|
Plagegeister aller Art und deren Bekämpfung: Doppelt grün unterstrichener WerbemüllWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
15.07.2014, 17:51 | #1 |
| Doppelt grün unterstrichener Werbemüll Hy Ich habe schon gelesen das dies wohl kein Trojaner ist sondern eine "innoivative" Werbeform zum Segen der Nutzer. Von irgendwem habe ich mir das Ding auch eingefangen. Ich brauche daher auch einmal Hilfe den Mist weg zu bekommen und wäre über eine Info dankbar wer mit diesem Mist zusammenarbeitet. Ich will jegliches Programm von meinem Rechner schmeißen das diese Form der Werbung unterstützt. Da die Anleitungen sich stark unterscheiden und es mehrere Verschiedene zu geben scheint will ich nicht blind irgend einer bestehenden Anleitung folgen..... Also danke für die Hilfe im Voraus! Frst: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-07-2014 Ran by Peter (administrator) on ERGO on 15-07-2014 18:37:59 Running from C:\instmp Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Windows\oem.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe () C:\Program Files (x86)\Universal Updater\UpdaterService.exe (My Digital Life Forums) C:\Windows\KMSEmu.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (PriceMeter) C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (ITE Tech. Inc.) C:\Windows\System32\IRMonitor.exe (Almico Software (www.almico.com)) C:\Program Files (x86)\SpeedFan\speedfan.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\livecomm.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe (ACD Systems) C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe (Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (André Rübel) C:\Program Files (x86)\DMEX\dmextoolmenu\dmextoolmenu.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe () C:\Program Files (x86)\Universal Updater\CrashMon.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Ghisler Software GmbH) C:\Program Files (x86)\totalcmd\TOTALCMD64.EXE (VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe () C:\Program Files (x86)\Opera\22.0.1471.70\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe () C:\Program Files (x86)\Isis\isis.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70\opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ACPW07DE] => C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe [1739080 2013-09-25] (ACD Systems) HKLM\...\Run: [ACPW07EN] => C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe [1739080 2013-09-25] (ACD Systems) HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2013-04-09] (Pixart Imaging Inc) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-04-23] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.) HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [78312 2012-05-09] (cyberlink) HKLM-x32\...\Run: [CrashMon] => C:\Program Files (x86)\Universal Updater\CrashMon.exe [388096 2014-06-18] () HKLM-x32\...\Run: [Isis] => C:\Program Files (x86)\Isis\isis.exe [330544 2014-07-15] () HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-04-23] (Samsung) HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [KiesAirMessage] => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [457728 2013-09-30] (Microsoft Corporation) HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [Facebook Update] => C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-02-15] (Facebook Inc.) HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd) HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [PriceMeterW] => "C:\Users\Peter\AppData\Local\PriceMeter\pricemeterw.exe" HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [KiesPDLR.exe] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-04-23] (Samsung) HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\MountPoints2: {61197b53-8df7-11e3-8269-806e6f6e6963} - "Y:\AutoRun\AutoRun.exe" HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\MountPoints2: {e6059545-c30d-11e3-828b-001e8c7a8508} - "H:\autorun.exe" IFEO\SppExtComObj.exe: [Debugger] SppHook.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk ShortcutTarget: TMMonitor.lnk -> C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.) Startup: C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DMEX Tools.lnk ShortcutTarget: DMEX Tools.lnk -> C:\Program Files (x86)\DMEX\dmextoolmenu\dmextoolmenu.exe (André Rübel) Startup: C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpeedFan.lnk ShortcutTarget: SpeedFan.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.exe (Almico Software (www.almico.com)) ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?ctid=CT3322287&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPE82D8A95-44C7-4A2B-A8AD-CA47F0430FC2&SSPV= HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x512F766B0919CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3322287&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPE82D8A95-44C7-4A2B-A8AD-CA47F0430FC2&q={searchTerms}&SSPV= SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3322287&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPE82D8A95-44C7-4A2B-A8AD-CA47F0430FC2&q={searchTerms}&SSPV= BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.updatepm.com/PriceMeterLiveUpdate Update;version=3 - C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll (PriceMeter) FF Plugin-x32: @tools.updatepm.com/PriceMeterLiveUpdate Update;version=9 - C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll (PriceMeter) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Peter\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-28] CHR Extension: (Google Drive) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-28] CHR Extension: (YouTube) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-28] CHR Extension: (McAfee Security Scan+) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-06-14] CHR Extension: (Last updated at $time$ on $date$) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-12] CHR Extension: (Google Search) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-28] CHR Extension: (dict.cc context menu) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijmkoefdiklbdnfbafpgekimgkgbkfna [2014-02-12] CHR Extension: (Google Wallet) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-28] CHR Extension: (YouTube Unblocker) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl [2014-02-12] CHR Extension: (Gmail) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-28] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2014-02-12] ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [242664 2012-05-09] (CyberLink) S2 pricemeterliveUpdate; C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe [150504 2014-05-03] (PriceMeter) S3 pricemeterliveUpdatem; C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe [150504 2014-05-03] (PriceMeter) R2 UniversalUpdater; C:\Program Files (x86)\Universal Updater\UpdaterService.exe [606136 2014-06-18] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-09-24] (Advanced Micro Devices) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2014-01-25] () R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2014-04-14] (DT Soft Ltd) R1 isis; C:\Windows\System32\drivers\isis.sys [52016 2014-07-15] (Windows (R) Win 7 DDK provider) S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [165504 2014-02-04] (ITE ) S3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2014-01-25] () R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] () R0 SI3112r; C:\Windows\System32\DRIVERS\SI3112r.sys [133160 2007-12-26] (Silicon Image, Inc) R0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [22056 2007-12-26] (Silicon Image, Inc) R3 t_mouse.sys; C:\Windows\system32\DRIVERS\t_mouse.sys [6144 2013-04-09] () S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) R3 yukonw8; C:\Windows\system32\DRIVERS\yk63x64.sys [295216 2013-06-18] (Marvell) S3 dgderdrv; System32\drivers\dgderdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-15 18:37 - 2014-07-15 18:38 - 00000000 ____D () C:\FRST 2014-07-15 15:21 - 2014-07-15 15:21 - 00000000 ____D () C:\Users\Peter\AppData\Local\HD Streamer 2014-07-15 14:51 - 2014-07-15 14:51 - 00052016 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\isis.sys 2014-07-15 02:07 - 2014-07-15 02:07 - 00000000 ____D () C:\ProgramData\PriceMeterLiveUpdate 2014-07-15 01:57 - 2014-07-15 02:19 - 00000000 ____D () C:\zoek_backup 2014-07-15 01:57 - 2014-07-15 02:05 - 00007810 _____ () C:\zoek-results.log 2014-07-14 18:12 - 2014-07-15 15:21 - 00000000 ____D () C:\Program Files (x86)\Isis 2014-07-11 08:53 - 2014-07-15 02:05 - 00002274 _____ () C:\Windows\PFRO.log 2014-07-10 22:47 - 2014-07-10 22:47 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-10 19:46 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-07-10 06:03 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-07-10 06:03 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-10 06:03 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-10 06:03 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-10 06:03 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2014-07-10 06:03 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-07-10 06:03 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2014-07-10 06:03 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2014-07-10 06:03 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2014-07-10 06:03 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-07-10 06:02 - 2014-07-01 00:45 - 00688128 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-10 06:02 - 2014-06-28 09:48 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-07-10 06:02 - 2014-06-28 09:07 - 00385536 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-07-10 06:02 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-10 06:02 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-10 06:02 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-10 06:02 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-10 06:02 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-10 06:02 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-10 06:02 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-10 06:02 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-10 06:02 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-10 06:02 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-10 06:02 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-10 06:02 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-10 06:02 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-10 06:02 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-10 06:02 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-10 06:02 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-10 06:02 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-10 06:02 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-10 06:02 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-10 06:02 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-10 06:02 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-10 06:02 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-10 06:02 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-10 06:02 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-07-10 06:02 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-10 06:02 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-10 06:02 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-07-10 06:02 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-10 06:02 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-10 06:02 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-07-10 06:02 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll 2014-07-10 06:02 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2014-07-10 06:02 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2014-07-10 06:02 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-10 06:02 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-07-10 06:02 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-07-10 06:02 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-10 06:02 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-07-10 06:02 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-07-10 06:02 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-07-10 06:02 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll 2014-07-10 06:02 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2014-07-10 06:02 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll 2014-07-10 06:02 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2014-07-10 05:59 - 2014-07-10 05:59 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\WSReset.exe 2014-07-01 18:25 - 2014-07-15 17:39 - 01106289 _____ () C:\Windows\WindowsUpdate.log 2014-06-26 12:23 - 2012-12-22 21:09 - 00444928 _____ (Alex Schepeljanski) C:\Users\Peter\Desktop\AS SSD Benchmark.exe 2014-06-17 17:02 - 2014-06-17 17:02 - 00001007 _____ () C:\Users\Peter\Desktop\MakeMKV.lnk 2014-06-17 17:02 - 2014-06-17 17:02 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MakeMKV 2014-06-17 17:02 - 2014-06-17 17:02 - 00000000 ____D () C:\Program Files (x86)\MakeMKV 2014-06-17 04:35 - 2014-06-17 04:35 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-06-17 04:35 - 2014-06-17 04:35 - 00000834 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-06-17 04:35 - 2014-06-17 04:35 - 00000000 ____D () C:\Program Files\CCleaner ==================== One Month Modified Files and Folders ======= 2014-07-15 18:38 - 2014-07-15 18:37 - 00000000 ____D () C:\FRST 2014-07-15 18:38 - 2014-01-27 12:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-15 18:37 - 2014-01-24 15:38 - 00000000 ____D () C:\instmp 2014-07-15 18:35 - 2014-01-24 16:21 - 00000000 ____D () C:\JDownloader 2014-07-15 18:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru 2014-07-15 17:53 - 2014-01-28 08:23 - 00001118 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-15 17:45 - 2014-05-03 17:40 - 00000974 _____ () C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job 2014-07-15 17:45 - 2014-05-03 17:40 - 00000970 _____ () C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job 2014-07-15 17:39 - 2014-07-01 18:25 - 01106289 _____ () C:\Windows\WindowsUpdate.log 2014-07-15 16:50 - 2014-02-15 11:45 - 00000938 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3412253895-2932389450-2306418526-1001UA.job 2014-07-15 16:09 - 2014-01-24 15:37 - 00003914 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{BDA3291A-B02F-4BBA-98C9-5BFD405CE7DF} 2014-07-15 15:21 - 2014-07-15 15:21 - 00000000 ____D () C:\Users\Peter\AppData\Local\HD Streamer 2014-07-15 15:21 - 2014-07-14 18:12 - 00000000 ____D () C:\Program Files (x86)\Isis 2014-07-15 15:21 - 2014-04-29 18:48 - 00000000 ____D () C:\Program Files (x86)\Addon Enabler 2014-07-15 15:10 - 2014-06-11 18:36 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-07-15 14:51 - 2014-07-15 14:51 - 00052016 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\isis.sys 2014-07-15 12:50 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness 2014-07-15 10:53 - 2014-01-28 08:23 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-15 10:50 - 2014-02-15 11:45 - 00000916 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3412253895-2932389450-2306418526-1001Core.job 2014-07-15 03:22 - 2014-01-24 15:37 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3412253895-2932389450-2306418526-1001 2014-07-15 02:37 - 2014-01-24 15:56 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\vlc 2014-07-15 02:25 - 2014-01-28 08:23 - 00000000 ____D () C:\Program Files (x86)\Google 2014-07-15 02:25 - 2013-12-22 14:54 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-15 02:25 - 2013-09-30 05:58 - 00764340 _____ () C:\Windows\system32\perfh007.dat 2014-07-15 02:25 - 2013-09-30 05:58 - 00159160 _____ () C:\Windows\system32\perfc007.dat 2014-07-15 02:24 - 2014-02-05 01:05 - 00000000 __RDO () C:\Users\Peter\SkyDrive 2014-07-15 02:24 - 2014-02-04 19:25 - 00000048 _____ () C:\monitor.log 2014-07-15 02:24 - 2014-01-24 23:06 - 00000000 ____D () C:\Program Files (x86)\SpeedFan 2014-07-15 02:24 - 2014-01-24 15:29 - 00000000 ____D () C:\Users\Peter 2014-07-15 02:21 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-15 02:20 - 2014-04-14 14:25 - 00000000 ____D () C:\ProgramData\DAEMON Tools Pro 2014-07-15 02:20 - 2014-01-24 15:35 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\GHISLER 2014-07-15 02:20 - 2013-12-22 15:05 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-07-15 02:19 - 2014-07-15 01:57 - 00000000 ____D () C:\zoek_backup 2014-07-15 02:19 - 2014-01-28 08:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec 2014-07-15 02:19 - 2014-01-27 10:39 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\OpenCandy 2014-07-15 02:19 - 2014-01-24 15:38 - 00000000 ____D () C:\ProgramData\Package Cache 2014-07-15 02:19 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\registration 2014-07-15 02:18 - 2014-01-28 08:21 - 00000000 ____D () C:\Program Files (x86)\MyFree Codec 2014-07-15 02:18 - 2013-12-22 15:01 - 00000000 ____D () C:\Program Files\Microsoft Office 2014-07-15 02:07 - 2014-07-15 02:07 - 00000000 ____D () C:\ProgramData\PriceMeterLiveUpdate 2014-07-15 02:05 - 2014-07-15 01:57 - 00007810 _____ () C:\zoek-results.log 2014-07-15 02:05 - 2014-07-11 08:53 - 00002274 _____ () C:\Windows\PFRO.log 2014-07-14 16:00 - 2013-12-22 15:01 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-07-12 10:46 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache 2014-07-11 08:53 - 2013-08-22 16:44 - 00473776 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-10 22:47 - 2014-07-10 22:47 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-10 22:47 - 2013-09-30 06:00 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-10 22:47 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData 2014-07-10 22:47 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-10 22:47 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-10 22:47 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore 2014-07-10 22:47 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-07-10 19:49 - 2014-01-27 05:08 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-10 19:49 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp 2014-07-10 19:48 - 2014-01-27 05:08 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-10 19:48 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-07-10 06:08 - 2014-01-24 15:38 - 00000000 ____D () C:\Users\Peter\AppData\Local\GHISLER 2014-07-10 05:59 - 2014-07-10 05:59 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\WSReset.exe 2014-07-08 18:38 - 2014-01-27 12:38 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-07-07 01:20 - 2014-01-24 15:39 - 00000786 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-07-07 01:20 - 2014-01-24 15:39 - 00000774 _____ () C:\Users\Public\Desktop\Opera.lnk 2014-07-01 22:41 - 2014-02-11 01:43 - 00042496 ___SH () C:\Users\Peter\Desktop\Thumbs.db 2014-07-01 00:45 - 2014-07-10 06:02 - 00688128 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-30 05:14 - 2014-01-24 15:39 - 00000000 ____D () C:\Program Files\Common Files\logishrd 2014-06-30 05:13 - 2014-01-29 16:10 - 00000000 ____D () C:\ProgramData\LogiShrd 2014-06-30 05:13 - 2014-01-29 16:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2014-06-28 09:48 - 2014-07-10 06:02 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-28 09:07 - 2014-07-10 06:02 - 00385536 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-06-26 22:55 - 2013-08-22 17:38 - 00703968 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:55 - 2013-08-22 17:38 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-26 22:32 - 2014-01-25 04:54 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\dvdcss 2014-06-26 01:00 - 2014-02-07 20:27 - 00032256 ___SH () C:\Users\Peter\Documents\Thumbs.db 2014-06-19 03:39 - 2014-07-10 06:02 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-19 02:48 - 2014-07-10 06:02 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-19 02:16 - 2014-07-10 06:02 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-19 02:09 - 2014-07-10 06:02 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-19 01:51 - 2014-07-10 06:02 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-19 01:50 - 2014-07-10 06:02 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-19 01:48 - 2014-07-10 06:02 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-19 01:46 - 2014-07-10 06:02 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-06-19 01:39 - 2014-07-10 06:02 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-19 01:33 - 2014-07-10 06:02 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-19 01:32 - 2014-07-10 06:02 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-19 01:27 - 2014-07-10 06:02 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-19 01:12 - 2014-07-10 06:02 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-19 00:59 - 2014-07-10 06:02 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-19 00:58 - 2014-07-10 06:02 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-19 00:58 - 2014-07-10 06:02 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-19 00:57 - 2014-07-10 06:02 - 00225280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-06-19 00:52 - 2014-07-10 06:02 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-19 00:51 - 2014-07-10 06:02 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-19 00:49 - 2014-07-10 06:02 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-19 00:45 - 2014-07-10 06:02 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-19 00:35 - 2014-07-10 06:02 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-19 00:34 - 2014-07-10 06:02 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-19 00:15 - 2014-07-10 06:02 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-19 00:13 - 2014-07-10 06:02 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-19 00:09 - 2014-07-10 06:02 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-19 00:07 - 2014-07-10 06:02 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-06-18 16:29 - 2014-01-31 11:30 - 00000000 ____D () C:\Program Files (x86)\Universal Updater 2014-06-18 12:11 - 2014-06-03 12:11 - 00003842 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1390570772 2014-06-18 12:11 - 2014-01-24 15:39 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-06-17 17:02 - 2014-06-17 17:02 - 00001007 _____ () C:\Users\Peter\Desktop\MakeMKV.lnk 2014-06-17 17:02 - 2014-06-17 17:02 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MakeMKV 2014-06-17 17:02 - 2014-06-17 17:02 - 00000000 ____D () C:\Program Files (x86)\MakeMKV 2014-06-17 10:48 - 2014-01-28 08:23 - 00004090 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-17 10:48 - 2014-01-28 08:23 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-17 04:36 - 2014-04-14 14:25 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\DAEMON Tools Pro 2014-06-17 04:36 - 2014-02-04 18:31 - 00000000 ____D () C:\Windows\Minidump 2014-06-17 04:36 - 2013-12-22 14:33 - 00000000 ____D () C:\Windows\Panther 2014-06-17 04:35 - 2014-06-17 04:35 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-06-17 04:35 - 2014-06-17 04:35 - 00000834 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-06-17 04:35 - 2014-06-17 04:35 - 00000000 ____D () C:\Program Files\CCleaner 2014-06-17 00:26 - 2014-07-10 06:03 - 00779264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-06-17 00:24 - 2014-07-10 06:03 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-06-16 20:05 - 2014-01-24 15:30 - 00000000 ____D () C:\Users\Peter\AppData\Local\Packages Some content of TEMP: ==================== C:\Users\Peter\AppData\Local\Temp\sfamcc00001.dll C:\Users\Peter\AppData\Local\Temp\sfareca00001.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-08 09:46 ==================== End Of Log ============================ --- --- --- additionalFRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2014 Ran by Peter at 2014-07-15 18:38:24 Running from C:\instmp Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 888poker (HKLM-x32\...\888poker) (Version: - ) ACDSee Pro 7 (64-bit) (HKLM\...\{D2A6EC54-CB46-49E4-A6FC-A9179F9D9D12}) (Version: 7.0.138 - ACD Systems International Inc.) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 13.20.100.31206 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{3C378793-5288-0165-FCA4-D319D5E4A490}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) ANNO 1404 - Venedig (HKLM-x32\...\{A07B2C21-863B-47AB-AE7E-20BB00BD7D33}) (Version: 2.01.5010 - Ubisoft) ANNO 1404 (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.02.0000 - Ubisoft) Anno 1404 (x32 Version: 1.00.0000 - Ubisoft) Hidden ArcSoft TotalMedia 3.5 (HKLM-x32\...\{74292F90-895A-4FC6-A692-9641532B1B63}) (Version: 3.5.28.322 - ArcSoft) AVS Media Player 4.2.2.104 (HKLM-x32\...\AVS Media Player_is1) (Version: 4.2.2.104 - Online Media Technologies Ltd.) AVS Video Converter 8 (HKLM-x32\...\AVS4YOU Video Converter 7_is1) (Version: 8.4.2.541 - Online Media Technologies Ltd.) CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) Hidden Canon MF Toolbox 4.9.1.1.mf16 (HKLM-x32\...\{6767DFEE-8909-453A-B553-C7693912B2EB}) (Version: 4.9.1.1.mf16 - CANON INC.) Canon MF4320-4350 (HKLM\...\{99A5569D-9F86-4f32-A227-1538B731DA42}) (Version: - ) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform) Civ3 Conquests v1.22 Full (HKLM-x32\...\{4C2BF3B9-7E8A-49DE-B662-3656FE60BB01}) (Version: - ) Civilization III - Play the World v1.27F (HKLM-x32\...\{210E1DB3-3451-4C32-8028-AACA931C4375}) (Version: - ) Civilization III (HKLM-x32\...\{0AD84416-63A4-4CF3-BDDF-8FA866711FB0}) (Version: - ) Civilization III Play the World (HKLM-x32\...\{E8650C8D-CCB2-496E-816C-ECC54A7EE411}) (Version: - ) Civilization III v1.21f (HKLM-x32\...\{253C3A51-A249-470F-A787-5645B289A118}) (Version: - ) Civilization III: Conquests (HKLM-x32\...\{F31BC49F-AB7B-4A53-A399-EB7331B585BC}) (Version: - ) CPUID CPU-Z 1.68 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CrystalDiskMark 3.0.3a (HKLM\...\CrystalDiskMark_is1) (Version: 3.0.3a - Crystal Dew World) CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.) CyberLink Media Suite 10 (x32 Version: 10.2021 - CyberLink Corp.) Hidden CyberLink PowerDVD 10 (x32 Version: 10.0.4125.52 - CyberLink Corp.) Hidden DAEMON Tools Pro (HKLM-x32\...\DAEMON Tools Pro) (Version: 5.2.0.0348 - DT Soft Ltd) Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D1C35197-B856-45E2-BA67-5ABB6B0CA9C2}) (Version: - Microsoft) DMEX Tool Collection (uninstall only) (HKLM-x32\...\DMEX_is1) (Version: - André Rübel) eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) Free YouTube to MP3 Converter version 3.12.34.430 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.34.430 - DVDVideoSoft Ltd.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version: - ) IT9130 Driver v12.2.3.1 (HKLM-x32\...\IT9130 DriverInstaller_12.2.3.1) (Version: - ) Java 7 Update 55 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417055FF}) (Version: 7.0.550 - Oracle) Java(TM) 6 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416045FF}) (Version: 6.0.450 - Oracle) klickTel Routenplaner Deutschland und Europa 2014 (HKLM-x32\...\{46DF1620-1A09-11E3-8FFD-0800200C9A66}) (Version: 1.00.0000 - telegate MEDIA AG) Logitech Webcam-Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.) LWS Facebook (x32 Version: 13.50.854.0 - Logitech) Hidden LWS Gallery (x32 Version: 13.51.827.0 - Logitech) Hidden LWS Help_main (x32 Version: 13.51.828.0 - Logitech) Hidden LWS Launcher (x32 Version: 13.51.828.0 - Logitech) Hidden LWS Motion Detection (x32 Version: 13.51.815.0 - Logitech) Hidden LWS Pictures And Video (x32 Version: 13.51.815.0 - Logitech) Hidden LWS Twitter (x32 Version: 13.30.1346.0 - Logitech) Hidden LWS Webcam Software (x32 Version: 13.51.815.0 - Logitech) Hidden LWS WLM Plugin (x32 Version: 1.30.1201.0 - Logitech) Hidden LWS YouTube Plugin (x32 Version: 13.31.1038.0 - Logitech) Hidden MakeMKV v1.8.10 (HKLM-x32\...\MakeMKV) (Version: v1.8.10 - GuinpinSoft inc) MegaTrainer eXperience V1.2.3.8 (HKLM-x32\...\MegaTrainer eXperience_is1) (Version: - ) MegaTrainer XL V1.5.8.0 (HKLM-x32\...\MegaTrainer XL_is1) (Version: - ) Microsoft Access MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft DCF MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Excel MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Groove MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft InfoPath MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Lync MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office 32-bit Components 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Korrekturhilfen 2013 - Deutsch (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM UX MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - Italiano (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft OneNote MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Outlook MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft PowerPoint MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Publisher MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Word MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden MyFreeCodec (HKCU\...\MyFreeCodec) (Version: - ) Nero Burning Core (x32 Version: 15.0.19000 - Nero AG) Hidden Nero Burning ROM (x32 Version: 15.0.19000 - Nero AG) Hidden Nero Burning ROM 2014 (HKLM-x32\...\{326AD556-E540-4C3F-B197-4A9456DABCF3}) (Version: 15.0.01300 - Nero AG) Nero Burning ROM Help (CHM) (x32 Version: 15.0.00015 - Nero AG) Hidden Nero ControlCenter (x32 Version: 11.0.16700 - Nero AG) Hidden Nero ControlCenter Help (CHM) (x32 Version: 15.0.00015 - Nero AG) Hidden Nero Core Components (x32 Version: 11.0.22500 - Nero AG) Hidden Nero SharedVideoCodecs (x32 Version: 1.0.15003 - Nero AG) Hidden Nero Update (x32 Version: 11.0.13300.42.0 - Nero AG) Hidden Opera 12.02 (HKLM-x32\...\{61CE07D6-2867-4BB1-84C3-CD117A1ABD54}) (Version: 12.02 - Opera Software ASA) Opera Stable 22.0.1471.70 (HKLM-x32\...\Opera 22.0.1471.70) (Version: 22.0.1471.70 - Opera Software ASA) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Prerequisite installer (x32 Version: 15.0.0005 - Nero AG) Hidden QupZilla 1.6.1 (HKLM-x32\...\QupZilla) (Version: 1.6.1 - QupZilla Team) Return to Castle Wolfenstein (HKLM-x32\...\Return to Castle Wolfenstein) (Version: 1.0 - Activision, Inc.) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.1.13105_7 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.6.1.13105_7 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.43.0 - SAMSUNG Electronics Co., Ltd.) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden Shark007 Advanced Codecs (HKLM-x32\...\{8C0CAA7A-3272-4991-A808-2C7559DE3409}) (Version: 4.4.6 - Shark007) Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-0018-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-001B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-00C1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2850074) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{CE9A9D7C-B6FB-4F6C-8BDE-9A1ADBBAC1EE}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760344) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EF77B4A6-DFEC-4010-A87D-9B6BF87FABEC}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760544) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{62857CDD-2985-4939-91BA-19ED0B0031A5}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2768012) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{0814662C-FD28-4DE0-ACE5-EE50D1D6C8FB}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817302) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{E79EFFDB-192A-4D9E-A2DB-C0F774E6EC32}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817302) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{E79EFFDB-192A-4D9E-A2DB-C0F774E6EC32}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2826040) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C4AEA56A-0759-4D08-9FAB-31A92137D0B8}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2837644) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D692E9FF-84BF-4F44-A0EA-D58ECE0D538E}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863843) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{290D80DE-03AB-47EC-9402-108AF4CE4F66}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880457) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EC2AF602-2730-4B05-9438-06CDE43153F2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{24584DD4-C680-4FEB-A464-D760C7A5B041}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{24584DD4-C680-4FEB-A464-D760C7A5B041}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{24584DD4-C680-4FEB-A464-D760C7A5B041}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880464) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{88B29AA5-71EE-4692-91E2-E89407F0B783}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880478) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{8116ED50-F1E7-49E1-9D8D-421497D34B0F}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{885C981B-F1E3-430A-A099-31CA9D28C251}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{885C981B-F1E3-430A-A099-31CA9D28C251}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 64-Bit Edition (HKLM\...\{90150000-0090-0407-1000-0000000FF1CE}_Office15.PROPLUS_{885C981B-F1E3-430A-A099-31CA9D28C251}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881074) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{9A479F9C-C1EC-4833-A115-A8B7A60480BD}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-0407-1000-0000000FF1CE}_Office15.PROPLUS_{00BBBFFE-8889-4953-956A-77DDE975A947}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-0409-1000-0000000FF1CE}_Office15.PROPLUS_{3A12DFA2-3FF5-450E-BDB1-A742551A5D1A}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}_Office15.PROPLUS_{EA8072E8-E3CF-46DF-A5DE-9F5975344327}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-0410-1000-0000000FF1CE}_Office15.PROPLUS_{BF0D921F-E77E-4E03-BE71-46D9D2C7A36A}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881086) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{ED3A8E98-FDD4-493F-A0EC-141821573EC2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881086) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{ED3A8E98-FDD4-493F-A0EC-141821573EC2}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-00BA-0407-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-00C1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BFD66A5D-F608-441E-9282-41E13F5E7412}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 64-Bit Edition (HKLM\...\{90150000-00A1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{BFD66A5D-F608-441E-9282-41E13F5E7412}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BFD66A5D-F608-441E-9282-41E13F5E7412}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2880470) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{34A169EC-990A-4DAE-AC65-9F981158B7DB}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2880470) 64-Bit Edition (HKLM\...\{90150000-001A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{34A169EC-990A-4DAE-AC65-9F981158B7DB}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2881075) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C8955821-EDAC-4E65-BEF3-C9C0A049517A}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2881075) 64-Bit Edition (HKLM\...\{90150000-0018-0407-1000-0000000FF1CE}_Office15.PROPLUS_{C8955821-EDAC-4E65-BEF3-C9C0A049517A}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2880999) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C07147B9-CC0B-4CC1-A107-A705889A54F2}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2880999) 64-Bit Edition (HKLM\...\{90150000-0019-0407-1000-0000000FF1CE}_Office15.PROPLUS_{C07147B9-CC0B-4CC1-A107-A705889A54F2}) (Version: - Microsoft) Update for Microsoft Visio 2013 (KB2837632) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{97183E08-6B06-40F1-80A9-585C4AEF98F1}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2878319) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BC51FE30-3A56-4802-8D9E-E9BC05B56B49}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881005) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{125BAFEC-EB26-45C3-B97A-475162C6BDC0}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881005) 64-Bit Edition (HKLM\...\{90150000-001A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{125BAFEC-EB26-45C3-B97A-475162C6BDC0}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881005) 64-Bit Edition (HKLM\...\{90150000-001B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{125BAFEC-EB26-45C3-B97A-475162C6BDC0}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881005) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{125BAFEC-EB26-45C3-B97A-475162C6BDC0}) (Version: - Microsoft) VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Restore Points ========================= 24-06-2014 11:51:57 Windows Update 02-07-2014 15:54:20 Geplanter Prüfpunkt 06-07-2014 23:20:09 Installed Opera 12.02. 10-07-2014 17:44:27 Windows Update 14-07-2014 13:59:58 Windows Update 15-07-2014 00:17:20 Wiederherstellungsvorgang ==================== Hosts content: ========================== 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {03BD76AE-D4BD-4667-9868-3E59606C7495} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {214141D0-4DF2-4981-BA5C-02C366107B92} - System32\Tasks\irMonitor => C:\Windows\system32\IRMonitor.exe [2014-02-04] (ITE Tech. Inc.) Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {3C85C686-7E27-4F3E-811A-7D33F5F616A2} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: {3D4059BC-231D-4208-807E-B9903EA4C7C9} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {46E51DC6-2B76-48D7-9BFC-B9FB938011F7} - System32\Tasks\Price Meter Updater => C:\Users\Peter\AppData\Roaming\PRICEM~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {5438A397-CBD4-4E4A-99E9-CDDC04AEF4DB} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {5CECC133-6228-45BB-84DC-8F740135B95E} - System32\Tasks\OEM => C:\Windows\oem.exe [2013-12-22] () Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {736C8FC4-9B84-4B09-9F71-CC86C42E1272} - System32\Tasks\Speedfan => C:\Program Files (x86)\SpeedFan\speedfan.exe [2013-03-15] (Almico Software (www.almico.com)) Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {7B5937E0-6EC8-4C07-B9DA-9BF023691F07} - System32\Tasks\Opera scheduled Autoupdate 1390570772 => C:\Program Files (x86)\Opera\launcher.exe [2014-06-16] (Opera Software) Task: {7FEC8443-4242-453E-B3A5-A6B7FCFA01E2} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-07-10] (Microsoft Corporation) Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {8F9410B3-0366-4AAA-9D35-97F295401A8E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {A0BDC6FE-A730-48FD-98D7-198DF80F62F3} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {A330FE4C-7D41-4AA0-96DB-115A7927D204} - System32\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA => C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe [2014-05-03] (PriceMeter) <==== ATTENTION Task: {A6D3D67E-E6E4-4922-9D12-F423CCABEB2F} - System32\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore => C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe [2014-05-03] (PriceMeter) <==== ATTENTION Task: {B0FAA184-96C1-45A3-9985-0D8C7ADCA1C9} - System32\Tasks\pricemeterdownloader => C:\Users\Peter\AppData\Local\PriceMeter\pricemeterd.exe <==== ATTENTION Task: {B45609A7-4B1F-4345-A21D-49C54D27F93B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-28] (Google Inc.) Task: {B9082931-6747-4E43-BADA-8898A9D45DAC} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {BBD1A455-C26E-4F1B-8D80-E7977C77E39D} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3412253895-2932389450-2306418526-1001Core => C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-02-15] (Facebook Inc.) Task: {BCF1BFDA-CF2B-48A7-AB59-54E4FB46B717} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3412253895-2932389450-2306418526-1001UA => C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-02-15] (Facebook Inc.) Task: {BD849EEB-2D0B-4CED-A798-50BAA2AC7E27} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-28] (Google Inc.) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D3BF9105-8BD2-4C4E-AA06-B5AE41EE2FB6} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {DDD6DFE1-39A1-4196-AA22-2A397621DDA7} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload Task: {DE51159C-B802-40AB-BEEF-304DD28CDA3F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd) Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {ED0045F3-DCE5-467A-8920-11CE795FF0BB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3412253895-2932389450-2306418526-1001Core.job => C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3412253895-2932389450-2306418526-1001UA.job => C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Price Meter Updater.job => C:\Users\Peter\AppData\Roaming\PRICEM~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2013-12-22 01:56 - 2013-12-22 18:45 - 00517862 _____ () C:\Windows\oem.exe 2014-06-18 15:51 - 2014-06-18 15:51 - 00606136 _____ () C:\Program Files (x86)\Universal Updater\UpdaterService.exe 2012-09-13 01:38 - 2012-09-13 01:38 - 00264040 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe 2014-06-18 15:50 - 2014-06-18 15:50 - 00388096 _____ () C:\Program Files (x86)\Universal Updater\CrashMon.exe 2014-06-18 12:11 - 2014-06-18 12:11 - 01396344 _____ () C:\Program Files (x86)\Opera\22.0.1471.70\opera_crashreporter.exe 2014-07-15 14:51 - 2014-07-15 14:51 - 00330544 _____ () C:\Program Files (x86)\Isis\isis.exe 2014-05-09 06:52 - 2014-07-15 02:25 - 00158720 _____ () C:\Users\Peter\AppData\Local\Temp\sfareca00001.dll 2014-01-24 23:07 - 2014-07-15 02:25 - 00192512 _____ () C:\Users\Peter\AppData\Local\Temp\sfamcc00001.dll 2014-04-14 14:26 - 2014-04-14 14:26 - 00107520 _____ () C:\Program Files (x86)\DAEMON Tools Pro\BRD.dll 2014-02-04 19:30 - 2007-04-19 10:33 - 00035584 _____ () C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\uPiApi.dll 2014-02-04 19:30 - 2008-11-26 17:59 - 00131584 _____ () C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\AbilisWinUsb.dll 2014-02-04 19:30 - 2008-10-22 17:01 - 00200704 _____ () C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\VendorCmdRW.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 02144104 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 07955304 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 00341352 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 00028008 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 00127336 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll 2012-09-13 01:39 - 2012-09-13 01:39 - 00336232 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00113171 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlc.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 02396179 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlccore.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00268307 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdshow_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00027667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libdirectsound_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00031251 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libwaveout_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00066579 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirectdraw_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 02021395 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\liblibbluray_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00100371 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_bd_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00240659 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdvdnav_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00076307 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_vdr_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00045587 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libfilesystem_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00060947 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libsmooth_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00531475 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libhttplive_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00708627 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libdash_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00114195 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libzip_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00040467 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libstream_filter_rar_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00014867 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\librecord_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00133139 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libplaylist_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 01512467 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libtaglib_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00296979 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\lua\liblua_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 01248787 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\misc\libxml_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00054291 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libhotkeys_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00038419 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libglobalhotkeys_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00189971 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmp4_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 11148307 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\gui\libqt4_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00091667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libavi_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00067603 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libasf_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00077331 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libflacsys_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00025619 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libes_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00074259 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmpc_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00016403 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libtta_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00023059 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libnuv_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00021523 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libwav_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00929299 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libsid_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00118803 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libsap_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00144403 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libogg_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 01194003 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmkv_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00036371 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libfolder_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00383507 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libupnp_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00021011 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libpodcast_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00017427 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libmediadirs_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00014867 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libwindrive_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00291859 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libpng_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00017939 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcdg_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 01280019 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libschroedinger_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00018451 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libdts_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00336403 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libtheora_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00344595 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libfaad_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00198675 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libflac_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00027155 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libg711_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00015891 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaes3_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 01371667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblibass_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00146451 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspeex_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00022035 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblpcm_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00733203 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libvorbis_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libmpeg_audio_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00026131 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaraw_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00171027 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libopus_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00019475 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liba52_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspudec_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 10396179 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libavcodec_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00724499 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\text_renderer\libfreetype_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00026643 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\sse2\libi420_yuy2_sse2_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmx\libi420_yuy2_mmx_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00013843 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_mixer\libfloat_mixer_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00555027 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libswscale_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libscaletempo_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00130579 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libmpgatofixed32_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00113683 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\sse2\libi420_rgb_sse2_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00168979 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdtstofloat32_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00027667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\sse2\libi422_yuy2_sse2_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00058899 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\liba52tofloat32_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmx\libi422_yuy2_mmx_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 01496083 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsamplerate_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00053779 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmx\libi420_rgb_mmx_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00019475 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsimple_channel_mixer_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00016915 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libyuy2_i422_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00013331 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\liba52tospdif_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libgrey_yuv_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00014355 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdtstospdif_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00032275 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00014867 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdolby_surround_decoder_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00014355 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libugly_resampler_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00020499 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libyuy2_i420_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libtrivial_channel_mixer_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00017427 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00025619 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libaudio_format_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_i420_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libscale_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00013843 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libyuvp_plugin.dll 2014-02-05 03:31 - 2014-02-05 03:31 - 00053779 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirect2d_plugin.dll 2014-02-05 03:32 - 2014-02-05 03:32 - 00187411 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libblend_plugin.dll 2014-06-18 12:11 - 2014-06-18 12:11 - 00877688 _____ () C:\Program Files (x86)\Opera\22.0.1471.70\libglesv2.dll 2014-06-18 12:11 - 2014-06-18 12:11 - 00135800 _____ () C:\Program Files (x86)\Opera\22.0.1471.70\libegl.dll 2014-06-18 12:11 - 2014-06-18 12:11 - 00957048 _____ () C:\Program Files (x86)\Opera\22.0.1471.70\ffmpegsumo.dll 2014-06-11 18:37 - 2014-07-12 02:53 - 01116672 _____ () C:\Program Files (x86)\Steam\libavcodec-55.dll 2014-06-11 18:37 - 2014-07-12 02:53 - 00399360 _____ () C:\Program Files (x86)\Steam\libavformat-55.dll 2014-06-11 18:37 - 2014-07-12 02:53 - 00331264 _____ () C:\Program Files (x86)\Steam\libavresample-1.dll 2014-06-11 18:37 - 2014-07-12 02:53 - 00438784 _____ () C:\Program Files (x86)\Steam\libavutil-53.dll 2014-06-11 18:37 - 2014-06-27 00:40 - 00764416 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2014-06-11 18:37 - 2014-07-12 02:53 - 02139328 _____ () C:\Program Files (x86)\Steam\video.dll 2014-06-11 18:37 - 2014-04-29 02:37 - 00519168 _____ () C:\Program Files (x86)\Steam\libswscale-2.dll 2014-06-11 18:37 - 2014-07-12 02:53 - 01116864 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2014-06-11 18:37 - 2014-05-02 01:35 - 20628160 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2014-04-04 10:25 - 2014-04-04 10:25 - 00102400 _____ () C:\Program Files (x86)\Isis\nfapi.dll 2014-06-05 06:41 - 2014-06-05 06:41 - 00331776 _____ () C:\Program Files (x86)\Isis\ProtocolFilters.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Peter\SkyDrive:ms-properties AlternateDataStreams: C:\Users\Peter\SkyDrive.old:ms-properties ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/15/2014 03:00:00 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (1204) SRUJet: Fehler -1811 (0xfffff8ed) beim Öffnen von Protokolldatei C:\Windows\system32\SRU\SRU00ECB.log. Error: (07/15/2014 02:26:04 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/15/2014 02:25:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: chrome.exe, Version: 35.0.1916.153, Zeitstempel: 0x538fb354 Name des fehlerhaften Moduls: chrome.dll, Version: 35.0.1916.153, Zeitstempel: 0x538fb051 Ausnahmecode: 0x80000003 Fehleroffset: 0x00485166 ID des fehlerhaften Prozesses: 0xc38 Startzeit der fehlerhaften Anwendung: 0xchrome.exe0 Pfad der fehlerhaften Anwendung: chrome.exe1 Pfad des fehlerhaften Moduls: chrome.exe2 Berichtskennung: chrome.exe3 Vollständiger Name des fehlerhaften Pakets: chrome.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: chrome.exe5 Error: (07/15/2014 02:24:28 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/15/2014 02:21:05 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/15/2014 02:17:21 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (07/15/2014 02:10:17 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/15/2014 02:05:26 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/15/2014 02:05:26 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/14/2014 03:59:59 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . System errors: ============= Error: (07/15/2014 02:26:04 AM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/15/2014 02:26:04 AM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/15/2014 02:26:04 AM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/15/2014 02:24:28 AM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/15/2014 02:24:28 AM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/15/2014 02:24:28 AM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/15/2014 02:21:10 AM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/15/2014 02:21:10 AM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/15/2014 02:21:05 AM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/15/2014 02:21:05 AM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Microsoft Office Sessions: ========================= Error: (07/15/2014 03:00:00 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost1204SRUJet: C:\Windows\system32\SRU\SRU00ECB.log-1811 (0xfffff8ed) Error: (07/15/2014 02:26:04 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/15/2014 02:25:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: chrome.exe35.0.1916.153538fb354chrome.dll35.0.1916.153538fb0518000000300485166c3801cf9fc33ecd7abcC:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\chrome.dll7ca28e86-0bb6-11e4-82a1-001e8c7a8508 Error: (07/15/2014 02:24:28 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/15/2014 02:21:05 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/15/2014 02:17:21 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert Error: (07/15/2014 02:10:17 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/15/2014 02:05:26 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/15/2014 02:05:26 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/14/2014 03:59:59 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert ==================== Memory info =========================== Percentage of memory in use: 36% Total physical RAM: 6143.17 MB Available physical RAM: 3929.58 MB Total Pagefile: 7231.17 MB Available Pagefile: 4240.24 MB Total Virtual: 131072 MB Available Virtual: 131071.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:119.24 GB) (Free:58.93 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Volume) (Fixed) (Total:2794.39 GB) (Free:654.29 GB) NTFS Drive e: (Volume) (Fixed) (Total:2794.39 GB) (Free:882.71 GB) NTFS Drive g: (Volume) (Fixed) (Total:1397.26 GB) (Free:496.83 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive h: (Elements) (Fixed) (Total:1397.27 GB) (Free:1243.34 GB) NTFS Drive y: (SuperMultiBlue) (CDROM) (Total:0.67 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: D05BC153) Partition 1: (Active) - (Size=119 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 2795 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1397 GB) (Disk ID: EACF34C8) Partition 1: (Active) - (Size=-698723990528) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows XP) (Size: 1397 GB) (Disk ID: 00031DF1) Partition 1: (Not Active) - (Size=-698721378304) - (Type=07 NTFS) ======================================================== Disk: 4 (MBR Code: Windows 7 or 8) (Size: 2795 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ |
15.07.2014, 18:56 | #2 |
/// TB-Ausbilder | Doppelt grün unterstrichener WerbemüllMein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags: So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Danke für deine Mitarbeit! Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3 Bitte deaktiviere dein Anti-Viren-Programm, da es das Ergebnis beeinflussen oder ggf. die Bereinigung stören kann. Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/ und speichere die Datei auf deinem Desktop.
Schritt 4
Bitte poste mit deiner nächsten Antwort
|
16.07.2014, 04:48 | #3 |
| Doppelt grün unterstrichener WerbemüllCode:
ATTFilter Schritt 1AdwCleaner Logfile: Ach ich habe übrigens noch ein paraleles Problem. Google spuckt SSL Verbindungsfehler bei der Suche aus. Bing funktioniert aber. Geändert von Chagall1985 (15.07.2014 um 22:14 Uhr) |
16.07.2014, 07:11 | #4 | |
/// TB-Ausbilder | Doppelt grün unterstrichener WerbemüllZitat:
Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start () C:\Program Files (x86)\Isis\isis.exe R1 isis; C:\Windows\System32\drivers\isis.sys [52016 2014-07-15] (Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\isis.sys HKLM-x32\...\Run: [Isis] => C:\Program Files (x86)\Isis\isis.exe [330544 2014-07-15] () C:\Program Files (x86)\Isis Reboot: end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2
Schritt 3
Noch Probleme mit Werbung und doppelt unterstrichenen Wörtern? Bitte poste mit deiner nächsten Antwort
Geändert von M-K-D-B (16.07.2014 um 10:15 Uhr) |
16.07.2014, 15:34 | #5 |
| Doppelt grün unterstrichener WerbemüllCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-07-2014 Ran by Peter at 2014-07-16 16:04:43 Run:1 Running from C:\Users\Peter\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** start () C:\Program Files (x86)\Isis\isis.exe R1 isis; C:\Windows\System32\drivers\isis.sys [52016 2014-07-15] (Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\isis.sys HKLM-x32\...\Run: [Isis] => C:\Program Files (x86)\Isis\isis.exe [330544 2014-07-15] () C:\Program Files (x86)\Isis Reboot: end ***************** [3452] C:\Program Files (x86)\Isis\isis.exe => Process closed successfully. isis => Unable to stop service isis => Service deleted successfully. C:\Windows\System32\drivers\isis.sys => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Isis => value deleted successfully. C:\Program Files (x86)\Isis => Moved successfully. The system needed a reboot. ==== End of Fixlog ==== Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2014 Ran by Peter at 2014-07-16 16:15:38 Running from C:\Users\Peter\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 888poker (HKLM-x32\...\888poker) (Version: - ) ACDSee Pro 7 (64-bit) (HKLM\...\{D2A6EC54-CB46-49E4-A6FC-A9179F9D9D12}) (Version: 7.0.138 - ACD Systems International Inc.) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 13.20.100.31206 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{3C378793-5288-0165-FCA4-D319D5E4A490}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) ANNO 1404 - Venedig (HKLM-x32\...\{A07B2C21-863B-47AB-AE7E-20BB00BD7D33}) (Version: 2.01.5010 - Ubisoft) ANNO 1404 (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.02.0000 - Ubisoft) Anno 1404 (x32 Version: 1.00.0000 - Ubisoft) Hidden ArcSoft TotalMedia 3.5 (HKLM-x32\...\{74292F90-895A-4FC6-A692-9641532B1B63}) (Version: 3.5.28.322 - ArcSoft) AVS Media Player 4.2.2.104 (HKLM-x32\...\AVS Media Player_is1) (Version: 4.2.2.104 - Online Media Technologies Ltd.) AVS Video Converter 8 (HKLM-x32\...\AVS4YOU Video Converter 7_is1) (Version: 8.4.2.541 - Online Media Technologies Ltd.) CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) Hidden Canon MF Toolbox 4.9.1.1.mf16 (HKLM-x32\...\{6767DFEE-8909-453A-B553-C7693912B2EB}) (Version: 4.9.1.1.mf16 - CANON INC.) Canon MF4320-4350 (HKLM\...\{99A5569D-9F86-4f32-A227-1538B731DA42}) (Version: - ) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform) Civ3 Conquests v1.22 Full (HKLM-x32\...\{4C2BF3B9-7E8A-49DE-B662-3656FE60BB01}) (Version: - ) Civilization III - Play the World v1.27F (HKLM-x32\...\{210E1DB3-3451-4C32-8028-AACA931C4375}) (Version: - ) Civilization III (HKLM-x32\...\{0AD84416-63A4-4CF3-BDDF-8FA866711FB0}) (Version: - ) Civilization III Play the World (HKLM-x32\...\{E8650C8D-CCB2-496E-816C-ECC54A7EE411}) (Version: - ) Civilization III v1.21f (HKLM-x32\...\{253C3A51-A249-470F-A787-5645B289A118}) (Version: - ) Civilization III: Conquests (HKLM-x32\...\{F31BC49F-AB7B-4A53-A399-EB7331B585BC}) (Version: - ) CPUID CPU-Z 1.68 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CrystalDiskMark 3.0.3a (HKLM\...\CrystalDiskMark_is1) (Version: 3.0.3a - Crystal Dew World) CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.) CyberLink Media Suite 10 (x32 Version: 10.2021 - CyberLink Corp.) Hidden CyberLink PowerDVD 10 (x32 Version: 10.0.4125.52 - CyberLink Corp.) Hidden DAEMON Tools Pro (HKLM-x32\...\DAEMON Tools Pro) (Version: 5.2.0.0348 - DT Soft Ltd) Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D1C35197-B856-45E2-BA67-5ABB6B0CA9C2}) (Version: - Microsoft) DMEX Tool Collection (uninstall only) (HKLM-x32\...\DMEX_is1) (Version: - André Rübel) eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) Free YouTube to MP3 Converter version 3.12.34.430 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.34.430 - DVDVideoSoft Ltd.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version: - ) IT9130 Driver v12.2.3.1 (HKLM-x32\...\IT9130 DriverInstaller_12.2.3.1) (Version: - ) Java 7 Update 55 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417055FF}) (Version: 7.0.550 - Oracle) Java(TM) 6 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416045FF}) (Version: 6.0.450 - Oracle) klickTel Routenplaner Deutschland und Europa 2014 (HKLM-x32\...\{46DF1620-1A09-11E3-8FFD-0800200C9A66}) (Version: 1.00.0000 - telegate MEDIA AG) Logitech Webcam-Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.) LWS Facebook (x32 Version: 13.50.854.0 - Logitech) Hidden LWS Gallery (x32 Version: 13.51.827.0 - Logitech) Hidden LWS Help_main (x32 Version: 13.51.828.0 - Logitech) Hidden LWS Launcher (x32 Version: 13.51.828.0 - Logitech) Hidden LWS Motion Detection (x32 Version: 13.51.815.0 - Logitech) Hidden LWS Pictures And Video (x32 Version: 13.51.815.0 - Logitech) Hidden LWS Twitter (x32 Version: 13.30.1346.0 - Logitech) Hidden LWS Webcam Software (x32 Version: 13.51.815.0 - Logitech) Hidden LWS WLM Plugin (x32 Version: 1.30.1201.0 - Logitech) Hidden LWS YouTube Plugin (x32 Version: 13.31.1038.0 - Logitech) Hidden MakeMKV v1.8.10 (HKLM-x32\...\MakeMKV) (Version: v1.8.10 - GuinpinSoft inc) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) MegaTrainer eXperience V1.2.3.8 (HKLM-x32\...\MegaTrainer eXperience_is1) (Version: - ) MegaTrainer XL V1.5.8.0 (HKLM-x32\...\MegaTrainer XL_is1) (Version: - ) Microsoft Access MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft DCF MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Excel MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Groove MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft InfoPath MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Lync MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office 32-bit Components 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Korrekturhilfen 2013 - Deutsch (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM UX MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - Italiano (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft OneNote MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Outlook MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft PowerPoint MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Publisher MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Word MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Mozilla Firefox 30.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla) MyFreeCodec (HKCU\...\MyFreeCodec) (Version: - ) Nero Burning Core (x32 Version: 15.0.19000 - Nero AG) Hidden Nero Burning ROM (x32 Version: 15.0.19000 - Nero AG) Hidden Nero Burning ROM 2014 (HKLM-x32\...\{326AD556-E540-4C3F-B197-4A9456DABCF3}) (Version: 15.0.01300 - Nero AG) Nero Burning ROM Help (CHM) (x32 Version: 15.0.00015 - Nero AG) Hidden Nero ControlCenter (x32 Version: 11.0.16700 - Nero AG) Hidden Nero ControlCenter Help (CHM) (x32 Version: 15.0.00015 - Nero AG) Hidden Nero Core Components (x32 Version: 11.0.22500 - Nero AG) Hidden Nero SharedVideoCodecs (x32 Version: 1.0.15003 - Nero AG) Hidden Nero Update (x32 Version: 11.0.13300.42.0 - Nero AG) Hidden Opera Stable 22.0.1471.70 (HKLM-x32\...\Opera 22.0.1471.70) (Version: 22.0.1471.70 - Opera Software ASA) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Prerequisite installer (x32 Version: 15.0.0005 - Nero AG) Hidden QupZilla 1.6.1 (HKLM-x32\...\QupZilla) (Version: 1.6.1 - QupZilla Team) Return to Castle Wolfenstein (HKLM-x32\...\Return to Castle Wolfenstein) (Version: 1.0 - Activision, Inc.) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.1.13105_7 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.6.1.13105_7 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.43.0 - SAMSUNG Electronics Co., Ltd.) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden Shark007 Advanced Codecs (HKLM-x32\...\{8C0CAA7A-3272-4991-A808-2C7559DE3409}) (Version: 4.4.6 - Shark007) Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-0018-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-001B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2881085) 64-Bit Edition (HKLM\...\{90150000-00C1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{58D92858-3C94-4C2F-A8E4-AEFF9304C3CF}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2850074) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{CE9A9D7C-B6FB-4F6C-8BDE-9A1ADBBAC1EE}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760344) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EF77B4A6-DFEC-4010-A87D-9B6BF87FABEC}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760544) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{62857CDD-2985-4939-91BA-19ED0B0031A5}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2768012) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{0814662C-FD28-4DE0-ACE5-EE50D1D6C8FB}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817302) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{E79EFFDB-192A-4D9E-A2DB-C0F774E6EC32}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817302) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{E79EFFDB-192A-4D9E-A2DB-C0F774E6EC32}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2826040) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C4AEA56A-0759-4D08-9FAB-31A92137D0B8}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2837644) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D692E9FF-84BF-4F44-A0EA-D58ECE0D538E}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863843) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{290D80DE-03AB-47EC-9402-108AF4CE4F66}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880457) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EC2AF602-2730-4B05-9438-06CDE43153F2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{24584DD4-C680-4FEB-A464-D760C7A5B041}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{24584DD4-C680-4FEB-A464-D760C7A5B041}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{24584DD4-C680-4FEB-A464-D760C7A5B041}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880464) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{88B29AA5-71EE-4692-91E2-E89407F0B783}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880478) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{8116ED50-F1E7-49E1-9D8D-421497D34B0F}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{885C981B-F1E3-430A-A099-31CA9D28C251}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 64-Bit Edition (HKLM\...\{90150000-0016-0407-1000-0000000FF1CE}_Office15.PROPLUS_{885C981B-F1E3-430A-A099-31CA9D28C251}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 64-Bit Edition (HKLM\...\{90150000-0090-0407-1000-0000000FF1CE}_Office15.PROPLUS_{885C981B-F1E3-430A-A099-31CA9D28C251}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881074) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{9A479F9C-C1EC-4833-A115-A8B7A60480BD}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-0407-1000-0000000FF1CE}_Office15.PROPLUS_{00BBBFFE-8889-4953-956A-77DDE975A947}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-0409-1000-0000000FF1CE}_Office15.PROPLUS_{3A12DFA2-3FF5-450E-BDB1-A742551A5D1A}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}_Office15.PROPLUS_{EA8072E8-E3CF-46DF-A5DE-9F5975344327}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881084) 64-Bit Edition (HKLM\...\{90150000-001F-0410-1000-0000000FF1CE}_Office15.PROPLUS_{BF0D921F-E77E-4E03-BE71-46D9D2C7A36A}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881086) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{ED3A8E98-FDD4-493F-A0EC-141821573EC2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881086) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{ED3A8E98-FDD4-493F-A0EC-141821573EC2}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-00BA-0407-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2881087) 64-Bit Edition (HKLM\...\{90150000-00C1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{3C6F4768-FB23-4ECF-8328-5C47E0664B65}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BFD66A5D-F608-441E-9282-41E13F5E7412}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 64-Bit Edition (HKLM\...\{90150000-00A1-0407-1000-0000000FF1CE}_Office15.PROPLUS_{BFD66A5D-F608-441E-9282-41E13F5E7412}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BFD66A5D-F608-441E-9282-41E13F5E7412}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2880470) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{34A169EC-990A-4DAE-AC65-9F981158B7DB}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2880470) 64-Bit Edition (HKLM\...\{90150000-001A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{34A169EC-990A-4DAE-AC65-9F981158B7DB}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2881075) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C8955821-EDAC-4E65-BEF3-C9C0A049517A}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2881075) 64-Bit Edition (HKLM\...\{90150000-0018-0407-1000-0000000FF1CE}_Office15.PROPLUS_{C8955821-EDAC-4E65-BEF3-C9C0A049517A}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2880999) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{C07147B9-CC0B-4CC1-A107-A705889A54F2}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2880999) 64-Bit Edition (HKLM\...\{90150000-0019-0407-1000-0000000FF1CE}_Office15.PROPLUS_{C07147B9-CC0B-4CC1-A107-A705889A54F2}) (Version: - Microsoft) Update for Microsoft Visio 2013 (KB2837632) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{97183E08-6B06-40F1-80A9-585C4AEF98F1}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition (HKLM\...\{90150000-006E-0407-1000-0000000FF1CE}_Office15.PROPLUS_{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2878319) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{BC51FE30-3A56-4802-8D9E-E9BC05B56B49}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881005) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{125BAFEC-EB26-45C3-B97A-475162C6BDC0}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881005) 64-Bit Edition (HKLM\...\{90150000-001A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{125BAFEC-EB26-45C3-B97A-475162C6BDC0}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881005) 64-Bit Edition (HKLM\...\{90150000-001B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{125BAFEC-EB26-45C3-B97A-475162C6BDC0}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2881005) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{125BAFEC-EB26-45C3-B97A-475162C6BDC0}) (Version: - Microsoft) VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Restore Points ========================= 24-06-2014 11:51:57 Windows Update 02-07-2014 15:54:20 Geplanter Prüfpunkt 06-07-2014 23:20:09 Installed Opera 12.02. 10-07-2014 17:44:27 Windows Update 14-07-2014 13:59:58 Windows Update 15-07-2014 00:17:20 Wiederherstellungsvorgang ==================== Hosts content: ========================== 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {03BD76AE-D4BD-4667-9868-3E59606C7495} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {214141D0-4DF2-4981-BA5C-02C366107B92} - System32\Tasks\irMonitor => C:\Windows\system32\IRMonitor.exe [2014-02-04] (ITE Tech. Inc.) Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {3C85C686-7E27-4F3E-811A-7D33F5F616A2} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: {3D4059BC-231D-4208-807E-B9903EA4C7C9} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {46E51DC6-2B76-48D7-9BFC-B9FB938011F7} - \Price Meter Updater No Task File <==== ATTENTION Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {5438A397-CBD4-4E4A-99E9-CDDC04AEF4DB} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {5CECC133-6228-45BB-84DC-8F740135B95E} - System32\Tasks\OEM => C:\Windows\oem.exe [2013-12-22] () Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {736C8FC4-9B84-4B09-9F71-CC86C42E1272} - System32\Tasks\Speedfan => C:\Program Files (x86)\SpeedFan\speedfan.exe [2013-03-15] (Almico Software (www.almico.com)) Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {7FEC8443-4242-453E-B3A5-A6B7FCFA01E2} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-07-10] (Microsoft Corporation) Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {8F9410B3-0366-4AAA-9D35-97F295401A8E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {A0BDC6FE-A730-48FD-98D7-198DF80F62F3} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {A330FE4C-7D41-4AA0-96DB-115A7927D204} - \PriceMeterLiveUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {A6D3D67E-E6E4-4922-9D12-F423CCABEB2F} - \PriceMeterLiveUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {B0FAA184-96C1-45A3-9985-0D8C7ADCA1C9} - \pricemeterdownloader No Task File <==== ATTENTION Task: {B45609A7-4B1F-4345-A21D-49C54D27F93B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-28] (Google Inc.) Task: {B9082931-6747-4E43-BADA-8898A9D45DAC} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {BBD1A455-C26E-4F1B-8D80-E7977C77E39D} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3412253895-2932389450-2306418526-1001Core => C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-02-15] (Facebook Inc.) Task: {BCF1BFDA-CF2B-48A7-AB59-54E4FB46B717} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3412253895-2932389450-2306418526-1001UA => C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-02-15] (Facebook Inc.) Task: {BD01F3AA-314D-4780-87E4-EE288B19B620} - System32\Tasks\Opera scheduled Autoupdate 1405455193 => C:\Program Files (x86)\Opera\launcher.exe [2014-06-16] (Opera Software) Task: {BD849EEB-2D0B-4CED-A798-50BAA2AC7E27} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-28] (Google Inc.) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D3BF9105-8BD2-4C4E-AA06-B5AE41EE2FB6} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {DDD6DFE1-39A1-4196-AA22-2A397621DDA7} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload Task: {DE51159C-B802-40AB-BEEF-304DD28CDA3F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd) Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {ED0045F3-DCE5-467A-8920-11CE795FF0BB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3412253895-2932389450-2306418526-1001Core.job => C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3412253895-2932389450-2306418526-1001UA.job => C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-12-22 01:56 - 2013-12-22 18:45 - 00517862 _____ () C:\Windows\oem.exe 2012-09-13 01:38 - 2012-09-13 01:38 - 00264040 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe 2014-07-15 22:13 - 2014-06-16 10:24 - 01396344 _____ () C:\Program Files (x86)\Opera\22.0.1471.70_0\opera_crashreporter.exe 2014-04-14 14:26 - 2014-04-14 14:26 - 00107520 _____ () C:\Program Files (x86)\DAEMON Tools Pro\BRD.dll 2014-07-15 22:56 - 2014-07-16 16:06 - 00158720 _____ () C:\Users\Peter\AppData\Local\Temp\sfareca00001.dll 2014-07-15 22:56 - 2014-07-16 16:06 - 00192512 _____ () C:\Users\Peter\AppData\Local\Temp\sfamcc00001.dll 2014-02-04 19:30 - 2007-04-19 10:33 - 00035584 _____ () C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\uPiApi.dll 2014-02-04 19:30 - 2008-11-26 17:59 - 00131584 _____ () C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\AbilisWinUsb.dll 2014-02-04 19:30 - 2008-10-22 17:01 - 00200704 _____ () C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\VendorCmdRW.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 02144104 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 07955304 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 00341352 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 00028008 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 00127336 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll 2012-09-13 01:39 - 2012-09-13 01:39 - 00336232 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll 2014-07-15 22:13 - 2014-06-16 10:25 - 00877688 _____ () C:\Program Files (x86)\Opera\22.0.1471.70_0\libglesv2.dll 2014-07-15 22:13 - 2014-06-16 10:25 - 00135800 _____ () C:\Program Files (x86)\Opera\22.0.1471.70_0\libegl.dll 2014-07-15 22:13 - 2014-06-16 10:25 - 00957048 _____ () C:\Program Files (x86)\Opera\22.0.1471.70_0\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Peter\SkyDrive:ms-properties AlternateDataStreams: C:\Users\Peter\SkyDrive.old:ms-properties ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/16/2014 04:11:01 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/16/2014 04:06:20 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/16/2014 04:06:02 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/16/2014 03:50:00 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/16/2014 03:45:33 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/16/2014 03:45:00 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/16/2014 03:44:54 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/16/2014 04:16:05 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm LiveComm.exe, Version 17.5.9600.20498 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: c24 Startzeit: 01cfa06f369ee4d6 Endzeit: 4294967295 Anwendungspfad: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exe Berichts-ID: 22a3e616-0c8f-11e4-82a3-001e8c7a8508 Vollständiger Name des fehlerhaften Pakets: microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ppleae38af2e007f4358a809ac99a64a67c1 Error: (07/15/2014 11:01:03 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> Error: (07/15/2014 10:56:21 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: Fehler des Regelmoduls beim Ausführen einer oder mehrerer geplanter Aktionen. Fehlercode:0x80070570 Pfad:<none> Argumente:<none> System errors: ============= Error: (07/16/2014 04:11:01 PM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/16/2014 04:11:01 PM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/16/2014 04:11:01 PM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/16/2014 04:06:20 PM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/16/2014 04:06:20 PM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/16/2014 04:06:20 PM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/16/2014 04:06:06 PM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/16/2014 04:06:06 PM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/16/2014 04:06:02 PM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Error: (07/16/2014 04:06:02 PM) (Source: DCOM) (EventID: 10000) (User: NT-AUTORITÄT) Description: C:\Windows\system32\SppExtComObj.exe -Embedding1392{3C296D07-90AE-4FAC-86F9-65EAA8B82D22} Microsoft Office Sessions: ========================= Error: (07/16/2014 04:11:01 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/16/2014 04:06:20 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/16/2014 04:06:02 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/16/2014 03:50:00 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/16/2014 03:45:33 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/16/2014 03:45:00 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/16/2014 03:44:54 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/16/2014 04:16:05 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: LiveComm.exe17.5.9600.20498c2401cfa06f369ee4d64294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exe22a3e616-0c8f-11e4-82a3-001e8c7a8508microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1 Error: (07/15/2014 11:01:03 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> Error: (07/15/2014 10:56:21 PM) (Source: Software Protection Platform Service) (EventID: 8229) (User: ) Description: 0x80070570<none><none> ==================== Memory info =========================== Percentage of memory in use: 24% Total physical RAM: 6143.17 MB Available physical RAM: 4613.82 MB Total Pagefile: 7231.17 MB Available Pagefile: 5151.2 MB Total Virtual: 131072 MB Available Virtual: 131071.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:119.24 GB) (Free:58.94 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Volume) (Fixed) (Total:2794.39 GB) (Free:654.29 GB) NTFS Drive e: (Volume) (Fixed) (Total:2794.39 GB) (Free:923.3 GB) NTFS Drive g: (Volume) (Fixed) (Total:1397.26 GB) (Free:496.83 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive h: (Elements) (Fixed) (Total:1397.27 GB) (Free:1243.34 GB) NTFS Drive y: (SuperMultiBlue) (CDROM) (Total:0.67 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: D05BC153) Partition 1: (Active) - (Size=119 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 2795 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1397 GB) (Disk ID: EACF34C8) Partition 1: (Active) - (Size=-698723990528) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows XP) (Size: 1397 GB) (Disk ID: 00031DF1) Partition 1: (Not Active) - (Size=-698721378304) - (Type=07 NTFS) ======================================================== Disk: 4 (MBR Code: Windows 7 or 8) (Size: 2795 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-07-2014 Ran by Peter (administrator) on ERGO on 16-07-2014 16:15:15 Running from C:\Users\Peter\Desktop Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Windows\oem.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (My Digital Life Forums) C:\Windows\KMSEmu.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\livecomm.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe (ITE Tech. Inc.) C:\Windows\System32\IRMonitor.exe (Almico Software (www.almico.com)) C:\Program Files (x86)\SpeedFan\speedfan.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (ACD Systems) C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe (Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (André Rübel) C:\Program Files (x86)\DMEX\dmextoolmenu\dmextoolmenu.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe () C:\Program Files (x86)\Opera\22.0.1471.70_0\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Ghisler Software GmbH) C:\Program Files (x86)\totalcmd\TOTALCMD64.EXE (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ACPW07DE] => C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe [1739080 2013-09-25] (ACD Systems) HKLM\...\Run: [ACPW07EN] => C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe [1739080 2013-09-25] (ACD Systems) HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2013-04-09] (Pixart Imaging Inc) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-04-23] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.) HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [78312 2012-05-09] (cyberlink) HKLM-x32\...\Run: [CrashMon] => "C:\Program Files (x86)\Universal Updater\CrashMon.exe" "UniversalUpdater" HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-04-23] (Samsung) HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [KiesAirMessage] => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [457728 2013-09-30] (Microsoft Corporation) HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [Facebook Update] => C:\Users\Peter\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-02-15] (Facebook Inc.) HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd) HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\Run: [KiesPDLR.exe] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-04-23] (Samsung) HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\MountPoints2: {61197b53-8df7-11e3-8269-806e6f6e6963} - "Y:\AutoRun\AutoRun.exe" HKU\S-1-5-21-3412253895-2932389450-2306418526-1001\...\MountPoints2: {e6059545-c30d-11e3-828b-001e8c7a8508} - "H:\autorun.exe" IFEO\SppExtComObj.exe: [Debugger] SppHook.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk ShortcutTarget: TMMonitor.lnk -> C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.) Startup: C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DMEX Tools.lnk ShortcutTarget: DMEX Tools.lnk -> C:\Program Files (x86)\DMEX\dmextoolmenu\dmextoolmenu.exe (André Rübel) Startup: C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpeedFan.lnk ShortcutTarget: SpeedFan.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.exe (Almico Software (www.almico.com)) ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x512F766B0919CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms} BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\05znu9z3.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Peter\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (Google Docs) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-28] CHR Extension: (Google Drive) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-28] CHR Extension: (YouTube) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-28] CHR Extension: (No Name) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-06-14] CHR Extension: (Last updated at $time$ on $date$) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-12] CHR Extension: (Google Search) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-28] CHR Extension: (dict.cc context menu) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijmkoefdiklbdnfbafpgekimgkgbkfna [2014-02-12] CHR Extension: (Google Wallet) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-28] CHR Extension: (YouTube Unblocker) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl [2014-02-12] CHR Extension: (Gmail) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-28] ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [242664 2012-05-09] (CyberLink) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-09-24] (Advanced Micro Devices) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2014-01-25] () R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2014-04-14] (DT Soft Ltd) S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [165504 2014-02-04] (ITE ) S3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2014-01-25] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-16] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] () R0 SI3112r; C:\Windows\System32\DRIVERS\SI3112r.sys [133160 2007-12-26] (Silicon Image, Inc) R0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [22056 2007-12-26] (Silicon Image, Inc) R3 t_mouse.sys; C:\Windows\system32\DRIVERS\t_mouse.sys [6144 2013-04-09] () S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) R3 yukonw8; C:\Windows\system32\DRIVERS\yk63x64.sys [295216 2013-06-18] (Marvell) S3 dgderdrv; System32\drivers\dgderdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-16 16:15 - 2014-07-16 16:15 - 00016582 _____ () C:\Users\Peter\Desktop\FRST.txt 2014-07-16 06:11 - 2014-07-16 06:11 - 00001175 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-07-16 06:11 - 2014-07-16 06:11 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-07-16 06:11 - 2014-07-16 06:11 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Mozilla 2014-07-16 06:11 - 2014-07-16 06:11 - 00000000 ____D () C:\Users\Peter\AppData\Local\Mozilla 2014-07-16 06:11 - 2014-07-16 06:11 - 00000000 ____D () C:\ProgramData\Mozilla 2014-07-16 06:11 - 2014-07-16 06:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-07-15 22:56 - 2014-07-15 22:56 - 00000000 ____D () C:\ProgramData\DAEMON Tools Pro 2014-07-15 22:54 - 2014-07-15 22:47 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-07-15 22:47 - 2014-07-15 02:05 - 00007810 _____ () C:\zoek-results2014-07-15-000523.log 2014-07-15 22:44 - 2014-07-15 22:44 - 01287168 _____ () C:\Users\Peter\Desktop\zoek.exe 2014-07-15 22:42 - 2014-07-15 22:42 - 00001039 _____ () C:\Users\Peter\Desktop\aaa.txt 2014-07-15 22:19 - 2014-07-16 16:06 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-15 22:19 - 2014-07-15 22:19 - 00001118 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-15 22:19 - 2014-07-15 22:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-15 22:19 - 2014-07-15 22:19 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-15 22:19 - 2014-07-15 22:19 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-15 22:19 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-15 22:19 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-15 22:19 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-15 22:18 - 2014-07-15 22:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Peter\Desktop\mbamsetup_20730.exe 2014-07-15 22:13 - 2014-07-15 22:13 - 00003832 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1405455193 2014-07-15 22:13 - 2014-07-15 22:13 - 00001145 _____ () C:\Users\Public\Desktop\Opera.lnk 2014-07-15 22:13 - 2014-07-15 22:13 - 00001145 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-07-15 21:58 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-07-15 21:57 - 2014-07-15 21:58 - 00000000 ____D () C:\AdwCleaner 2014-07-15 21:56 - 2014-07-15 21:56 - 01348263 _____ () C:\Users\Peter\Desktop\adwcleaner_3.215.exe 2014-07-15 18:37 - 2014-07-16 16:15 - 00000000 ____D () C:\FRST 2014-07-15 18:37 - 2014-07-15 18:37 - 02086912 _____ (Farbar) C:\Users\Peter\Desktop\FRST64.exe 2014-07-15 01:57 - 2014-07-15 22:56 - 00004400 _____ () C:\zoek-results.log 2014-07-15 01:57 - 2014-07-15 22:54 - 00000000 ____D () C:\zoek_backup 2014-07-11 08:53 - 2014-07-15 22:55 - 00003374 _____ () C:\Windows\PFRO.log 2014-07-10 22:47 - 2014-07-10 22:47 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-10 19:46 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-07-10 06:03 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-07-10 06:03 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-10 06:03 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-10 06:03 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-10 06:03 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2014-07-10 06:03 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-07-10 06:03 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2014-07-10 06:03 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2014-07-10 06:03 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2014-07-10 06:03 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-07-10 06:02 - 2014-07-01 00:45 - 00688128 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-10 06:02 - 2014-06-28 09:48 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-07-10 06:02 - 2014-06-28 09:07 - 00385536 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-07-10 06:02 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-10 06:02 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-10 06:02 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-10 06:02 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-10 06:02 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-10 06:02 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-10 06:02 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-10 06:02 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-10 06:02 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-10 06:02 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-10 06:02 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-10 06:02 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-10 06:02 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-10 06:02 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-10 06:02 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-10 06:02 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-10 06:02 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-10 06:02 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-10 06:02 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-10 06:02 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-10 06:02 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-10 06:02 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-10 06:02 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-10 06:02 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-07-10 06:02 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-10 06:02 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-10 06:02 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-07-10 06:02 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-10 06:02 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-10 06:02 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-07-10 06:02 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll 2014-07-10 06:02 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2014-07-10 06:02 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2014-07-10 06:02 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-10 06:02 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-07-10 06:02 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-07-10 06:02 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-10 06:02 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-07-10 06:02 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-07-10 06:02 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-07-10 06:02 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll 2014-07-10 06:02 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2014-07-10 06:02 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll 2014-07-10 06:02 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2014-07-10 05:59 - 2014-07-10 05:59 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\WSReset.exe 2014-07-01 18:25 - 2014-07-16 16:05 - 01342257 _____ () C:\Windows\WindowsUpdate.log 2014-06-26 12:23 - 2012-12-22 21:09 - 00444928 _____ (Alex Schepeljanski) C:\Users\Peter\Desktop\AS SSD Benchmark.exe 2014-06-17 17:02 - 2014-06-17 17:02 - 00001007 _____ () C:\Users\Peter\Desktop\MakeMKV.lnk 2014-06-17 17:02 - 2014-06-17 17:02 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MakeMKV 2014-06-17 17:02 - 2014-06-17 17:02 - 00000000 ____D () C:\Program Files (x86)\MakeMKV 2014-06-17 04:35 - 2014-06-17 04:35 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-06-17 04:35 - 2014-06-17 04:35 - 00000834 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-06-17 04:35 - 2014-06-17 04:35 - 00000000 ____D () C:\Program Files\CCleaner ==================== One Month Modified Files and Folders ======= 2014-07-16 16:15 - 2014-07-16 16:15 - 00016582 _____ () C:\Users\Peter\Desktop\FRST.txt 2014-07-16 16:15 - 2014-07-15 18:37 - 00000000 ____D () C:\FRST 2014-07-16 16:11 - 2014-01-24 15:37 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3412253895-2932389450-2306418526-1001 2014-07-16 16:10 - 2013-12-22 14:54 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-16 16:10 - 2013-09-30 05:58 - 00764340 _____ () C:\Windows\system32\perfh007.dat 2014-07-16 16:10 - 2013-09-30 05:58 - 00159160 _____ () C:\Windows\system32\perfc007.dat 2014-07-16 16:06 - 2014-07-15 22:19 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-16 16:06 - 2014-02-05 01:05 - 00000000 __RDO () C:\Users\Peter\SkyDrive 2014-07-16 16:06 - 2014-02-04 19:25 - 00000048 _____ () C:\monitor.log 2014-07-16 16:06 - 2014-01-28 08:23 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-16 16:06 - 2014-01-24 23:06 - 00000000 ____D () C:\Program Files (x86)\SpeedFan 2014-07-16 16:05 - 2014-07-01 18:25 - 01342257 _____ () C:\Windows\WindowsUpdate.log 2014-07-16 16:05 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-16 16:05 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-07-16 16:03 - 2014-01-24 15:38 - 00000000 ____D () C:\instmp 2014-07-16 16:03 - 2014-01-24 15:37 - 00003914 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{BDA3291A-B02F-4BBA-98C9-5BFD405CE7DF} 2014-07-16 16:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru 2014-07-16 15:55 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness 2014-07-16 15:53 - 2014-01-28 08:23 - 00001118 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-16 06:17 - 2014-01-24 15:56 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\vlc 2014-07-16 06:12 - 2014-06-11 18:36 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-07-16 06:11 - 2014-07-16 06:11 - 00001175 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-07-16 06:11 - 2014-07-16 06:11 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-07-16 06:11 - 2014-07-16 06:11 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Mozilla 2014-07-16 06:11 - 2014-07-16 06:11 - 00000000 ____D () C:\Users\Peter\AppData\Local\Mozilla 2014-07-16 06:11 - 2014-07-16 06:11 - 00000000 ____D () C:\ProgramData\Mozilla 2014-07-16 06:11 - 2014-07-16 06:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-07-16 06:11 - 2014-01-27 23:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-07-16 05:38 - 2014-01-27 12:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-16 04:50 - 2014-02-15 11:45 - 00000938 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3412253895-2932389450-2306418526-1001UA.job 2014-07-16 04:20 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\LiveKernelReports 2014-07-15 22:56 - 2014-07-15 22:56 - 00000000 ____D () C:\ProgramData\DAEMON Tools Pro 2014-07-15 22:56 - 2014-07-15 01:57 - 00004400 _____ () C:\zoek-results.log 2014-07-15 22:56 - 2014-01-24 15:29 - 00000000 ____D () C:\Users\Peter 2014-07-15 22:55 - 2014-07-11 08:53 - 00003374 _____ () C:\Windows\PFRO.log 2014-07-15 22:54 - 2014-07-15 01:57 - 00000000 ____D () C:\zoek_backup 2014-07-15 22:47 - 2014-07-15 22:54 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-07-15 22:44 - 2014-07-15 22:44 - 01287168 _____ () C:\Users\Peter\Desktop\zoek.exe 2014-07-15 22:42 - 2014-07-15 22:42 - 00001039 _____ () C:\Users\Peter\Desktop\aaa.txt 2014-07-15 22:19 - 2014-07-15 22:19 - 00001118 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-15 22:19 - 2014-07-15 22:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-15 22:19 - 2014-07-15 22:19 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-15 22:19 - 2014-07-15 22:19 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-15 22:18 - 2014-07-15 22:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Peter\Desktop\mbamsetup_20730.exe 2014-07-15 22:13 - 2014-07-15 22:13 - 00003832 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1405455193 2014-07-15 22:13 - 2014-07-15 22:13 - 00001145 _____ () C:\Users\Public\Desktop\Opera.lnk 2014-07-15 22:13 - 2014-07-15 22:13 - 00001145 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-07-15 22:13 - 2014-01-24 15:39 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-07-15 22:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF 2014-07-15 22:04 - 2014-02-07 20:27 - 00032256 ___SH () C:\Users\Peter\Documents\Thumbs.db 2014-07-15 21:58 - 2014-07-15 21:57 - 00000000 ____D () C:\AdwCleaner 2014-07-15 21:56 - 2014-07-15 21:56 - 01348263 _____ () C:\Users\Peter\Desktop\adwcleaner_3.215.exe 2014-07-15 18:37 - 2014-07-15 18:37 - 02086912 _____ (Farbar) C:\Users\Peter\Desktop\FRST64.exe 2014-07-15 18:35 - 2014-01-24 16:21 - 00000000 ____D () C:\JDownloader 2014-07-15 10:50 - 2014-02-15 11:45 - 00000916 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3412253895-2932389450-2306418526-1001Core.job 2014-07-15 02:25 - 2014-01-28 08:23 - 00000000 ____D () C:\Program Files (x86)\Google 2014-07-15 02:20 - 2014-01-24 15:35 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\GHISLER 2014-07-15 02:20 - 2013-12-22 15:05 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-07-15 02:19 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\registration 2014-07-15 02:18 - 2013-12-22 15:01 - 00000000 ____D () C:\Program Files\Microsoft Office 2014-07-15 02:05 - 2014-07-15 22:47 - 00007810 _____ () C:\zoek-results2014-07-15-000523.log 2014-07-14 16:00 - 2013-12-22 15:01 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-07-12 10:46 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache 2014-07-11 08:53 - 2013-08-22 16:44 - 00473776 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-10 22:47 - 2014-07-10 22:47 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-10 22:47 - 2013-09-30 06:00 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-10 22:47 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData 2014-07-10 22:47 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-10 22:47 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-10 22:47 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore 2014-07-10 19:49 - 2014-01-27 05:08 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-10 19:49 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp 2014-07-10 19:48 - 2014-01-27 05:08 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-10 19:48 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-07-10 06:08 - 2014-01-24 15:38 - 00000000 ____D () C:\Users\Peter\AppData\Local\GHISLER 2014-07-10 05:59 - 2014-07-10 05:59 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\WSReset.exe 2014-07-08 18:38 - 2014-01-27 12:38 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-07-01 22:41 - 2014-02-11 01:43 - 00042496 ___SH () C:\Users\Peter\Desktop\Thumbs.db 2014-07-01 00:45 - 2014-07-10 06:02 - 00688128 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-30 05:14 - 2014-01-24 15:39 - 00000000 ____D () C:\Program Files\Common Files\logishrd 2014-06-30 05:13 - 2014-01-29 16:10 - 00000000 ____D () C:\ProgramData\LogiShrd 2014-06-30 05:13 - 2014-01-29 16:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2014-06-28 09:48 - 2014-07-10 06:02 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-28 09:07 - 2014-07-10 06:02 - 00385536 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-06-26 22:55 - 2013-08-22 17:38 - 00703968 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:55 - 2013-08-22 17:38 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-26 22:32 - 2014-01-25 04:54 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\dvdcss 2014-06-19 03:39 - 2014-07-10 06:02 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-19 02:48 - 2014-07-10 06:02 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-19 02:16 - 2014-07-10 06:02 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-19 02:09 - 2014-07-10 06:02 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-19 01:51 - 2014-07-10 06:02 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-19 01:50 - 2014-07-10 06:02 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-19 01:48 - 2014-07-10 06:02 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-19 01:46 - 2014-07-10 06:02 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-06-19 01:39 - 2014-07-10 06:02 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-19 01:33 - 2014-07-10 06:02 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-19 01:32 - 2014-07-10 06:02 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-19 01:27 - 2014-07-10 06:02 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-19 01:12 - 2014-07-10 06:02 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-19 00:59 - 2014-07-10 06:02 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-19 00:58 - 2014-07-10 06:02 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-19 00:58 - 2014-07-10 06:02 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-19 00:57 - 2014-07-10 06:02 - 00225280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-06-19 00:52 - 2014-07-10 06:02 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-19 00:51 - 2014-07-10 06:02 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-19 00:49 - 2014-07-10 06:02 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-19 00:45 - 2014-07-10 06:02 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-19 00:35 - 2014-07-10 06:02 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-19 00:34 - 2014-07-10 06:02 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-19 00:15 - 2014-07-10 06:02 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-19 00:13 - 2014-07-10 06:02 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-19 00:09 - 2014-07-10 06:02 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-19 00:07 - 2014-07-10 06:02 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-06-17 17:02 - 2014-06-17 17:02 - 00001007 _____ () C:\Users\Peter\Desktop\MakeMKV.lnk 2014-06-17 17:02 - 2014-06-17 17:02 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MakeMKV 2014-06-17 17:02 - 2014-06-17 17:02 - 00000000 ____D () C:\Program Files (x86)\MakeMKV 2014-06-17 10:48 - 2014-01-28 08:23 - 00004090 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-17 10:48 - 2014-01-28 08:23 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-17 04:36 - 2014-04-14 14:25 - 00000000 ____D () C:\Users\Peter\AppData\Roaming\DAEMON Tools Pro 2014-06-17 04:36 - 2014-02-04 18:31 - 00000000 ____D () C:\Windows\Minidump 2014-06-17 04:36 - 2013-12-22 14:33 - 00000000 ____D () C:\Windows\Panther 2014-06-17 04:35 - 2014-06-17 04:35 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-06-17 04:35 - 2014-06-17 04:35 - 00000834 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-06-17 04:35 - 2014-06-17 04:35 - 00000000 ____D () C:\Program Files\CCleaner 2014-06-17 00:26 - 2014-07-10 06:03 - 00779264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-06-17 00:24 - 2014-07-10 06:03 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-06-16 20:05 - 2014-01-24 15:30 - 00000000 ____D () C:\Users\Peter\AppData\Local\Packages Some content of TEMP: ==================== C:\Users\Peter\AppData\Local\Temp\sfamcc00001.dll C:\Users\Peter\AppData\Local\Temp\sfareca00001.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-08 09:46 ==================== End Of Log ============================ --- --- --- Kannst Du mir nochmal eben erklären was das für ein Mistvieh ist und wo das herkommt? Ich habe seit Jahren keinen Schädling mehr gehabt. Geändert von Chagall1985 (16.07.2014 um 15:16 Uhr) |
16.07.2014, 17:25 | #6 | |
/// TB-Ausbilder | Doppelt grün unterstrichener WerbemüllZitat:
Gibt es noch Probleme mit Werbung? Wenn ja, in welchem Browser? Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 3 h) dauern. Im Anschluss entfernen wir alle verwendeten Tools und ich gebe dir noch ein paar Tipps mit auf den Weg. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start IFEO\SppExtComObj.exe: [Debugger] SppHook.exe Task: {A330FE4C-7D41-4AA0-96DB-115A7927D204} - \PriceMeterLiveUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {A6D3D67E-E6E4-4922-9D12-F423CCABEB2F} - \PriceMeterLiveUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {B0FAA184-96C1-45A3-9985-0D8C7ADCA1C9} - \pricemeterdownloader No Task File <==== ATTENTION Task: {46E51DC6-2B76-48D7-9BFC-B9FB938011F7} - \Price Meter Updater No Task File <==== ATTENTION Reboot: end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 ESET Online Scanner
Schritt 3 Downloade Dir bitte SecurityCheck und:
Schritt 4
Bitte poste mit deiner nächsten Antwort
|
20.07.2014, 09:21 | #7 |
/// TB-Ausbilder | Doppelt grün unterstrichener Werbemüll Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen! |
Themen zu Doppelt grün unterstrichener Werbemüll |
anleitungen, bli, blind, branding, brauche, cpu-z, dankbar, doppel, doppelt, dvdvideosoft ltd., folge, hilfe, onedrive, outlook 2013, programm, rechner, segen, stark, troja, trojaner, unterscheiden, verschiedene, werbemüll, werbung, windowsapps |