![]() |
|
Log-Analyse und Auswertung: Fake DHL EMail, zip runtergeladen, pdf doppelgeklickt, welches dann verschwunden ist...Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Fake DHL EMail, zip runtergeladen, pdf doppelgeklickt, welches dann verschwunden ist... Auch ich bin der DHL Fake Email auf den Leim gegangen und habe leider unüberlegt gehandelt. Ich habe den Link geöffnet, die zip runtergeladen und entpackt und das darin enthaltene pdf doppelgeklickt, welches danach einfach verschwand. Ich wusste natürlich direkt, dass etwas nicht stimmt und versuche nun hier mein Glück. Hier die Email: Code:
ATTFilter Verehrte Frau, verehrter Herr, Ihre unter der Nummer 10199743191319109974 erfaßte Sendung wurde von DHL in Empfang genommen und voraussichtlich für den 03.03.2015 zur Auslieferung vorgesehen. Über die nachfolgende Verlinkung werden weitere Informationen zu Ihrer Sendung ausgegeben: 10199743191319109974. Mit freundlichen Grüßen, Ihr Transport-Team Und hier der Link zur zip: Code:
ATTFilter hxxp://www.item.u5937083.fsdata.se/dhl_paket_de_pkp Windows Microsoft 8.1 Prozessor: Intel Core i7 CPU @ 2.67GHZ Arbeitsspeicher: 6GB Systemtyp: 64-Bit-Betriebssystem, x64-basierter Prozessor Grafikkarte: NVIDIA GeForce GTX 285 Anbei meine logs von FRST, Addition, TDSSKiller und mbar. Wäre nett wenn einer der Pros mal rein schauen würde, kenne mich leider nicht so gut aus. FRST FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-03-2015 Ran by Ben (administrator) on BEN-DESKTOP on 03-03-2015 22:55:07 Running from C:\Users\Ben\Desktop Loaded Profiles: Ben (Available profiles: Ben & DefaultAppPool) Platform: Windows 8.1 Pro with Media Center (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Apple Inc.) C:\Program Files (x86)\AirPrint\airprint.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (IVT Corporation) C:\Program Files (x86)\IVT Corporation\BlueSoleil\BlueSoleilCS.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Windows\splwow64.exe () C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (IVT Corporation) C:\Program Files (x86)\IVT Corporation\BlueSoleil\BsHelpCS.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Hobbyist Software) C:\Program Files (x86)\Hobbyist Software\VLC Streamer\VLC Streamer Configuration.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Spotify Ltd) C:\Users\Ben\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () C:\Users\Ben\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Sony Computer Entertainment Inc.) C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe (IVT Corporation) C:\Program Files (x86)\IVT Corporation\BlueSoleil\BtTray.exe (Sony Computer Entertainment Inc.) C:\Program Files (x86)\Sony\Content Manager Assistant\CMAWatcher.exe (IgniteGT) C:\IgniteGT\Simraceway\SRWAgent.exe (Razer USA Ltd) C:\Program Files (x86)\Razer\Lachesis 5600\LachesisSysTray.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe () C:\Users\Ben\Desktop\adwcleaner_4.111.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1840720 2007-04-03] (CANON INC.) HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [644696 2007-05-14] (CANON INC.) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation) HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2273056 2013-11-29] (NVIDIA Corporation) HKLM-x32\...\Run: [BtTray] => C:\Program Files (x86)\IVT Corporation\BlueSoleil\BtTray.exe [319574 2010-10-25] (IVT Corporation) HKLM-x32\...\Run: [MChk] => C:\Windows\system32\r.exe HKLM-x32\...\Run: [NBKeyScan] => "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" HKLM-x32\...\Run: [Razer Lachesis Driver] => C:\Program Files (x86)\Razer\Lachesis 5600\LachesisSysTray.exe [760720 2010-12-02] (Razer USA Ltd) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310128 2013-02-13] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [BingDesktop] => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2258056 2013-09-22] (Microsoft Corp.) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [193568 2014-10-13] (Geek Software GmbH) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM Group Policy restriction on software: C:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe <====== ATTENTION HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <====== ATTENTION HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <====== ATTENTION HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Run: [Hobbyist Software VLC Streamer] => C:\Program Files (x86)\Hobbyist Software\VLC Streamer\VLC Streamer Configuration.exe [1194824 2014-09-11] (Hobbyist Software) HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-02-22] (Hewlett-Packard Company) HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Run: [Spotify Web Helper] => C:\Users\Ben\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2015-01-17] (Spotify Ltd) HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Run: [Xvid] => C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] () HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1509232 2013-02-13] (Samsung) HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Run: [KiesAirMessage] => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe [578560 2013-02-06] (Samsung Electronics) HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Run: [] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844144 2013-02-13] (Samsung) HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Run: [Amazon Cloud Player] => C:\Users\Ben\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2013-12-12] () HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Run: [GoogleChromeAutoLaunch_8B4B86C2A5661DC92D9A84E265233F91] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592 2015-02-17] (Google Inc.) HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Run: [msdbd948108.exe] => C:\Users\Ben\AppData\Roaming\Microsoft\msdbd948108.exe [323661 2013-08-22] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Inhaltsmanager-Assistent für PlayStation(R).lnk ShortcutTarget: Inhaltsmanager-Assistent für PlayStation(R).lnk -> C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SRW Download Manager.lnk ShortcutTarget: SRW Download Manager.lnk -> C:\IgniteGT\Simraceway\SRWAgent.exe (IgniteGT) Startup: C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Ben\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File) ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: [S-1-5-21-3405083392-531059733-2769391109-1001] => http=127.0.0.1:5555 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKU\S-1-5-21-3405083392-531059733-2769391109-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM-x32 -> DefaultScope value is missing. BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default FF Homepage: hxxp://www.sweet-page.com/?type=hp&ts=1390044303&from=cor&uid=M4-CT128M4SSD1_00000000115203307FDF FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.102.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.7 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @real.com/nppl3260;version=6.0.12.448 -> C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 -> C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3405083392-531059733-2769391109-1001: @onlive.com/OnLiveGameClientDetector,version=1.0.0 -> C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll (OnLive) FF Plugin HKU\S-1-5-21-3405083392-531059733-2769391109-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101753.dll (Amazon.com, Inc.) FF Plugin HKU\S-1-5-21-3405083392-531059733-2769391109-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.) FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\alle-preise---guenstigerde.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\beemp3.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\dictcc-deen.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\filestube.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\geizhalsat-deutschland.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\google-autotranslate.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\google-images-1920x1080.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\guenstiger.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\idealode.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\imdb.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\mycroft-project.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\urban-dictionary.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\wiktionary-de.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\xrel.xml FF SearchPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\searchplugins\youtube-videosuche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml FF Extension: Fast Dial - C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\Extensions\fastdial@telega.phpnet.us [2014-09-24] FF Extension: ProxTube - C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\Extensions\ich@maltegoetz.de.xpi [2014-09-15] FF Extension: Awesome screenshot: Capture and Annotate - C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2012-05-11] FF Extension: Personas Plus - C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\Extensions\personas@christopher.beard.xpi [2013-03-01] FF Extension: Tab Counter - C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\Extensions\tabcounter@morac.xpi [2012-01-24] FF Extension: Download Status Bar - C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2013-12-27] FF Extension: Adblock Plus - C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-06-19] FF Extension: Download Statusbar - C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\cvnu3wic.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2011-11-02] Chrome: ======= CHR HomePage: Default -> CHR Profile: C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-12-13] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-15] CHR Extension: (YouTube) - C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-13] CHR Extension: (No Name) - C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml [2014-01-18] CHR Extension: (Google Search) - C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-13] CHR Extension: (Session Buddy) - C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\edacconmaakjimmfgnblocblbcdcpbko [2014-01-18] CHR Extension: (Google Analytics Opt-out Add-on (by Google)) - C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\fllaojicojecljbmefodhfapmkghcbnh [2012-12-13] CHR Extension: (AdBlock) - C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2012-12-13] CHR Extension: (Tabs Counter) - C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibokmmioadhomkeikgbfenloopldkcoi [2012-12-13] CHR Extension: (Search Box) - C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\mknehpjhljpfaghmicofickbkdagooni [2012-12-13] CHR Extension: (Google Wallet) - C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Gmail) - C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-13] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AirPrint; C:\Program Files (x86)\AirPrint\Airprint.exe [234784 2010-12-23] (Apple Inc.) R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-09-22] (Microsoft Corp.) R2 BlueSoleilCS; C:\Program Files (x86)\IVT Corporation\BlueSoleil\BlueSoleilCS.exe [1765484 2010-10-26] (IVT Corporation) [File not signed] R3 BsHelpCS; C:\Program Files (x86)\IVT Corporation\BlueSoleil\BsHelpCS.exe [192000 2010-10-25] (IVT Corporation) [File not signed] R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2711736 2015-01-13] (Microsoft Corporation) R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-02-22] (Hewlett-Packard Company) [File not signed] R2 MSMQ; C:\Windows\system32\mqsvc.exe [25600 2013-11-09] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1370912 2013-11-29] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15128352 2013-11-29] (NVIDIA Corporation) R2 Simraceway Update Service; C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe [1630720 2013-07-11] () [File not signed] S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-11-09] (Microsoft Corporation) R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [546304 2013-11-09] (Microsoft Corporation) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 Abyssus; C:\Windows\System32\drivers\Abyssus.sys [10880 2009-10-30] (Razer (Asia-Pacific) Pte Ltd) R3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [42888 2010-06-24] (IVT Corporation.) S3 Logi_Headset_DFU; C:\Windows\System32\Drivers\lhusbdfuamd64.sys [44136 2013-09-30] (CSR plc.) R1 MpKsl9d25ff37; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D0B6424B-853B-4B8A-88DA-F0DB58FD82B9}\MpKsl9d25ff37.sys [45352 2015-03-03] (Microsoft Corporation) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [173568 2013-11-09] (Microsoft Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2013-10-30] (NVIDIA Corporation) R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [141920 2012-08-31] (Acronis) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) R3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation) S3 cpuz136; \??\C:\WINDOWS\TEMP\cpuz136\cpuz136_x64.sys [X] U3 idsvc; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-03 22:55 - 2015-03-03 22:55 - 00027600 _____ () C:\Users\Ben\Desktop\FRST.txt 2015-03-03 22:53 - 2015-03-03 22:55 - 00000000 ____D () C:\FRST 2015-03-03 22:52 - 2015-03-03 22:52 - 02092544 _____ (Farbar) C:\Users\Ben\Desktop\FRST64.exe 2015-03-03 22:42 - 2015-03-03 22:43 - 02126848 _____ () C:\Users\Ben\Desktop\adwcleaner_4.111.exe 2015-02-24 23:48 - 2014-12-13 22:28 - 00513488 _____ () C:\WINDOWS\SysWOW64\locale.nls 2015-02-24 23:48 - 2014-12-13 22:28 - 00513488 _____ () C:\WINDOWS\system32\locale.nls 2015-02-24 23:48 - 2014-10-29 02:27 - 01200128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll 2015-02-24 23:48 - 2014-10-29 02:27 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll 2015-02-24 23:48 - 2014-10-29 02:04 - 00868352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll 2015-02-24 23:48 - 2014-10-29 02:04 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll 2015-02-21 16:59 - 2015-02-21 16:59 - 04560561 _____ () C:\Users\Ben\Desktop\Bewerbungsunterlagen.rar 2015-02-21 16:58 - 2015-02-21 16:58 - 00000000 ____D () C:\Users\Ben\Desktop\Bewerbungsunterlagen 2015-02-21 14:10 - 2015-02-24 23:48 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2015-02-13 18:29 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2015-02-13 18:29 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2015-02-11 00:56 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2015-02-11 00:56 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2015-02-11 00:56 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2015-02-11 00:56 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2015-02-11 00:56 - 2015-01-13 23:11 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2015-02-11 00:56 - 2015-01-13 23:04 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2015-02-11 00:56 - 2015-01-10 10:10 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2015-02-11 00:56 - 2015-01-10 10:10 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2015-02-11 00:56 - 2015-01-10 09:28 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2015-02-11 00:56 - 2015-01-10 08:00 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2015-02-11 00:56 - 2015-01-10 07:38 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2015-02-11 00:56 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scesrv.dll 2015-02-11 00:56 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll 2015-02-11 00:56 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll 2015-02-11 00:56 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 2015-02-11 00:56 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll 2015-02-11 00:56 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll 2015-02-11 00:56 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll 2015-02-11 00:56 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll 2015-02-11 00:56 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm64.dll 2015-02-11 00:56 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2015-02-11 00:56 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll 2015-02-11 00:56 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll 2015-02-11 00:56 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe 2015-02-11 00:56 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe 2015-02-11 00:56 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe 2015-02-11 00:55 - 2015-02-04 00:38 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2015-02-11 00:55 - 2015-02-04 00:08 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2015-02-11 00:55 - 2015-02-04 00:08 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2015-02-11 00:55 - 2015-02-03 00:11 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2015-02-11 00:55 - 2015-02-03 00:11 - 00894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2015-02-11 00:55 - 2015-02-03 00:11 - 00609280 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2015-02-11 00:55 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2015-02-11 00:55 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-02-11 00:55 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-02-11 00:55 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2015-02-11 00:55 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll 2015-02-11 00:55 - 2015-01-12 03:34 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2015-02-11 00:55 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-02-11 00:55 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 2015-02-11 00:55 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2015-02-11 00:55 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2015-02-11 00:55 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 2015-02-11 00:55 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-02-11 00:55 - 2015-01-12 02:58 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2015-02-11 00:55 - 2015-01-12 02:55 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2015-02-11 00:55 - 2015-01-12 02:51 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2015-02-11 00:55 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2015-02-11 00:55 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2015-02-11 00:55 - 2015-01-12 02:48 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2015-02-11 00:55 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2015-02-11 00:55 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll 2015-02-11 00:55 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-02-11 00:55 - 2015-01-12 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2015-02-11 00:55 - 2015-01-12 02:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2015-02-11 00:55 - 2015-01-12 02:27 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2015-02-11 00:55 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2015-02-11 00:55 - 2015-01-12 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2015-02-11 00:55 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2015-02-11 00:55 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2015-02-11 00:55 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2015-02-11 00:55 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-02-11 00:55 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-02-11 00:55 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2015-02-11 00:55 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2015-02-11 00:55 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-02-11 00:55 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2015-02-11 00:55 - 2015-01-10 09:22 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2015-02-11 00:55 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2015-02-11 00:55 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2015-02-11 00:55 - 2014-12-09 00:12 - 00391526 _____ () C:\WINDOWS\system32\ApnDatabase.xml 2015-02-10 23:23 - 2015-02-10 23:28 - 00000000 ____D () C:\Users\Ben\Desktop\GateWay 2015-02-10 23:17 - 2015-02-10 23:17 - 00337056 _____ () C:\WINDOWS\Minidump\021015-16125-01.dmp 2015-02-09 22:12 - 2015-02-09 22:12 - 00337112 _____ () C:\WINDOWS\Minidump\020915-9015-01.dmp 2015-02-09 21:52 - 2015-02-09 21:52 - 00001025 _____ () C:\Users\Public\Desktop\UE BOOM Update-Assistent 1.4.50.lnk 2015-02-09 21:52 - 2015-02-09 21:52 - 00000000 ____D () C:\Program Files (x86)\UE BOOM Update-Assistent 1.4.50 2015-02-07 16:27 - 2015-02-07 16:27 - 00000012 _____ () C:\Users\Ben\Desktop\3monkey.me VPN 2 Tage Test Code.txt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-03 22:52 - 2014-01-18 15:32 - 00000000 ____D () C:\AdwCleaner 2015-03-03 22:48 - 2013-03-18 12:40 - 01945726 _____ () C:\Simraceway.log 2015-03-03 22:37 - 2014-01-18 15:52 - 00000000 ____D () C:\Users\Ben\AppData\Local\JDownloader v2.0 2015-03-03 22:37 - 2013-09-30 05:14 - 02071876 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-03-03 22:37 - 2013-09-30 04:58 - 00879736 _____ () C:\WINDOWS\system32\perfh007.dat 2015-03-03 22:37 - 2013-09-30 04:58 - 00201766 _____ () C:\WINDOWS\system32\perfc007.dat 2015-03-03 22:29 - 2012-12-13 04:18 - 00001142 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-03 22:29 - 2012-12-13 04:18 - 00001138 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-03 22:18 - 2013-11-09 14:01 - 01132011 _____ () C:\WINDOWS\WindowsUpdate.log 2015-03-03 22:12 - 2012-09-14 13:21 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-03-03 22:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2015-03-03 21:58 - 2013-11-23 15:02 - 00000000 ___DO () C:\Users\Ben\SkyDrive 2015-03-03 21:58 - 2013-08-22 15:46 - 00042269 _____ () C:\WINDOWS\setupact.log 2015-03-03 21:58 - 2012-05-28 15:58 - 00005063 _____ () C:\WINDOWS\SysWOW64\LOCALSERVICE.INI 2015-03-03 21:58 - 2012-05-28 15:58 - 00000092 _____ () C:\WINDOWS\SysWOW64\LOCALDEVICE.INI 2015-03-03 21:58 - 2010-10-26 10:04 - 00001089 _____ () C:\WINDOWS\SysWOW64\bscs.ini 2015-03-03 21:57 - 2013-11-09 14:01 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-03-03 21:57 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-03-03 14:17 - 2009-10-14 06:13 - 00295552 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2015-03-02 22:49 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2015-02-28 19:10 - 2011-01-10 23:50 - 00000000 ____D () C:\Users\Ben\AppData\Roaming\vlc 2015-02-28 16:56 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2015-02-28 16:54 - 2012-12-04 23:26 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3405083392-531059733-2769391109-1001 2015-02-28 16:43 - 2013-03-18 12:40 - 00000000 ____D () C:\Users\Ben\AppData\Roaming\Simraceway 2015-02-28 16:40 - 2013-09-29 20:05 - 00083312 _____ () C:\WINDOWS\PFRO.log 2015-02-24 23:58 - 2014-08-07 22:48 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2015-02-24 23:46 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2015-02-21 16:21 - 2012-06-18 23:33 - 00000000 ____D () C:\Users\Ben\AppData\Roaming\Spotify 2015-02-21 15:19 - 2014-06-20 14:29 - 00000000 ____D () C:\Users\Ben\Desktop\Neue Musik 2015-02-21 14:35 - 2012-06-18 23:33 - 00000000 ____D () C:\Users\Ben\AppData\Local\Spotify 2015-02-21 14:34 - 2013-11-16 12:18 - 00000000 ____D () C:\ProgramData\Oracle 2015-02-21 14:21 - 2013-07-02 00:38 - 00000000 ____D () C:\Program Files\Java 2015-02-21 14:20 - 2014-02-15 11:04 - 00272296 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe 2015-02-21 14:20 - 2013-11-16 12:18 - 00176552 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe 2015-02-21 14:20 - 2013-11-16 12:18 - 00176552 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe 2015-02-21 14:20 - 2013-11-16 12:18 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2015-02-21 14:20 - 2013-11-16 12:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-02-21 14:20 - 2013-07-02 00:38 - 00319912 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2015-02-21 14:20 - 2013-07-02 00:38 - 00191400 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2015-02-21 14:20 - 2013-07-02 00:38 - 00190888 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2015-02-21 14:20 - 2013-07-02 00:38 - 00111016 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll 2015-02-21 14:20 - 2013-07-02 00:35 - 00000000 ____D () C:\Program Files (x86)\Java 2015-02-21 14:10 - 2011-06-21 16:25 - 00000000 ____D () C:\Program Files (x86)\Adobe 2015-02-21 14:10 - 2010-01-13 00:29 - 00000000 ____D () C:\ProgramData\Adobe 2015-02-17 22:38 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache 2015-02-13 18:24 - 2013-08-22 15:44 - 00493632 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2015-02-12 00:41 - 2014-12-13 17:30 - 00000000 ____D () C:\WINDOWS\system32\appraiser 2015-02-12 00:41 - 2014-07-13 19:13 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 2015-02-11 22:26 - 2013-08-14 09:49 - 00000000 ____D () C:\WINDOWS\system32\MRT 2015-02-11 22:21 - 2009-10-14 06:12 - 116773704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-02-11 00:08 - 2013-11-09 14:03 - 00000000 ____D () C:\Users\Ben 2015-02-10 23:22 - 2014-08-14 20:52 - 00000000 ____D () C:\Users\Ben\Desktop\Neuer Desktop Ordner nach 27 Zoll 2015-02-10 23:17 - 2013-11-10 21:02 - 00000000 ____D () C:\WINDOWS\Minidump 2015-02-09 22:24 - 2012-12-13 04:18 - 00004114 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-09 22:24 - 2012-12-13 04:18 - 00003878 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-09 21:52 - 2013-11-23 18:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultimate Ears 2015-02-07 17:12 - 2012-09-14 13:21 - 00003796 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-02-07 16:18 - 2013-11-10 21:32 - 02488832 ___SH () C:\Users\Ben\Desktop\Thumbs.db 2015-02-03 20:31 - 2013-08-22 16:38 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-02-03 20:31 - 2013-08-22 16:38 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-02-01 21:24 - 2012-05-11 13:56 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service ==================== Files in the root of some directories ======= 2010-02-07 11:04 - 2013-03-22 14:07 - 0000600 _____ () C:\Users\Ben\AppData\Roaming\winscp.rnd 2010-04-18 23:36 - 2013-02-04 18:50 - 0010240 _____ () C:\Users\Ben\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2010-09-22 00:22 - 2010-09-22 00:22 - 0000337 _____ () C:\Users\Ben\AppData\Local\Perfmon.PerfmonCfg 2010-01-24 17:30 - 2010-01-24 17:30 - 0000017 _____ () C:\Users\Ben\AppData\Local\resmon.resmoncfg Some content of TEMP: ==================== C:\Users\Ben\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcpowob.dll C:\Users\Ben\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Ben\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Ben\AppData\Local\Temp\jre-8u31-windows-au.exe C:\Users\Ben\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Ben\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Ben\AppData\Local\Temp\nvStInst.exe C:\Users\Ben\AppData\Local\Temp\pdf24-creator-update.exe C:\Users\Ben\AppData\Local\Temp\proxy_vole2059752059536163529.dll C:\Users\Ben\AppData\Local\Temp\Quarantine.exe C:\Users\Ben\AppData\Local\Temp\sfamcc00001.dll C:\Users\Ben\AppData\Local\Temp\sfextra.dll C:\Users\Ben\AppData\Local\Temp\sqlite3.dll C:\Users\Ben\AppData\Local\Temp\vlc-2.1.2-win32.exe C:\Users\Ben\AppData\Local\Temp\vlc-2.1.3-win32.exe C:\Users\Ben\AppData\Local\Temp\vlc-2.1.5-win32.exe C:\Users\Ben\AppData\Local\Temp\VLCStreamerSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-03 22:12 ==================== End Of Log ============================ Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-03-2015 Ran by Ben at 2015-03-03 22:55:54 Running from C:\Users\Ben\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 3DMark (HKLM-x32\...\{F1A6C690-C12C-4E7A-B4BD-958678215418}) (Version: 1.1 - Futuremark) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) AFPL Ghostscript 8.54 (HKLM-x32\...\AFPL Ghostscript 8.54) (Version: - ) AFPL Ghostscript Fonts (HKLM-x32\...\AFPL Ghostscript Fonts) (Version: - ) Amazon Cloud Player (HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Amazon Amazon Cloud Player) (Version: 2.2.0.399 - Amazon Services LLC) Amazon MP3-Downloader 1.0.17 (HKLM-x32\...\Amazon MP3-Downloader) (Version: 1.0.17 - Amazon Services LLC) Amazon Music Importer (HKLM-x32\...\com.amazon.music.uploader) (Version: 2.0.1 - Amazon Services LLC) Amazon Music Importer (x32 Version: 2.0.1 - Amazon Services LLC) Hidden Avidemux 2.6 (32-bit) (HKLM-x32\...\Avidemux 2.6) (Version: 2.6.3.8518 - ) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.1.7 - EA Digital Illusions CE AB) Bing-Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.322.0 - Microsoft Corporation) BlueSoleil 7.0.348.1 (HKLM\...\{208DF080-1321-4443-B9EE-D13380C3577C}) (Version: 7.0.348.1 - IVT Corporation) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Canon MP Navigator EX 1.0 (HKLM-x32\...\MP Navigator EX 1.0) (Version: - ) Canon MP610 series (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP610_series) (Version: - ) Canon MP610 series Benutzerregistrierung (HKLM-x32\...\Canon MP610 series Benutzerregistrierung) (Version: - ) Canon My Printer (HKLM\...\CanonMyPrinter) (Version: - ) Canon Utilities Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - ) Canon Utilities Solution Menu (HKLM-x32\...\CanonSolutionMenu) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.04 - Piriform) CD-LabelPrint (HKLM-x32\...\MediaNavigation.CDLabelPrint) (Version: - ) CIB pdf brewer (HKLM\...\{E9E6A9B7-89B7-41D3-90A1-710E82427097}) (Version: 2.6.0034 - CIB software GmbH) Core Temp 1.0 RC3 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.0 - Alcpu) CPUID HWMonitor 1.19 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) CrystalDiskInfo 5.0.0 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 5.0.0 - Crystal Dew World) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Dropbox) (Version: 2.10.27 - Dropbox, Inc.) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc) F1 2010 (x32 Version: 1.0.0001.132 - Codemasters) Hidden F1 2012 (HKLM-x32\...\Steam App 208500) (Version: - ) Fanatec Wheel (HKLM\...\{1212516D-C434-4A14-9107-CE271E186019}) (Version: 8.14.4 - Endor AG) Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.02 - Ubisoft) Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.17.0 - Futuremark Corporation) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Grand Theft Auto: Episodes from Liberty City (x32 Version: 1.0.0002.135 - Rockstar Games Inc.) Hidden HideIPVPN 2.0.0.3 (HKLM-x32\...\HideIPVPN) (Version: 2.0.0.3 - ) Inhaltsmanager-Assistent für PlayStation(R) (HKLM-x32\...\{32C46540-7693-49E1-A81E-121B09C8303B}) (Version: 3.00.7187.47 - Sony Computer Entertainment Inc.) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: - ) Java 8 Update 31 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418031F0}) (Version: 8.0.310 - Oracle Corporation) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) JavaFX 2.1.0 (HKLM-x32\...\{1111706F-666A-4037-7777-210328764D10}) (Version: 2.1.0 - Oracle Corporation) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LightScribe Applications (HKLM-x32\...\{88A4002B-BDBA-49A2-927C-D81E8DF32B1B}) (Version: 1.18.5.1 - LightScribe) LightScribe System Software (HKLM-x32\...\{6AFDE3BE-BC01-45A4-9D06-BBF5AD207313}) (Version: 1.18.12.1 - LightScribe) LightScribe Template Labeler (HKLM-x32\...\{7FD71A9E-C4D3-42ED-A998-CDA8290C39A3}) (Version: 1.18.5.1 - LightScribe) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Metro Last Light Update 2 (.v1.0.0.2.) 1.00 (HKLM-x32\...\Metro Last Light Update 2 (.v1.0.0.2.) 1.00) (Version: 1.00 - .x.X.RIDDICK.X.x.) Metro: Last Light (c) Deep Silver version 1 (HKLM-x32\...\TWV0cm9MYXN0TGlnaHQ=_is1) (Version: 1 - ) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Office Professional Plus 2013 - de-de (HKLM\...\ProPlusRetail - de-de) (Version: 15.0.4693.1002 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft) Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.1.177.0 - Microsoft Corporation) Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) Mozilla Thunderbird (5.0) (HKLM-x32\...\Mozilla Thunderbird (5.0)) (Version: 5.0 (de) - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MXGP (HKLM-x32\...\TVhHUA==_is1) (Version: 1 - ) NirSoft BlueScreenView (HKLM-x32\...\NirSoft BlueScreenView) (Version: - ) Notepad++ (HKLM-x32\...\Notepad++) (Version: 5.9.8 - ) NVIDIA 3D Vision Controller-Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.82 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.82 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8 - NVIDIA Corporation) NVIDIA Grafiktreiber 331.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.82 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation) NVIDIA Virtual Audio 1.2.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.12 - NVIDIA Corporation) Office 15 Click-to-Run Extensibility Component (Version: 15.0.4693.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4631.1004 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4631.1004 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4693.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (Version: 15.0.4693.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4631.1004 - Microsoft Corporation) Hidden OnLive (HKLM-x32\...\OnLive) (Version: - OnLive) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Origin (HKLM-x32\...\Origin) (Version: 9.2.1.4399 - Electronic Arts, Inc.) PDF Blender (HKLM-x32\...\PDF Blender) (Version: - ) PDF24 Creator 6.8.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Pflanzen gegen Zombies™ (HKLM-x32\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.) plist Editor for Windows 1.0.2 (HKLM-x32\...\plist Editor for Windows) (Version: 1.0.2 - VOWSoft,Ltd.) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.) PVSonyDll (Version: 1.00.0001 - NVIDIA Corporation) Hidden RaceRoom Racing Experience (HKLM-x32\...\Steam App 211500) (Version: - ) Razer Lachesis 5600 (HKLM-x32\...\{580AEA6C-E35C-4470-818F-0F0A083EE1AD}) (Version: 2.01.01 - Razer USA Ltd.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.5.0.12114_1 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.5.0.12114_1 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.18.0 - SAMSUNG Electronics Co., Ltd.) SHIELD Streaming (Version: 1.6.75 - NVIDIA Corporation) Hidden Simraceway 28.87 (HKLM-x32\...\Simraceway) (Version: 28.87 - Simraceway) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Sniper Elite 3 (HKLM-x32\...\U25pcGVyRWxpdGUz_is1) (Version: 1 - ) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Spotify (HKU\S-1-5-21-3405083392-531059733-2769391109-1001\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Steuersparer 2014 (HKLM-x32\...\{485DBEA2-58E9-4136-9E6C-6C3022B02349}) (Version: 21.00.8480 - Buhl Data Service GmbH) System Requirements Lab for Intel (HKLM-x32\...\{53C63F43-B827-42D9-8886-4698D91EA33B}) (Version: 4.5.15.0 - Husdawg, LLC) Trials Evolution Gold Edition (HKLM-x32\...\InstallShield_{07D857B8-C956-401D-BC8F-EDA8459AF037}) (Version: 1.0.0.3 - Ubisoft) Trials Evolution Gold Edition (x32 Version: 1.0.0.3 - Ubisoft) Hidden UE BOOM Update-Assistent (HKLM-x32\...\{3E5B449E-C707-49CE-B45B-1CCEF3FC27E2}) (Version: 1.4.50 - Logitech, Inc.) UE BOOM Update-Assistent (HKLM-x32\...\{E0426B93-AA36-4A2C-9BBD-9096BB9908F3}) (Version: 1.3.58 - Logitech, Inc.) Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft) VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM-x32\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) VLC Streamer 4.81 (HKLM-x32\...\VLC Streamer_is1) (Version: - ) Win7codecs (HKLM-x32\...\{8C0CAA7A-3272-4991-A808-2C7559DE3409}) (Version: 2.2.6 - Shark007) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) WinSCP 4.2.5 (HKLM-x32\...\winscp3_is1) (Version: 4.2.5 - Martin Prikryl) Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-3405083392-531059733-2769391109-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Ben\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File CustomCLSID: HKU\S-1-5-21-3405083392-531059733-2769391109-1001_Classes\CLSID\{312BFDCE-A901-4203-B4F2-ADCB957D1887}\InprocServer32 -> C:\ProgramData\Windows\msseedir.dll No File CustomCLSID: HKU\S-1-5-21-3405083392-531059733-2769391109-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ben\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3405083392-531059733-2769391109-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ben\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3405083392-531059733-2769391109-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ben\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3405083392-531059733-2769391109-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ben\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3405083392-531059733-2769391109-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ben\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3405083392-531059733-2769391109-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ben\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3405083392-531059733-2769391109-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ben\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3405083392-531059733-2769391109-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ben\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ==================== Restore Points ========================= ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2011-12-31 00:38 - 00000878 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0A2A8832-26AB-45F1-A3EB-9F69B315A36D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-07] (Adobe Systems Incorporated) Task: {1435CFF7-C187-4F9F-BB2B-9B3B258B07D9} - System32\Tasks\{C9DD2D2F-6DC2-4229-B2F7-7F186B1EC675} => C:\Program Files (x86)\SEGA\Renegade Ops\Launcher.exe Task: {1A670A5A-D193-43D1-9F8A-C93C6642CE51} - System32\Tasks\{858739C7-A111-4098-83F6-50FE6802566C} => pcalua.exe -a D:\Software\setupstb.exe -d D:\Software Task: {1CEF8394-7F98-4C4D-BB1A-3B0B344BE068} - System32\Tasks\{89F85CE3-4F28-42F0-9800-5CF9859C09E3} => pcalua.exe -a C:\Users\Ben\Desktop\jre-6u20-windows-i586-iftw-rv.exe -d C:\Users\Ben\Desktop Task: {2DDB6ACA-F0D0-4300-9A6C-7EA882A48D64} - System32\Tasks\{4C50E6BB-01E1-4D2A-AD46-E34598DC5624} => C:\Users\Ben\Desktop\ExtFat32_v2.00\DeleteBinFilesFromSystem32.exe Task: {370D8711-E790-4955-853B-345428513151} - System32\Tasks\{5ACBDDB1-78D7-48E4-A920-F179283830B8} => C:\Users\Ben\Desktop\iRecovery\iRecovery_SVN\iRecovery.exe Task: {392FFF77-1805-450B-B5C5-91AAB824E100} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-07-22] (Piriform Ltd) Task: {3AF964CC-16DF-4AE4-8AB4-9DB6E7734BAB} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\MpCmdRun.exe Task: {410E351D-52E7-4449-A7E2-2B7D64BC648A} - System32\Tasks\{F5B4C042-677A-453F-BB6E-3288865F132B} => pcalua.exe -a C:\Users\Ben\Desktop\blazingcolorsviz.exe -d C:\Users\Ben\Desktop Task: {4166FD90-5C1C-4190-BE59-4B43E1DFDF66} - System32\Tasks\{768EC248-ED6C-4043-9C62-232359258156} => pcalua.exe -a C:\Users\Ben\Desktop\cibpdfbrewer26.exe -d C:\Users\Ben\Desktop Task: {46BD9830-89CA-494C-86F8-04382CDEA9F8} - System32\Tasks\{3CE04636-715F-4F18-AD6F-E71D861BE861} => pcalua.exe -a C:\Users\Ben\Desktop\jxpiinstall.exe -d C:\Users\Ben\Desktop Task: {4D794245-759F-42C4-9B8E-C8CFD7D18D69} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-01-29] (Microsoft Corporation) Task: {51FA22C6-61BB-4958-8B21-5A8DF0BBBA0E} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-01-29] (Microsoft) Task: {5217DB58-FCB2-4AE8-BFB5-FADCA93D79D7} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-12-30] (Microsoft Corporation) Task: {53FF6DD0-655D-4464-A149-3B07DE75A253} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {57AC180D-59B0-4F05-9A83-26D4E65D2A08} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {588C1A24-EE59-4BF0-9521-15611CDE2B2B} - System32\Tasks\Microsoft_Hardware_Launch_rundll32_exe => Rundll32.exe url.dll,OpenURL hxxp://go.microsoft.com/fwlink/?LinkID=130644 Task: {5BADED4C-B830-4958-A3BC-7CE8E3C2DDC2} - System32\Tasks\{2C0CC774-6D98-4004-9C86-7A05F682B3E8} => C:\Users\Ben\Desktop\NFSHP_Activator\NFSHP_Activator.exe Task: {6A34A9A8-F811-4361-AF32-238CBD0AE4BB} - System32\Tasks\{F28C964F-E66C-4D8F-8B7C-E83C0C06630D} => C:\Users\Ben\Desktop\24335_88v3id\88v3 id\msinst.exe Task: {6FE1A5DF-0998-4C73-B850-2F52CAFACDC4} - System32\Tasks\{B6AE155C-B3D1-4C3B-BDDA-52F8A46EA349} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.) Task: {719C9196-81B2-4170-97E3-31E473F4400F} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-12-30] (Microsoft Corporation) Task: {75764863-0389-4524-8458-40B0BF854A8C} - System32\Tasks\{3D3F6698-4160-4F4D-885C-7508539BF9DD} => C:\Users\Ben\Desktop\ExtFat32_v2.00\DeleteBinFilesFromSystem32.exe Task: {79517377-8CC2-4A74-BC39-EECC8F03DEA2} - System32\Tasks\{7ED773AF-8B09-4867-8B05-DC73EF7BC27B} => C:\Users\Ben\Desktop\NFSHP_Activator\NFSHP_Activator.exe Task: {7A9609CC-E82A-44D9-B72A-C43876D41DE8} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-01-29] (Microsoft Corporation) Task: {81A44ADF-427A-43E2-ABBA-CD6A44D87F03} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-01-06] (Microsoft Corporation) Task: {855A09FA-BA56-462F-BDE5-41C2F3B88460} - System32\Tasks\{8483929B-DC43-4ACD-89AA-49CFF4FF713F} => C:\Users\Ben\Desktop\swissknife.exe Task: {8BCE1AFB-B175-43EB-B151-702EB1C927A3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-13] (Google Inc.) Task: {94081B12-FE71-4E16-9D3A-7F9B99120743} - System32\Tasks\{8723E56F-EF62-4EB1-B131-E0C7F954AD94} => pcalua.exe -a "C:\Users\Ben\Desktop\Firefox Setup 3.5.7.exe" -d C:\Users\Ben\Desktop Task: {94E1F138-8F92-4A03-AED8-64D7696133AD} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-02-11] (Microsoft Corporation) Task: {A1368E4B-FFF6-4597-AD64-D9C27C0AFE2F} - System32\Tasks\{EE44BEE5-0123-4A1A-8800-FF0E781324D5} => pcalua.exe -a "C:\Users\Ben\Desktop\Firefox Setup 3.5.6.exe" -d C:\Users\Ben\Desktop Task: {A62E043D-5760-4677-82C6-3DEAFBCA4AD8} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-01-29] (Microsoft Corporation) Task: {A9436078-2838-4949-B070-E77FC8F8D6C1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-13] (Google Inc.) Task: {AD6C911C-645A-4146-B756-9E1CC11C5D8B} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-01-29] (Microsoft Corporation) Task: {B3D87DEE-4896-437E-8417-8345CB963D45} - System32\Tasks\{97B33906-B173-4CCE-AECF-A36288C8BC31} => C:\Users\Ben\Desktop\24335_88v3id\88v3 id\msinst.exe Task: {D237B8DD-6461-41E7-85C9-B70FDFD54F85} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-01-06] (Microsoft Corporation) Task: {D7B6D21D-EDEA-4396-AAC9-60EFEF7D96DB} - System32\Tasks\{FCC6E398-5281-41F3-B872-96BF05F4BB69} => pcalua.exe -a "C:\Users\Ben\Desktop\I-Doser + All Doses\sbagen-win-1.4.4.exe" -d "C:\Users\Ben\Desktop\I-Doser + All Doses" Task: {D875CC52-BEAC-40ED-87B2-02FE479F1A06} - System32\Tasks\{08716D13-7091-4D6E-8DBE-D84E1C9F2DBB} => E:\jdownloads\_Games\3D Minidolf Ultra Deluxe\MINIGOLF.EXE Task: {DB53236B-A298-4FDD-8EE8-A5FF96EA3B75} - System32\Tasks\{1ED197C8-AEEE-4524-BB0A-24B9C954F987} => pcalua.exe -a C:\Users\Ben\Desktop\jxpiinstall(2).exe -d C:\Users\Ben\Desktop Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2013-11-09 14:01 - 2013-11-11 16:02 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2010-10-25 14:40 - 2010-10-25 14:40 - 00022016 _____ () C:\WINDOWS\System32\BsTrace.dll 2008-03-07 12:54 - 2008-03-07 12:54 - 17892352 _____ () C:\Windows\system32\BsLangInDepRes.dll 2010-10-25 14:40 - 2010-10-25 14:40 - 00022016 _____ () C:\Windows\system32\BsTrace.dll 2010-10-25 14:40 - 2010-10-25 14:40 - 00009728 _____ () C:\Windows\system32\BsHelpCSps.dll 2010-10-25 14:40 - 2010-10-25 14:40 - 00047616 _____ () C:\Windows\system32\BlueSoleilCSps.dll 2010-01-06 00:07 - 2009-12-12 15:12 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll 2014-08-07 22:48 - 2014-05-20 08:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2013-03-08 02:46 - 2013-07-11 23:27 - 01630720 _____ () C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe 2013-12-14 16:24 - 2013-12-12 20:56 - 03145536 _____ () C:\Users\Ben\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe 2015-03-03 22:42 - 2015-03-03 22:43 - 02126848 _____ () C:\Users\Ben\Desktop\adwcleaner_4.111.exe 2010-10-25 14:40 - 2010-10-25 14:40 - 00022016 _____ () C:\WINDOWS\SYSTEM32\BsTrace.dll 2010-10-25 14:37 - 2010-10-25 14:37 - 00118904 _____ () C:\Program Files (x86)\IVT Corporation\BlueSoleil\setup.dll 2010-05-13 15:30 - 2010-05-13 15:30 - 00028730 _____ () C:\Program Files (x86)\IVT Corporation\BlueSoleil\Driver\USB\btcusb.dll 2010-10-25 14:40 - 2010-10-25 14:40 - 00009728 _____ () C:\Windows\SYSTEM32\BsHelpCSps.dll 2010-10-25 14:40 - 2010-10-25 14:40 - 00047616 _____ () C:\Windows\SYSTEM32\BlueSoleilCSps.dll 2013-03-08 02:45 - 2013-07-11 23:27 - 00252832 _____ () C:\Program Files (x86)\SimracewayUpdater\PATCHW32.dll 2015-01-29 21:04 - 2015-01-29 21:04 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2010-12-02 09:18 - 2010-12-02 09:18 - 00014208 _____ () C:\Program Files (x86)\Razer\Lachesis 5600\RzHook.dll 2010-02-22 11:19 - 2010-02-22 11:19 - 02121728 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll 2010-02-22 11:19 - 2010-02-22 11:19 - 07745536 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll 2010-02-22 11:19 - 2010-02-22 11:19 - 00135168 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll 2008-03-07 12:54 - 2008-03-07 12:54 - 17892352 _____ () C:\Windows\SYSTEM32\BsLangInDepRes.dll 2010-10-25 14:40 - 2010-10-25 14:40 - 00022016 _____ () C:\Windows\SYSTEM32\BsTrace.dll 2015-02-20 21:29 - 2015-02-17 23:44 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\libglesv2.dll 2015-02-20 21:29 - 2015-02-17 23:44 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\libegl.dll 2015-02-20 21:29 - 2015-02-17 23:44 - 09171272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\pdf.dll 2008-03-07 12:54 - 2008-03-07 12:54 - 17892352 _____ () C:\WINDOWS\SYSTEM32\BsLangInDepRes.dll 2010-10-25 14:42 - 2010-10-25 14:42 - 00145920 _____ () C:\WINDOWS\SYSTEM32\BsProfilefunc.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 AlternateDataStreams: C:\ProgramData\TEMP:C8B8CEBD AlternateDataStreams: C:\Users\Ben\SkyDrive:ms-properties AlternateDataStreams: C:\Users\Ben\SkyDrive (2).old:ms-properties AlternateDataStreams: C:\Users\Ben\SkyDrive (3).old:ms-properties AlternateDataStreams: C:\Users\Ben\SkyDrive (4).old:ms-properties AlternateDataStreams: C:\Users\Ben\SkyDrive (5).old:ms-properties AlternateDataStreams: C:\Users\Ben\SkyDrive (6).old:ms-properties AlternateDataStreams: C:\Users\Ben\SkyDrive.old:ms-properties ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3405083392-531059733-2769391109-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Electronic Arts\EADM\EADMUI.exe" MSCONFIG\startupreg: Steam => "E:\Steam\Steam.exe" -silent ==================== Accounts: ============================= Administrator (S-1-5-21-3405083392-531059733-2769391109-500 - Administrator - Disabled) Ben (S-1-5-21-3405083392-531059733-2769391109-1001 - Administrator - Enabled) => C:\Users\Ben Gast (S-1-5-21-3405083392-531059733-2769391109-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3405083392-531059733-2769391109-1006 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (03/03/2015 10:12:24 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: Das Volume "System-reserviert" wurde aufgrund eines Fehlers nicht optimiert: Falscher Parameter. (0x80070057) Error: (03/02/2015 10:15:16 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: Das Volume "System-reserviert" wurde aufgrund eines Fehlers nicht optimiert: Falscher Parameter. (0x80070057) Error: (03/02/2015 10:04:06 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: Das Volume "System-reserviert" wurde aufgrund eines Fehlers nicht optimiert: Falscher Parameter. (0x80070057) Error: (03/02/2015 09:58:27 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: Das Volume "System-reserviert" wurde aufgrund eines Fehlers nicht optimiert: Falscher Parameter. (0x80070057) Error: (02/28/2015 06:47:06 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: Das Volume "System-reserviert" wurde aufgrund eines Fehlers nicht optimiert: Falscher Parameter. (0x80070057) Error: (02/28/2015 04:55:11 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: Das Volume "System-reserviert" wurde aufgrund eines Fehlers nicht optimiert: Falscher Parameter. (0x80070057) Error: (02/28/2015 04:54:49 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (02/24/2015 11:59:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: svchost.exe_stisvc, Version: 6.3.9600.16384, Zeitstempel: 0x5215dfe3 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17630, Zeitstempel: 0x54b0e17a Ausnahmecode: 0xc0000008 Fehleroffset: 0x0000000000092d1a ID des fehlerhaften Prozesses: 0xbf8 Startzeit der fehlerhaften Anwendung: 0xsvchost.exe_stisvc0 Pfad der fehlerhaften Anwendung: svchost.exe_stisvc1 Pfad des fehlerhaften Moduls: svchost.exe_stisvc2 Berichtskennung: svchost.exe_stisvc3 Vollständiger Name des fehlerhaften Pakets: svchost.exe_stisvc4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe_stisvc5 Error: (02/24/2015 11:47:35 PM) (Source: MsiInstaller) (EventID: 1024) (User: BEN-DESKTOP) Description: Produkt: Adobe Reader XI (11.0.09) - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011010}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (02/21/2015 04:06:42 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: 852: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) System errors: ============= Error: (02/28/2015 07:07:39 PM) (Source: volsnap) (EventID: 36) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (02/24/2015 11:59:49 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WSearch erreicht. Error: (02/24/2015 11:59:20 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Windows-Bilderfassung (WIA)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (02/20/2015 11:51:32 PM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (02/20/2015 10:30:08 PM) (Source: volsnap) (EventID: 36) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (02/17/2015 09:37:25 PM) (Source: DCOM) (EventID: 10016) (User: BEN-DESKTOP) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}BEN-DESKTOPBenS-1-5-21-3405083392-531059733-2769391109-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (02/17/2015 09:37:25 PM) (Source: DCOM) (EventID: 10016) (User: BEN-DESKTOP) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}BEN-DESKTOPBenS-1-5-21-3405083392-531059733-2769391109-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (02/13/2015 06:51:27 PM) (Source: volsnap) (EventID: 36) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (02/13/2015 06:43:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Windows-Bilderfassung (WIA)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (02/11/2015 00:57:11 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WSearch erreicht. Microsoft Office Sessions: ========================= Error: (03/03/2015 10:12:24 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: System-reserviertFalscher Parameter. (0x80070057) Error: (03/02/2015 10:15:16 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: System-reserviertFalscher Parameter. (0x80070057) Error: (03/02/2015 10:04:06 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: System-reserviertFalscher Parameter. (0x80070057) Error: (03/02/2015 09:58:27 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: System-reserviertFalscher Parameter. (0x80070057) Error: (02/28/2015 06:47:06 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: System-reserviertFalscher Parameter. (0x80070057) Error: (02/28/2015 04:55:11 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: System-reserviertFalscher Parameter. (0x80070057) Error: (02/28/2015 04:54:49 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert Error: (02/24/2015 11:59:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: svchost.exe_stisvc6.3.9600.163845215dfe3ntdll.dll6.3.9600.1763054b0e17ac00000080000000000092d1abf801d05083b2fb3615C:\WINDOWS\system32\svchost.exeC:\WINDOWS\SYSTEM32\ntdll.dllc37ac23d-bc78-11e4-80fa-00241d105d16 Error: (02/24/2015 11:47:35 PM) (Source: MsiInstaller) (EventID: 1024) (User: BEN-DESKTOP) Description: Adobe Reader XI (11.0.09) - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011010}1625(NULL)(NULL)(NULL) Error: (02/21/2015 04:06:42 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: 852: ERROR: read_msg errno 0 (Der Vorgang wurde erfolgreich beendet.) CodeIntegrity Errors: =================================== Date: 2015-02-28 16:56:44.600 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll that did not meet the Microsoft signing level requirements. Date: 2015-02-28 16:56:43.818 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll that did not meet the Microsoft signing level requirements. Date: 2015-02-28 16:56:43.326 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll that did not meet the Microsoft signing level requirements. Date: 2015-02-28 16:56:42.669 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll that did not meet the Microsoft signing level requirements. Date: 2015-02-28 16:56:42.194 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll that did not meet the Microsoft signing level requirements. Date: 2015-02-28 16:56:41.740 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll that did not meet the Microsoft signing level requirements. Date: 2015-02-28 16:56:38.262 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements. Date: 2015-02-28 16:56:37.442 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements. Date: 2015-02-21 16:25:11.202 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-02-21 16:25:10.384 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz Percentage of memory in use: 35% Total physical RAM: 6142.48 MB Available physical RAM: 3972.37 MB Total Pagefile: 12286.48 MB Available Pagefile: 8859.93 MB Total Virtual: 131072 MB Available Virtual: 131071.79 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:118.8 GB) (Free:3.59 GB) NTFS Drive e: (3TB Seagate) (Fixed) (Total:2794.39 GB) (Free:22.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: 000A4C68) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=118.8 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 2794.5 GB) (Disk ID: 4A4263C5) Partition: GPT Partition Type. ==================== End Of Log ============================ Geändert von frooser (04.03.2015 um 00:41 Uhr) |
Themen zu Fake DHL EMail, zip runtergeladen, pdf doppelgeklickt, welches dann verschwunden ist... |
ad-aware, adware, antivir, avira, bonjour, browser, canon, computer, defender, dhl email, email, fake dhl email, firefox, flash player, google, google analytics, homepage, installation, link geöffnet, mozilla, registry, rundll, scan, security, services.exe, shark, software, system, updates, windows |