Energie2000 | 18.01.2015 10:45 | Hallo Schrauber,
noch vorab - ich habe meinen Virenscanner MS Essentials, wie gefordert, deinstalliert.
Würdest Du den wieder empfehlen oder einen anderen?
Hier die 4 Dateien: Code:
----------------
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.01.2015
Suchlauf-Zeit: 10:00:03
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.01.18.05
Rootkit Datenbank: v2015.01.14.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: labuhn
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 353884
Verstrichene Zeit: 5 Min, 46 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 1
Trojan.Agent, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}, In Quarantäne, [8756e018d7b22610621802ffa75b649c],
Registrierungswerte: 0
(Keine schädliche Elemente erkannt)
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 0
(Keine schädliche Elemente erkannt)
Dateien: 6
Trojan.Agent, C:\Program Files (x86)\uNiisales\uNiisales.exe, In Quarantäne, [b22bb048701971c5e09ae71a37cb6c94],
Trojan.Agent, C:\Program Files (x86)\Live Radio Stations\Live Radio Stations.exe, In Quarantäne, [8756e018d7b22610621802ffa75b649c],
PUP.Optional.RegCleanerPro, C:\Users\labuhn\Downloads\rcpsetup_softonic_new_de_ros_new.exe, In Quarantäne, [18c576821d6ca78f5c4d71bc8180b54b],
PUP.Optional.Softonic, C:\Users\labuhn\Downloads\SoftonicDownloader_for_classic-pdf-editor.exe, In Quarantäne, [ad30e3150089d46277f7260152af48b8],
PUP.Optional.Softonic.A, C:\Users\labuhn\Downloads\SoftonicDownloader_fuer_pdf-redirect.exe, In Quarantäne, [b429a65264256cca2aa2281ab94848b8],
PUP.Optional.Somoto.A, C:\Users\labuhn\Downloads\VLCVideoConverterSetup.exe, In Quarantäne, [d10c14e4bdcc0d295f12a98f57a92bd5],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end)
---------------- Code:
----------------AdwCleaner Logfile:
Code:
# AdwCleaner v4.108 - Bericht erstellt am 18/01/2015 um 10:21:55
# Aktualisiert 17/01/2015 von Xplode
# Database : 2015-01-13.2 [Live]
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : labuhn - LABUHN-THINK
# Gestartet von : C:\Users\labuhn\Downloads\AdwCleaner_4.108.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\labuhn\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\labuhn\AppData\Roaming\Solvusoft
Datei Gelöscht : C:\Windows\Reimage.ini
Datei Gelöscht : C:\Windows\System32\roboot64.exe
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Pd7b173e2_2274_4119_89d1_396c57691e07_.Pd7b173e2_2274_4119_89d1_396c57691e07_
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Pd7b173e2_2274_4119_89d1_396c57691e07_.Pd7b173e2_2274_4119_89d1_396c57691e07_.9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{d7b173e2-2274-4119-89d1-396c57691e07}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d7b173e2-2274-4119-89d1-396c57691e07}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{d7b173e2-2274-4119-89d1-396c57691e07}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Reimage
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4CEE92A3-9F0C-51AB-ADC0-34EC24AD7B7E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Reimage
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v35.0 (x86 de)
-\\ Google Chrome v
*************************
AdwCleaner[R1].txt - [4647 octets] - [18/01/2015 10:18:47]
AdwCleaner[R2].txt - [4707 octets] - [18/01/2015 10:21:18]
AdwCleaner[S1].txt - [4284 octets] - [18/01/2015 10:21:55]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4344 octets] ########## --- --- ---
---------------- Code:
----------------JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Professional x64
Ran by labuhn on 18.01.2015 at 10:25:59,68
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\Users\labuhn\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com"
Successfully deleted: [File] C:\Windows\prefetch\DRIVERINSTALLERUTILITY.EXE-58FE0B56.pf
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\pcdr"
Successfully deleted: [Folder] "C:\Users\labuhn\AppData\Roaming\pcdr"
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{0FC9258D-424B-4225-A251-90002CC6466A}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{1590045A-4A65-46A4-BFB1-F8AE1895620E}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{1B52B66B-2EA9-4F18-865D-441D138A4923}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{1C436D92-1CEE-4BE5-9FA9-F13BEC705804}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{2838C558-6176-4648-B364-969F60983C0B}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{2C0329A4-F17D-40EA-8355-9A8E4F247338}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{33D2EFF2-24DC-492C-A343-ED77AF2EF8E9}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{41901703-0D31-4B14-ACC4-7E66C1A29D12}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{525453DB-A871-4220-914A-D7F917670AFD}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{5B6E9145-6268-4ED7-B71D-20E2AD8920E8}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{5EEC2651-B9B3-455A-809D-8617F2B9A0E5}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{603B241E-4C0F-4379-BCFC-6629F062D6E7}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{612F8AF9-6248-4FB7-862A-8864DB547239}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{6520D803-CE23-4BA9-9F93-2BDCF6BD7FF4}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{6676FBD9-1F3F-4193-96D6-5E5060D33D5F}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{6CEFA8ED-D54C-4128-A504-9F25EAD4B467}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{6EE9FFFB-2051-4344-AA0E-E2389AF63B65}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{6FCCB274-D888-4F56-9900-21A4BFCB88A7}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{702FEFB7-81F3-4CD4-BDD1-2BEE289ACDF0}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{70D53656-9BF2-41CD-825B-D1C74A5E7849}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{75A2A55C-ED9C-4749-B800-79EE3F1F6D6F}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{798AD570-B6ED-4858-9BEC-1B0BAEC0BFD5}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{7B3FCCF6-E81D-49C5-BF81-80A71481FBA0}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{9543B6D4-36A8-454E-82B7-F3D48D183432}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{96058351-1103-4445-BD73-62DBFF2A8F48}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{B289609A-4F3E-4A67-B469-1AB520DC9AAB}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{B5D32317-40AA-4167-88CD-FEE4465CF362}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{C3D1BB86-D0C0-4D26-8E95-14D590809145}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{C700976D-770F-4E83-93E3-00FDB1ECF7BE}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{C8CEB996-76E4-46D8-8581-3ED096B2080D}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{CB4E57A8-E359-4544-A64A-00E8FB181EFF}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{CD1C7B9C-EBD0-4413-B7BA-2B4DA883467E}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{CE6C7E97-DAA6-44B2-937F-6488851B8179}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{CFCCAB34-98C7-496D-92F6-DE5763EBBDC6}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{D170AA75-7EF0-4A5A-845D-2D4CB3A6B6F5}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{D2693611-654E-44CF-ADCB-66C6D8D96043}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{D62A84DA-A8CA-4988-A8D7-B046F14F8417}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{E0AD3550-E14B-43F8-87D6-E76B154F4AF9}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{E28A6FC9-9D8B-40D3-AA46-02738C4D9C5A}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{ECA27AFF-9BDC-4384-999D-2796E446D0D3}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{ED08F12A-4C20-4662-87DF-F9064C45EA76}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{EEB95024-3F3F-47DA-9A08-1CE69E4A26B4}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{F4BEC5AE-58A5-45CF-9952-C53718F7D524}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{F70F8B9D-6510-4E81-B20F-B506DAA4A784}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{F8C8C3FB-6E12-4193-B0AF-155A1E3CD127}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{FC58236B-EDB0-43DC-99EF-E4014B0FE59B}
Successfully deleted: [Empty Folder] C:\Users\labuhn\appdata\local\{FD22A05C-890D-4B88-B21E-1FC27E913661}
~~~ FireFox
Successfully deleted the following from C:\Users\labuhn\AppData\Roaming\mozilla\firefox\profiles\sbb75ta0.default\prefs.js
user_pref("extensions.guL2r1PD6Gt3PTzf.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnale
user_pref("extensions.yUPYt5aFjCeWPuIB.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnale
user_pref("extensions.yUPYt5aFjCeWPuIB.url", "hxxp://json-jpi.info/sync2/?q=hfZ9ofV9CShEAen0rTw6qHrMg708BNmGWj8wmihGheDUojw8rdwFrja5qjU9qGhIC7n0rjkErjwFrdUErdsFtNhVCT94tMVKhd9
Emptied folder: C:\Users\labuhn\AppData\Roaming\mozilla\firefox\profiles\sbb75ta0.default\minidumps [14 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.01.2015 at 10:29:23,67
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
---------------- Code:
----------------
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-01-2015
Ran by labuhn (administrator) on LABUHN-THINK on 18-01-2015 10:35:49
Running from C:\Users\labuhn\Desktop
Loaded Profiles: labuhn (Available profiles: UpdatusUser & labuhn)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Authentec Inc.) C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(X-Rite Inc.) C:\Program Files (x86)\X-Rite\Devices\Services\xritedeviced.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(X-Rite Inc.) C:\Program Files (x86)\X-Rite\Devices\Services\i1Display\i1DisplayDeviceService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\AutoLock\ALCKRESI.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(X-Rite Inc.) C:\Program Files (x86)\X-Rite\Devices\Lib\xritelegacyd.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ZOOM\TpScrex.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe
(Lenovo.) C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2789160 2011-05-19] (Synaptics Incorporated)
HKLM\...\Run: [TpShocks] => C:\Windows\system32\TpShocks.exe [380776 2010-12-09] (Lenovo.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2011-03-14] (Conexant systems, Inc.)
HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [40808 2011-05-31] (Lenovo Group Limited)
HKLM\...\Run: [ALCKRESI.EXE] => C:\Program Files\Lenovo\AutoLock\ALCKRESI.EXE [281960 2011-05-25] (Lenovo Group Limited)
HKLM\...\Run: [cssauth] => C:\Program Files\Lenovo\Client Security Solution\cssauth.exe [5990200 2011-06-10] (Lenovo Group Limited)
HKLM\...\Run: [AcWin7Hlpr] => C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe [63776 2014-07-10] (Lenovo)
HKLM-x32\...\Run: [RotateImage] => C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-01-17] (Intel Corporation)
HKLM-x32\...\Run: [PWMTRV] => rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
HKLM-x32\...\Run: [X-Rite Legacy Device] => C:\Program Files (x86)\X-Rite\Devices\Lib\xritelegacyd.exe [105984 2010-09-28] (X-Rite Inc.)
HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-13] (Lenovo, Inc.)
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [98616 2008-04-17] (ArcSoft Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [413696 2008-03-28] (Apple Inc.)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [193568 2014-11-28] (Geek Software GmbH)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (Authentec Inc.)
HKU\S-1-5-21-1102651152-2822926887-2028513216-1001\...\Run: [LTT] => C:\Program Files\PC-Doctor\EnableToolbarW32.exe [23120 2011-06-27] (PC-Doctor, Inc.)
HKU\S-1-5-21-1102651152-2822926887-2028513216-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7394584 2014-12-12] (Piriform Ltd)
AppInit_DLLs-x32: c:\Windows\SysWOW64\nvinit.dll => c:\Windows\SysWOW64\nvinit.dll [202600 2012-11-02] (NVIDIA Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1102651152-2822926887-2028513216-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1102651152-2822926887-2028513216-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1102651152-2822926887-2028513216-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1102651152-2822926887-2028513216-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENP_deDE462
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Symantec VIP Access Add-On -> {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} -> C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: IePasswordManagerHelper Class -> {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} -> C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
BHO-x32: Symantec VIP Access Add-On -> {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} -> C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation)
Toolbar: HKU\S-1-5-21-1102651152-2822926887-2028513216-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\labuhn\AppData\Roaming\Mozilla\Firefox\Profiles\sbb75ta0.default
FF NewTab: www.google.de
FF SelectedSearchEngine: Bing
FF Homepage: hxxp://www.google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.15.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\labuhn\AppData\Roaming\Mozilla\Firefox\Profiles\sbb75ta0.default\searchplugins\ChatZumSearch.xml
FF SearchPlugin: C:\Users\labuhn\AppData\Roaming\Mozilla\Firefox\Profiles\sbb75ta0.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\labuhn\AppData\Roaming\Mozilla\Firefox\Profiles\sbb75ta0.default\searchplugins\google-maps.xml
FF Extension: Flashblock - C:\Users\labuhn\AppData\Roaming\Mozilla\Firefox\Profiles\sbb75ta0.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2015-01-17]
FF Extension: Adblock Plus Pop-up Addon - C:\Users\labuhn\AppData\Roaming\Mozilla\Firefox\Profiles\sbb75ta0.default\Extensions\adblockpopups@jessehakanen.net.xpi [2015-01-17]
FF Extension: Element Hiding Helper for Adblock Plus - C:\Users\labuhn\AppData\Roaming\Mozilla\Firefox\Profiles\sbb75ta0.default\Extensions\elemhidehelper@adblockplus.org.xpi [2015-01-17]
FF Extension: Flash Block - C:\Users\labuhn\AppData\Roaming\Mozilla\Firefox\Profiles\sbb75ta0.default\Extensions\{95ab36d4-fb6f-47b0-8b8d-e5f3bd547953}.xpi [2015-01-17]
FF Extension: Adblock Plus - C:\Users\labuhn\AppData\Roaming\Mozilla\Firefox\Profiles\sbb75ta0.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-11-15]
FF Extension: Adblock Edge - C:\Users\labuhn\AppData\Roaming\Mozilla\Firefox\Profiles\sbb75ta0.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2015-01-17]
FF HKLM-x32\...\Firefox\Extensions: [VIP2X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client
FF Extension: Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client [2011-12-11]
FF HKLM-x32\...\Firefox\Extensions: [VIP3X@verisign.com] - C:\Program Files (x86)\Symantec\VIP Access Client
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\labuhn\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM-x32\...\Chrome\Extension: [ofbhmgdnoeallignocbmcpnpondfanip] - C:\ProgramData\SaveByclick\ofbhmgdnoeallignocbmcpnpondfanip.crx [Not Found]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [102712 2008-04-17] (ArcSoft Inc.) [File not signed]
R3 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [478056 2011-08-31] (Lenovo.)
R2 i1 Display Service; C:\Program Files (x86)\X-Rite\Devices\Services\i1Display\i1DisplayDeviceService.exe [163328 2010-09-28] (X-Rite Inc.) [File not signed]
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [272776 2014-10-16] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [50688 2011-04-13] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [66048 2011-04-13] (Hewlett-Packard) [File not signed]
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [24560 2014-06-18] ()
R2 UleadBurningHelper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [61440 2008-01-10] (Ulead Systems, Inc.) [File not signed]
R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [84080 2011-12-05] (Symantec Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-07-14] (Microsoft Corporation)
R2 xritedeviced; C:\Program Files (x86)\X-Rite\Devices\Services\xritedeviced.exe [142848 2010-09-28] (X-Rite Inc.) [File not signed]
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3325232 2012-06-25] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-18] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [284008 2012-11-02] (NVIDIA Corporation)
R2 smihlp; C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [13128 2011-05-30] (Authentec Inc.)
R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [41536 2009-09-24] (Lenovo (United States) Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz134; \??\C:\Users\labuhn\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 PCDSRVC{127174DC-C366ED8B-06020200}_0; \??\c:\program files\pc-doctor\pcdsrvc_x64.pkms [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-18 10:34 - 2015-01-18 10:34 - 00000000 ___DC () C:\Users\labuhn\Desktop\FRST-OlderVersion
2015-01-18 10:29 - 2015-01-18 10:29 - 00006786 ____C () C:\Users\labuhn\Desktop\JRT.txt
2015-01-18 10:25 - 2015-01-18 10:25 - 01707939 ____C (Thisisu) C:\Users\labuhn\Downloads\JRT.exe
2015-01-18 10:25 - 2015-01-18 10:25 - 00000000 ___DC () C:\Windows\ERUNT
2015-01-18 10:23 - 2015-01-18 10:23 - 00004464 ____C () C:\Users\labuhn\Desktop\AdwCleaner[S1].txt
2015-01-18 10:18 - 2015-01-18 10:21 - 00000000 ___DC () C:\AdwCleaner
2015-01-18 10:17 - 2015-01-18 10:17 - 02186752 ____C () C:\Users\labuhn\Downloads\AdwCleaner_4.108.exe
2015-01-18 10:13 - 2015-01-18 10:13 - 00002123 ____C () C:\Users\labuhn\Desktop\mbam.txt
2015-01-18 09:58 - 2015-01-18 10:30 - 00129752 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-18 09:57 - 2015-01-18 09:57 - 00001117 ____C () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-18 09:57 - 2015-01-18 09:57 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-18 09:57 - 2015-01-18 09:57 - 00000000 ___DC () C:\ProgramData\Malwarebytes
2015-01-18 09:57 - 2015-01-18 09:57 - 00000000 ___DC () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-18 09:57 - 2014-11-21 06:14 - 00093400 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-18 09:57 - 2014-11-21 06:14 - 00063704 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-18 09:57 - 2014-11-21 06:14 - 00025816 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-18 09:55 - 2015-01-18 09:56 - 20447072 ____C (Malwarebytes Corporation ) C:\Users\labuhn\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-17 20:55 - 2015-01-17 20:55 - 00032317 ____C () C:\ComboFix.txt
2015-01-17 20:48 - 2015-01-17 20:55 - 00000000 ___DC () C:\Qoobox
2015-01-17 20:48 - 2015-01-17 20:54 - 00000000 ___DC () C:\Windows\erdnt
2015-01-17 20:48 - 2011-06-26 07:45 - 00256000 ____C () C:\Windows\PEV.exe
2015-01-17 20:48 - 2010-11-07 18:20 - 00208896 ____C () C:\Windows\MBR.exe
2015-01-17 20:48 - 2009-04-20 05:56 - 00060416 ____C (NirSoft) C:\Windows\NIRCMD.exe
2015-01-17 20:48 - 2000-08-31 01:00 - 00518144 ____C (SteelWerX) C:\Windows\SWREG.exe
2015-01-17 20:48 - 2000-08-31 01:00 - 00406528 ____C (SteelWerX) C:\Windows\SWSC.exe
2015-01-17 20:48 - 2000-08-31 01:00 - 00098816 ____C () C:\Windows\sed.exe
2015-01-17 20:48 - 2000-08-31 01:00 - 00080412 ____C () C:\Windows\grep.exe
2015-01-17 20:48 - 2000-08-31 01:00 - 00068096 ____C () C:\Windows\zip.exe
2015-01-17 20:45 - 2015-01-18 10:22 - 00005618 ____C () C:\Windows\PFRO.log
2015-01-17 20:29 - 2015-01-17 20:29 - 05609736 ___RC (Swearware) C:\Users\labuhn\Desktop\ComboFix.exe
2015-01-17 20:26 - 2015-01-17 20:27 - 00000000 ___DC () C:\Users\labuhn\Downloads\RevoUninstallerPortable
2015-01-17 20:25 - 2015-01-17 20:25 - 02785665 ____C (PortableApps.com) C:\Users\labuhn\Downloads\RevoUninstallerPortable_1.95_Rev_2.paf.exe
2015-01-17 20:14 - 2015-01-17 20:14 - 00001279 ____C () C:\Users\labuhn\Desktop\Revo Uninstaller.lnk
2015-01-17 20:14 - 2015-01-17 20:14 - 00000000 ___DC () C:\Program Files (x86)\VS Revo Group
2015-01-17 20:13 - 2015-01-17 20:13 - 02623656 ____C (VS Revo Group Ltd.) C:\Users\labuhn\Downloads\revosetup95.exe
2015-01-17 12:08 - 2015-01-17 12:08 - 00035717 ____C () C:\Users\labuhn\Desktop\Addition.txt
2015-01-17 12:07 - 2015-01-18 10:35 - 00019793 ____C () C:\Users\labuhn\Desktop\FRST.txt
2015-01-17 12:07 - 2015-01-18 10:35 - 00000000 ___DC () C:\FRST
2015-01-17 12:07 - 2015-01-18 10:34 - 02126336 ____C (Farbar) C:\Users\labuhn\Desktop\FRST64.exe
2015-01-17 11:47 - 2015-01-17 11:47 - 00000000 ____C () C:\autoexec.bat
2015-01-17 11:12 - 2015-01-18 10:30 - 00001249 ____C () C:\Windows\setupact.log
2015-01-17 11:12 - 2015-01-17 11:12 - 00000000 ____C () C:\Windows\setuperr.log
2015-01-17 10:53 - 2015-01-17 10:53 - 00002774 ____C () C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-01-17 10:53 - 2015-01-17 10:53 - 00000833 ____C () C:\Users\Public\Desktop\CCleaner.lnk
2015-01-17 10:53 - 2015-01-17 10:53 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-01-17 10:52 - 2015-01-17 10:53 - 00000000 ___DC () C:\Program Files\CCleaner
2015-01-17 10:51 - 2015-01-17 10:51 - 04188536 ____C (Piriform Ltd) C:\Users\labuhn\Downloads\ccsetup501_slim.exe
2015-01-15 20:29 - 2015-01-18 10:17 - 00000884 ____C () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-15 20:29 - 2015-01-16 10:18 - 00003822 ____C () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-14 07:26 - 2015-01-14 08:32 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 07:26 - 2015-01-14 08:32 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 07:26 - 2015-01-14 08:32 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 07:26 - 2015-01-14 08:32 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 07:26 - 2015-01-14 08:32 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 07:26 - 2015-01-14 08:32 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 07:26 - 2015-01-14 08:32 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 07:26 - 2015-01-14 08:32 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 07:26 - 2015-01-14 08:32 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 07:26 - 2015-01-14 08:32 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 07:26 - 2015-01-14 08:32 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 07:26 - 2015-01-14 08:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 07:26 - 2015-01-14 08:32 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-13 18:23 - 2015-01-13 18:23 - 00000000 ___DC () C:\Program Files (x86)\Mozilla Firefox
2015-01-13 07:18 - 2015-01-13 08:49 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-01-13 07:18 - 2015-01-13 08:49 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-01-12 21:58 - 2015-01-12 21:58 - 00000773 ____C () C:\Windows\removeep.cmd
2015-01-12 21:41 - 2015-01-12 21:41 - 00000000 ___DC () C:\Users\labuhn\AppData\Roaming\reaper
2015-01-12 20:55 - 2015-01-12 20:55 - 00000000 ___DC () C:\Users\Public\Lenovo
2015-01-12 20:30 - 2015-01-12 20:30 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-01-12 20:30 - 2015-01-12 20:30 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2015-01-12 20:30 - 2015-01-12 20:30 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-01-12 20:30 - 2015-01-12 20:30 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-01-12 20:30 - 2015-01-12 20:30 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-01-12 20:30 - 2015-01-12 20:30 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-01-12 20:30 - 2015-01-12 20:30 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-01-12 20:30 - 2015-01-12 20:30 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-01-12 20:30 - 2015-01-12 20:30 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-01-12 20:30 - 2015-01-12 20:30 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2015-01-12 20:30 - 2015-01-12 20:30 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-01-12 20:30 - 2015-01-12 20:30 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-01-12 20:30 - 2015-01-12 20:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2015-01-12 20:30 - 2015-01-12 20:30 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-01-12 20:30 - 2015-01-12 20:30 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-01-11 10:00 - 2015-01-11 10:00 - 00000000 ___DC () C:\Program Files (x86)\Live Radio Stations
2015-01-11 09:59 - 2015-01-11 09:59 - 00000000 ___DC () C:\Program Files (x86)\uNiisales
2015-01-07 12:44 - 2015-01-07 12:47 - 00000000 ___DC () C:\Users\labuhn\Documents\2015 Bewerbungen
2014-12-27 11:29 - 2015-01-08 09:52 - 00000000 ___DC () C:\Users\labuhn\Documents\2014-01-28 Kontenklärung
2014-12-27 10:25 - 2014-12-27 11:19 - 00000000 __RDC () C:\Users\labuhn\Documents\Scannen
2014-12-26 18:28 - 2014-12-26 18:28 - 00000000 ___DC () C:\Users\labuhn\AppData\Roaming\MAGIX
2014-12-26 18:28 - 2014-12-26 18:28 - 00000000 ___DC () C:\Program Files\Common Files\MAGIX Shared
2014-12-26 18:27 - 2015-01-12 21:57 - 00000000 __RDC () C:\Users\labuhn\Documents\MAGIX
2014-12-26 18:27 - 2015-01-12 21:56 - 00000000 ___DC () C:\ProgramData\MAGIX
2014-12-26 18:16 - 2014-12-26 18:16 - 00000000 _RHDC () C:\Users\Public\Libraries
2014-12-26 18:16 - 2014-12-26 18:16 - 00000000 ___DC () C:\Users\labuhn\AppData\Local\Apple Computer
2014-12-26 18:07 - 2014-12-26 18:07 - 00000000 _SHDC () C:\Users\labuhn\AppData\Local\EmieUserList
2014-12-26 18:07 - 2014-12-26 18:07 - 00000000 _SHDC () C:\Users\labuhn\AppData\Local\EmieSiteList
2014-12-26 18:07 - 2014-12-26 18:07 - 00000000 _SHDC () C:\Users\labuhn\AppData\Local\EmieBrowserModeList
2014-12-26 18:04 - 2014-12-26 18:04 - 01174352 ____C () C:\Users\labuhn\Downloads\Magix Video Deluxe 2015 64 Bit - CHIP-Installer.exe
2014-12-24 08:44 - 2014-12-24 08:44 - 00003886 ____C () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-18 10:34 - 2011-12-11 08:37 - 00699682 ____C () C:\Windows\system32\perfh007.dat
2015-01-18 10:34 - 2011-12-11 08:37 - 00149790 ____C () C:\Windows\system32\perfc007.dat
2015-01-18 10:34 - 2009-07-14 06:13 - 01620684 ____C () C:\Windows\system32\PerfStringBackup.INI
2015-01-18 10:33 - 2011-12-11 00:04 - 01556596 ____C () C:\Windows\WindowsUpdate.log
2015-01-18 10:31 - 2011-12-26 16:40 - 00000000 ___DC () C:\Users\labuhn\AppData\Temp
2015-01-18 10:30 - 2011-12-10 23:58 - 00000000 ___DC () C:\ProgramData\NVIDIA
2015-01-18 10:30 - 2009-07-14 06:08 - 00000006 ___HC () C:\Windows\Tasks\SA.DAT
2015-01-18 10:29 - 2009-07-14 05:45 - 00031296 ___HC () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-18 10:29 - 2009-07-14 05:45 - 00031296 ___HC () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-18 10:06 - 2009-07-14 04:20 - 00000000 ___DC () C:\Windows\Web
2015-01-17 20:54 - 2009-07-14 03:34 - 00000215 ____C () C:\Windows\system.ini
2015-01-17 20:53 - 2009-07-14 03:34 - 93847552 _____ () C:\Windows\system32\config\SOFTWARE.bak
2015-01-17 20:53 - 2009-07-14 03:34 - 44040192 _____ () C:\Windows\system32\config\COMPONENTS.bak
2015-01-17 20:53 - 2009-07-14 03:34 - 19398656 _____ () C:\Windows\system32\config\SYSTEM.bak
2015-01-17 20:53 - 2009-07-14 03:34 - 05242880 _____ () C:\Windows\system32\config\DEFAULT.bak
2015-01-17 20:53 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2015-01-17 20:53 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2015-01-17 20:45 - 2013-11-10 11:50 - 00000000 ___DC () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-01-17 20:45 - 2011-12-15 21:06 - 00000466 ____C () C:\Windows\Tasks\SystemToolsDailyTest.job
2015-01-17 20:44 - 2013-11-10 11:50 - 00000000 ___DC () C:\ProgramData\Spybot - Search & Destroy
2015-01-17 20:44 - 2012-01-15 20:48 - 00001912 ____C () C:\Windows\epplauncher.mif
2015-01-17 20:33 - 2011-12-15 21:06 - 00003448 _____ () C:\Windows\System32\Tasks\PCDEventLauncher
2015-01-17 14:12 - 2014-07-11 07:46 - 00000000 ___DC () C:\Users\labuhn\AppData\Local\Windows Live
2015-01-17 13:00 - 2011-12-11 00:06 - 00003502 _____ () C:\Windows\System32\Tasks\SystemToolsDailyTest
2015-01-17 11:47 - 2011-12-15 21:05 - 00000000 ___DC () C:\Users\labuhn
2015-01-17 10:55 - 2012-11-17 18:03 - 00000000 ___DC () C:\Users\labuhn\AppData\Local\CrashDumps
2015-01-17 10:55 - 2012-01-07 19:15 - 00000000 ___DC () C:\Windows\Minidump
2015-01-17 10:55 - 2011-02-15 10:42 - 00000000 ___DC () C:\Windows\Panther
2015-01-16 20:07 - 2014-12-05 17:23 - 00000000 ___DC () C:\Users\labuhn\Documents\2014-10_bis_12 Neuseeland & Sydney
2015-01-16 10:18 - 2013-02-27 15:06 - 00701616 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-16 10:18 - 2011-12-25 19:43 - 00071344 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-15 20:37 - 2011-12-15 21:16 - 00000000 ___DC () C:\Users\labuhn\AppData\Local\Adobe
2015-01-15 20:28 - 2014-01-19 15:53 - 00000000 ___DC () C:\ProgramData\McAfee Security Scan
2015-01-14 08:32 - 2013-08-15 20:27 - 00000000 ___DC () C:\Windows\system32\MRT
2015-01-14 08:23 - 2011-12-18 19:12 - 113365784 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-13 19:34 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2015-01-13 19:07 - 2012-04-29 20:08 - 00000000 ___DC () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-13 18:33 - 2014-04-14 17:39 - 00000000 ___DC () C:\EFW 2014-04-14
2015-01-12 21:58 - 2014-04-27 09:50 - 00000000 ___DC () C:\Users\labuhn\AppData\Local\Lenovo
2015-01-12 21:58 - 2011-12-10 23:54 - 00000000 ___DC () C:\Program Files (x86)\Lenovo
2015-01-12 20:56 - 2011-12-11 00:04 - 00000000 ___DC () C:\Windows\Downloaded Installations
2015-01-12 20:56 - 2011-12-11 00:04 - 00000000 ____D () C:\Windows\System32\Tasks\Lenovo
2015-01-12 20:55 - 2012-10-13 18:45 - 00000000 __HDC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools
2015-01-08 09:55 - 2010-11-21 04:27 - 00298120 ____C (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-05 11:03 - 2013-02-10 18:27 - 00011861 _____ () C:\Users\labuhn\Documents\Silberhochzeitsliste.xlsx
2015-01-05 10:54 - 2013-07-28 07:44 - 00000000 ___DC () C:\Users\labuhn\Documents\2013-07-27 Silberhochzeit
2015-01-05 10:47 - 2014-02-23 19:05 - 00000000 ___DC () C:\Users\labuhn\Documents\2014-02-23 Natalie beim Griechen
2015-01-04 19:07 - 2011-12-28 18:50 - 00000000 ___DC () C:\ProgramData\Microsoft Help
2014-12-29 09:53 - 2014-08-15 18:39 - 00000000 ___DC () C:\Users\labuhn\Documents\2014-07-26 Vater und Torsten
2014-12-28 22:41 - 2014-02-23 19:34 - 00000000 ___DC () C:\Users\labuhn\Documents\2014-06-17 Dichtschlemme
2014-12-27 10:18 - 2014-01-28 13:39 - 00000000 ___DC () C:\Users\labuhn\Documents\Scanner
2014-12-26 18:52 - 2011-12-15 21:06 - 00152288 ____C () C:\Users\labuhn\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-26 18:52 - 2009-07-14 05:45 - 00481912 ____C () C:\Windows\system32\FNTCACHE.DAT
2014-12-26 18:27 - 2014-10-02 10:05 - 00000000 ___DC () C:\ProgramData\Package Cache
2014-12-26 18:27 - 2011-12-16 20:00 - 00000000 ___DC () C:\Program Files (x86)\MSXML 4.0
2014-12-26 18:14 - 2012-10-13 18:37 - 00000000 ___DC () C:\Users\labuhn\AppData\Roaming\vlc
2014-12-24 14:15 - 2011-12-26 16:57 - 00000000 ___DC () C:\Dateien 2014-12-31
2014-12-23 09:40 - 2011-12-15 21:06 - 00000528 ____C () C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2014-12-22 17:14 - 2011-12-11 00:06 - 00004242 _____ () C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask
==================== Files in the root of some directories =======
2012-06-28 09:20 - 2012-06-28 09:20 - 0033134 ____C () C:\Users\labuhn\AppData\Roaming\UserTile.png
2012-10-13 20:18 - 2012-10-13 20:18 - 0000438 ____C () C:\Users\labuhn\AppData\Local\WiDiLog.20121013.211832.txt
2012-10-13 20:18 - 2012-10-13 20:18 - 0018362 ____C () C:\Users\labuhn\AppData\Local\WiDiSetupLog.20121013.211803.txt
Files to move or delete:
====================
C:\Users\labuhn\Windows-KB890830-x64-V5.9.exe
Some content of TEMP:
====================
C:\Users\labuhn\AppData\Local\Temp\Quarantine.exe
C:\Users\labuhn\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-17 19:27
==================== End Of Log ============================ --- --- ---
----------------
Gruß
Energie2000 |