|
Mülltonne: Browser von download protect 2.2.7/2.2.8 befallen (Teil2) -- wegen Überlänge gesplittetWindows 7 Beiträge, die gegen unsere Regeln verstoßen haben, solche, die die Welt nicht braucht oder sonstiger Müll landet hier in der Mülltonne... |
10.07.2015, 20:06 | #1 |
| Browser von download protect 2.2.7/2.2.8 befallen (Teil2) -- wegen Überlänge gesplittet 3.Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version:24-06-2015 Ran by dietmar at 2015-06-26 03:19:16 Running from C:\Users\dietmar\Desktop\trojanerboard\FRST Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1349822815-2598862020-373602666-500 - Administrator - Disabled) dietmar (S-1-5-21-1349822815-2598862020-373602666-1001 - Administrator - Enabled) => C:\Users\dietmar Gast (S-1-5-21-1349822815-2598862020-373602666-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1349822815-2598862020-373602666-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.144 - Adobe Systems Incorporated) Adobe Digital Editions 4.0 (HKLM-x32\...\Adobe Digital Editions 4.0) (Version: 4.0.3 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.160 - Adobe Systems Incorporated) Android Studio (HKLM\...\Android Studio) (Version: 1.0 - Google Inc.) Anzeige am Bildschirm (HKLM\...\OnScreenDisplay) (Version: 7.12.25 - ) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Application Insights Tools for Visual Studio 2013 (x32 Version: 2.4 - Microsoft Corporation) Hidden AzureTools.Notifications (x32 Version: 2.1.10731.1602 - Microsoft Corporation) Hidden Behaviors SDK (Windows Phone) for Visual Studio 2013 (x32 Version: 12.0.50716.0 - Microsoft Corporation) Hidden Behaviors SDK (Windows) for Visual Studio 2013 (x32 Version: 12.0.50429.0 - Microsoft Corporation) Hidden Blend for Visual Studio 2013 (x32 Version: 12.0.41002.1 - Microsoft Corporation) Hidden Blend for Visual Studio 2013 ENU resources (x32 Version: 12.0.41002.1 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Browser-Security (HKLM-x32\...\Browser-Security) (Version: 1.0.5.0 - ) Build Tools - amd64 (Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools - x86 (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools Language Resources - amd64 (Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools Language Resources - x86 (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden ChessBase Symbol Fonts (HKLM-x32\...\ChessBase Symbol Fonts) (Version: - ) Classic Shell (HKLM\...\{7C129CF8-199F-4269-AAEE-60B5D8D716E2}) (Version: 4.2.1 - IvoSoft) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.9.0 - Conexant) Crystal Reports Basic for Visual Studio 2008 (HKLM-x32\...\{AA467959-A1D6-4F45-90CD-11DC57733F32}) (Version: 10.5.0.0 - Business Objects) Crystal Reports Basic German Language Pack for Visual Studio 2008 (HKLM-x32\...\{3924C3E7-C440-4B23-9740-9A9EC0545F21}) (Version: 10.5.0.0 - Business Objects) Crystal Reports Basic Runtime for Visual Studio 2008 (x64) (HKLM\...\{2BFA9B05-7418-4EDE-A6FC-620427BAAAA3}) (Version: 10.5.0.0 - Business Objects) Crystal Reports Basic Runtime German Language Pack for Visual Studio 2008 (x64) (HKLM\...\{1D5F34D0-6329-4D92-B81A-E24E9028910C}) (Version: 10.5.0.0 - Business Objects) Das große DGS Wörterbuch 1.0.2.6 (HKLM-x32\...\{71FB874A-A992-4ED6-9522-6EFF78ADDDCB}_is1) (Version: - Verlag Karin Kestner) Dependency Package Update (Version: 1.6.30.00 - Lenovo Inc.) Hidden Dependency Package Update (Version: 1.6.36.00 - Lenovo Inc.) Hidden Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden DisplayLink Core Software (HKLM\...\{BB07E020-7224-4EC3-864E-2AA0BF42A7DD}) (Version: 7.4.51572.0 - DisplayLink Corp.) DNSBlock (HKLM\...\{7b5da7f5-de7d-4e00-b330-a2e08e460095}) (Version: 1.0.0 - NETNS GMBH) Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc) Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4954.46574 - PreEmptive Solutions) Hidden Entity Framework 6.1.1 Tools for Visual Studio 2013 (HKLM-x32\...\{85253F13-EE42-4850-A3A5-79B90E92D7AC}) (Version: 12.0.30610.0 - Microsoft Corporation) Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden Hauppauge WinTV 7 (HKLM-x32\...\Hauppauge WinTV 7) (Version: v7.0.28314 - Hauppauge Computer Works) Hotfix für Microsoft Visual Studio 2008 Professional Edition - DEU (KBKB971091) (HKLM-x32\...\{445174EA-3D3A-308E-84AD-446127E71441}.KB971091) (Version: 1 - Microsoft Corporation) Hotfix für Microsoft Visual Studio 2008 Professional Edition - DEU (KBKB973674) (HKLM-x32\...\{445174EA-3D3A-308E-84AD-446127E71441}.KB973674) (Version: 1 - Microsoft Corporation) IIS 8.0 Express (HKLM\...\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}) (Version: 8.0.1557 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (HKLM\...\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb) (Version: - ) IIS Express Application Compatibility Database for x86 (HKLM\...\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb) (Version: - ) Integrated Camera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 5.13.911.3 - Vimicro) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3855 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 3.0.1335.5) (HKLM\...\{302600C1-6BDF-4FD1-1307-148929CC1385}) (Version: 3.1.1307.0362 - Intel Corporation) Intel(R) Smart Connect Technology (HKLM\...\{B1AC3709-3E98-4F2C-A84E-4BCA2A452E64}) (Version: 4.2.40.2418 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{105fa5c4-72e1-41f2-a82c-884d8aa4b381}) (Version: 16.6.0 - Intel Corporation) Java 8 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418045F0}) (Version: 8.0.450 - Oracle Corporation) Java SE Development Kit 8 Update 45 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180450}) (Version: 8.0.450.15 - Oracle Corporation) Kit SDK de vérification de Visual Studio 2012 - fra (x32 Version: 12.0.30501 - Microsoft Corporation) Hidden Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 2.13 - ) Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.36.00 - Lenovo Group Limited) Lenovo Patch Utility (x32 Version: 1.3.2.6 - Lenovo Group Limited) Hidden Lenovo Patch Utility 64 bit (Version: 1.4.0.4 - Lenovo Group Limited) Hidden Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.04.04 - ) Lenovo Settings - Camera Audio (HKLM\...\{88C6A6D9-324C-46E8-BA87-563D14021442}_is1) (Version: 4.1.12.100 - Lenovo Corporation) Lenovo Settings - Location Awareness (HKLM-x32\...\{C79D4402-E622-4922-9C02-89F9080BF081}_is1) (Version: 1.3.0.8 - Lenovo Group Limited) Lenovo Settings Dependency Package (HKLM\...\{3694BA2E-BE31-4B7E-886B-A0B559E69D4D}_is1) (Version: 2.0.0.9 - Lenovo Group Limited) Lenovo Settings UMDF driver (HKLM\...\{2BDC7413-65EA-4B99-8C4B-02F11075BE6D}_is1) (Version: 1.1.0.2 - Lenovo Group Limited) Lenovo Solution Center (HKLM\...\{1CA74803-5CB2-4C03-BDBE-061EDC81CC7F}) (Version: 2.8.004.00 - Lenovo Group Limited) Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.06.0037 - Lenovo) Lenovo Transition (HKLM\...\{660FFFA1-BC46-4B79-A3B5-E51D8964FF1F}) (Version: 1.0.002.00 - Lenovo Group Limited) Lenovo USB Graphics (HKLM\...\{7257526E-B74A-488E-BA2E-56327482B06B}) (Version: 7.4.51587.0 - Lenovo) Lenovo User Guide (HKLM-x32\...\{13F59938-C595-479C-B479-F171AB9AF64F}) (Version: 1.0.0012.00 - Lenovo Group Limited) Lenovo Warranty Information (HKLM-x32\...\{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}) (Version: 1.0.0011.00 - Lenovo) LibreOffice 4.4.3.2 (HKLM-x32\...\{A651A592-2F6C-4D66-AEA8-9BFE4B61BCB3}) (Version: 4.4.3.2 - The Document Foundation) LocalESPC Dev12 (x32 Version: 8.100.25984 - Microsoft Corporation) Hidden LocalESPCui for en-us Dev12 (x32 Version: 8.100.25984 - Microsoft) Hidden Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation) Maxthon Cloud Browser (HKLM-x32\...\Maxthon3) (Version: 4.4.1.2000 - Maxthon International Limited) Memory Profiler (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden Metric Collection SDK (x32 Version: 1.1.0005.00 - Lenovo Group Limited) Hidden Microsoft .NET Compact Framework 2.0 SP2 (HKLM-x32\...\{B1060346-9388-4C5B-AA52-176C39819E43}) (Version: 2.0.7045 - Microsoft Corporation) Microsoft .NET Compact Framework 3.5 (HKLM-x32\...\{72CCBEA1-8D57-4981-A337-81019F28C5BA}) (Version: 3.5.7283 - Microsoft Corporation) Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Device Emulator (64 Bit) Version 3.0 - DEU (HKLM\...\{7ECA1AEA-2B61-3DE6-8276-6A9A2693F111}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Document Explorer 2008 (HKLM-x32\...\Microsoft Document Explorer 2008) (Version: - Microsoft Corporation) Microsoft Document Explorer 2008 Language Pack - DEU (HKLM-x32\...\Microsoft Document Explorer 2008 Language Pack - DEU) (Version: - Microsoft Corporation) Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.1 Language Pack - DEU) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 2.1 (HKLM-x32\...\Microsoft Help Viewer 2.1) (Version: 2.1.21005 - Microsoft Corporation) Microsoft ODBC Driver 11 for SQL Server (HKLM\...\{7D1C6D7B-8E3F-4724-94C8-AA7EB7F60AE0}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Office Visio 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{CE144BF4-4950-4CDB-A5F7-CCE1888F49CB}) (Version: - Microsoft) Microsoft Office Visio Professional 2007 (HKLM-x32\...\VISPRO) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Report Viewer 2014-Laufzeit (HKLM-x32\...\{30956415-84C1-4F0C-B2AD-BC8944730DDA}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft Silverlight 5 SDK (HKLM-x32\...\{E1FBB3D4-ADB0-4949-B101-855DA061C735}) (Version: 5.0.61118.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{5973B12E-5FC1-4EF6-B63B-49C1C4AF2AAA}) (Version: 10.51.2500.0 - Microsoft Corporation) Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{58FED865-4F13-408D-A5BF-996019C4B936}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (HKLM-x32\...\{1B876496-B3A2-4D22-9B12-B608A3FD4B8B}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x64) (HKLM\...\{A6BA243E-85A3-4635-A269-32949C98AC7F}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (HKLM\...\{6C026A91-640F-4A23-8B68-05D589CC6F18}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (HKLM-x32\...\{2F7DBBE6-8EBC-495C-9041-46A772F4E311}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (HKLM\...\{43A5C316-9521-49C3-B9B6-FCE5E1005DF0}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{D411E9C9-CE62-4DBF-9D92-4CB22B750ED5}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (HKLM\...\{54C5041B-0E91-4E92-8417-AAA12493C790}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL Language Service (HKLM-x32\...\{04DD7AF4-A6D3-4E30-9BB9-3B3670719234}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 T-SQL Language Service (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014-Setup (Deutsch) (HKLM\...\{75990ACD-8124-45DB-BAED-6D5B51305F6D}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 Design Tools DEU (HKLM-x32\...\{E32260E7-0B10-43C7-9B77-AB9F4184676D}) (Version: 3.5.5386.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 DEU (HKLM-x32\...\{159098AF-4EB8-4C10-B0C6-24CDA32B45F9}) (Version: 3.5.5386.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 for Devices DEU (HKLM-x32\...\{1C3ADB5F-750E-4453-AC98-B75C5323845C}) (Version: 3.5.5386.0 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - enu (12.0.41012.0) (HKLM-x32\...\{AC8E0CF4-42A1-4151-B684-97CF6FD726CF}) (Version: 12.0.41012.0 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - enu (12.0.30919.1) (HKLM-x32\...\{6781FF9B-E87D-4A03-9373-A55A288B83FA}) (Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server Database Publishing Wizard 1.2 (HKLM-x32\...\{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}) (Version: 1.2.0.0 - Microsoft Corporation) Microsoft SQL Server System CLR Types (HKLM-x32\...\{A282A232-780C-45E2-A5E5-9B61D74DCC6E}) (Version: 10.51.2500.0 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x64) (HKLM\...\{4701DEDE-1888-49E0-BAE5-857875924CA2}) (Version: 10.50.1600.1 - Microsoft Corporation) Microsoft SQL Server 2014 (64-Bit) (HKLM\...\Microsoft SQL Server SQLServer2014) (Version: - Microsoft Corporation) Microsoft SQL Server 2014 Express LocalDB (HKLM\...\{CA191120-4CB1-4E3D-89B8-79FDB9017A2E}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Policies (HKLM-x32\...\{B23A3E56-8859-4F60-B3FA-FA14DE9050B5}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Transact-SQL Compiler Service (HKLM\...\{BC87D3DC-0257-4C81-8795-A0AAE6560B11}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{F2A2DB39-2C5A-4764-AA0F-5AB112663FFA}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{070C38AC-05CE-43DF-9A20-141332F6AB2B}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{05FF8209-C4F1-4C77-BC28-791653156D20}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{4AEB505C-95E1-4964-9B64-8D27F3186D30}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual Studio 2005 Tools for Office Runtime Language Pack (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Office Runtime Language Pack) (Version: - Microsoft Corporation) Microsoft Visual Studio 2008 Professional Edition - DEU (HKLM-x32\...\Microsoft Visual Studio 2008 Professional Edition - DEU) (Version: - Microsoft Corporation) Microsoft Visual Studio 2008 Remote Debugger - DEU (HKLM\...\Microsoft Visual Studio 2008 Remote Debugger - DEU) (Version: - Microsoft Corporation) Microsoft Visual Studio 2010 Shell (Isolated) - DEU (HKLM-x32\...\{987AE03F-234A-3623-BD28-6B31FD1D3AB3}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio Community 2013 with Update 4 (HKLM-x32\...\{96a8b90c-0a91-4e76-ab34-730c23923d11}) (Version: 12.0.31101 - Microsoft Corporation) Microsoft Visual Studio Web Authoring Component (HKLM-x32\...\VisualWebDeveloper) (Version: 12.0.4518.1066 - Microsoft Corporation) Microsoft VSS Writer für SQL Server 2014 (HKLM\...\{D390AADD-C825-4B31-8C79-83A9461D5524}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft Web Deploy 3.5 (HKLM\...\{69A998C5-00A9-42CA-AB4E-C31CFFCD9251}) (Version: 3.1237.1763 - Microsoft Corporation) Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools (HKLM\...\{AC888A60-9557-3B74-B52B-F353D01BD544}) (Version: 3.5.21022 - Microsoft) Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries (HKLM\...\{5DE154DF-A55E-4FA5-BE59-32E78FCACF3E}) (Version: 6.1.5288.17011 - Microsoft Corporation) Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense (HKLM\...\{9aa5f39c-a8de-46b0-919a-0248f8bc8490}) (Version: 6.1.5288.17011 - Microsoft Corporation) Microsoft Windows SDK for Visual Studio 2008 Tools (HKLM\...\{62EED300-E841-4083-A1D6-60B906271804}) (Version: 6.1.5288.17011 - Microsoft Corporation) Microsoft Windows SDK for Visual Studio 2008 Win32 Tools (HKLM\...\{A992BBAA-723D-4574-A07F-983BF8FAA3E1}) (Version: 6.1.5288.17011 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2014 (HKLM\...\{9408684F-E1CC-4D2E-AE15-886023557682}) (Version: 12.0.2000.8 - Microsoft Corporation) Mobile Partner (HKLM-x32\...\Mobile Partner) (Version: 16.002.03.01.40 - Huawei Technologies Co.,Ltd) Mozilla Firefox 38.0.5 (x86 de) (HKLM-x32\...\Mozilla Firefox 38.0.5 (x86 de)) (Version: 38.0.5 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 38.0.5 - Mozilla) MPC-HC 1.7.9 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.9 - MPC-HC Team) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.7.7 - Notepad++ Team) PowreShellIntegration.Notifications (x32 Version: 2.5.21003.1603 - Microsoft Corporation) Hidden PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.3197.1 - PreEmptive Solutions) Hidden Prerequisites for SSDT (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation) Prerequisites for SSDT (HKLM-x32\...\{35C1D9D6-87C0-46A3-B1B4-EDBCC063221C}) (Version: 11.1.3000.0 - Microsoft Corporation) Python Tools Redirection Template (x32 Version: 1.3 - Microsoft Corporation) Hidden QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) RapidBoot HDD Accelerator (HKLM-x32\...\Fastboot) (Version: 2.1.1.0 - Lenovo) SDK de comprobación de Visual Studio 2012 - esn (x32 Version: 12.0.30501 - Microsoft Corporation) Hidden SQL Server 2014 Client Tools (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Common Files (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Database Engine Services (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Database Engine Shared (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Management Studio (Version: 12.0.2000.8 - Microsoft Corporation) Hidden Sql Server Customer Experience Improvement Program (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server-Browser für SQL Server 2014 (HKLM-x32\...\{B7312B95-77C6-497E-A63F-596A77B20F31}) (Version: 12.0.2000.8 - Microsoft Corporation) Team Explorer for Microsoft Visual Studio 2013 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden ThinkPad OneLink Dock (HKLM-x32\...\{8E1CACF5-2493-4950-9AD5-189903FE57E7}) (Version: 1.08.25 - Lenovo) ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.12.68 - ) ThinkPad USB 3.0 Dock (HKLM-x32\...\{69109A9C-1D00-4A84-9ABF-AAE9CADD20DD}) (Version: 1.07.15 - Lenovo) Thinkpad USB 3.0 Ethernet Adapter Driver (HKLM-x32\...\{D8102684-7BA1-4948-88B9-535F84E6E588}) (Version: 8.8.911.2013 - Lenovo) ThinkVantage System für aktiven Festplattenschutz (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.78.0.10 - Lenovo) TypeScript Power Tool (x32 Version: 1.0.5.0 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2013 (x32 Version: 1.0.5.0 - Microsoft Corporation) Hidden Unterstützungsdateien für Microsoft SQL Server 2008-Setup (HKLM\...\{D8125A39-ADEE-4187-B04D-DB6CF489AF61}) (Version: 10.3.5500.0 - Microsoft Corporation) Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0021-0000-0000-0000000FF1CE}_VisualWebDeveloper_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Visual Studio 2008 Professional Edition - DEU (KBKB972221) (HKLM-x32\...\{445174EA-3D3A-308E-84AD-446127E71441}.KB972221) (Version: 1 - Microsoft Corporation) VBCABLE, The Virtual Audio Cable (HKLM\...\VB:VBCABLE {87459874-1236-4469}) (Version: - VB-Audio Software) VC Runtimes MSI (x32 Version: 9.0.21022 - Microsoft) Hidden Visual Studio .NET Prerequisites - English (HKLM\...\{ACD875CC-A146-3125-8F99-D3766F46FD86}) (Version: 9.0.21022 - Microsoft Corporation) Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation) Visual Studio 2010 Prerequisites - English (HKLM\...\{53952792-BF16-300E-ADF2-E7E4367E00CF}) (Version: 10.0.40219 - Microsoft Corporation) Visual Studio 2013 Update 4 (KB2829760) (HKLM-x32\...\{53d408db-eb91-43fb-9d8f-167681c19763}) (Version: 12.0.31101 - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio-Tools für Office System 3.0 Runtime Language Pack - DEU (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime Language Pack - DEU) (Version: - Microsoft Corporation) Voicemeeter, The Virtual Mixing Console (HKLM-x32\...\VB:Voicemeeter {17359A74-1236-5467}) (Version: - VB-Audio Software) VS Update core components (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden VueScan x64 (HKLM\...\VueScan x64) (Version: - ) WCF Data Services 5.6.0 Runtime (x32 Version: 5.6.61587.0 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2013 (x32 Version: 5.6.61587.0 - Microsoft Corporation) Hidden WCF RIA Services V1.0 SP2 (HKLM-x32\...\{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}) (Version: 4.1.62812.0 - Microsoft Corporation) WEB.DE MailCheck für Mozilla Firefox (HKLM-x32\...\1&1 Mail & Media GmbH Toolbar FF) (Version: 1.0.0.0 - 1&1 Mail & Media GmbH) Win32DiskImager version 0.9.5 (HKLM-x32\...\{D074CE74-912A-4AD3-A0BF-3937D9D01F17}_is1) (Version: 0.9.5 - ImageWriter Developers) Windows Mobile 5.0 SDK R2 for Pocket PC (HKLM-x32\...\{721B5CF0-D220-4955-BB6F-EBCFB1096DE7}) (Version: 5.00.1700.5.14343.06 - Microsoft Corporation) Windows Mobile 5.0 SDK R2 for Smartphone (HKLM-x32\...\{DA7F48EF-5F56-45FE-9169-3B8159A7A323}) (Version: 5.00.1700.5.14343.06 - Microsoft Corporation) Windows-Treiberpaket - Intel Corporation (iaStorA) HDC (08/01/2013 12.8.0.1016) (HKLM\...\C8A921233C0C441A4E4EAABC2AB08C872FD77A6E) (Version: 08/01/2013 12.8.0.1016 - Intel Corporation) Windows-Treiberpaket - Intel hdc (07/25/2013 9.4.0.1023) (HKLM\...\87403FF3ADDFA1770936C9436A187AC3B9FBC8DE) (Version: 07/25/2013 9.4.0.1023 - Intel) Windows-Treiberpaket - Intel System (07/25/2013 9.4.0.1023) (HKLM\...\BDBD400472735932E15286ACD00A1DA1856D2B6D) (Version: 07/25/2013 9.4.0.1023 - Intel) Windows-Treiberpaket - Intel System (08/21/2013 9.4.0.1027) (HKLM\...\FC58A12A405BF6933FC97269FF68C969D128F381) (Version: 08/21/2013 9.4.0.1027 - Intel) Windows-Treiberpaket - Intel USB (07/31/2013 9.4.0.1025) (HKLM\...\A6995A77D26D0B0292A9C3B4878836D232899FE0) (Version: 07/31/2013 9.4.0.1025 - Intel) Windows-Treiberpaket - Lenovo 1.67.04.04 (11/07/2013 1.67.04.04) (HKLM\...\70FB73D983446AEE2932B0ED51A770D1BD1348DA) (Version: 11/07/2013 1.67.04.04 - Lenovo) Windows-Treiberpaket - Synaptics (SmbDrv) System (02/06/2014 17.0.12.68) (HKLM\...\342F51AB97BF27B1CF8077CE6B9093FE14E716AE) (Version: 02/06/2014 17.0.12.68 - Synaptics) Windows-Treiberpaket - Synaptics (SynTP) Mouse (02/06/2014 17.0.12.68) (HKLM\...\9B411E2775A7792CE52FB04188C3F02E3F15957F) (Version: 02/06/2014 17.0.12.68 - Synaptics) WinHTTrack Website Copier 3.48-21 (x64) (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.48.21 - HTTrack) XAMPP (HKLM-x32\...\xampp) (Version: 5.6.8-0 - Bitnami) Xmarks for IE (HKLM-x32\...\{ABFA6EAE-C9C0-4B39-B722-02094EF6B889}) (Version: 127.0.177 - Xmarks) Пакет Visual Studio 2012 Verification SDK - rus (x32 Version: 12.0.30501 - Microsoft Corporation) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= 20-06-2015 15:55:44 AVG PC TuneUp 2015 wird entfernt 20-06-2015 15:56:52 AVG PC TuneUp 2015 (de-DE) wird entfernt 22-06-2015 02:09:03 AVG PC TuneUp 2015 (de-DE) wird entfernt 25-06-2015 23:48:32 Windows Update ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0357BEDE-4507-4F72-BDFA-0B8931028617} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2015-03-09] (Lenovo) Task: {042A31F1-534F-40BD-AE97-8EA0509E5CD6} - System32\Tasks\PMTask => C:\Program Files (x86)\ThinkPad\Utilities\PwmIdTsv.exe Task: {13CE099B-102C-41AB-B436-49ADDF5CF1B3} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation) Task: {14E7BF72-A5CB-4A19-BBDC-EBE430B97702} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2015-03-09] () Task: {2B204E76-39F6-4038-BBCA-F6B76B29E5F3} - System32\Tasks\Lenovo\Lenovo Transition Launcher => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [2013-09-05] () Task: {33DDAD0F-AAC4-45C1-B04C-3AFE1D487C23} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe Task: {388D033E-44F5-4F23-BC2D-C2E8C5E02F1B} - System32\Tasks\Opera N Sunday => C:\Program Files (x86)\Opera\launcher.exe Task: {7B9523EE-EBFB-495C-A0BF-8F671E4A929F} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation) Task: {7E763602-124E-49A5-82FA-C258B7685821} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated) Task: {8945A1A6-BA04-482E-AA81-E12233B84574} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation) Task: {8D736E06-EDBB-4F88-8B22-4C241A95C856} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Time-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation) Task: {9300C65A-FFDC-4BA2-ABBB-DE9CA3F07D90} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-03-06] () Task: {99F891AA-221F-4AD5-BAB4-B95118D01F69} - System32\Tasks\Lenovo\LSC\Lenovo Solution Center Notifications => C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe [2015-03-09] (Lenovo) Task: {AF1667B7-4EB5-4F64-80E5-363C94674960} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\mxup.exe [2014-12-10] (Maxthon International ltd.) Task: {B4ABC71B-CF30-4435-98DE-076EE7BE873D} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks Task: {BE207E10-D102-40AB-AE0F-3A18CBB99688} - System32\Tasks\Opera N Saturday => C:\Program Files (x86)\Opera\launcher.exe Task: {CB76B3E6-D321-4FF0-BFBB-CE18C45DA802} - System32\Tasks\UEUEUFX1 => C:\ProgramData\SecurityUtility\SecurityUtility.exe <==== ATTENTION Task: {D7A7BDC4-B6C4-4C00-A564-0045F2BB3072} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2015-05-15] () Task: {E699A9BE-E8FD-431F-A691-DA2E690EA731} - System32\Tasks\Chromium => C:\Users\dietmar\AppData\Local\Chromium\APPLIC~1\450242~1.0\INSTAL~1\UNINST~1.EXE Task: {F6F8A963-4905-4A40-A30B-B45900EE3549} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation) Task: {FB56D49B-27C7-4D31-B0EC-2BCFDDAF8873} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {FF49B497-86C2-4988-A31F-BFA4F3133B5B} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2015-03-06] (Lenovo) Task: C:\WINDOWS\Tasks\Chromium.job => C:\Users\dietmar\AppData\Local\Chromium\APPLIC~1\450242~1.0\INSTAL~1\UNINST~1.EXE Task: C:\WINDOWS\Tasks\UEUEUFX1.job => C:\ProgramData\SecurityUtility\SecurityUtility.exe <==== ATTENTION ==================== Loaded Modules (Whitelisted) ============== 2015-06-20 03:51 - 2015-06-20 03:51 - 00149024 _____ () C:\WINDOWS\system32\DnsBlockUpdateSvc.exe 2013-08-01 18:31 - 2013-08-01 18:31 - 00198120 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe 2013-08-01 18:31 - 2013-08-01 18:31 - 00054760 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll 2013-08-01 18:31 - 2013-08-01 18:31 - 00034792 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll 2014-02-28 00:02 - 2013-09-19 17:04 - 00273408 _____ () C:\WINDOWS\system32\drivers\umdf\Lenovo\SystemHardwareInfo.dll 2014-02-28 00:04 - 2013-10-11 08:44 - 00117248 _____ () C:\Program Files (x86)\ThinkPad\Utilities\GR\PWMRT64V.dll 2014-02-28 00:04 - 2013-11-01 18:16 - 00467720 _____ () C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe 2014-02-28 00:04 - 2013-11-01 18:16 - 00013064 _____ () C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe 2014-02-28 00:04 - 2013-10-11 08:44 - 00117248 _____ () C:\Program Files (x86)\ThinkPad\Utilities\GR\PWMRT64V.DLL 2015-06-20 03:52 - 2015-06-20 03:52 - 00788000 _____ () C:\Program Files (x86)\DnsBlock\DnsBlockTray.exe 2013-09-05 18:28 - 2013-09-05 18:28 - 00106856 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe 2015-06-13 13:26 - 2010-01-08 15:59 - 00540672 _____ () C:\Program Files (x86)\Mobile Partner\Mobile Partner.exe 2015-04-15 22:13 - 2015-04-15 22:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2013-09-05 18:28 - 2013-09-05 18:28 - 00292200 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe 2015-06-26 01:36 - 2010-10-26 11:40 - 00049056 _____ () C:\Program Files\Conexant\ForteConfig\fmapp.exe 2015-05-01 13:56 - 2015-05-01 13:56 - 00419328 _____ () C:\Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.16.0_x86__k1h2ywk1493x8\Lenovo.Discovery.exe 2014-02-28 00:01 - 2014-02-28 00:01 - 00033520 _____ () C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBServiceps.dll 2014-02-27 23:32 - 2013-09-16 21:19 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2015-05-03 19:08 - 2015-05-03 19:08 - 00799232 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Networking\86865ced79f3180ebdfa736d895e5edb\Windows.Networking.ni.dll 2015-05-23 04:11 - 2015-05-23 04:11 - 00228864 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Foundation\16c3eb7650767d95d002c998d0c73eb5\Windows.Foundation.ni.dll 2014-06-27 14:36 - 2014-06-27 14:36 - 00107520 _____ () C:\Program Files (x86)\Xmarks\IE Extension\zlib1.dll 2014-02-28 00:04 - 2013-07-25 17:58 - 02201088 _____ () C:\Program Files\Lenovo\Communications Utility\cxcore210.dll 2014-02-28 00:04 - 2013-07-25 17:58 - 02085888 _____ () C:\Program Files\Lenovo\Communications Utility\cv210.dll 2015-06-13 13:26 - 2010-01-15 14:53 - 00014848 _____ () C:\Program Files (x86)\Mobile Partner\isaputrace.dll 2015-06-13 13:26 - 2010-03-04 11:23 - 00114688 _____ () C:\Program Files (x86)\Mobile Partner\DeviceMgrPlugin.dll 2015-06-13 13:26 - 2010-03-04 11:24 - 00057344 _____ () C:\Program Files (x86)\Mobile Partner\ConfigFilePlugin.dll 2015-06-13 13:26 - 2010-03-04 11:21 - 00147456 _____ () C:\Program Files (x86)\Mobile Partner\NetInfoPlugin.dll 2015-06-13 13:26 - 2010-03-04 11:19 - 00090112 _____ () C:\Program Files (x86)\Mobile Partner\DialUpPlugin.dll 2015-06-13 13:26 - 2010-03-04 11:00 - 00991232 _____ () C:\Program Files (x86)\Mobile Partner\NDISAPI.dll 2015-06-13 13:26 - 2010-01-15 14:53 - 00167936 _____ () C:\Program Files (x86)\Mobile Partner\DetectDev.dll 2015-06-13 13:26 - 2010-01-15 14:53 - 00598016 _____ () C:\Program Files (x86)\Mobile Partner\atcomm.dll 2015-06-13 13:26 - 2010-01-15 14:53 - 00061440 _____ () C:\Program Files (x86)\Mobile Partner\XCodec.dll 2015-06-13 13:26 - 2010-01-15 14:53 - 00061440 _____ () C:\Program Files (x86)\Mobile Partner\DeviceOperate.dll 2015-06-13 13:26 - 2010-03-04 11:26 - 00032768 _____ () C:\Program Files (x86)\Mobile Partner\NotifyServicePlugin.dll 2015-06-13 13:26 - 2010-03-04 11:27 - 00139264 _____ () C:\Program Files (x86)\Mobile Partner\LocaleMgrPlugin.dll 2015-06-13 13:26 - 2010-03-04 11:18 - 00245760 _____ () C:\Program Files (x86)\Mobile Partner\DeviceMgrUIPlugin.dll 2015-06-13 13:26 - 2010-01-15 14:53 - 00090112 _____ () C:\Program Files (x86)\Mobile Partner\FileManager.dll 2015-06-13 13:26 - 2010-03-04 11:27 - 00163840 _____ () C:\Program Files (x86)\Mobile Partner\SMSPlugin.dll 2015-04-29 07:33 - 2015-04-29 07:33 - 01040160 _____ () C:\Program Files (x86)\LibreOffice 4\program\libxml2.dll 2015-04-29 07:32 - 2015-04-29 07:32 - 00357152 _____ () C:\Program Files (x86)\LibreOffice 4\program\glew32.dll 2015-04-29 07:33 - 2015-04-29 07:33 - 00182560 _____ () C:\Program Files (x86)\LibreOffice 4\program\libxslt.dll 2015-04-29 07:33 - 2015-04-29 07:33 - 00100640 _____ () C:\Program Files (x86)\LibreOffice 4\program\python3.dll 2015-04-29 02:35 - 2015-04-29 02:35 - 00049664 _____ () C:\Program Files (x86)\LibreOffice 4\program\python-core-3.3.3\lib\_socket.pyd 2013-09-05 18:28 - 2013-09-05 18:28 - 00097128 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll 2013-09-05 18:28 - 2013-09-05 18:28 - 00101224 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll 2015-05-03 19:08 - 2015-05-03 19:08 - 03530752 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.UI.Xaml\0b2afd93fc0545b7b94339e8a4a7af97\Windows.UI.Xaml.ni.dll 2015-05-03 19:08 - 2015-05-03 19:08 - 01131008 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.App640a3541#\72dff8d45b73e9b02b3838d29765607a\Windows.ApplicationModel.ni.dll 2015-05-03 19:08 - 2015-05-03 19:08 - 00808448 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Storage\7abff64c7c1ea1fae5bd170c8238b73e\Windows.Storage.ni.dll 2015-05-03 19:08 - 2015-05-03 19:08 - 00960000 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.UI\8ddd8ad15fe3fb05a871ef0115fb84e2\Windows.UI.ni.dll 2015-05-01 15:07 - 2015-05-01 15:07 - 01282048 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Devices\4764145200fcd33a90ced1505892fce6\Windows.Devices.ni.dll 2015-05-03 19:08 - 2015-05-03 19:08 - 00402432 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Security\ae4a1bf110c1a12f619514bde2b27939\Windows.Security.ni.dll 2015-05-03 19:08 - 2015-05-03 19:08 - 00133120 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.System\c639835fe3da556a2cbe2e03540996c0\Windows.System.ni.dll 2015-05-03 19:08 - 2015-05-03 19:08 - 00337920 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Data\98644a649e9bf9e880f2e97889501b07\Windows.Data.ni.dll 2015-04-16 00:11 - 2015-04-16 00:11 - 00014336 _____ () C:\Program Files (x86)\Notepad++\plugins\NppExport.dll 2015-04-16 00:11 - 2015-04-16 00:11 - 02748416 _____ () C:\Program Files (x86)\Notepad++\plugins\NppFTP.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Windows:nlsPreferences AlternateDataStreams: C:\Users\dietmar\SkyDrive:ms-properties ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-1349822815-2598862020-373602666-1001\...\hola.org -> hxxp://hola.org ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1349822815-2598862020-373602666-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{4020B7A5-CA19-4F5F-873B-15483EA13D5C}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{5FBF9BE7-B387-4BC1-83F9-DAAF9D8C14F4}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe FirewallRules: [{F99DA584-81DB-4B99-A70D-DCD2A544931D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe FirewallRules: [{E74E1D67-A7C4-4F48-80E2-B857C87100F5}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe FirewallRules: [{E13B7E83-E963-4172-95AE-1FA58E6127FE}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe FirewallRules: [{DA05E8E3-2908-44A1-8A82-6E7B4AB347D9}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\devenv.exe FirewallRules: [TCP Query User{366D027B-D2BB-4952-A14A-30AB7C2B126F}C:\program files (x86)\internet explorer\iexplore.exe] => (Block) C:\program files (x86)\internet explorer\iexplore.exe FirewallRules: [UDP Query User{5418BC7E-6CC5-47A1-81D6-FF0D8D1504EB}C:\program files (x86)\internet explorer\iexplore.exe] => (Block) C:\program files (x86)\internet explorer\iexplore.exe FirewallRules: [{D1B3E46D-56F9-4A1D-9A66-2221D834A057}] => (Allow) C:\Windows\System32\config\systemprofile\AppData\Local\Hola\firefox_hola\app\hola_plugin.exe FirewallRules: [{EA07E8B0-B47D-4989-B047-B4BBC492CE15}] => (Allow) C:\Windows\System32\config\systemprofile\AppData\Local\Hola\firefox_hola\app\hola_plugin.exe FirewallRules: [{F26E5B2E-EC32-4FC7-9C65-6E3D67BCD594}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe FirewallRules: [{56C13753-D791-4322-B197-A647B23601BF}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe FirewallRules: [{7DB79029-8301-4B52-886E-3E48EFB292A4}] => (Allow) C:\Program Files\Hola\app\hola_updater.exe FirewallRules: [{F8DEE95C-825E-4CC4-AFD1-955927C8573C}] => (Allow) C:\Program Files\Hola\app\hola_updater.exe FirewallRules: [{8BDA8D0D-18C6-49AA-962D-18AD120CC15A}] => (Allow) C:\Users\dietmar\AppData\Local\Hola\firefox\app\hola_plugin.exe FirewallRules: [{1FBB9DF3-3199-4A59-B747-BE0DCC9081B1}] => (Allow) C:\Users\dietmar\AppData\Local\Hola\firefox\app\hola_plugin.exe FirewallRules: [{3128A6D6-6AE5-42FD-A1D9-148A713A98FB}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe FirewallRules: [{29CF88BF-F5F7-4E95-88CE-2E88965AD67F}] => (Allow) C:\Users\dietmar\AppData\Local\Chromium\Application\chrome.exe FirewallRules: [{5F520873-356C-45EC-9B90-3FB9E7B6B9ED}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{DDAC28E0-6B62-420F-91EB-2051C7F20203}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/26/2015 02:25:03 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Explorer.EXE, Version 6.3.9600.17667 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1f1c Startzeit: 01d0af6eae041b79 Endzeit: 0 Anwendungspfad: C:\WINDOWS\Explorer.EXE Berichts-ID: e1bb4408-1b8a-11e5-82a7-0c8bfdd19371 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/26/2015 01:51:34 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 38.0.5.5623, Zeitstempel: 0x5563c49a Name des fehlerhaften Moduls: xul.dll, Version: 38.0.5.5623, Zeitstempel: 0x5563c343 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00943558 ID des fehlerhaften Prozesses: 0x23a0 Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Vollständiger Name des fehlerhaften Pakets: plugin-container.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: plugin-container.exe5 Error: (06/26/2015 01:51:31 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 38.0.5.5623, Zeitstempel: 0x5563c49a Name des fehlerhaften Moduls: mozalloc.dll, Version: 38.0.5.5623, Zeitstempel: 0x5563b229 Ausnahmecode: 0x80000003 Fehleroffset: 0x00001aa1 ID des fehlerhaften Prozesses: 0x1cb0 Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Vollständiger Name des fehlerhaften Pakets: plugin-container.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: plugin-container.exe5 Error: (06/25/2015 04:55:58 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Explorer.EXE, Version 6.3.9600.17667 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 11ec Startzeit: 01d0aedc2532d20d Endzeit: 5765 Anwendungspfad: C:\WINDOWS\Explorer.EXE Berichts-ID: 30dc7275-1b4a-11e5-82a6-0050b66f480d Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/24/2015 11:19:38 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Explorer.EXE, Version 6.3.9600.17667 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 10d4 Startzeit: 01d0aec29cdbb411 Endzeit: 0 Anwendungspfad: C:\WINDOWS\Explorer.EXE Berichts-ID: 67ff0ca2-1ab6-11e5-82a5-0c8bfdd19371 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (06/24/2015 10:47:10 PM) (Source: Adobe Reader) (EventID: 16) (User: ) Description: Error: (06/24/2015 11:17:23 AM) (Source: ISCTAgent) (EventID: 1000) (User: ) Description: ISCT - CAudioControl::UnsetMute Unable to change the mute state. GLE=14007 Error: (06/23/2015 02:58:40 AM) (Source: Adobe Reader) (EventID: 16) (User: ) Description: Error: (06/21/2015 02:53:17 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2147009284. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (06/21/2015 02:53:17 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2147009284. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. System errors: ============= Error: (06/26/2015 02:18:12 AM) (Source: DCOM) (EventID: 10016) (User: LENOVO-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Lenovo-PCdietmarS-1-5-21-1349822815-2598862020-373602666-1001LocalHost (unter Verwendung von LRPC)E046963F.LenovoCompanion_2.2.16.0_x86__k1h2ywk1493x8S-1-15-2-4089219695-2918877493-2298198654-3910773282-1202009102-2725390625-3479975918 Error: (06/26/2015 02:18:12 AM) (Source: DCOM) (EventID: 10016) (User: LENOVO-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Lenovo-PCdietmarS-1-5-21-1349822815-2598862020-373602666-1001LocalHost (unter Verwendung von LRPC)E046963F.LenovoCompanion_2.2.16.0_x86__k1h2ywk1493x8S-1-15-2-4089219695-2918877493-2298198654-3910773282-1202009102-2725390625-3479975918 Error: (06/26/2015 02:18:12 AM) (Source: DCOM) (EventID: 10016) (User: LENOVO-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Lenovo-PCdietmarS-1-5-21-1349822815-2598862020-373602666-1001LocalHost (unter Verwendung von LRPC)E046963F.LenovoCompanion_2.2.16.0_x86__k1h2ywk1493x8S-1-15-2-4089219695-2918877493-2298198654-3910773282-1202009102-2725390625-3479975918 Error: (06/26/2015 02:18:12 AM) (Source: DCOM) (EventID: 10016) (User: LENOVO-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Lenovo-PCdietmarS-1-5-21-1349822815-2598862020-373602666-1001LocalHost (unter Verwendung von LRPC)E046963F.LenovoCompanion_2.2.16.0_x86__k1h2ywk1493x8S-1-15-2-4089219695-2918877493-2298198654-3910773282-1202009102-2725390625-3479975918 Error: (06/26/2015 02:18:12 AM) (Source: DCOM) (EventID: 10016) (User: LENOVO-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Lenovo-PCdietmarS-1-5-21-1349822815-2598862020-373602666-1001LocalHost (unter Verwendung von LRPC)E046963F.LenovoCompanion_2.2.16.0_x86__k1h2ywk1493x8S-1-15-2-4089219695-2918877493-2298198654-3910773282-1202009102-2725390625-3479975918 Error: (06/26/2015 02:18:12 AM) (Source: DCOM) (EventID: 10016) (User: LENOVO-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Lenovo-PCdietmarS-1-5-21-1349822815-2598862020-373602666-1001LocalHost (unter Verwendung von LRPC)E046963F.LenovoCompanion_2.2.16.0_x86__k1h2ywk1493x8S-1-15-2-4089219695-2918877493-2298198654-3910773282-1202009102-2725390625-3479975918 Error: (06/26/2015 02:18:12 AM) (Source: DCOM) (EventID: 10016) (User: LENOVO-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Lenovo-PCdietmarS-1-5-21-1349822815-2598862020-373602666-1001LocalHost (unter Verwendung von LRPC)E046963F.LenovoCompanion_2.2.16.0_x86__k1h2ywk1493x8S-1-15-2-4089219695-2918877493-2298198654-3910773282-1202009102-2725390625-3479975918 Error: (06/26/2015 02:18:12 AM) (Source: DCOM) (EventID: 10016) (User: LENOVO-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Lenovo-PCdietmarS-1-5-21-1349822815-2598862020-373602666-1001LocalHost (unter Verwendung von LRPC)E046963F.LenovoCompanion_2.2.16.0_x86__k1h2ywk1493x8S-1-15-2-4089219695-2918877493-2298198654-3910773282-1202009102-2725390625-3479975918 Error: (06/26/2015 02:18:12 AM) (Source: DCOM) (EventID: 10016) (User: LENOVO-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Lenovo-PCdietmarS-1-5-21-1349822815-2598862020-373602666-1001LocalHost (unter Verwendung von LRPC)E046963F.LenovoCompanion_2.2.16.0_x86__k1h2ywk1493x8S-1-15-2-4089219695-2918877493-2298198654-3910773282-1202009102-2725390625-3479975918 Error: (06/26/2015 02:18:12 AM) (Source: DCOM) (EventID: 10016) (User: LENOVO-PC) Description: AnwendungsspezifischLokalAktivierung{0C0A3666-30C9-11D0-8F20-00805F2CD064}{9209B1A6-964A-11D0-9372-00A0C9034910}Lenovo-PCdietmarS-1-5-21-1349822815-2598862020-373602666-1001LocalHost (unter Verwendung von LRPC)E046963F.LenovoCompanion_2.2.16.0_x86__k1h2ywk1493x8S-1-15-2-4089219695-2918877493-2298198654-3910773282-1202009102-2725390625-3479975918 Microsoft Office: ========================= CodeIntegrity Errors: =================================== Date: 2015-06-26 01:51:19.232 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-26 01:51:18.931 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-26 01:51:18.607 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-26 01:51:18.296 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-26 01:51:17.364 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-26 01:51:11.447 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-26 01:51:11.140 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-26 01:51:10.880 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-26 01:51:03.571 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-06-26 01:50:42.844 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4200U CPU @ 1.60GHz Percentage of memory in use: 49% Total physical RAM: 8102.8 MB Available physical RAM: 4128.12 MB Total Pagefile: 9382.8 MB Available Pagefile: 4407.33 MB Total Virtual: 131072 MB Available Virtual: 131071.81 MB ==================== Drives ================================ Drive c: (Windows8_OS) (Fixed) (Total:625.05 GB) (Free:505.42 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 658E0480) Partition: GPT Partition Type. ======================================================== Disk: 1 (Size: 14.9 GB) (Disk ID: 8CF416B6) Partition: GPT Partition Type. ==================== End of log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2015-06-26 18:41:11 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000034 WDC_WD10SPCX-08HWST0 rev.01.01A01 931,51GB Running: Gmer-19357.exe; Driver: C:\Users\dietmar\AppData\Local\Temp\fxrirpog.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe[1092] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe[1092] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe[1092] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe[1092] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe[1092] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ff8be3d1f6a 4 bytes [3D, BE, F8, 7F] .text C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe[1092] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ff8be3d1f82 4 bytes [3D, BE, F8, 7F] .text C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe[1168] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe[1168] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe[1168] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe[1168] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\WLANExt.exe[1392] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\WLANExt.exe[1392] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\WLANExt.exe[1392] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\WLANExt.exe[1392] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\DnsBlockUpdateSvc.exe[1828] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\DnsBlockUpdateSvc.exe[1828] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\DnsBlockUpdateSvc.exe[1828] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\DnsBlockUpdateSvc.exe[1828] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1904] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1904] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1904] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1904] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1904] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ff8be3d1f6a 4 bytes [3D, BE, F8, 7F] .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1904] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ff8be3d1f82 4 bytes [3D, BE, F8, 7F] .text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[2264] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[2264] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[2264] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[2264] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS2014\MSSQL\Binn\sqlservr.exe[2488] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS2014\MSSQL\Binn\sqlservr.exe[2488] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS2014\MSSQL\Binn\sqlservr.exe[2488] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS2014\MSSQL\Binn\sqlservr.exe[2488] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[3408] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[3408] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[3408] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[3408] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[3456] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[3456] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[3456] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[3456] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3596] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3596] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3596] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3596] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[936] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[936] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[936] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[936] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5300] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5300] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5300] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5300] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[5556] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[5556] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[5556] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[5556] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\rundll32.exe[5944] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8c5de169a 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\rundll32.exe[5944] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8c5de16a2 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\rundll32.exe[5944] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8c5de181a 4 bytes [DE, C5, F8, 7F] .text C:\WINDOWS\system32\rundll32.exe[5944] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8c5de1832 4 bytes [DE, C5, F8, 7F] ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [588:596] fffff9600087ab90 Thread C:\WINDOWS\system32\svchost.exe [1248:5100] 00007ff89f1f4608 Thread C:\WINDOWS\system32\svchost.exe [1248:5112] 00007ff89f1c1584 Thread C:\WINDOWS\system32\svchost.exe [1248:4128] 00007ff89f0e1b30 Thread C:\WINDOWS\system32\svchost.exe [1248:7004] 00007ff89f1f1040 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5544:4884] 00007ff8c5d75aa0 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5544:6288] 00007ff8c3d90310 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5544:3176] 00007ff8c3d90310 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- |
10.07.2015, 20:12 | #2 |
/// TB-Ausbilder | Browser von download protect 2.2.7/2.2.8 befallen (Teil2) -- wegen Überlänge gesplittet bitte nichts splitten... dieses Thema wird geschlossen.
__________________Poste diese beiden Logdateien in deinem anderen Thema. |
Themen zu Browser von download protect 2.2.7/2.2.8 befallen (Teil2) -- wegen Überlänge gesplittet |
addon, adware, bildschirm, browser, chromium, computer, cpu, desktop, feedback, festplatte, firefox, flash player, google, helper, iexplore.exe, internet, internet explorer, maleware, nicht entfernbar, programm, rundll, scan, security, securityutility, server, software, svchost.exe, tcp, udp, usb, windows, windowsapps |