|
Log-Analyse und Auswertung: BKA-Trojaner aber keine SperrungenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
17.07.2015, 15:20 | #1 |
| BKA-Trojaner aber keine Sperrungen Hallo, Ich kenne mich überhaupt nicht mit Computern aus und hoffe, dass mir jemand weiterhelfen kann. Zum Thema: Ich wollte mir gestern einen Film auf eine dieser Streaming-Seiten ansehen, auf denen man bekanntlich weitergeleitet wird, wenn man sich den Film angucken möchte. Als ich auf eine dieser Seiten war, erschien ein kleines, weißes Fenster im oberen mittigen Bereich der Seite und meinte, dass auf meinem PC illegales Material gefunden wurde und er gesperrt werden würde, wenn man keine 100 Euro zahlt. Die Anzeige war ohne großen Schnick Schnack nur das weiße Kästchen mit der in schwarz gedruckten Aufforderung und einer kleinen Leiste am unteren Ende in der man einen Code eingeben soll (vermutlich Kreditkarte? Habe keine) um das Geld zu überweisen/abzuziehen. Mir war natürlich klar, dass das nicht sein konnte und habe versucht es wegzuklicken, doch es kam immer wieder. Die Seite an sich und den Browser konnte ich vorerst auch nicht schließen, habe es dann aber mit Rechtsklick und 'Fenster Schließen' geschafft. Als ich dann kurz darauf den Fall gegoogled habe, hat sich herausgestellt, dass es sich womöglich um den BKA-Trojaner handeln könnte, der sich bereits beim Betreten der Seite installiert, im Hintergrund herunterlädt und den Pc/Browser lahm legt bzw sperrt. An meinem Computer kann ich aber bis jetzt immer noch keine Veränderung feststellen. Hatte gestern nach der Meldung auch sofort mein Virenprogramm angeschmissen und es entdeckte auch gleich zwei mittelschwere Bedrohungen die er aber auch gleich entfernt hat. Dennoch denke ich, dass sich ein solcher Trojaner nicht so einfach entdecken und entfenen lässt. In einem anderen Forum wurde mir geraten Malwarebytes Antimalware herunterzuladen und meinen Laptop scannen zu lassen. Habe ich auch gleich gemacht und es kamen 82 Befunde heraus. Allerdings hatte mir dasProgramm erst nach dem Scan eröffnet, dass ich meine Datenbank aktualisieren sollte. Also schnell aktualisiert und nochmal durchlaufen lassen. Wieder 14 mal fündig geworden. habe sie erst einmal in Virenquarantäne gepackt und mir auf Anraten Malwarebytes Anti-Rootkit heruntergeladen und ebenfalls alles scannen lassen. Das Ergebnis konnte ich jedoch nicht mehr Einsehen, da mein PC sofort einen Neustart gemacht hat und danach noch einen zweiten, weil das Programm es für nötig Befunden hat, wie ich das aus der Englischen Anzeige lesen konnte, sie mir Windows kurz vor dem zweiten Neustart angezeigt hatte. Allerdings hat sich das Programm nach den Neustarts nicht wieder geöffnet oder mir sonst etwas angezeigt. Jetzt weiß ich nicht mehr weiter Da ich zum Zeitpunkt, als sich die Anzeige gezeigt hat, mein Adobe Reader und Flash Player nicht auf die neuste Version aktualisiert hatte, ist die Wahrscheinlichkeit doch groß, dass sich der Trojaner auf meinem Laptop befindet, oder? Doch wie und wo erkenne ich ihn und vor allem wie bekomme ich ihn wieder runter? Falls es hilft: habe einen Windows 8.1 Lenovo Laptop, Adobe Reader und Flash Player sind mittlerweile aktualisiert, Java ist deaktiviert, Google Chrome (Hatte ich zum Zeitpunkt benutzt) befand sich ebenfalls auf dem neusten Stand, als Virenprogramm benutzte ich AVG (free, nicht PRO). Es wäre wirklich großartig, wenn mir jemand (vielleicht mit viel Geduld ) helfen könnte. LG! |
17.07.2015, 15:25 | #2 |
/// TB-Ausbilder | BKA-Trojaner aber keine SperrungenMein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags: So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Danke für deine Mitarbeit! Alle Logdateien von MBAM mit Funden posten!!! Zur ersten Analyse bitte FRST und TDSS-Killer ausführen: Schritt 1 Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Schritt 2 Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
Bitte poste mit deiner nächsten Antwort
|
17.07.2015, 16:13 | #3 |
| BKA-Trojaner aber keine Sperrungen Hallo und danke für die schnelle Antwort! Leider auch schon das erste Problem: etwas stimmt mit unserer Internetverbindung nicht und wenn ich etwas runterlade dauert das eine Zeit und anscheinend hängt das manchmal auch mit der Seite zusammen. Auf jeden Fall startet der Download zu Farbar's Recovery Scan Tool bei mir einfach nicht. Es wird immer 0 Byte/s - 0 B von 2,0 MB angezeigt und es verändert sich nichts. Gibt es auch noch eine Möglichkeit es von einer anderen Seite zu Downloaden? Das gleiche Problem hatte ich mit dem Malwarebytes Anti-Rootkit. Da konnte ich es auch nicht von FilePony runterladen und musste eine andere Seite suchen.
__________________Okay hat wundersamerweise doch heruntergeladen Entschuldigung Okay hier ist FRST.txt. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015 Ran by Franziska (administrator) on LENOVO-PC on 17-07-2015 16:52:40 Running from C:\Users\Franziska\Desktop Loaded Profiles: Franziska (Available Profiles: Franziska) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe (AMD) C:\Windows\System32\atiesrxx.exe (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe () C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe (Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE (Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\ToolbarUpdater.exe () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\loggingserver.exe (Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (Lenovo) C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe (Pokki) C:\Users\Franziska\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIGJE.EXE (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe () C:\Program Files (x86)\AVG Web TuneUp\vprot.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Pokki) C:\Users\Franziska\AppData\Local\Pokki\Engine\HostAppService.exe (Pokki) C:\Users\Franziska\AppData\Local\Pokki\Engine\HostAppService.exe (AVG Secure Search) C:\Program Files (x86)\AVG Web TuneUp\avgcefrend.exe () C:\Program Files\Lenovo PhoneCompanion\adb.exe (Pokki) C:\Users\Franziska\AppData\Local\Pokki\Engine\StartMenuIndexer.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] () HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-04] (Conexant Systems, Inc.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891592 2014-02-11] (ELAN Microelectronics Corp.) HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [216064 2014-01-06] (Realtek Semiconductor Corporation) HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-08-15] (Lenovo) HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-08-15] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2014-08-15] (Lenovo(beijing) Limited) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-04-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [snp2uvc] => C:\WINDOWS\vsnp2uvc.exe HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3730344 2015-06-30] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [3174800 2015-07-12] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation) HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\Run: [Pokki] => "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\Run: [EPSON BX305 Series] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIGJE.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION) ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://mysearch.avg.com/?cid={AB46C594-7D09-4979-986C-153B9015C85B}&mid=9c81e2d5481d47d2a1e66159075d9129-c40fa69071f88bcc879e1f6686bbed7b8d9f4f45&lang=de&ds=AVG&coid=avgtbavg&cmpid=1214tb&pr=fr&d=2014-11-06 21:27:08&v=4.1.0.411&pid=wtu&sg=&sap=hp HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://lenovo13.msn.com/?pc=LCJB hxxp://www.lenovo.com HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2372557226-1662704196-739550879-1002 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={AB46C594-7D09-4979-986C-153B9015C85B}&mid=9c81e2d5481d47d2a1e66159075d9129-c40fa69071f88bcc879e1f6686bbed7b8d9f4f45&lang=de&ds=AVG&coid=avgtbavg&cmpid=1214tb&pr=fr&d=2014-11-06 21:27:08&v=4.1.0.411&pid=wtu&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-2372557226-1662704196-739550879-1002 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={AB46C594-7D09-4979-986C-153B9015C85B}&mid=9c81e2d5481d47d2a1e66159075d9129-c40fa69071f88bcc879e1f6686bbed7b8d9f4f45&lang=de&ds=AVG&coid=avgtbavg&cmpid=1214tb&pr=fr&d=2014-11-06 21:27:08&v=4.1.0.411&pid=wtu&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-2372557226-1662704196-739550879-1002 -> {97CB315F-D830-4B49-92BC-986D9C008592} URL = BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.1.4.948\AVG Web TuneUp.dll [2015-07-12] (AVG) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-17] (Oracle Corporation) BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.1.4.948\AVG Web TuneUp.dll [2015-07-12] (AVG) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-17] (Oracle Corporation) Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.2.0\ViProtocol.dll [2014-12-10] (AVG Secure Search) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{126079A8-E17A-4F05-894B-2B5B8A051737}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{E6F50CE2-672B-468B-BF96-C59F56340331}: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285 FF SelectedSearchEngine: AVG Secure Search FF Homepage: google.de FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-17] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-17] () FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.7.0\\npsitesafety.dll No File FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-17] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-17] (Oracle Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2013-12-12] (Nitro PDF) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\searchplugins\avg-secure-search.xml [2015-05-07] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2015-07-12] FF Extension: AVG Web TuneUp - C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\Extensions\avg@toolbar [2015-05-07] FF Extension: Adblock Plus - C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-18] Chrome: ======= CHR Profile: C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-17] CHR Extension: (Google Docs) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-17] CHR Extension: (Google Drive) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-17] CHR Extension: (YouTube) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-17] CHR Extension: (AVG Secure Search) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2014-11-06] CHR Extension: (Google Search) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-17] CHR Extension: (Google Sheets) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-17] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-19] CHR Extension: (Cath Kidston) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndlpkmaeinmnbiadacenijnhlolneopm [2014-10-19] CHR Extension: (Google Wallet) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-17] CHR Extension: (Gmail) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-18] (Advanced Micro Devices, Inc.) [File not signed] R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3518376 2015-06-30] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [314304 2015-06-30] (AVG Technologies CZ, s.r.o.) R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [84992 2014-01-22] () [File not signed] S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99632 2013-10-09] (ELAN Microelectronics Corp.) S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo) R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584632 2015-03-06] (LENOVO INCORPORATED.) R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-08-15] (Lenovo(beijing) Limited) S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1663880 2014-05-06] () S2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-12] (Nitro PDF Software) R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-08-15] (Lenovo) S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2014-08-15] (Lenovo) R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] () R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51712 2014-02-24] (Advanced Micro Devices, Inc.) R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-08-15] () R2 vToolbarUpdater18.7.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\ToolbarUpdater.exe [1874320 2015-07-12] (AVG Secure Search) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation) R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1195920 2015-07-12] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [85704 2014-02-24] (Advanced Micro Devices, Inc. ) R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-12] (Advanced Micro Devices, Inc.) R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [230088 2014-02-24] (Advanced Micro Devices, Inc. ) R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [224992 2013-11-01] (AppEx Networks Corporation) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices) S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [293296 2015-06-26] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [253408 2015-05-12] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [259040 2015-06-16] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [226784 2015-06-10] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [295400 2015-06-15] (AVG Technologies CZ, s.r.o.) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation) S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [107736 2015-07-17] (Malwarebytes Corporation) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation) S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation) R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-04-15] (Realtek Semiconductor Corporation) R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3593432 2014-10-07] (Realtek Semiconductor Corporation ) R3 SNP2UVC; C:\Windows\system32\DRIVERS\snp2uvc.sys [2853400 2014-01-23] (Sonix Co. Ltd.) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-17 16:52 - 2015-07-17 16:53 - 00021675 _____ C:\Users\Franziska\Desktop\FRST.txt 2015-07-17 16:52 - 2015-07-17 16:52 - 00000000 ____D C:\FRST 2015-07-17 16:51 - 2015-07-17 16:51 - 01814528 _____ C:\Users\Franziska\Downloads\Nicht bestätigt 599347.crdownload 2015-07-17 16:38 - 2015-07-17 16:43 - 02133504 _____ (Farbar) C:\Users\Franziska\Desktop\FRST64.exe 2015-07-17 14:23 - 2015-07-17 14:43 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2015-07-17 14:17 - 2015-07-17 14:48 - 00000000 ____D C:\Users\Franziska\Desktop\mbar 2015-07-17 13:54 - 2015-07-17 14:11 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Franziska\Downloads\mbar-1.09.1.1004.exe 2015-07-17 12:46 - 2015-07-17 12:46 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-07-17 12:46 - 2015-07-17 12:46 - 00002078 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2015-07-17 12:00 - 2015-07-17 12:00 - 00013555 _____ C:\Users\Franziska\Desktop\Malwarebytes antimalware befunde.txt 2015-07-17 11:08 - 2015-07-17 14:50 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-07-17 11:03 - 2015-07-17 14:17 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2015-07-17 11:03 - 2015-07-17 11:03 - 00001125 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-07-17 11:03 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2015-07-17 11:03 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2015-07-17 10:46 - 2015-07-17 10:57 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Franziska\Downloads\mbam-setup-2.1.8.1057.exe 2015-07-17 00:54 - 2015-07-17 00:54 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2015-07-17 00:54 - 2015-07-17 00:54 - 00000000 ____D C:\ProgramData\Sun 2015-07-17 00:54 - 2015-07-17 00:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-07-17 00:53 - 2015-07-17 00:53 - 00000000 ____D C:\ProgramData\Oracle 2015-07-17 00:53 - 2015-07-17 00:53 - 00000000 ____D C:\Program Files (x86)\Java 2015-07-17 00:15 - 2015-07-17 00:15 - 00563296 _____ (Oracle Corporation) C:\Users\Franziska\Downloads\chromeinstall-8u51.exe 2015-07-13 00:30 - 2015-07-13 00:45 - 33832046 _____ C:\Users\Franziska\Downloads\Adel Tawil - Lieder (Parodie) Luke Mockridge - Pimmelbingo .mp4 2015-07-11 22:33 - 2015-07-11 22:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-07-11 21:20 - 2015-07-11 21:20 - 00001957 _____ C:\Users\Public\Desktop\Lenovo Updates.lnk 2015-06-29 14:05 - 2015-06-29 14:05 - 00000000 ____D C:\Users\Franziska\Desktop\pdf 2015-06-27 18:18 - 2015-06-27 18:18 - 00025592 _____ C:\Users\Franziska\Desktop\Kündigung Mama und Oma Wohnung.odt 2015-06-27 15:08 - 2015-06-27 15:08 - 00000000 ____D C:\Users\Franziska\AppData\Local\GWX 2015-06-26 09:49 - 2015-06-26 09:49 - 00293296 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys 2015-06-22 21:09 - 2015-05-22 15:08 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2015-06-22 21:09 - 2015-05-21 15:08 - 01119232 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2015-06-22 21:09 - 2015-05-21 15:08 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2015-06-22 21:09 - 2015-05-21 15:08 - 00756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2015-06-22 21:09 - 2015-05-21 15:08 - 00422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2015-06-22 21:09 - 2015-05-21 15:08 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 2015-06-22 21:09 - 2015-05-21 15:08 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2015-06-22 21:09 - 2015-04-17 00:07 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2015-06-19 12:50 - 2015-06-19 12:50 - 00000000 ____D C:\Program Files\Common Files\AV 2015-06-19 12:38 - 2015-07-11 21:15 - 00001279 _____ C:\Users\Franziska\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-17 16:53 - 2014-08-15 00:39 - 01622397 _____ C:\WINDOWS\WindowsUpdate.log 2015-07-17 16:40 - 2014-11-18 14:43 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-07-17 16:31 - 2014-10-17 15:20 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2372557226-1662704196-739550879-1002 2015-07-17 16:08 - 2014-10-17 15:34 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-17 16:03 - 2013-08-22 17:20 - 00000000 ____D C:\WINDOWS\CbsTemp 2015-07-17 16:02 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru 2015-07-17 14:59 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness 2015-07-17 14:56 - 2013-08-22 16:46 - 00111918 _____ C:\WINDOWS\setupact.log 2015-07-17 14:48 - 2014-10-17 15:22 - 00000000 ___DO C:\Users\Franziska\OneDrive 2015-07-17 14:48 - 2014-10-17 15:12 - 00000000 ____D C:\Users\Franziska\AppData\Local\Pokki 2015-07-17 14:47 - 2014-10-17 15:34 - 00001134 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-17 14:46 - 2014-10-17 15:14 - 00421286 _____ C:\Users\Franziska\AppData\Local\BTServer.log 2015-07-17 14:46 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-07-17 14:45 - 2014-03-18 11:44 - 00022568 _____ C:\WINDOWS\PFRO.log 2015-07-17 14:44 - 2014-08-15 02:18 - 00008704 _____ C:\WINDOWS\system32\VfService.trf 2015-07-17 14:44 - 2014-08-15 01:22 - 10539970 _____ C:\WINDOWS\SysWOW64\rootpa.e2e 2015-07-17 14:41 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI 2015-07-17 14:40 - 2014-08-15 01:35 - 00000000 ____D C:\Program Files (x86)\Lenovo 2015-07-17 14:40 - 2014-08-15 01:25 - 06317768 _____ C:\Users\Public\CAFADEBUG.log 2015-07-17 13:07 - 2014-11-15 14:48 - 00000000 ____D C:\Users\Franziska\AppData\Local\Adobe 2015-07-17 12:47 - 2015-04-10 20:50 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2015-07-17 12:46 - 2014-08-15 02:14 - 00000000 ____D C:\ProgramData\Adobe 2015-07-17 12:46 - 2014-08-15 02:14 - 00000000 ____D C:\Program Files (x86)\Adobe 2015-07-17 11:17 - 2014-11-18 14:43 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-07-17 10:46 - 2014-10-17 16:02 - 00000000 ____D C:\ProgramData\MFAData 2015-07-17 10:46 - 2014-10-17 15:25 - 00003950 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{26E0C7CA-7B0C-4D1A-8D47-19EEFF6E6754} 2015-07-17 10:45 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM 2015-07-16 21:33 - 2015-01-23 12:49 - 00000000 ____D C:\Users\Franziska\Documents\Dok. Schule 2015-07-16 21:12 - 2014-10-17 15:34 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-07-16 21:03 - 2014-10-17 15:34 - 00004110 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2015-07-16 21:03 - 2014-10-17 15:34 - 00003874 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2015-07-13 00:47 - 2014-11-13 22:52 - 00141824 ___SH C:\Users\Franziska\Downloads\Thumbs.db 2015-07-12 23:02 - 2014-11-06 22:27 - 00000000 ____D C:\Users\Franziska\AppData\Local\AVG Web TuneUp 2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\ProgramData\AVG Web TuneUp 2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\Program Files\AVG Web TuneUp 2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp 2015-07-12 16:53 - 2014-11-08 18:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-07-11 22:21 - 2014-08-15 02:31 - 00000000 ____D C:\ProgramData\LU 2015-07-11 22:19 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\NDF 2015-07-11 22:18 - 2014-08-15 01:22 - 00000000 ____D C:\Program Files (x86)\Realtek 2015-07-10 16:42 - 2014-10-17 16:15 - 00001008 _____ C:\Users\Public\Desktop\AVG 2015.lnk 2015-07-10 16:42 - 2014-10-17 16:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2015-07-08 14:35 - 2015-03-19 16:13 - 00000000 ____D C:\Users\Franziska\Documents\gescannte Objekte 2015-07-06 23:24 - 2015-05-04 18:53 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-07-06 23:24 - 2015-05-04 18:53 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-06-30 23:31 - 2014-10-18 19:32 - 00603136 ___SH C:\Users\Franziska\Desktop\Thumbs.db 2015-06-27 18:20 - 2014-10-17 15:12 - 00000000 ____D C:\Users\Franziska 2015-06-27 14:34 - 2014-10-23 17:55 - 00000000 ____D C:\WINDOWS\system32\MRT 2015-06-27 14:23 - 2014-10-23 17:55 - 140135120 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-06-23 00:02 - 2014-12-28 20:41 - 00000000 ____D C:\WINDOWS\system32\appraiser 2015-06-23 00:02 - 2014-10-23 22:24 - 00000000 ___SD C:\WINDOWS\system32\CompatTel 2015-06-22 20:48 - 2014-08-15 10:23 - 00765582 _____ C:\WINDOWS\system32\perfh007.dat 2015-06-22 20:48 - 2014-08-15 10:23 - 00159366 _____ C:\WINDOWS\system32\perfc007.dat 2015-06-22 20:48 - 2014-03-18 11:53 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2015-06-21 20:16 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache 2015-06-21 14:09 - 2015-02-04 16:50 - 00000000 ____D C:\Users\Franziska\Desktop\Neuer Ordner ==================== Files in the root of some directories ======= 2014-10-17 15:14 - 2015-07-17 14:46 - 0421286 _____ () C:\Users\Franziska\AppData\Local\BTServer.log 2014-10-20 17:20 - 2014-11-01 17:39 - 0007596 _____ () C:\Users\Franziska\AppData\Local\resmon.resmoncfg 2014-08-15 01:24 - 2014-08-15 01:24 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some files in TEMP: ==================== C:\Users\Franziska\AppData\Local\Temp\1_flashplayer.exe C:\Users\Franziska\AppData\Local\Temp\2_flashplayer.exe C:\Users\Franziska\AppData\Local\Temp\AutoRun.exe C:\Users\Franziska\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Franziska\AppData\Local\Temp\drm_dialogs.dll C:\Users\Franziska\AppData\Local\Temp\drm_dyndata_7360010.dll C:\Users\Franziska\AppData\Local\Temp\drm_dyndata_7370012.dll C:\Users\Franziska\AppData\Local\Temp\eauninstall.exe C:\Users\Franziska\AppData\Local\Temp\oct3EA.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct4F2C.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct51DB.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct53B0.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct549A.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct5B9A.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct641E.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct6475.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct72B1.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct801A.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct948E.tmp.exe C:\Users\Franziska\AppData\Local\Temp\octE19D.tmp.exe C:\Users\Franziska\AppData\Local\Temp\The Sims 2 Pets_uninst.exe C:\Users\Franziska\AppData\Local\Temp\VP6Install.exe C:\Users\Franziska\AppData\Local\Temp\VP6VFW.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-07-17 12:28 ==================== End of log ============================ Auddition.txt. [CODE]Additional FRST Logfile: Code:
ATTFilter scan result of Farbar Recovery Scan Tool (x64) Version:13-07-2015 Ran by Franziska at 2015-07-17 16:54:44 Running from C:\Users\Franziska\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2372557226-1662704196-739550879-500 - Administrator - Disabled) Franziska (S-1-5-21-2372557226-1662704196-739550879-1002 - Administrator - Enabled) => C:\Users\Franziska Gast (S-1-5-21-2372557226-1662704196-739550879-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2372557226-1662704196-739550879-1004 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 3D-Schach 2.0 (HKLM-x32\...\{CE057820-2732-11D4-A8C5-0050DA353A30}) (Version: - ) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated) AMD Catalyst Install Manager (HKLM\...\{665D4B18-EA91-BE16-3212-218C63F5DC4E}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.4.8.0 - AppEx Networks) AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6081 - AVG Technologies) AVG 2015 (Version: 15.0.4392 - AVG Technologies) Hidden AVG 2015 (Version: 15.0.6081 - AVG Technologies) Hidden AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.1.4.948 - AVG Technologies) Benutzerhandbücher (x32 Version: 3.0.0.3 - Lenovo) Hidden CEP - Color Enable Package (HKLM-x32\...\CEP - Colour Enable Packages_is1) (Version: 6.0b (beta) - Numenor, for ModTheSims2) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.28.52 - Conexant) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.) CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden Dependency Package Update (Version: 1.6.25.00 - Lenovo Inc.) Hidden Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden Dependency Package Update (Version: 1.6.36.00 - Lenovo Inc.) Hidden Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden Die Sims 2: Open For Business (HKLM-x32\...\{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}) (Version: - ) Die Sims 2: Wilde Campus-Jahre (HKLM-x32\...\{01521746-02A6-4A72-00BD-A285DF6B80C6}) (Version: - ) Die Sims™ 2 Apartment-Leben (HKLM-x32\...\{B6F5B704-06D3-4687-90F3-6195304AD755}) (Version: - Electronic Arts) Die Sims™ 2 Gute Reise (HKLM-x32\...\{F248ADFA-64E0-4b03-8A83-059078BED6A0}) (Version: - Electronic Arts) Die Sims™ 2 Haustiere (HKLM-x32\...\{4817189D-1785-4627-A33C-39FD90919300}) (Version: - ) Die Sims™ 2 Super Deluxe (HKLM-x32\...\{2D37F6AE-D201-4580-B91A-6BF9BB93ED2D}) (Version: - Electronic Arts) Die Sims™ 2 Vier Jahreszeiten (HKLM-x32\...\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}) (Version: - ) Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc) Druckerdeinstallation für EPSON BX305 Series (HKLM\...\EPSON BX305 Series) (Version: - SEIKO EPSON Corporation) Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.17 - Lenovo) Energy Manager (x32 Version: 1.5.0.17 - Lenovo) Hidden EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) FarmVille 2 (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\Pokki_34e8f5c0c9e5744bf2cdb514283762dd0524776b) (Version: 1.0.4.55785 - Pokki) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.134 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden Hightail for Lenovo (HKLM\...\{2F10E937-F6D7-4174-8AB9-B299E8FC5CEC}) (Version: 2.4.97.2857 - Hightail, Inc.) Host App Service (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\Pokki) (Version: 0.269.7.660 - Pokki) Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation) Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.36.00 - Lenovo Group Limited) Lenovo EasyCamera (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 6.0.1321.0_WHQL - Sonix) Lenovo FusionEngine (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.) Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo) Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2619 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 8.1.0.2619 - CyberLink Corp.) Hidden Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.2 - Lenovo) Lenovo PhoneCompanion (x32 Version: 1.2.0.2 - Lenovo) Hidden Lenovo Photo Master (HKLM-x32\...\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.) Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.36.1 - ELAN Microelectronic Corp.) Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.) Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden Lenovo SHAREit (HKLM-x32\...\Lenovo SHAREit_is1) (Version: 2.0.5.0 - Lenovo Group Limited) Lenovo Solution Center (HKLM\...\{2F45A217-E9C7-4984-B0AC-5BE31FF4712B}) (Version: 2.4.003.00 - Lenovo Group Limited) Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo) Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden Lenovo VeriFace Pro (HKLM\...\Lenovo VeriFace) (Version: 5.0.14.1061 - Lenovo) Lenovo Web Start (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\Pokki_04bb6df446330549a2cb8d67fbd1a745025b7bd1) (Version: 1.0.2.53457 - Pokki) LibreOffice 4.3.4.1 (HKLM-x32\...\{7D983A32-F645-48AB-8E38-4ACD234F40BC}) (Version: 4.3.4.1 - The Document Foundation) Little Alchemy (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\littlealchemy-c7de5d8adcfd810d98ec68069ab57bd9) (Version: 1.1.1 - Recloak) Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation) Metric Collection SDK 35 (x32 Version: 1.2.0001.00 - Lenovo Group Limited) Hidden Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0.3 - Mozilla) Nitro Pro 9 (HKLM\...\{4C32F7E8-A65F-4D3C-9153-9F3B57CB6872}) (Version: 9.0.5.9 - Nitro) OEM Application Profile (HKLM-x32\...\{8F92E0CF-620B-5C20-F292-59C93567B06D}) (Version: 1.00.0000 - Ihr Firmenname) OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.) REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.805.806.012214 - REALTEK Semiconductor Corp.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39058 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek) REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.20.243 - REALTEK Semiconductor Corp.) Start Menu (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\Pokki_Start_Menu) (Version: 0.269.7.660 - Pokki) User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Windows-Treiberpaket - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) ==================== Restore Points ========================= 27-06-2015 14:21:49 Windows Update 10-07-2015 21:32:10 Windows Update 11-07-2015 22:17:33 Installiert REALTEK PCIE Wireless LAN Driver 17-07-2015 12:28:57 Windows Update ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {059FF85A-96A7-4F30-A151-025BF8D10B64} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.) Task: {0C6938DC-5060-47BB-A244-9A5EB9241201} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-05-06] (Lenovo) Task: {107C5BBF-0D1D-4850-A7CE-80A15540F1AE} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-06-27] (Microsoft Corporation) Task: {12470315-4A24-4A46-978B-34FE10051EE7} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.) Task: {13842334-9265-4B05-9B11-BB24C42F8DC4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {2C817108-BF13-4F80-A785-9C358584854F} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] () Task: {307BD0C3-750A-40EF-A3F9-4288EDF529BD} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-17] (Adobe Systems Incorporated) Task: {35FDB4CA-8E11-4760-899E-1C6B82C96F61} - System32\Tasks\{808CE7D6-F887-46A4-8EAC-78FDCF14B029} => pcalua.exe -a E:\Setup.exe -d E:\ Task: {3F25A2CE-84E0-4B57-8CD6-D67BEBA2A6E4} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] () Task: {4E3DA8B7-52C1-44FF-8494-9303931DF0B1} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2014-05-06] (Lenovo) Task: {9523A3F0-9354-4859-AB26-D73344A8B4FA} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-03-06] () Task: {AE485BC0-FDB5-4ECA-9875-A86CD8B8DBAE} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-05-30] (Lenovo) Task: {B8114FCD-1409-421C-B736-0F019EE4C980} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Office2013\OFFICEICON.vbs [2013-06-03] () Task: {FA2727FE-C2D9-4520-B56D-97513B9D0DAE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2015-02-25 17:02 - 2015-07-12 23:02 - 01195920 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe 2014-04-18 22:12 - 2014-04-18 22:12 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2014-08-15 01:27 - 2014-01-22 14:04 - 00084992 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe 2014-08-15 02:13 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2014-08-15 02:18 - 2014-08-15 02:18 - 00067856 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe 2014-08-15 02:18 - 2014-08-15 02:18 - 00672016 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfDataStorageInterface.dll 2015-07-12 23:02 - 2015-07-12 23:02 - 00168336 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\loggingserver.exe 2014-08-15 01:24 - 2010-10-26 06:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe 2014-03-26 12:50 - 2014-08-15 02:23 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll 2014-12-10 20:26 - 2015-07-12 23:02 - 03174800 _____ () C:\Program Files (x86)\AVG Web TuneUp\vprot.exe 2014-04-18 22:12 - 2014-04-18 22:12 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2014-08-15 02:18 - 2014-08-15 02:18 - 00815104 _____ () C:\Program Files\Lenovo PhoneCompanion\adb.exe 2015-07-12 23:02 - 2015-07-12 23:02 - 00528272 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\log4cplusU.dll 2014-11-06 22:26 - 2015-07-12 23:02 - 40638864 _____ () C:\Program Files (x86)\AVG Web TuneUp\libcef.dll 2015-04-28 22:15 - 2015-04-28 22:15 - 00569856 _____ () C:\Users\Franziska\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll 2015-04-28 22:15 - 2015-04-28 22:15 - 01400846 _____ () C:\Users\Franziska\AppData\Local\Pokki\Engine\avcodec-54.dll 2015-04-28 22:15 - 2015-04-28 22:15 - 00151054 _____ () C:\Users\Franziska\AppData\Local\Pokki\Engine\avutil-51.dll 2015-04-28 22:15 - 2015-04-28 22:15 - 00222734 _____ () C:\Users\Franziska\AppData\Local\Pokki\Engine\avformat-54.dll 2015-07-16 21:12 - 2015-07-13 23:55 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libglesv2.dll 2015-07-16 21:12 - 2015-07-13 23:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Windows:nlsPreferences AlternateDataStreams: C:\Users\Franziska\OneDrive:ms-properties ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDWFP => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VisualDiscovery => ""="service" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\Run32: => "snp2uvc" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{AFBD7067-D2F6-4D3C-85B3-88A008C18967}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe FirewallRules: [{663A46B4-3414-4F48-A319-A422F7F43977}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe FirewallRules: [{AC2767B5-A536-457E-B67B-50A79A754C46}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{77D8B7D4-27EC-4437-A263-031784DFAC63}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{55376DCC-D006-4A28-AA16-B85FAC106F3E}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE FirewallRules: [{084835F4-19BE-43D6-BEB8-78503B45965C}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe FirewallRules: [{1F9F0BC2-0CF8-4AA0-974C-7BA40E438A95}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe FirewallRules: [{EE98E101-3C74-4620-AE02-3ADF1B6FA0CD}] => (Allow) LPort=55100 FirewallRules: [{0798E54B-7073-4647-8B2A-685DE6EC27D3}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe FirewallRules: [{0A8AAECB-B085-4693-8040-C11384793642}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{AB42E82B-FAD0-4683-B81E-CBA57E9CE423}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{DA68199A-F30C-4B34-B07D-55BC97A1320D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{BEE4CC4D-667E-4F8F-A4B9-C3191BCA1FC5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{7FADA343-E843-4133-A0D4-4BC7788FC0A5}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{518A6693-CCCD-4A4B-B9D9-01F793BF96AE}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{1C8585A3-15F7-4FF0-A443-C7D6A06A964A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe FirewallRules: [{D1DD6BFC-A9A7-4E39-BCE5-7A467EDBD48B}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe FirewallRules: [{D53DDE3E-9291-4381-BFBE-4405895AD9D4}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe FirewallRules: [{A02C96FC-1AC8-4B35-AB3B-3530569EF51D}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe FirewallRules: [{28841159-30B7-405D-9466-DA3C044D5BE5}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe FirewallRules: [{43A83805-ED93-4F21-B195-E5CB8AE4B9DD}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe FirewallRules: [{6929263B-9A5C-42DA-835C-976C8D9937FE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= Name: Dell 3333dn Description: Dell 3333dn Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: Dell Service: usbscan Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/17/2015 02:43:57 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Bei der Aktivierung der App „Microsoft.WindowsAlarms_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/17/2015 02:41:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/17/2015 01:00:21 AM) (Source: MsiInstaller) (EventID: 1024) (User: LENOVO-PC) Description: Produkt: Adobe Reader XI (11.0.11) - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011012}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (07/17/2015 12:12:46 AM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT-AUTORITÄT) Description: There was an error with the Windows Location Provider database Error: (07/13/2015 03:54:09 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm LiveComm.exe, Version 17.5.9600.20911 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1160 Startzeit: 01d0bd72a923b637 Endzeit: 4294967295 Anwendungspfad: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe Berichts-ID: 9f362b2b-2966-11e5-838a-28d244c25993 Vollständiger Name des fehlerhaften Pakets: microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ppleae38af2e007f4358a809ac99a64a67c1 Error: (07/13/2015 12:18:00 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: WUDFHost.exe, Version: 6.3.9600.17415, Zeitstempel: 0x5450412e Name des fehlerhaften Moduls: amdocl64.dll, Version: 10.0.1359.5, Zeitstempel: 0x5351e341 Ausnahmecode: 0xc0000409 Fehleroffset: 0x0000000000cddf47 ID des fehlerhaften Prozesses: 0xd58 Startzeit der fehlerhaften Anwendung: 0xWUDFHost.exe0 Pfad der fehlerhaften Anwendung: WUDFHost.exe1 Pfad des fehlerhaften Moduls: WUDFHost.exe2 Berichtskennung: WUDFHost.exe3 Vollständiger Name des fehlerhaften Pakets: WUDFHost.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: WUDFHost.exe5 Error: (07/11/2015 10:11:14 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 System errors: ============= Error: (07/17/2015 02:44:04 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC) Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39} Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (07/17/2015 02:44:00 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (07/17/2015 02:43:56 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC) Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca Microsoft Office: ========================= Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141 Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141 Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141 Error: (07/17/2015 02:43:57 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Microsoft.WindowsAlarms_8wekyb3d8bbwe!App-2144927141 Error: (07/17/2015 02:41:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141 Error: (07/17/2015 01:00:21 AM) (Source: MsiInstaller) (EventID: 1024) (User: LENOVO-PC) Description: Adobe Reader XI (11.0.11) - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011012}1625(NULL)(NULL)(NULL) Error: (07/17/2015 12:12:46 AM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT-AUTORITÄT) Description: -2147024883 Error: (07/13/2015 03:54:09 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: LiveComm.exe17.5.9600.20911116001d0bd72a923b6374294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe9f362b2b-2966-11e5-838a-28d244c25993microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1 Error: (07/13/2015 12:18:00 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: WUDFHost.exe6.3.9600.174155450412eamdocl64.dll10.0.1359.55351e341c00004090000000000cddf47d5801d0bcef6e576b7fC:\Windows\System32\WUDFHost.exeC:\Windows\System32\amdocl64.dllda91dd9b-28e3-11e5-8389-28d244c25993 Error: (07/11/2015 10:11:14 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 ==================== Memory info =========================== Processor: AMD A6-6310 APU with AMD Radeon R4 Graphics Percentage of memory in use: 33% Total physical RAM: 7128.26 MB Available physical RAM: 4752.48 MB Total Virtual: 8280.26 MB Available Virtual: 5363.95 MB ==================== Drives ================================ Drive c: (Windows8_OS) (Fixed) (Total:890.1 GB) (Free:831.13 GB) NTFS ==>[system with boot components (obtained from reading drive)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:23.14 GB) NTFS Drive f: () (Removable) (Total:3.68 GB) (Free:0.14 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: E07FA830) Partition: GPT Partition Type. ======================================================== Disk: 1 (Size: 3.7 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End of log ============================ Der TDSSKiller hat jedoch nichts gefunden. Nach dem Scan heißt es 'No threats found' aber ich habe alle Schritte befolgt |
17.07.2015, 19:44 | #4 |
/// TB-Ausbilder | BKA-Trojaner aber keine Sperrungen Servus, und was ist mit den Logdateien von MBAM? Ich hatte dich doch gebeten, alle Logdateien mit Funden zu posten... In welchem Forum hast du denn um Hilfe gebeten? Bitte dazu einen Link posten. Geändert von M-K-D-B (17.07.2015 um 19:50 Uhr) |
17.07.2015, 20:10 | #5 |
| BKA-Trojaner aber keine Sperrungen Achso, stimmt! Ich war kurz verwirrt was mit MBMA gemeint ist. Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Error, 17.07.2015 11:10, SYSTEM, LENOVO-PC, Update, Bad md5 or size: akadomains, 11, Error, 17.07.2015 11:10, SYSTEM, LENOVO-PC, Update, Bad md5 or size: akaips, 11, Update, 17.07.2015 11:10, SYSTEM, LENOVO-PC, Manual, Remediation Database, 2015.5.13.1, 2015.7.15.2, Update, 17.07.2015 11:10, SYSTEM, LENOVO-PC, Manual, Domain Database, 0.0.0.0, 2015.6.12.1, Update, 17.07.2015 11:10, SYSTEM, LENOVO-PC, Manual, IP Database, 0.0.0.0, 2015.6.12.1, Update, 17.07.2015 11:10, SYSTEM, LENOVO-PC, Manual, Rootkit Database, 2015.6.2.1, 2015.7.16.1, Error, 17.07.2015 11:12, SYSTEM, LENOVO-PC, Manual, 0, Error, 17.07.2015 11:12, SYSTEM, LENOVO-PC, Manual, 0, Update, 17.07.2015 11:12, SYSTEM, LENOVO-PC, Manual, AKA IP Database, 0.0.0.0, 2015.7.15.1, Update, 17.07.2015 11:12, SYSTEM, LENOVO-PC, Manual, Malware Database, Failed, Unable to access update server, 2015.6.3.3, 2015.7.17.2, Update, 17.07.2015 11:12, SYSTEM, LENOVO-PC, Manual, AKA Domain Database, Failed, Unable to access update server, 0.0.0.0, 2015.7.16.1, Error, 17.07.2015 12:09, SYSTEM, LENOVO-PC, Update, Bad md5 or size: akadomains, 11, Error, 17.07.2015 12:09, SYSTEM, LENOVO-PC, Update, akaips: inflate, 4294967291, Update, 17.07.2015 12:09, SYSTEM, LENOVO-PC, Manual, AKA IP Database, 2015.7.15.1, 2015.7.15.1, Error, 17.07.2015 12:11, SYSTEM, LENOVO-PC, Manual, 0, Update, 17.07.2015 12:11, SYSTEM, LENOVO-PC, Manual, AKA Domain Database, Failed, Unable to access update server, 0.0.0.0, 2015.7.16.1, Update, 17.07.2015 12:23, SYSTEM, LENOVO-PC, Manual, Malware Database, 2015.6.3.3, 2015.7.17.2, Error, 17.07.2015 13:53, SYSTEM, LENOVO-PC, Update, Bad md5 or size: akadomains, 11, Update, 17.07.2015 13:54, SYSTEM, LENOVO-PC, Manual, Malware Database, 2015.7.17.2, 2015.7.17.3, Update, 17.07.2015 13:55, SYSTEM, LENOVO-PC, Manual, AKA Domain Database, 0.0.0.0, 2015.7.16.1, Scan, 17.07.2015 14:40, SYSTEM, LENOVO-PC, Manual, Start: 17.07.2015 13:55, Dauer: 43 Min. 3 Sek., Bedrohungssuchlauf, Abgeschlossen, 0 Malware-Erkennung, 82 Nicht-Malware-Erkennungen, Error, 17.07.2015 14:43, SYSTEM, LENOVO-PC, Protection, IsLicensed, 13, Protection, 17.07.2015 14:43, SYSTEM, LENOVO-PC, Protection, Malware Protection, Stopping, Protection, 17.07.2015 14:43, SYSTEM, LENOVO-PC, Protection, Malware Protection, Stopped, Error, 17.07.2015 14:46, SYSTEM, LENOVO-PC, Protection, IsLicensed, 13, Protection, 17.07.2015 14:46, SYSTEM, LENOVO-PC, Protection, Malware Protection, Stopping, Protection, 17.07.2015 14:46, SYSTEM, LENOVO-PC, Protection, Malware Protection, Stopped, Error, 17.07.2015 20:50, SYSTEM, LENOVO-PC, Protection, IsLicensed, 13, Protection, 17.07.2015 20:50, SYSTEM, LENOVO-PC, Protection, Malware Protection, Stopping, Protection, 17.07.2015 20:50, SYSTEM, LENOVO-PC, Protection, Malware Protection, Stopped, (end) Ich hatte mich vorher bei CHIP.de erkundigt: hxxp://forum.chip.de/viren-trojaner-wuermer/bka-virus-trojaner-keine-veraenderung-1838152.html |
18.07.2015, 10:24 | #6 | ||
/// TB-Ausbilder | BKA-Trojaner aber keine SperrungenZitat:
Zitat:
Gibt es aktuell irgendwelche Einschränkungen/Probleme mit dem Rechner? |
18.07.2015, 11:58 | #7 |
| BKA-Trojaner aber keine Sperrungen Achso Okay Das erste Suchlaufprotokoll: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 17.07.2015 Suchlaufzeit: 11:12 Protokolldatei: Suchlaufverlaufsprotokoll 1.txt Administrator: Ja Version: 2.1.8.1057 Malware-Datenbank: v2015.06.03.03 Rootkit-Datenbank: v2015.07.16.01 Lizenz: Kostenlose Version Malware-Schutz: Deaktiviert Schutz vor bösartigen Websites: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 358347 Abgelaufene Zeit: 46 Min., 34 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 57 PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\Superfish Inc. VisualDiscovery, , [ce811d999eecbe786be8b9304eb518e8], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\LENOVO\VisualDiscovery, , [df705c5a1872d1650551ffea28db718f], PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}, , [53fce4d29eec58dee7ef7076d82b6f91], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{617E26CE-E6E1-4C75-A68A-A001F2B98491}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8128586C-DF69-4266-873F-CF4C6F705A7C}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{617E26CE-E6E1-4C75-A68A-A001F2B98491}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8128586C-DF69-4266-873F-CF4C6F705A7C}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{617E26CE-E6E1-4C75-A68A-A001F2B98491}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8128586C-DF69-4266-873F-CF4C6F705A7C}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}, , [93bc9e18e4a6cb6b29546080fe05cd33], Registrierungswerte: 4 PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|FaviconURL, hxxp://homepage-web.com/favicon.ico, , [53fce4d29eec58dee7ef7076d82b6f91] PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|FaviconURLFallback, hxxp://homepage-web.com/favicon.ico, , [f55acfe7305a171f22b4885e976c9c64] PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|TopResultURL, hxxp://search.homepage-web.com/?src=omnibox&partner=lenovo&q={searchTerms}, , [113ef9bd4b3f59dd6a6c3bab689b52ae] PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|URL, hxxp://search.homepage-web.com/?src=omnibox&partner=lenovo&q={searchTerms}, , [5ef1d9dd1575e74f983e4c9a34cf6997] Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 1 PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery, , [93bc9e18e4a6cb6b29546080fe05cd33], Dateien: 20 PUP.Optional.APNToolBar.A, C:\Windows\Temp\7zS871A.tmp\Offercast343_AVG_.exe, , [2f2001b59af0b08602bc174cd0327e82], PUP.Optional.Winsock.HijackBoot, C:\Windows\System32\VisualDiscoveryOff.ini, , [e76863537d0dd06629284f9ab54ecd33], PUP.Optional.Winsock.HijackBoot, C:\Windows\SysWOW64\VisualDiscoveryOff.ini, , [aba45f570c7ed75f48096f7add26ea16], PUP.Optional.VisualDiscovery.A, C:\Windows\SysWOW64\VisualDiscovery.ini, , [70df773fb2d892a474dec920dc279070], PUP.Optional.VisualDiscovery.A, C:\Windows\Temp\VisualDiscoveryr.log, , [c689a31305856ec80153aa3fb15205fb], PUP.Optional.VisualDiscovery.A, C:\Windows\Temp\VisualDiscovery.log, , [410ed0e6becc6bcbda7ba64330d39967], PUP.Optional.WebSearch.A, C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\searchplugins\Web Search.xml, , [68e7674f6e1c072fedd20d1d16eec040], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\freebl3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\libnspr4.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\libplc4.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\libplds4.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nss3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nssckbi.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nssdbm3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nssutil3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\smime3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\softokn3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\sqlite3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\ssl3.dll, , [93bc9e18e4a6cb6b29546080fe05cd33], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\VisualDiscovery.tlb, , [93bc9e18e4a6cb6b29546080fe05cd33], Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) Das zweite: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 17.07.2015 Suchlaufzeit: 13:55 Protokolldatei: Suchlaufverlaufsprotokoll 2.txt Administrator: Ja Version: 2.1.8.1057 Malware-Datenbank: v2015.07.17.03 Rootkit-Datenbank: v2015.07.16.01 Lizenz: Kostenlose Version Malware-Schutz: Deaktiviert Schutz vor bösartigen Websites: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 353491 Abgelaufene Zeit: 43 Min., 3 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 57 PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\Superfish Inc. VisualDiscovery, In Quarantäne, [ac2b36ac55357cbaadcd9773c241b947], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\LENOVO\VisualDiscovery, In Quarantäne, [4c8b25bd0a803105750863a74eb57789], PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}, In Quarantäne, [c90e12d05f2bdd590ff7c246758e936d], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{617E26CE-E6E1-4C75-A68A-A001F2B98491}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8128586C-DF69-4266-873F-CF4C6F705A7C}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{617E26CE-E6E1-4C75-A68A-A001F2B98491}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8128586C-DF69-4266-873F-CF4C6F705A7C}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{617E26CE-E6E1-4C75-A68A-A001F2B98491}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8128586C-DF69-4266-873F-CF4C6F705A7C}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], Registrierungswerte: 4 PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|FaviconURL, hxxp://homepage-web.com/favicon.ico, In Quarantäne, [c90e12d05f2bdd590ff7c246758e936d] PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|FaviconURLFallback, hxxp://homepage-web.com/favicon.ico, In Quarantäne, [dbfc885a0b7fee48679f2fd923e025db] PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|TopResultURL, hxxp://search.homepage-web.com/?src=omnibox&partner=lenovo&q={searchTerms}, In Quarantäne, [8750c220c9c170c652b45eaad62ddd23] PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{92275743-CF26-11E4-8319-28D244C25993}|URL, hxxp://search.homepage-web.com/?src=omnibox&partner=lenovo&q={searchTerms}, In Quarantäne, [815639a97911d561b4522eda719225db] Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 1 PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], Dateien: 20 PUP.Optional.APNToolBar.A, C:\Windows\Temp\7zS871A.tmp\Offercast343_AVG_.exe, In Quarantäne, [2bace8fa800af046c98cfaad6998817f], PUP.Optional.Winsock.HijackBoot, C:\Windows\System32\VisualDiscoveryOff.ini, In Quarantäne, [8b4ce2008703c3738eeac1491de61de3], PUP.Optional.Winsock.HijackBoot, C:\Windows\SysWOW64\VisualDiscoveryOff.ini, In Quarantäne, [1eb98062f89245f1f5837991d13221df], PUP.Optional.VisualDiscovery.A, C:\Windows\SysWOW64\VisualDiscovery.ini, In Quarantäne, [f9deaf330684cc6a54250efc0300e917], PUP.Optional.VisualDiscovery.A, C:\Windows\Temp\VisualDiscoveryr.log, In Quarantäne, [b6218d554b3f62d4ee8d1af03bc88977], PUP.Optional.VisualDiscovery.A, C:\Windows\Temp\VisualDiscovery.log, In Quarantäne, [934469793a502e0805772fdb778c3cc4], PUP.Optional.WebSearch.A, C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\searchplugins\Web Search.xml, In Quarantäne, [ae29dd05c4c65dd9e10ee85d748ff60a], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\freebl3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\libnspr4.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\libplc4.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\libplds4.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nss3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nssckbi.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nssdbm3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\nssutil3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\smime3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\softokn3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\sqlite3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\ssl3.dll, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], PUP.Optional.VisualDiscovery.A, C:\Program Files (x86)\Lenovo\VisualDiscovery\VisualDiscovery.tlb, In Quarantäne, [ddfa11d10d7d2e082332c43a54ae8e72], Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) Nein, mein Laptop funktioniert einwandfrei, genauso wie immer. |
18.07.2015, 12:01 | #8 |
/// TB-Ausbilder | BKA-Trojaner aber keine Sperrungen Servus, da MBAM etwas Adware gefunden hat, schauen wir diesbezüglich nochmal nach, sollte relativ zügig gehen: Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 4
Bitte poste mit deiner nächsten Antwort
|
18.07.2015, 13:55 | #9 |
| BKA-Trojaner aber keine Sperrungen Hat doch ein wenig länger gedauert als ich dachte Logdatei von AdwCleaner: Code:
ATTFilter # AdwCleaner v4.208 - Bericht erstellt 18/07/2015 um 13:24:11 # Aktualisiert 09/07/2015 von Xplode # Datenbank : 2015-07-15.1 [Server] # Betriebssystem : Windows 8.1 (x64) # Benutzername : Franziska - LENOVO-PC # Gestarted von : C:\Users\Franziska\Desktop\AdwCleaner_4.208.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : vToolbarUpdater18.7.0 ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\AVG Secure Search Ordner Gelöscht : C:\ProgramData\AVG Security Toolbar Ordner Gelöscht : C:\ProgramData\pokki Ordner Gelöscht : C:\ProgramData\Avg_Update_0215tb Ordner Gelöscht : C:\ProgramData\Avg_Update_1214tb Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search Ordner Gelöscht : C:\Users\Franziska\AppData\Local\pokki Ordner Gelöscht : C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\Extensions\Avg@toolbar Ordner Gelöscht : C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn Datei Gelöscht : C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage Datei Gelöscht : C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage-journal Datei Gelöscht : C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\searchplugins\avg-secure-search.xml Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Classes\pokki Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Pokki] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\S Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt] Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Schlüssel Gelöscht : HKCU\Software\Classes\AllFileSystemObjects\shell\pokki Schlüssel Gelöscht : HKCU\Software\Classes\Directory\shell\pokki Schlüssel Gelöscht : HKCU\Software\Classes\Drive\shell\pokki Schlüssel Gelöscht : HKCU\Software\Classes\lnkfile\shell\pokki Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_04bb6df446330549a2cb8d67fbd1a745025b7bd1 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_34e8f5c0c9e5744bf2cdb514283762dd0524776b Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_Start_Menu Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Pokki Schlüssel Gelöscht : HKCU\Software\Avg Secure Update Schlüssel Gelöscht : HKLM\SOFTWARE\VisualDiscovery Schlüssel Gelöscht : HKU\.DEFAULT\Software\Avg Secure Update Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\AVG Secure Search ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17840 -\\ Mozilla Firefox v39.0 (x86 de) [s8645vto.default-1423061599285\prefs.js] - Zeile Gelöscht : user_pref("browser.search.hiddenOneOffs", "Yahoo,AVG Secure Search,Bing"); [s8645vto.default-1423061599285\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "AVG Secure Search"); -\\ Google Chrome v43.0.2357.134 [C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.homepage-web.com/?src=omnibox&partner=lenovo&q={searchTerms} [C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Gelöscht [Homepage] : management","nativeMessaging","searchProvider","startupPages","storage","tabs","unlimitedStorage","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"blacklist_state":0,"commands":{"_execute_page_action":{"suggested_key":"Alt+Shift+P","was_assigned":true}},"content_settings":[],"creation_flags":9,"disable_reasons":1,"events":[],"extension_can_script_all_urls":true,"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["browsingData","cookies","downloads","downloadsInternal","history","homepage","management","nativeMessaging","searchProvider","startupPages","tabs","unlimitedStorage","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13080309618149074","lastpingday":"13081590000423643","location":1,"manifest":{"background":{"page":"background.html","persistent":true},"chrome_settings_overrides":{"homepage":"hxxps://mysearch.avg.com/?rvt=1","search_provider":{"encoding":"UTF-8","favicon_url":"hxxps://mysearch.avg.com/favicon.ico","is_default":true,"keyword":"hxxps://mysearch.avg.com","name":"AVG Secure Search ************************* AdwCleaner[R0].txt - [8155 Bytes] - [18/07/2015 13:17:40] AdwCleaner[S0].txt - [7815 Bytes] - [18/07/2015 13:24:11] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7874 Bytes] ########## Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 18.07.2015 Suchlaufzeit: 13:34 Protokolldatei: mbam.txt Administrator: Ja Version: 2.1.8.1057 Malware-Datenbank: v2015.07.18.02 Rootkit-Datenbank: v2015.07.17.01 Lizenz: Kostenlose Version Malware-Schutz: Deaktiviert Schutz vor bösartigen Websites: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Franziska Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 349011 Abgelaufene Zeit: 36 Min., 59 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 0 (keine bösartigen Elemente erkannt) Registrierungswerte: 0 (keine bösartigen Elemente erkannt) Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 0 (keine bösartigen Elemente erkannt) Dateien: 0 (keine bösartigen Elemente erkannt) Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 7.5.1 (07.16.2015:1) OS: Windows 8.1 x64 Ran by Franziska on 18.07.2015 at 14:18:03,77 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Tasks ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main\\Start Page ~~~ Registry Keys ~~~ Files Successfully deleted: [File] C:\Users\Franziska\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\pc app store.lnk ~~~ Folders Failed to delete: [Folder] C:\Users\Franziska\Appdata\Local\pokki ~~~ Chrome [C:\Users\Franziska\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset [C:\Users\Franziska\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted: [C:\Users\Franziska\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset [C:\Users\Franziska\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted: [] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 18.07.2015 at 14:32:42,99 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Jetzt habe ich allerdings ein Problem. Als ich FRST64 starten wollte, hatte er zuerst nach Updates gesucht und ich konnte den Scan nicht starten. Das Programm hat sich aufgehangen und ich musste es schließen. Habe es dann noch einmal geöffnet und zu Ende nach Updates suchen lassen. Als es fertig war, konnte ich auf 'OK' drücken und wollte den Scan nun endlich starten, doch das Programm hat sich nur wieder aufgehangen und jetzt kann ich es gar nicht mehr öffnen. Wenn ich es versuche, zeigt mir Windows nur ein Fenster wo drin steht: 'Die App kann auf dem PC nicht ausgeführt werden. Wenden Sie sich an den Softwarehersteller, um eine geeignete Version für ihren PC zu finden.' Neu herunterladen habe ich auch versucht aber es kommt immer die gleiche Meldung. Ein weiteres Problem ist das ich in der Taskleiste nicht mehr auf das Startmenü und den PC App Store zugreifen kann. an der Stelle der Icons ist nur noch ein weißes Blatt mit Eselsohr. Ein Neustart konnte es auch nicht beheben. Habe ich etwas falsch gemacht? |
18.07.2015, 14:43 | #10 |
/// TB-Ausbilder | BKA-Trojaner aber keine Sperrungen Servus, FRST löschen, nochmal herunterladen und einen Suchlauf durchführen. |
18.07.2015, 16:22 | #11 |
| BKA-Trojaner aber keine Sperrungen Okay hat geklappt FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-07-2015 01 Ran by Franziska (administrator) on LENOVO-PC on 18-07-2015 17:12:44 Running from C:\Users\Franziska\Desktop Loaded Profiles: Franziska (Available Profiles: Franziska) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe (Lenovo) C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] () HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-04] (Conexant Systems, Inc.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891592 2014-02-11] (ELAN Microelectronics Corp.) HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [216064 2014-01-06] (Realtek Semiconductor Corporation) HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-08-15] (Lenovo) HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-08-15] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2014-08-15] (Lenovo(beijing) Limited) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-04-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [snp2uvc] => C:\WINDOWS\vsnp2uvc.exe HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3730344 2015-06-30] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation) ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://lenovo13.msn.com/?pc=LCJB hxxp://www.lenovo.com HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2372557226-1662704196-739550879-1002 -> {97CB315F-D830-4B49-92BC-986D9C008592} URL = BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-17] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-17] (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{126079A8-E17A-4F05-894B-2B5B8A051737}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{E6F50CE2-672B-468B-BF96-C59F56340331}: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285 FF Homepage: google.de FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-17] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-17] () FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-17] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-17] (Oracle Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2013-12-12] (Nitro PDF) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.) FF Extension: Adblock Plus - C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-18] Chrome: ======= CHR Profile: C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-17] CHR Extension: (Google Docs) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-17] CHR Extension: (Google Drive) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-17] CHR Extension: (YouTube) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-17] CHR Extension: (Google Search) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-17] CHR Extension: (Google Sheets) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-17] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-19] CHR Extension: (Cath Kidston) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndlpkmaeinmnbiadacenijnhlolneopm [2014-10-19] CHR Extension: (Google Wallet) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-17] CHR Extension: (Gmail) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-18] (Advanced Micro Devices, Inc.) [File not signed] R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3518376 2015-06-30] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [314304 2015-06-30] (AVG Technologies CZ, s.r.o.) S2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [84992 2014-01-22] () [File not signed] S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation) S2 ETDService; C:\Program Files\Elantech\ETDService.exe [99632 2013-10-09] (ELAN Microelectronics Corp.) S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo) S2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584632 2015-03-06] (LENOVO INCORPORATED.) S2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-08-15] (Lenovo(beijing) Limited) S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1663880 2014-05-06] () S2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) S2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-12] (Nitro PDF Software) S2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-08-15] (Lenovo) S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2014-08-15] (Lenovo) S2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] () S2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51712 2014-02-24] (Advanced Micro Devices, Inc.) S2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-08-15] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation) S2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1195920 2015-07-12] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [85704 2014-02-24] (Advanced Micro Devices, Inc. ) R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-12] (Advanced Micro Devices, Inc.) R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [230088 2014-02-24] (Advanced Micro Devices, Inc. ) R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [224992 2013-11-01] (AppEx Networks Corporation) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices) S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [293296 2015-06-26] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [253408 2015-05-12] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [259040 2015-06-16] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [226784 2015-06-10] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [295400 2015-06-15] (AVG Technologies CZ, s.r.o.) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation) S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [107736 2015-07-17] (Malwarebytes Corporation) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation) S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation) R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-04-15] (Realtek Semiconductor Corporation) R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3593432 2014-10-07] (Realtek Semiconductor Corporation ) R3 SNP2UVC; C:\Windows\system32\DRIVERS\snp2uvc.sys [2853400 2014-01-23] (Sonix Co. Ltd.) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-18 17:12 - 2015-07-18 17:13 - 00016798 _____ C:\Users\Franziska\Desktop\FRST.txt 2015-07-18 17:11 - 2015-07-18 17:12 - 02134528 _____ (Farbar) C:\Users\Franziska\Desktop\FRST64.exe 2015-07-18 14:37 - 2015-07-18 14:37 - 00000000 ____D C:\Users\Franziska\Desktop\FRST-OlderVersion 2015-07-18 14:32 - 2015-07-18 14:32 - 00002013 _____ C:\Users\Franziska\Desktop\JRT.txt 2015-07-18 14:16 - 2015-07-18 14:16 - 00001201 _____ C:\Users\Franziska\Desktop\mbam.txt..txt 2015-07-18 13:56 - 2015-07-18 14:01 - 01798288 _____ (Malwarebytes Corporation) C:\Users\Franziska\Desktop\JRT.exe 2015-07-18 13:33 - 2015-07-18 13:33 - 00007986 _____ C:\Users\Franziska\Desktop\AdwCleaner[S0].txt 2015-07-18 13:17 - 2015-07-18 13:25 - 00000000 ____D C:\AdwCleaner 2015-07-18 13:06 - 2015-07-18 13:08 - 02248704 _____ C:\Users\Franziska\Desktop\AdwCleaner_4.208.exe 2015-07-18 12:51 - 2015-07-18 12:51 - 00014615 _____ C:\Users\Franziska\Desktop\Suchlaufverlaufsprotokoll 2.txt 2015-07-18 12:50 - 2015-07-18 12:50 - 00013550 _____ C:\Users\Franziska\Desktop\Suchlaufverlaufsprotokoll 1.txt 2015-07-17 17:00 - 2015-07-17 17:03 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Franziska\Desktop\tdsskiller.exe 2015-07-17 16:52 - 2015-07-18 17:12 - 00000000 ____D C:\FRST 2015-07-17 16:18 - 2015-05-07 17:21 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll 2015-07-17 16:18 - 2015-05-07 17:05 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll 2015-07-17 16:18 - 2015-05-03 02:39 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2015-07-17 16:18 - 2015-04-30 01:22 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll 2015-07-17 16:13 - 2015-05-07 19:50 - 22292672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2015-07-17 16:13 - 2015-05-07 19:00 - 03109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2015-07-17 16:13 - 2015-05-07 18:53 - 19734960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2015-07-17 16:13 - 2015-05-07 18:12 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2015-07-17 16:07 - 2015-06-30 00:43 - 00026288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2015-07-17 16:07 - 2015-06-29 17:07 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2015-07-17 16:07 - 2015-06-29 17:07 - 01084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2015-07-17 16:07 - 2015-06-29 17:07 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2015-07-17 16:07 - 2015-06-29 17:07 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2015-07-17 16:07 - 2015-06-29 17:07 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2015-07-17 16:07 - 2015-06-27 01:21 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2015-07-17 16:07 - 2015-06-27 01:21 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2015-07-17 16:07 - 2015-05-11 20:17 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2015-07-17 16:07 - 2015-04-25 04:25 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023.sys 2015-07-17 16:07 - 2014-11-04 21:25 - 00059712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys 2015-07-17 16:07 - 2014-11-04 21:25 - 00051008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys 2015-07-17 16:07 - 2014-11-04 08:55 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys 2015-07-17 16:07 - 2014-11-04 08:54 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys 2015-07-17 16:07 - 2014-11-04 08:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys 2015-07-17 16:07 - 2014-11-04 08:54 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys 2015-07-17 16:06 - 2015-05-03 17:09 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2015-07-17 16:06 - 2015-05-03 16:58 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2015-07-17 16:06 - 2015-05-03 16:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2015-07-17 16:06 - 2015-05-03 16:49 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2015-07-17 16:03 - 2015-05-11 18:34 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll 2015-07-17 16:03 - 2015-04-28 15:13 - 00513480 _____ C:\WINDOWS\SysWOW64\locale.nls 2015-07-17 16:03 - 2015-04-28 15:13 - 00513480 _____ C:\WINDOWS\system32\locale.nls 2015-07-17 16:03 - 2015-04-23 17:47 - 03084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2015-07-17 16:03 - 2015-04-23 17:16 - 02471424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2015-07-17 16:02 - 2015-05-12 15:19 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll 2015-07-17 16:01 - 2015-05-02 01:33 - 00410739 _____ C:\WINDOWS\system32\ApnDatabase.xml 2015-07-17 16:00 - 2015-05-03 17:07 - 07784448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2015-07-17 16:00 - 2015-05-03 16:57 - 05264384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2015-07-17 14:23 - 2015-07-17 14:43 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2015-07-17 14:17 - 2015-07-17 14:48 - 00000000 ____D C:\Users\Franziska\Desktop\mbar 2015-07-17 13:54 - 2015-07-17 14:11 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Franziska\Downloads\mbar-1.09.1.1004.exe 2015-07-17 12:46 - 2015-07-17 12:46 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-07-17 12:46 - 2015-07-17 12:46 - 00002078 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2015-07-17 11:08 - 2015-07-18 14:15 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-07-17 11:03 - 2015-07-17 14:17 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2015-07-17 11:03 - 2015-07-17 11:03 - 00001125 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-07-17 11:03 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2015-07-17 11:03 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2015-07-17 10:46 - 2015-07-17 10:57 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Franziska\Downloads\mbam-setup-2.1.8.1057.exe 2015-07-17 00:54 - 2015-07-17 00:54 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2015-07-17 00:54 - 2015-07-17 00:54 - 00000000 ____D C:\ProgramData\Sun 2015-07-17 00:54 - 2015-07-17 00:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-07-17 00:53 - 2015-07-17 00:53 - 00000000 ____D C:\ProgramData\Oracle 2015-07-17 00:53 - 2015-07-17 00:53 - 00000000 ____D C:\Program Files (x86)\Java 2015-07-17 00:15 - 2015-07-17 00:15 - 00563296 _____ (Oracle Corporation) C:\Users\Franziska\Downloads\chromeinstall-8u51.exe 2015-07-16 21:58 - 2015-07-02 23:21 - 19877376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-07-16 21:58 - 2015-07-02 22:49 - 25193984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-07-16 21:57 - 2015-07-02 22:50 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-07-16 21:57 - 2015-07-02 22:23 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-07-16 21:57 - 2015-07-02 22:19 - 12855296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-07-16 21:57 - 2015-07-02 21:55 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-07-16 21:57 - 2015-07-02 21:20 - 14453248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-07-16 21:57 - 2015-07-02 20:59 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-07-16 21:42 - 2015-07-02 00:08 - 05923840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2015-07-16 21:41 - 2015-07-01 23:14 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2015-07-16 21:41 - 2015-06-16 00:39 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2015-07-16 21:41 - 2015-06-16 00:38 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll 2015-07-16 21:41 - 2015-06-16 00:26 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll 2015-07-16 21:41 - 2015-06-16 00:24 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2015-07-16 21:41 - 2015-06-16 00:02 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx 2015-07-16 21:41 - 2015-06-15 23:58 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll 2015-07-16 21:41 - 2015-06-15 23:57 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2015-07-16 21:41 - 2015-06-15 23:56 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2015-07-16 21:41 - 2015-06-15 23:55 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2015-07-16 21:41 - 2015-06-15 23:49 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2015-07-16 21:41 - 2015-06-15 23:41 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2015-07-16 21:41 - 2015-06-15 23:38 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2015-07-16 21:41 - 2015-06-15 23:36 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2015-07-16 21:41 - 2015-06-15 23:17 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2015-07-16 21:41 - 2015-06-15 23:16 - 02427392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2015-07-16 21:41 - 2015-06-15 23:15 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2015-07-16 21:41 - 2015-06-15 23:13 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 2015-07-16 21:41 - 2015-06-15 23:04 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll 2015-07-16 21:41 - 2015-06-15 23:03 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2015-07-16 21:41 - 2015-06-15 22:52 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2015-07-16 21:41 - 2015-06-15 22:47 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx 2015-07-16 21:41 - 2015-06-15 22:44 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll 2015-07-16 21:41 - 2015-06-15 22:43 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2015-07-16 21:41 - 2015-06-15 22:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2015-07-16 21:41 - 2015-06-15 22:41 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2015-07-16 21:41 - 2015-06-15 22:37 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2015-07-16 21:41 - 2015-06-15 22:32 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2015-07-16 21:41 - 2015-06-15 22:31 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2015-07-16 21:41 - 2015-06-15 22:30 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2015-07-16 21:41 - 2015-06-15 22:30 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2015-07-16 21:41 - 2015-06-15 22:17 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2015-07-16 21:41 - 2015-06-15 22:07 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2015-07-16 21:41 - 2015-06-15 22:02 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2015-07-16 21:30 - 2015-07-09 21:51 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2015-07-16 21:30 - 2015-07-09 20:40 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll 2015-07-16 21:30 - 2015-07-09 18:03 - 03701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2015-07-16 21:30 - 2015-07-09 17:54 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe 2015-07-16 21:30 - 2015-07-09 17:53 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll 2015-07-16 21:30 - 2015-07-09 17:50 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 2015-07-16 21:30 - 2015-07-09 17:50 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2015-07-16 21:30 - 2015-07-09 17:48 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2015-07-16 21:30 - 2015-07-09 17:46 - 02229248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 2015-07-16 21:30 - 2015-07-09 17:38 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe 2015-07-16 21:30 - 2015-07-09 17:37 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll 2015-07-16 21:30 - 2015-07-09 17:35 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2015-07-16 21:30 - 2015-07-09 17:34 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2015-07-16 21:30 - 2015-06-27 05:08 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2015-07-16 21:30 - 2015-06-27 05:08 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2015-07-16 21:30 - 2015-06-27 04:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2015-07-16 21:29 - 2015-07-03 15:52 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2015-07-16 21:29 - 2015-07-03 15:52 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2015-07-16 21:29 - 2015-07-03 15:50 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2015-07-16 21:29 - 2015-07-03 15:50 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2015-07-16 21:29 - 2015-06-28 07:07 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2015-07-16 21:29 - 2015-06-28 07:07 - 00178008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2015-07-16 21:29 - 2015-06-28 07:06 - 01311960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll 2015-07-16 21:29 - 2015-06-28 07:06 - 00332120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2015-07-16 21:29 - 2015-06-27 18:42 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll 2015-07-16 21:29 - 2015-06-27 05:13 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2015-07-16 21:29 - 2015-06-27 05:12 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2015-07-16 21:29 - 2015-06-27 05:12 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2015-07-16 21:29 - 2015-06-27 04:40 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2015-07-16 21:29 - 2015-06-27 04:05 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2015-07-16 21:29 - 2015-06-27 04:00 - 00989184 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2015-07-16 21:29 - 2015-06-27 03:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2015-07-16 21:29 - 2015-06-27 03:26 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2015-07-16 21:29 - 2015-06-25 04:31 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2015-07-16 21:29 - 2015-06-16 00:41 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe 2015-07-16 21:29 - 2015-06-16 00:24 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2015-07-16 21:29 - 2015-06-15 23:16 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe 2015-07-16 21:29 - 2015-06-15 23:09 - 03607552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2015-07-16 21:29 - 2015-06-15 22:50 - 02774528 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2015-07-16 21:29 - 2015-06-15 21:57 - 02460160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2015-07-16 21:29 - 2015-05-30 23:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2015-07-16 21:29 - 2015-05-30 21:36 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2015-07-16 21:29 - 2015-05-30 21:35 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2015-07-16 21:13 - 2015-06-16 07:36 - 01661576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2015-07-16 21:13 - 2015-06-16 07:36 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2015-07-16 21:13 - 2015-06-11 05:49 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2015-07-16 21:13 - 2015-06-10 18:13 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2015-07-16 21:13 - 2015-05-07 18:47 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll 2015-07-13 00:30 - 2015-07-13 00:45 - 33832046 _____ C:\Users\Franziska\Downloads\Adel Tawil - Lieder (Parodie) Luke Mockridge - Pimmelbingo .mp4 2015-07-11 22:33 - 2015-07-11 22:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-07-11 21:20 - 2015-07-11 21:20 - 00001957 _____ C:\Users\Public\Desktop\Lenovo Updates.lnk 2015-06-29 14:05 - 2015-06-29 14:05 - 00000000 ____D C:\Users\Franziska\Desktop\pdf 2015-06-27 18:18 - 2015-06-27 18:18 - 00025592 _____ C:\Users\Franziska\Desktop\Kündigung Mama und Oma Wohnung.odt 2015-06-27 15:08 - 2015-06-27 15:08 - 00000000 ____D C:\Users\Franziska\AppData\Local\GWX 2015-06-26 09:49 - 2015-06-26 09:49 - 00293296 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys 2015-06-22 21:09 - 2015-05-21 15:08 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 2015-06-19 12:50 - 2015-06-19 12:50 - 00000000 ____D C:\Program Files\Common Files\AV 2015-06-19 12:38 - 2015-07-11 21:15 - 00001279 _____ C:\Users\Franziska\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-18 17:12 - 2014-10-17 15:22 - 00000000 __RDO C:\Users\Franziska\OneDrive 2015-07-18 17:08 - 2014-10-17 15:34 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-18 17:08 - 2014-10-17 15:20 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2372557226-1662704196-739550879-1002 2015-07-18 17:04 - 2014-10-17 15:34 - 00001134 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-18 17:04 - 2014-08-15 00:39 - 01107907 _____ C:\WINDOWS\WindowsUpdate.log 2015-07-18 17:03 - 2014-10-17 15:14 - 00425704 _____ C:\Users\Franziska\AppData\Local\BTServer.log 2015-07-18 17:03 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru 2015-07-18 15:40 - 2014-11-18 14:43 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-07-18 14:24 - 2013-08-22 16:46 - 00112978 _____ C:\WINDOWS\setupact.log 2015-07-18 14:20 - 2014-08-15 02:18 - 00008704 _____ C:\WINDOWS\system32\VfService.trf 2015-07-18 14:20 - 2014-08-15 01:25 - 06377788 _____ C:\Users\Public\CAFADEBUG.log 2015-07-18 14:20 - 2014-08-15 01:22 - 10673535 _____ C:\WINDOWS\SysWOW64\rootpa.e2e 2015-07-18 14:14 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-07-18 14:12 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI 2015-07-18 13:25 - 2014-10-17 15:12 - 00000000 ____D C:\Users\Franziska\AppData\Local\Pokki 2015-07-18 12:53 - 2014-10-17 15:25 - 00003950 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{26E0C7CA-7B0C-4D1A-8D47-19EEFF6E6754} 2015-07-18 12:52 - 2014-10-17 16:02 - 00000000 ____D C:\ProgramData\MFAData 2015-07-17 20:50 - 2013-08-22 16:44 - 00423904 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2015-07-17 18:13 - 2014-12-28 20:41 - 00000000 ____D C:\WINDOWS\system32\appraiser 2015-07-17 18:13 - 2014-10-23 22:24 - 00000000 ___SD C:\WINDOWS\system32\CompatTel 2015-07-17 18:13 - 2013-08-22 17:36 - 00000000 ___RD C:\WINDOWS\ToastData 2015-07-17 18:13 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\WinStore 2015-07-17 18:08 - 2013-08-22 17:20 - 00000000 ____D C:\WINDOWS\CbsTemp 2015-07-17 17:44 - 2015-04-14 17:33 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX 2015-07-17 17:44 - 2015-04-14 17:33 - 00000000 ___SD C:\WINDOWS\system32\GWX 2015-07-17 14:59 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness 2015-07-17 14:45 - 2014-03-18 11:44 - 00022568 _____ C:\WINDOWS\PFRO.log 2015-07-17 14:40 - 2014-08-15 01:35 - 00000000 ____D C:\Program Files (x86)\Lenovo 2015-07-17 13:07 - 2014-11-15 14:48 - 00000000 ____D C:\Users\Franziska\AppData\Local\Adobe 2015-07-17 12:47 - 2015-04-10 20:50 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2015-07-17 12:46 - 2014-08-15 02:14 - 00000000 ____D C:\ProgramData\Adobe 2015-07-17 12:46 - 2014-08-15 02:14 - 00000000 ____D C:\Program Files (x86)\Adobe 2015-07-17 11:17 - 2014-11-18 14:43 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-07-17 10:45 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM 2015-07-16 21:33 - 2015-01-23 12:49 - 00000000 ____D C:\Users\Franziska\Documents\Dok. Schule 2015-07-16 21:12 - 2014-10-17 15:34 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-07-16 21:03 - 2014-10-17 15:34 - 00004110 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2015-07-16 21:03 - 2014-10-17 15:34 - 00003874 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2015-07-13 23:10 - 2015-05-04 18:53 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-07-13 23:10 - 2015-05-04 18:53 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-13 00:47 - 2014-11-13 22:52 - 00141824 ___SH C:\Users\Franziska\Downloads\Thumbs.db 2015-07-12 23:02 - 2014-11-06 22:27 - 00000000 ____D C:\Users\Franziska\AppData\Local\AVG Web TuneUp 2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\ProgramData\AVG Web TuneUp 2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\Program Files\AVG Web TuneUp 2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp 2015-07-12 16:53 - 2014-11-08 18:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-07-11 22:21 - 2014-08-15 02:31 - 00000000 ____D C:\ProgramData\LU 2015-07-11 22:19 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\NDF 2015-07-11 22:18 - 2014-08-15 01:22 - 00000000 ____D C:\Program Files (x86)\Realtek 2015-07-10 16:42 - 2014-10-17 16:15 - 00001008 _____ C:\Users\Public\Desktop\AVG 2015.lnk 2015-07-10 16:42 - 2014-10-17 16:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2015-07-08 14:35 - 2015-03-19 16:13 - 00000000 ____D C:\Users\Franziska\Documents\gescannte Objekte 2015-06-30 23:31 - 2014-10-18 19:32 - 00603136 ___SH C:\Users\Franziska\Desktop\Thumbs.db 2015-06-27 18:20 - 2014-10-17 15:12 - 00000000 ____D C:\Users\Franziska 2015-06-27 14:34 - 2014-10-23 17:55 - 00000000 ____D C:\WINDOWS\system32\MRT 2015-06-27 14:23 - 2014-10-23 17:55 - 140135120 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-06-22 20:48 - 2014-08-15 10:23 - 00765582 _____ C:\WINDOWS\system32\perfh007.dat 2015-06-22 20:48 - 2014-08-15 10:23 - 00159366 _____ C:\WINDOWS\system32\perfc007.dat 2015-06-22 20:48 - 2014-03-18 11:53 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2015-06-21 20:16 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache 2015-06-21 14:09 - 2015-02-04 16:50 - 00000000 ____D C:\Users\Franziska\Desktop\Neuer Ordner ==================== Files in the root of some directories ======= 2014-10-17 15:14 - 2015-07-18 17:03 - 0425704 _____ () C:\Users\Franziska\AppData\Local\BTServer.log 2014-10-20 17:20 - 2014-11-01 17:39 - 0007596 _____ () C:\Users\Franziska\AppData\Local\resmon.resmoncfg 2014-08-15 01:24 - 2014-08-15 01:24 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some files in TEMP: ==================== C:\Users\Franziska\AppData\Local\Temp\1_flashplayer.exe C:\Users\Franziska\AppData\Local\Temp\2_flashplayer.exe C:\Users\Franziska\AppData\Local\Temp\AutoRun.exe C:\Users\Franziska\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Franziska\AppData\Local\Temp\drm_dialogs.dll C:\Users\Franziska\AppData\Local\Temp\drm_dyndata_7360010.dll C:\Users\Franziska\AppData\Local\Temp\drm_dyndata_7370012.dll C:\Users\Franziska\AppData\Local\Temp\eauninstall.exe C:\Users\Franziska\AppData\Local\Temp\oct3EA.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct4F2C.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct51DB.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct53B0.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct549A.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct5B9A.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct641E.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct6475.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct72B1.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct801A.tmp.exe C:\Users\Franziska\AppData\Local\Temp\oct948E.tmp.exe C:\Users\Franziska\AppData\Local\Temp\octE19D.tmp.exe C:\Users\Franziska\AppData\Local\Temp\Quarantine.exe C:\Users\Franziska\AppData\Local\Temp\sqlite3.dll C:\Users\Franziska\AppData\Local\Temp\The Sims 2 Pets_uninst.exe C:\Users\Franziska\AppData\Local\Temp\VP6Install.exe C:\Users\Franziska\AppData\Local\Temp\VP6VFW.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-07-17 12:28 ==================== End of log ============================ Addition: [CODE]Additional FRST Logfile: Code:
ATTFilter scan result of Farbar Recovery Scan Tool (x64) Version:18-07-2015 01 Ran by Franziska at 2015-07-18 17:14:46 Running from C:\Users\Franziska\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2372557226-1662704196-739550879-500 - Administrator - Disabled) Franziska (S-1-5-21-2372557226-1662704196-739550879-1002 - Administrator - Enabled) => C:\Users\Franziska Gast (S-1-5-21-2372557226-1662704196-739550879-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2372557226-1662704196-739550879-1004 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 3D-Schach 2.0 (HKLM-x32\...\{CE057820-2732-11D4-A8C5-0050DA353A30}) (Version: - ) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated) AMD Catalyst Install Manager (HKLM\...\{665D4B18-EA91-BE16-3212-218C63F5DC4E}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.4.8.0 - AppEx Networks) AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6081 - AVG Technologies) AVG 2015 (Version: 15.0.4392 - AVG Technologies) Hidden AVG 2015 (Version: 15.0.6081 - AVG Technologies) Hidden AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.1.4.948 - AVG Technologies) Benutzerhandbücher (x32 Version: 3.0.0.3 - Lenovo) Hidden CEP - Color Enable Package (HKLM-x32\...\CEP - Colour Enable Packages_is1) (Version: 6.0b (beta) - Numenor, for ModTheSims2) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.28.52 - Conexant) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.) CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden Dependency Package Update (Version: 1.6.25.00 - Lenovo Inc.) Hidden Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden Dependency Package Update (Version: 1.6.36.00 - Lenovo Inc.) Hidden Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden Die Sims 2: Open For Business (HKLM-x32\...\{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}) (Version: - ) Die Sims 2: Wilde Campus-Jahre (HKLM-x32\...\{01521746-02A6-4A72-00BD-A285DF6B80C6}) (Version: - ) Die Sims™ 2 Apartment-Leben (HKLM-x32\...\{B6F5B704-06D3-4687-90F3-6195304AD755}) (Version: - Electronic Arts) Die Sims™ 2 Gute Reise (HKLM-x32\...\{F248ADFA-64E0-4b03-8A83-059078BED6A0}) (Version: - Electronic Arts) Die Sims™ 2 Haustiere (HKLM-x32\...\{4817189D-1785-4627-A33C-39FD90919300}) (Version: - ) Die Sims™ 2 Super Deluxe (HKLM-x32\...\{2D37F6AE-D201-4580-B91A-6BF9BB93ED2D}) (Version: - Electronic Arts) Die Sims™ 2 Vier Jahreszeiten (HKLM-x32\...\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}) (Version: - ) Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc) Druckerdeinstallation für EPSON BX305 Series (HKLM\...\EPSON BX305 Series) (Version: - SEIKO EPSON Corporation) Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.17 - Lenovo) Energy Manager (x32 Version: 1.5.0.17 - Lenovo) Hidden EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.134 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden Hightail for Lenovo (HKLM\...\{2F10E937-F6D7-4174-8AB9-B299E8FC5CEC}) (Version: 2.4.97.2857 - Hightail, Inc.) Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation) Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.36.00 - Lenovo Group Limited) Lenovo EasyCamera (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 6.0.1321.0_WHQL - Sonix) Lenovo FusionEngine (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.) Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo) Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2619 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 8.1.0.2619 - CyberLink Corp.) Hidden Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.2 - Lenovo) Lenovo PhoneCompanion (x32 Version: 1.2.0.2 - Lenovo) Hidden Lenovo Photo Master (HKLM-x32\...\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.) Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.36.1 - ELAN Microelectronic Corp.) Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.) Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden Lenovo SHAREit (HKLM-x32\...\Lenovo SHAREit_is1) (Version: 2.0.5.0 - Lenovo Group Limited) Lenovo Solution Center (HKLM\...\{2F45A217-E9C7-4984-B0AC-5BE31FF4712B}) (Version: 2.4.003.00 - Lenovo Group Limited) Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo) Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden Lenovo VeriFace Pro (HKLM\...\Lenovo VeriFace) (Version: 5.0.14.1061 - Lenovo) LibreOffice 4.3.4.1 (HKLM-x32\...\{7D983A32-F645-48AB-8E38-4ACD234F40BC}) (Version: 4.3.4.1 - The Document Foundation) Little Alchemy (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\littlealchemy-c7de5d8adcfd810d98ec68069ab57bd9) (Version: 1.1.1 - Recloak) Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation) Metric Collection SDK 35 (x32 Version: 1.2.0001.00 - Lenovo Group Limited) Hidden Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0.3 - Mozilla) Nitro Pro 9 (HKLM\...\{4C32F7E8-A65F-4D3C-9153-9F3B57CB6872}) (Version: 9.0.5.9 - Nitro) OEM Application Profile (HKLM-x32\...\{8F92E0CF-620B-5C20-F292-59C93567B06D}) (Version: 1.00.0000 - Ihr Firmenname) OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.) REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.805.806.012214 - REALTEK Semiconductor Corp.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39058 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek) REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.20.243 - REALTEK Semiconductor Corp.) User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Windows-Treiberpaket - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) ==================== Restore Points ========================= 27-06-2015 14:21:49 Windows Update 10-07-2015 21:32:10 Windows Update 11-07-2015 22:17:33 Installiert REALTEK PCIE Wireless LAN Driver 17-07-2015 12:28:57 Windows Update 18-07-2015 14:18:09 JRT Pre-Junkware Removal ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {059FF85A-96A7-4F30-A151-025BF8D10B64} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.) Task: {0C6938DC-5060-47BB-A244-9A5EB9241201} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-05-06] (Lenovo) Task: {12470315-4A24-4A46-978B-34FE10051EE7} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.) Task: {13842334-9265-4B05-9B11-BB24C42F8DC4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {2C817108-BF13-4F80-A785-9C358584854F} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] () Task: {307BD0C3-750A-40EF-A3F9-4288EDF529BD} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-17] (Adobe Systems Incorporated) Task: {35FDB4CA-8E11-4760-899E-1C6B82C96F61} - System32\Tasks\{808CE7D6-F887-46A4-8EAC-78FDCF14B029} => pcalua.exe -a E:\Setup.exe -d E:\ Task: {3F25A2CE-84E0-4B57-8CD6-D67BEBA2A6E4} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] () Task: {4E3DA8B7-52C1-44FF-8494-9303931DF0B1} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2014-05-06] (Lenovo) Task: {9523A3F0-9354-4859-AB26-D73344A8B4FA} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-03-06] () Task: {AE485BC0-FDB5-4ECA-9875-A86CD8B8DBAE} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-05-30] (Lenovo) Task: {B8114FCD-1409-421C-B736-0F019EE4C980} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Office2013\OFFICEICON.vbs [2013-06-03] () Task: {CF99EECC-97CB-45EF-836C-DEF2AFC71F69} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-06-27] (Microsoft Corporation) Task: {FA2727FE-C2D9-4520-B56D-97513B9D0DAE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2014-08-15 01:24 - 2010-10-26 06:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe 2014-03-26 12:50 - 2014-08-15 02:23 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll 2014-04-18 22:12 - 2014-04-18 22:12 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2015-07-16 21:12 - 2015-07-13 23:55 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libglesv2.dll 2015-07-16 21:12 - 2015-07-13 23:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Windows:nlsPreferences AlternateDataStreams: C:\Users\Franziska\OneDrive:ms-properties ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDWFP => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VisualDiscovery => ""="service" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\Run32: => "snp2uvc" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{AFBD7067-D2F6-4D3C-85B3-88A008C18967}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe FirewallRules: [{663A46B4-3414-4F48-A319-A422F7F43977}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe FirewallRules: [{AC2767B5-A536-457E-B67B-50A79A754C46}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{77D8B7D4-27EC-4437-A263-031784DFAC63}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{55376DCC-D006-4A28-AA16-B85FAC106F3E}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE FirewallRules: [{084835F4-19BE-43D6-BEB8-78503B45965C}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe FirewallRules: [{1F9F0BC2-0CF8-4AA0-974C-7BA40E438A95}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe FirewallRules: [{EE98E101-3C74-4620-AE02-3ADF1B6FA0CD}] => (Allow) LPort=55100 FirewallRules: [{0798E54B-7073-4647-8B2A-685DE6EC27D3}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe FirewallRules: [{0A8AAECB-B085-4693-8040-C11384793642}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{AB42E82B-FAD0-4683-B81E-CBA57E9CE423}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{DA68199A-F30C-4B34-B07D-55BC97A1320D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{BEE4CC4D-667E-4F8F-A4B9-C3191BCA1FC5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{7FADA343-E843-4133-A0D4-4BC7788FC0A5}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{518A6693-CCCD-4A4B-B9D9-01F793BF96AE}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{1C8585A3-15F7-4FF0-A443-C7D6A06A964A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe FirewallRules: [{D1DD6BFC-A9A7-4E39-BCE5-7A467EDBD48B}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe FirewallRules: [{D53DDE3E-9291-4381-BFBE-4405895AD9D4}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe FirewallRules: [{A02C96FC-1AC8-4B35-AB3B-3530569EF51D}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe FirewallRules: [{28841159-30B7-405D-9466-DA3C044D5BE5}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe FirewallRules: [{43A83805-ED93-4F21-B195-E5CB8AE4B9DD}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe FirewallRules: [{6929263B-9A5C-42DA-835C-976C8D9937FE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= Name: Dell 3333dn Description: Dell 3333dn Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: Dell Service: usbscan Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/18/2015 02:36:50 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm FRST64.exe, Version 13.7.2015.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: a10 Startzeit: 01d0c1565baf8bc1 Endzeit: 78 Anwendungspfad: C:\Users\Franziska\Desktop\FRST64.exe Berichts-ID: a610097f-2d49-11e5-8394-28d244c25993 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (07/18/2015 02:36:20 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm FRST64.exe, Version 13.7.2015.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 320 Startzeit: 01d0c15627a7966a Endzeit: 15 Anwendungspfad: C:\Users\Franziska\Desktop\FRST64.exe Berichts-ID: 93d18442-2d49-11e5-8394-28d244c25993 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (07/18/2015 01:24:13 PM) (Source: Perflib) (EventID: 1010) (User: ) Description: C:\Windows\System32\winspool.drvSpooler8 Error: (07/17/2015 05:08:13 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: tdsskiller.exe, Version: 3.0.0.44, Zeitstempel: 0x54c08a45 Name des fehlerhaften Moduls: tdsskiller.exe, Version: 3.0.0.44, Zeitstempel: 0x54c08a45 Ausnahmecode: 0x40000015 Fehleroffset: 0x0014348c ID des fehlerhaften Prozesses: 0x830 Startzeit der fehlerhaften Anwendung: 0xtdsskiller.exe0 Pfad der fehlerhaften Anwendung: tdsskiller.exe1 Pfad des fehlerhaften Moduls: tdsskiller.exe2 Berichtskennung: tdsskiller.exe3 Vollständiger Name des fehlerhaften Pakets: tdsskiller.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: tdsskiller.exe5 Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/17/2015 02:43:57 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Bei der Aktivierung der App „Microsoft.WindowsAlarms_8wekyb3d8bbwe!App“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/17/2015 02:41:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/17/2015 01:00:21 AM) (Source: MsiInstaller) (EventID: 1024) (User: LENOVO-PC) Description: Produkt: Adobe Reader XI (11.0.11) - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011012}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 System errors: ============= Error: (07/18/2015 05:09:39 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Error: (07/18/2015 05:08:28 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Error: (07/18/2015 05:07:44 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Error: (07/18/2015 05:06:00 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Error: (07/18/2015 05:03:26 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Error: (07/18/2015 03:46:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Error: (07/18/2015 03:46:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Error: (07/18/2015 03:46:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Error: (07/18/2015 03:46:32 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Error: (07/18/2015 03:46:31 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Microsoft Office: ========================= Error: (07/18/2015 02:36:50 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: FRST64.exe13.7.2015.1a1001d0c1565baf8bc178C:\Users\Franziska\Desktop\FRST64.exea610097f-2d49-11e5-8394-28d244c25993 Error: (07/18/2015 02:36:20 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: FRST64.exe13.7.2015.132001d0c15627a7966a15C:\Users\Franziska\Desktop\FRST64.exe93d18442-2d49-11e5-8394-28d244c25993 Error: (07/18/2015 01:24:13 PM) (Source: Perflib) (EventID: 1010) (User: ) Description: C:\Windows\System32\winspool.drvSpooler8 Error: (07/17/2015 05:08:13 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: tdsskiller.exe3.0.0.4454c08a45tdsskiller.exe3.0.0.4454c08a45400000150014348c83001d0c0a22cdb0476C:\Users\Franziska\Desktop\tdsskiller.exeC:\Users\Franziska\Desktop\tdsskiller.exea4b11beb-2c95-11e5-8390-28d244c25993 Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141 Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141 Error: (07/17/2015 02:44:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141 Error: (07/17/2015 02:43:57 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: Microsoft.WindowsAlarms_8wekyb3d8bbwe!App-2144927141 Error: (07/17/2015 02:41:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC) Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141 Error: (07/17/2015 01:00:21 AM) (Source: MsiInstaller) (EventID: 1024) (User: LENOVO-PC) Description: Adobe Reader XI (11.0.11) - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011012}1625(NULL)(NULL)(NULL) ==================== Memory info =========================== Processor: AMD A6-6310 APU with AMD Radeon R4 Graphics Percentage of memory in use: 25% Total physical RAM: 7128.26 MB Available physical RAM: 5294.6 MB Total Virtual: 8280.26 MB Available Virtual: 6220.7 MB ==================== Drives ================================ Drive c: (Windows8_OS) (Fixed) (Total:890.1 GB) (Free:829.63 GB) NTFS ==>[system with boot components (obtained from reading drive)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:23.14 GB) NTFS Drive f: () (Removable) (Total:3.68 GB) (Free:0.14 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: E07FA830) Partition: GPT Partition Type. ======================================================== Disk: 1 (Size: 3.7 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End of log ============================ Hat das jetzt eigentlich, dass ich nicht mehr auf das Startmenü zugreifen kann etwas mit den Scans oder dem Trojaner zutun? |
18.07.2015, 21:52 | #12 | |
/// TB-Ausbilder | BKA-Trojaner aber keine Sperrungen Servus, Zitat:
Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 2 h) dauern. Im Anschluss entfernen wir alle verwendeten Tools und ich gebe dir noch ein paar Tipps mit auf den Weg. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start CloseProcesses: C:\Users\Franziska\AppData\Local\pokki C:\ProgramData\pokki SearchScopes: HKU\S-1-5-21-2372557226-1662704196-739550879-1002 -> {97CB315F-D830-4B49-92BC-986D9C008592} URL = RemoveProxy: EmptyTemp: end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 ESET Online Scanner
Schritt 3 Downloade Dir bitte SecurityCheck und:
Schritt 4
Bitte poste mit deiner nächsten Antwort
|
19.07.2015, 10:41 | #13 |
| BKA-Trojaner aber keine Sperrungen Hier ist alles FRST-Fix: Code:
ATTFilter Fix result of Farbar Recovery Scan Tool (x64) Version:18-07-2015 01 Ran by Franziska at 2015-07-18 23:35:59 Run:1 Running from C:\Users\Franziska\Desktop Loaded Profiles: Franziska (Available Profiles: Franziska) Boot Mode: Normal ============================================== fixlist content: ***************** start CloseProcesses: C:\Users\Franziska\AppData\Local\pokki C:\ProgramData\pokki SearchScopes: HKU\S-1-5-21-2372557226-1662704196-739550879-1002 -> {97CB315F-D830-4B49-92BC-986D9C008592} URL = RemoveProxy: EmptyTemp: end ***************** Processes closed successfully. C:\Users\Franziska\AppData\Local\pokki => moved successfully. "C:\ProgramData\pokki" => File/Folder not found. "HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{97CB315F-D830-4B49-92BC-986D9C008592}" => key removed successfully HKCR\CLSID\{97CB315F-D830-4B49-92BC-986D9C008592} => key not found. ========= RemoveProxy: ========= HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\S-1-5-21-2372557226-1662704196-739550879-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully ========= End of RemoveProxy: ========= EmptyTemp: => 3 GB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 23:37:33 ==== Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=ca11530520c3c045aa0e13441a94a717 # end=init # utc_time=2015-07-18 09:49:58 # local_time=2015-07-18 11:49:58 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.2.9200 NT Update Init Update Download Update Finalize Updated modules version: 24869 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=ca11530520c3c045aa0e13441a94a717 # end=updated # utc_time=2015-07-18 09:53:08 # local_time=2015-07-18 11:53:08 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.2.9200 NT # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=ca11530520c3c045aa0e13441a94a717 # engine=24869 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-07-18 11:46:20 # local_time=2015-07-19 01:46:20 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='AVG AntiVirus Free Edition 2015' # compatibility_mode=1055 16777213 100 100 46480 124397164 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 9708080 29171842 0 0 # scanned=266370 # found=3 # cleaned=0 # scan_time=6791 sh=06CAA13FC95025FA7EFD9F029ADBC587B9A72E67 ft=1 fh=f46472aab4e6620b vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Franziska\Downloads\7 Zip 32 Bit - CHIP-Installer.exe" sh=EAEA54893BE2EB862A63F69CD9A3D290C8F85AB6 ft=1 fh=d3c0a1d1c4202a6f vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Franziska\Downloads\7 Zip 64 Bit - CHIP-Installer.exe" sh=6A1F7B56BF1FB13D31E6C8A9CD0128170E8B6B04 ft=1 fh=84d35e6595887ed5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Franziska\Downloads\OpenOffice - CHIP-Installer.exe" Code:
ATTFilter Results of screen317's Security Check version 1.004 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Defender AVG AntiVirus Free Edition 2015 Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` AVG Web TuneUp Java 8 Update 51 Java version 32-bit out of Date! Adobe Flash Player 18.0.0.209 Mozilla Firefox (39.0) Google Chrome (43.0.2357.132) Google Chrome (43.0.2357.134) ````````Process Check: objlist.exe by Laurent```````` AVG avgwdsvc.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-07-2015 01 Ran by Franziska (administrator) on LENOVO-PC on 19-07-2015 11:31:30 Running from C:\Users\Franziska\Desktop Loaded Profiles: Franziska (Available Profiles: Franziska) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe (AMD) C:\Windows\System32\atiesrxx.exe (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe () C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe (Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE (Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe (Lenovo) C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe () C:\Program Files\Lenovo PhoneCompanion\adb.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Users\Franziska\Desktop\SecurityCheck.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] () HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-04] (Conexant Systems, Inc.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891592 2014-02-11] (ELAN Microelectronics Corp.) HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [216064 2014-01-06] (Realtek Semiconductor Corporation) HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-08-15] (Lenovo) HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-08-15] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2014-08-15] (Lenovo(beijing) Limited) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-04-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [snp2uvc] => C:\WINDOWS\vsnp2uvc.exe HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3730344 2015-06-30] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation) ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://lenovo13.msn.com/?pc=LCJB hxxp://www.lenovo.com HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-17] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-17] (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{126079A8-E17A-4F05-894B-2B5B8A051737}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{E6F50CE2-672B-468B-BF96-C59F56340331}: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285 FF Homepage: google.de FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-17] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-17] () FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-17] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-17] (Oracle Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2013-12-12] (Nitro PDF) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.) FF Extension: Adblock Plus - C:\Users\Franziska\AppData\Roaming\Mozilla\Firefox\Profiles\s8645vto.default-1423061599285\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-18] Chrome: ======= CHR Profile: C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-17] CHR Extension: (Google Docs) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-17] CHR Extension: (Google Drive) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-17] CHR Extension: (YouTube) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-17] CHR Extension: (Google Search) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-17] CHR Extension: (Google Sheets) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-17] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-19] CHR Extension: (Cath Kidston) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndlpkmaeinmnbiadacenijnhlolneopm [2014-10-19] CHR Extension: (Google Wallet) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-17] CHR Extension: (Gmail) - C:\Users\Franziska\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-17] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-18] (Advanced Micro Devices, Inc.) [File not signed] R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3518376 2015-06-30] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [314304 2015-06-30] (AVG Technologies CZ, s.r.o.) R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [84992 2014-01-22] () [File not signed] S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99632 2013-10-09] (ELAN Microelectronics Corp.) S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo) R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584632 2015-03-06] (LENOVO INCORPORATED.) R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-08-15] (Lenovo(beijing) Limited) S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1663880 2014-05-06] () S2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-12] (Nitro PDF Software) R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-08-15] (Lenovo) S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2014-08-15] (Lenovo) R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] () R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51712 2014-02-24] (Advanced Micro Devices, Inc.) R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-08-15] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation) R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1195920 2015-07-12] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [85704 2014-02-24] (Advanced Micro Devices, Inc. ) R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-12] (Advanced Micro Devices, Inc.) R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [230088 2014-02-24] (Advanced Micro Devices, Inc. ) R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [224992 2013-11-01] (AppEx Networks Corporation) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices) S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [293296 2015-06-26] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [253408 2015-05-12] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [259040 2015-06-16] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [226784 2015-06-10] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [295400 2015-06-15] (AVG Technologies CZ, s.r.o.) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation) S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [107736 2015-07-17] (Malwarebytes Corporation) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation) S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation) R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-04-15] (Realtek Semiconductor Corporation) R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3593432 2014-10-07] (Realtek Semiconductor Corporation ) R3 SNP2UVC; C:\Windows\system32\DRIVERS\snp2uvc.sys [2853400 2014-01-23] (Sonix Co. Ltd.) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-19 11:27 - 2015-07-19 11:27 - 00852662 _____ C:\Users\Franziska\Desktop\SecurityCheck.exe 2015-07-18 23:49 - 2015-07-18 23:49 - 02870984 _____ (ESET) C:\Users\Franziska\Desktop\esetsmartinstaller_deu.exe 2015-07-18 23:49 - 2015-07-18 23:49 - 00000000 ____D C:\Program Files (x86)\ESET 2015-07-18 17:12 - 2015-07-19 11:32 - 00017910 _____ C:\Users\Franziska\Desktop\FRST.txt 2015-07-18 17:11 - 2015-07-18 17:12 - 02134528 _____ (Farbar) C:\Users\Franziska\Desktop\FRST64.exe 2015-07-18 14:37 - 2015-07-18 14:37 - 00000000 ____D C:\Users\Franziska\Desktop\FRST-OlderVersion 2015-07-18 14:32 - 2015-07-18 14:32 - 00002013 _____ C:\Users\Franziska\Desktop\JRT.txt 2015-07-18 14:16 - 2015-07-18 14:16 - 00001201 _____ C:\Users\Franziska\Desktop\mbam.txt..txt 2015-07-18 13:56 - 2015-07-18 14:01 - 01798288 _____ (Malwarebytes Corporation) C:\Users\Franziska\Desktop\JRT.exe 2015-07-18 13:33 - 2015-07-18 13:33 - 00007986 _____ C:\Users\Franziska\Desktop\AdwCleaner[S0].txt 2015-07-18 13:17 - 2015-07-18 13:25 - 00000000 ____D C:\AdwCleaner 2015-07-18 13:06 - 2015-07-18 13:08 - 02248704 _____ C:\Users\Franziska\Desktop\AdwCleaner_4.208.exe 2015-07-18 12:51 - 2015-07-18 12:51 - 00014615 _____ C:\Users\Franziska\Desktop\Suchlaufverlaufsprotokoll 2.txt 2015-07-18 12:50 - 2015-07-18 12:50 - 00013550 _____ C:\Users\Franziska\Desktop\Suchlaufverlaufsprotokoll 1.txt 2015-07-17 17:00 - 2015-07-17 17:03 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Franziska\Desktop\tdsskiller.exe 2015-07-17 16:52 - 2015-07-19 11:31 - 00000000 ____D C:\FRST 2015-07-17 16:18 - 2015-05-07 17:21 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll 2015-07-17 16:18 - 2015-05-07 17:05 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll 2015-07-17 16:18 - 2015-05-03 02:39 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2015-07-17 16:18 - 2015-04-30 01:22 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll 2015-07-17 16:13 - 2015-05-07 19:50 - 22292672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2015-07-17 16:13 - 2015-05-07 19:00 - 03109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2015-07-17 16:13 - 2015-05-07 18:53 - 19734960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2015-07-17 16:13 - 2015-05-07 18:12 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2015-07-17 16:07 - 2015-06-30 00:43 - 00026288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2015-07-17 16:07 - 2015-06-29 17:07 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2015-07-17 16:07 - 2015-06-29 17:07 - 01084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2015-07-17 16:07 - 2015-06-29 17:07 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2015-07-17 16:07 - 2015-06-29 17:07 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2015-07-17 16:07 - 2015-06-29 17:07 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2015-07-17 16:07 - 2015-06-27 01:21 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2015-07-17 16:07 - 2015-06-27 01:21 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2015-07-17 16:07 - 2015-05-11 20:17 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2015-07-17 16:07 - 2015-04-25 04:25 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023.sys 2015-07-17 16:07 - 2014-11-04 21:25 - 00059712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys 2015-07-17 16:07 - 2014-11-04 21:25 - 00051008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys 2015-07-17 16:07 - 2014-11-04 08:55 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys 2015-07-17 16:07 - 2014-11-04 08:54 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys 2015-07-17 16:07 - 2014-11-04 08:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys 2015-07-17 16:07 - 2014-11-04 08:54 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys 2015-07-17 16:06 - 2015-05-03 17:09 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2015-07-17 16:06 - 2015-05-03 16:58 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2015-07-17 16:06 - 2015-05-03 16:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2015-07-17 16:06 - 2015-05-03 16:49 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2015-07-17 16:03 - 2015-05-11 18:34 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll 2015-07-17 16:03 - 2015-04-28 15:13 - 00513480 _____ C:\WINDOWS\SysWOW64\locale.nls 2015-07-17 16:03 - 2015-04-28 15:13 - 00513480 _____ C:\WINDOWS\system32\locale.nls 2015-07-17 16:03 - 2015-04-23 17:47 - 03084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2015-07-17 16:03 - 2015-04-23 17:16 - 02471424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2015-07-17 16:02 - 2015-05-12 15:19 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll 2015-07-17 16:01 - 2015-05-02 01:33 - 00410739 _____ C:\WINDOWS\system32\ApnDatabase.xml 2015-07-17 16:00 - 2015-05-03 17:07 - 07784448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2015-07-17 16:00 - 2015-05-03 16:57 - 05264384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2015-07-17 14:23 - 2015-07-17 14:43 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2015-07-17 14:17 - 2015-07-17 14:48 - 00000000 ____D C:\Users\Franziska\Desktop\mbar 2015-07-17 13:54 - 2015-07-17 14:11 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Franziska\Downloads\mbar-1.09.1.1004.exe 2015-07-17 12:46 - 2015-07-17 12:46 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-07-17 12:46 - 2015-07-17 12:46 - 00002078 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2015-07-17 11:08 - 2015-07-18 14:15 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-07-17 11:03 - 2015-07-17 14:17 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2015-07-17 11:03 - 2015-07-17 11:03 - 00001125 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-07-17 11:03 - 2015-07-17 11:03 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-07-17 11:03 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2015-07-17 11:03 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2015-07-17 10:46 - 2015-07-17 10:57 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Franziska\Downloads\mbam-setup-2.1.8.1057.exe 2015-07-17 00:54 - 2015-07-17 00:54 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2015-07-17 00:54 - 2015-07-17 00:54 - 00000000 ____D C:\ProgramData\Sun 2015-07-17 00:54 - 2015-07-17 00:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-07-17 00:53 - 2015-07-17 00:53 - 00000000 ____D C:\ProgramData\Oracle 2015-07-17 00:53 - 2015-07-17 00:53 - 00000000 ____D C:\Program Files (x86)\Java 2015-07-17 00:15 - 2015-07-17 00:15 - 00563296 _____ (Oracle Corporation) C:\Users\Franziska\Downloads\chromeinstall-8u51.exe 2015-07-16 21:58 - 2015-07-02 23:21 - 19877376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-07-16 21:58 - 2015-07-02 22:49 - 25193984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-07-16 21:57 - 2015-07-02 22:50 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-07-16 21:57 - 2015-07-02 22:23 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-07-16 21:57 - 2015-07-02 22:19 - 12855296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-07-16 21:57 - 2015-07-02 21:55 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-07-16 21:57 - 2015-07-02 21:20 - 14453248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-07-16 21:57 - 2015-07-02 20:59 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-07-16 21:42 - 2015-07-02 00:08 - 05923840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2015-07-16 21:41 - 2015-07-01 23:14 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2015-07-16 21:41 - 2015-06-16 00:39 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2015-07-16 21:41 - 2015-06-16 00:38 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll 2015-07-16 21:41 - 2015-06-16 00:26 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll 2015-07-16 21:41 - 2015-06-16 00:24 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2015-07-16 21:41 - 2015-06-16 00:02 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx 2015-07-16 21:41 - 2015-06-15 23:58 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll 2015-07-16 21:41 - 2015-06-15 23:57 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2015-07-16 21:41 - 2015-06-15 23:56 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2015-07-16 21:41 - 2015-06-15 23:55 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2015-07-16 21:41 - 2015-06-15 23:49 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2015-07-16 21:41 - 2015-06-15 23:41 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2015-07-16 21:41 - 2015-06-15 23:38 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2015-07-16 21:41 - 2015-06-15 23:36 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2015-07-16 21:41 - 2015-06-15 23:17 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2015-07-16 21:41 - 2015-06-15 23:16 - 02427392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2015-07-16 21:41 - 2015-06-15 23:15 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2015-07-16 21:41 - 2015-06-15 23:13 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 2015-07-16 21:41 - 2015-06-15 23:04 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll 2015-07-16 21:41 - 2015-06-15 23:03 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2015-07-16 21:41 - 2015-06-15 22:52 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2015-07-16 21:41 - 2015-06-15 22:47 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx 2015-07-16 21:41 - 2015-06-15 22:44 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll 2015-07-16 21:41 - 2015-06-15 22:43 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2015-07-16 21:41 - 2015-06-15 22:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2015-07-16 21:41 - 2015-06-15 22:41 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2015-07-16 21:41 - 2015-06-15 22:37 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2015-07-16 21:41 - 2015-06-15 22:32 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2015-07-16 21:41 - 2015-06-15 22:31 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2015-07-16 21:41 - 2015-06-15 22:30 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2015-07-16 21:41 - 2015-06-15 22:30 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2015-07-16 21:41 - 2015-06-15 22:17 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2015-07-16 21:41 - 2015-06-15 22:07 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2015-07-16 21:41 - 2015-06-15 22:02 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2015-07-16 21:30 - 2015-07-09 21:51 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2015-07-16 21:30 - 2015-07-09 20:40 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll 2015-07-16 21:30 - 2015-07-09 18:03 - 03701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2015-07-16 21:30 - 2015-07-09 17:54 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe 2015-07-16 21:30 - 2015-07-09 17:53 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll 2015-07-16 21:30 - 2015-07-09 17:50 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 2015-07-16 21:30 - 2015-07-09 17:50 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2015-07-16 21:30 - 2015-07-09 17:48 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2015-07-16 21:30 - 2015-07-09 17:46 - 02229248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 2015-07-16 21:30 - 2015-07-09 17:38 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe 2015-07-16 21:30 - 2015-07-09 17:37 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll 2015-07-16 21:30 - 2015-07-09 17:35 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2015-07-16 21:30 - 2015-07-09 17:34 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2015-07-16 21:30 - 2015-06-27 05:08 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2015-07-16 21:30 - 2015-06-27 05:08 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2015-07-16 21:30 - 2015-06-27 04:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2015-07-16 21:29 - 2015-07-03 15:52 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2015-07-16 21:29 - 2015-07-03 15:52 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2015-07-16 21:29 - 2015-07-03 15:50 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2015-07-16 21:29 - 2015-07-03 15:50 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2015-07-16 21:29 - 2015-06-28 07:07 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2015-07-16 21:29 - 2015-06-28 07:07 - 00178008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2015-07-16 21:29 - 2015-06-28 07:06 - 01311960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll 2015-07-16 21:29 - 2015-06-28 07:06 - 00332120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2015-07-16 21:29 - 2015-06-27 18:42 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll 2015-07-16 21:29 - 2015-06-27 05:13 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2015-07-16 21:29 - 2015-06-27 05:12 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2015-07-16 21:29 - 2015-06-27 05:12 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2015-07-16 21:29 - 2015-06-27 04:40 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2015-07-16 21:29 - 2015-06-27 04:05 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2015-07-16 21:29 - 2015-06-27 04:00 - 00989184 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2015-07-16 21:29 - 2015-06-27 03:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2015-07-16 21:29 - 2015-06-27 03:26 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2015-07-16 21:29 - 2015-06-25 04:31 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2015-07-16 21:29 - 2015-06-16 00:41 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe 2015-07-16 21:29 - 2015-06-16 00:24 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2015-07-16 21:29 - 2015-06-15 23:16 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe 2015-07-16 21:29 - 2015-06-15 23:09 - 03607552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2015-07-16 21:29 - 2015-06-15 22:50 - 02774528 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2015-07-16 21:29 - 2015-06-15 21:57 - 02460160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2015-07-16 21:29 - 2015-05-30 23:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2015-07-16 21:29 - 2015-05-30 21:36 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2015-07-16 21:29 - 2015-05-30 21:35 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2015-07-16 21:13 - 2015-06-16 07:36 - 01661576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2015-07-16 21:13 - 2015-06-16 07:36 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2015-07-16 21:13 - 2015-06-11 05:49 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2015-07-16 21:13 - 2015-06-10 18:13 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2015-07-16 21:13 - 2015-05-07 18:47 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll 2015-07-13 00:30 - 2015-07-13 00:45 - 33832046 _____ C:\Users\Franziska\Downloads\Adel Tawil - Lieder (Parodie) Luke Mockridge - Pimmelbingo .mp4 2015-07-11 22:33 - 2015-07-11 22:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-07-11 21:20 - 2015-07-11 21:20 - 00001957 _____ C:\Users\Public\Desktop\Lenovo Updates.lnk 2015-06-29 14:05 - 2015-06-29 14:05 - 00000000 ____D C:\Users\Franziska\Desktop\pdf 2015-06-27 18:18 - 2015-06-27 18:18 - 00025592 _____ C:\Users\Franziska\Desktop\Kündigung Mama und Oma Wohnung.odt 2015-06-27 15:08 - 2015-06-27 15:08 - 00000000 ____D C:\Users\Franziska\AppData\Local\GWX 2015-06-26 09:49 - 2015-06-26 09:49 - 00293296 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys 2015-06-22 21:09 - 2015-05-21 15:08 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 2015-06-19 12:50 - 2015-06-19 12:50 - 00000000 ____D C:\Program Files\Common Files\AV 2015-06-19 12:38 - 2015-07-11 21:15 - 00001279 _____ C:\Users\Franziska\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-19 11:30 - 2014-10-17 16:02 - 00000000 ____D C:\ProgramData\MFAData 2015-07-19 11:29 - 2014-10-17 15:25 - 00003950 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{26E0C7CA-7B0C-4D1A-8D47-19EEFF6E6754} 2015-07-19 11:28 - 2014-08-15 00:39 - 01207383 _____ C:\WINDOWS\WindowsUpdate.log 2015-07-19 11:25 - 2014-10-17 15:14 - 00427871 _____ C:\Users\Franziska\AppData\Local\BTServer.log 2015-07-19 11:25 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru 2015-07-19 01:51 - 2014-10-17 15:20 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2372557226-1662704196-739550879-1002 2015-07-19 01:40 - 2014-11-18 14:43 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-07-19 01:08 - 2014-10-17 15:34 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-18 23:49 - 2013-08-22 16:46 - 00113392 _____ C:\WINDOWS\setupact.log 2015-07-18 23:40 - 2014-10-17 15:22 - 00000000 ___DO C:\Users\Franziska\OneDrive 2015-07-18 23:40 - 2014-08-15 01:22 - 10705205 _____ C:\WINDOWS\SysWOW64\rootpa.e2e 2015-07-18 23:39 - 2014-10-18 19:32 - 00603136 ___SH C:\Users\Franziska\Desktop\Thumbs.db 2015-07-18 23:39 - 2014-10-17 15:34 - 00001134 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-18 23:39 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-07-18 23:38 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI 2015-07-18 23:36 - 2014-08-15 01:25 - 06414416 _____ C:\Users\Public\CAFADEBUG.log 2015-07-18 14:20 - 2014-08-15 02:18 - 00008704 _____ C:\WINDOWS\system32\VfService.trf 2015-07-17 20:50 - 2013-08-22 16:44 - 00423904 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2015-07-17 18:13 - 2014-12-28 20:41 - 00000000 ____D C:\WINDOWS\system32\appraiser 2015-07-17 18:13 - 2014-10-23 22:24 - 00000000 ___SD C:\WINDOWS\system32\CompatTel 2015-07-17 18:13 - 2013-08-22 17:36 - 00000000 ___RD C:\WINDOWS\ToastData 2015-07-17 18:13 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\WinStore 2015-07-17 18:08 - 2013-08-22 17:20 - 00000000 ____D C:\WINDOWS\CbsTemp 2015-07-17 17:44 - 2015-04-14 17:33 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX 2015-07-17 17:44 - 2015-04-14 17:33 - 00000000 ___SD C:\WINDOWS\system32\GWX 2015-07-17 14:59 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness 2015-07-17 14:45 - 2014-03-18 11:44 - 00022568 _____ C:\WINDOWS\PFRO.log 2015-07-17 14:40 - 2014-08-15 01:35 - 00000000 ____D C:\Program Files (x86)\Lenovo 2015-07-17 13:07 - 2014-11-15 14:48 - 00000000 ____D C:\Users\Franziska\AppData\Local\Adobe 2015-07-17 12:47 - 2015-04-10 20:50 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2015-07-17 12:46 - 2014-08-15 02:14 - 00000000 ____D C:\ProgramData\Adobe 2015-07-17 12:46 - 2014-08-15 02:14 - 00000000 ____D C:\Program Files (x86)\Adobe 2015-07-17 11:17 - 2014-11-18 14:43 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-07-17 10:45 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM 2015-07-16 21:33 - 2015-01-23 12:49 - 00000000 ____D C:\Users\Franziska\Documents\Dok. Schule 2015-07-16 21:12 - 2014-10-17 15:34 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-07-16 21:03 - 2014-10-17 15:34 - 00004110 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2015-07-16 21:03 - 2014-10-17 15:34 - 00003874 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2015-07-13 23:10 - 2015-05-04 18:53 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-07-13 23:10 - 2015-05-04 18:53 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-13 00:47 - 2014-11-13 22:52 - 00141824 ___SH C:\Users\Franziska\Downloads\Thumbs.db 2015-07-12 23:02 - 2014-11-06 22:27 - 00000000 ____D C:\Users\Franziska\AppData\Local\AVG Web TuneUp 2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\ProgramData\AVG Web TuneUp 2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\Program Files\AVG Web TuneUp 2015-07-12 23:02 - 2014-11-06 22:26 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp 2015-07-12 16:53 - 2014-11-08 18:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-07-11 22:21 - 2014-08-15 02:31 - 00000000 ____D C:\ProgramData\LU 2015-07-11 22:19 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\NDF 2015-07-11 22:18 - 2014-08-15 01:22 - 00000000 ____D C:\Program Files (x86)\Realtek 2015-07-10 16:42 - 2014-10-17 16:15 - 00001008 _____ C:\Users\Public\Desktop\AVG 2015.lnk 2015-07-10 16:42 - 2014-10-17 16:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2015-07-08 14:35 - 2015-03-19 16:13 - 00000000 ____D C:\Users\Franziska\Documents\gescannte Objekte 2015-06-27 18:20 - 2014-10-17 15:12 - 00000000 ____D C:\Users\Franziska 2015-06-27 14:34 - 2014-10-23 17:55 - 00000000 ____D C:\WINDOWS\system32\MRT 2015-06-27 14:23 - 2014-10-23 17:55 - 140135120 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-06-22 20:48 - 2014-08-15 10:23 - 00765582 _____ C:\WINDOWS\system32\perfh007.dat 2015-06-22 20:48 - 2014-08-15 10:23 - 00159366 _____ C:\WINDOWS\system32\perfc007.dat 2015-06-22 20:48 - 2014-03-18 11:53 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2015-06-21 20:16 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache 2015-06-21 14:09 - 2015-02-04 16:50 - 00000000 ____D C:\Users\Franziska\Desktop\Neuer Ordner ==================== Files in the root of some directories ======= 2014-10-17 15:14 - 2015-07-19 11:25 - 0427871 _____ () C:\Users\Franziska\AppData\Local\BTServer.log 2014-10-20 17:20 - 2014-11-01 17:39 - 0007596 _____ () C:\Users\Franziska\AppData\Local\resmon.resmoncfg 2014-08-15 01:24 - 2014-08-15 01:24 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-07-17 12:28 ==================== End of log ============================ Addition.txt.: [CODE]Additional FRST Logfile: Code:
ATTFilter scan result of Farbar Recovery Scan Tool (x64) Version:18-07-2015 01 Ran by Franziska at 2015-07-19 11:33:29 Running from C:\Users\Franziska\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2372557226-1662704196-739550879-500 - Administrator - Disabled) Franziska (S-1-5-21-2372557226-1662704196-739550879-1002 - Administrator - Enabled) => C:\Users\Franziska Gast (S-1-5-21-2372557226-1662704196-739550879-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2372557226-1662704196-739550879-1004 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 3D-Schach 2.0 (HKLM-x32\...\{CE057820-2732-11D4-A8C5-0050DA353A30}) (Version: - ) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated) AMD Catalyst Install Manager (HKLM\...\{665D4B18-EA91-BE16-3212-218C63F5DC4E}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.4.8.0 - AppEx Networks) AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6081 - AVG Technologies) AVG 2015 (Version: 15.0.4392 - AVG Technologies) Hidden AVG 2015 (Version: 15.0.6081 - AVG Technologies) Hidden AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.1.4.948 - AVG Technologies) Benutzerhandbücher (x32 Version: 3.0.0.3 - Lenovo) Hidden CEP - Color Enable Package (HKLM-x32\...\CEP - Colour Enable Packages_is1) (Version: 6.0b (beta) - Numenor, for ModTheSims2) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.28.52 - Conexant) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.) CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden Dependency Package Update (Version: 1.6.25.00 - Lenovo Inc.) Hidden Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden Dependency Package Update (Version: 1.6.36.00 - Lenovo Inc.) Hidden Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden Die Sims 2: Open For Business (HKLM-x32\...\{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}) (Version: - ) Die Sims 2: Wilde Campus-Jahre (HKLM-x32\...\{01521746-02A6-4A72-00BD-A285DF6B80C6}) (Version: - ) Die Sims™ 2 Apartment-Leben (HKLM-x32\...\{B6F5B704-06D3-4687-90F3-6195304AD755}) (Version: - Electronic Arts) Die Sims™ 2 Gute Reise (HKLM-x32\...\{F248ADFA-64E0-4b03-8A83-059078BED6A0}) (Version: - Electronic Arts) Die Sims™ 2 Haustiere (HKLM-x32\...\{4817189D-1785-4627-A33C-39FD90919300}) (Version: - ) Die Sims™ 2 Super Deluxe (HKLM-x32\...\{2D37F6AE-D201-4580-B91A-6BF9BB93ED2D}) (Version: - Electronic Arts) Die Sims™ 2 Vier Jahreszeiten (HKLM-x32\...\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}) (Version: - ) Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc) Druckerdeinstallation für EPSON BX305 Series (HKLM\...\EPSON BX305 Series) (Version: - SEIKO EPSON Corporation) Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.17 - Lenovo) Energy Manager (x32 Version: 1.5.0.17 - Lenovo) Hidden EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.134 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden Hightail for Lenovo (HKLM\...\{2F10E937-F6D7-4174-8AB9-B299E8FC5CEC}) (Version: 2.4.97.2857 - Hightail, Inc.) Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation) Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.36.00 - Lenovo Group Limited) Lenovo EasyCamera (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 6.0.1321.0_WHQL - Sonix) Lenovo FusionEngine (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.) Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo) Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2619 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 8.1.0.2619 - CyberLink Corp.) Hidden Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.2 - Lenovo) Lenovo PhoneCompanion (x32 Version: 1.2.0.2 - Lenovo) Hidden Lenovo Photo Master (HKLM-x32\...\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.) Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.36.1 - ELAN Microelectronic Corp.) Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.) Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden Lenovo SHAREit (HKLM-x32\...\Lenovo SHAREit_is1) (Version: 2.0.5.0 - Lenovo Group Limited) Lenovo Solution Center (HKLM\...\{2F45A217-E9C7-4984-B0AC-5BE31FF4712B}) (Version: 2.4.003.00 - Lenovo Group Limited) Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo) Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden Lenovo VeriFace Pro (HKLM\...\Lenovo VeriFace) (Version: 5.0.14.1061 - Lenovo) LibreOffice 4.3.4.1 (HKLM-x32\...\{7D983A32-F645-48AB-8E38-4ACD234F40BC}) (Version: 4.3.4.1 - The Document Foundation) Little Alchemy (HKU\S-1-5-21-2372557226-1662704196-739550879-1002\...\littlealchemy-c7de5d8adcfd810d98ec68069ab57bd9) (Version: 1.1.1 - Recloak) Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation) Metric Collection SDK 35 (x32 Version: 1.2.0001.00 - Lenovo Group Limited) Hidden Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0.3 - Mozilla) Nitro Pro 9 (HKLM\...\{4C32F7E8-A65F-4D3C-9153-9F3B57CB6872}) (Version: 9.0.5.9 - Nitro) OEM Application Profile (HKLM-x32\...\{8F92E0CF-620B-5C20-F292-59C93567B06D}) (Version: 1.00.0000 - Ihr Firmenname) OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.) REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.805.806.012214 - REALTEK Semiconductor Corp.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39058 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek) REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.20.243 - REALTEK Semiconductor Corp.) User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Windows-Treiberpaket - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-2372557226-1662704196-739550879-1002_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) ==================== Restore Points ========================= 27-06-2015 14:21:49 Windows Update 10-07-2015 21:32:10 Windows Update 11-07-2015 22:17:33 Installiert REALTEK PCIE Wireless LAN Driver 17-07-2015 12:28:57 Windows Update 18-07-2015 14:18:09 JRT Pre-Junkware Removal ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {059FF85A-96A7-4F30-A151-025BF8D10B64} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.) Task: {0C6938DC-5060-47BB-A244-9A5EB9241201} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-05-06] (Lenovo) Task: {12470315-4A24-4A46-978B-34FE10051EE7} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.) Task: {13842334-9265-4B05-9B11-BB24C42F8DC4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {2C817108-BF13-4F80-A785-9C358584854F} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] () Task: {307BD0C3-750A-40EF-A3F9-4288EDF529BD} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-17] (Adobe Systems Incorporated) Task: {35FDB4CA-8E11-4760-899E-1C6B82C96F61} - System32\Tasks\{808CE7D6-F887-46A4-8EAC-78FDCF14B029} => pcalua.exe -a E:\Setup.exe -d E:\ Task: {3F25A2CE-84E0-4B57-8CD6-D67BEBA2A6E4} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] () Task: {4E3DA8B7-52C1-44FF-8494-9303931DF0B1} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2014-05-06] (Lenovo) Task: {9523A3F0-9354-4859-AB26-D73344A8B4FA} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-03-06] () Task: {AE485BC0-FDB5-4ECA-9875-A86CD8B8DBAE} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-05-30] (Lenovo) Task: {B8114FCD-1409-421C-B736-0F019EE4C980} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Office2013\OFFICEICON.vbs [2013-06-03] () Task: {CF99EECC-97CB-45EF-836C-DEF2AFC71F69} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-06-27] (Microsoft Corporation) Task: {FA2727FE-C2D9-4520-B56D-97513B9D0DAE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2015-02-25 17:02 - 2015-07-12 23:02 - 01195920 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe 2014-04-18 22:12 - 2014-04-18 22:12 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2014-08-15 01:27 - 2014-01-22 14:04 - 00084992 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe 2014-08-15 02:13 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2014-08-15 02:18 - 2014-08-15 02:18 - 00067856 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe 2014-08-15 02:18 - 2014-08-15 02:18 - 00672016 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfDataStorageInterface.dll 2014-08-15 01:24 - 2010-10-26 06:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe 2014-03-26 12:50 - 2014-08-15 02:23 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll 2014-04-18 22:12 - 2014-04-18 22:12 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2014-08-15 02:18 - 2014-08-15 02:18 - 00815104 _____ () C:\Program Files\Lenovo PhoneCompanion\adb.exe 2015-07-19 11:27 - 2015-07-19 11:27 - 00852662 _____ () C:\Users\Franziska\Desktop\SecurityCheck.exe 2015-07-16 21:12 - 2015-07-13 23:55 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libglesv2.dll 2015-07-16 21:12 - 2015-07-13 23:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Windows:nlsPreferences AlternateDataStreams: C:\Users\Franziska\OneDrive:ms-properties ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDWFP => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VisualDiscovery => ""="service" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2372557226-1662704196-739550879-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg DNS Servers: 192.168.2.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\Run32: => "snp2uvc" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{AFBD7067-D2F6-4D3C-85B3-88A008C18967}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe FirewallRules: [{663A46B4-3414-4F48-A319-A422F7F43977}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe FirewallRules: [{AC2767B5-A536-457E-B67B-50A79A754C46}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{77D8B7D4-27EC-4437-A263-031784DFAC63}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{55376DCC-D006-4A28-AA16-B85FAC106F3E}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE FirewallRules: [{084835F4-19BE-43D6-BEB8-78503B45965C}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe FirewallRules: [{1F9F0BC2-0CF8-4AA0-974C-7BA40E438A95}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe FirewallRules: [{EE98E101-3C74-4620-AE02-3ADF1B6FA0CD}] => (Allow) LPort=55100 FirewallRules: [{0798E54B-7073-4647-8B2A-685DE6EC27D3}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe FirewallRules: [{0A8AAECB-B085-4693-8040-C11384793642}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{AB42E82B-FAD0-4683-B81E-CBA57E9CE423}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{DA68199A-F30C-4B34-B07D-55BC97A1320D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{BEE4CC4D-667E-4F8F-A4B9-C3191BCA1FC5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{7FADA343-E843-4133-A0D4-4BC7788FC0A5}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{518A6693-CCCD-4A4B-B9D9-01F793BF96AE}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{1C8585A3-15F7-4FF0-A443-C7D6A06A964A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe FirewallRules: [{D1DD6BFC-A9A7-4E39-BCE5-7A467EDBD48B}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe FirewallRules: [{D53DDE3E-9291-4381-BFBE-4405895AD9D4}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe FirewallRules: [{A02C96FC-1AC8-4B35-AB3B-3530569EF51D}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe FirewallRules: [{28841159-30B7-405D-9466-DA3C044D5BE5}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe FirewallRules: [{43A83805-ED93-4F21-B195-E5CB8AE4B9DD}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe FirewallRules: [{6929263B-9A5C-42DA-835C-976C8D9937FE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= Name: Dell 3333dn Description: Dell 3333dn Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: Dell Service: usbscan Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/19/2015 01:49:08 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest. Error: (07/19/2015 01:22:50 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest. Error: (07/18/2015 11:49:53 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest. Error: (07/18/2015 11:49:51 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest. Error: (07/18/2015 11:49:41 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest. Error: (07/18/2015 11:49:41 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest. Error: (07/18/2015 11:49:22 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest. Error: (07/18/2015 11:49:18 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest. Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest. Error: (07/18/2015 02:36:50 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm FRST64.exe, Version 13.7.2015.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: a10 Startzeit: 01d0c1565baf8bc1 Endzeit: 78 Anwendungspfad: C:\Users\Franziska\Desktop\FRST64.exe Berichts-ID: a610097f-2d49-11e5-8394-28d244c25993 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (07/18/2015 02:36:20 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm FRST64.exe, Version 13.7.2015.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 320 Startzeit: 01d0c15627a7966a Endzeit: 15 Anwendungspfad: C:\Users\Franziska\Desktop\FRST64.exe Berichts-ID: 93d18442-2d49-11e5-8394-28d244c25993 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: System errors: ============= Error: (07/18/2015 11:50:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: %%1275 Error: (07/18/2015 11:50:56 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\FRANZI~1\AppData\Local\Temp\ehdrv.sys Error: (07/18/2015 11:50:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: %%1275 Error: (07/18/2015 11:50:55 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\FRANZI~1\AppData\Local\Temp\ehdrv.sys Error: (07/18/2015 11:50:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet: %%1275 Error: (07/18/2015 11:50:55 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\FRANZI~1\AppData\Local\Temp\ehdrv.sys Error: (07/18/2015 11:38:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Error: (07/18/2015 11:38:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Error: (07/18/2015 11:38:13 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet. Modulpfad: C:\WINDOWS\system32\Rtlihvs.dll Error: (07/18/2015 11:36:30 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Microsoft Office: ========================= Error: (07/19/2015 01:49:08 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (07/19/2015 01:22:50 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestc:\users\franziska\desktop\esetsmartinstaller_deu.exe Error: (07/18/2015 11:49:53 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Franziska\Desktop\esetsmartinstaller_deu.exe Error: (07/18/2015 11:49:51 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Franziska\Desktop\esetsmartinstaller_deu.exe Error: (07/18/2015 11:49:41 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Franziska\Desktop\esetsmartinstaller_deu.exe Error: (07/18/2015 11:49:41 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Franziska\Desktop\esetsmartinstaller_deu.exe Error: (07/18/2015 11:49:22 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Franziska\Desktop\esetsmartinstaller_deu.exe Error: (07/18/2015 11:49:18 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifestC:\Users\Franziska\Downloads\esetsmartinstaller_deu.exe Error: (07/18/2015 02:36:50 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: FRST64.exe13.7.2015.1a1001d0c1565baf8bc178C:\Users\Franziska\Desktop\FRST64.exea610097f-2d49-11e5-8394-28d244c25993 Error: (07/18/2015 02:36:20 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: FRST64.exe13.7.2015.132001d0c15627a7966a15C:\Users\Franziska\Desktop\FRST64.exe93d18442-2d49-11e5-8394-28d244c25993 ==================== Memory info =========================== Processor: AMD A6-6310 APU with AMD Radeon R4 Graphics Percentage of memory in use: 36% Total physical RAM: 7128.26 MB Available physical RAM: 4543.01 MB Total Virtual: 8280.26 MB Available Virtual: 5375.44 MB ==================== Drives ================================ Drive c: (Windows8_OS) (Fixed) (Total:890.1 GB) (Free:831.82 GB) NTFS ==>[system with boot components (obtained from reading drive)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:23.14 GB) NTFS Drive f: () (Removable) (Total:3.68 GB) (Free:0.14 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: E07FA830) Partition: GPT Partition Type. ======================================================== Disk: 1 (Size: 3.7 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End of log ============================ |
19.07.2015, 11:36 | #14 |
/// TB-Ausbilder | BKA-Trojaner aber keine Sperrungen Servus,
Danach berichten, wie es mit dem Startmenü aussieht. |
19.07.2015, 14:05 | #15 |
| BKA-Trojaner aber keine Sperrungen Das Programm ist fertig, hat auch heruntergefahren. Hab den Laptop dann wieder hoch gefahren aber es zeigt mir leider immer noch 'Verknüpfungsproblem. Die Laufwerk-oder Netzwerkverbindung, auf die sich die Verknüpfung "Start Menu.Ink" bezieht, ist nicht verfügbar. Stellen sie sicher, dass der Datenträger richtig eingelegt bzw. die Netzwerkressource verfügbar ist, und wiederholen sie den Vorgang.' an, wenn ich drauf klicke. Das Symbol hat sich auch nicht verändert |
Themen zu BKA-Trojaner aber keine Sperrungen |
antimalware, anzeige, browser, computer, ergebnis, flash player, gesperrt, hintergrund, laptop, malwarebytes, neustart, programm, pup.optional.apntoolbar.a, pup.optional.homepagehelper.a, pup.optional.visualdiscovery.a, pup.optional.websearch.a, pup.optional.winsock.hijackboot, rechtsklick, schließen, windows |