![]() |
|
Log-Analyse und Auswertung: Windows 7: McAfee findet ArtemisWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Windows 7: McAfee findet Artemis Hallo liebes Trojaner-Board-Team, McAfee hat heute bei einem Scan einen Artemis Trojaner gefunden. Der PC hatte heute Morgen Probleme beim Installieren von verschiedenen Updates. Gmer stürzt ab, sobald es zu "harddisk volume shadow copy" kommt. Auch im abgesicherten Modus. Bin für jede Hilfe dankbar. Hier die logs: Mc Afee: Code:
ATTFilter 17.04.2015 09:44:44 Modulversion = 5700.7163 17.04.2015 09:44:44 AntiVirus-DAT-Version = 7773.0 17.04.2015 09:44:44 Anzahl an Entdeckungssignaturen in EXTRA.DAT= Kein 17.04.2015 09:44:44 Namen der Entdeckungssignaturen in EXTRA.DAT= Kein 17.04.2015 09:44:44 Scanvorgang wurde gestartet -\Admin Vollständiger Scan 17.04.2015 11:31:56 Gelöscht Admin ODS[4320](Vollständiger Scan) c:\Users\Admin\AppData\Local\Temp\13072434260007418133.exe Artemis!B3737CCF8B6E (Trojanisches Pferd) 17.04.2015 11:32:04 Gelöscht Admin ODS[4320](Vollständiger Scan) c:\Users\Admin\AppData\Local\Temp\13072434392056970935.exe Artemis!B3737CCF8B6E (Trojanisches Pferd) 17.04.2015 11:33:05 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Admin\AppData\LocalLow\Sun\Java\jre1.7.0_09\Data1.cab 17.04.2015 11:33:06 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Admin\AppData\LocalLow\Sun\Java\jre1.7.0_11\Data1.cab 17.04.2015 11:33:28 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Admin\AppData\LocalLow\Sun\Java\jre1.7.0_21\Data1.cab 17.04.2015 11:33:30 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Admin\AppData\LocalLow\Sun\Java\jre1.7.0_25\Data1.cab 17.04.2015 11:33:52 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Admin\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab 17.04.2015 11:33:57 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Admin\AppData\LocalLow\Sun\Java\jre1.7.0_67\Data1.cab 17.04.2015 12:22:02 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Marci\AppData\Local\Mozilla\Firefox\Profiles\oc8xtaiy.default\cache2\entries\5F3C62B90583B630831A1F19278D7C587DEEC909 17.04.2015 12:30:29 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Marci\Local Settings\Mozilla\Firefox\Profiles\oc8xtaiy.default\cache2\entries\5F3C62B90583B630831A1F19278D7C587DEEC909 17.04.2015 12:35:58 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Standard User\AppData\Local\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\2A50ECF1604771AFA8F5D970C854B732F5EF1AD7 17.04.2015 12:36:31 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Standard User\AppData\Local\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\448817BCF02275C2AF6F755A2D24B82E8455AAE9 17.04.2015 12:37:35 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Standard User\AppData\Local\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\7B3F5C5B8F76EFE5BFC367BD9669ABD8E4A0E0E3 17.04.2015 12:38:08 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Standard User\AppData\Local\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\9A8BB03D78043B3C7F10F43A637D0CA064DC4EF7 17.04.2015 12:39:01 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Standard User\AppData\Local\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\CA46ADFC793D0200DAAF21B4AB458051B061E74A 17.04.2015 13:27:15 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Standard User\Local Settings\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\2A50ECF1604771AFA8F5D970C854B732F5EF1AD7 17.04.2015 13:27:37 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Standard User\Local Settings\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\448817BCF02275C2AF6F755A2D24B82E8455AAE9 17.04.2015 13:28:26 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Standard User\Local Settings\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\7B3F5C5B8F76EFE5BFC367BD9669ABD8E4A0E0E3 17.04.2015 13:28:53 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Standard User\Local Settings\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\9A8BB03D78043B3C7F10F43A637D0CA064DC4EF7 17.04.2015 13:29:37 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Standard User\Local Settings\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\CA46ADFC793D0200DAAF21B4AB458051B061E74A 17.04.2015 13:54:28 Nicht gescannt (Die Datei ist verschlüsselt) c:\Users\Standard User\Music\iTunes\iTunes Media\Mobile Applications\MadSkillsBMX 1.4.0.ipa 17.04.2015 15:03:25 Nicht gescannt (Die Datei ist verschlüsselt) c:\Windows\Installer\84178.msp 17.04.2015 15:51:26 Nicht gescannt (Die Datei ist verschlüsselt) c:\Windows\SoftwareDistribution\Download\acf67ef40852dc4544e261cb35f05219\BITB0CA.tmp 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Scan-Zusammenfassung 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Gescannte Prozesse: 78 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Entdeckte Prozesse: 0 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Gesäuberte Prozesse: 0 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Gescannte Boot-Sektoren: 2 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Entdeckte Boot-Sektoren: 0 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Gesäuberte Boot-Sektoren: 0 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Gescannte Dateien: 703562 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Dateien mit Entdeckungen: 2 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin DateiEntdeckungen: 2 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Gesäuberte Dateien: 0 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Gelöschte Dateien: 2 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Nicht gescannte Dateien: 145 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Scan-Zusammenfassung (Scannen der Registrierung) 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Gescannte Schlüssel: 86527 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Entdeckte Schlüssel: 0 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Gesäuberte Schlüssel: 0 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Gelöschte Schlüssel : 0 17.04.2015 16:18:56 Scan-Zusammenfassung -\Admin Laufzeit: 6:34:11 17.04.2015 16:18:56 Scanvorgang wurde beendet -\Admin Vollständiger Scan FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-04-2015 04 Ran by Standard User (ATTENTION: The logged in user is not administrator) on - on 17-04-2015 19:51:52 Running from C:\Users\Standard User\AppData\Local\Temp\mozOpenDownload Loaded Profiles: Admin & Standard User & (Available profiles: Admin & Standard User & Marci) Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) Failed to access process -> smss.exe Failed to access process -> csrss.exe Failed to access process -> wininit.exe Failed to access process -> csrss.exe Failed to access process -> services.exe Failed to access process -> lsass.exe Failed to access process -> lsm.exe Failed to access process -> winlogon.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> atiesrxx.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> svchost.exe Failed to access process -> UMVPFSrv.exe Failed to access process -> CTAudSvc.exe Failed to access process -> svchost.exe Failed to access process -> atieclxx.exe Failed to access process -> vpnagent.exe Failed to access process -> svchost.exe Failed to access process -> spoolsv.exe Failed to access process -> svchost.exe Failed to access process -> armsvc.exe Failed to access process -> AppleMobileDeviceService.exe Failed to access process -> mDNSResponder.exe Failed to access process -> svchost.exe Failed to access process -> FrameworkService.exe Failed to access process -> VsTskMgr.exe Failed to access process -> mfevtps.exe Failed to access process -> nlssrv32.exe Failed to access process -> mfeann.exe Failed to access process -> conhost.exe Failed to access process -> naPrdMgr.exe Failed to access process -> RosettaStoneDaemon.exe Failed to access process -> psia.exe Failed to access process -> svchost.exe Failed to access process -> mcshield.exe Failed to access process -> svchost.exe Failed to access process -> sua.exe Failed to access process -> USBVaccine.exe (McAfee, Inc.) C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.) C:\Program Files\McAfee\Common Framework\McTray.exe (Spotify Ltd) C:\Users\Standard User\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe () C:\Program Files\SWITCHdrive\SWITCHdrive.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader.exe Failed to access process -> wmpnetwk.exe Failed to access process -> svchost.exe (McAfee, Inc.) C:\Program Files\McAfee\VirusScan Enterprise\scan32.exe Failed to access process -> FNPLicensingService.exe () C:\Program Files\FileHippo.com\FileHippo.AppManager.exe (Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (McAfee, Inc.) C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe Failed to access process -> dllhost.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe Failed to access process -> WmiPrvSE.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [McAfeeUpdaterUI] => C:\Program Files\McAfee\Common Framework\udaterui.exe [337440 2013-06-25] (McAfee, Inc.) HKLM\...\Run: [ShStatEXE] => C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [243560 2014-01-15] (McAfee, Inc.) HKLM\...\Run: [] => [X] HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation) HKLM\...\RunOnce: [NSIS.Library.RegTool.v3] => C:\Program Files\SWITCHdrive\shellext\NSIS.Library.RegTool.v3.{B6CC7347-25B5-45E2-83AF-3195401C8860}.exe [6656 2014-09-22] () HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SandboxieControl] => "C:\Program Files\Sandboxie\SbieCtrl.exe" HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [Spotify Web Helper] => C:\Users\Standard User\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2018360 2015-04-02] (Spotify Ltd) HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.) HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.) HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [AppleIEDAV] => C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe [1080104 2014-09-19] (Apple Inc.) HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SWITCHdrive] => C:\Program Files\SWITCHdrive\SWITCHdrive.exe [23271459 2014-11-10] () HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [293888 2010-11-20] (Microsoft Corporation) HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SandboxieControl] => "C:\Program Files\Sandboxie\SbieCtrl.exe" HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify Web Helper] => C:\Users\Standard User\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2018360 2015-04-02] (Spotify Ltd) HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.) HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.) HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AppleIEDAV] => C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe [1080104 2014-09-19] (Apple Inc.) HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SWITCHdrive] => C:\Program Files\SWITCHdrive\SWITCHdrive.exe [23271459 2014-11-10] () HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [293888 2010-11-20] (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia) ShellIconOverlayIdentifiers: [ OCError] -> {0960F090-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.) ShellIconOverlayIdentifiers: [ OCErrorShared] -> {0960F091-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.) ShellIconOverlayIdentifiers: [ OCOK] -> {0960F092-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.) ShellIconOverlayIdentifiers: [ OCOKShared] -> {0960F093-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.) ShellIconOverlayIdentifiers: [ OCSync] -> {0960F094-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.) ShellIconOverlayIdentifiers: [ OCSyncShared] -> {0960F095-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.) ShellIconOverlayIdentifiers: [ OCWarning] -> {0960F096-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.) ShellIconOverlayIdentifiers: [ OCWarningShared] -> {0960F097-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: [S-1-5-21-3271901242-2791666843-1555295335-1003] => 127.0.0.1:4001 ProxyServer: [S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0] => 127.0.0.1:4001 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp URLSearchHook: [S-1-5-21-3271901242-2791666843-1555295335-1000] ATTENTION ==> Default URLSearchHook is missing. URLSearchHook: [S-1-5-21-3271901242-2791666843-1555295335-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0] ATTENTION ==> Default URLSearchHook is missing. URLSearchHook: [S-1-5-21-3271901242-2791666843-1555295335-1263-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0] ATTENTION ==> Default URLSearchHook is missing. BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-17] (Oracle Corporation) BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20141013204033.dll [2014-10-13] (McAfee, Inc.) BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-17] (Oracle Corporation) BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated) Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-3271901242-2791666843-1555295335-1003 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL No File [ ] Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60 FireFox: ======== FF ProfilePath: C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default FF Homepage: https://news.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-17] () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-17] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-17] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-29] (Adobe Systems) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-11-04] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-11-04] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-11-04] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-11-04] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-11-04] (Apple Inc.) FF Extension: OpenDownload² - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{210249CE-F888-11DD-B868-4CB456D89593} [2015-01-12] FF Extension: WOT - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-06-23] FF Extension: Ghostery - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\firefox@ghostery.com.xpi [2014-06-23] FF Extension: Zoom Page - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\zoompage@DW-dev.xpi [2015-03-30] FF Extension: 瀏覽頁組管理員 - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2014-08-28] FF Extension: Microsoft .NET Framework Assistant - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2014-06-23] FF Extension: NoScript - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-08-28] FF Extension: Simple RSS Reader (SRR) - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{A5475360-A7EA-437b-9A79-29208F476940}.xpi [2014-08-04] FF Extension: Right Links - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{B5F5E8D3-AE31-49A1-AC42-78B7B1CC5CDC}.xpi [2014-06-23] FF Extension: Image Preview - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{D0A81AC1-3B12-4cec-AA8D-40EBDC4241EA}.xpi [2014-06-23] FF Extension: Adblock Plus - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-23] FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-06-28] FF HKLM\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files\Common Files\McAfee\SystemCore FF Extension: McAfee ScriptScan for Firefox - C:\Program Files\Common Files\McAfee\SystemCore [2014-10-13] FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-04-03] Chrome: ======= CHR Profile: C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Docs) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-29] CHR Extension: (Google Drive) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-29] CHR Extension: (YouTube) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-29] CHR Extension: (Google Search) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-29] CHR Extension: (Google Wallet) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-29] CHR Extension: (Gmail) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-29] CHR HKLM\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - No Path Or update_url value CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-12-03] CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx [Not Found] CHR HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bckipplcmnfhblnpibpbehenelnkpecd] - C:\Program Files\OkayFreedom\okayfreedom.crx [Not Found] CHR HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bckipplcmnfhblnpibpbehenelnkpecd] - C:\Program Files\OkayFreedom\okayfreedom.crx [Not Found] Opera: ======= OPR Extension: (WOT) - C:\Users\Standard User\AppData\Roaming\Opera Software\Opera Stable\Extensions\eeokceolphhfjdfcibaiiopmekmcbedp [2013-07-12] OPR Extension: (Image Autosizer) - C:\Users\Standard User\AppData\Roaming\Opera Software\Opera Stable\Extensions\iikighlpichfheooodpapakdheilalcj [2013-07-12] OPR Extension: (Adblock Plus) - C:\Users\Standard User\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2013-07-12] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-09-23] (Creative Labs) [File not signed] R2 CTAudSvcService; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [307200 2009-02-23] (Creative Technology Ltd) [File not signed] R2 lmhosts; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation) R2 McAfeeFramework; C:\Program Files\McAfee\Common Framework\FrameworkService.exe [130080 2013-06-25] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [204320 2014-10-13] (McAfee, Inc.) R2 McTaskManager; C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe [208416 2014-01-15] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [174968 2014-10-13] (McAfee, Inc.) R2 NlaSvc; C:\Windows\System32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 nlsX86cc; C:\Windows\system32\nlssrv32.exe [66560 2011-02-15] (Nalpeiron Ltd.) [File not signed] R2 nsi; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) R2 RosettaStoneDaemon; C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [1646056 2011-03-31] (Rosetta Stone Ltd.) R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia) R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia) R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.) R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [563112 2014-08-15] (Cisco Systems, Inc.) S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) S2 FreemakeVideoCapture; "C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 acsock; C:\Windows\System32\DRIVERS\acsock.sys [92528 2014-08-15] (Cisco Systems, Inc.) S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [63464 2013-05-29] (FTDI Ltd.) R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [57112 2011-03-28] (Paragon Software Group) R1 ISODrive; C:\Program Files\UltraISO\drivers\ISODrive.sys [82168 2013-11-21] (EZB Systems, Inc.) R3 itecir; C:\Windows\System32\DRIVERS\itecir.sys [65640 2010-07-13] (ITE Tech. Inc. ) S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-07-20] (ManyCam LLC) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-04-17] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [25088 2012-07-20] (ManyCam LLC) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [134472 2014-10-13] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [236480 2014-10-13] (McAfee, Inc.) R3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [66408 2014-10-13] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [573136 2014-10-13] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [93144 2014-10-13] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [213872 2014-10-13] (McAfee, Inc.) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-12-06] (Secunia) S3 t3; C:\Windows\System32\drivers\t3.sys [413208 2009-05-06] (Creative Technology Ltd.) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project) R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [40824 2011-03-28] (Windows (R) 2000 DDK provider) R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [381032 2011-03-28] (Paragon) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva-6.sys [43888 2014-08-15] (Cisco Systems, Inc.) U3 pxldapow; C:\Users\Admin\AppData\Local\Temp\pxldapow.sys [104960 2015-04-17] (GMER) [File not signed] S3 ALSysIO; \??\C:\Users\Admin\AppData\Local\Temp\ALSysIO.sys [X] U3 mfeavfk01; No ImagePath S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP5c\WNt500x86\Sandra.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-17 19:51 - 2015-04-17 19:52 - 00000000 ____D () C:\FRST 2015-04-17 11:31 - 2015-04-17 19:37 - 00000000 ____D () C:\QUARANTINE 2015-04-17 09:47 - 2015-04-17 09:47 - 00000000 ____D () C:\Program Files\Common Files\Java 2015-04-15 19:49 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-04-15 19:49 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-04-15 19:49 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-04-15 19:49 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-04-15 19:49 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-04-15 19:49 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-04-15 19:49 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2015-04-15 19:49 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2015-04-15 19:48 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-04-15 19:48 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-04-15 19:48 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-04-15 19:48 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-04-15 19:48 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-04-15 19:48 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-04-15 19:48 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-04-15 19:48 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-04-15 19:48 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-04-15 19:48 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-04-15 19:48 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-04-15 19:48 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-04-15 19:48 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-04-15 19:48 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-04-15 19:48 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-04-15 19:48 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-04-15 19:48 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-04-15 19:48 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-04-15 19:48 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-04-15 19:48 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-04-15 19:48 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-04-15 19:41 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-04-15 19:41 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-04-15 19:41 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-04-15 19:41 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-04-15 19:41 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-04-15 19:41 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-04-15 19:41 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-04-15 19:41 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-04-15 19:41 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-04-15 19:41 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-04-15 19:41 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-04-15 19:41 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-04-15 19:41 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-04-15 19:41 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-04-15 19:41 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-04-15 19:41 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-04-15 19:41 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-04-15 19:41 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-04-15 19:41 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-04-15 19:41 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-04-15 19:41 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-04-15 19:41 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-04-15 19:41 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-04-15 19:41 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-04-15 19:41 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-04-15 19:41 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-04-15 19:41 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-04-15 19:41 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-04-15 19:41 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-04-15 19:41 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-04-15 19:41 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-04-15 19:41 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-04-15 19:38 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2015-04-15 19:14 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2015-04-15 19:14 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2015-04-11 11:58 - 2015-04-11 11:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-04-11 11:55 - 2015-04-11 11:58 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB 2015-04-11 11:55 - 2015-04-11 11:58 - 00000000 ____D () C:\Program Files\iTunes 2015-04-11 11:55 - 2015-04-11 11:55 - 00000000 ____D () C:\Program Files\iPod 2015-04-11 11:40 - 2015-04-11 11:40 - 00000000 ____D () C:\Users\Standard User\Tracing 2015-04-11 11:22 - 2015-04-11 11:25 - 00000000 ___SD () C:\Windows\system32\GWX 2015-04-11 09:10 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-04-11 09:10 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-04-11 09:10 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-04-11 09:10 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-04-11 09:09 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-04-11 09:09 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-04-11 09:09 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-04-11 09:09 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-04-11 09:09 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-04-11 09:09 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-04-11 09:09 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-04-11 09:09 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-04-11 09:09 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-04-11 09:09 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-04-11 09:09 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-04-11 09:09 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-04-11 09:09 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-04-11 09:09 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-04-11 09:09 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-04-02 12:02 - 2015-04-02 12:02 - 00000000 ____D () C:\Users\Standard User\Downloads\Manu Chao - La Radiolina 2015-04-02 11:54 - 2015-04-02 12:25 - 00000000 ____D () C:\Users\Standard User\Downloads\Siberie m etait conteee 2015-04-02 11:47 - 2015-04-02 12:27 - 00000000 ____D () C:\Users\Standard User\Downloads\Manu Chao and Friends - Manu Chao and Friends (2011) 2015-04-02 09:03 - 2015-04-02 09:03 - 00000678 _____ () C:\Windows\PFRO.log 2015-03-29 13:00 - 2015-03-29 13:00 - 00000000 __RSH () C:\MSDOS.SYS 2015-03-29 13:00 - 2015-03-29 13:00 - 00000000 __RSH () C:\IO.SYS 2015-03-23 08:57 - 2015-04-11 10:21 - 00000000 ____D () C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-17 19:31 - 2014-07-12 14:12 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-17 19:25 - 2015-03-01 21:12 - 00005568 _____ () C:\Windows\setupact.log 2015-04-17 19:21 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2015-04-17 19:18 - 2009-07-14 06:34 - 00025760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-17 19:18 - 2009-07-14 06:34 - 00025760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-17 19:11 - 2014-11-05 22:27 - 00000000 ____D () C:\Users\Marci\AppData\Roaming\Spotify 2015-04-17 19:07 - 2012-06-04 18:13 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-17 10:42 - 2012-06-04 11:35 - 01619570 _____ () C:\Windows\WindowsUpdate.log 2015-04-17 10:40 - 2014-05-14 11:59 - 00000000 ____D () C:\Users\Standard User\AppData\Local\C6B895D1-C4F4-4AA5-B457-2F5A43379524.aplzod 2015-04-17 10:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2015-04-17 09:59 - 2012-06-04 12:08 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-04-17 09:49 - 2013-11-19 16:42 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR 2015-04-17 09:47 - 2014-08-28 15:08 - 00000000 ____D () C:\Program Files\Java 2015-04-17 09:44 - 2015-03-06 18:56 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2015-04-17 09:39 - 2015-03-13 23:29 - 00003890 _____ () C:\Windows\SecuniaPackage.log 2015-04-17 09:36 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-17 09:20 - 2012-06-04 11:46 - 00785866 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-17 09:08 - 2013-11-05 22:16 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Spotify 2015-04-17 09:07 - 2014-12-17 21:11 - 00000000 ____D () C:\Users\Standard User\SWITCHdrive 2015-04-17 08:57 - 2012-07-06 19:26 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Adobe 2015-04-17 08:56 - 2013-11-05 22:15 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\Spotify 2015-04-17 08:56 - 2012-06-04 18:13 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-04-17 08:56 - 2012-06-04 17:40 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-04-17 08:52 - 2014-08-31 14:31 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe 2015-04-17 07:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat 2015-04-15 20:53 - 2014-10-10 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2015-04-15 20:52 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini 2015-04-15 20:47 - 2013-07-14 13:02 - 00000000 ____D () C:\Windows\system32\MRT 2015-04-15 20:42 - 2012-06-04 11:42 - 00000000 ____D () C:\Users\Admin 2015-04-15 20:31 - 2012-06-04 12:46 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-04-11 11:55 - 2012-06-04 18:50 - 00000000 ____D () C:\Program Files\Common Files\Apple 2015-04-11 11:41 - 2012-09-15 15:28 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\Skype 2015-04-11 11:39 - 2012-09-15 15:27 - 00000000 ____D () C:\ProgramData\Skype 2015-04-11 11:32 - 2012-06-05 09:18 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\foobar2000 2015-04-11 11:32 - 2012-06-04 17:33 - 00001035 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk 2015-04-11 11:32 - 2012-06-04 17:33 - 00000000 ____D () C:\Program Files\foobar2000 2015-04-11 11:24 - 2014-05-15 18:56 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-04-11 11:22 - 2014-12-12 14:03 - 00000000 ____D () C:\Windows\system32\appraiser 2015-04-11 11:22 - 2014-05-06 10:55 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-04-02 16:02 - 2015-01-24 17:19 - 00001838 _____ () C:\Users\Standard User\Desktop\Spotify.lnk 2015-04-02 16:02 - 2013-11-05 22:16 - 00001824 _____ () C:\Users\Standard User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk 2015-04-02 09:51 - 2012-06-26 10:44 - 00000000 ____D () C:\Program Files\JDownloader 2015-04-01 20:11 - 2015-02-15 16:25 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Popcorn-Time 2015-04-01 20:11 - 2012-09-03 14:36 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\vlc 2015-04-01 10:17 - 2012-06-04 19:28 - 00000000 ____D () C:\Program Files\CCleaner 2015-03-30 08:32 - 2014-06-29 20:22 - 00000000 ____D () C:\Users\Standard User\Downloads\navigon 2015-03-29 14:26 - 2012-08-26 20:54 - 00000000 ____D () C:\ProgramData\boost_interprocess 2015-03-23 21:36 - 2014-07-12 14:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-03-23 21:36 - 2014-07-12 14:12 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2015-03-23 17:03 - 2014-10-06 15:28 - 00000000 ____D () C:\Users\Marci\AppData\Roaming\Skype 2015-03-20 22:41 - 2014-09-08 21:27 - 00000000 ____D () C:\Users\Marci\AppData\Roaming\vlc ==================== Files in the root of some directories ======= 2012-06-05 10:35 - 2014-08-14 13:16 - 0000363 _____ () C:\Users\Standard User\AppData\Roaming\burnaware.ini 2012-10-23 03:23 - 2012-09-04 08:44 - 11624448 _____ () C:\Users\Standard User\AppData\Roaming\Sandra.mdb 2013-12-27 13:41 - 2014-02-18 23:18 - 0017408 _____ () C:\Users\Standard User\AppData\Local\WebpageIcons.db 2014-08-13 12:21 - 2014-08-13 12:21 - 0000057 _____ () C:\ProgramData\Ament.ini Some content of TEMP: ==================== C:\Users\Standard User\AppData\Local\Temp\i4jdel0.exe C:\Users\Standard User\AppData\Local\Temp\proxy_vole9193411994646851775.dll C:\Users\Standard User\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed ATTENTION: ==> Could not access BCD. Check to make sure user is administrator or see Addition.txt for additional information. ==================== End Of Log ============================ --- --- --- --- --- --- Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-04-2015 04 Ran by Standard User at 2015-04-17 19:55:03 Running from C:\Users\Standard User\AppData\Local\Temp\mozOpenDownload Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: McAfee VirusScan Enterprise (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AS: McAfee VirusScan Enterprise Antispyware Module (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) Adobe Acrobat XI Pro (HKLM\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.10 - Adobe Systems) Adobe AIR (HKLM\...\Adobe AIR) (Version: 17.0.0.144 - Adobe Systems Incorporated) Adobe Flash Player 15 Plugin (HKLM\...\{F1410A0A-8205-4D45-BF2B-9C7ACB2F4B24}) (Version: 15.0.0.239 - Adobe Systems Incorporated) Adobe Flash Player 17 ActiveX (HKLM\...\{8C901387-B304-404D-93C0-E2E0C2D53D90}) (Version: 17.0.0.134 - Adobe Systems Incorporated) Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated) Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated) Adobe Photoshop Lightroom 3.6 (HKLM\...\{D0ACE207-0F90-402C-8CFA-2CB3D44CE689}) (Version: 3.6.1 - Adobe) Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) AGEIA PhysX v7.09.13 (HKLM\...\{45235788-142C-44BE-8A4D-DDE9A84492E5}) (Version: 7.09.13 - AGEIA Technologies, Inc.) Apple Application Support (32-Bit) (HKLM\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Ashampoo Burning Studio 2014 v.12.0.5 (HKLM\...\{91B33C97-280F-B76D-E27B-E712D7041B76}_is1) (Version: 12.0.5 - Ashampoo GmbH & Co. KG) Biet-O-Matic v2.14.8 (HKLM\...\Biet-O-Matic v2.14.8) (Version: 2.14.8 - BOM Development Team) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) CameraHelperMsi (Version: 13.31.1038.0 - Logitech) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.04 - Piriform) Cisco AnyConnect Secure Mobility Client (HKLM\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.05182 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (Version: 3.1.05182 - Cisco Systems, Inc.) Hidden Color Efex Pro 3.0 Complete (HKLM\...\Color Efex Pro 3.0 Complete Stand-Alone) (Version: 3.1.1.0 - Nik Software, Inc.) Creative Audio-Systemsteuerung (HKLM\...\AudioCS) (Version: 3.00 - Creative Technology Limited) Creative Software AutoUpdate (HKLM\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited) Defraggler (HKLM\...\Defraggler) (Version: 2.19 - Piriform) Dfine 2.0 (HKLM\...\Dfine 2.0 Stand-Alone) (Version: 2.1.0.7 - Nik Software, Inc.) Eigenschaften von Creative Sound Blaster (HKLM\...\Creative Sound Blaster Properties) (Version: 1.02 - Creative Technology Limited) EndNote X7 (HKLM\...\{86B3F2D6-AC2B-0017-8AE1-F2F77F781B0C}) (Version: 17.0.2.7390 - Thomson Reuters) erLT (Version: 1.20.138.34 - Logitech, Inc.) Hidden FileHippo App Manager (HKLM\...\FileHippo.com) (Version: - FileHippo.com) foobar2000 v1.3.8 (HKLM\...\foobar2000) (Version: 1.3.8 - Peter Pawlowski) GoodSync (HKLM\...\{B26B00DA-2E5D-4CF2-83C5-911198C0F009}) (Version: 9.9.9.9 - Siber Systems) GraphPad Prism 5 (HKLM\...\{35B73650-6899-11DA-6784-00232A9018BE}) (Version: 5.04 - GraphPad Software) Host OpenAL (HKLM\...\Host OpenAL) (Version: 1.00 - Creative Technology Limited) HP Officejet Pro 8600 Basic Device Software (HKLM\...\{8EAB4100-B343-41AE-A880-418746998209}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) I.R.I.S. OCR (HKLM\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) IBM SPSS Statistics 21 (HKLM\...\{1E26B9C2-ED08-4EEA-83C8-A786502B41E5}) (Version: 21.0.0.0 - IBM Corp) iCloud (HKLM\...\{760BB327-3973-4608-85C8-88162E2FF3B6}) (Version: 4.0.6.28 - Apple Inc.) iTunes (HKLM\...\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.) Java 8 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Logitech Webcam Software (HKLM\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.0 - Logitech Inc.) Malwarebytes Anti-Malware Version 2.1.4.1018 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation) McAfee Agent (HKLM\...\{1FDB8EC6-BAF1-42F9-8E09-4D9AB369F1B5}) (Version: 4.8.0.887 - McAfee, Inc.) McAfee VirusScan Enterprise (HKLM\...\{CE15D1B6-19B6-4D4D-8F43-CF5D2C3356FF}) (Version: 8.8.04001 - McAfee, Inc.) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office Outlook Connector (HKLM\...\{95140000-0081-0407-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation) Moveslink for Movestick Mini (HKLM\...\{4D036ACA-DFDF-41B2-A680-E0D736F3E947}) (Version: 1.2.40 - Suunto) Mozilla Firefox 37.0.1 (x86 en-US) (HKLM\...\Mozilla Firefox 37.0.1 (x86 en-US)) (Version: 37.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Panda USB Vaccine 1.0.1.4 (HKLM\...\{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1) (Version: - Panda Security) Paragon Backup & Recovery™ 2011 Free (HKLM\...\{C268B5E1-A5DA-11DF-A289-005056C00008}) (Version: 90.00.0003 - Paragon Software) QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) R for Windows 3.0.2 (HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\R for Windows 3.0.2_is1) (Version: 3.0.2 - R Core Team) R for Windows 3.0.2 (HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\R for Windows 3.0.2_is1) (Version: 3.0.2 - R Core Team) ResearchSoft Direct Export Helper (HKLM\...\ResearchSoft Direct Export Helper) (Version: - Thomson Reuters) Rosetta Stone Ltd Services (HKLM\...\{7BB2EF8A-5376-4BAE-96D0-38BE49501F40}) (Version: 3.2.17 - Rosetta Stone Ltd.) Rosetta Stone TOTALe (HKLM\...\com.rosettastone.rosettastonetotale) (Version: 4.1.15.1 - Rosetta Stone, Ltd) Rosetta Stone TOTALe (Version: 4.1.1 - Rosetta Stone, Ltd) Hidden Rosetta Stone TOTALe (Version: 4.1.15.1 - Rosetta Stone, Ltd) Hidden RStudio (HKLM\...\RStudio) (Version: 0.98.501 - RStudio) Secunia PSI (3.0.0.9016) (HKLM\...\Secunia PSI) (Version: 3.0.0.9016 - Secunia) Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft) Sharpener Pro 3.0 (HKLM\...\Sharpener Pro 3.0 Stand-Alone) (Version: 3.0.0.5 - Nik Software, Inc.) SIGMA Photo Pro 5 (HKLM\...\{B99C3D18-BA4B-4D65-A500-D364E3D2A8A3}) (Version: 5.2.1 - SIGMA) Silver Efex Pro 2 (HKLM\...\Silver Efex Pro 2) (Version: 2.0.0.0 - Nik Software, Inc.) Skype™ 7.3 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Spotify) (Version: 1.0.3.101.gbfa97dfe - Spotify AB) Spotify (HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Spotify) (Version: 1.0.3.101.gbfa97dfe - Spotify AB) Stata 13 (HKLM\...\{217BE429-022D-4094-960F-0376E1CBE13E}) (Version: 13.0 - StataCorp LP) SWITCHdrive (HKLM\...\SWITCHdrive) (Version: 1.7.0.4198 - SWITCH) UltraISO Premium V9.62 (HKLM\...\UltraISO_is1) (Version: - ) Update for Skype for Business 2015 (KB2889853) 32-Bit Edition (HKLM\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{0C5B0539-7EDE-4297-947E-48890971B557}) (Version: - Microsoft) Viveza 2 (HKLM\...\Viveza 2) (Version: 2.0.0.4 - Nik Software, Inc.) VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN) Windows Driver Package - Suunto (libusb0) Suunto (10/02/2010 1.2.2.0) (HKLM\...\4E5E6491582172E255196D3F11B77725E6681767) (Version: 10/02/2010 1.2.2.0 - Suunto) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= ATTENTION: System Restore is disabled. Check "winmgmt" service or repair WMI. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2014-06-28 19:15 - 00000896 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ==================== Loaded Modules (whitelisted) ============== 2014-11-04 02:30 - 2014-11-04 02:30 - 00045568 _____ () C:\Program Files\SWITCHdrive\shellext\OCUtil_x86.dll 2015-01-20 23:35 - 2015-01-20 23:35 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-11-10 11:39 - 2014-11-10 11:39 - 23271459 _____ () C:\Program Files\SWITCHdrive\SWITCHdrive.exe 2014-11-10 11:38 - 2014-11-10 11:38 - 03044905 _____ () C:\Program Files\SWITCHdrive\libocsync.dll 2014-09-24 10:23 - 2014-09-24 10:23 - 00158048 _____ () C:\Program Files\SWITCHdrive\libneon-27.dll 2014-09-22 00:32 - 2014-09-22 00:32 - 00084012 _____ () C:\Program Files\SWITCHdrive\zlib1.dll 2014-09-22 03:45 - 2014-09-22 03:45 - 00095790 _____ () C:\Program Files\SWITCHdrive\libgcc_s_sjlj-1.dll 2014-09-22 03:13 - 2014-09-22 03:13 - 00172695 _____ () C:\Program Files\SWITCHdrive\libproxy.dll 2014-09-22 03:11 - 2014-09-22 03:11 - 00042626 _____ () C:\Program Files\SWITCHdrive\libmodman.dll 2014-09-22 03:45 - 2014-09-22 03:45 - 00847430 _____ () C:\Program Files\SWITCHdrive\libstdc++-6.dll 2014-09-22 02:05 - 2014-09-22 02:05 - 01150984 _____ () C:\Program Files\SWITCHdrive\libxml2-2.dll 2014-09-22 02:10 - 2014-09-22 02:10 - 02164003 _____ () C:\Program Files\SWITCHdrive\icui18n53.dll 2014-09-22 02:10 - 2014-09-22 02:10 - 01288240 _____ () C:\Program Files\SWITCHdrive\icuuc53.dll 2014-09-22 02:10 - 2014-09-22 02:10 - 21540519 _____ () C:\Program Files\SWITCHdrive\icudata53.dll 2014-09-22 02:16 - 2014-09-22 02:16 - 00144533 _____ () C:\Program Files\SWITCHdrive\libpcre16-0.dll 2014-09-22 02:15 - 2014-09-22 02:15 - 01345629 _____ () C:\Program Files\SWITCHdrive\libGLESv2.dll 2014-09-22 01:58 - 2014-09-22 01:58 - 00203567 _____ () C:\Program Files\SWITCHdrive\libpng16-16.dll 2014-11-10 11:39 - 2014-11-10 11:39 - 15897518 _____ () C:\Program Files\SWITCHdrive\libSWITCHdrivesync.dll 2014-09-22 02:15 - 2014-09-22 02:15 - 00150916 _____ () C:\Program Files\SWITCHdrive\libEGL.dll 2014-09-22 02:08 - 2014-09-22 02:08 - 00197062 _____ () C:\Program Files\SWITCHdrive\libjpeg-8.dll 2014-09-22 02:13 - 2014-09-22 02:13 - 00646511 _____ () C:\Program Files\SWITCHdrive\libsqlite3-0.dll 2014-09-22 03:28 - 2014-09-22 03:28 - 00247028 _____ () C:\Program Files\SWITCHdrive\libwebp-4.dll 2014-09-22 04:24 - 2014-09-22 04:24 - 00228655 _____ () C:\Program Files\SWITCHdrive\libxslt-1.dll 2014-09-24 09:38 - 2014-09-24 09:38 - 00052119 _____ () C:\Program Files\SWITCHdrive\libqt5keychain.dll 2014-09-22 12:25 - 2014-09-22 12:25 - 00702136 _____ () C:\Program Files\SWITCHdrive\platforms\qwindows.dll 2014-09-22 12:25 - 2014-09-22 12:25 - 00032568 _____ () C:\Program Files\SWITCHdrive\imageformats\qgif.dll 2014-09-22 12:25 - 2014-09-22 12:25 - 00035173 _____ () C:\Program Files\SWITCHdrive\imageformats\qico.dll 2014-09-22 12:25 - 2014-09-22 12:25 - 00048436 _____ () C:\Program Files\SWITCHdrive\imageformats\qjpeg.dll 2014-09-22 12:25 - 2014-09-22 12:25 - 00172128 _____ () C:\Program Files\SWITCHdrive\accessible\qtaccessiblewidgets.dll 2015-01-27 14:18 - 2015-01-27 14:18 - 02926800 _____ () C:\Program Files\FileHippo.com\FileHippo.AppManager.exe 2015-04-17 08:56 - 2015-04-17 08:56 - 16863920 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Windows:nlsPreferences ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Standard User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Standard User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 62.2.24.162 - 62.2.17.61 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Moveslink for Movestick Mini.lnk => C:\Windows\pss\Moveslink for Movestick Mini.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Produktregistrierung.lnk => C:\Windows\pss\Logitech . Produktregistrierung.lnk.Startup MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe" MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices MSCONFIG\startupreg: BrMfcWnd => C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR MSCONFIG\startupreg: Cisco AnyConnect Secure Mobility Agent for Windows => "C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized MSCONFIG\startupreg: ControlCenter3 => C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun MSCONFIG\startupreg: GarminExpressTrayApp => "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: Logitech Download Assistant => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch MSCONFIG\startupreg: Logitech Vid => "C:\Program Files\Logitech\Vid\Vid.exe" -bootmode MSCONFIG\startupreg: LWS => C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide MSCONFIG\startupreg: QuickTime Plugin Install => C:\Program Files\QuickTime\Plugins\DeleteMe1.exe MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SPIRunE => Rundll32 SPIRunE.dll,RunDLLEntry MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe MSCONFIG\startupreg: VirtualCloneDrive => "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s ==================== Accounts: ============================= Admin (S-1-5-21-3271901242-2791666843-1555295335-1000 - Administrator - Enabled) => C:\Users\Admin Administrator (S-1-5-21-3271901242-2791666843-1555295335-500 - Administrator - Disabled) Guest (S-1-5-21-3271901242-2791666843-1555295335-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3271901242-2791666843-1555295335-1261 - Limited - Enabled) Marci (S-1-5-21-3271901242-2791666843-1555295335-1263 - Limited - Enabled) => C:\Users\Marci Standard User (S-1-5-21-3271901242-2791666843-1555295335-1003 - Limited - Enabled) => C:\Users\Standard User ==================== Faulty Device Manager Devices ============= Name: Base System Device Description: Base System Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Base System Device Description: Base System Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (04/17/2015 04:18:56 PM) (Source: McLogEvent) (EventID: 259) (User: -) Description: Der Scan hat Entdeckungen gefunden. Scan-Modul der Version 5700.7163 DAT-Version 7773. Error: (04/17/2015 09:44:09 AM) (Source: MsiInstaller) (EventID: 11704) (User: -) Description: Product: Java 8 Update 45 -- Error 1704. An installation for Adobe Flash Player 15 Plugin is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes? Error: (04/17/2015 09:40:00 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program psi.exe version 3.0.0.9016 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: b18 Start Time: 01d078e18213cc2d Termination Time: 16 Application Path: C:\Program Files\Secunia\PSI\psi.exe Report Id: f06fc799-e4d4-11e4-b74e-002170820736 Error: (04/17/2015 09:15:22 AM) (Source: MsiInstaller) (EventID: 11705) (User: NT AUTHORITY) Description: Product: Adobe Flash Player 15 Plugin -- Error 1705.A previous installation for this product is in progress. You must undo the changes made by that installation to continue. Do you want to undo those changes? Error: (04/17/2015 08:59:27 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: explorer.exe, version: 6.1.7601.17567, time stamp: 0x4d6727a7 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0006f447 Faulting process id: 0x2cdc Faulting application start time: 0xexplorer.exe0 Faulting application path: explorer.exe1 Faulting module path: explorer.exe2 Report Id: explorer.exe3 Error: (04/17/2015 07:58:27 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (04/15/2015 06:52:00 PM) (Source: Windows Backup) (EventID: 4103) (User: ) Description: The backup did not complete because of an error writing to the backup location G:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006). Error: (04/15/2015 06:50:20 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (04/11/2015 09:15:11 AM) (Source: Microsoft Office 15) (EventID: 2001) (User: ) Description: Microsoft Outlook: Rejected Safe Mode action : Outlook konnte beim letzten Mal nicht gestartet werden. Der abgesicherte Modus kann Ihnen bei der Problembehandlung behilflich sein. Einige Features sind aber in diesem Modus möglicherweise nicht verfügbar. Möchten Sie im abgesicherten Modus starten?. Rejected Safe Mode action : Microsoft Outlook. Error: (04/11/2015 08:55:50 AM) (Source: Windows Backup) (EventID: 4103) (User: ) Description: The backup did not complete because of an error writing to the backup location G:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006). System errors: ============= Error: (04/17/2015 07:25:26 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (04/17/2015 07:25:02 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (04/17/2015 11:10:37 AM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (04/17/2015 11:10:13 AM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (04/17/2015 10:38:19 AM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (04/17/2015 09:55:50 AM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (04/17/2015 09:42:41 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Windows Update service hung on starting. Error: (04/17/2015 09:37:01 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The FreemakeVideoCapture service failed to start due to the following error: %%2 Error: (04/17/2015 09:36:46 AM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (04/17/2015 09:36:46 AM) (Source: atikmdag) (EventID: 19468) (User: ) Description: CPLIB :: General - Invalid Parameter Microsoft Office Sessions: ========================= Error: (04/17/2015 04:18:56 PM) (Source: McLogEvent) (EventID: 259) (User: -) Description: Der Scan hat Entdeckungen gefunden. Scan-Modul der Version 5700.7163 DAT-Version 7773. Error: (04/17/2015 09:44:09 AM) (Source: MsiInstaller) (EventID: 11704) (User: -) Description: Product: Java 8 Update 45 -- Error 1704. An installation for Adobe Flash Player 15 Plugin is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?(NULL)(NULL)(NULL)(NULL)(NULL) Error: (04/17/2015 09:40:00 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: psi.exe3.0.0.9016b1801d078e18213cc2d16C:\Program Files\Secunia\PSI\psi.exef06fc799-e4d4-11e4-b74e-002170820736 Error: (04/17/2015 09:15:22 AM) (Source: MsiInstaller) (EventID: 11705) (User: NT AUTHORITY) Description: Product: Adobe Flash Player 15 Plugin -- Error 1705.A previous installation for this product is in progress. You must undo the changes made by that installation to continue. Do you want to undo those changes?(NULL)(NULL)(NULL)(NULL)(NULL) Error: (04/17/2015 08:59:27 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: explorer.exe6.1.7601.175674d6727a7unknown0.0.0.000000000c00000050006f4472cdc01d078dbd3a0afdbC:\Windows\explorer.exeunknown493f9d43-e4cf-11e4-8544-002170820736 Error: (04/17/2015 07:58:27 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (04/15/2015 06:52:00 PM) (Source: Windows Backup) (EventID: 4103) (User: ) Description: G:\The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006) Error: (04/15/2015 06:50:20 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (04/11/2015 09:15:11 AM) (Source: Microsoft Office 15) (EventID: 2001) (User: ) Description: Microsoft OutlookOutlook konnte beim letzten Mal nicht gestartet werden. Der abgesicherte Modus kann Ihnen bei der Problembehandlung behilflich sein. Einige Features sind aber in diesem Modus möglicherweise nicht verfügbar. Möchten Sie im abgesicherten Modus starten? Error: (04/11/2015 08:55:50 AM) (Source: Windows Backup) (EventID: 4103) (User: ) Description: G:\The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006) CodeIntegrity Errors: =================================== Date: 2014-06-03 14:16:00.398 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll because the set of per-page image hashes could not be found on the system. Date: 2014-06-03 14:16:00.153 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll because the set of per-page image hashes could not be found on the system. Date: 2014-06-03 14:15:59.903 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll because the set of per-page image hashes could not be found on the system. Date: 2014-06-03 14:15:47.017 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.0.6001.18000_none_34daa5e8f21ef8d2\fveapi.dll because the set of per-page image hashes could not be found on the system. Date: 2014-06-03 14:15:46.767 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.0.6001.18000_none_34daa5e8f21ef8d2\fveapi.dll because the set of per-page image hashes could not be found on the system. Date: 2014-06-03 14:15:46.539 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.0.6001.18000_none_34daa5e8f21ef8d2\fveapi.dll because the set of per-page image hashes could not be found on the system. Date: 2014-06-03 14:14:48.042 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll because the set of per-page image hashes could not be found on the system. Date: 2014-06-03 14:14:47.802 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll because the set of per-page image hashes could not be found on the system. Date: 2014-06-03 14:14:47.568 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll because the set of per-page image hashes could not be found on the system. Date: 2014-06-03 14:13:49.467 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\Backup\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f_bcrypt.dll_e2f091ac because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz Percentage of memory in use: 57% Total physical RAM: 3581.98 MB Available physical RAM: 1518.06 MB Total Pagefile: 8830.27 MB Available Pagefile: 6449.47 MB Total Virtual: 2047.88 MB Available Virtual: 1898.96 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:287.95 GB) (Free:33.95 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:10 GB) (Free:4.97 GB) NTFS ==================== MBR & Partition Table ================== ==================== End Of Log ============================ Geändert von kittyhawk (17.04.2015 um 20:05 Uhr) |
Themen zu Windows 7: McAfee findet Artemis |
adobe, adware, avast, bcrypt.dll, bonjour, browser, cpu, defender, desktop, explorer, firefox, flash player, homepage, installation, lws.exe, mozilla, officejet, photoshop, prozesse, registry, rundll, scan, security, starten, superantispyware, temp, trojanisches pferd, windows |