|
Plagegeister aller Art und deren Bekämpfung: Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlllWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
02.09.2014, 17:37 | #1 |
| Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll Hallo zusammen, folgendes Problem besteht bei mir seit gestern. McAfee erkennt potentiell unerwünschtes Programm C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll Dieses laesst sich aber nicht isolieren und die Meldung poppt so immer wieder auf und lasst sich auch nicht dauerhaft schliessen. Kann mir jemand hierbei helfen? MfG, Lukas |
02.09.2014, 19:18 | #2 |
/// the machine /// TB-Ausbilder | Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
02.09.2014, 20:03 | #3 |
| Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll FRST Additions Logfile:
__________________[CODE]Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-08-2014 02 Ran by Lukas at 2014-09-02 20:44:43 Running from C:\Users\Lukas\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Acer Backup Manager (HKLM-x32\...\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.85 - NTI Corporation) Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1510 - CyberLink Corp.) Acer Crystal Eye Webcam (x32 Version: 1.0.1510 - CyberLink Corp.) Hidden Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3006 - Acer Incorporated) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Acer Incorporated) Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3004 - Acer Incorporated) Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0401.2011 - Acer Incorporated) Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3005 - Acer Incorporated) Acer VCM (HKLM-x32\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3004 - Acer Incorporated) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.) Adobe AIR (x32 Version: 1.5.0.7220 - Adobe Systems Inc.) Hidden Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Reader X (10.1.3) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.3 - Adobe Systems Incorporated) Adobe Reader XI (11.0.08) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) AppGraffiti (HKLM-x32\...\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1) (Version: 1.0.0.28 - Omega Partners Ltd) Ask Toolbar (HKLM-x32\...\{86D4B82A-ABED-442A-BE86-96357B70F4FE}) (Version: 1.14.1.0 - Ask.com) <==== ATTENTION Ask Toolbar Updater (HKCU\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.0.20007 - Ask.com) <==== ATTENTION Backup Manager V3 (x32 Version: 3.0.0.85 - NTI Corporation) Hidden Broadcom Gigabit Integrated Controller (HKLM\...\{394E442A-637D-43EF-B402-4CFD88263CF0}) (Version: 14.6.1.5 - Broadcom Corporation) CollageIt 1.9.3 (HKLM-x32\...\{D9757258-30B2-496E-86F2-84920C5858E1}_is1) (Version: 1.9.3 - PearlMountain Technology Co., Ltd) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.6.0 - Conexant) Corel WinDVD (HKLM-x32\...\{5C1F18D2-F6B7-4242-B803-B5A78648185D}) (Version: 10.0.5.846 - Corel Inc.) Custom (Version: 01.00.00.000 - Wave Systems Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden dm-Fotowelt (HKLM-x32\...\dm-Fotowelt) (Version: 5.0.1 - CEWE COLOR AG u Co. OHG) Doppelkopf XXL (HKCU\...\Doppelkopf XXL) (Version: - ) Dropbox (HKCU\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.) eBay Worldwide (HKLM-x32\...\{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}) (Version: 2.1.0901 - OEM) EgisTec ES603 WDM Driver (HKLM-x32\...\InstallShield_{AE4167B0-F589-4D2A-BF05-E181D543C49F}) (Version: 3.0.16.0 - Egis Technology Inc.) EMBASSY Security Center (Version: 04.03.00.081 - Wave Systems Corp.) Hidden Embassy Trust Suite - Acer Edition (Version: 01.02.01.000 - Wave Systems Corp) Hidden ES603 WDM Driver (x32 Version: 3.0.16.0 - Egis Technology Inc.) Hidden Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Garmin ANT Agent (HKLM\...\{4E21D7C1-80CA-48A0-9983-9F60EEA70B50}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Garmin Communicator Plugin (HKLM-x32\...\{8ED02445-D491-414C-A56D-2ED6BBB7239A}) (Version: 3.0.1 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries) Garmin WebUpdater (HKLM-x32\...\{00FE2935-FB56-4410-AB5F-D6E70C1771D2}) (Version: 2.5.6 - Garmin Ltd or its subsidiaries) Garmin WebUpdater (HKLM-x32\...\{B39177F9-269D-4A9B-82F2-7A48589CCCEF}) (Version: 2.5.2 - Garmin Ltd or its subsidiaries) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.143 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3006 - Acer Incorporated) Install Absolute Data Protect (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 1.0.0.39 - Absolute Software) InstantView (HKLM-x32\...\InstallShield_{9C92176C-CAA2-481D-BD9C-9DED2A36C290}) (Version: 3.0.12.0 - Splashtop Inc.) InstantView (x32 Version: 3.0.12.0 - Splashtop Inc.) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2345 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan) Java(TM) 7 Update 4 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417004FF}) (Version: 7.0.40 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Konz 2013 (HKLM-x32\...\InstallShield_{76651FD7-2B71-4B61-9F3A-E82F52F08D92}) (Version: 1.00.0000 - USM) Konz 2013 (x32 Version: 1.00.0000 - USM) Hidden Launch Manager (HKLM-x32\...\LManager) (Version: 6.0.4 - Acer Inc.) Malwarebytes Anti-Malware Version 1.70.0.1100 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.70.0.1100 - Malwarebytes Corporation) McAfee Internet Security Suite (HKLM-x32\...\MSC) (Version: 12.8.988 - McAfee, Inc.) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Save as PDF Add-in for 2007 Microsoft Office programs (HKLM-x32\...\{90120000-00B0-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) newsXpresso (HKLM-x32\...\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.) newsXpresso (x32 Version: 1.0.0.40 - esobi Inc.) Hidden Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8942 - NTI Corporation) NTI Media Maker 9 (x32 Version: 9.0.2.8942 - NTI Corporation) Hidden NTRU TCG Software Stack (Version: 2.1.34 - Security Innovation) Hidden Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ProShield (HKLM-x32\...\InstallShield_{08CCD7B4-9EED-4926-805D-C4FFF869989A}) (Version: 1.0.44.0 - Egis Technology Inc.) ProShield (Version: 1.0.44.0 - Egis Technology Inc.) Hidden ProShield TPM (Version: 01.01.00.012 - Wave Systems Corp) Hidden Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7600.69 - Realtek Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.30.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.30.0 - Renesas Electronics Corporation) Hidden Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) SiteRanker (HKLM-x32\...\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}_is1) (Version: 1.0.0.21 - Crawler, LLC) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SportTracks 3.1 (HKLM-x32\...\{99895EF0-B290-4B21-B1FE-FB00E1B5D195}) (Version: 3.1.4871 - Zone Five Software) Steuer 2012 (HKLM-x32\...\{01159E8A-44F7-4885-A7F9-872CE4D74063}) (Version: 20.00.8137 - Buhl Data Service GmbH) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1150 - SUPERAntiSpyware.com) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.14.0 - Synaptics Incorporated) t@x 2012 (HKLM-x32\...\{0E806605-5B82-4A4F-BC31-AA4FADA03C42}) (Version: 19.00.7303 - Buhl Data Service GmbH) t@x 2014 (HKLM-x32\...\{2547CF96-DBB7-4EDD-9327-0EFDD0D1FA8A}) (Version: 21.00.8480 - Buhl Data Service GmbH) TrainingPeaks Device Agent (HKLM-x32\...\{8C477370-143C-4D9D-BD33-289D1C1A0870}) (Version: 3.0.85 - TrainingPeaks) TuneUp Utilities 2012 (HKLM-x32\...\TuneUp Utilities 2012) (Version: 12.0.3500.13 - TuneUp Software) TuneUp Utilities 2012 (x32 Version: 12.0.3500.13 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3500.13 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) Wave Infrastructure Installer (Version: 07.67.00.0005 - Wave Systems Corp) Hidden Wave Support Software Installer (Version: 05.13.00.021 - Wave Systems Corp) Hidden Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3102 - Acer Incorporated) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7300 - Broadcom Corporation) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin) Windows Installer Clean Up (HKLM-x32\...\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}) (Version: 3.00.00.0000 - Microsoft Corporation) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows-Treiberpaket - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2) (HKLM\...\24DA573F901348FFDFF7717497830D45BE0C362E) (Version: 07/07/2009 1.12.2 - Dynastream Innovations) Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}\InprocServer32 -> C:\Program Files (x86)\AppGraffiti\AppGraffiti64.dll (Omega Partners Ltd) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}\InprocServer32 -> C:\Program Files (x86)\AppGraffiti\AppGraffiti64.dll (Omega Partners Ltd) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-501_Classes\CLSID\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}\InprocServer32 -> C:\Program Files (x86)\AppGraffiti\AppGraffiti64.dll (Omega Partners Ltd) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-501_Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}\InprocServer32 -> C:\Program Files (x86)\AppGraffiti\AppGraffiti64.dll (Omega Partners Ltd) ==================== Restore Points ========================= 10-08-2014 08:24:31 Windows Update 10-08-2014 17:01:08 Windows-Sicherung 12-08-2014 17:25:28 Wiederherstellungsvorgang 17-08-2014 18:43:00 Windows-Sicherung 24-08-2014 18:12:46 Windows-Sicherung 30-08-2014 20:32:06 Windows Update 31-08-2014 17:02:45 Windows-Sicherung 01-09-2014 13:45:48 Windows Update 01-09-2014 20:57:46 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2012-05-19 09:32 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {022A01D8-D879-4C1A-A4B2-AFF10FAF06CF} - System32\Tasks\{FF17CDB8-8C5B-4A26-848E-0F36130C8DA8} => Firefox.exe Skype auf Ihren Computer herunterladen ? Windows, Mac und Linux ? Skype herunterladen Task: {06A00C55-465C-42CE-87FA-2024B1E69F15} - System32\Tasks\{21D2A9EE-A847-4670-9FE7-6711B8FA9C6A} => Firefox.exe Task: {36158F5A-2FA7-46CA-99CB-9629EF26CC90} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-23] (Adobe Systems Incorporated) Task: {40961FA9-90ED-499A-B7DA-F83FA311B538} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2012-04-05] (TuneUp Software) Task: {803A023E-3F43-43AA-873F-71C6A1EB98E4} - System32\Tasks\{8CB05960-CF37-4A51-B3F3-8EE6370BE276} => Firefox.exe Skype auf Ihren Computer herunterladen ? Windows, Mac und Linux ? Skype herunterladen Task: {8A9C8ADE-EF09-4725-BA9C-9596D635B3D5} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {BC7462CC-E59A-4A52-9FDD-C2328FFD993B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21] (Google Inc.) Task: {CEB91A61-C512-446C-88FA-2178D898A876} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe Task: {E9AAF687-3A07-454D-969C-3CF9CF42B653} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe <==== ATTENTION Task: {EC303973-B23D-4645-8CFF-28679A8EF37C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-27 20:42 - 2014-07-02 11:55 - 00665088 ____N () c:\program files (x86)\movies toolbar\datamngr\x64\apcrtldr.dll 2011-03-31 19:58 - 2011-03-31 19:58 - 01407536 _____ () C:\Program Files\Acer ProShield\LIBEAY32.dll 2010-07-13 14:02 - 2010-07-13 14:02 - 01629696 _____ () C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe 2011-06-02 18:38 - 2011-03-27 01:29 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2010-12-10 15:53 - 2010-12-10 15:53 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2014-06-23 20:39 - 2013-10-30 17:45 - 00587856 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe 2014-05-08 20:40 - 2014-07-02 11:55 - 00019456 ____N () c:\program files (x86)\movies toolbar\datamngr\mgrldr.dll 2014-01-27 20:42 - 2014-07-02 11:55 - 00489472 ____N () c:\program files (x86)\movies toolbar\datamngr\apcrtldr.dll 2011-02-15 20:37 - 2011-02-15 20:37 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll 2011-02-15 20:36 - 2011-02-15 20:36 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll 2011-02-15 20:37 - 2011-02-15 20:37 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 09572944 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wgui14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00034896 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsdcom48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00308816 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rscorewinapi48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00321616 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsguiwinapi48.dll 2014-06-23 20:36 - 2013-10-30 17:46 - 03674192 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wcore14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00136272 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsodbc48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 02467408 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wfvie14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01855568 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wsteu14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01904208 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wreli14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 04277840 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wauff14.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 01043456 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-core.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 00094720 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-shared.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 00250368 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-contribs-lib.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01396816 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wmain14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 05019728 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae114.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01666128 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae214.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01786448 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae314.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01624144 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae414.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01125456 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\whau114.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01316944 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\whau214.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01278544 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wwerb14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 06818384 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wkont14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01266768 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wimp14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01322064 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wfabu14.dll 2014-09-02 17:39 - 2014-09-02 17:39 - 00043008 _____ () c:\users\lukas\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuyroh3.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Lukas\AppData\Roaming\Dropbox\bin\libcef.dll 2012-07-30 22:42 - 2014-08-07 11:22 - 03800688 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Lukas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: iLivid => "C:\Users\Lukas\AppData\Local\iLivid\iLivid.exe" -autorun MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Faulty Device Manager Devices ============= Name: Microsoft-Adapter für Miniports virtueller WiFis Description: Microsoft-Adapter für Miniports virtueller WiFis Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: vwifimp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (09/02/2014 08:36:57 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm FRST64.exe, Version 31.8.2014.2 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 940 Startzeit: 01cfc6dadc331a5a Endzeit: 9 Anwendungspfad: C:\Users\Lukas\Downloads\FRST64.exe Berichts-ID: 16aa8c3e-32d0-11e4-aa73-206a8a432415 Error: (09/02/2014 06:07:05 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 31.0.0.5310, Zeitstempel: 0x53c75e91 Name des fehlerhaften Moduls: mozalloc.dll, Version: 31.0.0.5310, Zeitstempel: 0x53c72e91 Ausnahmecode: 0x80000003 Fehleroffset: 0x0000141b ID des fehlerhaften Prozesses: 0x7cc Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Error: (09/02/2014 06:07:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 31.0.0.5310, Zeitstempel: 0x53c75e72 Name des fehlerhaften Moduls: apcrtldr.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x53b3d296 Ausnahmecode: 0xc0000005 Fehleroffset: 0x733a1340 ID des fehlerhaften Prozesses: 0x1060 Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0 Pfad der fehlerhaften Anwendung: firefox.exe1 Pfad des fehlerhaften Moduls: firefox.exe2 Berichtskennung: firefox.exe3 Error: (09/02/2014 05:47:54 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/02/2014 05:46:13 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/02/2014 02:48:19 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/01/2014 10:58:20 PM) (Source: MsiInstaller) (EventID: 11402) (User: NT-AUTORITÄT) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1402.Could not open key: UNKNOWN\Components\7E756C51681BDA34F86C2167896E312E\67D6ECF5CD5FBA732B8B22BAC8DE1B4D. System error 5. Verify that you have sufficient access to that key, or contact your support personnel. Error: (09/01/2014 09:36:18 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 31.0.0.5310, Zeitstempel: 0x53c75e72 Name des fehlerhaften Moduls: apcrtldr.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x53b3d296 Ausnahmecode: 0xc0000005 Fehleroffset: 0x73461340 ID des fehlerhaften Prozesses: 0x1c30 Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0 Pfad der fehlerhaften Anwendung: firefox.exe1 Pfad des fehlerhaften Moduls: firefox.exe2 Berichtskennung: firefox.exe3 Error: (09/01/2014 09:17:26 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/01/2014 08:22:31 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (09/02/2014 08:21:17 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SPMDES erreicht. Error: (09/02/2014 08:20:47 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SPMDES erreicht. Error: (09/02/2014 08:20:46 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {06622D85-6856-4460-8DE1-A81921B41C4B} Error: (09/02/2014 07:18:50 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SPMDES erreicht. Error: (09/02/2014 07:18:20 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SPMDES erreicht. Error: (09/02/2014 07:17:45 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SPMDES erreicht. Error: (09/02/2014 07:17:15 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SPMDES erreicht. Error: (09/02/2014 06:59:09 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SPMDES erreicht. Error: (09/02/2014 05:54:23 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Error: (09/02/2014 05:51:05 PM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Microsoft Office Sessions: ========================= Error: (05/03/2014 03:25:14 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6695.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 71 seconds with 60 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-06-26 17:52:25.731 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-26 17:52:25.419 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-02 18:56:47.885 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-02 18:56:47.602 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-22 19:44:48.728 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-22 19:44:48.517 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-05-19 00:03:56.921 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-05-19 00:03:56.889 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-08-2014 02 Ran by Lukas (administrator) on LUKAS-PC on 02-09-2014 20:23:00 Running from C:\Users\Lukas\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Egis Technology Inc. ) C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. ) C:\Program Files\Acer ProShield\x86\EgisService.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Bandoo Media Inc.) C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Bandoo Media Inc.) C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\ReminderService.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\DVMExportService.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Bandoo Media Inc.) C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\aoiosnap.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\LockKey.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (McAfee, Inc.) C:\Program Files\McAfee\MSM\McSmtFwk.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoUpdateCheck.exe (Microsoft Corporation) C:\Windows\System32\LogonUI.exe (McAfee, Inc.) C:\Program Files\McAfee\VirusScan\McVsShld.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\aoiosnap.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\LockKey.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe (GARMIN Corp.) C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe (Dropbox, Inc.) C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Egis Technology Inc. ) C:\Program Files\Acer ProShield\EgisTSR.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Crawler, LLC) C:\Program Files (x86)\SiteRanker\SiteRankTray.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (McAfee, Inc.) C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe (Microsoft Corporation) C:\Windows\System32\wermgr.exe (Microsoft Corporation) C:\Windows\System32\wermgr.exe (Microsoft Corporation) C:\Windows\System32\prevhost.exe (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (McAfee, Inc.) C:\Program Files\McAfee\VirusScan\McVsShld.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (McAfee, Inc.) C:\Program Files\McAfee\VirusScan\McVsMap.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [524928 2011-05-07] (Conexant Systems, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2697512 2011-02-18] (Synaptics Incorporated) HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-22] (Acer Incorporated) HKLM\...\Run: [ProShieldTSR] => C:\Program Files\Acer ProShield\EgisTSR.exe [165936 2011-03-31] (Egis Technology Inc. ) HKLM\...\Run: [InstantView Agent] => C:\Program Files (x86)\InstantView\tools\aoiosnap.exe [1127840 2011-04-28] (Splashtop Inc.) HKLM\...\Run: [InstantView LockKey] => C:\Program Files (x86)\InstantView\tools\LockKey.exe [1498472 2011-04-29] (Splashtop Inc.) HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-02-15] (NTI Corporation) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1097296 2011-04-13] (Dritek System Inc.) HKLM-x32\...\Run: [SiteRanker] => C:\Program Files (x86)\SiteRanker\SiteRankTray.exe [320000 2011-09-12] (Crawler, LLC) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [ANT Agent] => C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe [14731776 2013-02-15] (GARMIN Corp.) HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_14_0_0_145_Plugin.exe [851632 2014-07-23] (Adobe Systems Incorporated) HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-4073307474-3872349722-3587453100-501\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browsemngr.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browsermngr.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\bundlesweetimsetup.exe: [Debugger] tasklist.exe IFEO\cltmngsvc.exe: [Debugger] tasklist.exe IFEO\delta babylon.exe: [Debugger] tasklist.exe IFEO\delta tb.exe: [Debugger] tasklist.exe IFEO\delta2.exe: [Debugger] tasklist.exe IFEO\deltainstaller.exe: [Debugger] tasklist.exe IFEO\deltasetup.exe: [Debugger] tasklist.exe IFEO\deltatb.exe: [Debugger] tasklist.exe IFEO\deltatb_2501-c733154b.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\iminentsetup.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\rjatydimofu.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\sweetimsetup.exe: [Debugger] tasklist.exe IFEO\tbdelta.exetoolbar783881609.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk ShortcutTarget: Acer VCM.lnk -> C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\t@x aktuell.lnk ShortcutTarget: t@x aktuell.lnk -> C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe () Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch URLSearchHook: HKCU - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=887&systemid=406&v=a13251-240&apn_uid=5924321086234305&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=887&systemid=406&v=a13251-240&apn_uid=5924321086234305&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - DefaultScope {E93B7101-F66B-4178-82CF-36C2D0B941A9} URL = hxxp://de.search.yahoo.com/search?fr=mcafee&type=A011DE662&p={SearchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {09598583-814E-4AD3-946D-8332FFB2AB1E} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=887&systemid=406&v=a13251-240&apn_uid=5924321086234305&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - {E93B7101-F66B-4178-82CF-36C2D0B941A9} URL = hxxp://de.search.yahoo.com/search?fr=mcafee&type=A011DE662&p={SearchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: No Name -> {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} -> No File BHO-x32: AppGraffiti -> {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} -> C:\Program Files (x86)\AppGraffiti\AppGraffiti.dll (Omega Partners Ltd) BHO-x32: EgisPBIE Sign-in Helper -> {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} -> C:\Program Files\Acer ProShield\x86\EgisPBIE.dll (Egis Technology Inc.) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Toolbar: HKCU - No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Lukas\AppData\Roaming\Mozilla\Firefox\Profiles\iakpctl9.default-1406566022487 FF Homepage: hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-887&v=a13251-240&t=4 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.4.0 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.4.0 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{41ecbc0b-34d5-4cd4-935f-253a30e2cb7e}] - C:\Program Files\Acer ProShield\FFExt FF Extension: Online Accounts Extension - C:\Program Files\Acer ProShield\FFExt [2011-06-02] FF HKLM-x32\...\Firefox\Extensions: [{d4da7309-b89a-45ec-8ebb-cfb2ae13618b}] - C:\Program Files\Acer ProShield\FFExt20 FF Extension: Online Accounts Extension - C:\Program Files\Acer ProShield\FFExt20 [2011-06-02] FF HKLM-x32\...\Firefox\Extensions: [siteranker@siteranker.com] - C:\Program Files (x86)\SiteRanker\firefox FF Extension: SiteRanker - C:\Program Files (x86)\SiteRanker\firefox [2012-02-29] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-11-28] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2011-11-28] FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] Chrome: ======= CHR HomePage: Default -> hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-887&v=a13251-240&t=4 CHR RestoreOnStartup: Default -> "hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-887&v=a13251-240&t=4" CHR StartupUrls: Default -> "hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-887&v=a13251-240&t=4" CHR DefaultSearchProvider: Default -> Ask.com CHR DefaultSearchURL: Default -> hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=887&systemid=406&v=a13251-240&apn_uid=5924321086234305&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll No File CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.270.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U27) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (Adobe Acrobat) - c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Garmin Communicator Plug-In) - C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll () CHR Profile: C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (SiteAdvisor) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2012-05-21] CHR Extension: (Google Wallet) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-07] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2011-08-12] (SUPERAntiSpyware.com) [File not signed] R2 DatamngrCoordinator; C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe [3573248 2014-07-02] (Bandoo Media Inc.) R2 EgisTec Service; C:\Program Files\Acer ProShield\x86\EgisService.exe [195120 2011-03-31] (Egis Technology Inc. ) R2 EgisTec Ticket Service; C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe [205360 2011-03-31] (Egis Technology Inc. ) R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [398184 2012-12-14] (Malwarebytes Corporation) [File not signed] R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [682344 2012-12-14] (Malwarebytes Corporation) [File not signed] R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [603424 2014-06-12] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-07-24] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation) R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation) R2 ReminderService; C:\Program Files (x86)\InstantView\tools\ReminderService.exe [29560 2011-04-29] (Splashtop Inc.) R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated) S3 SecureStorageService; C:\Program Files\Acer ProShield\Secure Storage Manager\SecureStorageService.exe [2128776 2011-01-06] (Wave Systems Corp.) R2 SPMDES; C:\Program Files (x86)\InstantView\tools\DVMExportService.exe [467832 2011-04-29] (Splashtop Inc.) R2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1629696 2010-07-13] () [File not signed] R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143552 2012-04-05] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.) R1 DVMIO; C:\Program Files (x86)\InstantView\tools\dvmio_x64.sys [19560 2011-04-28] (DeviceVM, Inc.) R1 F06DEFF2-5B9C-490D-910F-35D3A91196222; C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\setmgrc2.cfg [41848 2014-07-02] (Bandoo Media Inc.) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [44480 2011-05-17] (libusb-win32 / Wiki / Home) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [24176 2012-12-14] (Malwarebytes Corporation) [File not signed] R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.) R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [444720 2014-07-24] (McAfee, Inc.) S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96592 2014-07-24] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-03-29] (TuneUp Software) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-02 20:23 - 2014-09-02 20:25 - 00033384 _____ () C:\Users\Lukas\Downloads\FRST.txt 2014-09-02 20:22 - 2014-09-02 20:23 - 00000000 ____D () C:\FRST 2014-09-02 20:22 - 2014-09-02 20:22 - 02104832 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64(1).exe 2014-09-02 20:21 - 2014-09-02 20:22 - 02104832 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64.exe 2014-09-02 17:41 - 2014-09-02 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-09-01 22:50 - 2014-09-01 22:50 - 00037888 ___SH () C:\Users\Lukas\Desktop\Thumbs.db 2014-08-27 17:29 - 2014-08-27 17:30 - 00000000 ____D () C:\Users\Lukas\AppData\Local\{F631B55A-3E1C-43D5-89C8-B9CBE4F63844} 2014-08-24 23:11 - 2014-08-24 23:13 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2014-2015 2014-08-18 21:25 - 2014-08-25 21:45 - 00000000 ____D () C:\Users\Gast\Desktop\Caro Koll.mat 2014-08-18 19:47 - 2014-08-30 18:42 - 00000001 ____R () C:\Users\Lukas\serverport 2014-08-18 19:47 - 2014-08-18 19:47 - 00000000 ____D () C:\Users\Lukas\.jivex 2014-08-14 13:50 - 2014-09-01 00:02 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Franz 2014-08-12 22:33 - 2014-05-03 16:49 - 10510963 ____R () C:\Users\Lukas\Documents\Historie von Schumacher, Lukas~backup-140812.logbook3 2014-08-12 20:12 - 2014-08-12 20:12 - 00000000 ____D () C:\Users\Gast\Desktop\Tischkalender 2014-08-12 20:09 - 2014-08-14 12:48 - 00000000 ____D () C:\Users\Gast\Desktop\UB's - Klausuren etc. anderer 2014-08-06 17:40 - 2014-08-24 15:22 - 00000000 ____D () C:\Users\Gast\Desktop\Statement Tanja 2014-08-06 14:08 - 2014-08-31 23:58 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Spanisch ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-02 20:25 - 2014-09-02 20:23 - 00033384 _____ () C:\Users\Lukas\Downloads\FRST.txt 2014-09-02 20:23 - 2014-09-02 20:22 - 00000000 ____D () C:\FRST 2014-09-02 20:22 - 2014-09-02 20:22 - 02104832 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64(1).exe 2014-09-02 20:22 - 2014-09-02 20:21 - 02104832 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64.exe 2014-09-02 20:22 - 2011-09-16 00:41 - 00000177 ____H () C:\dvmexp.idx 2014-09-02 20:20 - 2013-10-12 19:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-02 20:20 - 2012-05-21 21:29 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-09-02 20:20 - 2011-06-02 09:01 - 01891680 _____ () C:\Windows\WindowsUpdate.log 2014-09-02 17:41 - 2014-09-02 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-09-02 17:41 - 2011-05-18 19:45 - 00001848 _____ () C:\Users\Public\Desktop\McAfee Internet Security Suite.lnk 2014-09-02 17:40 - 2013-08-11 15:58 - 00000000 ___RD () C:\Users\Lukas\Dropbox 2014-09-02 17:40 - 2013-08-11 15:55 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Dropbox 2014-09-02 17:39 - 2012-05-21 21:29 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-09-02 17:39 - 2011-09-20 11:23 - 00000000 ____D () C:\Program Files (x86)\SiteRanker 2014-09-02 17:37 - 2014-07-04 18:21 - 00000000 ____D () C:\ProgramData\Datamngr 2014-09-02 14:56 - 2009-07-14 06:45 - 00024656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-02 14:56 - 2009-07-14 06:45 - 00024656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-02 14:48 - 2012-05-19 09:38 - 00000436 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-09-02 14:48 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-02 14:48 - 2009-07-14 06:51 - 00156341 _____ () C:\Windows\setupact.log 2014-09-01 22:50 - 2014-09-01 22:50 - 00037888 ___SH () C:\Users\Lukas\Desktop\Thumbs.db 2014-09-01 20:22 - 2010-11-21 05:47 - 00215774 _____ () C:\Windows\PFRO.log 2014-09-01 19:59 - 2013-08-11 15:56 - 00002757 _____ () C:\Windows\wininit.ini 2014-09-01 00:06 - 2011-09-16 13:15 - 00000432 _____ () C:\Windows\BRWMARK.INI 2014-09-01 00:02 - 2014-08-14 13:50 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Franz 2014-08-31 23:58 - 2014-08-06 14:08 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Spanisch 2014-08-30 18:42 - 2014-08-18 19:47 - 00000001 ____R () C:\Users\Lukas\serverport 2014-08-30 18:36 - 2011-09-15 13:18 - 00000000 ____D () C:\Users\Lukas 2014-08-28 19:38 - 2011-11-28 21:17 - 00000000 ____D () C:\Program Files\Common Files\McAfee 2014-08-28 19:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-08-27 17:30 - 2014-08-27 17:29 - 00000000 ____D () C:\Users\Lukas\AppData\Local\{F631B55A-3E1C-43D5-89C8-B9CBE4F63844} 2014-08-25 22:38 - 2014-07-28 17:45 - 00000000 ____D () C:\Users\Gast\Desktop\Franzi Mat Examen 2014-08-25 21:45 - 2014-08-18 21:25 - 00000000 ____D () C:\Users\Gast\Desktop\Caro Koll.mat 2014-08-24 23:21 - 2011-06-02 18:52 - 02097526 _____ () C:\Windows\system32\perfh007.dat 2014-08-24 23:21 - 2011-06-02 18:52 - 00599696 _____ () C:\Windows\system32\perfc007.dat 2014-08-24 23:21 - 2009-07-14 07:13 - 00006264 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-24 23:13 - 2014-08-24 23:11 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2014-2015 2014-08-24 15:22 - 2014-08-06 17:40 - 00000000 ____D () C:\Users\Gast\Desktop\Statement Tanja 2014-08-20 21:59 - 2014-05-23 22:48 - 00000000 ____D () C:\Users\Gast\Desktop\Kolloquium OBAS 2014-08-20 20:05 - 2011-09-16 15:14 - 00000000 ____D () C:\Users\Lukas\Documents\Meine Projekte 2014-08-18 19:51 - 2013-08-11 15:58 - 00001021 _____ () C:\Users\Lukas\Desktop\Dropbox.lnk 2014-08-18 19:51 - 2013-08-11 15:56 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-08-18 19:47 - 2014-08-18 19:47 - 00000000 ____D () C:\Users\Lukas\.jivex 2014-08-14 21:34 - 2013-09-03 17:43 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2013-14 2014-08-14 12:48 - 2014-08-12 20:09 - 00000000 ____D () C:\Users\Gast\Desktop\UB's - Klausuren etc. anderer 2014-08-14 10:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-08-12 22:33 - 2011-10-07 00:46 - 11686864 _____ () C:\Users\Lukas\Documents\Historie von Schumacher, Lukas.logbook3 2014-08-12 21:32 - 2011-10-15 14:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-08-12 20:13 - 2013-08-12 09:34 - 00000000 ____D () C:\Users\Gast\Desktop\Hochzeit 2013 2014-08-12 20:12 - 2014-08-12 20:12 - 00000000 ____D () C:\Users\Gast\Desktop\Tischkalender 2014-08-12 20:11 - 2013-08-14 23:20 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2012-2013 2014-08-12 20:08 - 2013-01-06 12:00 - 00000000 ____D () C:\Users\Gast\Desktop\Sonstiges 2014-08-12 20:08 - 2012-11-12 21:30 - 00000000 ____D () C:\Users\Gast\Desktop\OBAS 2014-08-12 19:52 - 2014-07-28 19:05 - 00000000 ____D () C:\Windows\pss 2014-08-12 19:52 - 2014-04-30 21:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-12 19:52 - 2012-10-20 10:23 - 00000000 ____D () C:\Users\Gast 2014-08-12 19:52 - 2012-07-30 22:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-12 19:52 - 2011-10-16 20:32 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-08-12 19:52 - 2011-09-16 00:31 - 00000000 ___HD () C:\dvmexp 2014-08-12 19:52 - 2011-05-18 20:24 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-08-12 19:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-08-12 19:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\L2Schemas 2014-08-06 18:35 - 2012-10-20 10:23 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Adobe 2014-08-05 09:16 - 2013-12-07 18:50 - 00000000 ____D () C:\Users\Lukas\Documents\Steuer Hatschiergasse Some content of TEMP: ==================== C:\Users\Lukas\AppData\Local\Temp\AntAgent_Installer_AMI.exe C:\Users\Lukas\AppData\Local\Temp\BundleSweetIMSetup.exe C:\Users\Lukas\AppData\Local\Temp\contentDATs.exe C:\Users\Lukas\AppData\Local\Temp\Delta.exe C:\Users\Lukas\AppData\Local\Temp\DeltaTB.exe C:\Users\Lukas\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuyroh3.dll C:\Users\Lukas\AppData\Local\Temp\install_reader11_de_ltr5x64d_awc_aih.exe C:\Users\Lukas\AppData\Local\Temp\MybabylonTB.exe C:\Users\Lukas\AppData\Local\Temp\SecurityScan_Release.exe C:\Users\Lukas\AppData\Local\Temp\SkypeSetup.exe C:\Users\Lukas\AppData\Local\Temp\WSSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-17 21:40 ==================== End Of Log ============================ --- --- --- |
03.09.2014, 14:02 | #4 |
/// the machine /// TB-Ausbilder | Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.09.2014, 21:58 | #5 |
| Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll hi, Combofix Logfile: Code:
ATTFilter ComboFix 14-08-31.01 - Lukas 03.09.2014 22:23:03.3.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3944.2065 [GMT 2:00] ausgeführt von:: c:\users\Lukas\Desktop\ComboFix.exe AV: McAfee Anti-Virus und Anti-Spyware *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892} FW: McAfee Firewall *Disabled* {959DA8E2-3527-57D1-4915-924367AD4FE9} SP: McAfee Anti-Virus und Anti-Spyware *Disabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Lukas\AppData\Local\assembly\tmp . . ((((((((((((((((((((((( Dateien erstellt von 2014-08-03 bis 2014-09-03 )))))))))))))))))))))))))))))) . . 2014-09-03 20:45 . 2014-09-03 20:45 -------- d-----w- c:\users\Public\AppData\Local\temp 2014-09-03 20:45 . 2014-09-03 20:45 -------- d-----w- c:\users\Gast\AppData\Local\temp 2014-09-03 20:45 . 2014-09-03 20:45 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-09-03 19:51 . 2014-09-03 19:51 3231696 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dcompiler_46.dll 2014-09-02 18:41 . 2014-08-07 09:22 75376 ----a-w- c:\program files (x86)\Mozilla Firefox\updated\breakpadinjector.dll 2014-09-02 18:41 . 2014-08-07 09:22 46704 ----a-w- c:\program files (x86)\Mozilla Firefox\updated\browser\components\browsercomps.dll 2014-09-02 18:41 . 2014-08-07 09:22 20080 ----a-w- c:\program files (x86)\Mozilla Firefox\updated\AccessibleMarshal.dll 2014-09-02 18:22 . 2014-09-02 18:52 -------- d-----w- C:\FRST 2014-08-18 17:47 . 2014-08-18 17:47 -------- d-----w- c:\users\Lukas\.jivex . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-08-30 16:33 . 2010-06-24 18:33 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2014-07-24 12:33 . 2014-07-24 12:33 11336 ----a-w- c:\windows\system32\drivers\mfeclnrk.sys 2014-07-24 12:32 . 2014-07-24 12:32 96592 ----a-w- c:\windows\system32\drivers\mfencrk.sys 2014-07-24 12:31 . 2014-07-24 12:31 444720 ----a-w- c:\windows\system32\drivers\mfencbdc.sys 2014-07-23 11:29 . 2013-08-11 17:15 96441528 ----a-w- c:\windows\system32\MRT.exe 2014-07-23 11:15 . 2013-10-12 17:26 699056 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-07-23 11:15 . 2011-10-16 18:32 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-07-23 11:14 . 2014-07-23 11:14 11204096 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2014-06-30 02:09 . 2014-07-23 10:43 519168 ----a-w- c:\windows\system32\aepdu.dll 2014-06-30 02:04 . 2014-07-23 10:43 424448 ----a-w- c:\windows\system32\aeinv.dll 2014-06-20 08:38 . 2014-03-17 17:02 72128 ----a-w- c:\windows\system32\drivers\cfwids.sys 2014-06-20 08:31 . 2014-03-17 16:54 348552 ----a-w- c:\windows\system32\drivers\mfewfpk.sys 2014-06-20 08:30 . 2014-04-19 07:50 189912 ----a-w- c:\windows\system32\mfevtps.exe 2014-06-20 08:26 . 2014-03-17 16:49 786296 ----a-w- c:\windows\system32\drivers\mfehidk.sys 2014-06-20 08:23 . 2014-03-17 16:47 523792 ----a-w- c:\windows\system32\drivers\mfefirek.sys 2014-06-20 08:21 . 2014-03-17 16:45 313544 ----a-w- c:\windows\system32\drivers\mfeavfk.sys 2014-06-20 08:20 . 2014-03-17 16:44 181704 ----a-w- c:\windows\system32\drivers\mfeapfk.sys 2014-06-19 02:12 . 2014-07-23 10:38 51712 ----a-w- c:\windows\system32\ie4uinit.exe 2014-06-19 02:12 . 2014-07-23 10:38 2239488 ----a-w- c:\windows\system32\wininet.dll 2014-06-19 02:12 . 2014-07-23 10:38 1366528 ----a-w- c:\windows\system32\urlmon.dll 2014-06-19 02:11 . 2014-07-23 10:38 197120 ----a-w- c:\windows\system32\msrating.dll 2014-06-19 02:11 . 2014-07-23 10:38 97792 ----a-w- c:\windows\system32\mshtmled.dll 2014-06-19 02:11 . 2014-07-23 10:38 19277312 ----a-w- c:\windows\system32\mshtml.dll 2014-06-19 02:10 . 2014-07-23 10:38 603136 ----a-w- c:\windows\system32\msfeeds.dll 2014-06-19 02:10 . 2014-07-23 10:38 3959296 ----a-w- c:\windows\system32\jscript9.dll 2014-06-19 02:10 . 2014-07-23 10:38 53760 ----a-w- c:\windows\system32\jsproxy.dll 2014-06-19 02:10 . 2014-07-23 10:38 855552 ----a-w- c:\windows\system32\jscript.dll 2014-06-19 02:10 . 2014-07-23 10:38 526336 ----a-w- c:\windows\system32\ieui.dll 2014-06-19 02:10 . 2014-07-23 10:38 2650624 ----a-w- c:\windows\system32\iertutil.dll 2014-06-19 02:10 . 2014-07-23 10:38 39936 ----a-w- c:\windows\system32\iernonce.dll 2014-06-19 02:10 . 2014-07-23 10:38 255488 ----a-w- c:\windows\system32\iedkcs32.dll 2014-06-19 02:10 . 2014-07-23 10:38 67072 ----a-w- c:\windows\system32\iesetup.dll 2014-06-19 02:10 . 2014-07-23 10:38 15369728 ----a-w- c:\windows\system32\ieframe.dll 2014-06-19 02:10 . 2014-07-23 10:38 136704 ----a-w- c:\windows\system32\iesysprep.dll 2014-06-19 02:10 . 2014-07-23 10:38 281600 ----a-w- c:\windows\system32\dxtrans.dll 2014-06-19 02:10 . 2014-07-23 10:38 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2014-06-19 02:09 . 2014-07-23 10:38 1508864 ----a-w- c:\windows\system32\inetcpl.cpl 2014-06-19 00:53 . 2014-07-23 10:38 1766400 ----a-w- c:\windows\SysWow64\wininet.dll 2014-06-19 00:52 . 2014-07-23 10:38 2863616 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-06-19 00:52 . 2014-07-23 10:38 61440 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-06-19 00:52 . 2014-07-23 10:38 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll 2014-06-19 00:52 . 2014-07-23 10:38 1440768 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-06-19 00:33 . 2014-07-23 10:38 2706432 ----a-w- c:\windows\system32\mshtml.tlb 2014-06-19 00:30 . 2014-07-23 10:38 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-06-18 23:37 . 2014-07-23 10:38 89600 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2014-06-18 23:34 . 2014-07-23 10:38 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2014-06-06 10:10 . 2014-07-23 10:39 624128 ----a-w- c:\windows\system32\qedit.dll 2014-06-06 09:44 . 2014-07-23 10:39 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2014-02-17 21:53 . 2014-02-17 21:53 49940480 ----a-w- c:\program files (x86)\GUT80AA.tmp . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"] @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"] @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"] @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"] @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ANT Agent"="c:\program files (x86)\Garmin\ANT Agent\ANT Agent.exe" [2013-02-15 14731776] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BackupManagerTray"="c:\program files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" [2011-02-15 297280] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2011-04-13 1097296] "SiteRanker"="c:\program files (x86)\SiteRanker\SiteRankTray.exe" [2011-09-12 320000] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2014-04-25 537992] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "mcpltui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2014-04-25 537992] . c:\users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-8-15 36414752] OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Acer VCM.lnk - c:\program files (x86)\Acer\Acer VCM\AcerVCM.exe [2011-5-18 704104] Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-12-10 1133856] McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.150\SSScheduler.exe [2014-4-9 332016] t@x aktuell.lnk - c:\program files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe [2014-6-23 587856] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) "ConsentPromptBehaviorAdmin"= 5 (0x5) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc] @="" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x] R3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys;c:\windows\SYSNATIVE\DRIVERS\btwampfl.sys [x] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x] R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys;c:\windows\SYSNATIVE\drivers\HipShieldK.sys [x] R3 libusb0;libusb-win32 - Kernel Driver 04/08/2011 1.2.4.0;c:\windows\system32\DRIVERS\libusb0.sys;c:\windows\SYSNATIVE\DRIVERS\libusb0.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe [x] R3 mfencrk;McAfee Inc. mfencrk;c:\windows\system32\DRIVERS\mfencrk.sys;c:\windows\SYSNATIVE\DRIVERS\mfencrk.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys;c:\windows\SYSNATIVE\drivers\mfewfpk.sys [x] S1 DVMIO;DVMIO;c:\program files (x86)\InstantView\tools\dvmio_x64.sys;c:\program files (x86)\InstantView\tools\dvmio_x64.sys [x] S1 F06DEFF2-5B9C-490D-910F-35D3A91196222;F06DEFF2-5B9C-490D-910F-35D3A91196222;c:\program files (x86)\Movies Toolbar\Datamngr\x64\setmgrc2.cfg;c:\program files (x86)\Movies Toolbar\Datamngr\x64\setmgrc2.cfg [x] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x] S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe;c:\windows\SYSNATIVE\CxAudMsg64.exe [x] S2 DatamngrCoordinator;Datamngr Coordinator;c:\program files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe;c:\program files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe [x] S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x] S2 EgisTec Service;EgisTec Service;c:\program files\Acer ProShield\x86\EgisService.exe;c:\program files\Acer ProShield\x86\EgisService.exe [x] S2 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files\Common Files\EgisTec\Services\EgisTicketService.exe;c:\program files\Common Files\EgisTec\Services\EgisTicketService.exe [x] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x] S2 FPSensor;EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys);c:\windows\system32\Drivers\FPSensor.sys;c:\windows\SYSNATIVE\Drivers\FPSensor.sys [x] S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x] S2 HomeNetSvc;McAfee Home Network;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x] S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x] S2 McAPExe;McAfee AP Service;c:\program files\McAfee\MSC\McAPExe.exe;c:\program files\McAfee\MSC\McAPExe.exe [x] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x] S2 mcpltsvc;McAfee Platform Services;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x] S2 mfecore;McAfee Anti-Malware Core;c:\program files\Common Files\McAfee\AMCore\mcshield.exe;c:\program files\Common Files\McAfee\AMCore\mcshield.exe [x] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe;c:\windows\SYSNATIVE\mfevtps.exe [x] S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [x] S2 ReminderService;Splashtop Reminder Service;c:\program files (x86)\InstantView\tools\ReminderService.exe;c:\program files (x86)\InstantView\tools\ReminderService.exe [x] S2 RS_Service;Raw Socket Service;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe [x] S2 SPMDES;Splashtop Meta Data Export Service;c:\program files (x86)\InstantView\tools\DVMExportService.exe;c:\program files (x86)\InstantView\tools\DVMExportService.exe [x] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys;c:\windows\SYSNATIVE\drivers\cfwids.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys;c:\windows\SYSNATIVE\drivers\mfefirek.sys [x] S3 mfencbdc;McAfee Inc. mfencbdc;c:\windows\system32\DRIVERS\mfencbdc.sys;c:\windows\SYSNATIVE\DRIVERS\mfencbdc.sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-08-13 16:33 1104200 ----a-w- c:\program files (x86)\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-09-03 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-12 11:15] . 2014-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21 19:29] . 2014-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21 19:29] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-31 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-31 392216] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-31 415768] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2011-05-07 524928] "Power Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2011-02-22 1796200] "ProShieldTSR"="c:\program files\Acer ProShield\EgisTSR.exe" [2011-03-31 165936] "InstantView Agent"="c:\program files (x86)\InstantView\tools\aoiosnap.exe" [2011-04-28 1127840] "InstantView LockKey"="c:\program files (x86)\InstantView\tools\LockKey.exe" [2011-04-29 1498472] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm IE: {{F15096F1-C84C-4c24-875A-189ABBA3BD38} - {b289cf57-0878-36e1-9cbd-8bb7fc2da46d} - mscoree.dll TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Lukas\AppData\Roaming\Mozilla\Firefox\Profiles\iakpctl9.default-1406566022487\ FF - prefs.js: browser.startup.homepage - hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-887&v=a13251-240&t=4 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . BHO-{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - (no file) Toolbar-10 - (no file) Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe Toolbar-10 - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\F06DEFF2-5B9C-490D-910F-35D3A91196222] "ImagePath"="\??\c:\program files (x86)\Movies Toolbar\Datamngr\x64\setmgrc2.cfg" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-4073307474-3872349722-3587453100-1000\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,3b,1b,0c,12,cd, 06,99,b8,ec,08,bd,9a,bc,17,8f,65,ff,dd "{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}"=hex:51,66,7a,6c,4c,1d,3b,1b,24,49,78, 71,dd,28,f4,07,99,8e,cd,01,e9,c7,7b,f1 "{7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9}"=hex:51,66,7a,6c,4c,1d,3b,1b,ae,d6,43, 65,cd,1a,c9,0e,a5,a7,91,b7,e7,8f,a4,e7 "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,3b,1b,74,ce,22, 8e,36,1c,d0,00,96,c0,17,24,75,43,21,d8 "{B164E929-A1B6-4A06-B104-2CD0E90A88FF}"=hex:51,66,7a,6c,4c,1d,3b,1b,39,f3,76, af,82,f1,69,00,a9,08,6a,90,ea,41,ca,e1 "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,3b,1b,54,1a,da, c5,71,f4,34,09,a4,78,da,65,c2,8e,ca,b7 "{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}"=hex:51,66,7a,6c,4c,1d,3b,1b,58,a4,a9, 10,e0,ea,23,01,96,56,17,2a,bd,81,a2,7a "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,3b,1b,ab,8d,06, 68,c4,86,43,0c,ae,e7,92,9a,f2,92,6f,5d "{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}"=hex:51,66,7a,6c,4c,1d,38,12,ab,c5,1e, a0,e2,37,c6,09,de,93,cc,b9,8c,f1,55,01 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.14" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\7E756C51681BDA34F86C2167896E312E\67D6ECF5CD5FBA732B8B22BAC8DE1B4D] @DACL=(02 0000) "PatchGUID"="" "MediaCabinet"="" "File"="FL_msdia71_dll_2_60035_amd64_ln.3643236F_FC70_11D3_A536_0090278A1BB8" "ComponentVersion"="9.0.30729.6161" "ProductVersion"="9.0.30729" "PatchSize"="0" "PatchAttributes"="0" "PatchSequence"="0" "SharedComponent"="0" "IsFullFile"="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\A771E8EB1E10BCE44AA8014E39DCC206\6E815EB96CCE9A53884E7857C57002F0] @DACL=(02 0000) "PatchGUID"="" "MediaCabinet"="" "File"="FL_msdia71_dll_2_60035_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8" "ComponentVersion"="9.0.30729.6161" "ProductVersion"="9.0.30729" "PatchSize"="0" "PatchAttributes"="0" "PatchSequence"="0" "SharedComponent"="0" "IsFullFile"="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-09-03 22:55:41 ComboFix-quarantined-files.txt 2014-09-03 20:55 . Vor Suchlauf: 32 Verzeichnis(se), 333.855.510.528 Bytes frei Nach Suchlauf: 38 Verzeichnis(se), 341.078.921.216 Bytes frei . - - End Of File - - 0BDB9D4D614E49F2173046D2274E0A8B |
04.09.2014, 14:43 | #6 |
/// the machine /// TB-Ausbilder | Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll |
04.09.2014, 21:54 | #7 |
| Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll hier die mbam.txt datei Code:
ATTFilter <?xml version="1.0" encoding="UTF-8" ?> <logs> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T21:14:02.342056+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="3ae7dfee-8288-4799-9ecc-929c004afbc3" result="Starting" subtype="Malware Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T21:14:02.368058+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="9e9f47a0-9ea7-4047-a09b-28ee363061a4" result="Started" subtype="Malware Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T21:14:02.506066+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="58cb69e0-beea-4f9f-a498-f6bfe0a9c053" result="Starting" subtype="Malicious Website Protection"></record> <record severity="debug" LoggingEventType="1" datetime="2014-09-04T21:14:05.614244+02:00" source="Manual" type="Update" username="SYSTEM" systemname="LUKAS-PC" fromVersion="2014.2.20.1" last_modified_tag="709c4e59-bda8-433c-8fa9-53152dc46770" name="Rootkit Database" toVersion="2014.8.21.1"></record> <record severity="debug" LoggingEventType="1" datetime="2014-09-04T21:14:11.456578+02:00" source="Manual" type="Update" username="SYSTEM" systemname="LUKAS-PC" fromVersion="2014.3.4.9" last_modified_tag="f721352a-bbf9-4362-8265-dc56de168506" name="Malware Database" toVersion="2014.9.4.9"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T21:14:13.161675+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="dbb9d4d2-e45a-42be-b36f-19f9b0c83d9b" result="Starting" subtype="Refresh"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T21:15:26.754885+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c5dae51e-8905-40c1-922a-4989db1a5a78" result="Started" subtype="Malicious Website Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T21:15:26.872891+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="b21559ea-1304-4261-b15c-0dcc7823543d" result="Stopping" subtype="Malicious Website Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T21:15:26.924894+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="583c0e1a-a341-4cfd-9894-c6bcc98ac0d3" result="Stopped" subtype="Malicious Website Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T21:15:35.822403+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5440386c-f750-4d09-b012-2d416c3583a0" result="Success" subtype="Refresh"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T21:15:35.875406+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="57dea89b-a180-4347-8abb-802049c8bdde" result="Starting" subtype="Malicious Website Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T21:15:36.340433+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a59dc4a6-608e-4b7e-a4c6-436b91bff853" result="Started" subtype="Malicious Website Protection"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:16:00.753829+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="0efd3fd2-7d53-44c1-9c44-61b73c94caf8" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:16:01.204855+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="aca169c2-d460-46e7-9c63-79667fe8d34b" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:16:01.225856+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="aca169c2-d460-46e7-9c63-79667fe8d34b" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:17:41.356583+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="f73a0cd6-b3e5-4946-ac97-b710ed190c97" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:17:41.629599+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="0d93b433-a659-4b6d-bcf2-a66a590bde40" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:17:41.641600+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="0d93b433-a659-4b6d-bcf2-a66a590bde40" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:19:21.931336+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="0f379b9c-9d18-4b65-b3d7-c849b1be1aae" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:19:22.357360+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="8b6920e1-a377-4ccd-92ef-3a18253123fc" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:19:22.377361+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="8b6920e1-a377-4ccd-92ef-3a18253123fc" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:20:35.222528+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="548f91f1-8324-451e-aff7-efa3d067fb84" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:20:35.799561+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="ced77bb4-2f56-42d9-82d5-eef92301223d" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:20:35.814562+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="ced77bb4-2f56-42d9-82d5-eef92301223d" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:21:39.631212+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="38cf6e09-b0ca-4136-8c54-ef1bb387a9bf" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:21:40.073237+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="18e871a6-9a2d-406a-b0e3-8b784332017a" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:21:40.087238+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="18e871a6-9a2d-406a-b0e3-8b784332017a" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:23:17.050784+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="ba433ffb-df96-40d6-9fb4-0d71efe290b7" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:23:17.533812+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="471d6e10-6247-485b-82b7-1445297aa9f3" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:23:17.550813+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="471d6e10-6247-485b-82b7-1445297aa9f3" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:24:57.435526+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="7b0ad469-865e-464b-afe1-8dd96e33f1b9" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:24:58.025559+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="e5800eb1-dd43-4190-b7c9-02b4c0953906" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:24:58.042560+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="e5800eb1-dd43-4190-b7c9-02b4c0953906" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:26:37.922273+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a51f5578-2878-42be-acb6-b81c6742ebe2" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:26:38.328296+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a6a8b7c6-cc25-4322-bc74-5285adf00928" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:26:38.345297+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a6a8b7c6-cc25-4322-bc74-5285adf00928" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:28:18.352017+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="24397125-99f4-4c9f-9c72-90616224beda" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:28:18.730039+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="dfe22e89-ccec-4ef9-9abd-8572a213e5ca" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:28:18.749040+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="dfe22e89-ccec-4ef9-9abd-8572a213e5ca" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:29:58.756760+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="9efdc384-16a5-4f42-a9c3-85a5fb196451" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:29:59.099780+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="93ee218f-b8fb-4d85-83c0-f1bdd68de5f9" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:29:59.117781+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="93ee218f-b8fb-4d85-83c0-f1bdd68de5f9" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:31:38.982493+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="669128a1-5206-4902-ae43-5822cd0dc1af" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:31:39.238507+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="9b77b775-56a5-4236-8fe8-52d2cb8c0265" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:31:39.246508+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="9b77b775-56a5-4236-8fe8-52d2cb8c0265" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:33:19.383235+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="85635f5a-bbd7-43eb-b82d-4874cfda4f1e" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:33:19.738256+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="4568c846-1cac-4e52-b6fd-e624593f2364" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:33:19.755257+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="4568c846-1cac-4e52-b6fd-e624593f2364" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:34:24.295948+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c503866c-7e76-4ab4-98f0-fa4965d4b699" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:34:24.752974+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="19635b8b-e310-43be-bc76-4eede030591f" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:34:24.767975+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="19635b8b-e310-43be-bc76-4eede030591f" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:36:04.748694+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a7a129a5-a411-4b49-a2d4-ded4cdb5251f" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:36:05.039710+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="dbdef6cc-1281-4c34-9308-99463b81608d" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:36:05.049711+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="dbdef6cc-1281-4c34-9308-99463b81608d" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:37:45.181438+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="fcbd8f97-d4e6-477e-831b-95af460cbfd9" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:37:45.568460+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d2b41af7-9ca2-4f3b-8d95-0d42249505ae" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:37:45.606463+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d2b41af7-9ca2-4f3b-8d95-0d42249505ae" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:39:25.595182+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="e02395e2-649c-4571-a823-461987d8a6a0" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:39:26.050208+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="7518eae3-35a7-4604-9d1e-d0eaaf65b1e2" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:39:26.069209+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="7518eae3-35a7-4604-9d1e-d0eaaf65b1e2" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:41:05.975923+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5e3bd9e4-09d4-4c17-9328-826d1d24eb7b" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:41:06.408948+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="953ff280-f28b-4c87-801e-cf39a37c3691" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:41:06.418948+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="953ff280-f28b-4c87-801e-cf39a37c3691" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:42:32.518873+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="68cc36b5-c2a6-4411-ab1e-660d33dcfd07" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:42:32.912896+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="0f25a271-3b52-40be-9e89-33a03f2e782d" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:42:32.956898+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="0f25a271-3b52-40be-9e89-33a03f2e782d" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:44:12.930616+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="da75061c-3c6a-4221-92bb-ad748c962a94" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:44:13.319638+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="8f9ff6c2-cd88-472e-928b-d05878c2f959" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:44:13.337639+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="8f9ff6c2-cd88-472e-928b-d05878c2f959" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:45:53.349360+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="7a95544b-fc60-4686-b673-e756b90f6628" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:45:53.776384+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="35b85353-387a-446a-a355-c746a57a871e" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:45:53.801386+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="35b85353-387a-446a-a355-c746a57a871e" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:47:33.801105+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="4787ab30-4a29-432e-aab9-362e2edbc789" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:47:34.180127+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5e9927e1-9f16-49bf-9636-4adafa22800d" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:47:34.200128+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5e9927e1-9f16-49bf-9636-4adafa22800d" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:49:14.199848+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="7ba6310d-25d2-4a77-8bde-3283a7aa64f6" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:49:14.604871+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="faf65871-b435-4fb3-9b70-1e91f9b2a7e3" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:49:14.620872+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="faf65871-b435-4fb3-9b70-1e91f9b2a7e3" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:50:54.708597+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="f3193481-f9ff-4ab2-bdb7-187922cca836" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:50:55.239627+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="da3fd438-c270-48b3-a87b-7641d24d4e8b" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:50:55.251628+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="da3fd438-c270-48b3-a87b-7641d24d4e8b" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:52:35.500362+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="cae3477c-0dbb-40bd-b31d-4aca53b7d871" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:52:36.201402+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="fd046b95-e985-4134-a81e-04d01b3fd74c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:52:36.221403+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="fd046b95-e985-4134-a81e-04d01b3fd74c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:54:16.062113+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="bd7f6897-f9e6-4101-a30e-03deed744a19" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:54:16.500138+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="457d0faf-43c9-4538-b431-53d53b28edcd" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:54:16.518139+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="457d0faf-43c9-4538-b431-53d53b28edcd" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:55:56.496858+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="96905e5d-f4c8-476f-8f78-6c60621506f0" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:55:56.880880+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="1777100b-3840-45e5-a0c2-f1b0c7454991" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:55:56.903881+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="1777100b-3840-45e5-a0c2-f1b0c7454991" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:57:36.980605+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="b39506c9-0f28-47b2-9602-074b12a19e2d" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:57:37.421630+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="da63461c-1e16-460f-940f-12ab7de9c76e" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:57:37.440632+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="da63461c-1e16-460f-940f-12ab7de9c76e" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T21:59:17.431351+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="88c84eb7-d1fd-43d2-840d-900eb31a40d9" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T21:59:17.943380+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="e32e6a6d-23d9-4585-b8e0-859e901a6f10" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T21:59:17.959381+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="e32e6a6d-23d9-4585-b8e0-859e901a6f10" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:00:57.797091+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5b149a02-f4e2-4b53-86bb-9eda64fe4512" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:00:58.111109+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="cfa8def8-5d2d-4c31-8a31-e1ca33e906f4" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:00:58.122110+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="cfa8def8-5d2d-4c31-8a31-e1ca33e906f4" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:01:58.086540+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a58b9244-1fc2-4962-88cc-f0cc834bee9a" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:01:58.376556+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="0c5fe0aa-9167-431f-9fb5-87d849fe25c5" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:01:58.392557+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="0c5fe0aa-9167-431f-9fb5-87d849fe25c5" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:02:58.339986+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="7f8dfd7a-6771-48f4-8103-24779325d855" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:02:58.626002+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="36874a68-a482-4698-9377-77204e32066a" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:02:58.642003+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="36874a68-a482-4698-9377-77204e32066a" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:03:58.686438+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="47ecf34f-6234-46c3-8b72-522cb481c0af" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:03:59.018457+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="8b91005e-e479-4bfc-a03f-88be2f1c8faf" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:03:59.030457+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="8b91005e-e479-4bfc-a03f-88be2f1c8faf" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:04:58.962885+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="e2999e4a-74d4-4286-87a9-d6f5860a2591" subtype="Malware Protection" ac <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:09:23.929596+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a48e6b5f-6e73-4b9c-b461-d3bf835fcddf" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> led" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:04:59.248902+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="cf54ca98-a431-4990-b05b-310efdecce82" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:05:59.291336+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="132088f9-f471-492c-821a-d90522ec10cb" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:05:59.580352+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d1fccc09-fba0-46ad-bc27-1701f2d58a49" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:05:59.594353+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d1fccc09-fba0-46ad-bc27-1701f2d58a49" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:06:59.654788+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c42a98a8-d744-4823-889f-32dc6e0a5a1e" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:06:59.938805+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c20a0430-3ec5-45b6-8c23-6b1a376c813c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:06:59.954806+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c20a0430-3ec5-45b6-8c23-6b1a376c813c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:07:59.887233+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c10e36f6-eafe-402c-ba78-abd472d8ecb2" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:08:00.215252+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a20f7bb1-22bf-45df-9038-1140f2a34ccf" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:08:00.228253+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a20f7bb1-22bf-45df-9038-1140f2a34ccf" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:08:43.787744+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d902b736-f4e9-4e59-8a5e-e11c86006351" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="04a5a841413a4fe7ca7211b7cb37ef11" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:08:43.900751+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c195ab3e-1103-4dd8-b758-4b3eb404ff66" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="SDKQuarantine" datetime="2014-09-04T22:08:43.907751+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c195ab3e-1103-4dd8-b758-4b3eb404ff66" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:09:23.928596+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="78d139d6-1a30-4e57-9be1-3608f1ad6095" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:09:24.099606+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c89253b9-2457-4ff0-950a-8fc33f73bcf1" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:09:24.105606+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c89253b9-2457-4ff0-950a-8fc33f73bcf1" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:09:24.176610+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="8ba44d41-37da-4ebc-a6a8-a28cf9555b75" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:09:24.191611+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="8ba44d41-37da-4ebc-a6a8-a28cf9555b75" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:10:24.002032+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="158669ab-ae4c-4508-a129-7b0172a216b7" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:10:24.183042+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="6f89c186-4233-4aa9-b96c-2e78ec8706f4" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:10:24.193043+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="6f89c186-4233-4aa9-b96c-2e78ec8706f4" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:11:24.355484+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="7f4551df-504f-4224-88a0-d7628177a6e4" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:11:24.766508+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="e6bd6f0c-6dc9-4863-a817-c00773b0c03c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:11:24.795509+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="e6bd6f0c-6dc9-4863-a817-c00773b0c03c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:12:24.745938+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="2d83d05d-3a1f-4c0b-9a70-c3c0cbb0244d" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:12:25.107959+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5ffcc57d-f557-4fb8-be79-a223062626ed" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:12:25.129960+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5ffcc57d-f557-4fb8-be79-a223062626ed" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:13:25.063388+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="f8cf27d4-5664-43c5-9078-3b4ff9e52b6f" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="7b2e5c8d6f0c5cda31c1b6772ed357a9" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:13:25.448410+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="af2f386c-cdc4-48d5-8b31-9928f9a83f06" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:13:25.484412+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="af2f386c-cdc4-48d5-8b31-9928f9a83f06" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T22:15:21.635880+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="cf3d151b-f98a-4754-8cac-b2498aedd69e" result="Starting" subtype="Malware Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T22:15:21.776280+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="956fb315-50f4-41af-9b77-b25172c80742" result="Started" subtype="Malware Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T22:15:21.823081+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="3303d3d7-2a4b-465f-a3b3-0c0ab3dac280" result="Starting" subtype="Malicious Website Protection"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:15:25.395487+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="360f0846-505e-471f-b84b-429b4e3a60a0" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:15:25.567087+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="caa60855-3605-40c2-ad5f-b7e61d49ef7d" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:15:25.582687+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="f4839f83-5054-418c-a683-e01f4100d09c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:15:25.582687+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="f4839f83-5054-418c-a683-e01f4100d09c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:15:25.613887+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a5e90b54-2554-479d-a396-9d8ad7c2a36c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:15:25.613887+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a5e90b54-2554-479d-a396-9d8ad7c2a36c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:15:33.616701+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d03961e4-46e9-4ed9-a49a-b2c018ca5b47" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:15:33.663501+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5d3f3fd7-8f2a-4b09-a6a5-9c0bf62b25df" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:15:33.772702+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="64936929-a840-474b-bce9-cbd01634592d" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:15:33.772702+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="64936929-a840-474b-bce9-cbd01634592d" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:15:33.835102+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="1c27a669-ffa4-42ed-8264-24484f2b9f46" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:15:33.835102+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="1c27a669-ffa4-42ed-8264-24484f2b9f46" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:15:33.866302+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="77dec92f-c06a-4759-a77d-8163a76b4219" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:15:33.881902+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5a90a736-b797-4f85-86c5-90d64320e996" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:15:34.147102+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="beb6fd10-d008-4cc8-9165-0fd6553bd024" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:15:34.162702+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="beb6fd10-d008-4cc8-9165-0fd6553bd024" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:15:34.225102+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="f06a9d2a-9de9-4541-8c0e-1821e08d0075" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:15:34.225102+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="f06a9d2a-9de9-4541-8c0e-1821e08d0075" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:15:42.321517+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="b34938b3-a369-4bd8-87da-8d7434efdcb5" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:15:42.493117+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="90a45830-1074-4d30-b88d-c83756d90065" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:15:42.524317+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="cbee5254-d67c-40fb-b9a9-bbadd9358166" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:15:42.539917+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="cbee5254-d67c-40fb-b9a9-bbadd9358166" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:15:42.586717+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="2eeda84c-59a3-4607-aaf0-5580227d01f1" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:15:42.602317+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="2eeda84c-59a3-4607-aaf0-5580227d01f1" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:15:45.394722+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="d4333826-6f81-4bf9-8719-dfbf4c068ec8" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:15:45.472722+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="49df5176-0c9c-4d97-bb48-0dee389564be" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:15:45.488322+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="49df5176-0c9c-4d97-bb48-0dee389564be" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:15:45.659922+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="1d98bfe7-6ec1-4c6d-a91a-4e090e46b046" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:15:45.940723+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="4c6b125d-e833-40c4-954a-925ea0adc723" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:15:45.956323+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="4c6b125d-e833-40c4-954a-925ea0adc723" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamn <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:29:40.470882+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5b6f465c-8d44-487d-93ab-c4c3a7bce262" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:15:52.157934+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="1e4993a2-01fc-4e25-8a42-a65b8f60a578" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:15:52.157934+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="1e4993a2-01fc-4e25-8a42-a65b8f60a578" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:15:52.220334+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="c9cebc01-c425-4edd-b6d2-281424d597a9" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:15:52.516735+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="ed8eed7f-476a-4553-ad57-c2cc3569764f" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:15:52.516735+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="ed8eed7f-476a-4553-ad57-c2cc3569764f" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:16:02.407152+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="4a29ab08-a55f-4a97-b573-8de8e14680f9" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:16:02.438352+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="db816023-7a89-4209-b0a4-9a94671f49a5" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:16:02.516352+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c0557123-c04c-40ae-bd2b-891f93df2ddf" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:16:02.516352+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c0557123-c04c-40ae-bd2b-891f93df2ddf" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:16:02.531952+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="4528bab8-8efb-4fd1-89a8-6485ff2f52c9" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:16:02.531952+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="4528bab8-8efb-4fd1-89a8-6485ff2f52c9" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:16:08.381963+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="609c777a-a2bf-403c-ae43-d79dae030caa" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\Datamngr.dll" hash="733628c1126985b1df132c013ac76799" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:16:08.475563+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="90946f8a-cb54-4bf1-932b-b6c8e9dc84e9" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\Datamngr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:16:08.475563+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="90946f8a-cb54-4bf1-932b-b6c8e9dc84e9" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\Datamngr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:16:08.865563+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5a2f0cd3-decf-4970-8fdf-9f60988cbe2c" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:16:08.990364+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="edca6d41-187c-4f6d-a163-ded3b833c2cc" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:16:08.990364+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="edca6d41-187c-4f6d-a163-ded3b833c2cc" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:16:11.299168+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="a9f7e0c6-ffde-4c6c-98b7-1603212b6c68" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:16:11.439568+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="019fa8f9-3c99-41fb-a3cb-6909febeb787" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:16:11.782769+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="702c31e8-4488-49be-b578-1eff510f3cdc" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:16:11.782769+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="702c31e8-4488-49be-b578-1eff510f3cdc" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:16:11.798369+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d369ad5e-87a0-4923-a5aa-cf53d282ecef" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:16:11.829569+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d369ad5e-87a0-4923-a5aa-cf53d282ecef" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:16:14.420173+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="e42d4235-150c-484e-abd2-30ed7be8f877" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:16:14.513773+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="61bbc6e0-1a42-43a2-906e-3e1b35715cd5" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:16:14.544973+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d84d78cd-63f7-4244-9bd4-65bade89e4df" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:16:14.560573+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d84d78cd-63f7-4244-9bd4-65bade89e4df" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:16:14.560573+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="90d31053-d3f3-4b4a-973e-2c342082150f" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:16:14.576173+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="90d31053-d3f3-4b4a-973e-2c342082150f" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:16:22.110987+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="4d2ea86e-3490-44dc-9ea8-f1704c7badf2" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\Datamngr.dll" hash="733628c1126985b1df132c013ac76799" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:16:22.485387+02:00" source="Protection" type="Protectio <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:17:16.274282+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="3b0aee7b-e960-44f9-a313-b8cc334c5103" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> TEM" systemname="LUKAS-PC" last_modified_tag="df02bc4b-9136-4127-9dd7-a47be10867f2" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\Datamngr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:16:40.628219+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="cd505233-d0fa-4824-b14c-179a6c036cb9" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:16:40.799820+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="51555ef3-a645-47df-921d-f6f357fa7a89" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:16:41.018220+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="336babbc-67a2-4a2d-a9a8-3d5007eaab62" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:16:41.018220+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="9c33ee33-0ced-4614-b4c9-9d648d1d37ce" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:16:41.033820+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="336babbc-67a2-4a2d-a9a8-3d5007eaab62" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:17:09.067069+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="61a33752-69f6-4227-b0b2-9e8d6309406b" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:17:09.347870+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="68aa94ee-ae4e-454f-b63d-ed2d2918d974" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:17:09.363470+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="68aa94ee-ae4e-454f-b63d-ed2d2918d974" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:17:15.915481+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="73ef7a83-3042-4bf7-90b4-f2ccec88a351" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:17:16.118282+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="9f2969ef-d74e-4c31-9871-8e50a733c92b" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:17:16.258682+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="98c3e944-96f4-4463-afac-b4bd1395841d" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:17:16.274282+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="98c3e944-96f4-4463-afac-b4bd1395841d" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:17:16.289882+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="3b0aee7b-e960-44f9-a313-b8cc334c5103" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:18:09.298775+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="fc81c15d-66cd-410a-9b1c-49874105af35" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:18:09.610776+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="285326d3-ac1d-4586-9fd4-f7afc8a1aa07" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:18:09.626376+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="285326d3-ac1d-4586-9fd4-f7afc8a1aa07" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T22:18:24.290401+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d024606b-6221-43ea-9e7b-c3f5dbff3082" result="Started" subtype="Malicious Website Protection"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:19:00.132469+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="72fe2c5b-6970-400a-97d7-054ff14c2518" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:19:00.194869+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="499e60f7-386b-4d6e-92f1-79fa94fec8f9" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:19:00.366470+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="b26532b4-b58c-4999-b5bc-ce61b4bc311c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:19:00.382070+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="b26532b4-b58c-4999-b5bc-ce61b4bc311c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:19:00.444470+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d64f5635-f1a4-42fa-9ac8-5901e1330985" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:19:00.460070+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d64f5635-f1a4-42fa-9ac8-5901e1330985" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:19:09.523686+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="150817b1-918c-42fb-a36f-7e0a30e7e428" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:19:09.851286+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="b9631fc4-f189-48f4-b2c5-2c829e927c9a" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:19:09.866886+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="b9631fc4-f189-48f4-b2c5-2c829e927c9a" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:20:49.966142+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c396361c-45a2-409d-830e-43323f7e8f2b" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:20:50.430167+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="db3d3e89-be40-4962-8087-f0cb84fab6b2" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:20:50.464169+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="db3d3e89-be40-4962-8087-f0cb84fab6b2" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:21:30.578635+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="95f36234-068c-435e-ab7d-05cf8329f47c" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:21:30.703435+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="26d1cd8f-4b08-406e-aece-4f3198ac9304" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:21:31.031035+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="354c8364-c4e2-4ff2-8e79-cdaa0665d8de" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:21:31.062235+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="354c8364-c4e2-4ff2-8e79-cdaa0665d8de" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:21:31.296236+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="3d37d26a-179d-4c63-b9a2-e4d6928928ca" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="SDKQuarantine" datetime="2014-09-04T22:21:31.311836+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="3d37d26a-179d-4c63-b9a2-e4d6928928ca" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:21:50.765070+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="1a7afabf-eee7-4d03-8c81-0901390dc4cb" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:21:51.139471+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a5b54545-4a08-4476-833c-c6f4e8473cf4" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:21:51.170671+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="a5b54545-4a08-4476-833c-c6f4e8473cf4" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:22:50.931662+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="7aff3ca6-d993-410f-8594-b353bc7a083f" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:22:51.128673+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="b5412883-838a-42ea-b172-b2f98c7ce0ef" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:22:51.139674+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="b5412883-838a-42ea-b172-b2f98c7ce0ef" result="Failed" filename="C:\Program Fil <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:29:40.470882+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="b823e015-1ca9-4d41-b8b6-2a3f308d3c3c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> vies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:23:06.535555+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="031820d1-b017-481b-856f-4a2bc42e3cdf" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:23:06.850573+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="6cadf53a-7de9-49eb-a534-5b983be7d992" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:23:06.872574+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="6cadf53a-7de9-49eb-a534-5b983be7d992" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:23:07.156590+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="3a2b1236-44c0-463d-8914-b0b3e8487ae3" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="SDKQuarantine" datetime="2014-09-04T22:23:07.177591+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="3a2b1236-44c0-463d-8914-b0b3e8487ae3" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:23:51.128669+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="9a721d2e-c42d-4ddc-b2a9-f8a5a7e1ad59" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:23:51.487469+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="4bf50973-e897-412e-a715-326c61eaeeea" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:23:51.503069+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="4bf50973-e897-412e-a715-326c61eaeeea" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:24:51.297974+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="6e957ce6-0ce1-4d37-a7c1-389454762945" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datet <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:29:40.517682+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="eef99c43-4f97-4fc4-9472-b94a551f6278" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> :51.609975+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="062d273d-19c0-41f5-8e05-54fdd24e300c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:25:51.514080+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="3b08ac20-c530-4104-ac3c-98f1283efedc" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:25:51.716880+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="74116048-e5a0-4903-bdc5-9831b659e173" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:25:51.732480+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="74116048-e5a0-4903-bdc5-9831b659e173" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:26:51.605785+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="240dc8fc-d73b-4374-8d46-0e0b422edc52" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:26:51.870985+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5d33b846-828d-48da-8ffd-28ea17a4d7a8" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:26:51.886585+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5d33b846-828d-48da-8ffd-28ea17a4d7a8" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:27:51.915491+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="da8d6ab3-0988-44fb-b0d6-91a4afacccac" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:27:52.211891+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="7bcb7367-6e38-4f2c-b442-79679e67c868" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:27:52.227491+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="7bcb7367-6e38-4f2c-b442-79679e67c868" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:28:00.776306+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d615a605-532b-4564-a93d-caf13ea8256b" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:28:00.885507+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="2dec6a52-be64-4ecb-87e1-491ea208a516" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:28:01.306707+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="8c4dd487-71cb-482b-89ab-ac302d860596" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="SDKQuarantine" datetime="2014-09-04T22:28:01.322307+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="8c4dd487-71cb-482b-89ab-ac302d860596" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:28:01.447108+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="09f2365f-5df0-47d7-b7f5-20100dbae3e6" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="SDKQuarantine" datetime="2014-09-04T22:28:01.462708+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="09f2365f-5df0-47d7-b7f5-20100dbae3e6" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:28:12.117526+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="c67a7016-7a8b-492f-8c7b-ffe1ebc25a4e" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:28:12.226726+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="8a339b94-97f1-4503-b251-afc5a38ad606" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:28:12.429527+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="685d1db5-2ff8-4cad-a49c-037690f777d0" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:28:12.460727+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5423d234-385b-445b-830d-10c98b613562" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="SDKQuarantine" datetime="2014-09-04T22:28 <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:29:40.314881+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="813165fa-207c-4e5f-8687-edabb9f4dbdf" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> bd33a" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:28:52.469597+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d77cac95-1821-4548-834c-f6b6bfde2feb" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:28:52.485197+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="d77cac95-1821-4548-834c-f6b6bfde2feb" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:29:22.452850+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="96929c09-0bd7-4075-976c-05a33c06cbb4" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:29:22.593250+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="db8b6896-031f-4c92-a3b0-abceeda13691" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:29:22.983251+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="3b133c46-47d7-4a9e-aaf1-f619128c3e6c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="SDKQuarantine" datetime="2014-09-04T22:29:22.998851+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="3b133c46-47d7-4a9e-aaf1-f619128c3e6c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:29:23.108051+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="20f931e1-5d5c-4f8a-a626-df373a4bd133" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="SDKQuarantine" datetime="2014-09-04T22:29:23.123651+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="20f931e1-5d5c-4f8a-a626-df373a4bd133" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:29:39.597280+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="1dce95b9-8e63-48c8-b16f-828e99c09132" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:29:39.628480+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="7cc29cad-804b-49da-b259-f18b42fe484f" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:29:39.659680+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="db80816f-dd65-45dc-8f77-7b6675d55d94" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:29:39.644080+02:00" source="Protection" type="Detection" username="Lukas" systemname="LUKAS-PC" last_modified_tag="eda79f0f-244d-47bf-8bed-f0c7fcddf7c2" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" hash="abfe2cbddd9ec96d3507b81006fc57a9" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:29:39.862481+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="2f7bdf16-67ab-410f-88e0-e05d5c5f0d8a" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:29:39.971681+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="64ff0427-e0e3-4762-b741-3560961bff5c" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:29:40.080881+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="43263ca6-36ca-4b0c-b0f2-d8bfe87385f3" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" hash="8425d91090eb46f0ec505d6bb54d50b0" malwaretype="File" vendor="PUP.Optional.MoviesToolbar.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:29:40.221281+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="dd55c592-3194-4405-a516-7096886561a7" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:29:40.236881+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="0b62fb31-dfe3-433d-9a2d-ddbd86d2cacb" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:29:40.346081+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="ef95c169-5ccb-4d33-a95f-df4218cc5a6c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="SDKQuarantine" datetime="2014-09-04T22:29:40.361681+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="0b62fb31-dfe3-433d-9a2d-ddbd86d2cacb" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:29:40.470882+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="ef616dec-bcc7-4870-94af-967f2474bb17" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="SDKQuarantine" datetime="2014-09-04T22:29:40.580082+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="b823e015-1ca9-4d41-b8b6-2a3f308d3c3c" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="SDKQuarantine" datetime="2014-09-04T22:29:40.595682+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="eef99c43-4f97-4fc4-9472-b94a551f6278" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="2" message="SDKQuarantine" datetime="2014-09-04T22:29:40.689282+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="45ca2b2b-084d-406f-ad29-0d5c1ffd98f4" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" code="5" LoggingEventType="4" message="SDKQuarantine" datetime="2014-09-04T22:29:40.829682+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="45ca2b2b-084d-406f-ad29-0d5c1ffd98f4" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll"></record> <record severity="debug" LoggingEventType="0" datetime="2014-09-04T22:29:52.389303+02:00" source="Protection" type="Detection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="5d96ce23-2a7e-422b-8a49-ab5a4cfc2245" subtype="Malware Protection" action="Quarantine" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe" hash="ffaa5c8d681341f5bd351c1118e9c838" malwaretype="File" vendor="PUP.Optional.Bandoo.A"></record> <record severity="debug" code="5" LoggingEventType="2" message="DeleteFile" datetime="2014-09-04T22:29:52.670103+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="77a62eb3-f44f-4dac-9189-9988cb3e4759" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" code="5" LoggingEventType="4" message="DeleteFile" datetime="2014-09-04T22:29:52.701303+02:00" source="Protection" type="Error" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="77a62eb3-f44f-4dac-9189-9988cb3e4759" result="Failed" filename="C:\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T22:31:29.440263+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="1c3feba5-cd1e-4366-8d0c-a2a615a46688" result="Starting" subtype="Malware Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T22:31:29.549463+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="c236ad0b-d99a-4f4d-9588-61acf846e41e" result="Started" subtype="Malware Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T22:31:29.565063+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="8ca71a56-ccd6-41c0-9812-a06b636006b1" result="Starting" subtype="Malicious Website Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2014-09-04T22:33:32.593080+02:00" source="Protection" type="Protection" username="SYSTEM" systemname="LUKAS-PC" last_modified_tag="fafbde9d-f50a-47c1-aae4-a76e90f4e306" result="Started" subtype="Malicious Website Protection"></record> </logs> |
04.09.2014, 22:23 | #8 |
| Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll und die adwcleaner log Code:
ATTFilter # AdwCleaner v3.309 - Bericht erstellt am 04/09/2014 um 22:28:46 # Aktualisiert 02/09/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Lukas - LUKAS-PC # Gestartet von : C:\Users\Lukas\Downloads\adwcleaner_3.309.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : DatamngrCoordinator [#] Dienst Gelöscht : F06DEFF2-5B9C-490D-910F-35D3A91196222 ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Ask Ordner Gelöscht : C:\ProgramData\BitGuard Ordner Gelöscht : C:\ProgramData\Browser Manager Ordner Gelöscht : C:\ProgramData\BrowserProtect [!] Ordner Gelöscht : C:\ProgramData\DataMngr Ordner Gelöscht : C:\ProgramData\wincert Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AppGraffiti Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SiteRanker Ordner Gelöscht : C:\Program Files (x86)\AppGraffiti [!] Ordner Gelöscht : C:\Program Files (x86)\Movies Toolbar Ordner Gelöscht : C:\Program Files (x86)\SiteRanker [/!\] Nicht Gelöscht ( Junction ) : C:\Program Files\Gemeinsame Dateien Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\AppGraffiti Ordner Gelöscht : C:\Users\Lukas\AppData\LocalLow\AppGraffiti Ordner Gelöscht : C:\Users\Lukas\AppData\LocalLow\AskToolbar Ordner Gelöscht : C:\Users\Lukas\AppData\LocalLow\SiteRanker Ordner Gelöscht : C:\Users\Lukas\AppData\Roaming\Movies Toolbar Ordner Gelöscht : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\ilividmoviestoolbar181 Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh Datei Gelöscht : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\invalidprefs.js Datei Gelöscht : C:\Users\Lukas\AppData\Roaming\Mozilla\Firefox\Profiles\iakpctl9.default-1406566022487\invalidprefs.js Datei Gelöscht : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\searchplugins\Ask.xml Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\Ask.xml ***** [ Tasks ] ***** Task Gelöscht : Scheduled Update for Ask Toolbar ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [siteranker@siteranker.com] Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh Schlüssel Gelöscht : HKCU\Software\Classes\iLivid.torrent Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppGraffiti.AppGraffitiJS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iLivid.torrent Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Wert Gelöscht : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64] Wert Gelöscht : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86] Wert Gelöscht : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64] Wert Gelöscht : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{022C9F90-2E96-47D6-A971-107650154563} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB02BC6B-B0F0-4074-99E6-884B70FCB6AE} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1DAC034-9FD9-4C13-A388-D2E10E57707F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{D3D233D5-9F6D-436C-B6C7-E63F77503B30}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{022C9F90-2E96-47D6-A971-107650154563} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Schlüssel Gelöscht : HKCU\Software\APN Schlüssel Gelöscht : HKCU\Software\APNDTX Schlüssel Gelöscht : HKCU\Software\AppGraffiti Schlüssel Gelöscht : HKCU\Software\Ask.com Schlüssel Gelöscht : HKCU\Software\CToolbar Schlüssel Gelöscht : HKCU\Software\ilivid Schlüssel Gelöscht : HKCU\Software\SiteRanker Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\APN Schlüssel Gelöscht : HKLM\SOFTWARE\AppGraffiti Schlüssel Gelöscht : HKLM\SOFTWARE\AskToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\CToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\DataMngr Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}_is1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90120000-00B0-0409-0000-0000000FF1CE} ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.17028 -\\ Mozilla Firefox v32.0 (x86 de) [ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\prefs.js ] Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-887&v=a12627-240&t=4"); [ Datei : C:\Users\Lukas\AppData\Roaming\Mozilla\Firefox\Profiles\iakpctl9.default-1406566022487\prefs.js ] Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-887&v=a13251-240&t=4"); -\\ Google Chrome v37.0.2062.103 [ Datei : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Extension] : bopakagnckmlgajfccecajhnimjiiedh [ Datei : C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Startup_urls] : hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-887&v=a13251-240&t=4 Gelöscht [Homepage] : hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-887&v=a13251-240&t=4 Gelöscht [Extension] : bopakagnckmlgajfccecajhnimjiiedh ************************* AdwCleaner[R0].txt - [10826 octets] - [04/09/2014 22:24:12] AdwCleaner[S0].txt - [10100 octets] - [04/09/2014 22:28:46] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10161 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Lukas on 04.09.2014 at 22:58:59,44 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\siteranker ~~~ Registry Keys Successfully deleted: [Registry Key] "hkey_current_user\software\microsoft\internet explorer\low rights\elevationpolicy\{a5aa24ea-11b8-4113-95ae-9ed71deaf12a}" ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{013D1687-6668-4A0E-A964-B2126D5DC881} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{07AF7EA8-D5A8-4136-9EB7-1419710D8477} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{099B67B2-C1A9-41D2-977C-4566BDB94A5E} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{0CAD3D7F-CBDA-46D4-956B-7BF678009222} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{0CF43FD4-9173-48EC-B82D-4F22496F4557} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{109940BF-7C20-41EC-83AA-0D2F31FB30B9} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{11F0921F-B5A7-493D-82DA-5D37F652C5D6} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{132B3DF0-07DF-4C8B-9468-6FB3C4A60DD9} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{14501F05-16F0-4E5D-B753-B39E30126B17} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{15E60F60-2629-452F-9034-5FC3208D7494} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{1762826F-5E21-4FE1-ACDA-4A8C5158DC93} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{17B60C37-F6F0-465B-ADE8-BD8115E69BC4} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{18F0C537-2D7E-44A0-A630-582D613C2674} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{19A218A8-69FB-4DF2-94E1-1605A2DC02C6} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{1B2CE237-EA2A-4E71-A631-8739983B393E} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{24D6788C-8377-41A2-B807-C37823AE97C2} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{288230AD-D4A2-4EED-8799-26041D024890} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{2C6A523A-1319-466B-8A96-8BE835812661} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{2E340F47-6BEA-4E97-B650-1D11AA5C7086} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{2FF4C702-A913-4DF0-9FA3-5D66CA32B0AB} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{30680156-A63A-4282-B251-D57CA3EB83D9} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{326664FE-7AFC-444B-B77C-A46C1C827BBB} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{35E32B1C-7150-462D-83A2-F6F08CB196AC} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{36C4B2FE-5287-4A40-978A-5AA017765B70} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{3A0F3B67-C53E-4DFA-8B8F-94AB8E778E1D} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{3BB5AADE-89AE-4071-83DD-A03AB4553ED0} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{41E2E47E-0FD6-40F6-A344-F87A13E05EC1} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{441E0F3B-EDC0-43C1-AEC3-DF9A5E91E13A} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{445C2CF5-618E-41EE-88A6-94670B26E313} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{466E3EEF-D34D-40EC-8D72-1DB602A27505} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{46BC6860-8E58-4533-858E-99E109460842} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{4712817C-6423-4464-9B9B-E5842017B004} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{4E933E14-9E59-4E54-984C-12E2F62859CB} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{52D0D343-85CC-4ED4-88A5-AFAC7D19E6B6} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{56B676A7-B61E-482B-8998-826C39342086} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{58A82386-0B77-45BF-91FF-69F85B9BDF17} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{58C369BE-EAF5-4A4A-B580-7D9D07B2EF86} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{61C0CBD6-5B59-48EF-9A71-24EBFF09A87D} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{6858BA22-4D42-4FA8-AFEF-19B78D81746C} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{745AD71C-7136-46F5-BB01-7CDCC6EF555B} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{77986364-B89A-4FEE-AF3F-DDA0EBBAE463} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{781B8CBC-5450-40A3-B13C-BEA1B1EE6231} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{7AAE2A2C-11DE-4DC2-8597-390F2BAFF2E0} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{7C43E242-4DCF-42B2-ACF4-44AA066F6126} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{7E0E6050-2270-428C-A206-6934D47D043A} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{7E5421C0-32B4-4DB0-98C3-4972B0DF91CF} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{7FC0269B-7A4E-4DE5-8FC6-F58C5B654C4A} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{83A8B3AD-3E2F-4194-AD8D-C6C4CAE6FAFD} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{867FC465-EE5E-4430-8451-298220CCDDA7} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{89C0D490-D153-45CD-8ED5-B6A2D4180161} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{8C9FD213-8471-46A3-A7DC-FF4CAC61503A} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{8F4466DB-01C5-4256-AC6D-5F090A0D6EEA} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{8FE34566-9984-4007-99FF-0801F6688C14} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{90AE8433-3EED-4CE5-8CBF-0B0CF9166827} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{91EBE36F-E29D-43A9-8D17-1725D2B7EBAC} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{92EDA4A2-7055-4367-A979-E0ED88AE06AF} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{9617D1FE-CE94-412C-9482-68D42118E965} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{986D90B8-1F19-4E69-AADC-2EDACA53BDD6} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{A0E6A254-46F2-4749-AE0E-478CE295500D} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{A0F1A9B2-174B-4980-96E4-D308E2BF524C} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{A1570D66-3240-42A8-969E-0C0416FC1801} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{A1BD3EA1-ED34-46FF-B309-50EED30C894A} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{A7A6789F-32AD-4581-AD51-446E81040BDE} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{AA3E6A27-1D7A-40C3-849F-6A66D0D52307} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{AA624BF4-73B0-4B8F-9D9B-51EE38B42552} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{AB950614-F444-47EB-A823-0D54D521F3A1} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{B58D73D0-4382-4A8B-967C-218522C96813} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{BD982706-B651-4CED-8CC5-5FE573F16A8C} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{BE974A8F-FC42-449F-8362-08634D51C7B7} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{BF5E71EA-8807-42F9-92A8-DA31A930558D} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{C1D00560-2632-484E-BB61-3FFED72A2EE6} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{C2784AF4-46A4-4909-B7E7-E20707F92606} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{C78C0D80-D86F-48A3-ADF2-680A76BE91A2} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{C7CF7392-F805-4A83-A3B4-5B091F7F1E0D} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{C83F5610-2657-4BE4-BE47-FAC846B17133} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{CC640BAC-A7A3-428A-AC18-3E54CED92481} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{D4552640-CF1D-4EAA-AB16-BE6689F690B6} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{D811776C-47B8-4431-96AC-209E32395BED} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{D8EB88A6-A9FE-469D-9CC0-087C262CA79D} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{DD0FF8C8-9FD6-46F6-BC16-AEDC0546E1DC} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{DF0C408D-1E91-4034-80ED-A50A0E792A83} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{E0EED726-FBCC-469B-BA7C-FBF1F768E01E} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{E585B917-3A19-4E6A-972D-0B398121A912} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{F01EAA3C-C461-460E-9844-B532008E0B76} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{F0AB6EB8-C54A-4594-927E-66EED80B29E0} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{F631B55A-3E1C-43D5-89C8-B9CBE4F63844} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{F79A7086-8F71-4A7B-ADFF-9C49169D297E} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{F818FAAB-FD2B-4FA1-B24D-D6681B0929E4} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{FC93A5B5-5107-49A0-8348-E2A59949C9A1} Successfully deleted: [Empty Folder] C:\Users\Lukas\appdata\local\{FCF30957-1728-450F-AABB-AC8041334109} ~~~ FireFox Emptied folder: C:\Users\Lukas\AppData\Roaming\mozilla\firefox\profiles\iakpctl9.default-1406566022487\minidumps [14 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 04.09.2014 at 23:15:33,68 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-08-2014 02 Ran by Lukas (administrator) on LUKAS-PC on 04-09-2014 23:18:50 Running from C:\Users\Lukas\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Egis Technology Inc. ) C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. ) C:\Program Files\Acer ProShield\x86\EgisService.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\ReminderService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\DVMExportService.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\aoiosnap.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\LockKey.exe (GARMIN Corp.) C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe (Dropbox, Inc.) C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Egis Technology Inc. ) C:\Program Files\Acer ProShield\EgisTSR.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoUpdateCheck.exe (Igor Pavlov) C:\Program Files (x86)\7-Zip\7zFM.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\wermgr.exe (Microsoft Corporation) C:\Windows\System32\wermgr.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [524928 2011-05-07] (Conexant Systems, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2697512 2011-02-18] (Synaptics Incorporated) HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-22] (Acer Incorporated) HKLM\...\Run: [ProShieldTSR] => C:\Program Files\Acer ProShield\EgisTSR.exe [165936 2011-03-31] (Egis Technology Inc. ) HKLM\...\Run: [InstantView Agent] => C:\Program Files (x86)\InstantView\tools\aoiosnap.exe [1127840 2011-04-28] (Splashtop Inc.) HKLM\...\Run: [InstantView LockKey] => C:\Program Files (x86)\InstantView\tools\LockKey.exe [1498472 2011-04-29] (Splashtop Inc.) HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-02-15] (NTI Corporation) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1097296 2011-04-13] (Dritek System Inc.) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoFolderOptions] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [ANT Agent] => C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe [14731776 2013-02-15] (GARMIN Corp.) HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\system32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk ShortcutTarget: Acer VCM.lnk -> C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\t@x aktuell.lnk ShortcutTarget: t@x aktuell.lnk -> C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe () Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {09598583-814E-4AD3-946D-8332FFB2AB1E} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {E93B7101-F66B-4178-82CF-36C2D0B941A9} URL = hxxp://de.search.yahoo.com/search?fr=mcafee&type=A011DE662&p={SearchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: EgisPBIE Sign-in Helper -> {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} -> C:\Program Files\Acer ProShield\x86\EgisPBIE.dll (Egis Technology Inc.) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Lukas\AppData\Roaming\Mozilla\Firefox\Profiles\iakpctl9.default-1406566022487 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.4.0 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.4.0 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{41ecbc0b-34d5-4cd4-935f-253a30e2cb7e}] - C:\Program Files\Acer ProShield\FFExt FF Extension: Online Accounts Extension - C:\Program Files\Acer ProShield\FFExt [2011-06-02] FF HKLM-x32\...\Firefox\Extensions: [{d4da7309-b89a-45ec-8ebb-cfb2ae13618b}] - C:\Program Files\Acer ProShield\FFExt20 FF Extension: Online Accounts Extension - C:\Program Files\Acer ProShield\FFExt20 [2011-06-02] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-11-28] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2011-11-28] FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] Chrome: ======= CHR HomePage: Default -> hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-887&v=a13251-240&t=4 CHR RestoreOnStartup: Default -> "hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-887&v=a13251-240&t=4" CHR StartupUrls: Default -> "hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-887&v=a13251-240&t=4" CHR DefaultSearchProvider: Default -> Ask.com CHR DefaultSearchURL: Default -> hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=887&systemid=406&v=a13251-240&apn_uid=5924321086234305&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll No File CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.270.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U27) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (Adobe Acrobat) - c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Garmin Communicator Plug-In) - C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll () CHR Profile: C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (SiteAdvisor) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2012-05-21] CHR Extension: (Google Wallet) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-07] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2011-08-12] (SUPERAntiSpyware.com) [File not signed] R2 EgisTec Service; C:\Program Files\Acer ProShield\x86\EgisService.exe [195120 2011-03-31] (Egis Technology Inc. ) R2 EgisTec Ticket Service; C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe [205360 2011-03-31] (Egis Technology Inc. ) R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [603424 2014-06-12] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-07-24] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation) R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation) R2 ReminderService; C:\Program Files (x86)\InstantView\tools\ReminderService.exe [29560 2011-04-29] (Splashtop Inc.) R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated) S3 SecureStorageService; C:\Program Files\Acer ProShield\Secure Storage Manager\SecureStorageService.exe [2128776 2011-01-06] (Wave Systems Corp.) R2 SPMDES; C:\Program Files (x86)\InstantView\tools\DVMExportService.exe [467832 2011-04-29] (Splashtop Inc.) R2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1629696 2010-07-13] () [File not signed] R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143552 2012-04-05] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.) R1 DVMIO; C:\Program Files (x86)\InstantView\tools\dvmio_x64.sys [19560 2011-04-28] (DeviceVM, Inc.) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [44480 2011-05-17] (hxxp://libusb-win32.sourceforge.net) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-04] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.) R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [444720 2014-07-24] (McAfee, Inc.) S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96592 2014-07-24] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-03-29] (TuneUp Software) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-04 23:15 - 2014-09-04 23:15 - 00010595 _____ () C:\Users\Lukas\Desktop\JRT.txt 2014-09-04 22:58 - 2014-09-04 22:58 - 01016261 _____ (Thisisu) C:\Users\Lukas\Downloads\JRT.exe 2014-09-04 22:58 - 2014-09-04 22:58 - 00000000 ____D () C:\Windows\ERUNT 2014-09-04 22:50 - 2014-09-04 22:50 - 00002469 _____ () C:\Users\Lukas\Desktop\AdwCleaner[S0].zip 2014-09-04 22:47 - 2014-09-04 22:47 - 00010550 _____ () C:\Users\Lukas\Desktop\protection-log-2014-09-04.zip 2014-09-04 22:45 - 2014-09-04 22:45 - 01110476 _____ () C:\Users\Lukas\Downloads\7z920.exe 2014-09-04 22:45 - 2014-09-04 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2014-09-04 22:45 - 2014-09-04 22:45 - 00000000 ____D () C:\Program Files (x86)\7-Zip 2014-09-04 22:42 - 2014-09-04 22:42 - 00118973 _____ () C:\Users\Lukas\Desktop\protection-log-2014-09-04.xml 2014-09-04 22:37 - 2014-09-04 22:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-09-04 22:33 - 2014-09-04 22:33 - 00010270 _____ () C:\Users\Lukas\Documents\AdwCleaner[S0].txt 2014-09-04 22:23 - 2014-09-04 22:29 - 00000000 ____D () C:\AdwCleaner 2014-09-04 22:22 - 2014-09-04 22:22 - 01370483 _____ () C:\Users\Lukas\Downloads\adwcleaner_3.309.exe 2014-09-04 21:13 - 2014-09-04 22:40 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-04 21:12 - 2014-09-04 21:12 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-09-04 21:12 - 2014-09-04 21:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-04 21:12 - 2014-09-04 21:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-04 21:12 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-09-04 21:12 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-09-04 21:10 - 2014-09-04 21:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lukas\Downloads\mbam-setup-2.0.2.1012.exe 2014-09-03 22:55 - 2014-09-03 22:55 - 00032500 _____ () C:\ComboFix.txt 2014-09-03 21:56 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-09-03 21:56 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-09-03 21:56 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-09-03 21:54 - 2014-09-03 22:55 - 00000000 ____D () C:\Qoobox 2014-09-02 20:52 - 2014-09-04 23:18 - 00026068 _____ () C:\Users\Lukas\Downloads\FRST.txt 2014-09-02 20:40 - 2014-09-02 20:43 - 00000234 _____ () C:\Users\Lukas\Downloads\Search.txt 2014-09-02 20:38 - 2014-09-02 20:38 - 02104832 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64(2).exe 2014-09-02 20:35 - 2014-09-02 20:35 - 00043133 _____ () C:\Users\Lukas\Desktop\FRST.txt 2014-09-02 20:26 - 2014-09-02 20:48 - 00047958 _____ () C:\Users\Lukas\Downloads\Addition.txt 2014-09-02 20:22 - 2014-09-04 23:18 - 00000000 ____D () C:\FRST 2014-09-02 20:22 - 2014-09-02 20:22 - 02104832 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64(1).exe 2014-09-02 20:21 - 2014-09-02 20:22 - 02104832 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64.exe 2014-09-01 22:50 - 2014-09-01 22:50 - 00037888 ___SH () C:\Users\Lukas\Desktop\Thumbs.db 2014-08-24 23:11 - 2014-08-24 23:13 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2014-2015 2014-08-18 21:25 - 2014-08-25 21:45 - 00000000 ____D () C:\Users\Gast\Desktop\Caro Koll.mat 2014-08-18 19:47 - 2014-08-30 18:42 - 00000001 ____R () C:\Users\Lukas\serverport 2014-08-18 19:47 - 2014-08-18 19:47 - 00000000 ____D () C:\Users\Lukas\.jivex 2014-08-14 13:50 - 2014-09-04 19:43 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Franz aktuell 2014-08-12 22:33 - 2014-05-03 16:49 - 10510963 ____R () C:\Users\Lukas\Documents\Historie von Schumacher, Lukas~backup-140812.logbook3 2014-08-12 20:12 - 2014-08-12 20:12 - 00000000 ____D () C:\Users\Gast\Desktop\Tischkalender 2014-08-12 20:09 - 2014-08-14 12:48 - 00000000 ____D () C:\Users\Gast\Desktop\UB's - Klausuren etc. anderer 2014-08-06 17:40 - 2014-08-24 15:22 - 00000000 ____D () C:\Users\Gast\Desktop\Statement Tanja 2014-08-06 14:08 - 2014-09-04 19:39 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Spanisch aktuell ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-04 23:19 - 2014-09-02 20:52 - 00026068 _____ () C:\Users\Lukas\Downloads\FRST.txt 2014-09-04 23:18 - 2014-09-02 20:22 - 00000000 ____D () C:\FRST 2014-09-04 23:15 - 2014-09-04 23:15 - 00010595 _____ () C:\Users\Lukas\Desktop\JRT.txt 2014-09-04 23:13 - 2011-09-16 00:41 - 00000177 ____H () C:\dvmexp.idx 2014-09-04 23:12 - 2013-10-12 19:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-04 22:58 - 2014-09-04 22:58 - 01016261 _____ (Thisisu) C:\Users\Lukas\Downloads\JRT.exe 2014-09-04 22:58 - 2014-09-04 22:58 - 00000000 ____D () C:\Windows\ERUNT 2014-09-04 22:50 - 2014-09-04 22:50 - 00002469 _____ () C:\Users\Lukas\Desktop\AdwCleaner[S0].zip 2014-09-04 22:47 - 2014-09-04 22:47 - 00010550 _____ () C:\Users\Lukas\Desktop\protection-log-2014-09-04.zip 2014-09-04 22:45 - 2014-09-04 22:45 - 01110476 _____ () C:\Users\Lukas\Downloads\7z920.exe 2014-09-04 22:45 - 2014-09-04 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2014-09-04 22:45 - 2014-09-04 22:45 - 00000000 ____D () C:\Program Files (x86)\7-Zip 2014-09-04 22:42 - 2014-09-04 22:42 - 00118973 _____ () C:\Users\Lukas\Desktop\protection-log-2014-09-04.xml 2014-09-04 22:40 - 2014-09-04 21:13 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-04 22:40 - 2009-07-14 06:45 - 00024656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-04 22:40 - 2009-07-14 06:45 - 00024656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-04 22:37 - 2014-09-04 22:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-09-04 22:37 - 2011-05-18 19:45 - 00001848 _____ () C:\Users\Public\Desktop\McAfee Internet Security Suite.lnk 2014-09-04 22:33 - 2014-09-04 22:33 - 00010270 _____ () C:\Users\Lukas\Documents\AdwCleaner[S0].txt 2014-09-04 22:33 - 2013-08-11 15:58 - 00000000 ___RD () C:\Users\Lukas\Dropbox 2014-09-04 22:33 - 2012-05-19 09:38 - 00000436 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-09-04 22:32 - 2013-08-11 15:55 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Dropbox 2014-09-04 22:32 - 2012-05-21 21:29 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-09-04 22:31 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-04 22:31 - 2009-07-14 06:51 - 00156733 _____ () C:\Windows\setupact.log 2014-09-04 22:30 - 2011-06-02 09:01 - 01362524 _____ () C:\Windows\WindowsUpdate.log 2014-09-04 22:30 - 2010-11-21 05:47 - 00217408 _____ () C:\Windows\PFRO.log 2014-09-04 22:29 - 2014-09-04 22:23 - 00000000 ____D () C:\AdwCleaner 2014-09-04 22:28 - 2012-05-21 21:29 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-09-04 22:22 - 2014-09-04 22:22 - 01370483 _____ () C:\Users\Lukas\Downloads\adwcleaner_3.309.exe 2014-09-04 21:12 - 2014-09-04 21:12 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-09-04 21:12 - 2014-09-04 21:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-04 21:12 - 2014-09-04 21:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-04 21:12 - 2012-05-03 22:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-09-04 21:10 - 2014-09-04 21:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lukas\Downloads\mbam-setup-2.0.2.1012.exe 2014-09-04 19:43 - 2014-08-14 13:50 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Franz aktuell 2014-09-04 19:39 - 2014-08-06 14:08 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Spanisch aktuell 2014-09-03 22:55 - 2014-09-03 22:55 - 00032500 _____ () C:\ComboFix.txt 2014-09-03 22:55 - 2014-09-03 21:54 - 00000000 ____D () C:\Qoobox 2014-09-03 22:49 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-09-03 22:14 - 2011-09-16 00:31 - 00000000 ___HD () C:\dvmexp 2014-09-03 22:14 - 2011-05-18 20:24 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-09-03 22:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-09-03 21:51 - 2012-07-30 22:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-09-03 21:51 - 2011-10-15 14:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-03 21:25 - 2011-06-02 18:52 - 02127110 _____ () C:\Windows\system32\perfh007.dat 2014-09-03 21:25 - 2011-06-02 18:52 - 00609168 _____ () C:\Windows\system32\perfc007.dat 2014-09-03 21:25 - 2009-07-14 07:13 - 00006264 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-02 20:57 - 2013-08-11 15:56 - 00002809 _____ () C:\Windows\wininit.ini 2014-09-02 20:48 - 2014-09-02 20:26 - 00047958 _____ () C:\Users\Lukas\Downloads\Addition.txt 2014-09-02 20:43 - 2014-09-02 20:40 - 00000234 _____ () C:\Users\Lukas\Downloads\Search.txt 2014-09-02 20:38 - 2014-09-02 20:38 - 02104832 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64(2).exe 2014-09-02 20:35 - 2014-09-02 20:35 - 00043133 _____ () C:\Users\Lukas\Desktop\FRST.txt 2014-09-02 20:22 - 2014-09-02 20:22 - 02104832 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64(1).exe 2014-09-02 20:22 - 2014-09-02 20:21 - 02104832 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64.exe 2014-09-01 22:50 - 2014-09-01 22:50 - 00037888 ___SH () C:\Users\Lukas\Desktop\Thumbs.db 2014-09-01 00:06 - 2011-09-16 13:15 - 00000432 _____ () C:\Windows\BRWMARK.INI 2014-08-30 18:42 - 2014-08-18 19:47 - 00000001 ____R () C:\Users\Lukas\serverport 2014-08-30 18:36 - 2011-09-15 13:18 - 00000000 ____D () C:\Users\Lukas 2014-08-28 19:38 - 2011-11-28 21:17 - 00000000 ____D () C:\Program Files\Common Files\McAfee 2014-08-28 19:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-08-25 22:38 - 2014-07-28 17:45 - 00000000 ____D () C:\Users\Gast\Desktop\Franzi Mat Examen 2014-08-25 21:45 - 2014-08-18 21:25 - 00000000 ____D () C:\Users\Gast\Desktop\Caro Koll.mat 2014-08-24 23:13 - 2014-08-24 23:11 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2014-2015 2014-08-24 15:22 - 2014-08-06 17:40 - 00000000 ____D () C:\Users\Gast\Desktop\Statement Tanja 2014-08-20 21:59 - 2014-05-23 22:48 - 00000000 ____D () C:\Users\Gast\Desktop\Kolloquium OBAS 2014-08-20 20:05 - 2011-09-16 15:14 - 00000000 ____D () C:\Users\Lukas\Documents\Meine Projekte 2014-08-18 19:51 - 2013-08-11 15:58 - 00001021 _____ () C:\Users\Lukas\Desktop\Dropbox.lnk 2014-08-18 19:51 - 2013-08-11 15:56 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-08-18 19:47 - 2014-08-18 19:47 - 00000000 ____D () C:\Users\Lukas\.jivex 2014-08-14 21:34 - 2013-09-03 17:43 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2013-14 2014-08-14 12:48 - 2014-08-12 20:09 - 00000000 ____D () C:\Users\Gast\Desktop\UB's - Klausuren etc. anderer 2014-08-14 10:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-08-12 22:33 - 2011-10-07 00:46 - 11686864 _____ () C:\Users\Lukas\Documents\Historie von Schumacher, Lukas.logbook3 2014-08-12 20:13 - 2013-08-12 09:34 - 00000000 ____D () C:\Users\Gast\Desktop\Hochzeit 2013 2014-08-12 20:12 - 2014-08-12 20:12 - 00000000 ____D () C:\Users\Gast\Desktop\Tischkalender 2014-08-12 20:11 - 2013-08-14 23:20 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2012-2013 2014-08-12 20:08 - 2013-01-06 12:00 - 00000000 ____D () C:\Users\Gast\Desktop\Sonstiges 2014-08-12 20:08 - 2012-11-12 21:30 - 00000000 ____D () C:\Users\Gast\Desktop\OBAS 2014-08-12 19:52 - 2014-07-28 19:05 - 00000000 ____D () C:\Windows\pss 2014-08-12 19:52 - 2014-04-30 21:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-12 19:52 - 2012-10-20 10:23 - 00000000 ____D () C:\Users\Gast 2014-08-12 19:52 - 2011-10-16 20:32 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-08-12 19:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\L2Schemas 2014-08-06 18:35 - 2012-10-20 10:23 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Adobe 2014-08-05 09:16 - 2013-12-07 18:50 - 00000000 ____D () C:\Users\Lukas\Documents\Steuer Hatschiergasse Some content of TEMP: ==================== C:\Users\Lukas\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmppseu1j.dll C:\Users\Lukas\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-17 21:40 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-08-2014 02 Ran by Lukas at 2014-09-04 23:21:39 Running from C:\Users\Lukas\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: McAfee Anti-Virus und Anti-Spyware (Disabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AS: McAfee Anti-Virus und Anti-Spyware (Disabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: McAfee Firewall (Disabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Acer Backup Manager (HKLM-x32\...\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.85 - NTI Corporation) Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1510 - CyberLink Corp.) Acer Crystal Eye Webcam (x32 Version: 1.0.1510 - CyberLink Corp.) Hidden Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3006 - Acer Incorporated) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Acer Incorporated) Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3004 - Acer Incorporated) Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0401.2011 - Acer Incorporated) Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3005 - Acer Incorporated) Acer VCM (HKLM-x32\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3004 - Acer Incorporated) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.) Adobe AIR (x32 Version: 1.5.0.7220 - Adobe Systems Inc.) Hidden Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Reader X (10.1.3) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.3 - Adobe Systems Incorporated) Adobe Reader XI (11.0.08) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) Backup Manager V3 (x32 Version: 3.0.0.85 - NTI Corporation) Hidden Broadcom Gigabit Integrated Controller (HKLM\...\{394E442A-637D-43EF-B402-4CFD88263CF0}) (Version: 14.6.1.5 - Broadcom Corporation) CollageIt 1.9.3 (HKLM-x32\...\{D9757258-30B2-496E-86F2-84920C5858E1}_is1) (Version: 1.9.3 - PearlMountain Technology Co., Ltd) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.6.0 - Conexant) Corel WinDVD (HKLM-x32\...\{5C1F18D2-F6B7-4242-B803-B5A78648185D}) (Version: 10.0.5.846 - Corel Inc.) Custom (Version: 01.00.00.000 - Wave Systems Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden dm-Fotowelt (HKLM-x32\...\dm-Fotowelt) (Version: 5.0.1 - CEWE COLOR AG u Co. OHG) Doppelkopf XXL (HKCU\...\Doppelkopf XXL) (Version: - ) Dropbox (HKCU\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.) eBay Worldwide (HKLM-x32\...\{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}) (Version: 2.1.0901 - OEM) EgisTec ES603 WDM Driver (HKLM-x32\...\InstallShield_{AE4167B0-F589-4D2A-BF05-E181D543C49F}) (Version: 3.0.16.0 - Egis Technology Inc.) EMBASSY Security Center (Version: 04.03.00.081 - Wave Systems Corp.) Hidden Embassy Trust Suite - Acer Edition (Version: 01.02.01.000 - Wave Systems Corp) Hidden ES603 WDM Driver (x32 Version: 3.0.16.0 - Egis Technology Inc.) Hidden Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Garmin ANT Agent (HKLM\...\{4E21D7C1-80CA-48A0-9983-9F60EEA70B50}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Garmin Communicator Plugin (HKLM-x32\...\{8ED02445-D491-414C-A56D-2ED6BBB7239A}) (Version: 3.0.1 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries) Garmin WebUpdater (HKLM-x32\...\{00FE2935-FB56-4410-AB5F-D6E70C1771D2}) (Version: 2.5.6 - Garmin Ltd or its subsidiaries) Garmin WebUpdater (HKLM-x32\...\{B39177F9-269D-4A9B-82F2-7A48589CCCEF}) (Version: 2.5.2 - Garmin Ltd or its subsidiaries) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.103 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3006 - Acer Incorporated) Install Absolute Data Protect (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 1.0.0.39 - Absolute Software) InstantView (HKLM-x32\...\InstallShield_{9C92176C-CAA2-481D-BD9C-9DED2A36C290}) (Version: 3.0.12.0 - Splashtop Inc.) InstantView (x32 Version: 3.0.12.0 - Splashtop Inc.) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2345 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan) Java(TM) 7 Update 4 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417004FF}) (Version: 7.0.40 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Konz 2013 (HKLM-x32\...\InstallShield_{76651FD7-2B71-4B61-9F3A-E82F52F08D92}) (Version: 1.00.0000 - USM) Konz 2013 (x32 Version: 1.00.0000 - USM) Hidden Launch Manager (HKLM-x32\...\LManager) (Version: 6.0.4 - Acer Inc.) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) McAfee Internet Security Suite (HKLM-x32\...\MSC) (Version: 12.8.988 - McAfee, Inc.) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 32.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0 (x86 de)) (Version: 32.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) newsXpresso (HKLM-x32\...\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.) newsXpresso (x32 Version: 1.0.0.40 - esobi Inc.) Hidden Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8942 - NTI Corporation) NTI Media Maker 9 (x32 Version: 9.0.2.8942 - NTI Corporation) Hidden NTRU TCG Software Stack (Version: 2.1.34 - Security Innovation) Hidden Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ProShield (HKLM-x32\...\InstallShield_{08CCD7B4-9EED-4926-805D-C4FFF869989A}) (Version: 1.0.44.0 - Egis Technology Inc.) ProShield (Version: 1.0.44.0 - Egis Technology Inc.) Hidden ProShield TPM (Version: 01.01.00.012 - Wave Systems Corp) Hidden Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7600.69 - Realtek Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.30.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.30.0 - Renesas Electronics Corporation) Hidden Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SportTracks 3.1 (HKLM-x32\...\{99895EF0-B290-4B21-B1FE-FB00E1B5D195}) (Version: 3.1.4871 - Zone Five Software) Steuer 2012 (HKLM-x32\...\{01159E8A-44F7-4885-A7F9-872CE4D74063}) (Version: 20.00.8137 - Buhl Data Service GmbH) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1150 - SUPERAntiSpyware.com) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.14.0 - Synaptics Incorporated) t@x 2012 (HKLM-x32\...\{0E806605-5B82-4A4F-BC31-AA4FADA03C42}) (Version: 19.00.7303 - Buhl Data Service GmbH) t@x 2014 (HKLM-x32\...\{2547CF96-DBB7-4EDD-9327-0EFDD0D1FA8A}) (Version: 21.00.8480 - Buhl Data Service GmbH) TrainingPeaks Device Agent (HKLM-x32\...\{8C477370-143C-4D9D-BD33-289D1C1A0870}) (Version: 3.0.85 - TrainingPeaks) TuneUp Utilities 2012 (HKLM-x32\...\TuneUp Utilities 2012) (Version: 12.0.3500.13 - TuneUp Software) TuneUp Utilities 2012 (x32 Version: 12.0.3500.13 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3500.13 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) Wave Infrastructure Installer (Version: 07.67.00.0005 - Wave Systems Corp) Hidden Wave Support Software Installer (Version: 05.13.00.021 - Wave Systems Corp) Hidden Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3102 - Acer Incorporated) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7300 - Broadcom Corporation) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin) Windows Installer Clean Up (HKLM-x32\...\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}) (Version: 3.00.00.0000 - Microsoft Corporation) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows-Treiberpaket - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2) (HKLM\...\24DA573F901348FFDFF7717497830D45BE0C362E) (Version: 07/07/2009 1.12.2 - Dynastream Innovations) Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}\InprocServer32 -> C:\PROGRA~2\APPGRA~1\APPGRA~2.DLL No File CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}\InprocServer32 -> C:\PROGRA~2\APPGRA~1\APPGRA~2.DLL No File CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ==================== Restore Points ========================= 17-08-2014 18:43:00 Windows-Sicherung 24-08-2014 18:12:46 Windows-Sicherung 30-08-2014 20:32:06 Windows Update 31-08-2014 17:02:45 Windows-Sicherung 01-09-2014 13:45:48 Windows Update 01-09-2014 20:57:46 Windows Update 03-09-2014 19:56:58 ComboFix created restore point 03-09-2014 19:57:47 ComboFix created restore point 03-09-2014 19:59:52 ComboFix created restore point 03-09-2014 20:08:14 Wiederherstellungsvorgang 03-09-2014 21:01:04 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2012-05-19 09:32 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {022A01D8-D879-4C1A-A4B2-AFF10FAF06CF} - System32\Tasks\{FF17CDB8-8C5B-4A26-848E-0F36130C8DA8} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.116/en/abandoninstall?page=tsMain Task: {06A00C55-465C-42CE-87FA-2024B1E69F15} - System32\Tasks\{21D2A9EE-A847-4670-9FE7-6711B8FA9C6A} => Firefox.exe Task: {36158F5A-2FA7-46CA-99CB-9629EF26CC90} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-23] (Adobe Systems Incorporated) Task: {40961FA9-90ED-499A-B7DA-F83FA311B538} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2012-04-05] (TuneUp Software) Task: {803A023E-3F43-43AA-873F-71C6A1EB98E4} - System32\Tasks\{8CB05960-CF37-4A51-B3F3-8EE6370BE276} => Firefox.exe hxxp://ui.skype.com/ui/0/5.8.0.158/en/abandoninstall?page=tsMain Task: {8A9C8ADE-EF09-4725-BA9C-9596D635B3D5} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {BC7462CC-E59A-4A52-9FDD-C2328FFD993B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21] (Google Inc.) Task: {CEB91A61-C512-446C-88FA-2178D898A876} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe Task: {EC303973-B23D-4645-8CFF-28679A8EF37C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-03-31 19:58 - 2011-03-31 19:58 - 01407536 _____ () C:\Program Files\Acer ProShield\LIBEAY32.dll 2010-07-13 14:02 - 2010-07-13 14:02 - 01629696 _____ () C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe 2011-06-02 18:38 - 2011-03-27 01:29 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2010-12-10 15:53 - 2010-12-10 15:53 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2014-06-23 20:39 - 2013-10-30 17:45 - 00587856 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe 2011-02-15 20:37 - 2011-02-15 20:37 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll 2011-02-15 20:36 - 2011-02-15 20:36 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll 2011-02-15 20:37 - 2011-02-15 20:37 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 09572944 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wgui14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00034896 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsdcom48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00308816 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rscorewinapi48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00321616 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsguiwinapi48.dll 2014-06-23 20:36 - 2013-10-30 17:46 - 03674192 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wcore14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00136272 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsodbc48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 02467408 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wfvie14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01855568 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wsteu14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01904208 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wreli14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 04277840 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wauff14.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 01043456 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-core.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 00094720 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-shared.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 00250368 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-contribs-lib.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01396816 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wmain14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 05019728 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae114.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01666128 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae214.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01786448 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae314.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01624144 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae414.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01125456 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\whau114.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01316944 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\whau214.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01278544 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wwerb14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 06818384 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wkont14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01266768 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wimp14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01322064 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wfabu14.dll 2014-09-04 22:32 - 2014-09-04 22:32 - 00043008 _____ () c:\users\lukas\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmppseu1j.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Lukas\AppData\Roaming\Dropbox\bin\libcef.dll 2012-07-30 22:42 - 2014-09-03 21:51 - 03715184 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Lukas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: iLivid => "C:\Users\Lukas\AppData\Local\iLivid\iLivid.exe" -autorun MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Faulty Device Manager Devices ============= Name: Microsoft-Adapter für Miniports virtueller WiFis Description: Microsoft-Adapter für Miniports virtueller WiFis Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: vwifimp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (09/04/2014 11:18:16 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Microsoft Office Sessions: ========================= Error: (05/03/2014 03:25:14 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6695.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 71 seconds with 60 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-06-26 17:52:25.731 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-26 17:52:25.419 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-02 18:56:47.885 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-04-02 18:56:47.602 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-22 19:44:48.728 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-02-22 19:44:48.517 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-05-19 00:03:56.921 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-05-19 00:03:56.889 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz Percentage of memory in use: 62% Total physical RAM: 3944.34 MB Available physical RAM: 1488.72 MB Total Pagefile: 7886.86 MB Available Pagefile: 4960.46 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:444.96 GB) (Free:316.53 GB) NTFS Drive d: (tax2014) (CDROM) (Total:0.49 GB) (Free:0 GB) CDFS Drive e: () (Removable) (Total:7.45 GB) (Free:5.3 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4FB426AA) Partition 1: (Not Active) - (Size=12.7 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=453 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 7.5 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ |
05.09.2014, 20:05 | #9 |
/// the machine /// TB-Ausbilder | Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlllESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.09.2014, 18:38 | #10 |
| Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll Results of screen317's Security Check version 0.99.87 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 Out of date! ``````````````Antivirus/Firewall Check:`````````````` McAfee Anti-Virus und Anti-Spyware WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` TuneUp Utilities 2012 TuneUp Utilities Language Pack (de-DE) Adobe Flash Player 14.0.0.145 Adobe Reader XI Mozilla Firefox (32.0) Google Chrome 36.0.1985.143 Google Chrome 37.0.2062.103 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Malwarebytes Anti-Malware mbamscheduler.exe Symantec Norton Online Backup NOBuAgent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=de39b6964faece419c85c5fdb61335ac # engine=20043 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2014-09-07 11:59:26 # local_time=2014-09-08 01:59:26 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 36325396 161764216 0 0 # scanned=241748 # found=80 # cleaned=0 # scan_time=13448 sh=8871BA7436B0D8B92BE4824C9B0DF4AF1EE01979 ft=1 fh=783c8a9d5bb7b11d vn="Win32/AdWare.Loadshop.A Anwendung" ac=I fn="C:\monitor.exe" sh=C5E60CCD154DB4E5978E33285DB016171C80ED79 ft=1 fh=58635ab0e5696ad2 vn="Win32/AdWare.Loadshop.A Anwendung" ac=I fn="C:\monitorsvc.exe" sh=E15DF75E5B81A209E0E453092C9610C3F8DC7073 ft=1 fh=8918dac93ad3a346 vn="Win32/Toolbar.SearchSuite.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\wincert\win32cert.dll.vir" sh=9B56D5787C88CF939DABA1E9273775A1D33EF25F ft=1 fh=8aacdf233e2d6e39 vn="Win32/Toolbar.SearchSuite.M evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\wincert\win32prop.dll.vir" sh=2FA019C3D1CC2BC1905FBD6765DA3CFBE851DD64 ft=1 fh=f275e610e24fd946 vn="Win64/Toolbar.SearchSuite.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\wincert\win64cert.dll.vir" sh=34ABB88310B01A075382292FDE9F2B6E727E5D66 ft=1 fh=1bef8d0f51d0bf3a vn="Win64/Toolbar.SearchSuite.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\wincert\win64prop.dll.vir" sh=0E21B4B011AF3625278279C3598B7584CEC6D7A9 ft=1 fh=db225e0c516169ed vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\LocalLow\AskToolbar\setup.exe.vir" sh=6ED813A630D624262ECEE3F534F9EA3CC53052E9 ft=1 fh=9aa4c9f5144d6046 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF10.dll.vir" sh=A34BC0051E27CE0B7E352300A9D112F7FF71675A ft=1 fh=168588223c734f78 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF11.dll.vir" sh=BFC51C8409B3BDCA6155D773DBFB950271F25008 ft=1 fh=6e209e52f63757fc vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF12.dll.vir" sh=D6DD9B3E0D2EB86028C1783861E2D9860DB82891 ft=1 fh=8bf73d1687568fa4 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF13.dll.vir" sh=633678C5A8F9EFF41F86E3A90DC3F100E1C77B8B ft=1 fh=faa2649f2bb6aafa vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF14.dll.vir" sh=3CCD2EFD57DBA9840572E6D12DE2940BEB299B3F ft=1 fh=19884fb3e20aba11 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF15.dll.vir" sh=788A3B4FEAABCA18C1A965ED9713BE41E4EDD743 ft=1 fh=cdb6f553cd8b332b vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF16.dll.vir" sh=8B31545B92F16DC7142E59DA8E9EA80727D9B1DE ft=1 fh=3347880f6cde8241 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF17.dll.vir" sh=298183076557800265EF43BBAA62D84D27AADC73 ft=1 fh=43935830dfb99302 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF18.dll.vir" sh=735E01AEC0DBABDF100513DB5973A4B5376144E6 ft=1 fh=80d6175230bedea8 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF19.dll.vir" sh=8047C15C004A125EA14FCE59960BE900DA5BDD74 ft=1 fh=0f2c8c3a346e1838 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF2.dll.vir" sh=205087345BF983FA31FCB04F20293A48FD642591 ft=1 fh=8028eab4f896a26d vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF20.dll.vir" sh=98ABA07A28E0BD9FEFE77F9B0C6C9160DF227DC6 ft=1 fh=e9612ddbe72d1a7a vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF21.dll.vir" sh=76CDCFFD177EE7C00BF5352DAFAA977CB62CDF6D ft=1 fh=a775e2b0e7763fb7 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF22.dll.vir" sh=1F76BC3967F9104D55B3270383F3B253AA3362A9 ft=1 fh=42cc7fdb1b6469c1 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF23.dll.vir" sh=A49AC504697A4734069DB1E216E26AA2E9116920 ft=1 fh=7f5f2bf2d5f8dccb vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF24.dll.vir" sh=383F8552C75BA9C41F1075FE45ADE9328B0F62E9 ft=1 fh=49e989bec7eda200 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF25.dll.vir" sh=B78AEB51E629E9238A77245511C4A1F1E5E90CE5 ft=1 fh=d45c651b103f550b vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF26.dll.vir" sh=E1EF19D9DFC206C60DB43DE01F2139EA102B7B41 ft=1 fh=2cd269b973b155b5 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF27.dll.vir" sh=E73C7F5F11503CC5FAF164B84CFE1659F70DE930 ft=1 fh=753be6a5765c12ca vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF28.dll.vir" sh=3D8A8E60CC5A661BB46B2AA78783F3B4814ABEC3 ft=1 fh=ee9d8e877a50be86 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF29.dll.vir" sh=D8221CBD9520FF09BEF676F086B2CE1F3B1CABB5 ft=1 fh=e01398c0d76fc71b vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF30.dll.vir" sh=A40B2B453F56AD76F7445B3912B2FCB605C6FB36 ft=1 fh=b151e3f20ccca123 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF31.dll.vir" sh=5EB427B4638E4AF65BD495992876B9C0128C6D5D ft=1 fh=ab3429fbb8301f61 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF32.dll.vir" sh=5D9AA104A71993E1C8061AAC16992A1359A249FA ft=1 fh=1bdb516c48138e02 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF4.dll.vir" sh=7DD5FE9144CFEB563ECA9672A89512994E03A71E ft=1 fh=30cb2246aa08d0be vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF5.dll.vir" sh=9928BFD0739D958F41A0B8B6E514290EDE3B5164 ft=1 fh=48de3bb051071801 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF6.dll.vir" sh=84C0062450607FBED3BF0A3CF187E5694C28B299 ft=1 fh=9312700dd1c8881e vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF7.dll.vir" sh=3A342938196DC74625EBC28A5CD137DA03144095 ft=1 fh=6bd472d851c9f3d4 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF8.dll.vir" sh=77D1904BECFE91879680B754F242115F1CED0BF3 ft=1 fh=da72a93d2c0cb607 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Lukas\AppData\Roaming\Movies Toolbar\Datamngr\components\DatamngrHlpFF9.dll.vir" sh=6D06D25BB79A82D2BAA3AAD03E901D1D12C0DC22 ft=1 fh=c71c00111b569fe2 vn="Variante von Win32/AdWare.Loadshop.A Anwendung" ac=I fn="C:\Program Files (x86)\Web Protect\PCProxyDLL.dll" sh=6A323C7F17097EC3A1C50FF05062A882DD53FDA8 ft=1 fh=8b8ece738f833e97 vn="Win32/AdWare.Loadshop.A Anwendung" ac=I fn="C:\Program Files (x86)\Web Protect\postcollect.exe" sh=DC4710E053EDCAB02CDA8E3F860ACF7CBD8A49E5 ft=1 fh=061dc47af0b1997f vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF10.dll" sh=764446613C66912805429EBAD62AFD1C2B2145DB ft=1 fh=47a54ca737c2b770 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF11.dll" sh=16A2A971597193BD174BBF446A743BF170FD2BA8 ft=1 fh=9d8dc4b8546985ba vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF12.dll" sh=62A5D44B6AA25EB10EEC9411A9088A6EBB5AD4B0 ft=1 fh=e3dd75675a7aced6 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF13.dll" sh=E35991E3CBC53D732DB5D6FEA12598B7094C3CFF ft=1 fh=deb615d9f2bd9111 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF14.dll" sh=5B23F9716F6836F09F8500AD5984930993FE00FA ft=1 fh=a8980dc88754f126 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF15.dll" sh=C9C97108E64B2A0572C4952CD47013AB3B27920E ft=1 fh=2025584fdc70bd03 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF16.dll" sh=CD7CC266568ECC16E4930B2F93C72C84AE51EA3E ft=1 fh=27f46dc5f8239349 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF17.dll" sh=2C7B662A851332F31EAB538C081017F6659F686C ft=1 fh=96e848d63797276e vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF18.dll" sh=67C90F155DC2E56BF6157DA93841EFEC26931AB3 ft=1 fh=ca635f9720ff0079 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF19.dll" sh=6FADC7587C7D5B0EB779A7101D918886A68E1DA9 ft=1 fh=6bd8844b511de926 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF2.dll" sh=F4B9F7454CE999655C0DBE40E3B475A1E7B39D41 ft=1 fh=3627f2133fb5bbb9 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF20.dll" sh=DD73DD9E13CBBA50EBA82C375EBB8A22A69CBD4D ft=1 fh=672df818e46cd097 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF21.dll" sh=71ED15D68AC8F0C2D8CF741F3F941DE4BAC7D2BC ft=1 fh=2822e665f809e59e vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF22.dll" sh=041AD771557BA8E3161E95165CFE95908B231553 ft=1 fh=dc95860e4611b3e3 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF23.dll" sh=B6EFA847DC41BEE6FA07A4C4D90015071C201166 ft=1 fh=71a7f750880a012b vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF24.dll" sh=C0D9719CCA64FC6AD28FEA85FC5E7F3724D9483F ft=1 fh=b9a8baa2055316ed vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF25.dll" sh=EEA7CE8FB834B922091EFEC02EF242539505F783 ft=1 fh=e8ae79e9b8a71d7b vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF26.dll" sh=FB9A187963CDD85694C90E3F1F061159D0B4B738 ft=1 fh=41adfce1220f70ce vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF27.dll" sh=13982327E989D1C77ACF94C9DECCFA89A8B405F7 ft=1 fh=e442870230896809 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF28.dll" sh=46336991FC2CB2778115AF16DC382280EA511A64 ft=1 fh=b6d23f24a41f5830 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF30.dll" sh=5249EF58DE167F31FF385E2BDE24882AD4B7762D ft=1 fh=590dfb9d9cc6b912 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF4.dll" sh=B8CC5AFBB00A2078EF899FEBED1288A063B01472 ft=1 fh=45a11458d65c9f46 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF5.dll" sh=2A5C2444820DA0E9F929338AFB25DEF29B8082A0 ft=1 fh=bf268765a715d7b5 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF6.dll" sh=14910F43EBCEA14B1A267379D3B6A6F66436218E ft=1 fh=a5d9c5b3bf23b774 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF7.dll" sh=650B9C8B45B39B53B81FC4F9E3F625A4F3B3B1C5 ft=1 fh=ffd99e437233b6ac vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF8.dll" sh=02DBFFDE65A5EFC16C084EEF45A2B92E2A926303 ft=1 fh=e1202b960e1270d5 vn="möglicherweise Variante von Win32/Toolbar.SearchSuite.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\eexu0xb2.default\extensions\{BE46A798-61BC-A9D8-46F4-CE1E027D52D9}\components\DatamngrHlpFF9.dll" sh=46AB0F3561D9268478BABC1BE6322E2626D0336F ft=1 fh=fd41b31aaaa50cda vn="Win32/Toolbar.SearchSuite evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\Downloads\iLividSetup(1).exe" sh=46AB0F3561D9268478BABC1BE6322E2626D0336F ft=1 fh=fd41b31aaaa50cda vn="Win32/Toolbar.SearchSuite evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\Downloads\iLividSetup(2).exe" sh=46AB0F3561D9268478BABC1BE6322E2626D0336F ft=1 fh=fd41b31aaaa50cda vn="Win32/Toolbar.SearchSuite evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Gast\Downloads\iLividSetup.exe" sh=9B72604832B83A5508824184D19DF2E98B654EA4 ft=1 fh=29a0d2f607c0a043 vn="Win32/Conduit.SearchProtect.Q evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Lukas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\02769I22\searchprotect_w_prechecker[1].exe" sh=55D34CE6C6205662904642029129AB63E8E99EE9 ft=1 fh=752105845350abbc vn="Variante von Win32/AdWare.Loadshop.A Anwendung" ac=I fn="C:\Users\Lukas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F1IPYCZQ\wp-adinject-adk.210[1].exe" sh=542CE206747FF7E65FFA92B41F39E31CDEB5A548 ft=1 fh=d8426f61a71ae618 vn="Variante von MSIL/Adware.iBryte.G Anwendung" ac=I fn="C:\Users\Lukas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JC4JZ505\rt-installer[1].exe" sh=A836A8346F791EC8A83B51BC78E84B2F6659E6DA ft=1 fh=0a2e45c370149901 vn="Win32/Wajam.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Lukas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JC4JZ505\wajam_validate[1].exe" sh=67112FF10778696366E20309A551BAC45D40F26A ft=1 fh=d5d993d7cb04e4ef vn="Win32/iLivid.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Lukas\Downloads\iLividSetup-r887-n-bf(1).exe" sh=67112FF10778696366E20309A551BAC45D40F26A ft=1 fh=d5d993d7cb04e4ef vn="Win32/iLivid.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Lukas\Downloads\iLividSetup-r887-n-bf(2).exe" sh=67112FF10778696366E20309A551BAC45D40F26A ft=1 fh=d5d993d7cb04e4ef vn="Win32/iLivid.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Lukas\Downloads\iLividSetup-r887-n-bf.exe" sh=5AD707FDE25B12F90F8C3CA1B9CD7DB04D28003B ft=1 fh=adcdec35425f92da vn="Variante von Win32/AdWare.iBryte.BH Anwendung" ac=I fn="C:\Users\Lukas\Downloads\Setup(1).exe" sh=5AD707FDE25B12F90F8C3CA1B9CD7DB04D28003B ft=1 fh=adcdec35425f92da vn="Variante von Win32/AdWare.iBryte.BH Anwendung" ac=I fn="C:\Users\Lukas\Downloads\Setup.exe" sh=D102D0E880558D12D81BB9A0C6EF480A3ACF8BFA ft=1 fh=9f3140d695f7767e vn="Variante von Win32/SoftonicDownloader.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Lukas\Downloads\SoftonicDownloader_fuer_photo-collage-creator.exe" sh=5942175491655D8CD11AB186C4E99EA2D62363B9 ft=0 fh=0000000000000000 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="C:\Windows\Installer\a7e31f.msi" FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-09-2014 01 Ran by Lukas (administrator) on LUKAS-PC on 08-09-2014 19:29:06 Running from C:\Downloads\Software Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Egis Technology Inc. ) C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. ) C:\Program Files\Acer ProShield\x86\EgisService.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Just Develop It) C:\Program Files (x86)\MyPC Backup\BackupStack.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe () C:\monitor.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\ReminderService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\DVMExportService.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\aoiosnap.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\LockKey.exe (GARMIN Corp.) C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (FreeDownloadManager.ORG) C:\Program Files (x86)\Free Download Manager\fdm.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Intel Corporation) C:\Windows\System32\igfxext.exe () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Egis Technology Inc. ) C:\Program Files\Acer ProShield\EgisTSR.exe (Dropbox, Inc.) C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (MyPCBackup.com) C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (McAfee, Inc.) C:\Program Files\McAfee\MSM\McSmtFwk.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (Microsoft Corporation) C:\Windows\System32\wermgr.exe (Microsoft Corporation) C:\Windows\System32\wermgr.exe (Microsoft Corporation) C:\Windows\System32\wermgr.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [524928 2011-05-07] (Conexant Systems, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2697512 2011-02-18] (Synaptics Incorporated) HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-22] (Acer Incorporated) HKLM\...\Run: [ProShieldTSR] => C:\Program Files\Acer ProShield\EgisTSR.exe [165936 2011-03-31] (Egis Technology Inc. ) HKLM\...\Run: [InstantView Agent] => C:\Program Files (x86)\InstantView\tools\aoiosnap.exe [1127840 2011-04-28] (Splashtop Inc.) HKLM\...\Run: [InstantView LockKey] => C:\Program Files (x86)\InstantView\tools\LockKey.exe [1498472 2011-04-29] (Splashtop Inc.) HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-02-15] (NTI Corporation) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1097296 2011-04-13] (Dritek System Inc.) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoFolderOptions] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [ANT Agent] => C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe [14731776 2013-02-15] (GARMIN Corp.) HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [Free Download Manager] => C:\Program Files (x86)\Free Download Manager\fdm.exe [6983168 2014-05-09] (FreeDownloadManager.ORG) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk ShortcutTarget: Acer VCM.lnk -> C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\t@x aktuell.lnk ShortcutTarget: t@x aktuell.lnk -> C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe () Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com) Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {09598583-814E-4AD3-946D-8332FFB2AB1E} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {E93B7101-F66B-4178-82CF-36C2D0B941A9} URL = hxxp://de.search.yahoo.com/search?fr=mcafee&type=A011DE662&p={SearchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: EgisPBIE Sign-in Helper -> {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} -> C:\Program Files\Acer ProShield\x86\EgisPBIE.dll (Egis Technology Inc.) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Free Download Manager -> {CC59E0F9-7E43-44FA-9FAA-8377850BF205} -> C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.) Winsock: Catalog9 01 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 02 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 03 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 04 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 16 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9-x64 01 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 02 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 03 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 04 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 16 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Lukas\AppData\Roaming\Mozilla\Firefox\Profiles\iakpctl9.default-1406566022487 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.4.0 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.4.0 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-09-2014 01 Ran by Lukas at 2014-09-08 19:30:42 Running from C:\Downloads\Software Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Acer Backup Manager (HKLM-x32\...\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.85 - NTI Corporation) Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1510 - CyberLink Corp.) Acer Crystal Eye Webcam (x32 Version: 1.0.1510 - CyberLink Corp.) Hidden Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3006 - Acer Incorporated) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Acer Incorporated) Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3004 - Acer Incorporated) Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0401.2011 - Acer Incorporated) Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3005 - Acer Incorporated) Acer VCM (HKLM-x32\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3004 - Acer Incorporated) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.) Adobe AIR (x32 Version: 1.5.0.7220 - Adobe Systems Inc.) Hidden Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Reader X (10.1.3) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.3 - Adobe Systems Incorporated) Adobe Reader XI (11.0.08) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) Backup Manager V3 (x32 Version: 3.0.0.85 - NTI Corporation) Hidden Broadcom Gigabit Integrated Controller (HKLM\...\{394E442A-637D-43EF-B402-4CFD88263CF0}) (Version: 14.6.1.5 - Broadcom Corporation) BrowserSafeguard with RocketTab (HKLM-x32\...\RocketTab) (Version: - BrowserSafeguard with RocketTab) <==== ATTENTION CollageIt 1.9.3 (HKLM-x32\...\{D9757258-30B2-496E-86F2-84920C5858E1}_is1) (Version: 1.9.3 - PearlMountain Technology Co., Ltd) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.6.0 - Conexant) Corel WinDVD (HKLM-x32\...\{5C1F18D2-F6B7-4242-B803-B5A78648185D}) (Version: 10.0.5.846 - Corel Inc.) Custom (Version: 01.00.00.000 - Wave Systems Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden dm-Fotowelt (HKLM-x32\...\dm-Fotowelt) (Version: 5.0.1 - CEWE COLOR AG u Co. OHG) Doppelkopf XXL (HKCU\...\Doppelkopf XXL) (Version: - ) Dropbox (HKCU\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.) eBay Worldwide (HKLM-x32\...\{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}) (Version: 2.1.0901 - OEM) EgisTec ES603 WDM Driver (HKLM-x32\...\InstallShield_{AE4167B0-F589-4D2A-BF05-E181D543C49F}) (Version: 3.0.16.0 - Egis Technology Inc.) EMBASSY Security Center (Version: 04.03.00.081 - Wave Systems Corp.) Hidden Embassy Trust Suite - Acer Edition (Version: 01.02.01.000 - Wave Systems Corp) Hidden ES603 WDM Driver (x32 Version: 3.0.16.0 - Egis Technology Inc.) Hidden ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Free Download Manager 3.9.4 (HKLM-x32\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Garmin ANT Agent (HKLM\...\{4E21D7C1-80CA-48A0-9983-9F60EEA70B50}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Garmin Communicator Plugin (HKLM-x32\...\{8ED02445-D491-414C-A56D-2ED6BBB7239A}) (Version: 3.0.1 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries) Garmin WebUpdater (HKLM-x32\...\{00FE2935-FB56-4410-AB5F-D6E70C1771D2}) (Version: 2.5.6 - Garmin Ltd or its subsidiaries) Garmin WebUpdater (HKLM-x32\...\{B39177F9-269D-4A9B-82F2-7A48589CCCEF}) (Version: 2.5.2 - Garmin Ltd or its subsidiaries) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.103 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3006 - Acer Incorporated) Install Absolute Data Protect (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 1.0.0.39 - Absolute Software) InstantView (HKLM-x32\...\InstallShield_{9C92176C-CAA2-481D-BD9C-9DED2A36C290}) (Version: 3.0.12.0 - Splashtop Inc.) InstantView (x32 Version: 3.0.12.0 - Splashtop Inc.) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2345 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan) Java(TM) 7 Update 4 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417004FF}) (Version: 7.0.40 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Konz 2013 (HKLM-x32\...\InstallShield_{76651FD7-2B71-4B61-9F3A-E82F52F08D92}) (Version: 1.00.0000 - USM) Konz 2013 (x32 Version: 1.00.0000 - USM) Hidden Launch Manager (HKLM-x32\...\LManager) (Version: 6.0.4 - Acer Inc.) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) McAfee Internet Security Suite (HKLM-x32\...\MSC) (Version: 12.8.988 - McAfee, Inc.) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 32.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0 (x86 de)) (Version: 32.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyPC Backup (HKLM\...\MyPC Backup) (Version: - JDi Backup Ltd) <==== ATTENTION newsXpresso (HKLM-x32\...\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.) newsXpresso (x32 Version: 1.0.0.40 - esobi Inc.) Hidden Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8942 - NTI Corporation) NTI Media Maker 9 (x32 Version: 9.0.2.8942 - NTI Corporation) Hidden NTRU TCG Software Stack (Version: 2.1.34 - Security Innovation) Hidden Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ProShield (HKLM-x32\...\InstallShield_{08CCD7B4-9EED-4926-805D-C4FFF869989A}) (Version: 1.0.44.0 - Egis Technology Inc.) ProShield (Version: 1.0.44.0 - Egis Technology Inc.) Hidden ProShield TPM (Version: 01.01.00.012 - Wave Systems Corp) Hidden Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7600.69 - Realtek Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.30.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.30.0 - Renesas Electronics Corporation) Hidden Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SportTracks 3.1 (HKLM-x32\...\{99895EF0-B290-4B21-B1FE-FB00E1B5D195}) (Version: 3.1.4871 - Zone Five Software) Steuer 2012 (HKLM-x32\...\{01159E8A-44F7-4885-A7F9-872CE4D74063}) (Version: 20.00.8137 - Buhl Data Service GmbH) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1150 - SUPERAntiSpyware.com) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.14.0 - Synaptics Incorporated) t@x 2012 (HKLM-x32\...\{0E806605-5B82-4A4F-BC31-AA4FADA03C42}) (Version: 19.00.7303 - Buhl Data Service GmbH) t@x 2014 (HKLM-x32\...\{2547CF96-DBB7-4EDD-9327-0EFDD0D1FA8A}) (Version: 21.00.8480 - Buhl Data Service GmbH) TrainingPeaks Device Agent (HKLM-x32\...\{8C477370-143C-4D9D-BD33-289D1C1A0870}) (Version: 3.0.85 - TrainingPeaks) TuneUp Utilities 2012 (HKLM-x32\...\TuneUp Utilities 2012) (Version: 12.0.3500.13 - TuneUp Software) TuneUp Utilities 2012 (x32 Version: 12.0.3500.13 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3500.13 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) Wave Infrastructure Installer (Version: 07.67.00.0005 - Wave Systems Corp) Hidden Wave Support Software Installer (Version: 05.13.00.021 - Wave Systems Corp) Hidden Web Protect for Windows (HKLM-x32\...\wp-adinject-adk) (Version: 10.0.0 - Web Protect) <==== ATTENTION Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3102 - Acer Incorporated) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7300 - Broadcom Corporation) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin) Windows Installer Clean Up (HKLM-x32\...\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}) (Version: 3.00.00.0000 - Microsoft Corporation) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows-Treiberpaket - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2) (HKLM\...\24DA573F901348FFDFF7717497830D45BE0C362E) (Version: 07/07/2009 1.12.2 - Dynastream Innovations) Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}\InprocServer32 -> C:\PROGRA~2\APPGRA~1\APPGRA~2.DLL No File CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}\InprocServer32 -> C:\PROGRA~2\APPGRA~1\APPGRA~2.DLL No File CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ==================== Restore Points ========================= 30-08-2014 20:32:06 Windows Update 31-08-2014 17:02:45 Windows-Sicherung 01-09-2014 13:45:48 Windows Update 01-09-2014 20:57:46 Windows Update 03-09-2014 19:56:58 ComboFix created restore point 03-09-2014 19:57:47 ComboFix created restore point 03-09-2014 19:59:52 ComboFix created restore point 03-09-2014 20:08:14 Wiederherstellungsvorgang 03-09-2014 21:01:04 Windows Update 05-09-2014 17:54:28 Windows Update 07-09-2014 17:00:49 Windows-Sicherung 08-09-2014 01:02:10 Windows Update 08-09-2014 05:16:48 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2012-05-19 09:32 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {022A01D8-D879-4C1A-A4B2-AFF10FAF06CF} - System32\Tasks\{FF17CDB8-8C5B-4A26-848E-0F36130C8DA8} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.116/en/abandoninstall?page=tsMain Task: {06A00C55-465C-42CE-87FA-2024B1E69F15} - System32\Tasks\{21D2A9EE-A847-4670-9FE7-6711B8FA9C6A} => Firefox.exe Task: {36158F5A-2FA7-46CA-99CB-9629EF26CC90} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-23] (Adobe Systems Incorporated) Task: {40961FA9-90ED-499A-B7DA-F83FA311B538} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2012-04-05] (TuneUp Software) Task: {803A023E-3F43-43AA-873F-71C6A1EB98E4} - System32\Tasks\{8CB05960-CF37-4A51-B3F3-8EE6370BE276} => Firefox.exe hxxp://ui.skype.com/ui/0/5.8.0.158/en/abandoninstall?page=tsMain Task: {8A9C8ADE-EF09-4725-BA9C-9596D635B3D5} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {BC7462CC-E59A-4A52-9FDD-C2328FFD993B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21] (Google Inc.) Task: {C1073839-8466-4FD8-B9D9-3BEA585C2491} - System32\Tasks\RocketTab => C:\Windows\system32\cmd.exe [2010-11-21] (Microsoft Corporation) Task: {C8EE1FFD-E848-4104-BE45-9274278136D6} - System32\Tasks\RocketTab Update Task => C:\Program Files (x86)\RocketTab\uninstall.exe Task: {CE5B9857-B030-4D76-859E-F42AC759AA5F} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe [2014-09-03] (MyPC Backup) <==== ATTENTION Task: {CEB91A61-C512-446C-88FA-2178D898A876} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe Task: {EC303973-B23D-4645-8CFF-28679A8EF37C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-03-31 19:58 - 2011-03-31 19:58 - 01407536 _____ () C:\Program Files\Acer ProShield\LIBEAY32.dll 2010-07-13 14:02 - 2010-07-13 14:02 - 01629696 _____ () C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe 2014-09-03 19:34 - 2014-09-03 19:34 - 01102336 _____ () C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll 2014-09-02 21:55 - 2014-09-02 21:55 - 00487483 _____ () C:\monitor.exe 2010-12-10 15:53 - 2010-12-10 15:53 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2011-06-02 18:38 - 2011-03-27 01:29 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-06-23 20:39 - 2013-10-30 17:45 - 00587856 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe 2014-09-03 19:39 - 2014-09-03 19:39 - 00012288 _____ () C:\Program Files (x86)\MyPC Backup\GetText.dll 2011-02-15 20:37 - 2011-02-15 20:37 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll 2011-02-15 20:36 - 2011-02-15 20:36 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll 2011-02-15 20:37 - 2011-02-15 20:37 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll 2014-09-07 10:14 - 2014-04-29 12:43 - 03553280 _____ () C:\Program Files (x86)\Free Download Manager\fdmbtsupp.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 09572944 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wgui14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00034896 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsdcom48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00308816 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rscorewinapi48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00321616 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsguiwinapi48.dll 2014-06-23 20:36 - 2013-10-30 17:46 - 03674192 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wcore14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00136272 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsodbc48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 02467408 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wfvie14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01855568 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wsteu14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01904208 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wreli14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 04277840 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wauff14.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 01043456 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-core.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 00094720 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-shared.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 00250368 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-contribs-lib.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01396816 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wmain14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 05019728 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae114.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01666128 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae214.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01786448 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae314.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01624144 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae414.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01125456 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\whau114.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01316944 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\whau214.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01278544 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wwerb14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 06818384 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wkont14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01266768 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wimp14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01322064 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wfabu14.dll 2014-09-08 19:22 - 2014-09-08 19:22 - 00043008 _____ () c:\users\lukas\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpa7u4jy.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Lukas\AppData\Roaming\Dropbox\bin\libcef.dll 2012-07-30 22:42 - 2014-09-03 21:51 - 03715184 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-09-07 10:14 - 2014-04-22 21:52 - 00106496 _____ () C:\Program Files (x86)\Free Download Manager\fdmumsp.dll 2014-09-07 10:14 - 2014-04-29 20:20 - 00284160 _____ () C:\Program Files (x86)\Free Download Manager\Firefox\Extension\components\vmsfdmff30.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Lukas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: iLivid => "C:\Users\Lukas\AppData\Local\iLivid\iLivid.exe" -autorun MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Faulty Device Manager Devices ============= Name: Microsoft-Adapter für Miniports virtueller WiFis Description: Microsoft-Adapter für Miniports virtueller WiFis Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: vwifimp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (09/08/2014 07:21:02 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/08/2014 07:17:28 AM) (Source: MsiInstaller) (EventID: 11402) (User: NT-AUTORITÄT) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1402.Could not open key: UNKNOWN\Components\7E756C51681BDA34F86C2167896E312E\67D6ECF5CD5FBA732B8B22BAC8DE1B4D. System error 5. Verify that you have sufficient access to that key, or contact your support personnel. Error: (09/08/2014 03:03:09 AM) (Source: MsiInstaller) (EventID: 11402) (User: NT-AUTORITÄT) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1402.Could not open key: UNKNOWN\Components\7E756C51681BDA34F86C2167896E312E\67D6ECF5CD5FBA732B8B22BAC8DE1B4D. System error 5. Verify that you have sufficient access to that key, or contact your support personnel. Error: (09/08/2014 02:51:32 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/08/2014 02:51:32 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/08/2014 02:51:32 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/08/2014 02:51:27 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/08/2014 02:51:27 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/08/2014 02:51:16 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/08/2014 02:51:16 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Error: (09/08/2014 07:23:31 PM) (Source: WMPNetworkSvc) (EventID: 14349) (User: ) Description: 0x800700b7 Error: (09/08/2014 07:23:31 PM) (Source: WMPNetworkSvc) (EventID: 14353) (User: ) Description: 00x800700b7hxxp://+:10243/WMPNSSv4/2811996591/ Error: (09/08/2014 07:23:31 PM) (Source: WMPNetworkSvc) (EventID: 14349) (User: ) Description: 0x800700b7 Error: (09/08/2014 07:23:31 PM) (Source: WMPNetworkSvc) (EventID: 14353) (User: ) Description: 00x800700b7hxxp://+:10243/WMPNSSv4/2811996591/ Error: (09/08/2014 07:20:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Protect Monitor" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (09/08/2014 07:20:47 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Protect Monitor erreicht. Error: (09/08/2014 07:20:16 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT-AUTORITÄT) Description: 0x8000002a36\SystemRoot\System32\Config\SOFTWARE Error: (09/08/2014 07:17:31 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package (KB2538243) Error: (09/08/2014 06:55:37 AM) (Source: ipnathlp) (EventID: 31004) (User: ) Description: 0 Error: (09/08/2014 04:50:17 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package (KB2538243) Microsoft Office Sessions: ========================= Error: (05/03/2014 03:25:14 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6695.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 71 seconds with 60 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-09-08 02:40:45.237 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 02:40:45.034 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 02:40:44.816 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 02:40:44.582 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 02:40:44.348 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 02:40:44.098 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-07 20:31:14.464 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-07 20:31:14.237 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-07 20:31:13.984 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-26 17:52:25.731 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz Percentage of memory in use: 73% Total physical RAM: 3944.34 MB Available physical RAM: 1033.04 MB Total Pagefile: 7886.86 MB Available Pagefile: 4688.17 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:444.96 GB) (Free:314.21 GB) NTFS Drive d: (tax2014) (CDROM) (Total:0.49 GB) (Free:0 GB) CDFS Drive e: () (Removable) (Total:7.45 GB) (Free:5.3 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4FB426AA) Partition 1: (Not Active) - (Size=12.7 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=453 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 7.5 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ Das Problem ist nicht mehr aufgetreten, vielen Dank dafür. Falls du noch Tipps hast wie ich mich vor solchen Dingen in Zukunft besser schützen kann, wäre ich dir dankbar für entsprechende Hinweise. Ansonsten nochmal vielen lieben Dank!!! --- --- --- |
09.09.2014, 16:37 | #11 |
/// the machine /// TB-Ausbilder | Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen FRST SCan bitte nochmal, das Log ist nicht vollständig.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.09.2014, 16:53 | #12 |
| Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-09-2014 Ran by Lukas (administrator) on LUKAS-PC on 10-09-2014 17:46:05 Running from C:\Users\Lukas\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Egis Technology Inc. ) C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. ) C:\Program Files\Acer ProShield\x86\EgisService.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\aoiosnap.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\LockKey.exe (GARMIN Corp.) C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (FreeDownloadManager.ORG) C:\Program Files (x86)\Free Download Manager\fdm.exe (Egis Technology Inc. ) C:\Program Files\Acer ProShield\EgisTSR.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe () C:\monitor.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\ReminderService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\DVMExportService.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe (Dropbox, Inc.) C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (MyPCBackup.com) C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\consent.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [524928 2011-05-07] (Conexant Systems, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2697512 2011-02-18] (Synaptics Incorporated) HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-22] (Acer Incorporated) HKLM\...\Run: [ProShieldTSR] => C:\Program Files\Acer ProShield\EgisTSR.exe [165936 2011-03-31] (Egis Technology Inc. ) HKLM\...\Run: [InstantView Agent] => C:\Program Files (x86)\InstantView\tools\aoiosnap.exe [1127840 2011-04-28] (Splashtop Inc.) HKLM\...\Run: [InstantView LockKey] => C:\Program Files (x86)\InstantView\tools\LockKey.exe [1498472 2011-04-29] (Splashtop Inc.) HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-02-15] (NTI Corporation) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1097296 2011-04-13] (Dritek System Inc.) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoFolderOptions] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [ANT Agent] => C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe [14731776 2013-02-15] (GARMIN Corp.) HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [Free Download Manager] => C:\Program Files (x86)\Free Download Manager\fdm.exe [6983168 2014-05-09] (FreeDownloadManager.ORG) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk ShortcutTarget: Acer VCM.lnk -> C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\t@x aktuell.lnk ShortcutTarget: t@x aktuell.lnk -> C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe () Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com) Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - DefaultScope {83C5CAA4-EB8D-4BAB-B1FF-671B3E150AF7} URL = https://de.search.yahoo.com/search?fr=mcafee&type=A011DE662&p={SearchTerms} SearchScopes: HKCU - {09598583-814E-4AD3-946D-8332FFB2AB1E} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {83C5CAA4-EB8D-4BAB-B1FF-671B3E150AF7} URL = https://de.search.yahoo.com/search?fr=mcafee&type=A011DE662&p={SearchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: EgisPBIE Sign-in Helper -> {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} -> C:\Program Files\Acer ProShield\x86\EgisPBIE.dll (Egis Technology Inc.) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Free Download Manager -> {CC59E0F9-7E43-44FA-9FAA-8377850BF205} -> C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.) Winsock: Catalog9 01 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 02 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 03 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 04 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 16 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9-x64 01 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 02 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 03 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 04 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 16 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Lukas\AppData\Roaming\Mozilla\Firefox\Profiles\iakpctl9.default-1406566022487 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll () FF Plugin: @java.com/DTPlugin,version=10.4.0 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.4.0 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{41ecbc0b-34d5-4cd4-935f-253a30e2cb7e}] - C:\Program Files\Acer ProShield\FFExt FF Extension: Online Accounts Extension - C:\Program Files\Acer ProShield\FFExt [2011-06-02] FF HKLM-x32\...\Firefox\Extensions: [{d4da7309-b89a-45ec-8ebb-cfb2ae13618b}] - C:\Program Files\Acer ProShield\FFExt20 FF Extension: Online Accounts Extension - C:\Program Files\Acer ProShield\FFExt20 [2011-06-02] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-11-28] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2011-11-28] FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "hxxp://www.google.com" CHR DefaultSearchKeyword: Default -> 6DCF556202F48477D008C34F47DA94C839F5281AF262EF8E93AD8F6E414D3A54 CHR DefaultSearchProvider: Default -> Ask.com CHR DefaultSearchURL: Default -> hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=887&systemid=406&v=a13251-240&apn_uid=5924321086234305&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.103\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.103\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.103\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.270.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U27) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (Adobe Acrobat) - c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Garmin Communicator Plug-In) - C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll () CHR Profile: C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Free Download Manager Chrome extension) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahmpjcflkgiildlgicmcieglgoilbfdp [2014-09-07] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-10] CHR Extension: (SiteAdvisor) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2012-05-21] CHR Extension: (Google Wallet) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-07] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2011-08-12] (SUPERAntiSpyware.com) [File not signed] S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36936 2014-09-03] (Just Develop It) R2 EgisTec Service; C:\Program Files\Acer ProShield\x86\EgisService.exe [195120 2011-03-31] (Egis Technology Inc. ) R2 EgisTec Ticket Service; C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe [205360 2011-03-31] (Egis Technology Inc. ) R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [603424 2014-06-12] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-07-24] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation) R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation) S2 ProtectMonitor; C:\monitorsvc.exe [34244 2014-09-02] () [File not signed] R2 ReminderService; C:\Program Files (x86)\InstantView\tools\ReminderService.exe [29560 2011-04-29] (Splashtop Inc.) R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated) S3 SecureStorageService; C:\Program Files\Acer ProShield\Secure Storage Manager\SecureStorageService.exe [2128776 2011-01-06] (Wave Systems Corp.) R2 SPMDES; C:\Program Files (x86)\InstantView\tools\DVMExportService.exe [467832 2011-04-29] (Splashtop Inc.) R2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1629696 2010-07-13] () [File not signed] R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143552 2012-04-05] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.) R1 DVMIO; C:\Program Files (x86)\InstantView\tools\dvmio_x64.sys [19560 2011-04-28] (DeviceVM, Inc.) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [44480 2011-05-17] (hxxp://libusb-win32.sourceforge.net) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-10] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.) R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [444720 2014-07-24] (McAfee, Inc.) S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96592 2014-07-24] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-03-29] (TuneUp Software) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-10 17:45 - 2014-09-10 17:45 - 00000000 ____D () C:\Users\Lukas\Downloads\FRST-OlderVersion 2014-09-10 17:37 - 2014-09-10 17:37 - 00001167 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-09-10 17:37 - 2014-09-10 17:37 - 00001155 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-09-10 17:37 - 2014-09-10 17:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-09-10 17:30 - 2014-09-10 17:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-09-10 17:16 - 2014-09-10 17:16 - 00001272 _____ () C:\Users\Lukas\Desktop\Revo Uninstaller.lnk 2014-09-10 17:16 - 2014-09-10 17:16 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-09-08 23:33 - 2014-09-08 23:33 - 00111282 _____ () C:\Users\Gast\Desktop\Podcast.pptx 2014-09-08 19:34 - 2014-09-08 19:34 - 00051980 _____ () C:\Users\Lukas\Desktop\Addition.txt 2014-09-08 19:31 - 2014-09-08 19:31 - 00016579 _____ () C:\Users\Lukas\Desktop\FRST.txt 2014-09-07 22:12 - 2014-09-07 22:12 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-09-07 21:24 - 2014-09-07 21:24 - 02347384 _____ (ESET) C:\Users\Lukas\Downloads\esetsmartinstaller_deu(1).exe 2014-09-07 14:45 - 2014-09-10 17:36 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Free Download Manager 2014-09-07 10:18 - 2014-09-07 10:18 - 02347384 _____ (ESET) C:\Users\Lukas\Downloads\esetsmartinstaller_deu.exe 2014-09-07 10:14 - 2014-09-07 10:14 - 00262008 _____ (Software Installer ) C:\Users\Lukas\Downloads\Setup(1).exe 2014-09-07 10:14 - 2014-09-07 10:14 - 00004026 _____ () C:\Windows\System32\Tasks\LaunchSignup 2014-09-07 10:14 - 2014-09-07 10:14 - 00001977 _____ () C:\Users\Lukas\Desktop\Sync Folder.lnk 2014-09-07 10:14 - 2014-09-07 10:14 - 00001095 _____ () C:\Users\Lukas\Desktop\MyPC Backup.lnk 2014-09-07 10:14 - 2014-09-07 10:14 - 00001075 _____ () C:\Users\Lukas\Desktop\Free Download Manager.lnk 2014-09-07 10:14 - 2014-09-07 10:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager 2014-09-07 10:14 - 2014-09-07 10:14 - 00000000 ____D () C:\Program Files (x86)\Free Download Manager 2014-09-07 10:13 - 2014-09-07 14:44 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup 2014-09-07 10:13 - 2014-09-07 10:14 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 2014-09-07 10:12 - 2014-09-01 20:28 - 00350768 _____ (MyOSCompany) C:\Windows\system32\MyOSProtect64.dll 2014-09-07 10:12 - 2014-09-01 20:28 - 00304776 _____ (MyOSCompany) C:\Windows\SysWOW64\MyOSProtect.dll 2014-09-07 10:11 - 2014-09-07 10:13 - 00000000 ____D () C:\Program Files (x86)\Web Protect 2014-09-07 10:10 - 2014-09-07 10:12 - 00000000 ____D () C:\Program Files (x86)\RocketTab 2014-09-07 10:10 - 2014-09-07 10:10 - 00004140 _____ () C:\Windows\System32\Tasks\RocketTab Update Task 2014-09-07 10:10 - 2014-09-07 10:10 - 00003354 _____ () C:\Windows\System32\Tasks\RocketTab 2014-09-07 10:07 - 2014-09-07 10:08 - 00262008 _____ (Software Installer ) C:\Users\Lukas\Downloads\Setup.exe 2014-09-04 23:23 - 2014-09-04 23:23 - 00040959 _____ () C:\Users\Lukas\Desktop\Additionneu.txt 2014-09-04 22:58 - 2014-09-04 22:58 - 01016261 _____ (Thisisu) C:\Users\Lukas\Downloads\JRT.exe 2014-09-04 22:58 - 2014-09-04 22:58 - 00000000 ____D () C:\Windows\ERUNT 2014-09-04 22:50 - 2014-09-04 22:50 - 00002469 _____ () C:\Users\Lukas\Desktop\AdwCleaner[S0].zip 2014-09-04 22:47 - 2014-09-04 22:47 - 00010550 _____ () C:\Users\Lukas\Desktop\protection-log-2014-09-04.zip 2014-09-04 22:45 - 2014-09-04 22:45 - 01110476 _____ () C:\Users\Lukas\Downloads\7z920.exe 2014-09-04 22:45 - 2014-09-04 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2014-09-04 22:45 - 2014-09-04 22:45 - 00000000 ____D () C:\Program Files (x86)\7-Zip 2014-09-04 22:33 - 2014-09-04 22:33 - 00010270 _____ () C:\Users\Lukas\Documents\AdwCleaner[S0].txt 2014-09-04 22:23 - 2014-09-04 22:29 - 00000000 ____D () C:\AdwCleaner 2014-09-04 22:22 - 2014-09-04 22:22 - 01370483 _____ () C:\Users\Lukas\Downloads\adwcleaner_3.309.exe 2014-09-04 21:13 - 2014-09-10 17:24 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-04 21:12 - 2014-09-04 21:12 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-09-04 21:12 - 2014-09-04 21:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-04 21:12 - 2014-09-04 21:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-04 21:12 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-09-04 21:12 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-09-04 21:10 - 2014-09-04 21:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lukas\Downloads\mbam-setup-2.0.2.1012.exe 2014-09-03 22:55 - 2014-09-03 22:55 - 00032500 _____ () C:\ComboFix.txt 2014-09-03 21:56 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-09-03 21:56 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-09-03 21:56 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-09-03 21:54 - 2014-09-03 22:55 - 00000000 ____D () C:\Qoobox 2014-09-02 21:55 - 2014-09-02 21:55 - 00487483 _____ () C:\monitor.exe 2014-09-02 21:55 - 2014-09-02 21:55 - 00034244 _____ () C:\monitorsvc.exe 2014-09-02 20:52 - 2014-09-10 17:47 - 00028325 _____ () C:\Users\Lukas\Downloads\FRST.txt 2014-09-02 20:40 - 2014-09-02 20:43 - 00000234 _____ () C:\Users\Lukas\Downloads\Search.txt 2014-09-02 20:26 - 2014-09-04 23:22 - 00040959 _____ () C:\Users\Lukas\Downloads\Addition.txt 2014-09-02 20:22 - 2014-09-10 17:46 - 00000000 ____D () C:\FRST 2014-09-02 20:21 - 2014-09-10 17:45 - 02105856 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64.exe 2014-08-24 23:11 - 2014-08-24 23:13 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2014-2015 2014-08-18 21:25 - 2014-08-25 21:45 - 00000000 ____D () C:\Users\Gast\Desktop\Caro Koll.mat 2014-08-18 19:47 - 2014-08-30 18:42 - 00000001 ____R () C:\Users\Lukas\serverport 2014-08-18 19:47 - 2014-08-18 19:47 - 00000000 ____D () C:\Users\Lukas\.jivex 2014-08-14 13:50 - 2014-09-09 17:30 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Franz aktuell 2014-08-12 22:33 - 2014-05-03 16:49 - 10510963 ____R () C:\Users\Lukas\Documents\Historie von Schumacher, Lukas~backup-140812.logbook3 2014-08-12 20:12 - 2014-08-12 20:12 - 00000000 ____D () C:\Users\Gast\Desktop\Tischkalender 2014-08-12 20:09 - 2014-08-14 12:48 - 00000000 ____D () C:\Users\Gast\Desktop\UB's - Klausuren etc. anderer ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-10 17:47 - 2014-09-02 20:52 - 00028325 _____ () C:\Users\Lukas\Downloads\FRST.txt 2014-09-10 17:46 - 2014-09-02 20:22 - 00000000 ____D () C:\FRST 2014-09-10 17:45 - 2014-09-10 17:45 - 00000000 ____D () C:\Users\Lukas\Downloads\FRST-OlderVersion 2014-09-10 17:45 - 2014-09-02 20:21 - 02105856 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64.exe 2014-09-10 17:43 - 2014-07-28 18:47 - 00000000 ____D () C:\Users\Lukas\Desktop\Alte Firefox-Daten 2014-09-10 17:37 - 2014-09-10 17:37 - 00001167 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-09-10 17:37 - 2014-09-10 17:37 - 00001155 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-09-10 17:37 - 2014-09-10 17:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-09-10 17:37 - 2011-10-15 14:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-10 17:36 - 2014-09-07 14:45 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Free Download Manager 2014-09-10 17:36 - 2011-09-16 00:41 - 00000177 ____H () C:\dvmexp.idx 2014-09-10 17:33 - 2009-07-14 06:45 - 00024656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-10 17:33 - 2009-07-14 06:45 - 00024656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-10 17:30 - 2014-09-10 17:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-09-10 17:30 - 2011-05-18 19:45 - 00001848 _____ () C:\Users\Public\Desktop\McAfee Internet Security Suite.lnk 2014-09-10 17:28 - 2012-05-21 21:29 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-09-10 17:28 - 2012-05-21 21:29 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-09-10 17:25 - 2013-08-11 15:58 - 00000000 ___RD () C:\Users\Lukas\Dropbox 2014-09-10 17:25 - 2013-08-11 15:55 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Dropbox 2014-09-10 17:25 - 2012-05-19 09:38 - 00000436 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-09-10 17:24 - 2014-09-04 21:13 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-10 17:23 - 2010-11-21 05:47 - 00220420 _____ () C:\Windows\PFRO.log 2014-09-10 17:23 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-10 17:23 - 2009-07-14 06:51 - 00157125 _____ () C:\Windows\setupact.log 2014-09-10 17:21 - 2011-06-02 09:01 - 01212617 _____ () C:\Windows\WindowsUpdate.log 2014-09-10 17:16 - 2014-09-10 17:16 - 00001272 _____ () C:\Users\Lukas\Desktop\Revo Uninstaller.lnk 2014-09-10 17:16 - 2014-09-10 17:16 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-09-10 17:12 - 2013-10-12 19:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-10 17:05 - 2013-10-12 19:26 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-09-10 07:59 - 2013-10-12 19:26 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-09-10 07:59 - 2011-10-16 20:32 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-09-09 17:30 - 2014-08-14 13:50 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Franz aktuell 2014-09-09 17:29 - 2013-09-03 17:43 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2013-14 2014-09-09 17:25 - 2014-08-06 14:08 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Spanisch aktuell 2014-09-08 23:33 - 2014-09-08 23:33 - 00111282 _____ () C:\Users\Gast\Desktop\Podcast.pptx 2014-09-08 19:34 - 2014-09-08 19:34 - 00051980 _____ () C:\Users\Lukas\Desktop\Addition.txt 2014-09-08 19:31 - 2014-09-08 19:31 - 00016579 _____ () C:\Users\Lukas\Desktop\FRST.txt 2014-09-07 22:12 - 2014-09-07 22:12 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-09-07 21:24 - 2014-09-07 21:24 - 02347384 _____ (ESET) C:\Users\Lukas\Downloads\esetsmartinstaller_deu(1).exe 2014-09-07 14:44 - 2014-09-07 10:13 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup 2014-09-07 10:18 - 2014-09-07 10:18 - 02347384 _____ (ESET) C:\Users\Lukas\Downloads\esetsmartinstaller_deu.exe 2014-09-07 10:14 - 2014-09-07 10:14 - 00262008 _____ (Software Installer ) C:\Users\Lukas\Downloads\Setup(1).exe 2014-09-07 10:14 - 2014-09-07 10:14 - 00004026 _____ () C:\Windows\System32\Tasks\LaunchSignup 2014-09-07 10:14 - 2014-09-07 10:14 - 00001977 _____ () C:\Users\Lukas\Desktop\Sync Folder.lnk 2014-09-07 10:14 - 2014-09-07 10:14 - 00001095 _____ () C:\Users\Lukas\Desktop\MyPC Backup.lnk 2014-09-07 10:14 - 2014-09-07 10:14 - 00001075 _____ () C:\Users\Lukas\Desktop\Free Download Manager.lnk 2014-09-07 10:14 - 2014-09-07 10:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager 2014-09-07 10:14 - 2014-09-07 10:14 - 00000000 ____D () C:\Program Files (x86)\Free Download Manager 2014-09-07 10:14 - 2014-09-07 10:13 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 2014-09-07 10:13 - 2014-09-07 10:11 - 00000000 ____D () C:\Program Files (x86)\Web Protect 2014-09-07 10:12 - 2014-09-07 10:10 - 00000000 ____D () C:\Program Files (x86)\RocketTab 2014-09-07 10:10 - 2014-09-07 10:10 - 00004140 _____ () C:\Windows\System32\Tasks\RocketTab Update Task 2014-09-07 10:10 - 2014-09-07 10:10 - 00003354 _____ () C:\Windows\System32\Tasks\RocketTab 2014-09-07 10:09 - 2011-06-02 18:52 - 02141902 _____ () C:\Windows\system32\perfh007.dat 2014-09-07 10:09 - 2011-06-02 18:52 - 00613904 _____ () C:\Windows\system32\perfc007.dat 2014-09-07 10:09 - 2009-07-14 07:13 - 00006264 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-07 10:08 - 2014-09-07 10:07 - 00262008 _____ (Software Installer ) C:\Users\Lukas\Downloads\Setup.exe 2014-09-04 23:23 - 2014-09-04 23:23 - 00040959 _____ () C:\Users\Lukas\Desktop\Additionneu.txt 2014-09-04 23:22 - 2014-09-02 20:26 - 00040959 _____ () C:\Users\Lukas\Downloads\Addition.txt 2014-09-04 22:58 - 2014-09-04 22:58 - 01016261 _____ (Thisisu) C:\Users\Lukas\Downloads\JRT.exe 2014-09-04 22:58 - 2014-09-04 22:58 - 00000000 ____D () C:\Windows\ERUNT 2014-09-04 22:50 - 2014-09-04 22:50 - 00002469 _____ () C:\Users\Lukas\Desktop\AdwCleaner[S0].zip 2014-09-04 22:47 - 2014-09-04 22:47 - 00010550 _____ () C:\Users\Lukas\Desktop\protection-log-2014-09-04.zip 2014-09-04 22:45 - 2014-09-04 22:45 - 01110476 _____ () C:\Users\Lukas\Downloads\7z920.exe 2014-09-04 22:45 - 2014-09-04 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2014-09-04 22:45 - 2014-09-04 22:45 - 00000000 ____D () C:\Program Files (x86)\7-Zip 2014-09-04 22:33 - 2014-09-04 22:33 - 00010270 _____ () C:\Users\Lukas\Documents\AdwCleaner[S0].txt 2014-09-04 22:29 - 2014-09-04 22:23 - 00000000 ____D () C:\AdwCleaner 2014-09-04 22:22 - 2014-09-04 22:22 - 01370483 _____ () C:\Users\Lukas\Downloads\adwcleaner_3.309.exe 2014-09-04 21:12 - 2014-09-04 21:12 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-09-04 21:12 - 2014-09-04 21:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-04 21:12 - 2014-09-04 21:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-04 21:12 - 2012-05-03 22:25 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Malwarebytes 2014-09-04 21:12 - 2012-05-03 22:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-09-04 21:10 - 2014-09-04 21:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lukas\Downloads\mbam-setup-2.0.2.1012.exe 2014-09-03 22:55 - 2014-09-03 22:55 - 00032500 _____ () C:\ComboFix.txt 2014-09-03 22:55 - 2014-09-03 21:54 - 00000000 ____D () C:\Qoobox 2014-09-03 22:49 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-09-03 22:14 - 2011-09-16 00:31 - 00000000 ___HD () C:\dvmexp 2014-09-03 22:14 - 2011-05-18 20:24 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-09-03 22:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-09-02 21:55 - 2014-09-02 21:55 - 00487483 _____ () C:\monitor.exe 2014-09-02 21:55 - 2014-09-02 21:55 - 00034244 _____ () C:\monitorsvc.exe 2014-09-02 20:57 - 2013-08-11 15:56 - 00002809 _____ () C:\Windows\wininit.ini 2014-09-02 20:43 - 2014-09-02 20:40 - 00000234 _____ () C:\Users\Lukas\Downloads\Search.txt 2014-09-01 20:28 - 2014-09-07 10:12 - 00350768 _____ (MyOSCompany) C:\Windows\system32\MyOSProtect64.dll 2014-09-01 20:28 - 2014-09-07 10:12 - 00304776 _____ (MyOSCompany) C:\Windows\SysWOW64\MyOSProtect.dll 2014-09-01 00:06 - 2011-09-16 13:15 - 00000432 _____ () C:\Windows\BRWMARK.INI 2014-08-30 18:42 - 2014-08-18 19:47 - 00000001 ____R () C:\Users\Lukas\serverport 2014-08-30 18:36 - 2011-09-15 13:18 - 00000000 ____D () C:\Users\Lukas 2014-08-28 19:38 - 2011-11-28 21:17 - 00000000 ____D () C:\Program Files\Common Files\McAfee 2014-08-28 19:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-08-25 22:38 - 2014-07-28 17:45 - 00000000 ____D () C:\Users\Gast\Desktop\Franzi Mat Examen 2014-08-25 21:45 - 2014-08-18 21:25 - 00000000 ____D () C:\Users\Gast\Desktop\Caro Koll.mat 2014-08-24 23:13 - 2014-08-24 23:11 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2014-2015 2014-08-24 15:22 - 2014-08-06 17:40 - 00000000 ____D () C:\Users\Gast\Desktop\Statement Tanja 2014-08-20 21:59 - 2014-05-23 22:48 - 00000000 ____D () C:\Users\Gast\Desktop\Kolloquium OBAS 2014-08-20 20:05 - 2011-09-16 15:14 - 00000000 ____D () C:\Users\Lukas\Documents\Meine Projekte 2014-08-18 19:51 - 2013-08-11 15:58 - 00001021 _____ () C:\Users\Lukas\Desktop\Dropbox.lnk 2014-08-18 19:51 - 2013-08-11 15:56 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-08-18 19:47 - 2014-08-18 19:47 - 00000000 ____D () C:\Users\Lukas\.jivex 2014-08-14 12:48 - 2014-08-12 20:09 - 00000000 ____D () C:\Users\Gast\Desktop\UB's - Klausuren etc. anderer 2014-08-14 10:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-08-12 22:33 - 2011-10-07 00:46 - 11686864 _____ () C:\Users\Lukas\Documents\Historie von Schumacher, Lukas.logbook3 2014-08-12 20:13 - 2013-08-12 09:34 - 00000000 ____D () C:\Users\Gast\Desktop\Hochzeit 2013 2014-08-12 20:12 - 2014-08-12 20:12 - 00000000 ____D () C:\Users\Gast\Desktop\Tischkalender 2014-08-12 20:11 - 2013-08-14 23:20 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2012-2013 2014-08-12 20:08 - 2013-01-06 12:00 - 00000000 ____D () C:\Users\Gast\Desktop\Sonstiges 2014-08-12 20:08 - 2012-11-12 21:30 - 00000000 ____D () C:\Users\Gast\Desktop\OBAS 2014-08-12 19:52 - 2014-07-28 19:05 - 00000000 ____D () C:\Windows\pss 2014-08-12 19:52 - 2014-04-30 21:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-12 19:52 - 2012-10-20 10:23 - 00000000 ____D () C:\Users\Gast 2014-08-12 19:52 - 2011-10-16 20:32 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-08-12 19:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\L2Schemas Some content of TEMP: ==================== C:\Users\Lukas\AppData\Local\Temp\CloudBackup7738.exe C:\Users\Lukas\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpen7qsz.dll C:\Users\Lukas\AppData\Local\Temp\Quarantine.exe C:\Users\Lukas\AppData\Local\Temp\SpOrder.dll C:\Users\Lukas\AppData\Local\Temp\System.Data.SQLite.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-09-08 02:23 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-09-2014 Ran by Lukas at 2014-09-10 17:49:42 Running from C:\Users\Lukas\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Acer Backup Manager (HKLM-x32\...\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.85 - NTI Corporation) Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1510 - CyberLink Corp.) Acer Crystal Eye Webcam (x32 Version: 1.0.1510 - CyberLink Corp.) Hidden Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3006 - Acer Incorporated) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Acer Incorporated) Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3004 - Acer Incorporated) Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0401.2011 - Acer Incorporated) Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3005 - Acer Incorporated) Acer VCM (HKLM-x32\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3004 - Acer Incorporated) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.) Adobe AIR (x32 Version: 1.5.0.7220 - Adobe Systems Inc.) Hidden Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader X (10.1.3) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.3 - Adobe Systems Incorporated) Adobe Reader XI (11.0.08) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) Backup Manager V3 (x32 Version: 3.0.0.85 - NTI Corporation) Hidden Broadcom Gigabit Integrated Controller (HKLM\...\{394E442A-637D-43EF-B402-4CFD88263CF0}) (Version: 14.6.1.5 - Broadcom Corporation) BrowserSafeguard with RocketTab (HKLM-x32\...\RocketTab) (Version: - BrowserSafeguard with RocketTab) <==== ATTENTION CollageIt 1.9.3 (HKLM-x32\...\{D9757258-30B2-496E-86F2-84920C5858E1}_is1) (Version: 1.9.3 - PearlMountain Technology Co., Ltd) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.6.0 - Conexant) Corel WinDVD (HKLM-x32\...\{5C1F18D2-F6B7-4242-B803-B5A78648185D}) (Version: 10.0.5.846 - Corel Inc.) Custom (Version: 01.00.00.000 - Wave Systems Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden dm-Fotowelt (HKLM-x32\...\dm-Fotowelt) (Version: 5.0.1 - CEWE COLOR AG u Co. OHG) Doppelkopf XXL (HKCU\...\Doppelkopf XXL) (Version: - ) Dropbox (HKCU\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.) eBay Worldwide (HKLM-x32\...\{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}) (Version: 2.1.0901 - OEM) EgisTec ES603 WDM Driver (HKLM-x32\...\InstallShield_{AE4167B0-F589-4D2A-BF05-E181D543C49F}) (Version: 3.0.16.0 - Egis Technology Inc.) EMBASSY Security Center (Version: 04.03.00.081 - Wave Systems Corp.) Hidden Embassy Trust Suite - Acer Edition (Version: 01.02.01.000 - Wave Systems Corp) Hidden ES603 WDM Driver (x32 Version: 3.0.16.0 - Egis Technology Inc.) Hidden ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Free Download Manager 3.9.4 (HKLM-x32\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Garmin ANT Agent (HKLM\...\{4E21D7C1-80CA-48A0-9983-9F60EEA70B50}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Garmin Communicator Plugin (HKLM-x32\...\{8ED02445-D491-414C-A56D-2ED6BBB7239A}) (Version: 3.0.1 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries) Garmin WebUpdater (HKLM-x32\...\{00FE2935-FB56-4410-AB5F-D6E70C1771D2}) (Version: 2.5.6 - Garmin Ltd or its subsidiaries) Garmin WebUpdater (HKLM-x32\...\{B39177F9-269D-4A9B-82F2-7A48589CCCEF}) (Version: 2.5.2 - Garmin Ltd or its subsidiaries) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.103 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3006 - Acer Incorporated) Install Absolute Data Protect (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 1.0.0.39 - Absolute Software) InstantView (HKLM-x32\...\InstallShield_{9C92176C-CAA2-481D-BD9C-9DED2A36C290}) (Version: 3.0.12.0 - Splashtop Inc.) InstantView (x32 Version: 3.0.12.0 - Splashtop Inc.) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2345 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan) Java(TM) 7 Update 4 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417004FF}) (Version: 7.0.40 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Konz 2013 (HKLM-x32\...\InstallShield_{76651FD7-2B71-4B61-9F3A-E82F52F08D92}) (Version: 1.00.0000 - USM) Konz 2013 (x32 Version: 1.00.0000 - USM) Hidden Launch Manager (HKLM-x32\...\LManager) (Version: 6.0.4 - Acer Inc.) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) McAfee Internet Security Suite (HKLM-x32\...\MSC) (Version: 12.8.988 - McAfee, Inc.) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 32.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0 (x86 de)) (Version: 32.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 32.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyPC Backup (HKLM\...\MyPC Backup) (Version: - JDi Backup Ltd) <==== ATTENTION newsXpresso (HKLM-x32\...\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.) newsXpresso (x32 Version: 1.0.0.40 - esobi Inc.) Hidden Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8942 - NTI Corporation) NTI Media Maker 9 (x32 Version: 9.0.2.8942 - NTI Corporation) Hidden NTRU TCG Software Stack (Version: 2.1.34 - Security Innovation) Hidden Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ProShield (HKLM-x32\...\InstallShield_{08CCD7B4-9EED-4926-805D-C4FFF869989A}) (Version: 1.0.44.0 - Egis Technology Inc.) ProShield (Version: 1.0.44.0 - Egis Technology Inc.) Hidden ProShield TPM (Version: 01.01.00.012 - Wave Systems Corp) Hidden Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7600.69 - Realtek Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.30.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.30.0 - Renesas Electronics Corporation) Hidden Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SportTracks 3.1 (HKLM-x32\...\{99895EF0-B290-4B21-B1FE-FB00E1B5D195}) (Version: 3.1.4871 - Zone Five Software) Steuer 2012 (HKLM-x32\...\{01159E8A-44F7-4885-A7F9-872CE4D74063}) (Version: 20.00.8137 - Buhl Data Service GmbH) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1150 - SUPERAntiSpyware.com) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.14.0 - Synaptics Incorporated) t@x 2012 (HKLM-x32\...\{0E806605-5B82-4A4F-BC31-AA4FADA03C42}) (Version: 19.00.7303 - Buhl Data Service GmbH) t@x 2014 (HKLM-x32\...\{2547CF96-DBB7-4EDD-9327-0EFDD0D1FA8A}) (Version: 21.00.8480 - Buhl Data Service GmbH) TrainingPeaks Device Agent (HKLM-x32\...\{8C477370-143C-4D9D-BD33-289D1C1A0870}) (Version: 3.0.85 - TrainingPeaks) TuneUp Utilities 2012 (HKLM-x32\...\TuneUp Utilities 2012) (Version: 12.0.3500.13 - TuneUp Software) TuneUp Utilities 2012 (x32 Version: 12.0.3500.13 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3500.13 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) Wave Infrastructure Installer (Version: 07.67.00.0005 - Wave Systems Corp) Hidden Wave Support Software Installer (Version: 05.13.00.021 - Wave Systems Corp) Hidden Web Protect for Windows (HKLM-x32\...\wp-adinject-adk) (Version: 10.0.0 - Web Protect) <==== ATTENTION Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3102 - Acer Incorporated) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7300 - Broadcom Corporation) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin) Windows Installer Clean Up (HKLM-x32\...\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}) (Version: 3.00.00.0000 - Microsoft Corporation) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows-Treiberpaket - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2) (HKLM\...\24DA573F901348FFDFF7717497830D45BE0C362E) (Version: 07/07/2009 1.12.2 - Dynastream Innovations) Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}\InprocServer32 -> C:\PROGRA~2\APPGRA~1\APPGRA~2.DLL No File CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}\InprocServer32 -> C:\PROGRA~2\APPGRA~1\APPGRA~2.DLL No File CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ==================== Restore Points ========================= 01-09-2014 20:57:46 Windows Update 03-09-2014 19:56:58 ComboFix created restore point 03-09-2014 19:57:47 ComboFix created restore point 03-09-2014 19:59:52 ComboFix created restore point 03-09-2014 20:08:14 Wiederherstellungsvorgang 03-09-2014 21:01:04 Windows Update 05-09-2014 17:54:28 Windows Update 07-09-2014 17:00:49 Windows-Sicherung 08-09-2014 01:02:10 Windows Update 08-09-2014 05:16:48 Windows Update 08-09-2014 22:52:07 Windows Update 10-09-2014 15:18:26 Revo Uninstaller's restore point - Mozilla Firefox 32.0 (x86 de) ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2012-05-19 09:32 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {022A01D8-D879-4C1A-A4B2-AFF10FAF06CF} - System32\Tasks\{FF17CDB8-8C5B-4A26-848E-0F36130C8DA8} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.116/en/abandoninstall?page=tsMain Task: {06A00C55-465C-42CE-87FA-2024B1E69F15} - System32\Tasks\{21D2A9EE-A847-4670-9FE7-6711B8FA9C6A} => Firefox.exe Task: {36158F5A-2FA7-46CA-99CB-9629EF26CC90} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10] (Adobe Systems Incorporated) Task: {40961FA9-90ED-499A-B7DA-F83FA311B538} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2012-04-05] (TuneUp Software) Task: {803A023E-3F43-43AA-873F-71C6A1EB98E4} - System32\Tasks\{8CB05960-CF37-4A51-B3F3-8EE6370BE276} => Firefox.exe hxxp://ui.skype.com/ui/0/5.8.0.158/en/abandoninstall?page=tsMain Task: {8A9C8ADE-EF09-4725-BA9C-9596D635B3D5} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {BC7462CC-E59A-4A52-9FDD-C2328FFD993B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21] (Google Inc.) Task: {C1073839-8466-4FD8-B9D9-3BEA585C2491} - System32\Tasks\RocketTab => C:\Windows\system32\cmd.exe [2010-11-21] (Microsoft Corporation) Task: {C8EE1FFD-E848-4104-BE45-9274278136D6} - System32\Tasks\RocketTab Update Task => C:\Program Files (x86)\RocketTab\uninstall.exe Task: {CE5B9857-B030-4D76-859E-F42AC759AA5F} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe [2014-09-03] (MyPC Backup) <==== ATTENTION Task: {CEB91A61-C512-446C-88FA-2178D898A876} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe Task: {EC303973-B23D-4645-8CFF-28679A8EF37C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-03-31 19:58 - 2011-03-31 19:58 - 01407536 _____ () C:\Program Files\Acer ProShield\LIBEAY32.dll 2010-07-13 14:02 - 2010-07-13 14:02 - 01629696 _____ () C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe 2010-12-10 15:53 - 2010-12-10 15:53 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2011-06-02 18:38 - 2011-03-27 01:29 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-09-02 21:55 - 2014-09-02 21:55 - 00487483 _____ () C:\monitor.exe 2014-06-23 20:39 - 2013-10-30 17:45 - 00587856 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe 2014-09-03 19:39 - 2014-09-03 19:39 - 00012288 _____ () C:\Program Files (x86)\MyPC Backup\GetText.dll 2014-09-03 19:34 - 2014-09-03 19:34 - 01102336 _____ () C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll 2014-09-07 10:14 - 2014-04-29 12:43 - 03553280 _____ () C:\Program Files (x86)\Free Download Manager\fdmbtsupp.dll 2011-02-15 20:37 - 2011-02-15 20:37 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll 2011-02-15 20:36 - 2011-02-15 20:36 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll 2011-02-15 20:37 - 2011-02-15 20:37 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 09572944 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wgui14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00034896 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsdcom48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00308816 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rscorewinapi48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00321616 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsguiwinapi48.dll 2014-06-23 20:36 - 2013-10-30 17:46 - 03674192 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wcore14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00136272 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsodbc48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 02467408 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wfvie14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01855568 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wsteu14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01904208 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wreli14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 04277840 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wauff14.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 01043456 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-core.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 00094720 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-shared.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 00250368 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-contribs-lib.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01396816 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wmain14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 05019728 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae114.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01666128 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae214.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01786448 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae314.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01624144 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae414.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01125456 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\whau114.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01316944 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\whau214.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01278544 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wwerb14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 06818384 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wkont14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01266768 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wimp14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01322064 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wfabu14.dll 2014-09-10 17:25 - 2014-09-10 17:25 - 00043008 _____ () c:\users\lukas\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpen7qsz.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Lukas\AppData\Roaming\Dropbox\bin\libcef.dll 2014-09-10 17:37 - 2014-08-26 10:14 - 03715184 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-09-07 10:14 - 2014-04-22 21:52 - 00106496 _____ () C:\Program Files (x86)\Free Download Manager\fdmumsp.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Lukas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: iLivid => "C:\Users\Lukas\AppData\Local\iLivid\iLivid.exe" -autorun MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Faulty Device Manager Devices ============= Name: Microsoft-Adapter für Miniports virtueller WiFis Description: Microsoft-Adapter für Miniports virtueller WiFis Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: vwifimp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (09/10/2014 05:45:14 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/10/2014 05:45:12 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/10/2014 05:45:11 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/10/2014 05:24:05 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/10/2014 05:09:32 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/10/2014 05:05:36 PM) (Source: MsiInstaller) (EventID: 11402) (User: NT-AUTORITÄT) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1402.Could not open key: UNKNOWN\Components\7E756C51681BDA34F86C2167896E312E\67D6ECF5CD5FBA732B8B22BAC8DE1B4D. System error 5. Verify that you have sufficient access to that key, or contact your support personnel. Error: (09/10/2014 05:05:08 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x81000101). Error: (09/09/2014 10:23:48 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/09/2014 00:52:51 AM) (Source: MsiInstaller) (EventID: 11402) (User: NT-AUTORITÄT) Description: Product: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 -- Error 1402.Could not open key: UNKNOWN\Components\7E756C51681BDA34F86C2167896E312E\67D6ECF5CD5FBA732B8B22BAC8DE1B4D. System error 5. Verify that you have sufficient access to that key, or contact your support personnel. Error: (09/08/2014 07:21:02 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (09/10/2014 05:27:37 PM) (Source: WMPNetworkSvc) (EventID: 14349) (User: ) Description: 0x800700b7 Error: (09/10/2014 05:27:37 PM) (Source: WMPNetworkSvc) (EventID: 14353) (User: ) Description: 00x800700b7hxxp://+:10243/WMPNSSv4/2811996591/ Error: (09/10/2014 05:27:37 PM) (Source: WMPNetworkSvc) (EventID: 14349) (User: ) Description: 0x800700b7 Error: (09/10/2014 05:27:37 PM) (Source: WMPNetworkSvc) (EventID: 14353) (User: ) Description: 00x800700b7hxxp://+:10243/WMPNSSv4/2811996591/ Error: (09/10/2014 05:23:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Protect Monitor" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (09/10/2014 05:23:53 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Protect Monitor erreicht. Error: (09/10/2014 05:23:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Computer Backup (MyPC Backup)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (09/10/2014 05:23:52 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Computer Backup (MyPC Backup) erreicht. Error: (09/10/2014 05:23:09 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT-AUTORITÄT) Description: 0x8000002a36\SystemRoot\System32\Config\SOFTWARE Error: (09/10/2014 05:11:46 PM) (Source: WMPNetworkSvc) (EventID: 14349) (User: ) Description: 0x800700b7 Microsoft Office Sessions: ========================= Error: (05/03/2014 03:25:14 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6695.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 71 seconds with 60 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-09-09 23:13:59.622 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-09 23:13:59.443 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-09 23:13:59.248 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 23:04:41.288 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 23:04:41.129 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 23:04:40.975 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 02:40:45.237 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 02:40:45.034 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 02:40:44.816 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 02:40:44.582 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz Percentage of memory in use: 66% Total physical RAM: 3944.34 MB Available physical RAM: 1313.17 MB Total Pagefile: 7886.86 MB Available Pagefile: 4730.54 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:444.96 GB) (Free:314.19 GB) NTFS Drive d: (tax2014) (CDROM) (Total:0.49 GB) (Free:0 GB) CDFS Drive e: () (Removable) (Total:7.45 GB) (Free:5.3 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4FB426AA) Partition 1: (Not Active) - (Size=12.7 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=453 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 7.5 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ |
11.09.2014, 11:11 | #13 |
/// the machine /// TB-Ausbilder | Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Winsock: Catalog9 01 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 02 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 03 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 04 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 16 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9-x64 01 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 02 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 03 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 04 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 16 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) cmd: netsh winsock reset C:\Windows\SysWOW64\MyOSProtect.dll C:\Windows\system32\MyOSProtect64.dll CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S2 ProtectMonitor; C:\monitorsvc.exe [34244 2014-09-02] () [File not signed] C:\monitorsvc.exe 2014-09-07 10:14 - 2014-09-07 10:14 - 00262008 _____ (Software Installer ) C:\Users\Lukas\Downloads\Setup(1).exe 2014-09-07 10:14 - 2014-09-07 10:14 - 00004026 _____ () C:\Windows\System32\Tasks\LaunchSignup 2014-09-07 10:14 - 2014-09-07 10:14 - 00001977 _____ () C:\Users\Lukas\Desktop\Sync Folder.lnk 2014-09-07 10:14 - 2014-09-07 10:14 - 00001095 _____ () C:\Users\Lukas\Desktop\MyPC Backup.lnk 2014-09-07 10:14 - 2014-09-07 10:14 - 00001075 _____ () C:\Users\Lukas\Desktop\Free Download Manager.lnk 2014-09-07 10:14 - 2014-09-07 10:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager 2014-09-07 10:14 - 2014-09-07 10:14 - 00000000 ____D () C:\Program Files (x86)\Free Download Manager 2014-09-07 10:13 - 2014-09-07 14:44 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup 2014-09-07 10:13 - 2014-09-07 10:14 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 2014-09-07 10:12 - 2014-09-01 20:28 - 00350768 _____ (MyOSCompany) C:\Windows\system32\MyOSProtect64.dll 2014-09-07 10:12 - 2014-09-01 20:28 - 00304776 _____ (MyOSCompany) C:\Windows\SysWOW64\MyOSProtect.dll 2014-09-07 10:11 - 2014-09-07 10:13 - 00000000 ____D () C:\Program Files (x86)\Web Protect 2014-09-07 10:10 - 2014-09-07 10:12 - 00000000 ____D () C:\Program Files (x86)\RocketTab 2014-09-07 10:10 - 2014-09-07 10:10 - 00004140 _____ () C:\Windows\System32\Tasks\RocketTab Update Task 2014-09-07 10:10 - 2014-09-07 10:10 - 00003354 _____ () C:\Windows\System32\Tasks\RocketTab 2014-09-07 10:07 - 2014-09-07 10:08 - 00262008 _____ (Software Installer ) C:\Users\Lukas\Downloads\Setup.exe Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.09.2014, 16:59 | #14 |
| Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlllCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-09-2014 Ran by Lukas at 2014-09-11 17:44:08 Run:1 Running from C:\Users\Lukas\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** Winsock: Catalog9 01 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 02 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 03 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 04 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9 16 C:\Windows\SysWOW64\MyOSProtect.dll [304776] (MyOSCompany) Winsock: Catalog9-x64 01 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 02 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 03 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 04 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) Winsock: Catalog9-x64 16 C:\Windows\system32\MyOSProtect64.dll [350768] (MyOSCompany) cmd: netsh winsock reset C:\Windows\SysWOW64\MyOSProtect.dll C:\Windows\system32\MyOSProtect64.dll CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S2 ProtectMonitor; C:\monitorsvc.exe [34244 2014-09-02] () [File not signed] C:\monitorsvc.exe 2014-09-07 10:14 - 2014-09-07 10:14 - 00262008 _____ (Software Installer ) C:\Users\Lukas\Downloads\Setup(1).exe 2014-09-07 10:14 - 2014-09-07 10:14 - 00004026 _____ () C:\Windows\System32\Tasks\LaunchSignup 2014-09-07 10:14 - 2014-09-07 10:14 - 00001977 _____ () C:\Users\Lukas\Desktop\Sync Folder.lnk 2014-09-07 10:14 - 2014-09-07 10:14 - 00001095 _____ () C:\Users\Lukas\Desktop\MyPC Backup.lnk 2014-09-07 10:14 - 2014-09-07 10:14 - 00001075 _____ () C:\Users\Lukas\Desktop\Free Download Manager.lnk 2014-09-07 10:14 - 2014-09-07 10:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager 2014-09-07 10:14 - 2014-09-07 10:14 - 00000000 ____D () C:\Program Files (x86)\Free Download Manager 2014-09-07 10:13 - 2014-09-07 14:44 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup 2014-09-07 10:13 - 2014-09-07 10:14 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 2014-09-07 10:12 - 2014-09-01 20:28 - 00350768 _____ (MyOSCompany) C:\Windows\system32\MyOSProtect64.dll 2014-09-07 10:12 - 2014-09-01 20:28 - 00304776 _____ (MyOSCompany) C:\Windows\SysWOW64\MyOSProtect.dll 2014-09-07 10:11 - 2014-09-07 10:13 - 00000000 ____D () C:\Program Files (x86)\Web Protect 2014-09-07 10:10 - 2014-09-07 10:12 - 00000000 ____D () C:\Program Files (x86)\RocketTab 2014-09-07 10:10 - 2014-09-07 10:10 - 00004140 _____ () C:\Windows\System32\Tasks\RocketTab Update Task 2014-09-07 10:10 - 2014-09-07 10:10 - 00003354 _____ () C:\Windows\System32\Tasks\RocketTab 2014-09-07 10:07 - 2014-09-07 10:08 - 00262008 _____ (Software Installer ) C:\Users\Lukas\Downloads\Setup.exe ***************** Winsock: Catalog entry 000000000001 => Deleted successfully. Winsock: Catalog entry 000000000002 => Deleted successfully. Winsock: Catalog entry 000000000003 => Deleted successfully. Winsock: Catalog entry 000000000004 => Deleted successfully. Winsock: Catalog entry 000000000016 => Deleted successfully. Winsock: Catalog entry 000000000001 => Deleted successfully. Winsock: Catalog entry 000000000002 => Deleted successfully. Winsock: Catalog entry 000000000003 => Deleted successfully. Winsock: Catalog entry 000000000004 => Deleted successfully. Winsock: Catalog entry 000000000016 => Deleted successfully. ========= netsh winsock reset ========= Die Initialisierungsfunktion InitHelperDll in NSHHTTP.DLL konnte nicht gestartet werden. Fehlercode 10107 Der Winsock-Katalog wurde zur�ckgesetzt. Sie m�ssen den Computer neu starten, um den Vorgang abzuschlie�en. ========= End of CMD: ========= C:\Windows\SysWOW64\MyOSProtect.dll => Moved successfully. C:\Windows\system32\MyOSProtect64.dll => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKCU\SOFTWARE\Policies\Google" => Key deleted successfully. ProtectMonitor => Service deleted successfully. C:\monitorsvc.exe => Moved successfully. C:\Users\Lukas\Downloads\Setup(1).exe => Moved successfully. C:\Windows\System32\Tasks\LaunchSignup => Moved successfully. C:\Users\Lukas\Desktop\Sync Folder.lnk => Moved successfully. C:\Users\Lukas\Desktop\MyPC Backup.lnk => Moved successfully. C:\Users\Lukas\Desktop\Free Download Manager.lnk => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager => Moved successfully. "C:\Program Files (x86)\Free Download Manager" directory move: C:\Program Files (x86)\Free Download Manager\detoured.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\dlall.htm => Moved successfully. C:\Program Files (x86)\Free Download Manager\dlfvideo.htm => Moved successfully. C:\Program Files (x86)\Free Download Manager\dllink.htm => Moved successfully. C:\Program Files (x86)\Free Download Manager\dlpage.htm => Moved successfully. C:\Program Files (x86)\Free Download Manager\dlselected.htm => Moved successfully. C:\Program Files (x86)\Free Download Manager\etasks.exe => Moved successfully. C:\Program Files (x86)\Free Download Manager\fdm.exe => Moved successfully. C:\Program Files (x86)\Free Download Manager\fdm.tlb => Moved successfully. C:\Program Files (x86)\Free Download Manager\fdm.url => Moved successfully. C:\Program Files (x86)\Free Download Manager\fdmbtsupp.dll => Moved successfully. Could not move "C:\Program Files (x86)\Free Download Manager\fdmcs.dat" => Scheduled to move on reboot. C:\Program Files (x86)\Free Download Manager\fdmumsp.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\fdmwi.exe => Moved successfully. C:\Program Files (x86)\Free Download Manager\fdm_01.gif => Moved successfully. C:\Program Files (x86)\Free Download Manager\flvsniff.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\iefdm2.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\iefdmdm.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\license.txt => Moved successfully. C:\Program Files (x86)\Free Download Manager\MediaConverter.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\msdl.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\npfdm.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\player.swf => Moved successfully. C:\Program Files (x86)\Free Download Manager\sigkey.dat => Moved successfully. C:\Program Files (x86)\Free Download Manager\tips.dat => Moved successfully. C:\Program Files (x86)\Free Download Manager\unins000.dat => Moved successfully. C:\Program Files (x86)\Free Download Manager\unins000.exe => Moved successfully. C:\Program Files (x86)\Free Download Manager\Updater.exe => Moved successfully. C:\Program Files (x86)\Free Download Manager\vistafx.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\How to create a skin.url => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\back.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\back_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\checks.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\choosefolder.ico => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\creategroup.ico => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\dldtasks.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\dldtasks_sel.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\dlinfo.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\dropbox.ico => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\filelist.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\filelist_sel.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\go.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\groups.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\groupsmenu.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\groupsmenu_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\login.ico => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\logstat.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\mute.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\scheduler.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\scheduler_sel.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\settime.ico => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\sitelist.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\sitelist_sel.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\skin.ini => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool0.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool0_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool0_small.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool0_small_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_bt.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_bt_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_bt_small.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_bt_small_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_dld.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_dld_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_dld_small.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_dld_small_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_hfe.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_hfe_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_hfe_small.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_hfe_small_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_sch.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_sch_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_sch_small.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_sch_small_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_sites.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_sites_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_sites_small.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_sites_small_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_spider.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_spider_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_spider_small.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tool_spider_small_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tosel.ico => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tounsel.ico => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tray.ico => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tray_down.ico => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tray_err.ico => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\tray_starting.ico => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\vidman.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Skins\old style\vidman_d.bmp => Moved successfully. C:\Program Files (x86)\Free Download Manager\Server\adddownloadres_err.html => Moved successfully. C:\Program Files (x86)\Free Download Manager\Server\adddownloadres_ok.html => Moved successfully. C:\Program Files (x86)\Free Download Manager\Server\compdlds.html => Moved successfully. C:\Program Files (x86)\Free Download Manager\Server\index.html => Moved successfully. C:\Program Files (x86)\Free Download Manager\Plugins\FDM plugins SDK.url => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\alb.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\arb.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\bul.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\cat.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\chs.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\cht.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\cro.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\czk.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\dan.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\dut.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\ell.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\eng.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\far.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\fin.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\fre.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\gal.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\ger.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\heb.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\hun.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\id.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\ita.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\jpn.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\kor.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\lt.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\mac.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\nor.LNG => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\pol.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\ptbr.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\pt_PT.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\rom.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\rus.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\slo.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\spn.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\srb.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\svk.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\swe.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\tha.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\tur.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\ukr.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\uzb.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\val.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Language\vie.lng => Moved successfully. C:\Program Files (x86)\Free Download Manager\Help\Free Download Manager.chm => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\chrome.manifest => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\install.rdf => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\components\.autoreg => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\components\ivmsfdmff.xpt => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\components\ivmsfdmff22.xpt => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\components\ivmsfdmff30.xpt => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\components\vmsfdmff.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\components\vmsfdmff22.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\components\vmsfdmff30.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\chrome\content\fdm_brcache.js => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\chrome\content\fdm_dldObserver.js => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\chrome\content\fdm_ffext.js => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\chrome\content\fdm_ffext.xul => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\chrome\content\fdm_ffextDM.js => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\chrome\content\fdm_ffextDM.xul => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\chrome\content\fdm_ffpxy.js => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\chrome\content\fdm_fmbtn.js => Moved successfully. C:\Program Files (x86)\Free Download Manager\Firefox\extension\chrome\content\fdm_objtabs.css => Moved successfully. C:\Program Files (x86)\Free Download Manager\Chrome\fdm_nativehost.exe => Moved successfully. C:\Program Files (x86)\Free Download Manager\Chrome\manifest.json => Moved successfully. C:\Program Files (x86)\Free Download Manager\Archive\unrar.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\Archive\7-zip\Formats\arj.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\Archive\7-zip\Formats\zip.dll => Moved successfully. C:\Program Files (x86)\Free Download Manager\Archive\7-zip\Codecs\Deflate.dll => Moved successfully. Could not move "C:\Program Files (x86)\Free Download Manager" directory. => Scheduled to move on reboot. "C:\Program Files (x86)\MyPC Backup" directory move: C:\Program Files (x86)\MyPC Backup\aff.conf => Moved successfully. C:\Program Files (x86)\MyPC Backup\AlphaVSS.51.x86.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\AlphaVSS.52.x64.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\AlphaVSS.52.x86.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\AlphaVSS.60.x64.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\AlphaVSS.60.x86.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\AlphaVSS.Common.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\AWSSDK.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\BackupStack.exe => Moved successfully. C:\Program Files (x86)\MyPC Backup\Configuration Updater.exe => Moved successfully. C:\Program Files (x86)\MyPC Backup\Crypto32.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\Crypto64.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\de_DE.mo => Moved successfully. C:\Program Files (x86)\MyPC Backup\diffstack.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\es_ES.mo => Moved successfully. C:\Program Files (x86)\MyPC Backup\fr_FR.mo => Moved successfully. C:\Program Files (x86)\MyPC Backup\GetText.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\it_IT.mo => Moved successfully. C:\Program Files (x86)\MyPC Backup\LinqBridge.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\LogicNP.EZShellExtensions.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\MPCBClient.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\MPCBContextMenu.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\MPCBIconOverlays.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe => Moved successfully. C:\Program Files (x86)\MyPC Backup\mypcbackup.ico => Moved successfully. C:\Program Files (x86)\MyPC Backup\ObjectListView.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\pt_PT.mo => Moved successfully. C:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet20_x64.exe => Moved successfully. C:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet20_x86.exe => Moved successfully. C:\Program Files (x86)\MyPC Backup\RestartExplorer.exe => Moved successfully. C:\Program Files (x86)\MyPC Backup\Service Start.exe => Moved successfully. C:\Program Files (x86)\MyPC Backup\Shared Stack.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe => Moved successfully. C:\Program Files (x86)\MyPC Backup\syncicon.ico => Moved successfully. C:\Program Files (x86)\MyPC Backup\syncing.ico => Moved successfully. C:\Program Files (x86)\MyPC Backup\tick.ico => Moved successfully. C:\Program Files (x86)\MyPC Backup\uninst.exe => Moved successfully. C:\Program Files (x86)\MyPC Backup\UnRegisterExtensions.exe => Moved successfully. C:\Program Files (x86)\MyPC Backup\Updater.exe => Moved successfully. C:\Program Files (x86)\MyPC Backup\x86\System.Data.SQLite.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\APPLICATION.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\AUTH.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\BACKOFF.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\CLIENT.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\GRID_RECOVERY.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\GRID_RECOVERY_INIT.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\LICENCE.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\NETWORK_SHARES.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\REMOTING.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\REQUEST.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\SERVICE.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\SHELL.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\UPDATER.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\UTC_MIGRATION.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\log\WAIT_HANDLES.log => Moved successfully. C:\Program Files (x86)\MyPC Backup\Database\mpcb_backup_conf.db => Moved successfully. C:\Program Files (x86)\MyPC Backup\Database\mpcb_file_cache.db => Moved successfully. C:\Program Files (x86)\MyPC Backup\Database\mpcb_queues.db => Moved successfully. Could not move "C:\Program Files (x86)\MyPC Backup\Database\mpcb_settings.db" => Scheduled to move on reboot. C:\Program Files (x86)\MyPC Backup\Database\mpcb_sig_cache.db => Moved successfully. C:\Program Files (x86)\MyPC Backup\Database\mpcb_version_queue.db => Moved successfully. C:\Program Files (x86)\MyPC Backup\Config\api.ts2 => Moved successfully. Could not move "C:\Program Files (x86)\MyPC Backup" directory. => Scheduled to move on reboot. C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup => Moved successfully. "C:\Windows\system32\MyOSProtect64.dll" => File/Directory not found. "C:\Windows\SysWOW64\MyOSProtect.dll" => File/Directory not found. C:\Program Files (x86)\Web Protect => Moved successfully. C:\Program Files (x86)\RocketTab => Moved successfully. C:\Windows\System32\Tasks\RocketTab Update Task => Moved successfully. C:\Windows\System32\Tasks\RocketTab => Moved successfully. C:\Users\Lukas\Downloads\Setup.exe => Moved successfully. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-09-11 17:47:06)<= C:\Program Files (x86)\Free Download Manager\fdmcs.dat => Is moved successfully. C:\Program Files (x86)\Free Download Manager => Is moved successfully. C:\Program Files (x86)\MyPC Backup\Database\mpcb_settings.db => Is moved successfully. C:\Program Files (x86)\MyPC Backup => Is moved successfully. ==== End of Fixlog ==== FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-09-2014 Ran by Lukas (administrator) on LUKAS-PC on 11-09-2014 17:53:08 Running from C:\Users\Lukas\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Egis Technology Inc. ) C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. ) C:\Program Files\Acer ProShield\x86\EgisService.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\ReminderService.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\DVMExportService.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\aoiosnap.exe (Splashtop Inc.) C:\Program Files (x86)\InstantView\tools\LockKey.exe (GARMIN Corp.) C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Intel Corporation) C:\Windows\System32\igfxext.exe () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe (NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Dropbox, Inc.) C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Egis Technology Inc. ) C:\Program Files\Acer ProShield\EgisTSR.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\wermgr.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [524928 2011-05-07] (Conexant Systems, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2697512 2011-02-18] (Synaptics Incorporated) HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-22] (Acer Incorporated) HKLM\...\Run: [ProShieldTSR] => C:\Program Files\Acer ProShield\EgisTSR.exe [165936 2011-03-31] (Egis Technology Inc. ) HKLM\...\Run: [InstantView Agent] => C:\Program Files (x86)\InstantView\tools\aoiosnap.exe [1127840 2011-04-28] (Splashtop Inc.) HKLM\...\Run: [InstantView LockKey] => C:\Program Files (x86)\InstantView\tools\LockKey.exe [1498472 2011-04-29] (Splashtop Inc.) HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-02-15] (NTI Corporation) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1097296 2011-04-13] (Dritek System Inc.) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoFolderOptions] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [ANT Agent] => C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe [14731776 2013-02-15] (GARMIN Corp.) HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-4073307474-3872349722-3587453100-1000\...\Run: [Free Download Manager] => "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk ShortcutTarget: Acer VCM.lnk -> C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\t@x aktuell.lnk ShortcutTarget: t@x aktuell.lnk -> C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe () Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (No File) Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - DefaultScope {83C5CAA4-EB8D-4BAB-B1FF-671B3E150AF7} URL = https://de.search.yahoo.com/search?fr=mcafee&type=A011DE662&p={SearchTerms} SearchScopes: HKCU - {09598583-814E-4AD3-946D-8332FFB2AB1E} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {83C5CAA4-EB8D-4BAB-B1FF-671B3E150AF7} URL = https://de.search.yahoo.com/search?fr=mcafee&type=A011DE662&p={SearchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: EgisPBIE Sign-in Helper -> {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} -> C:\Program Files\Acer ProShield\x86\EgisPBIE.dll (Egis Technology Inc.) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Free Download Manager -> {CC59E0F9-7E43-44FA-9FAA-8377850BF205} -> C:\Program Files (x86)\Free Download Manager\iefdm2.dll No File BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Lukas\AppData\Roaming\Mozilla\Firefox\Profiles\258k2g9c.default-1410363803435 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll () FF Plugin: @java.com/DTPlugin,version=10.4.0 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.4.0 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{41ecbc0b-34d5-4cd4-935f-253a30e2cb7e}] - C:\Program Files\Acer ProShield\FFExt FF Extension: Online Accounts Extension - C:\Program Files\Acer ProShield\FFExt [2011-06-02] FF HKLM-x32\...\Firefox\Extensions: [{d4da7309-b89a-45ec-8ebb-cfb2ae13618b}] - C:\Program Files\Acer ProShield\FFExt20 FF Extension: Online Accounts Extension - C:\Program Files\Acer ProShield\FFExt20 [2011-06-02] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-11-28] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2011-11-28] FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "hxxp://www.google.com" CHR DefaultSearchKeyword: Default -> 6DCF556202F48477D008C34F47DA94C839F5281AF262EF8E93AD8F6E414D3A54 CHR DefaultSearchProvider: Default -> Ask.com CHR DefaultSearchURL: Default -> hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=887&systemid=406&v=a13251-240&apn_uid=5924321086234305&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.103\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.103\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.103\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.270.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U27) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (Adobe Acrobat) - c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Garmin Communicator Plug-In) - C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll () CHR Profile: C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Free Download Manager Chrome extension) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahmpjcflkgiildlgicmcieglgoilbfdp [2014-09-07] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-10] CHR Extension: (SiteAdvisor) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2012-05-21] CHR Extension: (Google Wallet) - C:\Users\Lukas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-07] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2011-08-12] (SUPERAntiSpyware.com) [File not signed] R2 EgisTec Service; C:\Program Files\Acer ProShield\x86\EgisService.exe [195120 2011-03-31] (Egis Technology Inc. ) R2 EgisTec Ticket Service; C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe [205360 2011-03-31] (Egis Technology Inc. ) R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [603424 2014-06-12] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-07-24] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation) R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation) R2 ReminderService; C:\Program Files (x86)\InstantView\tools\ReminderService.exe [29560 2011-04-29] (Splashtop Inc.) R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated) S3 SecureStorageService; C:\Program Files\Acer ProShield\Secure Storage Manager\SecureStorageService.exe [2128776 2011-01-06] (Wave Systems Corp.) R2 SPMDES; C:\Program Files (x86)\InstantView\tools\DVMExportService.exe [467832 2011-04-29] (Splashtop Inc.) R2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1629696 2010-07-13] () [File not signed] R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2143552 2012-04-05] (TuneUp Software) S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.) R1 DVMIO; C:\Program Files (x86)\InstantView\tools\dvmio_x64.sys [19560 2011-04-28] (DeviceVM, Inc.) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [44480 2011-05-17] (hxxp://libusb-win32.sourceforge.net) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-11] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.) R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [444720 2014-07-24] (McAfee, Inc.) S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96592 2014-07-24] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2012-03-29] (TuneUp Software) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-11 17:53 - 2014-09-11 17:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-09-11 17:41 - 2014-09-11 17:41 - 00002869 _____ () C:\Users\Lukas\Desktop\fixlist.txt 2014-09-10 17:45 - 2014-09-11 17:42 - 00000000 ____D () C:\Users\Lukas\Downloads\FRST-OlderVersion 2014-09-10 17:37 - 2014-09-10 17:37 - 00001167 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-09-10 17:37 - 2014-09-10 17:37 - 00001155 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-09-10 17:37 - 2014-09-10 17:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-09-10 17:16 - 2014-09-10 17:16 - 00001272 _____ () C:\Users\Lukas\Desktop\Revo Uninstaller.lnk 2014-09-10 17:16 - 2014-09-10 17:16 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-09-08 23:33 - 2014-09-08 23:33 - 00111282 _____ () C:\Users\Gast\Desktop\Podcast.pptx 2014-09-08 19:34 - 2014-09-08 19:34 - 00051980 _____ () C:\Users\Lukas\Desktop\Addition.txt 2014-09-08 19:31 - 2014-09-08 19:31 - 00016579 _____ () C:\Users\Lukas\Desktop\FRST.txt 2014-09-07 22:12 - 2014-09-07 22:12 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-09-07 21:24 - 2014-09-07 21:24 - 02347384 _____ (ESET) C:\Users\Lukas\Downloads\esetsmartinstaller_deu(1).exe 2014-09-07 14:45 - 2014-09-10 17:36 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Free Download Manager 2014-09-07 10:18 - 2014-09-07 10:18 - 02347384 _____ (ESET) C:\Users\Lukas\Downloads\esetsmartinstaller_deu.exe 2014-09-04 23:23 - 2014-09-04 23:23 - 00040959 _____ () C:\Users\Lukas\Desktop\Additionneu.txt 2014-09-04 22:58 - 2014-09-04 22:58 - 01016261 _____ (Thisisu) C:\Users\Lukas\Downloads\JRT.exe 2014-09-04 22:58 - 2014-09-04 22:58 - 00000000 ____D () C:\Windows\ERUNT 2014-09-04 22:50 - 2014-09-04 22:50 - 00002469 _____ () C:\Users\Lukas\Desktop\AdwCleaner[S0].zip 2014-09-04 22:47 - 2014-09-04 22:47 - 00010550 _____ () C:\Users\Lukas\Desktop\protection-log-2014-09-04.zip 2014-09-04 22:45 - 2014-09-04 22:45 - 01110476 _____ () C:\Users\Lukas\Downloads\7z920.exe 2014-09-04 22:45 - 2014-09-04 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2014-09-04 22:45 - 2014-09-04 22:45 - 00000000 ____D () C:\Program Files (x86)\7-Zip 2014-09-04 22:33 - 2014-09-04 22:33 - 00010270 _____ () C:\Users\Lukas\Documents\AdwCleaner[S0].txt 2014-09-04 22:23 - 2014-09-04 22:29 - 00000000 ____D () C:\AdwCleaner 2014-09-04 22:22 - 2014-09-04 22:22 - 01370483 _____ () C:\Users\Lukas\Downloads\adwcleaner_3.309.exe 2014-09-04 21:13 - 2014-09-11 17:47 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-04 21:12 - 2014-09-04 21:12 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-09-04 21:12 - 2014-09-04 21:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-04 21:12 - 2014-09-04 21:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-04 21:12 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-09-04 21:12 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-09-04 21:10 - 2014-09-04 21:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lukas\Downloads\mbam-setup-2.0.2.1012.exe 2014-09-03 22:55 - 2014-09-03 22:55 - 00032500 _____ () C:\ComboFix.txt 2014-09-03 21:56 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-09-03 21:56 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-09-03 21:56 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-09-03 21:56 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-09-03 21:54 - 2014-09-03 22:55 - 00000000 ____D () C:\Qoobox 2014-09-02 20:52 - 2014-09-11 17:53 - 00027053 _____ () C:\Users\Lukas\Downloads\FRST.txt 2014-09-02 20:40 - 2014-09-02 20:43 - 00000234 _____ () C:\Users\Lukas\Downloads\Search.txt 2014-09-02 20:26 - 2014-09-10 17:52 - 00048448 _____ () C:\Users\Lukas\Downloads\Addition.txt 2014-09-02 20:22 - 2014-09-11 17:53 - 00000000 ____D () C:\FRST 2014-09-02 20:21 - 2014-09-10 17:45 - 02105856 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64.exe 2014-08-24 23:11 - 2014-08-24 23:13 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2014-2015 2014-08-18 21:25 - 2014-08-25 21:45 - 00000000 ____D () C:\Users\Gast\Desktop\Caro Koll.mat 2014-08-18 19:47 - 2014-08-30 18:42 - 00000001 ____R () C:\Users\Lukas\serverport 2014-08-18 19:47 - 2014-08-18 19:47 - 00000000 ____D () C:\Users\Lukas\.jivex 2014-08-14 13:50 - 2014-09-09 17:30 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Franz aktuell 2014-08-12 22:33 - 2014-05-03 16:49 - 10510963 ____R () C:\Users\Lukas\Documents\Historie von Schumacher, Lukas~backup-140812.logbook3 2014-08-12 20:12 - 2014-08-12 20:12 - 00000000 ____D () C:\Users\Gast\Desktop\Tischkalender 2014-08-12 20:09 - 2014-08-14 12:48 - 00000000 ____D () C:\Users\Gast\Desktop\UB's - Klausuren etc. anderer ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-11 17:54 - 2014-09-02 20:52 - 00027053 _____ () C:\Users\Lukas\Downloads\FRST.txt 2014-09-11 17:53 - 2014-09-11 17:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-09-11 17:53 - 2014-09-02 20:22 - 00000000 ____D () C:\FRST 2014-09-11 17:53 - 2011-05-18 19:45 - 00001848 _____ () C:\Users\Public\Desktop\McAfee Internet Security Suite.lnk 2014-09-11 17:50 - 2013-08-11 15:58 - 00000000 ___RD () C:\Users\Lukas\Dropbox 2014-09-11 17:50 - 2013-08-11 15:55 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Dropbox 2014-09-11 17:47 - 2014-09-04 21:13 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-11 17:47 - 2012-05-21 21:29 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-09-11 17:46 - 2012-05-19 09:38 - 00000436 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-09-11 17:46 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-11 17:46 - 2009-07-14 06:51 - 00157237 _____ () C:\Windows\setupact.log 2014-09-11 17:45 - 2011-09-16 00:41 - 00000012 ____H () C:\dvmexp.idx 2014-09-11 17:45 - 2011-06-02 09:01 - 01390644 _____ () C:\Windows\WindowsUpdate.log 2014-09-11 17:43 - 2009-07-14 06:45 - 00024656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-11 17:43 - 2009-07-14 06:45 - 00024656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-11 17:42 - 2014-09-10 17:45 - 00000000 ____D () C:\Users\Lukas\Downloads\FRST-OlderVersion 2014-09-11 17:41 - 2014-09-11 17:41 - 00002869 _____ () C:\Users\Lukas\Desktop\fixlist.txt 2014-09-10 23:28 - 2012-05-21 21:29 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-09-10 23:12 - 2013-10-12 19:26 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-10 17:52 - 2014-09-02 20:26 - 00048448 _____ () C:\Users\Lukas\Downloads\Addition.txt 2014-09-10 17:45 - 2014-09-02 20:21 - 02105856 _____ (Farbar) C:\Users\Lukas\Downloads\FRST64.exe 2014-09-10 17:43 - 2014-07-28 18:47 - 00000000 ____D () C:\Users\Lukas\Desktop\Alte Firefox-Daten 2014-09-10 17:37 - 2014-09-10 17:37 - 00001167 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-09-10 17:37 - 2014-09-10 17:37 - 00001155 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-09-10 17:37 - 2014-09-10 17:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-09-10 17:37 - 2011-10-15 14:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-10 17:36 - 2014-09-07 14:45 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Free Download Manager 2014-09-10 17:23 - 2010-11-21 05:47 - 00220420 _____ () C:\Windows\PFRO.log 2014-09-10 17:16 - 2014-09-10 17:16 - 00001272 _____ () C:\Users\Lukas\Desktop\Revo Uninstaller.lnk 2014-09-10 17:16 - 2014-09-10 17:16 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-09-10 17:05 - 2013-10-12 19:26 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-09-10 07:59 - 2013-10-12 19:26 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-09-10 07:59 - 2011-10-16 20:32 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-09-09 17:30 - 2014-08-14 13:50 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Franz aktuell 2014-09-09 17:29 - 2013-09-03 17:43 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2013-14 2014-09-09 17:25 - 2014-08-06 14:08 - 00000000 ____D () C:\Users\Gast\Desktop\UPP Spanisch aktuell 2014-09-08 23:33 - 2014-09-08 23:33 - 00111282 _____ () C:\Users\Gast\Desktop\Podcast.pptx 2014-09-08 19:34 - 2014-09-08 19:34 - 00051980 _____ () C:\Users\Lukas\Desktop\Addition.txt 2014-09-08 19:31 - 2014-09-08 19:31 - 00016579 _____ () C:\Users\Lukas\Desktop\FRST.txt 2014-09-07 22:12 - 2014-09-07 22:12 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-09-07 21:24 - 2014-09-07 21:24 - 02347384 _____ (ESET) C:\Users\Lukas\Downloads\esetsmartinstaller_deu(1).exe 2014-09-07 10:18 - 2014-09-07 10:18 - 02347384 _____ (ESET) C:\Users\Lukas\Downloads\esetsmartinstaller_deu.exe 2014-09-07 10:09 - 2011-06-02 18:52 - 02141902 _____ () C:\Windows\system32\perfh007.dat 2014-09-07 10:09 - 2011-06-02 18:52 - 00613904 _____ () C:\Windows\system32\perfc007.dat 2014-09-07 10:09 - 2009-07-14 07:13 - 00006264 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-04 23:23 - 2014-09-04 23:23 - 00040959 _____ () C:\Users\Lukas\Desktop\Additionneu.txt 2014-09-04 22:58 - 2014-09-04 22:58 - 01016261 _____ (Thisisu) C:\Users\Lukas\Downloads\JRT.exe 2014-09-04 22:58 - 2014-09-04 22:58 - 00000000 ____D () C:\Windows\ERUNT 2014-09-04 22:50 - 2014-09-04 22:50 - 00002469 _____ () C:\Users\Lukas\Desktop\AdwCleaner[S0].zip 2014-09-04 22:47 - 2014-09-04 22:47 - 00010550 _____ () C:\Users\Lukas\Desktop\protection-log-2014-09-04.zip 2014-09-04 22:45 - 2014-09-04 22:45 - 01110476 _____ () C:\Users\Lukas\Downloads\7z920.exe 2014-09-04 22:45 - 2014-09-04 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2014-09-04 22:45 - 2014-09-04 22:45 - 00000000 ____D () C:\Program Files (x86)\7-Zip 2014-09-04 22:33 - 2014-09-04 22:33 - 00010270 _____ () C:\Users\Lukas\Documents\AdwCleaner[S0].txt 2014-09-04 22:29 - 2014-09-04 22:23 - 00000000 ____D () C:\AdwCleaner 2014-09-04 22:22 - 2014-09-04 22:22 - 01370483 _____ () C:\Users\Lukas\Downloads\adwcleaner_3.309.exe 2014-09-04 21:12 - 2014-09-04 21:12 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-09-04 21:12 - 2014-09-04 21:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-04 21:12 - 2014-09-04 21:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-04 21:12 - 2012-05-03 22:25 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Malwarebytes 2014-09-04 21:12 - 2012-05-03 22:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-09-04 21:10 - 2014-09-04 21:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lukas\Downloads\mbam-setup-2.0.2.1012.exe 2014-09-03 22:55 - 2014-09-03 22:55 - 00032500 _____ () C:\ComboFix.txt 2014-09-03 22:55 - 2014-09-03 21:54 - 00000000 ____D () C:\Qoobox 2014-09-03 22:49 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-09-03 22:14 - 2011-09-16 00:31 - 00000000 ___HD () C:\dvmexp 2014-09-03 22:14 - 2011-05-18 20:24 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-09-03 22:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-09-02 20:57 - 2013-08-11 15:56 - 00002809 _____ () C:\Windows\wininit.ini 2014-09-02 20:43 - 2014-09-02 20:40 - 00000234 _____ () C:\Users\Lukas\Downloads\Search.txt 2014-09-01 00:06 - 2011-09-16 13:15 - 00000432 _____ () C:\Windows\BRWMARK.INI 2014-08-30 18:42 - 2014-08-18 19:47 - 00000001 ____R () C:\Users\Lukas\serverport 2014-08-30 18:36 - 2011-09-15 13:18 - 00000000 ____D () C:\Users\Lukas 2014-08-28 19:38 - 2011-11-28 21:17 - 00000000 ____D () C:\Program Files\Common Files\McAfee 2014-08-28 19:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-08-25 22:38 - 2014-07-28 17:45 - 00000000 ____D () C:\Users\Gast\Desktop\Franzi Mat Examen 2014-08-25 21:45 - 2014-08-18 21:25 - 00000000 ____D () C:\Users\Gast\Desktop\Caro Koll.mat 2014-08-24 23:13 - 2014-08-24 23:11 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2014-2015 2014-08-24 15:22 - 2014-08-06 17:40 - 00000000 ____D () C:\Users\Gast\Desktop\Statement Tanja 2014-08-20 21:59 - 2014-05-23 22:48 - 00000000 ____D () C:\Users\Gast\Desktop\Kolloquium OBAS 2014-08-20 20:05 - 2011-09-16 15:14 - 00000000 ____D () C:\Users\Lukas\Documents\Meine Projekte 2014-08-18 19:51 - 2013-08-11 15:58 - 00001021 _____ () C:\Users\Lukas\Desktop\Dropbox.lnk 2014-08-18 19:51 - 2013-08-11 15:56 - 00000000 ____D () C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-08-18 19:47 - 2014-08-18 19:47 - 00000000 ____D () C:\Users\Lukas\.jivex 2014-08-14 12:48 - 2014-08-12 20:09 - 00000000 ____D () C:\Users\Gast\Desktop\UB's - Klausuren etc. anderer 2014-08-14 10:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-08-12 22:33 - 2011-10-07 00:46 - 11686864 _____ () C:\Users\Lukas\Documents\Historie von Schumacher, Lukas.logbook3 2014-08-12 20:13 - 2013-08-12 09:34 - 00000000 ____D () C:\Users\Gast\Desktop\Hochzeit 2013 2014-08-12 20:12 - 2014-08-12 20:12 - 00000000 ____D () C:\Users\Gast\Desktop\Tischkalender 2014-08-12 20:11 - 2013-08-14 23:20 - 00000000 ____D () C:\Users\Gast\Desktop\Schuljahr 2012-2013 2014-08-12 20:08 - 2013-01-06 12:00 - 00000000 ____D () C:\Users\Gast\Desktop\Sonstiges 2014-08-12 20:08 - 2012-11-12 21:30 - 00000000 ____D () C:\Users\Gast\Desktop\OBAS 2014-08-12 19:52 - 2014-07-28 19:05 - 00000000 ____D () C:\Windows\pss 2014-08-12 19:52 - 2014-04-30 21:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-12 19:52 - 2012-10-20 10:23 - 00000000 ____D () C:\Users\Gast 2014-08-12 19:52 - 2011-10-16 20:32 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-08-12 19:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\L2Schemas Some content of TEMP: ==================== C:\Users\Lukas\AppData\Local\Temp\CloudBackup7738.exe C:\Users\Lukas\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpyc9ohz.dll C:\Users\Lukas\AppData\Local\Temp\Quarantine.exe C:\Users\Lukas\AppData\Local\Temp\SpOrder.dll C:\Users\Lukas\AppData\Local\Temp\System.Data.SQLite.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-09-08 02:23 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-09-2014 Ran by Lukas at 2014-09-11 17:56:58 Running from C:\Users\Lukas\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Acer Backup Manager (HKLM-x32\...\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.85 - NTI Corporation) Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1510 - CyberLink Corp.) Acer Crystal Eye Webcam (x32 Version: 1.0.1510 - CyberLink Corp.) Hidden Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3006 - Acer Incorporated) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Acer Incorporated) Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3004 - Acer Incorporated) Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0401.2011 - Acer Incorporated) Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3005 - Acer Incorporated) Acer VCM (HKLM-x32\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3004 - Acer Incorporated) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.) Adobe AIR (x32 Version: 1.5.0.7220 - Adobe Systems Inc.) Hidden Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated) Adobe Reader X (10.1.3) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.3 - Adobe Systems Incorporated) Adobe Reader XI (11.0.08) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) Backup Manager V3 (x32 Version: 3.0.0.85 - NTI Corporation) Hidden Broadcom Gigabit Integrated Controller (HKLM\...\{394E442A-637D-43EF-B402-4CFD88263CF0}) (Version: 14.6.1.5 - Broadcom Corporation) BrowserSafeguard with RocketTab (HKLM-x32\...\RocketTab) (Version: - BrowserSafeguard with RocketTab) <==== ATTENTION CollageIt 1.9.3 (HKLM-x32\...\{D9757258-30B2-496E-86F2-84920C5858E1}_is1) (Version: 1.9.3 - PearlMountain Technology Co., Ltd) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.6.0 - Conexant) Corel WinDVD (HKLM-x32\...\{5C1F18D2-F6B7-4242-B803-B5A78648185D}) (Version: 10.0.5.846 - Corel Inc.) Custom (Version: 01.00.00.000 - Wave Systems Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden dm-Fotowelt (HKLM-x32\...\dm-Fotowelt) (Version: 5.0.1 - CEWE COLOR AG u Co. OHG) Doppelkopf XXL (HKCU\...\Doppelkopf XXL) (Version: - ) Dropbox (HKCU\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.) eBay Worldwide (HKLM-x32\...\{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}) (Version: 2.1.0901 - OEM) EgisTec ES603 WDM Driver (HKLM-x32\...\InstallShield_{AE4167B0-F589-4D2A-BF05-E181D543C49F}) (Version: 3.0.16.0 - Egis Technology Inc.) EMBASSY Security Center (Version: 04.03.00.081 - Wave Systems Corp.) Hidden Embassy Trust Suite - Acer Edition (Version: 01.02.01.000 - Wave Systems Corp) Hidden ES603 WDM Driver (x32 Version: 3.0.16.0 - Egis Technology Inc.) Hidden ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Free Download Manager 3.9.4 (HKLM-x32\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Garmin ANT Agent (HKLM\...\{4E21D7C1-80CA-48A0-9983-9F60EEA70B50}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Garmin Communicator Plugin (HKLM-x32\...\{8ED02445-D491-414C-A56D-2ED6BBB7239A}) (Version: 3.0.1 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries) Garmin WebUpdater (HKLM-x32\...\{00FE2935-FB56-4410-AB5F-D6E70C1771D2}) (Version: 2.5.6 - Garmin Ltd or its subsidiaries) Garmin WebUpdater (HKLM-x32\...\{B39177F9-269D-4A9B-82F2-7A48589CCCEF}) (Version: 2.5.2 - Garmin Ltd or its subsidiaries) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.103 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3006 - Acer Incorporated) Install Absolute Data Protect (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 1.0.0.39 - Absolute Software) InstantView (HKLM-x32\...\InstallShield_{9C92176C-CAA2-481D-BD9C-9DED2A36C290}) (Version: 3.0.12.0 - Splashtop Inc.) InstantView (x32 Version: 3.0.12.0 - Splashtop Inc.) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2345 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan) Java(TM) 7 Update 4 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417004FF}) (Version: 7.0.40 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Konz 2013 (HKLM-x32\...\InstallShield_{76651FD7-2B71-4B61-9F3A-E82F52F08D92}) (Version: 1.00.0000 - USM) Konz 2013 (x32 Version: 1.00.0000 - USM) Hidden Launch Manager (HKLM-x32\...\LManager) (Version: 6.0.4 - Acer Inc.) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) McAfee Internet Security Suite (HKLM-x32\...\MSC) (Version: 12.8.988 - McAfee, Inc.) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 32.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0 (x86 de)) (Version: 32.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 32.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyPC Backup (HKLM\...\MyPC Backup) (Version: - JDi Backup Ltd) <==== ATTENTION newsXpresso (HKLM-x32\...\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.) newsXpresso (x32 Version: 1.0.0.40 - esobi Inc.) Hidden Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8942 - NTI Corporation) NTI Media Maker 9 (x32 Version: 9.0.2.8942 - NTI Corporation) Hidden NTRU TCG Software Stack (Version: 2.1.34 - Security Innovation) Hidden Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ProShield (HKLM-x32\...\InstallShield_{08CCD7B4-9EED-4926-805D-C4FFF869989A}) (Version: 1.0.44.0 - Egis Technology Inc.) ProShield (Version: 1.0.44.0 - Egis Technology Inc.) Hidden ProShield TPM (Version: 01.01.00.012 - Wave Systems Corp) Hidden Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7600.69 - Realtek Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.30.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.30.0 - Renesas Electronics Corporation) Hidden Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SportTracks 3.1 (HKLM-x32\...\{99895EF0-B290-4B21-B1FE-FB00E1B5D195}) (Version: 3.1.4871 - Zone Five Software) Steuer 2012 (HKLM-x32\...\{01159E8A-44F7-4885-A7F9-872CE4D74063}) (Version: 20.00.8137 - Buhl Data Service GmbH) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1150 - SUPERAntiSpyware.com) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.14.0 - Synaptics Incorporated) t@x 2012 (HKLM-x32\...\{0E806605-5B82-4A4F-BC31-AA4FADA03C42}) (Version: 19.00.7303 - Buhl Data Service GmbH) t@x 2014 (HKLM-x32\...\{2547CF96-DBB7-4EDD-9327-0EFDD0D1FA8A}) (Version: 21.00.8480 - Buhl Data Service GmbH) TrainingPeaks Device Agent (HKLM-x32\...\{8C477370-143C-4D9D-BD33-289D1C1A0870}) (Version: 3.0.85 - TrainingPeaks) TuneUp Utilities 2012 (HKLM-x32\...\TuneUp Utilities 2012) (Version: 12.0.3500.13 - TuneUp Software) TuneUp Utilities 2012 (x32 Version: 12.0.3500.13 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3500.13 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) Wave Infrastructure Installer (Version: 07.67.00.0005 - Wave Systems Corp) Hidden Wave Support Software Installer (Version: 05.13.00.021 - Wave Systems Corp) Hidden Web Protect for Windows (HKLM-x32\...\wp-adinject-adk) (Version: 10.0.0 - Web Protect) <==== ATTENTION Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3102 - Acer Incorporated) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7300 - Broadcom Corporation) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin) Windows Installer Clean Up (HKLM-x32\...\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}) (Version: 3.00.00.0000 - Microsoft Corporation) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows-Treiberpaket - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2) (HKLM\...\24DA573F901348FFDFF7717497830D45BE0C362E) (Version: 07/07/2009 1.12.2 - Dynastream Innovations) Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}\InprocServer32 -> C:\PROGRA~2\APPGRA~1\APPGRA~2.DLL No File CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}\InprocServer32 -> C:\PROGRA~2\APPGRA~1\APPGRA~2.DLL No File CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4073307474-3872349722-3587453100-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukas\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ==================== Restore Points ========================= 03-09-2014 19:56:58 ComboFix created restore point 03-09-2014 19:57:47 ComboFix created restore point 03-09-2014 19:59:52 ComboFix created restore point 03-09-2014 20:08:14 Wiederherstellungsvorgang 03-09-2014 21:01:04 Windows Update 05-09-2014 17:54:28 Windows Update 07-09-2014 17:00:49 Windows-Sicherung 08-09-2014 01:02:10 Windows Update 08-09-2014 05:16:48 Windows Update 08-09-2014 22:52:07 Windows Update 10-09-2014 15:18:26 Revo Uninstaller's restore point - Mozilla Firefox 32.0 (x86 de) 11-09-2014 15:42:07 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2012-05-19 09:32 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {022A01D8-D879-4C1A-A4B2-AFF10FAF06CF} - System32\Tasks\{FF17CDB8-8C5B-4A26-848E-0F36130C8DA8} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.116/en/abandoninstall?page=tsMain Task: {06A00C55-465C-42CE-87FA-2024B1E69F15} - System32\Tasks\{21D2A9EE-A847-4670-9FE7-6711B8FA9C6A} => Firefox.exe Task: {36158F5A-2FA7-46CA-99CB-9629EF26CC90} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10] (Adobe Systems Incorporated) Task: {40961FA9-90ED-499A-B7DA-F83FA311B538} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2012-04-05] (TuneUp Software) Task: {803A023E-3F43-43AA-873F-71C6A1EB98E4} - System32\Tasks\{8CB05960-CF37-4A51-B3F3-8EE6370BE276} => Firefox.exe hxxp://ui.skype.com/ui/0/5.8.0.158/en/abandoninstall?page=tsMain Task: {8A9C8ADE-EF09-4725-BA9C-9596D635B3D5} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {BC7462CC-E59A-4A52-9FDD-C2328FFD993B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21] (Google Inc.) Task: {C1073839-8466-4FD8-B9D9-3BEA585C2491} - \RocketTab No Task File <==== ATTENTION Task: {C8EE1FFD-E848-4104-BE45-9274278136D6} - \RocketTab Update Task No Task File <==== ATTENTION Task: {CE5B9857-B030-4D76-859E-F42AC759AA5F} - \LaunchSignup No Task File <==== ATTENTION Task: {CEB91A61-C512-446C-88FA-2178D898A876} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe Task: {EC303973-B23D-4645-8CFF-28679A8EF37C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-03-31 19:58 - 2011-03-31 19:58 - 01407536 _____ () C:\Program Files\Acer ProShield\LIBEAY32.dll 2010-07-13 14:02 - 2010-07-13 14:02 - 01629696 _____ () C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe 2010-12-10 15:53 - 2010-12-10 15:53 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2011-06-02 18:38 - 2011-03-27 01:29 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-06-23 20:39 - 2013-10-30 17:45 - 00587856 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe 2011-02-15 20:37 - 2011-02-15 20:37 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll 2011-02-15 20:36 - 2011-02-15 20:36 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll 2011-02-15 20:37 - 2011-02-15 20:37 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 09572944 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wgui14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00034896 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsdcom48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00308816 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rscorewinapi48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00321616 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsguiwinapi48.dll 2014-06-23 20:36 - 2013-10-30 17:46 - 03674192 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wcore14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 00136272 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\rsodbc48.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 02467408 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wfvie14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01855568 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wsteu14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01904208 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wreli14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 04277840 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wauff14.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 01043456 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-core.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 00094720 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-shared.dll 2014-06-23 20:36 - 2013-10-30 17:37 - 00250368 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\clucene-contribs-lib.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01396816 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wmain14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 05019728 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae114.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01666128 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae214.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01786448 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae314.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01624144 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wbae414.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01125456 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\whau114.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01316944 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\whau214.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01278544 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wwerb14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 06818384 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wkont14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01266768 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wimp14.dll 2014-06-23 20:36 - 2013-10-30 17:45 - 01322064 ____N () C:\Program Files (x86)\Buhl finance\tax Steuersoftware 2014\wfabu14.dll 2014-09-11 17:49 - 2014-09-11 17:49 - 00043008 _____ () c:\users\lukas\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpyc9ohz.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Lukas\AppData\Roaming\Dropbox\bin\libcef.dll 2014-09-10 17:37 - 2014-08-26 10:14 - 03715184 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-09-10 07:59 - 2014-09-10 07:59 - 16825520 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Lukas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: iLivid => "C:\Users\Lukas\AppData\Local\iLivid\iLivid.exe" -autorun MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Faulty Device Manager Devices ============= Name: Microsoft-Adapter für Miniports virtueller WiFis Description: Microsoft-Adapter für Miniports virtueller WiFis Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: vwifimp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (09/11/2014 05:52:54 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/11/2014 05:52:53 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/11/2014 05:52:48 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/11/2014 05:47:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: mcshield.exe, Version: 1.1.3.178, Zeitstempel: 0x53d17f6f Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000004e4e4 ID des fehlerhaften Prozesses: 0xba4 Startzeit der fehlerhaften Anwendung: 0xmcshield.exe0 Pfad der fehlerhaften Anwendung: mcshield.exe1 Pfad des fehlerhaften Moduls: mcshield.exe2 Berichtskennung: mcshield.exe3 Error: (09/11/2014 05:47:33 PM) (Source: AVLogEvent) (EventID: 5004) (User: NT-AUTORITÄT) Description: McShield crashed. Error Code:c0000005 Error: (09/11/2014 05:47:31 PM) (Source: AVLogEvent) (EventID: 5004) (User: NT-AUTORITÄT) Description: McShield crashed. Error Code:c0000005 Error: (09/11/2014 05:47:06 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/11/2014 05:41:20 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/11/2014 05:41:20 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (09/11/2014 05:41:12 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Error: (09/11/2014 05:49:07 PM) (Source: WMPNetworkSvc) (EventID: 14349) (User: ) Description: 0x800700b7 Error: (09/11/2014 05:49:07 PM) (Source: WMPNetworkSvc) (EventID: 14353) (User: ) Description: 00x800700b7hxxp://+:10243/WMPNSSv4/2811996591/ Error: (09/11/2014 05:49:07 PM) (Source: WMPNetworkSvc) (EventID: 14349) (User: ) Description: 0x800700b7 Error: (09/11/2014 05:49:07 PM) (Source: WMPNetworkSvc) (EventID: 14353) (User: ) Description: 00x800700b7hxxp://+:10243/WMPNSSv4/2811996591/ Error: (09/11/2014 05:48:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "McAfee Anti-Malware Core" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts. Error: (09/11/2014 05:46:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Computer Backup (MyPC Backup)" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (09/11/2014 05:46:26 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT-AUTORITÄT) Description: 0x8000002a36\SystemRoot\System32\Config\SOFTWARE Error: (09/11/2014 05:45:13 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package (KB2538243) Error: (09/11/2014 05:44:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Installer" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (09/11/2014 05:44:20 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Installer erreicht. Microsoft Office Sessions: ========================= Error: (05/03/2014 03:25:14 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6695.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 71 seconds with 60 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-09-10 23:02:28.846 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-10 23:02:28.556 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-10 23:02:28.261 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-09 23:13:59.622 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-09 23:13:59.443 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-09 23:13:59.248 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 23:04:41.288 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 23:04:41.129 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 23:04:40.975 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-09-08 02:40:45.237 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Web Protect\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz Percentage of memory in use: 66% Total physical RAM: 3944.34 MB Available physical RAM: 1337.43 MB Total Pagefile: 7886.86 MB Available Pagefile: 4804.21 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:444.96 GB) (Free:314.85 GB) NTFS Drive d: (tax2014) (CDROM) (Total:0.49 GB) (Free:0 GB) CDFS Drive e: () (Removable) (Total:7.45 GB) (Free:5.3 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4FB426AA) Partition 1: (Not Active) - (Size=12.7 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=453 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 7.5 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ |
12.09.2014, 10:51 | #15 |
/// the machine /// TB-Ausbilder | Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Startup: C:\Users\Lukas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (No File) S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [X] Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Mc Afee kann Programm nicht entfernen, C:\Program Files (x86)\movies toolbar\Datamngr\x64\apcrt\dr.dlll |
conduit.search, conduit.search entfernen, datamngr, fehlercode 0x0, fehlercode 0x80000003, fehlercode 0xc0000005, immer wieder, msil/adware.ibryte.g, programm, unerwünschtes, unerwünschtes programm, win32/adware.ibryte.bh, win32/adware.loadshop.a, win32/bundled.toolbar.ask, win32/bundled.toolbar.ask.g, win32/conduit.searchprotect.q, win32/ilivid.a, win32/softonicdownloader.f, win32/toolbar.searchsuite, win32/toolbar.searchsuite.m, win32/toolbar.searchsuite.q, win32/wajam.f, win64/toolbar.searchsuite.b, zusammen |