|
Log-Analyse und Auswertung: Windows 8.1: Werbe-Popups in Google Chrome und OperaWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
21.07.2014, 08:56 | #1 |
| Windows 8.1: Werbe-Popups in Google Chrome und Opera Guten Morgen! Seit Ende letzter Woche habe ich das nervige Problem das in Google Chrome und auch Opera ständig Werbe-Popups aufgehen. Es sind verschieden Seiten die aufgehen, 123srv, ein angebliches Java Update, Alldaysavings...! Das installierte Kaspersky Internet Security meckert nicht! Auf manchen Seiten erscheinen auch Werbebanner in Form von kleinen Fenstern! Habe jetzt alles wie in der Anleitung beschrieben durchgeführt! Unten dann die Logfiles. GMER funktioniert nicht richtig, startet zwar meldet dann aber "C:/Windows/system32/config/system: Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird" Dann lässt es mich den Scan durchführen und danach kommt die selbe Meldung. Logfile ist auch unten! Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 09:22 on 21/07/2014 (Florian-KFZMeister) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014 Ran by Florian-KFZMeister (administrator) on WERKSTATT-PC on 21-07-2014 09:25:52 Running from C:\Users\Florian-KFZMeister\Desktop Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Program Files\005\cyycfhtzro64.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe () C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe (WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\livecomm.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191824 2012-08-10] (Realtek Semiconductor) HKLM\...\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [766080 2012-12-05] (Qualcomm Atheros) HKLM\...\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [128640 2012-12-05] (Atheros Communications) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2917688 2012-10-16] (Synaptics Incorporated) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2014-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [97392 2012-08-15] (CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation) HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de) HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe [24504 2012-12-14] (Kaspersky Lab ZAO) HKLM-x32\...\Run: [StartDDM] => C:\Program Files (x86)\Bosch\DownloadManager\bin\runDDM.exe [260608 2012-02-10] (Robert Bosch GmbH) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-18] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1825984 2014-04-24] (Valve Corporation) HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Florian-KFZMeister\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHel (the data entry has 8 more characters). HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [Amazon Cloud Player] => C:\Users\Florian-KFZMeister\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2013-12-12] () HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Policies\system: [DisableLockWorkstation] 0 IFEO: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung13.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com SearchScopes: HKLM - DefaultScope {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS SearchScopes: HKLM - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKLM-x32 - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS SearchScopes: HKCU - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) DPF: HKLM-x32 {55369874-02F5-47E2-A0F7-AC67E1B1866E} hxxp://www.centrodigital.de/smart/setup.ocx Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Florian-KFZMeister\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Florian-KFZMeister\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-05-15] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-05-15] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-05-15] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013-05-15] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013-05-15] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://www.google.com/" CHR Extension: (Google Docs) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-23] CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-01-23] CHR Extension: (Sicherer Zahlungsverkehr) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-01-23] CHR Extension: (Modul für das Blockieren gefährlicher Webseiten) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-01-23] CHR Extension: (Virtuelle Tastatur) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-01-23] CHR Extension: (Google Wallet) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-23] CHR Extension: (Anti-Banner) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-01-23] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-12-14] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-12-14] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-12-14] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2013-05-15] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-12-14] ==================== Services (Whitelisted) ================= R2 AllDaySavingsService64; C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe [172544 2014-07-10] () [File not signed] S4 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [231552 2012-12-05] (Qualcomm Atheros Commnucations) S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) R2 cyycfhtzro64; C:\Program Files\005\cyycfhtzro64.exe [709120 2014-07-16] () [File not signed] R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593976 2012-09-05] (Samsung Electronics CO., LTD.) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 Simraceway Update Service; C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe [1630720 2013-07-11] () [File not signed] S4 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2412344 2014-01-28] (TuneUp Software) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) S4 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-05] (Atheros) [File not signed] ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-21] (Advanced Micro Devices, Inc.) R3 BTATH_HID; C:\Windows\system32\DRIVERS\btath_hid.sys [222360 2012-12-05] (Qualcomm Atheros) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-05] (Qualcomm Atheros) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) S3 CH341SER_A64; C:\Windows\System32\Drivers\CH341S64.SYS [58368 2011-11-04] (www.winchiphead.com) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [146856 2013-06-04] (Windows (R) Win 7 DDK provider) R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [21928 2013-06-04] (Windows (R) Win 7 DDK provider) S3 IntcDAud; C:\Windows\system32\DRIVERS\IntcDAud.sys [342528 2012-06-19] (Intel(R) Corporation) [File not signed] S3 intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [5338848 2012-09-17] (Intel Corporation) [File not signed] R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [627296 2014-05-20] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-12-11] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2013-05-15] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2013-05-15] (Kaspersky Lab ZAO) R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-07-10] (NetFilterSDK.com) R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-11-16] (TuneUp Software) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) U3 kgloquow; \??\C:\Users\FLORIA~1\AppData\Local\Temp\kgloquow.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-21 09:46 - 2014-07-21 09:46 - 00007268 _____ () C:\Users\Florian-KFZMeister\Desktop\GMER.log 2014-07-21 09:29 - 2014-07-21 09:29 - 704339485 _____ () C:\WINDOWS\MEMORY.DMP 2014-07-21 09:29 - 2014-07-21 09:29 - 00299272 _____ () C:\WINDOWS\Minidump\072114-35515-01.dmp 2014-07-21 09:29 - 2014-07-21 09:29 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-21 09:25 - 2014-07-21 09:49 - 00021583 _____ () C:\Users\Florian-KFZMeister\Desktop\FRST.txt 2014-07-21 09:25 - 2014-07-21 09:49 - 00000000 ____D () C:\FRST 2014-07-21 09:25 - 2014-07-21 09:26 - 00053834 _____ () C:\Users\Florian-KFZMeister\Desktop\Addition.txt 2014-07-21 09:24 - 2014-07-21 09:32 - 00000498 _____ () C:\Users\Florian-KFZMeister\Desktop\defogger_disable.log 2014-07-21 09:24 - 2014-07-21 09:24 - 00000000 _____ () C:\Users\Florian-KFZMeister\defogger_reenable 2014-07-21 09:22 - 2014-07-21 09:22 - 02089984 _____ (Farbar) C:\Users\Florian-KFZMeister\Desktop\FRST64.exe 2014-07-21 09:22 - 2014-07-21 09:22 - 00380416 _____ () C:\Users\Florian-KFZMeister\Desktop\8kgufznd.exe 2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe 2014-07-21 09:00 - 2014-07-21 09:00 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-07-21 08:59 - 2014-07-21 08:59 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe 2014-07-21 08:59 - 2014-07-21 08:59 - 02088532 _____ () C:\Users\Florian-KFZMeister\Downloads\FRST64.exe 2014-07-19 08:41 - 2014-07-19 08:41 - 00000000 ____H () C:\ProgramData\cm-lock 2014-07-19 08:31 - 2014-07-19 08:31 - 00000697 _____ () C:\Users\Florian-KFZMeister\Desktop\JRT.txt 2014-07-19 08:28 - 2014-07-19 08:28 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-07-19 08:13 - 2014-07-19 08:13 - 00003228 _____ () C:\WINDOWS\System32\Tasks\{195AC1F4-9216-4E5D-970E-EE662B1F6FAB} 2014-07-19 08:10 - 2014-07-19 08:10 - 01707144 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer (1).exe 2014-07-19 08:08 - 2014-07-21 09:35 - 00000000 ____D () C:\Program Files\AllDaySavings 2014-07-19 08:05 - 2014-07-19 08:05 - 00822568 _____ (Reimage®) C:\Users\Florian-KFZMeister\Downloads\ReimageRepair.exe 2014-07-19 08:03 - 2014-07-19 08:04 - 01705692 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer.exe 2014-07-19 07:51 - 2014-07-19 07:51 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LavasoftStatistics 2014-07-19 07:50 - 2014-07-19 07:50 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-07-19 07:43 - 2014-07-19 07:43 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-07-18 17:17 - 2014-07-19 08:40 - 00004440 _____ () C:\WINDOWS\PFRO.log 2014-07-18 17:17 - 2014-07-18 17:18 - 00491000 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-07-18 17:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll 2014-07-18 17:13 - 2014-07-19 08:39 - 00000000 ____D () C:\AdwCleaner 2014-07-18 12:28 - 2014-07-19 07:57 - 00003496 _____ () C:\WINDOWS\System32\Tasks\Reimage Reminder 2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Reimage Protector 2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair 2014-07-18 12:16 - 2014-07-18 12:28 - 00000000 ____D () C:\rei 2014-07-18 12:15 - 2014-07-18 12:28 - 00000163 _____ () C:\WINDOWS\Reimage.ini 2014-07-18 09:07 - 2014-07-18 09:07 - 00000000 _____ () C:\Users\Florian-KFZMeister\com.attensity.bosch.esi.updateclient.StartUpdateClient.tmp 2014-07-16 11:55 - 2014-07-17 07:20 - 00000000 ____D () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131 2014-07-16 11:54 - 2014-07-16 11:54 - 00000000 ____D () C:\Program Files\005 2014-07-14 08:31 - 2014-07-14 08:31 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\.eva 2014-07-14 08:29 - 2014-07-14 08:29 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Daimler 2014-07-10 21:40 - 2014-07-10 21:40 - 00046376 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\netfilter64.sys 2014-07-09 07:58 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll 2014-07-09 07:43 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe 2014-07-09 07:43 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe 2014-07-09 07:43 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2014-07-09 07:43 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2014-07-09 07:43 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2014-07-09 07:43 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 2014-07-09 07:43 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll 2014-07-09 07:43 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2014-07-09 07:43 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2014-07-09 07:43 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2014-07-09 07:42 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-07-09 07:42 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-07-09 07:42 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-07-09 07:42 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 2014-07-09 07:42 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-07-09 07:42 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-07-09 07:42 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2014-07-09 07:42 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2014-07-09 07:42 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-07-09 07:42 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-07-09 07:42 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-07-09 07:42 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2014-07-09 07:42 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-07-09 07:42 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-07-09 07:42 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-07-09 07:42 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2014-07-09 07:42 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-07-09 07:42 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-07-09 07:42 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-07-09 07:42 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-07-09 07:42 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-07-09 07:42 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-07-09 07:42 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-07-09 07:42 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-07-09 07:42 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-07-09 07:42 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-07-09 07:42 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-07-09 07:42 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll 2014-07-09 07:42 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll 2014-07-09 07:42 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2014-07-09 07:42 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2014-07-09 07:42 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2014-07-09 07:42 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2014-07-09 07:42 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 07:42 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2014-07-09 07:42 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2014-07-09 07:42 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 07:42 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2014-07-09 07:42 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2014-07-09 07:42 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2014-07-09 07:42 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2014-07-09 07:42 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2014-07-09 07:42 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2014-07-09 07:42 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2014-06-30 13:53 - 2014-06-30 13:53 - 00001674 _____ () C:\Users\Florian-KFZMeister\AppData\Local\recently-used.xbel 2014-06-30 13:44 - 2014-07-19 07:53 - 00000000 ____D () C:\Users\Florian-KFZMeister\Downloads\Musikjunkie - Guano Apes 2014 Offline Bitrate VBR 04 Numen ==================== One Month Modified Files and Folders ======= 2014-07-21 09:50 - 2014-07-21 09:25 - 00021583 _____ () C:\Users\Florian-KFZMeister\Desktop\FRST.txt 2014-07-21 09:49 - 2014-07-21 09:25 - 00000000 ____D () C:\FRST 2014-07-21 09:46 - 2014-07-21 09:46 - 00007268 _____ () C:\Users\Florian-KFZMeister\Desktop\GMER.log 2014-07-21 09:46 - 2013-04-14 11:43 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2830974330-3213038589-3334289725-1002 2014-07-21 09:35 - 2014-07-19 08:08 - 00000000 ____D () C:\Program Files\AllDaySavings 2014-07-21 09:35 - 2013-10-30 13:04 - 01576606 _____ () C:\WINDOWS\WindowsUpdate.log 2014-07-21 09:35 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-07-21 09:34 - 2013-09-30 06:14 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-07-21 09:34 - 2013-09-30 05:56 - 00766620 _____ () C:\WINDOWS\system32\perfh007.dat 2014-07-21 09:34 - 2013-09-30 05:56 - 00159902 _____ () C:\WINDOWS\system32\perfc007.dat 2014-07-21 09:33 - 2013-05-15 10:19 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-07-21 09:32 - 2014-07-21 09:24 - 00000498 _____ () C:\Users\Florian-KFZMeister\Desktop\defogger_disable.log 2014-07-21 09:32 - 2014-01-23 12:31 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-21 09:31 - 2014-01-23 12:30 - 00001156 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-21 09:30 - 2014-04-17 11:11 - 00000000 __RDO () C:\Users\Florian-KFZMeister\SkyDrive 2014-07-21 09:30 - 2013-04-15 09:52 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\FreePDF_XP 2014-07-21 09:30 - 2012-11-26 08:01 - 00000868 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-07-21 09:29 - 2014-07-21 09:29 - 704339485 _____ () C:\WINDOWS\MEMORY.DMP 2014-07-21 09:29 - 2014-07-21 09:29 - 00299272 _____ () C:\WINDOWS\Minidump\072114-35515-01.dmp 2014-07-21 09:29 - 2014-07-21 09:29 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-21 09:29 - 2013-10-30 12:44 - 00000000 ____D () C:\Users\Florian-KFZMeister 2014-07-21 09:29 - 2013-10-30 10:43 - 00000064 __RSH () C:\WINDOWS\system32\Drivers\VSTXRAID.winsecurity 2014-07-21 09:29 - 2013-10-30 10:14 - 00000064 __RSH () C:\WINDOWS\system32\Drivers\WUDFPf.winsecurity 2014-07-21 09:29 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-07-21 09:29 - 2013-08-06 13:50 - 00599635 _____ () C:\Simraceway.log 2014-07-21 09:26 - 2014-07-21 09:25 - 00053834 _____ () C:\Users\Florian-KFZMeister\Desktop\Addition.txt 2014-07-21 09:24 - 2014-07-21 09:24 - 00000000 _____ () C:\Users\Florian-KFZMeister\defogger_reenable 2014-07-21 09:22 - 2014-07-21 09:22 - 02089984 _____ (Farbar) C:\Users\Florian-KFZMeister\Desktop\FRST64.exe 2014-07-21 09:22 - 2014-07-21 09:22 - 00380416 _____ () C:\Users\Florian-KFZMeister\Desktop\8kgufznd.exe 2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe 2014-07-21 09:03 - 2014-01-23 12:31 - 00001160 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-21 09:00 - 2014-07-21 09:00 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-07-21 09:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-07-21 08:59 - 2014-07-21 08:59 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe 2014-07-21 08:59 - 2014-07-21 08:59 - 02088532 _____ () C:\Users\Florian-KFZMeister\Downloads\FRST64.exe 2014-07-21 08:27 - 2013-12-13 13:46 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LumacDaemon 2014-07-21 08:17 - 2014-03-03 13:54 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Battle.net 2014-07-19 09:56 - 2012-11-26 08:09 - 00000000 ____D () C:\ProgramData\WinClon 2014-07-19 08:41 - 2014-07-19 08:41 - 00000000 ____H () C:\ProgramData\cm-lock 2014-07-19 08:40 - 2014-07-18 17:17 - 00004440 _____ () C:\WINDOWS\PFRO.log 2014-07-19 08:40 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2014-07-19 08:39 - 2014-07-18 17:13 - 00000000 ____D () C:\AdwCleaner 2014-07-19 08:31 - 2014-07-19 08:31 - 00000697 _____ () C:\Users\Florian-KFZMeister\Desktop\JRT.txt 2014-07-19 08:28 - 2014-07-19 08:28 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-07-19 08:13 - 2014-07-19 08:13 - 00003228 _____ () C:\WINDOWS\System32\Tasks\{195AC1F4-9216-4E5D-970E-EE662B1F6FAB} 2014-07-19 08:10 - 2014-07-19 08:10 - 01707144 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer (1).exe 2014-07-19 08:05 - 2014-07-19 08:05 - 00822568 _____ (Reimage®) C:\Users\Florian-KFZMeister\Downloads\ReimageRepair.exe 2014-07-19 08:04 - 2014-07-19 08:03 - 01705692 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer.exe 2014-07-19 08:01 - 2013-08-24 08:39 - 00000000 ____D () C:\Games 2014-07-19 07:57 - 2014-07-18 12:28 - 00003496 _____ () C:\WINDOWS\System32\Tasks\Reimage Reminder 2014-07-19 07:53 - 2014-06-30 13:44 - 00000000 ____D () C:\Users\Florian-KFZMeister\Downloads\Musikjunkie - Guano Apes 2014 Offline Bitrate VBR 04 Numen 2014-07-19 07:51 - 2014-07-19 07:51 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LavasoftStatistics 2014-07-19 07:50 - 2014-07-19 07:50 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-07-19 07:43 - 2014-07-19 07:43 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-07-19 07:40 - 2013-04-15 08:19 - 00000000 ____D () C:\KfzKaufmann 2014-07-19 07:30 - 2013-07-12 17:24 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\re 2014-07-18 17:18 - 2014-07-18 17:17 - 00491000 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-07-18 17:17 - 2013-04-15 08:37 - 00000000 ____D () C:\Users\Florian-KFZMeister\.thumbnails 2014-07-18 17:12 - 2013-03-28 17:40 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\repline 2014-07-18 15:55 - 2012-11-26 08:01 - 00000870 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-07-18 13:01 - 2013-09-19 08:20 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\vlc 2014-07-18 12:28 - 2014-07-18 12:16 - 00000000 ____D () C:\rei 2014-07-18 12:28 - 2014-07-18 12:15 - 00000163 _____ () C:\WINDOWS\Reimage.ini 2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Reimage Protector 2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair 2014-07-18 09:07 - 2014-07-18 09:07 - 00000000 _____ () C:\Users\Florian-KFZMeister\com.attensity.bosch.esi.updateclient.StartUpdateClient.tmp 2014-07-17 13:56 - 2014-04-16 10:02 - 00000000 ____D () C:\ProgramData\WarThunder 2014-07-17 07:29 - 2013-06-11 09:43 - 00000000 ____D () C:\ProgramData\Bosch 2014-07-17 07:28 - 2013-06-11 09:43 - 00000488 _____ () C:\WINDOWS\RbSystem.ini 2014-07-17 07:20 - 2014-07-16 11:55 - 00000000 ____D () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131 2014-07-16 17:11 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF 2014-07-16 12:06 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-07-16 11:54 - 2014-07-16 11:54 - 00000000 ____D () C:\Program Files\005 2014-07-16 07:13 - 2014-04-16 10:02 - 00000000 ____D () C:\Program Files (x86)\WarThunder 2014-07-14 16:39 - 2013-04-24 10:52 - 00133799 _____ () C:\Users\Florian-KFZMeister\ewa_client_0.log 2014-07-14 16:39 - 2013-04-24 10:52 - 00000000 ____D () C:\Users\Florian-KFZMeister\XFER 2014-07-14 16:24 - 2013-04-24 10:52 - 00000122 _____ () C:\Users\Florian-KFZMeister\.ewanapi_cookie 2014-07-14 08:55 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-07-14 08:31 - 2014-07-14 08:31 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\.eva 2014-07-14 08:29 - 2014-07-14 08:29 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Daimler 2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore 2014-07-10 21:40 - 2014-07-10 21:40 - 00046376 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\netfilter64.sys 2014-07-10 17:42 - 2014-03-03 13:54 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-07-09 08:03 - 2013-04-14 20:50 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-07-09 08:03 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2014-07-09 08:02 - 2013-07-23 09:05 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-07-09 08:00 - 2013-04-15 07:41 - 96441528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-07-09 07:58 - 2013-09-30 05:59 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-08 08:05 - 2014-03-03 13:55 - 00000000 ____D () C:\Program Files (x86)\Diablo III 2014-07-04 13:02 - 2014-01-23 17:12 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\Schaltpläne 2014-07-02 16:35 - 2013-06-19 10:56 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\Formulare und Vorlagen 2014-06-30 13:53 - 2014-06-30 13:53 - 00001674 _____ () C:\Users\Florian-KFZMeister\AppData\Local\recently-used.xbel 2014-06-30 13:53 - 2013-04-15 08:36 - 00000000 ____D () C:\Users\Florian-KFZMeister\.gimp-2.8 2014-06-30 08:50 - 2013-09-16 07:27 - 00002487 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-06-30 08:50 - 2013-09-16 07:27 - 00002039 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk 2014-06-26 22:55 - 2014-04-30 08:06 - 00703968 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:55 - 2014-04-30 08:06 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-25 17:58 - 2014-01-23 12:31 - 00004132 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-25 17:58 - 2014-01-23 12:30 - 00003896 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-23 10:16 - 2013-04-14 11:49 - 00001382 _____ () C:\Users\Public\Desktop\CENTROdigital SmartClient.lnk Files to move or delete: ==================== C:\ProgramData\MakeMarkerFile.exe C:\Users\EasySurvey\EasySurvey.exe Some content of TEMP: ==================== C:\Users\Florian-KFZMeister\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-19 08:52 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-07-2014 Ran by Florian-KFZMeister at 2014-07-21 09:25:52 Running from C:\Users\Florian-KFZMeister\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Kaspersky Internet Security (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.125 - Adobe Systems Incorporated) Adobe Reader X (10.1.10) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.10 - Adobe Systems Incorporated) Adobe SVG Viewer 3.0 (HKLM-x32\...\Adobe SVG Viewer) (Version: 3.0 - ) AllSharePlayLink (HKLM-x32\...\{CE1836A8-3F2B-49BD-8395-93DD414068D2}) (Version: 1.0.0 - Samsung Electronics Co., Ltd.) Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.2.0.399 - Amazon Services LLC) Amazon MP3-Downloader 1.0.18 (HKCU\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC) AMD Accelerated Video Transcoding (Version: 13.15.100.30918 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2013.0918.1802.30548 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{4BA4F2F5-F19F-AF23-DE7C-F417B7E78B51}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Artcut2009 (HKLM-x32\...\{FA01D751-CE47-4533-BB5D-9BB34514A43B}) (Version: 7.0 - Beijing Wentai Technology Co. Ltd) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Bierbuden Autoupdate (remove only) (HKCU\...\Bierbuden Autoupdate) (Version: - ) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Bosch Diagnostic Download Manager (HKLM-x32\...\{8A0A5999-CABE-402F-8527-88B5995DA5EC}) (Version: 2.1.3 (2013-04-10_414) - Robert Bosch GmbH) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.0918.1802.30548 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.0918.1802.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.0918.1802.30548 - Advanced Micro Devices, Inc.) Hidden CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.4003 - CDBurnerXP) CENTROdigital SmartClient (HKLM-x32\...\{78046543-DBBE-4CBC-B7DB-AC608221E29C}) (Version: 14.03.000 - vidicom) CodeMeter Runtime Kit v4.50c (HKLM\...\{D2ABD3EE-94BD-48BB-A6C6-E4FFDA64001E}) (Version: 4.50.906.503 - WIBU-SYSTEMS AG) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.0.1912 - CyberLink Corp.) CyberLink Power2Go 8 (x32 Version: 8.0.0.1912 - CyberLink Corp.) Hidden CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4421.02 - CyberLink Corp.) CyberLink PowerDVD 10 (x32 Version: 10.0.4421.02 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5C78021E-3C8E-4EDF-97EA-E9B8D808FD6D}) (Version: - Microsoft) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) Easy File Share (HKLM-x32\...\{A7C37D4B-F37A-42E8-9B6A-B28C18AD4C12}) (Version: 1.3.6 - Samsung Electronics CO.,LTD.) E-POP (HKLM-x32\...\{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}) (Version: 1.0.1 - Samsung Electronics CO., LTD.) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Fotogalerie (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Free Zip Viewer (HKLM-x32\...\Free Zip Viewer) (Version: 1.0 - Tripro Limited) FreePDF (Remove only) (HKLM-x32\...\FreePDF_XP) (Version: - ) Galerie de photos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden GIMP 2.8.4 (HKLM\...\GIMP-2_is1) (Version: 2.8.4 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden GPL Ghostscript (HKLM\...\GPL Ghostscript 9.04) (Version: 9.04 - Artifex Software Inc.) GT Power Expansion (HKLM-x32\...\Steam App 44650) (Version: - SimBin) GTR Evolution (HKLM-x32\...\Steam App 8660) (Version: - SimBin) helo_usb_drv_x64 (HKLM-x32\...\{8169725C-186E-4F92-AE39-26611F45ACE3}) (Version: 1.00.0000 - HELO) HeloCut 5 (HKLM-x32\...\{8580EDDE-ACD8-4AC5-A5A3-309C41B16BF4}) (Version: 5.09.8000 - ) HeloCut 5 (HKLM-x32\...\{BC79822D-3183-4AA0-AC02-E1DF4C4183EC}) (Version: 5.09.8000 - VECAP Software Solutions) Help Desk (HKLM\...\{22B32087-797D-4A1B-AFA7-072C87580ADC}) (Version: 1.0.9 - Samsung Electronics CO., LTD.) Inkscape 0.48.3.1 (HKLM-x32\...\Inkscape) (Version: 0.48.3.1 - ) Intel AppUp(SM) center (HKLM-x32\...\Intel AppUp(SM) center 33070) (Version: 3.6.1.33070.11 - Intel) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation) Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36354 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3316 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden iTunes (HKLM\...\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}) (Version: 11.1.3.8 - Apple Inc.) Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Kaspersky Internet Security 2013 (HKLM-x32\...\InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}) (Version: 13.0.1.4190 - Kaspersky Lab) Kaspersky Internet Security 2013 (x32 Version: 13.0.1.4190 - Kaspersky Lab) Hidden KfzKaufmann (HKLM-x32\...\{BB16C933-8638-4A33-B68D-FFCF5FF332C0}_is1) (Version: - RU-Software) Lumac (HKLM-x32\...\InstallShield_{5DE11949-2B11-4F13-BAD5-1C237122CFDB}) (Version: 1.1.92.0 - Firstload) Lumac (x32 Version: 1.1.92.0 - Firstload) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.2.173.0 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (Version: 2.2.173.0 - Microsoft Corporation) Hidden Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1108.0727 - Microsoft) Hidden Need for Speed 5 Porsche Unleashed (HKLM-x32\...\{4CA7F8A0-DB20-11D4-8B30-000021015D1C}) (Version: - ) Need For Speed™ World (HKLM-x32\...\{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1) (Version: 1.0.0.1398 - Electronic Arts) Onlinesupport 5.0.8232 QS (HKLM-x32\...\{9520BD31-226A-4D5D-B900-6C0CDBA75BF0}_is1) (Version: - Robert Bosch GmbH) Opera 12.17 (HKLM-x32\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA) Photo Common (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden Python 2.7.5 (64-bit) (HKLM\...\{DBDD570E-0952-475f-9453-AB88F3DD565a}) (Version: 2.7.5150 - Python Software Foundation) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.216 - Qualcomm Atheros Communications) Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros) Raccolta foto (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden RACE 07 (HKLM-x32\...\Steam App 8600) (Version: - SimBin) Race Injection (HKLM-x32\...\Steam App 44680) (Version: - SimBin Studios AB) RaceRoom Racing Experience (HKLM-x32\...\Steam App 211500) (Version: - SimBin Studios AB) RaceRoom Racing Experience Launcher (HKLM-x32\...\{1FD9F07F-7BBF-4C91-B3F0-A23714A3A913}_is1) (Version: 1.0 - SimBin) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6702 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39030 - Realtek Semiconductor Corp.) Recovery (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 6.0.10.0 - Samsung Electronics CO., LTD.) RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: - ) Reimage Repair (HKLM\...\Reimage Repair) (Version: 1.6.6.4 - Reimage) RU Kfz-Kaufman (HKLM-x32\...\RU Kfz-Kaufman ) (Version: - ) S Agent (Version: 1.1.45 - Samsung Electronics CO., LTD.) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden Settings (HKLM-x32\...\{52E5DE60-C96B-42CC-9A37-FE04725940AE}) (Version: 2.0.0 - Samsung Electronics CO., LTD.) Simraceway 28.92 (HKLM-x32\...\Simraceway) (Version: 28.92 - Simraceway) STCC II (HKLM-x32\...\Steam App 44620) (Version: - SimBin) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) SteelSeries SRW-S1 (HKLM-x32\...\SteelSeries SRW-S1) (Version: 1.0 - SteelSeries ApS) Support Center (HKLM\...\{843A1BDC-0879-4E5B-83E1-B81CC0CF3580}) (Version: 2.1.1201 - Samsung Electronics CO., LTD.) Support Center FAQ (x32 Version: 1.0.9 - Samsung Electronics CO., LTD.) Hidden SW Update (HKLM-x32\...\{DA06101F-FD76-4BF0-88BD-B26A197005E3}) (Version: 2.1.21 - Samsung Electronics CO., LTD.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.14.2 - Synaptics Incorporated) The Retro Expansion (HKLM-x32\...\Steam App 44660) (Version: - SimBin) The WTCC 2010 Pack (HKLM-x32\...\Steam App 44670) (Version: - SimBin) Total Access Components 2007 (HKLM-x32\...\Total Access Components 2007) (Version: - ) TuneUp Utilities 2013 (HKLM-x32\...\TuneUp Utilities 2013) (Version: 13.0.4000.245 - TuneUp Software) TuneUp Utilities 2013 (x32 Version: 13.0.4000.245 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 13.0.4000.245 - TuneUp Software) Hidden Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Excel 2010 (KB2837600) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4ACD847E-547D-493F-9A86-F73EAE1B5174}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0D672F7-883E-4279-8E75-D97A5445AB46}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{C0BDC1DE-C35E-422B-8CBD-C1D555468720}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B9B89E01-5B6B-4F73-BC34-B2C0D8ACB4CD}) (Version: - Microsoft) User Guide (HKLM-x32\...\{C7588111-1A12-4EFE-8CA0-DA4344480D92}) (Version: 1.4.00 - Samsung Electronics CO., LTD.) VLC media player 2.0.3 (HKLM-x32\...\VLC media player) (Version: 2.0.3 - VideoLAN) VLC media player 2.0.7 (HKLM\...\VLC media player) (Version: 2.0.7 - VideoLAN) War Thunder Launcher 1.0.1.353 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - Gaijin Entertainment) Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows Driver Package - wch.cn (CH341SER_A64) Ports (11/04/2011 3.3.2011.11) (HKLM\...\97C9A01181CB4369C61AF9B1459B09809636C13D) (Version: 11/04/2011 3.3.2011.11 - wch.cn) Windows Live (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net) wxPython 2.8.12.1 (unicode) for Python 2.7 (HKLM\...\wxPython2.8-unicode-py27_is1) (Version: 2.8.12.1-unicode - Total Control Software) Xerox PhotoCafe (HKLM-x32\...\Xerox PhotoCafe) (Version: 1.0.0.6162 - Xerox) ==================== Restore Points ========================= 16-07-2014 12:39:17 Geplanter Prüfpunkt 19-07-2014 05:43:33 AA11 21-07-2014 07:07:53 AA11 ==================== Hosts content: ========================== 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {01224181-5D3F-40BE-A91C-7F99EAF59049} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-10-16] (Synaptics Incorporated) Task: {040F7F1F-A9FF-4425-92C3-93F73412F4A7} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {14953268-B4A5-467C-BE17-F978CBBB5E1A} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft) Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {2B8F2C7F-8F11-4EB4-A4FC-CC7298473982} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-04-16] (Intel Corporation) Task: {2BBFD98F-6EBC-480F-A7D1-CE11692BC00A} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {3E60A8C8-4E9B-4C68-A606-00EBF984E096} - System32\Tasks\Reimage Reminder => C:\Program Files\Reimage\Reimage Repair\ReimageReminder.exe Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {4BCCC83B-C81C-4A12-B4FD-76F0AD334CEF} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {60CBA487-14D5-41E3-B0FF-C88FF461B092} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {662FBA0B-4F9B-42DA-B987-2D5FB31ADC57} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6D1F9747-94E3-4428-A027-4633C2468BA9} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-04-16] (Intel Corporation) Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {719D6477-981D-4075-B9EB-A491E00CC838} - System32\Tasks\Xerox PhotoCafe Communicator => C:\ProgramData\Xerox PhotoCafe\MessageCheck.exe [2011-10-26] () Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {77FEBEC5-A53A-452A-9362-535DCD4F1D61} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {84460274-B38B-487E-A2E1-7E8CF72561D5} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {99367B58-21BA-4C70-97B4-498A49794EF0} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated) Task: {9A15AAE9-763B-4F3D-963E-1C8AD1A52D41} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload Task: {9BB6D06F-8C76-4E16-B15F-A2A0E5E50151} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2013-10-16] (Samsung Electronics CO., LTD.) Task: {9BD9601F-772B-4F46-8403-DF5D28EFDD5E} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe [2014-01-28] (TuneUp Software) Task: {9D8C51FE-440E-427E-AEB9-9283E49A61AC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-23] (Google Inc.) Task: {9F6CE7DE-FCCB-44FA-AFB5-DD9D3CCE29D9} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {A019CC72-234A-41D0-89CB-522B2C46F6F7} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2012-09-05] (Samsung Electronics CO., LTD.) Task: {A8C89B3D-C3FA-40C5-9C1F-92D29B62AF1D} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe Task: {B6166A99-AE09-4DB3-B587-9C2D1569E710} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {B7D9F543-294D-4910-B4B4-EF53CBE0D9F7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-23] (Google Inc.) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {E6B35171-09C0-4E57-A00F-26D0472B79D8} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {E9ECD765-9DD0-4BB5-8935-DCA6967C4D28} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-07-09] (Microsoft Corporation) Task: {F9BC2B20-A801-44A6-8DED-BEA03BFF5367} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2013-08-23] (SEC) Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe Task: C:\WINDOWS\Tasks\Xerox PhotoCafe Communicator.job => C:\ProgramData\Xerox PhotoCafe\MessageCheck.exe ==================== Loaded Modules (whitelisted) ============= 2013-04-15 09:51 - 2010-06-17 20:56 - 00087040 _____ () C:\WINDOWS\System32\redmonnt.dll 2014-07-10 21:40 - 2014-07-10 21:40 - 00172544 _____ () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe 2014-07-10 21:40 - 2014-07-10 21:40 - 00110080 _____ () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\nfapi.dll 2014-07-10 21:40 - 2014-07-10 21:40 - 00456192 _____ () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\ProtocolFilters.dll 2014-07-16 11:54 - 2014-07-16 11:54 - 00709120 _____ () C:\Program Files\005\cyycfhtzro64.exe 2013-07-11 23:04 - 2013-07-11 23:04 - 01630720 _____ () C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe 2014-01-28 10:37 - 2014-01-28 10:37 - 00741176 _____ () C:\Program Files (x86)\TuneUp Utilities 2013\avgrepliba.dll 2012-09-05 09:50 - 2012-09-05 09:50 - 00085112 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe 2013-10-04 00:42 - 2013-10-04 00:42 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-10-16 19:15 - 2013-10-16 19:15 - 00088624 _____ () C:\Program Files\Samsung\S Agent\ToastX64.dll 2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe 2013-09-13 20:51 - 2013-09-13 20:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-09-13 20:51 - 2013-09-13 20:51 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-07-11 23:03 - 2013-07-11 23:03 - 00252832 _____ () C:\Program Files (x86)\SimracewayUpdater\PATCHW32.dll 2012-11-26 08:01 - 2012-06-25 19:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2012-09-05 09:50 - 2012-09-05 09:50 - 00028792 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll 2012-09-05 09:50 - 2012-09-05 09:50 - 01012856 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmd.dll 2012-09-05 09:50 - 2012-09-05 09:50 - 00110712 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsBase.dll 2012-09-05 09:50 - 2012-09-05 09:50 - 00056440 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\HookDllPS2.dll 2012-09-05 09:50 - 2012-09-05 09:50 - 00211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll 2012-09-05 09:50 - 2012-09-05 09:50 - 00026744 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll 2012-09-05 09:50 - 2012-09-05 09:50 - 00110712 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll 2012-09-05 09:50 - 2012-09-05 09:50 - 00060536 _____ () C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll 2012-09-05 09:50 - 2012-09-05 09:50 - 00103544 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll 2013-07-11 11:00 - 2014-05-05 07:27 - 00835584 _____ () C:\Program Files (x86)\Opera\gstreamer\gstreamer.dll 2013-07-11 11:00 - 2014-05-05 07:27 - 00093696 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioconvert.dll 2013-07-11 11:00 - 2014-05-05 07:27 - 00094208 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioresample.dll 2013-07-11 11:00 - 2014-05-05 07:27 - 00057344 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstautodetect.dll 2013-07-11 11:00 - 2014-05-05 07:27 - 00096256 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstcoreplugins.dll 2013-07-11 11:00 - 2014-05-05 07:27 - 00062976 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstdecodebin2.dll 2013-07-11 11:00 - 2014-05-05 07:27 - 00067072 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstdirectsound.dll 2013-07-11 11:00 - 2014-05-05 07:27 - 00158208 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstffmpegcolorspace.dll 2013-07-11 11:00 - 2014-05-05 07:27 - 00312832 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstoggdec.dll 2013-07-11 11:00 - 2014-05-05 07:27 - 00038912 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstwaveform.dll 2013-07-11 11:00 - 2014-05-05 07:27 - 00073728 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstwavparse.dll 2013-07-11 11:00 - 2014-05-05 07:27 - 00101888 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstwebmdec.dll 2014-07-10 07:15 - 2014-07-10 07:16 - 26065408 _____ () C:\Program Files (x86)\Battle.net\Battle.net.4826\libcef.dll 2012-08-17 21:38 - 2012-08-17 21:38 - 00479160 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll 2012-12-14 13:45 - 2012-12-14 13:45 - 01310136 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kpcengine.2.2.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Windows:CM_1f24a44e6b128c2d77667e26df6bc247ed05d9ea5eb435533ab783378d367198 AlternateDataStreams: C:\Windows:CM_4c09c6a837b828f8e71ff53bdfa462592466a103481eefe431e5b35c94a386a5 AlternateDataStreams: C:\Users\Florian-KFZMeister\SkyDrive:ms-properties ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= HKLM\...\StartupApproved\StartupFolder: => "CodeMeter Control Center.lnk" HKLM\...\StartupApproved\Run: => "BtTray" HKLM\...\StartupApproved\Run: => "BtvStack" HKLM\...\StartupApproved\Run32: => "Adobe Reader Speed Launcher" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKLM\...\StartupApproved\Run32: => "RemoteControl10" HKLM\...\StartupApproved\Run32: => "CLMLServer_For_P2G8" HKLM\...\StartupApproved\Run32: => "CLVirtualDrive" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "StartDDM" HKLM\...\StartupApproved\Run32: => "ApnTBMon" HKLM\...\StartupApproved\Run32: => "APSDaemon" HKLM\...\StartupApproved\Run32: => "iTunesHelper" HKCU\...\StartupApproved\Run: => "Steam" HKCU\...\StartupApproved\Run: => "AmazonMP3DownloaderHelper" HKCU\...\StartupApproved\Run: => "Amazon Cloud Player" ==================== Faulty Device Manager Devices ============= Name: Bluetooth Audio Device Description: Bluetooth Audio Device Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318} Manufacturer: Qualcomm Atheros Communications Service: BTATH_A2DP Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Virtual Bluetooth Support (Include Audio) Description: Virtual Bluetooth Support (Include Audio) Class Guid: {c7c038ad-1f2d-44d4-b2fe-d912be20e6d5} Manufacturer: Qualcomm Atheros Communications Service: AthBTPort Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Bluetooth LWFLT Device Description: Bluetooth LWFLT Device Class Guid: {c7c038ad-1f2d-44d4-b2fe-d912be20e6d5} Manufacturer: Qualcomm Atheros Communications Service: BTATH_LWFLT Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver ==================== Event log errors: ========================= Application errors: ================== Error: (07/21/2014 09:09:52 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (07/21/2014 09:09:50 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (07/21/2014 09:05:28 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (07/21/2014 09:00:33 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (07/21/2014 09:00:31 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (07/21/2014 09:00:25 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (07/21/2014 09:00:25 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. System errors: ============= Microsoft Office Sessions: ========================= Error: (07/21/2014 09:09:52 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe Error: (07/21/2014 09:09:50 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe Error: (07/21/2014 09:05:28 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe Error: (07/21/2014 09:00:33 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe Error: (07/21/2014 09:00:31 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe Error: (07/21/2014 09:00:25 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe Error: (07/21/2014 09:00:25 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe CodeIntegrity Errors: =================================== Date: 2013-11-21 07:27:38.589 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\igdpmd64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Percentage of memory in use: 25% Total physical RAM: 8083.55 MB Available physical RAM: 6006.16 MB Total Pagefile: 9363.55 MB Available Pagefile: 6599.69 MB Total Virtual: 131072 MB Available Virtual: 131071.79 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:437.92 GB) (Free:202.45 GB) NTFS Drive d: (KfzKaufmann) (CDROM) (Total:0.2 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 1F995863) Partition: GPT Partition Type. ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-07-21 09:46:27 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000023 Hitachi_HTS547550A9E384 rev.JE3OA50A 465,76GB Running: 8kgufznd.exe; Driver: C:\Users\FLORIA~1\AppData\Local\Temp\kgloquow.sys ---- User code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\atiesrxx.exe[988] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffb2f81169a 4 bytes [81, 2F, FB, 7F] .text C:\WINDOWS\system32\atiesrxx.exe[988] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F] .text C:\WINDOWS\system32\atiesrxx.exe[988] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffb2f81181a 4 bytes [81, 2F, FB, 7F] .text C:\WINDOWS\system32\atiesrxx.exe[988] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffb2f811832 4 bytes [81, 2F, FB, 7F] .text C:\WINDOWS\system32\atieclxx.exe[1140] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffb2f81169a 4 bytes [81, 2F, FB, 7F] .text C:\WINDOWS\system32\atieclxx.exe[1140] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F] .text C:\WINDOWS\system32\atieclxx.exe[1140] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffb2f81181a 4 bytes [81, 2F, FB, 7F] .text C:\WINDOWS\system32\atieclxx.exe[1140] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffb2f811832 4 bytes [81, 2F, FB, 7F] .text C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe[1692] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffb2f81169a 4 bytes [81, 2F, FB, 7F] .text C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe[1692] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F] .text C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe[1692] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffb2f81181a 4 bytes [81, 2F, FB, 7F] .text C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe[1692] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffb2f811832 4 bytes [81, 2F, FB, 7F] .text C:\Program Files\005\cyycfhtzro64.exe[1760] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffb2f81169a 4 bytes [81, 2F, FB, 7F] .text C:\Program Files\005\cyycfhtzro64.exe[1760] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F] .text C:\Program Files\005\cyycfhtzro64.exe[1760] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffb2f81181a 4 bytes [81, 2F, FB, 7F] .text C:\Program Files\005\cyycfhtzro64.exe[1760] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffb2f811832 4 bytes [81, 2F, FB, 7F] .text C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe[2068] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffb2f81169a 4 bytes [81, 2F, FB, 7F] .text C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe[2068] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F] .text C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe[2068] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffb2f81181a 4 bytes [81, 2F, FB, 7F] .text C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe[2068] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffb2f811832 4 bytes [81, 2F, FB, 7F] .text C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe[3216] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffb2f81169a 4 bytes [81, 2F, FB, 7F] .text C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe[3216] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F] .text C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe[3216] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffb2f81181a 4 bytes [81, 2F, FB, 7F] .text C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe[3216] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffb2f811832 4 bytes [81, 2F, FB, 7F] .text C:\Windows\System32\igfxpers.exe[4888] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffb2f81169a 4 bytes [81, 2F, FB, 7F] .text C:\Windows\System32\igfxpers.exe[4888] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F] .text C:\Windows\System32\igfxpers.exe[4888] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffb2f81181a 4 bytes [81, 2F, FB, 7F] .text C:\Windows\System32\igfxpers.exe[4888] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffb2f811832 4 bytes [81, 2F, FB, 7F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[5264] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ffb23841f6a 4 bytes [84, 23, FB, 7F] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[5264] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ffb23841f82 4 bytes [84, 23, FB, 7F] ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [844:868] fffff960009bbb90 Thread c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [3200:4624] 00007ffb0df5c680 Thread c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3232:3036] 00007ffb0dcb838c Thread c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3232:5976] 00007ffb0df5c680 Thread C:\Windows\System32\SettingSyncHost.exe [5148:4340] 00007ffb2f531b54 Thread C:\Windows\System32\SettingSyncHost.exe [5148:4260] 00007ffb0dec41f4 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- Vielen Dank für eure Mühen im Vorraus! Florian |
21.07.2014, 09:12 | #2 |
/// TB-Ausbilder | Windows 8.1: Werbe-Popups in Google Chrome und Opera Hallo flo344i
__________________Mein Name ist Timo und ich werde Dir bei deinem Problem behilflich sein.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist immer der sicherste Weg. Wir "arbeiten" hier alle freiwillig und in unserer Freizeit *hust*. Daher kann es bei Antworten zu Verzögerungen kommen. Solltest du innerhalb 48 Std keine Antwort von mir erhalten, dann schreib mit eine PM Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis ich oder jemand vom Team sagt, dass Du clean bist. Wichtig: |
21.07.2014, 10:34 | #3 |
/// TB-Ausbilder | Windows 8.1: Werbe-Popups in Google Chrome und OperaHinweis: Registry Cleaner Ich sehe, dass du sogenannte Registry Cleaner installiert hast. In deinem Fall TuneUp Utilities. Wir raten von der Verwendung jeglicher Art von Registry Cleaner ab. Der Grund ist ganz einfach: Die Registry ist das Hirn des Systems. Funktioniert das Hirn nicht, funktioniert der Rest nicht mehr wirklich. Man sollte nicht unnötigerweise an der Registry rumbasteln. Schon ein kleiner Fehler kann gravierende Folgen haben und auch Programme machen manchmal Fehler. Zerstörst du die Registry, zerstörst du Windows. Zudem ist der Nutzen zur Performancesteigerung umstritten und meist kaum im wahrnehmbaren Bereich. Ich würde dir empfehlen, Registry Cleaner nicht weiterhin zu verwenden und über Start --> Systemsteuerung --> Software (bei Windows XP)zu deinstallieren. Schritt 1 Deinstallation von Programmen:
Deinstalliere auch - falls du es nicht absichtlich installiert hast - alles was den Zusatz "Toolbar" enthält, sowie Downloader-Anwendungen Gehe bitte die folgende Liste durch und deinstalliere die genannten Programme, falls vorhanden: CCleaner oder andere Registry-Cleaner, TuneUp Utilities (inkl. Language Pack), Glary Utilities, Spybot S & D (inklusive Teatimer), Zonealarm Firewall, McAfee Security Scan, Spyware Hunter, Spyware Terminator, Java 6 (alle), Pokersoftware, xp-Antispy, Hotspot Shield, iLivid, Amazon Icon, DriverEasy, Advanced Driver Updater, DriverCure, Uniblue DriverScanner, FireJump, SearchAnonymizer, SpeedMaxPC Schritt 2 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 3 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 4 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 5 Starte noch einmal FRST.
Bitte in der Antwort posten:
|
21.07.2014, 12:46 | #4 |
| Windows 8.1: Werbe-Popups in Google Chrome und Opera Alles ausgeführt wie du mir aufgetragen hast:-) Hier die Log Files Code:
ATTFilter # AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 11:50:06 # Aktualisiert 17/07/2014 von Xplode # Betriebssystem : Windows 8.1 (64 bits) # Benutzername : Florian-KFZMeister - WERKSTATT-PC # Gestartet von : C:\Users\Florian-KFZMeister\Desktop\adwcleaner_3.216.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage Datei Gefunden : C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17126 -\\ Google Chrome v35.0.1916.153 [ Datei : C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [1157 octets] - [21/07/2014 11:50:06] ########## EOF - C:\AdwCleaner\AdwCleaner[R3].txt - [1397 octets] ########## Code:
ATTFilter # AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 11:50:36 # Aktualisiert 17/07/2014 von Xplode # Betriebssystem : Windows 8.1 (64 bits) # Benutzername : Florian-KFZMeister - WERKSTATT-PC # Gestartet von : C:\Users\Florian-KFZMeister\Desktop\adwcleaner_3.216.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gelöscht : C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage Datei Gelöscht : C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17126 -\\ Google Chrome v35.0.1916.153 [ Datei : C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [1477 octets] - [21/07/2014 11:50:06] AdwCleaner[S0].txt - [1398 octets] - [21/07/2014 11:50:36] ########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1458 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 8.1 x64 Ran by Florian-KFZMeister on 21.07.2014 at 11:58:39,54 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 21.07.2014 at 12:01:40,08 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 21.07.2014 Suchlauf-Zeit: 12:05:42 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.03.04.09 Rootkit Datenbank: v2014.02.20.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Florian-KFZMeister Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 294804 Verstrichene Zeit: 7 Min, 54 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014 Ran by Florian-KFZMeister (administrator) on WERKSTATT-PC on 21-07-2014 13:40:21 Running from C:\Users\Florian-KFZMeister\Desktop Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\005\cyycfhtzro64.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe () C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Samsung Electronics CO., LTD.) C:\ProgramData\SAMSUNG\SW Update Service\SWMAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191824 2012-08-10] (Realtek Semiconductor) HKLM\...\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [766080 2012-12-05] (Qualcomm Atheros) HKLM\...\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [128640 2012-12-05] (Atheros Communications) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2917688 2012-10-16] (Synaptics Incorporated) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [97392 2012-08-15] (CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation) HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de) HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe [24504 2012-12-14] (Kaspersky Lab ZAO) HKLM-x32\...\Run: [StartDDM] => C:\Program Files (x86)\Bosch\DownloadManager\bin\runDDM.exe [260608 2012-02-10] (Robert Bosch GmbH) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-18] (Advanced Micro Devices, Inc.) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1825984 2014-04-24] (Valve Corporation) HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Florian-KFZMeister\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHel (the data entry has 8 more characters). HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [Amazon Cloud Player] => C:\Users\Florian-KFZMeister\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2013-12-12] () HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Policies\system: [DisableLockWorkstation] 0 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung13.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com SearchScopes: HKLM - DefaultScope {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS SearchScopes: HKLM - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKLM-x32 - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS SearchScopes: HKCU - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) DPF: HKLM-x32 {55369874-02F5-47E2-A0F7-AC67E1B1866E} hxxp://www.centrodigital.de/smart/setup.ocx Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Florian-KFZMeister\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Florian-KFZMeister\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-05-15] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-05-15] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-05-15] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013-05-15] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013-05-15] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://www.google.com/" CHR Extension: (Google Docs) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-23] CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-01-23] CHR Extension: (Sicherer Zahlungsverkehr) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-01-23] CHR Extension: (Modul für das Blockieren gefährlicher Webseiten) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-01-23] CHR Extension: (Virtuelle Tastatur) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-01-23] CHR Extension: (Google Wallet) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-23] CHR Extension: (Anti-Banner) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-01-23] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-12-14] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-12-14] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-12-14] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2013-05-15] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-12-14] ==================== Services (Whitelisted) ================= R2 AllDaySavingsService64; C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe [172544 2014-07-10] () [File not signed] R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [231552 2012-12-05] (Qualcomm Atheros Commnucations) S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) R2 cyycfhtzro64; C:\Program Files\005\cyycfhtzro64.exe [709120 2014-07-16] () [File not signed] R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593976 2012-09-05] (Samsung Electronics CO., LTD.) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 Simraceway Update Service; C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe [1630720 2013-07-11] () [File not signed] R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-05] (Atheros) [File not signed] ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-21] (Advanced Micro Devices, Inc.) R3 BTATH_HID; C:\Windows\system32\DRIVERS\btath_hid.sys [222360 2012-12-05] (Qualcomm Atheros) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-05] (Qualcomm Atheros) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) S3 CH341SER_A64; C:\Windows\System32\Drivers\CH341S64.SYS [58368 2011-11-04] (www.winchiphead.com) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [146856 2013-06-04] (Windows (R) Win 7 DDK provider) R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [21928 2013-06-04] (Windows (R) Win 7 DDK provider) S3 IntcDAud; C:\Windows\system32\DRIVERS\IntcDAud.sys [342528 2012-06-19] (Intel(R) Corporation) [File not signed] S3 intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [5338848 2012-09-17] (Intel Corporation) [File not signed] R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [627296 2014-05-20] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-12-11] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2013-05-15] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2013-05-15] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-21] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-07-10] (NetFilterSDK.com) R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-21 13:39 - 2014-07-21 13:39 - 00001156 _____ () C:\Users\Florian-KFZMeister\Desktop\mbam.txt 2014-07-21 12:03 - 2014-07-21 12:30 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-07-21 12:03 - 2014-07-21 12:03 - 00001118 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-21 12:03 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-07-21 12:03 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2014-07-21 12:03 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-07-21 12:02 - 2014-07-21 12:02 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Florian-KFZMeister\Desktop\mbam-setup-2.0.2.1012.exe 2014-07-21 12:01 - 2014-07-21 12:01 - 00000627 _____ () C:\Users\Florian-KFZMeister\Desktop\JRT.txt 2014-07-21 11:57 - 2014-07-21 11:57 - 01016261 _____ (Thisisu) C:\Users\Florian-KFZMeister\Desktop\JRT.exe 2014-07-21 11:52 - 2014-07-21 11:52 - 00000000 ___RD () C:\Users\Florian-KFZMeister\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-07-21 11:51 - 2014-07-21 11:51 - 00000000 ____H () C:\ProgramData\cm-lock 2014-07-21 11:48 - 2014-07-21 11:48 - 01354223 _____ () C:\Users\Florian-KFZMeister\Desktop\adwcleaner_3.216.exe 2014-07-21 09:46 - 2014-07-21 09:46 - 00007268 _____ () C:\Users\Florian-KFZMeister\Desktop\GMER.log 2014-07-21 09:29 - 2014-07-21 09:29 - 704339485 _____ () C:\WINDOWS\MEMORY.DMP 2014-07-21 09:29 - 2014-07-21 09:29 - 00299272 _____ () C:\WINDOWS\Minidump\072114-35515-01.dmp 2014-07-21 09:29 - 2014-07-21 09:29 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-21 09:25 - 2014-07-21 13:40 - 00021138 _____ () C:\Users\Florian-KFZMeister\Desktop\FRST.txt 2014-07-21 09:25 - 2014-07-21 13:40 - 00000000 ____D () C:\FRST 2014-07-21 09:25 - 2014-07-21 09:26 - 00053834 _____ () C:\Users\Florian-KFZMeister\Desktop\Addition.txt 2014-07-21 09:24 - 2014-07-21 09:32 - 00000498 _____ () C:\Users\Florian-KFZMeister\Desktop\defogger_disable.log 2014-07-21 09:24 - 2014-07-21 09:24 - 00000000 _____ () C:\Users\Florian-KFZMeister\defogger_reenable 2014-07-21 09:22 - 2014-07-21 09:22 - 02089984 _____ (Farbar) C:\Users\Florian-KFZMeister\Desktop\FRST64.exe 2014-07-21 09:22 - 2014-07-21 09:22 - 00380416 _____ () C:\Users\Florian-KFZMeister\Desktop\8kgufznd.exe 2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe 2014-07-21 09:00 - 2014-07-21 09:00 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-07-21 08:59 - 2014-07-21 08:59 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe 2014-07-21 08:59 - 2014-07-21 08:59 - 02088532 _____ () C:\Users\Florian-KFZMeister\Downloads\FRST64.exe 2014-07-19 08:28 - 2014-07-19 08:28 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-07-19 08:13 - 2014-07-19 08:13 - 00003228 _____ () C:\WINDOWS\System32\Tasks\{195AC1F4-9216-4E5D-970E-EE662B1F6FAB} 2014-07-19 08:10 - 2014-07-19 08:10 - 01707144 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer (1).exe 2014-07-19 08:08 - 2014-07-21 09:56 - 00000000 ____D () C:\Program Files\AllDaySavings 2014-07-19 08:05 - 2014-07-19 08:05 - 00822568 _____ (Reimage®) C:\Users\Florian-KFZMeister\Downloads\ReimageRepair.exe 2014-07-19 08:03 - 2014-07-19 08:04 - 01705692 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer.exe 2014-07-19 07:51 - 2014-07-19 07:51 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LavasoftStatistics 2014-07-19 07:50 - 2014-07-19 07:50 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-07-19 07:43 - 2014-07-19 07:43 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-07-18 17:17 - 2014-07-21 11:51 - 00005694 _____ () C:\WINDOWS\PFRO.log 2014-07-18 17:17 - 2014-07-18 17:18 - 00491000 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-07-18 17:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll 2014-07-18 17:13 - 2014-07-21 11:56 - 00000000 ____D () C:\AdwCleaner 2014-07-18 12:28 - 2014-07-21 11:46 - 00003494 _____ () C:\WINDOWS\System32\Tasks\Reimage Reminder 2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Reimage Protector 2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair 2014-07-18 12:16 - 2014-07-18 12:28 - 00000000 ____D () C:\rei 2014-07-18 12:15 - 2014-07-18 12:28 - 00000163 _____ () C:\WINDOWS\Reimage.ini 2014-07-18 09:07 - 2014-07-18 09:07 - 00000000 _____ () C:\Users\Florian-KFZMeister\com.attensity.bosch.esi.updateclient.StartUpdateClient.tmp 2014-07-16 11:55 - 2014-07-17 07:20 - 00000000 ____D () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131 2014-07-16 11:54 - 2014-07-16 11:54 - 00000000 ____D () C:\Program Files\005 2014-07-14 08:31 - 2014-07-14 08:31 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\.eva 2014-07-14 08:29 - 2014-07-14 08:29 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Daimler 2014-07-10 21:40 - 2014-07-10 21:40 - 00046376 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\netfilter64.sys 2014-07-09 07:58 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll 2014-07-09 07:43 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe 2014-07-09 07:43 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe 2014-07-09 07:43 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2014-07-09 07:43 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2014-07-09 07:43 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2014-07-09 07:43 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 2014-07-09 07:43 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll 2014-07-09 07:43 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2014-07-09 07:43 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2014-07-09 07:43 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2014-07-09 07:42 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-07-09 07:42 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-07-09 07:42 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-07-09 07:42 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 2014-07-09 07:42 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-07-09 07:42 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-07-09 07:42 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2014-07-09 07:42 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2014-07-09 07:42 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-07-09 07:42 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-07-09 07:42 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-07-09 07:42 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2014-07-09 07:42 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-07-09 07:42 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-07-09 07:42 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-07-09 07:42 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2014-07-09 07:42 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-07-09 07:42 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-07-09 07:42 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-07-09 07:42 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-07-09 07:42 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-07-09 07:42 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-07-09 07:42 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-07-09 07:42 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-07-09 07:42 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-07-09 07:42 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-07-09 07:42 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-07-09 07:42 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll 2014-07-09 07:42 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll 2014-07-09 07:42 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2014-07-09 07:42 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2014-07-09 07:42 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2014-07-09 07:42 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2014-07-09 07:42 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 07:42 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2014-07-09 07:42 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2014-07-09 07:42 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 07:42 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2014-07-09 07:42 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2014-07-09 07:42 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2014-07-09 07:42 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2014-07-09 07:42 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2014-07-09 07:42 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2014-07-09 07:42 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2014-06-30 13:53 - 2014-06-30 13:53 - 00001674 _____ () C:\Users\Florian-KFZMeister\AppData\Local\recently-used.xbel 2014-06-30 13:44 - 2014-07-19 07:53 - 00000000 ____D () C:\Users\Florian-KFZMeister\Downloads\Musikjunkie - Guano Apes 2014 Offline Bitrate VBR 04 Numen ==================== One Month Modified Files and Folders ======= 2014-07-21 13:40 - 2014-07-21 09:25 - 00021138 _____ () C:\Users\Florian-KFZMeister\Desktop\FRST.txt 2014-07-21 13:40 - 2014-07-21 09:25 - 00000000 ____D () C:\FRST 2014-07-21 13:39 - 2014-07-21 13:39 - 00001156 _____ () C:\Users\Florian-KFZMeister\Desktop\mbam.txt 2014-07-21 13:13 - 2013-10-30 10:43 - 00000064 __RSH () C:\WINDOWS\system32\Drivers\VSTXRAID.winsecurity 2014-07-21 13:10 - 2013-10-30 13:04 - 01722873 _____ () C:\WINDOWS\WindowsUpdate.log 2014-07-21 13:04 - 2014-01-23 12:31 - 00001160 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-21 13:02 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-07-21 13:01 - 2012-11-26 08:17 - 00000360 _____ () C:\WINDOWS\Tasks\Xerox PhotoCafe Communicator.job 2014-07-21 12:47 - 2013-10-30 10:14 - 00000064 __RSH () C:\WINDOWS\system32\Drivers\WUDFPf.winsecurity 2014-07-21 12:30 - 2014-07-21 12:03 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-07-21 12:14 - 2013-04-14 11:43 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2830974330-3213038589-3334289725-1002 2014-07-21 12:03 - 2014-07-21 12:03 - 00001118 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-21 12:02 - 2014-07-21 12:02 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Florian-KFZMeister\Desktop\mbam-setup-2.0.2.1012.exe 2014-07-21 12:01 - 2014-07-21 12:01 - 00000627 _____ () C:\Users\Florian-KFZMeister\Desktop\JRT.txt 2014-07-21 11:58 - 2013-09-30 06:14 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-07-21 11:58 - 2013-09-30 05:56 - 00766620 _____ () C:\WINDOWS\system32\perfh007.dat 2014-07-21 11:58 - 2013-09-30 05:56 - 00159902 _____ () C:\WINDOWS\system32\perfc007.dat 2014-07-21 11:57 - 2014-07-21 11:57 - 01016261 _____ (Thisisu) C:\Users\Florian-KFZMeister\Desktop\JRT.exe 2014-07-21 11:56 - 2014-07-18 17:13 - 00000000 ____D () C:\AdwCleaner 2014-07-21 11:55 - 2012-11-26 08:09 - 00000000 ____D () C:\ProgramData\WinClon 2014-07-21 11:54 - 2014-01-23 12:31 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-21 11:54 - 2013-05-15 10:19 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-07-21 11:53 - 2014-01-23 12:30 - 00001156 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-21 11:52 - 2014-07-21 11:52 - 00000000 ___RD () C:\Users\Florian-KFZMeister\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-07-21 11:52 - 2014-04-17 11:11 - 00000000 __RDO () C:\Users\Florian-KFZMeister\SkyDrive 2014-07-21 11:52 - 2013-04-15 09:52 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\FreePDF_XP 2014-07-21 11:52 - 2012-11-26 08:01 - 00000868 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-07-21 11:51 - 2014-07-21 11:51 - 00000000 ____H () C:\ProgramData\cm-lock 2014-07-21 11:51 - 2014-07-18 17:17 - 00005694 _____ () C:\WINDOWS\PFRO.log 2014-07-21 11:51 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-07-21 11:51 - 2013-08-06 13:50 - 00599686 _____ () C:\Simraceway.log 2014-07-21 11:50 - 2013-10-30 12:44 - 00000000 ____D () C:\Users\Florian-KFZMeister 2014-07-21 11:50 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2014-07-21 11:49 - 2013-04-15 08:19 - 00000000 ____D () C:\KfzKaufmann 2014-07-21 11:48 - 2014-07-21 11:48 - 01354223 _____ () C:\Users\Florian-KFZMeister\Desktop\adwcleaner_3.216.exe 2014-07-21 11:47 - 2013-04-14 21:37 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-07-21 11:46 - 2014-07-18 12:28 - 00003494 _____ () C:\WINDOWS\System32\Tasks\Reimage Reminder 2014-07-21 11:46 - 2012-11-26 08:17 - 00003298 _____ () C:\WINDOWS\System32\Tasks\Xerox PhotoCafe Communicator 2014-07-21 11:45 - 2012-11-26 08:11 - 00000000 ____D () C:\ProgramData\Adobe 2014-07-21 11:10 - 2014-01-23 17:12 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\Schaltpläne 2014-07-21 09:56 - 2014-07-19 08:08 - 00000000 ____D () C:\Program Files\AllDaySavings 2014-07-21 09:46 - 2014-07-21 09:46 - 00007268 _____ () C:\Users\Florian-KFZMeister\Desktop\GMER.log 2014-07-21 09:41 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-07-21 09:32 - 2014-07-21 09:24 - 00000498 _____ () C:\Users\Florian-KFZMeister\Desktop\defogger_disable.log 2014-07-21 09:29 - 2014-07-21 09:29 - 704339485 _____ () C:\WINDOWS\MEMORY.DMP 2014-07-21 09:29 - 2014-07-21 09:29 - 00299272 _____ () C:\WINDOWS\Minidump\072114-35515-01.dmp 2014-07-21 09:29 - 2014-07-21 09:29 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-21 09:26 - 2014-07-21 09:25 - 00053834 _____ () C:\Users\Florian-KFZMeister\Desktop\Addition.txt 2014-07-21 09:24 - 2014-07-21 09:24 - 00000000 _____ () C:\Users\Florian-KFZMeister\defogger_reenable 2014-07-21 09:22 - 2014-07-21 09:22 - 02089984 _____ (Farbar) C:\Users\Florian-KFZMeister\Desktop\FRST64.exe 2014-07-21 09:22 - 2014-07-21 09:22 - 00380416 _____ () C:\Users\Florian-KFZMeister\Desktop\8kgufznd.exe 2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe 2014-07-21 09:00 - 2014-07-21 09:00 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-07-21 08:59 - 2014-07-21 08:59 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe 2014-07-21 08:59 - 2014-07-21 08:59 - 02088532 _____ () C:\Users\Florian-KFZMeister\Downloads\FRST64.exe 2014-07-21 08:27 - 2013-12-13 13:46 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LumacDaemon 2014-07-21 08:17 - 2014-03-03 13:54 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Battle.net 2014-07-19 08:28 - 2014-07-19 08:28 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-07-19 08:13 - 2014-07-19 08:13 - 00003228 _____ () C:\WINDOWS\System32\Tasks\{195AC1F4-9216-4E5D-970E-EE662B1F6FAB} 2014-07-19 08:10 - 2014-07-19 08:10 - 01707144 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer (1).exe 2014-07-19 08:05 - 2014-07-19 08:05 - 00822568 _____ (Reimage®) C:\Users\Florian-KFZMeister\Downloads\ReimageRepair.exe 2014-07-19 08:04 - 2014-07-19 08:03 - 01705692 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer.exe 2014-07-19 08:01 - 2013-08-24 08:39 - 00000000 ____D () C:\Games 2014-07-19 07:53 - 2014-06-30 13:44 - 00000000 ____D () C:\Users\Florian-KFZMeister\Downloads\Musikjunkie - Guano Apes 2014 Offline Bitrate VBR 04 Numen 2014-07-19 07:51 - 2014-07-19 07:51 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LavasoftStatistics 2014-07-19 07:50 - 2014-07-19 07:50 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-07-19 07:43 - 2014-07-19 07:43 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-07-19 07:30 - 2013-07-12 17:24 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\re 2014-07-18 17:18 - 2014-07-18 17:17 - 00491000 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-07-18 17:17 - 2013-04-15 08:37 - 00000000 ____D () C:\Users\Florian-KFZMeister\.thumbnails 2014-07-18 17:12 - 2013-03-28 17:40 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\repline 2014-07-18 15:55 - 2012-11-26 08:01 - 00000870 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-07-18 13:01 - 2013-09-19 08:20 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\vlc 2014-07-18 12:28 - 2014-07-18 12:16 - 00000000 ____D () C:\rei 2014-07-18 12:28 - 2014-07-18 12:15 - 00000163 _____ () C:\WINDOWS\Reimage.ini 2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Reimage Protector 2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair 2014-07-18 09:07 - 2014-07-18 09:07 - 00000000 _____ () C:\Users\Florian-KFZMeister\com.attensity.bosch.esi.updateclient.StartUpdateClient.tmp 2014-07-17 13:56 - 2014-04-16 10:02 - 00000000 ____D () C:\ProgramData\WarThunder 2014-07-17 07:29 - 2013-06-11 09:43 - 00000000 ____D () C:\ProgramData\Bosch 2014-07-17 07:28 - 2013-06-11 09:43 - 00000488 _____ () C:\WINDOWS\RbSystem.ini 2014-07-17 07:20 - 2014-07-16 11:55 - 00000000 ____D () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131 2014-07-16 17:11 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF 2014-07-16 12:06 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-07-16 11:54 - 2014-07-16 11:54 - 00000000 ____D () C:\Program Files\005 2014-07-16 07:13 - 2014-04-16 10:02 - 00000000 ____D () C:\Program Files (x86)\WarThunder 2014-07-14 16:39 - 2013-04-24 10:52 - 00133799 _____ () C:\Users\Florian-KFZMeister\ewa_client_0.log 2014-07-14 16:39 - 2013-04-24 10:52 - 00000000 ____D () C:\Users\Florian-KFZMeister\XFER 2014-07-14 16:24 - 2013-04-24 10:52 - 00000122 _____ () C:\Users\Florian-KFZMeister\.ewanapi_cookie 2014-07-14 08:55 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-07-14 08:31 - 2014-07-14 08:31 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\.eva 2014-07-14 08:29 - 2014-07-14 08:29 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Daimler 2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore 2014-07-10 21:40 - 2014-07-10 21:40 - 00046376 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\netfilter64.sys 2014-07-10 17:42 - 2014-03-03 13:54 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-07-09 08:03 - 2013-04-14 20:50 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-07-09 08:03 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2014-07-09 08:02 - 2013-07-23 09:05 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-07-09 08:00 - 2013-04-15 07:41 - 96441528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-07-09 07:58 - 2013-09-30 05:59 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-08 08:05 - 2014-03-03 13:55 - 00000000 ____D () C:\Program Files (x86)\Diablo III 2014-07-02 16:35 - 2013-06-19 10:56 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\Formulare und Vorlagen 2014-06-30 13:53 - 2014-06-30 13:53 - 00001674 _____ () C:\Users\Florian-KFZMeister\AppData\Local\recently-used.xbel 2014-06-30 13:53 - 2013-04-15 08:36 - 00000000 ____D () C:\Users\Florian-KFZMeister\.gimp-2.8 2014-06-26 22:55 - 2014-04-30 08:06 - 00703968 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:55 - 2014-04-30 08:06 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-25 17:58 - 2014-01-23 12:31 - 00004132 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-25 17:58 - 2014-01-23 12:30 - 00003896 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-23 10:16 - 2013-04-14 11:49 - 00001382 _____ () C:\Users\Public\Desktop\CENTROdigital SmartClient.lnk Files to move or delete: ==================== C:\ProgramData\MakeMarkerFile.exe C:\Users\EasySurvey\EasySurvey.exe Some content of TEMP: ==================== C:\Users\Florian-KFZMeister\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-21 12:14 ==================== End Of Log ============================ --- --- --- |
21.07.2014, 12:54 | #5 |
/// TB-Ausbilder | Windows 8.1: Werbe-Popups in Google Chrome und Opera Hm, ok - hier müssen wir von Hand nachhelfen: Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe () C:\Program Files\005\cyycfhtzro64.exe R2 AllDaySavingsService64; C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe [172544 2014-07-10] () [File not signed] R2 cyycfhtzro64; C:\Program Files\005\cyycfhtzro64.exe [709120 2014-07-16] () [File not signed] AlternateDataStreams: C:\Windows:CM_1f24a44e6b128c2d77667e26df6bc247ed05d9ea5eb435533ab783378d367198 AlternateDataStreams: C:\Windows:CM_4c09c6a837b828f8e71ff53bdfa462592466a103481eefe431e5b35c94a386a5 C:\Program Files\005 C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\ Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
|
21.07.2014, 13:00 | #6 |
| Windows 8.1: Werbe-Popups in Google Chrome und OperaCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-07-2014 Ran by Florian-KFZMeister at 2014-07-21 13:59:16 Run:1 Running from C:\Users\Florian-KFZMeister\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe () C:\Program Files\005\cyycfhtzro64.exe R2 AllDaySavingsService64; C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe [172544 2014-07-10] () [File not signed] R2 cyycfhtzro64; C:\Program Files\005\cyycfhtzro64.exe [709120 2014-07-16] () [File not signed] AlternateDataStreams: C:\Windows:CM_1f24a44e6b128c2d77667e26df6bc247ed05d9ea5eb435533ab783378d367198 AlternateDataStreams: C:\Windows:CM_4c09c6a837b828f8e71ff53bdfa462592466a103481eefe431e5b35c94a386a5 C:\Program Files\005 C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\ ***************** [1712] C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe => Process closed successfully. [1856] C:\Program Files\005\cyycfhtzro64.exe => Process closed successfully. AllDaySavingsService64 => Service stopped successfully. AllDaySavingsService64 => Service deleted successfully. cyycfhtzro64 => Service deleted successfully. C:\Windows => ":CM_1f24a44e6b128c2d77667e26df6bc247ed05d9ea5eb435533ab783378d367198" ADS removed successfully. C:\Windows => ":CM_4c09c6a837b828f8e71ff53bdfa462592466a103481eefe431e5b35c94a386a5" ADS removed successfully. C:\Program Files\005 => Moved successfully. C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131 => Moved successfully. ==== End of Fixlog ==== |
21.07.2014, 13:05 | #7 |
/// TB-Ausbilder | Windows 8.1: Werbe-Popups in Google Chrome und Opera OK, dann machen wir so weiter: ESET Online Scanner
Der Scan dauert länger. Sind die Popups noch da ? |
21.07.2014, 13:18 | #8 |
| Windows 8.1: Werbe-Popups in Google Chrome und Opera |
21.07.2014, 13:24 | #9 |
/// TB-Ausbilder | Windows 8.1: Werbe-Popups in Google Chrome und Opera Hab auch nix anderes erwartet Dann schauen wir noch was ESET sagt. |
22.07.2014, 07:16 | #10 |
| Windows 8.1: Werbe-Popups in Google Chrome und OperaCode:
ATTFilter ESETSmartInstaller@High as downloader log: Can not extract cabC:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScanner.cabErr:Der Vorgang wurde erfolgreich beendet. ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=aff4aa0471552244977369db06e6f747 # engine=19274 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-07-21 03:25:17 # local_time=2014-07-21 05:25:17 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='Kaspersky Internet Security' # compatibility_mode=1291 16777214 100 98 19946 60726239 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 5392504 30837610 0 0 # scanned=651398 # found=4 # cleaned=0 # scan_time=10884 sh=41EA136148FB653782E8A2479EA0D86666F30377 ft=1 fh=51a53a33d3e8c027 vn="Variante von MSIL/Adware.iBryte.D Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsersafeguard\uninstall.BrowserSafeguard.exe.vir" sh=96A5AEBAF5A2C96B869168D409FAF54BC52F4BFB ft=1 fh=95a04965e73ede3e vn="Variante von Win64/Adware.Adpeak.C Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\005\cyycfhtzro64.exe" sh=D8C35097E17E1FD96E1A04F66D828C386B758310 ft=1 fh=56ce06f6adf24540 vn="Win32/Toolbar.Babylon.T evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Florian-KFZMeister\AppData\Local\Microsoft\Windows\INetCache\IE\LGWG11SD\ProtectorPackage2001x64[1].exe" sh=E5B4DFCD56B817D4B03316FFE8CE05F535E856E8 ft=1 fh=36a8d984243397e5 vn="Win32/DriverBoss.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Florian-KFZMeister\Downloads\hp-laserjet-3050-driver-utility.exe" Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 22.07.2014 Suchlauf-Zeit: 07:39:42 Logdatei: mbam1.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.07.21.09 Rootkit Datenbank: v2014.07.17.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Florian-KFZMeister Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 356565 Verstrichene Zeit: 16 Min, 8 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 4 PUP.Optional.Adpeak.A, HKLM\SOFTWARE\AllDaySavings, , [cb622d75c5b6c274dcfaf9caff0315eb], PUP.Optional.Adpeak.A, HKLM\SOFTWARE\WOW6432NODE\AllDaySavings, , [51dc059d116a62d4dff76c579b6720e0], PUP.Optional.AdPeak, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\netfilter64, , [e9443969b1ca9a9caa0a0ab842c0b64a], PUP.Optional.SuperFish.A, HKU\S-1-5-21-2830974330-3213038589-3334289725-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com, , [cc6151517cffbe78bf7be7e28e74b34d], Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 2 PUP.Optional.Adpeak.A, C:\Program Files\AllDaySavings, , [72bbdfc3fa81be78abe05f614bb72bd5], PUP.Optional.Adpeak.A, C:\Program Files\AllDaySavings\SSL, , [72bbdfc3fa81be78abe05f614bb72bd5], Dateien: 5 PUP.Optional.BetterDeals.A, C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage, , [95989111483387af3e7ffbd415edd12f], PUP.Optional.BetterDeals.A, C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage-journal, , [59d4554dc5b66fc705b8468979899a66], PUP.Optional.Superfish.A, C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, , [eb42c6dc3546f04662963f9517eb26da], PUP.Optional.Superfish.A, C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, , [fc31b7eb6c0fff378276e3f139c97e82], PUP.Optional.AdPeak, C:\Windows\System32\drivers\netfilter64.sys, , [e9443969b1ca9a9caa0a0ab842c0b64a], Physische Sektoren: 0 (No malicious items detected) (end) |
22.07.2014, 07:31 | #11 |
/// TB-Ausbilder | Windows 8.1: Werbe-Popups in Google Chrome und Opera Ok, ESET hat auch nur noch marginales gefunden. Das löschen wir grad und dann noch ein frisches FRST Log: Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Florian-KFZMeister\Downloads\hp-laserjet-3050-driver-utility.exe C:\Users\Florian-KFZMeister\AppData\Local\Microsoft\Windows\INetCache\IE\LGWG11SD\ProtectorPackage2001x64[1].exe Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Starte noch einmal FRST.
|
22.07.2014, 07:44 | #12 |
| Windows 8.1: Werbe-Popups in Google Chrome und OperaCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-07-2014 Ran by Florian-KFZMeister at 2014-07-22 08:42:09 Run:2 Running from C:\Users\Florian-KFZMeister\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Florian-KFZMeister\Downloads\hp-laserjet-3050-driver-utility.exe C:\Users\Florian-KFZMeister\AppData\Local\Microsoft\Windows\INetCache\IE\LGWG11SD\ProtectorPackage2001x64[1].exe ***************** C:\Users\Florian-KFZMeister\Downloads\hp-laserjet-3050-driver-utility.exe => Moved successfully. C:\Users\Florian-KFZMeister\AppData\Local\Microsoft\Windows\INetCache\IE\LGWG11SD\ProtectorPackage2001x64[1].exe => Moved successfully. ==== End of Fixlog ==== FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-07-2014 Ran by Florian-KFZMeister (administrator) on WERKSTATT-PC on 22-07-2014 08:42:28 Running from C:\Users\Florian-KFZMeister\Desktop Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe () C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Samsung Electronics CO., LTD.) C:\ProgramData\SAMSUNG\SW Update Service\SWMAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSACCESS.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191824 2012-08-10] (Realtek Semiconductor) HKLM\...\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [766080 2012-12-05] (Qualcomm Atheros) HKLM\...\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [128640 2012-12-05] (Atheros Communications) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2917688 2012-10-16] (Synaptics Incorporated) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [97392 2012-08-15] (CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation) HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de) HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe [24504 2012-12-14] (Kaspersky Lab ZAO) HKLM-x32\...\Run: [StartDDM] => C:\Program Files (x86)\Bosch\DownloadManager\bin\runDDM.exe HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-18] (Advanced Micro Devices, Inc.) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1825984 2014-04-24] (Valve Corporation) HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Florian-KFZMeister\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHel (the data entry has 8 more characters). HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [Amazon Cloud Player] => C:\Users\Florian-KFZMeister\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2013-12-12] () HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Policies\system: [DisableLockWorkstation] 0 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung13.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com SearchScopes: HKLM - DefaultScope {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS SearchScopes: HKLM - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKLM-x32 - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS SearchScopes: HKCU - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) DPF: HKLM-x32 {55369874-02F5-47E2-A0F7-AC67E1B1866E} hxxp://www.centrodigital.de/smart/setup.ocx Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Florian-KFZMeister\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Florian-KFZMeister\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-05-15] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-05-15] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-05-15] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013-05-15] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013-05-15] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://www.google.com/" CHR Extension: (Google Docs) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-23] CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-01-23] CHR Extension: (Sicherer Zahlungsverkehr) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-01-23] CHR Extension: (Modul für das Blockieren gefährlicher Webseiten) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-01-23] CHR Extension: (Virtuelle Tastatur) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-01-23] CHR Extension: (Google Wallet) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-23] CHR Extension: (Anti-Banner) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-01-23] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-12-14] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-12-14] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-12-14] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2013-05-15] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-12-14] ==================== Services (Whitelisted) ================= R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [231552 2012-12-05] (Qualcomm Atheros Commnucations) S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593976 2012-09-05] (Samsung Electronics CO., LTD.) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 Simraceway Update Service; C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe [1630720 2013-07-11] () [File not signed] R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-05] (Atheros) [File not signed] ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-21] (Advanced Micro Devices, Inc.) R3 BTATH_HID; C:\Windows\system32\DRIVERS\btath_hid.sys [222360 2012-12-05] (Qualcomm Atheros) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-05] (Qualcomm Atheros) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) S3 CH341SER_A64; C:\Windows\System32\Drivers\CH341S64.SYS [58368 2011-11-04] (www.winchiphead.com) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [146856 2013-06-04] (Windows (R) Win 7 DDK provider) R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [21928 2013-06-04] (Windows (R) Win 7 DDK provider) S3 IntcDAud; C:\Windows\system32\DRIVERS\IntcDAud.sys [342528 2012-06-19] (Intel(R) Corporation) [File not signed] S3 intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [5338848 2012-09-17] (Intel Corporation) [File not signed] R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [627296 2014-05-20] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-12-11] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2013-05-15] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2013-05-15] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-22] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-07-10] (NetFilterSDK.com) R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-22 08:42 - 2014-07-22 08:42 - 00000000 ____D () C:\Users\Florian-KFZMeister\Desktop\FRST-OlderVersion 2014-07-22 08:14 - 2014-07-22 08:14 - 00002722 _____ () C:\Users\Florian-KFZMeister\Desktop\mbam1.txt 2014-07-21 14:08 - 2014-07-21 14:09 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Desktop\esetsmartinstaller_deu.exe 2014-07-21 13:39 - 2014-07-21 13:39 - 00001156 _____ () C:\Users\Florian-KFZMeister\Desktop\mbam.txt 2014-07-21 12:03 - 2014-07-22 07:39 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-07-21 12:03 - 2014-07-21 12:03 - 00001118 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-21 12:03 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-07-21 12:03 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2014-07-21 12:03 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-07-21 12:02 - 2014-07-21 12:02 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Florian-KFZMeister\Desktop\mbam-setup-2.0.2.1012.exe 2014-07-21 12:01 - 2014-07-21 12:01 - 00000627 _____ () C:\Users\Florian-KFZMeister\Desktop\JRT.txt 2014-07-21 11:57 - 2014-07-21 11:57 - 01016261 _____ (Thisisu) C:\Users\Florian-KFZMeister\Desktop\JRT.exe 2014-07-21 11:52 - 2014-07-21 11:52 - 00000000 ___RD () C:\Users\Florian-KFZMeister\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-07-21 11:51 - 2014-07-21 11:51 - 00000000 ____H () C:\ProgramData\cm-lock 2014-07-21 11:48 - 2014-07-21 11:48 - 01354223 _____ () C:\Users\Florian-KFZMeister\Desktop\adwcleaner_3.216.exe 2014-07-21 09:46 - 2014-07-21 09:46 - 00007268 _____ () C:\Users\Florian-KFZMeister\Desktop\GMER.log 2014-07-21 09:29 - 2014-07-21 09:29 - 704339485 _____ () C:\WINDOWS\MEMORY.DMP 2014-07-21 09:29 - 2014-07-21 09:29 - 00299272 _____ () C:\WINDOWS\Minidump\072114-35515-01.dmp 2014-07-21 09:29 - 2014-07-21 09:29 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-21 09:25 - 2014-07-22 08:42 - 00020819 _____ () C:\Users\Florian-KFZMeister\Desktop\FRST.txt 2014-07-21 09:25 - 2014-07-22 08:42 - 00000000 ____D () C:\FRST 2014-07-21 09:25 - 2014-07-21 09:26 - 00053834 _____ () C:\Users\Florian-KFZMeister\Desktop\Addition.txt 2014-07-21 09:24 - 2014-07-21 09:32 - 00000498 _____ () C:\Users\Florian-KFZMeister\Desktop\defogger_disable.log 2014-07-21 09:24 - 2014-07-21 09:24 - 00000000 _____ () C:\Users\Florian-KFZMeister\defogger_reenable 2014-07-21 09:22 - 2014-07-22 08:42 - 02090496 _____ (Farbar) C:\Users\Florian-KFZMeister\Desktop\FRST64.exe 2014-07-21 09:22 - 2014-07-21 09:22 - 00380416 _____ () C:\Users\Florian-KFZMeister\Desktop\8kgufznd.exe 2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe 2014-07-21 08:59 - 2014-07-21 08:59 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe 2014-07-21 08:59 - 2014-07-21 08:59 - 02088532 _____ () C:\Users\Florian-KFZMeister\Downloads\FRST64.exe 2014-07-19 08:28 - 2014-07-19 08:28 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-07-19 08:13 - 2014-07-19 08:13 - 00003228 _____ () C:\WINDOWS\System32\Tasks\{195AC1F4-9216-4E5D-970E-EE662B1F6FAB} 2014-07-19 08:10 - 2014-07-19 08:10 - 01707144 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer (1).exe 2014-07-19 08:08 - 2014-07-21 13:57 - 00000000 ____D () C:\Program Files\AllDaySavings 2014-07-19 08:05 - 2014-07-19 08:05 - 00822568 _____ (Reimage®) C:\Users\Florian-KFZMeister\Downloads\ReimageRepair.exe 2014-07-19 08:03 - 2014-07-19 08:04 - 01705692 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer.exe 2014-07-19 07:51 - 2014-07-19 07:51 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LavasoftStatistics 2014-07-19 07:50 - 2014-07-19 07:50 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-07-19 07:43 - 2014-07-19 07:43 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-07-18 17:17 - 2014-07-21 11:51 - 00005694 _____ () C:\WINDOWS\PFRO.log 2014-07-18 17:17 - 2014-07-18 17:18 - 00491000 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-07-18 17:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll 2014-07-18 17:13 - 2014-07-21 13:43 - 00000000 ____D () C:\AdwCleaner 2014-07-18 12:28 - 2014-07-21 11:46 - 00003494 _____ () C:\WINDOWS\System32\Tasks\Reimage Reminder 2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Reimage Protector 2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair 2014-07-18 12:16 - 2014-07-18 12:28 - 00000000 ____D () C:\rei 2014-07-18 12:15 - 2014-07-18 12:28 - 00000163 _____ () C:\WINDOWS\Reimage.ini 2014-07-18 09:07 - 2014-07-18 09:07 - 00000000 _____ () C:\Users\Florian-KFZMeister\com.attensity.bosch.esi.updateclient.StartUpdateClient.tmp 2014-07-14 08:31 - 2014-07-14 08:31 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\.eva 2014-07-14 08:29 - 2014-07-14 08:29 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Daimler 2014-07-10 21:40 - 2014-07-10 21:40 - 00046376 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\netfilter64.sys 2014-07-09 07:58 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll 2014-07-09 07:43 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe 2014-07-09 07:43 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe 2014-07-09 07:43 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2014-07-09 07:43 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2014-07-09 07:43 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2014-07-09 07:43 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 2014-07-09 07:43 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll 2014-07-09 07:43 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2014-07-09 07:43 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2014-07-09 07:43 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2014-07-09 07:42 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-07-09 07:42 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-07-09 07:42 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-07-09 07:42 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 2014-07-09 07:42 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-07-09 07:42 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-07-09 07:42 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2014-07-09 07:42 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2014-07-09 07:42 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-07-09 07:42 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-07-09 07:42 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-07-09 07:42 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2014-07-09 07:42 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-07-09 07:42 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-07-09 07:42 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-07-09 07:42 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2014-07-09 07:42 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-07-09 07:42 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-07-09 07:42 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-07-09 07:42 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-07-09 07:42 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-07-09 07:42 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-07-09 07:42 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-07-09 07:42 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-07-09 07:42 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-07-09 07:42 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-07-09 07:42 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-07-09 07:42 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll 2014-07-09 07:42 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll 2014-07-09 07:42 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2014-07-09 07:42 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2014-07-09 07:42 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2014-07-09 07:42 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2014-07-09 07:42 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 07:42 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2014-07-09 07:42 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2014-07-09 07:42 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 07:42 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2014-07-09 07:42 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2014-07-09 07:42 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2014-07-09 07:42 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2014-07-09 07:42 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2014-07-09 07:42 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2014-07-09 07:42 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2014-06-30 13:53 - 2014-06-30 13:53 - 00001674 _____ () C:\Users\Florian-KFZMeister\AppData\Local\recently-used.xbel 2014-06-30 13:44 - 2014-07-19 07:53 - 00000000 ____D () C:\Users\Florian-KFZMeister\Downloads\Musikjunkie - Guano Apes 2014 Offline Bitrate VBR 04 Numen ==================== One Month Modified Files and Folders ======= 2014-07-22 08:42 - 2014-07-22 08:42 - 00000000 ____D () C:\Users\Florian-KFZMeister\Desktop\FRST-OlderVersion 2014-07-22 08:42 - 2014-07-21 09:25 - 00020819 _____ () C:\Users\Florian-KFZMeister\Desktop\FRST.txt 2014-07-22 08:42 - 2014-07-21 09:25 - 00000000 ____D () C:\FRST 2014-07-22 08:42 - 2014-07-21 09:22 - 02090496 _____ (Farbar) C:\Users\Florian-KFZMeister\Desktop\FRST64.exe 2014-07-22 08:39 - 2013-10-30 13:04 - 01759912 _____ () C:\WINDOWS\WindowsUpdate.log 2014-07-22 08:39 - 2013-04-14 11:43 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2830974330-3213038589-3334289725-1002 2014-07-22 08:34 - 2014-01-23 12:31 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-22 08:34 - 2014-01-23 12:31 - 00001160 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-22 08:20 - 2013-10-30 10:43 - 00000064 __RSH () C:\WINDOWS\system32\Drivers\VSTXRAID.winsecurity 2014-07-22 08:14 - 2014-07-22 08:14 - 00002722 _____ () C:\Users\Florian-KFZMeister\Desktop\mbam1.txt 2014-07-22 08:04 - 2013-05-15 10:19 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-07-22 08:02 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-07-22 08:01 - 2012-11-26 08:17 - 00000360 _____ () C:\WINDOWS\Tasks\Xerox PhotoCafe Communicator.job 2014-07-22 07:56 - 2013-03-28 17:40 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\repline 2014-07-22 07:54 - 2013-10-30 10:14 - 00000064 __RSH () C:\WINDOWS\system32\Drivers\WUDFPf.winsecurity 2014-07-22 07:47 - 2013-04-15 08:19 - 00000000 ____D () C:\KfzKaufmann 2014-07-22 07:42 - 2013-09-30 06:14 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-07-22 07:42 - 2013-09-30 05:56 - 00766620 _____ () C:\WINDOWS\system32\perfh007.dat 2014-07-22 07:42 - 2013-09-30 05:56 - 00159902 _____ () C:\WINDOWS\system32\perfc007.dat 2014-07-22 07:39 - 2014-07-21 12:03 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-07-21 18:03 - 2014-01-23 12:30 - 00001156 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-21 15:55 - 2012-11-26 08:01 - 00000870 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-07-21 14:09 - 2014-07-21 14:08 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Desktop\esetsmartinstaller_deu.exe 2014-07-21 13:57 - 2014-07-19 08:08 - 00000000 ____D () C:\Program Files\AllDaySavings 2014-07-21 13:43 - 2014-07-18 17:13 - 00000000 ____D () C:\AdwCleaner 2014-07-21 13:39 - 2014-07-21 13:39 - 00001156 _____ () C:\Users\Florian-KFZMeister\Desktop\mbam.txt 2014-07-21 12:03 - 2014-07-21 12:03 - 00001118 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-21 12:02 - 2014-07-21 12:02 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Florian-KFZMeister\Desktop\mbam-setup-2.0.2.1012.exe 2014-07-21 12:01 - 2014-07-21 12:01 - 00000627 _____ () C:\Users\Florian-KFZMeister\Desktop\JRT.txt 2014-07-21 11:57 - 2014-07-21 11:57 - 01016261 _____ (Thisisu) C:\Users\Florian-KFZMeister\Desktop\JRT.exe 2014-07-21 11:55 - 2012-11-26 08:09 - 00000000 ____D () C:\ProgramData\WinClon 2014-07-21 11:52 - 2014-07-21 11:52 - 00000000 ___RD () C:\Users\Florian-KFZMeister\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-07-21 11:52 - 2014-04-17 11:11 - 00000000 __RDO () C:\Users\Florian-KFZMeister\SkyDrive 2014-07-21 11:52 - 2013-04-15 09:52 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\FreePDF_XP 2014-07-21 11:52 - 2012-11-26 08:01 - 00000868 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-07-21 11:51 - 2014-07-21 11:51 - 00000000 ____H () C:\ProgramData\cm-lock 2014-07-21 11:51 - 2014-07-18 17:17 - 00005694 _____ () C:\WINDOWS\PFRO.log 2014-07-21 11:51 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-07-21 11:51 - 2013-08-06 13:50 - 00599686 _____ () C:\Simraceway.log 2014-07-21 11:50 - 2013-10-30 12:44 - 00000000 ____D () C:\Users\Florian-KFZMeister 2014-07-21 11:50 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2014-07-21 11:48 - 2014-07-21 11:48 - 01354223 _____ () C:\Users\Florian-KFZMeister\Desktop\adwcleaner_3.216.exe 2014-07-21 11:47 - 2013-04-14 21:37 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-07-21 11:46 - 2014-07-18 12:28 - 00003494 _____ () C:\WINDOWS\System32\Tasks\Reimage Reminder 2014-07-21 11:46 - 2012-11-26 08:17 - 00003298 _____ () C:\WINDOWS\System32\Tasks\Xerox PhotoCafe Communicator 2014-07-21 11:45 - 2012-11-26 08:11 - 00000000 ____D () C:\ProgramData\Adobe 2014-07-21 11:10 - 2014-01-23 17:12 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\Schaltpläne 2014-07-21 09:46 - 2014-07-21 09:46 - 00007268 _____ () C:\Users\Florian-KFZMeister\Desktop\GMER.log 2014-07-21 09:41 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-07-21 09:32 - 2014-07-21 09:24 - 00000498 _____ () C:\Users\Florian-KFZMeister\Desktop\defogger_disable.log 2014-07-21 09:29 - 2014-07-21 09:29 - 704339485 _____ () C:\WINDOWS\MEMORY.DMP 2014-07-21 09:29 - 2014-07-21 09:29 - 00299272 _____ () C:\WINDOWS\Minidump\072114-35515-01.dmp 2014-07-21 09:29 - 2014-07-21 09:29 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-21 09:26 - 2014-07-21 09:25 - 00053834 _____ () C:\Users\Florian-KFZMeister\Desktop\Addition.txt 2014-07-21 09:24 - 2014-07-21 09:24 - 00000000 _____ () C:\Users\Florian-KFZMeister\defogger_reenable 2014-07-21 09:22 - 2014-07-21 09:22 - 00380416 _____ () C:\Users\Florian-KFZMeister\Desktop\8kgufznd.exe 2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe 2014-07-21 08:59 - 2014-07-21 08:59 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe 2014-07-21 08:59 - 2014-07-21 08:59 - 02088532 _____ () C:\Users\Florian-KFZMeister\Downloads\FRST64.exe 2014-07-21 08:27 - 2013-12-13 13:46 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LumacDaemon 2014-07-21 08:17 - 2014-03-03 13:54 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Battle.net 2014-07-19 08:28 - 2014-07-19 08:28 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-07-19 08:13 - 2014-07-19 08:13 - 00003228 _____ () C:\WINDOWS\System32\Tasks\{195AC1F4-9216-4E5D-970E-EE662B1F6FAB} 2014-07-19 08:10 - 2014-07-19 08:10 - 01707144 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer (1).exe 2014-07-19 08:05 - 2014-07-19 08:05 - 00822568 _____ (Reimage®) C:\Users\Florian-KFZMeister\Downloads\ReimageRepair.exe 2014-07-19 08:04 - 2014-07-19 08:03 - 01705692 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer.exe 2014-07-19 08:01 - 2013-08-24 08:39 - 00000000 ____D () C:\Games 2014-07-19 07:53 - 2014-06-30 13:44 - 00000000 ____D () C:\Users\Florian-KFZMeister\Downloads\Musikjunkie - Guano Apes 2014 Offline Bitrate VBR 04 Numen 2014-07-19 07:51 - 2014-07-19 07:51 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LavasoftStatistics 2014-07-19 07:50 - 2014-07-19 07:50 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft 2014-07-19 07:43 - 2014-07-19 07:43 - 00000000 ____D () C:\ProgramData\Lavasoft 2014-07-19 07:30 - 2013-07-12 17:24 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\re 2014-07-18 17:18 - 2014-07-18 17:17 - 00491000 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-07-18 17:17 - 2013-04-15 08:37 - 00000000 ____D () C:\Users\Florian-KFZMeister\.thumbnails 2014-07-18 13:01 - 2013-09-19 08:20 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\vlc 2014-07-18 12:28 - 2014-07-18 12:16 - 00000000 ____D () C:\rei 2014-07-18 12:28 - 2014-07-18 12:15 - 00000163 _____ () C:\WINDOWS\Reimage.ini 2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Reimage Protector 2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair 2014-07-18 09:07 - 2014-07-18 09:07 - 00000000 _____ () C:\Users\Florian-KFZMeister\com.attensity.bosch.esi.updateclient.StartUpdateClient.tmp 2014-07-17 13:56 - 2014-04-16 10:02 - 00000000 ____D () C:\ProgramData\WarThunder 2014-07-17 07:29 - 2013-06-11 09:43 - 00000000 ____D () C:\ProgramData\Bosch 2014-07-17 07:28 - 2013-06-11 09:43 - 00000488 _____ () C:\WINDOWS\RbSystem.ini 2014-07-16 17:11 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF 2014-07-16 12:06 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-07-16 07:13 - 2014-04-16 10:02 - 00000000 ____D () C:\Program Files (x86)\WarThunder 2014-07-14 16:39 - 2013-04-24 10:52 - 00133799 _____ () C:\Users\Florian-KFZMeister\ewa_client_0.log 2014-07-14 16:39 - 2013-04-24 10:52 - 00000000 ____D () C:\Users\Florian-KFZMeister\XFER 2014-07-14 16:24 - 2013-04-24 10:52 - 00000122 _____ () C:\Users\Florian-KFZMeister\.ewanapi_cookie 2014-07-14 08:55 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-07-14 08:31 - 2014-07-14 08:31 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\.eva 2014-07-14 08:29 - 2014-07-14 08:29 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Daimler 2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore 2014-07-10 21:40 - 2014-07-10 21:40 - 00046376 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\netfilter64.sys 2014-07-10 17:42 - 2014-03-03 13:54 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-07-09 08:03 - 2013-04-14 20:50 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-07-09 08:03 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2014-07-09 08:02 - 2013-07-23 09:05 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-07-09 08:00 - 2013-04-15 07:41 - 96441528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-07-09 07:58 - 2013-09-30 05:59 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-08 08:05 - 2014-03-03 13:55 - 00000000 ____D () C:\Program Files (x86)\Diablo III 2014-07-02 16:35 - 2013-06-19 10:56 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\Formulare und Vorlagen 2014-06-30 13:53 - 2014-06-30 13:53 - 00001674 _____ () C:\Users\Florian-KFZMeister\AppData\Local\recently-used.xbel 2014-06-30 13:53 - 2013-04-15 08:36 - 00000000 ____D () C:\Users\Florian-KFZMeister\.gimp-2.8 2014-06-26 22:55 - 2014-04-30 08:06 - 00703968 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:55 - 2014-04-30 08:06 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-25 17:58 - 2014-01-23 12:31 - 00004132 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-25 17:58 - 2014-01-23 12:30 - 00003896 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-23 10:16 - 2013-04-14 11:49 - 00001382 _____ () C:\Users\Public\Desktop\CENTROdigital SmartClient.lnk Files to move or delete: ==================== C:\ProgramData\MakeMarkerFile.exe C:\Users\EasySurvey\EasySurvey.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-21 12:14 ==================== End Of Log ============================ |
22.07.2014, 09:53 | #13 |
/// TB-Ausbilder | Windows 8.1: Werbe-Popups in Google Chrome und Opera Die Logs sehen für mich jetzt sauber aus Noch 1-2 Sachen: Update: Adobe Reader Deinstalliere bitte deine aktuelle Version von Adobe Reader Start--> Systemsteuerung--> Software--> Adobe Reader und lade dir die neue Version von Hier herunter- Entferne den Haken für den McAfee SecurityScan bzw. Google Chrome. Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Reste entfernen: Die Reihenfolge ist hier entscheidend.
Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti-Viren-Programm und zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden. Mozilla Firefox
Performance
Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
22.07.2014, 11:18 | #14 | |
| Windows 8.1: Werbe-Popups in Google Chrome und OperaZitat:
Mehr Fragen hab ich nicht und ansonsten bleibt mir nur zu sagen Vielen Vielen Dank für die verdammt schnelle und gute Hilfe!!!!! |
22.07.2014, 12:08 | #15 |
/// TB-Ausbilder | Windows 8.1: Werbe-Popups in Google Chrome und Opera IMHO: Wir haben auf Arbeit auch Kaspersky, find die Erkennungsrate sehr gut. Gibt zwar (für mich als Sysadmin) andere Ärgernisse bei Kaspersky, aber die haben eher mit administrativen Aufgaben zu tun ;-) Malwarebytes kannst du problemlos zusätzlich einsetzen, da ein On-Demand Scanner, also "Auf Aufforderung". Somit hat Kaspersky oder jeder andere On-Access (Bei Zugriff auf Dateien) freie Bahn und wird nicht gestört. Daheim nutz ich Emsisoft Anti Malware als Virenschutz. Das "beste" Virenschutzprogramm gibts eh nicht. Avira unterstütze ich, sowie ein Großteil der Board-Mitarbeiter nicht, da Avira die Ask-Toolbar mit der Free-Version koppelt. Das ist, wie gesagt, meine persönliche Meinung und muss sich nicht mit den Aussagen anderer Boardmitarbeiter decken. |
Themen zu Windows 8.1: Werbe-Popups in Google Chrome und Opera |
branding, device driver, ebanking, flash player, homepage, igdpmd64.sys, installation, internet, kaspersky, monitor, msil/adware.ibryte.d, problem, prozess, pup.optional.adpeak, pup.optional.adpeak.a, pup.optional.betterdeals.a, pup.optional.superfish.a, required, security, software, svchost.exe, tastatur, usb, win32/driverboss.b, win32/toolbar.babylon.t, win64/adware.adpeak.c, windows, windowsapps |