600-14A342F22AC3} - C:\Program Files (x86)\SupraSavings\2rs3.dll () BHO-x32: MediaPlayerplus - {11111111-1111-1111-1111-110511421146} - C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-bho.dll (Freeven) BHO-x32: SmartbarInternetExplorerBHOEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited) BHO-x32: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\x86\IEBHO.dll (AuthenTec Inc.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Samsung BHO Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files (x86)\Samsung AnyWeb Print\W2PBrowser.dll () BHO-x32: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation) Toolbar: HKLM - Shopping Helper Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Shopping Helper Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default FF NewTab: hxxp://search.conduit.com/?gd=&ctid=CT3323900&octid=EB_ORIGINAL_CTID&ISID=M865116B7-E3C5-41BC-959F-BE8033E23DE1&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SPE5B598BD-7664-4BF9-A569-42E851CA7503 FF SelectedSearchEngine: Conduit Search FF Homepage: hxxp://search.conduit.com/?gd=&ctid=CT3323900&octid=EB_ORIGINAL_CTID&ISID=M865116B7-E3C5-41BC-959F-BE8033E23DE1&SearchSource=55&CUI=&UM=5&UP=SPE5B598BD-7664-4BF9-A569-42E851CA7503&SSPV= FF Keyword.URL: hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna0_ccKZ8Eu5STmGwuIPQf1aGviDWZStUkblTAO0jz8PCQEO19OZE-ToI8FGQzqXpwqreIKViF6lC9u0wnuZ7ZJbRaiVRGgcsZAM13CPitSi_SAwDOd4aNcA6MLZ3Fr9wA,,&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @authentec.com/ffwloplugin - C:\Program Files\Lenovo Fingerprint Reader\npffwloplugin.dll (AuthenTec, Inc) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\searchplugins\conduit-search.xml FF SearchPlugin: C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\delta-homes.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: free ven - C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\Extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com [2014-03-13] FF Extension: MediaPlayerplus - C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\Extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com [2014-04-23] FF Extension: Quick Start - C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\Extensions\quick_start@gmail.com [2014-02-26] FF Extension: SupraSavings - C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\Extensions\SupraSavings@jetpack [2014-04-23] FF Extension: Shopping Helper Smartbar - C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\Extensions\{4d0d6d2c-42a1-e9d7-e187-3f1847b7305f} [2014-03-13] FF HKLM-x32\...\Firefox\Extensions: [VIP1X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] FF HKLM-x32\...\Firefox\Extensions: [VIP2X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] FF HKLM-x32\...\Firefox\Extensions: [quick_start@gmail.com] - C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\extensions\quick_start@gmail.com FF Extension: Quick Start - C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\extensions\quick_start@gmail.com [2014-02-26] FF HKCU\...\Firefox\Extensions: [{88849db3-dcd8-4efe-bcbb-af92b5c8ec55}] - C:\Program Files (x86)\Re-markit-soft\157.xpi FF Extension: Re-markit - C:\Program Files (x86)\Re-markit-soft\157.xpi [2014-03-13] Chrome: ======= CHR StartupUrls: "http://www.trojaner-board.de/" CHR Extension: (SupraSavings) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\afjegdojkkoghnbiollpogeeimocanmk [2014-04-23] CHR Extension: (Newhub) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\aoejbmmillcdifgagjpdlaamnalbielp [2014-03-14] CHR Extension: (Google Docs) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-14] CHR Extension: (Google Drive) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-14] CHR Extension: (YouTube) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-14] CHR Extension: (Website Logon) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\clglhglbidpdbjffpfcldkifhdegdfle [2014-03-14] CHR Extension: (Google-Suche) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-14] CHR Extension: (MediaPlayerplus) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd [2014-04-23] CHR Extension: (Google Wallet) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-14] CHR Extension: (Google Mail) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-14] CHR HKLM\...\Chrome\Extension: [aoejbmmillcdifgagjpdlaamnalbielp] - C:\Users\Pippifax\AppData\Local\nwhb-v9.4.15.crx [2014-03-14] CHR HKCU\...\Chrome\Extension: [aoejbmmillcdifgagjpdlaamnalbielp] - C:\Users\Pippifax\AppData\Local\nwhb-v9.4.15.crx [2014-03-14] CHR HKLM-x32\...\Chrome\Extension: [aoejbmmillcdifgagjpdlaamnalbielp] - C:\Users\Pippifax\AppData\Local\nwhb-v9.4.15.crx [2014-03-14] CHR HKLM-x32\...\Chrome\Extension: [clglhglbidpdbjffpfcldkifhdegdfle] - C:\Program Files\Lenovo Fingerprint Reader\x86\tschrome.crx [2013-04-01] ==================== Services (Whitelisted) ================= R2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36392 2014-02-18] (Just Develop It) R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-27] (Microsoft Corp.) R2 buuoujqmrk64; C:\Program Files\003\buuoujqmrk64.exe [706560 2014-04-23] () R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [2470688 2014-04-08] (Conduit) R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [169776 2012-01-17] (Lenovo) R2 FPLService; C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe [2139944 2013-08-07] (AuthenTec, Inc) R2 IePluginService; C:\ProgramData\IePluginService\PluginService.exe [705136 2014-04-11] (Cherished Technololgy LIMITED) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-07] () R2 Intel(R) Small Business Advantage; C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe [46816 2012-04-23] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-07] (Intel Corporation) R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [179568 2012-06-01] (Lenovo Group Limited) R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited) R2 LPTSystemUpdater; C:\Program Files (x86)\LPT\srpts.exe [32288 2014-02-09] () S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1674720 2013-09-25] () R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 Re-markit; C:\Program Files (x86)\Re-markit-soft\Re-markit157.exe [194048 2014-03-13] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2008-11-25] () R2 Samsung AiO Network Discovery Service; C:\Program Files (x86)\Samsung Inkjet\AiO\Center\SPAiOHostService.exe [395168 2012-11-14] (Samsung) R2 Samsung AIO Status Monitor Service; C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPPrinterSDK.exe [722336 2012-11-14] (Samsung) R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [503344 2013-01-14] (Samsung Electronics Co., Ltd.) S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22888 2013-09-17] () R3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401704 2013-07-22] (AuthenTec, Inc.) R2 Update RightSurf; C:\Program Files (x86)\RightSurf\updateRightSurf.exe [350496 2014-04-23] () R2 Util RightSurf; C:\Program Files (x86)\RightSurf\bin\utilRightSurf.exe [350496 2014-04-23] () R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [84080 2012-04-19] (Symantec Corporation) R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [425104 2014-02-26] (Taiwan Shui Mu Chih Ching Technology Limited.) R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [501904 2014-02-26] (Cherished Technololgy LIMITED) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) R2 SAService; %SystemRoot%\system32\SAsrv.exe [X] ==================== Drivers (Whitelisted) ==================== S3 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [70416 2012-01-17] (Windows (R) Win 7 DDK provider) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.) R3 SmbDrvIntel; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [27448 2012-06-19] (Synaptics Incorporated) R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.) R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-07] (ThinkVantage Communications Utility) R1 wStLib64; C:\Windows\System32\drivers\wStLib64.sys [61112 2014-03-18] (StdLib) R1 wStLibG64; C:\Windows\System32\drivers\wStLibG64.sys [61112 2014-03-14] (StdLib) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-23 23:38 - 2014-04-23 23:39 - 00034707 _____ () C:\Users\Pippifax\Downloads\FRST.txt 2014-04-23 23:38 - 2014-04-23 23:38 - 00000000 ____D () C:\FRST 2014-04-23 23:37 - 2014-04-23 23:38 - 02061312 _____ (Farbar) C:\Users\Pippifax\Downloads\FRST64 (1).exe 2014-04-23 23:37 - 2014-04-23 23:37 - 02061312 _____ (Farbar) C:\Users\Pippifax\Downloads\FRST64.exe 2014-04-23 23:33 - 2014-04-23 23:33 - 00991504 _____ () C:\Users\Pippifax\Downloads\setup (5).exe 2014-04-23 23:28 - 2014-04-23 23:28 - 00000316 _____ () C:\Windows\PFRO.log 2014-04-23 20:11 - 2014-04-23 20:11 - 00001715 _____ () C:\Users\Pippifax\Desktop\Continue FLV Player.lnk 2014-04-23 20:10 - 2014-04-23 20:10 - 00000000 ____D () C:\Program Files (x86)\SearchProtect 2014-04-23 20:09 - 2014-04-23 20:09 - 00991504 _____ () C:\Users\Pippifax\Downloads\setup (4).exe 2014-04-23 20:08 - 2014-04-23 20:09 - 00991504 _____ () C:\Users\Pippifax\Downloads\setup (3).exe 2014-04-23 20:08 - 2014-04-23 20:09 - 00991504 _____ () C:\Users\Pippifax\Downloads\setup (2).exe 2014-04-23 20:08 - 2014-04-23 20:08 - 00991504 _____ () C:\Users\Pippifax\Downloads\setup (1).exe 2014-04-23 20:06 - 2014-04-23 20:06 - 00000000 ____D () C:\Users\Pippifax\Documents\Optimizer Pro 2014-04-23 19:59 - 2014-04-23 19:59 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\com 2014-04-23 19:51 - 2014-04-23 19:51 - 00000000 ____D () C:\Program Files\suprasavings 2014-04-23 19:51 - 2014-04-23 19:51 - 00000000 ____D () C:\Program Files (x86)\SupraSavings 2014-04-23 19:50 - 2014-04-23 23:34 - 00003132 _____ () C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-3.job 2014-04-23 19:50 - 2014-04-23 23:29 - 00002208 _____ () C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-4.job 2014-04-23 19:50 - 2014-04-23 23:29 - 00001504 _____ () C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-5.job 2014-04-23 19:50 - 2014-04-23 23:29 - 00001446 _____ () C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-1.job 2014-04-23 19:50 - 2014-04-23 23:29 - 00001428 _____ () C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-2.job 2014-04-23 19:50 - 2014-04-23 20:35 - 00000000 ____D () C:\Users\Pippifax\AppData\Roaming\Activeris 2014-04-23 19:50 - 2014-04-23 19:50 - 00006162 _____ () C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-3 2014-04-23 19:50 - 2014-04-23 19:50 - 00005238 _____ () C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-4 2014-04-23 19:50 - 2014-04-23 19:50 - 00004534 _____ () C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-5 2014-04-23 19:50 - 2014-04-23 19:50 - 00004476 _____ () C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-1 2014-04-23 19:50 - 2014-04-23 19:50 - 00004458 _____ () C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-2 2014-04-23 19:50 - 2014-04-23 19:50 - 00000000 ____D () C:\Program Files (x86)\MediaPlayerplus 2014-04-23 19:49 - 2014-04-23 19:51 - 00000000 ____D () C:\Program Files\003 2014-04-23 19:48 - 2014-04-23 19:48 - 00803320 _____ () C:\Users\Pippifax\Downloads\Setup.exe 2014-04-23 19:43 - 2014-04-23 23:28 - 00000112 _____ () C:\Windows\setupact.log 2014-04-23 19:43 - 2014-04-23 19:43 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-09 22:45 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 22:45 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 22:45 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 22:45 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 22:44 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 22:44 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 22:44 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 22:44 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 22:44 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 22:44 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 22:44 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 22:44 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 22:44 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 22:44 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 22:44 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe ==================== One Month Modified Files and Folders ======= 2014-04-23 23:39 - 2014-04-23 23:38 - 00034707 _____ () C:\Users\Pippifax\Downloads\FRST.txt 2014-04-23 23:38 - 2014-04-23 23:38 - 00000000 ____D () C:\FRST 2014-04-23 23:38 - 2014-04-23 23:37 - 02061312 _____ (Farbar) C:\Users\Pippifax\Downloads\FRST64 (1).exe 2014-04-23 23:37 - 2014-04-23 23:37 - 02061312 _____ (Farbar) C:\Users\Pippifax\Downloads\FRST64.exe 2014-04-23 23:36 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-23 23:36 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-23 23:34 - 2014-04-23 19:50 - 00003132 _____ () C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-3.job 2014-04-23 23:34 - 2012-12-15 13:57 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-04-23 23:34 - 2012-12-15 13:57 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-04-23 23:34 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-23 23:33 - 2014-04-23 23:33 - 00991504 _____ () C:\Users\Pippifax\Downloads\setup (5).exe 2014-04-23 23:33 - 2014-03-13 13:59 - 00000398 _____ () C:\Windows\Tasks\Re-markit Update.job 2014-04-23 23:32 - 2014-03-14 11:00 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-23 23:32 - 2012-12-15 05:12 - 01794004 _____ () C:\Windows\WindowsUpdate.log 2014-04-23 23:31 - 2014-02-26 12:42 - 00000000 ____D () C:\Program Files (x86)\WinZipper 2014-04-23 23:31 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini 2014-04-23 23:29 - 2014-04-23 19:50 - 00002208 _____ () C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-4.job 2014-04-23 23:29 - 2014-04-23 19:50 - 00001504 _____ () C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-5.job 2014-04-23 23:29 - 2014-04-23 19:50 - 00001446 _____ () C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-1.job 2014-04-23 23:29 - 2014-04-23 19:50 - 00001428 _____ () C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-2.job 2014-04-23 23:29 - 2014-03-14 11:00 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-23 23:29 - 2014-03-13 13:59 - 00000396 _____ () C:\Windows\Tasks\Re-markit_wd.job 2014-04-23 23:29 - 2013-03-07 10:58 - 00017408 _____ () C:\Windows\system32\rpcnetp.exe 2014-04-23 23:29 - 2013-03-07 10:53 - 00000000 ____D () C:\ProgramData\Samsung Inkjet 2014-04-23 23:29 - 2013-03-03 20:44 - 00000000 ____D () C:\Users\Pippifax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-04-23 23:29 - 2012-12-15 05:14 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-04-23 23:28 - 2014-04-23 23:28 - 00000316 _____ () C:\Windows\PFRO.log 2014-04-23 23:28 - 2014-04-23 19:43 - 00000112 _____ () C:\Windows\setupact.log 2014-04-23 23:28 - 2013-03-07 10:58 - 00017408 _____ () C:\Windows\SysWOW64\rpcnetp.exe 2014-04-23 23:28 - 2013-03-07 10:58 - 00017408 _____ () C:\Windows\SysWOW64\rpcnetp.dll 2014-04-23 23:28 - 2013-03-02 22:51 - 00069792 _____ (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.dll 2014-04-23 23:28 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-23 20:35 - 2014-04-23 19:50 - 00000000 ____D () C:\Users\Pippifax\AppData\Roaming\Activeris 2014-04-23 20:20 - 2013-03-07 10:20 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-23 20:12 - 2014-02-09 01:12 - 00000304 _____ () C:\Windows\Tasks\UpdaterEX.job 2014-04-23 20:11 - 2014-04-23 20:11 - 00001715 _____ () C:\Users\Pippifax\Desktop\Continue FLV Player.lnk 2014-04-23 20:10 - 2014-04-23 20:10 - 00000000 ____D () C:\Program Files (x86)\SearchProtect 2014-04-23 20:10 - 2014-03-13 13:59 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\SearchProtect 2014-04-23 20:09 - 2014-04-23 20:09 - 00991504 _____ () C:\Users\Pippifax\Downloads\setup (4).exe 2014-04-23 20:09 - 2014-04-23 20:08 - 00991504 _____ () C:\Users\Pippifax\Downloads\setup (3).exe 2014-04-23 20:09 - 2014-04-23 20:08 - 00991504 _____ () C:\Users\Pippifax\Downloads\setup (2).exe 2014-04-23 20:08 - 2014-04-23 20:08 - 00991504 _____ () C:\Users\Pippifax\Downloads\setup (1).exe 2014-04-23 20:06 - 2014-04-23 20:06 - 00000000 ____D () C:\Users\Pippifax\Documents\Optimizer Pro 2014-04-23 19:59 - 2014-04-23 19:59 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\com 2014-04-23 19:51 - 2014-04-23 19:51 - 00000000 ____D () C:\Program Files\suprasavings 2014-04-23 19:51 - 2014-04-23 19:51 - 00000000 ____D () C:\Program Files (x86)\SupraSavings 2014-04-23 19:51 - 2014-04-23 19:49 - 00000000 ____D () C:\Program Files\003 2014-04-23 19:50 - 2014-04-23 19:50 - 00006162 _____ () C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-3 2014-04-23 19:50 - 2014-04-23 19:50 - 00005238 _____ () C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-4 2014-04-23 19:50 - 2014-04-23 19:50 - 00004534 _____ () C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-5 2014-04-23 19:50 - 2014-04-23 19:50 - 00004476 _____ () C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-1 2014-04-23 19:50 - 2014-04-23 19:50 - 00004458 _____ () C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-2 2014-04-23 19:50 - 2014-04-23 19:50 - 00000000 ____D () C:\Program Files (x86)\MediaPlayerplus 2014-04-23 19:50 - 2014-03-13 14:00 - 00000000 ____D () C:\Program Files (x86)\LPT 2014-04-23 19:49 - 2014-03-13 13:59 - 00000000 _____ () C:\END 2014-04-23 19:48 - 2014-04-23 19:48 - 00803320 _____ () C:\Users\Pippifax\Downloads\Setup.exe 2014-04-23 19:43 - 2014-04-23 19:43 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-21 21:40 - 2014-02-09 01:12 - 00000000 ____D () C:\ProgramData\IePluginService 2014-04-21 21:40 - 2014-02-09 01:12 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-04-21 21:34 - 2014-03-14 11:00 - 00002186 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-21 21:02 - 2013-03-07 10:20 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-21 21:02 - 2013-03-07 10:20 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-21 21:02 - 2013-03-07 10:20 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-21 21:02 - 2013-02-14 18:11 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\Adobe 2014-04-10 10:23 - 2013-08-16 13:21 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 10:19 - 2013-03-07 10:07 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-10 10:17 - 2013-03-02 22:50 - 00069792 ____N (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe 2014-04-09 22:34 - 2013-07-17 23:16 - 00000000 ____D () C:\Users\Pippifax\Fibu 2014-04-08 13:37 - 2013-02-08 22:37 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-04-08 13:37 - 2013-02-08 22:36 - 00002128 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk 2014-04-08 13:37 - 2013-02-08 22:36 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-04-08 13:37 - 2013-02-08 22:36 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2014-04-08 13:33 - 2012-12-14 21:43 - 00000000 ____D () C:\ProgramData\Lenovo 2014-04-08 13:27 - 2014-03-14 11:00 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-08 13:27 - 2014-03-14 11:00 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-31 03:16 - 2014-04-09 22:45 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 22:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 22:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 22:45 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll Some content of TEMP: ==================== C:\Users\Pippifax\AppData\Local\Temp\1_Offer_5.exe C:\Users\Pippifax\AppData\Local\Temp\amsetup_activeris_default_010414_installer.exe C:\Users\Pippifax\AppData\Local\Temp\f978377c-b7d4-4536-8e10-14ca97b13394.exe C:\Users\Pippifax\AppData\Local\Temp\instract.exe C:\Users\Pippifax\AppData\Local\Temp\mainapp.exe C:\Users\Pippifax\AppData\Local\Temp\mediaplayerpluus.exe C:\Users\Pippifax\AppData\Local\Temp\nsa95FC.exe C:\Users\Pippifax\AppData\Local\Temp\nsaAB52.exe C:\Users\Pippifax\AppData\Local\Temp\nsaE6C2.exe C:\Users\Pippifax\AppData\Local\Temp\nsqDA52.exe C:\Users\Pippifax\AppData\Local\Temp\nsqE0B9.exe C:\Users\Pippifax\AppData\Local\Temp\nsv9F50.exe C:\Users\Pippifax\AppData\Local\Temp\optimizerpro.exe C:\Users\Pippifax\AppData\Local\Temp\SearchProtectINT.exe C:\Users\Pippifax\AppData\Local\Temp\setup.exe C:\Users\Pippifax\AppData\Local\Temp\spidentifierimpl.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-20 14:51 ==================== End Of Log ============================ C:/Addition.txt:FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-04-2014 Ran by Pippifax at 2014-04-23 23:40:14 Running from C:\Users\Pippifax\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.9.0.1380 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.9.0.1380 - Adobe Systems Incorporated) Hidden Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.182 - Adobe Systems Incorporated) Adobe Reader X (10.1.9) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.9 - Adobe Systems Incorporated) aioscnnr (x32 Version: 1.2.3.10 - Your Company Name) Hidden Anzeige am Bildschirm (HKLM\...\OnScreenDisplay) (Version: 6.72.00 - ) Bing-Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.174.0 - Microsoft Corporation) Burn.Now 4.5 (x32 Version: 4.5.0 - Corel Corporation) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.27 - Piriform) center (x32 Version: 1.2.5.0 - Samsung Electronics) Hidden Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.34.0 - Conexant) Corel Burn.Now Lenovo Edition (HKLM-x32\...\InstallShield_{A3BE3F1E-2472-4211-8735-E8239BE49D9F}) (Version: 4.5.0 - Corel Corporation) Corel DVD MovieFactory 7 (x32 Version: 7.0.0 - Corel Corporation) Hidden Corel DVD MovieFactory Lenovo Edition (HKLM-x32\...\InstallShield_{50F68032-B5B7-4513-9116-C978DBD8F27A}) (Version: 7.0.0 - Corel Corporation) Corel WinDVD (HKLM-x32\...\{5C1F18D2-F6B7-4242-B803-B5A78648185D}) (Version: 10.0.6.392 - Corel Inc.) Create Recovery Media (HKLM-x32\...\{50DC5136-21E8-48BC-97E5-1AD055F6B0B6}) (Version: 1.20.0.00 - Lenovo Group Limited) CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.2604 - CyberLink Corp.) CyberLink DVD Suite (x32 Version: 6.0.2604 - CyberLink Corp.) Hidden CyberLink LabelPrint (HKLM-x32\...\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.20.3605 - CyberLink Corp.) CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.2809 - CyberLink Corp.) CyberLink Power2Go (x32 Version: 6.0.2809 - CyberLink Corp.) Hidden CyberLink PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2426 - CyberLink Corp.) CyberLink PowerDirector (x32 Version: 7.0.2426 - CyberLink Corp.) Hidden CyberLink PowerDVD 8 (HKLM-x32\...\InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}) (Version: 8.0.2815 - CyberLink Corp.) CyberLink PowerDVD 8 (x32 Version: 8.0.2815 - CyberLink Corp.) Hidden CyberLink PowerProducer (HKLM-x32\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.0.1.1410 - CyberLink Corp.) CyberLink PowerProducer (x32 Version: 5.0.1.1410 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Direct DiscRecorder (x32 Version: 1.00.0000 - Corel Corporation) Hidden Energie-Manager (HKLM-x32\...\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}) (Version: 6.32 - ) essentials (x32 Version: 1.2.5.0 - Samsung Electronics) Hidden Evernote v. 4.2.3 (HKLM-x32\...\{F761359C-9CED-45AE-9A51-9D6605CD55C4}) (Version: 4.2.3.15 - Evernote Corp.) Extended Update (HKCU\...\UpdaterEX) (Version: - Extended Update) Fingerprint Reader (HKLM\...\{7DD99174-299B-4450-A179-7F27F4C2D042}) (Version: 6.0.200.105 - AuthenTec, Inc.) Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden IePluginService12.27.0.3326 (HKLM-x32\...\IePlugins) (Version: 12.27.0.3326 - Cherished Technololgy LIMITED) <==== ATTENTION Integrated Camera Driver Installer Package Ver.1.2.1.18 (HKLM-x32\...\{A78800AF-1779-4AE8-8EBE-16E1BE727C71}) (Version: 1.2.1.18 - RICOH) Intel AppUp(SM) center (HKLM-x32\...\Intel AppUp(SM) center 33057) (Version: 3.6.1.33057.10 - Intel) Intel PROSet Wireless (Version: - ) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.4.1441 - Intel Corporation) Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2778 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\...\{37EC048A-81A2-452A-8D1F-3BE2018E767D}) (Version: 15.1.0.0096 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{3015F546-6C3E-4E6A-B564-BCDF88C0BA2A}) (Version: 2.1.1.0153 - Intel Corporation) Intel(R) Update Manager (x32 Version: 1.0.0.34813 - Intel Corporation) Hidden Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.225 - Intel Corporation) Intel(R) WiDi (HKLM-x32\...\{93F34C5C-ACAA-48F3-9B26-70359A117F12}) (Version: 3.0.12.0 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel® PROSet/Wireless WiFi-Software (HKLM\...\{E97F409F-9E1C-42A0-B72D-765A78DF3696}) (Version: 15.01.0000.0830 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 1.11 - ) Lenovo Patch Utility (HKLM-x32\...\{6E6E7725-C7BC-4C39-8B3F-14B67331A120}) (Version: 1.3.0.9 - Lenovo Group Limited) Lenovo Patch Utility 64 bit (HKLM\...\{0369F866-2CE0-4EB9-B426-88FA122C6E82}) (Version: 1.3.0.9 - Lenovo Group Limited) Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.04.04 - ) Lenovo Registration (HKLM-x32\...\{6707C034-ED6B-4B6A-B21F-969B3606FBDE}) (Version: 1.0.4 - Lenovo Inc.) Lenovo SimpleTap (HKLM\...\{BF601122-9F0A-41A9-BA06-3158D9FB4B80}) (Version: 3.2.0004.00 - Lenovo Group Limited) Lenovo Solution Center (HKLM\...\{D60E3A84-5DDC-49ED-B9A5-E3466996EB36}) (Version: 2.3.002.00 - Lenovo Group Limited) Lenovo Solutions for Small Business (HKLM-x32\...\{6A6D86CD-B004-46b7-8951-7BB75A776F8C}) (Version: - Intel(R) Corporation) Lenovo Solutions for Small Business Customizations (HKLM-x32\...\{5B5DEF99-85E9-423D-A1A3-B83202697B09}) (Version: 1.0.0006.00 - Lenovo Group Limited) Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.03.0005 - Lenovo) Lenovo User Guide (HKLM-x32\...\{13F59938-C595-479C-B479-F171AB9AF64F}) (Version: 1.0.0009.00 - Lenovo Group Limited) Lenovo Warranty Information (HKLM-x32\...\{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}) (Version: 1.0.0005.00 - Lenovo) Lenovo Welcome (HKLM-x32\...\{2DC26D10-CC6A-494F-BEA3-B5BC21126D5E}) (Version: 3.1.0020.00 - Lenovo Group Limited) LPT System Updater Service (x32 Version: 1.0.0.0 - LPT) Hidden <==== ATTENTION MAGIX Foto Manager MX Deluxe (HKLM-x32\...\MAGIX_{6E6FF6CD-9CF3-4434-BB5D-24943FD54FFC}) (Version: 9.0.2.251 - MAGIX AG) MAGIX Foto Manager MX Deluxe (Version: 9.0.2.251 - MAGIX AG) Hidden MAGIX Slideshow Maker 2 (HKLM-x32\...\MAGIX_{48897B17-3DD2-4BAA-A81D-4E4EA8E9FD51}) (Version: 2.0.1.9 - MAGIX AG) MAGIX Slideshow Maker 2 (Version: 2.0.1.9 - MAGIX AG) Hidden MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{87DCF176-32A1-4BC2-B86B-AAEB2CF7DA15}) (Version: 7.0.2.6 - MAGIX AG) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden MAGIX Video deluxe 2013 (HKLM-x32\...\MAGIX_{8C73E551-5AFA-42EE-B76E-64821590BCD3}) (Version: 12.0.2.2 - MAGIX AG) MAGIX Video deluxe 2013 (Version: 12.0.2.2 - MAGIX AG) Hidden MediaPlayerplus (HKLM-x32\...\MediaPlayerplus) (Version: 1.34.4.10 - Freeven) <==== ATTENTION Mein Verein (HKLM-x32\...\{9ACE3A18-EE13-4012-989C-2BCDC95BA6B9}_is1) (Version: 14.0 - Buhl Data Service GmbH) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Message Center Plus (HKLM\...\{3849486C-FF09-4F5D-B491-3E179D58EE15}) (Version: 3.1.0004.00 - Lenovo Group Limited) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 27.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyPC Backup (HKLM\...\MyPC Backup) (Version: - JDi Backup Ltd) <==== ATTENTION ocr (x32 Version: 6.0.0.0 - Samsung Electronics) Hidden OpenOffice.org 3.4.1 (HKLM-x32\...\{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}) (Version: 3.41.9593 - Apache Software Foundation) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.8 - Google, Inc.) PreReq (x32 Version: 6.2.3.0 - Eastman Kodak Company) Hidden RapidBoot HDD Accelerator (HKLM-x32\...\Fastboot) (Version: 1.00.0802 - Lenovo) RapidBoot Shield (HKLM\...\{5E2652DF-743F-482B-A593-C95F431A5769}) (Version: 1.23 - Lenovo) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.29005 - Realtek Semiconductor Corp.) Re-markit (HKLM-x32\...\1ac6ebd8-24fb-42f2-89aa-135a3b547de0) (Version: - Re-markit Software) <==== ATTENTION RightSurf (HKLM\...\RightSurf) (Version: 2014.02.07.164730 - RightSurf) <==== ATTENTION Samsung AIO Printer (Version: 1.2.3.0 - Eastman Kodak Company) Hidden Samsung All-in-One Software (HKLM-x32\...\{F6CF5E37-1B3A-4e5e-87AC-CFEFCC464A1B}) (Version: 1.2.5.0 - Samsung Electronics Co., Ltd.) Samsung AnyWeb Print (HKLM-x32\...\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 2.0.75.0 - Samsung Electronics Co., Ltd.) Samsung Easy Color Manager (HKLM-x32\...\{778EACF8-06C1-47AA-9284-91550E9BAD39}) (Version: 3.02.04 - Samsung Electronics Co., Ltd.) Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.02.91.00(16.01.2013) - Samsung Electronics Co., Ltd.) Samsung Network PC Fax (HKLM-x32\...\Samsung Network PC Fax) (Version: 1.09.11 (14.01.2013) - Samsung Electronics Co., Ltd.) Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 1.2.6.0 - Samsung Electronics Co., Ltd.) Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.12.20.154 - Conduit) <==== ATTENTION Shopping Helper Smartbar (HKLM-x32\...\{AC6E9B2A-A7E6-4B17-8A6C-29D519673E12}) (Version: 10.215.63.15249 - ReSoft Ltd.) <==== ATTENTION Shopping Helper Smartbar Engine (HKCU\...\{bc6557d1-046d-4e43-a41c-f0cfd5784c7f}) (Version: 10.215.63.15249 - ReSoft Ltd.) <==== ATTENTION SugarSync Manager (HKLM-x32\...\SugarSync) (Version: 1.9.61.90905 - SugarSync, Inc.) suprasavings (HKLM\...\suprasavings) (Version: 2.0.1 - suprasavings) <==== ATTENTION SupraSavings (x32 Version: 1.0.0.0 - SupraSavings) Hidden <==== ATTENTION SupTab (HKLM-x32\...\SupTab) (Version: 1.1.1.0 - ) <==== ATTENTION ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.19.7 - ) ThinkVantage Communications Utility (HKLM\...\{88C6A6D9-324C-46E8-BA87-563D14021442}_is1) (Version: 3.0.34.0 - Lenovo) ThinkVantage System für aktiven Festplattenschutz (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.76 - Lenovo) VIP Access (HKLM-x32\...\{E8D46836-CD55-453C-A107-A59EC51CB8DC}) (Version: 2.0.5.13 - VeriSign) VLC media player 2.0.7 (HKLM-x32\...\VLC media player) (Version: 2.0.7 - VideoLAN) VO Package (HKLM-x32\...\VOPackage) (Version: 1.0.0.0 - ) <==== ATTENTION Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows-Treiberpaket - Intel (iaStor) hdc (11/29/2011 11.0.0.1032) (HKLM\...\64A62163FE43328D13305746CB8BCC93F2DF6545) (Version: 11/29/2011 11.0.0.1032 - Intel) Windows-Treiberpaket - Lenovo 1.65.05.21 (01/11/2012 1.65.05.21) (HKLM\...\FD2ED46D31CE7DF190049D079E92DE03D347A634) (Version: 01/11/2012 1.65.05.21 - Lenovo) WinZipper (HKLM-x32\...\WinZipper) (Version: 1.5.29 - Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION ==================== Restore Points ========================= 08-02-2014 22:27:32 Windows-Sicherung 08-02-2014 22:38:53 Windows-Sicherung 08-02-2014 22:46:46 Windows-Sicherung 08-02-2014 23:23:19 Uniblue DriverScanner installation 08-02-2014 23:35:17 Windows-Sicherung 26-02-2014 10:49:31 Windows Update 06-03-2014 12:21:39 Windows Update 07-03-2014 07:39:57 Windows Update 09-03-2014 20:29:09 Windows-Sicherung 13-03-2014 11:54:17 Windows Update 14-03-2014 08:50:36 Windows Update 18-03-2014 12:41:40 Windows Update 08-04-2014 11:27:18 Windows Update 08-04-2014 11:34:07 Windows Update 10-04-2014 08:18:41 Windows Update 21-04-2014 19:06:36 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {08ABBD0A-FF66-4C7E-9F05-267962A640DC} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {09684A18-3CC2-4B32-9E27-D0EE63FCC9A4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-14] (Google Inc.) Task: {12579CAC-0B72-4B60-97F6-83E7853BF818} - System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-5 => C:\Program Files (x86)\MediaPlayerplus\34c732ce-385e-453a-80a0-2300f29d65ac-5.exe [2014-04-23] (Freeven) <==== ATTENTION Task: {244F7349-9E29-4605-BE4E-72D43BC500A0} - System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-1 => C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-codedownloader.exe [2014-04-23] (Freeven) <==== ATTENTION Task: {28E1FFAE-C56F-4A37-90BA-4104945F333D} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2013-09-25] (Lenovo) Task: {2D5AD224-C74E-4DA1-AA70-8AE0B4F17308} - System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-3 => C:\Program Files (x86)\MediaPlayerplus\34c732ce-385e-453a-80a0-2300f29d65ac-3.exe [2014-04-23] (Freeven) <==== ATTENTION Task: {33AB8577-B7D2-42FF-83DE-26F1FA57DE8E} - System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-2 => C:\Program Files (x86)\MediaPlayerplus\34c732ce-385e-453a-80a0-2300f29d65ac-2.exe [2014-04-23] (Freeven) <==== ATTENTION Task: {5675129E-A4BF-4A83-81C7-2DA3D5AA7C33} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-21] (Adobe Systems Incorporated) Task: {582D01E8-9105-4039-BB0B-A39D8A2A845F} - System32\Tasks\{B903FE48-5794-4FE2-90CC-D112C976E910} => Firefox.exe Task: {697D5C95-73D1-4377-8F63-35A25C8E18A5} - System32\Tasks\PMTask => C:\Program Files (x86)\ThinkPad\Utilities\PWMIDTSV.EXE [2012-05-15] (Lenovo Group Limited) Task: {6C23F7E8-2CEA-4FE2-B5C9-957B8CC0D51E} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2013-09-25] (Lenovo) Task: {6EC5B411-5730-456C-A78E-3EF6013813A9} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2013-09-17] () Task: {8BF85A18-1DA0-4FE4-92C6-5C0E9C2A1F3D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-14] (Google Inc.) Task: {90721164-FC71-46D7-9E6D-98E3C90C50E1} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2013-09-25] () Task: {94097C26-547F-4A59-B899-3616AFC56113} - System32\Tasks\Lenovo\SimpleTap\Start SimpleTap for Pippifax-THINK.Pippifax => C:\Program Files\Lenovo\SimpleTap\SimpleTap.exe [2012-05-15] (Lenovo) Task: {95E68F3F-DA90-476D-B5A0-41DA0FCC52BA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd) Task: {9784065B-66D0-4F2E-A785-D2BB43B14FD2} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {9C70C9D3-56A9-4B3E-8F20-93473D954F86} - System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-4 => C:\Program Files (x86)\MediaPlayerplus\34c732ce-385e-453a-80a0-2300f29d65ac-4.exe [2014-04-23] (Freeven) <==== ATTENTION Task: {A9CD530F-701F-47A6-8E25-751E10302AAD} - System32\Tasks\Lenovo\Message Center Plus Launcher => C:\Program Files (x86)\Lenovo\message center plus\mcplaunch.exe [2012-05-15] (Lenovo) Task: {B1EE36EE-73F8-4A06-B4E5-D54FCB701758} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {C68DAC31-C417-430E-8BCB-D4BB75516CF6} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {CC3BF299-9DEE-4868-9162-23BAC955CEF1} - System32\Tasks\Re-markit_wd => C:\Program Files (x86)\Re-markit-soft\Re-markit_wd.exe [2014-03-13] () <==== ATTENTION Task: {CC485FCE-DDAC-4B55-B3EB-EF8CFF5399A0} - System32\Tasks\UpdaterEX => C:\Users\Pippifax\AppData\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {CFF372DC-22AE-4AB1-B134-44D0323422B4} - System32\Tasks\Microsoft\Windows\PLA\LSC Memory => Rundll32.exe C:\Windows\system32\pla.dll,PlaHost "LSC Memory" "$(Arg0)" Task: {D7F721BE-10B3-41C0-8210-BAA84B4B69BC} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {D9921AC7-F6C3-4AEE-86A4-76B8F3258119} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2013-09-25] () Task: {DC30AC8C-69D1-4A1D-958F-CE8504FFDD57} - System32\Tasks\Re-markit Update => C:\Program Files (x86)\Re-markit-soft\ReMar.exe [2014-03-13] () <==== ATTENTION Task: {DD8D1A27-A264-487E-882E-BB50BC0803CB} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-1.job => C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-codedownloader.exe Task: C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-2.job => C:\Program Files (x86)\MediaPlayerplus\34c732ce-385e-453a-80a0-2300f29d65ac-2.exe Task: C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-3.job => C:\Program Files (x86)\MediaPlayerplus\34c732ce-385e-453a-80a0-2300f29d65ac-3.exe Task: C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-4.job => C:\Program Files (x86)\MediaPlayerplus\34c732ce-385e-453a-80a0-2300f29d65ac-4.exe Task: C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-5.job => C:\Program Files (x86)\MediaPlayerplus\34c732ce-385e-453a-80a0-2300f29d65ac-5.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\Re-markit Update.job => C:\Program Files (x86)\Re-markit-soft\ReMar.exe <==== ATTENTION Task: C:\Windows\Tasks\Re-markit_wd.job => C:\Program Files (x86)\Re-markit-soft\Re-markit_wd.exe <==== ATTENTION Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\Pippifax\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2014-02-18 15:32 - 2014-02-18 15:32 - 01102336 _____ () C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll 2014-04-23 19:51 - 2014-04-23 19:51 - 00706560 _____ () C:\Program Files\003\buuoujqmrk64.exe 2012-12-15 05:13 - 2012-03-07 00:49 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 2014-02-09 13:41 - 2014-02-09 13:41 - 00032288 _____ () C:\Program Files (x86)\LPT\srpts.exe 2014-03-13 13:59 - 2014-03-13 13:59 - 00194048 _____ () C:\Program Files (x86)\Re-markit-soft\Re-markit157.exe 2013-03-03 20:50 - 2008-11-25 16:27 - 00247152 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2014-02-07 18:47 - 2014-04-23 20:17 - 00350496 _____ () C:\Program Files (x86)\RightSurf\updateRightSurf.exe 2014-02-09 09:54 - 2014-04-23 19:44 - 00350496 _____ () C:\Program Files (x86)\RightSurf\bin\utilRightSurf.exe 2012-12-15 05:23 - 2012-05-15 23:32 - 00103936 ____N () C:\Program Files (x86)\ThinkPad\Utilities\GR\PWMRT64V.DLL 2012-12-15 05:14 - 2012-06-25 08:19 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-08-07 04:03 - 2013-08-07 04:03 - 01130792 _____ () C:\Program Files\Lenovo Fingerprint Reader\DataManager.dll 2013-08-07 04:04 - 2013-08-07 04:04 - 00087848 _____ () C:\Program Files\Lenovo Fingerprint Reader\ssutil.dll 2012-12-15 05:19 - 2010-10-26 06:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe 2014-02-18 15:38 - 2014-02-18 15:38 - 00012288 _____ () C:\Program Files (x86)\MyPC Backup\GetText.dll 2014-03-13 13:59 - 2014-03-13 13:59 - 00093696 _____ () C:\Program Files (x86)\Re-markit-soft\Re-markit_wd.exe 2014-02-09 13:40 - 2014-02-09 13:40 - 00012832 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Lrcnta.exe 2014-03-14 11:20 - 2014-03-14 11:20 - 00287008 _____ () C:\Program Files (x86)\RightSurf\bin\FilterApp_C64.exe 2014-04-23 20:15 - 2014-04-17 22:26 - 00095520 _____ () C:\Program Files (x86)\RightSurf\bin\RightSurf.BrowserAdapter.exe 2011-01-27 16:28 - 2011-01-27 16:28 - 00706048 _____ () C:\Windows\system32\SnMinDrv.dll 2013-01-14 19:19 - 2013-01-14 19:19 - 00091136 _____ () C:\Windows\system32\SSDEVM64.DLL 2014-02-26 12:42 - 2014-02-26 12:42 - 00612496 _____ () C:\Program Files (x86)\WinZipper\sqlite3.dll 2012-12-15 05:30 - 2012-01-17 08:29 - 00030512 ____N () C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBServiceps.dll 2012-12-15 05:24 - 2011-08-02 05:58 - 02201088 _____ () C:\Program Files\Lenovo\Communications Utility\cxcore210.dll 2012-12-15 05:24 - 2011-08-02 05:58 - 02085888 _____ () C:\Program Files\Lenovo\Communications Utility\cv210.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00070176 _____ () C:\Program Files (x86)\LPT\srpt.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00022048 _____ () C:\Program Files (x86)\LPT\srptc.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00018976 _____ () C:\Program Files (x86)\LPT\Smartbar.Common.dll 2013-03-03 20:50 - 2008-11-25 16:27 - 00034088 ____N () C:\Program Files (x86)\Cyberlink\Shared files\RichVideops.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00033824 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00063520 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\srau.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00166432 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 02310688 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00058400 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\spbl.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00152608 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00013344 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\siem.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00054304 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\sppsm.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00728096 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00082464 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00014368 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00017440 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00052256 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\srut.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00020512 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\srsbs.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00059424 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00037408 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\srbu.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00014368 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\sgml.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00053280 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00014880 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\srpdm.dll 2014-02-09 13:40 - 2014-02-09 13:40 - 00048160 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\MACTrackBarLib.dll 2014-02-09 13:37 - 2014-02-09 13:37 - 00026144 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00025632 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00193056 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\sgmu.dll 2014-02-09 13:37 - 2014-02-09 13:37 - 00061440 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll 2014-02-09 13:41 - 2014-02-09 13:41 - 00247328 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\srns.dll 2014-04-21 21:34 - 2014-04-02 03:57 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll 2014-04-23 20:15 - 2014-04-17 22:26 - 00179488 _____ () C:\Program Files (x86)\RightSurf\bin\RightSurfBAApp.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00891392 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\QtNetwork4.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 02281984 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\QtCore4.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00322048 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\log4cplus.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00339456 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\QtXml4.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00400384 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\sqlite3.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00016896 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\featureController.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00062976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\osEvents.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00195584 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\libgsoap.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00062464 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\zlib1.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00446976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\deviceProfile.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00019456 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\eventsSender.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00062976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\serviceManagerStarter.dll 2008-12-24 13:29 - 2008-12-24 13:29 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2008-12-24 13:30 - 2008-12-24 13:30 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2014-04-21 21:34 - 2014-04-02 03:57 - 00674632 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libglesv2.dll 2014-04-21 21:34 - 2014-04-02 03:57 - 00093000 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libegl.dll 2014-04-21 21:34 - 2014-04-02 03:57 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll 2014-04-21 21:34 - 2014-04-02 03:58 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll 2014-04-21 21:34 - 2014-04-02 03:57 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll 2012-08-10 17:51 - 2012-08-10 17:51 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 2009-03-30 15:02 - 2009-03-30 15:02 - 01197352 ____N () C:\Program Files (x86)\CyberLink\Power2Go\Language\DEU\P2GRC.dll 2007-11-27 22:14 - 2007-11-27 22:14 - 00144680 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLVistaAudioMixer.dll 2014-02-09 13:40 - 2014-02-09 13:40 - 00020512 _____ () C:\Users\Pippifax\AppData\Local\Smartbar\Application\lrcnt.dll 2012-12-15 05:13 - 2012-03-07 00:27 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2012-12-15 05:45 - 2012-04-23 16:03 - 00030432 _____ () C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\ProcessPrivileges.dll 2012-12-15 05:45 - 2012-04-23 16:03 - 00215264 _____ () C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\System.ComponentModel.Composition.dll 2012-12-15 05:45 - 2012-04-23 16:03 - 00051424 _____ () C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Interop.TaskScheduler.dll 2014-04-21 21:34 - 2014-04-02 03:58 - 13691720 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (04/23/2014 11:28:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/23/2014 07:53:45 PM) (Source: MsiInstaller) (User: Pippifax-THINK) Description: Product: SupraSavings -- Error 1925. You do not have sufficient privileges to complete this installation for all users of the machine. Log on as administrator and then retry this installation. Error: (04/23/2014 07:51:57 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: MsiExec.exe, Version: 5.0.7601.17514, Zeitstempel: 0x4ce792c4 Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b96f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000efc6 ID des fehlerhaften Prozesses: 0x3418 Startzeit der fehlerhaften Anwendung: 0xMsiExec.exe0 Pfad der fehlerhaften Anwendung: MsiExec.exe1 Pfad des fehlerhaften Moduls: MsiExec.exe2 Berichtskennung: MsiExec.exe3 Error: (04/23/2014 07:43:34 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/21/2014 09:38:14 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/21/2014 08:55:29 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/10/2014 10:17:45 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: jscript9.dll, Version: 11.0.9600.16521, Zeitstempel: 0x53115050 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00161600 ID des fehlerhaften Prozesses: 0x1fc4 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/10/2014 10:17:21 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: jscript9.dll, Version: 11.0.9600.16521, Zeitstempel: 0x53115050 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00161600 ID des fehlerhaften Prozesses: 0xf14 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/10/2014 10:14:52 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/09/2014 09:43:38 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (04/23/2014 11:29:46 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (04/23/2014 07:54:21 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Installer" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (04/23/2014 07:52:21 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/23/2014 07:44:33 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (04/21/2014 09:39:13 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (04/21/2014 08:56:28 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (04/21/2014 08:55:39 PM) (Source: Microsoft Antimalware) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 110.31.0.0 Aktualisierungsquelle: %NT-AUTORITÄT51 Aktualisierungsphase: 4.5.0216.00 Quellpfad: 4.5.0216.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\NETZWERKDIENST Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Error: (04/21/2014 08:55:39 PM) (Source: Microsoft Antimalware) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.169.2028.0 Aktualisierungsquelle: %NT-AUTORITÄT51 Aktualisierungsphase: 4.5.0216.00 Quellpfad: 4.5.0216.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\NETZWERKDIENST Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Error: (04/21/2014 08:55:39 PM) (Source: Microsoft Antimalware) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.169.2028.0 Aktualisierungsquelle: %NT-AUTORITÄT51 Aktualisierungsphase: 4.5.0216.00 Quellpfad: 4.5.0216.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\NETZWERKDIENST Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Error: (04/21/2014 08:55:39 PM) (Source: Microsoft Antimalware) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.169.2028.0 Aktualisierungsquelle: %NT-AUTORITÄT59 Aktualisierungsphase: 4.5.0216.00 Quellpfad: 4.5.0216.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\SYSTEM Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Microsoft Office Sessions: ========================= Error: (04/23/2014 11:28:51 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/23/2014 07:53:45 PM) (Source: MsiInstaller)(User: Pippifax-THINK) Description: Product: SupraSavings -- Error 1925. You do not have sufficient privileges to complete this installation for all users of the machine. Log on as administrator and then retry this installation.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (04/23/2014 07:51:57 PM) (Source: Application Error)(User: ) Description: MsiExec.exe5.0.7601.175144ce792c4ole32.dll6.1.7601.175144ce7b96fc00000050000efc6341801cf5f1cb595b463c:\Windows\syswow64\MsiExec.exeC:\Windows\syswow64\ole32.dllf5fe13d4-cb0f-11e3-bbdd-6036dd83012a Error: (04/23/2014 07:43:34 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/21/2014 09:38:14 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/21/2014 08:55:29 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/10/2014 10:17:45 AM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399jscript9.dll11.0.9600.1652153115050c0000005001616001fc401cf5495524ef179C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\jscript9.dll97a799bd-c088-11e3-b1a4-6036dd83012a Error: (04/10/2014 10:17:21 AM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399jscript9.dll11.0.9600.1652153115050c000000500161600f1401cf54951f9829acC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\jscript9.dll897dfbda-c088-11e3-b1a4-6036dd83012a Error: (04/10/2014 10:14:52 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/09/2014 09:43:38 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2013-06-13 10:42:58.792 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-13 10:42:58.752 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-13 10:42:58.702 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\gpapi.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-13 10:42:58.572 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\gpapi.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-02 22:06:51.228 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-02 22:06:51.208 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-02 22:06:51.178 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\gpapi.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-02 22:06:51.158 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\gpapi.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 18:47:56.391 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 18:47:56.361 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 39% Total physical RAM: 7781.47 MB Available physical RAM: 4701.25 MB Total Pagefile: 15561.12 MB Available Pagefile: 11989.77 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (Windows7_OS) (Fixed) (Total:446.72 GB) (Free:366.69 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive q: (Lenovo_Recovery) (Fixed) (Total:17.58 GB) (Free:5.18 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 8F1615B9) Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=447 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=18 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
24.04.2014, 12:46 | #4 |
/// the machine /// TB-Ausbilder | Windows 7: C:/Trojan:Win32/Wysotot!Ink Revo Uninstaller - Download - Filepony Damit alles deinstallieren was Du in der Additional.txt findest mit dem Zusatz <== ATTENTION Mit Revo auch Moderat die Reste entfernen lassen. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.04.2014, 21:12 | #5 |
| Windows 7: C:/Trojan:Win32/Wysotot!Ink Hallo Schrauber, also ich weiß nicht ob das mit dem Uninstaller alles so glatt lief. Denn einiges aus der Additional.txt war nicht zu finden, ich werde es unten noch aufführen welche. Ich habe mich entschieden, nun jetzt schon zu schreiben, ohne die nachfolgenden Schritte gemacht zu haben. Das ganze kommt mir hier komisch vor. Beim ersten öffnen vom Uninstaller kamen 81 Programme/Komponente gefunden, habe fleißig immer moderat deinstalliert, gelöscht, allerdings die letzten Einträge wurden immer vom Uninstaller in den Papierkorb verschoben, den habe ich vorerst nicht geleert. Dann kam ich zum Löschen von VO Package (HKLM-x32\...\VOPackage) (Version: 1.0.0.0 - ) <==== ATTENTION Der Scan dauerte sehr lang, im Gegensatz zu den anderen. Dann verschwanden plötzlich alle angezeigten Programme, (während des Scans) bis auf zwei. Sie kehren auch nicht nach einem Neustart des Uninstallers zurück. Dann gab es über 4000 gefundende Registry Einträge in den 'Resten' (fett gedruckt) die ich dann aber nicht gelöscht habe und habe auf abbrechen geklickt. Weil es mir zu seltsam vorkam. War das falsch? Wenn ich nun den Uninstaller starte dann stehen da -Extended Update und Lenovo Simple Tap- mehr nicht. Erfolgreich deinstalliert, bevor alles "verschwand" wurde: 1.IePluginService12.27.0.3326 (HKLM-x32\...\IePlugins) (Version: 12.27.0.3326 - Cherished Technololgy LIMITED) <==== ATTENTION 2.MediaPlayerplus (HKLM-x32\...\MediaPlayerplus) (Version: 1.34.4.10 - Freeven) <==== ATTENTION 3.Re-markit (HKLM-x32\...\1ac6ebd8-24fb-42f2-89aa-135a3b547de0) (Version: - Re-markit Software) <==== ATTENTION 4.Shopping Helper Smartbar (HKLM-x32\...\{AC6E9B2A-A7E6-4B17-8A6C-29D519673E12}) (Version: 10.215.63.15249 - ReSoft Ltd.) <==== ATTENTION 5.Shopping Helper Smartbar Engine (HKCU\...\{bc6557d1-046d-4e43-a41c-f0cfd5784c7f}) (Version: 10.215.63.15249 - ReSoft Ltd.) <==== ATTENTION 6.SupTab (HKLM-x32\...\SupTab) (Version: 1.1.1.0 - ) <==== ATTENTION Nicht gelöscht wurde weil es nicht da stand: 1.LPT System Updater Service (x32 Version: 1.0.0.0 - LPT) Hidden <==== ATTENTION 2.MyPC Backup (HKLM\...\MyPC Backup) (Version: - JDi Backup Ltd) <==== ATTENTION 3.RightSurf (HKLM\...\RightSurf) (Version: 2014.02.07.164730 - RightSurf) <==== ATTENTION 4.suprasavings (HKLM\...\suprasavings) (Version: 2.0.1 - suprasavings) <==== ATTENTION 5.SupraSavings (x32 Version: 1.0.0.0 - SupraSavings) Hidden <==== ATTENTION 6.WinZipper (HKLM-x32\...\WinZipper) (Version: 1.5.29 - Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION (Win Zipper war vor dem löschen von VO Package in der Liste vorhanden, doch dann ja nicht mehr) Und nun, wie soll ich weiter machen? |
25.04.2014, 18:53 | #6 |
/// the machine /// TB-Ausbilder | Windows 7: C:/Trojan:Win32/Wysotot!Ink Bite mal die drei tools laufen lassen. Dann FRST öffnen, Haken setzen bei Additional und scannen, poste bitte beide Logfiles.
__________________ --> Windows 7: C:/Trojan:Win32/Wysotot!Ink |
27.04.2014, 11:17 | #7 |
| Windows 7: C:/Trojan:Win32/Wysotot!Ink Hallo Schrauber, ich muss erstmal eine Pause einlegen, mit der PC Reparatur, da ich in den Kurzurlaub gefahren bin. Habe zwar Internetzugang, aber den PC wollte ich nicht unbedingt mitnehmen;-) Am 07.05. kann ich dann wieder weiter machen. Ich hoffe das ist in Ordung für Dich. Grüße Faxikus |
28.04.2014, 08:34 | #8 |
/// the machine /// TB-Ausbilder | Windows 7: C:/Trojan:Win32/Wysotot!Ink klar
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.05.2014, 21:38 | #9 |
| Windows 7: C:/Trojan:Win32/Wysotot!Ink Hallo Schrauber, ich bin wieder am Start.... Habe nun die 3 Tools laufen lassen, hier sind die Ergebnisse: Ist mbam.txt richtig? Also das da nur was von update steht? Es gab -zig Funde, alle in Quarantäne geschoben usw....alles gemacht wie 'vorgeschrieben'. Beim Browser Chrome ist auch nach der Reinigung schon Besserung zu merken, endlich gehen nicht mehr 1000 ungewollte Tabs oder Fenster auf!!!! Es schalteten sich sogar die Webseiten von allein auf irgend ein Quatsch um...... ------gruß Faxikus C:/ mbam.text: Malwarebytes Anti-Malware www.malwarebytes.org Update, 09.05.2014 21:20:47, SYSTEM, PIPPIFAX-THINK, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1, Update, 09.05.2014 21:20:53, SYSTEM, PIPPIFAX-THINK, Manual, Malware Database, 2014.3.4.9, 2014.5.9.11, (end) C:/ adw cleaner.txt: AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.207 - Bericht erstellt am 09/05/2014 um 22:00:19 # Aktualisiert 05/05/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Pippifax - PIPPIFAX-THINK # Gestartet von : C:\Users\Pippifax\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : BackupStack [#] Dienst Gelöscht : buuoujqmrk64 [#] Dienst Gelöscht : Update RightSurf [#] Dienst Gelöscht : Util RightSurf Dienst Gelöscht : winzipersvc [#] Dienst Gelöscht : Wpm Dienst Gelöscht : wStLibG64 ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Partner Ordner Gelöscht : C:\ProgramData\simplitec Ordner Gelöscht : C:\ProgramData\Uniblue Ordner Gelöscht : C:\ProgramData\WPM Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup Ordner Gelöscht : C:\Program Files (x86)\PC Speed Maximizer Ordner Gelöscht : C:\Program Files (x86)\RightSurf Ordner Gelöscht : C:\Program Files (x86)\SupraSavings Ordner Gelöscht : C:\Program Files (x86)\WinZipper Ordner Gelöscht : C:\Program Files\003 Ordner Gelöscht : C:\Program Files\SupraSavings Ordner Gelöscht : C:\Users\Pippifax\AppData\Local\LPT Ordner Gelöscht : C:\Users\Pippifax\AppData\Local\Smartbar Ordner Gelöscht : C:\Users\Pippifax\AppData\Local\Temp\Smartbar Ordner Gelöscht : C:\Users\Pippifax\AppData\LocalLow\Smartbar Ordner Gelöscht : C:\Users\Pippifax\AppData\Roaming\Activeris Ordner Gelöscht : C:\Users\Pippifax\AppData\Roaming\simplitec Ordner Gelöscht : C:\Users\Pippifax\AppData\Roaming\SupTab Ordner Gelöscht : C:\Users\Pippifax\AppData\Roaming\UpdaterEX Ordner Gelöscht : C:\Users\Pippifax\AppData\Roaming\WinZipper Ordner Gelöscht : C:\Users\Pippifax\Documents\Optimizer Pro Ordner Gelöscht : C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\Extensions\quick_start@gmail.com Ordner Gelöscht : C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\Extensions\SupraSavings@jetpack Ordner Gelöscht : C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\Extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com Ordner Gelöscht : C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\Extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com Ordner Gelöscht : C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd Ordner Gelöscht : C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\afjegdojkkoghnbiollpogeeimocanmk Datei Gelöscht : C:\END Datei Gelöscht : C:\Users\Pippifax\AppData\Roaming\aps.uninstall.scan.results Datei Gelöscht : C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\searchplugins\conduit-search.xml Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\delta-homes.xml Datei Gelöscht : C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\searchplugins\Web Search.xml Datei Gelöscht : C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage Datei Gelöscht : C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage-journal Datei Gelöscht : C:\Windows\Tasks\APSnotifierPP1.job Datei Gelöscht : C:\Windows\System32\Tasks\APSnotifierPP1 Datei Gelöscht : C:\Windows\Tasks\APSnotifierPP2.job Datei Gelöscht : C:\Windows\System32\Tasks\APSnotifierPP2 Datei Gelöscht : C:\Windows\Tasks\APSnotifierPP3.job Datei Gelöscht : C:\Windows\System32\Tasks\APSnotifierPP3 Datei Gelöscht : C:\Windows\Tasks\UpdaterEX.job Datei Gelöscht : C:\Windows\System32\Tasks\UpdaterEX Datei Gelöscht : C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-1.job Datei Gelöscht : C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-1 Datei Gelöscht : C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-2.job Datei Gelöscht : C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-2 Datei Gelöscht : C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-3.job Datei Gelöscht : C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-3 Datei Gelöscht : C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-4.job Datei Gelöscht : C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-4 Datei Gelöscht : C:\Windows\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-5.job Datei Gelöscht : C:\Windows\System32\Tasks\34c732ce-385e-453a-80a0-2300f29d65ac-5 ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Pippifax\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [quick_start@gmail.com] Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bho Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ActiverisAntiMalware_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ActiverisAntiMalware_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0051678.BHO Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0051678.BHO.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0051678.Sandbox Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0051678.Sandbox.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command Schlüssel Gelöscht : HKCU\Software\AnyProtect Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions Schlüssel Gelöscht : HKCU\Software\RightSurf Schlüssel Gelöscht : HKCU\Software\SearchProtectINT Schlüssel Gelöscht : HKCU\Software\SmartBar Schlüssel Gelöscht : HKCU\Software\smartbarbackup Schlüssel Gelöscht : HKCU\Software\smartbarlog Schlüssel Gelöscht : HKCU\Software\suprasavings Schlüssel Gelöscht : HKCU\Software\UpdaterEX Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\MediaPlayerplus Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Supra Savings Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\suprasavings Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Schlüssel Gelöscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C} Schlüssel Gelöscht : HKLM\Software\delta-homesSoftware Schlüssel Gelöscht : HKLM\Software\hdcode Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions Schlüssel Gelöscht : HKLM\Software\RightSurf Schlüssel Gelöscht : HKLM\Software\supWPM Schlüssel Gelöscht : HKLM\Software\sweet-pageSoftware Schlüssel Gelöscht : HKLM\Software\Uniblue Schlüssel Gelöscht : HKLM\Software\V9 Schlüssel Gelöscht : HKLM\Software\winzipersvc Schlüssel Gelöscht : HKLM\Software\Wpm Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\UpdaterEX Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\LevelQualityWatcher Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\suprasavings Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RightSurf Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\suprasavings ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17041 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default] Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] -\\ Mozilla Firefox v27.0.1 (de) [ Datei : C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\prefs.js ] Zeile gelöscht : user_pref("browser.search.selectedEngine", "Conduit Search"); Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?gd=&ctid=CT3323900&octid=EB_ORIGINAL_CTID&ISID=M865116B7-E3C5-41BC-959F-BE8033E23DE1&SearchSource=55&CUI=&UM=5&UP=SPE5B598BD-7664-4BF9[...] Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false); Zeile gelöscht : user_pref("extensions.helperbar.Visibility", true); Zeile gelöscht : user_pref("extensions.helperbar.backPageCapacity", 3); Zeile gelöscht : user_pref("extensions.helperbar.backPageCounter", 0); Zeile gelöscht : user_pref("extensions.helperbar.backPageDay", 14); Zeile gelöscht : user_pref("extensions.helperbar.backPageLastEvent", "1394614503479"); Zeile gelöscht : user_pref("extensions.helperbar.backPageMinInterval", 15); Zeile gelöscht : user_pref("extensions.helperbar.barcodeid", "129845"); Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "de"); Zeile gelöscht : user_pref("extensions.helperbar.downloadprovider", "ob_[[pubid]]_ch"); Zeile gelöscht : user_pref("extensions.helperbar.fromautoupdate", "false"); Zeile gelöscht : user_pref("extensions.helperbar.installationid", "4d0d6d2c-42a1-e9d7-e187-3f1847b7305f"); Zeile gelöscht : user_pref("extensions.helperbar.installdate", "13/03/2014"); Zeile gelöscht : user_pref("extensions.helperbar.keepAliveLastevent", "1394712153"); Zeile gelöscht : user_pref("extensions.helperbar.publisher", "shoppinghelper"); Zeile gelöscht : user_pref("keyword.URL", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna0_ccKZ8Eu5STmGwuIPQf1aGviDWZStUkblTAO0jz8PCQEO19OZE-ToI8FGQzqXpwqreIKV[...] -\\ Google Chrome v34.0.1847.131 [ Datei : C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Extension] : afjegdojkkoghnbiollpogeeimocanmk Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb Gelöscht [Extension] : majjphhgppkndjjkmhhnbgafooenebhd ************************* AdwCleaner[R0].txt - [21201 octets] - [09/05/2014 21:58:55] AdwCleaner[S0].txt - [17207 octets] - [09/05/2014 22:00:19] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [17268 octets] ########## C:/ JRT.txt: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Pippifax on 09.05.2014 at 22:08:46,88 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Pippifax\appdata\local\{5B7DD395-1094-434B-BE25-A845C21AC06C} Successfully deleted: [Empty Folder] C:\Users\Pippifax\appdata\local\{5DE2DEF5-8D1C-40EB-BAD2-924F54DFCE65} Successfully deleted: [Empty Folder] C:\Users\Pippifax\appdata\local\{694E7D98-5A90-4F6E-BCE1-23E87D655ECC} Successfully deleted: [Empty Folder] C:\Users\Pippifax\appdata\local\{79E42B6F-E4D7-43DD-BCE4-3714DA72B2AC} Successfully deleted: [Empty Folder] C:\Users\Pippifax\appdata\local\{D9A95948-5900-4BA0-92EC-C54768A16341} Successfully deleted: [Empty Folder] C:\Users\Pippifax\appdata\local\{E080D483-F1B8-4246-A8AF-154632C0222A} ~~~ FireFox Emptied folder: C:\Users\Pippifax\AppData\Roaming\mozilla\firefox\profiles\1bg3kpf9.default\minidumps [12 files] ~~~ Event Viewer Logs were cleared Scan was completed on 09.05.2014 at 22:17:14,83 End of JRT log C:/ FRST.txt: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-05-2014 01 Ran by Pippifax (administrator) on PIPPIFAX-THINK on 09-05-2014 22:20:17 Running from C:\Users\Pippifax\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AuthenTec, Inc) C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\TouchControl.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe (Samsung) C:\Program Files (x86)\Samsung Inkjet\AiO\Center\SPAiOHostService.exe (Samsung) C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPPrinterSDK.exe (Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxServer64.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Lenovo.) C:\Windows\System32\TpShocks.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxTray64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe (Intel Corporation) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE (Samsung) C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPStatusMonitor.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Lenovo) C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpressServer.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [178960 2012-03-15] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11407120 2012-03-27] (Intel Corporation) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [564352 2012-03-01] (Conexant Systems, Inc.) HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] () HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1654400 2012-02-21] (Conexant Systems, Inc.) HKLM\...\Run: [TpShocks] => C:\Windows\system32\TpShocks.exe [382528 2012-02-25] (Lenovo.) HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [290160 2012-06-01] (Lenovo Group Limited) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [IntelPROSet] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4756240 2012-02-26] (Intel(R) Corporation) HKLM\...\Run: [] => [X] HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-03-07] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-04-13] (Intel Corporation) HKLM-x32\...\Run: [RotateImage] => C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.) HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [507744 2011-12-20] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [PWMTRV] => rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [1091376 2012-01-17] (Lenovo) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-13] (Lenovo, Inc.) HKLM-x32\...\Run: [IntelSBA] => C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\UI\IntelSmallBusinessAdvantage.exe [4243168 2012-04-23] (Intel Corporation) HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2008-12-24] (CyberLink) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePDRShortCut] => C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl8] => C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe [91432 2009-04-16] (CyberLink Corp.) HKLM-x32\...\Run: [PDVD8LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe [50472 2009-04-16] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePPShortCut] => C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2009-03-12] (CyberLink Corp.) HKLM-x32\...\Run: [BingDesktop] => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2249352 2013-06-27] (Microsoft Corp.) HKLM-x32\...\Run: [Conime] => %windir%\system32\conime.exe HKLM-x32\...\Run: [SPStatusMonitor] => C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPStatusMonitor.exe [2778016 2012-11-14] (Samsung) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3270821018-310773288-2480351254-1000\...\Run: [GoogleChromeAutoLaunch_2814A6EC815B16EF397FE9F43BF95EB7] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [841032 2014-04-24] (Google Inc.) HKU\S-1-5-21-3270821018-310773288-2480351254-1000\...\MountPoints2: {6f751c26-4664-11e2-bc78-806e6f6e6963} - Q:\LenovoQDrive.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: MediaPlayerplus - {11111111-1111-1111-1111-110511421146} - C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-bho64.dll No File BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\IEBHO.DLL (AuthenTec Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation) BHO-x32: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\x86\IEBHO.dll (AuthenTec Inc.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Samsung BHO Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files (x86)\Samsung AnyWeb Print\W2PBrowser.dll () BHO-x32: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @authentec.com/ffwloplugin - C:\Program Files\Lenovo Fingerprint Reader\npffwloplugin.dll (AuthenTec, Inc) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Shopping Helper Smartbar - C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\Extensions\{4d0d6d2c-42a1-e9d7-e187-3f1847b7305f} [2014-03-13] FF HKLM-x32\...\Firefox\Extensions: [VIP1X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] FF HKLM-x32\...\Firefox\Extensions: [VIP2X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] Chrome: ======= CHR HomePage: CHR StartupUrls: "Trojaner-Board - Viren und Trojaner entfernen - kostenlos CHR Extension: (Newhub) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\aoejbmmillcdifgagjpdlaamnalbielp [2014-03-14] CHR Extension: (Google Docs) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-14] CHR Extension: (Google Drive) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-14] CHR Extension: (YouTube) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-14] CHR Extension: (Website Logon) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\clglhglbidpdbjffpfcldkifhdegdfle [2014-03-14] CHR Extension: (Google-Suche) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-14] CHR Extension: (Google Wallet) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-14] CHR Extension: (Google Mail) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-14] CHR HKLM\...\Chrome\Extension: [aoejbmmillcdifgagjpdlaamnalbielp] - C:\Users\Pippifax\AppData\Local\nwhb-v9.4.15.crx [2014-03-14] CHR HKCU\...\Chrome\Extension: [aoejbmmillcdifgagjpdlaamnalbielp] - C:\Users\Pippifax\AppData\Local\nwhb-v9.4.15.crx [2014-03-14] CHR HKLM-x32\...\Chrome\Extension: [aoejbmmillcdifgagjpdlaamnalbielp] - C:\Users\Pippifax\AppData\Local\nwhb-v9.4.15.crx [2014-03-14] CHR HKLM-x32\...\Chrome\Extension: [clglhglbidpdbjffpfcldkifhdegdfle] - C:\Program Files\Lenovo Fingerprint Reader\x86\tschrome.crx [2013-04-01] ==================== Services (Whitelisted) ================= R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-27] (Microsoft Corp.) R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [169776 2012-01-17] (Lenovo) R2 FPLService; C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe [2139944 2013-08-07] (AuthenTec, Inc) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-07] () R2 Intel(R) Small Business Advantage; C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe [46816 2012-04-23] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-07] (Intel Corporation) R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [179568 2012-06-01] (Lenovo Group Limited) R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited) S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1674720 2013-09-25] () R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2008-11-25] () R2 Samsung AiO Network Discovery Service; C:\Program Files (x86)\Samsung Inkjet\AiO\Center\SPAiOHostService.exe [395168 2012-11-14] (Samsung) R2 Samsung AIO Status Monitor Service; C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPPrinterSDK.exe [722336 2012-11-14] (Samsung) R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [503344 2013-01-14] (Samsung Electronics Co., Ltd.) S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22888 2013-09-17] () R3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401704 2013-07-22] (AuthenTec, Inc.) R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [84080 2012-04-19] (Symantec Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) R2 SAService; %SystemRoot%\system32\SAsrv.exe [X] ==================== Drivers (Whitelisted) ==================== S3 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [70416 2012-01-17] (Windows (R) Win 7 DDK provider) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.) R3 SmbDrvIntel; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [27448 2012-06-19] (Synaptics Incorporated) R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.) R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-07] (ThinkVantage Communications Utility) R1 wStLib64; C:\Windows\System32\drivers\wStLib64.sys [61112 2014-03-18] (StdLib) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-09 22:20 - 2014-05-09 22:20 - 00000000 ____D () C:\Users\Pippifax\Desktop\FRST-OlderVersion 2014-05-09 22:17 - 2014-05-09 22:17 - 00001419 _____ () C:\Users\Pippifax\Desktop\JRT.txt 2014-05-09 22:08 - 2014-05-09 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-05-09 22:07 - 2014-05-09 22:08 - 01016261 _____ (Thisisu) C:\Users\Pippifax\Downloads\JRT.exe 2014-05-09 21:59 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-09 21:58 - 2014-05-09 22:00 - 00000000 ____D () C:\AdwCleaner 2014-05-09 21:55 - 2014-05-09 21:55 - 01316991 _____ () C:\Users\Pippifax\Downloads\adwcleaner.exe 2014-05-09 21:53 - 2014-05-09 21:53 - 00000273 _____ () C:\Users\Pippifax\Desktop\mbam.txt 2014-05-09 21:48 - 2014-05-09 21:48 - 00706696 _____ () C:\Users\Pippifax\Downloads\Nicht bestätigt 95849.crdownload 2014-05-09 21:20 - 2014-05-09 21:50 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-09 21:20 - 2014-05-09 21:20 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-09 21:20 - 2014-05-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-09 21:19 - 2014-05-09 21:20 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-09 21:19 - 2014-05-09 21:19 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-09 21:19 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-09 21:19 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-09 21:19 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-09 21:18 - 2014-05-09 21:19 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Pippifax\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-09 21:16 - 2014-05-09 21:16 - 00340480 _____ () C:\Users\Pippifax\Downloads\Setup__4227_il891497.exe 2014-05-09 21:14 - 2014-05-09 21:14 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (6).exe 2014-05-09 21:14 - 2014-05-09 21:14 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (5).exe 2014-05-09 21:09 - 2014-05-09 21:10 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (4).exe 2014-05-09 21:06 - 2014-05-09 21:06 - 00495104 _____ () C:\Users\Pippifax\Downloads\test (3).exe 2014-04-25 22:44 - 2014-04-25 22:44 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (3).exe 2014-04-25 22:41 - 2014-04-25 22:42 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (2).exe 2014-04-25 22:40 - 2014-05-09 22:03 - 00000000 ____D () C:\Users\Pippifax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-04-24 20:46 - 2014-04-24 20:46 - 00001275 _____ () C:\Users\Pippifax\Desktop\Revo Uninstaller.lnk 2014-04-24 20:46 - 2014-04-24 20:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-24 20:45 - 2014-04-24 20:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Pippifax\Downloads\revosetup95.exe 2014-04-24 20:45 - 2014-04-24 20:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Pippifax\Downloads\revosetup95 (1).exe 2014-04-24 20:41 - 2014-04-24 20:41 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (1).exe 2014-04-23 23:56 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-23 23:56 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-23 23:56 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-23 23:56 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-23 23:56 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-23 23:56 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-23 23:56 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-23 23:56 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-23 23:56 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-23 23:56 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-23 23:56 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-23 23:56 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-23 23:56 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-23 23:56 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-23 23:55 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-23 23:55 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-23 23:55 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-23 23:55 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-23 23:55 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-23 23:55 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-23 23:55 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-23 23:55 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-23 23:55 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-23 23:55 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-23 23:55 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-23 23:55 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-23 23:55 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-23 23:55 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-23 23:55 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-23 23:55 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-23 23:55 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-23 23:55 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-23 23:55 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-23 23:55 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-23 23:55 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-23 23:55 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-23 23:55 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-23 23:55 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-23 23:55 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-23 23:55 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-23 23:55 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-23 23:55 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-23 23:55 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-23 23:55 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-23 23:55 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-23 23:55 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-23 23:55 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-23 23:55 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-23 23:40 - 2014-04-23 23:41 - 00051528 _____ () C:\Users\Pippifax\Desktop\Addition.txt 2014-04-23 23:38 - 2014-05-09 22:20 - 00022369 _____ () C:\Users\Pippifax\Desktop\FRST.txt 2014-04-23 23:38 - 2014-05-09 22:20 - 00000000 ____D () C:\FRST 2014-04-23 23:37 - 2014-05-09 22:20 - 02064384 _____ (Farbar) C:\Users\Pippifax\Desktop\FRST64.exe 2014-04-23 23:28 - 2014-05-09 22:01 - 00003142 _____ () C:\Windows\PFRO.log 2014-04-23 19:59 - 2014-04-23 19:59 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\com 2014-04-23 19:48 - 2014-04-23 19:48 - 00803320 _____ () C:\Users\Pippifax\Downloads\Setup.exe 2014-04-23 19:43 - 2014-05-09 22:02 - 00000392 _____ () C:\Windows\setupact.log 2014-04-23 19:43 - 2014-04-23 19:43 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-09 22:44 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 22:44 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 22:44 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 22:44 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 22:44 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 22:44 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 22:44 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 22:44 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 22:44 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 22:44 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 22:44 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe ==================== One Month Modified Files and Folders ======= 2014-05-09 22:21 - 2014-04-23 23:38 - 00022369 _____ () C:\Users\Pippifax\Desktop\FRST.txt 2014-05-09 22:20 - 2014-05-09 22:20 - 00000000 ____D () C:\Users\Pippifax\Desktop\FRST-OlderVersion 2014-05-09 22:20 - 2014-04-23 23:38 - 00000000 ____D () C:\FRST 2014-05-09 22:20 - 2014-04-23 23:37 - 02064384 _____ (Farbar) C:\Users\Pippifax\Desktop\FRST64.exe 2014-05-09 22:20 - 2013-03-07 10:20 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-09 22:20 - 2013-03-07 10:20 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-09 22:20 - 2013-03-07 10:20 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-09 22:20 - 2013-03-07 10:20 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-09 22:17 - 2014-05-09 22:17 - 00001419 _____ () C:\Users\Pippifax\Desktop\JRT.txt 2014-05-09 22:10 - 2014-03-14 11:00 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-09 22:10 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-09 22:10 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-09 22:08 - 2014-05-09 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-05-09 22:08 - 2014-05-09 22:07 - 01016261 _____ (Thisisu) C:\Users\Pippifax\Downloads\JRT.exe 2014-05-09 22:07 - 2012-12-15 13:57 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-05-09 22:07 - 2012-12-15 13:57 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-05-09 22:07 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-09 22:06 - 2012-12-15 05:12 - 01955966 _____ () C:\Windows\WindowsUpdate.log 2014-05-09 22:04 - 2013-03-07 10:58 - 00017408 _____ () C:\Windows\system32\rpcnetp.exe 2014-05-09 22:03 - 2014-04-25 22:40 - 00000000 ____D () C:\Users\Pippifax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-05-09 22:03 - 2014-03-14 11:00 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-09 22:03 - 2012-12-15 05:14 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-05-09 22:02 - 2014-04-23 19:43 - 00000392 _____ () C:\Windows\setupact.log 2014-05-09 22:02 - 2013-03-07 10:58 - 00017408 _____ () C:\Windows\SysWOW64\rpcnetp.dll 2014-05-09 22:02 - 2013-03-07 10:53 - 00000000 ____D () C:\ProgramData\Samsung Inkjet 2014-05-09 22:02 - 2013-03-02 22:51 - 00069792 _____ (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.dll 2014-05-09 22:02 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-09 22:01 - 2014-04-23 23:28 - 00003142 _____ () C:\Windows\PFRO.log 2014-05-09 22:01 - 2013-03-07 10:58 - 00017408 _____ () C:\Windows\SysWOW64\rpcnetp.exe 2014-05-09 22:00 - 2014-05-09 21:58 - 00000000 ____D () C:\AdwCleaner 2014-05-09 21:55 - 2014-05-09 21:55 - 01316991 _____ () C:\Users\Pippifax\Downloads\adwcleaner.exe 2014-05-09 21:53 - 2014-05-09 21:53 - 00000273 _____ () C:\Users\Pippifax\Desktop\mbam.txt 2014-05-09 21:50 - 2014-05-09 21:20 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-09 21:48 - 2014-05-09 21:48 - 00706696 _____ () C:\Users\Pippifax\Downloads\Nicht bestätigt 95849.crdownload 2014-05-09 21:42 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini 2014-05-09 21:20 - 2014-05-09 21:20 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-09 21:20 - 2014-05-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-09 21:20 - 2014-05-09 21:19 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-09 21:19 - 2014-05-09 21:19 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-09 21:19 - 2014-05-09 21:18 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Pippifax\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-09 21:16 - 2014-05-09 21:16 - 00340480 _____ () C:\Users\Pippifax\Downloads\Setup__4227_il891497.exe 2014-05-09 21:14 - 2014-05-09 21:14 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (6).exe 2014-05-09 21:14 - 2014-05-09 21:14 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (5).exe 2014-05-09 21:14 - 2014-03-14 11:00 - 00002186 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-05-09 21:13 - 2013-12-06 11:12 - 00000000 ____D () C:\ldiag 2014-05-09 21:13 - 2012-12-15 05:42 - 00000000 ____D () C:\Windows\System32\Tasks\TVT 2014-05-09 21:13 - 2012-12-15 05:23 - 00000000 ___HD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools 2014-05-09 21:13 - 2012-12-15 05:19 - 00000000 ____D () C:\Program Files (x86)\Lenovo 2014-05-09 21:13 - 2012-12-14 21:43 - 00000000 ____D () C:\ProgramData\Lenovo 2014-05-09 21:10 - 2014-05-09 21:09 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (4).exe 2014-05-09 21:06 - 2014-05-09 21:06 - 00495104 _____ () C:\Users\Pippifax\Downloads\test (3).exe 2014-05-09 21:05 - 2014-03-14 11:00 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-09 21:05 - 2014-03-14 11:00 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-25 22:44 - 2014-04-25 22:44 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (3).exe 2014-04-25 22:42 - 2014-04-25 22:41 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (2).exe 2014-04-24 21:07 - 2014-03-13 13:59 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-04-24 20:46 - 2014-04-24 20:46 - 00001275 _____ () C:\Users\Pippifax\Desktop\Revo Uninstaller.lnk 2014-04-24 20:46 - 2014-04-24 20:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-24 20:45 - 2014-04-24 20:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Pippifax\Downloads\revosetup95.exe 2014-04-24 20:45 - 2014-04-24 20:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Pippifax\Downloads\revosetup95 (1).exe 2014-04-24 20:41 - 2014-04-24 20:41 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (1).exe 2014-04-24 20:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-23 23:41 - 2014-04-23 23:40 - 00051528 _____ () C:\Users\Pippifax\Desktop\Addition.txt 2014-04-23 19:59 - 2014-04-23 19:59 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\com 2014-04-23 19:48 - 2014-04-23 19:48 - 00803320 _____ () C:\Users\Pippifax\Downloads\Setup.exe 2014-04-23 19:43 - 2014-04-23 19:43 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-21 21:02 - 2013-02-14 18:11 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\Adobe 2014-04-10 10:23 - 2013-08-16 13:21 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 10:19 - 2013-03-07 10:07 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-10 10:17 - 2013-03-02 22:50 - 00069792 ____N (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe 2014-04-09 22:34 - 2013-07-17 23:16 - 00000000 ____D () C:\Users\Pippifax\Fibu Some content of TEMP: ==================== C:\Users\Pippifax\AppData\Local\Temp\1_Offer_5.exe C:\Users\Pippifax\AppData\Local\Temp\amsetup_activeris_default_010414_installer.exe C:\Users\Pippifax\AppData\Local\Temp\f978377c-b7d4-4536-8e10-14ca97b13394.exe C:\Users\Pippifax\AppData\Local\Temp\instract.exe C:\Users\Pippifax\AppData\Local\Temp\mainapp.exe C:\Users\Pippifax\AppData\Local\Temp\mediaplayerpluus.exe C:\Users\Pippifax\AppData\Local\Temp\nsa95FC.exe C:\Users\Pippifax\AppData\Local\Temp\nsaAB52.exe C:\Users\Pippifax\AppData\Local\Temp\nsaE6C2.exe C:\Users\Pippifax\AppData\Local\Temp\nsi5FC0.exe C:\Users\Pippifax\AppData\Local\Temp\nsqDA52.exe C:\Users\Pippifax\AppData\Local\Temp\nsqE0B9.exe C:\Users\Pippifax\AppData\Local\Temp\nsv9F50.exe C:\Users\Pippifax\AppData\Local\Temp\optimizerpro.exe C:\Users\Pippifax\AppData\Local\Temp\Quarantine.exe C:\Users\Pippifax\AppData\Local\Temp\SearchProtectINT.exe C:\Users\Pippifax\AppData\Local\Temp\setup.exe C:\Users\Pippifax\AppData\Local\Temp\spidentifierimpl.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-20 14:51 ==================== End Of Log ============================ C:/ Additional.txt:FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-05-2014 01 Ran by Pippifax at 2014-05-09 22:41:27 Running from C:\Users\Pippifax\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.206 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.206 - Adobe Systems Incorporated) Anzeige am Bildschirm (HKLM\...\OnScreenDisplay) (Version: 6.72.00 - ) CCleaner (HKLM\...\CCleaner) (Version: 3.27 - Piriform) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.34.0 - Conexant) Fingerprint Reader (HKLM\...\{7DD99174-299B-4450-A179-7F27F4C2D042}) (Version: 6.0.200.105 - AuthenTec, Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.131 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden Intel PROSet Wireless (Version: - ) Hidden Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\...\{37EC048A-81A2-452A-8D1F-3BE2018E767D}) (Version: 15.1.0.0096 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{3015F546-6C3E-4E6A-B564-BCDF88C0BA2A}) (Version: 2.1.1.0153 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel® PROSet/Wireless WiFi-Software (HKLM\...\{E97F409F-9E1C-42A0-B72D-765A78DF3696}) (Version: 15.01.0000.0830 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation) Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 1.11 - ) Lenovo Patch Utility 64 bit (HKLM\...\{0369F866-2CE0-4EB9-B426-88FA122C6E82}) (Version: 1.3.0.9 - Lenovo Group Limited) Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.04.04 - ) Lenovo SimpleTap (HKLM\...\{BF601122-9F0A-41A9-BA06-3158D9FB4B80}) (Version: 3.2.0004.00 - Lenovo Group Limited) Lenovo Solution Center (HKLM\...\{D60E3A84-5DDC-49ED-B9A5-E3466996EB36}) (Version: 2.3.002.00 - Lenovo Group Limited) Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.05.0009 - Lenovo) MAGIX Foto Manager MX Deluxe (Version: 9.0.2.251 - MAGIX AG) Hidden MAGIX Slideshow Maker 2 (Version: 2.0.1.9 - MAGIX AG) Hidden MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden MAGIX Video deluxe 2013 (Version: 12.0.2.2 - MAGIX AG) Hidden Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) Message Center Plus (HKLM\...\{3849486C-FF09-4F5D-B491-3E179D58EE15}) (Version: 3.1.0004.00 - Lenovo Group Limited) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) RapidBoot Shield (HKLM\...\{5E2652DF-743F-482B-A593-C95F431A5769}) (Version: 1.23 - Lenovo) Samsung AIO Printer (Version: 1.2.3.0 - Eastman Kodak Company) Hidden ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.19.7 - ) ThinkVantage Communications Utility (HKLM\...\{88C6A6D9-324C-46E8-BA87-563D14021442}_is1) (Version: 3.0.34.0 - Lenovo) ThinkVantage System für aktiven Festplattenschutz (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.76 - Lenovo) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows-Treiberpaket - Intel (iaStor) hdc (11/29/2011 11.0.0.1032) (HKLM\...\64A62163FE43328D13305746CB8BCC93F2DF6545) (Version: 11/29/2011 11.0.0.1032 - Intel) Windows-Treiberpaket - Lenovo 1.65.05.21 (01/11/2012 1.65.05.21) (HKLM\...\FD2ED46D31CE7DF190049D079E92DE03D347A634) (Version: 01/11/2012 1.65.05.21 - Lenovo) ==================== Restore Points ========================= 09-03-2014 20:29:09 Windows-Sicherung 13-03-2014 11:54:17 Windows Update 14-03-2014 08:50:36 Windows Update 18-03-2014 12:41:40 Windows Update 08-04-2014 11:27:18 Windows Update 08-04-2014 11:34:07 Windows Update 10-04-2014 08:18:41 Windows Update 21-04-2014 19:06:36 Windows Update 23-04-2014 21:55:27 Windows Update 24-04-2014 18:55:29 Revo Uninstaller's restore point - IePluginService12.27.0.3326 24-04-2014 19:04:31 Revo Uninstaller's restore point - MediaPlayerplus 24-04-2014 19:07:14 Revo Uninstaller's restore point - Re-markit 24-04-2014 19:10:54 Revo Uninstaller's restore point - Search Protect 24-04-2014 19:16:08 Revo Uninstaller's restore point - Shopping Helper Smartbar 24-04-2014 19:18:17 Revo Uninstaller's restore point - Shopping Helper Smartbar 24-04-2014 19:20:03 Revo Uninstaller's restore point - Shopping Helper Smartbar Engine 24-04-2014 19:21:44 Revo Uninstaller's restore point - SupTab 24-04-2014 19:25:09 Revo Uninstaller's restore point - VO Package 09-05-2014 19:06:20 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {08ABBD0A-FF66-4C7E-9F05-267962A640DC} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {09684A18-3CC2-4B32-9E27-D0EE63FCC9A4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-14] (Google Inc.) Task: {12579CAC-0B72-4B60-97F6-83E7853BF818} - \34c732ce-385e-453a-80a0-2300f29d65ac-5 No Task File <==== ATTENTION Task: {244F7349-9E29-4605-BE4E-72D43BC500A0} - \34c732ce-385e-453a-80a0-2300f29d65ac-1 No Task File <==== ATTENTION Task: {28E1FFAE-C56F-4A37-90BA-4104945F333D} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2013-09-25] (Lenovo) Task: {2D5AD224-C74E-4DA1-AA70-8AE0B4F17308} - \34c732ce-385e-453a-80a0-2300f29d65ac-3 No Task File <==== ATTENTION Task: {33AB8577-B7D2-42FF-83DE-26F1FA57DE8E} - \34c732ce-385e-453a-80a0-2300f29d65ac-2 No Task File <==== ATTENTION Task: {5675129E-A4BF-4A83-81C7-2DA3D5AA7C33} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-09] (Adobe Systems Incorporated) Task: {56DD8E27-C5F9-48E7-A200-B645AA4136EC} - System32\Tasks\TVT\LenovoWERMonitor => C:\Program Files (x86)\Common Files\lenovo\SUP\sup_wermonitor.exe [2014-01-21] (Microsoft) Task: {582D01E8-9105-4039-BB0B-A39D8A2A845F} - System32\Tasks\{B903FE48-5794-4FE2-90CC-D112C976E910} => Firefox.exe Task: {697D5C95-73D1-4377-8F63-35A25C8E18A5} - System32\Tasks\PMTask => C:\Program Files (x86)\ThinkPad\Utilities\PWMIDTSV.EXE [2012-05-15] (Lenovo Group Limited) Task: {6C23F7E8-2CEA-4FE2-B5C9-957B8CC0D51E} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2013-09-25] (Lenovo) Task: {6EC5B411-5730-456C-A78E-3EF6013813A9} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2014-02-21] () Task: {8BF85A18-1DA0-4FE4-92C6-5C0E9C2A1F3D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-14] (Google Inc.) Task: {90721164-FC71-46D7-9E6D-98E3C90C50E1} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2013-09-25] () Task: {94097C26-547F-4A59-B899-3616AFC56113} - System32\Tasks\Lenovo\SimpleTap\Start SimpleTap for Pippifax-THINK.Pippifax => C:\Program Files\Lenovo\SimpleTap\SimpleTap.exe [2012-05-15] (Lenovo) Task: {95E68F3F-DA90-476D-B5A0-41DA0FCC52BA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd) Task: {9784065B-66D0-4F2E-A785-D2BB43B14FD2} - \APSnotifierPP3 No Task File <==== ATTENTION Task: {9C70C9D3-56A9-4B3E-8F20-93473D954F86} - \34c732ce-385e-453a-80a0-2300f29d65ac-4 No Task File <==== ATTENTION Task: {A9CD530F-701F-47A6-8E25-751E10302AAD} - System32\Tasks\Lenovo\Message Center Plus Launcher => C:\Program Files (x86)\Lenovo\message center plus\mcplaunch.exe [2012-05-15] (Lenovo) Task: {B1EE36EE-73F8-4A06-B4E5-D54FCB701758} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {C68DAC31-C417-430E-8BCB-D4BB75516CF6} - \APSnotifierPP2 No Task File <==== ATTENTION Task: {CC485FCE-DDAC-4B55-B3EB-EF8CFF5399A0} - \UpdaterEX No Task File <==== ATTENTION Task: {CFF372DC-22AE-4AB1-B134-44D0323422B4} - System32\Tasks\Microsoft\Windows\PLA\LSC Memory => Rundll32.exe C:\Windows\system32\pla.dll,PlaHost "LSC Memory" "$(Arg0)" Task: {D7F721BE-10B3-41C0-8210-BAA84B4B69BC} - \APSnotifierPP1 No Task File <==== ATTENTION Task: {D9921AC7-F6C3-4AEE-86A4-76B8F3258119} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2013-09-25] () Task: {DD8D1A27-A264-487E-882E-BB50BC0803CB} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Loaded Modules (whitelisted) ============= 2013-08-07 04:03 - 2013-08-07 04:03 - 01130792 _____ () C:\Program Files\Lenovo Fingerprint Reader\DataManager.dll 2013-08-07 04:04 - 2013-08-07 04:04 - 00087848 _____ () C:\Program Files\Lenovo Fingerprint Reader\ssutil.dll 2012-12-15 05:13 - 2012-03-07 00:49 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 2013-03-03 20:50 - 2008-11-25 16:27 - 00247152 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2012-12-15 05:14 - 2012-06-25 08:19 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-12-15 05:19 - 2010-10-26 06:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe 2011-01-27 16:28 - 2011-01-27 16:28 - 00706048 _____ () C:\Windows\system32\SnMinDrv.dll 2013-01-14 19:19 - 2013-01-14 19:19 - 00091136 _____ () C:\Windows\system32\SSDEVM64.DLL 2012-12-15 05:23 - 2012-05-15 23:32 - 00103936 ____N () C:\Program Files (x86)\ThinkPad\Utilities\GR\PWMRT64V.DLL 2012-12-15 05:30 - 2012-01-17 08:29 - 00030512 ____N () C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBServiceps.dll 2012-12-15 05:24 - 2011-08-02 05:58 - 02201088 _____ () C:\Program Files\Lenovo\Communications Utility\cxcore210.dll 2012-12-15 05:24 - 2011-08-02 05:58 - 02085888 _____ () C:\Program Files\Lenovo\Communications Utility\cv210.dll 2013-03-03 20:50 - 2008-11-25 16:27 - 00034088 ____N () C:\Program Files (x86)\Cyberlink\Shared files\RichVideops.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00891392 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\QtNetwork4.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 02281984 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\QtCore4.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00322048 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\log4cplus.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00339456 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\QtXml4.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00400384 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\sqlite3.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00016896 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\featureController.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00062976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\osEvents.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00195584 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\libgsoap.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00062464 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\zlib1.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00446976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\deviceProfile.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00019456 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\eventsSender.dll 2012-12-15 05:35 - 2012-07-12 14:59 - 00062976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\serviceManagerStarter.dll 2008-12-24 13:29 - 2008-12-24 13:29 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2008-12-24 13:30 - 2008-12-24 13:30 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2009-03-30 15:02 - 2009-03-30 15:02 - 01197352 ____N () C:\Program Files (x86)\CyberLink\Power2Go\Language\DEU\P2GRC.dll 2007-11-27 22:14 - 2007-11-27 22:14 - 00144680 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLVistaAudioMixer.dll 2012-12-15 05:13 - 2012-03-07 00:27 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2012-12-15 05:45 - 2012-04-23 16:03 - 00030432 _____ () C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\ProcessPrivileges.dll 2012-12-15 05:45 - 2012-04-23 16:03 - 00215264 _____ () C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\System.ComponentModel.Composition.dll 2012-12-15 05:45 - 2012-04-23 16:03 - 00051424 _____ () C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Interop.TaskScheduler.dll 2014-05-09 21:13 - 2014-04-24 02:33 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\chrome_elf.dll 2014-05-09 21:13 - 2014-04-24 02:33 - 00674632 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\libglesv2.dll 2014-05-09 21:13 - 2014-04-24 02:33 - 00093000 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\libegl.dll 2014-05-09 21:13 - 2014-04-24 02:33 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\pdf.dll 2014-05-09 21:13 - 2014-04-24 02:33 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll 2014-05-09 21:13 - 2014-04-24 02:33 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-06-13 10:42:58.792 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-13 10:42:58.752 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-13 10:42:58.702 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\gpapi.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-13 10:42:58.572 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\gpapi.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-02 22:06:51.228 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-02 22:06:51.208 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-02 22:06:51.178 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\gpapi.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-02 22:06:51.158 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\gpapi.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 18:47:56.391 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 18:47:56.361 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\cryptnet.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 34% Total physical RAM: 7781.47 MB Available physical RAM: 5126.83 MB Total Pagefile: 15561.12 MB Available Pagefile: 12639.52 MB Total Virtual: 8192 MB Available Virtual: 8191.86 MB ==================== Drives ================================ Drive c: (Windows7_OS) (Fixed) (Total:446.72 GB) (Free:366.56 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive q: (Lenovo_Recovery) (Fixed) (Total:17.58 GB) (Free:5.18 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 8F1615B9) Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=447 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=18 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Geändert von Faxikus (09.05.2014 um 21:45 Uhr) Grund: Habe/Hatte die Additional.txt vergessen. |
10.05.2014, 17:49 | #10 |
/// the machine /// TB-Ausbilder | Windows 7: C:/Trojan:Win32/Wysotot!InkESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.05.2014, 09:38 | #11 |
| Windows 7: C:/Trojan:Win32/Wysotot!Ink Also der Online Scaner hatte 3 Funde, habe wie geschrieben nichts gelöscht, (nur Ergebnis gepostet) und Mozilla als Browser funtioniert nicht. Sonst bis jetzt keine Probleme mehr erkennbar. gruß Faxikus B]C:/EsetOnlineScaner.txt:[/B] ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=7e8a6d5ccf793443ad19c81694986939 # engine=18213 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-05-10 10:44:01 # local_time=2014-05-11 12:44:01 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 23424924 151391691 0 0 # scanned=210770 # found=3 # cleaned=0 # scan_time=9839 sh=628B8082320DB416922488A6F7871061EDDCDE5E ft=1 fh=ab55c892c6bdec01 vn="Win32/SpeedingUpMyPC.J Anwendung" ac=I fn="C:\Users\Pippifax\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PAFQ6KTF\OptimizerPro[1].exe" sh=628B8082320DB416922488A6F7871061EDDCDE5E ft=1 fh=ab55c892c6bdec01 vn="Win32/SpeedingUpMyPC.J Anwendung" ac=I fn="C:\Users\Pippifax\AppData\Local\Temp\optimizerpro.exe" sh=095355B5F6407556A930974E561011A3EFFB9A73 ft=1 fh=85adefd70ea34ad2 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Pippifax\AppData\Local\Temp\setup.exe" C:/Checkup.txt Results of screen317's Security Check version 0.99.82 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 13.0.0.206 Google Chrome 34.0.1847.116 Google Chrome 34.0.1847.131 ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials msseces.exe Windows Defender MSMpEng.exe Common Files Microsoft Shared Windows Live Intel.SmallBusinessAdvantage.WindowsService.exe -?- `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` C:/FRST.txt: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014 Ran by Pippifax (administrator) on PIPPIFAX-THINK on 11-05-2014 10:30:05 Running from C:\Users\Pippifax\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AuthenTec, Inc) C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe (Samsung) C:\Program Files (x86)\Samsung Inkjet\AiO\Center\SPAiOHostService.exe (Samsung) C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPPrinterSDK.exe (Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxServer64.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Lenovo.) C:\Windows\System32\TpShocks.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxTray64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe (Intel Corporation) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (Samsung) C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPStatusMonitor.exe (AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\TouchControl.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpressServer.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe (Lenovo) C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [178960 2012-03-15] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11407120 2012-03-27] (Intel Corporation) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [564352 2012-03-01] (Conexant Systems, Inc.) HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] () HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1654400 2012-02-21] (Conexant Systems, Inc.) HKLM\...\Run: [TpShocks] => C:\Windows\system32\TpShocks.exe [382528 2012-02-25] (Lenovo.) HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [290160 2012-06-01] (Lenovo Group Limited) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [IntelPROSet] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4756240 2012-02-26] (Intel(R) Corporation) HKLM\...\Run: [] => [X] HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-03-07] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-04-13] (Intel Corporation) HKLM-x32\...\Run: [RotateImage] => C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.) HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [507744 2011-12-20] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [PWMTRV] => rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [1091376 2012-01-17] (Lenovo) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-13] (Lenovo, Inc.) HKLM-x32\...\Run: [IntelSBA] => C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\UI\IntelSmallBusinessAdvantage.exe [4243168 2012-04-23] (Intel Corporation) HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2008-12-24] (CyberLink) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePDRShortCut] => C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl8] => C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe [91432 2009-04-16] (CyberLink Corp.) HKLM-x32\...\Run: [PDVD8LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe [50472 2009-04-16] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePPShortCut] => C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2009-03-12] (CyberLink Corp.) HKLM-x32\...\Run: [BingDesktop] => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2249352 2013-06-27] (Microsoft Corp.) HKLM-x32\...\Run: [Conime] => %windir%\system32\conime.exe HKLM-x32\...\Run: [SPStatusMonitor] => C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPStatusMonitor.exe [2778016 2012-11-14] (Samsung) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3270821018-310773288-2480351254-1000\...\Run: [GoogleChromeAutoLaunch_2814A6EC815B16EF397FE9F43BF95EB7] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [841032 2014-04-24] (Google Inc.) HKU\S-1-5-21-3270821018-310773288-2480351254-1000\...\MountPoints2: {6f751c26-4664-11e2-bc78-806e6f6e6963} - Q:\LenovoQDrive.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: MediaPlayerplus - {11111111-1111-1111-1111-110511421146} - C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-bho64.dll No File BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\IEBHO.DLL (AuthenTec Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation) BHO-x32: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\x86\IEBHO.dll (AuthenTec Inc.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Samsung BHO Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files (x86)\Samsung AnyWeb Print\W2PBrowser.dll () BHO-x32: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @authentec.com/ffwloplugin - C:\Program Files\Lenovo Fingerprint Reader\npffwloplugin.dll (AuthenTec, Inc) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Shopping Helper Smartbar - C:\Users\Pippifax\AppData\Roaming\Mozilla\Firefox\Profiles\1bg3kpf9.default\Extensions\{4d0d6d2c-42a1-e9d7-e187-3f1847b7305f} [2014-03-13] FF HKLM-x32\...\Firefox\Extensions: [VIP1X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] FF HKLM-x32\...\Firefox\Extensions: [VIP2X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] Chrome: ======= CHR HomePage: CHR StartupUrls: "http://www.trojaner-board.de/" CHR Extension: (Newhub) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\aoejbmmillcdifgagjpdlaamnalbielp [2014-03-14] CHR Extension: (Google Docs) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-14] CHR Extension: (Google Drive) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-14] CHR Extension: (YouTube) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-14] CHR Extension: (Website Logon) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\clglhglbidpdbjffpfcldkifhdegdfle [2014-03-14] CHR Extension: (Google-Suche) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-14] CHR Extension: (Google Wallet) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-14] CHR Extension: (Google Mail) - C:\Users\Pippifax\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-14] CHR HKLM\...\Chrome\Extension: [aoejbmmillcdifgagjpdlaamnalbielp] - C:\Users\Pippifax\AppData\Local\nwhb-v9.4.15.crx [2014-03-14] CHR HKCU\...\Chrome\Extension: [aoejbmmillcdifgagjpdlaamnalbielp] - C:\Users\Pippifax\AppData\Local\nwhb-v9.4.15.crx [2014-03-14] CHR HKLM-x32\...\Chrome\Extension: [aoejbmmillcdifgagjpdlaamnalbielp] - C:\Users\Pippifax\AppData\Local\nwhb-v9.4.15.crx [2014-03-14] CHR HKLM-x32\...\Chrome\Extension: [clglhglbidpdbjffpfcldkifhdegdfle] - C:\Program Files\Lenovo Fingerprint Reader\x86\tschrome.crx [2013-04-01] ==================== Services (Whitelisted) ================= R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-27] (Microsoft Corp.) R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [169776 2012-01-17] (Lenovo) R2 FPLService; C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe [2139944 2013-08-07] (AuthenTec, Inc) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-07] () R2 Intel(R) Small Business Advantage; C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe [46816 2012-04-23] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-07] (Intel Corporation) R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [179568 2012-06-01] (Lenovo Group Limited) R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited) S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1674720 2013-09-25] () R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2008-11-25] () R2 Samsung AiO Network Discovery Service; C:\Program Files (x86)\Samsung Inkjet\AiO\Center\SPAiOHostService.exe [395168 2012-11-14] (Samsung) R2 Samsung AIO Status Monitor Service; C:\Program Files (x86)\Samsung Inkjet\AiO\StatusMonitor\SPPrinterSDK.exe [722336 2012-11-14] (Samsung) R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [503344 2013-01-14] (Samsung Electronics Co., Ltd.) S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22888 2013-09-17] () R3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401704 2013-07-22] (AuthenTec, Inc.) R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [84080 2012-04-19] (Symantec Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) R2 SAService; %SystemRoot%\system32\SAsrv.exe [X] ==================== Drivers (Whitelisted) ==================== S3 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [70416 2012-01-17] (Windows (R) Win 7 DDK provider) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.) R3 SmbDrvIntel; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [27448 2012-06-19] (Synaptics Incorporated) R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.) R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-07] (ThinkVantage Communications Utility) R1 wStLib64; C:\Windows\System32\drivers\wStLib64.sys [61112 2014-03-18] (StdLib) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-11 10:27 - 2014-05-11 10:27 - 00855379 _____ () C:\Users\Pippifax\Desktop\SecurityCheck.exe 2014-05-10 21:53 - 2014-05-10 21:53 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-05-10 21:50 - 2014-05-10 21:50 - 02347384 _____ (ESET) C:\Users\Pippifax\Downloads\esetsmartinstaller_deu.exe 2014-05-09 22:50 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-09 22:50 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-09 22:50 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-09 22:50 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-09 22:20 - 2014-05-11 10:29 - 00000000 ____D () C:\Users\Pippifax\Desktop\FRST-OlderVersion 2014-05-09 22:17 - 2014-05-09 22:17 - 00001419 _____ () C:\Users\Pippifax\Desktop\JRT.txt 2014-05-09 22:08 - 2014-05-09 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-05-09 22:07 - 2014-05-09 22:08 - 01016261 _____ (Thisisu) C:\Users\Pippifax\Downloads\JRT.exe 2014-05-09 21:59 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-09 21:58 - 2014-05-09 22:00 - 00000000 ____D () C:\AdwCleaner 2014-05-09 21:55 - 2014-05-09 21:55 - 01316991 _____ () C:\Users\Pippifax\Downloads\adwcleaner.exe 2014-05-09 21:53 - 2014-05-09 21:53 - 00000273 _____ () C:\Users\Pippifax\Desktop\mbam.txt 2014-05-09 21:48 - 2014-05-09 21:48 - 00706696 _____ () C:\Users\Pippifax\Downloads\Nicht bestätigt 95849.crdownload 2014-05-09 21:20 - 2014-05-09 21:50 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-09 21:20 - 2014-05-09 21:20 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-09 21:20 - 2014-05-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-09 21:19 - 2014-05-09 21:20 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-09 21:19 - 2014-05-09 21:19 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-09 21:19 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-09 21:19 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-09 21:19 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-09 21:18 - 2014-05-09 21:19 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Pippifax\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-09 21:16 - 2014-05-09 21:16 - 00340480 _____ () C:\Users\Pippifax\Downloads\Setup__4227_il891497.exe 2014-05-09 21:14 - 2014-05-09 21:14 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (6).exe 2014-05-09 21:14 - 2014-05-09 21:14 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (5).exe 2014-05-09 21:09 - 2014-05-09 21:10 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (4).exe 2014-05-09 21:06 - 2014-05-09 21:06 - 00495104 _____ () C:\Users\Pippifax\Downloads\test (3).exe 2014-04-25 22:44 - 2014-04-25 22:44 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (3).exe 2014-04-25 22:41 - 2014-04-25 22:42 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (2).exe 2014-04-25 22:40 - 2014-05-11 10:20 - 00000000 ____D () C:\Users\Pippifax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-04-24 20:46 - 2014-04-24 20:46 - 00001275 _____ () C:\Users\Pippifax\Desktop\Revo Uninstaller.lnk 2014-04-24 20:46 - 2014-04-24 20:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-24 20:45 - 2014-04-24 20:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Pippifax\Downloads\revosetup95.exe 2014-04-24 20:45 - 2014-04-24 20:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Pippifax\Downloads\revosetup95 (1).exe 2014-04-24 20:41 - 2014-04-24 20:41 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (1).exe 2014-04-23 23:56 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-23 23:56 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-23 23:56 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-23 23:56 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-23 23:56 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-23 23:56 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-23 23:56 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-23 23:56 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-23 23:56 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-23 23:56 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-23 23:56 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-23 23:56 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-23 23:55 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-23 23:55 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-23 23:55 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-23 23:55 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-23 23:55 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-23 23:55 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-23 23:55 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-23 23:55 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-23 23:55 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-23 23:55 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-23 23:55 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-23 23:55 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-23 23:55 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-23 23:55 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-23 23:55 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-23 23:55 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-23 23:55 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-23 23:55 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-23 23:55 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-23 23:55 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-23 23:55 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-23 23:55 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-23 23:55 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-23 23:55 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-23 23:55 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-23 23:55 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-23 23:55 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-23 23:55 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-23 23:55 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-23 23:55 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-23 23:55 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-23 23:55 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-23 23:40 - 2014-05-09 22:42 - 00021793 _____ () C:\Users\Pippifax\Desktop\Addition.txt 2014-04-23 23:38 - 2014-05-11 10:30 - 00022322 _____ () C:\Users\Pippifax\Desktop\FRST.txt 2014-04-23 23:38 - 2014-05-11 10:30 - 00000000 ____D () C:\FRST 2014-04-23 23:37 - 2014-05-11 10:29 - 02066432 _____ (Farbar) C:\Users\Pippifax\Desktop\FRST64.exe 2014-04-23 23:28 - 2014-05-09 22:01 - 00003142 _____ () C:\Windows\PFRO.log 2014-04-23 19:59 - 2014-04-23 19:59 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\com 2014-04-23 19:48 - 2014-04-23 19:48 - 00803320 _____ () C:\Users\Pippifax\Downloads\Setup.exe 2014-04-23 19:43 - 2014-05-11 10:19 - 00000504 _____ () C:\Windows\setupact.log 2014-04-23 19:43 - 2014-04-23 19:43 - 00000000 _____ () C:\Windows\setuperr.log ==================== One Month Modified Files and Folders ======= 2014-05-11 10:30 - 2014-04-23 23:38 - 00022322 _____ () C:\Users\Pippifax\Desktop\FRST.txt 2014-05-11 10:30 - 2014-04-23 23:38 - 00000000 ____D () C:\FRST 2014-05-11 10:29 - 2014-05-09 22:20 - 00000000 ____D () C:\Users\Pippifax\Desktop\FRST-OlderVersion 2014-05-11 10:29 - 2014-04-23 23:37 - 02066432 _____ (Farbar) C:\Users\Pippifax\Desktop\FRST64.exe 2014-05-11 10:27 - 2014-05-11 10:27 - 00855379 _____ () C:\Users\Pippifax\Desktop\SecurityCheck.exe 2014-05-11 10:27 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-11 10:27 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-11 10:24 - 2012-12-15 13:57 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-05-11 10:24 - 2012-12-15 13:57 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-05-11 10:24 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-11 10:22 - 2012-12-15 05:12 - 02040653 _____ () C:\Windows\WindowsUpdate.log 2014-05-11 10:21 - 2014-03-14 11:00 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-11 10:21 - 2012-12-15 05:14 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-05-11 10:20 - 2014-04-25 22:40 - 00000000 ____D () C:\Users\Pippifax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-05-11 10:20 - 2013-03-07 10:58 - 00017408 _____ () C:\Windows\system32\rpcnetp.exe 2014-05-11 10:20 - 2013-03-07 10:20 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-11 10:19 - 2014-04-23 19:43 - 00000504 _____ () C:\Windows\setupact.log 2014-05-11 10:19 - 2013-03-07 10:58 - 00017408 _____ () C:\Windows\SysWOW64\rpcnetp.exe 2014-05-11 10:19 - 2013-03-07 10:58 - 00017408 _____ () C:\Windows\SysWOW64\rpcnetp.dll 2014-05-11 10:19 - 2013-03-07 10:53 - 00000000 ____D () C:\ProgramData\Samsung Inkjet 2014-05-11 10:19 - 2013-03-02 22:51 - 00069792 _____ (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.dll 2014-05-11 10:19 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-11 09:10 - 2014-03-14 11:00 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-11 01:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-10 21:53 - 2014-05-10 21:53 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-05-10 21:50 - 2014-05-10 21:50 - 02347384 _____ (ESET) C:\Users\Pippifax\Downloads\esetsmartinstaller_deu.exe 2014-05-09 22:42 - 2014-04-23 23:40 - 00021793 _____ () C:\Users\Pippifax\Desktop\Addition.txt 2014-05-09 22:20 - 2013-03-07 10:20 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-09 22:20 - 2013-03-07 10:20 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-09 22:20 - 2013-03-07 10:20 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-09 22:17 - 2014-05-09 22:17 - 00001419 _____ () C:\Users\Pippifax\Desktop\JRT.txt 2014-05-09 22:08 - 2014-05-09 22:08 - 00000000 ____D () C:\Windows\ERUNT 2014-05-09 22:08 - 2014-05-09 22:07 - 01016261 _____ (Thisisu) C:\Users\Pippifax\Downloads\JRT.exe 2014-05-09 22:01 - 2014-04-23 23:28 - 00003142 _____ () C:\Windows\PFRO.log 2014-05-09 22:00 - 2014-05-09 21:58 - 00000000 ____D () C:\AdwCleaner 2014-05-09 21:55 - 2014-05-09 21:55 - 01316991 _____ () C:\Users\Pippifax\Downloads\adwcleaner.exe 2014-05-09 21:53 - 2014-05-09 21:53 - 00000273 _____ () C:\Users\Pippifax\Desktop\mbam.txt 2014-05-09 21:50 - 2014-05-09 21:20 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-09 21:48 - 2014-05-09 21:48 - 00706696 _____ () C:\Users\Pippifax\Downloads\Nicht bestätigt 95849.crdownload 2014-05-09 21:42 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini 2014-05-09 21:20 - 2014-05-09 21:20 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-09 21:20 - 2014-05-09 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-09 21:20 - 2014-05-09 21:19 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-09 21:19 - 2014-05-09 21:19 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-09 21:19 - 2014-05-09 21:18 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Pippifax\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-09 21:16 - 2014-05-09 21:16 - 00340480 _____ () C:\Users\Pippifax\Downloads\Setup__4227_il891497.exe 2014-05-09 21:14 - 2014-05-09 21:14 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (6).exe 2014-05-09 21:14 - 2014-05-09 21:14 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (5).exe 2014-05-09 21:14 - 2014-03-14 11:00 - 00002186 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-05-09 21:13 - 2013-12-06 11:12 - 00000000 ____D () C:\ldiag 2014-05-09 21:13 - 2012-12-15 05:42 - 00000000 ____D () C:\Windows\System32\Tasks\TVT 2014-05-09 21:13 - 2012-12-15 05:23 - 00000000 ___HD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools 2014-05-09 21:13 - 2012-12-15 05:19 - 00000000 ____D () C:\Program Files (x86)\Lenovo 2014-05-09 21:13 - 2012-12-14 21:43 - 00000000 ____D () C:\ProgramData\Lenovo 2014-05-09 21:10 - 2014-05-09 21:09 - 00994176 _____ () C:\Users\Pippifax\Downloads\setup (4).exe 2014-05-09 21:06 - 2014-05-09 21:06 - 00495104 _____ () C:\Users\Pippifax\Downloads\test (3).exe 2014-05-09 21:05 - 2014-03-14 11:00 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-09 21:05 - 2014-03-14 11:00 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-29 16:01 - 2014-05-09 22:50 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-29 15:40 - 2014-05-09 22:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-29 14:48 - 2014-05-09 22:50 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-29 14:34 - 2014-05-09 22:50 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-25 22:44 - 2014-04-25 22:44 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (3).exe 2014-04-25 22:42 - 2014-04-25 22:41 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (2).exe 2014-04-24 21:07 - 2014-03-13 13:59 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-04-24 20:46 - 2014-04-24 20:46 - 00001275 _____ () C:\Users\Pippifax\Desktop\Revo Uninstaller.lnk 2014-04-24 20:46 - 2014-04-24 20:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-24 20:45 - 2014-04-24 20:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Pippifax\Downloads\revosetup95.exe 2014-04-24 20:45 - 2014-04-24 20:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Pippifax\Downloads\revosetup95 (1).exe 2014-04-24 20:41 - 2014-04-24 20:41 - 00991832 _____ () C:\Users\Pippifax\Downloads\setup (1).exe 2014-04-24 20:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-23 19:59 - 2014-04-23 19:59 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\com 2014-04-23 19:48 - 2014-04-23 19:48 - 00803320 _____ () C:\Users\Pippifax\Downloads\Setup.exe 2014-04-23 19:43 - 2014-04-23 19:43 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-21 21:02 - 2013-02-14 18:11 - 00000000 ____D () C:\Users\Pippifax\AppData\Local\Adobe Some content of TEMP: ==================== C:\Users\Pippifax\AppData\Local\Temp\1_Offer_5.exe C:\Users\Pippifax\AppData\Local\Temp\amsetup_activeris_default_010414_installer.exe C:\Users\Pippifax\AppData\Local\Temp\f978377c-b7d4-4536-8e10-14ca97b13394.exe C:\Users\Pippifax\AppData\Local\Temp\instract.exe C:\Users\Pippifax\AppData\Local\Temp\mainapp.exe C:\Users\Pippifax\AppData\Local\Temp\mediaplayerpluus.exe C:\Users\Pippifax\AppData\Local\Temp\nsa95FC.exe C:\Users\Pippifax\AppData\Local\Temp\nsaAB52.exe C:\Users\Pippifax\AppData\Local\Temp\nsaE6C2.exe C:\Users\Pippifax\AppData\Local\Temp\nsi5FC0.exe C:\Users\Pippifax\AppData\Local\Temp\nsqDA52.exe C:\Users\Pippifax\AppData\Local\Temp\nsqE0B9.exe C:\Users\Pippifax\AppData\Local\Temp\nsv9F50.exe C:\Users\Pippifax\AppData\Local\Temp\optimizerpro.exe C:\Users\Pippifax\AppData\Local\Temp\Quarantine.exe C:\Users\Pippifax\AppData\Local\Temp\SearchProtectINT.exe C:\Users\Pippifax\AppData\Local\Temp\setup.exe C:\Users\Pippifax\AppData\Local\Temp\spidentifierimpl.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-11 00:58 ==================== End Of Log ============================ |
12.05.2014, 10:06 | #12 |
/// the machine /// TB-Ausbilder | Windows 7: C:/Trojan:Win32/Wysotot!Ink Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter GroupPolicy: Group Policy on Chrome detected <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.05.2014, 19:22 | #13 |
| Windows 7: C:/Trojan:Win32/Wysotot!Ink Hallo Schrauber, entschuldige Bitte die verspätete Antwort, streß- & Arbeitsbedingt kam ich nicht dazu die letzte Sache noch hier am PC zu erledigen. Aber heute... Hier die C:/ Fixlog.txt: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-05-2014 Ran by Pippifax at 2014-05-16 20:10:02 Run:1 Running from C:\Users\Pippifax\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ***************** "C:\Windows\system32\GroupPolicy\Machine" => File/Directory not found. ==== End of Fixlog ==== Alles andere bin ich durchgegangen und werde dieTips beherzigen, wenn du jetzt sagst nun müßte alles laufen und wieder sauber sein, dann bin ich auch fertig und habe auch keine Fragen mehr. Danke vielmals nochmal!!!! Gruß Faxikus |
17.05.2014, 19:39 | #14 |
/// the machine /// TB-Ausbilder | Windows 7: C:/Trojan:Win32/Wysotot!Ink passt, fertig. Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7: C:/Trojan:Win32/Wysotot!Ink |
alter, brauch, essen, fenster, firefox, freund, google, kleine, meldungen, microsoft, mozilla, natürlich, nutzen, private, schonmal, security, spyware, trojaner, verlauf, verschiedene, webseite, win, windows, windows 7, öffnen |