|
Log-Analyse und Auswertung: Win 7 Laptop ruckelt plötzlichWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
30.04.2014, 08:29 | #1 |
| Win 7 Laptop ruckelt plötzlich Hi Leute, bin neu hier und hoffe ihr könnt mir helfen! Habe seit Sonntag Probleme mit meinem Windows 7 64bit Laptop. Und zwar wurde er sehr langsam, am meisten fällt es beim Schreiben auf. Hier wird das getippte stark verzögert angezeigt, was es echt schwer macht einen vernünftigen Text zu schreiben. Manchmal klappt es für ein paar Sekunden ganz normal, dann fängt es aber wieder an. In eigentlich allen Programmen geht es so. Außerdem verstellt sich manchmal die Tastatur und die Maus, sodass zum Beispiel in Chrome, wenn man etwas antippt, der Link heruntergeladen wird anstatt zu öffnen. Das Problem trat sehr plötzlich auf, zumindest ist mir am Tag davor noch nichts aufgefallen, was aber bei diesem Ruckeln fast unmöglich ist. Gerade eben habe ich wieder gesehen, dass die svchost.exe sehr viel Arbeitsspeicher benötigt hat. Kaum habe ich das gesehen, hat sich die Größe wieder verringert. Habe auch allerlei Virenprogramme laufen lassen, habe bis auf Microsoft Security Essentials alle Logs. Die haben alle etwas gefunden, seht ihr ja aber in den logs MSE hat einen "Downloadtrojaner" gefunden und gleich gelöscht. Habe alles gemacht wie es in der Anleitung steht und habe hoffentlich nichts vergessen |
30.04.2014, 09:34 | #2 |
/// the machine /// TB-Ausbilder | Win 7 Laptop ruckelt plötzlich Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. Ich kann auf Arbeit keine Anhänge öffnen, danke. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
30.04.2014, 11:31 | #3 |
| Win 7 Laptop ruckelt plötzlich tut mir leid, wusste ich nicht
__________________übrigens: die Festplatte ist eine Samsung SSD, nur falls dies wichtig ist hoffe jetzt ist es besser! FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-04-2014 Ran by Silas (administrator) on SILAS-PC on 29-04-2014 16:38:54 Running from C:\Users\Silas\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corp.) C:\Program Files\Broadcom\BPowMon\BPowMon.exe (Broadcom Corporation) C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Samsung Electronics Co., Ltd.) C:\Windows\system32\RAPID\SamsungRapidSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\RAPID\CacheFilter\SamsungRapidApp.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Samsung Electronics.) C:\Program Files (x86)\Samsung SSD Magician\Samsung Magician.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (BlackBerry Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (BlackBerry Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe () C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-22] (Alcor Micro Corp.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [7477016 2013-04-25] (Logitech Inc.) HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [2991856 2013-02-21] (Logitech, Inc.) HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [456704 2012-02-20] () HKLM\...\Run: [SamsungRapidApp] => C:\Program Files (x86)\RAPID\CacheFilter\SamsungRapidApp.exe [109280 2013-07-29] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-12-23] (Intel Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [443408 2014-01-21] (BlackBerry Limited) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKU\S-1-5-21-2937941739-3390224605-2116822940-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-2937941739-3390224605-2116822940-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-2937941739-3390224605-2116822940-1001\...\MountPoints2: {f0ca1a60-a283-11e2-8518-d9d05fc4d272} - E:\LaunchU3.exe -a Startup: C:\Users\Silas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Magician.lnk ShortcutTarget: Samsung Magician.lnk -> C:\Program Files (x86)\Samsung SSD Magician\Samsung Magician.exe (Samsung Electronics.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xD70133BACCDECD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/$22/ SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&affID=119779&tt=gc_&babsrc=SP_ss&mntrId=94D778E4000FEF33 BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No File BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: 127.0.0.1 secure.tune-up.com Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.13.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll () FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Extension: HDvid Codec - C:\Users\Silas\AppData\Roaming\Mozilla\Firefox\profiles\extensions\hdvc@hdvc.com.xpi [2013-04-17] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013-05-20] Chrome: ======= CHR HomePage: hxxp://www.ask.com/?l=dis&o=1586cr&gct=hp CHR StartupUrls: "hxxp://de-de.facebook.com/", "hxxp://www.die-staemme.de/", "hxxp://web.de/" CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\pdf.dll () CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (Microsoft Office 2013) - C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 7 U13) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office 2013) - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Java Deployment Toolkit 7.0.130.20) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) CHR Extension: (Google Drive) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-12-20] CHR Extension: (YouTube) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-20] CHR Extension: (Adblock Plus) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2012-12-20] CHR Extension: (Monster Dash) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\cknghehebaconkajgiobncfleofebcog [2012-12-20] CHR Extension: (Google-Suche) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-20] CHR Extension: (Tampermonkey) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-04-05] CHR Extension: (CinemaxX Trailer) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\dopcgojamofpmhidpadjjfilkiiehjea [2012-12-20] CHR Extension: (Logitech SetPoint) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\edaibbiobngpbmeonadpbfafbkimjbdd [2013-05-20] CHR Extension: (Photo Zoom for Facebook) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2012-12-20] CHR Extension: (AdBlock) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2012-12-20] CHR Extension: (ProxMate - Proxy on steroids!) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifalmiidchkjjmkkbkoaibpmoeichmki [2014-03-03] CHR Extension: (Fuball Ergebnisse) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgikkhahmpgcibceopehblcifilnkpko [2012-12-20] CHR Extension: (Google Wallet) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-05] CHR Extension: (beautiful megan) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbihhhkaldmedflhmdmkhmpmpijbaajo [2012-12-20] CHR Extension: (Google Mail) - C:\Users\Silas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-20] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2012-12-20] CHR HKLM-x32\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx [2013-04-28] CHR HKLM-x32\...\Chrome\Extension: [kpkbnefaikfaeadgidhpoanckoiaheli] - C:\Program Files (x86)\HDvidCodec.com\HDvidCodec10.crx [2013-04-28] ==================== Services (Whitelisted) ================= R3 BlackBerry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [585728 2014-01-21] (BlackBerry Limited) R2 BrcmMgmtAgent; C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [152064 2009-10-23] (Broadcom Corporation) R2 CLHNServiceForPowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe [90640 2012-08-16] (CyberLink Corp.) R2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [78352 2012-08-16] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [295440 2012-08-16] (CyberLink) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-12-24] () R2 SamsungRapidSvc; C:\Windows\System32\RAPID\SamsungRapidSvc.exe [27360 2013-07-29] (Samsung Electronics Co., Ltd.) ==================== Drivers (Whitelisted) ==================== S3 cpudrv64; C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [17864 2011-06-02] () R3 k57nd; C:\Windows\System32\DRIVERS\k57amd64.sys [333864 2009-12-11] (Broadcom Corporation) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66800 2013-01-17] (Logitech Inc.) R3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [44272 2013-01-17] (Logitech Inc.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R2 ntk_PowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [83704 2012-06-20] (Cyberlink Corp.) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [79872 2013-12-02] (BlackBerry Limited) R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd) R0 SamsungRapidDiskFltr; C:\Windows\System32\DRIVERS\SamsungRapidDiskFltr.sys [240864 2013-07-29] (Samsung Electronics Co., Ltd.) R0 SamsungRapidFSFltr; C:\Windows\System32\DRIVERS\SamsungRapidFSFltr.sys [111328 2013-07-29] (Samsung Electronics Co., Ltd.) R2 {73526619-C24F-470B-9BED-53D455FBB5C6}; C:\Program Files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl [147704 2012-08-14] (CyberLink Corp.) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X] S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X] U3 kgloypow; \??\C:\Users\Silas\AppData\Local\Temp\kgloypow.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-29 16:38 - 2014-04-29 16:39 - 00021093 _____ () C:\Users\Silas\Downloads\FRST.txt 2014-04-29 16:38 - 2014-04-29 16:38 - 00000472 _____ () C:\Users\Silas\Downloads\defogger_disable.log 2014-04-29 16:38 - 2014-04-29 16:38 - 00000000 ____D () C:\FRST 2014-04-29 16:38 - 2014-04-29 16:38 - 00000000 _____ () C:\Users\Silas\defogger_reenable 2014-04-29 16:27 - 2014-04-29 16:27 - 02061824 _____ (Farbar) C:\Users\Silas\Downloads\FRST64.exe 2014-04-29 16:21 - 2014-04-29 16:21 - 00050477 _____ () C:\Users\Silas\Downloads\Defogger.exe 2014-04-29 16:01 - 2014-04-29 16:01 - 00008431 _____ () C:\Users\Silas\Documents\gmer.log 2014-04-29 11:59 - 2014-04-29 11:59 - 00380416 _____ () C:\Users\Silas\Downloads\Gmer-19357.exe 2014-04-28 12:07 - 2014-04-29 16:33 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-04-28 12:07 - 2014-04-28 12:07 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-04-28 12:06 - 2014-04-28 12:06 - 05049344 _____ (Crawler.com ) C:\Users\Silas\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-04-27 18:40 - 2014-04-29 16:32 - 00000000 ____D () C:\ProgramData\SecTaskMan 2014-04-27 18:39 - 2014-04-27 18:39 - 02365840 _____ () C:\Users\Silas\Downloads\SecurityTaskManager_Setup.exe 2014-04-27 18:38 - 2014-04-27 18:38 - 00540072 _____ (Neuber Software) C:\Users\Silas\Downloads\SvchostAnalyzer.exe 2014-04-27 18:13 - 2014-04-29 09:52 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-27 18:11 - 2014-04-27 18:11 - 00613200 _____ (Chip Digital GmbH) C:\Users\Silas\Downloads\Malwarebytes Anti Malware - CHIP-Downloader.exe 2014-04-27 18:11 - 2014-04-27 18:11 - 00613200 _____ (Chip Digital GmbH) C:\Users\Silas\Downloads\Malwarebytes Anti Malware - CHIP-Downloader (1).exe 2014-04-25 11:39 - 2014-04-25 11:40 - 14298467 _____ () C:\Users\Silas\Downloads\nw_14643_handbrakexwinguiexe.exe 2014-04-22 20:17 - 2014-04-22 20:17 - 00000000 __SHD () C:\Users\Silas\AppData\Local\EmieUserList 2014-04-22 20:17 - 2014-04-22 20:17 - 00000000 __SHD () C:\Users\Silas\AppData\Local\EmieSiteList 2014-04-21 19:37 - 2014-04-21 19:37 - 00004853 _____ () C:\Users\Silas\Downloads\kroatien urlaub.odt 2014-04-11 09:46 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-11 09:46 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-11 09:46 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-11 09:46 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-11 09:46 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-11 09:46 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-11 09:46 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-11 09:46 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-11 09:46 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-11 09:46 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-11 09:46 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-11 09:46 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-11 09:46 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-11 09:46 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-11 09:46 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-11 09:46 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-11 09:46 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-11 09:46 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-11 09:46 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-11 09:46 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-11 09:46 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-11 09:46 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-11 09:46 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-11 09:46 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-11 09:46 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-11 09:46 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-11 09:46 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-11 09:46 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-11 09:46 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-11 09:46 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-11 09:46 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-11 09:46 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-11 09:46 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-11 09:46 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-11 09:46 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-11 09:46 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-11 09:46 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-11 09:46 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-11 09:46 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-11 09:46 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-11 09:46 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-11 09:46 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-11 09:46 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-11 09:46 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-11 09:46 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-11 09:46 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-11 09:46 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-11 09:46 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-10 19:26 - 2014-04-10 19:26 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-04-10 19:26 - 2014-04-10 19:26 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-04-10 19:26 - 2014-04-10 19:26 - 00000000 ____D () C:\Users\Silas\AppData\Local\Skype 2014-04-10 19:26 - 2014-04-10 19:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-04-10 10:27 - 2009-12-11 00:32 - 00333864 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\k57amd64.sys 2014-04-10 10:26 - 2014-04-10 10:27 - 00000000 ____D () C:\Users\Silas\Desktop\LAN_Broadcom_12.4.0.3_Win7x86x64 2014-04-10 10:24 - 2014-04-10 10:24 - 00000000 ____D () C:\Users\Silas\Desktop\Modem_LSI_2.2.99.0_Win7x86x64 2014-04-10 10:23 - 2014-04-10 10:23 - 02134334 _____ () C:\Users\Silas\Downloads\Modem_LSI_2.2.99.0_W7x86W7x64_A.zip 2014-04-10 10:22 - 2014-04-10 10:26 - 139876507 _____ () C:\Users\Silas\Downloads\Lan_Broadcom_12.4.0.3_W7x86W7x64_A.zip 2014-04-10 10:01 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 10:01 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 10:01 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 10:01 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 10:01 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 10:01 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 10:01 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 10:01 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 10:01 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 10:01 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 10:01 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 10:01 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 10:01 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 10:01 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 10:01 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 10:01 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 10:00 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-08 22:13 - 2014-04-08 22:13 - 00000635 _____ () C:\Users\Silas\Desktop\Cyperia - Verknüpfung.lnk 2014-04-08 18:39 - 2014-04-08 22:13 - 00000000 ____D () C:\Users\Silas\Desktop\Cyperia 2013 Client 2014-04-08 16:52 - 2014-04-08 18:39 - 904446119 _____ () C:\Users\Silas\Downloads\Cyperia2013Client.zip 2014-04-08 13:08 - 2014-04-08 13:08 - 01768986 _____ () C:\Users\Silas\Downloads\switchbot.zip 2014-04-08 12:24 - 2014-04-08 12:25 - 29990274 _____ () C:\Users\Silas\Downloads\cyperia.rar 2014-04-02 17:44 - 2014-04-03 17:27 - 00000000 ____D () C:\Users\Silas\AppData\Local\Downloaded Installations 2014-04-02 17:43 - 2014-04-02 17:44 - 00013785 _____ () C:\ads_err.adt 2014-04-02 17:43 - 2014-04-02 17:44 - 00004559 _____ () C:\ads_err.adm 2014-04-02 17:43 - 2014-04-02 17:44 - 00003072 _____ () C:\ads_err.adi 2014-04-02 17:43 - 2014-04-02 17:43 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf 2014-04-02 17:43 - 2014-04-02 17:43 - 00000000 ____D () C:\Users\Silas\Documents\BlackBerry 2014-04-02 17:33 - 2014-04-02 18:59 - 00000308 _____ () C:\Users\Silas\AppData\Roaming\Rim.DesktopHelper.Exception.log 2014-04-02 17:33 - 2014-04-02 18:59 - 00000308 _____ () C:\Users\Silas\AppData\Roaming\Rim.Desktop.Exception.log 2014-04-02 17:33 - 2014-04-02 18:27 - 00000000 ____D () C:\Users\Silas\AppData\Local\Research In Motion 2014-04-02 17:33 - 2014-04-02 17:33 - 00000000 ____D () C:\Users\Silas\AppData\Roaming\Research In Motion 2014-04-02 17:32 - 2014-04-02 17:32 - 00002231 _____ () C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk 2014-04-02 17:32 - 2014-04-02 17:32 - 00001153 _____ () C:\Users\Silas\AppData\Roaming\Rim.Desktop.HttpServerSetup.log 2014-04-02 17:32 - 2014-04-02 17:32 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf 2014-04-02 17:32 - 2014-04-02 17:32 - 00000000 ____D () C:\ProgramData\Research In Motion 2014-04-02 17:32 - 2014-04-02 17:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry 2014-04-02 17:32 - 2014-04-02 17:32 - 00000000 ____D () C:\Program Files (x86)\Research In Motion 2014-04-02 17:32 - 2012-12-10 15:48 - 00044544 _____ (Research in Motion Ltd) C:\Windows\system32\Drivers\RimSerial_AMD64.sys 2014-04-02 17:26 - 2014-04-02 17:29 - 119528976 _____ () C:\Users\Silas\Downloads\710_b042_multilanguage.exe ==================== One Month Modified Files and Folders ======= 2014-04-29 16:39 - 2014-04-29 16:38 - 00021093 _____ () C:\Users\Silas\Downloads\FRST.txt 2014-04-29 16:38 - 2014-04-29 16:38 - 00000472 _____ () C:\Users\Silas\Downloads\defogger_disable.log 2014-04-29 16:38 - 2014-04-29 16:38 - 00000000 ____D () C:\FRST 2014-04-29 16:38 - 2014-04-29 16:38 - 00000000 _____ () C:\Users\Silas\defogger_reenable 2014-04-29 16:38 - 2012-12-20 18:08 - 00000000 ____D () C:\Users\Silas 2014-04-29 16:36 - 2014-02-23 20:35 - 00000000 ____D () C:\Users\Silas\AppData\Local\E3683022-6603-40FF-BA8F-5B741D87BBFC.aplzod 2014-04-29 16:36 - 2014-02-23 16:44 - 00000000 ____D () C:\Users\Silas\Documents\Outlook-Dateien 2014-04-29 16:33 - 2014-04-28 12:07 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-04-29 16:32 - 2014-04-27 18:40 - 00000000 ____D () C:\ProgramData\SecTaskMan 2014-04-29 16:28 - 2012-12-20 20:35 - 00000000 ____D () C:\Users\Silas\AppData\Roaming\Dropbox 2014-04-29 16:27 - 2014-04-29 16:27 - 02061824 _____ (Farbar) C:\Users\Silas\Downloads\FRST64.exe 2014-04-29 16:27 - 2012-12-20 18:09 - 00000000 ___RD () C:\Users\Silas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-29 16:25 - 2014-03-01 14:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare 2014-04-29 16:25 - 2014-03-01 14:06 - 00000000 ____D () C:\Program Files (x86)\Wondershare 2014-04-29 16:25 - 2013-05-02 21:28 - 00000000 ____D () C:\Users\Silas\AppData\Roaming\rinsebyreal 2014-04-29 16:21 - 2014-04-29 16:21 - 00050477 _____ () C:\Users\Silas\Downloads\Defogger.exe 2014-04-29 16:21 - 2012-12-20 19:45 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-04-29 16:09 - 2012-12-20 18:13 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-29 16:02 - 2012-12-20 18:08 - 01825891 _____ () C:\Windows\WindowsUpdate.log 2014-04-29 16:01 - 2014-04-29 16:01 - 00008431 _____ () C:\Users\Silas\Documents\gmer.log 2014-04-29 16:01 - 2009-07-14 19:58 - 00704912 _____ () C:\Windows\system32\perfh007.dat 2014-04-29 16:01 - 2009-07-14 19:58 - 00151224 _____ () C:\Windows\system32\perfc007.dat 2014-04-29 16:01 - 2009-07-14 07:13 - 01628308 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-29 11:59 - 2014-04-29 11:59 - 00380416 _____ () C:\Users\Silas\Downloads\Gmer-19357.exe 2014-04-29 09:52 - 2014-04-27 18:13 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-29 09:42 - 2009-07-14 06:45 - 00021984 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-29 09:42 - 2009-07-14 06:45 - 00021984 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-29 09:36 - 2012-12-20 20:37 - 00000000 ___RD () C:\Users\Silas\Dropbox 2014-04-29 09:36 - 2012-12-20 18:13 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-29 09:35 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-29 09:35 - 2009-07-14 06:51 - 00054423 _____ () C:\Windows\setupact.log 2014-04-28 21:15 - 2012-12-20 21:56 - 00000000 ____D () C:\Users\Silas\Documents\Schule 2014-04-28 18:22 - 2012-12-20 18:39 - 00474810 _____ () C:\Windows\PFRO.log 2014-04-28 12:07 - 2014-04-28 12:07 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-04-28 12:06 - 2014-04-28 12:06 - 05049344 _____ (Crawler.com ) C:\Users\Silas\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-04-27 19:47 - 2013-03-06 23:38 - 00000000 ____D () C:\Users\Silas\AppData\Local\Windows Live 2014-04-27 18:39 - 2014-04-27 18:39 - 02365840 _____ () C:\Users\Silas\Downloads\SecurityTaskManager_Setup.exe 2014-04-27 18:38 - 2014-04-27 18:38 - 00540072 _____ (Neuber Software) C:\Users\Silas\Downloads\SvchostAnalyzer.exe 2014-04-27 18:33 - 2012-12-20 20:46 - 00000000 ____D () C:\Windows\PCHEALTH 2014-04-27 18:11 - 2014-04-27 18:11 - 00613200 _____ (Chip Digital GmbH) C:\Users\Silas\Downloads\Malwarebytes Anti Malware - CHIP-Downloader.exe 2014-04-27 18:11 - 2014-04-27 18:11 - 00613200 _____ (Chip Digital GmbH) C:\Users\Silas\Downloads\Malwarebytes Anti Malware - CHIP-Downloader (1).exe 2014-04-27 17:50 - 2013-01-11 16:44 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-04-27 14:29 - 2013-07-27 16:29 - 00000000 ____D () C:\Users\Silas\Documents\Scan 2014-04-26 13:27 - 2012-12-25 12:08 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-04-25 11:40 - 2014-04-25 11:39 - 14298467 _____ () C:\Users\Silas\Downloads\nw_14643_handbrakexwinguiexe.exe 2014-04-22 20:17 - 2014-04-22 20:17 - 00000000 __SHD () C:\Users\Silas\AppData\Local\EmieUserList 2014-04-22 20:17 - 2014-04-22 20:17 - 00000000 __SHD () C:\Users\Silas\AppData\Local\EmieSiteList 2014-04-21 19:37 - 2014-04-21 19:37 - 00004853 _____ () C:\Users\Silas\Downloads\kroatien urlaub.odt 2014-04-17 19:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-15 15:40 - 2012-12-20 18:13 - 00112000 _____ () C:\Users\Silas\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-15 15:40 - 2009-07-14 06:45 - 00443464 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-15 12:07 - 2012-12-20 20:42 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-15 12:07 - 2009-07-14 04:34 - 00000478 _____ () C:\Windows\win.ini 2014-04-11 11:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-10 20:01 - 2012-12-21 12:49 - 00000000 ____D () C:\Users\Silas\AppData\Roaming\Skype 2014-04-10 19:26 - 2014-04-10 19:26 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-04-10 19:26 - 2014-04-10 19:26 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-04-10 19:26 - 2014-04-10 19:26 - 00000000 ____D () C:\Users\Silas\AppData\Local\Skype 2014-04-10 19:26 - 2014-04-10 19:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-04-10 19:26 - 2012-12-21 12:49 - 00000000 ____D () C:\ProgramData\Skype 2014-04-10 12:11 - 2013-01-23 23:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-04-10 10:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-04-10 10:27 - 2014-04-10 10:26 - 00000000 ____D () C:\Users\Silas\Desktop\LAN_Broadcom_12.4.0.3_Win7x86x64 2014-04-10 10:26 - 2014-04-10 10:22 - 139876507 _____ () C:\Users\Silas\Downloads\Lan_Broadcom_12.4.0.3_W7x86W7x64_A.zip 2014-04-10 10:24 - 2014-04-10 10:24 - 00000000 ____D () C:\Users\Silas\Desktop\Modem_LSI_2.2.99.0_Win7x86x64 2014-04-10 10:23 - 2014-04-10 10:23 - 02134334 _____ () C:\Users\Silas\Downloads\Modem_LSI_2.2.99.0_W7x86W7x64_A.zip 2014-04-09 19:40 - 2013-08-14 13:01 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 19:38 - 2012-12-21 17:55 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-08 22:13 - 2014-04-08 22:13 - 00000635 _____ () C:\Users\Silas\Desktop\Cyperia - Verknüpfung.lnk 2014-04-08 22:13 - 2014-04-08 18:39 - 00000000 ____D () C:\Users\Silas\Desktop\Cyperia 2013 Client 2014-04-08 18:39 - 2014-04-08 16:52 - 904446119 _____ () C:\Users\Silas\Downloads\Cyperia2013Client.zip 2014-04-08 16:51 - 2013-01-12 20:24 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2014-04-08 13:08 - 2014-04-08 13:08 - 01768986 _____ () C:\Users\Silas\Downloads\switchbot.zip 2014-04-08 12:25 - 2014-04-08 12:24 - 29990274 _____ () C:\Users\Silas\Downloads\cyperia.rar 2014-04-04 13:04 - 2012-12-21 12:45 - 00046355 _____ () C:\Windows\DirectX.log 2014-04-04 11:13 - 2013-03-26 23:36 - 00000000 ____D () C:\Users\Silas\Documents\Bewerbung 2014-04-03 17:27 - 2014-04-02 17:44 - 00000000 ____D () C:\Users\Silas\AppData\Local\Downloaded Installations 2014-04-03 09:04 - 2012-12-20 18:13 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-03 09:04 - 2012-12-20 18:13 - 00003852 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-02 18:59 - 2014-04-02 17:33 - 00000308 _____ () C:\Users\Silas\AppData\Roaming\Rim.DesktopHelper.Exception.log 2014-04-02 18:59 - 2014-04-02 17:33 - 00000308 _____ () C:\Users\Silas\AppData\Roaming\Rim.Desktop.Exception.log 2014-04-02 18:27 - 2014-04-02 17:33 - 00000000 ____D () C:\Users\Silas\AppData\Local\Research In Motion 2014-04-02 17:44 - 2014-04-02 17:43 - 00013785 _____ () C:\ads_err.adt 2014-04-02 17:44 - 2014-04-02 17:43 - 00004559 _____ () C:\ads_err.adm 2014-04-02 17:44 - 2014-04-02 17:43 - 00003072 _____ () C:\ads_err.adi 2014-04-02 17:43 - 2014-04-02 17:43 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf 2014-04-02 17:43 - 2014-04-02 17:43 - 00000000 ____D () C:\Users\Silas\Documents\BlackBerry 2014-04-02 17:33 - 2014-04-02 17:33 - 00000000 ____D () C:\Users\Silas\AppData\Roaming\Research In Motion 2014-04-02 17:32 - 2014-04-02 17:32 - 00002231 _____ () C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk 2014-04-02 17:32 - 2014-04-02 17:32 - 00001153 _____ () C:\Users\Silas\AppData\Roaming\Rim.Desktop.HttpServerSetup.log 2014-04-02 17:32 - 2014-04-02 17:32 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf 2014-04-02 17:32 - 2014-04-02 17:32 - 00000000 ____D () C:\ProgramData\Research In Motion 2014-04-02 17:32 - 2014-04-02 17:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry 2014-04-02 17:32 - 2014-04-02 17:32 - 00000000 ____D () C:\Program Files (x86)\Research In Motion 2014-04-02 17:29 - 2014-04-02 17:26 - 119528976 _____ () C:\Users\Silas\Downloads\710_b042_multilanguage.exe Some content of TEMP: ==================== C:\Users\Silas\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmprjmxg_.dll C:\Users\Silas\AppData\Local\Temp\TUUUninstallHelper.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-29 13:47 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-04-2014 Ran by Silas at 2014-04-29 16:39:24 Running from C:\Users\Silas\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3502 - Acer Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.7.0.2090 - Adobe Systems Incorporated) Hidden Adobe Reader XI (11.0.03) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated) Alcor Micro USB Card Reader (HKLM-x32\...\InstallShield_{6030FCD7-8F1A-427D-AF05-8DD1A2EA2ABA}) (Version: 1.5.17.05094 - Alcor Micro Corp.) Alcor Micro USB Card Reader (x32 Version: 1.5.17.05094 - Alcor Micro Corp.) Hidden AMD Accelerated Video Transcoding (Version: 12.5.100.20928 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.1016.4 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{ABFC0970-7FDF-9E49-C049-5D24CB1F150E}) (Version: 8.0.891.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.70928.1539 - Advanced Micro Devices, Inc.) Hidden Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - Atheros) Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros) BlackBerry Desktop Software 7.1 (HKLM-x32\...\BlackBerry_Desktop) (Version: 7.1.0.41 - Research in Motion Ltd.) BlackBerry Desktop Software 7.1 (x32 Version: 7.1.0.41 - Research in Motion Ltd.) Hidden BlackBerry Device Software Updater (HKLM-x32\...\{5BF3423C-4397-4FE3-A318-C9850EA24CB3}) (Version: 8.0.0.46 - Research In Motion Ltd) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Broadcom Management Programs (HKLM\...\{688758A2-8520-4470-8FA6-765BAC86FC53}) (Version: 12.53.01 - Broadcom Corporation) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center (x32 Version: 2012.0928.1532.26058 - Ihr Firmenname) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0928.1532.26058 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2012.0928.1532.26058 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2012.0928.1532.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2012.0928.1531.26058 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2012.0928.1532.26058 - Advanced Micro Devices, Inc.) Hidden Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) Common Desktop Agent (Version: 1.62.0 - OEM) Hidden CrystalDiskInfo 5.2.2 Shizuku Edition (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 5.2.2 - Crystal Dew World) CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.1905c.56 - CyberLink Corp.) CyberLink PowerDVD 12 (x32 Version: 12.0.1905c.56 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Definition Update for Microsoft Office 2013 (KB2760587) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{9D8D67FD-8FAB-4B98-A121-4CFA10380058}) (Version: - Microsoft) Dota 2 (HKLM-x32\...\Steam App 570) (Version: - ) Download.am (HKLM-x32\...\Download.am) (Version: - ) Driver Checker v2.7.5 (HKLM-x32\...\Driver Checker_is1) (Version: 2.7.5 - driverchecker.com, Inc.) eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Free YouTube Download version 3.2.20.1230 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.20.1230 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.20.1230 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.20.1230 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.131 - Google Inc.) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.) ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.5.6.1001 - Intel Corporation) Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.02.00.1002 - Intel Corporation) iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.) Java 7 Update 13 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217013FF}) (Version: 7.0.130 - Oracle) Java Auto Updater (x32 Version: 2.1.9.0 - Sun Microsystems, Inc.) Hidden JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) K-Lite Codec Pack 10.2.0 Basic (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.2.0 - ) Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden Logitech Gaming Software 8.46 (HKLM\...\Logitech Gaming Software) (Version: 8.46.27 - Logitech Inc.) Logitech SetPoint 6.52 (HKLM\...\sp6) (Version: 6.52.74 - Logitech) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Access MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Excel MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Groove MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft InfoPath MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Lync MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office 64-bit Components 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Korrekturhilfen 2013 - Deutsch (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM UX MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - English (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - Italiano (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft OneNote MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Outlook MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft PowerPoint MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Publisher MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Word MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden Outils de vérification linguistique 2013 de Microsoft Office*- Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden PDF24 Creator 5.7.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.) QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.) RAPID Mode (Version: 1.0.1.42 - Samsung Electronics Co., Ltd.) Hidden Revo Uninstaller Pro 2.5.9 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 2.5.9 - VS Revo Group, Ltd.) Samsung CLX-3300 Series (HKLM-x32\...\Samsung CLX-3300 Series) (Version: 1.01 (01/05/2012) - Samsung Electronics Co., Ltd.) Samsung Easy Document Creator (HKLM-x32\...\Samsung Easy Document Creator) (Version: 1.02.09 (25/04/2012) - Samsung Electronics Co., Ltd.) Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.02.45.02(01/05/2012) - Samsung Electronics Co., Ltd.) Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.3.0 - Samsung Electronics) Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) Samsung Scan Process Machine (x32 Version: 1.00.18.04 - Samsung Electronics Co., Ltd.) Hidden Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (x32 Version: - Microsoft) Hidden SilkroadR (HKLM-x32\...\SilkroadR) (Version: - ) SIW version 2011.10.29 (HKLM-x32\...\{AB67580-257C-45FF-B8F4-C8C30682091A}_is1) (Version: 2011.10.29 - Topala Software Solutions) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) SNS Upload for Easy Document Creator (HKLM-x32\...\{B6B5F07C-88D5-49D3-A1A7-A6D4BC37DCCC}) (Version: 1.0.0 - Samsung Electronics Co.,Ltd) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) System Requirements Lab for Intel (HKLM-x32\...\{63B7AC7E-0178-4F4F-A79B-08D97ADD02D7}) (Version: 4.5.11.0 - Husdawg, LLC) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.10 - TeamSpeak Systems GmbH) Überwachungstool für die Intel® Turbo-Boost-Technik (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.186.6 - Intel) Überwachungstool für die Intel® Turbo-Boost-Technik 2.6 (HKLM\...\{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.6.2.0 - Intel) Update for Microsoft Excel 2013 (KB2752087) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{90060D4D-6BB2-4B29-B804-3C23563EEA6B}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2752087) 32-Bit Edition (HKLM-x32\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{90060D4D-6BB2-4B29-B804-3C23563EEA6B}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2752087) 32-Bit Edition (HKLM-x32\...\{90150000-0018-0407-0000-0000000FF1CE}_Office15.PROPLUS_{90060D4D-6BB2-4B29-B804-3C23563EEA6B}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2752087) 32-Bit Edition (HKLM-x32\...\{90150000-001B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{90060D4D-6BB2-4B29-B804-3C23563EEA6B}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2752087) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{90060D4D-6BB2-4B29-B804-3C23563EEA6B}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2817678) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{7FBE2D23-9F3C-4983-B927-2A4BF600B7A7}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2863908) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{6764E50D-D076-41BC-B069-08DD488AE88B}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2863908) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{6764E50D-D076-41BC-B069-08DD488AE88B}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2863908) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{885A0D95-13A8-4A31-B01C-B02454F414AA}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760344) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{A7610F07-E844-4444-8E1D-D5BC8AD0B4C5}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760544) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{45B7D395-EB9B-414F-9E46-5849B42326E2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2768012) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{66421820-D3CA-450A-898C-78D7E40108E6}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817636) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{2D355F71-076A-42AD-8747-6132105441F4}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817636) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{2D355F71-076A-42AD-8747-6132105441F4}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2825631) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{E458713D-E208-4098-A155-EA1152F9B301}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2825631) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{E458713D-E208-4098-A155-EA1152F9B301}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2827272) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{5A645CF3-3C40-4172-BCEB-19E3FC855266}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2827272) 32-Bit Edition (HKLM-x32\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{5A645CF3-3C40-4172-BCEB-19E3FC855266}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863825) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{96754DD8-5AF9-4CF8-A5A9-19770CD9AFBC}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{AD7045B8-1D75-4B4C-8120-12F045D206C7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{AD7045B8-1D75-4B4C-8120-12F045D206C7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863844) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{8AEAF88E-A488-4C1E-B10D-F00143BA650F}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863860) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{4E47A3B9-D863-4CE7-9488-847F2981361B}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863860) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{4E47A3B9-D863-4CE7-9488-847F2981361B}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2863864) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{48D4C003-065C-460C-A864-BB18A159F3D6}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2863864) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{48D4C003-065C-460C-A864-BB18A159F3D6}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2863864) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{48D4C003-065C-460C-A864-BB18A159F3D6}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2863864) 32-Bit Edition (HKLM-x32\...\{90150000-00BA-0407-0000-0000000FF1CE}_Office15.PROPLUS_{48D4C003-065C-460C-A864-BB18A159F3D6}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2817628) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{DF36A224-4C72-4FF4-9961-CD4873DDAE6C}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2817628) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{DF36A224-4C72-4FF4-9961-CD4873DDAE6C}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2817628) 32-Bit Edition (HKLM-x32\...\{90150000-00A1-0407-0000-0000000FF1CE}_Office15.PROPLUS_{DF36A224-4C72-4FF4-9961-CD4873DDAE6C}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2863911) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{6022B459-32A4-4318-A9A4-815C0BCEF977}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2863911) 32-Bit Edition (HKLM-x32\...\{90150000-001A-0407-0000-0000000FF1CE}_Office15.PROPLUS_{DA3F3D63-4C9F-407B-9CA1-39638F85BDDD}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2837627) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{CA8215E2-4E68-4BCA-BBEB-D4ED8140F037}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2837627) 32-Bit Edition (HKLM-x32\...\{90150000-0018-0407-0000-0000000FF1CE}_Office15.PROPLUS_{CA8215E2-4E68-4BCA-BBEB-D4ED8140F037}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{25C61889-2E44-4BE1-9E96-9364BFDCF501}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{25C61889-2E44-4BE1-9E96-9364BFDCF501}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2863909) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{FF3BD143-BA46-4948-A71F-5B07AA1706BB}) (Version: - Microsoft) Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) ==================== Restore Points ========================= 15-04-2014 10:06:49 Windows Update 18-04-2014 13:41:07 Windows Update 21-04-2014 14:13:33 Windows Update 25-04-2014 15:39:00 Windows Update 28-04-2014 18:34:56 Windows Update 29-04-2014 14:20:44 Revo Uninstaller Pro's restore point - TuneUp Utilities 2013 29-04-2014 14:20:59 TuneUp Utilities 2013 wird entfernt 29-04-2014 14:21:18 TuneUp Utilities Language Pack (de-DE) wird entfernt 29-04-2014 14:23:25 Revo Uninstaller Pro's restore point - Rinse 29-04-2014 14:23:35 Removed Rinse 29-04-2014 14:25:14 Revo Uninstaller Pro's restore point - Wondershare Dr.Fone für iOS(Build 4.0.1.75) 29-04-2014 14:27:25 Revo Uninstaller Pro's restore point - Dropbox 29-04-2014 14:28:43 Revo Uninstaller Pro's restore point - Malwarebytes Anti-Malware Version 2.0.1.1004 29-04-2014 14:32:26 Revo Uninstaller Pro's restore point - Security Task Manager 1.8g 29-04-2014 14:33:30 Revo Uninstaller Pro's restore point - Spyware Terminator 2012 ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-01-11 16:57 - 00000854 __RAH C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 secure.tune-up.com ==================== Scheduled Tasks (whitelisted) ============= Task: {2D26ECD1-582B-43DB-B0B2-39AE5418B5D8} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe Task: {3147FEFA-5AB3-4A1D-90DC-A711007D59E1} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation) Task: {3CEAE202-4A0E-4311-8EBA-67897AA6F1FC} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {9436BD86-B333-4D21-AF90-25D3873D444A} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe Task: {B3EBF746-8FB6-4DE2-88F8-C9FD03A54B71} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-20] (Google Inc.) Task: {B41F8E7A-3FE2-4210-BDE0-E06A3D4BF2DA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-20] (Google Inc.) Task: {C98D8581-FEB1-412B-90B3-EDD91078FE26} - System32\Tasks\EPUpdater => C:\Users\Silas\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe <==== ATTENTION Task: {F0ED3525-DD0C-4B80-8B2A-4A64AE23E416} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03] (Sun Microsystems, Inc.) Task: {F5221A1A-BB3E-4737-95D9-CB817E48C42E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2012-01-09 12:47 - 2012-01-09 12:47 - 00034304 _____ () C:\Windows\System32\sst7clm.dll 2012-12-21 12:45 - 2012-12-24 15:58 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2012-02-20 22:23 - 2012-02-20 22:23 - 00456704 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe 2012-02-20 22:23 - 2012-02-20 22:23 - 00051200 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll 2012-05-01 10:20 - 2012-05-01 10:20 - 01541712 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2012-12-20 19:14 - 2009-12-23 18:32 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2013-09-14 02:51 - 2013-09-14 02:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll 2013-09-14 02:50 - 2013-09-14 02:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll 2013-12-27 13:59 - 2013-11-28 13:14 - 00013824 _____ () C:\Program Files (x86)\Samsung SSD Magician\SAMSUNG_SSD.dll 2013-12-27 13:59 - 2013-11-28 19:59 - 00098816 _____ () C:\Program Files (x86)\Samsung SSD Magician\PAL.dll 2013-12-27 13:59 - 2013-11-28 19:59 - 00034304 _____ () C:\Program Files (x86)\Samsung SSD Magician\SATA.dll 2013-12-27 13:59 - 2013-11-28 19:59 - 00032768 _____ () C:\Program Files (x86)\Samsung SSD Magician\SAT.dll 2013-12-27 13:59 - 2013-11-28 20:00 - 00031232 _____ () C:\Program Files (x86)\Samsung SSD Magician\SMINI.dll 2013-12-27 13:59 - 2013-11-28 19:59 - 00029696 _____ () C:\Program Files (x86)\Samsung SSD Magician\SAS.dll 2012-02-15 15:17 - 2012-02-15 15:17 - 00310272 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\sslog.dll 2012-03-21 07:22 - 2012-03-21 07:22 - 00683520 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\SASkin.dll 2012-03-21 07:23 - 2012-03-21 07:23 - 00615424 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\SAStyle.cjstyles 2012-02-20 22:22 - 2012-02-20 22:22 - 00050688 _____ () C:\Program Files (x86)\Common Files\Common Desktop Agent\CDASrvPS.dll 2012-04-23 12:14 - 2012-04-23 12:14 - 02013184 _____ () C:\Program Files (x86)\Samsung\Easy Printer Manager\sf.dll 2014-04-26 17:12 - 2014-04-24 02:33 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\chrome_elf.dll 2014-04-26 17:12 - 2014-04-24 02:33 - 00674632 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\libglesv2.dll 2014-04-26 17:12 - 2014-04-24 02:33 - 00093000 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\libegl.dll 2014-04-26 17:12 - 2014-04-24 02:33 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\pdf.dll 2014-04-26 17:12 - 2014-04-24 02:33 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll 2014-04-26 17:12 - 2014-04-24 02:33 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ffmpegsumo.dll 2014-01-23 15:55 - 2014-01-23 15:55 - 01030312 _____ () C:\Program Files (x86)\Microsoft Office\Office15\ADDINS\UmOutlookAddin.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^Users^Silas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Samsung SSD Magician.lnk => C:\Windows\pss\Samsung SSD Magician.lnk.Startup ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/29/2014 04:20:43 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {deb1dc83-9239-4b63-aac1-298cc80799ad} Error: (04/25/2014 11:24:40 AM) (Source: Application Hang) (User: ) Description: Programm PowerDVD12.exe, Version 12.0.11175.1925 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: a28 Startzeit: 01cf6067da62011c Endzeit: 7 Anwendungspfad: C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe Berichts-ID: 69f9a7f7-cc5b-11e3-8b7b-00262d9d8fa7 Error: (04/22/2014 07:24:10 PM) (Source: Bonjour Service) (User: ) Description: Client application bug: DNSServiceResolve(ec:35:86:c8:01:96@fe80::ee35:86ff:fec8:196._apple-mobdev2._tcp.local.) active for over two minutes. This places considerable burden on the network. Error: (04/21/2014 09:59:32 PM) (Source: Bonjour Service) (User: ) Description: Client application bug: DNSServiceResolve(ec:35:86:c8:01:96@fe80::ee35:86ff:fec8:196._apple-mobdev2._tcp.local.) active for over two minutes. This places considerable burden on the network. Error: (04/18/2014 03:33:44 PM) (Source: Bonjour Service) (User: ) Description: Client application bug: DNSServiceResolve(ec:35:86:c8:01:96@fe80::ee35:86ff:fec8:196._apple-mobdev2._tcp.local.) active for over two minutes. This places considerable burden on the network. Error: (04/11/2014 02:56:39 PM) (Source: Bonjour Service) (User: ) Description: Client application bug: DNSServiceResolve(ec:35:86:c8:01:96@fe80::ee35:86ff:fec8:196._apple-mobdev2._tcp.local.) active for over two minutes. This places considerable burden on the network. Error: (04/10/2014 05:33:19 PM) (Source: Bonjour Service) (User: ) Description: 472: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error: (04/10/2014 05:33:19 PM) (Source: Bonjour Service) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (04/10/2014 03:07:08 PM) (Source: Bonjour Service) (User: ) Description: 548: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error: (04/10/2014 03:07:08 PM) (Source: Bonjour Service) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 System errors: ============= Error: (04/26/2014 08:17:17 PM) (Source: Microsoft Antimalware) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.173.603.0 Aktualisierungsquelle: %NT-AUTORITÄT59 Aktualisierungsphase: 4.5.0216.00 Quellpfad: 4.5.0216.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\SYSTEM Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Error: (04/10/2014 10:07:39 AM) (Source: Microsoft Antimalware) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.169.2070.0 Aktualisierungsquelle: %NT-AUTORITÄT59 Aktualisierungsphase: 4.5.0216.00 Quellpfad: 4.5.0216.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\SYSTEM Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Error: (04/09/2014 07:37:45 PM) (Source: DCOM) (User: ) Description: {74944725-B65F-4E37-8633-BD4DDE193921} Error: (04/09/2014 05:53:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde nicht richtig gestartet. Error: (04/02/2014 05:46:57 PM) (Source: Service Control Manager) (User: ) Description: Dienst "Blackberry Device Manager" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (04/01/2014 02:30:58 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10. Error: (04/01/2014 02:30:58 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10. Error: (04/01/2014 02:30:58 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10. Error: (04/01/2014 02:30:58 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10. Error: (04/01/2014 02:30:54 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus lautet: 10. Microsoft Office Sessions: ========================= Error: (04/29/2014 04:20:43 PM) (Source: VSS)(User: ) Description: 0x80070005, Zugriff verweigert Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {deb1dc83-9239-4b63-aac1-298cc80799ad} Error: (04/25/2014 11:24:40 AM) (Source: Application Hang)(User: ) Description: PowerDVD12.exe12.0.11175.1925a2801cf6067da62011c7C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe69f9a7f7-cc5b-11e3-8b7b-00262d9d8fa7 Error: (04/22/2014 07:24:10 PM) (Source: Bonjour Service)(User: ) Description: Client application bug: DNSServiceResolve(ec:35:86:c8:01:96@fe80::ee35:86ff:fec8:196._apple-mobdev2._tcp.local.) active for over two minutes. This places considerable burden on the network. Error: (04/21/2014 09:59:32 PM) (Source: Bonjour Service)(User: ) Description: Client application bug: DNSServiceResolve(ec:35:86:c8:01:96@fe80::ee35:86ff:fec8:196._apple-mobdev2._tcp.local.) active for over two minutes. This places considerable burden on the network. Error: (04/18/2014 03:33:44 PM) (Source: Bonjour Service)(User: ) Description: Client application bug: DNSServiceResolve(ec:35:86:c8:01:96@fe80::ee35:86ff:fec8:196._apple-mobdev2._tcp.local.) active for over two minutes. This places considerable burden on the network. Error: (04/11/2014 02:56:39 PM) (Source: Bonjour Service)(User: ) Description: Client application bug: DNSServiceResolve(ec:35:86:c8:01:96@fe80::ee35:86ff:fec8:196._apple-mobdev2._tcp.local.) active for over two minutes. This places considerable burden on the network. Error: (04/10/2014 05:33:19 PM) (Source: Bonjour Service)(User: ) Description: 472: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error: (04/10/2014 05:33:19 PM) (Source: Bonjour Service)(User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (04/10/2014 03:07:08 PM) (Source: Bonjour Service)(User: ) Description: 548: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error: (04/10/2014 03:07:08 PM) (Source: Bonjour Service)(User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 ==================== Memory info =========================== Percentage of memory in use: 80% Total physical RAM: 3956.5 MB Available physical RAM: 778.62 MB Total Pagefile: 4396.51 MB Available Pagefile: 906.61 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:238.37 GB) (Free:105.04 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: 8E8583B3) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=238 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-04-29 21:46:11 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Samsung_ rev.DXM0 238,47GB Running: Gmer-19357.exe; Driver: C:\Users\Silas\AppData\Local\Temp\kgloypow.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002dfe000 45 bytes [60, 94, 2C, 05, 00, 00, 00, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff80002dfe02f 16 bytes [00, 06, 00, 00, 00, 00, 00, ...] ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2124] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076171465 2 bytes [17, 76] .text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2124] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761714bb 2 bytes [17, 76] .text ... * 2 .text C:\Windows\SysWOW64\PnkBstrA.exe[2608] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000071ad1a22 2 bytes [AD, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[2608] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000071ad1ad0 2 bytes [AD, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[2608] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000071ad1b08 2 bytes [AD, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[2608] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000071ad1bba 2 bytes [AD, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[2608] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000071ad1bda 2 bytes [AD, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076171465 2 bytes [17, 76] .text C:\Windows\SysWOW64\PnkBstrA.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761714bb 2 bytes [17, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2572] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076171465 2 bytes [17, 76] .text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2572] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761714bb 2 bytes [17, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076171465 2 bytes [17, 76] .text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761714bb 2 bytes [17, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[2528] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076171465 2 bytes [17, 76] .text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[2528] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761714bb 2 bytes [17, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader.exe[5416] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076171465 2 bytes [17, 76] .text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader.exe[5416] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761714bb 2 bytes [17, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[7884] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076171465 2 bytes [17, 76] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[7884] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000761714bb 2 bytes [17, 76] .text ... * 2 ---- EOF - GMER 2.1 ---- |
30.04.2014, 11:33 | #4 |
| Win 7 Laptop ruckelt plötzlich hier noch die logs der Virenscans: Code:
ATTFilter ------ Logfile von Spyware Terminator (db:) ------ Scann Zeit: 28/04/2014 12:16:56 länge: 0:20:50 Plattform: W7 (6.1.0.7601) Benutzer: Admin Scann typ: Umfangreicher Scann Gescannte Objekte: 354025 (Kritisch: 5) ------ laufende Prozesse ------ smss.exe [Microsoft Corporation] : %SYSDIR%\smss.exe csrss.exe [Microsoft Corporation] : %SYSDIR%\csrss.exe wininit.exe [Microsoft Corporation] : %SYSDIR%\wininit.exe csrss.exe [Microsoft Corporation] : %SYSDIR%\csrss.exe services.exe [Microsoft Corporation] : %SYSDIR%\services.exe lsass.exe [Microsoft Corporation] : %SYSDIR%\lsass.exe lsm.exe [Microsoft Corporation] : %SYSDIR%\lsm.exe winlogon.exe [Microsoft Corporation] : %SYSDIR%\winlogon.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe MsMpEng.exe [Microsoft Corporation] : %SystemDiskRoot%\Program Files\Microsoft Security Client\MsMpEng.exe atiesrxx.exe [AMD] : %SYSDIR%\atiesrxx.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe atieclxx.exe [AMD] : %SYSDIR%\atieclxx.exe wlanext.exe [Microsoft Corporation] : %SYSDIR%\wlanext.exe conhost.exe [Microsoft Corporation] : %SYSDIR%\conhost.exe spoolsv.exe [Microsoft Corporation] : %SYSDIR%\spoolsv.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe AppleMobileDeviceService.exe [Apple Inc.] : %COMMONFILES32%\Apple\Mobile Device Support\AppleMobileDeviceService.exe taskhost.exe [Microsoft Corporation] : %SYSDIR%\taskhost.exe dwm.exe [Microsoft Corporation] : %SYSDIR%\dwm.exe explorer.exe [Microsoft Corporation] : %WINDIR%\explorer.exe mDNSResponder.exe [Apple Inc.] : %SystemDiskRoot%\Program Files\Bonjour\mDNSResponder.exe BPowMon.exe [Broadcom Corp.] : %SystemDiskRoot%\Program Files\Broadcom\BPowMon\BPowMon.exe BrcmMgmtAgent.exe [Broadcom Corporation] : %SystemDiskRoot%\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe CLMSMonitorServicePDVD12.exe [CyberLink] : %PROGRAMFILES32%\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe CLMSServerPDVD12.exe [CyberLink] : %PROGRAMFILES32%\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe UpdaterService.exe [Acer Incorporated] : %PROGRAMFILES%\Acer\Acer Updater\UpdaterService.exe PnkBstrA.exe : %SYSDIR32%\PnkBstrA.exe SamsungRapidSvc.exe [Samsung Electronics Co., Ltd.] : %SYSDIR%\RAPID\SamsungRapidSvc.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe TuneUpUtilitiesService64.exe [TuneUp Software] : %PROGRAMFILES%\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe WLIDSVC.EXE [Microsoft Corp.] : %SystemDiskRoot%\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE IAStorDataMgrSvc.exe [Intel Corporation] : %PROGRAMFILES32%\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe WLIDSVCM.EXE [Microsoft Corp.] : %SystemDiskRoot%\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE AmIcoSinglun64.exe [Alcor Micro Corp.] : %PROGRAMFILES%\AmIcoSingLun\AmIcoSinglun64.exe msseces.exe [Microsoft Corporation] : %SystemDiskRoot%\Program Files\Microsoft Security Client\msseces.exe LCore.exe [Logitech Inc.] : %SystemDiskRoot%\Program Files\Logitech Gaming Software\LCore.exe SetPoint.exe [Logitech, Inc.] : %SystemDiskRoot%\Program Files\Logitech\SetPointP\SetPoint.exe CDASrv.exe : %SystemDiskRoot%\Program Files\Common Files\Common Desktop Agent\CDASrv.exe SamsungRapidApp.exe [Samsung Electronics Co., Ltd.] : %PROGRAMFILES%\RAPID\CacheFilter\SamsungRapidApp.exe sidebar.exe [Microsoft Corporation] : %SystemDiskRoot%\Program Files\Windows Sidebar\sidebar.exe iCloudServices.exe [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\iCloudServices.exe TuneUpUtilitiesApp64.exe [TuneUp Software] : %PROGRAMFILES%\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe ApplePhotoStreams.exe [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\ApplePhotoStreams.exe Dropbox.exe [Dropbox, Inc.] : %APPDATA%\Dropbox\bin\Dropbox.exe Samsung Magician.exe [Samsung Electronics.] : %PROGRAMFILES32%\Samsung SSD Magician\Samsung Magician.exe IAStorIcon.exe [Intel Corporation] : %PROGRAMFILES32%\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe iTunesHelper.exe [Apple Inc.] : %PROGRAMFILES32%\iTunes\iTunesHelper.exe RIMBBLaunchAgent.exe [BlackBerry Limited] : %COMMONFILES32%\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe KHALMNPR.exe [Logitech, Inc.] : %SystemDiskRoot%\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe NisSrv.exe [Microsoft Corporation] : %SystemDiskRoot%\Program Files\Microsoft Security Client\NisSrv.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe TurboBoost.exe [Intel(R) Corporation] : %SystemDiskRoot%\Program Files\Intel\TurboBoost\TurboBoost.exe iPodService.exe [Apple Inc.] : %SystemDiskRoot%\Program Files\iPod\bin\iPodService.exe APSDaemon.exe [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\APSDaemon.exe BbDevMgr.exe [BlackBerry Limited] : %COMMONFILES32%\Research In Motion\USB Drivers\BbDevMgr.exe SearchIndexer.exe [Microsoft Corporation] : %SYSDIR%\SearchIndexer.exe wmpnetwk.exe [Microsoft Corporation] : %SystemDiskRoot%\Program Files\Windows Media Player\wmpnetwk.exe ApplePhotoStreamsDownloader.exe [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\ApplePhotoStreamsDownloader.exe svchost.exe [Microsoft Corporation] : %SYSDIR%\svchost.exe dllhost.exe [Microsoft Corporation] : %SYSDIR%\dllhost.exe CLHNServiceForPowerDVD12.exe [CyberLink Corp.] : %PROGRAMFILES32%\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe CDAS2PC.exe : %PROGRAMFILES32%\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe jusched.exe [Sun Microsystems, Inc.] : %COMMONFILES32%\Java\Java Update\jusched.exe jucheck.exe [Sun Microsystems, Inc.] : %COMMONFILES32%\Java\Java Update\jucheck.exe chrome.exe [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\chrome.exe WmiPrvSE.exe [Microsoft Corporation] : %SYSDIR%\wbem\WmiPrvSE.exe st_rsser64.exe [Crawler.com] : %PROGRAMFILES%\Spyware Terminator\st_rsser64.exe SpywareTerminatorUpdate.exe [Crawler.com] : %PROGRAMFILES32%\Spyware Terminator\SpywareTerminatorUpdate.exe SpywareTerminatorShield.exe [Crawler.com] : %PROGRAMFILES32%\Spyware Terminator\SpywareTerminatorShield.exe SpywareTerminator.exe [Crawler.com] : %PROGRAMFILES32%\Spyware Terminator\SpywareTerminator.exe chrome.exe [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\chrome.exe ------ Laufende Services und Treiber ------ ACPI [Microsoft Corporation] : %SYSDIR%\drivers\acpi.sys AeLookupSvc [Microsoft Corporation] : %SYSDIR%\svchost.exe AFD [Microsoft Corporation] : %SYSDIR%\drivers\afd.sys AMD External Events Utility [AMD] : %SYSDIR%\atiesrxx.exe amdkmdag [Advanced Micro Devices, Inc.] : %SYSDIR%\drivers\atikmdag.sys amdkmdap [Advanced Micro Devices, Inc.] : %SYSDIR%\drivers\atikmpag.sys amdxata [Advanced Micro Devices] : %SYSDIR%\drivers\amdxata.sys Apple Mobile Device [Apple Inc.] : %COMMONFILES32%\Apple\Mobile Device Support\AppleMobileDeviceService.exe atapi [Microsoft Corporation] : %SYSDIR%\drivers\atapi.sys athr [Atheros Communications, Inc.] : %SYSDIR%\drivers\athrx.sys AtiHDAudioService [Advanced Micro Devices] : %SYSDIR%\drivers\AtihdW76.sys AudioEndpointBuilder [Microsoft Corporation] : %SYSDIR%\svchost.exe AudioSrv [Microsoft Corporation] : %SYSDIR%\svchost.exe BFE [Microsoft Corporation] : %SYSDIR%\svchost.exe BITS [Microsoft Corporation] : %SYSDIR%\svchost.exe BlackBerry Device Manager [BlackBerry Limited] : %COMMONFILES32%\Research In Motion\USB Drivers\BbDevMgr.exe blbdrive [Microsoft Corporation] : %SYSDIR%\drivers\blbdrive.sys Bonjour Service [Apple Inc.] : %SystemDiskRoot%\Program Files\Bonjour\mDNSResponder.exe bowser [Microsoft Corporation] : %SYSDIR%\drivers\bowser.sys BPowMon [Broadcom Corp.] : %SystemDiskRoot%\Program Files\Broadcom\BPowMon\BPowMon.exe BrcmMgmtAgent [Broadcom Corporation] : %SystemDiskRoot%\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe Browser [Microsoft Corporation] : %SYSDIR%\svchost.exe cdrom [Microsoft Corporation] : %SYSDIR%\drivers\cdrom.sys CLFS [Microsoft Corporation] : %SYSDIR%\clfs.sys CLHNServiceForPowerDVD12 [CyberLink Corp.] : %PROGRAMFILES32%\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe CmBatt [Microsoft Corporation] : %SYSDIR%\drivers\CmBatt.sys CNG [Microsoft Corporation] : %SYSDIR%\drivers\cng.sys Compbatt [Microsoft Corporation] : %SYSDIR%\drivers\compbatt.sys CompositeBus [Microsoft Corporation] : %SYSDIR%\drivers\CompositeBus.sys CryptSvc [Microsoft Corporation] : %SYSDIR%\svchost.exe CSC [Microsoft Corporation] : %SYSDIR%\drivers\csc.sys CscService [Microsoft Corporation] : %SYSDIR%\svchost.exe CyberLink PowerDVD 12 Media Server Monitor Service [CyberLink] : %PROGRAMFILES32%\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe CyberLink PowerDVD 12 Media Server Service [CyberLink] : %PROGRAMFILES32%\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe DcomLaunch [Microsoft Corporation] : %SYSDIR%\svchost.exe DfsC [Microsoft Corporation] : %SYSDIR%\drivers\dfsc.sys Dhcp [Microsoft Corporation] : %SYSDIR%\svchost.exe discache [Microsoft Corporation] : %SYSDIR%\drivers\discache.sys Disk [Microsoft Corporation] : %SYSDIR%\drivers\disk.sys Dnscache [Microsoft Corporation] : %SYSDIR%\svchost.exe dot3svc [Microsoft Corporation] : %SYSDIR%\svchost.exe DPS [Microsoft Corporation] : %SYSDIR%\svchost.exe DXGKrnl [Microsoft Corporation] : %SYSDIR%\drivers\dxgkrnl.sys EapHost [Microsoft Corporation] : %SYSDIR%\svchost.exe eventlog [Microsoft Corporation] : %SYSDIR%\svchost.exe EventSystem [Microsoft Corporation] : %SYSDIR%\svchost.exe fdPHost [Microsoft Corporation] : %SYSDIR%\svchost.exe FDResPub [Microsoft Corporation] : %SYSDIR%\svchost.exe FileInfo [Microsoft Corporation] : %SYSDIR%\drivers\fileinfo.sys FltMgr [Microsoft Corporation] : %SYSDIR%\drivers\fltMgr.sys FontCache [Microsoft Corporation] : %SYSDIR%\svchost.exe fvevol [Microsoft Corporation] : %SYSDIR%\drivers\fvevol.sys GEARAspiWDM [GEAR Software Inc.] : %SYSDIR%\drivers\GEARAspiWDM.sys gpsvc [Microsoft Corporation] : %SYSDIR%\svchost.exe HdAudAddService [Microsoft Corporation] : %SYSDIR%\drivers\HdAudio.sys HDAudBus [Microsoft Corporation] : %SYSDIR%\drivers\hdaudbus.sys HECIx64 [Intel Corporation] : %SYSDIR%\drivers\HECIx64.sys HidUsb [Microsoft Corporation] : %SYSDIR%\drivers\hidusb.sys HomeGroupListener [Microsoft Corporation] : %SYSDIR%\svchost.exe HomeGroupProvider [Microsoft Corporation] : %SYSDIR%\svchost.exe HTTP [Microsoft Corporation] : %SYSDIR%\drivers\http.sys hwpolicy [Microsoft Corporation] : %SYSDIR%\drivers\hwpolicy.sys i8042prt [Microsoft Corporation] : %SYSDIR%\drivers\i8042prt.sys iaStor [Intel Corporation] : %SYSDIR%\drivers\iaStor.sys IAStorDataMgrSvc [Intel Corporation] : %PROGRAMFILES32%\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe Impcd [Intel Corporation] : %SYSDIR%\drivers\Impcd.sys intelppm [Microsoft Corporation] : %SYSDIR%\drivers\intelppm.sys IPBusEnum [Microsoft Corporation] : %SYSDIR%\svchost.exe iphlpsvc [Microsoft Corporation] : %SYSDIR%\svchost.exe iPod Service [Apple Inc.] : %SystemDiskRoot%\Program Files\iPod\bin\iPodService.exe k57nd [Broadcom Corporation] : %SYSDIR%\drivers\k57amd64.sys kbdclass [Microsoft Corporation] : %SYSDIR%\drivers\kbdclass.sys kbdhid [Microsoft Corporation] : %SYSDIR%\drivers\kbdhid.sys KeyIso [Microsoft Corporation] : %SYSDIR%\lsass.exe KSecDD [Microsoft Corporation] : %SYSDIR%\drivers\ksecdd.sys KSecPkg [Microsoft Corporation] : %SYSDIR%\drivers\ksecpkg.sys ksthunk [Microsoft Corporation] : %SYSDIR%\drivers\ksthunk.sys LanmanServer [Microsoft Corporation] : %SYSDIR%\svchost.exe LanmanWorkstation [Microsoft Corporation] : %SYSDIR%\svchost.exe LGBusEnum [Logitech Inc.] : %SYSDIR%\drivers\LGBusEnum.sys LGSHidFilt [Logitech Inc.] : %SYSDIR%\drivers\LGSHidFilt.Sys LGSUsbFilt [Logitech Inc.] : %SYSDIR%\drivers\LGSUsbFilt.Sys LGVirHid [Logitech Inc.] : %SYSDIR%\drivers\LGVirHid.sys Live Updater Service [Acer Incorporated] : %PROGRAMFILES%\Acer\Acer Updater\UpdaterService.exe lltdio [Microsoft Corporation] : %SYSDIR%\drivers\lltdio.sys lmhosts [Microsoft Corporation] : %SYSDIR%\svchost.exe luafv [Microsoft Corporation] : %SYSDIR%\drivers\luafv.sys Modem [Microsoft Corporation] : %SYSDIR%\drivers\modem.sys monitor [Microsoft Corporation] : %SYSDIR%\drivers\monitor.sys mouclass [Microsoft Corporation] : %SYSDIR%\drivers\mouclass.sys mouhid [Microsoft Corporation] : %SYSDIR%\drivers\mouhid.sys mountmgr [Microsoft Corporation] : %SYSDIR%\drivers\mountmgr.sys MpFilter [Microsoft Corporation] : %SYSDIR%\drivers\MpFilter.sys mpsdrv [Microsoft Corporation] : %SYSDIR%\drivers\mpsdrv.sys MpsSvc [Microsoft Corporation] : %SYSDIR%\svchost.exe mrxsmb [Microsoft Corporation] : %SYSDIR%\drivers\mrxsmb.sys mrxsmb10 [Microsoft Corporation] : %SYSDIR%\drivers\mrxsmb10.sys mrxsmb20 [Microsoft Corporation] : %SYSDIR%\drivers\mrxsmb20.sys msahci [Microsoft Corporation] : %SYSDIR%\drivers\msahci.sys msisadrv [Microsoft Corporation] : %SYSDIR%\drivers\msisadrv.sys MsMpSvc [Microsoft Corporation] : %SystemDiskRoot%\Program Files\Microsoft Security Client\MsMpEng.exe mssmbios [Microsoft Corporation] : %SYSDIR%\drivers\mssmbios.sys Mup [Microsoft Corporation] : %SYSDIR%\drivers\mup.sys NativeWifiP [Microsoft Corporation] : %SYSDIR%\drivers\nwifi.sys NDIS [Microsoft Corporation] : %SYSDIR%\drivers\ndis.sys NdisTapi [Microsoft Corporation] : %SYSDIR%\drivers\ndistapi.sys Ndisuio [Microsoft Corporation] : %SYSDIR%\drivers\ndisuio.sys NdisWan [Microsoft Corporation] : %SYSDIR%\drivers\ndiswan.sys NetBIOS [Microsoft Corporation] : %SYSDIR%\drivers\netbios.sys NetBT [Microsoft Corporation] : %SYSDIR%\drivers\netbt.sys Netman [Microsoft Corporation] : %SYSDIR%\svchost.exe netprofm [Microsoft Corporation] : %SYSDIR%\svchost.exe NisDrv [Microsoft Corporation] : %SYSDIR%\drivers\NisDrvWFP.sys NisSrv [Microsoft Corporation] : %SystemDiskRoot%\Program Files\Microsoft Security Client\NisSrv.exe NlaSvc [Microsoft Corporation] : %SYSDIR%\svchost.exe nsi [Microsoft Corporation] : %SYSDIR%\svchost.exe nsiproxy [Microsoft Corporation] : %SYSDIR%\drivers\nsiproxy.sys ntk_PowerDVD12 [Cyberlink Corp.] : %PROGRAMFILES%\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys p2pimsvc [Microsoft Corporation] : %SYSDIR%\svchost.exe p2psvc [Microsoft Corporation] : %SYSDIR%\svchost.exe partmgr [Microsoft Corporation] : %SYSDIR%\drivers\partmgr.sys PcaSvc [Microsoft Corporation] : %SYSDIR%\svchost.exe pci [Microsoft Corporation] : %SYSDIR%\drivers\pci.sys pcw [Microsoft Corporation] : %SYSDIR%\drivers\pcw.sys PEAUTH [Microsoft Corporation] : %SYSDIR%\drivers\PEAuth.sys PlugPlay [Microsoft Corporation] : %SYSDIR%\svchost.exe PnkBstrA : %SYSDIR32%\PnkBstrA.exe PNRPsvc [Microsoft Corporation] : %SYSDIR%\svchost.exe PolicyAgent [Microsoft Corporation] : %SYSDIR%\svchost.exe Power [Microsoft Corporation] : %SYSDIR%\svchost.exe PptpMiniport [Microsoft Corporation] : %SYSDIR%\drivers\raspptp.sys ProfSvc [Microsoft Corporation] : %SYSDIR%\svchost.exe Psched [Microsoft Corporation] : %SYSDIR%\drivers\pacer.sys RasAgileVpn [Microsoft Corporation] : %SYSDIR%\drivers\agilevpn.sys Rasl2tp [Microsoft Corporation] : %SYSDIR%\drivers\rasl2tp.sys RasMan [Microsoft Corporation] : %SYSDIR%\svchost.exe RasPppoe [Microsoft Corporation] : %SYSDIR%\drivers\raspppoe.sys RasSstp [Microsoft Corporation] : %SYSDIR%\drivers\rassstp.sys rdbss [Microsoft Corporation] : %SYSDIR%\drivers\rdbss.sys rdpbus [Microsoft Corporation] : %SYSDIR%\drivers\rdpbus.sys RDPCDD [Microsoft Corporation] : %SYSDIR%\drivers\RDPCDD.sys RDPENCDD [Microsoft Corporation] : %SYSDIR%\drivers\RDPENCDD.sys RDPREFMP [Microsoft Corporation] : %SYSDIR%\drivers\RDPREFMP.sys rdyboost [Microsoft Corporation] : %SYSDIR%\drivers\rdyboost.sys RimVSerPort [Research in Motion Ltd] : %SYSDIR%\drivers\RimSerial_AMD64.sys ROOTMODEM [Microsoft Corporation] : %SYSDIR%\drivers\rootmdm.sys RpcEptMapper [Microsoft Corporation] : %SYSDIR%\svchost.exe RpcSs [Microsoft Corporation] : %SYSDIR%\svchost.exe rspndr [Microsoft Corporation] : %SYSDIR%\drivers\rspndr.sys SamSs [Microsoft Corporation] : %SYSDIR%\lsass.exe SamsungRapidDiskFltr [Samsung Electronics Co., Ltd.] : %SYSDIR%\drivers\SamsungRapidDiskFltr.sys SamsungRapidFSFltr [Samsung Electronics Co., Ltd.] : %SYSDIR%\drivers\SamsungRapidFSFltr.sys SamsungRapidSvc [Samsung Electronics Co., Ltd.] : %SYSDIR%\RAPID\SamsungRapidSvc.exe Schedule [Microsoft Corporation] : %SYSDIR%\svchost.exe SENS [Microsoft Corporation] : %SYSDIR%\svchost.exe ShellHWDetection [Microsoft Corporation] : %SYSDIR%\svchost.exe speedfan [Almico Software] : %SYSDIR32%\speedfan.sys Spooler [Microsoft Corporation] : %SYSDIR%\spoolsv.exe srv [Microsoft Corporation] : %SYSDIR%\drivers\srv.sys srv2 [Microsoft Corporation] : %SYSDIR%\drivers\srv2.sys srvnet [Microsoft Corporation] : %SYSDIR%\drivers\srvnet.sys SSDPSRV [Microsoft Corporation] : %SYSDIR%\svchost.exe SSPORT [Samsung Electronics] : %SYSDIR%\drivers\SSPORT.sys SstpSvc [Microsoft Corporation] : %SYSDIR%\svchost.exe stisvc [Microsoft Corporation] : %SYSDIR%\svchost.exe storflt [Microsoft Corporation] : %SYSDIR%\drivers\vmstorfl.sys swenum [Microsoft Corporation] : %SYSDIR%\drivers\swenum.sys TapiSrv [Microsoft Corporation] : %SYSDIR%\svchost.exe Tcpip [Microsoft Corporation] : %SYSDIR%\drivers\tcpip.sys tcpipreg [Microsoft Corporation] : %SYSDIR%\drivers\tcpipreg.sys tdx [Microsoft Corporation] : %SYSDIR%\drivers\tdx.sys TermDD [Microsoft Corporation] : %SYSDIR%\drivers\termdd.sys Themes [Microsoft Corporation] : %SYSDIR%\svchost.exe TrkWks [Microsoft Corporation] : %SYSDIR%\svchost.exe TuneUp.UtilitiesSvc [TuneUp Software] : %PROGRAMFILES%\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe TuneUpUtilitiesDrv [TuneUp Software] : %PROGRAMFILES%\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys tunnel [Microsoft Corporation] : %SYSDIR%\drivers\tunnel.sys TurboB [Intel(R) Corporation] : %SYSDIR%\drivers\TurboB.sys TurboBoost [Intel(R) Corporation] : %SystemDiskRoot%\Program Files\Intel\TurboBoost\TurboBoost.exe umbus [Microsoft Corporation] : %SYSDIR%\drivers\umbus.sys upnphost [Microsoft Corporation] : %SYSDIR%\svchost.exe usbccgp [Microsoft Corporation] : %SYSDIR%\drivers\usbccgp.sys usbehci [Microsoft Corporation] : %SYSDIR%\drivers\usbehci.sys usbhub [Microsoft Corporation] : %SYSDIR%\drivers\usbhub.sys usbvideo [Microsoft Corporation] : %SYSDIR%\drivers\usbvideo.sys UxSms [Microsoft Corporation] : %SYSDIR%\svchost.exe vdrvroot [Microsoft Corporation] : %SYSDIR%\drivers\vdrvroot.sys VgaSave [Microsoft Corporation] : %SYSDIR%\drivers\vga.sys vmbus [Microsoft Corporation] : %SYSDIR%\drivers\vmbus.sys volmgr [Microsoft Corporation] : %SYSDIR%\drivers\volmgr.sys volmgrx [Microsoft Corporation] : %SYSDIR%\drivers\volmgrx.sys volsnap [Microsoft Corporation] : %SYSDIR%\drivers\volsnap.sys vpcbus [Microsoft Corporation] : %SYSDIR%\drivers\vpchbus.sys vpcnfltr [Microsoft Corporation] : %SYSDIR%\drivers\vpcnfltr.sys vpcusb [Microsoft Corporation] : %SYSDIR%\drivers\vpcusb.sys vpcvmm [Microsoft Corporation] : %SYSDIR%\drivers\vpcvmm.sys vwifibus [Microsoft Corporation] : %SYSDIR%\drivers\vwifibus.sys vwififlt [Microsoft Corporation] : %SYSDIR%\drivers\vwififlt.sys W32Time [Microsoft Corporation] : %SYSDIR%\svchost.exe Wanarpv6 [Microsoft Corporation] : %SYSDIR%\drivers\wanarp.sys Wdf01000 [Microsoft Corporation] : %SYSDIR%\drivers\Wdf01000.sys WdiServiceHost [Microsoft Corporation] : %SYSDIR%\svchost.exe WfpLwf [Microsoft Corporation] : %SYSDIR%\drivers\wfplwf.sys Winmgmt [Microsoft Corporation] : %SYSDIR%\svchost.exe Wlansvc [Microsoft Corporation] : %SYSDIR%\svchost.exe wlidsvc [Microsoft Corp.] : %SystemDiskRoot%\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE WmiAcpi [Microsoft Corporation] : %SYSDIR%\drivers\wmiacpi.sys WMPNetworkSvc [Microsoft Corporation] : %SystemDiskRoot%\Program Files\Windows Media Player\wmpnetwk.exe wscsvc [Microsoft Corporation] : %SYSDIR%\svchost.exe WSearch [Microsoft Corporation] : %SYSDIR%\SearchIndexer.exe wuauserv [Microsoft Corporation] : %SYSDIR%\svchost.exe {73526619-C24F-470B-9BED-53D455FBB5C6} [CyberLink Corp.] : %PROGRAMFILES%\CyberLink\PowerDVD12\Common\NavFilter\000.fcl ST2012_Svc [Crawler.com] : %PROGRAMFILES%\Spyware Terminator\st_rsser64.exe sp_rsdrv2 [Windows (R) Win 7 DDK provider] : %SYSDIR%\drivers\stflt.sys ------ geladene Bibliotheken ------ Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\ntdll.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\kernel32.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\KERNELBASE.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\advapi32.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\msvcrt.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\sechost.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\rpcrt4.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\sspicli.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\CRYPTBASE.dll Microsoft® Visual Studio® 2010 [Microsoft Corporation] : %SYSDIR32%\msvcp100.dll Microsoft® Visual Studio® 2010 [Microsoft Corporation] : %SYSDIR32%\msvcr100.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\shlwapi.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\gdi32.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\user32.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\lpk.dll Microsoft(R) Uniscribe Unicode script processor [Microsoft Corporation] : %SYSDIR32%\usp10.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\imm32.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\msctf.dll Apple Software Support Version Check [Apple Inc.] : %COMMONFILES32%\Apple\Apple Application Support\AppleVersions.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\version.dll [Apple Inc.]%COMMONFILES32%\Apple\Apple Application Support\YSCrashDump.DLL CoreFoundation [Apple Inc.] : %COMMONFILES32%\Apple\Apple Application Support\CoreFoundation.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\shell32.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\ws2_32.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\nsi.dll objc4 [Apple Inc.] : %COMMONFILES32%\Apple\Apple Application Support\objc.dll WinASL [Apple Inc.] : %COMMONFILES32%\Apple\Apple Application Support\ASL.dll libdispatch [Apple Inc.] : %COMMONFILES32%\Apple\Apple Application Support\libdispatch.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\winmm.dll International Components for Unicode [The ICU Project] : %COMMONFILES32%\Apple\Apple Application Support\libicuin.dll International Components for Unicode [The ICU Project] : %COMMONFILES32%\Apple\Apple Application Support\libicuuc.dll International Components for Unicode [The ICU Project] : %COMMONFILES32%\Apple\Apple Application Support\icudt49.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\ole32.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\profapi.dll Apple Mobile Device Service [Apple Inc.] : %COMMONFILES32%\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll POSIX Threads for Windows LPGL [Open Source Software community LGPL] : %COMMONFILES32%\Apple\Apple Application Support\pthreadVC2.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\setupapi.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\cfgmgr32.dll [Microsoft Corporation]%SYSDIR32%\oleaut32.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\devobj.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\userenv.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\wsock32.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\wtsapi32.dll Bonjour [Apple Inc.] : %SYSDIR32%\dnssd.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\mswsock.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\WSHTCPIP.DLL iTunesMobileDevice [Apple Inc.] : %COMMONFILES32%\Apple\Mobile Device Support\MobileDevice.dll Internet Explorer [Microsoft Corporation] : %SYSDIR32%\wininet.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\api-ms-win-downlevel-user32-l1-1-0.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\api-ms-win-downlevel-shlwapi-l1-1-0.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\api-ms-win-downlevel-version-l1-1-0.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\api-ms-win-downlevel-normaliz-l1-1-0.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\normaliz.dll Internet Explorer [Microsoft Corporation] : %SYSDIR32%\iertutil.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\api-ms-win-downlevel-advapi32-l1-1-0.dll zlib : %COMMONFILES32%\Apple\Apple Application Support\zlib1.dll CFNetwork [Apple, Inc.] : %COMMONFILES32%\Apple\Apple Application Support\CFNetwork.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\crypt32.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\msasn1.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\IPHLPAPI.DLL Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\winnsi.dll libxml2.dll : %COMMONFILES32%\Apple\Apple Application Support\libxml2.dll TODO: <Product name> [Apple Inc.] : %COMMONFILES32%\Apple\Apple Application Support\SQLite3.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\wintrust.dll The OpenSSL Toolkit [The OpenSSL Project, hxxp://www.openssl.org/] : %COMMONFILES32%\Apple\Mobile Device Support\ssleay32.dll The OpenSSL Toolkit [The OpenSSL Project, hxxp://www.openssl.org/] : %COMMONFILES32%\Apple\Mobile Device Support\libeay32.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\ntmarta.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\Wldap32.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\cryptsp.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\rsaenh.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\wship6.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\apphelp.dll Microsoft® Visual Studio .NET [Microsoft Corporation] : %PROGRAMFILES32%\CyberLink\PowerDVD12\Kernel\DMS\msvcp71.dll Microsoft® Visual Studio .NET [Microsoft Corporation] : %PROGRAMFILES32%\CyberLink\PowerDVD12\Kernel\DMS\msvcr71.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\psapi.dll CyberLink PCMMediaServer [CyberLink] : %PROGRAMFILES32%\CyberLink\PowerDVD12\Kernel\DMS\PCMMediaServer.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %WINDIR%\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\GdiPlus.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\WMVCORE.DLL Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\WMASF.DLL Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\clbcatq.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\wmp.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\dwmapi.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\wmploc.DLL Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\msmpeg2vdec.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\mfplat.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\avrt.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\evr.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\powrprof.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\slc.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\bcrypt.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\quartz.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\CPFilters.dll Microsoft® PlayReady™ PC Runtime v 1.3 [Microsoft Corporation] : %SYSDIR32%\MCEWMDRMNDBootstrap.DLL Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\winhttp.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\webio.dll Microsoft® DRM [Microsoft Corporation] : %SYSDIR32%\wmdrmsdk.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\tvratings.dll Microsoft(R) MSXML 3.0 SP11 [Microsoft Corporation] : %SYSDIR32%\msxml3.dll Internet Explorer [Microsoft Corporation] : %SYSDIR32%\urlmon.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\api-ms-win-downlevel-ole32-l1-1-0.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\api-ms-win-downlevel-shlwapi-l2-1-0.dll CyberLink RTSP Web Service [Cyberlink Corporation.] : %PROGRAMFILES32%\CyberLink\PowerDVD12\Kernel\DMS\CLRTSPSrv.dll CyberLink CLMSTransManWrapper [Cyberlink] : %PROGRAMFILES32%\CyberLink\PowerDVD12\Kernel\DMS\CLMSTransManWrapper.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\winsta.dll CLMediaServer Module [CyberLink] : %PROGRAMFILES32%\CyberLink\PowerDVD12\Kernel\DMS\CLMediaServer.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\nlaapi.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\NapiNSP.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\pnrpnsp.dll Bonjour [Apple Inc.] : %PROGRAMFILES32%\Bonjour\mdnsNSP.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\dnsapi.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\winrnr.dll Microsoft® CoReXT [Microsoft Corp.] : %COMMONFILES32%\Microsoft Shared\Windows Live\WLIDNSP.DLL Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\dhcpcsvc.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\FWPUCLNT.DLL Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\rasadhlp.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\winspool.drv Microsoft® .NET Framework [Microsoft Corporation] : %SYSDIR32%\mscoree.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll Microsoft® Visual Studio® 2005 [Microsoft Corporation] : %WINDIR%\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\assembly\NativeImages_v2.0.50727_32\mscorlib\ede2c6c842840e009f01bcc74fa4c457\mscorlib.ni.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\assembly\NativeImages_v2.0.50727_32\System\b3a78269847005365001c33870cd121f\System.ni.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\b34b348a9935338b1282fd0c9309eb1f\System.ServiceProcess.ni.dll IAStorService [Intel Corporation] : %PROGRAMFILES32%\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgr.dll IAStorUtil [Intel Corporation] : %PROGRAMFILES32%\Intel\Intel(R) Rapid Storage Technology\IAStorUtil.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\assembly\NativeImages_v2.0.50727_32\System.Configuration\5b6ddf934128d538cd5cd77bf4209b93\System.Configuration.ni.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\assembly\NativeImages_v2.0.50727_32\System.Xml\217ece46920546d718414291d463bb1c\System.Xml.ni.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\59312674865dc2a19c27f9f460b1673b\System.Runtime.Remoting.ni.dll %PROGRAMFILES32%\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll Microsoft® Visual Studio® 2008 [Microsoft Corporation] : %WINDIR%\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll Intel Storage Driver Interface Dynamic Lib [Intel Corporation] : %PROGRAMFILES32%\Intel\Intel(R) Rapid Storage Technology\ISDI.dll Microsoft® Visual Studio® 2008 [Microsoft Corporation] : %WINDIR%\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcm90.dll IAStorService [Intel Corporation] : %PROGRAMFILES32%\Intel\Intel(R) Rapid Storage Technology\de-DE\IAStorDataMgr.resources.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\assembly\GAC_MSIL\System.ServiceProcess.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.ServiceProcess.resources.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\assembly\NativeImages_v2.0.50727_32\WindowsBase\1d696b2d3de530f7ee971070263667ff\WindowsBase.ni.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\assembly\NativeImages_v2.0.50727_32\System.Web\4b1795df6372b251625f958595e08d3d\System.Web.ni.dll Microsoft® Visual Studio® 2005 [Microsoft Corporation] : %WINDIR%\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll Apple Software Support Version Check [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\AppleVersions.dll [Apple Inc.]%COMMONFILES32%\Apple\Internet Services\YSCrashDump.DLL CoreFoundation [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\CoreFoundation.dll [Open Source Software community project]%COMMONFILES32%\Apple\Internet Services\pthreadVC2.dll objc4 [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\objc.dll libdispatch [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\libdispatch.dll International Components for Unicode [The ICU Project] : %COMMONFILES32%\Apple\Internet Services\libicuin.dll International Components for Unicode [The ICU Project] : %COMMONFILES32%\Apple\Internet Services\libicuuc.dll International Components for Unicode [The ICU Project] : %COMMONFILES32%\Apple\Internet Services\icudt46.dll [Apple Inc.]%COMMONFILES32%\Apple\Internet Services\ASL.dll iCloud [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\iCloudServices_main.dll AOSKit Dynamic Link Library [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\AOSKit.dll CFNetwork [Apple, Inc.] : %COMMONFILES32%\Apple\Internet Services\CFNetwork.dll SQLite3 [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\SQLite3.dll zlib : %COMMONFILES32%\Apple\Internet Services\zlib1.dll libxml2.dll : %COMMONFILES32%\Apple\Internet Services\libxml2.dll Foundation [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\Foundation.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\netapi32.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\netutils.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\srvcli.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\wkscli.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\samcli.dll [Apple Inc.]%COMMONFILES32%\Apple\Internet Services\libtidy.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\uxtheme.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\secur32.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %WINDIR%\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\RpcRtRemote.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\sxs.dll iCloud Control Panel [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\ApplePhotoStreams_main.dll AVFoundationCF [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\AVFoundationCF.dll CoreMedia [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\MediaToolbox.dll QuartzCore [Apple, Inc.] : %COMMONFILES32%\Apple\Internet Services\QuartzCore.dll CoreGraphics [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\CoreGraphics.dll CodeVideo.dll [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\CoreVideo.dll [Apple Inc.]%COMMONFILES32%\Apple\Internet Services\CoreText.dll CoreAudio [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\CoreAudioToolbox.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\dsound.dll CoreMedia [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\VideoToolbox.dll CoreMedia [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\CoreMedia.dll [Apple Inc.]%COMMONFILES32%\Apple\Internet Services\mmcs.dll [Apple Inc.]%COMMONFILES32%\Apple\Internet Services\ChunkingLibrary.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\WindowsCodecs.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\actxprxy.dll iCloud [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\ApplePushService.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\api-ms-win-downlevel-advapi32-l2-1-0.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\netprofm.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\npmproxy.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\credssp.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\schannel.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\ncrypt.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\bcryptprimitives.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\gpapi.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\cryptnet.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\SensApi.dll wxWidgets [wxWidgets development team] : %APPDATA%\Dropbox\bin\wxmsw28uh_vc.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\comdlg32.dll Microsoft® Visual Studio® 2008 [Microsoft Corporation] : %WINDIR%\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\security.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\ntdsapi.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\logoncli.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\sfc.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\sfc_os.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\msimg32.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\wbem\wbemdisp.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\wbemcomn.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\wbem\wbemprox.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\wbem\wmiutils.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\wbem\wbemsvc.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\wbem\fastprox.dll %TEMP%\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp2ubje6.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\FirewallAPI.dll Chromium Embedded Framework (CEF) Dynamic Link Library : %APPDATA%\Dropbox\bin\libcef.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\oleacc.dll International Components for Unicode [The ICU Project] : %APPDATA%\Dropbox\bin\icudt.dll Microsoft® DirectX for Windows® [Microsoft Corporation] : %SYSDIR32%\d3dcompiler_43.dll Microsoft® DirectX for Windows® [Microsoft Corporation] : %SYSDIR32%\D3DX9_43.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\dhcpcsvc6.DLL Logger32 [Samsung India Software Operations] : %PROGRAMFILES32%\Samsung SSD Magician\Logger32.dll Microsoft® Visual Studio® 2010 [Microsoft Corporation] : %PROGRAMFILES32%\Samsung SSD Magician\msvcp100.dll Microsoft® Visual Studio® 2010 [Microsoft Corporation] : %PROGRAMFILES32%\Samsung SSD Magician\msvcr100.dll %PROGRAMFILES32%\Samsung SSD Magician\SAMSUNG_SSD.dll Microsoft® Visual Studio® 10 [Microsoft Corporation] : %PROGRAMFILES32%\Samsung SSD Magician\mfc100u.dll Samsung SSD Magician [Samsung Electronics.] : %PROGRAMFILES32%\Samsung SSD Magician\Magician_Ger_Res.dll Microsoft RichEdit Control, version 3.1 [Microsoft Corporation] : %SYSDIR32%\riched20.dll %PROGRAMFILES32%\Samsung SSD Magician\PAL.dll %PROGRAMFILES32%\Samsung SSD Magician\SATA.dll %PROGRAMFILES32%\Samsung SSD Magician\SAT.dll %PROGRAMFILES32%\Samsung SSD Magician\SMINI.dll %PROGRAMFILES32%\Samsung SSD Magician\SAS.dll Windows® Search [Microsoft Corporation] : %SYSDIR32%\propsys.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\devrtl.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\mpr.dll Microsoft(R) MSXML 6.0 SP3 [Microsoft Corporation] : %SYSDIR32%\msxml6.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\mlang.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\assembly\NativeImages_v2.0.50727_32\System.Drawing\5c24d3b0041ebf4f48a93615b9fa3de9\System.Drawing.ni.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\8bc548587e91ecf0552a40e47bbf99cc\System.Windows.Forms.ni.dll Microsoft® .NET Framework [Microsoft Corporation] : %WINDIR%\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll IAStorIcon [Intel Corporation] : %PROGRAMFILES32%\Intel\Intel(R) Rapid Storage Technology\de-DE\IAStorIcon.resources.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\shfolder.dll IntelVisualDesign [Intel Corporation] : %PROGRAMFILES32%\Intel\Intel(R) Rapid Storage Technology\IntelVisualDesign.dll IntelVisualDesign [Intel Corporation] : %PROGRAMFILES32%\Intel\Intel(R) Rapid Storage Technology\de-DE\IntelVisualDesign.resources.dll IAStorUtil [Intel Corporation] : %PROGRAMFILES32%\Intel\Intel(R) Rapid Storage Technology\IAStorUIHelper.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %WINDIR%\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll iTunes [Apple Inc.] : %PROGRAMFILES32%\iTunes\iTunesHelper.dll iTunes [Apple Inc.] : %PROGRAMFILES32%\iTunes\iTunesHelper.Resources\de.lproj\iTunesHelperLocalized.DLL iTunes [Apple Inc.] : %PROGRAMFILES32%\iTunes\iTunesHelper.Resources\iTunesHelper.DLL iTunesMobileDevice [Apple Inc.] : %COMMONFILES32%\Apple\Mobile Device Support\iTunesMobileDevice.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %WINDIR%\AppPatch\AcLayers.dll Windows Installer - Unicode [Microsoft Corporation] : %SYSDIR32%\msiltcfg.dll Windows Installer - Unicode [Microsoft Corporation] : %SYSDIR32%\msi.dll RIM handheld driver [BlackBerry Limited] : %COMMONFILES32%\Research In Motion\USB Drivers\BbDevMgrPs.dll iCloud [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\APSDaemon_main.dll BlackBerry PlayBook Driver Interface [Research In Motion Limited] : %COMMONFILES32%\Research In Motion\BBBI Drivers\tablet.dll Microsoft XML Core Services [Microsoft Corporation] : %SYSDIR32%\xmllite.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\PortableDeviceApi.dll iCloud Control Panel [Apple Inc.] : %COMMONFILES32%\Apple\Internet Services\ApplePhotoStreamsDownloader_main.dll LOG Dynamic Link Library : %PROGRAMFILES32%\Samsung\Easy Printer Manager\CDAS2PC\sslog.dll Scan Assistant v.1.03 [Samsung Electronics Co., Ltd.] : %PROGRAMFILES32%\Samsung\Easy Printer Manager\CDAS2PC\SASkin.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\imagehlp.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\MMDevAPI.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\wdmaud.drv Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\ksuser.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\AudioSes.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\msacm32.drv Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\msacm32.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\midimap.dll %PROGRAMFILES32%\Samsung\Easy Printer Manager\CDAS2PC\SAStyle.cjstyles Common Desktop Agent : %COMMONFILES32%\Common Desktop Agent\CDASrvPS.dll Easy Printer Manager [Samsung Electronics Co., Ltd.] : %PROGRAMFILES32%\Samsung\Easy Printer Manager\IDS.PCScanConfig.dll %PROGRAMFILES32%\Samsung\Easy Printer Manager\sf.dll Microsoft® Visual Studio® 2008 [Microsoft Corporation] : %WINDIR%\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll Microsoft® Visual Studio® 2008 [Microsoft Corporation] : %WINDIR%\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.6161_none_51cd0a7abbe4e19b\ATL90.dll Microsoft® Visual Studio® 2008 [Microsoft Corporation] : %WINDIR%\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_49768ef57548175e\MFC90DEU.DLL Easy Printer Manager [Samsung Electronics Co., Ltd.] : %PROGRAMFILES32%\Samsung\Easy Printer Manager\IDS.Config.dll %PROGRAMFILES32%\Google\Chrome\Application\34.0.1847.131\chrome_elf.dll Google Chrome [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\34.0.1847.131\chrome.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\credui.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\hid.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\dbghelp.dll AMD Inc. Radeon DirectX 11 Driver [Advanced Micro Devices, Inc. ] : %SYSDIR32%\aticfx32.dll Windows® Search [Microsoft Corporation] : %SYSDIR32%\mssprxy.dll Windows [Microsoft Corporation] : %SYSDIR32%\Wpc.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\wevtapi.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\samlib.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\mscms.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\ntshrui.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\cscapi.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\linkinfo.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\explorerframe.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\duser.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\dui70.dll Microsoft Office 2013 [Microsoft Corporation] : %PROGRAMFILES32%\Microsoft Office\Office15\GROOVEEX.DLL Microsoft® Visual Studio® 10 [Microsoft Corporation] : %SYSDIR32%\atl100.dll Microsoft Office 2013 [Microsoft Corporation] : %PROGRAMFILES32%\Microsoft Office\Office15\1031\GrooveIntlResource.dll Dropbox [Dropbox, Inc.] : %APPDATA%\Dropbox\bin\DropboxExt.22.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\EhStorShell.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\shdocvw.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %PROGRAMFILES32%\Windows Defender\MpOAV.dll Microsoft Malware Protection [Microsoft Corporation] : %PROGRAMFILES32%\Microsoft Security Client\MpOAv.dll Microsoft Malware Protection [Microsoft Corporation] : %PROGRAMFILES32%\Microsoft Security Client\MpClient.dll Google Chrome [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\34.0.1847.131\chrome_child.dll Microsoft® DirectX for Windows® [Microsoft Corporation] : %PROGRAMFILES32%\Google\Chrome\Application\34.0.1847.131\D3DCompiler_46.dll ANGLE libGLESv2 Dynamic Link Library : %PROGRAMFILES32%\Google\Chrome\Application\34.0.1847.131\libglesv2.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\d3d9.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\d3d8thk.dll ANGLE libEGL Dynamic Link Library : %PROGRAMFILES32%\Google\Chrome\Application\34.0.1847.131\libegl.dll Advanced Micro Devices, Inc PowerXpress Vista User Mode Driver [Advanced Micro Devices, Inc. ] : %SYSDIR32%\atiu9pag.dll Advanced Micro Devices, Inc. Radeon DirectX Universal Driver [Advanced Micro Devices, Inc. ] : %SYSDIR32%\atiumdag.dll Advanced Micro Devices, Inc. Radeon Video Acceleration Universal Driver [Advanced Micro Devices, Inc. ] : %SYSDIR32%\atiumdva.dll Chrome PDF Viewer : %PROGRAMFILES32%\Google\Chrome\Application\34.0.1847.131\pdf.dll %PROGRAMFILES32%\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll Google Chrome [Google Inc.] : %PROGRAMFILES32%\Google\Chrome\Application\34.0.1847.131\libpeerconnection.dll %PROGRAMFILES32%\Google\Chrome\Application\34.0.1847.131\ffmpegsumo.dll [Microsoft Corporation]%SYSDIR32%\olepro32.dll Spyware Terminator 2011 [Crawler.com] : %PROGRAMFILES32%\Spyware Terminator\TorrentDll.dll Internet Explorer [Microsoft Corporation] : %SYSDIR32%\ieframe.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\api-ms-win-downlevel-shell32-l1-1-0.dll Internet Explorer [Microsoft Corporation] : %SYSDIR32%\mshtml.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\d2d1.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\DWrite.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\dxgi.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\d3d11.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\D3D10Warp.dll Betriebssystem Microsoft® Windows® [Microsoft Corporation] : %SYSDIR32%\msimtf.dll Microsoft® Line Services [Microsoft Corporation] : %SYSDIR32%\msls31.dll Microsoft® Windows® Operating System [Microsoft Corporation] : %SYSDIR32%\cabinet.dll ------ Report Ende ------ Code:
ATTFilter <?xml version="1.0" encoding="UTF-16" ?> <mbam-log> <header> <date>2014/04/27 18:33:20 +0200</date> <log>mbam-log-2014-04-27 (18-14-31).xml</log> <isadmin>yes</isadmin> </header> <engine> <version>2.00.1.1004</version> <rules-database>v2014.04.27.04</rules-database> <swissarmy-database>v2014.03.27.01</swissarmy-database> <license>trial</license> <file-protection>enabled</file-protection> <web-protection>enabled</web-protection> <self-protection>disabled</self-protection> </engine> <system> <osversion>Windows 7 Service Pack 1</osversion> <arch>x64</arch> <username>Silas</username> <filesys>NTFS</filesys> </system> <summary> <type>threat</type> <result>completed</result> <objects>267819</objects> <time>1127</time> <processes>0</processes> <modules>0</modules> <keys>9</keys> <values>0</values> <datas>1</datas> <folders>3</folders> <files>11</files> <sectors>0</sectors> </summary> <options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>disabled</rootkits> <deeprootkit>disabled</deeprootkit> <shuriken>enabled</shuriken> <pup>enabled</pup> <pum>enabled</pum> </options> <items> <key><path>HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}</path><vendor>PUP.Optional.Delta.A</vendor><action>success</action><hash>034ddd52a1da0f279efbb19f778b34cc</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}</path><vendor>PUP.Optional.Delta.A</vendor><action>success</action><hash>034ddd52a1da0f279efbb19f778b34cc</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}</path><vendor>PUP.Optional.Delta.A</vendor><action>success</action><hash>8ec2b07f1f5c0630206d0d43748efd03</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\eooncjejnppfjjklapaamhcdmjbilmde</path><vendor>PUP.Optional.Delta.A</vendor><action>success</action><hash>311fbb741566a39364ec217b01023bc5</hash></key> <key><path>HKU\S-1-5-21-2937941739-3390224605-2116822940-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload</path><vendor>PUP.Optional.1ClickDownload.A</vendor><action>success</action><hash>a5ab38f7b8c39f97a005b6e7da2927d9</hash></key> <key><path>HKU\S-1-5-21-2937941739-3390224605-2116822940-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr</path><vendor>PUP.Optional.DataMngr.A</vendor><action>success</action><hash>1b35d9562259ce68da4b7e1e32d18c74</hash></key> <key><path>HKU\S-1-5-21-2937941739-3390224605-2116822940-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar</path><vendor>PUP.Optional.DataMngr.A</vendor><action>success</action><hash>e16f43ec54273cfadd47a2fae320738d</hash></key> <key><path>HKU\S-1-5-21-2937941739-3390224605-2116822940-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater</path><vendor>PUP.Optional.Babylon.A</vendor><action>success</action><hash>2d236cc3f5860c2ac36b405d8b78867a</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\1ClickDownload</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>66ea8fa0601b81b5b65170f5af530df3</hash></key> <data><path>HKU\S-1-5-21-2937941739-3390224605-2116822940-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN</path><valuename>Start Page</valuename><vendor>PUP.Optional.StartPage</vendor><action>replaced</action><valuedata>hxxp://www1.delta-search.com/?affID=119779&tt=gc_&babsrc=HP_ss&mntrId=94D778E4000FEF33</valuedata><baddata>hxxp://www1.delta-search.com/?affID=119779&tt=gc_&babsrc=HP_ss&mntrId=94D778E4000FEF33</baddata><gooddata>hxxp://www.google.com</gooddata><hash>133d66c999e2a59166be8aa72dd753ad</hash></data> <folder><path>C:\Users\Silas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>95bb82ad6d0ec76f54df2677c83b758b</hash></folder> <folder><path>C:\Users\Silas\AppData\Local\Temp\mt_ffx\Delta</path><vendor>PUP.Optional.Delta.A</vendor><action>success</action><hash>88c89d9274077db996187de6c83aa060</hash></folder> <folder><path>C:\Program Files (x86)\hdvidcodec.com</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>66ea8fa0601b81b5b65170f5af530df3</hash></folder> <file><path>C:\Users\Silas\AppData\Roaming\BabSolution\CR\Delta.crx</path><vendor>PUP.Optional.Delta.A</vendor><action>success</action><hash>5cf4c26d7704e056976d670b8f738f71</hash></file> <file><path>C:\Users\Silas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com\HDVidCodec.lnk</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>95bb82ad6d0ec76f54df2677c83b758b</hash></file> <file><path>C:\Users\Silas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com\Uninstall.lnk</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>95bb82ad6d0ec76f54df2677c83b758b</hash></file> <file><path>C:\Program Files (x86)\hdvidcodec.com\b.bmp</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>66ea8fa0601b81b5b65170f5af530df3</hash></file> <file><path>C:\Program Files (x86)\hdvidcodec.com\finish.bmp</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>66ea8fa0601b81b5b65170f5af530df3</hash></file> <file><path>C:\Program Files (x86)\hdvidcodec.com\FinishHDVID.exe</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>66ea8fa0601b81b5b65170f5af530df3</hash></file> <file><path>C:\Program Files (x86)\hdvidcodec.com\HDVidCodec.exe</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>66ea8fa0601b81b5b65170f5af530df3</hash></file> <file><path>C:\Program Files (x86)\hdvidcodec.com\HDvidCodec10.crx</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>66ea8fa0601b81b5b65170f5af530df3</hash></file> <file><path>C:\Program Files (x86)\hdvidcodec.com\hdvidextsetup.exe</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>66ea8fa0601b81b5b65170f5af530df3</hash></file> <file><path>C:\Program Files (x86)\hdvidcodec.com\hdvid_temp.bmp</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>66ea8fa0601b81b5b65170f5af530df3</hash></file> <file><path>C:\Program Files (x86)\hdvidcodec.com\uninst.exe</path><vendor>PUP.Optional.HDVidCodec.A</vendor><action>success</action><hash>66ea8fa0601b81b5b65170f5af530df3</hash></file> </items> </mbam-log> |
01.05.2014, 06:25 | #5 | |
/// the machine /// TB-Ausbilder | Win 7 Laptop ruckelt plötzlich Rechner ist unauffällig, bis auf: Zitat:
2) TuneUp ist scheisse!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! 3) Zuning zerstört in 100% der Fälle den PC 4) Tuning NIEMALS mit einer SSD!!!!
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.05.2014, 08:37 | #6 |
| Win 7 Laptop ruckelt plötzlich Habe ich mir mittlerweile auch gedacht und entfernt... Sonst keine Ideen? |
02.05.2014, 07:21 | #7 |
/// the machine /// TB-Ausbilder | Win 7 Laptop ruckelt plötzlich PLatt machen, neu aufsetzen, Finger weg von Cracks und geklauten Programmen, und aufhören zu tunen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Win 7 Laptop ruckelt plötzlich |
anleitung, arbeitsspeicher, download, essen, langsam, laptop, leute, link, maus, microsoft, neu, nichts, plötzlich, probleme, programme, ruckel, ruckelt, schwer, security, sekunden, sonntag, svchost.exe, tastatur, win, win7 64 bit, windows, windows 7 |