|
Plagegeister aller Art und deren Bekämpfung: Windows 7: div. Probleme seit Softonic Download, Virus?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
10.05.2014, 17:41 | #1 |
| Windows 7: div. Probleme seit Softonic Download, Virus? Liebes Trojaner-Board-Team! Nach einem Download des Unity Web Players mit dem Softonic-Downloader (gestern) habe ich diverse Probleme auf meinem Computer. 1. Direkt nach dem Download hatte ich "default-search.net" als Startseite von Firefox statt Google. Ich habe in der Systemsteuerung nachgesehen und das Programm "Linkey" deinstalliert. Daraufhin funktionierte Firefox wieder normal. Nach kurzem Surfen habe ich den Computer gestern nicht mehr weiterverwendet. 2. Seit heute: Der Computer ist zwar mit dem Netzwerk verbunden, aber die Verbindung zum Internet funktioniert nicht mehr. Ich habe versucht, im abgesicherten Modus zu starten, aber auch das funktioniert nicht. 3. Ich habe noch zwei weitere Programme gefunden, die gestern wohl im Zuge des Softonic-Downloads installiert wurden: - Foxy Security (ließ sich deinstallieren) - Settings Manager (lässt sich nicht deinstallieren und auch nicht aus dem Verzeichnis (C:Windows7/Programme (x86)/Settings Manager) löschen. Ich habe einen vollständigen Scan mit Microsoft Essentials gemacht, jedoch ohne Ergebnis. Bin nun etwas ratlos... Wie kann ich weiter vorgehen? Vielen Dank und viele Grüße Annett |
10.05.2014, 17:55 | #2 |
/// the machine /// TB-Ausbilder | Windows 7: div. Probleme seit Softonic Download, Virus? hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
10.05.2014, 21:25 | #3 |
| Windows 7: div. Probleme seit Softonic Download, Virus? Hallo Schrauber,
__________________nachdem ich ja mit dem besagten Computer nicht ins Internet komme - soll ich das Scan Tool auf einen Stick speichern und von dort laden? Die Logfiles dan wieder auf dem Stick speichern und vom Zweitgerät posten? Ist die Stickvariante sicher? Danke für deine Hilfe! Hi, ich hab es jetzt doch einfach mit dem Stick gemacht, hoffe es passt so: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-05-2014 Ran by Administrator (administrator) on NATA-THINK on 10-05-2014 22:16:05 Running from C:\Users\Administrator\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AuthenTec, Inc) C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe (Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Aztec Media Inc) C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Aztec Media Inc) C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\TouchControl.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Lenovo.) C:\Windows\System32\TpShocks.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (Lenovo, Inc.) C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\x86\BioMonitor.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Aztec Media Inc) C:\Program Files (x86)\Settings Manager\systemk\systemku.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe (Lenovo) C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [177936 2012-02-17] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11406608 2012-02-21] (Intel Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12476520 2012-04-10] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-03-09] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2881336 2012-06-19] (Synaptics Incorporated) HKLM\...\Run: [TpShocks] => C:\Windows\system32\TpShocks.exe [382528 2012-02-24] (Lenovo.) HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [290160 2012-06-01] (Lenovo Group Limited) HKLM\...\Run: [] => [X] HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-02-29] (Intel Corporation) HKLM-x32\...\Run: [RotateImage] => C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [PWMTRV] => rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [507744 2011-12-20] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [1091376 2012-01-17] (Lenovo) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-13] (Lenovo, Inc.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3449097423-3504793074-380607187-500\...\MountPoints2: {f80d5996-ec1e-11e1-b279-806e6f6e6963} - Q:\LenovoQDrive.exe IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe () Startup: C:\Users\nata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Administrator\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) HKLM\...\AppCertDlls: [x86] -> C:\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll [490000 2014-04-28] () HKLM\...\AppCertDlls: [x64] -> C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll [664592 2014-04-28] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12521&tm=342&src=ds&p={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12521&tm=342&src=ds&p={searchTerms} SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENP SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENP BHO: No Name - {4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} - No File BHO: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\IEBHO.DLL (AuthenTec Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation) BHO-x32: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\x86\IEBHO.dll (AuthenTec Inc.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 255.0.0.0 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF - C:\Program Files (x86)\Nitro PDF\Professional 7\npnitromozilla.dll ( ) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012-12-19] FF HKLM-x32\...\Firefox\Extensions: [VIP1X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] FF HKLM-x32\...\Firefox\Extensions: [VIP2X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] ==================== Services (Whitelisted) ================= R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-03-30] (Diskeeper Corporation) R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [169776 2012-01-17] (Lenovo) R2 FPLService; C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe [328552 2012-06-07] (AuthenTec, Inc) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-29] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-29] (Intel Corporation) R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [179568 2012-06-01] (Lenovo Group Limited) R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 NitroDriverReadSpool2; C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe [216072 2012-05-23] (Nitro PDF Software) S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22888 2013-09-17] () R2 SystemkService; C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe [3543056 2014-04-28] (Aztec Media Inc) R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [84080 2012-04-19] (Symantec Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) S2 DM1Service; C:\Program Files (x86)\Olympus\DeviceDetector\DM1Service.exe [X] ==================== Drivers (Whitelisted) ==================== R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] () R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-03-30] (Diskeeper Corporation) R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [95024 2012-03-30] (Diskeeper Corporation) R1 F06DEFF2-5B9C-490D-910F-35D3A91196222; C:\Program Files (x86)\Settings Manager\systemk\x64\systemkmgrc1.cfg [36240 2014-04-28] (Aztec Media Inc) S3 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [70416 2012-01-17] (Windows (R) Win 7 DDK provider) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.) R3 SmbDrvIntel; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [27448 2012-06-19] (Synaptics Incorporated) R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.) R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-07] (ThinkVantage Communications Utility) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-10 22:08 - 2014-05-10 22:16 - 00020514 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-05-10 22:06 - 2014-05-10 21:39 - 02065408 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe 2014-05-10 22:04 - 2014-05-10 22:16 - 00000000 ____D () C:\FRST 2014-05-10 21:49 - 2014-05-10 21:51 - 00000000 ____D () C:\Users\Administrator\AppData\Local\LSC 2014-05-10 21:49 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LSC 2014-05-10 21:41 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Nitro PDF 2014-05-10 21:39 - 2014-05-10 21:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Password Vault 2014-05-10 17:46 - 2014-05-10 17:46 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PwrMgr 2014-05-10 17:45 - 2014-05-10 17:45 - 00109296 _____ () C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT 2014-05-10 17:45 - 2014-05-10 17:45 - 00109296 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Lenovo 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Leadertech 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Lenovo 2014-05-10 17:44 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-05-10 17:44 - 2014-05-10 17:45 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-10 17:44 - 2014-05-10 17:45 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-10 17:44 - 2014-05-10 17:44 - 00001432 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-10 17:44 - 2014-05-10 17:44 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Intel 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _____ () C:\Users\Administrator\agent.log 2014-05-10 17:44 - 2012-12-21 23:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Microsoft Help 2014-05-10 17:44 - 2012-08-22 08:20 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia 2014-05-10 17:44 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-05-10 17:44 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-05-10 17:41 - 2014-05-10 17:41 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-10 14:51 - 2014-05-10 14:51 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Adobe 2014-05-10 14:50 - 2014-05-10 14:50 - 00003124 _____ () C:\Windows\System32\Tasks\{6C7A5AC4-342A-4676-89AE-4BA82B109572} 2014-05-09 14:31 - 2014-05-10 22:16 - 00000000 ____D () C:\ProgramData\systemk 2014-05-09 14:30 - 2014-05-09 14:30 - 00000000 ____D () C:\Program Files (x86)\Settings Manager 2014-05-09 14:29 - 2014-05-10 14:51 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Security Systems 2014-05-06 17:06 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-06 17:06 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-06 00:49 - 2014-04-29 18:00 - 23133184 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 00:49 - 2014-04-29 17:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-06 00:49 - 2014-04-29 16:47 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-06 00:49 - 2014-04-29 16:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-05 23:17 - 2014-05-05 23:18 - 00000000 ____D () C:\Users\nata\AppData\Local\{4CC0FB4D-67D0-4A88-BF45-A1C9FFEC2DEB} 2014-05-05 23:16 - 2014-05-05 23:16 - 00000000 ____D () C:\Users\nata\AppData\Local\{795EA3FA-DB86-464D-BD6F-E276B51A127B} 2014-05-01 20:36 - 2014-05-02 08:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-10 11:23 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 11:23 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 11:23 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 11:23 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 11:23 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 11:23 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 11:23 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 11:23 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 11:23 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 11:23 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 11:23 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 11:23 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 11:23 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 11:23 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 11:23 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 11:23 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 11:23 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys ==================== One Month Modified Files and Folders ======= 2014-05-10 22:16 - 2014-05-10 22:08 - 00020514 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-05-10 22:16 - 2014-05-10 22:04 - 00000000 ____D () C:\FRST 2014-05-10 22:16 - 2014-05-09 14:31 - 00000000 ____D () C:\ProgramData\systemk 2014-05-10 22:15 - 2012-08-22 08:23 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-10 22:04 - 2012-08-22 17:55 - 00714294 _____ () C:\Windows\system32\perfh007.dat 2014-05-10 22:04 - 2012-08-22 17:55 - 00154346 _____ () C:\Windows\system32\perfc007.dat 2014-05-10 22:04 - 2009-07-14 07:13 - 01648944 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-10 21:56 - 2013-05-27 21:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-10 21:51 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\Administrator\AppData\Local\LSC 2014-05-10 21:49 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LSC 2014-05-10 21:49 - 2014-05-10 21:41 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Nitro PDF 2014-05-10 21:49 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-05-10 21:49 - 2012-08-22 08:09 - 01716103 _____ () C:\Windows\WindowsUpdate.log 2014-05-10 21:39 - 2014-05-10 22:06 - 02065408 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe 2014-05-10 21:39 - 2014-05-10 21:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Password Vault 2014-05-10 21:39 - 2012-08-22 08:23 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-10 21:39 - 2012-08-22 08:12 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-05-10 18:25 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-10 18:25 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-10 18:17 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-10 18:17 - 2009-07-14 06:51 - 00090825 _____ () C:\Windows\setupact.log 2014-05-10 18:04 - 2014-01-18 20:56 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Skype 2014-05-10 18:04 - 2013-01-09 12:07 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Dropbox 2014-05-10 17:46 - 2014-05-10 17:46 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PwrMgr 2014-05-10 17:45 - 2014-05-10 17:45 - 00109296 _____ () C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT 2014-05-10 17:45 - 2014-05-10 17:45 - 00109296 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Lenovo 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Leadertech 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Lenovo 2014-05-10 17:45 - 2014-05-10 17:44 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-10 17:45 - 2014-05-10 17:44 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-10 17:45 - 2009-07-14 06:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-05-10 17:44 - 2014-05-10 17:44 - 00001432 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-10 17:44 - 2014-05-10 17:44 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Intel 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _____ () C:\Users\Administrator\agent.log 2014-05-10 17:41 - 2014-05-10 17:41 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-10 15:46 - 2012-12-19 18:20 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Nitro PDF 2014-05-10 14:51 - 2014-05-10 14:51 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Adobe 2014-05-10 14:51 - 2014-05-09 14:29 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Security Systems 2014-05-10 14:50 - 2014-05-10 14:50 - 00003124 _____ () C:\Windows\System32\Tasks\{6C7A5AC4-342A-4676-89AE-4BA82B109572} 2014-05-10 14:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-05-10 14:39 - 2013-01-28 14:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco Systems VPN Client 2014-05-10 14:39 - 2012-12-19 18:10 - 00000000 ____D () C:\Users\nata 2014-05-10 14:39 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-10 13:01 - 2012-08-22 08:12 - 00000830 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-05-09 14:34 - 2013-01-09 12:10 - 00000000 ___RD () C:\Users\nata\Dropbox 2014-05-09 14:33 - 2013-11-24 13:16 - 00000000 ____D () C:\Users\nata\AppData\Local\Unity 2014-05-09 14:30 - 2014-05-09 14:30 - 00000000 ____D () C:\Program Files (x86)\Settings Manager 2014-05-05 23:18 - 2014-05-05 23:17 - 00000000 ____D () C:\Users\nata\AppData\Local\{4CC0FB4D-67D0-4A88-BF45-A1C9FFEC2DEB} 2014-05-05 23:17 - 2014-02-25 22:52 - 00000000 ____D () C:\Users\nata\AppData\Local\Windows Live 2014-05-05 23:16 - 2014-05-05 23:16 - 00000000 ____D () C:\Users\nata\AppData\Local\{795EA3FA-DB86-464D-BD6F-E276B51A127B} 2014-05-03 18:06 - 2012-12-19 22:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-02 08:37 - 2014-05-01 20:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-05-01 22:14 - 2013-04-18 13:44 - 00000000 ____D () C:\Users\nata\Desktop\orga ablage 2014-04-29 18:00 - 2014-05-06 00:49 - 23133184 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-29 17:24 - 2014-05-06 00:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-29 16:47 - 2014-05-06 00:49 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-29 16:14 - 2014-05-06 00:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-28 21:56 - 2013-05-27 21:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-28 21:56 - 2012-12-19 23:30 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-28 21:56 - 2012-12-19 23:30 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-15 14:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-14 13:35 - 2013-01-04 18:25 - 00000000 ____D () C:\Users\nata\AppData\Local\Adobe 2014-04-14 04:24 - 2014-05-06 17:06 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-14 04:19 - 2014-05-06 17:06 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-10 18:50 - 2012-12-19 23:37 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-10 17:32 - 2013-07-15 22:37 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 17:31 - 2012-12-26 15:03 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\nata\AppData\Local\Temp\DelayInst.exe C:\Users\nata\AppData\Local\Temp\FoxySecuritySetup.exe C:\Users\nata\AppData\Local\Temp\installservice.exe C:\Users\nata\AppData\Local\Temp\ose00000.exe C:\Users\nata\AppData\Local\Temp\SettingsManagerSetup.exe C:\Users\nata\AppData\Local\Temp\vpnclient_setup.exe C:\Users\nata\AppData\Local\Temp\wyqv4shi.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-02 08:12 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-05-2014 Ran by Administrator at 2014-05-10 22:16:18 Running from C:\Users\Administrator\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== Anzeige am Bildschirm (HKLM\...\OnScreenDisplay) (Version: 6.72.00 - ) Cisco Systems VPN Client 5.0.07.0440 (HKLM\...\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}) (Version: 5.0.7 - Cisco Systems, Inc.) ExpressCache (HKLM\...\{2EBEFDA8-F905-4C39-AC1C-D5ABE7B3E0AE}) (Version: 1.0.86 - Diskeeper Corporation) Fingerprint Reader (HKLM\...\{C5BB9380-D729-410A-A440-061EBCADCCB9}) (Version: 5.4.100.232 - AuthenTec, Inc.) Intel PROSet Wireless (Version: - ) Hidden Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\...\{37EC048A-81A2-452A-8D1F-3BE2018E767D}) (Version: 15.1.0.0096 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{520C4DD4-2BC7-409B-BA48-E1A4F832662D}) (Version: 2.1.0.0140 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel® PROSet/Wireless WiFi-Software (HKLM\...\{E97F409F-9E1C-42A0-B72D-765A78DF3696}) (Version: 15.01.0000.0830 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation) Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 1.11 - ) Lenovo Patch Utility 64 bit (HKLM\...\{0369F866-2CE0-4EB9-B426-88FA122C6E82}) (Version: 1.3.0.9 - Lenovo Group Limited) Lenovo SimpleTap (HKLM\...\{BF601122-9F0A-41A9-BA06-3158D9FB4B80}) (Version: 3.2.0004.00 - Lenovo Group Limited) Lenovo Solution Center (HKLM\...\{DD00F699-6861-4DCF-A19F-8CF61E5E28ED}) (Version: 1.1.007.00 - Lenovo Group Limited) Message Center Plus (HKLM\...\{3849486C-FF09-4F5D-B491-3E179D58EE15}) (Version: 3.1.0004.00 - Lenovo Group Limited) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Nitro Pro 7 (HKLM\...\{36710189-55DF-4D75-8B6A-523CC61B7047}) (Version: 7.4.1.4 - Nitro PDF Software) NVIDIA Grafiktreiber 295.68 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 295.68 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.62.312 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.7.12 (Version: 1.7.12 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 295.68 (Version: 295.68 - NVIDIA Corporation) Hidden NVIDIA Update 1.7.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.7.12 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.7.12 - NVIDIA Corporation) Hidden RapidBoot Shield (HKLM\...\{5E2652DF-743F-482B-A593-C95F431A5769}) (Version: 1.23 - Lenovo) ThinkPad Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.65.05.20 - ) ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.1.4.17 - ) ThinkVantage Communications Utility (HKLM\...\{88C6A6D9-324C-46E8-BA87-563D14021442}_is1) (Version: 3.0.34.0 - Lenovo) ThinkVantage System für aktiven Festplattenschutz (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.76 - Lenovo) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows-Treiberpaket - Intel (iaStor) hdc (02/01/2012 11.1.0.1006) (HKLM\...\1B12F81FD20B1E96876BF8D3E9B41F2BEEB943A0) (Version: 02/01/2012 11.1.0.1006 - Intel) Windows-Treiberpaket - Lenovo 1.65.05.20 (02/29/2012 1.65.05.20) (HKLM\...\E3535F123E7F666D573665142F90D3E5004DC326) (Version: 02/29/2012 1.65.05.20 - Lenovo) Windows-Treiberpaket - Synaptics (SmbDrvAMDASF) System (06/21/2012 16.1.4.17) (HKLM\...\A333D414B3783936ED9A3F663498AB82EB07B7A3) (Version: 06/21/2012 16.1.4.17 - Synaptics) Windows-Treiberpaket - Synaptics (SynTP) Mouse (06/21/2012 16.1.4.17) (HKLM\...\FE61CFFCEFBF4E2D83AE176443D33414275365FC) (Version: 06/21/2012 16.1.4.17 - Synaptics) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0386D704-CDA9-426D-A52D-21DE5B986CC0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-08-22] (Google Inc.) Task: {27BC2338-9401-4F97-885F-537CA69ACC28} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2013-09-17] () Task: {43798620-E410-41D0-AA53-A8E15E171E7F} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2012-05-16] () Task: {458C8FB8-EB4A-4103-928B-B031111F6B24} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-08-22] (Google Inc.) Task: {788E4F21-838E-45C6-AFC9-3389CB2F8010} - System32\Tasks\PMTask => C:\Program Files (x86)\ThinkPad\Utilities\PWMIDTSV.EXE [2012-05-15] (Lenovo Group Limited) Task: {88EA4294-43D3-4667-BAA4-0E6A9D59AFF0} - System32\Tasks\Lenovo\Message Center Plus Launcher => C:\Program Files (x86)\Lenovo\message center plus\mcplaunch.exe [2012-05-15] (Lenovo) Task: {8FDF6274-B3DA-4422-9F13-1BDDD01AFBFD} - System32\Tasks\Lenovo\SimpleTap\Start SimpleTap for nata-THINK.nata => C:\Program Files\Lenovo\SimpleTap\SimpleTap.exe [2012-05-15] (Lenovo) Task: {912B2281-2FAD-48FC-B95C-C36A2EC816F1} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {C5AAFFEC-BA00-4083-9BA6-EF455B9B835C} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2012-05-16] (Lenovo) Task: {EA0A28A6-21BD-4610-B96B-C87E77661B84} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\lsc.exe [2012-05-16] () Task: {FA19B631-0445-4795-A205-C3BCCA15F61F} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {FA61416D-78C5-41B3-B2E6-3D68AE46F9C3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-28] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Loaded Modules (whitelisted) ============= 2014-05-09 14:30 - 2014-04-28 11:38 - 00664592 _____ () C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll 2009-11-19 06:01 - 2009-11-19 06:01 - 00022016 _____ () C:\Windows\System32\sugw2l6.dll 2012-08-22 08:11 - 2012-02-29 03:20 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2012-08-22 08:19 - 2012-05-15 23:32 - 00103936 ____N () C:\Program Files (x86)\ThinkPad\Utilities\GR\PWMRT64V.DLL 2012-05-23 23:14 - 2012-05-23 23:14 - 00108040 _____ () C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NPShellExtension64.dll 2012-06-07 00:03 - 2012-06-07 00:03 - 01163624 _____ () C:\Program Files\Lenovo Fingerprint Reader\DataManager.dll 2012-06-07 00:04 - 2012-06-07 00:04 - 00087912 _____ () C:\Program Files\Lenovo Fingerprint Reader\ssutil.dll 2012-08-22 08:09 - 2012-03-19 23:09 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2011-03-04 13:49 - 2011-03-04 13:49 - 00202752 _____ () C:\Program Files (x86)\Cisco Systems\VPN Client\vpnapi.dll 2012-08-22 08:22 - 2012-01-17 08:29 - 00030512 ____N () C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBServiceps.dll 2012-08-22 08:20 - 2011-08-02 04:58 - 02201088 _____ () C:\Program Files\Lenovo\Communications Utility\cxcore210.dll 2012-08-22 08:20 - 2011-08-02 04:58 - 02085888 _____ () C:\Program Files\Lenovo\Communications Utility\cv210.dll 2014-05-09 14:30 - 2014-04-28 11:38 - 00020496 _____ () C:\Program Files (x86)\Settings Manager\systemk\syskldr.dll 2014-05-09 14:30 - 2014-04-28 11:38 - 00490000 _____ () C:\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll 2012-08-22 08:11 - 2012-02-21 22:09 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Microsoft Virtual WiFi Miniport Adapter #2 Description: Microsoft-Adapter für Miniports virtueller WiFis Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: vwifimp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Cisco Systems VPN Adapter for 64-bit Windows Description: Cisco Systems VPN Adapter for 64-bit Windows Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: CVirtA Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: INTENSO USB Description: USB Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a} Manufacturer: INTENSO Service: WUDFRd Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver ==================== Event log errors: ========================= Application errors: ================== Error: (05/10/2014 06:18:14 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:16:41 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:13:52 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:12:36 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:10:53 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:09:51 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:03:54 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:02:53 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:00:39 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 05:59:21 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (05/10/2014 10:03:02 PM) (Source: Disk) (User: ) (EventID: 11) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (05/10/2014 10:03:01 PM) (Source: Disk) (User: ) (EventID: 11) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (05/10/2014 10:03:01 PM) (Source: Disk) (User: ) (EventID: 11) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (05/10/2014 10:03:00 PM) (Source: Disk) (User: ) (EventID: 11) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (05/10/2014 09:49:13 PM) (Source: Microsoft Antimalware) (User: ) (EventID: 2001) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.173.1707.0 Aktualisierungsquelle: %NT-AUTORITÄT59 Aktualisierungsphase: 4.5.0216.00 Quellpfad: 4.5.0216.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\SYSTEM Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Error: (05/10/2014 06:27:40 PM) (Source: Microsoft Antimalware) (User: ) (EventID: 2001) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.173.1707.0 Aktualisierungsquelle: %NT-AUTORITÄT59 Aktualisierungsphase: 4.5.0216.00 Quellpfad: 4.5.0216.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\SYSTEM Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Error: (05/10/2014 06:17:38 PM) (Source: Service Control Manager) (User: ) (EventID: 7000) Description: Der Dienst "DM1Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (05/10/2014 06:16:45 PM) (Source: Service Control Manager) (User: ) (EventID: 7023) Description: Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%16405 Error: (05/10/2014 06:16:09 PM) (Source: Service Control Manager) (User: ) (EventID: 7000) Description: Der Dienst "DM1Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (05/10/2014 06:16:05 PM) (Source: ACPI) (User: ) (EventID: 13) Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft. Microsoft Office Sessions: ========================= Error: (05/10/2014 06:18:14 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:16:41 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:13:52 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:12:36 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:10:53 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:09:51 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:03:54 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:02:53 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 06:00:39 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/10/2014 05:59:21 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2014-03-04 09:04:05.162 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-03-02 13:50:40.151 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-28 08:44:22.119 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-26 11:22:02.115 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-25 09:30:13.238 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-22 09:48:37.040 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-21 17:50:26.378 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-20 21:14:09.965 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-19 21:31:39.942 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-19 15:42:06.075 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 66% Total physical RAM: 3689.9 MB Available physical RAM: 1244.06 MB Total Pagefile: 7377.98 MB Available Pagefile: 4579.48 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: (Windows7_OS) (Fixed) (Total:448.67 GB) (Free:393.67 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (INTENSO USB) (Removable) (Total:1.87 GB) (Free:1.86 GB) FAT Drive q: (Lenovo_Recovery) (Fixed) (Total:15.62 GB) (Free:3.46 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 493A967E) Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=449 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=16 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 15 GB) (Disk ID: 493A9675) Partition 1: (Not Active) - (Size=8 GB) - (Type=84) Partition 2: (Not Active) - (Size=7 GB) - (Type=73) ======================================================== Disk: 2 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: 2F65BD4E) Partition 1: (Active) - (Size=2 GB) - (Type=06) ==================== End Of Log ============================ |
11.05.2014, 16:42 | #4 |
/// the machine /// TB-Ausbilder | Windows 7: div. Probleme seit Softonic Download, Virus? Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.05.2014, 08:28 | #5 |
| Windows 7: div. Probleme seit Softonic Download, Virus? ok, hier kommen die logs: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 12.05.2014 Suchlauf-Zeit: 06:58:52 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.03.04.09 Rootkit Datenbank: v2014.02.20.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Administrator Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 295421 Verstrichene Zeit: 9 Min, 4 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 2 Trojan.BHO, HKU\S-1-5-21-3449097423-3504793074-380607187-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}, In Quarantäne, [b19810effe7cfb3b08e0044cfd0534cc], Trojan.BHO, HKU\S-1-5-21-3449097423-3504793074-380607187-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}, In Quarantäne, [b19810effe7cfb3b08e0044cfd0534cc], Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 1 PUP.Optional.Softonic.A, C:\$Recycle.Bin\S-1-5-21-3449097423-3504793074-380607187-1001\$RCU8ATH.exe, In Quarantäne, [a1a8738c99e175c10bf873ef45bc08f8], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.208 - Bericht erstellt am 12/05/2014 um 07:12:13 # Aktualisiert 11/05/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Administrator - NATA-THINK # Gestartet von : C:\Users\Administrator\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : F06DEFF2-5B9C-490D-910F-35D3A91196222 [#] Dienst Gelöscht : SystemkService ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Partner [!] Ordner Gelöscht : C:\ProgramData\systemk [!] Ordner Gelöscht : C:\Program Files (x86)\Settings Manager Ordner Gelöscht : C:\Users\nata\AppData\LocalLow\DataMngr Datei Gelöscht : C:\Users\nata\AppData\Roaming\Mozilla\Firefox\Profiles\t18ym8k4.default\invalidprefs.js Datei Gelöscht : C:\Users\nata\AppData\Roaming\Mozilla\Firefox\Profiles\t18ym8k4.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe Wert Gelöscht : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64] Wert Gelöscht : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86] Wert Gelöscht : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64] Wert Gelöscht : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} Schlüssel Gelöscht : HKLM\Software\Solvusoft Schlüssel Gelöscht : HKLM\Software\SystemK Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17041 ************************* AdwCleaner[R0].txt - [5612 octets] - [12/05/2014 07:10:49] AdwCleaner[S0].txt - [4890 octets] - [12/05/2014 07:12:13] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4950 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Administrator on 12.05.2014 at 9:09:06,43 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12.05.2014 at 9:14:48,88 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-05-2014 Ran by Administrator (administrator) on NATA-THINK on 12-05-2014 09:19:44 Running from C:\Users\Administrator\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AuthenTec, Inc) C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe (Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Lenovo.) C:\Windows\System32\TpShocks.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (Lenovo, Inc.) C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Lenovo) C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe (Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe (AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\TouchControl.exe (AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\x86\BioMonitor.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [177936 2012-02-17] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11406608 2012-02-21] (Intel Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12476520 2012-04-10] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-03-09] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2881336 2012-06-19] (Synaptics Incorporated) HKLM\...\Run: [TpShocks] => C:\Windows\system32\TpShocks.exe [382528 2012-02-24] (Lenovo.) HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [290160 2012-06-01] (Lenovo Group Limited) HKLM\...\Run: [] => [X] HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-02-29] (Intel Corporation) HKLM-x32\...\Run: [RotateImage] => C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [PWMTRV] => rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [507744 2011-12-20] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [1091376 2012-01-17] (Lenovo) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-13] (Lenovo, Inc.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3449097423-3504793074-380607187-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKU\S-1-5-21-3449097423-3504793074-380607187-1001\...\MountPoints2: {f80d5996-ec1e-11e1-b279-806e6f6e6963} - Q:\LenovoQDrive.exe HKU\S-1-5-21-3449097423-3504793074-380607187-500\...\MountPoints2: {f80d5996-ec1e-11e1-b279-806e6f6e6963} - Q:\LenovoQDrive.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe () Startup: C:\Users\nata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Administrator\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) HKLM\...\AppCertDlls: [x64] -> c:\program files (x86)\settings manager\systemk\x64\sysapcrt.dll HKLM\...\AppCertDlls: [x86] -> c:\program files (x86)\settings manager\systemk\sysapcrt.dll ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENP BHO: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\IEBHO.DLL (AuthenTec Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation) BHO-x32: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\x86\IEBHO.dll (AuthenTec Inc.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 255.0.0.0 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF - C:\Program Files (x86)\Nitro PDF\Professional 7\npnitromozilla.dll ( ) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012-12-19] FF HKLM-x32\...\Firefox\Extensions: [VIP1X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] FF HKLM-x32\...\Firefox\Extensions: [VIP2X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] Chrome: ======= CHR HomePage: hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP CHR StartupUrls: "hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP" CHR Extension: (Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-12] CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-12] CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-12] CHR Extension: (Website Logon) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdkedefaddcdlpmiafhicjnkbogjiogj [2014-05-12] CHR Extension: (Google-Suche) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-12] CHR Extension: (Citavi Picker) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2014-05-12] CHR Extension: (Google Mail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-12] CHR HKLM-x32\...\Chrome\Extension: [cdkedefaddcdlpmiafhicjnkbogjiogj] - C:\Program Files\Lenovo Fingerprint Reader\x86\tschrome.crx [2012-03-13] CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - C:\Program Files (x86)\Citavi 4\Pickers\Chrome\ChromePicker.crx [2014-02-07] ==================== Services (Whitelisted) ================= R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-03-30] (Diskeeper Corporation) R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [169776 2012-01-17] (Lenovo) R2 FPLService; C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe [328552 2012-06-07] (AuthenTec, Inc) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-29] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-29] (Intel Corporation) R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [179568 2012-06-01] (Lenovo Group Limited) R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 NitroDriverReadSpool2; C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe [216072 2012-05-23] (Nitro PDF Software) S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22888 2013-09-17] () R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [84080 2012-04-19] (Symantec Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) S2 DM1Service; C:\Program Files (x86)\Olympus\DeviceDetector\DM1Service.exe [X] ==================== Drivers (Whitelisted) ==================== R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] () R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-03-30] (Diskeeper Corporation) R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [95024 2012-03-30] (Diskeeper Corporation) S3 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [70416 2012-01-17] (Windows (R) Win 7 DDK provider) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-12] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.) R3 SmbDrvIntel; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [27448 2012-06-19] (Synaptics Incorporated) R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.) R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-07] (ThinkVantage Communications Utility) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-12 09:19 - 2014-05-12 09:19 - 00020842 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-05-12 09:14 - 2014-05-12 09:14 - 00000633 _____ () C:\Users\Administrator\Desktop\JRT.txt 2014-05-12 09:09 - 2014-05-12 09:09 - 00000000 ____D () C:\Windows\ERUNT 2014-05-12 09:08 - 2014-05-12 09:03 - 01016261 _____ (Thisisu) C:\Users\Administrator\Desktop\JRT.exe 2014-05-12 09:03 - 2014-05-12 09:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-05-12 07:10 - 2014-05-12 07:12 - 00000000 ____D () C:\AdwCleaner 2014-05-12 07:10 - 2014-05-12 07:09 - 01325827 _____ () C:\Users\Administrator\Desktop\adwcleaner.exe 2014-05-12 07:06 - 2014-05-12 07:06 - 00001746 _____ () C:\Users\Administrator\Desktop\mbam.txt 2014-05-12 07:04 - 2014-05-12 07:04 - 00287024 _____ () C:\Windows\Minidump\051214-19125-01.dmp 2014-05-12 06:49 - 2014-05-12 07:13 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-12 06:49 - 2014-05-12 06:49 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-12 06:49 - 2014-05-12 06:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-12 06:49 - 2014-05-12 06:49 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-12 06:49 - 2014-05-12 06:49 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-12 06:49 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 06:49 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 06:49 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-12 06:47 - 2014-05-12 06:45 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Administrator\Desktop\mbam-setup-2.0.1.1004.exe 2014-05-12 06:39 - 2014-05-12 06:40 - 00000000 ____D () C:\Users\Administrator\Desktop\frst eins 2014-05-12 06:39 - 2014-05-12 06:39 - 00000000 ____D () C:\Users\Administrator\AppData\Local\AuthenTec 2014-05-12 06:39 - 2014-05-12 06:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fingerprint Reader 2014-05-10 22:06 - 2014-05-10 21:39 - 02065408 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe 2014-05-10 22:04 - 2014-05-12 09:19 - 00000000 ____D () C:\FRST 2014-05-10 21:49 - 2014-05-10 21:51 - 00000000 ____D () C:\Users\Administrator\AppData\Local\LSC 2014-05-10 21:49 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LSC 2014-05-10 21:41 - 2014-05-12 07:23 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Nitro PDF 2014-05-10 17:46 - 2014-05-10 17:46 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PwrMgr 2014-05-10 17:45 - 2014-05-10 17:45 - 00109296 _____ () C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT 2014-05-10 17:45 - 2014-05-10 17:45 - 00109296 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Lenovo 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Leadertech 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Lenovo 2014-05-10 17:44 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-05-10 17:44 - 2014-05-10 17:45 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-10 17:44 - 2014-05-10 17:45 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-10 17:44 - 2014-05-10 17:44 - 00001432 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-10 17:44 - 2014-05-10 17:44 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Intel 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _____ () C:\Users\Administrator\agent.log 2014-05-10 17:44 - 2012-12-21 23:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Microsoft Help 2014-05-10 17:44 - 2012-08-22 08:20 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia 2014-05-10 17:44 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-05-10 17:44 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-05-10 17:41 - 2014-05-10 17:41 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-10 17:41 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-10 17:41 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-10 17:41 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-05-10 17:41 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-10 17:41 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-05-10 17:41 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-05-10 17:41 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-05-10 17:41 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-05-10 17:41 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-05-10 17:41 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-05-10 17:41 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-10 17:41 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-05-10 17:41 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-05-10 17:41 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-05-10 17:41 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-05-10 17:41 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-05-10 17:41 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-05-10 17:41 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-05-10 17:41 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-05-10 17:41 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-05-10 17:41 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-05-10 17:41 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-05-10 17:41 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-05-10 17:41 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-05-10 17:41 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-05-10 17:41 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-05-10 17:41 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-05-10 17:41 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-05-10 17:41 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-05-10 17:41 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-05-10 17:41 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-05-10 17:41 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-05-10 17:41 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-05-10 17:41 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-05-10 17:41 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-05-10 17:41 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-05-10 17:41 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-05-10 17:41 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-05-10 17:41 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-05-10 17:41 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-05-10 17:41 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-05-10 17:41 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-05-10 17:41 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-05-10 17:41 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-05-10 17:41 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-05-10 17:41 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-05-10 17:41 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-05-10 17:41 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-05-10 14:51 - 2014-05-10 14:51 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Adobe 2014-05-10 14:50 - 2014-05-10 14:50 - 00003124 _____ () C:\Windows\System32\Tasks\{6C7A5AC4-342A-4676-89AE-4BA82B109572} 2014-05-09 14:31 - 2014-05-12 07:13 - 00000000 ____D () C:\ProgramData\systemk 2014-05-09 14:29 - 2014-05-10 14:51 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Security Systems 2014-05-06 17:06 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-06 17:06 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-05 23:17 - 2014-05-05 23:18 - 00000000 ____D () C:\Users\nata\AppData\Local\{4CC0FB4D-67D0-4A88-BF45-A1C9FFEC2DEB} 2014-05-05 23:16 - 2014-05-05 23:16 - 00000000 ____D () C:\Users\nata\AppData\Local\{795EA3FA-DB86-464D-BD6F-E276B51A127B} 2014-05-01 20:36 - 2014-05-02 08:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird ==================== One Month Modified Files and Folders ======= 2014-05-12 09:19 - 2014-05-12 09:19 - 00020842 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-05-12 09:19 - 2014-05-10 22:04 - 00000000 ____D () C:\FRST 2014-05-12 09:16 - 2012-08-22 08:23 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-12 09:14 - 2014-05-12 09:14 - 00000633 _____ () C:\Users\Administrator\Desktop\JRT.txt 2014-05-12 09:12 - 2012-08-22 08:09 - 01818610 _____ () C:\Windows\WindowsUpdate.log 2014-05-12 09:10 - 2012-08-22 17:55 - 00714294 _____ () C:\Windows\system32\perfh007.dat 2014-05-12 09:10 - 2012-08-22 17:55 - 00154346 _____ () C:\Windows\system32\perfc007.dat 2014-05-12 09:10 - 2009-07-14 07:13 - 01648944 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-12 09:09 - 2014-05-12 09:09 - 00000000 ____D () C:\Windows\ERUNT 2014-05-12 09:03 - 2014-05-12 09:08 - 01016261 _____ (Thisisu) C:\Users\Administrator\Desktop\JRT.exe 2014-05-12 09:03 - 2014-05-12 09:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-05-12 09:02 - 2013-05-27 21:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-12 07:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-12 07:23 - 2014-05-10 21:41 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Nitro PDF 2014-05-12 07:20 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-12 07:20 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-12 07:13 - 2014-05-12 06:49 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-12 07:13 - 2014-05-09 14:31 - 00000000 ____D () C:\ProgramData\systemk 2014-05-12 07:13 - 2012-08-22 08:23 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-12 07:13 - 2012-08-22 08:12 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-05-12 07:13 - 2010-11-21 05:47 - 00679640 _____ () C:\Windows\PFRO.log 2014-05-12 07:13 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-12 07:13 - 2009-07-14 06:51 - 00091049 _____ () C:\Windows\setupact.log 2014-05-12 07:12 - 2014-05-12 07:10 - 00000000 ____D () C:\AdwCleaner 2014-05-12 07:09 - 2014-05-12 07:10 - 01325827 _____ () C:\Users\Administrator\Desktop\adwcleaner.exe 2014-05-12 07:06 - 2014-05-12 07:06 - 00001746 _____ () C:\Users\Administrator\Desktop\mbam.txt 2014-05-12 07:04 - 2014-05-12 07:04 - 00287024 _____ () C:\Windows\Minidump\051214-19125-01.dmp 2014-05-12 07:04 - 2013-09-13 14:45 - 1549460872 _____ () C:\Windows\MEMORY.DMP 2014-05-12 07:04 - 2013-09-13 14:45 - 00000000 ____D () C:\Windows\Minidump 2014-05-12 06:59 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-05-12 06:49 - 2014-05-12 06:49 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-12 06:49 - 2014-05-12 06:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-12 06:49 - 2014-05-12 06:49 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-12 06:49 - 2014-05-12 06:49 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-12 06:45 - 2014-05-12 06:47 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Administrator\Desktop\mbam-setup-2.0.1.1004.exe 2014-05-12 06:40 - 2014-05-12 06:39 - 00000000 ____D () C:\Users\Administrator\Desktop\frst eins 2014-05-12 06:39 - 2014-05-12 06:39 - 00000000 ____D () C:\Users\Administrator\AppData\Local\AuthenTec 2014-05-12 06:39 - 2014-05-12 06:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fingerprint Reader 2014-05-10 21:51 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\Administrator\AppData\Local\LSC 2014-05-10 21:49 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LSC 2014-05-10 21:49 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-05-10 21:39 - 2014-05-10 22:06 - 02065408 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe 2014-05-10 18:04 - 2014-01-18 20:56 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Skype 2014-05-10 18:04 - 2013-01-09 12:07 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Dropbox 2014-05-10 17:46 - 2014-05-10 17:46 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PwrMgr 2014-05-10 17:45 - 2014-05-10 17:45 - 00109296 _____ () C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT 2014-05-10 17:45 - 2014-05-10 17:45 - 00109296 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Lenovo 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Leadertech 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Lenovo 2014-05-10 17:45 - 2014-05-10 17:44 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-10 17:45 - 2014-05-10 17:44 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-10 17:45 - 2009-07-14 06:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-05-10 17:44 - 2014-05-10 17:44 - 00001432 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-10 17:44 - 2014-05-10 17:44 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Intel 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _____ () C:\Users\Administrator\agent.log 2014-05-10 17:41 - 2014-05-10 17:41 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-10 15:46 - 2012-12-19 18:20 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Nitro PDF 2014-05-10 14:51 - 2014-05-10 14:51 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Adobe 2014-05-10 14:51 - 2014-05-09 14:29 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Security Systems 2014-05-10 14:50 - 2014-05-10 14:50 - 00003124 _____ () C:\Windows\System32\Tasks\{6C7A5AC4-342A-4676-89AE-4BA82B109572} 2014-05-10 14:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-05-10 14:39 - 2013-01-28 14:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco Systems VPN Client 2014-05-10 14:39 - 2012-12-19 18:10 - 00000000 ____D () C:\Users\nata 2014-05-10 14:39 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-10 13:01 - 2012-08-22 08:12 - 00000830 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-05-09 14:34 - 2013-01-09 12:10 - 00000000 ___RD () C:\Users\nata\Dropbox 2014-05-09 14:33 - 2013-11-24 13:16 - 00000000 ____D () C:\Users\nata\AppData\Local\Unity 2014-05-05 23:18 - 2014-05-05 23:17 - 00000000 ____D () C:\Users\nata\AppData\Local\{4CC0FB4D-67D0-4A88-BF45-A1C9FFEC2DEB} 2014-05-05 23:17 - 2014-02-25 22:52 - 00000000 ____D () C:\Users\nata\AppData\Local\Windows Live 2014-05-05 23:16 - 2014-05-05 23:16 - 00000000 ____D () C:\Users\nata\AppData\Local\{795EA3FA-DB86-464D-BD6F-E276B51A127B} 2014-05-03 18:06 - 2012-12-19 22:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-02 08:37 - 2014-05-01 20:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-05-01 22:14 - 2013-04-18 13:44 - 00000000 ____D () C:\Users\nata\Desktop\orga ablage 2014-04-28 21:56 - 2013-05-27 21:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-28 21:56 - 2012-12-19 23:30 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-28 21:56 - 2012-12-19 23:30 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-14 13:35 - 2013-01-04 18:25 - 00000000 ____D () C:\Users\nata\AppData\Local\Adobe 2014-04-14 04:24 - 2014-05-06 17:06 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-14 04:19 - 2014-05-06 17:06 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll Some content of TEMP: ==================== C:\Users\Administrator\AppData\Local\Temp\Quarantine.exe C:\Users\nata\AppData\Local\Temp\DelayInst.exe C:\Users\nata\AppData\Local\Temp\FoxySecuritySetup.exe C:\Users\nata\AppData\Local\Temp\installservice.exe C:\Users\nata\AppData\Local\Temp\ose00000.exe C:\Users\nata\AppData\Local\Temp\SettingsManagerSetup.exe C:\Users\nata\AppData\Local\Temp\vpnclient_setup.exe C:\Users\nata\AppData\Local\Temp\wyqv4shi.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-12 07:32 ==================== End Of Log ============================ --- --- --- Bin mal gespannt auf deine Rückmeldung... danke schonmal :-) ach ja: seit ich die von dir beschriebenen Aktionen ausgeführt habe, funktioniert die Verbindung zum Internet wieder. Geändert von Annett (12.05.2014 um 08:34 Uhr) |
12.05.2014, 17:46 | #6 |
/// the machine /// TB-Ausbilder | Windows 7: div. Probleme seit Softonic Download, Virus?ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Windows 7: div. Probleme seit Softonic Download, Virus? |
12.05.2014, 21:26 | #7 |
| Windows 7: div. Probleme seit Softonic Download, Virus?Code:
ATTFilter ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=551be1dff7799441b81f75bfdfcd9a74 # engine=18234 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-05-12 08:13:56 # local_time=2014-05-12 10:13:56 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 26391116 151555486 0 0 # scanned=152380 # found=0 # cleaned=0 # scan_time=1906 Code:
ATTFilter Results of screen317's Security Check version 0.99.82 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials (On Access scanning disabled!) Error obtaining update status for antivirus! `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 13.0.0.206 Google Chrome 34.0.1847.116 Google Chrome 34.0.1847.131 ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014 01 Ran by Administrator (administrator) on NATA-THINK on 12-05-2014 22:20:11 Running from C:\Users\Administrator\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AuthenTec, Inc) C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe (Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Lenovo.) C:\Windows\System32\TpShocks.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\TouchControl.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\x86\BioMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Lenovo) C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [177936 2012-02-17] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11406608 2012-02-21] (Intel Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12476520 2012-04-10] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-03-09] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2881336 2012-06-19] (Synaptics Incorporated) HKLM\...\Run: [TpShocks] => C:\Windows\system32\TpShocks.exe [382528 2012-02-24] (Lenovo.) HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [290160 2012-06-01] (Lenovo Group Limited) HKLM\...\Run: [] => [X] HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-02-29] (Intel Corporation) HKLM-x32\...\Run: [RotateImage] => C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [PWMTRV] => rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [507744 2011-12-20] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [1091376 2012-01-17] (Lenovo) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-13] (Lenovo, Inc.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3449097423-3504793074-380607187-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKU\S-1-5-21-3449097423-3504793074-380607187-1001\...\MountPoints2: {f80d5996-ec1e-11e1-b279-806e6f6e6963} - Q:\LenovoQDrive.exe HKU\S-1-5-21-3449097423-3504793074-380607187-500\...\MountPoints2: {f80d5996-ec1e-11e1-b279-806e6f6e6963} - Q:\LenovoQDrive.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe () Startup: C:\Users\nata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Administrator\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) HKLM\...\AppCertDlls: [x64] -> c:\program files (x86)\settings manager\systemk\x64\sysapcrt.dll HKLM\...\AppCertDlls: [x86] -> c:\program files (x86)\settings manager\systemk\sysapcrt.dll ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENP BHO: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\IEBHO.DLL (AuthenTec Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation) BHO-x32: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\x86\IEBHO.dll (AuthenTec Inc.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{4C279CFE-306B-45E3-A2C8-0B22F55E8036}: [NameServer]192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\d8hrz8rz.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF - C:\Program Files (x86)\Nitro PDF\Professional 7\npnitromozilla.dll ( ) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012-12-19] FF HKLM-x32\...\Firefox\Extensions: [VIP1X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] FF HKLM-x32\...\Firefox\Extensions: [VIP2X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client\ FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\ [] Chrome: ======= CHR HomePage: hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP CHR StartupUrls: "hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP" CHR Extension: (Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-12] CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-12] CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-12] CHR Extension: (Website Logon) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdkedefaddcdlpmiafhicjnkbogjiogj [2014-05-12] CHR Extension: (Google-Suche) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-12] CHR Extension: (Citavi Picker) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2014-05-12] CHR Extension: (Google Mail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-12] CHR HKLM-x32\...\Chrome\Extension: [cdkedefaddcdlpmiafhicjnkbogjiogj] - C:\Program Files\Lenovo Fingerprint Reader\x86\tschrome.crx [2012-03-13] CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - C:\Program Files (x86)\Citavi 4\Pickers\Chrome\ChromePicker.crx [2014-02-07] ==================== Services (Whitelisted) ================= R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-03-30] (Diskeeper Corporation) R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [169776 2012-01-17] (Lenovo) R2 FPLService; C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe [328552 2012-06-07] (AuthenTec, Inc) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-29] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-29] (Intel Corporation) R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [179568 2012-06-01] (Lenovo Group Limited) R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 NitroDriverReadSpool2; C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe [216072 2012-05-23] (Nitro PDF Software) S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22888 2013-09-17] () R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [84080 2012-04-19] (Symantec Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) S2 DM1Service; C:\Program Files (x86)\Olympus\DeviceDetector\DM1Service.exe [X] ==================== Drivers (Whitelisted) ==================== R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] () R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-03-30] (Diskeeper Corporation) R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [95024 2012-03-30] (Diskeeper Corporation) S3 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [70416 2012-01-17] (Windows (R) Win 7 DDK provider) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-12] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.) R3 SmbDrvIntel; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [27448 2012-06-19] (Synaptics Incorporated) R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.) R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-07] (ThinkVantage Communications Utility) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-12 22:20 - 2014-05-12 22:20 - 00020978 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-05-12 22:20 - 2014-05-12 22:20 - 00000000 ____D () C:\Users\Administrator\Desktop\FRST-OlderVersion 2014-05-12 22:17 - 2014-05-12 21:34 - 00855379 _____ () C:\Users\Administrator\Desktop\SecurityCheck.exe 2014-05-12 11:20 - 2014-05-12 11:20 - 00001746 _____ () C:\Users\Administrator\Desktop\mbam2.txt 2014-05-12 09:30 - 2014-05-12 09:31 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla 2014-05-12 09:30 - 2014-05-12 09:30 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla 2014-05-12 09:19 - 2014-05-12 09:20 - 00044431 _____ () C:\Users\Administrator\Desktop\FRST zwei.txt 2014-05-12 09:14 - 2014-05-12 09:14 - 00000633 _____ () C:\Users\Administrator\Desktop\JRT.txt 2014-05-12 09:09 - 2014-05-12 09:09 - 00000000 ____D () C:\Windows\ERUNT 2014-05-12 09:08 - 2014-05-12 09:03 - 01016261 _____ (Thisisu) C:\Users\Administrator\Desktop\JRT.exe 2014-05-12 09:03 - 2014-05-12 09:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-05-12 07:10 - 2014-05-12 07:12 - 00000000 ____D () C:\AdwCleaner 2014-05-12 07:10 - 2014-05-12 07:09 - 01325827 _____ () C:\Users\Administrator\Desktop\adwcleaner.exe 2014-05-12 07:06 - 2014-05-12 07:06 - 00001746 _____ () C:\Users\Administrator\Desktop\mbam.txt 2014-05-12 07:04 - 2014-05-12 07:04 - 00287024 _____ () C:\Windows\Minidump\051214-19125-01.dmp 2014-05-12 06:49 - 2014-05-12 21:32 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-12 06:49 - 2014-05-12 06:49 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-12 06:49 - 2014-05-12 06:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-12 06:49 - 2014-05-12 06:49 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-12 06:49 - 2014-05-12 06:49 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-12 06:49 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 06:49 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 06:49 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-12 06:39 - 2014-05-12 06:40 - 00000000 ____D () C:\Users\Administrator\Desktop\frst eins 2014-05-12 06:39 - 2014-05-12 06:39 - 00000000 ____D () C:\Users\Administrator\AppData\Local\AuthenTec 2014-05-12 06:39 - 2014-05-12 06:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fingerprint Reader 2014-05-10 22:06 - 2014-05-12 22:20 - 02066944 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe 2014-05-10 22:04 - 2014-05-12 22:20 - 00000000 ____D () C:\FRST 2014-05-10 21:49 - 2014-05-12 21:42 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LSC 2014-05-10 21:49 - 2014-05-10 21:51 - 00000000 ____D () C:\Users\Administrator\AppData\Local\LSC 2014-05-10 21:41 - 2014-05-12 21:42 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Nitro PDF 2014-05-10 17:46 - 2014-05-10 17:46 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PwrMgr 2014-05-10 17:45 - 2014-05-10 17:45 - 00109296 _____ () C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT 2014-05-10 17:45 - 2014-05-10 17:45 - 00109296 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Lenovo 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Leadertech 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Lenovo 2014-05-10 17:44 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-05-10 17:44 - 2014-05-10 17:45 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-10 17:44 - 2014-05-10 17:45 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-10 17:44 - 2014-05-10 17:44 - 00001432 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-10 17:44 - 2014-05-10 17:44 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Intel 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _____ () C:\Users\Administrator\agent.log 2014-05-10 17:44 - 2012-12-21 23:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Microsoft Help 2014-05-10 17:44 - 2012-08-22 08:20 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia 2014-05-10 17:44 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-05-10 17:44 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-05-10 17:41 - 2014-05-10 17:41 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-10 17:41 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-10 17:41 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-10 17:41 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-05-10 17:41 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-10 17:41 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-05-10 17:41 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-05-10 17:41 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-05-10 17:41 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-05-10 17:41 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-05-10 17:41 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-05-10 17:41 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-10 17:41 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-05-10 17:41 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-05-10 17:41 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-05-10 17:41 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-05-10 17:41 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-05-10 17:41 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-05-10 17:41 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-05-10 17:41 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-05-10 17:41 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-05-10 17:41 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-05-10 17:41 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-05-10 17:41 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-05-10 17:41 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-05-10 17:41 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-05-10 17:41 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-05-10 17:41 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-05-10 17:41 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-05-10 17:41 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-05-10 17:41 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-05-10 17:41 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-05-10 17:41 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-05-10 17:41 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-05-10 17:41 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-05-10 17:41 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-05-10 17:41 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-05-10 17:41 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-05-10 17:41 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-05-10 17:41 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-05-10 17:41 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-05-10 17:41 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-05-10 17:41 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-05-10 17:41 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-05-10 17:41 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-05-10 17:41 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-05-10 17:41 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-05-10 17:41 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-05-10 17:41 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-05-10 14:51 - 2014-05-10 14:51 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Adobe 2014-05-10 14:50 - 2014-05-10 14:50 - 00003124 _____ () C:\Windows\System32\Tasks\{6C7A5AC4-342A-4676-89AE-4BA82B109572} 2014-05-09 14:31 - 2014-05-12 07:13 - 00000000 ____D () C:\ProgramData\systemk 2014-05-09 14:29 - 2014-05-10 14:51 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Security Systems 2014-05-06 17:06 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-06 17:06 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-05 23:17 - 2014-05-05 23:18 - 00000000 ____D () C:\Users\nata\AppData\Local\{4CC0FB4D-67D0-4A88-BF45-A1C9FFEC2DEB} 2014-05-05 23:16 - 2014-05-05 23:16 - 00000000 ____D () C:\Users\nata\AppData\Local\{795EA3FA-DB86-464D-BD6F-E276B51A127B} 2014-05-01 20:36 - 2014-05-02 08:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird ==================== One Month Modified Files and Folders ======= 2014-05-12 22:20 - 2014-05-12 22:20 - 00020978 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-05-12 22:20 - 2014-05-12 22:20 - 00000000 ____D () C:\Users\Administrator\Desktop\FRST-OlderVersion 2014-05-12 22:20 - 2014-05-10 22:06 - 02066944 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe 2014-05-12 22:20 - 2014-05-10 22:04 - 00000000 ____D () C:\FRST 2014-05-12 22:20 - 2012-08-22 08:23 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-12 22:20 - 2012-08-22 08:23 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-12 22:15 - 2012-08-22 08:23 - 00004120 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-12 22:15 - 2012-08-22 08:23 - 00003868 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-12 22:02 - 2012-08-22 08:09 - 01910200 _____ () C:\Windows\WindowsUpdate.log 2014-05-12 21:56 - 2013-05-27 21:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-12 21:42 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LSC 2014-05-12 21:42 - 2014-05-10 21:41 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Nitro PDF 2014-05-12 21:42 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-12 21:42 - 2009-07-14 06:45 - 00031248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-12 21:38 - 2012-08-22 08:20 - 00000000 ____D () C:\Windows\System32\Tasks\Lenovo 2014-05-12 21:37 - 2012-08-22 17:55 - 00714294 _____ () C:\Windows\system32\perfh007.dat 2014-05-12 21:37 - 2012-08-22 17:55 - 00154346 _____ () C:\Windows\system32\perfc007.dat 2014-05-12 21:37 - 2009-07-14 07:13 - 01648944 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-12 21:34 - 2014-05-12 22:17 - 00855379 _____ () C:\Users\Administrator\Desktop\SecurityCheck.exe 2014-05-12 21:32 - 2014-05-12 06:49 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-12 21:32 - 2012-08-22 08:12 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-05-12 21:31 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-12 21:31 - 2009-07-14 06:51 - 00091105 _____ () C:\Windows\setupact.log 2014-05-12 15:17 - 2012-08-22 08:12 - 00000830 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-05-12 11:20 - 2014-05-12 11:20 - 00001746 _____ () C:\Users\Administrator\Desktop\mbam2.txt 2014-05-12 09:31 - 2014-05-12 09:30 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla 2014-05-12 09:30 - 2014-05-12 09:30 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla 2014-05-12 09:20 - 2014-05-12 09:19 - 00044431 _____ () C:\Users\Administrator\Desktop\FRST zwei.txt 2014-05-12 09:14 - 2014-05-12 09:14 - 00000633 _____ () C:\Users\Administrator\Desktop\JRT.txt 2014-05-12 09:09 - 2014-05-12 09:09 - 00000000 ____D () C:\Windows\ERUNT 2014-05-12 09:03 - 2014-05-12 09:08 - 01016261 _____ (Thisisu) C:\Users\Administrator\Desktop\JRT.exe 2014-05-12 09:03 - 2014-05-12 09:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-05-12 07:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-12 07:13 - 2014-05-09 14:31 - 00000000 ____D () C:\ProgramData\systemk 2014-05-12 07:13 - 2010-11-21 05:47 - 00679640 _____ () C:\Windows\PFRO.log 2014-05-12 07:12 - 2014-05-12 07:10 - 00000000 ____D () C:\AdwCleaner 2014-05-12 07:09 - 2014-05-12 07:10 - 01325827 _____ () C:\Users\Administrator\Desktop\adwcleaner.exe 2014-05-12 07:06 - 2014-05-12 07:06 - 00001746 _____ () C:\Users\Administrator\Desktop\mbam.txt 2014-05-12 07:04 - 2014-05-12 07:04 - 00287024 _____ () C:\Windows\Minidump\051214-19125-01.dmp 2014-05-12 07:04 - 2013-09-13 14:45 - 1549460872 _____ () C:\Windows\MEMORY.DMP 2014-05-12 07:04 - 2013-09-13 14:45 - 00000000 ____D () C:\Windows\Minidump 2014-05-12 06:59 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-05-12 06:49 - 2014-05-12 06:49 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-12 06:49 - 2014-05-12 06:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-12 06:49 - 2014-05-12 06:49 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-12 06:49 - 2014-05-12 06:49 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-12 06:40 - 2014-05-12 06:39 - 00000000 ____D () C:\Users\Administrator\Desktop\frst eins 2014-05-12 06:39 - 2014-05-12 06:39 - 00000000 ____D () C:\Users\Administrator\AppData\Local\AuthenTec 2014-05-12 06:39 - 2014-05-12 06:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fingerprint Reader 2014-05-10 21:51 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\Administrator\AppData\Local\LSC 2014-05-10 21:49 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-05-10 18:04 - 2014-01-18 20:56 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Skype 2014-05-10 18:04 - 2013-01-09 12:07 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Dropbox 2014-05-10 17:46 - 2014-05-10 17:46 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PwrMgr 2014-05-10 17:45 - 2014-05-10 17:45 - 00109296 _____ () C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT 2014-05-10 17:45 - 2014-05-10 17:45 - 00109296 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Lenovo 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Leadertech 2014-05-10 17:45 - 2014-05-10 17:45 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Lenovo 2014-05-10 17:45 - 2014-05-10 17:44 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-10 17:45 - 2014-05-10 17:44 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-10 17:45 - 2009-07-14 06:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-05-10 17:44 - 2014-05-10 17:44 - 00001432 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-10 17:44 - 2014-05-10 17:44 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Intel 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 ____D () C:\Users\Administrator 2014-05-10 17:44 - 2014-05-10 17:44 - 00000000 _____ () C:\Users\Administrator\agent.log 2014-05-10 17:41 - 2014-05-10 17:41 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-10 15:46 - 2012-12-19 18:20 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Nitro PDF 2014-05-10 14:51 - 2014-05-10 14:51 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Adobe 2014-05-10 14:51 - 2014-05-09 14:29 - 00000000 ____D () C:\Users\nata\AppData\Roaming\Security Systems 2014-05-10 14:50 - 2014-05-10 14:50 - 00003124 _____ () C:\Windows\System32\Tasks\{6C7A5AC4-342A-4676-89AE-4BA82B109572} 2014-05-10 14:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-05-10 14:39 - 2013-01-28 14:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco Systems VPN Client 2014-05-10 14:39 - 2012-12-19 18:10 - 00000000 ____D () C:\Users\nata 2014-05-10 14:39 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-09 14:34 - 2013-01-09 12:10 - 00000000 ___RD () C:\Users\nata\Dropbox 2014-05-09 14:33 - 2013-11-24 13:16 - 00000000 ____D () C:\Users\nata\AppData\Local\Unity 2014-05-05 23:18 - 2014-05-05 23:17 - 00000000 ____D () C:\Users\nata\AppData\Local\{4CC0FB4D-67D0-4A88-BF45-A1C9FFEC2DEB} 2014-05-05 23:17 - 2014-02-25 22:52 - 00000000 ____D () C:\Users\nata\AppData\Local\Windows Live 2014-05-05 23:16 - 2014-05-05 23:16 - 00000000 ____D () C:\Users\nata\AppData\Local\{795EA3FA-DB86-464D-BD6F-E276B51A127B} 2014-05-03 18:06 - 2012-12-19 22:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-02 08:37 - 2014-05-01 20:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-05-01 22:14 - 2013-04-18 13:44 - 00000000 ____D () C:\Users\nata\Desktop\orga ablage 2014-04-28 21:56 - 2013-05-27 21:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-28 21:56 - 2012-12-19 23:30 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-28 21:56 - 2012-12-19 23:30 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-14 13:35 - 2013-01-04 18:25 - 00000000 ____D () C:\Users\nata\AppData\Local\Adobe 2014-04-14 04:24 - 2014-05-06 17:06 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-14 04:19 - 2014-05-06 17:06 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll Some content of TEMP: ==================== C:\Users\Administrator\AppData\Local\Temp\Quarantine.exe C:\Users\nata\AppData\Local\Temp\DelayInst.exe C:\Users\nata\AppData\Local\Temp\FoxySecuritySetup.exe C:\Users\nata\AppData\Local\Temp\installservice.exe C:\Users\nata\AppData\Local\Temp\ose00000.exe C:\Users\nata\AppData\Local\Temp\SettingsManagerSetup.exe C:\Users\nata\AppData\Local\Temp\vpnclient_setup.exe C:\Users\nata\AppData\Local\Temp\wyqv4shi.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-12 07:32 ==================== End Of Log ============================ Was meinst Du? Für mich scheint alles wieder zu funktionieren - aber ist "ES" wirklich weg? |
13.05.2014, 15:42 | #8 | |
/// the machine /// TB-Ausbilder | Windows 7: div. Probleme seit Softonic Download, Virus?Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.05.2014, 15:29 | #9 |
| Windows 7: div. Probleme seit Softonic Download, Virus? Nö!! Der ist auch erst seit dem Softonic Download drauf. Ich wollte ihn löschen, das ging nicht... |
15.05.2014, 10:07 | #10 |
/// the machine /// TB-Ausbilder | Windows 7: div. Probleme seit Softonic Download, Virus? Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM\...\AppCertDlls: [x64] -> c:\program files (x86)\settings manager\systemk\x64\sysapcrt.dll HKLM\...\AppCertDlls: [x86] -> c:\program files (x86)\settings manager\systemk\sysapcrt.dll c:\program files (x86)\settings manager Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.05.2014, 12:12 | #11 |
| Windows 7: div. Probleme seit Softonic Download, Virus? Lieber Schrauber, über einen Freund habe ich Kontakt zu jemandem bekommen, der mir die "Virusreste" noch vom Rechner entfernt hat. Ich möchte mich herzlich bei dir für die Hilfe bedanken. Am Ende war ich mir einfach nicht sicher, ob alles weg ist und brauchte jemanden, der mir das nochmal f2f versichert ;-) Grüße Annett |
19.05.2014, 08:41 | #12 |
/// the machine /// TB-Ausbilder | Windows 7: div. Probleme seit Softonic Download, Virus? ok.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7: div. Probleme seit Softonic Download, Virus? |
diverse, download, funktioniert nicht, internet, manager, microsoft, microsoft essentials, netzwerk, nicht mehr, probleme, programm, programme, pup.optional.softonic.a, scan, security, starten, startseite, systemsteuerung, trojan.bho, verbindung, windows, windows 7 |