Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 26.12.2014 09:07:57, SYSTEM, KLAMMERTOM, Protection, Malware Protection, Starting,
Protection, 26.12.2014 09:07:57, SYSTEM, KLAMMERTOM, Protection, Malware Protection, Started,
Protection, 26.12.2014 09:07:57, SYSTEM, KLAMMERTOM, Protection, Malicious Website Protection, Starting,
Update, 26.12.2014 09:08:03, SYSTEM, KLAMMERTOM, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1,
Update, 26.12.2014 09:08:03, SYSTEM, KLAMMERTOM, Manual, Rootkit Database, 2014.11.18.1, 2014.12.23.2,
Update, 26.12.2014 09:08:13, SYSTEM, KLAMMERTOM, Manual, Malware Database, 2014.11.20.6, 2014.12.26.4,
Protection, 26.12.2014 09:08:13, SYSTEM, KLAMMERTOM, Protection, Refresh, Starting,
Protection, 26.12.2014 09:08:22, SYSTEM, KLAMMERTOM, Protection, Malicious Website Protection, Started,
Protection, 26.12.2014 09:08:22, SYSTEM, KLAMMERTOM, Protection, Malicious Website Protection, Stopping,
Protection, 26.12.2014 09:08:22, SYSTEM, KLAMMERTOM, Protection, Malicious Website Protection, Stopped,
Protection, 26.12.2014 09:08:28, SYSTEM, KLAMMERTOM, Protection, Refresh, Success,
Protection, 26.12.2014 09:08:28, SYSTEM, KLAMMERTOM, Protection, Malicious Website Protection, Starting,
Protection, 26.12.2014 09:08:28, SYSTEM, KLAMMERTOM, Protection, Malicious Website Protection, Started,
Update, 26.12.2014 09:37:21, SYSTEM, KLAMMERTOM, Manual, Malware Database, 2014.12.26.4, 2014.12.26.5,
Protection, 26.12.2014 09:37:21, SYSTEM, KLAMMERTOM, Protection, Refresh, Starting,
Protection, 26.12.2014 09:37:21, SYSTEM, KLAMMERTOM, Protection, Malicious Website Protection, Stopping,
Protection, 26.12.2014 09:37:21, SYSTEM, KLAMMERTOM, Protection, Malicious Website Protection, Stopped,
Protection, 26.12.2014 09:37:57, SYSTEM, KLAMMERTOM, Protection, Refresh, Success,
Protection, 26.12.2014 09:37:57, SYSTEM, KLAMMERTOM, Protection, Malicious Website Protection, Starting,
Protection, 26.12.2014 09:37:58, SYSTEM, KLAMMERTOM, Protection, Malicious Website Protection, Started,
Scan, 26.12.2014 09:38:22, SYSTEM, KLAMMERTOM, Manual, Start: % 1 "% 2", Dauer: % 1 min 25 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, 12-Malwareerkennung,
Protection, 26.12.2014 09:44:21, SYSTEM, KLAMMERTOM, Protection, Malware Protection, Starting,
Protection, 26.12.2014 09:44:21, SYSTEM, KLAMMERTOM, Protection, Malware Protection, Started,
Protection, 26.12.2014 09:44:21, SYSTEM, KLAMMERTOM, Protection, Malicious Website Protection, Starting,
Protection, 26.12.2014 09:46:07, SYSTEM, KLAMMERTOM, Protection, Malicious Website Protection, Started,
(end) Code:
# AdwCleaner v4.106 - Bericht erstellt am 26/12/2014 um 10:00:41
# Aktualisiert 21/12/2014 von Xplode
# Database : 2014-12-21.4 [Live]
# Betriebssystem : Windows 7 Home Premium (32 bits)
# Benutzername : Klammer Tom - KLAMMERTOM
# Gestartet von : C:\Users\Klammer Tom\Desktop\AdwCleaner_4.106.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Babsi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Ordner Gelöscht : C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Datei Gelöscht : C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage-journal
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DCB7100-DF86-4384-8842-8FA844297B3F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8DCB7100-DF86-4384-8842-8FA844297B3F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
***** [ Browser ] *****
-\\ Internet Explorer v8.0.7601.17514
-\\ Google Chrome v
[C:\Users\Babsi\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : lifbcibllhkdhoafpjfnlhfpfgnpldfl
[C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://mystart.incredibar.com/?loc=IB_DS&search={searchTerms}&a=6R8i6q7A7l&i=26
[C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://mystart.incredibar.com/?loc=IB_DS&search={searchTerms}&a=6R8i6q7A7l&i=26
[C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms}
[C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBDDI6Pk-fpITtt_7-dx2uywuT-4gdlOLmKF8AQeX1uQ_lptDURdxlE1786D-JcfAN0BZpoxwLfcd_VGjx_pwznmpfgTJQmOByNV6qjCRyzAiyzIdh7DV7Jxhs_diEFWvxdIKlxDICvIEXVOv1xnYFER614hn4pI_E8Do3SSrw3Q,,&q={searchTerms}
[C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.second-hand.it/index.php.de.php?search={searchTerms}&page=0&startsearch=suchen
[C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={94FDB544-7492-4179-B786-FB67E147D0BB}
*************************
AdwCleaner[R0].txt - [33240 octets] - [26/08/2014 08:43:09]
AdwCleaner[R1].txt - [24471 octets] - [30/08/2014 05:20:06]
AdwCleaner[R2].txt - [4174 octets] - [26/12/2014 09:57:30]
AdwCleaner[S0].txt - [7056 octets] - [26/08/2014 08:44:45]
AdwCleaner[S1].txt - [23536 octets] - [30/08/2014 05:25:12]
AdwCleaner[S2].txt - [4095 octets] - [26/12/2014 10:00:41]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [4155 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Home Premium x86
Ran by Klammer Tom on 26.12.2014 at 10:08:46,59
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\Users\Klammer Tom\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com"
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files\dll-files.com fixer"
Successfully deleted: [Folder] "C:\Program Files\myfree codec"
Successfully deleted: [Folder] "C:\Users\Klammer Tom\music\qtrax media library"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26.12.2014 at 10:10:39,79
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-12-2014 01
Ran by Klammer Tom (administrator) on KLAMMERTOM on 26-12-2014 10:13:03
Running from C:\Users\Klammer Tom\Desktop
Loaded Profile: Klammer Tom (Available profiles: Klammer Tom & Babsi & Gast)
Platform: Microsoft Windows 7 Home Premium (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(MS) C:\Program Files\LSM\aus.exe
(AVM Berlin) C:\Program Files\FRITZ!Fernzugang\avmike.exe
(AVM Berlin) C:\Program Files\FRITZ!Fernzugang\certsrv.exe
(Fitbit, Inc.) C:\Program Files\Fitbit Connect\FitbitConnectService.exe
(MS) C:\Program Files\LSM\lsm.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(AVM Berlin) C:\Program Files\FRITZ!Fernzugang\nwtsrv.exe
(Sony Corporation) C:\Program Files\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
(TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\Wyse\PocketCloud Windows Companion\PocketCloudService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(MS) C:\Program Files\LSM\lsm.exe
(Fitbit, Inc.) C:\Program Files\Fitbit Connect\Fitbit Connect.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(Sony Corporation) C:\Program Files\Sony\PlayMemories Home\PMBVolumeWatcher.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(Siemens IT Solutions and Services GmbH) C:\Program Files\Siemens\CardOS API\bin\siecacst.exe
(Numera) C:\Program Files\BiLink Gateway\GatewaySysTray.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
(Google Inc.) C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8555040 2010-04-07] (Realtek Semiconductor)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-05-27] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [Fitbit Connect] => C:\Program Files\Fitbit Connect\Fitbit Connect.exe [3093024 2013-02-25] (Fitbit, Inc.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-04-15] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] ()
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-09-04] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [PMBVolumeWatcher] => C:\Program Files\Sony\PlayMemories Home\PMBVolumeWatcher.exe [740888 2013-04-24] (Sony Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-1212480921-3000280771-3724376844-1001\...\Run: [Fitbit Connect] => C:\Program Files\Fitbit Connect\Fitbit Connect.exe [3093024 2013-02-25] (Fitbit, Inc.)
HKU\S-1-5-21-1212480921-3000280771-3724376844-1001\...\Run: [7458D9638A71E4DCC1B6741438512A391BC80893._service_run] => C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\chrome.exe [856904 2014-12-06] (Google Inc.)
HKU\S-1-5-21-1212480921-3000280771-3724376844-1001\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-09-04] (Samsung)
HKU\S-1-5-21-1212480921-3000280771-3724376844-1001\...\Run: [GoogleChromeAutoLaunch_1258C2E50858114A6758F2E90A1B01AA] => C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\chrome.exe [856904 2014-12-06] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CardOS API.lnk
ShortcutTarget: CardOS API.lnk -> C:\Program Files\Siemens\CardOS API\bin\siecacst.exe (Siemens IT Solutions and Services GmbH)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Omron BiLink Gateway.lnk
ShortcutTarget: Omron BiLink Gateway.lnk -> C:\Windows\Installer\{63041551-16E0-4841-AC48-92A825711C93}\NewShortcut1_8188288DFAC14FF2859A19505BA528D5.exe (Flexera Software LLC)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1212480921-3000280771-3724376844-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1212480921-3000280771-3724376844-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1212480921-3000280771-3724376844-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1212480921-3000280771-3724376844-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Klammer Tom\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKU\S-1-5-21-1212480921-3000280771-3724376844-1001: @talk.google.com/O1DPlugin -> C:\Users\Klammer Tom\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKU\S-1-5-21-1212480921-3000280771-3724376844-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-1212480921-3000280771-3724376844-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Klammer Tom\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Klammer Tom\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF Extension: Anti-Banner - C:\Program Files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru [2011-01-19]
FF Extension: Modul zur Link-Untersuchung - C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru [2011-01-19]
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-05-19]
Chrome:
=======
CHR HomePage: Default -> https://drive.google.com/keep/
CHR StartupUrls: Default -> "https://drive.google.com/keep/", "hxxp://www.google.com/"
CHR DefaultSearchKeyword: Default -> google.com_
CHR DefaultSearchURL: Default -> hxxp://www.google.com/search?q={searchTerms}
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR Profile: C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-06-20]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-08]
CHR Extension: (YouTube) - C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-06-21]
CHR Extension: (Google-Suche) - C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-06-21]
CHR Extension: (Avira Browserschutz) - C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-27]
CHR Extension: (AdBlock) - C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-12-23]
CHR Extension: (Google Wallet) - C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-27]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-06-20]
CHR Extension: (Google Chrome to Phone Extension) - C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco [2013-06-21]
CHR Extension: (Google Mail) - C:\Users\Klammer Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-21]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2013-05-06]
CHR HKU\S-1-5-21-1212480921-3000280771-3724376844-1001\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\KLAMME~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-04]
CHR StartMenuInternet: Google Chrome - C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG)
R2 AUS; C:\Program Files\LSM\aus.exe [287744 2014-02-22] (MS) [File not signed]
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG)
R2 avmike; C:\Program Files\FRITZ!Fernzugang\avmike.exe [255904 2012-11-28] (AVM Berlin)
R2 certsrv; C:\Program Files\FRITZ!Fernzugang\certsrv.exe [122272 2012-11-28] (AVM Berlin)
R2 Fitbit Connect; C:\Program Files\Fitbit Connect\FitbitConnectService.exe [1239584 2013-02-25] (Fitbit, Inc.) [File not signed]
R2 Log S.M.; C:\Program Files\LSM\lsm.exe [428032 2014-02-22] (MS) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
R2 nwtsrv; C:\Program Files\FRITZ!Fernzugang\nwtsrv.exe [155488 2013-06-10] (AVM Berlin)
R2 PMBDeviceInfoProvider; C:\Program Files\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [483864 2013-04-24] (Sony Corporation)
R2 WysePocketCloud; C:\Program Files\Wyse\PocketCloud Windows Companion\PocketCloudService.exe [177056 2012-05-11] () [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 61883; C:\Windows\System32\DRIVERS\61883.sys [46976 2009-07-14] (Microsoft Corporation)
S3 A38CCID; C:\Windows\System32\DRIVERS\a38ccid.sys [38016 2009-12-15] (Advanced Card Systems Ltd.) [File not signed]
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-09] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-09] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-08-15] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-12-20] (Disc Soft Ltd)
S3 grmnusb; C:\Windows\System32\drivers\grmnusb.sys [15720 2012-04-18] (GARMIN Corp.)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
S3 HTCAND32; C:\Windows\System32\Drivers\ANDROIDUSB.sys [25088 2009-10-26] (HTC, Corporation) [File not signed]
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2014-12-26] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R3 NWIM; C:\Windows\System32\DRIVERS\avmnwim.sys [334712 2011-07-05] (AVM Berlin)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
S3 Ser2plx86; C:\Windows\System32\DRIVERS\ser2pl.sys [139776 2013-10-25] (Prolific Technology Inc.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-08-15] (Avira GmbH)
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [181912 2013-06-05] (DEVGURU Co., LTD.(www.devguru.co.kr))
R3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [186592 2007-06-17] (Jungo)
S1 acnppeaf; No ImagePath
S1 ajvxhtkn; No ImagePath
S1 alrpfdow; No ImagePath
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S1 bbckdoel; No ImagePath
S1 blnyluax; No ImagePath
S1 bxvknznz; No ImagePath
S1 calwkyoh; No ImagePath
S3 catchme; \??\C:\Users\KLAMME~1\AppData\Local\Temp\catchme.sys [X]
S1 csouovll; \??\C:\Windows\system32\drivers\csouovll.sys [X]
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S1 eyhmkoxc; No ImagePath
S1 gmcyysxe; \??\C:\Windows\system32\drivers\gmcyysxe.sys [X]
S1 gzovqwlo; No ImagePath
S1 hgrketja; \??\C:\Windows\system32\drivers\hgrketja.sys [X]
S1 hjbaugtf; No ImagePath
S1 hpzcmekn; No ImagePath
S1 idgksizh; \??\C:\Windows\system32\drivers\idgksizh.sys [X]
S1 imxpezof; No ImagePath
S1 iomzqlia; No ImagePath
S1 jhvusnro; No ImagePath
S1 johxzjxo; \??\C:\Windows\system32\drivers\johxzjxo.sys [X]
S1 kixlqqis; \??\C:\Windows\system32\drivers\kixlqqis.sys [X]
S1 kyernmvt; No ImagePath
S1 lmohiqys; \??\C:\Windows\system32\drivers\lmohiqys.sys [X]
S1 lqhtsnyi; \??\C:\Windows\system32\drivers\lqhtsnyi.sys [X]
S1 mohuhjbr; No ImagePath
S1 nbqboypg; No ImagePath
S1 nioyafri; No ImagePath
S3 Profos; No ImagePath
S1 qbtpojbw; \??\C:\Windows\system32\drivers\qbtpojbw.sys [X]
S1 qkhdjhrz; No ImagePath
S1 szfbsrkv; No ImagePath
S1 sztoigbt; No ImagePath
S1 tafkhagl; \??\C:\Windows\system32\drivers\tafkhagl.sys [X]
S1 tzeqybma; \??\C:\Windows\system32\drivers\tzeqybma.sys [X]
S1 wkrcjoqc; \??\C:\Windows\system32\drivers\wkrcjoqc.sys [X]
S1 xbapjmcg; \??\C:\Windows\system32\drivers\xbapjmcg.sys [X]
S1 xetepzfq; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-26 10:13 - 2014-12-26 10:13 - 00023896 _____ () C:\Users\Klammer Tom\Desktop\FRST.txt
2014-12-26 10:10 - 2014-12-26 10:10 - 00000979 _____ () C:\Users\Klammer Tom\Desktop\JRT.txt
2014-12-26 10:08 - 2014-12-26 10:08 - 00000000 ____D () C:\Windows\ERUNT
2014-12-26 10:07 - 2014-12-26 10:07 - 01707646 _____ (Thisisu) C:\Users\Klammer Tom\Desktop\JRT.exe
2014-12-26 09:55 - 2014-12-26 09:56 - 02173952 _____ () C:\Users\Klammer Tom\Desktop\AdwCleaner_4.106.exe
2014-12-26 09:51 - 2014-12-26 09:51 - 00002669 _____ () C:\Users\Klammer Tom\Desktop\mbam.txt
2014-12-26 09:38 - 2014-12-26 09:38 - 00001876 _____ () C:\Users\Public\Desktop\NewShortcut4.lnk
2014-12-26 09:38 - 2014-12-26 09:38 - 00000000 ____D () C:\Users\Klammer Tom\AppData\Roaming\Omron
2014-12-26 09:38 - 2014-12-26 09:38 - 00000000 ____D () C:\Users\Klammer Tom\AppData\Roaming\Numera.Gateway
2014-12-26 09:38 - 2014-12-26 09:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BiLink Gateway
2014-12-26 09:38 - 2014-12-26 09:38 - 00000000 ____D () C:\Program Files\BiLink Gateway
2014-12-26 09:33 - 2014-12-26 09:35 - 85883120 _____ (Omron) C:\Users\Klammer Tom\Downloads\Bi-LINKGateway.exe
2014-12-26 09:07 - 2014-12-26 10:04 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-26 09:07 - 2014-12-26 09:07 - 00001068 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-26 09:07 - 2014-12-26 09:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-26 09:07 - 2014-12-26 09:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-26 09:07 - 2014-12-26 09:07 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-12-26 09:07 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-26 09:07 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-26 09:07 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-26 09:03 - 2014-12-26 10:12 - 00000000 ____D () C:\Users\Klammer Tom\PC Hilfe
2014-12-25 11:25 - 2014-12-25 11:25 - 00053614 _____ () C:\Users\Klammer Tom\Desktop\Cobofix.txt
2014-12-25 11:21 - 2014-12-25 11:21 - 00053614 _____ () C:\ComboFix.txt
2014-12-25 07:26 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-12-25 07:26 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-12-25 07:26 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-12-25 07:26 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-12-25 07:26 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-12-25 07:26 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-12-25 07:26 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-12-25 07:26 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-12-25 07:20 - 2014-12-25 11:21 - 00000000 ____D () C:\Qoobox
2014-12-25 07:20 - 2014-12-25 11:20 - 00000000 ____D () C:\Windows\erdnt
2014-12-25 07:16 - 2014-12-25 10:24 - 05603465 ____R (Swearware) C:\Users\Klammer Tom\Desktop\ComboFix.exe
2014-12-25 07:09 - 2014-12-25 07:09 - 00001230 _____ () C:\Users\Klammer Tom\Desktop\Revo Uninstaller.lnk
2014-12-25 07:09 - 2014-12-25 07:09 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-12-23 09:26 - 2014-12-23 09:27 - 00047313 _____ () C:\Users\Klammer Tom\Downloads\Addition.txt
2014-12-23 09:24 - 2014-12-26 10:13 - 00000000 ____D () C:\FRST
2014-12-23 09:24 - 2014-12-23 09:27 - 00034576 _____ () C:\Users\Klammer Tom\Downloads\FRST.txt
2014-12-23 09:24 - 2014-12-23 09:24 - 01114112 _____ (Farbar) C:\Users\Klammer Tom\Desktop\FRST.exe
2014-12-23 09:20 - 2014-12-23 09:20 - 00000554 _____ () C:\Users\Klammer Tom\Downloads\defogger_disable.log
2014-12-23 09:20 - 2014-12-23 09:20 - 00000156 _____ () C:\Users\Klammer Tom\defogger_reenable
2014-12-23 09:19 - 2014-12-23 09:20 - 00050477 _____ () C:\Users\Klammer Tom\Downloads\Defogger.exe
2014-12-22 13:56 - 2014-12-22 13:56 - 04000729 _____ () C:\Users\Klammer Tom\Downloads\UPDATE-SuperSU-v2.40.zip
2014-12-22 10:39 - 2014-12-22 10:39 - 02015655 _____ () C:\Users\Klammer Tom\Downloads\Trebuchet_i9505_GPe5.zip
2014-12-22 10:37 - 2014-12-22 10:37 - 05395433 _____ () C:\Users\Klammer Tom\Downloads\GoogleDialer_Contacts_Dark_i9505_GPe5(2).zip
2014-12-22 10:36 - 2014-12-22 10:47 - 270120964 _____ () C:\Users\Klammer Tom\Downloads\Danvdh-GPE-5-12172014.zip
2014-12-20 17:12 - 2014-12-20 17:12 - 00000000 _____ () C:\Windows\system32\sho3BFF.tmp
2014-12-20 15:00 - 2014-12-20 15:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-12-20 15:00 - 2014-12-20 15:00 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-12-20 14:43 - 2014-12-20 14:43 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-12-20 13:39 - 2014-12-20 13:39 - 00001563 _____ () C:\Windows\IE11_main.log
2014-12-20 10:32 - 2014-12-20 10:32 - 00347816 _____ (Microsoft Corporation) C:\Users\Klammer Tom\Downloads\Nicht bestätigt 502266.crdownload
2014-12-20 07:31 - 2014-12-20 07:31 - 00001904 _____ () C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2014-12-20 07:30 - 2014-12-20 07:31 - 00000000 ____D () C:\Users\Klammer Tom\AppData\Roaming\DAEMON Tools Lite
2014-12-20 07:30 - 2014-12-20 07:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2014-12-20 07:30 - 2014-12-20 07:30 - 00243128 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2014-12-20 07:30 - 2014-12-20 07:30 - 00000000 ____D () C:\Program Files\DAEMON Tools Lite
2014-12-20 07:29 - 2014-12-20 07:32 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite
2014-12-20 07:14 - 2014-12-20 07:18 - 229638144 _____ () C:\Users\Klammer Tom\Downloads\gparted-live-0.20.0-2-i486.iso
2014-12-16 09:10 - 2014-12-16 09:11 - 00000000 ____D () C:\Users\Klammer Tom\Desktop\XBMC
2014-12-16 08:47 - 2014-12-17 09:05 - 00000411 _____ () C:\Users\Klammer Tom\.swfinfo
2014-12-16 07:33 - 2014-12-20 12:25 - 00000000 ____D () C:\Users\Klammer Tom\AppData\Roaming\XBMC
2014-12-16 07:30 - 2014-12-16 07:36 - 00000000 ____D () C:\Program Files\XBMC
2014-12-16 07:28 - 2014-12-16 07:29 - 63850156 _____ () C:\Users\Klammer Tom\Downloads\xbmc-13.2-Gotham.exe
2014-12-15 12:04 - 2014-12-15 12:04 - 00001099 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-12-14 18:25 - 2014-12-14 18:25 - 03044736 _____ (Enigma Software Group USA, LLC.) C:\Users\Klammer Tom\Downloads\SpyHunter-Installer.exe
2014-11-26 08:31 - 2014-11-26 08:31 - 01857948 _____ () C:\Users\Klammer Tom\Downloads\enigma2-plugin-extensions-xbmcaddons_8.0_r0_all.ipk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-26 10:10 - 2009-07-14 05:34 - 00018928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-26 10:10 - 2009-07-14 05:34 - 00018928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-26 10:07 - 2010-09-30 09:16 - 01178111 _____ () C:\Windows\WindowsUpdate.log
2014-12-26 10:04 - 2012-03-27 09:58 - 00000374 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-12-26 10:02 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-26 10:01 - 2010-10-01 07:41 - 00460370 _____ () C:\Windows\PFRO.log
2014-12-26 10:01 - 2009-07-14 05:39 - 00218909 _____ () C:\Windows\setupact.log
2014-12-26 10:00 - 2014-08-26 08:43 - 00000000 ____D () C:\AdwCleaner
2014-12-26 09:33 - 2011-04-16 17:33 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1212480921-3000280771-3724376844-1004UA.job
2014-12-26 09:26 - 2010-10-03 08:19 - 00001144 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1212480921-3000280771-3724376844-1001UA.job
2014-12-26 09:03 - 2010-09-30 09:24 - 00000000 ____D () C:\Users\Klammer Tom
2014-12-26 07:33 - 2011-04-16 17:33 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1212480921-3000280771-3724376844-1004Core.job
2014-12-25 16:26 - 2010-10-03 08:19 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1212480921-3000280771-3724376844-1001Core.job
2014-12-25 11:21 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default
2014-12-25 11:21 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2014-12-25 11:17 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2014-12-25 07:13 - 2013-08-26 08:15 - 00000000 ____D () C:\Users\Klammer Tom\AppData\Local\FuzeZip
2014-12-21 15:00 - 2010-06-29 14:26 - 01733494 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-21 14:55 - 2010-06-30 09:35 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-12-20 15:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-12-20 15:11 - 2012-06-29 17:20 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-20 15:01 - 2011-09-18 15:17 - 00000000 ____D () C:\ProgramData\Skype
2014-12-20 15:00 - 2011-09-18 15:17 - 00000000 ___RD () C:\Program Files\Skype
2014-12-20 14:54 - 2011-03-02 16:34 - 00002057 _____ () C:\Windows\epplauncher.mif
2014-12-20 14:19 - 2012-07-11 07:50 - 00002121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-12-20 14:19 - 2011-03-02 16:33 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-12-20 14:18 - 2009-07-14 03:04 - 00000478 _____ () C:\Windows\win.ini
2014-12-20 14:11 - 2013-09-27 15:43 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-20 13:53 - 2010-06-30 09:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-12-20 07:56 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-20 07:24 - 2011-09-03 14:51 - 00000000 ____D () C:\Users\Klammer Tom\AppData\Roaming\ImgBurn
2014-12-15 12:04 - 2014-08-27 06:06 - 00000000 ____D () C:\ProgramData\Package Cache
2014-12-15 12:04 - 2014-08-27 06:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-12-15 12:04 - 2014-08-27 06:04 - 00000000 ____D () C:\Program Files\Avira
2014-12-12 02:30 - 2010-10-03 08:20 - 00002396 _____ () C:\Users\Klammer Tom\Desktop\Google Chrome.lnk
2014-11-27 16:40 - 2010-06-30 09:36 - 109818608 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Klammer Tom\AppData\Local\temp\avgnt.exe
C:\Users\Klammer Tom\AppData\Local\temp\CP210xVCPInstaller_x64.exe
C:\Users\Klammer Tom\AppData\Local\temp\CP210xVCPInstaller_x86.exe
C:\Users\Klammer Tom\AppData\Local\temp\Quarantine.exe
C:\Users\Klammer Tom\AppData\Local\temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-25 14:52
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-12-2014 01
Ran by Klammer Tom at 2014-12-26 10:13:47
Running from C:\Users\Klammer Tom\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Microsoft Security Essentials (Disabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Disabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
ActvMap V 4.7 (HKLM\...\ActvMap V 4.7) (Version: - Your Company)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.7.0.2090 - Adobe Systems Incorporated)
Adobe Flash Player 11 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 11.7.700.224 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 11.7.700.224 - Adobe Systems Incorporated)
Adobe Reader X (10.1.12) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.12 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM\...\Adobe Shockwave Player) (Version: 11.6.8.638 - Adobe Systems, Inc.)
Apple Application Support (HKLM\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ATI Catalyst Install Manager (HKLM\...\{BE4AE3A7-190D-BCB8-A953-A708C9E8E8AA}) (Version: 3.0.778.0 - ATI Technologies, Inc.)
Avira (HKLM\...\{e7c7c227-b742-4878-9425-f09bbf9951db}) (Version: 1.1.27.25527 - Avira Operations & Co. KG)
Avira (Version: 1.1.27.25527 - Avira Operations & Co. KG) Hidden
Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira)
AVM FRITZ!Fernzugang (HKLM\...\{F2B03BB1-D679-4FFF-951D-3058A669A823}) (Version: 1.3.1 - AVM Berlin)
AZtrinoLoader (HKLM\...\{EAC850A4-5422-4632-9AFC-A33EC41B6F7E}) (Version: 1.1 - OpenSat)
AZUp (HKLM\...\{FBDBE1F0-AED1-496B-BCBA-7E2608D622FC}) (Version: 1.00.0000 - RTi)
Bi-LINK Gateway (HKLM\...\{63041551-16E0-4841-AC48-92A825711C93}) (Version: 1.00.5000 - Ihr Firmenname)
Brother BRAdmin Light 1.21.0002 (HKLM\...\{DB75941E-30C4-4D97-B000-D17C764B998C}) (Version: 1.21.0002 - Brother)
Bürgerkarte/Carta Servizi (HKLM\...\{CB610D37-34F7-4D85-AE73-EAA9BE748B4F}) (Version: 1.0.0 - Autonome Provinz Bozen/Provincia Autonoma di Bolzano)
CandyBox (HKLM\...\CandyBox_is1) (Version: - )
Canon Camera DV WIA Driver 6.1.2 (HKLM\...\InstallShield_{4CA5A658-D909-4F52-94FF-A2D02868D9F0}) (Version: 6.1.2 - Canon)
Canon DV WIA Driver (Version: 6.1.2 - Canon) Hidden
CardOS API (HKLM\...\{8E814717-DE49-4A4A-BD12-39102F9C9FD0}) (Version: 3.3.018 - Siemens IT Solutions and Services GmbH)
CAS Interface Studio 9.0.0 (HKLM\...\{198BDA47-7F40-4F2D-9214-07FF720BF39A}) (Version: 9.0.0 - Duolabs)
ccc-core-static (Version: 2010.0527.1242.20909 - ATI) Hidden
CorelDRAW Essentials 4 - Content (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Draw (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Filters (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - ICA (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - IPM - No VBA (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang BR (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang DE (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang EN (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang ES (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang FR (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang IT (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang NL (Version: 4.0 - Uw bedrijfsnaam) Hidden
CorelDRAW Essentials 4 - PHOTO-PAINT (Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Windows Shell Extension (HKLM\...\_{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}) (Version: - Corel Corporation)
CorelDRAW Essentials 4 - Windows Shell Extension (Version: 1.1 - Corel Corporation) Hidden
CorelDRAW Essentials 4 (HKLM\...\_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}) (Version: - Corel Corporation)
CorelDRAW Essentials 4 (Version: 4.0 - Corel Corporation) Hidden
CyberLink LabelPrint (HKLM\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2515 - CyberLink Corp.)
CyberLink Power2Go (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3602c - CyberLink Corp.)
CyberLink PowerDVD Copy (HKLM\...\InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}) (Version: 1.5.1306 - CyberLink Corp.)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
DirectVobSub 2.40.4209 (HKLM\...\vsfilter_is1) (Version: 2.40.4209 - MPC-HC Team)
DivX-Setup (HKLM\...\DivX Setup) (Version: 2.6.1.8 - DivX, LLC)
DogSettings Version 1.5.0.1 (HKLM\...\{7A03618C-AD50-4BDC-BA2E-A172A4410C73}_is1) (Version: 1.5.0.1 - DogStrike)
ffdshow v1.1.4399 [2012-03-22] (HKLM\...\ffdshow_is1) (Version: 1.1.4399.0 - )
Fitbit Connect (HKLM\...\Fitbit Connect) (Version: 1.0.0.2578 - Fitbit Inc.)
Fotogalerie (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
FoxyDeal version 1.0.0 (HKLM\...\FoxyDeal_is1) (Version: 1.0.0 - R&E Media GmbH)
Free MP3 Cutter and Editor 2.6 (HKLM\...\Free MP3 Cutter and Editor_is1) (Version: - musetips.com)
FRITZ!Box-Fernzugang einrichten (HKLM\...\{EFADD989-D9F2-49F6-A280-675951CC78D3}) (Version: 1.0.3 - AVM Berlin)
Garmin Communicator Plugin (HKLM\...\{647BB978-2876-487B-9B0E-FDB73F0EA4A2}) (Version: 4.0.4 - Garmin Ltd or its subsidiaries)
Garmin MapSource (HKLM\...\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}) (Version: 6.16.3 - Garmin Ltd or its subsidiaries)
Garmin Training Center (HKLM\...\{7D542452-84EB-47C0-97BA-735C523AB555}) (Version: 3.6.5 - Garmin Ltd or its subsidiaries)
Garmin USB Drivers (HKLM\...\{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries)
Garmin WebUpdater (HKLM\...\{AE1EC58E-B2AC-4959-A4C2-C38202A25239}) (Version: 2.5.6 - Garmin Ltd or its subsidiaries)
GO Contact Sync Mod (HKLM\...\{B805EB38-C9ED-4102-89AA-C1F25F945F57}) (Version: 3.5.17 - WebGear, Create Software, Stru.be, saller.NET)
Google Chrome (HKU\S-1-5-21-1212480921-3000280771-3724376844-1001\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Drive (HKLM\...\{418BAAD1-754D-48B4-B078-46EF4F25AF42}) (Version: 1.15.6556.8063 - Google, Inc.)
Google Talk Plugin (HKLM\...\{0C5C1177-94C5-3EFB-A8BE-3F6AF1AF887F}) (Version: 5.38.6.0 - Google)
Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden
ImgBurn (HKLM\...\ImgBurn) (Version: 2.5.6.0 - LIGHTNING UK!)
Intel(R) Rapid Storage Technology (HKLM\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.0.1014 - Intel Corporation)
iTunes (HKLM\...\{2F21564D-DE05-4C6D-B21E-08B9D313FAB3}) (Version: 11.1.5.5 - Apple Inc.)
Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
JDownloader (HKLM\...\JDownloader) (Version: - AppWork UG (haftungsbeschränkt))
Junk Mail filter update (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Medion Home Cinema (HKLM\...\InstallShield_{AB770FDE-8087-4C98-9A85-BD64262C104C}) (Version: 6.0.0000 - CyberLink Corp.)
Medion Home Cinema (Version: 6.0.0000 - CyberLink Corp.) Hidden
Microsoft .NET Framework 1.1 (HKLM\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Help Viewer 1.0 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.0 Language Pack - DEU) (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Office 2010 (HKLM\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}) (Version: - Microsoft)
Microsoft Office Klick-und-Los 2010 (HKLM\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM\...\{95140000-007A-0407-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Professional 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - Deutsch (HKLM\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM\...\{95140000-007D-0409-0000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-1212480921-3000280771-3724376844-1001\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [DEU] (HKLM\...\{BAC80EF3-E106-4AEA-8C57-F217F9BC7358}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 DEU (HKLM\...\{0125D081-30D0-4A97-82A8-C28D444B6256}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual FoxPro OLE DB Provider (HKLM\...\{3DA245C5-23B1-4874-BFA7-287B7D6C1EF6}) (Version: 1.0.0 - Microsoft Corporation)
miniLector (Version: 3.0.0 - Bit4Id) Hidden
MiniTool Partition Wizard Home Edition 8.1.1 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.)
MoneyManagerEX Version 0.9.8.0 (HKLM\...\{2C48DC11-E113-4912-8AFC-366D1918101E}_is1) (Version: 0.9.8.0 - CodeLathe, LLC)
Movie Maker (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
MyPhoneExplorer (HKLM\...\MPE) (Version: 1.8.5 - F.J. Wechselberger)
Photocity Silver 3.2.5.2 (HKLM\...\Photocity Silver_is1) (Version: 3.2.5.2 - Photocity.it)
PL-2303 USB-to-Serial (HKLM\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.7.0 - Prolific Technology INC)
PlayMemories Home (HKLM\...\{0657DE52-8F5C-4073-B70C-ED4F3F7FA076}) (Version: 7.0.03.04240 - Sony Corporation)
PlayReady PC Runtime x86 (HKLM\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
PocketCloud Windows Companion (HKLM\...\{BD8F867A-0ACB-427D-A4F2-9AEE29FBF98B}) (Version: 2.4.19 - Wyse Technology)
PSPad editor (HKLM\...\PSPad editor_is1) (Version: - Jan Fiala)
Qtrax Player (HKLM\...\{89505A66-35F0-4401-B3AD-D077051F8698}) (Version: 01.001.0001 - Qtrax)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6083 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.)
Samsung Kies (Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.) Hidden
Samsung Story Album Viewer (HKLM\...\InstallShield_{698BBAD8-B116-495D-B879-0F07A533E57F}) (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.)
Samsung Story Album Viewer (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.25.0 - SAMSUNG Electronics Co., Ltd.)
Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.6.8442 - Skype Technologies S.A.)
Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Sony Image Data Suite (HKLM\...\{359FCAA7-B544-4147-AE3B-8C8A526E2427}) (Version: 3.2.00.15160 - Sony Corporation)
Spelling Dictionaries Support For Adobe Reader 9 (HKLM\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TomTom HOME 2.8.3.2499 (HKLM\...\TomTom HOME) (Version: 2.8.3.2499 - TomTom)
TomTom HOME Visual Studio Merge Modules (HKLM\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: 7.55a - Ghisler Software GmbH)
Twinbase Manager 2.11 (HKLM\...\{D6FA5A7E-C500-4D00-9F6E-72572A613076}) (Version: 2.1.1 - Duolabs)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) (HKLM\...\49CF605F02C7954F4E139D18828DE298CD59217C) (Version: 06/03/2009 2.3.0.0 - Garmin)
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Windows Live Sync (HKLM\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
Windows Mobile-Gerätecenter (HKLM\...\{904CCF62-818D-4675-BC76-D37EB399F917}) (Version: 6.1.6965.0 - Microsoft Corporation)
WinRAR (HKLM\...\WinRAR archiver) (Version: - )
WinZip 14.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}) (Version: 14.5.9095 - WinZip Computing, S.L. )
XBMC (HKU\S-1-5-21-1212480921-3000280771-3724376844-1001\...\XBMC) (Version: - Team XBMC)
Xvid Video Codec (HKLM\...\Xvid Video Codec 1.3.2) (Version: 1.3.2 - Xvid Team)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.21.135\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 -> No File Path
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{0E55CBE1-B06A-49B6-AD8D-9EFAA0160C6F}\InprocServer32 -> No File Path
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.25.5\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{218D2740-5A50-42A8-AB9F-62FF1B168782}\InprocServer32 -> No File Path
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{29A96789-9595-4947-BEDB-0FCC776F7DB8}\InprocServer32 -> No File Path
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{320F0FDB-BE0A-4648-9D18-4A2C3448C007}\InprocServer32 -> No File Path
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.23.9\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{39125640-8D80-11DC-A2FE-C5C455D89593}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Google Talk Plugin\googletalkax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{50BAEED9-ED25-11D2-B97B-000000000000}\InprocServer32 -> C:\Program Files\Common Files\System\ole db\vfpoledb.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{50BAEEDA-ED25-11D2-B97B-000000000000}\InprocServer32 -> C:\Program Files\Common Files\System\ole db\vfpoledb.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{50BAEEDB-ED25-11D2-B97B-000000000000}\InprocServer32 -> C:\Program Files\Common Files\System\ole db\vfpoledb.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\39.0.2171.95\delegate_execute.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.21.145\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.21.123\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.21.153\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}\localserver32 -> C:\Users\Klammer Tom\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.24.15\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.21.149\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.22.3\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.21.165\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}\localserver32 -> C:\Users\Klammer Tom\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{AB9F4455-E591-4132-A386-0B91EAEDB96C}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Google Talk Plugin\o1dax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.21.115\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{DB25D157-76D4-41C1-97B5-359E4A4CECEB}\InprocServer32 -> No File Path
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.25.11\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{EB06378B-ABB6-4B3C-9B40-D488DD8A6E93}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.22.5\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\FileSyncApi.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.21.111\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1212480921-3000280771-3724376844-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Klammer Tom\AppData\Local\Google\Update\1.3.24.7\psuser.dll No File
==================== Restore Points =========================
25-12-2014 07:11:28 Revo Uninstaller's restore point - FuzeZip
25-12-2014 07:12:36 Revo Uninstaller's restore point - FuzeZip
25-12-2014 07:16:07 Windows Update
26-12-2014 09:38:03 Installed Bi-LINK Gateway.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:04 - 2014-12-25 11:15 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0C075D54-3C83-47AE-96DC-6D1705C848A4} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION
Task: {19813342-5F48-4A54-9390-D26920556680} - System32\Tasks\{F2DCD6C3-BF98-489E-B052-01BE7BD554EE} => C:\Program Files\Skype\\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {284CF58D-6BE8-4E41-A012-24361695D8A5} - System32\Tasks\PenWes => C:\Program Files\PenWes\penwes.exe <==== ATTENTION
Task: {330509CC-EE4F-425C-BE40-488C1558A958} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21] (Adobe Systems Incorporated)
Task: {399D78B7-B851-4413-8D40-A6AB8A0ECF99} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1212480921-3000280771-3724376844-1004UA => C:\Users\Babsi\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-29] (Google Inc.)
Task: {4208095E-90B5-493F-B570-F2C2D8A23D89} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-10-07] (Oracle Corporation)
Task: {481CA072-544A-47B8-83FA-7A3B64A8ECB2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1212480921-3000280771-3724376844-1001UA => C:\Users\Klammer Tom\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-18] (Google Inc.)
Task: {4869E72E-E196-48D0-ABDD-176F339B2521} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1212480921-3000280771-3724376844-1004Core => C:\Users\Babsi\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-29] (Google Inc.)
Task: {581B7E0B-9842-42DA-AA23-69B8655E0C5F} - System32\Tasks\{2EAB9CC2-169B-4675-BF9B-ED3BAE64C025} => pcalua.exe -a "C:\Users\Klammer Tom\Desktop\softonic-Deutsch.exe" -d "C:\Users\Klammer Tom\Desktop"
Task: {638D1223-EC23-4228-B56B-5ECB6BA45629} - System32\Tasks\{AFF0020B-802C-4926-9147-C1148DD84125} => pcalua.exe -a E:\setup.exe -d E:\
Task: {76206859-0407-4871-BD88-722836584F58} - System32\Tasks\{3025F925-A23B-4DFA-9F64-1405AC642E88} => pcalua.exe -a "C:\Users\Klammer Tom\AppData\Local\Temp\Temp1_VirtualDub-1.9.11.zip\auxsetup.exe"
Task: {80EFFEBC-270B-4A27-B395-8234F889E59F} - System32\Tasks\{7E71D9BD-7640-4392-89A6-1625CA74C655} => pcalua.exe -a "C:\Users\Klammer Tom\Downloads\TrainingCenter_365.exe" -d "C:\Users\Klammer Tom\Downloads"
Task: {993C1955-53FD-445D-B4A8-EBD1B107DA35} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A759210A-94AB-4D08-90B8-9FD90E85C24A} - System32\Tasks\Google Updater and Installer => C:\Users\Klammer Tom\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-18] (Google Inc.)
Task: {C92AA16A-F023-4BD7-B6C9-009437BC25B9} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {D306B6AF-5917-4293-9B20-37ABA78E4906} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1212480921-3000280771-3724376844-1001Core => C:\Users\Klammer Tom\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-18] (Google Inc.)
Task: {F5BEDD76-F567-44D4-A46A-A374FE34B733} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1212480921-3000280771-3724376844-1001Core.job => C:\Users\Klammer Tom\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1212480921-3000280771-3724376844-1001UA.job => C:\Users\Klammer Tom\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1212480921-3000280771-3724376844-1004Core.job => C:\Users\Babsi\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1212480921-3000280771-3724376844-1004UA.job => C:\Users\Babsi\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-02-12 19:58 - 2014-02-12 19:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 19:58 - 2014-02-12 19:58 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2012-05-11 14:09 - 2012-05-11 14:09 - 00177056 _____ () C:\Program Files\Wyse\PocketCloud Windows Companion\PocketCloudService.exe
2012-05-11 14:05 - 2012-05-11 14:05 - 00056832 _____ () C:\Program Files\Wyse\PocketCloud Windows Companion\ServerNetworkInterface.dll
2012-05-11 14:06 - 2012-05-11 14:06 - 01590272 _____ () C:\Program Files\Wyse\PocketCloud Windows Companion\AetherCommLib.dll
2012-05-11 14:04 - 2012-05-11 14:04 - 00061440 _____ () C:\Program Files\Wyse\PocketCloud Windows Companion\WyseWebServerLib.DLL
2013-02-13 03:37 - 2013-02-13 03:37 - 01263952 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe
2013-02-13 03:38 - 2013-02-13 03:38 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
2008-04-18 14:56 - 2008-04-18 14:56 - 00311296 _____ () C:\Windows\system32\siecaces.dll
2007-04-16 12:01 - 2007-04-16 12:01 - 00184320 _____ () C:\Windows\system32\gmp4_2_1.dll
2010-05-27 20:40 - 2010-05-27 20:40 - 00270336 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2014-12-20 14:21 - 2014-12-20 14:21 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\818c5277bd028fb9cb78a30e3720eb0f\IsdiInterop.ni.dll
2010-06-29 16:19 - 2010-03-04 04:08 - 00058880 _____ () C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2011-01-19 07:45 - 2010-03-15 11:28 - 00141824 _____ () C:\Program Files\WinRAR\rarext.dll
2014-12-12 02:30 - 2014-12-06 02:50 - 01077064 _____ () C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\39.0.2171.95\libglesv2.dll
2014-12-12 02:30 - 2014-12-06 02:50 - 00211272 _____ () C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\39.0.2171.95\libegl.dll
2014-12-12 02:30 - 2014-12-06 02:50 - 09009480 _____ () C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\39.0.2171.95\pdf.dll
2014-12-12 02:30 - 2014-12-06 02:50 - 01677128 _____ () C:\Users\Klammer Tom\AppData\Local\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CardOS API.lnk => C:\Windows\pss\CardOS API.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Klammer Tom^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Widget vodafone.lnk => C:\Windows\pss\Widget vodafone.lnk.Startup
MSCONFIG\startupreg: CLMLServer => "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: IAStorIcon => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
MSCONFIG\startupreg: PocketCloud Location => C:\Program Files\Wyse\PocketCloud Windows Companion\WyseBrowser.exe
========================= Accounts: ==========================
Administrator (S-1-5-21-1212480921-3000280771-3724376844-500 - Administrator - Disabled)
ASPNET (S-1-5-21-1212480921-3000280771-3724376844-1008 - Limited - Enabled)
Babsi (S-1-5-21-1212480921-3000280771-3724376844-1004 - Limited - Enabled) => C:\Users\Babsi
Gast (S-1-5-21-1212480921-3000280771-3724376844-501 - Limited - Disabled) => C:\Users\Gast
HomeGroupUser$ (S-1-5-21-1212480921-3000280771-3724376844-1003 - Limited - Enabled)
Klammer Tom (S-1-5-21-1212480921-3000280771-3724376844-1001 - Administrator - Enabled) => C:\Users\Klammer Tom
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: Pentium(R) Dual-Core CPU E5700 @ 3.00GHz
Percentage of memory in use: 52%
Total physical RAM: 3071.24 MB
Available physical RAM: 1456.25 MB
Total Pagefile: 6140.77 MB
Available Pagefile: 3778.32 MB
Total Virtual: 2047.88 MB
Available Virtual: 1908.26 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:890.41 GB) (Free:598.61 GB) NTFS
Drive d: (Recover) (Fixed) (Total:40 GB) (Free:23.53 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=82 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=890.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=40 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
==================== End Of Log ============================ |