Munchkin86 | 13.11.2013 09:53 | Windows 7: Virenfund per Malwarebytes, PC ab und zu langsamer (Browser) Hallo alle miteinander,
da ich schon ein oder zweimal hier im Forum gepostet habe, da ich den PC meiner Eltern bereinigen lassen musste (Polizei-Trojaner), muss ich mich jetzt selbst auch mal melden.
Ich sorge eigentlich immer dafür, dass mein PC sich auf dem neusten Stand befindet was Sicherheitsupdates und ähnliches betrifft.
Irgendwie hat sich aber jetzt doch etwas eingeschlichen.
Ich weiß nicht, ob es an dem Virenbefall liegt oder woran, dass mein PC bzw. eher der Aufbau von Internetseiten manchmal länger dauert, das es dazu kommt, dass es immer eine Zeit brauch, bis eine Seite geladen wird. Ich gehe aber mal davon aus, dass es eher daran liegt, dass ich meine Wohnung gewechselst habe und es vielleicht hier mit dem Internet Probleme gibt.
Es kommt nämlich immer mal wieder vor, dass Online Armor meldet, dass eine neue Internetverbindung besteht und nachfragt, ob diese sicher ist, obwohl es sich um die zuvor ausgewählte handelt. Ich bekomme diese Frage auch immer, nachdem ich den PC ausgeschaltet habe und dann am nächsten Morgen anschalte. Ich werde im nachfolgenden dann auch mal einen Screenshot davon erstellen.
Weil eigentlich sollte sich ja die IP-Adresse nicht ändern, der Router wird ja nicht neugestartet.
Ich habe beim letzten Voll-Scan von Malwarebytes dann einige Viren entdeckt, handelt sich dabei nicht um die üblichen Tracking-Cookies oder ähnliches, sondern anscheinend sind normal harmlose Programme befallen worden, wieso auch immer.
Mein System:
Antivirus-Software: Emsisoft Anti-Malware Premium 8.1.0.19
Firewall: Emsisoft Online-Armor Freeware 7.0.0.1866
Antimalware: Malwarebytes Antimalware 1.75.0.1300
File-Hippo Update-Checker 1.040
Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-11-2013 01
Ran by Yannick at 2013-11-11 05:10:23
Running from C:\Users\Yannick\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Emsisoft Anti-Malware (Enabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
FW: Online Armor Firewall (Enabled) {BD3F5FCA-866B-1E2E-0A68-58900A751EA1}
==================== Installed Programs ======================
Adobe Acrobat XI Pro (x32 Version: 11.0.05)
Adobe After Effects CC (x32 Version: 12.1)
Adobe AIR (x32 Version: 3.9.0.1030)
Adobe Audition CC (x32 Version: 6.0)
Adobe Creative Cloud (x32 Version: 2.0.2.189)
Adobe Download Assistant (x32 Version: 1.2.5)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Help Manager (x32 Version: 4.0.244)
Adobe Media Player (x32 Version: 1.8)
Adobe PDF iFilter 11 for 64-bit platforms (Version: 11.0.00)
Adobe Photoshop CS6 (x32 Version: 13.0)
Adobe Premiere Pro CC (x32 Version: 7.0.0)
Adobe Shockwave Player 12.0 (x32 Version: 12.0.2.122)
Adobe Story (x32 Version: 1.0.571)
AIDA64 Extreme Edition v3.00 (x32 Version: 3.00)
Amazon Kindle (x32)
AMD Accelerated Video Transcoding (Version: 2.00.0002)
AMD APP SDK Runtime (Version: 10.0.898.1)
AMD Catalyst Install Manager (Version: 3.0.868.0)
android converter (x32 Version: 1.11.0715)
AnyDVD (x32 Version: 7.3.1.0)
Anzeige am Bildschirm (Version: 7.12.21)
Apple Application Support (x32 Version: 2.3.6)
Apple Mobile Device Support (Version: 7.0.0.117)
Apple Software Update (x32 Version: 2.1.3.127)
Ask Toolbar (x32 Version: 12.7.0.2279)
ATI Uninstaller (Version: 8.951-120308a-137408C-Lenovo)
Audible Download Manager (x32 Version: 6.6.0.15)
AudibleManager (x32 Version: 1998732526.48.56.13576866)
AVS Video Converter 8 (x32 Version: 8.3.2.533)
BisonCam Twain Pro (x32 Version: 1.5.4.7)
bl (x32 Version: 1.0.0)
Blender (Version: 2.68a)
BlueStacks App Player (x32 Version: 0.7.15.909)
BlueStacks Notification Center (x32 Version: 0.7.15.909)
Bonjour (Version: 3.0.0.10)
CameraHelperMsi (x32 Version: 13.31.1038.0)
Camfrog Video Chat 6.5 (x32 Version: 6.5.300)
Camtasia Studio 8 (x32 Version: 8.0.4.1060)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center (x32 Version: 2012.0309.43.976)
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0309.43.976)
Catalyst Control Center InstallProxy (x32 Version: 2012.0309.43.976)
Catalyst Control Center Localization All (x32 Version: 2012.0309.43.976)
Catalyst Control Center Profiles Mobile (x32 Version: 2012.0309.43.976)
CCC Help Chinese Standard (x32 Version: 2012.0309.0042.976)
CCC Help Chinese Traditional (x32 Version: 2012.0309.0042.976)
CCC Help Czech (x32 Version: 2012.0309.0042.976)
CCC Help Danish (x32 Version: 2012.0309.0042.976)
CCC Help Dutch (x32 Version: 2012.0309.0042.976)
CCC Help English (x32 Version: 2012.0309.0042.976)
CCC Help Finnish (x32 Version: 2012.0309.0042.976)
CCC Help French (x32 Version: 2012.0309.0042.976)
CCC Help German (x32 Version: 2012.0309.0042.976)
CCC Help Greek (x32 Version: 2012.0309.0042.976)
CCC Help Hungarian (x32 Version: 2012.0309.0042.976)
CCC Help Italian (x32 Version: 2012.0309.0042.976)
CCC Help Japanese (x32 Version: 2012.0309.0042.976)
CCC Help Korean (x32 Version: 2012.0309.0042.976)
CCC Help Norwegian (x32 Version: 2012.0309.0042.976)
CCC Help Polish (x32 Version: 2012.0309.0042.976)
CCC Help Portuguese (x32 Version: 2012.0309.0042.976)
CCC Help Russian (x32 Version: 2012.0309.0042.976)
CCC Help Spanish (x32 Version: 2012.0309.0042.976)
CCC Help Swedish (x32 Version: 2012.0309.0042.976)
CCC Help Thai (x32 Version: 2012.0309.0042.976)
CCC Help Turkish (x32 Version: 2012.0309.0042.976)
ccc-utility64 (Version: 2012.0309.43.976)
CCleaner (Version: 4.07)
Chinese Traditional Fonts Support For Adobe Reader X (x32 Version: 10.0.0)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.00495)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.00495)
Citavi (x32 Version: 3.4.0.2)
CloneDVD2 (x32 Version: 2.9.3.0)
Color Efex Pro 3.0 Standard (x32 Version: 3.1.0.9)
concept/design onlineTV 8 (x32 Version: 8.5.0.10)
Conexant HD Audio (Version: 8.32.27.0)
ContainerEx Decrypter (HKCU Version: 1.0.1.57)
Copy Handler 1.32Final (Version: 1.32Final)
CPUID CPU-Z 1.67
CVE-2012-1889
CyberLink PowerDVD 13 (x32 Version: 13.0.3105.58)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition
Defraggler (Version: 2.16)
DivX-Setup (x32 Version: 2.6.1.87)
Dropbox (HKCU Version: 2.0.22)
DVDFab 9.0.7.2 (18/10/2013) (x32)
EASEUS Partition Master 9.1.1 Home Edition (x32)
Emsisoft Anti-Malware (x32 Version: 7.0)
Energie-Manager (x32 Version: 6.62.10)
EPSON Scan (x32)
erLT (x32 Version: 1.20.138.34)
EvilLyrics (x32)
Exifer (x32)
f.lux (HKCU)
Facebook Video Calling 1.0.0.8953 (x32 Version: 1.0.8953)
FastStone Capture 5.3 (x32 Version: 5.3)
FastStone Photo Resizer 3.1 (x32 Version: 3.1)
FileHippo.com Update Checker (x32)
Files Suite v1.2 (x32)
Fotogalerie (x32 Version: 16.4.3508.0205)
FRANZIS onlineTV 8 (x32 Version: FRANZIS onlineTV 8)
Free Audio Converter version 5.0.26.628 (x32 Version: 5.0.26.628)
Free YouTube to MP3 Converter version 3.12.13.925 (x32 Version: 3.12.13.925)
GEAR driver installer 4.020 (x32 Version: 4.020.5)
Ghostery IE Plugin (x32 Version: 2.5.2.0)
Google Chrome (HKCU Version: 30.0.1599.101)
Google Update Helper (x32 Version: 1.3.21.99)
HandBrake 0.9.9.1 (x32 Version: 0.9.9.1)
Hex Workshop v6.7 (Version: 6.7.3.5308)
HTC Home Apis (x32 Version: 3.0.620.0)
ImgBurn (x32 Version: 2.5.8.0)
Integrated Camera Driver Installer Package Ver.1.1.0.1147 (x32 Version: 1.1.0.1147)
Intel PROSet Wireless (x32)
Intel(R) Display Audio Driver (x32 Version: 6.14.00.3074)
Intel(R) Identity Protection Technology 1.1.2.0 (x32 Version: 1.1.2.0)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144)
Intel(R) PROSet/Wireless WiFi-Software (Version: 14.03.0000)
Intel(R) Wireless Display
Intel(R) Wireless Display (x32 Version: 2.0.31.0)
IrfanView (remove only) (x32 Version: 4.36)
iTunes (Version: 11.1.3.8)
Java 7 Update 40 (64-bit) (Version: 7.0.400)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
JDownloader 0.9 (x32 Version: 0.9)
JDownloader 2 (x32 Version: 2)
KC Softwares SUMo (x32 Version: 3.7.1.204)
KKMAN (x32 Version: 3.2)
Lenovo Auto Scroll Utility (Version: 1.11)
Lenovo Patch Utility (x32 Version: 1.3.2.6)
Lenovo Patch Utility 64 bit (Version: 1.3.2.6)
Lenovo Power Management Driver (Version: 1.67.03.13)
Lenovo System Interface Driver (Version: 1.05)
Lenovo System Update (x32 Version: 5.03.0005)
LINE (x32 Version: 3.2.1.83)
LingoPad 2.6 (Build 360) (x32 Version: 2.6)
Logitech Webcam-Software (x32 Version: 2.31)
LWS Facebook (x32 Version: 13.31.1038.0)
LWS Gallery (x32 Version: 13.31.1038.0)
LWS Help_main (x32 Version: 13.31.1044.0)
LWS Launcher (x32 Version: 13.31.1038.0)
LWS Motion Detection (x32 Version: 13.30.1395.0)
LWS Pictures And Video (x32 Version: 13.31.1038.0)
LWS Twitter (x32 Version: 13.30.1346.0)
LWS Video Mask Maker (x32 Version: 13.30.1379.0)
LWS VideoEffects (Version: 13.30.1379.0)
LWS Webcam Software (x32 Version: 13.31.1038.0)
LWS WLM Plugin (x32 Version: 1.30.1201.0)
LWS YouTube Plugin (x32 Version: 13.31.1038.0)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
MediaInfo 0.7.64 (Version: 0.7.64)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.88.0)
Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SkyDrive (HKCU Version: 16.4.6013.0910)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft VC80 Support DLLs (x32 Version: 1.0.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Xbox 360 Accessories 1.2 (Version: 1.20.146.0)
Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1)
Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1)
Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053)
Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000)
MiniTool Partition Wizard Home Edition 7.0 (x32)
MKVToolNix 6.3.0 (x32 Version: 6.3.0)
Movie Maker (x32 Version: 16.4.3508.0205)
Mozilla Firefox 25.0 (x86 de) (x32 Version: 25.0)
Mozilla Maintenance Service (x32 Version: 25.0)
Mp3tag v2.58 (x32 Version: v2.58)
MSI to redistribute MS VS2005 CRT libraries (x32 Version: 8.0.50727.42)
MSVC80_x64_v2 (Version: 1.0.3.0)
MSVC80_x86_v2 (x32 Version: 1.0.3.0)
MSVC90_x64 (Version: 1.0.1.2)
MSVC90_x86 (x32 Version: 1.0.1.2)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT Redists (Version: 1.0)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
MSXML 4.0 SP2 (KB925672) (x32 Version: 4.20.9839.0)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0)
MyMDb 3.6 (x32)
MysticThumbs (Version: 1.9.8)
Nero Burning ROM (x32 Version: 12.5.5001)
Nero Burning ROM Help (CHM) (x32 Version: 12.0.3000)
Nero BurningROM 10 Help (CHM) (x32 Version: 10.5.10100)
Nero BurningROM 12 (x32 Version: 12.5.00900)
Nero Control Center 10 (x32 Version: 10.2.10600.0.6)
Nero ControlCenter (x32 Version: 11.0.15600)
Nero ControlCenter Help (CHM) (x32 Version: 12.0.12000)
Nero Core Components (x32 Version: 11.0.20200)
Nero Core Components 10 (x32 Version: 2.0.17400.8.2)
Nero SharedVideoCodecs (x32 Version: 1.0.12100.2.0)
No23 Recorder (x32 Version: 2.1.0.3)
NVIDIA PhysX (x32 Version: 9.09.0720)
Online Armor 6.0 (x32 Version: 6.0)
Paint.NET v3.5.11 (Version: 3.61.0)
Paragon Disk Wiper™ 10 Personal (x32 Version: 90.00.0003)
PC Inspector File Recovery (x32 Version: 4.0)
PDF Settings CS6 (x32 Version: 11.0)
PDF24 Creator 5.0.0 (x32)
ph (x32 Version: 1.0.0)
Photo Common (x32 Version: 16.4.3508.0205)
Photo Gallery (x32 Version: 16.4.3508.0205)
PhotoScape (x32)
Picasa 3 (x32 Version: 3.9)
PL-2303 USB-to-Serial (x32 Version: 1.2.10)
PlagiarismFinder 2.1 (x32 Version: 2.1.18)
PowerXpressHybrid (x32 Version: 1.00.0000)
Prerequisite installer (x32 Version: 12.0.0003)
PX Profile Update (x32 Version: 1.00.1.)
PxMergeModule (x32 Version: 1.00.0000)
Python 2.7.3 (64-bit) (Version: 2.7.3150)
QuickTime (x32 Version: 7.74.80.86)
RAD Video Tools (x32)
Rainlendar2 (remove only) (x32)
RapidBoot (Version: 1.11)
Realtek Ethernet Controller Driver (x32 Version: 7.37.1229.2010)
Recuva (Version: 1.48)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.1.28.0)
RICOH_Media_Driver_v2.14.18.01 (x32 Version: 2.14.18.01)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.16.0)
SecurityKISS Tunnel v0.3.0
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition
Shutdown Timer (Version: 3.1)
Shutdown Timer (Version: 3.3.4)
SimplyGoodPictures (x32 Version: 1.0.12.127)
Skype Web Plugin (x32 Version: 2.3.12417.17599)
Skype™ 6.10 (x32 Version: 6.10.104)
Songr (x32 Version: 2.0.2189)
SopCast 3.5.0 (x32 Version: 3.5.0)
Steam (x32 Version: 1.0.0.0)
StreamTransport version: 1.0.2.2171 (x32)
SubtitleCreator (x32 Version: V2.3rc1)
swMSM (x32 Version: 12.0.0.1)
System Explorer 3.8.6 (x32)
System Requirements Lab for Intel (x32 Version: 4.5.3.0)
TeamViewer 8 (x32 Version: 8.0.19617)
The Panorama Factory V5 m32 Edition (x32 Version: 5.3.2800)
ThinkPad Bluetooth with Enhanced Data Rate Software (Version: 6.4.0.2900)
ThinkPad UltraNav Driver (Version: 16.2.19.9)
ThinkVantage Communications Utility (Version: 2.11.0.0)
ThinkVantage System für aktiven Festplattenschutz (Version: 1.77.0.9)
Torrent Stream 2.0.4.1 (HKCU Version: 2.0.4.1)
UltraISO Premium V9.52 (x32)
Unlocker 1.9.1-x64 (Version: 1.9.1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3)
Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition
Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition
Update for Microsoft Word 2010 (KB2827323) 64-Bit Edition
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
Veetle TV (x32 Version: 0.9.19)
Vegas Pro 11.0 (64-bit) (Version: 11.0.595)
VirtualCloneDrive (x32)
VLC media player 2.1.0 (Version: 2.1.0)
V-Ray for Rhinoceros (x32 Version: 01.05.29)
Vuze (Version: 5.1.0.0)
Wenlin 3.4.1 (x32 Version: 3.4.1)
Winamp (x32 Version: 5.65 )
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1)
Windows Live Communications Platform (x32 Version: 16.4.3508.0205)
Windows Live Essentials (x32 Version: 16.4.3508.0205)
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0)
Windows Live Installer (x32 Version: 16.4.3508.0205)
Windows Live Photo Common (x32 Version: 16.4.3508.0205)
Windows Live PIMT Platform (x32 Version: 16.4.3508.0205)
Windows Live SOXE (x32 Version: 16.4.3508.0205)
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205)
Windows Live UX Platform (x32 Version: 16.4.3508.0205)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205)
Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8)
WinPcap 4.1.2 (x32 Version: 4.1.0.2001)
WinRAR 5.00 (64-Bit) (Version: 5.00.0)
World of Tanks (x32)
WOT for Internet Explorer (x32 Version: 11.7.20.0)
Yahoo! Messenger (x32)
Youtube Downloader HD v. 2.9.6 (x32)
==================== Restore Points =========================
07-11-2013 20:35:52 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2009-07-14 10:34 - 2013-08-30 02:49 - 00004534 ___RA C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 fr.a2dfp.net
127.0.0.1 m.fr.a2dfp.net
127.0.0.1 ad.a8.net
127.0.0.1 asy.a8ww.net
127.0.0.1 abcstats.com
127.0.0.1 a.abv.bg
127.0.0.1 adserver.abv.bg
127.0.0.1 adv.abv.bg
127.0.0.1 bimg.abv.bg
127.0.0.1 ca.abv.bg
127.0.0.1 www2.a-counter.kiev.ua
127.0.0.1 track.acclaimnetwork.com
127.0.0.1 accuserveadsystem.com
127.0.0.1 www.accuserveadsystem.com
127.0.0.1 achmedia.com
127.0.0.1 csh.actiondesk.com
127.0.0.1 www.activemeter.com #[Tracking.Cookie]
127.0.0.1 ads.activepower.net
127.0.0.1 app.activetrail.com
127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
127.0.0.1 cms.ad2click.nl
127.0.0.1 ad2games.com
127.0.0.1 ads.ad2games.com
127.0.0.1 content.ad20.net
127.0.0.1 core.ad20.net
127.0.0.1 banner.ad.nu
127.0.0.1 cl21.v4.adaction.se
127.0.0.1 adadvisor.net
127.0.0.1 tag1.adaptiveads.com
There are 15457 more lines.
==================== Scheduled Tasks (whitelisted) =============
Task: {02C4CAAE-516F-4A06-BC09-0830FEAFAA5F} - System32\Tasks\{9F9FACBE-E9B6-425B-8E81-888ED9145D42} => Firefox.exe hxxp://ui.skype.com/ui/0/6.2.0.106/de/go/help.faq.installer?source=lightinstaller&LastError=1603
Task: {0560A647-4E4E-4D92-BDD4-A771E706B6CF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-10] (Adobe Systems Incorporated)
Task: {15EEA1F3-F4B8-49FD-8776-7FADF31D960E} - System32\Tasks\{A6B965FC-DF15-4470-8F0D-6525AE32C78C} => Firefox.exe hxxp://ui.skype.com/ui/0/6.3.0.105/de/abandoninstall?page=tsProgressBar
Task: {1AAFCBFA-DDA1-4FE5-9E3D-2731B833ED47} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2011-01-16] (Microsoft Corporation)
Task: {1D49D28D-1E58-40B8-A981-29752335A28D} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-874405144-3379903360-3449110331-1000Core => C:\Users\Yannick\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {1E87F126-BB05-4843-A251-A67C06E0A83F} - System32\Tasks\{2B1B0D72-0712-4225-B9AF-D3D1CFC49EC3} => Firefox.exe hxxp://ui.skype.com/ui/0/6.5.0.158/de/go/help.faq.installer?LastError=1603
Task: {33298997-BD10-4B37-A268-EBCD502A740D} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe
Task: {3C58DF08-5B75-4D88-A286-05C0861C974F} - System32\Tasks\Core Temp Autostart Yannick => C:\Program Files\Core Temp\Core Temp.exe
Task: {43D885EE-F73E-4733-8DF8-EE65FE5D1BFB} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe
Task: {4F2B2C8A-60C5-4CE6-8A2C-DC59D662EDCD} - System32\Tasks\{CEDEC26B-A410-4F41-A1B3-63409FE63871} => Firefox.exe hxxp://ui.skype.com/ui/0/5.8.0.156/de/go/help.faq.installer?LastError=1603
Task: {4FFFC899-3430-480E-A035-009BC8F45EE8} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2013-09-17] ()
Task: {53323C08-242E-49B0-97B7-583A28C96470} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {587690A9-8139-40E5-B6BA-29E3B42A7A79} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-874405144-3379903360-3449110331-1000Core => C:\Users\Yannick\AppData\Local\Google\Update\GoogleUpdate.exe [2013-10-03] (Google Inc.)
Task: {58892C7C-3672-4954-8DCD-60BF2046EA38} - System32\Tasks\{22052FE8-E454-4E79-81B1-218C1CD92C05} => Firefox.exe hxxp://ui.skype.com/ui/0/6.2.0.106/de/go/help.faq.installer?source=lightinstaller&LastError=1603
Task: {5A1403F4-A650-4BB4-B7A2-E0D0507E8D70} - System32\Tasks\{993DDF8C-290B-4C38-B37C-4AA501B714A1} => Firefox.exe hxxp://ui.skype.com/ui/0/6.3.0.105/de/abandoninstall?source=lightinstaller&page=tsMain
Task: {5B5C6098-9507-4AF4-B7A5-D87B34EB28C3} - System32\Tasks\{24B348C6-E115-4583-B3E2-7A3C1BF915F2} => Firefox.exe hxxp://ui.skype.com/ui/0/5.8.0.156/de/go/help.faq.installer?LastError=1603
Task: {5BD90107-2C90-4E6A-926E-C828583984BF} - System32\Tasks\{0C805CBF-8A97-4ED2-A166-27EE7062097D} => Firefox.exe hxxp://ui.skype.com/ui/0/6.3.0.105/de/abandoninstall?page=tsProgressBar
Task: {690C5907-DD44-4D17-83BB-585D890916D8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-22] (Piriform Ltd)
Task: {6DE5FBE3-E878-46CE-9F50-D30FF2C09004} - System32\Tasks\{6730DC81-064F-4DB5-9100-99EFF6EB00A3} => Firefox.exe hxxp://ui.skype.com/ui/0/6.2.0.106/de/go/help.faq.installer?LastError=1603
Task: {70F0C1EF-3567-4A85-B987-BD4A6DBCCC3A} - System32\Tasks\{D7140019-0A74-4B6D-A543-E6BDC5F43A2C} => Firefox.exe hxxp://ui.skype.com/ui/0/5.9.0.114/de/go/help.faq.installer?LastError=1603
Task: {724E3505-2E07-4BD4-9E7C-6A7ECB020F8E} - System32\Tasks\{E20AA358-C065-42EB-BC33-C7C740D1AB5A} => Firefox.exe hxxp://ui.skype.com/ui/0/5.8.0.158/de/go/help.faq.installer?LastError=1603
Task: {773F61C9-32D8-4014-82A8-59B2F916CAEE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {780F478A-4B99-4D08-A595-4F54D79A585A} - System32\Tasks\{49708782-3445-484D-B4E1-D602CBCBF090} => Firefox.exe hxxp://ui.skype.com/ui/0/6.3.0.105/de/go/help.faq.installer?LastError=1603
Task: {7CF255D7-F4A1-45A5-AA85-617412BFCF2F} - System32\Tasks\AdobeAAMUpdater-1.0-Aragorn-Yannick => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2013-06-03] (Adobe Systems Incorporated)
Task: {7E330DBC-3335-4EC3-864F-5C7EB2E40C01} - System32\Tasks\{C7095D96-E195-4638-A099-8F26889D1FBC} => Firefox.exe hxxp://ui.skype.com/ui/0/6.1.60.129/de/abandoninstall?page=tsMain
Task: {7F46F27E-5DAC-4F9D-8487-CBD71157F20A} - System32\Tasks\{2BBE02A8-6D08-45BA-A9FD-E69B165B7CFA} => Firefox.exe hxxp://ui.skype.com/ui/0/6.2.0.106/de/go/help.faq.installer?LastError=1603
Task: {971577B6-02E3-43CA-B61D-88705118987D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-874405144-3379903360-3449110331-1000UA => C:\Users\Yannick\AppData\Local\Google\Update\GoogleUpdate.exe [2013-10-03] (Google Inc.)
Task: {97CB9276-DAE5-4057-A33F-5F263700C197} - System32\Tasks\{338A9749-A748-416F-AFB1-CDFC28109E51} => Firefox.exe hxxp://ui.skype.com/ui/0/5.9.0.114/de/go/help.faq.installer?source=lightinstaller&LastError=1603
Task: {99011A73-66C7-4ED9-BB1A-8B622DD005D6} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-874405144-3379903360-3449110331-1000UA => C:\Users\Yannick\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {9DD04FE1-D60D-4DEF-BAD2-A029CF159784} - System32\Tasks\{7F56149E-AE49-4702-B430-D83D89AE337C} => Firefox.exe hxxp://ui.skype.com/ui/0/6.2.0.106/de/go/help.faq.installer?LastError=1603
Task: {C9062027-F8A0-4466-A6EF-E9DF941EECBD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {CBC70020-3281-4E8A-B443-45FD8A143294} - System32\Tasks\{B40B7196-DB55-4073-8F07-7C2DA69FFE38} => Firefox.exe hxxp://ui.skype.com/ui/0/6.5.0.158/de/go/help.faq.installer?LastError=1603
Task: {E2C9ED99-2C0B-4DD7-93CC-BDC894FAE981} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-874405144-3379903360-3449110331-1000Core.job => C:\Users\Yannick\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-874405144-3379903360-3449110331-1000UA.job => C:\Users\Yannick\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-874405144-3379903360-3449110331-1000Core.job => C:\Users\Yannick\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-874405144-3379903360-3449110331-1000UA.job => C:\Users\Yannick\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-06-20 00:45 - 2013-06-20 00:45 - 03317616 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll
2011-08-06 06:22 - 2013-08-01 06:02 - 00117248 ____N () C:\Program Files (x86)\ThinkPad\Utilities\GR\PWMRT64V.DLL
2012-02-17 15:37 - 2010-03-07 19:05 - 00290816 _____ () C:\Program Files\Copy Handler\chext64.dll
2010-07-15 12:44 - 2010-07-15 12:44 - 00020032 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll
2013-04-04 01:09 - 2013-04-04 01:09 - 04300432 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2011-08-06 05:42 - 2011-03-25 23:28 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-06-21 14:06 - 2011-06-21 14:06 - 00249344 _____ () C:\Program Files (x86)\HTC Home\Home.Base.dll
2011-06-20 21:12 - 2011-06-20 21:12 - 00011776 _____ () C:\Program Files (x86)\HTC Home\Home.Packaging.dll
2011-06-21 14:06 - 2011-06-22 16:15 - 00016896 _____ () C:\Program Files (x86)\HTC Home\Weather.Base.dll
2011-06-20 21:12 - 2011-06-22 16:15 - 00018432 _____ () C:\Program Files (x86)\HTC Home\Extras\Weather\MSN.dll
2011-06-20 16:49 - 2011-06-20 16:49 - 04660736 _____ () C:\Program Files (x86)\HTC Home\UIFramework.Weather.dll
2012-05-17 03:12 - 2012-05-17 03:12 - 00179200 _____ () C:\Program Files\Rainlendar2\lua52.dll
2013-03-12 05:11 - 2013-03-12 05:11 - 00334432 _____ () C:\Program Files\Rainlendar2\plugins\iCalendarPlugin.dll
2012-06-17 21:21 - 2012-06-17 21:21 - 00015360 _____ () C:\Program Files\Rainlendar2\lfs.dll
2012-08-04 03:53 - 2012-08-04 03:53 - 00062968 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
2011-06-25 04:56 - 2011-06-25 04:56 - 00087328 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2011-06-25 04:56 - 2011-06-25 04:56 - 01241888 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-03-14 04:48 - 2013-03-14 04:48 - 24978944 _____ () C:\Users\Yannick\AppData\Roaming\Dropbox\bin\libcef.dll
2012-09-23 20:43 - 2012-09-23 20:43 - 00010240 _____ () C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\locale\de_de\acrotray.deu
2011-06-12 21:09 - 2011-06-12 21:09 - 00038400 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\_socket.pyd
2011-06-12 21:09 - 2011-06-12 21:09 - 00720896 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\_ssl.pyd
2011-07-16 03:37 - 2011-07-16 03:37 - 00981504 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\wx._core_.pyd
2011-07-16 03:38 - 2011-07-16 03:38 - 00746496 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\wx._gdi_.pyd
2011-07-16 03:38 - 2011-07-16 03:38 - 00670720 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\wx._windows_.pyd
2011-07-16 03:38 - 2011-07-16 03:38 - 00966144 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\wx._controls_.pyd
2011-07-16 03:38 - 2011-07-16 03:38 - 00674816 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\wx._misc_.pyd
2011-06-12 21:06 - 2011-06-12 21:06 - 00287232 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\_hashlib.pyd
2011-01-19 05:56 - 2011-01-19 05:56 - 00334336 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\M2Crypto.__m2crypto.pyd
2011-06-12 21:06 - 2011-06-12 21:06 - 00011776 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\select.pyd
2011-06-12 21:06 - 2011-06-12 21:06 - 00152576 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\pyexpat.pyd
2012-02-08 00:37 - 2012-02-08 00:37 - 00098816 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\win32api.pyd
2012-02-08 00:35 - 2012-02-08 00:35 - 00110080 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\pywintypes27.dll
2012-02-08 00:38 - 2012-02-08 00:38 - 00358912 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\pythoncom27.dll
2012-02-08 00:36 - 2012-02-08 00:36 - 00111616 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\win32file.pyd
2012-02-08 00:36 - 2012-02-08 00:36 - 00024064 _____ () C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\lib\win32pdh.pyd
2013-11-03 13:06 - 2013-11-03 13:07 - 03368048 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2012-01-08 16:55 - 2013-01-29 02:04 - 00122880 _____ () C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox\components\CitaviPickerCommunication.dll
2013-10-10 01:55 - 2013-10-10 01:55 - 16233864 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
==================== Faulty Device Manager Devices =============
Name: Microsoft-Adapter für Miniports virtueller WiFis
Description: Microsoft-Adapter für Miniports virtueller WiFis
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/11/2013 03:06:00 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: vlc.exe, Version: 2.1.0.0, Zeitstempel: 0x52432b75
Name des fehlerhaften Moduls: vlc.exe, Version: 2.1.0.0, Zeitstempel: 0x52432b75
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000019b4
ID des fehlerhaften Prozesses: 0x16084
Startzeit der fehlerhaften Anwendung: 0xvlc.exe0
Pfad der fehlerhaften Anwendung: vlc.exe1
Pfad des fehlerhaften Moduls: vlc.exe2
Berichtskennung: vlc.exe3
Error: (11/09/2013 03:52:41 PM) (Source: MsiInstaller) (User: NT-AUTORITÄT)
Description: Produkt: Ask Toolbar -- Fehler 1406. Wert ApnTBMon konnte nicht unter den Schlüssel \SOFTWARE\Microsoft\Windows\CurrentVersion\Run geschrieben werden. Systemfehler . Überprüfen Sie, ob Sie ausreichende Zugriffsrechte auf diesen Schlüssel besitzen, oder setzen Sie sich mit dem Supportpersonal in Verbindung.
Error: (11/09/2013 03:48:50 PM) (Source: BstHdAndroidSvc) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (11/08/2013 01:12:42 PM) (Source: BstHdAndroidSvc) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (11/08/2013 01:06:27 PM) (Source: Application Hang) (User: )
Description: Programm a2start.exe, Version 8.1.0.19 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 6c2c
Startzeit: 01cedc36fed6ceb5
Endzeit: 79
Anwendungspfad: c:\program files (x86)\emsisoft anti-malware\a2start.exe
Berichts-ID: 837467e1-4833-11e3-b0ea-f0def1613e29
Error: (11/08/2013 11:27:59 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3089
Error: (11/08/2013 11:27:59 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3089
Error: (11/08/2013 11:27:59 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (11/08/2013 11:27:58 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2075
Error: (11/08/2013 11:27:58 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2075
System errors:
=============
Error: (11/11/2013 03:48:41 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535
Error: (11/11/2013 03:48:41 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535
Error: (11/11/2013 03:48:41 AM) (Source: PNRPSvc) (User: )
Description: 0x80630801
Error: (11/11/2013 03:48:32 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535
Error: (11/11/2013 03:48:32 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535
Error: (11/11/2013 03:48:32 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535
Error: (11/11/2013 03:48:32 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535
Error: (11/11/2013 03:48:32 AM) (Source: PNRPSvc) (User: )
Description: 0x80630801
Error: (11/11/2013 03:48:32 AM) (Source: PNRPSvc) (User: )
Description: 0x80630801
Error: (11/11/2013 03:47:12 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535
Microsoft Office Sessions:
=========================
Error: (11/11/2013 03:06:00 AM) (Source: Application Error)(User: )
Description: vlc.exe2.1.0.052432b75vlc.exe2.1.0.052432b75c000000500000000000019b41608401cede47d3234a22C:\Program Files\VideoLAN\VLC\vlc.exeC:\Program Files\VideoLAN\VLC\vlc.exe2294baf5-4a3b-11e3-ae5b-f0def1613e29
Error: (11/09/2013 03:52:41 PM) (Source: MsiInstaller)(User: NT-AUTORITÄT)
Description: Produkt: Ask Toolbar -- Fehler 1406. Wert ApnTBMon konnte nicht unter den Schlüssel \SOFTWARE\Microsoft\Windows\CurrentVersion\Run geschrieben werden. Systemfehler . Überprüfen Sie, ob Sie ausreichende Zugriffsrechte auf diesen Schlüssel besitzen, oder setzen Sie sich mit dem Supportpersonal in Verbindung.(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (11/09/2013 03:48:50 PM) (Source: BstHdAndroidSvc)(User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (11/08/2013 01:12:42 PM) (Source: BstHdAndroidSvc)(User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (11/08/2013 01:06:27 PM) (Source: Application Hang)(User: )
Description: a2start.exe8.1.0.196c2c01cedc36fed6ceb579c:\program files (x86)\emsisoft anti-malware\a2start.exe837467e1-4833-11e3-b0ea-f0def1613e29
Error: (11/08/2013 11:27:59 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3089
Error: (11/08/2013 11:27:59 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3089
Error: (11/08/2013 11:27:59 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (11/08/2013 11:27:58 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2075
Error: (11/08/2013 11:27:58 AM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2075
CodeIntegrity Errors:
===================================
Date: 2012-09-20 12:09:21.326
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-09-20 12:09:20.889
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-09-20 12:08:15.416
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-09-20 12:08:15.275
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-09-19 21:39:39.615
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-09-19 21:39:39.480
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-09-19 21:39:39.345
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-09-19 21:39:39.210
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-08-09 16:15:27.370
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Downloads\JDownload\Sandboxie 3.62 x64\Sandboxie_3.62_x64\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-08-09 16:15:27.256
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Downloads\JDownload\Sandboxie 3.62 x64\Sandboxie_3.62_x64\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 61%
Total physical RAM: 6055.23 MB
Available physical RAM: 2301.48 MB
Total Pagefile: 12108.65 MB
Available Pagefile: 7959.09 MB
Total Virtual: 8192 MB
Available Virtual: 8191.78 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:85.77 GB) (Free:11.16 GB) NTFS
Drive d: (Spiele) (Fixed) (Total:20.26 GB) (Free:9.87 GB) NTFS
Drive e: (Daten) (Fixed) (Total:358.55 GB) (Free:15.96 GB) NTFS
Drive g: (SYSTEM_DRV) (Fixed) (Total:1.17 GB) (Free:0.51 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: B9B20D09)
Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=86 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=379 GB) - (Type=OF Extended)
==================== End Of Log ============================ FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2013 01
Ran by Yannick (administrator) on ARAGORN on 11-11-2013 05:06:02
Running from C:\Users\Yannick\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
(Lenovo.) C:\Windows\system32\ibmpmsvc.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\OAcat.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\oasrv.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\HOTKEY\tpnumlk.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Fork Ltd.) C:\Program Files (x86)\Prey\platform\windows\cronsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SAsrv.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\OAui.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files (x86)\HTC Home\Clock.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\OAhlp.exe
() C:\Program Files\Rainlendar2\Rainlendar2.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Flux Software LLC) C:\Users\Yannick\AppData\Local\FluxSoftware\Flux\flux.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
(Dropbox, Inc.) C:\Users\Yannick\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Virtual Clone Drive\VCDDaemon.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Lenovo Group Limited) C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
() C:\Users\Yannick\AppData\Roaming\TorrentStream\updater\tsupdate.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ForteConfig] - C:\Program Files\CONEXANT\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [TpShocks] - C:\Windows\System32\TpShocks.exe [228744 2012-09-20] (Lenovo.)
HKLM\...\Run: [LENOVO.TPKNRRES] - C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe [60920 2013-05-29] (Lenovo Group Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-06-03] (Adobe Systems Incorporated)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [@OnlineArmor GUI] - C:\Program Files (x86)\Online Armor\OAui.exe [7558464 2013-10-17] (Emsisoft GmbH)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-05-29] (Synaptics Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\SYSTEM32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [FileHippo.com] - C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [307712 2012-11-23] (FileHippo.com)
HKCU\...\Run: [Clock Widget (HTC Home)] - C:\Program Files (x86)\HTC Home\Clock.exe [2036736 2011-11-28] ()
HKCU\...\Run: [Rainlendar2] - C:\Program Files\Rainlendar2\Rainlendar2.exe [4373600 2013-03-12] ()
HKCU\...\Run: [F.lux] - C:\Users\Yannick\AppData\Local\FluxSoftware\Flux\flux.exe [1016712 2013-10-16] (Flux Software LLC)
HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [911040 2013-04-22] (Microsoft Corporation)
HKCU\...\Run: [Google Update] - C:\Users\Yannick\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-10-03] (Google Inc.)
HKCU\...\Policies\Explorer: [NoInternetOpenWith] 1
HKLM-x32\...\Run: [RotateImage] - C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [PWMTRV] - C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL [6618920 2013-08-01] (Lenovo Group Limited)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048 2011-09-16] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [AMD AVT] - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [10752 2012-01-31] ()
HKLM-x32\...\Run: [emsisoft anti-malware] - C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe [3478392 2013-09-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Virtual Clone Drive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [685048 2012-08-04] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-09-11] (DivX, LLC)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1707472 2013-11-07] (APN)
HKU\Default\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\Default User\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
IMEO\taskmgr.exe: [Debugger] "C:\Program Files (x86)\System Explorer\SystemExplorer.exe"
Startup: C:\Users\Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Yannick\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA359E87BF395CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: No Name - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No File
BHO-x32: Ghostery Add-On - {237EB6DA-3FEA-4DD2-8A61-A901B5C489D7} - C:\Program Files (x86)\GhosteryIEplugin\GhosteryBrowserHelperObject.dll ()
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: HKLM-x32 {10000000-1000-1000-1000-100000000000} hxxp://cdn.betteradvertising.com/ghostery/addons/ie/2.4.2.0/ghostery.cab
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {816BE035-1450-40D0-8A3B-BA7825A83A77} hxxp://support.lenovo.com/Resources/Lenovo/AutoDetect/Lenovo_AutoDetect2.cab
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
Filter: text/html - {4459DC76-1FDE-4B16-BAD0-E4F8E7647555} - No File
Filter-x32: text/html - {4459DC76-1FDE-4B16-BAD0-E4F8E7647555} - C:\Program Files (x86)\GhosteryIEplugin\GhosteryMimeFilter.dll ()
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default
FF DefaultSearchEngine: Amazon.de
FF SelectedSearchEngine: Amazon.de
FF Homepage: hxxp://www.spiegel.de/index.html
FF NetworkProxy: "http", "127.0.0.1"
FF NetworkProxy: "http_port", 8555
FF NetworkProxy: "type", 1
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
FF Plugin-x32: @Skype Technologies S.A..com/Skype Web Plugin - C:\Program Files (x86)\SkypeWebPlugin\npSkypeWebPlugin.dll (Skype)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll No File
FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Yannick\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Yannick\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Yannick\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @torrentstream.net/tsplugin,version=2.0.4.1 - C:\Users\Yannick\AppData\Roaming\TorrentStream\player\npts_plugin.dll (Innovative Digital Technologies)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Fast Dial - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\fastdial@telega.phpnet.us
FF Extension: Mein-Deal.com GutscheinFinder - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\firefox@mein-deal.com
FF Extension: FoxyProxy Basic - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\foxyproxy@eric.h.jung
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\ich@maltegoetz.de
FF Extension: Mandarin Popup - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\mandarinpopup@gmail.com
FF Extension: IE Tab 2 (FF 3.6+) - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
FF Extension: FEBE - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
FF Extension: WOT - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF Extension: DownloadHelper - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: FoxClocks - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
FF Extension: adblockpopups - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\adblockpopups@jessehakanen.net.xpi
FF Extension: amptra - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\amptra@keepa.com.xpi
FF Extension: check-compatibility - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\check-compatibility@dactyl.googlecode.com.xpi
FF Extension: extension - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\extension@ciuvo.com.xpi
FF Extension: facebook - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\facebook@disconnect.me.xpi
FF Extension: firefox - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\firefox@ghostery.com.xpi
FF Extension: toolbar - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\toolbar@qipu.de.xpi
FF Extension: toolbar_CMG-V7 - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\toolbar_CMG-V7@apn.ask.com.xpi
FF Extension: No Name - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi
FF Extension: googlebarlite - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{79c50f9a-2ffe-4ee0-8a37-fae4f5dacd4f}.xpi
FF Extension: No Name - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF Extension: Adblock Plus - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: bprivacyprefs - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
FF Extension: downbarconfig - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF Extension: No Name - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{DB981CCA-088E-4731-A4A2-2FE218703C0E}.xpi
FF Extension: dta - C:\Users\Yannick\AppData\Roaming\Mozilla\Firefox\Profiles\pfi9wnut.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{09F060FA-566D-42D7-BF79-97AB30863433}] - C:\Program Files (x86)\Steganos Privacy Suite 12\pfplugin
FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Privacy Suite 12\spmplugin3
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF HKCU\...\Firefox\Extensions: [magicplayer@torrentstream.org] - C:\Users\Yannick\AppData\Roaming\TorrentStream\extensions\firefox\magicplayer@torrentstream.org
FF Extension: TS Magic Player - C:\Users\Yannick\AppData\Roaming\TorrentStream\extensions\firefox\magicplayer@torrentstream.org
Chrome:
=======
CHR Extension: (Awesome Screenshot: Capture & Annotate) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\alelhddbbhepgpmgidjdcjakblofbmce\3.4.5_0
CHR Extension: (Google Docs) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (WOT) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\2.0.18_0
CHR Extension: (YouTube) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Blink 182 Theme) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\cangecedbkhjaiiepnhadebhlfnfpldo\1.2_0
CHR Extension: (Adblock Plus) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.6.1_0
CHR Extension: (Google Search) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Adobe Acrobat - Create PDF) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj\11.0.3.37_0
CHR Extension: (DoNotTrackMe) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd\2.2.9.912_0
CHR Extension: (TinEye Reverse Image Search) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl\1.1.3_0
CHR Extension: (Downloads) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngbcgifdaopbfflfhbcfeomijfbbcadi\1.5_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Gmail) - C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx
==================== Services (Whitelisted) =================
R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-11-07] (APN LLC.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [393032 2013-07-04] (BlueStack Systems, Inc.)
S4 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [384840 2013-07-04] (BlueStack Systems, Inc.)
R2 CronService; C:\Program Files (x86)\Prey\platform\windows\cronsvc.exe [19968 2011-02-16] (Fork Ltd.)
S4 CyberLink PowerDVD 13 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe [77576 2013-07-05] (CyberLink)
S4 CyberLink PowerDVD 13 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe [327432 2013-07-05] (CyberLink)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited)
R2 OAcat; C:\Program Files (x86)\Online Armor\OAcat.exe [584864 2013-10-17] (Emsisoft GmbH)
S4 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-26] (CACE Technologies, Inc.)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22888 2013-09-17] ()
R2 SvcOnlineArmor; C:\Program Files (x86)\Online Armor\oasrv.exe [4457688 2013-10-17] (Emsisoft GmbH)
S4 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [776848 2012-03-01] (Mister Group)
==================== Drivers (Whitelisted) ====================
R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [70960 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [17384 2013-03-28] (Emsisoft GmbH)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [31872 2012-02-01] (Advanced Micro Devices, Inc.)
R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [139352 2013-07-31] (SlySoft, Inc.)
R3 AnyDVD; C:\Windows\SysWow64\Drivers\AnyDVD.sys [139352 2013-07-31] (SlySoft, Inc.)
S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [70984 2013-07-04] (BlueStack Systems)
R3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-08-20] (Emsisoft GmbH)
S3 cpudrv64; C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [17864 2011-06-02] ()
R2 cpuz135; C:\Windows\system32\drivers\cpuz135_x64.sys [21992 2011-09-21] (CPUID)
S3 DCamUSBVM; C:\Windows\System32\Drivers\usbVM31b.sys [142336 2005-09-19] (Vimicro Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-01-21] (DT Soft Ltd)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
S3 epmntdrv; C:\Windows\SysWow64\epmntdrv.sys [14216 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\SysWow64\EuGdiDrv.sys [8456 2011-07-29] ()
R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [37456 2011-10-26] (Paragon Software Group)
R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-26] (CACE Technologies, Inc.)
R1 OADevice; C:\Windows\SysWow64\Drivers\OADriver.sys [64720 2013-10-17] ()
R1 oahlpXX; C:\Windows\syswow64\drivers\oahlp64.sys [62008 2013-10-16] ()
R1 OAmon; C:\Windows\SysWOW64\Drivers\OAmon.sys [52360 2013-10-17] (Emsisoft)
R3 OAnet; C:\Windows\System32\DRIVERS\oanet.sys [35368 2013-10-17] (Emsisoft)
R1 PHCORE; C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [32104 2011-07-08] (Lenovo Group Limited)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19936 2011-09-03] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [13280 2011-09-03] ()
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [44784 2013-05-29] (Synaptics Incorporated)
S3 ssudobex; C:\Windows\System32\DRIVERS\ssudobex.sys [203104 2012-09-20] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-06-21] (Anchorfree Inc.)
R2 {09F57980-3432-4AFC-957D-27AC45FAE1F5}; C:\Program Files (x86)\CyberLink\PowerDVD13\Common\NavFilter\000.fcl [130320 2013-07-06] (CyberLink Corp.)
S3 ALSysIO; \??\C:\Users\Yannick\AppData\Local\Temp\ALSysIO64.sys [x]
S3 dgderdrv; System32\drivers\dgderdrv.sys [x]
S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [x]
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-02] ()
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-11 05:05 - 2013-11-11 05:05 - 00000000 ____D C:\FRST
2013-11-11 05:03 - 2013-11-11 05:03 - 01957590 _____ (Farbar) C:\Users\Yannick\Desktop\FRST64.exe
2013-11-11 05:01 - 2013-11-11 05:02 - 00000528 _____ C:\Users\Yannick\Desktop\defogger_disable.log
2013-11-11 04:59 - 2013-11-11 05:00 - 00050477 _____ C:\Users\Yannick\Desktop\Defogger.exe
2013-11-07 11:59 - 2013-11-09 15:46 - 00004568 _____ C:\Windows\PFRO.log
2013-11-07 06:35 - 2013-11-07 06:36 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Camfrog
2013-11-07 06:35 - 2013-11-07 06:35 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-11-07 06:35 - 2013-11-07 06:35 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
2013-11-07 06:34 - 2013-11-07 06:34 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Camfrog Video Chat 6.5
2013-11-07 06:34 - 2013-11-07 06:34 - 00000000 ____D C:\Users\Yannick\AppData\Local\CrashRpt
2013-11-07 06:34 - 2013-11-07 06:34 - 00000000 ____D C:\ProgramData\APN
2013-11-07 06:34 - 2013-11-07 06:34 - 00000000 ____D C:\Program Files (x86)\Camfrog
2013-11-07 03:54 - 2013-11-07 03:54 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\concept design
2013-11-07 03:54 - 2013-11-07 03:54 - 00000000 ____D C:\Program Files (x86)\concept design
2013-11-07 00:23 - 2013-11-07 00:24 - 00262144 _____ C:\Windows\Minidump\110713-45801-01.dmp
2013-11-06 20:18 - 2013-11-06 20:18 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-11-06 20:18 - 2013-11-06 20:18 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-11-06 20:18 - 2013-11-06 20:18 - 00000000 ____D C:\Program Files\iTunes
2013-11-06 20:18 - 2013-11-06 20:18 - 00000000 ____D C:\Program Files\iPod
2013-11-06 20:18 - 2013-11-06 20:18 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-11-05 12:41 - 2013-11-05 12:41 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\27986
2013-11-04 17:22 - 2013-11-04 17:22 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\DVDFab9
2013-11-04 17:21 - 2013-11-05 12:41 - 00000000 ____D C:\Program Files (x86)\DVDFab 9
2013-11-03 13:06 - 2013-11-03 13:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-26 20:48 - 2013-11-11 00:32 - 00003136 _____ C:\Windows\setupact.log
2013-10-26 20:48 - 2013-10-26 20:48 - 00000000 _____ C:\Windows\setuperr.log
2013-10-26 18:17 - 2013-11-11 04:57 - 00010193 _____ C:\Users\Yannick\Desktop\1.xlsx
2013-10-19 11:06 - 2013-10-19 11:06 - 00001497 _____ C:\Users\Yannick\AppData\Local\PDLSetup.20131019.110631.txt
2013-10-18 13:37 - 2013-10-18 13:37 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\EurekaLab s.a.s
2013-10-17 12:54 - 2013-10-17 12:54 - 00000000 ____D C:\Program Files\BreakPoint Software
2013-10-17 12:53 - 2013-10-17 12:53 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\BreakPoint Software
2013-10-16 15:44 - 2013-10-16 15:44 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flux
2013-10-16 15:43 - 2013-10-16 15:43 - 00000000 ____D C:\Users\Yannick\AppData\Local\FluxSoftware
2013-10-16 15:35 - 2013-10-16 15:35 - 00004249 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-16 15:35 - 2013-10-08 07:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-16 15:35 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-16 15:35 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-16 15:35 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-13 02:09 - 2013-10-13 02:09 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EvilLyrics
2013-10-13 02:08 - 2013-10-13 02:42 - 00000000 ____D C:\Program Files (x86)\EvilLyrics
2013-10-12 11:24 - 2013-10-12 11:24 - 00000000 ____D C:\Users\Yannick\AppData\Local\Tvsukernel
2013-10-12 11:10 - 2013-10-12 11:24 - 00000000 ____D C:\Program Files\Common Files\Lenovo
==================== One Month Modified Files and Folders =======
2013-11-11 05:07 - 2012-10-21 21:50 - 00000000 ____D C:\Program Files (x86)\Emsisoft Anti-Malware
2013-11-11 05:05 - 2013-11-11 05:05 - 00000000 ____D C:\FRST
2013-11-11 05:03 - 2013-11-11 05:03 - 01957590 _____ (Farbar) C:\Users\Yannick\Desktop\FRST64.exe
2013-11-11 05:02 - 2013-11-11 05:01 - 00000528 _____ C:\Users\Yannick\Desktop\defogger_disable.log
2013-11-11 05:02 - 2013-10-03 01:43 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-874405144-3379903360-3449110331-1000UA.job
2013-11-11 05:00 - 2013-11-11 04:59 - 00050477 _____ C:\Users\Yannick\Desktop\Defogger.exe
2013-11-11 04:57 - 2013-10-26 18:17 - 00010193 _____ C:\Users\Yannick\Desktop\1.xlsx
2013-11-11 04:57 - 2011-08-06 07:32 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Macromedia
2013-11-11 04:54 - 2012-03-29 22:31 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-11 04:53 - 2012-10-02 23:47 - 00000000 ____D C:\Program Files (x86)\JDownloader 2
2013-11-11 04:51 - 2013-09-27 15:48 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\vlc
2013-11-11 04:48 - 2013-01-13 20:13 - 00000029 _____ C:\Windows\SysWOW64\TempWmicBatchFile.bat
2013-11-11 04:33 - 2011-08-07 18:07 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Skype
2013-11-11 03:06 - 2012-12-09 04:40 - 00000000 ____D C:\Users\Yannick\AppData\Local\CrashDumps
2013-11-11 02:41 - 2011-08-07 00:14 - 00395124 _____ C:\Windows\system32\prfh0404.dat
2013-11-11 02:41 - 2011-08-07 00:14 - 00115082 _____ C:\Windows\system32\prfc0404.dat
2013-11-11 02:41 - 2009-07-15 01:58 - 00715384 _____ C:\Windows\system32\perfh007.dat
2013-11-11 02:41 - 2009-07-15 01:58 - 00154092 _____ C:\Windows\system32\perfc007.dat
2013-11-11 02:41 - 2009-07-14 13:13 - 02151050 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-11 02:00 - 2011-08-06 20:38 - 00000000 ____D C:\Users\Yannick\AppData\Local\Adobe
2013-11-11 00:32 - 2013-10-26 20:48 - 00003136 _____ C:\Windows\setupact.log
2013-11-11 00:32 - 2011-10-27 12:17 - 01259824 _____ C:\Windows\WindowsUpdate.log
2013-11-11 00:32 - 2011-08-08 07:58 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs
2013-11-11 00:11 - 2011-12-10 10:34 - 00000000 ____D C:\Windows\system32\log
2013-11-10 18:02 - 2013-10-03 01:43 - 00001076 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-874405144-3379903360-3449110331-1000Core.job
2013-11-10 00:07 - 2012-12-08 23:03 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\.Torrent Stream
2013-11-10 00:07 - 2012-12-08 23:03 - 00000000 ____D C:\Program Files (x86)\TorrentStream
2013-11-09 15:56 - 2009-07-14 12:45 - 00020704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-09 15:56 - 2009-07-14 12:45 - 00020704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-09 15:50 - 2013-03-25 19:07 - 00000000 ____D C:\Program Files (x86)\HTC Home
2013-11-09 15:50 - 2011-12-28 01:03 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Dropbox
2013-11-09 15:49 - 2013-01-30 12:54 - 00671084 _____ C:\QcOSD.txt
2013-11-09 15:49 - 2012-06-07 16:45 - 00000000 ____D C:\Users\Yannick\.rainlendar2
2013-11-09 15:48 - 2009-07-14 13:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-09 15:46 - 2013-11-07 11:59 - 00004568 _____ C:\Windows\PFRO.log
2013-11-07 07:20 - 2013-01-26 04:38 - 00000000 ____D C:\Program Files\SecurityKISS Tunnel
2013-11-07 06:36 - 2013-11-07 06:35 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Camfrog
2013-11-07 06:35 - 2013-11-07 06:35 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-11-07 06:35 - 2013-11-07 06:35 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
2013-11-07 06:34 - 2013-11-07 06:34 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Camfrog Video Chat 6.5
2013-11-07 06:34 - 2013-11-07 06:34 - 00000000 ____D C:\Users\Yannick\AppData\Local\CrashRpt
2013-11-07 06:34 - 2013-11-07 06:34 - 00000000 ____D C:\ProgramData\APN
2013-11-07 06:34 - 2013-11-07 06:34 - 00000000 ____D C:\Program Files (x86)\Camfrog
2013-11-07 03:54 - 2013-11-07 03:54 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\concept design
2013-11-07 03:54 - 2013-11-07 03:54 - 00000000 ____D C:\Program Files (x86)\concept design
2013-11-07 00:24 - 2013-11-07 00:23 - 00262144 _____ C:\Windows\Minidump\110713-45801-01.dmp
2013-11-07 00:23 - 2013-05-10 00:11 - 00000000 ____D C:\Windows\Minidump
2013-11-06 22:04 - 2011-08-06 07:32 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Adobe
2013-11-06 20:18 - 2013-11-06 20:18 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-11-06 20:18 - 2013-11-06 20:18 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-11-06 20:18 - 2013-11-06 20:18 - 00000000 ____D C:\Program Files\iTunes
2013-11-06 20:18 - 2013-11-06 20:18 - 00000000 ____D C:\Program Files\iPod
2013-11-06 20:18 - 2013-11-06 20:18 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-11-06 13:56 - 2011-08-12 02:39 - 00000000 ____D C:\Program Files (x86)\DivX
2013-11-06 13:56 - 2011-08-12 02:38 - 00000000 ____D C:\ProgramData\DivX
2013-11-06 13:54 - 2011-08-12 02:42 - 00000000 ____D C:\Program Files\DivX
2013-11-06 13:52 - 2011-08-12 02:43 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\DivX
2013-11-06 13:50 - 2013-06-03 14:01 - 00000000 _____ C:\END
2013-11-05 18:18 - 2011-08-06 05:33 - 00000000 ____D C:\Users\Yannick
2013-11-05 12:49 - 2012-03-03 08:10 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\dvdcss
2013-11-05 12:41 - 2013-11-05 12:41 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\27986
2013-11-05 12:41 - 2013-11-04 17:21 - 00000000 ____D C:\Program Files (x86)\DVDFab 9
2013-11-05 10:59 - 2012-05-04 07:12 - 00000454 _____ C:\Users\Yannick\Desktop\Gutscheine.txt
2013-11-04 17:22 - 2013-11-04 17:22 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\DVDFab9
2013-11-04 01:07 - 2013-08-30 12:21 - 00000040 ___SH C:\ProgramData\.zreglib
2013-11-03 22:36 - 2012-09-06 19:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-03 13:07 - 2013-11-03 13:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-31 18:08 - 2011-09-30 00:36 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Mp3tag
2013-10-31 16:24 - 2011-08-07 18:07 - 00000000 ____D C:\ProgramData\Skype
2013-10-31 16:22 - 2013-01-12 02:33 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-28 17:42 - 2011-08-07 21:50 - 00000866 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-10-27 16:18 - 2011-08-10 23:08 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Winamp
2013-10-27 16:12 - 2012-05-05 00:53 - 00000000 ____D C:\Program Files (x86)\Songr
2013-10-26 20:48 - 2013-10-26 20:48 - 00000000 _____ C:\Windows\setuperr.log
2013-10-26 14:01 - 2013-09-04 22:52 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Azureus
2013-10-26 14:01 - 2011-08-06 23:46 - 00000000 ____D C:\Users\Yannick\AppData\Local\Paint.NET
2013-10-26 14:00 - 2011-08-07 21:50 - 00000000 ____D C:\Program Files\CCleaner
2013-10-25 12:55 - 2009-07-14 13:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-24 17:45 - 2011-08-07 21:56 - 00000000 ____D C:\Program Files\Defraggler
2013-10-19 11:06 - 2013-10-19 11:06 - 00001497 _____ C:\Users\Yannick\AppData\Local\PDLSetup.20131019.110631.txt
2013-10-18 13:37 - 2013-10-18 13:37 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\EurekaLab s.a.s
2013-10-17 13:01 - 2013-01-12 15:29 - 00000000 ____D C:\Program Files (x86)\Online Armor
2013-10-17 12:54 - 2013-10-17 12:54 - 00000000 ____D C:\Program Files\BreakPoint Software
2013-10-17 12:53 - 2013-10-17 12:53 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\BreakPoint Software
2013-10-17 11:32 - 2013-01-12 15:29 - 00064720 _____ C:\Windows\SysWOW64\Drivers\OADriver.sys
2013-10-17 11:32 - 2013-01-12 15:29 - 00052360 _____ (Emsisoft) C:\Windows\SysWOW64\Drivers\OAmon.sys
2013-10-17 11:32 - 2013-01-12 15:29 - 00035368 _____ (Emsisoft) C:\Windows\system32\Drivers\OAnet.sys
2013-10-16 15:44 - 2013-10-16 15:44 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flux
2013-10-16 15:43 - 2013-10-16 15:43 - 00000000 ____D C:\Users\Yannick\AppData\Local\FluxSoftware
2013-10-16 15:36 - 2013-09-14 18:51 - 00000000 ____D C:\ProgramData\Oracle
2013-10-16 15:35 - 2013-10-16 15:35 - 00004249 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-16 15:35 - 2013-02-23 12:50 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-16 09:18 - 2013-01-12 15:29 - 00062008 _____ C:\Windows\SysWOW64\Drivers\oahlp64.sys
2013-10-13 02:52 - 2011-10-27 16:16 - 00000030 _____ C:\Program Files (x86)\Exiferupdate.ini
2013-10-13 02:42 - 2013-10-13 02:08 - 00000000 ____D C:\Program Files (x86)\EvilLyrics
2013-10-13 02:09 - 2013-10-13 02:09 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EvilLyrics
2013-10-13 02:06 - 2011-09-30 00:35 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2013-10-12 14:17 - 2011-08-07 21:54 - 00000000 ____D C:\Users\Yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System
2013-10-12 14:16 - 2012-09-06 22:14 - 00000000 ____D C:\Program Files (x86)\Virtual Router
2013-10-12 11:24 - 2013-10-12 11:24 - 00000000 ____D C:\Users\Yannick\AppData\Local\Tvsukernel
2013-10-12 11:24 - 2013-10-12 11:10 - 00000000 ____D C:\Program Files\Common Files\Lenovo
2013-10-12 11:18 - 2009-07-14 11:20 - 00000000 __RSD C:\Windows\Media
2013-10-12 09:37 - 2012-01-05 18:37 - 00000000 ____D C:\ProgramData\Lenovo
2013-10-12 09:26 - 2012-05-24 19:09 - 00000000 ____D C:\Windows\System32\Tasks\TVT
2013-10-12 09:24 - 2011-08-06 06:30 - 00000000 ____D C:\Program Files (x86)\Lenovo
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-10 04:17
==================== End Of Log ============================ --- --- ---
--- --- ---
defogger_disable Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 05:02 on 11/11/2013 (Yannick)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
SPTD -> Already disabled
-=E.O.F=- MBAM-log-2013-11-08 (19-45-11) Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.11.08.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
Yannick :: ARAGORN [Administrator]
08.11.2013 17:28:46
MBAM-log-2013-11-08 (19-45-11).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 591305
Laufzeit: 1 Stunde(n), 59 Minute(n), 14 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 3
C:\Users\Yannick\AppData\Local\Temp\ct3288691 (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\Yannick\AppData\Local\Temp\ct3297265 (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\Yannick\AppData\Local\Temp\ct3297861 (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
Infizierte Dateien: 20
E:\MediaInfo_GUI_0.7.64_Windows.exe (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
E:\Downloads\DaemonTool Lite 4.461-0328.exe (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
E:\Downloads\FreeYouTubeToMP3Converter.exe (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
E:\Downloads\Setup-SopCast-3.8.3-2013-6-26.exe (PUP.Optional.Spigot.A) -> Keine Aktion durchgeführt.
E:\Downloads\SetupImgBurn_2.5.8.0.exe (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
E:\Downloads\veetle-0.9.19.exe (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
E:\Downloads\winamp565_full_emusic-7plus_all.exe (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
E:\Downloads\Media Player\Winamp 5.63.exe (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
C:\Users\Yannick\AppData\Local\Temp\ct3288691\chromeid.txt (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\Yannick\AppData\Local\Temp\ct3288691\setup.ini.txt (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\Yannick\AppData\Local\Temp\ct3297265\ism.exe (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\Yannick\AppData\Local\Temp\ct3297861\chromeid.txt (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\Yannick\AppData\Local\Temp\ct3297861\setup.ini.txt (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
(Ende) |