|
Log-Analyse und Auswertung: PUP.Optional.Squeaky.A durch MalewareBytes auf dem Rechner gefundenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
28.02.2015, 16:16 | #1 |
| PUP.Optional.Squeaky.A durch MalewareBytes auf dem Rechner gefunden Hallo zusammen, leider schon wieder ein Fund. Malewarebytes hat PUP.Optional.Squeaky.A gefunden. Diesen natürlich in Quarantäne geschickt und folgendes Logfile gesichert: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 28.02.2015 Suchlauf-Zeit: 15:07:30 Logdatei: MalewareBytes.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2015.02.28.03 Rootkit Datenbank: v2015.02.25.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Jeanette Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 459237 Verstrichene Zeit: 36 Min, 43 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 1 PUP.Optional.Squeaky.A, HKU\S-1-5-21-884760279-2294033944-2841522718-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Squeaky, , [6a6932f1f39774c24f70c7d58182c937], Registrierungswerte: 0 (Keine schädliche Elemente erkannt) Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 0 (Keine schädliche Elemente erkannt) Dateien: 0 (Keine schädliche Elemente erkannt) Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) Viele Grüße, ennachen Und noch ein frisches FRST: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-02-2015 01 Ran by Jeanette (administrator) on KASSIOPEIA on 28-02-2015 16:04:51 Running from C:\Users\Jeanette\Desktop Loaded Profiles: Jeanette & (Available profiles: Jeanette & Christoph & Finja) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\mDNSResponder.exe (Lenovo) C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\tunmgr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\BbDevMgr.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Intel Corporation) C:\Windows\System32\GfxUI.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynBtnAsst.exe (Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe () C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Dropbox, Inc.) C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (Lenovo) C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlideNavVDM.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe (Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\RIMBBLaunchAgent.exe (Lenovo) C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe (Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\PeerManager.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Mozilla Corporation) C:\Program Files (x86)\Internet\Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11725928 2010-12-23] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2186856 2010-12-10] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2101032 2010-05-03] (Synaptics Incorporated) HKLM\...\Run: [SynBtnAsst] => C:\Program Files\Synaptics\SynTP\SynBtnAsst.exe [54568 2010-05-03] (Synaptics Incorporated) HKLM\...\Run: [OnekeyStudio] => C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [789920 2011-05-17] (Lenovo) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4448704 2010-03-11] (Lenovo(beijing) Limited) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [7056832 2010-03-11] (Lenovo (Beijing) Limited) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-06-29] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [MuteSync] => C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe [336384 2009-12-28] (Lenovo) HKLM-x32\...\Run: [Lenovo SplitScreen] => C:\Program Files\Lenovo\Lenovo SplitScreen\SplitScreen\AutoRunSpS.exe [778592 2010-06-23] (Lenovo) HKLM-x32\...\Run: [UCam_Menu] => c:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [YouCam Mirror Tray icon] => c:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167008 2010-02-03] (CyberLink Corp.) HKLM-x32\...\Run: [Lenovo SlideNav2] => C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlideNavVDM.exe [318400 2009-12-30] (Lenovo) HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [74752 2011-10-26] (Nullsoft, Inc.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [443408 2013-09-09] (Research In Motion Limited) HKLM-x32\...\Run: [RIM PeerManager] => C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe [4424704 2013-11-05] (Research In Motion Limited) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [703888 2013-06-19] (Cisco Systems, Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-11-24] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\ Malwarebytes Anti-Malware \mbamdor.exe [54072 2014-11-21] (Malwarebytes Corporation) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-884760279-2294033944-2841522718-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2014-10-14] (Microsoft Corporation) HKU\S-1-5-21-884760279-2294033944-2841522718-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [2874048 2015-02-19] (Valve Corporation) HKU\S-1-5-21-884760279-2294033944-2841522718-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2014-10-14] (Microsoft Corporation) HKU\S-1-5-21-884760279-2294033944-2841522718-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [2874048 2015-02-19] (Valve Corporation) HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [BlackBerryLink.exe] => C:\Program Files (x86)\Research In Motion\BlackBerry Link\BlackBerryLink.exe [1450000 2013-11-06] (Research In Motion) HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2014-10-14] (Microsoft Corporation) HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\MountPoints2: {ff52ffef-8099-11e0-b0f3-806e6f6e6963} - F:\setup.exe HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [BlackBerryLink.exe] => C:\Program Files (x86)\Research In Motion\BlackBerry Link\BlackBerryLink.exe [1450000 2013-11-06] (Research In Motion) HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2014-10-14] (Microsoft Corporation) HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {ff52ffef-8099-11e0-b0f3-806e6f6e6963} - F:\setup.exe HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\MountPoints2: {ff52ffef-8099-11e0-b0f3-806e6f6e6963} - F:\setup.exe HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {ff52ffef-8099-11e0-b0f3-806e6f6e6963} - F:\setup.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\REALTEK 11n USB Wireless LAN Utility.lnk ShortcutTarget: REALTEK 11n USB Wireless LAN Utility.lnk -> C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp.) Startup: C:\Users\Christoph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-884760279-2294033944-2841522718-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-884760279-2294033944-2841522718-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-884760279-2294033944-2841522718-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-884760279-2294033944-2841522718-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.msn.com HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.msn.com HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ URLSearchHook: HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File URLSearchHook: HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1000 -> URL hxxp://search.conduit.com/Results.aspx?ctid=CT3319434&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPBDE042E6-0BAD-4323-A6C5-2B2CAAB01454&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1000 -> SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1000 -> {94bd6970-1a83-41dc-9be5-bf50b3d0238f} URL = SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> URL hxxp://search.conduit.com/Results.aspx?ctid=CT3319434&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPBDE042E6-0BAD-4323-A6C5-2B2CAAB01454&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {94bd6970-1a83-41dc-9be5-bf50b3d0238f} URL = SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> DefaultScope {473ABF35-4666-4187-AA00-B7147C62A4B5} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {473ABF35-4666-4187-AA00-B7147C62A4B5} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {473ABF35-4666-4187-AA00-B7147C62A4B5} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {473ABF35-4666-4187-AA00-B7147C62A4B5} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox BHO: avast! Online Security -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll No File BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll No File Toolbar: HKLM-x32 - TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH) DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Jeanette\AppData\Roaming\Mozilla\Firefox\Profiles\3kpso6nv.default-1387541310027 FF DefaultSearchEngine: Google FF Homepage: www.google.de FF Keyword.URL: FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll () FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\TV\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @zylom.com/ZylomGamesPlayer -> C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll No File FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Christoph\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Christoph\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Extension: NoScript - C:\Users\Jeanette\AppData\Roaming\Mozilla\Firefox\Profiles\3kpso6nv.default-1387541310027\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-02-08] FF Extension: Adblock Plus - C:\Users\Jeanette\AppData\Roaming\Mozilla\Firefox\Profiles\3kpso6nv.default-1387541310027\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-08] FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012-01-09] FF HKU\S-1-5-21-884760279-2294033944-2841522718-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-03-03] FF HKU\S-1-5-21-884760279-2294033944-2841522718-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Internet\Firefox\firefox.exe Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - https://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG) R3 BlackBerry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [585728 2013-09-09] (Research In Motion Limited) [File not signed] R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [873248 2010-01-12] (Broadcom Corporation.) R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [File not signed] S3 IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-15] (Lenovo Group Limited) S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited) S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [575304 2009-11-17] (Lenovo Group Limited) S3 PS_MDP; C:\Program Files (x86)\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited) S2 ReadyComm.DirectRouter; C:\Program Files (x86)\Lenovo\ReadyComm\common\router.dll [103688 2009-07-15] (Lenovo Group Limited) R2 RIM MDNS; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe [389632 2013-11-05] (Apple Inc.) [File not signed] R2 RIM Tunnel Service; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe [1286656 2013-11-05] (Research In Motion Limited) [File not signed] R2 Slidebar Notifier Service; C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe [69568 2009-12-30] (Lenovo) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S1 acedrv07; C:\windows\system32\drivers\acedrv07.sys [125440 2013-01-13] () [File not signed] R1 acedrv09; C:\windows\system32\drivers\acedrv09.sys [134880 2014-06-06] () S3 AF15BDA; C:\Windows\System32\DRIVERS\AF15BDA.sys [368832 2009-11-05] (AfaTech ) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-11-24] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-11-24] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG) S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [79376 2009-07-16] (Lenovo) S3 ezplay; C:\Windows\System32\Drivers\ezplay.sys [118400 2011-10-06] (VSO Software) R3 JmUsbCcgp; C:\Windows\System32\DRIVERS\jmccgp.sys [17904 2010-02-05] (JMicron Technology Corp.) R3 JmUsbVideo; C:\Windows\System32\Drivers\jmcam.sys [56688 2010-02-05] (JMicron Technology Corp.) R3 JmUsbVideo2; C:\Windows\System32\Drivers\jmcam_lo.sys [31088 2010-02-05] (JMicron Technology Corp.) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [79872 2013-06-27] (Research In Motion Limited) R3 rimvndis; C:\Windows\System32\Drivers\rimvndis6_AMD64.sys [17920 2013-11-05] (Research in Motion Limited) R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd) S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [113704 2008-10-21] (MCCI Corporation) S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [19496 2008-10-21] (MCCI Corporation) S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [152616 2008-10-21] (MCCI Corporation) S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [133160 2008-10-21] (MCCI Corporation) S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [34856 2008-10-21] (MCCI Corporation) S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [128552 2008-10-21] (MCCI Corporation) S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [145960 2008-10-21] (MCCI Corporation) S3 usbrndis6; C:\Windows\system32\drivers\usb80236.sys [19968 2013-02-12] (Microsoft Corporation) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52080 2013-06-19] (Cisco Systems, Inc.) R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11280 2009-07-16] (Lenovo) U3 BcmSqlStartupSvc; No ImagePath S3 catchme; \??\C:\ComboFix\catchme.sys [X] U2 IviRegMgr; No ImagePath U2 RichVideo; No ImagePath S2 sbapifs; system32\DRIVERS\sbapifs.sys [X] U3 SQLWriter; No ImagePath S3 zlportio; \??\C:\Program Files (x86)\UltraStar\zlportio.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-28 16:03 - 2015-02-28 16:04 - 00045162 _____ () C:\Users\Jeanette\Desktop\Addition.txt 2015-02-28 16:02 - 2015-02-28 16:02 - 00050477 _____ () C:\Users\Jeanette\Downloads\Defogger.exe 2015-02-28 16:02 - 2015-02-28 16:02 - 00000478 _____ () C:\Users\Jeanette\Downloads\defogger_disable.log 2015-02-28 16:02 - 2015-02-28 16:02 - 00000000 _____ () C:\Users\Jeanette\defogger_reenable 2015-02-28 16:01 - 2015-02-28 16:04 - 00033514 _____ () C:\Users\Jeanette\Desktop\FRST.txt 2015-02-28 16:01 - 2015-02-28 16:04 - 00000000 ____D () C:\FRST 2015-02-28 16:00 - 2015-02-28 16:00 - 02087936 _____ (Farbar) C:\Users\Jeanette\Desktop\FRST64.exe 2015-02-28 15:44 - 2015-02-28 15:44 - 00001351 _____ () C:\Users\Jeanette\Desktop\MalewareBytes.txt 2015-02-28 15:06 - 2015-02-28 15:06 - 00016896 _____ () C:\Users\Jeanette\Documents\AW Diplomarbeit.msg 2015-02-27 18:03 - 2015-02-27 18:03 - 00278144 _____ () C:\windows\Minidump\022715-33867-01.dmp 2015-02-26 12:58 - 2015-02-28 15:18 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2015-02-26 12:58 - 2015-02-26 12:58 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2015-02-26 12:58 - 2015-02-26 12:58 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-02-26 12:58 - 2015-02-26 12:58 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2015-02-26 10:04 - 2015-01-09 00:44 - 00419936 _____ () C:\windows\SysWOW64\locale.nls 2015-02-26 10:04 - 2015-01-09 00:43 - 00419936 _____ () C:\windows\system32\locale.nls 2015-02-26 09:59 - 2015-02-26 09:59 - 05007216 _____ (Adobe Systems Inc.) C:\Users\Jeanette\Downloads\Shockwave_Installer_Slim.exe 2015-02-26 09:37 - 2015-02-26 10:21 - 00002560 _____ () C:\windows\_MSRSTRT.EXE 2015-02-26 09:15 - 2015-02-26 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Franzis 2015-02-26 09:15 - 2015-02-26 09:15 - 00000000 ____D () C:\Program Files (x86)\Franzis 2015-02-26 09:10 - 2015-02-26 09:10 - 00278144 _____ () C:\windows\Minidump\022615-39967-01.dmp 2015-02-21 11:58 - 2015-02-21 13:28 - 00005718 _____ () C:\Users\Finja\Documents\Pferde.odt 2015-02-21 11:28 - 2015-02-21 11:28 - 00000000 ____D () C:\Users\Finja\AppData\Roaming\Avira 2015-02-20 10:02 - 2015-02-20 10:02 - 00000000 ____D () C:\Users\Jeanette\AppData\Local\Steam 2015-02-18 16:21 - 2015-02-18 16:21 - 00001845 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2015-02-18 16:21 - 2015-02-18 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2015-02-18 16:21 - 2015-02-18 16:21 - 00000000 ____D () C:\ProgramData\Apple Computer 2015-02-18 16:21 - 2015-02-18 16:21 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2015-02-18 12:23 - 2015-02-18 12:23 - 00003954 _____ () C:\Users\Jeanette\Desktop\Planspiel - Verknüpfung.lnk 2015-02-16 15:45 - 2015-02-16 15:46 - 00278144 _____ () C:\windows\Minidump\021615-94505-01.dmp 2015-02-16 15:27 - 2015-02-16 15:27 - 00448512 _____ (OldTimer Tools) C:\Users\Jeanette\Downloads\TFC.exe 2015-02-16 09:40 - 2015-02-16 09:40 - 00000000 ____D () C:\Users\Christoph\AppData\Roaming\Avira 2015-02-15 21:08 - 2015-02-15 21:08 - 00000000 ____D () C:\Users\Jeanette\AppData\Local\BVRP Software 2015-02-15 21:05 - 2015-01-24 13:09 - 00176552 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe 2015-02-15 21:05 - 2015-01-24 13:09 - 00176552 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe 2015-02-15 21:05 - 2015-01-24 13:09 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll 2015-02-14 20:51 - 2015-02-14 20:51 - 00000000 ____D () C:\Program Files (x86)\ESET 2015-02-13 10:32 - 2015-02-13 10:32 - 00272216 _____ () C:\windows\Minidump\021315-39795-01.dmp 2015-02-12 08:34 - 2015-01-23 05:42 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2015-02-12 08:34 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2015-02-12 08:34 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2015-02-12 08:34 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2015-02-12 08:19 - 2015-02-12 08:19 - 00458624 _____ () C:\windows\Minidump\021215-62103-01.dmp 2015-02-11 09:50 - 2015-02-11 09:50 - 00067310 _____ () C:\Users\Jeanette\Downloads\bluescreenview_v1.55.zip 2015-02-11 09:50 - 2015-02-11 09:50 - 00000000 ____D () C:\Users\Jeanette\Downloads\bluescreenview_v1.55 2015-02-11 09:08 - 2015-02-11 09:08 - 00270952 _____ () C:\windows\Minidump\021115-101260-01.dmp 2015-02-11 08:31 - 2015-01-09 04:14 - 00950272 _____ (Microsoft Corporation) C:\windows\system32\perftrack.dll 2015-02-11 08:31 - 2015-01-09 04:14 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\wdi.dll 2015-02-11 08:31 - 2015-01-09 04:14 - 00029696 _____ (Microsoft Corporation) C:\windows\system32\powertracker.dll 2015-02-11 08:31 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdi.dll 2015-02-11 08:05 - 2015-02-11 08:06 - 00270888 _____ () C:\windows\Minidump\021115-61869-01.dmp 2015-02-10 22:25 - 2015-02-10 22:25 - 00000000 ____D () C:\d0cb5eb160bce8c232 2015-02-10 22:03 - 2015-02-10 22:03 - 00000000 ____D () C:\Users\Jeanette\AppData\Roaming\Avira 2015-02-10 21:49 - 2015-02-04 04:16 - 00894976 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll 2015-02-10 21:49 - 2015-02-04 04:16 - 00762368 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll 2015-02-10 21:49 - 2015-02-04 04:16 - 00609280 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll 2015-02-10 21:49 - 2015-02-04 04:16 - 00414720 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll 2015-02-10 21:49 - 2015-02-04 04:16 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2015-02-10 21:49 - 2015-02-04 04:16 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll 2015-02-10 21:49 - 2015-02-04 04:13 - 01098752 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2015-02-10 21:49 - 2015-01-28 00:36 - 01239720 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe 2015-02-10 21:49 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2015-02-10 21:49 - 2015-01-12 04:05 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2015-02-10 21:49 - 2015-01-12 03:48 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2015-02-10 21:49 - 2015-01-12 03:39 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2015-02-10 21:49 - 2015-01-12 03:34 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2015-02-10 21:49 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2015-02-10 21:49 - 2015-01-12 03:13 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2015-02-10 21:49 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2015-02-10 21:49 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2015-02-10 21:49 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2015-02-10 21:49 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2015-02-10 21:49 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-02-10 21:49 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2015-02-10 21:49 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2015-02-10 21:49 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2015-02-10 21:49 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2015-02-10 21:49 - 2015-01-10 07:48 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll 2015-02-10 21:49 - 2015-01-10 07:48 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2015-02-10 21:49 - 2015-01-10 07:48 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll 2015-02-10 21:49 - 2015-01-10 07:48 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll 2015-02-10 21:49 - 2015-01-10 07:48 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll 2015-02-10 21:49 - 2015-01-10 07:48 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll 2015-02-10 21:49 - 2015-01-10 07:48 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll 2015-02-10 21:49 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll 2015-02-10 21:49 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll 2015-02-10 21:49 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll 2015-02-10 21:49 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll 2015-02-10 21:49 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll 2015-02-10 21:49 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll 2015-02-10 21:49 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll 2015-02-10 21:48 - 2015-01-14 06:47 - 00389808 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2015-02-10 21:48 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2015-02-10 21:48 - 2015-01-12 04:05 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2015-02-10 21:48 - 2015-01-12 03:49 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2015-02-10 21:48 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2015-02-10 21:48 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2015-02-10 21:48 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2015-02-10 21:48 - 2015-01-12 03:40 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2015-02-10 21:48 - 2015-01-12 03:36 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2015-02-10 21:48 - 2015-01-12 03:34 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2015-02-10 21:48 - 2015-01-12 03:25 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2015-02-10 21:48 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2015-02-10 21:48 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2015-02-10 21:48 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2015-02-10 21:48 - 2015-01-12 03:08 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2015-02-10 21:48 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2015-02-10 21:48 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2015-02-10 21:48 - 2015-01-12 03:04 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2015-02-10 21:48 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2015-02-10 21:48 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2015-02-10 21:48 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2015-02-10 21:48 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2015-02-10 21:48 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2015-02-10 21:48 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2015-02-10 21:48 - 2015-01-12 02:46 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2015-02-10 21:48 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2015-02-10 21:48 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2015-02-10 21:48 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2015-02-10 21:48 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2015-02-10 21:48 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2015-02-10 21:48 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2015-02-10 21:48 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2015-02-10 21:48 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2015-02-10 21:48 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2015-02-10 21:48 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2015-02-10 21:48 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2015-02-10 21:47 - 2015-01-15 09:14 - 00155072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys 2015-02-10 21:47 - 2015-01-15 09:14 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys 2015-02-10 21:47 - 2015-01-15 09:09 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2015-02-10 21:47 - 2015-01-15 09:09 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll 2015-02-10 21:47 - 2015-01-15 09:09 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe 2015-02-10 21:47 - 2015-01-15 09:09 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll 2015-02-10 21:47 - 2015-01-15 09:09 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll 2015-02-10 21:47 - 2015-01-15 09:08 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe 2015-02-10 21:47 - 2015-01-15 09:06 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll 2015-02-10 21:47 - 2015-01-15 09:06 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll 2015-02-10 21:47 - 2015-01-15 09:04 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll 2015-02-10 21:47 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe 2015-02-10 21:47 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll 2015-02-10 21:47 - 2015-01-15 08:41 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll 2015-02-10 21:47 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll 2015-02-10 21:47 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll 2015-02-10 21:47 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll 2015-02-10 21:47 - 2015-01-15 05:22 - 00458824 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys 2015-02-10 21:47 - 2015-01-13 04:10 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll 2015-02-10 21:47 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll 2015-02-10 21:46 - 2014-12-12 06:31 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll 2015-02-10 21:46 - 2014-12-12 06:07 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll 2015-02-10 21:46 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll 2015-02-10 21:46 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll 2015-02-10 21:46 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll 2015-02-10 21:46 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll 2015-02-10 21:45 - 2015-01-14 07:09 - 05554112 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2015-02-10 21:45 - 2015-01-14 07:05 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll 2015-02-10 21:45 - 2015-01-14 07:05 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll 2015-02-10 21:45 - 2015-01-14 07:04 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe 2015-02-10 21:45 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe 2015-02-10 21:45 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe 2015-02-10 21:45 - 2015-01-14 06:41 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll 2015-02-10 21:45 - 2014-11-26 04:53 - 00861696 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll 2015-02-10 21:45 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll 2015-02-10 21:43 - 2014-12-08 04:09 - 00406528 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll 2015-02-10 21:43 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\windows\SysWOW64\scesrv.dll 2015-02-10 21:40 - 2015-01-09 03:03 - 03201536 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2015-02-10 21:21 - 2015-02-10 21:16 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys 2015-02-10 21:14 - 2014-11-24 10:23 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys 2015-02-10 21:14 - 2014-11-24 10:23 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys 2015-02-10 21:14 - 2014-11-24 10:23 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys 2015-02-10 20:54 - 2015-02-10 20:54 - 00000000 ____D () C:\OETemp 2015-02-10 20:37 - 2015-01-24 13:09 - 00272296 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe 2015-02-10 20:17 - 2015-02-10 20:17 - 00278144 _____ () C:\windows\Minidump\021015-46925-01.dmp 2015-02-09 21:34 - 2015-02-10 21:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-02-09 21:34 - 2015-02-10 21:14 - 00000000 ____D () C:\ProgramData\Avira 2015-02-09 21:34 - 2015-02-10 21:14 - 00000000 ____D () C:\Program Files (x86)\Avira 2015-02-09 21:34 - 2015-02-09 21:34 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk 2015-02-09 21:34 - 2015-02-09 21:34 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-09 21:00 - 2015-02-09 21:00 - 00272216 _____ () C:\windows\Minidump\020915-33306-01.dmp 2015-02-09 14:50 - 2015-02-09 14:50 - 04515896 _____ (Avira Operations & Co. KG) C:\Users\Jeanette\Downloads\avira_de_av_5839340206__ws.exe 2015-02-08 18:08 - 2015-02-10 22:06 - 00000000 ____D () C:\Program Files (x86)\SpywareBlaster 2015-02-08 18:08 - 2015-02-08 18:08 - 00001079 _____ () C:\Users\Public\Desktop\SpywareBlaster.lnk 2015-02-08 18:08 - 2015-02-08 18:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster 2015-02-08 18:08 - 2009-03-24 12:52 - 00129872 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSSTDFMT.DLL 2015-02-08 17:58 - 2015-02-08 18:09 - 42096984 _____ (Apple Inc.) C:\Users\Jeanette\Downloads\QuickTimeInstaller.exe 2015-02-08 17:54 - 2015-02-10 20:37 - 00001484 _____ () C:\windows\SecuniaPackage.log 2015-02-08 10:49 - 2015-02-08 10:54 - 465199132 _____ () C:\Users\Jeanette\Downloads\Die Analphabetin, die rechnen konnte.wma 2015-02-08 10:35 - 2015-02-08 10:35 - 04095448 _____ (BrightFort LLC ) C:\Users\Jeanette\Downloads\spywareblastersetup50.exe 2015-02-08 10:34 - 2015-02-08 10:38 - 372014989 _____ () C:\Users\Jeanette\Downloads\Süßer Tod.wma 2015-02-08 10:31 - 2015-02-08 10:31 - 00543951 _____ () C:\Users\Jeanette\Downloads\noscript-2.6.9.12.xpi.zip 2015-02-08 10:24 - 2015-02-08 10:24 - 05490752 _____ (Secunia) C:\Users\Jeanette\Downloads\PSISetup10004.exe 2015-02-07 22:00 - 2015-02-07 22:23 - 129967104 _____ () C:\Users\Jeanette\Downloads\Die Eifel-Connection_05.wma 2015-02-07 21:37 - 2015-02-07 22:01 - 125126544 _____ () C:\Users\Jeanette\Downloads\Die Eifel-Connection_04.wma 2015-02-07 21:10 - 2015-02-07 22:01 - 127152408 _____ () C:\Users\Jeanette\Downloads\Die Eifel-Connection_03.wma 2015-02-07 20:38 - 2015-02-07 21:43 - 124427352 _____ () C:\Users\Jeanette\Downloads\Die Eifel-Connection_02.wma 2015-02-07 19:37 - 2015-02-07 20:38 - 405903016 _____ () C:\Users\Jeanette\Downloads\Smaragdgrün - Liebe geht durch alle Zeiten(1).wma 2015-02-07 19:23 - 2015-02-07 21:23 - 130253952 _____ () C:\Users\Jeanette\Downloads\Die Eifel-Connection_01.wma 2015-02-07 16:18 - 2015-02-07 16:26 - 81307064 _____ (Swiss Academic Software) C:\Users\Jeanette\Downloads\Citavi4Setup(1).exe 2015-02-02 17:10 - 2015-02-02 17:12 - 00278144 _____ () C:\windows\Minidump\020215-34242-01.dmp 2015-01-31 10:54 - 2015-01-31 10:54 - 00004901 _____ () C:\Users\Jeanette\Downloads\sf535adWBhQ&fs=1&rel=0&autoplay=1 2015-01-29 18:03 - 2015-01-29 18:37 - 00014302 _____ () C:\Users\Jeanette\Documents\Sicherungskopie von Kassenbericht 2014.wbk ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-28 16:02 - 2011-06-05 09:16 - 00000000 ____D () C:\Users\Jeanette 2015-02-28 15:51 - 2012-04-01 12:03 - 00001110 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-28 15:51 - 2012-04-01 12:03 - 00001106 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-28 15:43 - 2011-05-17 16:16 - 01115704 _____ () C:\windows\WindowsUpdate.log 2015-02-28 15:07 - 2015-01-21 15:40 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2015-02-28 15:06 - 2011-11-27 14:43 - 00000000 ____D () C:\Users\Jeanette\Documents\Outlook-Dateien 2015-02-28 11:10 - 2013-11-27 19:23 - 00000000 ____D () C:\Users\Jeanette\Documents\Citavi 4 2015-02-28 10:50 - 2009-07-14 05:45 - 00019296 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-28 10:50 - 2009-07-14 05:45 - 00019296 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-28 10:49 - 2011-05-17 23:46 - 00699682 _____ () C:\windows\system32\perfh007.dat 2015-02-28 10:49 - 2011-05-17 23:46 - 00149790 _____ () C:\windows\system32\perfc007.dat 2015-02-28 10:49 - 2009-07-14 06:13 - 01620684 _____ () C:\windows\system32\PerfStringBackup.INI 2015-02-28 10:45 - 2013-12-09 16:03 - 00000000 ___RD () C:\Users\Jeanette\Dropbox 2015-02-28 10:45 - 2013-12-09 15:59 - 00000000 ____D () C:\Users\Jeanette\AppData\Roaming\Dropbox 2015-02-28 10:43 - 2014-12-29 11:51 - 00000000 ____D () C:\Program Files (x86)\Steam 2015-02-28 10:42 - 2013-12-07 17:32 - 00039417 _____ () C:\windows\setupact.log 2015-02-28 10:42 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2015-02-27 18:03 - 2014-02-27 18:24 - 563702608 _____ () C:\windows\MEMORY.DMP 2015-02-27 18:03 - 2011-09-18 14:01 - 00000000 ____D () C:\windows\Minidump 2015-02-26 13:09 - 2014-06-20 07:53 - 00000000 ____D () C:\Users\Jeanette\AppData\Local\Adobe 2015-02-26 10:22 - 2013-12-08 15:22 - 01074080 _____ () C:\windows\PFRO.log 2015-02-26 09:57 - 2012-08-28 09:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-02-26 09:57 - 2011-06-06 09:53 - 00000000 ____D () C:\Program Files (x86)\Internet 2015-02-22 17:05 - 2014-05-03 15:19 - 00000000 ____D () C:\Users\Finja\Documents\Citavi 4 2015-02-21 13:27 - 2011-12-13 12:33 - 00000000 ____D () C:\Users\Finja\AppData\Local\Microsoft Help 2015-02-16 15:20 - 2013-12-14 13:02 - 00002180 _____ () C:\DelFix.txt 2015-02-16 09:21 - 2012-11-23 09:29 - 00000000 ____D () C:\Program Files (x86)\OXXOGames 2015-02-15 21:27 - 2013-10-04 11:38 - 00000000 ____D () C:\Users\Jeanette\.gimp-2.8 2015-02-15 21:22 - 2015-01-16 17:38 - 00000000 ____D () C:\Program Files\HWiNFO64 2015-02-15 21:22 - 2012-04-03 21:57 - 00000000 ____D () C:\Program Files (x86)\Purplehills 2015-02-15 21:22 - 2012-03-14 09:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Purplehills 2015-02-15 21:18 - 2011-06-06 11:19 - 00000000 ____D () C:\Program Files (x86)\Spiele 2015-02-15 21:17 - 2011-09-10 11:23 - 00000000 ____D () C:\Program Files (x86)\Sony 2015-02-15 21:12 - 2011-09-10 11:29 - 00000000 ____D () C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sony Ericsson 2015-02-15 21:12 - 2011-09-10 11:07 - 00000000 ____D () C:\Program Files (x86)\Sony Ericsson 2015-02-15 21:09 - 2011-09-10 11:27 - 00000000 ____D () C:\Users\Jeanette\AppData\Local\Sony 2015-02-15 21:08 - 2011-05-17 16:24 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-02-15 21:07 - 2014-06-17 09:02 - 00000000 ____D () C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\USM 2015-02-15 21:07 - 2014-06-17 09:02 - 00000000 ____D () C:\Program Files (x86)\USM 2015-02-15 21:05 - 2011-06-06 11:20 - 00000000 ____D () C:\Program Files (x86)\Java 2015-02-13 11:04 - 2011-06-12 21:33 - 00000000 ____D () C:\Users\Jeanette\vista alt 2015-02-13 10:42 - 2013-12-08 18:55 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-02-12 21:37 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache 2015-02-12 19:05 - 2012-07-07 08:41 - 01594964 _____ () C:\windows\SysWOW64\PerfStringBackup.INI 2015-02-11 08:56 - 2014-12-11 14:06 - 00000000 ____D () C:\windows\system32\appraiser 2015-02-11 08:56 - 2014-07-09 16:41 - 00000000 ___SD () C:\windows\system32\CompatTel 2015-02-11 08:56 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\tracing 2015-02-11 08:54 - 2011-08-19 10:07 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-02-11 08:54 - 2009-07-14 03:34 - 00000478 _____ () C:\windows\win.ini 2015-02-11 08:11 - 2013-12-09 16:00 - 00000000 ____D () C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-02-11 08:05 - 2009-07-14 05:45 - 00459784 _____ () C:\windows\system32\FNTCACHE.DAT 2015-02-10 22:24 - 2013-07-16 21:55 - 00000000 ____D () C:\windows\system32\MRT 2015-02-10 22:13 - 2011-06-08 20:03 - 116773704 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2015-02-10 22:06 - 2011-05-17 16:43 - 00000000 ____D () C:\ProgramData\Temp 2015-02-10 20:43 - 2013-12-20 13:12 - 00007603 _____ () C:\Users\Jeanette\AppData\Local\Resmon.ResmonCfg 2015-02-08 18:09 - 2012-09-28 11:28 - 00000000 ____D () C:\ProgramData\Licenses 2015-02-07 16:57 - 2013-11-27 18:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citavi 4 2015-02-07 16:57 - 2012-01-09 19:12 - 00000000 ____D () C:\ProgramData\Swiss Academic Software 2015-02-07 16:51 - 2011-09-10 11:23 - 00000000 ____D () C:\Users\Jeanette\AppData\Local\Downloaded Installations 2015-02-07 15:46 - 2012-04-01 12:03 - 00004106 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-07 15:46 - 2012-04-01 12:03 - 00003854 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-04 08:06 - 2009-07-14 06:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD 2015-02-04 08:05 - 2011-12-13 12:33 - 00001421 _____ () C:\Users\Finja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ==================== Files in the root of some directories ======= 2013-12-18 14:28 - 2013-12-18 14:45 - 50063360 _____ () C:\Program Files (x86)\GUTD662.tmp 2011-10-06 08:42 - 2012-02-12 20:33 - 0007833 _____ () C:\Users\Jeanette\AppData\Roaming\ezplay.cat 2011-10-06 08:42 - 2012-02-12 20:33 - 0001127 _____ () C:\Users\Jeanette\AppData\Roaming\ezplay.inf 2011-10-06 08:42 - 2011-10-06 08:42 - 0000125 _____ () C:\Users\Jeanette\AppData\Roaming\ezplay.ini 2011-10-06 08:43 - 2012-02-12 20:33 - 0000033 _____ () C:\Users\Jeanette\AppData\Roaming\ezplay.log 2011-10-06 08:42 - 2012-02-12 20:33 - 0118400 _____ (VSO Software) C:\Users\Jeanette\AppData\Roaming\ezplay.sys 2011-10-06 08:42 - 2012-02-12 20:33 - 0099384 _____ () C:\Users\Jeanette\AppData\Roaming\inst.exe 2012-11-15 14:15 - 2012-11-15 14:15 - 0021887 _____ () C:\Users\Jeanette\AppData\Roaming\Kommagetrennte Werte (Windows).ADR 2012-01-02 15:47 - 2012-01-02 15:47 - 0004096 ____H () C:\Users\Jeanette\AppData\Local\keyfile3.drm 2013-11-08 14:22 - 2013-11-08 14:22 - 0005506 _____ () C:\Users\Jeanette\AppData\Local\recently-used.xbel 2013-12-20 13:12 - 2015-02-10 20:43 - 0007603 _____ () C:\Users\Jeanette\AppData\Local\Resmon.ResmonCfg 2011-10-05 14:26 - 2012-04-17 11:47 - 0000040 ___SH () C:\ProgramData\.zreglib 2011-06-05 13:29 - 2011-06-05 13:29 - 0000088 _____ () C:\ProgramData\profile.xml Some content of TEMP: ==================== C:\Users\Christoph\AppData\Local\Temp\avgnt.exe C:\Users\Finja\AppData\Local\Temp\avgnt.exe C:\Users\Jeanette\AppData\Local\Temp\avgnt.exe C:\Users\Jeanette\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp9pxctj.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-23 20:19 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-02-2015 01 Ran by Jeanette at 2015-02-28 16:03:04 Running from C:\Users\Jeanette\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) AAVUpdateManager (HKLM-x32\...\{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}) (Version: 18.00.0000 - Wolters Kluwer Deutschland GmbH) Abenteuer Wikinger (HKLM-x32\...\Abenteuer Wikinger) (Version: - Serious Games Solutions GmbH) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.9.0.1380 - Adobe Systems Incorporated) Adobe Digital Editions 2.0 (HKLM-x32\...\Adobe Digital Editions 2.0) (Version: 2.0.1 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Ashampoo Burning Studio 2013 v.11.0.6 (HKLM-x32\...\{91B33C97-0FBA-74AE-E802-D782F5C8AA89}_is1) (Version: 11.0.6 - Ashampoo GmbH & Co. KG) ATI Catalyst Install Manager (HKLM\...\{1D2A4D59-D4FF-9093-050F-8F042B26E6A1}) (Version: 3.0.782.0 - ATI Technologies, Inc.) AudibleManager (HKLM-x32\...\AudibleManager) (Version: 2004103296.48.56.2755954 - Audible, Inc.) Audiograbber 1.83 SE (HKLM-x32\...\Audiograbber) (Version: 1.83 SE - Audiograbber) Audiograbber MP3-Plugin (HKLM-x32\...\Audiograbber-Lame) (Version: 1.0 - AG) Avira (HKLM-x32\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG) Avira (x32 Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) Bad Piggies (HKLM-x32\...\{32941438-AD79-4EF4-B7E4-86039E41B4D3}) (Version: 1.0.0 - Rovio) BlackBerry Link (HKLM-x32\...\BlackBerry_10_Desktop) (Version: 1.2.1.31 - BlackBerry Ltd.) BlackBerry Link (x32 Version: 1.2.1.31 - BlackBerry Ltd.) Hidden Broadcom 802.11 Wireless Driver (HKLM-x32\...\{8991E763-21F5-4DEA-A938-5D9D77DCB488}) (Version: 1.0.0.0 - ) Broadcom Gigabit NetLink Controller (HKLM\...\{A84DB02B-9C2B-4272-9D2D-A80E00A56513}) (Version: 12.52.01 - Broadcom Corporation) Cars 2 (HKLM-x32\...\{FF10D622-7BFE-48C6-8DF6-40D8CB1D3C1B}) (Version: 1.00.0000 - Disney Interactive Studios) ccc-core-static (x32 Version: 2010.0629.2222.38338 - Ihr Firmenname) Hidden Christmasville (HKLM-x32\...\{D178746E-0919-424E-88A7-81A0E46FF03E}) (Version: 1.00.0000 - Purplehills) Cinergy T USB XE (MKII) V6.09.28.05b (HKLM-x32\...\Cinergy T USB XE (MKII)) (Version: 6.09.28.05b - ) Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.04059 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.04059 - Cisco Systems, Inc.) Hidden Citavi (HKLM-x32\...\{E12C6653-1FF0-4686-ADB8-589C13AE761F}) (Version: 3.4.0.2 - Swiss Academic Software) Citavi 4 (HKLM-x32\...\{CC0A85B2-734A-45B3-B678-05F6A6499AC7}) (Version: 4.5.0.11 - Swiss Academic Software) Contenta Converter BASIC (HKLM-x32\...\ContentaConverter-BASIC) (Version: - Contenta Software) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2603 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Demolition Company (HKLM-x32\...\DemolitionCompanyDE_is1) (Version: - GIANTS Software) Dropbox (HKU\S-1-5-21-884760279-2294033944-2841522718-1000\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.) Dropbox (HKU\S-1-5-21-884760279-2294033944-2841522718-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.) Energy Management (HKLM-x32\...\{0CE226F3-EB27-4ECD-BBF5-F088716779FD}) (Version: 5.4.1.6 - Lenovo) Epson Easy Photo Print 2 (HKLM-x32\...\{30E01116-5666-4807-8EF1-D80E9FF16717}) (Version: 2.3.2.0 - SEIKO EPSON CORPORATION) Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2) EPSON PhotoQuicker3.5 (HKLM-x32\...\{65F5B7AF-3363-11D7-BB6B-00018021113F}) (Version: - ) Epson Print CD (HKLM-x32\...\{D16A31F9-276D-4968-A753-FFEAC56995D0}) (Version: 2.00.00 - SEIKO EPSON CORPORATION) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Eye of the Kraken (HKLM-x32\...\Eye of the Kraken_is1) (Version: - Absurdus) Eyesight Challenge (HKLM-x32\...\165-com.novelgames.flashgames.eyesight) (Version: 1.2.0 - Novel Games Limited) Eyesight Challenge (x32 Version: 1.2.0 - Novel Games Limited) Hidden Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}) (Version: 2.1.27.0 - MAGIX AG) Flash Games 1.0 (HKLM-x32\...\Flash Games_is1) (Version: - Free-Soft) Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com) Free YouTube Download version 3.2.2.430 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.2.430 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.27.225 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.27.225 - DVDVideoSoft Ltd.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Grace Abenteuer; Die Jagd auf die Kunsträuber (HKLM-x32\...\Grace Abenteuer; Die Jagd auf die Kunsträuber) (Version: - ) Holly - Ein Weihnachtsmärchen (HKLM-x32\...\{8F08E12A-363F-4F69-8BC8-0E0EA502A6ED}) (Version: 1.00.0000 - Purplehills) Holly im Wunderland (HKLM-x32\...\Holly im Wunderland) (Version: - ) Inkscape 0.48.4 (HKLM-x32\...\Inkscape) (Version: 0.48.4 - ) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.0.1014 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Laura Jones and the Gates of Good and Evil (HKLM-x32\...\Laura Jones and the Gates of Good and Evil) (Version: - ) Laura Jones und das geheime Erbe des Nikola Tesla (HKLM-x32\...\Laura Jones und das geheime Erbe des Nikola Tesla) (Version: - ) LEGO Digital Designer (HKLM-x32\...\New LEGO Digital Designer) (Version: - LEGO A/S) LEGO® Harry Potter™: Die Jahre 5-7 (HKLM-x32\...\{5C5A944F-096E-4ADD-B8E8-887F18BA6228}) (Version: 1.0.0.0 - WB Games) Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.1.1200 - Broadcom Corporation) Lenovo DirectShare (HKLM-x32\...\InstallShield_{B2164CCB-C002-4B80-8550-7535D80DF237}) (Version: 1.0.1.38 - ArcSoft) Lenovo DirectShare (x32 Version: 1.0.1.38 - ArcSoft) Hidden Lenovo EasyCamera (HKLM-x32\...\{F5608FF7-17C0-440A-80C7-29C48363BD87}) (Version: 1.0.9.2 - Suyin Optronics Corp.) Lenovo Games Console (HKLM-x32\...\Lenovo Games Console) (Version: 0.38.389.2 - Oberon Media Inc.) Lenovo MuteSync (HKLM-x32\...\InstallShield_{2955FADE-ADED-44AD-A853-D1EAEA7ACAD5}) (Version: 1.0.0.2 - Lenovo) Lenovo MuteSync (x32 Version: 1.0.0.2 - Lenovo) Hidden Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1230 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 7.0.1230 - CyberLink Corp.) Hidden Lenovo ReadyComm 5 (HKLM-x32\...\{17542DBF-E17C-4562-BC4D-FA3EF3076C45}) (Version: 5.1.1.22 - Lenovo) Lenovo ReadyComm 5.0 Service (HKLM-x32\...\{76C66170-C538-4E77-B54D-48E136B5B533}) (Version: 5.0.0.1 - Lenovo Group Limited) Lenovo SlideNav (HKLM-x32\...\Lenovo SlideNav2) (Version: 2.0.1230.0003 - Lenovo) Lenovo SplitScreen (HKLM-x32\...\Lenovo SplitScreen) (Version: 1.00.1823.0001 - Lenovo) Magicians Handbook (HKLM-x32\...\{6850696D-FC0A-48A7-9097-7EB301FB0FEA}) (Version: 1.00.0000 - Purplehills) Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Mein CEWE FOTOBUCH (HKLM-x32\...\Mein CEWE FOTOBUCH) (Version: 5.0.4 - CEWE COLOR AG u Co. OHG) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Mozilla Firefox 36.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0 (x86 de)) (Version: 36.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) Mp3tag v2.49 (HKLM-x32\...\Mp3tag) (Version: v2.49 - Florian Heidenreich) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) mufin player 2.0 (HKLM-x32\...\MAGIX_MSI_mufin_player_2) (Version: 2.0.3.680 - mufin GmbH) mufin player 2.0 (x32 Version: 2.0.3.680 - mufin GmbH) Hidden Mushroom Age (HKLM-x32\...\Mushroom Age) (Version: - ) Mysteryville 2 (HKLM-x32\...\{7730D510-6DE2-4CD4-8F58-0B04680AEFE6}) (Version: 1.00.0000 - Mysteryville 2) NirSoft BlueScreenView (HKLM-x32\...\NirSoft BlueScreenView) (Version: - ) Onekey Theater (HKLM-x32\...\InstallShield_{D4B060B9-AD4A-4152-9D99-28B93C615AFE}) (Version: 2.0.2.6 - Lenovo) Onekey Theater (x32 Version: 2.0.2.6 - Lenovo) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) PassbildPro v2.3d (HKLM-x32\...\PassbildPro_is1) (Version: - PassbildPro) Pelikan Schulschriften (HKLM-x32\...\Vereinfachte Ausgangsschrift VA_is1) (Version: - Will Software) Picture Collage Maker Pro 3.3.9 (HKLM-x32\...\{6D308A90-6C14-4A02-9B04-CB0EF17894A9}_is1) (Version: 3.3.9 - PearlMountain Technology Co., Ltd) PlayStation(R)Network Downloader (HKLM-x32\...\{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}) (Version: 2.06.00741 - Sony Computer Entertainment Inc.) PlayStation(R)Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.3.3.12540 - Sony Computer Entertainment Inc.) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.4809d4 - CyberLink Corp.) PowerXpressHybrid (x32 Version: 1.00.0000 - Ihr Firmenname) Hidden PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) Ravensburger tiptoi (HKLM-x32\...\Ravensburger tiptoi) (Version: - ) Realtek HDMI Audio Driver for ATI (HKLM-x32\...\{5449FB4F-1802-4D5B-A6D8-087DB1142147}) (Version: 6.0.1.6121 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6278 - Realtek Semiconductor Corp.) Schach & Matt (HKLM-x32\...\Schach & Matt_is1) (Version: - Tivola Development GmbH) Sea3D 1.2.0a (HKLM-x32\...\Sea3D_is1) (Version: 1.2.0a - Jason Fugate) Sealegends - Geisterhaftes Licht (HKLM-x32\...\Sealegends - Geisterhaftes Licht) (Version: - ) Secret Maryo Chronicles (HKLM-x32\...\secretmaryo) (Version: 1.7 - Florian Richter) SecuROM Diagnostic Tool (HKLM-x32\...\SecuROM Diagnostic Tool) (Version: - Sony DADC Austria) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Shockwave (HKLM-x32\...\Shockwave) (Version: - ) Simple Sudoku 4.2 (HKLM-x32\...\Simple Sudoku_is1) (Version: - ) Snark Busters: Willkommen im Club (HKLM-x32\...\Snark Busters: Willkommen im Club) (Version: - Alawar Entertainment Inc.) SpywareBlaster 5.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Stellarium 0.10.6.1 (HKLM-x32\...\Stellarium_is1) (Version: - ) Steuer-Spar-Erklärung 2011 (HKLM-x32\...\{9F5FD796-86F0-4360-85F8-D54C0F5411EB}) (Version: 16.14 - Akademische Arbeitsgemeinschaft Verlag) Steuer-Spar-Erklärung 2012 (HKLM-x32\...\{CCD2BAD2-0919-40CB-80CC-E9538B0E4C2E}) (Version: 17.11 - Wolters Kluwer Deutschland GmbH) Steuer-Spar-Erklärung 2013 (HKLM-x32\...\{AEB61F7A-4BBA-4292-A096-7893E09034A4}) (Version: 18.10 - Wolters Kluwer Deutschland GmbH) SteuerSparErklärung 2014 (HKLM-x32\...\{A463EB06-22A6-47F5-9593-E52B291EF13E}) (Version: 19.10.89 - Akademische Arbeitsgemeinschaft) STOPzilla (HKLM-x32\...\{17FE15BF-9656-461F-B9E7-077A9C061955}) (Version: 6.1.55.11 - iS3 Inc.) StreamTransport version: 1.0.2.2171 (HKLM-x32\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - ) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.19.1 - Synaptics Incorporated) Tales of Monkey Island (HKLM-x32\...\Tales of Monkey Island) (Version: 3.0.0.0 - Daedalic Entertainment) TerraTec Home Cinema (HKLM-x32\...\{63B9BAB5-F36A-4A3B-9E5C-68A7F212BFB9}) (Version: 6.27.4 - ) The Journey Down: Chapter One (HKLM-x32\...\Steam App 220090) (Version: - SkyGoblin) Unity Web Player (HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\UnityWebPlayer) (Version: 2.6.1f3_31223 - Unity Technologies ApS) Unity Web Player (HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\UnityWebPlayer) (Version: 2.6.1f3_31223 - Unity Technologies ApS) VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN) Winamp (HKLM-x32\...\Winamp) (Version: 5.622 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKU\S-1-5-21-884760279-2294033944-2841522718-1000\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKU\S-1-5-21-884760279-2294033944-2841522718-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows Driver Package - Broadcom Bluetooth (01/06/2010 6.2.0.9416) (HKLM\...\DFEA59689C004DFD0378309F3A583EA32D78A1B3) (Version: 01/06/2010 6.2.0.9416 - Broadcom) Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (HKLM\...\3BA80AB4C7E9F8497C115C844953A3D4BEB84D21) (Version: 07/28/2009 6.2.0.9800 - Broadcom) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) Windows-Treiberpaket - Lenovo (ACPIVPC) System (10/19/2009 5.4.0.1) (HKLM\...\0A4175B489A1B4A6E07E11B063A6263480C51D71) (Version: 10/19/2009 5.4.0.1 - Lenovo) Zylom Games Player Plugin (HKLM-x32\...\Zylom Games Player Plugin) (Version: - Zylom Games) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-884760279-2294033944-2841522718-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-884760279-2294033944-2841522718-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-884760279-2294033944-2841522718-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-884760279-2294033944-2841522718-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-884760279-2294033944-2841522718-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-884760279-2294033944-2841522718-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-884760279-2294033944-2841522718-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-884760279-2294033944-2841522718-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-884760279-2294033944-2841522718-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ==================== Restore Points ========================= 16-02-2015 15:20:16 Ende der Bereinigung 22-02-2015 19:00:47 Windows-Sicherung 26-02-2015 10:04:01 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2015-02-07 15:26 - 00000184 ____A C:\windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 129.217.129.34 vpnserver.tu-dortmund.de ###Cisco AnyConnect VPN client modified this file. Please do not modify contents until this comment is removed. ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {23A81EB4-1C18-466C-A4D1-A4EE619F95B7} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {4C44B3EE-78E4-4F72-9F15-8777AEF170BE} - System32\Tasks\{0D0787D1-1D42-42AE-9C10-25A49ECFB518} => pcalua.exe -a C:\Users\Jeanette\Downloads\epson327610eu.exe -d "C:\Program Files (x86)\Internet\Firefox" Task: {61625DAF-1B72-4E0C-8F06-5CE46DBDF145} - System32\Tasks\{B8595506-B271-4D33-BA96-7970A6B1C923} => pcalua.exe -a "C:\Program Files (x86)\Tivola\Der Schatz der Delfine\uninst.exe" Task: {8D55C888-DCE0-4817-9661-9E1F0945E4A4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-01] (Google Inc.) Task: {9FD3D689-7F1F-4D5B-B9D2-5D8CEAAF1140} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-01] (Google Inc.) Task: {A2AC4A64-DC01-4A1C-92E2-C712AA00C266} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-26] (Adobe Systems Incorporated) Task: {B8B9CC00-E87D-4508-891C-6D81D9CE719E} - System32\Tasks\{A844BC1C-5241-4BAA-95C7-2164AAF6DE0C} => pcalua.exe -a F:\Setup.exe -d F:\ Task: {B913AAF9-E10D-4018-9497-5A100C253DB1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {B9E614BA-448B-4F8F-B9B0-F4B39F5F3B02} - System32\Tasks\{72A6C988-6041-4108-8CDF-F20A877890B1} => pcalua.exe -a C:\Users\Jeanette\Downloads\QuickTimeInstaller(1).exe -d "C:\Program Files (x86)\Internet\Firefox" Task: {CB208028-0B49-4ADA-930E-81C2926E36DE} - System32\Tasks\{13DB6345-5314-4FFD-976F-B558204B2FCD} => pcalua.exe -a F:\Setup.exe -d F:\ Task: {D7762F0F-CA57-4D69-8C40-9E0DA5AF6992} - System32\Tasks\{493DA952-3CCF-4C4C-ADC7-B84811E71E91} => pcalua.exe -a C:\Users\Jeanette\Downloads\BroeslXP.exe -d C:\Users\Jeanette\Downloads Task: {E06C6FC6-71BF-4F26-9ACC-515C7E14E32B} - System32\Tasks\{2459E739-ACE0-4B08-9AEC-B344D7575637} => pcalua.exe -a C:\Users\Jeanette\Downloads\FlashGamesFullSetup.exe -d "C:\Program Files (x86)\Internet\Firefox" Task: {E9D28F9F-7EF0-45F7-815C-1E66C349CD6F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {F9643504-42F4-465C-8869-1C444C61F69C} - System32\Tasks\{7A21C288-75BE-415F-8241-1431C51864E5} => pcalua.exe -a C:\Users\Jeanette\Downloads\epson320037eu.exe -d "C:\Program Files (x86)\Internet\Firefox" Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2008-10-24 16:35 - 2008-10-24 16:35 - 00128296 _____ () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe 2010-10-18 15:50 - 2010-10-18 15:50 - 00202144 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\ActiveDetect64.dll 2010-10-18 15:52 - 2010-10-18 15:52 - 00156576 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\WindowsApiHookDll64.dll 2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2011-05-17 17:03 - 2009-07-15 16:55 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll 2011-05-17 17:03 - 2009-07-15 16:55 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll 2011-05-17 16:46 - 2011-05-17 16:46 - 00100256 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe 2010-01-12 17:15 - 2010-01-12 17:15 - 00173344 _____ () C:\Program Files\Lenovo\Bluetooth Software\btkeyind.dll 2010-07-08 18:33 - 2010-07-08 18:33 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-06-29 23:21 - 2010-06-29 23:21 - 00270336 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2013-06-19 11:00 - 2013-06-19 11:00 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2010-10-18 15:46 - 2010-10-18 15:46 - 00161696 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\ActiveDetect32.dll 2010-10-18 15:49 - 2010-10-18 15:49 - 00133024 _____ () C:\Program Files (x86)\Lenovo\Onekey Theater\WindowsApiHookDll32.dll 2014-11-11 10:47 - 2014-11-11 19:47 - 00774656 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2015-01-21 15:27 - 2014-12-02 01:29 - 05002752 _____ () C:\Program Files (x86)\Steam\v8.dll 2015-01-21 15:27 - 2014-12-02 01:29 - 01612800 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2015-01-21 15:27 - 2014-12-02 01:29 - 01210368 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2014-11-18 12:23 - 2015-02-19 00:51 - 02360000 _____ () C:\Program Files (x86)\Steam\video.dll 2014-11-11 10:48 - 2014-12-01 22:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2014-11-11 10:48 - 2014-12-01 22:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2014-11-11 10:48 - 2014-12-01 22:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2014-11-11 10:48 - 2014-12-01 22:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2014-11-11 10:48 - 2014-12-01 22:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2014-11-18 12:23 - 2015-02-19 00:51 - 00702656 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2015-02-10 22:00 - 2015-02-10 22:00 - 00750080 _____ () C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2015-02-28 10:43 - 2015-02-28 10:43 - 00043008 _____ () c:\users\jeanette\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp9pxctj.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00047616 _____ () C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\libEGL.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00865280 _____ () C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll 2015-02-10 22:00 - 2015-02-10 22:00 - 00200704 _____ () C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll 2014-11-11 10:48 - 2015-01-28 02:30 - 34641288 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2014-12-20 16:28 - 2014-12-20 16:28 - 00170496 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\3d576cbc4ffc5ad06fd61510c5d8f326\IsdiInterop.ni.dll 2011-05-17 16:24 - 2010-03-03 21:08 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\Temp:5C321E34 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) HKU\S-1-5-21-884760279-2294033944-2841522718-1000\Software\Classes\exefile: <===== ATTENTION! ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-884760279-2294033944-2841522718-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-884760279-2294033944-2841522718-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Christoph\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-884760279-2294033944-2841522718-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Christoph\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Finja\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-884760279-2294033944-2841522718-1008-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Finja\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== Accounts: ============================= Administrator (S-1-5-21-884760279-2294033944-2841522718-500 - Administrator - Disabled) Christoph (S-1-5-21-884760279-2294033944-2841522718-1003 - Limited - Enabled) => C:\Users\Christoph Finja (S-1-5-21-884760279-2294033944-2841522718-1008 - Limited - Enabled) => C:\Users\Finja Gast (S-1-5-21-884760279-2294033944-2841522718-501 - Limited - Enabled) HomeGroupUser$ (S-1-5-21-884760279-2294033944-2841522718-1010 - Limited - Enabled) Jeanette (S-1-5-21-884760279-2294033944-2841522718-1000 - Administrator - Enabled) => C:\Users\Jeanette ==================== Faulty Device Manager Devices ============= Name: High Definition Audio-Controller Description: High Definition Audio-Controller Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: HDAudBus Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 552: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 556: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 512: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 672: DNSServiceGetAddrInfo v4v6 BLACKBERRY-47A9.local. Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 672: Could not write data to client because of error - aborting connection Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: send_msg ERROR: failed to write 89 of 89 bytes to fd 672 errno 10053 (Eine bestehende Verbindung wurde softwaregesteuert durch den Hostcomputer abgebrochen.) Error: (02/28/2015 11:10:56 AM) (Source: Microsoft Office 14) (EventID: 2001) (User: ) Description: Microsoft Word: Rejected Safe Mode action : Schwerwiegender Fehler in Word beim send to bluetooth-Add-In. Falls diese Fehlermeldung mehrmals angezeigt wurde, sollten Sie dieses Add-In deaktivieren und überprüfen, ob ein Update verfügbar ist. Möchten Sie dieses Add-In deaktivieren?. Rejected Safe Mode action : Microsoft Word. System errors: ============= Error: (02/28/2015 10:45:19 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "ReadyComm.DirectRouter" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (02/28/2015 10:43:41 AM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (02/28/2015 10:43:14 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: acedrv07 Error: (02/28/2015 10:42:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "sbapifs" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (02/27/2015 06:09:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "ReadyComm.DirectRouter" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (02/27/2015 06:07:07 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: acedrv07 Error: (02/27/2015 06:04:19 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (02/27/2015 06:03:40 PM) (Source: BugCheck) (EventID: 1001) (User: ) Description: 0x00000050 (0xfffff8a016ea1000, 0x0000000000000000, 0xfffff88002eb1c02, 0x0000000000000000)C:\windows\MEMORY.DMP022715-33867-01 Error: (02/27/2015 06:03:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "sbapifs" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (02/27/2015 06:03:16 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 27.02.2015 um 18:02:02 unerwartet heruntergefahren. Microsoft Office Sessions: ========================= Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 552: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 556: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 512: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 672: DNSServiceGetAddrInfo v4v6 BLACKBERRY-47A9.local. Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 672: Could not write data to client because of error - aborting connection Error: (02/28/2015 00:20:17 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: send_msg ERROR: failed to write 89 of 89 bytes to fd 672 errno 10053 (Eine bestehende Verbindung wurde softwaregesteuert durch den Hostcomputer abgebrochen.) Error: (02/28/2015 11:10:56 AM) (Source: Microsoft Office 14) (EventID: 2001) (User: ) Description: Microsoft WordSchwerwiegender Fehler in Word beim send to bluetooth-Add-In. Falls diese Fehlermeldung mehrmals angezeigt wurde, sollten Sie dieses Add-In deaktivieren und überprüfen, ob ein Update verfügbar ist. Möchten Sie dieses Add-In deaktivieren? CodeIntegrity Errors: =================================== Date: 2015-02-28 10:42:46.138 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-28 10:42:45.904 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-27 18:03:07.071 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-27 18:03:06.837 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-27 15:40:02.638 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-27 15:40:02.404 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-26 10:22:50.513 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-26 10:22:50.294 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-26 10:07:35.904 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-26 10:07:35.655 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3 CPU M 380 @ 2.53GHz Percentage of memory in use: 49% Total physical RAM: 3892.48 MB Available physical RAM: 1975.41 MB Total Pagefile: 7783.14 MB Available Pagefile: 4997.57 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:653 GB) (Free:391.78 GB) NTFS Drive d: (LENOVO) (Fixed) (Total:30.69 GB) (Free:0.01 GB) NTFS Drive f: (Tales of Monkey Island) (CDROM) (Total:3.19 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: 8DC0DBDA) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=653 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=30.7 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=14.8 GB) - (Type=12) ==================== End Of Log ============================ |
28.02.2015, 16:24 | #2 |
/// the machine /// TB-Ausbilder | PUP.Optional.Squeaky.A durch MalewareBytes auf dem Rechner gefunden hi,
__________________alles sauber, das war nur ein Reg-Key. Office programs may crash with the SendToBluetooth add-in installed
__________________ |
28.02.2015, 21:22 | #3 |
| PUP.Optional.Squeaky.A durch MalewareBytes auf dem Rechner gefunden Puh, da bin ich erleichtert. Dann sind wir schon fertig.
__________________Vielen Dank, ennachen |
01.03.2015, 15:47 | #4 |
/// the machine /// TB-Ausbilder | PUP.Optional.Squeaky.A durch MalewareBytes auf dem Rechner gefunden Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu PUP.Optional.Squeaky.A durch MalewareBytes auf dem Rechner gefunden |
antivir, antivirus, branding, browser, combofix, converter, device driver, downloader, dvdvideosoft ltd., failed, firefox, flash player, homepage, installation, logfile, mozilla, pup.optional.squeaky.a, realtek, registry, security, software, svchost.exe, tunnel, windows |