|
Plagegeister aller Art und deren Bekämpfung: Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-SymbolWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
14.10.2014, 10:11 | #16 |
/// the machine /// TB-Ausbilder | Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol ok, dann bleiben noch 200 ESET meckert immer viel an, aber da ist schon einiges dabei was runter muss
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.10.2014, 13:43 | #17 |
| Status / next step? hallo Schrauber
__________________.... ich biin etwas verunsichert. Seit dem Poste # 9 hänge ich etwas in der Luft, der damalige Status war ja, dass ich das Tool ESET deinstallierenund gelöschen musste, die 250 (noch nicht bewerteten) Befunde aber sind m.E. noch unbearbeitet auf dem System -was soll/muss für die abschliessende Bereinigung noch machen? Gruss & Dank für deine Bemühungen sugus666 |
16.10.2014, 18:56 | #18 |
/// the machine /// TB-Ausbilder | Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol Was meinst Du mit in der Luft hängen? Ich hab gesagt Du sollst alles löschen was ESET gefunden hat. Die Sachen die Du sicher kennst kannste natürlich behalten.
__________________Poste bitte mal ein frisches FRST Log, sollten aber durch sein.
__________________ |
17.10.2014, 07:17 | #19 |
| Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol hi Schrauber das muss ein Missverständnis sein... bei welchem Post hast du mir geschrieben wegen der Löschung (in # 9 war die Rde von ESET Programm / Daten / Papierkorb). Sind die Befunde irgendwo in Quarathäne? Mit welchem Tool soll gelöscht werden? Gruss sugus666 Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-10-2014 Ran by Marcel at 2014-10-17 08:12:37 Running from F:\90 Daten Systemordner\Downloads_sys Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Flash Player 15 Plugin (HKLM-x32\...\{AF82C1A9-56DC-4CCD-A36C-CAE56D541DFA}) (Version: 15.0.0.189 - Adobe Systems Incorporated) Adobe Photoshop Album 2.0 Starter Edition (HKLM-x32\...\{11B569C2-4BF6-4ED0-9D17-A4273943CB24}) (Version: 2.00.100 - Adobe Systems, Inc.) Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated) AllShare Framework DMS (HKLM\...\{83232C27-8C3F-44A5-9EB2-BB7161228ADD}) (Version: 1.3.23 - Samsung) Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASUS Wireless Router Device Discovery Utility (HKLM-x32\...\{09CDCA35-23FF-4ED6-AFDA-BBD55235CE4B}) (Version: 1.4.6.5 - ASUS) avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Brother MFL-Pro Suite MFC-9440CN (HKLM-x32\...\{C83FB11D-9EC6-49D7-99A7-DDDB2264883C}) (Version: 1.0.1.0 - Brother Industries, Ltd.) Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.22 - Cliqz.com) Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) CPUID CPU-Z 1.69.2 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.) CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden Dependency Package Update (Version: 1.6.25.00 - Lenovo Inc.) Hidden Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden Dependency Package Update (x32 Version: 1.6.30.00 - Lenovo Group Limited) Hidden DisplayLink Core Software (HKLM\...\{BB07E020-7224-4EC3-864E-2AA0BF42A7DD}) (Version: 7.4.51572.0 - DisplayLink Corp.) Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc) Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.0.1.51 - Lenovo) Energy Manager (x32 Version: 1.0.1.51 - Lenovo) Hidden eTax.zug 2013 jP 1.0.0 (HKLM-x32\...\9994-2633-2807-7220) (Version: 1.0.0 - Information Factory AG) Evernote v. 5.5.3 (HKLM-x32\...\{B1A0F908-1448-11E4-8684-00163E98E7D0}) (Version: 5.5.3.4236 - Evernote Corp.) FileZilla Client 3.9.0.5 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.5 - Tim Kosse) FileZilla Server (HKLM-x32\...\FileZilla Server) (Version: beta 0.9.44 - FileZilla Project) FreeFileSync 6.9 (HKLM-x32\...\FreeFileSync) (Version: 6.9 - Zenju) Freemake Video Converter Version 4.1.4 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.4 - Ellora Assets Corporation) Freemake Video Downloader (HKLM-x32\...\Freemake Video Downloader_is1) (Version: 3.7.0 - Ellora Assets Corporation) FreeMind (HKLM-x32\...\B991B020-2968-11D8-AF23-444553540000_is1) (Version: 1.0.1 - ) ICP Basis 7.00 (HKLM-x32\...\ICP Basis 7.00) (Version: - ) inSSIDer Home (HKLM-x32\...\{9E54E4AE-B67A-4925-8E92-0E1F9817FD73}) (Version: 3.1.2.1 - MetaGeek, LLC) Intel Experience Center - Configuration (x32 Version: 1.9.0.8 - Intel) Hidden Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\FFD10ECE-F715-4a86-9BD8-F6F47DA5DA1C) (Version: 7.1.0.2103 - Intel Corporation) Intel(R) Experience Center Desktop Software (HKLM-x32\...\{85de612b-ee05-476a-87cc-52e5740de420}) (Version: 1.9.0.8 - Intel) Intel(R) Experience Center Driver (Version: 1.9.0.8 - Intel Corporation) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation) Intel(R) PRO/Wireless Driver (Version: 16.05.3000.0599 - Intel Corporation) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3304 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation) Intel(R) Rapid Storage Technology (Version: 12.8.0.1016 - Intel Corporation) Hidden Intel(R) Smart Connect Technology (HKLM\...\{D6FBF816-ACB8-46CC-ACC6-C8BBA85F497D}) (Version: 4.2.40.2418 - Intel Corporation) Intel(R) Update Manager (HKLM-x32\...\{12914061-EB9B-4AE7-AC7E-0B8A607C7DF4}) (Version: 2.3.1338 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{1c7272f2-45cf-469f-b7e9-17c6b212549c}) (Version: 16.5.3 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.) Java 7 Update 67 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417067FF}) (Version: 7.0.670 - Oracle) Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle) Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden join.me (HKCU\...\JoinMe) (Version: 1.17.0.153 - LogMeIn, Inc.) K-Lite Codec Pack 9.3.0 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.3.0 - ) Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.29.00 - Lenovo Group Limited) Lenovo EasyCamera (HKLM-x32\...\Sunplus SPUVCb) (Version: 3.4.5.35 - SunplusIT) Lenovo Motion Control (HKLM-x32\...\InstallShield_{0D740B00-2307-44AC-B91B-F3E67444ECA6}) (Version: 2.0.1.0107 - PointGrab) Lenovo Motion Control (x32 Version: 2.0.1.0107 - PointGrab) Hidden Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 8.0.0.2105 - CyberLink Corp.) Hidden Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.0 - Lenovo) Lenovo Transition (HKLM\...\Lenovo Transition) (Version: 2.0.13.12271 - Lenovo) Lenovo USB Graphics (HKLM\...\{7257526E-B74A-488E-BA2E-56327482B06B}) (Version: 7.4.51587.0 - Lenovo) Lenovo VeriFace (HKLM\...\Lenovo VeriFace) (Version: 5.0.13.5261 - Lenovo) Lenovo Yoga PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.1.9.3 - Lenovo) Lenovo Yoga PhoneCompanion (x32 Version: 1.1.9.3 - Lenovo) Hidden MailStore Home 8.2.0.9316 (HKLM-x32\...\MailStore Home_universal1) (Version: 8.2.0.9316 - MailStore Software GmbH) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0407-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Visio Professional 2003 (HKLM-x32\...\{90510407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Project Standard 2002 (HKLM-x32\...\{903A0407-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2915.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works 6-9 Converter (HKLM-x32\...\{95140000-0137-0407-0000-0000000FF1CE}) (Version: 14.0.6120.5002 - Microsoft Corporation) Mozilla Firefox 32.0.3 (x86 de) (HKLM-x32\...\Mozilla Firefox 32.0.3 (x86 de)) (Version: 32.0.3 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) My Swisscom Assistant (HKLM-x32\...\My Swisscom Assistant) (Version: 1.1.0.71 - Swisscom (Schweiz) AG) NirSoft ShellExView (HKLM-x32\...\NirSoft ShellExView) (Version: - ) Nitro Reader 3 (HKLM\...\{4756C731-B54E-451A-9AF1-86E8AB1BEBBB}) (Version: 3.5.6.5 - Nitro) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.1 - Notepad++ Team) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Private Tax 2013 1.4.0 (HKLM-x32\...\0579-4231-5684-8562) (Version: 1.4.0 - Information Factory AG) Q-Dir (HKLM\...\Q-Dir) (Version: - ) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30164 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7058 - Realtek Semiconductor Corp.) ReminderInstaller (HKLM-x32\...\InstallShield_{48B99BC9-CEB0-485E-96B1-4609BC86D2DE}) (Version: 1.00.0000 - Absolute Software.) ReminderInstaller (x32 Version: 1.00.0000 - Absolute Software.) Hidden Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Samsung Link 2.0.0.1409291832 (HKLM\...\8474-7877-9059-0204) (Version: 2.0.0.1409291832 - Copyright 2013 SAMSUNG) Sandboxie 4.12 (64-bit) (HKLM\...\Sandboxie) (Version: 4.12 - Sandboxie Holdings, LLC) Screenpresso (HKCU\...\Screenpresso) (Version: 1.5.2.0 - Learnpulse) Secunia PSI (3.0.0.9016) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.9016 - Secunia) Snapform Viewer 1.7.36 (HKLM\...\2841-5017-1617-4151) (Version: 1.7.36 - Ringler Informatik AG) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.8.7 - Synaptics Incorporated) ThinkPad USB 3.0 Dock (HKLM-x32\...\{69109A9C-1D00-4A84-9ABF-AAE9CADD20DD}) (Version: 1.07.15 - Lenovo) TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft en-us Dictionary (Version: 16.1.924.1 - Microsoft Corporation) Hidden Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2899475) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{23AE87D8-AB2F-4539-935C-442BC976F469}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.15 - Lenovo) UserGuide (x32 Version: 1.0.0.15 - Lenovo) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) WHS ProStation (HKCU\...\InstallShield_{E56B8E1D-8E90-46DC-AE55-EBA87ED69A5F}) (Version: 2.38.56.10.2 - WH SELFINVEST) WHS ProStation (x32 Version: 2.38.56.10.2 - WH SELFINVEST) Hidden Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation) Windows Driver Package - Lenovo (ACPIVPC) System (02/17/2013 9.52.0.776) (HKLM\...\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo) Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) XAMPP (HKLM-x32\...\xampp) (Version: 1.8.3-4 - Bitnami) Yoga Picks (HKLM-x32\...\{267C8BA0-876B-4589-9F14-EFB84ABCEA7F}) (Version: 1.5.014.0106 - Lenovo) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-3121602427-3534730855-1075997385-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B}\InprocServer32 -> {1FA5F244-9468-D082-1262-D4EE85889A47} No File CustomCLSID: HKU\S-1-5-21-3121602427-3534730855-1075997385-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Marcel\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3121602427-3534730855-1075997385-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Marcel\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3121602427-3534730855-1075997385-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850}\InprocServer32 -> {5FB02946-9468-D082-10B9-C1AE85889A47} No File CustomCLSID: HKU\S-1-5-21-3121602427-3534730855-1075997385-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Marcel\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3121602427-3534730855-1075997385-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Marcel\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 09-10-2014 21:21:58 Revo Uninstaller's restore point - Avira Savings Advisor 13-10-2014 06:41:12 Installed Java 7 Update 67 15-10-2014 09:21:46 Installed Oracle VM VirtualBox 4.3.18 ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {04232B5E-E0AC-4061-BED7-2DB835B4BAE2} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {114B555B-6E44-421B-90EC-509925C4578F} - System32\Tasks\4Team updater => C:\Program Files (x86)\4Team Corporation\4Team-Updater\4Team-Updater.exe Task: {11CF1733-D8D7-4871-9BB3-A8BBE91DE674} - System32\Tasks\MsgUpdateCheck (ed5bac9b-5ca0-4f99-aa46-a881a08ff6f3) => C:\SmartDraw CI\MarkedUp\tray\TrayNotifierNET35.exe [2014-04-30] (MarkedUp Inc) Task: {19676596-235C-492C-9BBD-B736CE6B4742} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] () Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {47DAC2D1-53B1-4FA7-BBF0-C85625213A6A} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-16] (Adobe Systems Incorporated) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {4A43190F-D283-4BB8-BEF5-86B2DB9FC4F4} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: {5177C064-CC6E-4D71-BE7A-B42FA270C361} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] () Task: {52F8F128-3155-435F-B4DD-99F8EC651CC8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2014-09-10] (Microsoft Corporation) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6AB1569F-4369-4546-88C8-735FD098A9AD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {74EAEBD2-C829-4716-8089-1355EFA5D9EB} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {79A937C3-5C94-4168-8180-CE1A5CFF2A6F} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2014-08-18] () Task: {7BA762F4-A324-42D5-8657-FF70FD0439B1} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {945A01A3-31C7-48BE-ADA2-064B92034779} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {AB1B2D4F-AD1B-4388-807F-BA561CDE4FD9} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-03-28] (Lenovo) Task: {C71A6436-7370-460F-864E-09FE1370A395} - System32\Tasks\SDMsgUpdate (TE) => C:\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] () Task: {CD89B46E-816E-4B02-A703-1EF419CC48DE} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {DDA1C19D-4569-46B7-A2D6-43AA1E21C36B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-10-10] (AVAST Software) Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {F97DB1F3-B11D-48E1-B038-8906E0AA1B7E} - System32\Tasks\SDMsgUpdate (Local) => C:\SmartDraw CI\Messages\SDNotify.exe [2012-08-13] () Task: {FFA9A996-FEC2-420E-8B15-7FB5F295BCF6} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-08-29] (Synaptics Incorporated) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-08-02 02:31 - 2013-08-02 02:31 - 00198120 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe 2013-08-02 02:31 - 2013-08-02 02:31 - 00054760 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll 2013-08-02 02:31 - 2013-08-02 02:31 - 00034792 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll 2014-03-28 08:55 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2014-08-30 09:15 - 2014-09-29 18:32 - 00025088 _____ () C:\Program Files\Samsung\Samsung Link\JniSys.dll 2014-08-30 09:15 - 2014-09-29 18:32 - 02633728 _____ () C:\Program Files\Samsung\Samsung Link\scone_proxy.dll 2014-08-30 09:15 - 2014-09-29 18:32 - 02540544 _____ () C:\Program Files\Samsung\Samsung Link\scone_stub.dll 2013-12-21 11:25 - 2013-12-21 11:25 - 00036864 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\JNIInterface.dll 2013-12-21 11:26 - 2013-12-21 11:26 - 00144384 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\ASFAPI.dll 2013-12-21 11:27 - 2013-12-21 11:27 - 00018944 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\MediaDB_Manager.dll 2013-10-22 09:52 - 2013-10-22 09:52 - 00030720 _____ () C:\windows\SYSTEM32\MediaDB64.dll 2013-10-22 09:52 - 2013-10-22 09:52 - 00908800 _____ () C:\windows\SYSTEM32\ContentDirectoryPresenter64.dll 2013-12-21 11:27 - 2013-12-21 11:27 - 00521728 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\DMS_Manager.dll 2013-07-23 19:19 - 2013-07-23 19:19 - 00049152 _____ () C:\windows\SYSTEM32\boost_date_time-vc90-mt-1_47.dll 2013-07-23 19:19 - 2013-07-23 19:19 - 00016896 _____ () C:\windows\SYSTEM32\boost_system-vc90-mt-1_47.dll 2013-07-23 19:19 - 2013-07-23 19:19 - 00058880 _____ () C:\windows\SYSTEM32\boost_thread-vc90-mt-1_47.dll 2013-07-23 19:19 - 2013-07-23 19:19 - 00299520 _____ () C:\windows\SYSTEM32\boost_serialization-vc90-mt-1_47.dll 2014-08-30 09:16 - 2014-08-30 09:16 - 00669696 _____ () C:\Windows\Temp\sqlite-3.7.151-amd64-sqlitejdbc.dll 2014-08-30 09:15 - 2014-09-29 18:32 - 00049664 _____ () C:\Program Files\Samsung\Samsung Link\JniIO.dll 2014-08-30 09:15 - 2014-09-29 18:32 - 00500224 _____ () C:\Program Files\Samsung\Samsung Link\utils\MetaExtractorDLL.dll 2014-04-22 20:23 - 2005-04-22 13:36 - 00143360 ____N () C:\windows\system32\BrSNMP64.dll 2014-03-28 08:55 - 2014-03-28 08:55 - 00068368 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe 2014-03-28 08:55 - 2014-03-28 08:55 - 00669288 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfDataStorageInterface.dll 2014-03-28 08:55 - 2014-03-28 08:55 - 00062224 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll 2014-03-28 08:53 - 2014-01-07 00:14 - 00019440 _____ () C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe 2014-10-10 07:33 - 2014-10-10 07:33 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll 2014-10-15 11:46 - 2014-10-15 11:46 - 02874368 _____ () C:\Program Files\AVAST Software\Avast\defs\14101500\algo.dll 2014-10-16 08:18 - 2014-10-16 08:18 - 02874368 _____ () C:\Program Files\AVAST Software\Avast\defs\14101506\algo.dll 2013-12-11 16:46 - 2013-12-11 16:46 - 01114624 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DMSManager.dll 2013-07-23 19:18 - 2013-07-23 19:18 - 00227840 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_serialization-vc90-mt-1_47.dll 2013-07-23 19:18 - 2013-07-23 19:18 - 00038912 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_date_time-vc90-mt-1_47.dll 2013-07-23 19:18 - 2013-07-23 19:18 - 00012800 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_system-vc90-mt-1_47.dll 2013-07-23 19:18 - 2013-07-23 19:18 - 00046592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_thread-vc90-mt-1_47.dll 2013-10-22 09:48 - 2013-10-22 09:48 - 00707072 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ContentDirectoryPresenter.dll 2013-10-24 16:53 - 2013-10-24 16:53 - 00107008 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DCMCDP.dll 2013-12-11 16:46 - 2013-12-11 16:46 - 00102400 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\FolderCDP.dll 2013-10-24 16:53 - 2013-10-24 16:53 - 00032768 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\Autobackup.dll 2013-04-19 16:38 - 2013-04-19 16:38 - 00055808 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\RosettaAllShare.dll 2013-12-11 16:46 - 2013-12-11 16:46 - 00077312 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\MetadataFramework.dll 2013-02-14 19:42 - 2013-02-14 19:42 - 00520234 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\sqlite3.dll 2013-02-14 19:42 - 2013-02-14 19:42 - 00450560 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\MoodExtractor.dll 2013-02-14 19:42 - 2013-02-14 19:42 - 05717504 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DCMImgExtractor.dll 2013-10-25 19:48 - 2013-10-25 19:48 - 00028672 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AutoChaptering.dll 2013-10-25 19:49 - 2013-10-25 19:49 - 00028160 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AudioExtractor.dll 2013-12-11 16:45 - 2013-12-11 16:45 - 00017920 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoExtractor.dll 2013-10-25 19:53 - 2013-10-25 19:53 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ImageExtractor.dll 2013-10-25 19:48 - 2013-10-25 19:48 - 00013824 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\TextExtractor.dll 2013-02-14 19:42 - 2013-02-14 19:42 - 00147456 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libexpat.dll 2013-10-25 19:48 - 2013-10-25 19:48 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoThumb.dll 2013-10-25 19:48 - 2013-10-25 19:48 - 00064000 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ID3Driver.dll 2013-10-25 19:48 - 2013-10-25 19:48 - 00023040 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\RichInfoDriver.dll 2013-10-25 19:53 - 2013-10-25 19:53 - 00117248 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ThumbnailMaker.dll 2013-12-11 16:45 - 2013-12-11 16:45 - 00134144 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoMetadataDriver.dll 2013-10-25 19:48 - 2013-10-25 19:48 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\SECMetaDriver.dll 2013-10-25 19:48 - 2013-10-25 19:48 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\photoDriver.dll 2013-02-14 19:42 - 2013-02-14 19:42 - 04671488 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avcodec-52.dll 2013-02-14 19:42 - 2013-02-14 19:42 - 00686080 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avformat-52.dll 2013-02-14 19:42 - 2013-02-14 19:42 - 00070656 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avutil-50.dll 2013-02-14 19:42 - 2013-02-14 19:42 - 00152064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\swscale-0.dll 2013-02-14 19:42 - 2013-02-14 19:42 - 00366592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\tag.dll 2013-10-25 19:48 - 2013-10-25 19:48 - 00289792 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libThumbnail.dll 2013-10-25 19:53 - 2013-10-25 19:53 - 01033728 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ImageMagickWrapper.dll 2013-10-25 19:48 - 2013-10-25 19:48 - 00290816 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libKeyFrame.dll 2013-02-14 19:42 - 2013-02-14 19:42 - 00399826 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libexif-12.dll.dll 2013-02-14 19:42 - 2013-02-14 19:42 - 00044032 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\us.dll 2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-12 20:58 - 2014-02-12 20:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-03-28 08:39 - 2013-08-08 22:25 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2009-02-26 13:46 - 2009-02-26 13:46 - 00064344 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\ColleagueImport.dll 2011-06-22 11:46 - 2011-06-22 11:46 - 00434016 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll 2013-07-10 18:07 - 2013-07-10 18:07 - 00756888 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL 2014-10-10 07:33 - 2014-10-10 07:33 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2014-07-25 16:22 - 2014-07-25 16:22 - 00436576 _____ () C:\Program Files (x86)\Evernote\Evernote\libxml2.dll 2014-07-25 16:22 - 2014-07-25 16:22 - 00318304 _____ () C:\Program Files (x86)\Evernote\Evernote\libtidy.dll 2014-03-28 08:55 - 2014-03-28 08:55 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll 2014-09-25 09:57 - 2014-09-25 09:57 - 03715184 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Users\Marcel\SkyDrive:ms-properties ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "Secunia PSI Tray.lnk" HKLM\...\StartupApproved\Run: => "BTMTrayAgent" HKLM\...\StartupApproved\Run: => "Yoga PhoneCompanion" HKLM\...\StartupApproved\Run: => "AutoStartTransition" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKLM\...\StartupApproved\Run32: => "Yoga Picks" HKLM\...\StartupApproved\Run32: => "BrMfcWnd" HKLM\...\StartupApproved\Run32: => "ControlCenter3" HKLM\...\StartupApproved\Run32: => "FileZilla Server Interface" HKLM\...\StartupApproved\Run32: => "My Swisscom Assistant" HKCU\...\StartupApproved\Run: => "AshSnap" ========================= Accounts: ========================== Administrator (S-1-5-21-3121602427-3534730855-1075997385-500 - Administrator - Enabled) => C:\Users\Administrator Guest (S-1-5-21-3121602427-3534730855-1075997385-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3121602427-3534730855-1075997385-1003 - Limited - Enabled) Marcel (S-1-5-21-3121602427-3534730855-1075997385-1001 - Administrator - Enabled) => C:\Users\Marcel ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/17/2014 08:11:19 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (10/16/2014 06:20:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: WHS ProStation.exe, Version: 2.38.56.10, Zeitstempel: 0x2a425e19 Name des fehlerhaften Moduls: log4cxx.dll, Version: 0.0.0.0, Zeitstempel: 0x48f48443 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000061b2 ID des fehlerhaften Prozesses: 0x17d4 Startzeit der fehlerhaften Anwendung: 0xWHS ProStation.exe0 Pfad der fehlerhaften Anwendung: WHS ProStation.exe1 Pfad des fehlerhaften Moduls: WHS ProStation.exe2 Berichtskennung: WHS ProStation.exe3 Vollständiger Name des fehlerhaften Pakets: WHS ProStation.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WHS ProStation.exe5 Error: (10/16/2014 04:49:55 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (10/16/2014 03:54:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: WHS ProStation.exe, Version: 2.38.56.10, Zeitstempel: 0x2a425e19 Name des fehlerhaften Moduls: log4cxx.dll, Version: 0.0.0.0, Zeitstempel: 0x48f48443 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000061b2 ID des fehlerhaften Prozesses: 0x2004 Startzeit der fehlerhaften Anwendung: 0xWHS ProStation.exe0 Pfad der fehlerhaften Anwendung: WHS ProStation.exe1 Pfad des fehlerhaften Moduls: WHS ProStation.exe2 Berichtskennung: WHS ProStation.exe3 Vollständiger Name des fehlerhaften Pakets: WHS ProStation.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WHS ProStation.exe5 Error: (10/16/2014 11:43:12 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (10/16/2014 10:40:00 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (10/16/2014 08:26:26 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (10/15/2014 11:46:24 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: FreemakeUtilsService.exe, Version: 1.0.0.0, Zeitstempel: 0x5407f460 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.3.9600.17278, Zeitstempel: 0x53eeb460 Ausnahmecode: 0xe0434352 Fehleroffset: 0x00012f71 ID des fehlerhaften Prozesses: 0x9a8 Startzeit der fehlerhaften Anwendung: 0xFreemakeUtilsService.exe0 Pfad der fehlerhaften Anwendung: FreemakeUtilsService.exe1 Pfad des fehlerhaften Moduls: FreemakeUtilsService.exe2 Berichtskennung: FreemakeUtilsService.exe3 Vollständiger Name des fehlerhaften Pakets: FreemakeUtilsService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: FreemakeUtilsService.exe5 Error: (10/15/2014 11:46:23 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: FreemakeUtilsService.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.ArgumentException Stack: at System.Security.Principal.SecurityIdentifier..ctor(System.String) at FreemakeUtilsService.Common.ToolbarInstallationChecker.GetSidToUsernameDictionary() at FreemakeUtilsService.Common.ToolbarInstallationChecker.CheckInfo(FreemakeUtilsService.Common.FreemakeToolbarsInfo) at FreemakeUtilsService.Statistics.Manager.StartToolbarInfoCheck() at FreemakeUtilsService.Statistics.Manager.SettingsSyncFailed(System.Object, System.EventArgs) at FreemakeUtilsService.Common.Synchronizer.OnWorkerCompleted(System.Object, System.ComponentModel.RunWorkerCompletedEventArgs) at System.ComponentModel.BackgroundWorker.OnRunWorkerCompleted(System.ComponentModel.RunWorkerCompletedEventArgs) at System.ComponentModel.BackgroundWorker.AsyncOperationCompleted(System.Object) at System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() at System.Threading.ThreadPoolWorkQueue.Dispatch() at System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (10/15/2014 02:09:53 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 System errors: ============= Error: (10/17/2014 08:12:20 AM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: Error: (10/17/2014 08:06:04 AM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: Error: (10/17/2014 08:03:51 AM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: Error: (10/17/2014 08:01:12 AM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: Error: (10/17/2014 08:01:09 AM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (10/16/2014 07:49:43 PM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (10/16/2014 07:49:43 PM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (10/16/2014 07:49:43 PM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (10/16/2014 07:49:42 PM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (10/16/2014 07:49:42 PM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Microsoft Office Sessions: ========================= Error: (09/12/2014 11:09:25 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6700.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 3782 seconds with 480 seconds of active time. This session ended with a crash. Error: (06/27/2014 11:30:39 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 1123 seconds with 360 seconds of active time. This session ended with a crash. Error: (05/21/2014 10:22:13 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6691.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-05-07 11:05:12.534 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements. Date: 2014-05-07 11:05:12.425 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements. Date: 2014-05-07 10:48:58.512 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements. Date: 2014-05-07 10:48:58.387 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements. Date: 2014-05-06 14:05:56.982 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements. Date: 2014-05-06 14:05:56.857 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements. Date: 2014-05-05 14:52:47.959 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Windows signing level requirements. Date: 2014-05-05 14:52:47.834 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\services.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Windows signing level requirements. Date: 2014-05-04 18:15:35.488 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-05-04 18:15:35.363 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4500U CPU @ 1.80GHz Percentage of memory in use: 32% Total physical RAM: 8104.27 MB Available physical RAM: 5486.56 MB Total Pagefile: 9384.27 MB Available Pagefile: 6112.27 MB Total Virtual: 131072 MB Available Virtual: 131071.84 MB ==================== Drives ================================ Drive c: (Windows8_OS) (Fixed) (Total:217.68 GB) (Free:148.41 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.89 GB) NTFS Drive e: (MAESE_SAFE) (Fixed) (Total:465.75 GB) (Free:20.49 GB) NTFS Drive f: (Daten) (Fixed) (Total:216.58 GB) (Free:185.33 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 476.9 GB) (Disk ID: D9341526) Partition: GPT Partition Type. ======================================================== Disk: 1 (Size: 465.8 GB) (Disk ID: 8D399BC0) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
17.10.2014, 20:29 | #20 |
/// the machine /// TB-Ausbilder | Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol Vergiss es, ich hab grad gesehen dass die Formulierung nit zielführend war von meiner einer Also bitte die Funde von ESET auf den externen Medien von Hand löschen, ausser du kennst die und weißt sie sind sauber. FRST log bitte, keine Addition.txt
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.10.2014, 22:16 | #21 |
| FRST logFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-10-2014 Ran by Marcel (administrator) on SUGUS on 17-10-2014 23:11:18 Running from F:\90 Daten Systemordner\Downloads_sys Loaded Profile: Marcel (Available profiles: Marcel & Administrator) Platform: Windows 8.1 (X64) OS Language: Englisch (Vereinigte Staaten) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe (Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (CrypKey (Canada) Ltd.) C:\Windows\System32\Crypserv.exe (Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe (Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe (Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe (FileZilla Project) C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe (PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe (Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe (Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe () C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\livecomm.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe (Learnpulse) C:\Users\Marcel\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Docking Station) C:\Program Files (x86)\Lenovo\USB3.0 Dock\igpxtskmgn64win8.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\ielowutil.exe (Nenad Hrg (SoftwareOK.com)) C:\Program Files\Q-Dir\Q-Dir.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13656792 2013-10-04] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1353432 2013-09-26] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\windows\system32\DptfPolicyLpmServiceHelper.exe [111976 2013-08-02] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM\...\Run: [Yoga PhoneCompanion] => C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe [844304 2014-03-28] (Lenovo) HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-03-28] () HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [59923440 2014-03-28] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2014-03-28] (Lenovo(beijing) Limited) HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [607584 2014-09-29] (Copyright 2013 SAMSUNG) HKLM-x32\...\Run: [Yoga Picks] => C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe [119280 2014-01-06] (Lenovo) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [BrMfcWnd] => C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.) HKLM-x32\...\Run: [ControlCenter3] => C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.) HKLM-x32\...\Run: [My Swisscom Assistant] => C:\Program Files (x86)\Swisscom\My Swisscom Assistant\MySwisscomAssistant_Launcher.exe [7503792 2014-02-27] (Swisscom (Schweiz) AG) HKLM-x32\...\Run: [FileZilla Server Interface] => C:\Program Files (x86)\FileZilla Server\FileZilla Server Interface.exe [2322944 2014-04-08] (FileZilla Project) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-10-10] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [Screenpresso] => C:\Users\Marcel\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe [10983952 2014-09-22] (Learnpulse) HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [AshSnap] => C:\Program Files (x86)\Ashampoo\Ashampoo Snap 6\ashsnap.exe HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [msnmsgr] => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [784392 2014-05-29] (Sandboxie Holdings, LLC) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\igpxtskmgn.lnk ShortcutTarget: igpxtskmgn.lnk -> C:\Program Files (x86)\Lenovo\USB3.0 Dock\igpxtskmgn64win8.exe (Docking Station) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) Startup: C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Startup: C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\start.bat () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - {72A5F580-1FA0-4C34-B0EF-61D4BC34A5E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB SearchScopes: HKLM-x32 - {72A5F580-1FA0-4C34-B0EF-61D4BC34A5E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB SearchScopes: HKCU - {72A5F580-1FA0-4C34-B0EF-61D4BC34A5E0} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {A6616B31-4860-41E2-98E3-CA7649AF172F} file:///E:/00%20A%20Temp/001%20USB%20DOking/launch.ocx Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - No File Handler-x32: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default FF SelectedSearchEngine: Google FF Homepage: https://www.google.ch/?gfe_rd=cr&ei=ochAVKyvLYuH8Qe04oCYBQ&gws_rd=ssl FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll () FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\searchplugins\google-maps.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira Browser Safety - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\abs@avira.com [2014-09-30] FF Extension: Xmarks - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\foxmarks@kei.com [2014-09-17] FF Extension: My Swisscom Assistant - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\{6A6114A5-EEF5-45F4-BCD1-B00A7B33E04B} [2014-05-15] FF Extension: Cliqz Beta - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\cliqz@cliqz.com.xpi [2014-10-15] FF Extension: Tab Mix Plus - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-09-30] FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com [2014-04-29] FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com [2014-04-29] FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox [2014-09-06] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-10-10] FF HKCU\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\extensions\cliqz@cliqz.com Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.google.com/" CHR Profile: C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-10] CHR Extension: (Google Docs) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-10] CHR Extension: (Google Drive) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-10] CHR Extension: (YouTube) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-10] CHR Extension: (Google-Suche) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-10] CHR Extension: (Google Tabellen) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-10] CHR Extension: (Avira Browser Safety) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-10-10] CHR Extension: (avast! Online Security) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-10-10] CHR Extension: (Google Wallet) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-10] CHR Extension: (Google Mail) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-10] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-10] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) [File not signed] R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-10] (AVAST Software) R2 Crypkey License; C:\windows\system32\crypserv.exe [122880 2008-05-08] (CrypKey (Canada) Ltd.) [File not signed] R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [9281840 2013-10-11] (DisplayLink Corp.) R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [115632 2013-08-02] (Intel Corporation) R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116656 2013-08-02] (Intel Corporation) R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [148688 2013-08-02] (Intel Corporation) R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [124880 2013-08-02] (Intel Corporation) R2 FileZilla Server; C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe [627712 2014-04-08] (FileZilla Project) [File not signed] S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-09-04] (Freemake) [File not signed] R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-05-22] (Ellora Assets Corp.) [File not signed] R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation) R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-19] (Intel Corporation) R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-08-02] () S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation) S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation) R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-08-18] (LENOVO INCORPORATED.) S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation) R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-03-28] (Lenovo) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation) R2 NitroReaderDriverReadSpool3; C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [230416 2013-07-26] (Nitro PDF Software) R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2014-01-08] (PointGrab LTD) R2 PhoneCompanionPusher; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe [249872 2014-03-28] (Lenovo) S3 PhoneCompanionVap; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionVap.exe [328720 2014-03-28] (Lenovo) R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] () R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [288472 2013-09-13] (Realtek Semiconductor) R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [616288 2014-09-29] (Copyright 2013 SAMSUNG) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [174088 2014-05-29] (Sandboxie Holdings, LLC) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia) S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation) S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation) R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2014-03-28] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [34576 2014-03-28] (Lenovo) R2 YogaPicks.AppService; C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe [19440 2014-01-07] () S3 McAWFwk; c:\PROGRA~1\COMMON~1\mcafee\actwiz\mcawfwk.exe [X] S4 McOobeSv2; "C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-10-10] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-10-10] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-10-10] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-10-10] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-10-10] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-10-10] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-10-10] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-10-10] () S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-18] (ASIX Electronics Corp.) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-23] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-06] (Motorola Solutions, Inc.) R3 DisplayLinkUsbIo_x64; C:\Windows\System32\drivers\DisplayLinkUsbIo_x64_7.4.48800.0.sys [44944 2013-10-07] () R3 dlcdcncm6_x64; C:\Windows\system32\DRIVERS\dlcdcncm6_x64.sys [80688 2013-10-11] (DisplayLink Corp.) R3 dlusbaudio; C:\Windows\system32\DRIVERS\dlusbaudio_x64.sys [203152 2013-10-11] (DisplayLink Corp.) R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [114680 2013-08-02] (Intel Corporation) R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [287160 2013-08-02] (Intel Corporation) R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [494272 2013-08-02] (Intel Corporation) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [118728 2013-09-19] (Intel Corporation) R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21408 2013-08-02] () R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21920 2013-08-02] () R3 INETMON; C:\windows\System32\Drivers\INETMON.sys [29088 2013-08-02] () R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-08-02] () R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-10-17] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation) R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3589600 2013-09-19] (Intel Corporation) S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation) R1 NetworkX; C:\Windows\system32\ckldrv.sys [28664 2008-03-17] () R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia) S3 qzozigbn; C:\Windows\System32\Drivers\qzozigbn.sys [423240 2014-05-07] (AVAST Software) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [185352 2014-05-29] (Sandboxie Holdings, LLC) R3 SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation) R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation) S3 sidtohjv; C:\Windows\System32\Drivers\sidtohjv.sys [423240 2014-05-04] (AVAST Software) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-29] (Synaptics Incorporated) R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1527928 2013-08-23] (Sunplus) S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2014-05-07] () S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink) S3 PCASp60; System32\Drivers\PCASp60.sys [X] S3 VBoxNetFlt; \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys [X] S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X] S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-15 14:43 - 2014-10-15 14:43 - 00000000 ___RD () C:\Sandbox 2014-10-15 14:40 - 2014-10-16 15:57 - 00001672 _____ () C:\windows\Sandboxie.ini 2014-10-15 14:40 - 2014-10-15 14:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie 2014-10-15 14:39 - 2014-10-15 14:39 - 00000000 ____D () C:\Program Files\Sandboxie 2014-10-15 11:32 - 2014-10-17 23:08 - 00000435 _____ () C:\windows\system32\Drivers\etc\hosts.ics 2014-10-15 11:23 - 2014-10-15 11:23 - 00000000 ____D () C:\Users\Marcel\VirtualBox VMs 2014-10-15 11:22 - 2014-10-15 12:25 - 00000000 ____D () C:\Users\Marcel\.VirtualBox 2014-10-15 11:22 - 2014-10-11 13:29 - 00917112 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxDrv.sys 2014-10-15 11:22 - 2014-10-11 13:27 - 00129168 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxUSBMon.sys 2014-10-15 11:21 - 2014-10-15 11:21 - 00000000 ____D () C:\Program Files\Oracle 2014-10-15 09:51 - 2014-10-10 00:16 - 00678400 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-10-15 09:51 - 2014-10-09 00:09 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll 2014-10-15 09:51 - 2014-09-19 03:24 - 00527360 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-10-15 09:51 - 2014-09-13 08:02 - 02779648 _____ (Microsoft Corporation) C:\windows\system32\msi.dll 2014-10-15 09:51 - 2014-09-13 07:30 - 03117568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll 2014-10-15 09:51 - 2014-09-04 02:10 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\winbici.dll 2014-10-15 09:51 - 2014-09-04 01:57 - 00921600 _____ (Microsoft Corporation) C:\windows\system32\MrmCoreR.dll 2014-10-15 09:51 - 2014-09-04 01:49 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\MrmCoreR.dll 2014-10-15 09:51 - 2014-08-29 03:58 - 00109568 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll 2014-10-15 09:51 - 2014-08-29 01:56 - 02646016 _____ (Microsoft Corporation) C:\windows\system32\authui.dll 2014-10-15 09:51 - 2014-08-29 01:47 - 02321920 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll 2014-10-15 08:38 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\windows\SysWOW64\dhRichClient3.dll 2014-10-15 08:38 - 2011-03-25 20:42 - 00338432 _____ () C:\windows\SysWOW64\sqlite36_engine.dll 2014-10-15 08:06 - 2014-09-28 00:25 - 04183040 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2014-10-15 08:06 - 2014-09-26 00:50 - 13619200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-10-15 08:06 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-10-15 08:06 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-10-15 08:06 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-10-15 08:06 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-10-15 08:06 - 2014-09-26 00:31 - 02108416 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-10-15 08:06 - 2014-09-19 04:25 - 23631360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-10-15 08:06 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-10-15 08:06 - 2014-09-19 03:41 - 02796032 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-10-15 08:06 - 2014-09-19 03:40 - 00547328 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-10-15 08:06 - 2014-09-19 03:38 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2014-10-15 08:06 - 2014-09-19 03:36 - 05829632 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-10-15 08:06 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-10-15 08:06 - 2014-09-19 03:25 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-10-15 08:06 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-10-15 08:06 - 2014-09-19 03:00 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-10-15 08:06 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2014-10-15 08:06 - 2014-09-19 02:58 - 00289280 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-10-15 08:06 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-10-15 08:06 - 2014-09-19 02:42 - 00731136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-10-15 08:06 - 2014-09-19 02:42 - 00710656 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-10-15 08:06 - 2014-09-19 02:42 - 00363008 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-10-15 08:06 - 2014-09-19 02:33 - 02309632 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-10-15 08:06 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-10-15 08:06 - 2014-09-19 02:20 - 00315904 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2014-10-15 08:06 - 2014-09-19 02:14 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-10-15 08:06 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-10-15 08:06 - 2014-09-19 01:59 - 00775168 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-10-15 08:06 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-10-15 08:06 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-10-15 08:05 - 2014-09-08 05:15 - 00054752 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe 2014-10-15 08:05 - 2014-09-08 03:46 - 00059904 _____ (Microsoft Corporation) C:\windows\system32\wups.dll 2014-10-15 08:05 - 2014-09-08 03:46 - 00050688 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll 2014-10-15 08:05 - 2014-09-08 02:08 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe 2014-10-15 08:05 - 2014-09-08 02:07 - 00137728 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll 2014-10-15 08:05 - 2014-09-08 02:05 - 03448320 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll 2014-10-15 08:05 - 2014-09-08 02:04 - 00388608 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll 2014-10-15 08:05 - 2014-09-08 02:04 - 00093696 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll 2014-10-15 08:05 - 2014-09-08 02:03 - 01702400 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll 2014-10-15 08:05 - 2014-09-08 02:03 - 00839680 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll 2014-10-15 08:05 - 2014-09-08 01:59 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll 2014-10-15 08:05 - 2014-09-08 01:59 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe 2014-10-15 08:05 - 2014-09-08 01:56 - 00672256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll 2014-10-15 08:05 - 2014-09-08 01:56 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll 2014-10-15 08:04 - 2014-09-13 08:29 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\packager.dll 2014-10-15 08:04 - 2014-09-13 07:49 - 00068608 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll 2014-10-15 08:04 - 2014-09-04 02:12 - 00590336 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll 2014-10-15 08:04 - 2014-09-04 02:01 - 00514048 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll 2014-10-15 08:04 - 2014-08-16 06:08 - 21195616 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll 2014-10-15 08:04 - 2014-08-16 06:08 - 01507648 _____ (Microsoft Corporation) C:\windows\system32\propsys.dll 2014-10-15 08:04 - 2014-08-16 06:01 - 01710184 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll 2014-10-15 08:04 - 2014-08-16 05:58 - 01112512 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll 2014-10-15 08:04 - 2014-08-16 05:57 - 02498880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2014-10-15 08:04 - 2014-08-16 05:57 - 00428864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS 2014-10-15 08:04 - 2014-08-16 05:16 - 18722600 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll 2014-10-15 08:04 - 2014-08-16 05:16 - 01205976 _____ (Microsoft Corporation) C:\windows\SysWOW64\propsys.dll 2014-10-15 08:04 - 2014-08-16 05:03 - 01467384 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll 2014-10-15 08:04 - 2014-08-16 03:31 - 00838144 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll 2014-10-15 08:04 - 2014-08-16 03:04 - 00359424 _____ (Microsoft Corporation) C:\windows\system32\Wldap32.dll 2014-10-15 08:04 - 2014-08-16 02:58 - 00287744 _____ (Microsoft Corporation) C:\windows\system32\SystemEventsBrokerServer.dll 2014-10-15 08:04 - 2014-08-16 02:53 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\httpprxm.dll 2014-10-15 08:04 - 2014-08-16 02:46 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\ProximityService.dll 2014-10-15 08:04 - 2014-08-16 02:45 - 00267776 _____ (Microsoft Corporation) C:\windows\system32\bisrv.dll 2014-10-15 08:04 - 2014-08-16 02:43 - 00321024 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wldap32.dll 2014-10-15 08:04 - 2014-08-16 02:43 - 00075776 _____ (Microsoft Corporation) C:\windows\system32\adhsvc.dll 2014-10-15 08:04 - 2014-08-16 02:31 - 00914432 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll 2014-10-15 08:04 - 2014-08-16 02:31 - 00286208 _____ (Microsoft Corporation) C:\windows\system32\pcsvDevice.dll 2014-10-15 08:04 - 2014-08-16 02:29 - 00249344 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-10-15 08:04 - 2014-08-16 02:23 - 01106432 _____ (Microsoft Corporation) C:\windows\system32\SearchFolder.dll 2014-10-15 08:04 - 2014-08-16 02:22 - 00717824 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveTelemetry.dll 2014-10-15 08:04 - 2014-08-16 02:22 - 00286208 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveShell.dll 2014-10-15 08:04 - 2014-08-16 02:19 - 00189952 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-10-15 08:04 - 2014-08-16 02:18 - 04758528 _____ (Microsoft Corporation) C:\windows\system32\SyncEngine.dll 2014-10-15 08:04 - 2014-08-16 02:17 - 08757760 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Search.dll 2014-10-15 08:04 - 2014-08-16 02:14 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\SkyDriveShell.dll 2014-10-15 08:04 - 2014-08-16 02:13 - 06649344 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll 2014-10-15 08:04 - 2014-08-16 02:13 - 05902848 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Search.dll 2014-10-15 08:04 - 2014-08-16 02:13 - 00840192 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFolder.dll 2014-10-15 08:04 - 2014-08-16 02:11 - 00920064 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll 2014-10-15 08:04 - 2014-08-16 02:10 - 01120768 _____ (Microsoft Corporation) C:\windows\system32\SkyDrive.exe 2014-10-15 08:04 - 2014-08-16 02:08 - 05777408 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll 2014-10-15 08:04 - 2014-08-16 02:07 - 00756224 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll 2014-10-15 08:04 - 2014-08-01 01:22 - 00388729 _____ () C:\windows\system32\ApnDatabase.xml 2014-10-14 18:55 - 2014-10-15 10:02 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\VMware 2014-10-14 18:55 - 2014-10-14 19:51 - 00000000 ____D () C:\Users\Marcel\AppData\Local\VMware 2014-10-14 18:53 - 2014-10-15 10:02 - 00000000 ____D () C:\ProgramData\VMware 2014-10-14 11:31 - 2014-10-14 11:31 - 00001126 _____ () C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\join.me.lnk 2014-10-14 11:31 - 2014-10-14 11:31 - 00000000 ____D () C:\Users\Marcel\AppData\Local\LogMeIn 2014-10-14 11:31 - 2014-10-14 11:31 - 00000000 ____D () C:\ProgramData\LogMeIn 2014-10-14 11:26 - 2014-10-14 11:31 - 00000000 ____D () C:\Users\Marcel\AppData\Local\join.me 2014-10-13 10:07 - 2014-10-13 10:07 - 00319912 _____ (Oracle Corporation) C:\windows\system32\javaws.exe 2014-10-13 10:07 - 2014-10-13 10:07 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe 2014-10-13 10:07 - 2014-10-13 10:07 - 00189352 _____ (Oracle Corporation) C:\windows\system32\java.exe 2014-10-13 10:07 - 2014-10-13 10:07 - 00111016 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll 2014-10-13 08:41 - 2014-10-17 13:48 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-13 08:41 - 2014-10-17 13:46 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll 2014-10-13 08:41 - 2014-10-17 13:46 - 00000000 ____D () C:\Program Files (x86)\Java 2014-10-13 08:41 - 2014-10-13 08:41 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe 2014-10-13 08:41 - 2014-10-13 08:41 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe 2014-10-13 08:41 - 2014-10-13 08:41 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe 2014-10-13 08:33 - 2014-10-13 08:33 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Oracle 2014-10-11 13:27 - 2014-10-11 13:27 - 00142528 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxNetAdp.sys 2014-10-10 07:34 - 2014-10-10 07:34 - 00001993 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-10-10 07:34 - 2014-10-10 07:34 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\AVAST Software 2014-10-10 07:34 - 2014-10-10 07:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2014-10-10 07:33 - 2014-10-10 07:34 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update 2014-10-10 07:33 - 2014-10-10 07:33 - 01041168 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00427360 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00307344 _____ (AVAST Software) C:\windows\system32\aswBoot.exe 2014-10-10 07:33 - 2014-10-10 07:33 - 00224896 _____ () C:\windows\system32\Drivers\aswVmm.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00093568 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00092008 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00079184 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00065776 _____ () C:\windows\system32\Drivers\aswRvrt.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-10-10 07:33 - 2014-10-10 07:33 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys 2014-10-10 07:32 - 2014-10-10 07:32 - 00000000 ____D () C:\Program Files\AVAST Software 2014-10-10 00:16 - 2014-10-10 00:16 - 00001716 _____ () C:\Users\Marcel\Desktop\JRT.txt 2014-10-10 00:14 - 2014-10-10 00:14 - 00000000 ____D () C:\windows\ERUNT 2014-10-09 23:27 - 2014-10-17 23:07 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-09 23:26 - 2014-10-09 23:26 - 00001129 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-09 23:26 - 2014-10-09 23:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-09 23:26 - 2014-10-09 23:26 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-09 23:26 - 2014-10-09 23:26 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-10-09 23:26 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-10-09 23:26 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-10-09 23:26 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-10-09 23:20 - 2014-10-09 23:20 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-10-08 17:30 - 2014-10-17 23:11 - 00000000 ____D () C:\FRST 2014-10-03 11:30 - 2014-10-03 17:10 - 00000000 ____D () C:\Program Files\Q-Dir 2014-10-03 11:19 - 2014-10-03 11:19 - 00000000 ____D () C:\Users\Marcel\AppData\Local\GHISLER 2014-10-03 11:17 - 2014-10-03 11:17 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\GHISLER 2014-10-03 09:03 - 2014-10-03 09:18 - 00000004 _____ () C:\windows\vx86036.dat 2014-10-03 09:03 - 2014-10-03 09:13 - 00000260 _____ () C:\CKINFO.TXT 2014-10-03 09:03 - 2014-10-03 09:03 - 00000000 ____D () C:\ProgramData\CrypKey 2014-10-03 09:02 - 2014-10-15 13:44 - 00036047 _____ () C:\windows\errord.log 2014-10-03 09:02 - 2014-10-15 13:44 - 00000868 _____ () C:\windows\error.log 2014-10-03 09:02 - 2014-10-03 09:18 - 00003360 _____ () C:\windows\system32\esnecil.ind 2014-10-03 09:02 - 2014-10-03 09:18 - 00000127 _____ () C:\windows\Crypkey.ini 2014-10-03 09:02 - 2014-10-03 09:18 - 00000000 ____D () C:\Program Files\Stellar Phoenix Outlook PST Repair 2014-10-03 09:02 - 2008-05-08 01:29 - 00122880 _____ (CrypKey (Canada) Ltd.) C:\windows\system32\Crypserv.exe 2014-10-03 09:02 - 2008-03-17 19:12 - 00028664 _____ () C:\windows\system32\Ckldrv.sys 2014-10-03 09:02 - 1999-06-18 22:49 - 00165888 _____ (Kenonic Controls) C:\windows\Ckconfig.exe 2014-10-03 09:02 - 1996-05-03 18:21 - 00027648 ____R () C:\windows\Setup_ck.exe 2014-10-03 09:02 - 1996-05-03 16:36 - 00018432 _____ () C:\windows\Setup_ck.dll 2014-10-03 09:02 - 1995-07-04 19:33 - 00011776 _____ () C:\windows\Ckrfresh.exe 2014-10-02 18:42 - 2014-10-02 18:42 - 00003974 _____ () C:\windows\System32\Tasks\4Team updater 2014-10-02 18:41 - 2014-10-03 16:56 - 00000000 ____D () C:\Program Files (x86)\4Team Corporation 2014-10-02 18:41 - 2014-10-02 18:41 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\4Team 2014-10-02 18:41 - 2014-10-02 18:41 - 00000000 ____D () C:\Users\Marcel\AppData\Local\IsolatedStorage 2014-10-02 09:40 - 2014-10-02 09:40 - 00000000 ____D () C:\Neuer Ordner 2014-10-01 09:42 - 2014-10-09 12:03 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\FileZilla 2014-09-26 15:41 - 2014-09-30 08:40 - 00000000 ____D () C:\Users\Marcel\Tracing 2014-09-26 15:40 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_7.dll 2014-09-26 15:40 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_7.dll 2014-09-26 15:40 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_5.dll 2014-09-26 15:40 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_5.dll 2014-09-26 15:40 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_43.dll 2014-09-26 15:40 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_43.dll 2014-09-26 15:40 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\windows\system32\d3dx11_43.dll 2014-09-26 15:40 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx11_43.dll 2014-09-26 15:39 - 2014-09-26 15:39 - 00002242 _____ () C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2014-09-26 15:39 - 2014-09-26 15:39 - 00002147 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2014-09-26 15:39 - 2014-09-26 15:39 - 00002147 _____ () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2014-09-26 15:39 - 2014-09-26 15:39 - 00000196 _____ () C:\windows\DirectX.log 2014-09-26 15:39 - 2014-09-26 15:39 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive 2014-09-26 15:39 - 2014-09-26 15:39 - 00000000 ____D () C:\Program Files (x86)\Microsoft SkyDrive 2014-09-26 15:39 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_42.dll 2014-09-26 15:39 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_42.dll 2014-09-26 15:39 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_32.dll 2014-09-26 15:39 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_32.dll 2014-09-26 15:38 - 2014-09-30 08:54 - 00000000 ____D () C:\Users\Marcel\AppData\Local\Windows Live 2014-09-25 13:13 - 2014-10-08 16:50 - 00003718 _____ () C:\windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 2014-09-25 13:13 - 2014-09-25 13:13 - 00003476 _____ () C:\windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon 2014-09-25 09:57 - 2014-09-25 09:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-24 17:16 - 2014-09-24 17:16 - 00000000 ____D () C:\Users\Marcel\AppData\Local\FreemakeVideoDownloader ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-17 23:10 - 2014-04-22 15:38 - 00003922 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{F5291F67-CB16-4602-A1AA-B673A0FBD3F7} 2014-10-17 23:08 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\AppReadiness 2014-10-17 23:07 - 2014-04-22 15:14 - 00000000 __RDO () C:\Users\Marcel\SkyDrive 2014-10-17 23:07 - 2014-03-28 08:55 - 00010752 _____ () C:\windows\system32\VfService.trf 2014-10-17 23:07 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\sru 2014-10-17 17:50 - 2014-04-30 12:43 - 00000000 ____D () C:\Users\Marcel\AppData\Local\CrashDumps 2014-10-17 16:56 - 2014-04-29 09:31 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-10-17 16:53 - 2014-04-22 19:56 - 00000432 _____ () C:\windows\BRWMARK.INI 2014-10-17 13:53 - 2014-04-22 15:13 - 00003600 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3121602427-3534730855-1075997385-1001 2014-10-17 13:46 - 2014-04-22 16:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-17 13:39 - 2014-03-28 08:34 - 01963149 _____ () C:\windows\WindowsUpdate.log 2014-10-17 13:19 - 2014-04-28 20:40 - 00000000 ____D () C:\windows\system32\MRT 2014-10-17 13:16 - 2014-04-28 20:40 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-10-17 10:57 - 2014-05-05 11:47 - 00000000 ____D () C:\xampp 2014-10-16 18:24 - 2014-04-22 19:41 - 00000000 ____D () C:\ProgramData\firebird 2014-10-16 13:35 - 2014-06-12 07:50 - 00011082 _____ () C:\windows\SecuniaPackage.log 2014-10-16 13:35 - 2014-04-29 09:31 - 00003718 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-10-16 08:20 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\NDF 2014-10-15 14:42 - 2014-04-20 09:09 - 00000000 ____D () C:\MADProg 2014-10-15 14:42 - 2014-04-20 09:08 - 00000000 ____D () C:\MADDaten 2014-10-15 13:49 - 2014-03-28 09:27 - 00955470 _____ () C:\windows\system32\perfh00C.dat 2014-10-15 13:49 - 2014-03-28 09:27 - 00256758 _____ () C:\windows\system32\perfc00C.dat 2014-10-15 13:49 - 2014-03-28 09:24 - 01046540 _____ () C:\windows\system32\perfh007.dat 2014-10-15 13:49 - 2014-03-28 09:24 - 00258988 _____ () C:\windows\system32\perfc007.dat 2014-10-15 13:49 - 2013-10-07 20:27 - 00005934 _____ () C:\windows\system32\PerfStringBackup.INI 2014-10-15 13:44 - 2013-08-22 16:46 - 00034703 _____ () C:\windows\setupact.log 2014-10-15 13:44 - 2013-08-22 16:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-10-15 13:44 - 2013-08-22 16:44 - 00499656 _____ () C:\windows\system32\FNTCACHE.DAT 2014-10-15 13:34 - 2013-08-22 17:36 - 00000000 ___RD () C:\windows\ToastData 2014-10-15 13:34 - 2013-08-22 15:25 - 00524288 ___SH () C:\windows\system32\config\BBI 2014-10-15 13:33 - 2014-07-09 18:28 - 00000000 ___SD () C:\windows\system32\CompatTel 2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\WinStore 2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\MediaViewer 2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\FileManager 2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\Camera 2014-10-15 12:32 - 2014-04-22 17:16 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-10-15 12:32 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-10-15 12:32 - 2013-08-22 17:20 - 00000000 ____D () C:\windows\CbsTemp 2014-10-15 11:23 - 2014-04-22 15:08 - 00000000 ____D () C:\Users\Marcel 2014-10-15 11:10 - 2014-04-29 10:05 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\vlc 2014-10-14 18:54 - 2014-03-28 08:43 - 00006124 _____ () C:\windows\SysWOW64\PerfStringBackup.INI 2014-10-13 10:07 - 2013-10-07 20:23 - 00152266 _____ () C:\windows\PFRO.log 2014-10-10 07:37 - 2014-04-22 16:35 - 00000000 ____D () C:\Program Files (x86)\Google 2014-10-10 07:34 - 2014-04-22 16:35 - 00000000 ____D () C:\Users\Marcel\AppData\Local\Google 2014-10-10 00:38 - 2014-04-22 16:42 - 00022391 _____ () C:\windows\Q-Dir.ini 2014-10-10 00:31 - 2014-05-04 19:20 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-10-10 00:31 - 2014-03-28 08:43 - 00000000 ____D () C:\ProgramData\Package Cache 2014-10-10 00:09 - 2013-08-22 15:25 - 00262144 ___SH () C:\windows\system32\config\ELAM 2014-10-09 23:58 - 2014-05-07 11:16 - 00000000 ____D () C:\AdwCleaner 2014-10-09 23:43 - 2014-05-07 18:53 - 00000000 ____D () C:\Users\Administrator 2014-10-08 16:42 - 2014-04-22 15:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-10-05 13:23 - 2014-06-19 14:39 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\SmartDraw 2014-10-03 11:32 - 2014-04-22 16:42 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Q-Dir 2014-10-02 18:40 - 2014-03-28 08:55 - 00000000 ____D () C:\ProgramData\Downloaded Installations 2014-10-01 09:43 - 2014-04-22 16:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2014-10-01 09:43 - 2014-04-22 16:35 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client 2014-10-01 07:58 - 2014-08-30 09:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2014-09-30 00:45 - 2013-08-22 17:38 - 00706016 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-09-30 00:45 - 2013-08-22 17:38 - 00105440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-09-26 13:19 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\rescache 2014-09-25 17:44 - 2014-04-22 17:41 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Nitro PDF 2014-09-25 13:13 - 2014-03-28 08:43 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2014-09-22 09:07 - 2014-04-22 16:37 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-09-22 08:42 - 2014-05-04 18:19 - 00278152 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe 2014-09-17 19:14 - 2014-09-06 07:48 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\RHEng 2014-09-17 19:14 - 2014-04-29 14:34 - 00000967 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileSync.lnk 2014-09-17 19:14 - 2014-04-29 14:34 - 00000957 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealtimeSync.lnk Some content of TEMP: ==================== C:\Users\Administrator\AppData\Local\Temp\avgnt.exe C:\Users\Marcel\AppData\Local\Temp\avgnt.exe C:\Users\Marcel\AppData\Local\Temp\FreemakeVideoDownloader_3.6.4.3.exe C:\Users\Marcel\AppData\Local\Temp\FreemakeVideoDownloader_3.7.0.1.exe C:\Users\Marcel\AppData\Local\Temp\gkey.exe C:\Users\Marcel\AppData\Local\Temp\i4jdel0.exe C:\Users\Marcel\AppData\Local\Temp\ICReinstall_COMPUTER_BILD-Download-Manager_fuer_Screenpresso.exe C:\Users\Marcel\AppData\Local\Temp\K-Lite_Codec_Pack_Basic.exe C:\Users\Marcel\AppData\Local\Temp\ms.exe C:\Users\Marcel\AppData\Local\Temp\msvcr71.dll C:\Users\Marcel\AppData\Local\Temp\MySwisscomAssistant_Setup.exe C:\Users\Marcel\AppData\Local\Temp\nitro_reader3_64.exe C:\Users\Marcel\AppData\Local\Temp\optprosetup.exe C:\Users\Marcel\AppData\Local\Temp\pkeyui.exe C:\Users\Marcel\AppData\Local\Temp\Q-Dir_uninstall.exe C:\Users\Marcel\AppData\Local\Temp\Quarantine.exe C:\Users\Marcel\AppData\Local\Temp\safepstbackup_1_00.exe C:\Users\Marcel\AppData\Local\Temp\SamsungAPInstaller_1412143055024.exe C:\Users\Marcel\AppData\Local\Temp\ScreenpressoUpd.exe C:\Users\Marcel\AppData\Local\Temp\vcredist_x64.exe C:\Users\Marcel\AppData\Local\Temp\wabk.exe C:\Users\Marcel\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-14 12:26 ==================== End Of Log ============================ |
18.10.2014, 09:54 | #22 |
| Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol hi Schrauber habe nun alle suspekten files gelöscht, nachfolgend nochmals frst.txt Gruss sugus666 FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-10-2014 Ran by Marcel (administrator) on SUGUS on 18-10-2014 10:51:21 Running from F:\90 Daten Systemordner\Downloads_sys Loaded Profiles: Marcel & (Available profiles: Marcel & Administrator) Platform: Windows 8.1 (X64) OS Language: Englisch (Vereinigte Staaten) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe (Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (CrypKey (Canada) Ltd.) C:\Windows\System32\Crypserv.exe (Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe (Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe (Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe (FileZilla Project) C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe (PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe (Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe (Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe () C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe (Learnpulse) C:\Users\Marcel\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe (Docking Station) C:\Program Files (x86)\Lenovo\USB3.0 Dock\igpxtskmgn64win8.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Nenad Hrg (SoftwareOK.com)) C:\Program Files\Q-Dir\Q-Dir.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\livecomm.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13656792 2013-10-04] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1353432 2013-09-26] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\windows\system32\DptfPolicyLpmServiceHelper.exe [111976 2013-08-02] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM\...\Run: [Yoga PhoneCompanion] => C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe [844304 2014-03-28] (Lenovo) HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-03-28] () HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [59923440 2014-03-28] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2014-03-28] (Lenovo(beijing) Limited) HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [607584 2014-09-29] (Copyright 2013 SAMSUNG) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5595848 2014-09-22] (ESET) HKLM-x32\...\Run: [Yoga Picks] => C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe [119280 2014-01-06] (Lenovo) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [BrMfcWnd] => C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.) HKLM-x32\...\Run: [ControlCenter3] => C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.) HKLM-x32\...\Run: [My Swisscom Assistant] => C:\Program Files (x86)\Swisscom\My Swisscom Assistant\MySwisscomAssistant_Launcher.exe [7503792 2014-02-27] (Swisscom (Schweiz) AG) HKLM-x32\...\Run: [FileZilla Server Interface] => C:\Program Files (x86)\FileZilla Server\FileZilla Server Interface.exe [2322944 2014-04-08] (FileZilla Project) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-10-10] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [Screenpresso] => C:\Users\Marcel\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe [10983952 2014-09-22] (Learnpulse) HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [AshSnap] => C:\Program Files (x86)\Ashampoo\Ashampoo Snap 6\ashsnap.exe HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [msnmsgr] => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background HKU\S-1-5-21-3121602427-3534730855-1075997385-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [784392 2014-05-29] (Sandboxie Holdings, LLC) HKU\S-1-5-21-3121602427-3534730855-1075997385-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Screenpresso] => C:\Users\Marcel\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe [10983952 2014-09-22] (Learnpulse) HKU\S-1-5-21-3121602427-3534730855-1075997385-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AshSnap] => C:\Program Files (x86)\Ashampoo\Ashampoo Snap 6\ashsnap.exe HKU\S-1-5-21-3121602427-3534730855-1075997385-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [msnmsgr] => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background HKU\S-1-5-21-3121602427-3534730855-1075997385-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [784392 2014-05-29] (Sandboxie Holdings, LLC) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\igpxtskmgn.lnk ShortcutTarget: igpxtskmgn.lnk -> C:\Program Files (x86)\Lenovo\USB3.0 Dock\igpxtskmgn64win8.exe (Docking Station) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) Startup: C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Startup: C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\start.bat () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - {72A5F580-1FA0-4C34-B0EF-61D4BC34A5E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB SearchScopes: HKLM-x32 - {72A5F580-1FA0-4C34-B0EF-61D4BC34A5E0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB SearchScopes: HKCU - {72A5F580-1FA0-4C34-B0EF-61D4BC34A5E0} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {A6616B31-4860-41E2-98E3-CA7649AF172F} file:///E:/00%20A%20Temp/001%20USB%20DOking/launch.ocx Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - No File Handler-x32: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default FF SelectedSearchEngine: Google FF Homepage: https://www.google.ch/?gfe_rd=cr&ei=ochAVKyvLYuH8Qe04oCYBQ&gws_rd=ssl FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll () FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\searchplugins\google-maps.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira Browser Safety - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\abs@avira.com [2014-09-30] FF Extension: Xmarks - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\foxmarks@kei.com [2014-09-17] FF Extension: My Swisscom Assistant - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\{6A6114A5-EEF5-45F4-BCD1-B00A7B33E04B} [2014-05-15] FF Extension: Cliqz Beta - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\cliqz@cliqz.com.xpi [2014-10-15] FF Extension: Tab Mix Plus - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-09-30] FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com [2014-04-29] FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com [2014-04-29] FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox [2014-09-06] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-10-10] FF HKCU\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\kwtr2tzx.default\extensions\cliqz@cliqz.com Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.google.com/" CHR Profile: C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-10] CHR Extension: (Google Docs) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-10] CHR Extension: (Google Drive) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-10] CHR Extension: (YouTube) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-10] CHR Extension: (Google-Suche) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-10] CHR Extension: (Google Tabellen) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-10] CHR Extension: (Avira Browser Safety) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-10-10] CHR Extension: (avast! Online Security) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-10-10] CHR Extension: (Google Wallet) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-10] CHR Extension: (Google Mail) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-10] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-10] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) [File not signed] R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-10] (AVAST Software) R2 Crypkey License; C:\windows\system32\crypserv.exe [122880 2008-05-08] (CrypKey (Canada) Ltd.) [File not signed] R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [9281840 2013-10-11] (DisplayLink Corp.) R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [115632 2013-08-02] (Intel Corporation) R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116656 2013-08-02] (Intel Corporation) R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [148688 2013-08-02] (Intel Corporation) R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [124880 2013-08-02] (Intel Corporation) R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1350112 2014-09-16] (ESET) R2 FileZilla Server; C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe [627712 2014-04-08] (FileZilla Project) [File not signed] S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-09-04] (Freemake) [File not signed] R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-05-22] (Ellora Assets Corp.) [File not signed] R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation) R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-19] (Intel Corporation) R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-08-02] () S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation) S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation) R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-08-18] (LENOVO INCORPORATED.) S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation) R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-03-28] (Lenovo) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation) R2 NitroReaderDriverReadSpool3; C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [230416 2013-07-26] (Nitro PDF Software) R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2014-01-08] (PointGrab LTD) R2 PhoneCompanionPusher; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe [249872 2014-03-28] (Lenovo) S3 PhoneCompanionVap; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionVap.exe [328720 2014-03-28] (Lenovo) R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] () R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [288472 2013-09-13] (Realtek Semiconductor) R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [616288 2014-09-29] (Copyright 2013 SAMSUNG) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [174088 2014-05-29] (Sandboxie Holdings, LLC) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia) S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation) S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation) R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2014-03-28] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [34576 2014-03-28] (Lenovo) R2 YogaPicks.AppService; C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe [19440 2014-01-07] () S3 McAWFwk; c:\PROGRA~1\COMMON~1\mcafee\actwiz\mcawfwk.exe [X] S4 McOobeSv2; "C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-10-10] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-10-10] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-10-10] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-10-10] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-10-10] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-10-10] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-10-10] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-10-10] () S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-18] (ASIX Electronics Corp.) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-23] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-09-06] (Motorola Solutions, Inc.) R3 DisplayLinkUsbIo_x64; C:\Windows\System32\drivers\DisplayLinkUsbIo_x64_7.4.48800.0.sys [44944 2013-10-07] () R3 dlcdcncm6_x64; C:\Windows\system32\DRIVERS\dlcdcncm6_x64.sys [80688 2013-10-11] (DisplayLink Corp.) R3 dlusbaudio; C:\Windows\system32\DRIVERS\dlusbaudio_x64.sys [203152 2013-10-11] (DisplayLink Corp.) R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [114680 2013-08-02] (Intel Corporation) R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [287160 2013-08-02] (Intel Corporation) R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [494272 2013-08-02] (Intel Corporation) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-08-18] (ESET) S0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [241368 2014-08-18] (ESET) R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [169280 2014-08-18] (ESET) R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [158968 2014-09-18] (ESET) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [118728 2013-09-19] (Intel Corporation) R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21408 2013-08-02] () R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21920 2013-08-02] () R3 INETMON; C:\windows\System32\Drivers\INETMON.sys [29088 2013-08-02] () R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-08-02] () R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-10-18] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation) R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3589600 2013-09-19] (Intel Corporation) S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation) R1 NetworkX; C:\Windows\system32\ckldrv.sys [28664 2008-03-17] () R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia) S3 qzozigbn; C:\Windows\System32\Drivers\qzozigbn.sys [423240 2014-05-07] (AVAST Software) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [185352 2014-05-29] (Sandboxie Holdings, LLC) R3 SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation) R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation) S3 sidtohjv; C:\Windows\System32\Drivers\sidtohjv.sys [423240 2014-05-04] (AVAST Software) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-29] (Synaptics Incorporated) R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1527928 2013-08-23] (Sunplus) S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2014-05-07] () S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink) S3 PCASp60; System32\Drivers\PCASp60.sys [X] S3 VBoxNetFlt; \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys [X] S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X] S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-18 10:07 - 2014-10-18 10:07 - 00000000 ____D () C:\Users\Marcel\AppData\Local\ESET 2014-10-18 10:04 - 2014-10-18 10:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET 2014-10-18 10:04 - 2014-10-18 10:04 - 00000000 ____D () C:\ProgramData\ESET 2014-10-18 10:04 - 2014-10-18 10:04 - 00000000 ____D () C:\Program Files\ESET 2014-10-18 08:06 - 2014-10-18 08:06 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-10-15 14:43 - 2014-10-15 14:43 - 00000000 ___RD () C:\Sandbox 2014-10-15 14:40 - 2014-10-18 10:05 - 00001704 _____ () C:\windows\Sandboxie.ini 2014-10-15 14:40 - 2014-10-15 14:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie 2014-10-15 14:39 - 2014-10-15 14:39 - 00000000 ____D () C:\Program Files\Sandboxie 2014-10-15 11:32 - 2014-10-18 08:00 - 00000435 _____ () C:\windows\system32\Drivers\etc\hosts.ics 2014-10-15 11:23 - 2014-10-15 11:23 - 00000000 ____D () C:\Users\Marcel\VirtualBox VMs 2014-10-15 11:22 - 2014-10-15 12:25 - 00000000 ____D () C:\Users\Marcel\.VirtualBox 2014-10-15 11:22 - 2014-10-11 13:29 - 00917112 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxDrv.sys 2014-10-15 11:22 - 2014-10-11 13:27 - 00129168 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxUSBMon.sys 2014-10-15 11:21 - 2014-10-15 11:21 - 00000000 ____D () C:\Program Files\Oracle 2014-10-15 09:51 - 2014-10-10 00:16 - 00678400 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-10-15 09:51 - 2014-10-09 00:09 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll 2014-10-15 09:51 - 2014-09-19 03:24 - 00527360 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-10-15 09:51 - 2014-09-13 08:02 - 02779648 _____ (Microsoft Corporation) C:\windows\system32\msi.dll 2014-10-15 09:51 - 2014-09-13 07:30 - 03117568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll 2014-10-15 09:51 - 2014-09-04 02:10 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\winbici.dll 2014-10-15 09:51 - 2014-09-04 01:57 - 00921600 _____ (Microsoft Corporation) C:\windows\system32\MrmCoreR.dll 2014-10-15 09:51 - 2014-09-04 01:49 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\MrmCoreR.dll 2014-10-15 09:51 - 2014-08-29 03:58 - 00109568 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll 2014-10-15 09:51 - 2014-08-29 01:56 - 02646016 _____ (Microsoft Corporation) C:\windows\system32\authui.dll 2014-10-15 09:51 - 2014-08-29 01:47 - 02321920 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll 2014-10-15 08:38 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\windows\SysWOW64\dhRichClient3.dll 2014-10-15 08:38 - 2011-03-25 20:42 - 00338432 _____ () C:\windows\SysWOW64\sqlite36_engine.dll 2014-10-15 08:06 - 2014-09-28 00:25 - 04183040 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2014-10-15 08:06 - 2014-09-26 00:50 - 13619200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-10-15 08:06 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-10-15 08:06 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-10-15 08:06 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-10-15 08:06 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-10-15 08:06 - 2014-09-26 00:31 - 02108416 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-10-15 08:06 - 2014-09-19 04:25 - 23631360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-10-15 08:06 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-10-15 08:06 - 2014-09-19 03:41 - 02796032 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-10-15 08:06 - 2014-09-19 03:40 - 00547328 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-10-15 08:06 - 2014-09-19 03:38 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2014-10-15 08:06 - 2014-09-19 03:36 - 05829632 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-10-15 08:06 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-10-15 08:06 - 2014-09-19 03:25 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-10-15 08:06 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-10-15 08:06 - 2014-09-19 03:00 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-10-15 08:06 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2014-10-15 08:06 - 2014-09-19 02:58 - 00289280 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-10-15 08:06 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-10-15 08:06 - 2014-09-19 02:42 - 00731136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-10-15 08:06 - 2014-09-19 02:42 - 00710656 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-10-15 08:06 - 2014-09-19 02:42 - 00363008 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-10-15 08:06 - 2014-09-19 02:33 - 02309632 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-10-15 08:06 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-10-15 08:06 - 2014-09-19 02:20 - 00315904 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2014-10-15 08:06 - 2014-09-19 02:14 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-10-15 08:06 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-10-15 08:06 - 2014-09-19 01:59 - 00775168 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-10-15 08:06 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-10-15 08:06 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-10-15 08:05 - 2014-09-08 05:15 - 00054752 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe 2014-10-15 08:05 - 2014-09-08 03:46 - 00059904 _____ (Microsoft Corporation) C:\windows\system32\wups.dll 2014-10-15 08:05 - 2014-09-08 03:46 - 00050688 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll 2014-10-15 08:05 - 2014-09-08 02:08 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe 2014-10-15 08:05 - 2014-09-08 02:07 - 00137728 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll 2014-10-15 08:05 - 2014-09-08 02:05 - 03448320 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll 2014-10-15 08:05 - 2014-09-08 02:04 - 00388608 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll 2014-10-15 08:05 - 2014-09-08 02:04 - 00093696 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll 2014-10-15 08:05 - 2014-09-08 02:03 - 01702400 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll 2014-10-15 08:05 - 2014-09-08 02:03 - 00839680 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll 2014-10-15 08:05 - 2014-09-08 01:59 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll 2014-10-15 08:05 - 2014-09-08 01:59 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe 2014-10-15 08:05 - 2014-09-08 01:56 - 00672256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll 2014-10-15 08:05 - 2014-09-08 01:56 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll 2014-10-15 08:04 - 2014-09-13 08:29 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\packager.dll 2014-10-15 08:04 - 2014-09-13 07:49 - 00068608 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll 2014-10-15 08:04 - 2014-09-04 02:12 - 00590336 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll 2014-10-15 08:04 - 2014-09-04 02:01 - 00514048 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll 2014-10-15 08:04 - 2014-08-16 06:08 - 21195616 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll 2014-10-15 08:04 - 2014-08-16 06:08 - 01507648 _____ (Microsoft Corporation) C:\windows\system32\propsys.dll 2014-10-15 08:04 - 2014-08-16 06:01 - 01710184 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll 2014-10-15 08:04 - 2014-08-16 05:58 - 01112512 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll 2014-10-15 08:04 - 2014-08-16 05:57 - 02498880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2014-10-15 08:04 - 2014-08-16 05:57 - 00428864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS 2014-10-15 08:04 - 2014-08-16 05:16 - 18722600 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll 2014-10-15 08:04 - 2014-08-16 05:16 - 01205976 _____ (Microsoft Corporation) C:\windows\SysWOW64\propsys.dll 2014-10-15 08:04 - 2014-08-16 05:03 - 01467384 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll 2014-10-15 08:04 - 2014-08-16 03:31 - 00838144 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll 2014-10-15 08:04 - 2014-08-16 03:04 - 00359424 _____ (Microsoft Corporation) C:\windows\system32\Wldap32.dll 2014-10-15 08:04 - 2014-08-16 02:58 - 00287744 _____ (Microsoft Corporation) C:\windows\system32\SystemEventsBrokerServer.dll 2014-10-15 08:04 - 2014-08-16 02:53 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\httpprxm.dll 2014-10-15 08:04 - 2014-08-16 02:46 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\ProximityService.dll 2014-10-15 08:04 - 2014-08-16 02:45 - 00267776 _____ (Microsoft Corporation) C:\windows\system32\bisrv.dll 2014-10-15 08:04 - 2014-08-16 02:43 - 00321024 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wldap32.dll 2014-10-15 08:04 - 2014-08-16 02:43 - 00075776 _____ (Microsoft Corporation) C:\windows\system32\adhsvc.dll 2014-10-15 08:04 - 2014-08-16 02:31 - 00914432 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll 2014-10-15 08:04 - 2014-08-16 02:31 - 00286208 _____ (Microsoft Corporation) C:\windows\system32\pcsvDevice.dll 2014-10-15 08:04 - 2014-08-16 02:29 - 00249344 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-10-15 08:04 - 2014-08-16 02:23 - 01106432 _____ (Microsoft Corporation) C:\windows\system32\SearchFolder.dll 2014-10-15 08:04 - 2014-08-16 02:22 - 00717824 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveTelemetry.dll 2014-10-15 08:04 - 2014-08-16 02:22 - 00286208 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveShell.dll 2014-10-15 08:04 - 2014-08-16 02:19 - 00189952 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-10-15 08:04 - 2014-08-16 02:18 - 04758528 _____ (Microsoft Corporation) C:\windows\system32\SyncEngine.dll 2014-10-15 08:04 - 2014-08-16 02:17 - 08757760 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Search.dll 2014-10-15 08:04 - 2014-08-16 02:14 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\SkyDriveShell.dll 2014-10-15 08:04 - 2014-08-16 02:13 - 06649344 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll 2014-10-15 08:04 - 2014-08-16 02:13 - 05902848 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Search.dll 2014-10-15 08:04 - 2014-08-16 02:13 - 00840192 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFolder.dll 2014-10-15 08:04 - 2014-08-16 02:11 - 00920064 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll 2014-10-15 08:04 - 2014-08-16 02:10 - 01120768 _____ (Microsoft Corporation) C:\windows\system32\SkyDrive.exe 2014-10-15 08:04 - 2014-08-16 02:08 - 05777408 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll 2014-10-15 08:04 - 2014-08-16 02:07 - 00756224 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll 2014-10-15 08:04 - 2014-08-01 01:22 - 00388729 _____ () C:\windows\system32\ApnDatabase.xml 2014-10-14 18:55 - 2014-10-15 10:02 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\VMware 2014-10-14 18:55 - 2014-10-14 19:51 - 00000000 ____D () C:\Users\Marcel\AppData\Local\VMware 2014-10-14 18:53 - 2014-10-15 10:02 - 00000000 ____D () C:\ProgramData\VMware 2014-10-14 11:31 - 2014-10-14 11:31 - 00001126 _____ () C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\join.me.lnk 2014-10-14 11:31 - 2014-10-14 11:31 - 00000000 ____D () C:\Users\Marcel\AppData\Local\LogMeIn 2014-10-14 11:31 - 2014-10-14 11:31 - 00000000 ____D () C:\ProgramData\LogMeIn 2014-10-14 11:26 - 2014-10-14 11:31 - 00000000 ____D () C:\Users\Marcel\AppData\Local\join.me 2014-10-13 10:07 - 2014-10-13 10:07 - 00319912 _____ (Oracle Corporation) C:\windows\system32\javaws.exe 2014-10-13 10:07 - 2014-10-13 10:07 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe 2014-10-13 10:07 - 2014-10-13 10:07 - 00189352 _____ (Oracle Corporation) C:\windows\system32\java.exe 2014-10-13 10:07 - 2014-10-13 10:07 - 00111016 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll 2014-10-13 08:41 - 2014-10-17 13:48 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-13 08:41 - 2014-10-17 13:46 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll 2014-10-13 08:41 - 2014-10-17 13:46 - 00000000 ____D () C:\Program Files (x86)\Java 2014-10-13 08:41 - 2014-10-13 08:41 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe 2014-10-13 08:41 - 2014-10-13 08:41 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe 2014-10-13 08:41 - 2014-10-13 08:41 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe 2014-10-13 08:33 - 2014-10-13 08:33 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Oracle 2014-10-11 13:27 - 2014-10-11 13:27 - 00142528 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxNetAdp.sys 2014-10-10 07:34 - 2014-10-10 07:34 - 00001993 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-10-10 07:34 - 2014-10-10 07:34 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\AVAST Software 2014-10-10 07:34 - 2014-10-10 07:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2014-10-10 07:33 - 2014-10-10 07:34 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update 2014-10-10 07:33 - 2014-10-10 07:33 - 01041168 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00427360 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00307344 _____ (AVAST Software) C:\windows\system32\aswBoot.exe 2014-10-10 07:33 - 2014-10-10 07:33 - 00224896 _____ () C:\windows\system32\Drivers\aswVmm.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00093568 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00092008 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00079184 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00065776 _____ () C:\windows\system32\Drivers\aswRvrt.sys 2014-10-10 07:33 - 2014-10-10 07:33 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-10-10 07:33 - 2014-10-10 07:33 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys 2014-10-10 07:32 - 2014-10-10 07:32 - 00000000 ____D () C:\Program Files\AVAST Software 2014-10-10 00:16 - 2014-10-10 00:16 - 00001716 _____ () C:\Users\Marcel\Desktop\JRT.txt 2014-10-10 00:14 - 2014-10-10 00:14 - 00000000 ____D () C:\windows\ERUNT 2014-10-09 23:27 - 2014-10-18 08:57 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-09 23:26 - 2014-10-09 23:26 - 00001129 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-09 23:26 - 2014-10-09 23:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-09 23:26 - 2014-10-09 23:26 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-09 23:26 - 2014-10-09 23:26 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-10-09 23:26 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-10-09 23:26 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-10-09 23:26 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-10-09 23:20 - 2014-10-09 23:20 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-10-08 17:30 - 2014-10-18 10:51 - 00000000 ____D () C:\FRST 2014-10-03 11:30 - 2014-10-03 17:10 - 00000000 ____D () C:\Program Files\Q-Dir 2014-10-03 11:19 - 2014-10-03 11:19 - 00000000 ____D () C:\Users\Marcel\AppData\Local\GHISLER 2014-10-03 11:17 - 2014-10-03 11:17 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\GHISLER 2014-10-03 09:03 - 2014-10-03 09:18 - 00000004 _____ () C:\windows\vx86036.dat 2014-10-03 09:03 - 2014-10-03 09:13 - 00000260 _____ () C:\CKINFO.TXT 2014-10-03 09:03 - 2014-10-03 09:03 - 00000000 ____D () C:\ProgramData\CrypKey 2014-10-03 09:02 - 2014-10-15 13:44 - 00036047 _____ () C:\windows\errord.log 2014-10-03 09:02 - 2014-10-15 13:44 - 00000868 _____ () C:\windows\error.log 2014-10-03 09:02 - 2014-10-03 09:18 - 00003360 _____ () C:\windows\system32\esnecil.ind 2014-10-03 09:02 - 2014-10-03 09:18 - 00000127 _____ () C:\windows\Crypkey.ini 2014-10-03 09:02 - 2014-10-03 09:18 - 00000000 ____D () C:\Program Files\Stellar Phoenix Outlook PST Repair 2014-10-03 09:02 - 2008-05-08 01:29 - 00122880 _____ (CrypKey (Canada) Ltd.) C:\windows\system32\Crypserv.exe 2014-10-03 09:02 - 2008-03-17 19:12 - 00028664 _____ () C:\windows\system32\Ckldrv.sys 2014-10-03 09:02 - 1999-06-18 22:49 - 00165888 _____ (Kenonic Controls) C:\windows\Ckconfig.exe 2014-10-03 09:02 - 1996-05-03 18:21 - 00027648 ____R () C:\windows\Setup_ck.exe 2014-10-03 09:02 - 1996-05-03 16:36 - 00018432 _____ () C:\windows\Setup_ck.dll 2014-10-03 09:02 - 1995-07-04 19:33 - 00011776 _____ () C:\windows\Ckrfresh.exe 2014-10-02 18:42 - 2014-10-02 18:42 - 00003974 _____ () C:\windows\System32\Tasks\4Team updater 2014-10-02 18:41 - 2014-10-03 16:56 - 00000000 ____D () C:\Program Files (x86)\4Team Corporation 2014-10-02 18:41 - 2014-10-02 18:41 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\4Team 2014-10-02 18:41 - 2014-10-02 18:41 - 00000000 ____D () C:\Users\Marcel\AppData\Local\IsolatedStorage 2014-10-02 09:40 - 2014-10-02 09:40 - 00000000 ____D () C:\Neuer Ordner 2014-10-01 09:42 - 2014-10-09 12:03 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\FileZilla 2014-09-26 15:41 - 2014-09-30 08:40 - 00000000 ____D () C:\Users\Marcel\Tracing 2014-09-26 15:40 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_7.dll 2014-09-26 15:40 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\windows\system32\XAudio2_7.dll 2014-09-26 15:40 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\windows\system32\XAPOFX1_5.dll 2014-09-26 15:40 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_5.dll 2014-09-26 15:40 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_43.dll 2014-09-26 15:40 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_43.dll 2014-09-26 15:40 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\windows\system32\d3dx11_43.dll 2014-09-26 15:40 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx11_43.dll 2014-09-26 15:39 - 2014-09-26 15:39 - 00002242 _____ () C:\Users\Marcel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2014-09-26 15:39 - 2014-09-26 15:39 - 00002147 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2014-09-26 15:39 - 2014-09-26 15:39 - 00002147 _____ () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk 2014-09-26 15:39 - 2014-09-26 15:39 - 00000196 _____ () C:\windows\DirectX.log 2014-09-26 15:39 - 2014-09-26 15:39 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive 2014-09-26 15:39 - 2014-09-26 15:39 - 00000000 ____D () C:\Program Files (x86)\Microsoft SkyDrive 2014-09-26 15:39 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_42.dll 2014-09-26 15:39 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_42.dll 2014-09-26 15:39 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\windows\system32\d3dx9_32.dll 2014-09-26 15:39 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_32.dll 2014-09-26 15:38 - 2014-09-30 08:54 - 00000000 ____D () C:\Users\Marcel\AppData\Local\Windows Live 2014-09-25 13:13 - 2014-10-08 16:50 - 00003718 _____ () C:\windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 2014-09-25 13:13 - 2014-09-25 13:13 - 00003476 _____ () C:\windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon 2014-09-25 09:57 - 2014-09-25 09:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-24 17:16 - 2014-09-24 17:16 - 00000000 ____D () C:\Users\Marcel\AppData\Local\FreemakeVideoDownloader 2014-09-18 12:38 - 2014-09-18 12:38 - 00158968 _____ (ESET) C:\windows\system32\Drivers\epfwwfpr.sys ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-18 10:36 - 2014-03-28 08:34 - 02052464 _____ () C:\windows\WindowsUpdate.log 2014-10-18 10:02 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\sru 2014-10-18 09:56 - 2014-04-29 09:31 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-10-18 09:39 - 2014-04-22 19:56 - 00000432 _____ () C:\windows\BRWMARK.INI 2014-10-18 09:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\rescache 2014-10-18 08:03 - 2014-04-22 15:38 - 00003922 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{F5291F67-CB16-4602-A1AA-B673A0FBD3F7} 2014-10-18 08:01 - 2014-04-22 15:14 - 00000000 ___DO () C:\Users\Marcel\SkyDrive 2014-10-17 23:08 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\AppReadiness 2014-10-17 23:07 - 2014-03-28 08:55 - 00010752 _____ () C:\windows\system32\VfService.trf 2014-10-17 17:50 - 2014-04-30 12:43 - 00000000 ____D () C:\Users\Marcel\AppData\Local\CrashDumps 2014-10-17 13:53 - 2014-04-22 15:13 - 00003600 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3121602427-3534730855-1075997385-1001 2014-10-17 13:46 - 2014-04-22 16:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-17 13:19 - 2014-04-28 20:40 - 00000000 ____D () C:\windows\system32\MRT 2014-10-17 13:16 - 2014-04-28 20:40 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-10-17 10:57 - 2014-05-05 11:47 - 00000000 ____D () C:\xampp 2014-10-16 18:24 - 2014-04-22 19:41 - 00000000 ____D () C:\ProgramData\firebird 2014-10-16 13:35 - 2014-06-12 07:50 - 00011082 _____ () C:\windows\SecuniaPackage.log 2014-10-16 13:35 - 2014-04-29 09:31 - 00003718 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-10-16 08:20 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\NDF 2014-10-15 14:42 - 2014-04-20 09:09 - 00000000 ____D () C:\MADProg 2014-10-15 14:42 - 2014-04-20 09:08 - 00000000 ____D () C:\MADDaten 2014-10-15 13:49 - 2014-03-28 09:27 - 00955470 _____ () C:\windows\system32\perfh00C.dat 2014-10-15 13:49 - 2014-03-28 09:27 - 00256758 _____ () C:\windows\system32\perfc00C.dat 2014-10-15 13:49 - 2014-03-28 09:24 - 01046540 _____ () C:\windows\system32\perfh007.dat 2014-10-15 13:49 - 2014-03-28 09:24 - 00258988 _____ () C:\windows\system32\perfc007.dat 2014-10-15 13:49 - 2013-10-07 20:27 - 00005934 _____ () C:\windows\system32\PerfStringBackup.INI 2014-10-15 13:44 - 2013-08-22 16:46 - 00034703 _____ () C:\windows\setupact.log 2014-10-15 13:44 - 2013-08-22 16:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-10-15 13:44 - 2013-08-22 16:44 - 00499656 _____ () C:\windows\system32\FNTCACHE.DAT 2014-10-15 13:34 - 2013-08-22 17:36 - 00000000 ___RD () C:\windows\ToastData 2014-10-15 13:34 - 2013-08-22 15:25 - 00524288 ___SH () C:\windows\system32\config\BBI 2014-10-15 13:33 - 2014-07-09 18:28 - 00000000 ___SD () C:\windows\system32\CompatTel 2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\WinStore 2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\MediaViewer 2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\FileManager 2014-10-15 13:33 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\Camera 2014-10-15 12:32 - 2014-04-22 17:16 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-10-15 12:32 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-10-15 12:32 - 2013-08-22 17:20 - 00000000 ____D () C:\windows\CbsTemp 2014-10-15 11:23 - 2014-04-22 15:08 - 00000000 ____D () C:\Users\Marcel 2014-10-15 11:10 - 2014-04-29 10:05 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\vlc 2014-10-14 18:54 - 2014-03-28 08:43 - 00006124 _____ () C:\windows\SysWOW64\PerfStringBackup.INI 2014-10-13 10:07 - 2013-10-07 20:23 - 00152266 _____ () C:\windows\PFRO.log 2014-10-10 07:37 - 2014-04-22 16:35 - 00000000 ____D () C:\Program Files (x86)\Google 2014-10-10 07:34 - 2014-04-22 16:35 - 00000000 ____D () C:\Users\Marcel\AppData\Local\Google 2014-10-10 00:38 - 2014-04-22 16:42 - 00022391 _____ () C:\windows\Q-Dir.ini 2014-10-10 00:31 - 2014-05-04 19:20 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-10-10 00:31 - 2014-03-28 08:43 - 00000000 ____D () C:\ProgramData\Package Cache 2014-10-10 00:09 - 2013-08-22 15:25 - 00262144 ___SH () C:\windows\system32\config\ELAM 2014-10-09 23:43 - 2014-05-07 18:53 - 00000000 ____D () C:\Users\Administrator 2014-10-08 16:42 - 2014-04-22 15:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-10-05 13:23 - 2014-06-19 14:39 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\SmartDraw 2014-10-03 11:32 - 2014-04-22 16:42 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Q-Dir 2014-10-02 18:40 - 2014-03-28 08:55 - 00000000 ____D () C:\ProgramData\Downloaded Installations 2014-10-01 09:43 - 2014-04-22 16:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2014-10-01 09:43 - 2014-04-22 16:35 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client 2014-10-01 07:58 - 2014-08-30 09:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2014-09-30 00:45 - 2013-08-22 17:38 - 00706016 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-09-30 00:45 - 2013-08-22 17:38 - 00105440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-09-25 17:44 - 2014-04-22 17:41 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Nitro PDF 2014-09-25 13:13 - 2014-03-28 08:43 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2014-09-22 09:07 - 2014-04-22 16:37 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-09-22 08:42 - 2014-05-04 18:19 - 00278152 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe Some content of TEMP: ==================== C:\Users\Administrator\AppData\Local\Temp\avgnt.exe C:\Users\Marcel\AppData\Local\Temp\avgnt.exe C:\Users\Marcel\AppData\Local\Temp\FreemakeVideoDownloader_3.6.4.3.exe C:\Users\Marcel\AppData\Local\Temp\FreemakeVideoDownloader_3.7.0.1.exe C:\Users\Marcel\AppData\Local\Temp\gkey.exe C:\Users\Marcel\AppData\Local\Temp\i4jdel0.exe C:\Users\Marcel\AppData\Local\Temp\InstHelper.exe C:\Users\Marcel\AppData\Local\Temp\K-Lite_Codec_Pack_Basic.exe C:\Users\Marcel\AppData\Local\Temp\ms.exe C:\Users\Marcel\AppData\Local\Temp\msvcr71.dll C:\Users\Marcel\AppData\Local\Temp\MySwisscomAssistant_Setup.exe C:\Users\Marcel\AppData\Local\Temp\nitro_reader3_64.exe C:\Users\Marcel\AppData\Local\Temp\pkeyui.exe C:\Users\Marcel\AppData\Local\Temp\Q-Dir_uninstall.exe C:\Users\Marcel\AppData\Local\Temp\Quarantine.exe C:\Users\Marcel\AppData\Local\Temp\safepstbackup_1_00.exe C:\Users\Marcel\AppData\Local\Temp\SamsungAPInstaller_1412143055024.exe C:\Users\Marcel\AppData\Local\Temp\ScreenpressoUpd.exe C:\Users\Marcel\AppData\Local\Temp\vcredist_x64.exe C:\Users\Marcel\AppData\Local\Temp\wabk.exe C:\Users\Marcel\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-14 12:26 ==================== End Of Log ============================ |
18.10.2014, 16:20 | #23 |
/// the machine /// TB-Ausbilder | Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol Schaut gut aus. Bestehen noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.10.2014, 16:49 | #24 |
| Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol keine Probleme, nochmals Danke!!! |
20.10.2014, 10:57 | #25 |
/// the machine /// TB-Ausbilder | Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.10.2014, 15:29 | #26 |
| Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol hi Schrauber ist alles erledigt - muss nur noch Spende auslösen Sugus666 |
21.10.2014, 11:47 | #27 |
/// the machine /// TB-Ausbilder | Bluescren - Polizeiwarnung - Ultrabook startet nur noch bis Lenovo-Symbol Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |