Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Win7: werde regelmäßig auf Desktop geschmissen, Programm öffnet und schließt sich kurz in Programmleiste (https://www.trojaner-board.de/163771-win7-regelmaessig-desktop-geschmissen-programm-oeffnet-schliesst-kurz-programmleiste.html)

LarryPerkins 09.02.2015 12:59

Win7: werde regelmäßig auf Desktop geschmissen, Programm öffnet und schließt sich kurz in Programmleiste
 
Hallo,

ich werde regelmässig auf den Desktop geschmissen und aus dem aktuell laufenden Programm (Spiel oder Email schreiben). Dabei öffnet sich sehr kurz ein Programm in der Leiste und schließt sich wieder.
Bin für jede Hilfe dankbar.


Junkware Removal Tool:


JRT Logfile:JRT Logfile:
Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Professional x64
Ran by XXX YYY on 09.02.2015 at  9:45:31,14
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{27B4851A-3207-45A2-B947-BE8AFE6163AB}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{27B4851A-3207-45A2-B947-BE8AFE6163AB}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
Successfully deleted: [Empty Folder] C:\Users\XXX YYY\appdata\local\{00117357-098D-4607-B578-EA895FB3BDCC}
Successfully deleted: [Empty Folder] C:\Users\XXX YYY\appdata\local\{0015BDB9-E463-410E-AF47-D3FA19F7A24A}
Successfully deleted: [Empty Folder] C:\Users\XXX YYY\appdata\local\{00193A7B-AFAC-4EC0-A098-E770E575232C}
Successfully deleted: [Empty Folder] C:\Users\XXX YYY\appdata\local\{00ED0629-4593-42C0-BA0B-F9743F041517}
Successfully deleted: [Empty Folder] C:\Users\XXX YYY\appdata\local\{00FC3838-9A0A-4AED-A712-87735292151E}
...
(hier folgen lauter leere ORdner, denke nicht dass das viel bringt, außedem wird der Post damit zu lang)



~~~ FireFox

Successfully deleted the following from C:\Users\XXX YYY\AppData\Roaming\mozilla\firefox\profiles\gwlew6n9.default\prefs.js

user_pref("extensions.alexa.searchconf", "{\n  \"google\" : {\n    \"urlexp\" : \"hxxp(?:s)?:\\\\/\\\\/(?:www[0-9]*\\\\.|encrypted\\\\.)(?:l\\\\.)?google\\\\..*\\\\/.*[?#&]q=
user_pref("services.sync.client.syncID", "Tv9AODYDY9mr");
Emptied folder: C:\Users\XXX YYY\AppData\Roaming\mozilla\firefox\profiles\gwlew6n9.default\minidumps [364 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 09.02.2015 at  9:49:16,05
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

--- --- ---


Malwarebytes Scan Log vor Malwarebytes Removal:

Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 05.02.2015
Scan Time: 16:56:49
Logfile: Malwarebytes Scan.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.02.05.07
Rootkit Database: v2015.02.03.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: YYY XXX

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 348571
Time Elapsed: 15 min, 15 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 2
PUP.Optional.DigitalSites.A, HKU\S-1-5-21-3557091032-3563988234-1886976076-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DSiteProducts, Delete-on-Reboot, [a833bd5d44463ef841902edc2bda45bb],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3557091032-3563988234-1886976076-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Delete-on-Reboot, [27b4ac6ea6e4ff37bba9746edc28de22],

Registry Values: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3557091032-3563988234-1886976076-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0L1N1H2O1S, Delete-on-Reboot, [27b4ac6ea6e4ff37bba9746edc28de22]

Registry Data: 1
PUP.Optional.StartPage, HKU\S-1-5-21-3557091032-3563988234-1886976076-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=5ABA002710DD58F0&affID=119357&tsp=4958, Good: (www.google.com), Bad: (hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=5ABA002710DD58F0&affID=119357&tsp=4958),Delete-on-Reboot,[5883bd5de1a9a19573b40ca6ee17f907]

Folders: 4
PUP.Optional.DigitalSite.A, C:\Users\YYY XXX\AppData\Roaming\DigitalSite\UpdateProc, Quarantined, [697273a7395145f124db537b62a116ea],
PUP.Optional.Babylon.A, C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com, Quarantined, [934863b7c8c240f605e05a2628db5ca4],
PUP.Optional.Babylon.A, C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com\defaults, Quarantined, [934863b7c8c240f605e05a2628db5ca4],
PUP.Optional.Babylon.A, C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com\defaults\preferences, Quarantined, [934863b7c8c240f605e05a2628db5ca4],

Files: 7
PUP.Optional.Delta.A, C:\Users\YYY XXX\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www1.delta-search.com_0.localstorage, Quarantined, [02d9d644f09acf67a223891140c31ce4],
PUP.Optional.Delta.A, C:\Users\YYY XXX\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www1.delta-search.com_0.localstorage-journal, Quarantined, [20bbec2edfabb77f23a26931c53e3fc1],
PUP.Optional.Babylon.A, C:\Users\YYY XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\searchplugins\babylon.xml, Quarantined, [89524fcbbcce01350b93239e47bcac54],
PUP.Optional.DigitalSite.A, C:\Users\YYY XXX\AppData\Roaming\DigitalSite\UpdateProc\config.dat, Quarantined, [697273a7395145f124db537b62a116ea],
PUP.Optional.DigitalSite.A, C:\Users\YYY XXX\AppData\Roaming\DigitalSite\UpdateProc\prod.dat, Quarantined, [697273a7395145f124db537b62a116ea],
PUP.Optional.BrowserDefender.A, C:\Users\YYY XXX\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage, Quarantined, [a13abe5cfc8ee94d8dfffbea41c3936d],
PUP.Optional.Babylon.A, C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com\defaults\preferences\dflt.js, Quarantined, [934863b7c8c240f605e05a2628db5ca4],

Physical Sectors: 0
(No malicious items detected)


(end)

Malwarebytes Protection Log:

Code:

Malwarebytes Anti-Malware
www.malwarebytes.org


Update, 05.02.2015 16:56:38, SYSTEM, YYYXXX-VAIO, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1,
Update, 05.02.2015 16:56:38, SYSTEM, YYYXXX-VAIO, Manual, Rootkit Database, 2014.11.18.1, 2015.2.3.1,
Update, 05.02.2015 16:56:42, SYSTEM, YYYXXX-VAIO, Manual, Malware Database, 2014.11.20.6, 2015.2.5.7,
Scan, 05.02.2015 17:17:15, SYSTEM, YYYXXX-VAIO, Manual, Start:05.02.2015 16:56:49, Duration:15 min 15 sec, Threat Scan, Completed, 0 Malware Detections, 15 Non-Malware Detections,

(end)



Malwarebytes Scan Log after Malwarebytes Removal:


Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 08.02.2015
Scan Time: 16:36:45
Logfile: Malwarebytes Scan after Malwarebytes Removal.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.02.08.04
Rootkit Database: v2015.02.03.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: YYY YYY

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 348841
Time Elapsed: 16 min, 8 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

defogger:

Code:

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 11:59 on 09/02/2015 (XXX)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-

FRST:

Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-02-2015
Ran by YYY XXX (administrator) on YYYXXX-VAIO on 09-02-2015 12:01:02
Running from C:\Users\YYY XXX\Downloads
Loaded Profiles: YYY XXX (Available profiles: YYY XXX)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvservice.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(UPEK Inc.) C:\Program Files\Protector Suite\upeksvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(QUALCOMM, Inc.) C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(UPEK Inc.) C:\Program Files\Protector Suite\psqltray.exe
(Microsoft Corporation) C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESGfxMgr.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files (x86)\FastStone Capture\FSCapture.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
(Sony Corporation) C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\csisyncclient.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
() C:\Program Files\Sony\VAIO Care\listener.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe
() C:\Users\YYY XXX\Downloads\Defogger.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9962016 2010-06-18] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1886504 2010-03-01] (Synaptics Incorporated)
HKLM\...\Run: [PSQLLauncher] => C:\Program Files\Protector Suite\launcher.exe [84744 2010-04-27] (UPEK Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [673136 2010-05-31] (Sony Corporation)
HKLM-x32\...\Run: [MobileBroadband] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [253440 2010-05-18] (Vodafone)
HKLM-x32\...\Run: [MarketingTools] => C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [26624 2013-03-19] (Sony Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-11] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585536 2015-01-06] (Razer Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-08-19] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2014-12-31] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (UPEK Inc.)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1942720 2015-01-23] (Valve Corporation)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [SkyDrive] => C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [277672 2014-09-25] (Microsoft Corporation)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30879328 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [Wondershare Helper Compact.exe] => "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelperSetup.exe"
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [GoogleChromeAutoLaunch_550EDA027B4B11347618D98EDCBB3ADF] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592 2015-02-04] (Google Inc.)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\RunOnce: [Uninstall C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64"
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\RunOnce: [Uninstall C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64"
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\RunOnce: [Uninstall C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\17.3.1165.0612\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\17.3.1165.0612\amd64"
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\RunOnce: [Uninstall C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618\amd64"
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\RunOnce: [Uninstall C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64"
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {852a4381-bbbe-11e2-9681-0024bed7ff33} - D:\AutoRun.exe
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {852a43a5-bbbe-11e2-9681-0024bed7ff33} - D:\AutoRun.exe
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {c8b79af5-29a7-11e3-9355-0024bed7ff33} - E:\AutoRun.exe
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {d80812ee-1fbb-11e3-afed-0024bed7ff33} - E:\AutoRun.exe
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {d80812ff-1fbb-11e3-afed-0024bed7ff33} - E:\AutoRun.exe
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {d808131c-1fbb-11e3-afed-0024bed7ff33} - E:\AutoRun.exe
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {d808133f-1fbb-11e3-afed-0024bed7ff33} - E:\AutoRun.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-18] (Microsoft Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\YYY XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\YYY XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk
ShortcutTarget: FastStone Capture.lnk -> C:\Program Files (x86)\FastStone Capture\FSCapture.exe ()
Startup: C:\Users\YYY XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [UEAFOverlay] -> {F2F31467-B1AC-4df0-AE79-FD5FA085E22B} => C:\Program Files\Protector Suite\farchns.dll (UPEK Inc.)
ShellIconOverlayIdentifiers: [UEAFOverlayOpen] -> {A3E208F7-0E3A-4182-A7A6-B169D5D691AA} => C:\Program Files\Protector Suite\farchns.dll (UPEK Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEE&bmod=SVEE
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {3617BCD7-E991-4BB5-8542-09A0B20EE913} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {794C16B2-C354-42CB-8212-172F5BD771B6} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms}
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {A70EC677-F517-45E6-831A-E87104D7AC0B} URL = hxxp://de.shopping.com/?linkin_id=8056363
BHO: No Name -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} ->  No File
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} ->  No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{876E33B5-EE1E-4322-8F79-79EB6087A1E2}: [NameServer] 
Tcpip\..\Interfaces\{AA2DF348-6AB3-482F-A8BC-41E89158A468}: [NameServer] 10.74.210.210 10.74.210.211

FireFox:
========
FF ProfilePath: C:\Users\YYY XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default
FF DefaultSearchEngine: Google
FF SelectedSearchEngine: Google
FF Homepage: www.google.de
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20((url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20us07.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\Sony\MSS\3.8.130\npMcAfeeMss.dll No File
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\YYY XXX\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3557091032-3563988234-1886976076-1000: @citrixonline.com/appdetectorplugin -> C:\Users\YYY XXX\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin HKU\S-1-5-21-3557091032-3563988234-1886976076-1000: LWAPlugin15.8 -> C:\Users\YYY XXX\AppData\Roaming\Mozilla\Plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\YYY XXX\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\YYY XXX\AppData\Roaming\mozilla\plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\YYY XXX\AppData\Roaming\mozilla\plugins\npoctoshape.dll (Octoshape ApS)
FF SearchPlugin: C:\Users\YYY XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\searchplugins\translate-korean-to-english.xml
FF Extension: Avira Browser Safety - C:\Users\YYY XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\abs@avira.com [2015-02-03]
FF Extension: Password Bank - C:\Users\YYY XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\passwordbank@upek.com [2013-03-20]
FF Extension: Ghostery - C:\Users\YYY XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\firefox@ghostery.com.xpi [2013-08-19]
FF Extension: FireGestures - C:\Users\YYY XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\firegestures@xuldev.org.xpi [2013-03-20]
FF Extension: ProxMate - Proxy on steroids! - C:\Users\YYY XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-08-09]
FF Extension: Yesware Email Tracking - C:\Users\YYY XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\jid1-T5mdAATMX3urKA@jetpack.xpi [2013-04-24]
FF Extension: Rapportive - C:\Users\YYY XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\rapportive@rapportive.com.xpi [2013-06-20]
FF Extension: TinEye Reverse Image Search - C:\Users\YYY XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\tineye@ideeinc.com.xpi [2013-03-20]
FF Extension: Screengrab - C:\Users\YYY XXX\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\{02450954-cdd9-410f-b1da-db804e18c671}.xpi [2013-03-20]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor

GMER:

GMER Logfile:
Code:

GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-02-09 12:53:01
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Intel___ rev.1.0. 119,25GB
Running: Gmer-19357.exe; Driver: C:\Users\YYYRAU~1\AppData\Local\Temp\kftyrpoc.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560                                                                                                                                                                                                fffff800037f5070 25 bytes [C4, 08, 4C, 89, 64, 24, 50, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 586                                                                                                                                                                                                fffff800037f508a 6 bytes [00, 00, 00, 80, 05, 00]

---- User code sections - GMER 2.1 ----

.text    C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe[2380] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                                              0000000077011465 2 bytes [01, 77]
.text    C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe[2380] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                                            00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
.text    C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe[2704] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                                                          0000000077011465 2 bytes [01, 77]
.text    C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe[2704] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                                                          00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
.text    C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe[3016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                                                        0000000077011465 2 bytes [01, 77]
.text    C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe[3016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                                                      00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
.text    C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe[2672] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                                        0000000077011465 2 bytes [01, 77]
.text    C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe[2672] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                                      00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
.text    C:\ProgramData\DatacardService\DCSHelper.exe[3788] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                                                                        0000000077011465 2 bytes [01, 77]
.text    C:\ProgramData\DatacardService\DCSHelper.exe[3788] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                                                                      00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
.text    C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                                                    0000000077011465 2 bytes [01, 77]
.text    C:\Users\YYY XXX\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                                                  00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
.text    C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe[1416] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69                                                                                                                                          0000000077011465 2 bytes [01, 77]
.text    C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe[1416] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155                                                                                                                                        00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
.text    C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe[5240] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                                  0000000077011465 2 bytes [01, 77]
.text    C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe[5240] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                                  00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
.text    C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[5324] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                                                              0000000077011465 2 bytes [01, 77]
.text    C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[5324] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                                                            00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
.text    C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe[5352] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                                                                  0000000077011465 2 bytes [01, 77]
.text    C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe[5352] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                                                                00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
.text    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                                                              0000000077011465 2 bytes [01, 77]
.text    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                                                            00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
?        C:\Windows\system32\mssprxy.dll [5456] entry point in ".rdata" section                                                                                                                                                                                            00000000593d71e6
.text    C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe[5492] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                                                0000000077011465 2 bytes [01, 77]
.text    C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe[5492] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                                              00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
.text    C:\Windows\SysWOW64\RunDll32.exe[5540] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                                                                                    0000000077011465 2 bytes [01, 77]
.text    C:\Windows\SysWOW64\RunDll32.exe[5540] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                                                                                  00000000770114bb 2 bytes [01, 77]
.text    ...                                                                                                                                                                                                                                                              * 2
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                                                                                                        00000000775bf9e0 5 bytes JMP 000000010f68ea93
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtOpenKey                                                                                                                                                      00000000775bfa28 5 bytes JMP 000000010f68f0f8
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtEnumerateValueKey                                                                                                                                            00000000775bfa40 5 bytes JMP 000000010f68d830
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtQueryKey                                                                                                                                                    00000000775bfa90 5 bytes JMP 000000010f68d38c
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtQueryValueKey                                                                                                                                                00000000775bfaa8 5 bytes JMP 000000010f68d67d
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtCreateKey                                                                                                                                                    00000000775bfb40 5 bytes JMP 000000010f68f338
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile                                                                                                                                          00000000775bfc38 5 bytes JMP 000000010f69a713
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtEnumerateKey                                                                                                                                                00000000775bfd4c 5 bytes JMP 000000010f68d1d4
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                                                                                                    00000000775bfd64 5 bytes JMP 000000010f699d35
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtQueryDirectoryFile                                                                                                                                          00000000775bfd98 5 bytes JMP 000000010f69a030
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtDuplicateObject                                                                                                                                              00000000775bfe44 5 bytes JMP 000000010f68e668
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile                                                                                                                                          00000000775bfe5c 5 bytes JMP 000000010f699e5e
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                                                                                                                  00000000775c00b4 5 bytes JMP 000000010f699b7a
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtSetValueKey                                                                                                                                                  00000000775c01c4 5 bytes JMP 000000010f68d9d8
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtCreateKeyTransacted                                                                                                                                          00000000775c0754 5 bytes JMP 000000010f68f3da
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtDeleteFile                                                                                                                                                  00000000775c09e4 5 bytes JMP 000000010f699d72
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtDeleteKey                                                                                                                                                    00000000775c09fc 5 bytes JMP 000000010f68cfa8
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtDeleteValueKey                                                                                                                                              00000000775c0a44 5 bytes JMP 000000010f68db8e
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtFlushKey                                                                                                                                                    00000000775c0b80 5 bytes JMP 000000010f68d0be
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtNotifyChangeKey                                                                                                                                              00000000775c0f70 5 bytes JMP 000000010f68e01b
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtNotifyChangeMultipleKeys                                                                                                                                    00000000775c0f88 5 bytes JMP 000000010f68e1b7
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtOpenKeyEx                                                                                                                                                    00000000775c1018 5 bytes JMP 000000010f68f185
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtOpenKeyTransacted                                                                                                                                            00000000775c1030 5 bytes JMP 000000010f68f2a8
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtOpenKeyTransactedEx                                                                                                                                          00000000775c1048 5 bytes JMP 000000010f68f215
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile                                                                                                                                      00000000775c133c 5 bytes JMP 000000010f699f47
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtQueryMultipleValueKey                                                                                                                                        00000000775c147c 5 bytes JMP 000000010f68de8e
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtQuerySecurityObject                                                                                                                                          00000000775c1528 5 bytes JMP 000000010f68e37b
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtRenameKey                                                                                                                                                    00000000775c1718 5 bytes JMP 000000010f68dd06
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationKey                                                                                                                                            00000000775c1a58 5 bytes JMP 000000010f68d535
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\SysWOW64\ntdll.dll!NtSetSecurityObject                                                                                                                                            00000000775c1b9c 5 bytes JMP 000000010f68e4fd
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                                                                                                                              0000000076c8103d 5 bytes JMP 000000010f673904
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                                                                                                                              0000000076c81072 5 bytes JMP 000000010f673d68
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                                                                                                                                        0000000076cac9b5 5 bytes JMP 000000010f673a1e
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\kernel32.dll!WinExec                                                                                                                                                    0000000076d02ff1 5 bytes JMP 000000010f673c62
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                                                                                                                        00000000770b2642 5 bytes JMP 000000010f673f75
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\USER32.dll!RegisterClipboardFormatW                                                                                                                                      0000000075229ebd 5 bytes JMP 00000001027499ff
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\USER32.dll!RegisterClipboardFormatA                                                                                                                                      0000000075230afa 5 bytes JMP 000000010274e26c
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\USER32.dll!BeginPaint                                                                                                                                                    0000000075231361 5 bytes JMP 000000010275c8b4
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\USER32.dll!ValidateRect                                                                                                                                                  0000000075237849 5 bytes JMP 00000001028d1f12
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!OleLoadFromStream                                                                                                                                              0000000075316143 5 bytes JMP 0000000102ecdebe
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!CoResumeClassObjects + 7                                                                                                                                      000000007531ea09 7 bytes JMP 000000010f6ae370
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!OleRun                                                                                                                                                        00000000753207de 5 bytes JMP 000000010f6ade9e
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!CoRegisterClassObject                                                                                                                                          00000000753221e1 5 bytes JMP 000000010f6b1745
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!OleUninitialize                                                                                                                                                000000007532eba1 6 bytes JMP 000000010f6ade15
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!OleInitialize                                                                                                                                                  000000007532efd7 5 bytes JMP 000000010f6addcd
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!CoGetClassObject                                                                                                                                              00000000753454ad 5 bytes JMP 000000010f6afdbb
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!CoInitializeEx                                                                                                                                                00000000753509ad 5 bytes JMP 000000010f6add6d
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!CoUninitialize                                                                                                                                                00000000753586d3 5 bytes JMP 000000010f6b07cf
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                                                                                              0000000075359d0b 5 bytes JMP 000000010f6b14ec
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx                                                                                                                                            0000000075359d4e 5 bytes JMP 000000010f6af3c7
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!CoSuspendClassObjects + 7                                                                                                                                      000000007537bb09 7 bytes JMP 000000010f6adee6
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!CoRevokeClassObject                                                                                                                                            000000007539eacf 5 bytes JMP 000000010f6afa7c
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!CoGetInstanceFromFile                                                                                                                                          00000000753d340b 5 bytes JMP 000000010f6b08cf
.text    C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe[5816] C:\Windows\syswow64\ole32.dll!OleRegEnumFormatEtc                                                                                                                                            000000007541cfd9 5 bytes JMP 000000010f6ade56

---- Devices - GMER 2.1 ----

Device    \Driver\semav6thermal64ro \Device\semav6thermal64ro                                                                                                                                                                                                              fffff88005688010
---- Processes - GMER 2.1 ----

Library  C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [2272](2013-09-17 17:11:47)                                                                                                000000006fbc0000
Library  C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [2272](2013-09-17 17:11:47)                                                                                          000000006e940000
Library  C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [2272](2013-09-17 17:11:47)                                                                                                  000000006a1c0000
Library  C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [2272](2013-09-17 17:11:48)                                                                                              000000006ff00000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Qt5Widgets.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-22 00:22:46)        00000000581a0000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Qt5Gui.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-22 00:22:38)            0000000057840000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\libGLESv2.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416](2014-10-22 00:22:50)                                                                                        0000000060f10000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Qt5Core.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-22 00:22:38)          00000000560c0000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\icuin52.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (ICU I18N DLL/The ICU Project)(2014-10-22 00:22:50)                                                          000000004a900000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\icuuc52.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (ICU Common DLL/The ICU Project)(2014-10-22 00:22:50)                                                        00000000040c0000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\icudt52.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (ICU Data DLL/The ICU Project)(2014-10-22 00:22:50)                                                          000000004ad00000
Library  c:\users\YYYrau~1\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp7jjwhg.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416](2015-02-09 11:41:14)                                        0000000003a70000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Qt5Network.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-22 00:22:38)        000000005f840000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Qt5WebKit.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-22 00:22:40)        0000000006050000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Qt5Quick.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-22 00:22:40)          000000005b830000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Qt5Qml.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-22 00:22:40)            000000005b5d0000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Qt5Sql.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-22 00:22:40)            0000000060650000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\libEGL.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416](2014-10-22 00:22:50)                                                                                          00000000601b0000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Qt5WebKitWidgets.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-22 00:22:46)  0000000060180000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Qt5OpenGL.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-22 00:22:38)        000000005f800000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Qt5PrintSupport.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-22 00:22:38)  000000005f570000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416](2014-10-22 00:22:48)                                                                      000000005af70000
Library  C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll (*** suspicious ***) @ C:\Users\YYY XXX\AppData\Roaming\Dropbox\bin\Dropbox.exe [1416](2014-10-22 00:22:46)                                                                      000000005f530000
Library  C:\ProgramData\Razer\Synapse\Devices\RazerConfigNative.dll (*** suspicious ***) @ C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [5352] (Razer Configurator/Razer Inc.)(2015-01-07 03:14:46)                                                                  000000005b050000
Library  C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\mso.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5816]                                                                                                0000000002720000
Library  C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\riched20.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5816]                                                                                          000000000f940000
Library  C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\MSPTLS.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5816]                                                                                            0000000004c20000
Library  C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\csi.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5816]                                                                                                000000000b9e0000
Library  C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\ACEOLEDB.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5816]                                                                                          000000000f470000
Library  C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\ACECORE.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5816]                                                                                            000000000bf10000
Library  C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\1031\ACEWSTR.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5816]                                                                                      000000000f4f0000
Library  C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\ACEES.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5816]                                                                                              000000000f7b0000
Library  C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\VBAJET32.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5816]                                                                                          0000000061a60000
Library  C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\expsrv.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [5816]                                                                                            0000000004190000

---- Registry - GMER 2.1 ----

Reg      HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\506313dbb8cf                                                                                                                                                                                     
Reg      HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0cb38e14ca9                                                                                                                                                                                     
Reg      HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0cb38e14ca9@b8c68eaf2231                                                                                                                                                                          0xFC 0x54 0x3D 0x7F ...
Reg      HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0cb38e14ca9@c0eefb32dc7a                                                                                                                                                                          0xF9 0xE5 0x14 0x1B ...
Reg      HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\506313dbb8cf (not active ControlSet)                                                                                                                                                                 
Reg      HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0cb38e14ca9 (not active ControlSet)                                                                                                                                                                 
Reg      HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0cb38e14ca9@b8c68eaf2231                                                                                                                                                                              0xFC 0x54 0x3D 0x7F ...
Reg      HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0cb38e14ca9@c0eefb32dc7a                                                                                                                                                                              0xF9 0xE5 0x14 0x1B ...

---- EOF - GMER 2.1 ----

--- --- ---

Warlord711 09.02.2015 15:13

Hallo LarryPerkins

:hallo:

Mein Name ist Timo und ich werde Dir bei deinem Problem behilflich sein.
  • Bitte arbeite alle Schritte der Reihe nach ab.
  • Hier findest du die Anleitung für Hilfesuchende
  • Lese die Anleitungen sorgfältig. Sollte es Probleme geben, bitte stoppen und hier so gut es geht beschreiben.
  • Nur Scans durchführen zu denen Du von einem Helfer aufgefordert wirst.
  • Bitte kein Crossposting ( posten in mehreren Foren).
  • Installiere oder Deinstalliere während der Bereinigung keine Software ausser Du wurdest dazu aufgefordert.
  • Lese Dir die Anleitung zuerst vollständig durch. Sollte etwas unklar sein, frage bevor Du beginnst.
  • Poste die Logfiles direkt in deinen Thread. Nicht anhängen ausser ich fordere Dich dazu auf.

Hinweis:
Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist immer der sicherste Weg.

Wir arbeiten hier alle freiwillig und meist auch nur in unserer Freizeit. Daher kann es bei Antworten zu Verzögerungen kommen.
Solltest du innerhalb 48 Std keine Antwort von mir erhalten, dann schreib mit eine PM
Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis ich oder jemand vom Team sagt, dass Du clean bist.


Führe sämtliche Tools mit administrativen Rechten aus, Vista, Win7,Win8 User mit Rechtsklick "als Administrator starten".



Kannst du das FRST Log erneut posten, es ist nicht komplett. Ausserdem die Addition.txt

Falls keine aktuelle Addition.txt vorhanden ist, bitte FRST neu starten, Haken setzen bei addition.txt dann auf Scan klicken

http://saved.im/mtg0mjy4yjlu/2014-04...ryscantool.png

LarryPerkins 09.02.2015 17:27

Hallo Timo,

das FRST bricht leider mit einer Fehlermeldung ab
"FRST funktioniert nicht mehr richtig"

Eine Datei spuckt es scheinbar trotzdem aus, wenn auch keine addition.txt:

Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-02-2015
Ran by XXX YYY (administrator) on XXXYYY-VAIO on 09-02-2015 17:24:11
Running from C:\Users\XXX YYY\Downloads
Loaded Profiles: XXX YYY (Available profiles: XXX YYY)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvservice.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(UPEK Inc.) C:\Program Files\Protector Suite\upeksvr.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(QUALCOMM, Inc.) C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Microsoft Corporation) C:\Windows\System32\WerFault.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(UPEK Inc.) C:\Program Files\Protector Suite\psqltray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files (x86)\FastStone Capture\FSCapture.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
(Sony Corporation) C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\csisyncclient.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
() C:\Program Files\Sony\VAIO Care\listener.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
Failed to access process -> dllhost.exe
Failed to access process -> dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9962016 2010-06-18] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1886504 2010-03-01] (Synaptics Incorporated)
HKLM\...\Run: [PSQLLauncher] => C:\Program Files\Protector Suite\launcher.exe [84744 2010-04-27] (UPEK Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [673136 2010-05-31] (Sony Corporation)
HKLM-x32\...\Run: [MobileBroadband] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [253440 2010-05-18] (Vodafone)
HKLM-x32\...\Run: [MarketingTools] => C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [26624 2013-03-19] (Sony Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-11] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585536 2015-01-06] (Razer Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-08-19] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2014-12-31] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (UPEK Inc.)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1942720 2015-01-23] (Valve Corporation)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [SkyDrive] => C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [277672 2014-09-25] (Microsoft Corporation)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30879328 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [Wondershare Helper Compact.exe] => "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelperSetup.exe"
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [GoogleChromeAutoLaunch_550EDA027B4B11347618D98EDCBB3ADF] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592 2015-02-04] (Google Inc.)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\RunOnce: [Uninstall C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64"
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\RunOnce: [Uninstall C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64"
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\RunOnce: [Uninstall C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1165.0612\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1165.0612\amd64"
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\RunOnce: [Uninstall C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618\amd64"
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\RunOnce: [Uninstall C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64"
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {852a4381-bbbe-11e2-9681-0024bed7ff33} - D:\AutoRun.exe
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {852a43a5-bbbe-11e2-9681-0024bed7ff33} - D:\AutoRun.exe
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {c8b79af5-29a7-11e3-9355-0024bed7ff33} - E:\AutoRun.exe
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {d80812ee-1fbb-11e3-afed-0024bed7ff33} - E:\AutoRun.exe
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {d80812ff-1fbb-11e3-afed-0024bed7ff33} - E:\AutoRun.exe
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {d808131c-1fbb-11e3-afed-0024bed7ff33} - E:\AutoRun.exe
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\MountPoints2: {d808133f-1fbb-11e3-afed-0024bed7ff33} - E:\AutoRun.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-18] (Microsoft Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk
ShortcutTarget: FastStone Capture.lnk -> C:\Program Files (x86)\FastStone Capture\FSCapture.exe ()
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [UEAFOverlay] -> {F2F31467-B1AC-4df0-AE79-FD5FA085E22B} => C:\Program Files\Protector Suite\farchns.dll (UPEK Inc.)
ShellIconOverlayIdentifiers: [UEAFOverlayOpen] -> {A3E208F7-0E3A-4182-A7A6-B169D5D691AA} => C:\Program Files\Protector Suite\farchns.dll (UPEK Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SVEE&bmod=SVEE
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {3617BCD7-E991-4BB5-8542-09A0B20EE913} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {794C16B2-C354-42CB-8212-172F5BD771B6} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms}
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {A70EC677-F517-45E6-831A-E87104D7AC0B} URL = hxxp://de.shopping.com/?linkin_id=8056363
BHO: No Name -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} ->  No File
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} ->  No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{876E33B5-EE1E-4322-8F79-79EB6087A1E2}: [NameServer] 
Tcpip\..\Interfaces\{AA2DF348-6AB3-482F-A8BC-41E89158A468}: [NameServer] 10.74.210.210 10.74.210.211

FireFox:
========
FF ProfilePath: C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default
FF DefaultSearchEngine: Google
FF SelectedSearchEngine: Google
FF Homepage: www.google.de
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*'))%20%7B%20return%20'PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\Sony\MSS\3.8.130\npMcAfeeMss.dll No File
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\XXX YYY\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3557091032-3563988234-1886976076-1000: @citrixonline.com/appdetectorplugin -> C:\Users\XXX YYY\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin HKU\S-1-5-21-3557091032-3563988234-1886976076-1000: LWAPlugin15.8 -> C:\Users\XXX YYY\AppData\Roaming\Mozilla\Plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\XXX YYY\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\XXX YYY\AppData\Roaming\mozilla\plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\XXX YYY\AppData\Roaming\mozilla\plugins\npoctoshape.dll (Octoshape ApS)
FF SearchPlugin: C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\searchplugins\translate-korean-to-english.xml
FF Extension: Avira Browser Safety - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\abs@avira.com [2015-02-03]
FF Extension: Password Bank - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\passwordbank@upek.com [2013-03-20]
FF Extension: Ghostery - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\firefox@ghostery.com.xpi [2013-08-19]
FF Extension: FireGestures - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\firegestures@xuldev.org.xpi [2013-03-20]
FF Extension: ProxMate - Proxy on steroids! - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-08-09]
FF Extension: Yesware Email Tracking - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\jid1-T5mdAATMX3urKA@jetpack.xpi [2013-04-24]
FF Extension: Rapportive - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\rapportive@rapportive.com.xpi [2013-06-20]
FF Extension: TinEye Reverse Image Search - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\tineye@ideeinc.com.xpi [2013-03-20]
FF Extension: Alexa Sparky - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\toolbar@alexa.com.xpi [2015-02-09]
FF Extension: Screengrab - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\{02450954-cdd9-410f-b1da-db804e18c671}.xpi [2013-03-20]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor


Warlord711 09.02.2015 17:33

Probier mal aus:

Bitte lasse die Datei aus der Code-Box bei Virustotal überprüfen.
  • Klicke auf Wählen Sie eine
  • Kopiere nun folgendes in die Suchleiste
    Code:

    C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
  • und klicke auf Öffnen.
  • Klicke auf Scannen!.
  • Warte bitte bis die Datei vollständig hochgeladen wurde. Solltest Du folgende Meldung bekommen
    Zitat:

    Diese Datei wurde bereits von VirusTotal analysiert...
    klicke auf Neu analysieren.
  • Warte bis dir das Analysedatum angezeigt wird und der Scan abgeschlossen ist.
  • Kopiere den Link aus deiner Adresszeile und poste ihn hier.

Warlord711 09.02.2015 17:35

Und ausserdem:
Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

LarryPerkins 09.02.2015 18:41

Danke für Deine Mühe, gefunden wurde aber bei beiden wohl nichts:

Link:

Code:

https://www.virustotal.com/de/file/0f3c059965263738ab63fd1cd864fa4d272576ff7a0e58c40f287c2058e3d6b4/analysis/1423501210/
Malwarebytes Rootkit (musste nicht rebooten):

Code:

Malwarebytes Anti-Rootkit BETA 1.08.3.1004
www.malwarebytes.org

Database version:
  main:    v2015.02.09.08
  rootkit: v2015.02.03.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.17501
Tom Rauhe :: TOMRAUHE-VAIO [administrator]

09.02.2015 18:05:08
mbar-log-2015-02-09 (18-05-08).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 348966
Time elapsed: 13 minute(s), 49 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

Könnte schwören es wäre nochmal aufgetreten, aber jetzt ist seit 10min Ruhe... denke ich.
Warte mal ob es wieder kommt bevor Du noch mehr Arbeit rein steckst :) Danke! Ich geb aber noch endgültiges Feedback..!

Warlord711 09.02.2015 18:53

Hast du mal nen Rechner Neustart gemacht und dann direkt FRST64.exe gestartet ?

LarryPerkins 09.02.2015 19:24

Also ich werd doch immernoch auf den Desktop geschmissen.

Ja hab auch mal Neustart gemacht und alles deaktiviert, auch so Startup Programme wie Razer und Skype usw und Virenscanner ausgeschaltet.

Das Programm stürzt immernoch mit "funktioniert nicht mehr" Fehlermeldung ab (das 64er, das andere geht ja gar nicht weil 64er System).

Hab's auch nochmal runtergeladen, selbes Ergebnis.

Warlord711 09.02.2015 20:18

Dann mach mal:

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


LarryPerkins 09.02.2015 21:16

Code:

ComboFix 15-02-09.01 - XXX YYY 09.02.2015  20:58:51.1.4 - x64
Microsoft Windows 7 Professional  6.1.7601.1.1252.49.1031.18.3766.1621 [GMT 1:00]
ausgeführt von:: c:\users\XXX YYY\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\XXX YYY\AppData\Local\lame_enc.dll
c:\users\XXX YYY\AppData\Local\Microsoft\Windows\Temporary Internet Files\{DF4D83B2-7B07-4161-8485-61A4EF0A2DBD}.xps
c:\users\XXX YYY\AppData\Local\no23xwrapper.dll
c:\users\XXX YYY\AppData\Local\ogg.dll
c:\users\XXX YYY\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\users\XXX YYY\AppData\Local\vorbis.dll
c:\users\XXX YYY\AppData\Local\vorbisenc.dll
c:\users\XXX YYY\AppData\Local\vorbisfile.dll
c:\users\XXX YYY\AppData\Roaming\.#
c:\users\XXXRAU~1\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\windows\msdownld.tmp
.
.
(((((((((((((((((((((((  Dateien erstellt von 2015-01-09 bis 2015-02-09  ))))))))))))))))))))))))))))))
.
.
2015-02-09 17:04 . 2015-02-09 17:21        --------        d-----w-        c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-02-09 16:59 . 2015-02-09 16:59        --------        d-----w-        c:\programdata\OnlineUpdate
2015-02-09 16:59 . 2015-02-09 16:59        --------        d-----w-        c:\programdata\log
2015-02-09 11:00 . 2015-02-09 18:21        --------        d-----w-        C:\FRST
2015-02-09 08:37 . 2015-02-09 08:41        --------        d-----w-        C:\AdwCleaner
2015-02-05 15:56 . 2015-02-09 17:04        136408        ----a-w-        c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-02-05 15:56 . 2015-02-09 17:03        97496        ----a-w-        c:\windows\system32\drivers\mbamchameleon.sys
2015-02-05 15:56 . 2015-02-05 15:56        --------        d-----w-        c:\program files (x86)\Malwarebytes Anti-Malware
2015-02-05 15:56 . 2015-02-05 15:56        --------        d-----w-        c:\programdata\Malwarebytes
2015-02-05 15:56 . 2014-11-21 05:14        63704        ----a-w-        c:\windows\system32\drivers\mwac.sys
2015-02-05 15:56 . 2014-11-21 05:14        25816        ----a-w-        c:\windows\system32\drivers\mbam.sys
2015-01-24 15:42 . 2015-01-24 18:43        --------        d-----w-        c:\programdata\Steam
2015-01-23 15:45 . 2015-01-23 15:45        --------        d-----w-        c:\programdata\VTech
2015-01-23 15:45 . 2015-01-23 15:45        --------        d-----w-        c:\program files (x86)\VTech
2015-01-21 14:56 . 2015-01-21 15:05        --------        d-----w-        c:\users\XXX YYY\AppData\Roaming\webex
2015-01-21 14:56 . 2015-01-21 14:56        --------        d-----w-        c:\programdata\WebEx
2015-01-21 14:56 . 2015-01-21 14:56        --------        d-----w-        c:\users\XXX YYY\AppData\Local\WebEx
2015-01-19 12:39 . 2014-06-16 06:01        110336        ----a-w-        c:\windows\system32\drivers\ssudbus.sys
2015-01-19 12:24 . 2015-01-19 12:24        --------        d-----w-        c:\program files\SAMSUNG
2015-01-19 12:22 . 2015-01-19 12:22        --------        d-----w-        c:\programdata\Samsung
2015-01-19 12:21 . 2015-01-19 12:21        --------        d-----w-        c:\program files (x86)\ClockworkMod
2015-01-17 17:47 . 2015-01-19 09:17        --------        d-----w-        c:\program files (x86)\Mozilla Thunderbird
2015-01-15 14:37 . 2015-01-15 14:37        --------        d-----w-        c:\windows\de
2015-01-15 14:36 . 2010-05-26 10:41        2106216        ----a-w-        c:\windows\SysWow64\D3DCompiler_43.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-02-05 15:28 . 2013-03-20 10:36        71344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-02-05 15:28 . 2013-03-20 10:36        701616        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2015-02-04 14:20 . 2013-03-20 10:10        113365784        ----a-w-        c:\windows\system32\MRT.exe
2014-12-30 13:58 . 2014-04-16 08:09        13792        ----a-w-        c:\windows\system32\drivers\semav6thermal64ro.sys
2014-12-30 09:35 . 2014-12-30 09:35        177832        ----a-w-        c:\windows\system32\drivers\rzudd.sys
2014-12-30 09:28 . 2014-12-30 09:28        990720        ----a-w-        c:\windows\SysWow64\rzdevicedll.dll
2014-12-30 09:28 . 2014-12-30 09:28        78848        ----a-w-        c:\windows\SysWow64\rzvirtualdev.dll
2014-12-30 09:28 . 2014-12-30 09:28        89088        ----a-w-        c:\windows\SysWow64\rzdevinfo.dll
2014-12-30 09:28 . 2014-12-30 09:28        155136        ----a-w-        c:\windows\SysWow64\rztouchdll.dll
2014-12-30 09:28 . 2014-12-30 09:28        117248        ----a-w-        c:\windows\SysWow64\rzdisplaydll.dll
2014-12-30 09:28 . 2014-12-30 09:28        419840        ----a-w-        c:\windows\SysWow64\rzaudiodll.dll
2014-12-19 03:22 . 2014-12-19 03:22        9728        ----a-w-        c:\windows\SysWow64\RzStats.IPC.dll
2014-12-10 20:43 . 2015-01-08 11:59        129600        ----a-w-        c:\windows\system32\drivers\rzpnk.sys
2014-12-09 22:21 . 2015-01-08 11:59        37184        ----a-w-        c:\windows\system32\drivers\rzpmgrk.sys
2014-12-04 02:50 . 2014-12-10 13:27        413184        ----a-w-        c:\windows\system32\generaltel.dll
2014-12-04 02:50 . 2014-12-10 13:27        741376        ----a-w-        c:\windows\system32\invagent.dll
2014-12-04 02:50 . 2014-12-10 13:27        396800        ----a-w-        c:\windows\system32\devinv.dll
2014-12-04 02:50 . 2014-12-10 13:27        830976        ----a-w-        c:\windows\system32\appraiser.dll
2014-12-04 02:50 . 2014-12-10 13:27        192000        ----a-w-        c:\windows\system32\aepic.dll
2014-12-04 02:50 . 2014-12-10 13:27        227328        ----a-w-        c:\windows\system32\aepdu.dll
2014-12-04 02:44 . 2014-12-10 13:27        1083392        ----a-w-        c:\windows\system32\aeinv.dll
2014-12-01 23:28 . 2014-12-10 13:27        1232040        ----a-w-        c:\windows\system32\aitstatic.exe
2014-11-27 01:43 . 2014-12-10 13:28        389296        ----a-w-        c:\windows\system32\iedkcs32.dll
2014-11-22 03:13 . 2014-12-10 13:28        25059840        ----a-w-        c:\windows\system32\mshtml.dll
2014-11-22 03:06 . 2014-12-10 13:28        2724864        ----a-w-        c:\windows\system32\mshtml.tlb
2014-11-22 03:06 . 2014-12-10 13:28        4096        ----a-w-        c:\windows\system32\ieetwcollectorres.dll
2014-11-22 02:50 . 2014-12-10 13:28        66560        ----a-w-        c:\windows\system32\iesetup.dll
2014-11-22 02:50 . 2014-12-10 13:28        580096        ----a-w-        c:\windows\system32\vbscript.dll
2014-11-22 02:49 . 2014-12-10 13:28        48640        ----a-w-        c:\windows\system32\ieetwproxystub.dll
2014-11-22 02:49 . 2014-12-10 13:28        2885120        ----a-w-        c:\windows\system32\iertutil.dll
2014-11-22 02:48 . 2014-12-10 13:28        88064        ----a-w-        c:\windows\system32\MshtmlDac.dll
2014-11-22 02:41 . 2014-12-10 13:28        54784        ----a-w-        c:\windows\system32\jsproxy.dll
2014-11-22 02:40 . 2014-12-10 13:28        34304        ----a-w-        c:\windows\system32\iernonce.dll
2014-11-22 02:37 . 2014-12-10 13:28        633856        ----a-w-        c:\windows\system32\ieui.dll
2014-11-22 02:35 . 2014-12-10 13:28        114688        ----a-w-        c:\windows\system32\ieetwcollector.exe
2014-11-22 02:34 . 2014-12-10 13:28        814080        ----a-w-        c:\windows\system32\jscript9diag.dll
2014-11-22 02:34 . 2014-12-10 13:28        6039552        ----a-w-        c:\windows\system32\jscript9.dll
2014-11-22 02:26 . 2014-12-10 13:28        968704        ----a-w-        c:\windows\system32\MsSpellCheckingFacility.exe
2014-11-22 02:22 . 2014-12-10 13:28        490496        ----a-w-        c:\windows\system32\dxtmsft.dll
2014-11-22 02:20 . 2014-12-10 13:28        2724864        ----a-w-        c:\windows\SysWow64\mshtml.tlb
2014-11-22 02:14 . 2014-12-10 13:28        77824        ----a-w-        c:\windows\system32\JavaScriptCollectionAgent.dll
2014-11-22 02:09 . 2014-12-10 13:28        199680        ----a-w-        c:\windows\system32\msrating.dll
2014-11-22 02:08 . 2014-12-10 13:28        92160        ----a-w-        c:\windows\system32\mshtmled.dll
2014-11-22 02:07 . 2014-12-10 13:28        501248        ----a-w-        c:\windows\SysWow64\vbscript.dll
2014-11-22 02:07 . 2014-12-10 13:28        62464        ----a-w-        c:\windows\SysWow64\iesetup.dll
2014-11-22 02:06 . 2014-12-10 13:28        47616        ----a-w-        c:\windows\SysWow64\ieetwproxystub.dll
2014-11-22 02:05 . 2014-12-10 13:28        64000        ----a-w-        c:\windows\SysWow64\MshtmlDac.dll
2014-11-22 02:05 . 2014-12-10 13:28        316928        ----a-w-        c:\windows\system32\dxtrans.dll
2014-11-22 01:54 . 2014-12-10 13:28        620032        ----a-w-        c:\windows\SysWow64\jscript9diag.dll
2014-11-22 01:49 . 2014-12-10 13:28        718848        ----a-w-        c:\windows\system32\ie4uinit.exe
2014-11-22 01:49 . 2014-12-10 13:28        800768        ----a-w-        c:\windows\system32\msfeeds.dll
2014-11-22 01:47 . 2014-12-10 13:28        1359360        ----a-w-        c:\windows\system32\mshtmlmedia.dll
2014-11-22 01:46 . 2014-12-10 13:28        2125312        ----a-w-        c:\windows\system32\inetcpl.cpl
2014-11-22 01:43 . 2014-12-10 13:28        14412800        ----a-w-        c:\windows\system32\ieframe.dll
2014-11-22 01:40 . 2014-12-10 13:28        60416        ----a-w-        c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-11-22 01:29 . 2014-12-10 13:28        4299264        ----a-w-        c:\windows\SysWow64\jscript9.dll
2014-11-22 01:28 . 2014-12-10 13:28        2358272        ----a-w-        c:\windows\system32\wininet.dll
2014-11-22 01:22 . 2014-12-10 13:28        2052096        ----a-w-        c:\windows\SysWow64\inetcpl.cpl
2014-11-22 01:21 . 2014-12-10 13:28        1155072        ----a-w-        c:\windows\SysWow64\mshtmlmedia.dll
2014-11-22 01:15 . 2014-12-10 13:28        1548288        ----a-w-        c:\windows\system32\urlmon.dll
2014-11-22 01:03 . 2014-12-10 13:28        800768        ----a-w-        c:\windows\system32\ieapfltr.dll
2014-11-22 01:00 . 2014-12-10 13:28        1888256        ----a-w-        c:\windows\SysWow64\wininet.dll
2014-11-19 03:31 . 2014-11-19 03:31        1217192        ----a-w-        c:\windows\SysWow64\FM20.DLL
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-09-25 10:37        239272        ----a-w-        c:\users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-09-25 10:37        239272        ----a-w-        c:\users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-09-25 10:37        239272        ----a-w-        c:\users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04        131480        ----a-w-        c:\users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04        131480        ----a-w-        c:\users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04        131480        ----a-w-        c:\users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2015-01-23 1942720]
"SkyDrive"="c:\users\XXX YYY\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" [2014-09-25 277672]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-12-11 30879328]
"GoogleChromeAutoLaunch_550EDA027B4B11347618D98EDCBB3ADF"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2015-02-04 843592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2010-05-31 673136]
"MobileBroadband"="c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-05-18 253440]
"MarketingTools"="c:\program files (x86)\Sony\Marketing Tools\MarketingTools.exe" [2013-03-19 26624]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-12-11 702768]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2015-01-06 585536]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-10-28 49208]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"DivXMediaServer"="c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" [2014-08-19 448856]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2014-01-10 1861968]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-10-02 421888]
"AgentMonitor"="c:\program files (x86)\VTech\DownloadManager\System\AgentMonitor.exe" [2014-06-20 401280]
"Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2014-12-31 126712]
.
c:\users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-12-9 39207112]
FastStone Capture.lnk - c:\program files (x86)\FastStone Capture\FSCapture.exe -Silent [2007-2-12 1111552]
OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2013-6-25 228552]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-6-8 1128224]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages        REG_MULTI_SZ          scecli c:\program files\Protector Suite\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 0067591363772028mcinstcleanup;McAfee Application Installer Cleanup (0067591363772028);c:\windows\TEMP\006759~1.EXE;c:\windows\TEMP\006759~1.EXE [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 Internet Manager. RunOuc;Internet Manager. OUC;c:\program files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe;c:\program files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [x]
R2 mcbootdelaystartsvc;McAfee Boot Delay Start Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [x]
R2 PDFProFiltSrv;PDFProFiltSrv;c:\program files (x86)\Nuance\PDF Professional 8\PDFProFiltSrv.exe;c:\program files (x86)\Nuance\PDF Professional 8\PDFProFiltSrv.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys;c:\windows\SYSNATIVE\DRIVERS\ew_hwusbdev.sys [x]
R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys;c:\windows\SYSNATIVE\DRIVERS\ew_usbenumfilter.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbnet.sys [x]
R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys;c:\windows\SYSNATIVE\drivers\HipShieldK.sys [x]
R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys;c:\windows\SYSNATIVE\drivers\hitmanpro37.sys [x]
R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jucdcacm.sys [x]
R3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\system32\DRIVERS\ew_juextctrl.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juextctrl.sys [x]
R3 huawei_wwanecm;huawei_wwanecm;c:\windows\system32\DRIVERS\ew_juwwanecm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juwwanecm.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 McComponentHostServiceSony;McAfee Security Scan Component Host Service for Sony;c:\program files (x86)\Sony\MSS\3.8.130\McCHSvc.exe;c:\program files (x86)\Sony\MSS\3.8.130\McCHSvc.exe [x]
R3 qcfiltersny2k;Qualcomm Gobi 2000 USB Composite Device Filter 9225;c:\windows\system32\DRIVERS\qcfiltersny2k.sys;c:\windows\SYSNATIVE\DRIVERS\qcfiltersny2k.sys [x]
R3 qcombussny;Gobi 2000 USB Composite Device Driver(05C6-9225);c:\windows\system32\DRIVERS\qcombussny.sys;c:\windows\SYSNATIVE\DRIVERS\qcombussny.sys [x]
R3 qcusbnetsny2k;Gobi 2000 USB-NDIS miniport(05C6-9225);c:\windows\system32\DRIVERS\qcusbnetsny2k.sys;c:\windows\SYSNATIVE\DRIVERS\qcusbnetsny2k.sys [x]
R3 qcusbsersny2k;Gobi 2000 USB Device for Legacy Serial Communication(05C6-9225);c:\windows\system32\DRIVERS\qcusbserSny2k.sys;c:\windows\SYSNATIVE\DRIVERS\qcusbserSny2k.sys [x]
R3 RRNetCap;RRNetCap Service;c:\windows\system32\DRIVERS\rrnetcap.sys;c:\windows\SYSNATIVE\DRIVERS\rrnetcap.sys [x]
R3 rzendpt;rzendpt;c:\windows\system32\DRIVERS\rzendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzendpt.sys [x]
R3 rzmpos;rzmpos;c:\windows\system32\DRIVERS\rzmpos.sys;c:\windows\SYSNATIVE\DRIVERS\rzmpos.sys [x]
R3 rzudd;Razer Mouse Driver;c:\windows\system32\DRIVERS\rzudd.sys;c:\windows\SYSNATIVE\DRIVERS\rzudd.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USER_ESRV_SVC;User Energy Server Service;c:\program files\Sony\VAIO Care\ESRV\esrv_svc.exe;c:\program files\Sony\VAIO Care\ESRV\esrv_svc.exe [x]
R3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe;c:\program files\Sony\VAIO Care\VCService.exe [x]
R3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update\vuagent.exe;c:\program files\Sony\VAIO Update\vuagent.exe [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 RzFilter;RzFilter;c:\windows\system32\drivers\RzFilter.sys;c:\windows\SYSNATIVE\drivers\RzFilter.sys [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x]
S2 ClickToRunSvc;Microsoft Office-Klick-und-Los-Dienst;c:\program files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe;c:\program files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [x]
S2 ESRV_SVC;Energy Server Service;c:\program files\Sony\VAIO Care\ESRV\esrv_svc.exe --AUTO_START --start --address 127.0.0.1;c:\program files\Sony\VAIO Care\ESRV\esrv_svc.exe --AUTO_START --start --address 127.0.0.1 [x]
S2 HWDeviceService64.exe;HWDeviceService64.exe;c:\programdata\DatacardService\HWDeviceService64.exe;c:\programdata\DatacardService\HWDeviceService64.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 nvservice;NVIDIA GuardService;c:\windows\system32\nvservice.exe;c:\windows\SYSNATIVE\nvservice.exe [x]
S2 QDLService2kSony;Qualcomm Gobi 2000 Download Service (Sony);c:\program files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe;c:\program files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe [x]
S2 Razer Game Scanner Service;Razer Game Scanner;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [x]
S2 rimspci;rimspci;c:\windows\system32\drivers\rimssne64.sys;c:\windows\SYSNATIVE\drivers\rimssne64.sys [x]
S2 risdsnpe;risdsnpe;c:\windows\system32\drivers\risdsne64.sys;c:\windows\SYSNATIVE\drivers\risdsne64.sys [x]
S2 RzOvlMon;Razer Overlay Subsystem Emergency Service;c:\program files (x86)\Razer\Core\64bit\rzovlmon.exe;c:\program files (x86)\Razer\Core\64bit\rzovlmon.exe [x]
S2 rzpmgrk;rzpmgrk;c:\windows\system32\drivers\rzpmgrk.sys;c:\windows\SYSNATIVE\drivers\rzpmgrk.sys [x]
S2 rzpnk;rzpnk;c:\windows\system32\drivers\rzpnk.sys;c:\windows\SYSNATIVE\drivers\rzpnk.sys [x]
S2 SampleCollector;Intel(R) System Behavior Tracker Collector Service;c:\program files\Sony\VAIO Care\VCPerfService.exe;c:\program files\Sony\VAIO Care\VCPerfService.exe [x]
S2 ss_conn_service;SAMSUNG Mobile Connectivity Service;c:\program files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe;c:\program files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe;c:\program files\Sony\VAIO Power Management\SPMService.exe [x]
S2 VmbService;Vodafone-Mobile-Broadband-Dienst;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [x]
S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe;c:\program files\Sony\VAIO Smart Network\VSNService.exe [x]
S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1k62x64.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys;c:\windows\SYSNATIVE\drivers\HECIx64.sys [x]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jubusenum.sys [x]
S3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys;c:\windows\SYSNATIVE\drivers\Impcd.sys [x]
S3 NETw5s64;Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x]
S3 RRNetCapMP;RRNetCapMP;c:\windows\system32\DRIVERS\rrnetcap.sys;c:\windows\SYSNATIVE\DRIVERS\rrnetcap.sys [x]
S3 RzDxgk;RzDxgk;c:\windows\system32\drivers\RzDxgk.sys;c:\windows\SYSNATIVE\drivers\RzDxgk.sys [x]
S3 semav6thermal64ro;semav6thermal64ro;c:\windows\system32\drivers\semav6thermal64ro.sys;c:\windows\SYSNATIVE\drivers\semav6thermal64ro.sys [x]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys;c:\windows\SYSNATIVE\DRIVERS\SFEP.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-02-07 07:15        1086280        ----a-w-        c:\program files (x86)\Google\Chrome\Application\40.0.2214.111\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2015-02-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-20 15:28]
.
2015-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-03-19 15:04]
.
2015-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-03-19 15:04]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-09-25 10:37        266416        ----a-w-        c:\users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-09-25 10:37        266416        ----a-w-        c:\users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-09-25 10:37        266416        ----a-w-        c:\users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-11-12 08:07        2334928        ----a-w-        c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-11-12 08:07        2334928        ----a-w-        c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-11-12 08:07        2334928        ----a-w-        c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04        164760        ----a-w-        c:\users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04        164760        ----a-w-        c:\users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04        164760        ----a-w-        c:\users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04        164760        ----a-w-        c:\users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2010-04-27 14:48        5947656        ----a-w-        c:\program files\Protector Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2010-04-27 14:48        5947656        ----a-w-        c:\program files\Protector Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-06-22 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-06-22 390680]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-06-22 410136]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-06-04 16414824]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-18 9962016]
"PSQLLauncher"="c:\program files\Protector Suite\launcher.exe" [2010-04-27 84744]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\program files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.178.1
TCP: Interfaces\{AA2DF348-6AB3-482F-A8BC-41E89158A468}: NameServer = 10.74.210.210 10.74.210.211
FF - ProfilePath - c:\users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.de
FF - prefs.js: network.proxy.type - 2
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-Wondershare Helper Compact.exe - c:\program files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelperSetup.exe
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=10000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1\" \"/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\%C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\""
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.16"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\programdata\Internet Manager\OnlineUpdate\ouc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Sony\VAIO Event Service\VESMgr.exe
c:\windows\SysWOW64\DllHost.exe
c:\program files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
c:\program files\Sony\VAIO Care\listener.exe
c:\program files\Microsoft Office 15\Root\Office15\MsoSync.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-02-09  21:15:13 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2015-02-09 20:15
.
Vor Suchlauf: 8.711.974.912 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 13.290.799.104 Bytes frei
.
- - End Of File - - 87A4221DB87E492E89DF75D9043CFC52


Warlord711 09.02.2015 21:51

Ok, mach mal Rechner-Neustart und dann nochmal versuchen, ein FRST Log zu erstellen.

LarryPerkins 09.02.2015 22:57

Nope, stürzt leider immernoch ab, erzeugt aber wie gesagt ein (anscheinend unvollständiges) File wieder:

Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-02-2015
Ran by XXX YYY (administrator) on XXXYYY-VAIO on 09-02-2015 22:54:17
Running from C:\Users\XXX YYY\Downloads
Loaded Profiles: XXX YYY (Available profiles: XXX YYY)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvservice.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
(UPEK Inc.) C:\Program Files\Protector Suite\upeksvr.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(QUALCOMM, Inc.) C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(UPEK Inc.) C:\Program Files\Protector Suite\psqltray.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files (x86)\FastStone Capture\FSCapture.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
(Sony Corporation) C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\csisyncclient.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\msosync.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
Failed to access process -> dllhost.exe
Failed to access process -> dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9962016 2010-06-18] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1886504 2010-03-01] (Synaptics Incorporated)
HKLM\...\Run: [PSQLLauncher] => C:\Program Files\Protector Suite\launcher.exe [84744 2010-04-27] (UPEK Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [673136 2010-05-31] (Sony Corporation)
HKLM-x32\...\Run: [MobileBroadband] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [253440 2010-05-18] (Vodafone)
HKLM-x32\...\Run: [MarketingTools] => C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [26624 2013-03-19] (Sony Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-11] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585536 2015-01-06] (Razer Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-08-19] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2014-12-31] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (UPEK Inc.)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1942720 2015-01-23] (Valve Corporation)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [SkyDrive] => C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [277672 2014-09-25] (Microsoft Corporation)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30879328 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [GoogleChromeAutoLaunch_550EDA027B4B11347618D98EDCBB3ADF] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592 2015-02-04] (Google Inc.)
Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk
ShortcutTarget: FastStone Capture.lnk -> C:\Program Files (x86)\FastStone Capture\FSCapture.exe ()
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [UEAFOverlay] -> {F2F31467-B1AC-4df0-AE79-FD5FA085E22B} => C:\Program Files\Protector Suite\farchns.dll (UPEK Inc.)
ShellIconOverlayIdentifiers: [UEAFOverlayOpen] -> {A3E208F7-0E3A-4182-A7A6-B169D5D691AA} => C:\Program Files\Protector Suite\farchns.dll (UPEK Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {3617BCD7-E991-4BB5-8542-09A0B20EE913} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {794C16B2-C354-42CB-8212-172F5BD771B6} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms}
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {A70EC677-F517-45E6-831A-E87104D7AC0B} URL = hxxp://de.shopping.com/?linkin_id=8056363
BHO: No Name -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} ->  No File
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} ->  No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{876E33B5-EE1E-4322-8F79-79EB6087A1E2}: [NameServer] 
Tcpip\..\Interfaces\{AA2DF348-6AB3-482F-A8BC-41E89158A468}: [NameServer] 10.74.210.210 10.74.210.211

FireFox:
========
FF ProfilePath: C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default
FF DefaultSearchEngine: Google
FF SelectedSearchEngine: Google
FF Homepage: www.google.de
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*'))%20%7B%20return%20'PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\Sony\MSS\3.8.130\npMcAfeeMss.dll No File
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\XXX YYY\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3557091032-3563988234-1886976076-1000: @citrixonline.com/appdetectorplugin -> C:\Users\XXX YYY\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin HKU\S-1-5-21-3557091032-3563988234-1886976076-1000: LWAPlugin15.8 -> C:\Users\XXX YYY\AppData\Roaming\Mozilla\Plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\XXX YYY\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\XXX YYY\AppData\Roaming\mozilla\plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\XXX YYY\AppData\Roaming\mozilla\plugins\npoctoshape.dll (Octoshape ApS)
FF SearchPlugin: C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\searchplugins\translate-korean-to-english.xml
FF Extension: Avira Browser Safety - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\abs@avira.com [2015-02-03]
FF Extension: Password Bank - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\passwordbank@upek.com [2013-03-20]
FF Extension: Ghostery - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\firefox@ghostery.com.xpi [2013-08-19]
FF Extension: FireGestures - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\firegestures@xuldev.org.xpi [2013-03-20]
FF Extension: ProxMate - Proxy on steroids! - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-08-09]
FF Extension: Yesware Email Tracking - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\jid1-T5mdAATMX3urKA@jetpack.xpi [2013-04-24]
FF Extension: Rapportive - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\rapportive@rapportive.com.xpi [2013-06-20]
FF Extension: TinEye Reverse Image Search - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\tineye@ideeinc.com.xpi [2013-03-20]
FF Extension: Alexa Sparky - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\toolbar@alexa.com.xpi [2015-02-09]
FF Extension: Screengrab - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\{02450954-cdd9-410f-b1da-db804e18c671}.xpi [2013-03-20]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor


Warlord711 09.02.2015 23:05

Das ist echt schräg.

AdwCleaner hattest du auch schon laufen lassen wie ich sehe.

Downloade dir die passende Version von HitmanPro auf deinen Desktop: HitmanPro - 32 Bit | HitmanPro - 64 Bit.
  • Starte die HitmanPro.exe
  • Klicke auf
  • Entferne den Haken bei
  • Klicke auf
    und
  • Akzeptiere die Lizenzbedingungen und klicke auf
  • Klicke auf

    und auf
  • Wenn der Scan beendet wurde, nichts löschen lassen etc. sondern wähle unten links auf der Button-Leiste
    und speichere die Logdatei auf Deinem Desktop.
  • Schließe HitmanPro und poste mir das Log.

 


LarryPerkins 10.02.2015 02:57

Meine Lizenz von HitmanPro ist 2013 abgelaufen, scheinbar hab ich das da schonmal laufen lassen.
Gibt's ne Alternative? Der fragt nach nem Prododuktschlüssel

...abgesehen davon hat der Scan nichts gefunden außer paar Ad Cookies so wie ich das verstanden hab...

Warlord711 10.02.2015 09:44

Kannst du beim FRST Scan mal den AV-Schutz komplett deaktivieren ?

LarryPerkins 10.02.2015 14:53

Also wenn ich AV deaktiviere... hatte ich ja auch schon versucht.
Er bricht ab bei "Scanning Chrome Extensions".

Warlord711 10.02.2015 15:33

Dann vielleicht so:
Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8)
Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
  • Downloade dir bitte die passende Version des Tools (im Zweifel beide) und speichere diese auf einen USB Stick: FRST Download FRST 32-Bit | FRST 64-Bit
  • Schließe den USB Stick an das infizierte System an und boote das System in die System Reparatur Option.
  • Scanne jetzt nach der bebilderten Anleitung oder verwende die folgende Kurzanleitung:
Über den Boot Manager:
  • Starte den Rechner neu.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD (auch bei Windows 8 möglich):
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu und starte von der CD.
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen: Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument: Datei > Speichern unter... und wähle Computer.
    Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt, merke ihn dir.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein.
    e:\frst.exe bzw. e:\frst64.exe
    Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks, den du dir gemerkt hast. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Ja und klicke Untersuchen
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier nach Möglichkeit in Code-Tags (Anleitung).


LarryPerkins 10.02.2015 16:26

Ha! Jetzt hat's geklappt.
Allerdings waren da andere Scan Optionen mit Haken dran..? Also anders als im Bild.
Hier jedenfalls mal das File:


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-02-2015
Ran by SYSTEM on MININT-RUPRF0B on 10-02-2015 16:19:07
Running from G:\
Platform: Windows 7 Professional (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9962016 2010-06-18] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1886504 2010-03-01] (Synaptics Incorporated)
HKLM\...\Run: [PSQLLauncher] => C:\Program Files\Protector Suite\launcher.exe [84744 2010-04-27] (UPEK Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [673136 2010-05-31] (Sony Corporation)
HKLM-x32\...\Run: [MobileBroadband] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [253440 2010-05-18] (Vodafone)
HKLM-x32\...\Run: [MarketingTools] => C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [26624 2013-03-19] (Sony Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-11] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585536 2015-01-06] (Razer Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-08-19] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2014-12-31] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (UPEK Inc.)
HKU\XXX YYY\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1942720 2015-01-23] (Valve Corporation)
HKU\XXX YYY\...\Run: [SkyDrive] => C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [277672 2014-09-25] (Microsoft Corporation)
HKU\XXX YYY\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30879328 2014-12-11] (Skype Technologies S.A.)
HKU\XXX YYY\...\Run: [GoogleChromeAutoLaunch_550EDA027B4B11347618D98EDCBB3ADF] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592 2015-02-04] (Google Inc.)
Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk ->  (No File)
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk
ShortcutTarget: FastStone Capture.lnk -> C:\Program Files (x86)\FastStone Capture\FSCapture.exe ()
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG)
S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [178424 2014-12-31] (Avira Operations GmbH & Co. KG)
S2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
S2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [377768 2013-11-01] (Intel Corporation)
S2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2011-06-17] ()
S3 McComponentHostServiceSony; C:\Program Files (x86)\Sony\MSS\3.8.130\McCHSvc.exe [235216 2013-10-16] (McAfee, Inc.)
S2 nvservice; C:\Windows\system32\nvservice.exe [192800 2013-02-04] (NVIDIA Corporation)
S2 QDLService2kSony; c:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe [332024 2010-06-03] (QUALCOMM, Inc.)
S2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [186048 2014-12-09] ()
S2 RzOvlMon; C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe [32960 2014-04-18] (Razer, Inc.)
S2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [266168 2013-11-01] (Intel Corporation)
S2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [741640 2014-06-16] (DEVGURU Co., LTD.)
S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [377768 2013-11-01] (Intel Corporation)
S3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1642544 2014-02-28] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 0067591363772028mcinstcleanup; C:\Windows\TEMP\006759~1.EXE -cleanup -nolog [X]
S2 mcbootdelaystartsvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 PDFProFiltSrv; C:\Program Files (x86)\Nuance\PDF Professional 8\PDFProFiltSrv.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-29] (Avira Operations GmbH & Co. KG)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-29] (Avira Operations GmbH & Co. KG)
S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [238080 2012-04-23] (Huawei Technologies Co., Ltd.)
S3 qcfiltersny2k; C:\Windows\System32\DRIVERS\qcfiltersny2k.sys [6400 2010-06-03] (QUALCOMM Incorporated)
S3 qcombussny; C:\Windows\System32\DRIVERS\qcombussny.sys [137800 2010-06-03] (MCCI)
S3 qcusbnetsny2k; C:\Windows\System32\DRIVERS\qcusbnetsny2k.sys [442368 2010-06-03] (QUALCOMM Incorporated)
S3 qcusbsersny2k; C:\Windows\System32\DRIVERS\qcusbserSny2k.sys [230784 2010-06-03] (QUALCOMM Incorporated)
S3 RRNetCap; C:\Windows\System32\DRIVERS\rrnetcap.sys [37480 2013-03-22] (RapidSolution Software AG)
S3 RRNetCapMP; C:\Windows\System32\DRIVERS\rrnetcap.sys [37480 2013-03-22] (RapidSolution Software AG)
S3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-04-18] (Razer, Inc.)
S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39592 2014-09-05] (Razer Inc)
S1 RzFilter; C:\Windows\system32\drivers\RzFilter.sys [74432 2014-04-18] (Razer, Inc.)
S3 rzmpos; C:\Windows\System32\DRIVERS\rzmpos.sys [35496 2014-09-05] (Razer Inc)
S2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2014-12-09] (Razer, Inc.)
S2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2014-12-10] (Razer, Inc.)
S3 semav6thermal64ro; C:\Windows\system32\drivers\semav6thermal64ro.sys [13792 2014-12-30] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-10 16:04 - 2015-02-10 16:04 - 00039026 _____ () C:\Users\XXX YYY\Desktop\HitmanPro_20150210_1603.log
2015-02-09 23:05 - 2015-02-09 23:05 - 11225840 _____ (SurfRight B.V.) C:\Users\XXX YYY\Downloads\HitmanPro_x64.exe
2015-02-09 21:15 - 2015-02-09 21:15 - 00039064 _____ () C:\ComboFix.txt
2015-02-09 20:56 - 2015-02-09 21:15 - 00000000 ____D () C:\Qoobox
2015-02-09 20:56 - 2015-02-09 21:13 - 00000000 ____D () C:\Windows\erdnt
2015-02-09 20:56 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-09 20:56 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-09 20:56 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-09 20:54 - 2015-02-09 20:55 - 05611930 ____R (Swearware) C:\Users\XXX YYY\Desktop\ComboFix.exe
2015-02-09 20:54 - 2015-02-09 20:54 - 05611930 _____ (Swearware) C:\Users\XXX YYY\Downloads\ComboFix.exe.part
2015-02-09 19:21 - 2015-02-09 19:21 - 02132992 _____ (Farbar) C:\Users\XXX YYY\Downloads\FRST64.exe
2015-02-09 18:04 - 2015-02-09 18:21 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-02-09 18:03 - 2015-02-09 18:21 - 00000000 ____D () C:\Users\XXX YYY\Desktop\mbar
2015-02-09 18:02 - 2015-02-09 18:02 - 16466552 _____ (Malwarebytes Corp.) C:\Users\XXX YYY\Downloads\mbar-1.08.3.1004.exe
2015-02-09 17:59 - 2015-02-09 17:59 - 00000000 ____D () C:\ProgramData\OnlineUpdate
2015-02-09 17:59 - 2015-02-09 17:59 - 00000000 ____D () C:\ProgramData\log
2015-02-09 17:23 - 2015-02-09 17:23 - 01124352 _____ (Farbar) C:\Users\XXX YYY\Downloads\FRST.exe
2015-02-09 15:05 - 2015-02-09 15:05 - 00442624 _____ () C:\Windows\Minidump\020915-9968-01.dmp
2015-02-09 12:53 - 2015-02-09 12:55 - 00042052 _____ () C:\Users\XXX YYY\Desktop\GMER.log
2015-02-09 12:40 - 2015-02-09 12:40 - 00268832 _____ () C:\Windows\Minidump\020915-10140-01.dmp
2015-02-09 12:29 - 2015-02-09 12:57 - 00149082 _____ () C:\Users\XXX YYY\Desktop\Trojanerboad Forumpost 090215.txt
2015-02-09 12:29 - 2015-02-09 12:29 - 00000869 _____ () C:\Users\XXX YYY\Desktop\Anleitung GMER.txt
2015-02-09 12:28 - 2015-02-09 12:28 - 00064922 _____ () C:\Users\XXX YYY\Downloads\Trojanerboad Forumpost 090215.txt
2015-02-09 12:23 - 2015-02-09 12:26 - 00001097 _____ () C:\Users\XXX YYY\Desktop\Malwarebytes Scan after Malwarebytes Removal.txt
2015-02-09 12:21 - 2015-02-09 12:30 - 00003827 _____ () C:\Users\XXX YYY\Desktop\Malwarebytes Scan.txt
2015-02-09 12:18 - 2015-02-09 12:18 - 00380416 _____ () C:\Users\XXX YYY\Downloads\Gmer-19357.exe
2015-02-09 12:01 - 2015-02-10 14:51 - 00024881 _____ () C:\Users\XXX YYY\Downloads\FRST.txt
2015-02-09 12:00 - 2015-02-10 14:51 - 00000000 ____D () C:\FRST
2015-02-09 11:58 - 2015-02-09 12:28 - 00000470 _____ () C:\Users\XXX YYY\Downloads\defogger_disable.log
2015-02-09 11:58 - 2015-02-09 11:58 - 00000000 _____ () C:\Users\XXX YYY\defogger_reenable
2015-02-09 11:57 - 2015-02-09 11:57 - 00050477 _____ () C:\Users\XXX YYY\Downloads\Defogger.exe
2015-02-09 09:49 - 2015-02-09 13:04 - 00003028 _____ () C:\Users\XXX YYY\Desktop\JRT.txt
2015-02-09 09:43 - 2015-02-09 09:43 - 01388274 _____ (Thisisu) C:\Users\XXX YYY\Downloads\JRT.exe
2015-02-09 09:37 - 2015-02-09 09:41 - 00000000 ____D () C:\AdwCleaner
2015-02-09 09:37 - 2015-02-09 09:37 - 02112512 _____ () C:\Users\XXX YYY\Downloads\AdwCleaner_4.110.exe
2015-02-07 08:01 - 2015-02-07 08:01 - 00262144 _____ () C:\Windows\Minidump\020715-11793-01.dmp
2015-02-05 17:20 - 2015-02-05 17:20 - 00000000 ____D () C:\Users\XXX YYY\Documents\Dungeon of the Endless
2015-02-05 16:56 - 2015-02-09 18:04 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\MBAMSwissArmy.sys
2015-02-05 16:56 - 2015-02-09 18:03 - 00097496 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamchameleon.sys
2015-02-05 16:56 - 2015-02-05 16:56 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-05 16:56 - 2015-02-05 16:56 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-05 16:56 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mwac.sys
2015-02-05 16:56 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2015-02-05 16:55 - 2015-02-05 16:55 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\XXX YYY\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-04 15:20 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2015-02-04 15:20 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxdav.sys
2015-02-04 15:20 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2015-02-04 15:20 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-02-04 15:20 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2015-02-04 15:20 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll
2015-02-04 15:20 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe
2015-02-04 15:20 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll
2015-02-04 15:20 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-02-04 15:20 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-02-04 15:20 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-02-04 15:20 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe
2015-02-04 15:20 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\System32\nlasvc.dll
2015-02-04 15:20 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-02-04 15:20 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-02-03 15:00 - 2015-02-03 15:01 - 07811072 _____ () C:\Users\XXX YYY\Downloads\LWAPlugin64BitInstaller32.msi
2015-01-29 14:05 - 2015-01-29 14:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-24 16:42 - 2015-01-24 19:43 - 00000000 ____D () C:\ProgramData\Steam
2015-01-23 16:45 - 2015-01-23 16:45 - 00001169 _____ () C:\Users\Public\Desktop\VTech Download Manager.lnk
2015-01-23 16:45 - 2015-01-23 16:45 - 00000000 ____D () C:\ProgramData\VTech
2015-01-23 16:45 - 2015-01-23 16:45 - 00000000 ____D () C:\Program Files (x86)\VTech
2015-01-23 16:44 - 2015-01-23 16:45 - 20758664 _____ (VTech) C:\Users\XXX YYY\Downloads\Kidizoom1407_DE_ger_Setup.exe
2015-01-21 16:05 - 2015-01-21 16:05 - 00217384 _____ (Cisco WebEx LLC) C:\Users\XXX YYY\Downloads\eggits2_Awebex_Acom,eggits2-de,2077473508,-1093361774,MC,0-0,SDJTSwAAAAJeWSAuzW-CSBddk8nRdEnMuWSMwGr2g0C4q48zrQRhMg2_webex.exe
2015-01-21 15:56 - 2015-01-21 16:05 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\webex
2015-01-21 15:56 - 2015-01-21 15:56 - 00646648 _____ (Cisco WebEx LLC) C:\Users\XXX YYY\Downloads\Cisco_WebEx_Add-On.exe
2015-01-21 15:56 - 2015-01-21 15:56 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\WebEx
2015-01-21 15:56 - 2015-01-21 15:56 - 00000000 ____D () C:\ProgramData\WebEx
2015-01-20 14:11 - 2015-01-20 14:11 - 00359961 _____ () C:\Users\XXX YYY\Downloads\Dokument
2015-01-19 15:12 - 2015-01-19 15:12 - 00002263 _____ () C:\Users\XXX YYY\Desktop\Chrome App Launcher.lnk
2015-01-19 14:58 - 2015-01-19 14:58 - 00000000 ____D () C:\Users\XXX YYY\Documents\Google USB driver
2015-01-19 14:53 - 2015-01-19 14:53 - 08682859 _____ () C:\Users\XXX YYY\Downloads\latest_usb_driver_windows.zip
2015-01-19 13:39 - 2014-06-16 07:01 - 00110336 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudbus.sys
2015-01-19 13:36 - 2015-01-19 13:36 - 16007072 _____ (SAMSUNG Electronics Co., Ltd.) C:\Users\XXX YYY\Downloads\SAMSUNG_USB_Driver_for_Mobile_Phones_v1.5.45.0.exe
2015-01-19 13:24 - 2015-01-19 13:24 - 00000000 ____D () C:\Program Files\SAMSUNG
2015-01-19 13:22 - 2015-01-19 13:22 - 00000000 ____D () C:\ProgramData\Samsung
2015-01-19 13:21 - 2015-01-19 13:21 - 24111736 _____ (SAMSUNG Electronics Co., Ltd.) C:\Users\XXX YYY\Downloads\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
2015-01-19 13:21 - 2015-01-19 13:21 - 00000000 ____D () C:\Program Files (x86)\ClockworkMod
2015-01-19 13:20 - 2015-01-19 13:20 - 11060224 _____ () C:\Users\XXX YYY\Downloads\CarbonSetup.msi
2015-01-17 18:47 - 2015-01-19 10:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2015-01-15 16:55 - 2015-01-15 17:09 - 453311842 _____ () C:\Users\XXX YYY\Downloads\Mobalo folder.zip
2015-01-15 15:37 - 2015-01-15 15:37 - 00000000 ____D () C:\Windows\de
2015-01-15 15:36 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2015-01-13 17:25 - 2015-01-13 17:25 - 09175231 _____ (MusicBrainz) C:\Users\XXX YYY\Downloads\picard-setup-1.3.2.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-10 16:15 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-10 16:15 - 2009-07-14 05:51 - 00216244 _____ () C:\Windows\setupact.log
2015-02-10 16:13 - 2014-05-02 11:30 - 00005172 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for XXXYYY-VAIO-XXX YYY XXXYYY-VAIO
2015-02-10 16:13 - 2014-05-02 11:27 - 00000000 ___RD () C:\Users\XXX YYY\OneDrive
2015-02-10 16:13 - 2013-04-02 10:55 - 00000000 ___RD () C:\Users\XXX YYY\Dropbox
2015-02-10 16:13 - 2013-03-20 12:01 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\Skype
2015-02-10 16:13 - 2013-03-19 16:48 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-10 16:13 - 2013-03-19 16:48 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-10 16:12 - 2013-04-02 10:51 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\Dropbox
2015-02-10 16:12 - 2013-04-02 09:33 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-02-10 16:05 - 2013-03-19 16:35 - 00703214 _____ () C:\Windows\System32\perfh007.dat
2015-02-10 16:05 - 2013-03-19 16:35 - 00150822 _____ () C:\Windows\System32\perfc007.dat
2015-02-10 16:05 - 2009-07-14 06:13 - 01629436 _____ () C:\Windows\System32\PerfStringBackup.INI
2015-02-10 16:04 - 2013-03-19 16:42 - 01452400 _____ () C:\Windows\WindowsUpdate.log
2015-02-10 16:03 - 2013-04-02 10:14 - 00000000 ____D () C:\Users\XXX YYY\Documents\mobalo
2015-02-10 15:28 - 2013-03-20 11:36 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-09 23:00 - 2009-07-14 05:45 - 00021872 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-09 23:00 - 2009-07-14 05:45 - 00021872 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-09 21:15 - 2013-03-20 12:05 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\Apps\2.0
2015-02-09 21:15 - 2009-07-14 04:20 - 00000000 __RHD () C:\users\Default
2015-02-09 21:12 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-02-09 21:10 - 2010-07-19 21:44 - 00503914 _____ () C:\Windows\PFRO.log
2015-02-09 15:05 - 2013-03-23 17:07 - 00000000 ____D () C:\Windows\Minidump
2015-02-09 11:58 - 2013-03-19 16:59 - 00000000 ____D () C:\users\XXX YYY
2015-02-09 09:46 - 2013-03-19 17:01 - 00003966 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{74DD3A27-0DC4-4DEC-A150-6D12E280742E}
2015-02-08 16:08 - 2013-03-19 16:48 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-08 16:08 - 2013-03-19 16:48 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-05 17:19 - 2013-03-20 11:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-05 17:19 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\addins
2015-02-05 16:28 - 2013-03-20 11:36 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-05 16:28 - 2013-03-20 11:36 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-05 16:28 - 2013-03-20 11:36 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-05 15:46 - 2014-12-22 11:11 - 00001097 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-02-05 15:46 - 2013-12-06 11:02 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-05 15:46 - 2013-03-23 22:04 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-02-04 15:41 - 2009-07-14 05:45 - 00446136 _____ () C:\Windows\System32\FNTCACHE.DAT
2015-02-04 15:31 - 2013-08-19 18:06 - 00000000 ____D () C:\Windows\System32\MRT
2015-02-04 15:20 - 2013-03-20 11:10 - 113365784 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2015-02-02 12:18 - 2013-03-19 16:59 - 00117264 _____ () C:\Users\XXX YYY\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-02 12:08 - 2010-07-19 21:45 - 00626734 _____ () C:\Windows\DPINST.LOG
2015-01-24 19:43 - 2014-12-12 18:11 - 00000000 ____D () C:\ProgramData\PopCap Games
2015-01-21 18:27 - 2013-04-02 10:22 - 00000000 ____D () C:\Users\XXX YYY\.thinkbuzan
2015-01-21 18:26 - 2013-04-02 10:22 - 00000000 ____D () C:\ProgramData\ThinkBuzan
2015-01-21 18:26 - 2013-04-02 10:22 - 00000000 ____D () C:\ProgramData\JSoft
2015-01-18 13:24 - 2014-12-22 00:54 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\Cinders
2015-01-15 15:48 - 2013-04-24 16:20 - 00000000 ____D () C:\Users\XXX YYY\Tracing
2015-01-15 15:36 - 2013-03-19 16:53 - 00000000 ____D () C:\Program Files\Windows Live
2015-01-15 15:36 - 2013-03-19 16:52 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-01-15 15:35 - 2013-03-19 16:53 - 00151643 _____ () C:\Windows\DirectX.log

ZeroAccess:
C:\Users\XXX YYY\AppData\Local\{4fa287a5-a9e8-a902-8c66-f7e1d24caa8e}

Some content of TEMP:
====================
C:\Users\XXX YYY\AppData\Local\Temp\avgnt.exe
C:\Users\XXX YYY\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpdhh4az.dll


==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

(There is no auXXXatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points  =========================

Restore point made on: 2015-02-09 23:13:21

==================== Memory info ===========================

Percentage of memory in use: 16%
Total physical RAM: 3765.82 MB
Available physical RAM: 3127.61 MB
Total Pagefile: 3763.97 MB
Available Pagefile: 3115.65 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.17 GB) (Free:12.39 GB) NTFS
Drive e: (Recovery) (Fixed) (Total:7.98 GB) (Free:0.79 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive g: () (Removable) (Total:1.87 GB) (Free:0.75 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: 720CB564)
Partition 1: (Not Active) - (Size=8 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=111.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 1.9 GB) (Disk ID: F9A2B4B0)
Partition 1: (Not Active) - (Size=1.9 GB) - (Type=06)


LastRegBack: 2015-01-26 14:22

==================== End Of Log ============================

--- --- ---

Warlord711 11.02.2015 14:51

Tjo, komische Sache.

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

emptytemp:

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.




Mach dann nach nem Neustart nochmal den Versuch, nen FRST Log zu erstellen.

LarryPerkins 11.02.2015 15:34

Code:

Results of screen317's Security Check version 0.99.96 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
 Windows Security Center service is not running! This report may not be accurate!
Avira Desktop 
 Antivirus up to date! 
`````````Anti-malware/Other Utilities Check:`````````
  Java 64-bit 8 Update 31 
 Adobe Flash Player 16.0.0.305 
 Adobe Reader XI 
 Mozilla Firefox (35.0.1)
 Mozilla Thunderbird (31.4.0)
 Google Chrome (40.0.2214.111)
 Google Chrome (40.0.2214.94)
````````Process Check: objlist.exe by Laurent```````` 
 Avira Antivir avgnt.exe
 Avira Antivir avguard.exe
 Internet Manager OnlineUpdate ouc.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-02-2015
Ran by XXX at 2015-02-11 15:25:22 Run:1
Running from C:\Users\XXX\Desktop
Loaded Profiles: XXX (Available profiles: XXX)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
emptytemp:
*****************

EmptyTemp: => Removed 1016.8 MB temporary data.


The system needed a reboot.

==== End of Fixlog 15:26:13 ====


Warlord711 11.02.2015 15:46

Versuch bitte nochmal nen Log zu erstellen (mit FRST)

LarryPerkins 11.02.2015 16:08

Nein, bricht leider immernoch mit "Farbar REcovery Scan Tool funktioniert nicht mehr" bei
Scanning Chrome Extensions.

Oder soll ich das mit dem USB Stick nochmal machen?

Warlord711 11.02.2015 16:41

Nö, wir greifen mal auf etwas älteres zurück:

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden ).
  • Doppelklick auf die OTL.exe
  • Oben findest Du ein Kästchen mit Ausgabe. Wähle bitte Minimal Ausgabe
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.

LarryPerkins 12.02.2015 11:25

Code:

OTL logfile created on: 12.02.2015 10:59:08 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\XXX YYY\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,68 Gb Total Physical Memory | 0,85 Gb Available Physical Memory | 23,00% Memory free
7,35 Gb Paging File | 3,89 Gb Available in Paging File | 52,85% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 111,17 Gb Total Space | 12,80 Gb Free Space | 11,51% Space Free | Partition Type: NTFS
 
Computer Name: XXXYYY-VAIO | User Name: XXX YYY | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\XXX YYY\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe ()
PRC - C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Programme\Sony\VAIO Care\VCService.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\csisyncclient.exe (Microsoft Corporation)
PRC - C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe ()
PRC - C:\Programme\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe (DEVGURU Co., LTD.)
PRC - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Programme\Sony\VAIO Care\listener.exe ()
PRC - C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe (Sony Corporation)
PRC - C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe ()
PRC - C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe ()
PRC - C:\ProgramData\DatacardService\DCSHelper.exe (Huawei Technologies Co., Ltd.)
PRC - C:\Windows\SysWOW64\prevhost.exe (Microsoft Corporation)
PRC - c:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe (QUALCOMM, Inc.)
PRC - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
PRC - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\FastStone Capture\FSCapture.exe ()
 
 
========== Modules (No Company Name) ==========
 
MOD - c:\users\XXXrau~1\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp_a6zrt.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\Steam\video.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\nsldap32v60.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\nsldappr32v60.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\92a3b88ac6300af062edd6503bc5903c\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\316b149dbb031d0e35c9d57bb2fc4b6e\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\7ab3e68c2e523f60bfc4f222cbd1c1d0\System.Xml.Linq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\38d6578b4fe29bede85ffff08e3697b6\PresentationFramework-SystemXml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio4b37ff64#\9370714a38ae2805434296b26a9f5b14\PresentationFramework-SystemXmlLinq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio84a7b877#\4df6733efc348c009a4a6e0adccc42a6\PresentationFramework-SystemData.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Model.Shor#\6d11b1280a9a392d44aa6521e2556554\Vodafone.Model.Shortcut.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Model.Conn#\1f7c7abe1f996fc1c0b3f7b84756935a\Vodafone.Model.Connection.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.View.Secon#\fdbb2979fdc6741ea5831d2f3c33c817\Vodafone.View.SecondaryWindows.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Vpn\c6e757994ee024eb51b8315d50b830d4\Vodafone.Vpn.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.FortinetCo#\acc9994c2360c02708f2df8545964a05\Vodafone.FortinetConnector.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.BusinessLo#\d215f84e68a80fd6764101688d8d6afc\Vodafone.BusinessLogic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.DeviceMana#\172dd8b2ffe4d266341ed18fc2b0ad42\Vodafone.DeviceManagement.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.LanWlanMan#\00276057b3eab06ccf44e69342fee7cd\Vodafone.LanWlanManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Common.Logging\130217a40884b8223387289476e0b369\Common.Logging.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Spring.Core\9abaae8e1e3d1f7e2f1b29dc7cbebafb\Spring.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Contracts.#\2606b67de3a2bfa7330c30f3a1afb5ff\Vodafone.Contracts.Presenter.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.InstancePr#\6b3bbbd2d8df19986ca6d81d71c4a620\Vodafone.InstanceProvider.Impl.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.CommonDial#\7ddbfd7d906aba4a4ceafb46695bcb1e\Vodafone.CommonDialogs.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Contracts.#\02f6143d2c1c4a56f4859fddc52b1b1b\Vodafone.Contracts.View.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Contracts.#\38c6e4589d8305015e679397491ac790\Vodafone.Contracts.Model.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.UpdateMana#\d91aa460c6ef2e24c8d894926324ca00\Vodafone.UpdateManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.ReportingM#\6b7f22226fa804f268049d7a1cc8e069\Vodafone.ReportingManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.SmsContact#\d9a5f52353cfb0bdae1008b37a9a661b\Vodafone.SmsContactManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.OutlookCon#\5d57d33088f8b61a2e67724c5c9d448e\Vodafone.OutlookConnector.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.TrafficOpt#\80a661491008870892b3df895c7c9494\Vodafone.TrafficOptimiser.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.WwanWrapper\141c9d8ee374af48e387086029847736\Vodafone.WwanWrapper.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.MobileBroa#\6d16b105f4110fe112de7033fde6080f\Vodafone.MobileBroadband.CallbackHandler.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Connection#\fb0231c220234f61cb937ce8b59eac38\Vodafone.ConnectionServices.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Contracts.#\c6aed7007b040c395bd822602b38663e\Vodafone.Contracts.Common.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Contracts.#\598964772a2907ab8164c095f316336a\Vodafone.Contracts.Adapter.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Applicatio#\6e21f0516168665f220378804c93e5f5\Vodafone.ApplicationHost.Impl.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.SettingsMa#\40bdbb0dc4396b08b4e252f0a98b1e49\Vodafone.SettingsManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.DataAccess#\f808ee3535387fb7135d906fd06f99ab\Vodafone.DataAccessor.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\MobileBroadbandReso#\ac46c145e1e72641f2f324c7f78a395c\MobileBroadbandResources.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Win32\1f3d0d19fe930a5d2b38723a9514b887\Vodafone.Win32.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Common\5850044a65af63ab08b3c3f6f8250412\Vodafone.Common.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Data\5d2d2ef2c4da9cc3bd59449347125aa7\Vodafone.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Platform\c52f2b752f831abf01960e77ab4de8e6\Vodafone.Platform.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.LogEngine\9d036ebb6ab008752843fabd507f4d0f\Vodafone.LogEngine.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\MobileBroadband\0ef374b6e55a6d75448955c6f338f187\MobileBroadband.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\99cdfef98595ed91f14936cf52a49c54\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\1f861b2b88c8a5a5b3b6c6144dc261d2\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\a229c5bed4a12b5db6ca55d223ada6df\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Design\03a626bdcfdec1158034377d1edc5f4d\System.Design.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\b4001d722e320fa42cd87b04b5249b2d\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\875c35969785fa170d186e7ca546ac9e\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\f45bc0251cceb599622f55cc1c7f4aba\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\4b335bfaa07fc54f2d72213d33f53e97\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1453d9e9a4989833ef3db4b22549ba1a\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\836e10dfd0811b303553216f5cb092ef\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\fc21baf1fd69ebbc21be4a9189951fc0\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d49908aa93a23c84847b1f8b1b667860\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\237d509a79aeef6e4635b09450d98f2a\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d97a5aa0eb7697aca7c6e90ae471af2b\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\908ba9e296e92b4e14bdc2437edac603\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\3646375313dd2b8e3afecbf945960336\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\006d28e7c86f3e70db90ce06ea2f33fb\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\8b133e0d94535a7534719f70873ca7fe\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\94bbd298ec8575f3c6151a59538a109c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\7971f3a1c08c4043cf981f457855b4d4\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\5d2c01ae1ca8c40ed74cdfd7b7b7dcb1\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\db563d596d76daed04e9b5d25b2f4cb9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Compba577418#\cc7bb025e7cca401787cec5893c2cb67\System.ComponentModel.Composition.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\5e84979fadb7eb63caedea9f4acefcc9\System.Data.Linq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\7147fa233a070283dba824da40089bf1\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\046058f81b039ab6fd839e03e67595f8\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\691c1ad89d16f49d80e84fa06a79089a\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\35d3a1b878542de59cb4fc0593992404\System.ServiceModel.Internals.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\f9f13cd8fe1cefaad78579a7c3a41464\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b4c08872c259018b17b2801da33ac80f\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\0648dbecb7e3fb9523565107e04a5caf\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\c90a4b709b46b64c89fce02585d55370\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\902843918d037f5f3511d679bf1e2216\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\17a393b77ae757f0768501fb95ff5af6\System.ni.dll ()
MOD - C:\Program Files (x86)\Steam\v8.dll ()
MOD - C:\Program Files (x86)\Steam\icui18n.dll ()
MOD - C:\Program Files (x86)\Steam\icuuc.dll ()
MOD - C:\Program Files (x86)\Steam\libavcodec-56.dll ()
MOD - C:\Program Files (x86)\Steam\libswscale-3.dll ()
MOD - C:\Program Files (x86)\Steam\libavformat-56.dll ()
MOD - C:\Program Files (x86)\Steam\libavutil-54.dll ()
MOD - C:\Program Files (x86)\Steam\libavresample-2.dll ()
MOD - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll ()
MOD - C:\Program Files (x86)\Steam\SDL2.dll ()
MOD - C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\libGLESv2.dll ()
MOD - C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\libEGL.dll ()
MOD - C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll ()
MOD - C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Interop.FNCClient11#\3a55f96f50938ec904bc6c62066529c3\Interop.FNCClient11Lib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Interop.Shell32\f28f529f01ffbdb55a4099ad9c9394c3\Interop.Shell32.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Connection#\6d59d9742c26700fc254ea66189c9b70\Vodafone.ConnectionManagement.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.SmsProfile#\ca50dccc60c3d966e536b6b9842f98de\Vodafone.SmsProfileManager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.Conflictin#\8e25c8199d77606fda99470ea99726ad\Vodafone.ConflictingApplications.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vodafone.NtServiceM#\37a397c89b8d3479378d1eab94c95579\Vodafone.NtServiceMessaging.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\0483c93466914f3fbd5b44454b0c8a98\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll ()
MOD - C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\LoggingPlatform.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtiff.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qmng.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qwbmp.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtga.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\plugins\sensors\qtsensors_dummy.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qsvg.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\plugins\platforms\qwindows.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qico.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qgif.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qjpeg.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qnativewifibearer.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qgenericbearer.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\QHttpServer.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files (x86)\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAuXXXationTypes\75b6a68103e1b76063d9f69b8275ae61\UIAuXXXationTypes.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\4c8a153aa66fcd62db6fff269a2ef2b4\System.Numerics.ni.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Programme\Sony\VAIO Care\listener.exe ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
MOD - C:\Program Files (x86)\Sony\Marketing Tools\Win32Interop.dll ()
MOD - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\NPSWF32.dll ()
MOD - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\sqlite.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Windows\SysWOW64\msjetoledb40.dll ()
MOD - C:\Program Files (x86)\FastStone Capture\FSCapture.exe ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (mcbootdelaystartsvc) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (ClickToRunSvc) -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe (Microsoft Corporation)
SRV:64bit: - (SampleCollector) -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Intel Corporation)
SRV:64bit: - (nvservice) -- C:\Windows\SysNative\nvservice.exe (NVIDIA Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Avira.OE.ServiceHost) -- C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Razer Game Scanner Service) -- C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe ()
SRV - (VCService) -- C:\Programme\Sony\VAIO Care\VCService.exe (Sony Corporation)
SRV - (ss_conn_service) -- C:\Programme\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe (DEVGURU Co., LTD.)
SRV - (TeamViewer9) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (RzOvlMon) -- C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe (Razer, Inc.)
SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (VUAgent) -- C:\Programme\Sony\VAIO Update\VUAgent.exe (Sony Corporation)
SRV - (USER_ESRV_SVC) -- C:\Programme\Sony\VAIO Care\ESRV\esrv_svc.exe (Intel Corporation)
SRV - (ESRV_SVC) -- C:\Programme\Sony\VAIO Care\ESRV\esrv_svc.exe (Intel Corporation)
SRV - (McComponentHostServiceSony) -- C:\Program Files (x86)\Sony\MSS\3.8.130\McCHSvc.exe (McAfee, Inc.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (Internet Manager. RunOuc) -- C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe ()
SRV - (HWDeviceService64.exe) -- C:\ProgramData\DatacardService\HWDeviceService64.exe ()
SRV - (WinHttpAutoProxySvc) -- winhttp.dll (Microsoft Corporation)
SRV - (VSNService) -- C:\Programme\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation)
SRV - (VAIO Power Management) -- C:\Programme\Sony\VAIO Power Management\SPMService.exe (Sony Corporation)
SRV - (btwdins) -- C:\Programme\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (QDLService2kSony) -- c:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe (QUALCOMM, Inc.)
SRV - (VAIO Event Service) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (VmbService) -- C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (ACDaemon) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (EvtEng) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV - (RegSrvc) -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (semav6thermal64ro) -- C:\Windows\SysNative\drivers\semav6thermal64ro.sys ()
DRV:64bit: - (rzudd) -- C:\Windows\SysNative\drivers\rzudd.sys (Razer Inc)
DRV:64bit: - (rzpnk) -- C:\Windows\SysNative\drivers\rzpnk.sys (Razer, Inc.)
DRV:64bit: - (rzpmgrk) -- C:\Windows\SysNative\drivers\rzpmgrk.sys (Razer, Inc.)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (rzmpos) -- C:\Windows\SysNative\drivers\rzmpos.sys (Razer Inc)
DRV:64bit: - (rzendpt) -- C:\Windows\SysNative\drivers\rzendpt.sys (Razer Inc)
DRV:64bit: - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (RzDxgk) -- C:\Windows\SysNative\drivers\RzDxgk.sys (Razer, Inc.)
DRV:64bit: - (RzFilter) -- C:\Windows\SysNative\drivers\RzFilter.sys (Razer, Inc.)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (tbhsd) -- C:\Windows\SysNative\drivers\tbhsd.sys (RapidSolution Software AG)
DRV:64bit: - (RRNetCapMP) -- C:\Windows\SysNative\drivers\rrnetcap.sys (RapidSolution Software AG)
DRV:64bit: - (RRNetCap) -- C:\Windows\SysNative\drivers\rrnetcap.sys (RapidSolution Software AG)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (huawei_wwanecm) -- C:\Windows\SysNative\drivers\ew_juwwanecm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (huawei_cdcacm) -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (huawei_enumerator) -- C:\Windows\SysNative\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (huawei_ext_ctrl) -- C:\Windows\SysNative\drivers\ew_juextctrl.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (HipShieldK) -- C:\Windows\SysNative\drivers\HipShieldK.sys (McAfee, Inc.)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (hwdatacard) -- C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (ew_hwusbdev) -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (risdsnpe) -- C:\Windows\SysNative\drivers\risdsne64.sys (REDC)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Impcd) -- C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (rimspci) -- C:\Windows\SysNative\drivers\rimssne64.sys (REDC)
DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (btwampfl) -- C:\Windows\SysNative\drivers\btwampfl.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwl2cap) -- C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (qcusbnetsny2k) -- C:\Windows\SysNative\drivers\qcusbnetsny2k.sys (QUALCOMM Incorporated)
DRV:64bit: - (qcusbsersny2k) -- C:\Windows\SysNative\drivers\qcusbserSny2k.sys (QUALCOMM Incorporated)
DRV:64bit: - (qcombussny) -- C:\Windows\SysNative\drivers\qcombussny.sys (MCCI)
DRV:64bit: - (qcfiltersny2k) -- C:\Windows\SysNative\drivers\qcfiltersny2k.sys (QUALCOMM Incorporated)
DRV:64bit: - (NETw5s64) -- C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:64bit: - (SFEP) -- C:\Windows\SysNative\drivers\SFEP.sys (Sony Corporation)
DRV:64bit: - (ew_usbenumfilter) -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (e1kexpress) -- C:\Windows\SysNative\drivers\e1k62x64.sys (Intel Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (HECIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{3617BCD7-E991-4BB5-8542-09A0B20EE913}: "URL" = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\..\SearchScopes\{794C16B2-C354-42CB-8212-172F5BD771B6}: "URL" = hxxp://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms}
IE - HKCU\..\SearchScopes\{A70EC677-F517-45E6-831A-E87104D7AC0B}: "URL" = hxxp://de.shopping.com/?linkin_id=8056363
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.isUS: false
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.de"
FF - prefs.js..extensions.enabledAddons: tineye%40ideeinc.com:1.1
FF - prefs.js..extensions.enabledAddons: toolbar%40alexa.com:1.8.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:35.0.1
FF - prefs.js..extensions.enabledItems: toolbar@alexa.com:2.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: passwordbank@upek.com:5.9.3.6319.3.6
FF - prefs.js..network.proxy.autoconfig_url: "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*'))%20%7B%20return%20'PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF - prefs.js..network.proxy.type: 2
FF - prefs.js..services.sync.prefs.sync.browser.search.selectedEngine: true
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\Sony\MSS\3.8.130\npMcAfeeMss.dll File not found
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL File not found
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@raidcall.en/RCplugin: C:\Users\XXX YYY\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\XXX YYY\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\LWAPlugin15.8: C:\Users\XXX YYY\AppData\Roaming\Mozilla\Plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 31.4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 31.4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
 
[2013.03.20 12:29:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\Extensions
[2013.03.19 02:15:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2015.02.10 17:26:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\Firefox\Profiles\gwlew6n9.default\extensions
[2015.02.03 10:47:08 | 000,000,000 | ---D | M] (Avira Browser Safety) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\Firefox\Profiles\gwlew6n9.default\extensions\abs@avira.com
[2013.03.20 12:33:34 | 000,000,000 | ---D | M] (Password Bank) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\Firefox\Profiles\gwlew6n9.default\extensions\passwordbank@upek.com
[2013.03.20 11:28:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\Firefox\Profiles\rsv63erq.default\extensions
[2014.10.28 17:08:14 | 001,443,602 | ---- | M] () (No name found) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\firefox\profiles\gwlew6n9.default\extensions\firefox@ghostery.com.xpi
[2014.07.06 13:36:20 | 000,394,918 | ---- | M] () (No name found) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\firefox\profiles\gwlew6n9.default\extensions\firegestures@xuldev.org.xpi
[2015.02.10 17:26:58 | 000,174,448 | ---- | M] () (No name found) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\firefox\profiles\gwlew6n9.default\extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi
[2015.02.10 17:26:59 | 002,178,746 | ---- | M] () (No name found) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\firefox\profiles\gwlew6n9.default\extensions\jid1-T5mdAATMX3urKA@jetpack.xpi
[2013.06.20 17:13:34 | 000,178,105 | ---- | M] () (No name found) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\firefox\profiles\gwlew6n9.default\extensions\rapportive@rapportive.com.xpi
[2013.03.19 02:16:06 | 000,008,001 | ---- | M] () (No name found) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\firefox\profiles\gwlew6n9.default\extensions\tineye@ideeinc.com.xpi
[2015.02.09 12:15:39 | 000,086,749 | ---- | M] () (No name found) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\firefox\profiles\gwlew6n9.default\extensions\toolbar@alexa.com.xpi
[2013.03.19 02:16:06 | 000,077,793 | ---- | M] () (No name found) -- C:\Users\XXX YYY\AppData\Roaming\mozilla\firefox\profiles\gwlew6n9.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}.xpi
[2013.03.19 02:16:10 | 000,002,103 | ---- | M] () -- C:\Users\XXX YYY\AppData\Roaming\mozilla\firefox\profiles\gwlew6n9.default\searchplugins\translate-korean-to-english.xml
[2015.02.05 17:17:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2015.01.29 14:05:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2015.01.29 14:05:27 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2015.01.29 14:05:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\distribution\extensions
[2015.01.29 14:05:19 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped\6.6_0\
CHR - Extension: No name found = C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk\1.4.4_0\
CHR - Extension: No name found = C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpglbgbpeobllokpmeagpoagjbfknanl\1.0.0.9_0\
CHR - Extension: No name found = C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
 
O1 HOSTS File: ([2015.02.09 21:10:00 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (no name) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No CLSID value found.
O2:64bit: - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found.
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\urlredir.dll (Microsoft Corporation)
O2:64bit: - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office 15\root\office15\urlredir.dll (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PSQLLauncher] C:\Program Files\Protector Suite\launcher.exe (UPEK Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [AgentMonitor] C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [MarketingTools] C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe (Sony Corporation)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [Razer Synapse] C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.)
O4 - HKCU..\Run: [GoogleChromeAutoLaunch_550EDA027B4B11347618D98EDCBB3ADF] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [SkyDrive] C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk = C:\Program Files (x86)\FastStone Capture\FSCapture.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnie.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnie.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation)
O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - c:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - c:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.10
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{151AB8A6-ED2A-4662-A219-5E83E7F62040}: DhcpNameServer = 192.168.0.10
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{876E33B5-EE1E-4322-8F79-79EB6087A1E2}: NameServer = 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AA2DF348-6AB3-482F-A8BC-41E89158A468}: DhcpNameServer = 10.74.210.210 10.74.210.211
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AA2DF348-6AB3-482F-A8BC-41E89158A468}: NameServer = 10.74.210.210 10.74.210.211
O18:64bit: - Protocol\Handler\dssrequest - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\osf - No CLSID value found
O18:64bit: - Protocol\Handler\sacore - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest - No CLSID value found
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Programme\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-mfe-ipt - No CLSID value found
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\psfus: DllName - (C:\Program Files\Protector Suite\psqlpwd.dll) - C:\Programme\Protector Suite\psqlpwd.dll (UPEK Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2015.02.12 10:56:41 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\XXX YYY\Desktop\OTL.exe
[2015.02.11 15:25:14 | 000,000,000 | ---D | C] -- C:\Users\XXX YYY\Desktop\FRST-OlderVersion
[2015.02.11 15:24:20 | 002,134,016 | ---- | C] (Farbar) -- C:\Users\XXX YYY\Desktop\FRST64.exe
[2015.02.09 21:12:24 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2015.02.09 20:56:17 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2015.02.09 20:56:17 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2015.02.09 20:56:17 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2015.02.09 20:56:10 | 000,000,000 | ---D | C] -- C:\Qoobox
[2015.02.09 20:56:00 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2015.02.09 20:54:56 | 005,611,930 | R--- | C] (Swearware) -- C:\Users\XXX YYY\Desktop\ComboFix.exe
[2015.02.09 18:04:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2015.02.09 18:03:25 | 000,000,000 | ---D | C] -- C:\Users\XXX YYY\Desktop\mbar
[2015.02.09 17:59:00 | 000,000,000 | ---D | C] -- C:\ProgramData\OnlineUpdate
[2015.02.09 17:59:00 | 000,000,000 | ---D | C] -- C:\ProgramData\log
[2015.02.09 12:00:25 | 000,000,000 | ---D | C] -- C:\FRST
[2015.02.09 09:37:50 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2015.02.05 17:20:32 | 000,000,000 | ---D | C] -- C:\Users\XXX YYY\Documents\Dungeon of the Endless
[2015.02.05 16:56:36 | 000,136,408 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015.02.05 16:56:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2015.02.05 16:56:00 | 000,097,496 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2015.02.05 16:56:00 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2015.02.05 16:56:00 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2015.02.05 16:56:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2015.02.05 16:56:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2015.02.04 15:20:33 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe
[2015.02.04 15:20:29 | 005,553,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2015.02.04 15:20:29 | 003,971,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2015.02.04 15:20:28 | 003,916,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2015.02.04 15:20:28 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2015.02.04 15:20:28 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2015.02.04 15:20:28 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2015.02.04 15:20:25 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncsi.dll
[2015.02.04 15:20:14 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2015.02.04 15:20:14 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2015.01.29 14:05:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2015.01.24 16:42:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Steam
[2015.01.23 16:45:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech
[2015.01.23 16:45:32 | 000,000,000 | ---D | C] -- C:\ProgramData\VTech
[2015.01.23 16:45:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VTech
[2015.01.21 15:56:50 | 000,000,000 | ---D | C] -- C:\Users\XXX YYY\AppData\Roaming\webex
[2015.01.21 15:56:23 | 000,000,000 | ---D | C] -- C:\ProgramData\WebEx
[2015.01.21 15:56:20 | 000,000,000 | ---D | C] -- C:\Users\XXX YYY\AppData\Local\WebEx
[2015.01.19 15:12:51 | 000,000,000 | ---D | C] -- C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome-Apps
[2015.01.19 15:12:47 | 000,000,000 | ---D | C] -- C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2015.01.19 14:58:04 | 000,000,000 | ---D | C] -- C:\Users\XXX YYY\Documents\Google USB driver
[2015.01.19 13:39:09 | 000,110,336 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudbus.sys
[2015.01.19 13:24:02 | 000,000,000 | ---D | C] -- C:\Program Files\SAMSUNG
[2015.01.19 13:22:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung
[2015.01.19 13:21:07 | 000,000,000 | ---D | C] -- C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ClockworkMod
[2015.01.19 13:21:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ClockworkMod
[2015.01.17 18:47:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2015.01.15 15:37:41 | 000,000,000 | ---D | C] -- C:\Windows\de
[2015.01.15 15:37:28 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2015.01.15 15:36:09 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll
[2007.08.13 16:46:00 | 000,102,912 | ---- | C] (Albert L Faber) -- C:\Users\XXX YYY\AppData\Local\CDRip.dll
[2007.01.18 20:09:54 | 000,623,616 | ---- | C] (Ivan Bischof ©2003 - 2005) -- C:\Users\XXX YYY\AppData\Local\No23 Recorder.exe
[2006.12.11 18:13:14 | 000,013,872 | ---- | C] (Un4seen Developments) -- C:\Users\XXX YYY\AppData\Local\basscd.dll
[2006.12.11 18:13:12 | 000,097,336 | ---- | C] (Un4seen Developments) -- C:\Users\XXX YYY\AppData\Local\bass.dll
[2 C:\*.tmp files -> C:\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2015.02.12 10:57:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\XXX YYY\Desktop\OTL.exe
[2015.02.12 10:53:43 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015.02.12 10:52:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015.02.12 10:52:38 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015.02.11 16:13:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015.02.11 16:04:49 | 002,134,016 | ---- | M] (Farbar) -- C:\Users\XXX YYY\Desktop\FRST64.exe
[2015.02.11 15:35:00 | 000,021,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015.02.11 15:35:00 | 000,021,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015.02.11 15:33:36 | 001,629,436 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2015.02.11 15:33:36 | 000,703,214 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2015.02.11 15:33:36 | 000,657,406 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2015.02.11 15:33:36 | 000,150,822 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2015.02.11 15:33:36 | 000,123,218 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2015.02.11 15:27:14 | 2961,563,648 | -HS- | M] () -- C:\hiberfil.sys
[2015.02.11 15:18:05 | 000,852,594 | ---- | M] () -- C:\Users\XXX YYY\Desktop\SecurityCheck.exe
[2015.02.09 21:10:00 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2015.02.09 20:55:00 | 005,611,930 | R--- | M] (Swearware) -- C:\Users\XXX YYY\Desktop\ComboFix.exe
[2015.02.09 18:04:32 | 000,136,408 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015.02.09 18:03:28 | 000,097,496 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2015.02.09 11:58:11 | 000,000,000 | ---- | M] () -- C:\Users\XXX YYY\defogger_reenable
[2015.02.05 16:28:09 | 000,701,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2015.02.05 16:28:09 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2015.02.04 15:41:38 | 000,446,136 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2015.01.23 16:45:52 | 000,001,169 | ---- | M] () -- C:\Users\Public\Desktop\VTech Download Manager.lnk
[2015.01.21 15:32:54 | 000,103,435 | ---- | M] () -- C:\Users\XXX YYY\Documents\zustimmung_uste2012-signed.pdf
[2015.01.21 15:32:16 | 000,102,722 | ---- | M] () -- C:\Users\XXX YYY\Documents\zustimmung_este2012-signed.pdf
[2015.01.20 14:18:41 | 000,368,519 | ---- | M] () -- C:\Users\XXX YYY\Documents\379827381 Geschäftskonto von 2012.pdf
[2015.01.20 14:18:12 | 001,687,247 | ---- | M] () -- C:\Users\XXX YYY\Documents\7150717 von 2012.pdf
[2015.01.19 15:12:47 | 000,002,263 | ---- | M] () -- C:\Users\XXX YYY\Desktop\Chrome App Launcher.lnk
[2 C:\*.tmp files -> C:\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2015.02.11 15:18:02 | 000,852,594 | ---- | C] () -- C:\Users\XXX YYY\Desktop\SecurityCheck.exe
[2015.02.09 20:56:17 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2015.02.09 20:56:17 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2015.02.09 20:56:17 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2015.02.09 20:56:17 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2015.02.09 20:56:17 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2015.02.09 11:58:11 | 000,000,000 | ---- | C] () -- C:\Users\XXX YYY\defogger_reenable
[2015.01.23 16:45:52 | 000,001,169 | ---- | C] () -- C:\Users\Public\Desktop\VTech Download Manager.lnk
[2015.01.21 15:32:54 | 000,103,435 | ---- | C] () -- C:\Users\XXX YYY\Documents\zustimmung_uste2012-signed.pdf
[2015.01.21 15:32:16 | 000,102,722 | ---- | C] () -- C:\Users\XXX YYY\Documents\zustimmung_este2012-signed.pdf
[2015.01.20 14:18:41 | 000,368,519 | ---- | C] () -- C:\Users\XXX YYY\Documents\379827381 Geschäftskonto von 2012.pdf
[2015.01.20 14:18:12 | 001,687,247 | ---- | C] () -- C:\Users\XXX YYY\Documents\7150717 von 2012.pdf
[2015.01.19 15:12:47 | 000,002,263 | ---- | C] () -- C:\Users\XXX YYY\Desktop\Chrome App Launcher.lnk
[2015.01.15 15:37:25 | 000,001,265 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
[2014.04.05 12:13:59 | 000,000,017 | ---- | C] () -- C:\Users\XXX YYY\AppData\Local\resmon.resmoncfg
[2014.01.07 17:28:04 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2013.09.13 13:59:12 | 000,001,509 | ---- | C] () -- C:\Users\XXX YYY\AppData\Local\RecConfig.xml
[2013.06.18 09:01:33 | 000,000,870 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2013.06.06 12:42:26 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2013.04.23 09:18:09 | 000,074,703 | ---- | C] () -- C:\Windows\SysWow64\mfc45.dll
[2013.03.25 14:28:50 | 000,000,032 | ---- | C] () -- C:\Users\XXX YYY\.simfy
[2013.03.25 12:25:49 | 001,603,716 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.03.20 12:05:56 | 000,000,000 | ---- | C] () -- C:\Users\XXX YYY\AppData\Local\{E0B5EB61-5E6A-4483-A017-B5D5359A35B3}
[2013.03.20 12:05:56 | 000,000,000 | ---- | C] () -- C:\Users\XXX YYY\AppData\Local\{8163A258-9D27-40E7-8400-AAC988DB596D}
[2010.05.17 14:20:06 | 000,157,382 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
 
========== ZeroAccess Check ==========
 
[2013.03.19 02:13:42 | 000,000,000 | ---D | M] -- C:\Users\XXX YYY\AppData\Local\{4fa287a5-a9e8-a902-8c66-f7e1d24caa8e}\L
[2013.03.19 02:13:42 | 000,000,000 | ---D | M] -- C:\Users\XXX YYY\AppData\Local\{4fa287a5-a9e8-a902-8c66-f7e1d24caa8e}\U
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014.06.25 03:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014.06.25 02:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== Files - Unicode (All) ==========
[2013.10.22 07:50:35 | 102,303,549 | ---- | M] ()(C:\Windows\SysWow64\???D) -- C:\Windows\SysWow64\ႢअD
[2013.10.21 21:57:42 | 102,303,549 | ---- | C] ()(C:\Windows\SysWow64\???D) -- C:\Windows\SysWow64\ႢअD
[2013.09.26 08:48:15 | 097,892,804 | ---- | M] ()(C:\Windows\SysWow64\????) -- C:\Windows\SysWow64\ꅤꋼˆ
[2013.09.26 08:48:15 | 097,892,804 | ---- | C] ()(C:\Windows\SysWow64\????) -- C:\Windows\SysWow64\ꅤꋼˆ
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:7C784982

< End of report >


LarryPerkins 12.02.2015 11:28

Code:

OTL Extras logfile created on: 12.02.2015 10:59:08 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\XXX YYY\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,68 Gb Total Physical Memory | 0,85 Gb Available Physical Memory | 23,00% Memory free
7,35 Gb Paging File | 3,89 Gb Available in Paging File | 52,85% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 111,17 Gb Total Space | 12,80 Gb Free Space | 11,51% Space Free | Partition Type: NTFS
 
Computer Name: XXXYYY-VAIO | User Name: XXX YYY | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{063A3779-2A95-4225-A532-70711CA6746D}" = lport=10243 | protocol=6 | dir=in | app=system |
"{0BCBA248-8D90-4A04-81F7-2811E2E8D271}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{16E195E0-1B6C-413F-8E52-3D46E19F4FDD}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{203CE65A-898F-4C46-97CA-44EF06ED06E7}" = lport=12972 | protocol=6 | dir=in | name=audials localhttpserver 12972 |
"{21AC4557-8664-43E6-A09E-39A3D485195C}" = lport=138 | protocol=17 | dir=in | app=system |
"{2A337B81-23B2-401F-972B-D79EFEA3463C}" = lport=9997 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vaioshell.exe |
"{39B20583-D18B-4C05-8793-FA1EAA38B6ED}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{41E0D1EB-68B5-4E6A-B8E2-E6839D649B4B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{45D0967E-49DE-4524-AEBB-DC1BB1489683}" = lport=137 | protocol=17 | dir=in | app=system |
"{4B7ABFDA-1D2C-4EFE-A32C-13440ACF603F}" = lport=9996 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcsystemtray.exe |
"{4EF779D1-A8EC-48BD-9CD0-5383C3852C39}" = lport=139 | protocol=6 | dir=in | app=system |
"{50FE81F8-7C9A-40A1-BD9D-6CA92A0EA745}" = lport=31931 | protocol=6 | dir=in | name=audials localhttpserver 31931 |
"{511982EB-13C1-47A7-AFE6-3FBDAEFAB5DB}" = rport=138 | protocol=17 | dir=out | app=system |
"{580B05D9-F478-4154-9AB1-17600EE2363B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6DC34417-CEA5-4F34-84A3-13C7124D5071}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7376E49C-E0C2-411E-8477-15984B449014}" = rport=445 | protocol=6 | dir=out | app=system |
"{73E7AC66-3A06-4CF3-A8C2-086759F725A9}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{771FECFD-B8EF-4BAB-A6F7-F68B60AAD487}" = rport=139 | protocol=6 | dir=out | app=system |
"{77C251A7-DD4A-4008-9678-8616708F6D50}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{90F9E177-8F48-4641-9764-06D5F93D8031}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{92A2267C-6DB4-4303-B8A8-0DF5352A93B1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{974FBFBA-6423-49AD-A4E5-7BFB2D8F7EF6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A1F5A213-4EF1-4F37-B802-1A012AEC4F7C}" = lport=445 | protocol=6 | dir=in | app=system |
"{AE210627-49D0-40B3-B6BA-260946820D5D}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AEDF4E97-C394-4A4B-B830-931698D2A3FA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B4F6D652-D738-4EA9-A2BF-439F4FC0B406}" = lport=9998 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcadmin.exe |
"{B8A5C112-7A58-4350-B1FB-1F8012CC7D20}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{C1D64EE0-1624-48E8-8FEC-E89E3832B729}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C8D8AAC2-D961-40FB-85FD-533CC94E7523}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D329CFD5-35BA-47E0-983A-416E08CB603F}" = lport=14714 | protocol=6 | dir=in | name=audials localhttpserver 14714 |
"{D52601B5-E066-4E3B-BCE6-3D0B66E0B5F5}" = rport=137 | protocol=17 | dir=out | app=system |
"{D87391AF-22B0-40CD-B723-F469A3C2AD36}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{E0FDA7CC-FA10-407F-97CC-9CA1E101C181}" = lport=9999 | protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcagent.exe |
"{E4425786-8787-4022-B443-368FE10E40B1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{E6A92D03-B137-4C8E-82AE-A19BD821A481}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FA44A6B5-FC17-4E5A-BCAC-D8E06C3C0750}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{FBC2CAB8-7B65-40A3-8762-9AA1FADE8BE1}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\outlook.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02008C47-649D-4151-BE15-29FF78DBD1FC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\giana sisters twisted dreams\launcher\gslauncher.exe |
"{0224A574-4717-48D4-B5FD-BF2FCD9C5EF2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chainsawwarrior\cwsteampc.exe |
"{04F8793C-AF62-4B8C-8452-D13AB273535B}" = dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\devicesetup.exe |
"{07083557-CEF9-4515-AA61-217578126BA0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cinders\cinders.exe |
"{0A6D06E8-4909-438D-BC45-503BC49178EF}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe |
"{0BF70633-85F9-4C96-A9F6-E4AC583740B7}" = protocol=6 | dir=out | app=system |
"{0C16132A-2B4E-4ADA-A973-6947893ACF18}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sokobond\sokobond.exe |
"{0CE3D085-4BD3-4612-90E4-1AC31243942F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chainsawwarrior\cwsteampc.exe |
"{0E9B3FC2-7B98-4FBF-8CC9-258547E0D2E1}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\pdf professional 8\bin\gpdfdirect.exe |
"{0ED87E37-53C6-41EA-9DF1-383BDCD81C15}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gunpoint\gunpoint.exe |
"{10325DB3-E8DE-414A-9F11-510CCD3C3002}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2689\agent.exe |
"{114010BC-697E-453B-A3C0-4CC0BFF92A04}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\frozen synapse\frozensynapse.exe |
"{11AAFFFB-76A8-43BC-BB7C-A2FC97DD2928}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{1310E7E9-AC9A-4355-A0AF-9D6278BACBBC}" = protocol=6 | dir=in | app=c:\users\XXX YYY\appdata\roaming\processmaker-2_5_0\mysql\bin\mysqld.exe |
"{160EFD61-51F8-47A5-9911-6ABB7EF0A444}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mars war logs\marswarlogs.exe |
"{19BF4201-7638-41BF-BBF7-0ED1039FA25D}" = protocol=17 | dir=in | app=c:\users\XXX YYY\appdata\roaming\processmaker-2_5_0\apache\bin\httpd.exe |
"{1A2B8A77-C5BC-4ED7-9E30-D73E7E79986D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{1A7ADA1F-3EE6-4889-949F-D5A7DC934B3F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{1C7F41E3-E8A3-42C0-85F0-1C1086F474AD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\giana sisters twisted dreams\launcher\gslauncher.exe |
"{20028CC3-77EA-4E80-8D42-21468DB951BF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bejeweled 2 deluxe\winbej2.exe |
"{2147848A-E363-4D2A-87FC-0A44B68C638C}" = protocol=17 | dir=in | app=c:\users\XXX YYY\appdata\roaming\processmaker-2_5_0\mysql\bin\mysqld.exe |
"{224F2E49-9050-4D82-B08D-3CC48B847300}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2328\agent.exe |
"{229B80CC-B97D-4F71-912E-9D019F140E0B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe |
"{2455EE32-CF35-44D1-8593-B72FD53D51B7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe |
"{269D2C47-496C-48D2-9C2B-18461296BE7E}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{26CDA42C-A90C-4B9C-B047-49981B910D87}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\insaniquarium deluxe\insaniquarium.exe |
"{289A7D37-4A91-4445-B0B3-CF0C391C15CD}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3147\agent.exe |
"{291094B8-7CF8-4FBC-A4B5-8940A9C611DB}" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe |
"{295490EF-2FF1-4074-B6B7-D516CE36BF86}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{2A0C8770-DD61-4CAD-B537-305DF3B1D1C5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe |
"{2ACA3EE9-31A3-4FFF-9714-FFD1226967BF}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3507\agent.exe |
"{2B2A4120-7DFA-4BAF-AB6C-297167C4530D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\uplink\uplink.exe |
"{2CC6D04D-3935-4D65-90B5-AE63BFF4BB52}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe |
"{2CDCCD0D-04C4-4ADE-827B-B4FCBA09B2D7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2689\agent.exe |
"{320388BF-A223-46F1-9514-78BBC2B95233}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe |
"{32096324-DB3C-47DD-8499-BBBEFFDAABBA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chainsawwarrior\cwsteam.exe |
"{32950067-100A-4FCF-84F5-8D628F41B822}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\pdf professional 8\bin\gaaihodoc.exe |
"{338B56DE-6DF1-4B34-830C-AEFEC1EADC39}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2293\agent.exe |
"{37534F4C-33EC-4B82-9CBC-6C9C573FFCF8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deathskidmarks\deathskidmarks.exe |
"{39F615DE-1A28-4A1F-AD4A-E6A00F392B6C}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe |
"{3A315B74-B76B-480B-92A6-B4A43F67B5B9}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe |
"{3BB2BF63-CD42-41F2-8867-C40FA0E7E5A9}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2293\agent.exe |
"{3CD0D160-B8FF-40F0-9F87-CF048FAEF1D7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3147\agent.exe |
"{3ED2E9D0-3D9A-4074-9A89-B13B18ED10FA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\monster loves you!\monsterlovesyou.exe |
"{401486E7-905F-4E32-BEE4-1E18BDAE6565}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{411D4B47-9890-4F70-A5EB-5B39C429CDD1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead mans draw\deadmansdraw.exe |
"{4445547F-BA73-4C9B-8DCA-2ED4E72B1A35}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\psyhigh\psyhigh.exe |
"{478FA93C-EDAD-49C4-8A7F-3852287C8D00}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2328\agent.exe |
"{48FA7DF2-7871-42C7-A03F-D05D5A811C26}" = dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicatorcom.exe |
"{497538E6-1305-4EE5-AB2D-50AA4DB8C4D6}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2787\agent.exe |
"{49D1877B-905F-47CB-BB5A-B4F45427AA73}" = protocol=6 | dir=in | app=c:\users\XXX YYY\appdata\roaming\processmaker-2_5_0\apache\bin\httpd.exe |
"{49EFD2C9-C4AA-4C20-B9AF-C75A17A9C162}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4A3CCADF-3F07-4885-BCB1-16FD19D3A42B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{4A8A2AA4-10E7-4CCD-9141-87A54462DE92}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{4A9B0620-A229-4E8B-AB10-F2E5478F6F98}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darkestdungeon\_windows\darkest.exe |
"{4D2EAE32-63CA-4489-AA93-65478A7FB1C7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4D8DF0A5-FDF4-4ECC-BBF1-5D19FBA7DF89}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3182\agent.exe |
"{4F465210-4E0D-44FD-A944-F24E84B7F06B}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe |
"{5175858A-6BC5-45ED-9C8A-79643F24E959}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe |
"{533C2862-1013-474F-B493-98D85B0C49A6}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe |
"{57BDA756-2DB9-4E9D-87F0-596C9D0DD9AB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\solforge\solforge.exe |
"{58839502-EBCA-4B3D-A691-2206D4BB4F05}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darkestdungeon\_windows\darkest.exe |
"{58FA5AB6-48A4-49E3-878B-9C5985330E80}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\solforge\solforge.exe |
"{5928E315-08E5-43F2-B55D-00365490E7FF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\papersplease\papersplease.exe |
"{59309D35-D85F-447D-B0DA-E3493F81ED8B}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\pdf professional 8\pdfrouter.exe |
"{5A0DD736-797B-4B5E-B322-91F4F89004FB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\7 grand steps 01\7 grand steps.exe |
"{5A1FEC78-AA3A-4283-907C-F3BC7B0CDF6F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe |
"{5AB883A1-96DE-4C71-B0B0-49D7D3CB18ED}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5B236954-6935-41A6-84CC-4F5CB6621064}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe |
"{5B27FCE7-ECBC-4CE5-9DA2-047E5D6F01E9}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2689\agent.exe |
"{5B558A15-953C-493B-BBEA-7DDBFE424F5A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2006\agent.exe |
"{5EE5D99C-3D59-409B-9509-6FF497D86267}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe |
"{630248D2-E4E0-4421-A202-26B1A7699489}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe |
"{64C5A639-5D4F-4D26-81F3-0A4EB19F3D89}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3507\agent.exe |
"{65A08817-4103-4D3C-8311-71DAE0CF213B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ftl faster than light\ftlgame.exe |
"{67D23936-1A77-4C36-9DBB-B46F6B7D7C05}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bejeweled 2 deluxe\winbej2.exe |
"{688A2778-AFB4-4A6A-BCB9-5AAE76DEF090}" = protocol=6 | dir=in | app=c:\users\XXX YYY\appdata\roaming\dropbox\bin\dropbox.exe |
"{696456D4-0D9F-487B-A0E8-3A23836C3178}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{69F0C99F-D208-4400-93E6-D5C6871A8E7A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{6A5DD0A5-EB80-4C60-AB5B-0A347BD05F3D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2689\agent.exe |
"{6A6107D1-364A-4DF9-BFF9-27838231BEA5}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\pdf professional 8\bin\gpdfdirect.exe |
"{6C82EC69-9BB7-45FE-823C-D0A693389C5A}" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"{6D7836A3-CA5E-4C34-B7C6-3E3E2DF084D5}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{6D864A8F-0CAF-4B16-8A67-34DB655B658A}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{6DCEB033-F3C0-4E46-867F-CC5DCA36D0F9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\choiceofthedeathless\choiceofthedeathless.exe |
"{6DE989A7-7ADD-4776-84EB-FA933DC78F15}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7151DC97-90B9-4F85-8CA2-EB1EA01BD444}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\papersplease\papersplease.exe |
"{7265972C-A4C8-4C6E-8CF2-E0D11D3FBC79}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gunpoint\gunpoint.exe |
"{7295C924-92C2-4A8B-9AA6-B2DE8D4A3AF7}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{72B7A49E-3AFE-4608-958F-D2488DC899CE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\insaniquarium deluxe\insaniquarium.exe |
"{736DA503-3391-4C5E-A7D6-86E1FADA14C9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\kentuckyroutezero\kentuckyroutezero.exe |
"{776A0C4E-2607-47E3-AF18-0B0DCEB470C5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\world of goo\worldofgoo.exe |
"{777A6642-8DB9-49C0-949D-1546CC03DFF0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ftl faster than light\ftlgame.exe |
"{77A8D97B-8193-4648-9D2E-ABCC60564B02}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2514\agent.exe |
"{788DCA7D-C401-4E0D-B17A-B0B7222D4503}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe |
"{7A6D00BA-872C-4D1D-BB63-DD29252F2086}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{7C651631-F54E-4DDF-BB36-AAFD5CACC604}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{7D778E56-1FDA-4712-9C91-0923E016A783}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotline_miami\hotlinemiami.exe |
"{7DE4CDA4-6558-4ADC-81DB-44419076A2C2}" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe |
"{7F93FF39-CC7A-4744-9740-60A53B3397D4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thebridge\the bridge.exe |
"{806D5682-328F-4189-B5B4-CF2A8087944C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{82ACF05B-F714-4A44-A601-1827240DB4C5}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{85493BBA-85F2-4076-84F3-71D2A0267304}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{89C8AB0E-54D4-4C73-AE63-EEB2C5B847AA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe |
"{89D1AA9A-2973-4B7C-BA55-B307469244CD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzle quest\puzzle quest.exe |
"{8B4B5CCA-3251-49F4-9C48-6D9227C0BEA1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thievesgambitcurseoftheblackcat\thievesgambitcurseoftheblackcat.exe |
"{8C3C68C8-22D2-467A-A3FB-8D4F055328C8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe |
"{8CC1C7F7-16B0-4752-B7FA-3C653B5E6195}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe |
"{8D665BB6-FC39-4290-80FD-AFC24A3F3C09}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3182\agent.exe |
"{8DA63AC2-E9D3-44DF-A0AB-FBE6FD35A79B}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2680\agent.exe |
"{8E17DCE8-4394-4FF8-A3A0-22A0F1B463C2}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2680\agent.exe |
"{9072C1F6-F110-4523-867B-7F0299B4D0C2}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{913506BF-061F-496E-863A-F00F64B474FD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\pixel piracy\pixelpiracy.exe |
"{968F7C19-4F50-46C2-8AA8-257A5F1F13AC}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\pdf professional 8\pdfrouter.exe |
"{9757B46A-F09C-43BD-A90C-DCC91AADD60B}" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"{977FA20B-58AF-4357-819D-1181F02CD1F3}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\pdf professional 8\pdfpro8hook.exe |
"{985F9F31-5913-4E91-A778-9D314D1F3188}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\valiant hearts\valiant hearts.exe |
"{994BEFE9-0A80-42FD-B7C1-6484172F7D38}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2880\agent.exe |
"{994E93E3-39A3-4004-A1D2-74C41AB85F67}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{9C69083C-0501-4873-A5F0-BD5F8CDBE73F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mars war logs\marswarlogs.exe |
"{9CCD6EB9-0019-468F-9D48-3F66EFC4669C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bad hotel\badhotel.exe |
"{9D877398-DB23-40FC-8A18-C3709CC919EA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chainsawwarrior\cwsteam.exe |
"{9EEC4112-1187-4651-8112-D9DAC637EC67}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzle quest\puzzle quest.exe |
"{9F93060D-385E-48F3-A430-301B3B1DD80A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\papersplease\papersplease.exe |
"{A06AA6FB-6BD9-4A90-9884-68F5C1241D98}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A18E1C9C-C369-4D33-962F-8149DC929237}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{A37D8CD3-0F82-4DAF-9B65-3118722B402E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A5BAB6BE-C710-4E59-9C3A-E2FA8B030EC0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chainsawwarrior\cwsteampc.exe |
"{A927A942-8B95-4204-B471-CC22F99E261B}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe |
"{A95A81E8-1B16-42CA-98D8-D4A30069E7F3}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2680\agent.exe |
"{AA98799D-0FE1-48B5-BA8B-F095D6B8F932}" = dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"{AB61A989-B108-4172-BDE6-1A53FBF0A0C3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thirty_flights_of_loving\tfol.exe |
"{ABE43271-C567-4B3B-AD91-05CA157FB254}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead mans draw\deadmansdraw.exe |
"{AC4810FD-A4CB-435F-AE7F-C70CE3A3FDEA}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3182\agent.exe |
"{ADCD9574-A3BB-41F4-A5C3-F15A39E37B13}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gods will be watching\gwbw.exe |
"{ADFE0088-E7A9-485F-BF0E-0A4E49D77EAC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3182\agent.exe |
"{AE2E2113-FC68-4121-B266-4B8C1BD7DFD8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{AFB873B0-98C9-4B50-ACEA-818C3915BBE8}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe |
"{AFB9F416-C22D-4AC1-9792-CC08E5A50C6B}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2006\agent.exe |
"{B1E9DC40-2AE6-410C-A7E4-472DA712CEA2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\kentuckyroutezero\kentuckyroutezero.exe |
"{B2B8CF8D-0D86-41FC-9EB6-6CAAD02E218F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3023\agent.exe |
"{B31B28DF-0DB7-419B-910C-5839657A0788}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thievesgambitcurseoftheblackcat\thievesgambitcurseoftheblackcat.exe |
"{B3F76875-4675-49BE-BF8B-7F8F1FE65C61}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{B43DFF8E-D85E-4FC3-BC1F-D86F533DAE6D}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe |
"{B6778EB7-E0FD-4430-A169-2E2E28A011A1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cinders\cinders.exe |
"{B87B5401-A081-4179-BC86-12F0E91B4879}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\pdf professional 8\bin\gaaihodoc.exe |
"{BA17F4DA-5B9D-4168-806F-429BC315E016}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BAF8A419-8FA4-426D-ABA5-43200D0D8E8F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{BB2E37E6-F95D-4ECD-B3A6-76B4B3103C93}" = protocol=17 | dir=in | app=c:\users\XXX YYY\appdata\roaming\dropbox\bin\dropbox.exe |
"{BBBBC9B9-DB6C-47F9-9B4F-0D90F22EAF7A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2514\agent.exe |
"{BE32B3AF-4089-49B2-94FD-A2C4FA8E8D74}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BE6CC741-50E4-4DA0-B92D-92D3B58F9CD5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe |
"{BF34B154-B45B-445F-8C5D-4583A9963FEF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gods will be watching\gwbw.exe |
"{BFE764E3-861F-441A-9A94-B7E9DEDAB0CD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\frozen synapse\frozensynapse.exe |
"{C0034611-D367-4541-BF8C-5837231C7E59}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\monster loves you!\monsterlovesyou.exe |
"{C175F619-7418-4344-95A4-FE74F735CBC9}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe |
"{C17CA9E8-B134-4B54-8A3D-CC0E69679E8A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3526\agent.exe |
"{C2130A43-640A-42E3-9120-7DB74A8CD1C0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe |
"{C2C75672-63A0-4433-84D1-55B2C9FC45D7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotline_miami\hotlinemiami.exe |
"{C53FE17B-7C00-4089-9614-9A22ABA04258}" = dir=in | app=c:\program files (x86)\audials\audials 10\audials.exe |
"{C648378E-BB72-4D0A-BFFB-B0BC6F2907AA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\valiant hearts\valiant hearts.exe |
"{C8A264EB-517C-46EC-B652-A4199CD67A34}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\pdf professional 8\pdfpro8hook.exe |
"{C8BCFE36-8939-4386-8439-57CD050480AC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3023\agent.exe |
"{C8C8F3F9-002C-4AE4-A041-6B40E58410AB}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{C8D4A43C-1E26-464C-B0FF-057054BECE4E}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{CA2675A9-0B2D-4136-954E-E0A473509FDE}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe |
"{CB7DF63E-8EFF-448A-B6BC-CD2D629B4284}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{CC2BCD2E-C9D4-41C9-B268-1AA62EE4C9C4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2787\agent.exe |
"{CE95BD6D-16AC-4063-BF8C-09C89DD0BBB6}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{D16605B5-0AFC-4C75-9DF7-23FA864E50DE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\choiceofthedeathless\choiceofthedeathless.exe |
"{D320729E-534F-42AA-A42A-E61AC051C436}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sokobond\sokobond.exe |
"{D4E11A18-2900-4404-9032-5FECEA775B25}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3507\agent.exe |
"{D50F3439-5402-4502-8290-EBE7563FB420}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\7 grand steps 01\7 grand steps.exe |
"{D5506D8C-AD9A-4601-8014-0030E5D4543D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{D641E5C4-1700-4C35-BB1A-306C3BAB5BC5}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{D8AAFEE6-1597-4AAC-AE4B-8588238131E4}" = dir=in | app=c:\users\XXX YYY\appdata\local\microsoft\skydrive\skydrive.exe |
"{D9036449-3238-4C51-A128-716A34737085}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\coj gunslinger\cojgunslinger.exe |
"{D9C1BF69-B35A-4B19-872D-3AF4682F2907}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\pixel piracy\pixelpiracy.exe |
"{DB51673B-05C4-4F7F-8B68-15E7B308025E}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{DBC55C1E-E0B6-41FA-A074-8DD35CF0D343}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chainsawwarrior\cwsteam1.2a.exe |
"{DBEB6B5F-A7D1-4644-AF01-05F013B63736}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DBF84447-E69D-4C8E-BDB6-7F9F9DE37932}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DDA7D390-04DC-4B8C-BDD3-A455938E44A7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\world of goo\worldofgoo.exe |
"{DDB9D844-7317-4E96-A1B8-78262BA403CE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thebridge\the bridge.exe |
"{DE69B345-949F-47D6-9382-300C1DFBDBC4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{E14058B7-CFB4-46AE-9AEE-CBE7D775628D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chainsawwarrior\cwsteampc.exe |
"{E145C576-F932-4B8A-9C27-CAD74796F655}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{E29A7063-5DD8-43A3-B887-C9B90AEE1E5E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\psyhigh\psyhigh.exe |
"{E37B7EF4-AFDE-4FA7-A366-09FAA452BB62}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\uplink\uplink.exe |
"{E3D8BC56-AA0C-4347-A7CE-AC4E65C8A409}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2328\agent.exe |
"{E4D643EF-8C39-4654-8CAA-F50F44804874}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\luftrausers\bin\luftrausers.exe |
"{E53539E5-3FF8-44AB-8E7F-42E5B36E889C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2328\agent.exe |
"{E7F3A7F5-EB92-4D96-9D0D-2B46A5ED5EF8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chainsawwarrior\cwsteam1.2a.exe |
"{E8639517-ACC3-435A-AEE1-B84F5B8D7C8A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E8FA622B-6490-42DB-A1F9-9F760961C37C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{ECA61226-C8EC-4F61-A478-37A2A92D448F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2880\agent.exe |
"{ECA77D72-5928-49EE-9418-9DC9AF3A9A46}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{F176D770-0F15-416C-BECF-0B74B9C5CF6C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chuzzle deluxe\chuzzle.exe |
"{F201D8BE-C56B-42B1-8EA4-8545C34B0B83}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thirty_flights_of_loving\tfol.exe |
"{F2218791-0F27-4224-9FB6-A69F23D2A97B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{F2F696B5-723B-497E-B9C9-F968660F2CC2}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2680\agent.exe |
"{F3C09EA6-CAD4-4C9D-A81E-698B455802C0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\coj gunslinger\cojgunslinger.exe |
"{F41BC041-62E3-43BE-8AFF-A48D2F6FD9FC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chuzzle deluxe\chuzzle.exe |
"{F4639785-E7C7-4BFD-9326-49A1C98D0541}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2293\agent.exe |
"{F5392D4E-B5EA-434B-B194-549A5DD5F28C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deathskidmarks\deathskidmarks.exe |
"{F659472E-5192-4F43-BA85-DD7B9D991F0E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\luftrausers\bin\luftrausers.exe |
"{F6F861EC-D738-45D3-9160-7DA21636A4E8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bad hotel\badhotel.exe |
"{F717BB1A-76E6-44DD-8371-68063E5FB41C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3526\agent.exe |
"{F88DDCBD-1C32-4CB6-BE97-8B755B0ADDC6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F8980643-C42C-4E19-AE8E-B013147CFB14}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{FA37396B-A15B-4CD8-8FD2-0D3D407E282F}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{FB250DF9-47FE-4F80-A217-028759EC197B}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2293\agent.exe |
"{FCD88F62-B7D6-4509-882F-C2B9A2DFB843}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\papersplease\papersplease.exe |
"{FF41C6E5-4AEF-4A9B-B054-69D24A07FA8D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3507\agent.exe |
"{FFD325A6-6E9C-4A4C-BB16-DB5BBDEA4C44}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"TCP Query User{41E2BC74-E6A8-458B-BF2D-77999F849E9C}C:\program files (x86)\starcraft ii\versions\base26490\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base26490\sc2.exe |
"TCP Query User{7306D5E0-4038-4711-ABC0-ED77928EECCC}C:\program files (x86)\starcraft ii\versions\base24944\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base24944\sc2.exe |
"TCP Query User{7D8A0A29-7A26-44C7-94F3-BB7B5F8B0702}C:\program files (x86)\starcraft ii\versions\base28667\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base28667\sc2.exe |
"TCP Query User{7E0A3558-D051-4C63-9B4D-5F1E25B12B9A}C:\users\XXX YYY\appdata\local\microsoft\lwaplugin\x86\15.8\lwaplugin.exe" = protocol=6 | dir=in | app=c:\users\XXX YYY\appdata\local\microsoft\lwaplugin\x86\15.8\lwaplugin.exe |
"TCP Query User{93DCFAB4-2EAB-406F-9BC4-1E54F4AD1E3B}C:\program files (x86)\hearthstone\hearthstone.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"TCP Query User{99019B52-1BB4-4FF3-AF89-C65658D03EC7}C:\program files (x86)\starcraft ii\versions\base26490\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base26490\sc2.exe |
"TCP Query User{9D26D9CD-E748-402A-BF1A-7AD11A06A15E}C:\users\XXX YYY\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\XXX YYY\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{A2D0B27B-1622-437D-B6FB-67F66E338FDC}C:\users\XXX YYY\appdata\local\temp\keygen.exe" = protocol=6 | dir=in | app=c:\users\XXX YYY\appdata\local\temp\keygen.exe |
"TCP Query User{B62A04FC-8BF7-488F-9389-76DE581F8ADD}C:\program files (x86)\starcraft ii\versions\base24944\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base24944\sc2.exe |
"TCP Query User{E1415188-21C3-4923-A617-04D237609E70}C:\program files (x86)\steam\steam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"TCP Query User{F250CFED-67B1-4329-A096-F2D45A06EF99}C:\program files (x86)\starcraft ii\versions\base28667\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base28667\sc2.exe |
"UDP Query User{0C4BE49E-9563-4FBD-AD7A-67106C6EF1BC}C:\program files (x86)\starcraft ii\versions\base24944\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base24944\sc2.exe |
"UDP Query User{16847C87-2931-4C2D-868D-EB9E4D56B3C4}C:\program files (x86)\starcraft ii\versions\base28667\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base28667\sc2.exe |
"UDP Query User{2A81068D-663F-446A-8047-8B0A42A50B1E}C:\users\XXX YYY\appdata\local\microsoft\lwaplugin\x86\15.8\lwaplugin.exe" = protocol=17 | dir=in | app=c:\users\XXX YYY\appdata\local\microsoft\lwaplugin\x86\15.8\lwaplugin.exe |
"UDP Query User{3B3C3F1A-1775-4224-80FE-313EDD3F3786}C:\program files (x86)\hearthstone\hearthstone.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"UDP Query User{6712700A-2688-45C0-BF78-E6CF784ABCF1}C:\users\XXX YYY\appdata\local\temp\keygen.exe" = protocol=17 | dir=in | app=c:\users\XXX YYY\appdata\local\temp\keygen.exe |
"UDP Query User{67B25918-80FE-428A-82A9-C6EE51ECE401}C:\users\XXX YYY\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\XXX YYY\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{79C0A985-B13D-42BC-9EB9-AB02983F41D2}C:\program files (x86)\steam\steam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"UDP Query User{9E18685F-B363-4A46-BBA9-9B3487290BD1}C:\program files (x86)\starcraft ii\versions\base28667\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base28667\sc2.exe |
"UDP Query User{A044C5B5-CE76-456F-BF94-4649B01F5D8E}C:\program files (x86)\starcraft ii\versions\base26490\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base26490\sc2.exe |
"UDP Query User{BD264D43-C7D1-4611-BD8D-908D0B0F683A}C:\program files (x86)\starcraft ii\versions\base26490\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base26490\sc2.exe |
"UDP Query User{E8F34B47-07BF-4E88-A684-FDE9BF790B96}C:\program files (x86)\starcraft ii\versions\base24944\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base24944\sc2.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0F841121-4DB6-4B31-839F-7F5AB3BB3423}" = Protector Suite 2009
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{25058321-C33E-496B-8915-6FD64D362CAF}" = Windows Live MIME IFilter
"{26A24AE4-039D-4CA4-87B4-2F86417045FF}" = Java 7 Update 45 (64-bit)
"{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610
"{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = WIDCOMM Bluetooth Software
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6619085B-A9D5-4DDD-800B-964903EAF546}" = Microsoft Lync Web App Plug-in
"{6B7DE186-374B-4873-AEC1-7464DA337DD6}" = VU5x64
"{6ED1750E-F44F-4635-8F0D-B76B9262B7FB}" = VAIO Care Recovery
"{72EF03F5-0507-4861-9A44-D99FD4C41418}" = Paint.NET v3.5.11
"{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{90150000-008F-0000-1000-0000000FF1CE}" = Office 15 Click-to-Run Licensing Component
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031" = Microsoft .NET Framework 4.5.1 (Deutsch)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.GuardService" = NVIDIA Guard Service 1.3
"{C513739C-5F16-37B5-9ACF-99925FF1C1F3}" = Microsoft .NET Framework 4.5.1 (DEU)
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D16A2127-B927-4379-B153-3DEC091E4EEB}" = Intel(R) PROSet/Wireless WiFi-Software
"{D9FFE40D-1A85-4541-992C-5EF505F391A4}" = VAIO Care
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{EF3293DE-FCAC-4742-91BF-AD0174143FC3}" = HP Deskjet 3050 J610 series - Grundlegende Software für das Gerät
"{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64
"Canon UFR II Printer Driver" = Deinst. f. Druckertreiber UFR II
"NVIDIA Drivers" = NVIDIA Drivers
"O365HomePremRetail - de-de" = Microsoft Office 365 - de-de
"ProInst" = Intel PROSet Wireless
"Recuva" = Recuva
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"TOP" = TOP
"WinRAR archiver" = WinRAR 5.01 beta 1 (64-bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}" = Windows Live UX Platform
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04BE4035-3C8E-4B48-BFB8-1655849C0C8B}" = Windows Live Writer
"{07AAB66E-4718-422D-9218-4AFB3C922A71}" = Photo Gallery
"{0899D75A-C2FC-42EA-A702-5B9A5F24EAD5}" = VAIO Smart Network
"{0BE9E708-5DC0-4963-9CFD-0AA519090E79}" = Junk Mail filter update
"{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}" = Razer Synapse
"{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}" = Windows Live Photo Common
"{1DB91A95-C548-4BA5-9D4C-18C7DEAAC39F}_is1" = Wondershare Dr.Fone for Android(Build 4.8.1.136)
"{1F4E59C0-EE31-47EE-BCC3-1A73C3F023BF}" = Qualcomm Gobi 2000 Package for Sony
"{22B0E143-2B0B-435B-9F56-136A3D16065F}" = No23 Recorder
"{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 7.0
"{2F9D63BE-A891-4E39-AFB3-7402D486800C}" = VAIO Hardware Diagnostics
"{30827CFE-8B67-9DF9-580F-78BAA616E50E}" = simfy
"{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}" = QuickTime 7
"{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{41BF4A3B-D60A-4E92-883F-C88C8C157261}" = Fotogalerie
"{41C61308-6CFD-4D54-AB6A-7136ED08A18E}" = Windows Live Communications Platform
"{462A1E00-58EA-4D63-96F4-3EFAEC9A5BCA}" = Avira
"{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}" = VAIO-Support für Übertragungen
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{636E94DA-99C0-448F-A931-3DAD83B4975F}" = SharpKeys
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{659CB81C-B54E-4DF1-B618-F35777393A54}" = Windows Live Installer
"{66233218-CA57-4AB2-BA43-A97AA4635960}" = Windows Live Essentials
"{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}" = Vodafone Mobile Broadband
"{6D320CE8-79EB-4D45-8C6D-DEF74D84B49A}" =
"{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}" = HP Update
"{70991E0A-1108-437E-BA7D-085702C670C0}" =
"{70C91B91-61E8-4D06-86D6-A9DCC291983A}" = Movie Maker
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{714E162E-CD4F-4F1B-8302-7F5179409C25}" = Windows Live Writer
"{72042FA6-5609-489F-A8EA-3C2DD650F667}" = VAIO Control Center
"{77D28FF5-242F-488A-8215-937D6A4D69E0}" = Adobe AIR
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{803E4FA5-A940-4420-B89D-A8BC2E160247}" =
"{8211C280-5B02-4E7E-B55F-845A207249BA}" = VAIO Data Restore Tool
"{82F09B1C-F602-4552-9C40-5BD5F8EAF750}" =
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{855DDD3C-131E-42A8-BCBD-F9581F80CACB}" =
"{87DABDEA-47A4-4182-AA7C-2C90DAAE3117}" = Photo Common
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010
"{90150000-008C-0000-0000-0000000FF1CE}" = Office 15 Click-to-Run Extensibility Component
"{90150000-008C-0407-0000-0000000FF1CE}" = Office 15 Click-to-Run Localization Component
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{955E4722-1480-4198-A144-65FA5F4446DA}" = Windows Live Writer
"{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A781940-AC41-4D5E-8E1E-76A04B916FB9}" = Helium
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D12A8B5-9D41-4465-BF11-70719EB0CD02}" = VU5x86
"{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}" = VAIO Update
"{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
"{A7C30414-2382-4086-B0D6-01A88ABA21C3}" = VAIO Gate
"{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}" =
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A951D5DA-4759-4C3B-9C36-C6BF30082A2F}" = Windows Live Writer Resources
"{AC76BA86-0804-1033-1959-001802114130}" = Adobe Refresh Manager
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.10) - Deutsch
"{AC7E7905-8C59-4806-A96D-30936A2B1FC5}" = Citrix Online Launcher
"{B23EE11C-66FA-4395-AB02-5F7103DC485C}" = Windows Live Messenger
"{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}" = Windows Live PIMT Platform
"{B7546697-2A80-4256-A24B-1C33163F535B}" = VAIO Gate Default
"{B775C26B-EAA8-4A11-ACBF-76E52DF6B805}" = Windows Live Mail
"{bd538030-07d4-4999-a525-7fafa2483f56}" = Avira
"{C5711BC2-2E1C-4556-9922-02BF2865A5EE}" = iMindMap 6
"{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}" = VAIO-Handbuch
"{C7477742-DDB4-43E5-AC8D-0259E1E661B1}" =
"{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}" = Windows Live SOXE
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1893000-EA77-493C-8DDD-E262436E959B}" = Windows Live SOXE Definitions
"{D2D23D08-D10E-43D6-883C-78E0B2AC9CC6}" = VU5x86
"{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}" = Microsoft XNA Framework Redistributable 4.0 Refresh
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel(R) Turbo Boost Technology Driver
"{D928A4B7-126D-47B6-AD76-9848E51E1426}" = Audials
"{DB083AE1-3354-4AAD-BD44-5F2CC4B2ECE6}" = VTech Download Agent Library
"{DD67BE4B-7E62-4215-AFA3-F123A800A389}" = Movie Maker
"{DE8AAC73-6D8D-483E-96EA-CAEDDADB9079}" = ArcSoft WebCam Companion 3
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3723A04-A894-4036-A78E-282E18F43C0A}_is1" = Tinypic 3.18
"{E703613B-BDAB-433E-A66A-DE0263E3D35D}" = Windows Live Messenger
"{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F7232FE1-BC35-4229-8D76-D49941FE9929}" = Windows Live Mail
"{F761359C-9CED-45AE-9A51-9D6605CD55C4}" = Evernote
"{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}" = HP Deskjet 3050 J610 series Hilfe
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{FB77DB0C-6951-47B6-9D80-A0FDBEE0334C}" =
"{FC071B45-4A5F-408F-92F8-4D9D693E866F}" = Windows Live UX Platform Language Pack
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 16 ActiveX
"Adobe Flash Player NPAPI" = Adobe Flash Player 16 NPAPI
"Avira AntiVir Desktop" = Avira Free Antivirus
"Battle.net" = Battle.net
"DED9B6BE-2B04-4799-A88F-8BBF4D114AAF_is1" = TBBackup 2 (Freiversion)
"DivX Setup" = DivX-Setup
"FastStone Capture" = FastStone Capture 5.3
"Google Chrome" = Google Chrome
"Internet Manager" = Internet Manager
"julitecCRM_is1" = julitecCRM 7.5
"Long Live The Queen_is1" = Long Live The Queen (Demo) 1.0
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware Version 2.0.4.1028
"MarketingTools" = VAIO Marketing Tools
"Mozilla Firefox 35.0.1 (x86 de)" = Mozilla Firefox 35.0.1 (x86 de)
"Mozilla Thunderbird 31.4.0 (x86 de)" = Mozilla Thunderbird 31.4.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"OpenAL" = OpenAL
"RaidCall" = RaidCall
"Razer Core" = Razer Core
"Simfy" = simfy
"Steam App 12500" = Puzzle Quest
"Steam App 1510" = Uplink
"Steam App 204240" = The Bridge
"Steam App 212680" = FTL: Faster Than Light
"Steam App 214700" = Thirty Flights of Loving
"Steam App 219150" = Hotline Miami
"Steam App 22000" = World of Goo
"Steam App 226740" = Monster Loves You!
"Steam App 231200" = Kentucky Route Zero
"Steam App 231720" = Bad Hotel
"Steam App 233150" = LUFTRAUSERS
"Steam App 238930" = 7 Grand Steps, Step 1: What Ancients Begat
"Steam App 239030" = Papers, Please
"Steam App 251710" = Chainsaw Warrior
"Steam App 260230" = Valiant Hearts: The Great War™ / Soldats Inconnus : Mémoires de la Grande Guerre™
"Steam App 262060" = Darkest Dungeon
"Steam App 262450" = Dead Man's Draw
"Steam App 264140" = Pixel Piracy
"Steam App 274290" = Gods Will Be Watching
"Steam App 290260" = Sokobond
"Steam App 293680" = Cinders
"Steam App 318310" = Choice of the Deathless
"Steam App 326150" = Death Skid Marks
"Steam App 328550" = Thieves' Gambit: Curse of the Black Cat
"Steam App 3300" = Bejeweled 2 Deluxe
"Steam App 3310" = Chuzzle Deluxe
"Steam App 3320" = Insaniquarium! Deluxe
"Steam App 339510" = Psy High
"Steam App 3590" = Plants vs. Zombies: Game of the Year
"Steam App 98200" = Frozen Synapse
"TeamViewer 9" = TeamViewer 9
"TreeSize Free_is1" = TreeSize Free V2.7
"VAIO Help and Support" =
"VAIO screensaver" = VAIO screensaver
"VTechDownloadManager" = VTech Download Manager
"WinLiveSuite" = Windows Live Essentials
"XnView_is1" = XnView 2.22
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ActiveTouchMeetingClient" = Cisco WebEx Meetings
"Dropbox" = Dropbox
"GoXXXeeting" = GoXXXeeting 6.0.0.1259
"OneDriveSetup.exe" = Microsoft OneDrive
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 10.02.2015 11:05:02 | Computer Name = XXXYYY-VAIO | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: VCAgent.exe, Version: 8.4.2.12030,
 Zeitstempel: 0x5476d099  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0,
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000007fe927eaa71
ID
 des fehlerhaften Prozesses: 0xf90  Startzeit der fehlerhaften Anwendung: 0x01d044b37be3b110
Pfad
 der fehlerhaften Anwendung: C:\Program Files\Sony\VAIO Care\VCAgent.exe  Pfad des
 fehlerhaften Moduls: unknown  Berichtskennung: 2fbe96c6-b136-11e4-8008-0024bed7ff33
 
Error - 10.02.2015 11:13:52 | Computer Name = XXXYYY-VAIO | Source = VmbService | ID = 0
Description = GetProcessOwner
 
Error - 10.02.2015 13:05:14 | Computer Name = XXXYYY-VAIO | Source = .NET Runtime | ID = 1026
Description =
 
Error - 10.02.2015 13:05:15 | Computer Name = XXXYYY-VAIO | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: VCAgent.exe, Version: 8.4.2.12030,
 Zeitstempel: 0x5476d099  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0,
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000007fe942aaa71
ID
 des fehlerhaften Prozesses: 0xab0  Startzeit der fehlerhaften Anwendung: 0x01d04545f56955ba
Pfad
 der fehlerhaften Anwendung: C:\Program Files\Sony\VAIO Care\VCAgent.exe  Pfad des
 fehlerhaften Moduls: unknown  Berichtskennung: fb4c71f3-b146-11e4-8937-0024bed7ff33
 
Error - 11.02.2015 10:25:24 | Computer Name = XXXYYY-VAIO | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: plugin-container.exe, Version: 35.0.1.5500,
 Zeitstempel: 0x54c1f9f3  Name des fehlerhaften Moduls: mozalloc.dll, Version: 35.0.1.5500,
 Zeitstempel: 0x54c1f224  Ausnahmecode: 0x80000003  Fehleroffset: 0x00001425  ID des fehlerhaften
 Prozesses: 0x1794  Startzeit der fehlerhaften Anwendung: 0x01d045dd26db1aa4  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
Pfad
 des fehlerhaften Moduls: C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll  Berichtskennung:
 d0750001-b1f9-11e4-b649-0024bed7ff33
 
Error - 11.02.2015 10:26:41 | Computer Name = XXXYYY-VAIO | Source = .NET Runtime | ID = 1026
Description =
 
Error - 11.02.2015 10:26:41 | Computer Name = XXXYYY-VAIO | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: VCAgent.exe, Version: 8.4.2.12030,
 Zeitstempel: 0x5476d099  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0,
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000007fe93fbaeb1
ID
 des fehlerhaften Prozesses: 0x17f4  Startzeit der fehlerhaften Anwendung: 0x01d045ddab418f50
Pfad
 der fehlerhaften Anwendung: C:\Program Files\Sony\VAIO Care\VCAgent.exe  Pfad des
 fehlerhaften Moduls: unknown  Berichtskennung: febe3e5e-b1f9-11e4-b649-0024bed7ff33
 
Error - 11.02.2015 10:27:27 | Computer Name = XXXYYY-VAIO | Source = Avira Service Host | ID = 0
Description = Fehler beim Verarbeiten von Sitzungsänderung. System.NullReferenceException:
 Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt.    bei Avira.OE.ServiceHost.ServiceHost.OnSessionChange(SessionChangeDescription
 changeDescription)    bei System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32
 eventType, Int32 sessionId)
 
Error - 11.02.2015 10:50:11 | Computer Name = XXXYYY-VAIO | Source = Application Hang | ID = 1002
Description = Programm DeadMansDraw.exe, Version 0.0.0.0 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 168c    Startzeit:
 01d04609e9f8941f    Endzeit: 2773    Anwendungspfad: C:\Program Files (x86)\Steam\steamapps\common\Dead
 Mans Draw\DeadMansDraw.exe    Berichts-ID: 3ed509c4-b1fd-11e4-bd64-0024bed7ff33 
 
Error - 11.02.2015 11:06:06 | Computer Name = XXXYYY-VAIO | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: FRST64.exe, Version: 11.2.2015.1,
 Zeitstempel: 0x54db6942  Name des fehlerhaften Moduls: FRST64.exe, Version: 11.2.2015.1,
 Zeitstempel: 0x54db6942  Ausnahmecode: 0xc00000fd  Fehleroffset: 0x0000000000014c33
ID
 des fehlerhaften Prozesses: 0x1898  Startzeit der fehlerhaften Anwendung: 0x01d0460c161067db
Pfad
 der fehlerhaften Anwendung: C:\Users\XXX YYY\Desktop\FRST64.exe  Pfad des fehlerhaften
 Moduls: C:\Users\XXX YYY\Desktop\FRST64.exe  Berichtskennung: 805f71b4-b1ff-11e4-bd64-0024bed7ff33
 
[ ESRV_SVC Events ]
Error - 09.01.2015 05:26:38 | Computer Name = XXXYYY-VAIO | Source = ESRV_SVC | ID = 2
Description =
 
Error - 09.01.2015 15:12:56 | Computer Name = XXXYYY-VAIO | Source = ESRV_SVC | ID = 2
Description =
 
Error - 10.01.2015 05:18:59 | Computer Name = XXXYYY-VAIO | Source = ESRV_SVC | ID = 2
Description =
 
Error - 18.01.2015 07:07:20 | Computer Name = XXXYYY-VAIO | Source = ESRV_SVC | ID = 2
Description =
 
Error - 19.01.2015 05:18:30 | Computer Name = XXXYYY-VAIO | Source = ESRV_SVC | ID = 2
Description =
 
Error - 19.01.2015 08:32:22 | Computer Name = XXXYYY-VAIO | Source = ESRV_SVC | ID = 2
Description =
 
Error - 19.01.2015 09:17:08 | Computer Name = XXXYYY-VAIO | Source = ESRV_SVC | ID = 2
Description =
 
Error - 26.01.2015 04:39:38 | Computer Name = XXXYYY-VAIO | Source = ESRV_SVC | ID = 2
Description =
 
Error - 26.01.2015 08:54:29 | Computer Name = XXXYYY-VAIO | Source = ESRV_SVC | ID = 2
Description =
 
Error - 28.01.2015 04:37:28 | Computer Name = XXXYYY-VAIO | Source = ESRV_SVC | ID = 2
Description =
 
[ System Events ]
Error - 10.02.2015 11:21:19 | Computer Name = XXXYYY-VAIO | Source = Service Control Manager | ID = 7000
Description = Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%2
 
Error - 10.02.2015 11:21:19 | Computer Name = XXXYYY-VAIO | Source = Service Control Manager | ID = 7000
Description = Der Dienst "PDFProFiltSrv" wurde aufgrund folgenden Fehlers nicht
gestartet:  %%2
 
Error - 11.02.2015 05:26:54 | Computer Name = XXXYYY-VAIO | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Internet Manager. OUC erreicht.
 
Error - 11.02.2015 05:26:54 | Computer Name = XXXYYY-VAIO | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers
 nicht gestartet:  %%1053
 
Error - 11.02.2015 05:26:54 | Computer Name = XXXYYY-VAIO | Source = Service Control Manager | ID = 7000
Description = Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%2
 
Error - 11.02.2015 05:26:54 | Computer Name = XXXYYY-VAIO | Source = Service Control Manager | ID = 7000
Description = Der Dienst "PDFProFiltSrv" wurde aufgrund folgenden Fehlers nicht
gestartet:  %%2
 
Error - 11.02.2015 10:27:24 | Computer Name = XXXYYY-VAIO | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Internet Manager. OUC erreicht.
 
Error - 11.02.2015 10:27:24 | Computer Name = XXXYYY-VAIO | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers
 nicht gestartet:  %%1053
 
Error - 11.02.2015 10:27:24 | Computer Name = XXXYYY-VAIO | Source = Service Control Manager | ID = 7000
Description = Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden
 Fehlers nicht gestartet:  %%2
 
Error - 11.02.2015 10:27:24 | Computer Name = XXXYYY-VAIO | Source = Service Control Manager | ID = 7000
Description = Der Dienst "PDFProFiltSrv" wurde aufgrund folgenden Fehlers nicht
gestartet:  %%2
 
[ USER_ESRV_SVC Events ]
Error - 05.12.2014 06:33:57 | Computer Name = XXXYYY-VAIO | Source = USER_ESRV_SVC | ID = 2
Description =
 
Error - 05.12.2014 06:33:57 | Computer Name = XXXYYY-VAIO | Source = USER_ESRV_SVC | ID = 2
Description =
 
Error - 05.12.2014 06:33:57 | Computer Name = XXXYYY-VAIO | Source = USER_ESRV_SVC | ID = 2
Description =
 
Error - 05.12.2014 06:33:57 | Computer Name = XXXYYY-VAIO | Source = USER_ESRV_SVC | ID = 2
Description =
 
Error - 30.12.2014 09:58:22 | Computer Name = XXXYYY-VAIO | Source = USER_ESRV_SVC | ID = 2
Description =
 
Error - 30.12.2014 09:58:22 | Computer Name = XXXYYY-VAIO | Source = USER_ESRV_SVC | ID = 2
Description =
 
Error - 30.12.2014 09:58:22 | Computer Name = XXXYYY-VAIO | Source = USER_ESRV_SVC | ID = 2
Description =
 
 
< End of report >


Warlord711 12.02.2015 13:36

Ok, im Log erstmal nichts auffälliges. Dann lass uns mal mit ESET Scan schauen. Der dauert länger:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Warlord711 12.02.2015 16:05

Ach und bitte nochmal FRST64.exe neu herunterladen, da es eine neue Version gibt.
FRST Updated sich zwar selbst, aber sicher ist sicher.

LarryPerkins 12.02.2015 16:12

Da bin ich wohl zu schnell auf Deinstall gegangen (die Option gibt's ja schon im Fenster).. scheinbar löscht der das logfile auch mit. Schade. Muss ich dann heute Abend oder morgen dann nochmal machen. Dauer waren 2,5h.

Warlord711 12.02.2015 16:39

;(

Evtl im Papierkorb ?

LarryPerkins 12.02.2015 17:44

Liste der Anhänge anzeigen (Anzahl: 2)
HA! Ich hab ihn.
Ich hab ein Desktop Recording Programm genommen und meinen Desktop aufgezeichnet, dann als es kam Frame für Frame vorgespult.

Im Anhang ist ein Bild des Programms das für den Bruchteil einer Sekunde aufgeht.
Sieht aus wie ein Foto-Drucker-irgendwas Programm was da irgendwas versucht.
Erkennst Du was das sein kann?

Anbei auch noch Bild der Drucker die ich installiert hab.

Warlord711 12.02.2015 19:03

Kannst du bitte nochmal schauen, ob du mit der neuesten FRST64.exe ein Log erzeugen kannst ?

LarryPerkins 13.02.2015 13:26

Geht auch mit der neuen Version nicht.
Hast Du meinen letzten Post gesehen? Ich hab den XPS und die OneNote "Drucker" deinstalliert, das Problem ist aber immernoch da. Aber das sieht mir nicht nach einem Virus oder sowas aus sondern eher nach einem falsch installierten oder deinstalliertem Zeug..? Guck's Dir nochmal an.

Hier der ESET:

Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=366e0a0c8412ea499403f525d7fbf3d2
# engine=22452
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-02-13 12:08:13
# local_time=2015-02-13 01:08:13 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Avira Desktop'
# compatibility_mode=1810 16777213 100 100 76477 59760277 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 50216945 175459143 0 0
# scanned=353694
# found=11
# cleaned=0
# scan_time=7603
sh=DC060598C6BB8B49184A22A54E818FF0B2E51446 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\invalidprefs.js.vir"
sh=7DB172E43CF14E6ACD62A781BB075AF50DDA2491 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\user.js.vir"
sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\XXXRAU~1\AppData\Local\Temp\OCS\ocs_v71b.exe.vir"
sh=47B19AB97028D8925579BED54EFEE88C8107D6B6 ft=1 fh=34f71966959b3eb8 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX YYY\AppData\Local\Temp\DMR\dmr_72.exe"
sh=0B651F7E15E30C15A76894AEF522F46772C61997 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\prefs.js"
sh=A2B21761329415253A328FB765D1471913969163 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\prefs.js.BAK"
sh=E27DDC0524343F61A920256EF18288D7233B1E91 ft=1 fh=7e15088d40e766d0 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX YYY\Downloads\debut178psetup.exe"
sh=43E21DB830195927ECF157B4B0764E33186F6DD0 ft=1 fh=a365e1b8754f3835 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX YYY\Downloads\QT Lite - CHIP-Installer.exe"
sh=3BADDEAAFD6C4ACD283DD401F7BB12C752A43053 ft=1 fh=a9720ddf5a6b68b2 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX YYY\Downloads\Screen Recorder - CHIP-Installer.exe"
sh=36E63EA38042D8B767E3D8B9FDB04F65A6BC47C8 ft=1 fh=73617d6529c7c29d vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX YYY\Downloads\TeamViewer - CHIP-Downloader.exe"
sh=7592805D300B27EBEAC9A364B5E4DDFFE0C0D685 ft=1 fh=186be5bc4ed8fdf4 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\XXX YYY\Downloads\XnView Komplett - CHIP-Installer.exe"


Warlord711 13.02.2015 15:20

Lass mal Windows All in One Repair laufen:

http://www.trojaner-board.de/126216-...epair-aio.html

LarryPerkins 17.02.2015 02:15

Sooooooo... hier ist das Log:

Code:

Tweaking.com - Windows Repair v2.11.0
--------------------------------------------------------------------------------

System Variables
--------------------------------------------------------------------------------
OS: Windows 7 Professional
OS Architecture: 64-bit
OS Version: 6.1.7601
OS Service Pack: Service Pack 1
Computer Name: XXXXXX-VAIO
Windows Drive: C:\
Windows Path: C:\Windows
Program Files: C:\Program Files
Program Files (x86): C:\Program Files (x86)
Current Profile: C:\Users\XXX XXX
Current Profile SID: S-1-5-21-3557091032-3563988234-1886976076-1000
Current Profile Classes: S-1-5-21-3557091032-3563988234-1886976076-1000_Classes
Profiles Location: C:\Users
Profiles Location 2: C:\Windows\ServiceProfiles
Local Settings AppData: C:\Users\XXX XXX\AppData\Local
--------------------------------------------------------------------------------

System Information
--------------------------------------------------------------------------------
System Up Time: 0 Days 00:04:24

Process Count: 122
Commit Total: 2,80 GB
Commit Limit: 7,35 GB
Commit Peak: 2,83 GB
Handle Count: 34900
Kernel Total: 409,43 MB
Kernel Paged: 300,34 MB
Kernel Non Paged: 109,08 MB
System Cache: 1,32 GB
Thread Count: 1578
--------------------------------------------------------------------------------

Memory Before Cleaning with CleanMem
--------------------------------------------------------------------------------
Memory Total: 3,68 GB
Memory Used: 2,30 GB(62,5943%)
Memory Avail.: 1,38 GB
--------------------------------------------------------------------------------

Cleaning Memory Before Starting Repairs...

Memory After Cleaning with CleanMem
--------------------------------------------------------------------------------
Memory Total: 3,68 GB
Memory Used: 1,73 GB(47,0409%)
Memory Avail.: 1,95 GB
--------------------------------------------------------------------------------

Starting Repairs...
  Started at (16.02.2015 16:08:12)

Setting Any Missing 'InstallDate' From Uninstall Sections Before Running Repair...
Total Missing 'InstallDate' Fixed: 178
 
01 - Reset Registry Permissions 01/03
  HKEY_CURRENT_USER & Sub Keys
  Start (16.02.2015 16:08:14)

  You can tell the repair is working as SetACL_32.exe or SetACL_64.exe will be running.

  Running Repair Under Current User Account
  Done (16.02.2015 16:08:34)

01 - Reset Registry Permissions 02/03
  HKEY_LOCAL_MACHINE & Sub Keys
  Start (16.02.2015 16:08:34)

  You can tell the repair is working as SetACL_32.exe or SetACL_64.exe will be running.

  Running Repair Under System Account
  Done (16.02.2015 16:21:39)

01 - Reset Registry Permissions 03/03
  HKEY_CLASSES_ROOT & Sub Keys
  Start (16.02.2015 16:21:39)

  You can tell the repair is working as SetACL_32.exe or SetACL_64.exe will be running.

  Running Repair Under System Account
  Done (16.02.2015 16:24:42)

03 - Reset Service Permissions
  Start (16.02.2015 16:24:42)

  You can tell the repair is working as SetACL_32.exe or SetACL_64.exe will be running.

  Running Repair Under System Account
  Done (16.02.2015 16:24:49)

04 - Register System Files
  Start (16.02.2015 16:24:49)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:25:19)

05 - Repair WMI
  Start (16.02.2015 16:25:19)

  Starting Security Center So We Can Export The Security Info.

  Exporting Antivirus Info...
  Avira Desktop Exported.

  Exporting AntiSpyware Info...
  Avira Desktop Exported.
  Windows Defender Exported.

  Exporting 3rd Party Firewall Info...
  No Firewall Products Reported.

  Running Repair Under Current User Account
  Done (16.02.2015 16:27:42)

06 - Repair Windows Firewall
  Start (16.02.2015 16:27:43)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:28:20)

07 - Repair Internet Explorer
  Start (16.02.2015 16:28:20)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:28:48)

08 - Repair MDAC/MS Jet
  Start (16.02.2015 16:28:48)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:28:58)

09 - Repair Hosts File
  Start (16.02.2015 16:28:58)
  Running Repair Under System Account
  Done (16.02.2015 16:28:59)

10 - Remove Policies Set By Infections
  Start (16.02.2015 16:28:59)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:29:04)

11 - Repair Start Menu Icons Removed By Infections
  Start (16.02.2015 16:29:04)
  Running Repair Under System Account
  Done (16.02.2015 16:29:05)

12 - Repair Icons
  Start (16.02.2015 16:29:05)
  Running Repair Under Current User Account
  Done (16.02.2015 16:29:07)

13 - Repair Winsock & DNS Cache
  Start (16.02.2015 16:29:07)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:29:25)

15 - Repair Proxy Settings
  Start (16.02.2015 16:29:25)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:29:27)

17 - Repair Windows Updates
  Start (16.02.2015 16:29:27)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Setting Windows Updates Files That Are In Use To Be Removed At Next Boot.
  Done (16.02.2015 16:29:59)

18 - Repair CD/DVD Missing/Not Working
  Start (16.02.2015 16:29:59)
  iTunes not found, not applying UpperFilters iTunes Reg Key
  Done (16.02.2015 16:29:59)

19 - Repair Volume Shadow Copy Service
  Start (16.02.2015 16:29:59)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:30:24)

21 - Repair MSI (Windows Installer)
  Start (16.02.2015 16:30:24)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:30:38)

23.01 - Repair bat Association
  Start (16.02.2015 16:30:38)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:30:41)

23.02 - Repair cmd Association
  Start (16.02.2015 16:30:41)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:30:43)

23.03 - Repair com Association
  Start (16.02.2015 16:30:43)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:30:45)

23.04 - Repair Directory Association
  Start (16.02.2015 16:30:45)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:30:48)

23.05 - Repair Drive Association
  Start (16.02.2015 16:30:48)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:30:50)

23.06 - Repair exe Association
  Start (16.02.2015 16:30:50)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:30:53)

23.07 - Repair Folder Association
  Start (16.02.2015 16:30:53)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:30:55)

23.08 - Repair inf Association
  Start (16.02.2015 16:30:55)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:30:57)

23.09 - Repair lnk (Shortcuts) Association
  Start (16.02.2015 16:30:57)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:31:00)

23.10 - Repair msc Association
  Start (16.02.2015 16:31:00)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:31:02)

23.11 - Repair reg Association
  Start (16.02.2015 16:31:02)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:31:05)

23.12 - Repair scr Association
  Start (16.02.2015 16:31:05)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:31:07)

24 - Repair Windows Safe Mode
  Start (16.02.2015 16:31:07)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:31:09)

25 - Repair Print Spooler
  Start (16.02.2015 16:31:09)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:31:28)

26 - Restore Important Windows Services
  Start (16.02.2015 16:31:28)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:31:39)

27 - Set Windows Services To Default Startup
  Start (16.02.2015 16:31:39)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:31:45)

  Skipping Repair.
  Repair is for Windows v6.2 (Windows 8 & Newer) or higher.
  Current version: 6.1

  Skipping Repair.
  Repair is for Windows v6.2 (Windows 8 & Newer) or higher.
  Current version: 6.1

  Skipping Repair.
  Repair is for Windows v6.2 (Windows 8 & Newer) or higher.
  Current version: 6.1

31 - Repair Windows 'New' Submenu
  Start (16.02.2015 16:31:46)
  Running Repair Under Current User Account
  Running Repair Under System Account
  Done (16.02.2015 16:31:48)

Cleaning up empty logs...

All Selected Repairs Done.
  Done at (16.02.2015 16:31:48)
  Total Repair Time: 00:23:37


...YOU MUST RESTART YOUR SYSTEM...


Warlord711 17.02.2015 09:03

Hat das ne Verbesserung gebracht ?

Warlord711 18.02.2015 09:06

Achja, und funktioniert FRST inzwischen ?

Falls nicht, dann habe ich eine Bitte, könntest du den Ordner %localappdata%\Google\Chrome\User Data in eine .zip Datei packen und hier als Anhang, oder auch per PM, hochladen ?

Habe den Fehler dem Entwickler gemeldet und dessen Bitte war, diesen Ordner, falls möglich, zu bekommen.

LarryPerkins 18.02.2015 09:39

Fehler ist immernoch da, FRST geht noch nicht.
Kannst Du aus dem Screenshot den ich gemacht hab wirklich nichts entnehmen?
Scheinbar ist es irgend eine Art Druckertreiber der irgendwas regelmäßig sucht...

Ich kann den Ordner nicht anhängen weil er 81MB groß ist (als .rar), max erlaubte Größe hier sind 4,7MB.
Bei den Profilnachrichten kann ich nix anhängen so wie's aussieht?

Weiß ja nicht was alles in dem Ordner ist, aber kannst Du das hier dann bitte löschen wenn Du fertig mit dem download bist..? Klingt irgendwie seltsam einen Userdata Ordner von chrome hier im Netz zu haben?

Warlord711 18.02.2015 10:05

Zitat:

Zitat von LarryPerkins (Beitrag 1428654)
Fehler ist immernoch da, FRST geht noch nicht.
Kannst Du aus dem Screenshot den ich gemacht hab wirklich nichts entnehmen?
Scheinbar ist es irgend eine Art Druckertreiber der irgendwas regelmäßig sucht...

Ich kann den Ordner nicht anhängen weil er 81MB groß ist (als .rar), max erlaubte Größe hier sind 4,7MB.
Bei den Profilnachrichten kann ich nix anhängen so wie's aussieht?

Weiß ja nicht was alles in dem Ordner ist, aber kannst Du das hier dann bitte löschen wenn Du fertig mit dem download bist..? Klingt irgendwie seltsam einen Userdata Ordner von chrome hier im Netz zu haben?

Das ist ja auch optional und keine Plicht.
Der Entwickler von FRST möchte den Fehler gern nachstellen können (und beheben).

Vielleicht hast du die Möglichkeit, Dropbox oder Google Drive oder ähnliches zu nutzen, um die Datei hochzuladen ?

Den Link dazu dann per PM an mich.

LarryPerkins 18.02.2015 10:25

Hab Dir ne PM mit dem Google Drive Link geschickt.

Hab noch keine Antwort bzgl des Screenshots von Seite 3?
Wie machen wir weiter? Wie gesagt, Problem existiert noch, auch nachdem ich alle Drucker die so aussehen wie auf dem Screenshot deinstalliert hab...

Warlord711 18.02.2015 15:31

Ereignisse mit VEW exportieren

Bitte lade VEW.exe von Vino Rosso herunter und speichere das Tool auf Deinem Desktop.
Starte die vew.exe durch Doppelklick und mache folgende Einstellungen:

http://www.trojaner-board.de/picture...&pictureid=520

Drücke den Button Run, um den Suchlauf zu starten.
Wenn der Suchlauf beendet ist, öffnet sich der Editor mit dem Logfile.
Kopiere das Logfile (C:\vew.txt) hier in den Thread.

Warlord711 18.02.2015 17:03

Habe schon Antwort erhalten.

Bitte starte Chrome, lass Chrome die Startseite laden und warte dann einige Sekunden.
Dann bitte Chrome wieder schliessen und im Anschluss FRST - Scan durchführen.

Warlord711 18.02.2015 18:28

Farbar meint, du hast mehrere Chrome Profile.
Bitte Chrome mit allen vorhandenen Profilen mind. 1 mal starten, also einfach der Reihe nach.

Danach sollte FRST funktionieren. Zum Scan braucht Chrome nicht zu laufen, wichtig ist, das alle Profile mind. 1 mal geladen werden.

LarryPerkins 19.02.2015 11:55

Jetzt hab ich was sehr schräges... ich kann in c./ nichts speichern aus dem editor heraus. das heißt er kann auch keine vew.txt erzeugen weil der Zugriff verweigert wurde (ich solle mich an einen Administrator wenden?!).

Hab versucht das zu umgehen indem ich c:/ für alle freigegeben hab.. das hat aber nicht funktioniert.

Warlord711 19.02.2015 12:58

Als Administrator gestartet ?

LarryPerkins 19.02.2015 13:19

Ich Dödel. Sorry.

Code:

Vino's Event Viewer v01c run on Windows 2008 in German
Report run at 19/02/2015 13:18:09

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Kritisch Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Fehler Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 19/02/2015 10:48:42
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "C:\Users\XXX YYY\AppData\Local\join.me\join.me.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 19/02/2015 10:48:42
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "C:\Users\XXX YYY\AppData\Local\join.me\join.me.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 19/02/2015 10:48:42
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "C:\Users\XXX YYY\AppData\Local\join.me\join.me.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 19/02/2015 10:43:23
Type: Fehler Category: 0
Event: 0 Source: Avira Service Host
Fehler beim Verarbeiten von Sitzungsänderung. System.NullReferenceException: Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt.    bei Avira.OE.ServiceHost.ServiceHost.OnSessionChange(SessionChangeDescription changeDescription)    bei System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)

Log: 'Application' Date/Time: 19/02/2015 10:42:40
Type: Fehler Category: 100
Event: 1000 Source: Application Error
Name der fehlerhaften Anwendung: VCAgent.exe, Version: 8.4.2.12030, Zeitstempel: 0x5476d099 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000007fe9331aa71 ID des fehlerhaften Prozesses: 0x1d50 Startzeit der fehlerhaften Anwendung: 0x01d04b54180c070f Pfad der fehlerhaften Anwendung: C:\Program Files\Sony\VAIO Care\VCAgent.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 06859bd1-b824-11e4-8007-0024bed7ff33

Log: 'Application' Date/Time: 19/02/2015 10:42:38
Type: Fehler Category: 0
Event: 1026 Source: .NET Runtime
Anwendung: VCAgent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
  bei VCAgent.View.MainWindow.WindowProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei System.Windows.Interop.HwndSource.PublicHooksFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
  bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
  bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
  bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.DefWndProcWrapper(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.GetMessage(System.Windows.Interop.MSG ByRef, IntPtr, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
  bei System.Windows.Application.RunInternal(System.Windows.Window)
  bei System.Windows.Application.Run()
  bei VCAgent.App.Main()


Log: 'Application' Date/Time: 19/02/2015 09:48:58
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "C:\Users\XXX YYY\Downloads\esetsmartinstaller_deu(1).exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 19/02/2015 09:48:58
Type: Fehler Category: 0
Event: 80 Source: SideBySide
Fehler beim Generieren des Aktivierungskontexts für "C:\Users\XXX YYY\Downloads\esetsmartinstaller_deu.exe". Fehler in Manifest- oder Richtliniendatei "" in Zeile . Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Log: 'Application' Date/Time: 19/02/2015 09:08:41
Type: Fehler Category: 100
Event: 1000 Source: Application Error
Name der fehlerhaften Anwendung: svchost.exe_WbioSrvc, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc3c1 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x5315a05a Ausnahmecode: 0x80004004 Fehleroffset: 0x000000000000940d ID des fehlerhaften Prozesses: 0x1264 Startzeit der fehlerhaften Anwendung: 0x01d04b535cef8de8 Pfad der fehlerhaften Anwendung: C:\Windows\system32\svchost.exe Pfad des fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll Berichtskennung: e599669c-b816-11e4-8007-0024bed7ff33

Log: 'Application' Date/Time: 18/02/2015 08:11:14
Type: Fehler Category: 100
Event: 1000 Source: Application Error
Name der fehlerhaften Anwendung: VCAgent.exe, Version: 8.4.2.12030, Zeitstempel: 0x5476d099 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000007fe9284aa71 ID des fehlerhaften Prozesses: 0x370 Startzeit der fehlerhaften Anwendung: 0x01d049feca3127c3 Pfad der fehlerhaften Anwendung: C:\Program Files\Sony\VAIO Care\VCAgent.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: b477e860-b745-11e4-bdba-0024bed7ff33

Log: 'Application' Date/Time: 18/02/2015 08:11:13
Type: Fehler Category: 0
Event: 1026 Source: .NET Runtime
Anwendung: VCAgent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
  bei VCAgent.View.MainWindow.WindowProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei System.Windows.Interop.HwndSource.PublicHooksFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
  bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
  bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
  bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.DefWndProcWrapper(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.GetMessage(System.Windows.Interop.MSG ByRef, IntPtr, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
  bei System.Windows.Application.RunInternal(System.Windows.Window)
  bei System.Windows.Application.Run()
  bei VCAgent.App.Main()


Log: 'Application' Date/Time: 16/02/2015 15:35:13
Type: Fehler Category: 0
Event: 1103 Source: .NET Runtime Optimization Service
.NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown


Log: 'Application' Date/Time: 16/02/2015 15:35:13
Type: Fehler Category: 0
Event: 1103 Source: .NET Runtime Optimization Service
.NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown


Log: 'Application' Date/Time: 16/02/2015 15:32:37
Type: Fehler Category: 100
Event: 1000 Source: Application Error
Name der fehlerhaften Anwendung: VCAgent.exe, Version: 8.4.2.12030, Zeitstempel: 0x5476d099 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000007fe9363a321 ID des fehlerhaften Prozesses: 0x1380 Startzeit der fehlerhaften Anwendung: 0x01d049fa8981b167 Pfad der fehlerhaften Anwendung: C:\Program Files\Sony\VAIO Care\VCAgent.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 08b5d4d4-b5f1-11e4-8099-0024bed7ff33

Log: 'Application' Date/Time: 16/02/2015 15:32:37
Type: Fehler Category: 0
Event: 1026 Source: .NET Runtime
Anwendung: VCAgent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
  bei VCAgent.View.MainWindow.WindowProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei System.Windows.Interop.HwndSource.PublicHooksFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
  bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
  bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
  bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.DefWndProcWrapper(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.GetMessage(System.Windows.Interop.MSG ByRef, IntPtr, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
  bei System.Windows.Application.RunInternal(System.Windows.Window)
  bei System.Windows.Application.Run()
  bei VCAgent.App.Main()


Log: 'Application' Date/Time: 16/02/2015 15:04:03
Type: Fehler Category: 0
Event: 0 Source: Avira Service Host
Fehler beim Verarbeiten von Sitzungsänderung. System.NullReferenceException: Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt.    bei Avira.OE.ServiceHost.ServiceHost.OnSessionChange(SessionChangeDescription changeDescription)    bei System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)

Log: 'Application' Date/Time: 16/02/2015 15:03:21
Type: Fehler Category: 100
Event: 1000 Source: Application Error
Name der fehlerhaften Anwendung: VCAgent.exe, Version: 8.4.2.12030, Zeitstempel: 0x5476d099 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000007fe9321aa71 ID des fehlerhaften Prozesses: 0x1b58 Startzeit der fehlerhaften Anwendung: 0x01d049f7a46ad2ae Pfad der fehlerhaften Anwendung: C:\Program Files\Sony\VAIO Care\VCAgent.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: f1f6aa5c-b5ec-11e4-86f9-0024bed7ff33

Log: 'Application' Date/Time: 16/02/2015 15:03:20
Type: Fehler Category: 0
Event: 1026 Source: .NET Runtime
Anwendung: VCAgent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
  bei VCAgent.View.MainWindow.WindowProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei System.Windows.Interop.HwndSource.PublicHooksFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
  bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
  bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
  bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.DefWndProcWrapper(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.GetMessage(System.Windows.Interop.MSG ByRef, IntPtr, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
  bei System.Windows.Application.RunInternal(System.Windows.Window)
  bei System.Windows.Application.Run()
  bei VCAgent.App.Main()


Log: 'Application' Date/Time: 16/02/2015 14:39:42
Type: Fehler Category: 100
Event: 1000 Source: Application Error
Name der fehlerhaften Anwendung: VCAgent.exe, Version: 8.4.2.12030, Zeitstempel: 0x5476d099 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000007fe934eaa71 ID des fehlerhaften Prozesses: 0x12dc Startzeit der fehlerhaften Anwendung: 0x01d0460796435535 Pfad der fehlerhaften Anwendung: C:\Program Files\Sony\VAIO Care\VCAgent.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: a450a836-b5e9-11e4-bd64-0024bed7ff33

Log: 'Application' Date/Time: 16/02/2015 14:39:41
Type: Fehler Category: 0
Event: 1026 Source: .NET Runtime
Anwendung: VCAgent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
  bei VCAgent.View.MainWindow.WindowProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei System.Windows.Interop.HwndSource.PublicHooksFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
  bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
  bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
  bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.DefWndProcWrapper(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.GetMessage(System.Windows.Interop.MSG ByRef, IntPtr, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
  bei System.Windows.Application.RunInternal(System.Windows.Window)
  bei System.Windows.Application.Run()
  bei VCAgent.App.Main()


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Informationen Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 19/02/2015 12:17:43
Type: Informationen Category: 0
Event: 0 Source: VSNService
The event description cannot be found.

Log: 'Application' Date/Time: 19/02/2015 12:17:42
Type: Informationen Category: 0
Event: 0 Source: VSNService
The event description cannot be found.

Log: 'Application' Date/Time: 19/02/2015 12:17:42
Type: Informationen Category: 1
Event: 257 Source: SampleCollector
Started listener in session 1, pid 8368: C:\Program Files\Sony\VAIO Care/listener.exe /silent /slot=0

Log: 'Application' Date/Time: 19/02/2015 12:17:42
Type: Informationen Category: 1
Event: 257 Source: SampleCollector
Starting SampleCollector: dir: C:\ProgramData\Sony Corporation\VAIO Care\inteldata, interval: 10000 ms, proc: 5, dll: 120, nsamples: 3600, counters: 23


Log: 'Application' Date/Time: 19/02/2015 12:17:42
Type: Informationen Category: 0
Event: 1000 Source: Interactive Services detection
Bei einem Gerät oder Programm ist Ihr Eingreifen erforderlich. Gerät/Anwendung: C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\RunLiveUpd.exe Nachrichtentitel: C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\RunLiveUpd.exe.

Log: 'Application' Date/Time: 19/02/2015 11:15:41
Type: Informationen Category: 0
Event: 0 Source: VSNService
The event description cannot be found.

Log: 'Application' Date/Time: 19/02/2015 11:15:41
Type: Informationen Category: 1
Event: 257 Source: SampleCollector
Stopped listener in session 1, pid 3880

Log: 'Application' Date/Time: 19/02/2015 11:13:52
Type: Informationen Category: 0
Event: 903 Source: Office Software Protection Platform Service
The Software Protection service has stopped.

Log: 'Application' Date/Time: 19/02/2015 11:13:52
Type: Informationen Category: 0
Event: 16384 Source: Office Software Protection Platform Service
Successfully scheduled Software Protection service for re-start at 2015-02-19T13:07:52Z. Reason: GVLK.

Log: 'Application' Date/Time: 19/02/2015 11:13:20
Type: Informationen Category: 0
Event: 1000 Source: Interactive Services detection
Bei einem Gerät oder Programm ist Ihr Eingreifen erforderlich. Gerät/Anwendung: C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\RunLiveUpd.exe Nachrichtentitel: C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\RunLiveUpd.exe.

Log: 'Application' Date/Time: 19/02/2015 11:03:51
Type: Informationen Category: 0
Event: 902 Source: Office Software Protection Platform Service
The Software Protection service has started. 15.0.169.500

Log: 'Application' Date/Time: 19/02/2015 11:03:51
Type: Informationen Category: 0
Event: 1066 Source: Office Software Protection Platform Service
Initialization status for service objects. C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000


Log: 'Application' Date/Time: 19/02/2015 11:03:49
Type: Informationen Category: 0
Event: 900 Source: Office Software Protection Platform Service
The Software Protection service is starting.

Log: 'Application' Date/Time: 19/02/2015 10:58:20
Type: Informationen Category: 0
Event: 1000 Source: Interactive Services detection
Bei einem Gerät oder Programm ist Ihr Eingreifen erforderlich. Gerät/Anwendung: C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\RunLiveUpd.exe Nachrichtentitel: C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\RunLiveUpd.exe.

Log: 'Application' Date/Time: 19/02/2015 10:56:32
Type: Informationen Category: 0
Event: 1001 Source: Windows Error Reporting
Fehlerbucket 3372333141, Typ 5 Ereignisname: WUDFHostProblem Antwort: Nicht verfügbar CAB-Datei-ID: 0  Problemsignatur: P1: HostProblem P2: HostTimeout P3: 2 P4: 6.2.9200.16384. (win8_rtm.120725-1247) P5: 103 P6: 3 P7: 11b17 P8: ffffffff P9: USB\VID_147E&PID_1001&REV_0043 P10:  Angefügte Dateien: C:\Windows\Temp\WER3D2A.tmp.hdmp C:\Windows\Temp\WER3F5D.tmp.mdmp  Diese Dateien befinden sich möglicherweise hier: C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_HostProblem_538a7bbe812746aff5114824c4cc4d632caf4e8_01504b9f  Analysesymbol:  Es wird erneut nach einer Lösung gesucht: 0 Berichts-ID: d95ee196-b816-11e4-8007-0024bed7ff33 Berichtstatus: 0

Log: 'Application' Date/Time: 19/02/2015 10:56:26
Type: Informationen Category: 0
Event: 1001 Source: Windows Error Reporting
Fehlerbucket , Typ 0 Ereignisname: LiveKernelEvent Antwort: Nicht verfügbar CAB-Datei-ID: 0  Problemsignatur: P1:  P2:  P3:  P4:  P5:  P6:  P7:  P8:  P9:  P10:  Angefügte Dateien: C:\Windows\LiveKernelReports\WATCHDOG\WD-20141125-0857.dmp C:\Windows\Temp\WER-3905313-0.sysdata.xml C:\Windows\Temp\WERC8AC.tmp.WERInternalMetadata.xml  Diese Dateien befinden sich möglicherweise hier: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_0_0_cab_4bffc8ac  Analysesymbol:  Es wird erneut nach einer Lösung gesucht: 0 Berichts-ID: b7484411-7478-11e4-b937-0024bed7ff33 Berichtstatus: 0

Log: 'Application' Date/Time: 19/02/2015 10:56:26
Type: Informationen Category: 0
Event: 1001 Source: Windows Error Reporting
Fehlerbucket , Typ 0 Ereignisname: LiveKernelEvent Antwort: Nicht verfügbar CAB-Datei-ID: 0  Problemsignatur: P1:  P2:  P3:  P4:  P5:  P6:  P7:  P8:  P9:  P10:  Angefügte Dateien: C:\Windows\LiveKernelReports\WATCHDOG\WD-20130731-0904.dmp C:\Windows\Temp\WER-514400067-0.sysdata.xml C:\Windows\Temp\WER400C.tmp.WERInternalMetadata.xml  Diese Dateien befinden sich möglicherweise hier: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_0_0_cab_3559401c  Analysesymbol:  Es wird erneut nach einer Lösung gesucht: 0 Berichts-ID: 7226df2f-f9af-11e2-80f1-0024bed7ff33 Berichtstatus: 0

Log: 'Application' Date/Time: 19/02/2015 10:56:26
Type: Informationen Category: 0
Event: 1001 Source: Windows Error Reporting
Fehlerbucket , Typ 0 Ereignisname: LiveKernelEvent Antwort: Nicht verfügbar CAB-Datei-ID: 0  Problemsignatur: P1:  P2:  P3:  P4:  P5:  P6:  P7:  P8:  P9:  P10:  Angefügte Dateien: C:\Windows\LiveKernelReports\WATCHDOG\WD-20140208-1448-01.dmp C:\Windows\Temp\WER-82649797-0.sysdata.xml C:\Windows\Temp\WER2B6D.tmp.WERInternalMetadata.xml  Diese Dateien befinden sich möglicherweise hier: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_0_0_cab_26412b6c  Analysesymbol:  Es wird erneut nach einer Lösung gesucht: 0 Berichts-ID: c0b585b3-90c7-11e3-ad1c-0024bed7ff33 Berichtstatus: 0

Log: 'Application' Date/Time: 19/02/2015 10:56:26
Type: Informationen Category: 0
Event: 1001 Source: Windows Error Reporting
Fehlerbucket , Typ 0 Ereignisname: LiveKernelEvent Antwort: Nicht verfügbar CAB-Datei-ID: 0  Problemsignatur: P1:  P2:  P3:  P4:  P5:  P6:  P7:  P8:  P9:  P10:  Angefügte Dateien: C:\Windows\LiveKernelReports\WATCHDOG\WD-20130605-1852.dmp C:\Windows\Temp\WER-27613066-0.sysdata.xml C:\Windows\Temp\WER74E9.tmp.WERInternalMetadata.xml  Diese Dateien befinden sich möglicherweise hier: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_0_0_cab_207d74e9  Analysesymbol:  Es wird erneut nach einer Lösung gesucht: 0 Berichts-ID: 3ef6298e-ce00-11e2-b9e8-0024bed7ff33 Berichtstatus: 0

Log: 'Application' Date/Time: 19/02/2015 10:56:26
Type: Informationen Category: 0
Event: 1001 Source: Windows Error Reporting
Fehlerbucket , Typ 0 Ereignisname: LiveKernelEvent Antwort: Nicht verfügbar CAB-Datei-ID: 0  Problemsignatur: P1:  P2:  P3:  P4:  P5:  P6:  P7:  P8:  P9:  P10:  Angefügte Dateien: C:\Windows\LiveKernelReports\WATCHDOG\WD-20130325-1517.dmp C:\Windows\Temp\WER-5545117-0.sysdata.xml C:\Windows\Temp\WERB377.tmp.WERInternalMetadata.xml  Diese Dateien befinden sich möglicherweise hier: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_0_0_cab_1924b387  Analysesymbol:  Es wird erneut nach einer Lösung gesucht: 0 Berichts-ID: b9775614-9556-11e2-a5e1-0024bed7ff33 Berichtstatus: 0

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warnung Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 19/02/2015 10:45:54
Type: Warnung Category: 1
Event: 258 Source: SampleCollector
Expand Counter: PdhExpandWildCardPath: No match for: ctrbase=\Processor(*)\%C3 Time native=\Prozessor(*)\


Log: 'Application' Date/Time: 19/02/2015 10:45:54
Type: Warnung Category: 1
Event: 258 Source: SampleCollector
Intel(R) System Behavior Tracker Collector Service.
Copyright (C) 2013, Intel Corporation. All rights reserved.
Version 3.2.0.1 usage:
SBTService [/help|/uninstall|/savecsv {files...} OR
SBTService /install /service {Args...} OR
SBTService /standalone] {Args...}]
Args =
        /directory=name
        /nsamples=number
        /dllinterval=number
        /procinterval=number
        counter=ctrname[:interval]
        verbose[=level]
        /expandcounter=ctrname[:interval]
        /sstates
        /nosstates


Log: 'Application' Date/Time: 19/02/2015 10:45:54
Type: Warnung Category: 1
Event: 258 Source: SampleCollector
Unrecognized argument:


Log: 'Application' Date/Time: 19/02/2015 10:43:20
Type: Warnung Category: 0
Event: 1 Source: LMS
LMS Service cannot connect to Intel(R) MEI driver

Log: 'Application' Date/Time: 18/02/2015 08:14:11
Type: Warnung Category: 1
Event: 258 Source: SampleCollector
Expand Counter: PdhExpandWildCardPath: No match for: ctrbase=\Processor(*)\%C3 Time native=\Prozessor(*)\


Log: 'Application' Date/Time: 18/02/2015 08:14:11
Type: Warnung Category: 1
Event: 258 Source: SampleCollector
Intel(R) System Behavior Tracker Collector Service.
Copyright (C) 2013, Intel Corporation. All rights reserved.
Version 3.2.0.1 usage:
SBTService [/help|/uninstall|/savecsv {files...} OR
SBTService /install /service {Args...} OR
SBTService /standalone] {Args...}]
Args =
        /directory=name
        /nsamples=number
        /dllinterval=number
        /procinterval=number
        counter=ctrname[:interval]
        verbose[=level]
        /expandcounter=ctrname[:interval]
        /sstates
        /nosstates


Log: 'Application' Date/Time: 18/02/2015 08:14:11
Type: Warnung Category: 1
Event: 258 Source: SampleCollector
Unrecognized argument:


Log: 'Application' Date/Time: 18/02/2015 08:11:55
Type: Warnung Category: 0
Event: 1 Source: LMS
LMS Service cannot connect to Intel(R) MEI driver

Log: 'Application' Date/Time: 18/02/2015 08:11:05
Type: Warnung Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Es wurde festgestellt, dass Ihre Registrierungsdatei noch von anderen Anwendungen oder Diensten verwendet wird. Die Datei wird nun entladen. Die Anwendungen oder Dienste, die Ihre Registrierungsdatei anhalten, funktionieren anschließend u. U. nicht mehr ordnungsgemäß.    DETAIL -  4 user registry handles leaked from \Registry\User\S-1-5-21-3557091032-3563988234-1886976076-1000:
Process 1000 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3557091032-3563988234-1886976076-1000
Process 1808 (\Device\HarddiskVolume3\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe) has opened key \REGISTRY\USER\S-1-5-21-3557091032-3563988234-1886976076-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 2108 (\Device\HarddiskVolume3\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe) has opened key \REGISTRY\USER\S-1-5-21-3557091032-3563988234-1886976076-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall
Process 2108 (\Device\HarddiskVolume3\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe) has opened key \REGISTRY\USER\S-1-5-21-3557091032-3563988234-1886976076-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall


Log: 'Application' Date/Time: 16/02/2015 16:39:47
Type: Warnung Category: 1
Event: 258 Source: SampleCollector
Expand Counter: PdhExpandWildCardPath: No match for: ctrbase=\Processor(*)\%C3 Time native=\Prozessor(*)\


Log: 'Application' Date/Time: 16/02/2015 16:39:47
Type: Warnung Category: 1
Event: 258 Source: SampleCollector
Intel(R) System Behavior Tracker Collector Service.
Copyright (C) 2013, Intel Corporation. All rights reserved.
Version 3.2.0.1 usage:
SBTService [/help|/uninstall|/savecsv {files...} OR
SBTService /install /service {Args...} OR
SBTService /standalone] {Args...}]
Args =
        /directory=name
        /nsamples=number
        /dllinterval=number
        /procinterval=number
        counter=ctrname[:interval]
        verbose[=level]
        /expandcounter=ctrname[:interval]
        /sstates
        /nosstates


Log: 'Application' Date/Time: 16/02/2015 16:39:47
Type: Warnung Category: 1
Event: 258 Source: SampleCollector
Unrecognized argument:


Log: 'Application' Date/Time: 16/02/2015 15:37:18
Type: Warnung Category: 1
Event: 258 Source: SampleCollector
Expand Counter: PdhExpandWildCardPath: No match for: ctrbase=\Processor(*)\%C3 Time native=\Prozessor(*)\


Log: 'Application' Date/Time: 16/02/2015 15:37:18
Type: Warnung Category: 1
Event: 258 Source: SampleCollector
Intel(R) System Behavior Tracker Collector Service.
Copyright (C) 2013, Intel Corporation. All rights reserved.
Version 3.2.0.1 usage:
SBTService [/help|/uninstall|/savecsv {files...} OR
SBTService /install /service {Args...} OR
SBTService /standalone] {Args...}]
Args =
        /directory=name
        /nsamples=number
        /dllinterval=number
        /procinterval=number
        counter=ctrname[:interval]
        verbose[=level]
        /expandcounter=ctrname[:interval]
        /sstates
        /nosstates


Log: 'Application' Date/Time: 16/02/2015 15:37:18
Type: Warnung Category: 1
Event: 258 Source: SampleCollector
Unrecognized argument:


Log: 'Application' Date/Time: 16/02/2015 15:34:28
Type: Warnung Category: 0
Event: 1 Source: LMS
LMS Service cannot connect to Intel(R) MEI driver

Log: 'Application' Date/Time: 16/02/2015 15:32:30
Type: Warnung Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Es wurde festgestellt, dass Ihre Registrierungsdatei noch von anderen Anwendungen oder Diensten verwendet wird. Die Datei wird nun entladen. Die Anwendungen oder Dienste, die Ihre Registrierungsdatei anhalten, funktionieren anschließend u. U. nicht mehr ordnungsgemäß.    DETAIL -  1 user registry handles leaked from \Registry\User\S-1-5-21-3557091032-3563988234-1886976076-1000:
Process 1972 (\Device\HarddiskVolume3\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe) has opened key \REGISTRY\USER\S-1-5-21-3557091032-3563988234-1886976076-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon


Log: 'Application' Date/Time: 16/02/2015 15:27:36
Type: Warnung Category: 0
Event: 63 Source: Microsoft-Windows-WMI
Ein WpcClamperProv-Anbieter wurde im WMI-Namespace (Windows-Verwaltungsinstrumentation) ROOT\CIMV2\Applications\WindowsParentalControls zur Verwendung des Kontos "LocalSystem" registriert. Dieses Konto ist ein privilegiertes Konto, d. h. der Anbieter kann Sicherheitsverletzungen verursachen, wenn der Identitätswechsel für Benutzeranforderungen nicht korrekt ausgeführt wird.

Log: 'Application' Date/Time: 16/02/2015 15:27:36
Type: Warnung Category: 0
Event: 63 Source: Microsoft-Windows-WMI
Ein WpcClamperProv-Anbieter wurde im WMI-Namespace (Windows-Verwaltungsinstrumentation) ROOT\CIMV2\Applications\WindowsParentalControls zur Verwendung des Kontos "LocalSystem" registriert. Dieses Konto ist ein privilegiertes Konto, d. h. der Anbieter kann Sicherheitsverletzungen verursachen, wenn der Identitätswechsel für Benutzeranforderungen nicht korrekt ausgeführt wird.

Log: 'Application' Date/Time: 16/02/2015 15:27:13
Type: Warnung Category: 0
Event: 63 Source: Microsoft-Windows-WMI
Ein WpcClamperProv-Anbieter wurde im WMI-Namespace (Windows-Verwaltungsinstrumentation) ROOT\CIMV2\Applications\WindowsParentalControls zur Verwendung des Kontos "LocalSystem" registriert. Dieses Konto ist ein privilegiertes Konto, d. h. der Anbieter kann Sicherheitsverletzungen verursachen, wenn der Identitätswechsel für Benutzeranforderungen nicht korrekt ausgeführt wird.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Kritisch Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 19/02/2015 09:08:22
Type: Kritisch Category: 64
Event: 10111 Source: Microsoft-Windows-DriverFrameworks-UserMode
Das Gerät "TouchStrip Fingerprint Sensor (WBF advanced mode)" (Ort "Port_#0001.Hub_#0003") ist aufgrund eines Ausfalls eines Benutzermodustreibers offline. Ein Neustart des Geräts wird 5 Mal versucht. Weitere Informationen zu diesem Problem erhalten Sie beim Gerätehersteller.

Log: 'System' Date/Time: 19/02/2015 09:08:22
Type: Kritisch Category: 64
Event: 10110 Source: Microsoft-Windows-DriverFrameworks-UserMode
Bei mindestens einem Benutzermodustreiber ist ein Problem aufgetreten, und der Hostprozess wurde beendet. Möglicherweise können Sie vorübergehend nicht auf die Geräte zugreifen.

Log: 'System' Date/Time: 09/02/2015 14:04:53
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

Log: 'System' Date/Time: 09/02/2015 11:40:32
Type: Kritisch Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
Das System wurde neu gestartet, ohne dass es zuvor ordnungsgemäß heruntergefahren wurde. Dieser Fehler kann auftreten, wenn das System nicht mehr reagiert hat oder abgestürzt ist oder die Stromzufuhr unerwartet unterbrochen wurde.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Fehler Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 19/02/2015 10:43:20
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "PDFProFiltSrv" wurde aufgrund folgenden Fehlers nicht gestartet:  Das System kann die angegebene Datei nicht finden.

Log: 'System' Date/Time: 19/02/2015 10:43:20
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden Fehlers nicht gestartet:  Das System kann die angegebene Datei nicht finden.

Log: 'System' Date/Time: 19/02/2015 10:43:20
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:  Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Log: 'System' Date/Time: 19/02/2015 10:43:20
Type: Fehler Category: 0
Event: 7009 Source: Service Control Manager
Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht.

Log: 'System' Date/Time: 19/02/2015 09:14:40
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet:  Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Log: 'System' Date/Time: 19/02/2015 09:14:40
Type: Fehler Category: 0
Event: 7009 Source: Service Control Manager
Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.

Log: 'System' Date/Time: 19/02/2015 09:08:42
Type: Fehler Category: 0
Event: 7034 Source: Service Control Manager
Dienst "Windows-Biometriedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Log: 'System' Date/Time: 18/02/2015 08:11:55
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "PDFProFiltSrv" wurde aufgrund folgenden Fehlers nicht gestartet:  Das System kann die angegebene Datei nicht finden.

Log: 'System' Date/Time: 18/02/2015 08:11:55
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden Fehlers nicht gestartet:  Das System kann die angegebene Datei nicht finden.

Log: 'System' Date/Time: 18/02/2015 08:11:55
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:  Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Log: 'System' Date/Time: 18/02/2015 08:11:55
Type: Fehler Category: 0
Event: 7009 Source: Service Control Manager
Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht.

Log: 'System' Date/Time: 18/02/2015 08:04:32
Type: Fehler Category: 0
Event: 7011 Source: Service Control Manager
Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst AntiVirSchedulerService erreicht.

Log: 'System' Date/Time: 18/02/2015 08:04:33
Type: Fehler Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
Der Server "{F9717507-6651-4EDB-BFF7-AE615179BCCF}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Log: 'System' Date/Time: 18/02/2015 08:04:33
Type: Fehler Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
Der Server "{9F070738-F6EA-408A-A6BD-AED405E67A13}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Log: 'System' Date/Time: 18/02/2015 08:04:33
Type: Fehler Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
Der Server "{674F4516-C91C-4C3E-AC1F-6FCF9861E7CD}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Log: 'System' Date/Time: 18/02/2015 08:04:32
Type: Fehler Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
Der Server "{1A1F4206-0688-4E7F-BE03-D82EC69DF9A5}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Log: 'System' Date/Time: 17/02/2015 01:34:59
Type: Fehler Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
Der Server "{F9717507-6651-4EDB-BFF7-AE615179BCCF}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Log: 'System' Date/Time: 16/02/2015 17:09:08
Type: Fehler Category: 0
Event: 36 Source: volsnap
Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Log: 'System' Date/Time: 16/02/2015 15:34:28
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "PDFProFiltSrv" wurde aufgrund folgenden Fehlers nicht gestartet:  Das System kann die angegebene Datei nicht finden.

Log: 'System' Date/Time: 16/02/2015 15:34:28
Type: Fehler Category: 0
Event: 7000 Source: Service Control Manager
Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden Fehlers nicht gestartet:  Das System kann die angegebene Datei nicht finden.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Informationen Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 19/02/2015 12:17:46
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "TCP/IP-NetBIOS-Hilfsdienst" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 19/02/2015 12:17:44
Type: Informationen Category: 0
Event: 1 Source: Microsoft-Windows-Power-Troubleshooter
Das System wurde aus dem Energiesparmodus reaktiviert.  Zeit im Energiesparmodus: ?2015?-?02?-?19T11:15:39.567067100Z Reaktivierungszeit: ?2015?-?02?-?19T12:17:42.964140900Z  Reaktivierungsquelle: Unbekannt

Log: 'System' Date/Time: 19/02/2015 12:17:44
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Adobe Flash Player Update Service" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 19/02/2015 12:17:44
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Adobe Flash Player Update Service" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 19/02/2015 12:17:43
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Windows-Bilderfassung (WIA)" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 19/02/2015 12:17:42
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Intel(R) System Behavior Tracker Collector Service" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 19/02/2015 12:17:42
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Diagnosesystemhost" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 19/02/2015 12:17:40
Type: Informationen Category: 0
Event: 1 Source: Microsoft-Windows-Kernel-General
Die Systemzeit wurde von ?2015?-?02?-?19T11:15:49.335625800Z auf ?2015?-?02?-?19T12:17:40.500000000Z geändert.

Log: 'System' Date/Time: 19/02/2015 11:15:47
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "TCP/IP-NetBIOS-Hilfsdienst" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 19/02/2015 11:15:47
Type: Informationen Category: 0
Event: 7042 Source: Service Control Manager
Der Steuerbefehl "beenden" wurde erfolgreich an den Dienst "TCP/IP-NetBIOS-Hilfsdienst" gesendet.    Angegebene Ursache: 0x40030011 [Betriebssystem: Netzwerkkonnektivität (Geplant)]  Kommentar: Kein

Log: 'System' Date/Time: 19/02/2015 11:15:47
Type: Informationen Category: 64
Event: 42 Source: Microsoft-Windows-Kernel-Power
Das System wird in den Standbymodus versetzt.  Grund: Das System ist inaktiv.

Log: 'System' Date/Time: 19/02/2015 11:15:42
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Windows-Bilderfassung (WIA)" befindet sich jetzt im Status "Angehalten".

Log: 'System' Date/Time: 19/02/2015 11:15:41
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Intel(R) System Behavior Tracker Collector Service" befindet sich jetzt im Status "Angehalten".

Log: 'System' Date/Time: 19/02/2015 11:13:52
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Office Software Protection Platform" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 19/02/2015 11:08:21
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Anwendungserfahrung" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 19/02/2015 11:03:49
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Office Software Protection Platform" befindet sich jetzt im Status "Ausgeführt".

Log: 'System' Date/Time: 19/02/2015 11:00:09
Type: Informationen Category: 0
Event: 6013 Source: EventLog
Die aktive Systemzeit ist 1022 Sekunden.

Log: 'System' Date/Time: 19/02/2015 10:57:42
Type: Informationen Category: 0
Event: 7036 Source: Service Control Manager
Dienst "Windows Modules Installer" befindet sich jetzt im Status "Beendet".

Log: 'System' Date/Time: 19/02/2015 10:57:42
Type: Informationen Category: 0
Event: 7040 Source: Service Control Manager
Der Starttyp des Diensts "Windows Modules Installer" wurde von AuXXXatisch starten in Manuell starten geändert.

Log: 'System' Date/Time: 19/02/2015 10:57:42
Type: Informationen Category: 0
Event: 7040 Source: Service Control Manager
Der Starttyp des Diensts "Windows Modules Installer" wurde von Manuell starten in AuXXXatisch starten geändert.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warnung Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 19/02/2015 12:17:42
Type: Warnung Category: 0
Event: 27 Source: e1kexpress
Intel(R) 82577LC Gigabit Network Connection  Network link has been disconnected.

Log: 'System' Date/Time: 19/02/2015 10:43:17
Type: Warnung Category: 0
Event: 27 Source: e1kexpress
Intel(R) 82577LC Gigabit Network Connection  Network link has been disconnected.

Log: 'System' Date/Time: 19/02/2015 10:43:14
Type: Warnung Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
Fehler beim Laden des Treibers \Driver\WUDFRd für das Gerät USB\VID_147E&PID_1001\6&35c0b730&0&1.

Log: 'System' Date/Time: 19/02/2015 10:42:47
Type: Warnung Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
Der Dienst für die auXXXatische WLAN-Konfiguration wurde erfolgreich beendet.

Log: 'System' Date/Time: 19/02/2015 10:42:47
Type: Warnung Category: 0
Event: 10002 Source: Microsoft-Windows-WLAN-AutoConfig
Das WLAN-Erweiterungsmodul wurde beendet.  Modulpfad: C:\Windows\System32\IWMSSvc.dll

Log: 'System' Date/Time: 19/02/2015 08:58:49
Type: Warnung Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Zeitüberschreitung bei der Namensauflösung für den Namen isatap.rw.local, nachdem keiner der konfigurierten DNS-Server geantwortet hat.

Log: 'System' Date/Time: 19/02/2015 08:58:43
Type: Warnung Category: 0
Event: 27 Source: e1kexpress
Intel(R) 82577LC Gigabit Network Connection  Network link has been disconnected.

Log: 'System' Date/Time: 18/02/2015 13:14:29
Type: Warnung Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Zeitüberschreitung bei der Namensauflösung für den Namen isatap.fritz.box, nachdem keiner der konfigurierten DNS-Server geantwortet hat.

Log: 'System' Date/Time: 18/02/2015 13:14:21
Type: Warnung Category: 0
Event: 27 Source: e1kexpress
Intel(R) 82577LC Gigabit Network Connection  Network link has been disconnected.

Log: 'System' Date/Time: 18/02/2015 09:03:40
Type: Warnung Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Zeitüberschreitung bei der Namensauflösung für den Namen video55.fra01.hls.twitch.tv, nachdem keiner der konfigurierten DNS-Server geantwortet hat.

Log: 'System' Date/Time: 18/02/2015 08:11:52
Type: Warnung Category: 0
Event: 27 Source: e1kexpress
Intel(R) 82577LC Gigabit Network Connection  Network link has been disconnected.

Log: 'System' Date/Time: 18/02/2015 08:11:49
Type: Warnung Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
Fehler beim Laden des Treibers \Driver\WUDFRd für das Gerät USB\VID_147E&PID_1001\6&35c0b730&0&1.

Log: 'System' Date/Time: 18/02/2015 08:11:21
Type: Warnung Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
Der Dienst für die auXXXatische WLAN-Konfiguration wurde erfolgreich beendet.

Log: 'System' Date/Time: 18/02/2015 08:11:21
Type: Warnung Category: 0
Event: 10002 Source: Microsoft-Windows-WLAN-AutoConfig
Das WLAN-Erweiterungsmodul wurde beendet.  Modulpfad: C:\Windows\System32\IWMSSvc.dll

Log: 'System' Date/Time: 18/02/2015 08:05:13
Type: Warnung Category: 0
Event: 1073 Source: USER32
Der Versuch von Benutzer XXXYYY-VAIO\XXX YYY, Computer XXXYYY-VAIO neu zu starten bzw. herunterzufahren ist fehlgeschlagen.

Log: 'System' Date/Time: 18/02/2015 08:04:41
Type: Warnung Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Zeitüberschreitung bei der Namensauflösung für den Namen dns.msftncsi.com, nachdem keiner der konfigurierten DNS-Server geantwortet hat.

Log: 'System' Date/Time: 18/02/2015 08:04:34
Type: Warnung Category: 0
Event: 27 Source: e1kexpress
Intel(R) 82577LC Gigabit Network Connection  Network link has been disconnected.

Log: 'System' Date/Time: 17/02/2015 07:39:16
Type: Warnung Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Zeitüberschreitung bei der Namensauflösung für den Namen teredo.ipv6.microsoft.com, nachdem keiner der konfigurierten DNS-Server geantwortet hat.

Log: 'System' Date/Time: 17/02/2015 07:39:09
Type: Warnung Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Zeitüberschreitung bei der Namensauflösung für den Namen isatap.fritz.box, nachdem keiner der konfigurierten DNS-Server geantwortet hat.

Log: 'System' Date/Time: 17/02/2015 07:39:07
Type: Warnung Category: 0
Event: 27 Source: e1kexpress
Intel(R) 82577LC Gigabit Network Connection  Network link has been disconnected.


Warlord711 19.02.2015 13:49

Ok, während ich das Log anschaue, hast du denn mal die Anweisung zu Chrome durchgeführt ? Lt. Farbar soll die neueste FRST Version von gestern auch auf deinem Rechner laufen ;-)

Warlord711 19.02.2015 14:07

Kannst du wg. dem Drucker mal folgendes deaktivieren:
  • Start\Systemsteuerung\Netzwerk und Internet\Netzwerk- und Freigabecenter, dort dann auf Erweiterte Freigabeeinstellungen ändern klicken
  • Beim Punkt "Netzwerkerkennung" die Option auf Netzwerkerkennung ausschalten umstellen

Und dann schauen ob das Verhalten sich ändert.

LarryPerkins 19.02.2015 16:19

HA! Es klappt tatsächlich.
Netzwerkfreigabe war ausgeschaltet... hab aber das von den Druckern auch deaktiviert.

Hier also endlich das Addition:

Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-02-2015 01
Ran by XXX YYY at 2015-02-19 16:15:52
Running from C:\Users\XXX YYY\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7 Grand Steps, Step 1: What Ancients Begat (HKLM-x32\...\Steam App 238930) (Version:  - Mousechief)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.110 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Apowersoft kostenloser Bildschirmrekorder V1.4.0 (HKLM-x32\...\{4EFA42DB-E4EC-4537-9DF3-5158D08A9785}_is1) (Version: 1.4.0 - APOWERSOFT LIMITED)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft WebCam Companion 3 (HKLM-x32\...\{DE8AAC73-6D8D-483E-96EA-CAEDDADB9079}) (Version: 3.0.21.368 - ArcSoft)
Audials (HKLM-x32\...\{D928A4B7-126D-47B6-AD76-9848E51E1426}) (Version: 10.2.14807.700 - Audials AG)
Avira (HKLM-x32\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG)
Avira (x32 Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira)
Bad Hotel (HKLM-x32\...\Steam App 231720) (Version:  - Lucky Frame)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bejeweled 2 Deluxe (HKLM-x32\...\Steam App 3300) (Version:  - PopCap Games, Inc.)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.3868 - CDBurnerXP)
Chainsaw Warrior (HKLM-x32\...\Steam App 251710) (Version:  - Auroch Digital)
Choice of the Deathless (HKLM-x32\...\Steam App 318310) (Version:  - Choice of Games)
Chuzzle Deluxe (HKLM-x32\...\Steam App 3310) (Version:  - PopCap Games, Inc.)
Cinders (HKLM-x32\...\Steam App 293680) (Version:  - MoaCube)
Cisco WebEx Meetings (HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Citrix Online Launcher (HKLM-x32\...\{AC7E7905-8C59-4806-A96D-30936A2B1FC5}) (Version: 1.0.168 - Citrix)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Darkest Dungeon (HKLM-x32\...\Steam App 262060) (Version:  - Red Hook Studios)
Dead Man's Draw (HKLM-x32\...\Steam App 262450) (Version:  - Stardock Entertainment)
Death Skid Marks (HKLM-x32\...\Steam App 326150) (Version:  - Studio Whisky Tango Inc.)
Deinst. f. Druckertreiber UFR II (HKLM\...\Canon UFR II Printer Driver) (Version: 5, 4, 0, 0 - Canon Inc.)
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.3.80 - DivX, LLC)
Dropbox (HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Evernote (HKLM-x32\...\{F761359C-9CED-45AE-9A51-9D6605CD55C4}) (Version: 3.5.4.2224 - Evernote Corp.)
FastStone Capture 5.3 (HKLM-x32\...\FastStone Capture) (Version: 5.3 - FastStone Soft)
Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Frozen Synapse (HKLM-x32\...\Steam App 98200) (Version:  - Mode 7)
FTL: Faster Than Light (HKLM-x32\...\Steam App 212680) (Version:  - Subset Games)
Gods Will Be Watching (HKLM-x32\...\Steam App 274290) (Version:  - Deconstructeam)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.111 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
GoXXXeeting 6.0.0.1259 (HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\GoXXXeeting) (Version: 6.0.0.1259 - CitrixOnline)
Helium (HKLM-x32\...\{9A781940-AC41-4D5E-8E1E-76A04B916FB9}) (Version: 1.0.0 - ClockworkMod)
Hotline Miami (HKLM-x32\...\Steam App 219150) (Version:  - Dennaton Games)
HP Deskjet 3050 J610 series - Grundlegende Software für das Gerät (HKLM\...\{EF3293DE-FCAC-4742-91BF-AD0174143FC3}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050 J610 series Hilfe (HKLM-x32\...\{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}) (Version: 140.0.63.63 - Hewlett Packard)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
iMindMap 6 (HKLM-x32\...\{C5711BC2-2E1C-4556-9922-02BF2865A5EE}) (Version: 6.0.617 - ThinkBuzan)
Insaniquarium! Deluxe (HKLM-x32\...\Steam App 3320) (Version:  - PopCap Games, Inc.)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi-Software (HKLM\...\{D16A2127-B927-4379-B153-3DEC091E4EEB}) (Version: 13.02.1000 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.0.1014 - Intel Corporation)
Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.00.01.1002 - Intel Corporation)
Internet Manager (HKLM-x32\...\Internet Manager) (Version: 22.001.18.68.55 - Huawei Technologies Co.,Ltd)
Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle)
julitecCRM 7.5 (HKLM-x32\...\julitecCRM_is1) (Version:  - )
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Kentucky Route Zero (HKLM-x32\...\Steam App 231200) (Version:  - Cardboard Computer)
Long Live The Queen (Demo) 1.0 (HKLM-x32\...\Long Live The Queen_is1) (Version:  - Hanako Games)
LUFTRAUSERS (HKLM-x32\...\Steam App 233150) (Version:  - Vlambeer)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Lync Web App Plug-in (HKLM\...\{6619085B-A9D5-4DDD-800B-964903EAF546}) (Version: 15.8.8308.726 - Microsoft Corporation)
Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 15.0.4675.1003 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Monster Loves You! (HKLM-x32\...\Steam App 226740) (Version:  - Radial Games Corp)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 31.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.4.0 (x86 de)) (Version: 31.4.0 - Mozilla)
No23 Recorder (HKLM-x32\...\{22B0E143-2B0B-435B-9F56-136A3D16065F}) (Version: 2.1.0.3 - No23)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.61.39 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC)
Papers, Please (HKLM-x32\...\Steam App 239030) (Version:  - 3909)
Pixel Piracy (HKLM-x32\...\Steam App 264140) (Version:  - Vitali Kirpu)
Plants vs. Zombies: Game of the Year (HKLM-x32\...\Steam App 3590) (Version:  - PopCap Games, Inc.)
Plush (HKLM-x32\...\Steam App 341820) (Version:  - Red Head Games)
Protector Suite 2009 (HKLM\...\{0F841121-4DB6-4B31-839F-7F5AB3BB3423}) (Version: 5.9.3.6321 - UPEK Inc.)
Psy High (HKLM-x32\...\Steam App 339510) (Version:  - Choice of Games)
Puzzle Quest (HKLM-x32\...\Steam App 12500) (Version:  - D3)
Qualcomm Gobi 2000 Package for Sony (HKLM-x32\...\{1F4E59C0-EE31-47EE-BCC3-1A73C3F023BF}) (Version: 1.1.160 - QUALCOMM)
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
RaidCall (HKLM-x32\...\RaidCall) (Version: 7.2.4-1.0.7299.14 - raidcall.com)
Razer Core (HKLM-x32\...\Razer Core) (Version: 1.0.1.66 - Razer Inc)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.19.23944 - Razer Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6028 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
SharpKeys (HKLM-x32\...\{636E94DA-99C0-448F-A931-3DAD83B4975F}) (Version: 3.5.0000 - RandyRants.com)
simfy (HKLM-x32\...\Simfy) (Version: 1.7.6 - simfy AG)
simfy (x32 Version: 1.7.6 - simfy AG) Hidden
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Sokobond (HKLM-x32\...\Steam App 290260) (Version:  - Alan Hazelden)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.16.0 - Synaptics Incorporated)
TBBackup 2 (Freiversion) (HKLM-x32\...\DED9B6BE-2B04-4799-A88F-8BBF4D114AAF_is1) (Version: 2 - Priotecs IT GmbH)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.28223 - TeamViewer)
The Bridge (HKLM-x32\...\Steam App 204240) (Version:  - Ty Taylor and Mario Castañeda)
Thieves' Gambit: Curse of the Black Cat (HKLM-x32\...\Steam App 328550) (Version:  - Choice of Games)
Thirty Flights of Loving (HKLM-x32\...\Steam App 214700) (Version:  - Blendo Games)
Tinypic 3.18 (HKLM-x32\...\{E3723A04-A894-4036-A78E-282E18F43C0A}_is1) (Version: Tinypic 3.18 - E. Fiedler)
TOP (HKLM\...\TOP) (Version: 2.1.1.0 - mediMACH GmbH & Co. KG)
TreeSize Free V2.7 (HKLM-x32\...\TreeSize Free_is1) (Version: 2.7 - JAM Software)
Uplink (HKLM-x32\...\Steam App 1510) (Version:  - Introversion Software)
VAIO Care (HKLM\...\{D9FFE40D-1A85-4541-992C-5EF505F391A4}) (Version: 8.4.2.12041 - Sony Corporation)
VAIO Care Recovery (HKLM\...\{6ED1750E-F44F-4635-8F0D-B76B9262B7FB}) (Version: 1.1.1.13230 - Sony Corporation)
VAIO Control Center (HKLM-x32\...\{72042FA6-5609-489F-A8EA-3C2DD650F667}) (Version: 4.3.0.05310 - Sony Corporation)
VAIO Data Restore Tool (HKLM-x32\...\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}) (Version: 1.4.0.05240 - Sony Corporation)
VAIO Data Restore Tool (x32 Version: 1.4.0.05240 - Sony Corporation) Hidden
VAIO Gate (HKLM-x32\...\{A7C30414-2382-4086-B0D6-01A88ABA21C3}) (Version: 2.2.0.06080 - Sony Corporation)
VAIO Gate Default (HKLM-x32\...\{B7546697-2A80-4256-A24B-1C33163F535B}) (Version: 2.2.0.07020 - Sony Corporation)
VAIO Hardware Diagnostics (x32 Version: 4.0.0.06230 - Sony Corporation) Hidden
VAIO Marketing Tools (HKLM-x32\...\MarketingTools) (Version:  - Sony Corporation)
VAIO screensaver (HKLM-x32\...\VAIO screensaver) (Version: 1.0.0.0 - Sony Europe)
VAIO Smart Network (HKLM-x32\...\{0899D75A-C2FC-42EA-A702-5B9A5F24EAD5}) (Version: 3.3.1.08110 - Sony Corporation)
VAIO Update (HKLM-x32\...\{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}) (Version: 7.0.1.02280 - Sony Corporation)
VAIO-Handbuch (HKLM-x32\...\{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}) (Version: 1.1.0.05280 - Sony Corporation)
VAIO-Support für Übertragungen (HKLM-x32\...\{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}) (Version: 1.2.0.06230 - Sony Corporation)
Valiant Hearts: The Great War™ / Soldats Inconnus : Mémoires de la Grande Guerre™ (HKLM-x32\...\Steam App 260230) (Version:  - Ubisoft Montpellier)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Vodafone Mobile Broadband (HKLM-x32\...\{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}) (Version: 10.0.300.23587 - Vodafone)
VTech Download Agent Library (x32 Version: 1.00.0000 - VTech) Hidden
VTech Download Manager (HKLM-x32\...\VTechDownloadManager) (Version:  - VTech)
VU5x64 (Version: 1.1.0 - Sony Corporation ) Hidden
VU5x86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden
VU5x86 (x32 Version: 1.1.0 - Sony Corporation ) Hidden
WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.5600 - Broadcom Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation)
WinRAR 5.01 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.1 - win.rar GmbH)
Wondershare Dr.Fone for Android(Build 4.8.1.136) (HKLM-x32\...\{1DB91A95-C548-4BA5-9D4C-18C7DEAAC39F}_is1) (Version: 4.8.1.136 - Wondershare Software Co.,Ltd.)
World of Goo (HKLM-x32\...\Steam App 22000) (Version:  - 2D BOY)
XnView 2.22 (HKLM-x32\...\XnView_is1) (Version: 2.22 - Gougelet Pierre-e)

==================== CusXXX CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\XXX YYY\AppData\Local\Citrix\GoXXXeeting\1259\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)

==================== Restore Points  =========================

17-02-2015 00:15:44 Geplanter Prüfpunkt

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2015-02-16 16:28 - 00000855 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {07003042-FCBF-4E03-9084-D7217B6EC518} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated)
Task: {0F0A4936-B027-44CB-B669-5B9F92B3F192} - System32\Tasks\SONY\VAIO Power Management\VPM Logon Start => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {0FDA89CB-57A1-40E2-9EA8-C4433EDA0076} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2014-02-28] (Sony Corporation)
Task: {187BF442-5A85-44DE-9CC7-0241C7AC7642} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe
Task: {1A5ED98B-E26E-4F78-8E49-5AAF4F656B37} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-28] (Google Inc.)
Task: {1FA704D2-62BF-43D6-840A-2D4F9786E076} - System32\Tasks\SONY\SUS-BCF\Level4Month => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {2CE11264-F006-4465-8975-FA2EA0245B3D} - System32\Tasks\SONY\SUS-BCF\Level4Daily => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {2D0606BE-BE7B-4C6F-942C-07B45CBB4D01} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {367F27E4-A729-4EB5-80C6-6B08FE47DB1F} - System32\Tasks\Sony Corporation\VAIO Care\GetPOTInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {402882DC-CDFE-49E2-A954-3F809F37851D} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {413513C7-60B9-4045-8171-6A8D9EBDD495} - System32\Tasks\Sony Corporation\VAIO Care\VCCheckIolo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {568B3CF3-0B50-4A11-9478-284D3A055670} - System32\Tasks\SONY\VAIO Power Management\VPM Unlock => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {576BD409-939A-4F67-B3ED-0E82591D6BF3} - System32\Tasks\Sony Corporation\VAIO Care\ActiveStatusCollect => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {61B8DD12-39BF-4BBF-B084-8F92D5F3A324} - System32\Tasks\Sony Corporation\VAIO Care\VCMetrics => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {8064F21C-7DCF-4763-9DBF-7722C2057EC9} - System32\Tasks\Microsoft\Office\Office AuXXXatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-11-04] (Microsoft Corporation)
Task: {80EF32D9-20FD-4C21-9265-C33EBCE1A4FD} - System32\Tasks\Sony Corporation\VAIO Care\VCRLog => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {81A39738-5497-488C-8C74-6567DD8AAD4B} - System32\Tasks\Sony Corporation\VAIO Care\VCSelfHeal => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {85FB3BD6-50D8-4849-9EBA-D1986B341972} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-11-12] (Microsoft Corporation)
Task: {888841F4-9762-4C71-B89D-B7EDB973865A} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2014-03-01] (Sony Corporation)
Task: {89E6205E-831F-4B74-BF7B-3026B6E6B365} - System32\Tasks\Sony Corporation\VAIO Care\CheckSystemInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {941F4092-FB9C-45CD-A9C2-B169B06301AE} - System32\Tasks\Sony Corporation\VAIO Care\UpdateSolution => C:\Program Files\Sony\VAIO Care\Solution.Updater.exe [2014-12-03] (Sony Corporation)
Task: {9F25FF11-44D1-4805-9E91-03529AA0C68C} - System32\Tasks\USER_ESRV_SVC => Wscript.exe //B //NoLogo "C:\Program Files\Sony\VAIO Care\ESRV\task.vbs"
Task: {B770129E-F306-434C-B31D-A16B84710116} - System32\Tasks\SONY\VAIO Power Management\VPM Session Change => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {BDDACF5E-FAE8-4757-B563-36FD9129FE8B} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {C8E76728-2150-4BA0-B8A4-312038C6D67C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-28] (Google Inc.)
Task: {C9569DB7-51E7-4271-825E-5D767A82801B} - System32\Tasks\SONY\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2010-06-08] (Sony Corporation)
Task: {CDEE1781-E40E-48A6-AF87-12F74E527282} - System32\Tasks\Sony Corporation\VAIO Care\UploadPOT => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {D82BD1C7-8232-4603-BFFC-6C038A5B5C53} - System32\Tasks\Sony Corporation\VAIO Care\DeployCRMflag => C:\Program Files\Sony\VAIO Care\DeployCRMflag.exe [2014-01-16] (Sony Corporation)
Task: {DBB38736-AA50-4AD2-9F1F-C2365E1C0309} - System32\Tasks\Microsoft Office 15 Sync Maintenance for XXXYYY-VAIO-XXX YYY XXXYYY-VAIO => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2014-11-04] (Microsoft Corporation)
Task: {E0069895-C592-4682-9B56-15AF40694CCF} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {E21FD473-244F-4C5F-A416-6E806AADD30D} - System32\Tasks\{AA8032E1-7990-40E7-9D86-A05BAD4EA3DB} => pcalua.exe -a "C:\Program Files (x86)\QT Lite\QTSystem\quicktime.cpl"
Task: {EA1DFED2-7347-45D2-9332-8F46642B0487} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2010-06-08] (Sony Corporation)
Task: {EAB4BD7C-A20A-4956-B70F-B8FB3C9F2A3C} - System32\Tasks\SONY\VAIO Wallpaper Setting Tool\VAIO Wallpaper Setting Tool => C:\Program Files (x86)\Sony\VAIO Wallpaper Setting Tool\VWSet.exe
Task: {F8544C8C-401A-4588-9992-5F23AC4E6FD4} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2010-03-05 09:21 - 2010-03-05 09:21 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2014-05-02 11:19 - 2014-05-20 08:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2011-03-14 16:27 - 2011-03-14 16:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe
2013-09-17 18:11 - 2011-06-17 12:04 - 00224096 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
2014-12-09 23:22 - 2014-12-09 23:22 - 00186048 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2007-02-12 20:51 - 2007-02-12 20:51 - 01111552 _____ () C:\Program Files (x86)\FastStone Capture\FSCapture.exe
2014-01-10 06:26 - 2014-01-10 06:26 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2014-10-13 02:49 - 2014-06-20 07:42 - 00401280 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
2013-10-02 09:38 - 2011-06-17 12:04 - 01434464 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe
2013-11-01 14:59 - 2013-11-01 14:59 - 00062464 _____ () C:\Program Files\Sony\VAIO Care\listener.exe
2013-09-17 18:11 - 2009-01-10 11:32 - 00011362 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll
2013-09-17 18:11 - 2009-06-22 19:42 - 00043008 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll
2013-09-17 18:11 - 2010-05-05 09:47 - 02415104 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll
2013-09-17 18:11 - 2010-02-10 15:10 - 01148416 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll
2013-03-19 16:48 - 2010-05-31 19:18 - 00013824 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll
2013-03-19 16:48 - 2010-05-31 19:18 - 00013312 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSubPS.dll
2013-03-25 13:23 - 2014-11-11 19:47 - 00774656 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-01-24 19:33 - 2014-12-02 01:29 - 05002752 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-01-24 19:33 - 2014-12-02 01:29 - 01612800 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-01-24 19:33 - 2014-12-02 01:29 - 01210368 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2014-05-22 22:02 - 2015-02-19 00:51 - 02360000 _____ () C:\Program Files (x86)\Steam\video.dll
2014-08-29 09:13 - 2014-12-01 22:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2014-08-29 09:13 - 2014-12-01 22:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2014-08-29 09:13 - 2014-12-01 22:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2014-08-29 09:13 - 2014-12-01 22:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2014-08-29 09:13 - 2014-12-01 22:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2013-03-29 10:53 - 2015-02-19 00:51 - 00702656 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2014-09-25 11:37 - 2014-09-25 11:37 - 00081056 _____ () C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\LoggingPlatform.dll
2014-09-25 11:37 - 2014-09-25 11:37 - 00081056 _____ () C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\LoggingPlatform.DLL
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2015-02-10 22:00 - 2015-02-10 22:00 - 00750080 _____ () C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-02-19 11:43 - 2015-02-19 11:43 - 00043008 _____ () c:\Users\XXX YYY\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp6av0gr.dll
2015-02-10 22:00 - 2015-02-10 22:00 - 00047616 _____ () C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-02-10 22:00 - 2015-02-10 22:00 - 00865280 _____ () C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-02-10 22:00 - 2015-02-10 22:00 - 00200704 _____ () C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2009-07-13 22:03 - 2009-07-14 02:15 - 00364544 _____ () C:\Windows\SysWOW64\msjetoledb40.dll
2013-03-19 16:51 - 2013-03-19 16:51 - 00054784 _____ () C:\Program Files (x86)\Sony\Marketing Tools\Win32Interop.dll
2014-01-10 06:28 - 2014-01-10 06:28 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2014-10-13 02:49 - 2014-03-04 12:20 - 00117760 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll
2014-10-13 02:49 - 2014-04-22 03:14 - 00065536 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpServer.dll
2014-10-13 02:49 - 2014-05-06 06:39 - 00861184 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\platforms\qwindows.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00021504 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qgif.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00020992 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qico.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00204800 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qjpeg.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00218112 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qmng.dll
2014-10-13 02:49 - 2014-05-06 06:58 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qsvg.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00015360 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtga.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00307712 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtiff.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00014848 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qwbmp.dll
2014-10-13 02:49 - 2014-05-06 07:31 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\sensors\qtsensors_dummy.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00036352 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qgenericbearer.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00038912 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qnativewifibearer.dll
2013-03-26 15:16 - 2015-01-28 02:30 - 34641288 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2014-09-26 15:48 - 2014-11-18 14:08 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll
2015-01-29 14:05 - 2015-01-29 14:05 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2015-01-17 18:47 - 2015-01-17 18:47 - 03347056 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2015-01-17 18:47 - 2015-01-17 18:47 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2015-01-17 18:47 - 2015-01-17 18:47 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2014-12-08 18:04 - 2014-12-08 18:04 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\3d576cbc4ffc5ad06fd61510c5d8f326\IsdiInterop.ni.dll
2010-07-19 21:49 - 2010-03-04 04:08 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-09-17 18:11 - 2010-02-10 15:43 - 09515520 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtGui4.dll
2013-10-02 09:38 - 2012-10-08 02:41 - 00082944 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\plugins\imageformats\qgif4.dll
2013-10-02 09:38 - 2012-10-08 02:41 - 00081920 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\plugins\imageformats\qico4.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:7C784982

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no auXXXatic fix for this section.)

HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.178.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no auXXXatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-3557091032-3563988234-1886976076-500 - Administrator - Disabled)
Gast (S-1-5-21-3557091032-3563988234-1886976076-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3557091032-3563988234-1886976076-1002 - Limited - Enabled)
XXX YYY (S-1-5-21-3557091032-3563988234-1886976076-1000 - Administrator - Enabled) => C:\Users\XXX YYY

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/19/2015 11:48:42 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/19/2015 11:48:42 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/19/2015 11:48:42 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/19/2015 11:43:23 AM) (Source: Avira Service Host) (EventID: 0) (User: )
Description: Fehler beim Verarbeiten von Sitzungsänderung. System.NullReferenceException: Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt.
  bei Avira.OE.ServiceHost.ServiceHost.OnSessionChange(SessionChangeDescription changeDescription)
  bei System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)

Error: (02/19/2015 11:42:40 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: VCAgent.exe, Version: 8.4.2.12030, Zeitstempel: 0x5476d099
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000007fe9331aa71
ID des fehlerhaften Prozesses: 0x1d50
Startzeit der fehlerhaften Anwendung: 0xVCAgent.exe0
Pfad der fehlerhaften Anwendung: VCAgent.exe1
Pfad des fehlerhaften Moduls: VCAgent.exe2
Berichtskennung: VCAgent.exe3

Error: (02/19/2015 11:42:38 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: VCAgent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
  bei VCAgent.View.MainWindow.WindowProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei System.Windows.Interop.HwndSource.PublicHooksFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
  bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
  bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
  bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.DefWndProcWrapper(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.GetMessage(System.Windows.Interop.MSG ByRef, IntPtr, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
  bei System.Windows.Application.RunInternal(System.Windows.Window)
  bei System.Windows.Application.Run()
  bei VCAgent.App.Main()

Error: (02/19/2015 10:48:58 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/19/2015 10:48:58 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/19/2015 10:08:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe_WbioSrvc, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc3c1
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x5315a05a
Ausnahmecode: 0x80004004
Fehleroffset: 0x000000000000940d
ID des fehlerhaften Prozesses: 0x1264
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe_WbioSrvc0
Pfad der fehlerhaften Anwendung: svchost.exe_WbioSrvc1
Pfad des fehlerhaften Moduls: svchost.exe_WbioSrvc2
Berichtskennung: svchost.exe_WbioSrvc3

Error: (02/18/2015 09:11:14 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: VCAgent.exe, Version: 8.4.2.12030, Zeitstempel: 0x5476d099
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000007fe9284aa71
ID des fehlerhaften Prozesses: 0x370
Startzeit der fehlerhaften Anwendung: 0xVCAgent.exe0
Pfad der fehlerhaften Anwendung: VCAgent.exe1
Pfad des fehlerhaften Moduls: VCAgent.exe2
Berichtskennung: VCAgent.exe3


System errors:
=============
Error: (02/19/2015 11:43:20 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "PDFProFiltSrv" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (02/19/2015 11:43:20 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (02/19/2015 11:43:20 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (02/19/2015 11:43:20 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht.

Error: (02/19/2015 10:14:40 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (02/19/2015 10:14:40 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.

Error: (02/19/2015 10:08:42 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Windows-Biometriedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (02/18/2015 09:11:55 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "PDFProFiltSrv" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (02/18/2015 09:11:55 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (02/18/2015 09:11:55 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053


Microsoft Office Sessions:
=========================
Error: (02/19/2015 11:48:42 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\XXX YYY\AppData\Local\join.me\join.me.exe

Error: (02/19/2015 11:48:42 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\XXX YYY\AppData\Local\join.me\join.me.exe

Error: (02/19/2015 11:48:42 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\XXX YYY\AppData\Local\join.me\join.me.exe

Error: (02/19/2015 11:43:23 AM) (Source: Avira Service Host) (EventID: 0) (User: )
Description: Fehler beim Verarbeiten von Sitzungsänderung. System.NullReferenceException: Der Objektverweis wurde nicht auf eine Objektinstanz festgelegt.
  bei Avira.OE.ServiceHost.ServiceHost.OnSessionChange(SessionChangeDescription changeDescription)
  bei System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)

Error: (02/19/2015 11:42:40 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: VCAgent.exe8.4.2.120305476d099unknown0.0.0.000000000c0000005000007fe9331aa711d5001d04b54180c070fC:\Program Files\Sony\VAIO Care\VCAgent.exeunknown06859bd1-b824-11e4-8007-0024bed7ff33

Error: (02/19/2015 11:42:38 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: VCAgent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
  bei VCAgent.View.MainWindow.WindowProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei System.Windows.Interop.HwndSource.PublicHooksFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
  bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
  bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
  bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.DefWndProcWrapper(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.GetMessage(System.Windows.Interop.MSG ByRef, IntPtr, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
  bei System.Windows.Application.RunInternal(System.Windows.Window)
  bei System.Windows.Application.Run()
  bei VCAgent.App.Main()

Error: (02/19/2015 10:48:58 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\XXX YYY\Downloads\esetsmartinstaller_deu(1).exe

Error: (02/19/2015 10:48:58 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\XXX YYY\Downloads\esetsmartinstaller_deu.exe

Error: (02/19/2015 10:08:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe_WbioSrvc6.1.7600.163854a5bc3c1KERNELBASE.dll6.1.7601.184095315a05a80004004000000000000940d126401d04b535cef8de8C:\Windows\system32\svchost.exeC:\Windows\system32\KERNELBASE.dlle599669c-b816-11e4-8007-0024bed7ff33

Error: (02/18/2015 09:11:14 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: VCAgent.exe8.4.2.120305476d099unknown0.0.0.000000000c0000005000007fe9284aa7137001d049feca3127c3C:\Program Files\Sony\VAIO Care\VCAgent.exeunknownb477e860-b745-11e4-bdba-0024bed7ff33


CodeIntegrity Errors:
===================================
  Date: 2015-02-09 21:07:05.858
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-02-09 21:07:05.655
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5 CPU M 460 @ 2.53GHz
Percentage of memory in use: 74%
Total physical RAM: 3765.82 MB
Available physical RAM: 972.47 MB
Total Pagefile: 7529.83 MB
Available Pagefile: 3634.45 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.17 GB) (Free:11.05 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: 720CB564)
Partition 1: (Not Active) - (Size=8 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=111.2 GB) - (Type=07 NTFS)

==================== End Of Log ============================


Und das FRST:


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2015 01
Ran by XXX YYY (administrator) on XXXYYY-VAIO on 19-02-2015 16:13:26
Running from C:\Users\XXX YYY\Desktop
Loaded Profiles: XXX YYY (Available profiles: XXX YYY)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvservice.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
(UPEK Inc.) C:\Program Files\Protector Suite\upeksvr.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(QUALCOMM, Inc.) C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(UPEK Inc.) C:\Program Files\Protector Suite\psqltray.exe
(Microsoft Corporation) C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files (x86)\FastStone Capture\FSCapture.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
(Sony Corporation) C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\csisyncclient.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
( ) C:\Users\XXX YYY\Desktop\VEW.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAdmin.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
() C:\Program Files\Sony\VAIO Care\listener.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Farbar) C:\Users\XXX YYY\Desktop\FRST64(1).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9962016 2010-06-18] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1886504 2010-03-01] (Synaptics Incorporated)
HKLM\...\Run: [PSQLLauncher] => C:\Program Files\Protector Suite\launcher.exe [84744 2010-04-27] (UPEK Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [673136 2010-05-31] (Sony Corporation)
HKLM-x32\...\Run: [MobileBroadband] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [253440 2010-05-18] (Vodafone)
HKLM-x32\...\Run: [MarketingTools] => C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [26624 2013-03-19] (Sony Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-11] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585536 2015-01-06] (Razer Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-08-19] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (UPEK Inc.)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2874048 2015-02-19] (Valve Corporation)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [SkyDrive] => C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [277672 2014-09-25] (Microsoft Corporation)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30879328 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [GoogleChromeAutoLaunch_550EDA027B4B11347618D98EDCBB3ADF] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592 2015-02-04] (Google Inc.)
Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk
ShortcutTarget: FastStone Capture.lnk -> C:\Program Files (x86)\FastStone Capture\FSCapture.exe ()
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [UEAFOverlay] -> {F2F31467-B1AC-4df0-AE79-FD5FA085E22B} => C:\Program Files\Protector Suite\farchns.dll (UPEK Inc.)
ShellIconOverlayIdentifiers: [UEAFOverlayOpen] -> {A3E208F7-0E3A-4182-A7A6-B169D5D691AA} => C:\Program Files\Protector Suite\farchns.dll (UPEK Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {3617BCD7-E991-4BB5-8542-09A0B20EE913} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {794C16B2-C354-42CB-8212-172F5BD771B6} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms}
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {A70EC677-F517-45E6-831A-E87104D7AC0B} URL = hxxp://de.shopping.com/?linkin_id=8056363
BHO: No Name -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} ->  No File
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} ->  No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{876E33B5-EE1E-4322-8F79-79EB6087A1E2}: [NameServer] 
Tcpip\..\Interfaces\{AA2DF348-6AB3-482F-A8BC-41E89158A468}: [NameServer] 10.74.210.210 10.74.210.211

FireFox:
========
FF ProfilePath: C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default
FF DefaultSearchEngine: Google
FF SelectedSearchEngine: Google
FF Homepage: www.google.de
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*'))%20%7B%20return%20'PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\Sony\MSS\3.8.130\npMcAfeeMss.dll No File
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\XXX YYY\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3557091032-3563988234-1886976076-1000: @citrixonline.com/appdetectorplugin -> C:\Users\XXX YYY\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin HKU\S-1-5-21-3557091032-3563988234-1886976076-1000: LWAPlugin15.8 -> C:\Users\XXX YYY\AppData\Roaming\Mozilla\Plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\XXX YYY\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\XXX YYY\AppData\Roaming\mozilla\plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\XXX YYY\AppData\Roaming\mozilla\plugins\npoctoshape.dll (Octoshape ApS)
FF SearchPlugin: C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\searchplugins\translate-korean-to-english.xml
FF Extension: ProxMate - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-08-09]
FF Extension: TinEye Reverse Image Search - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\tineye@ideeinc.com.xpi [2013-03-20]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor

Chrome:
=======
CHR HomePage: Default -> hxxp://google.de/
CHR StartupUrls: Default -> "hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=5ABA002710DD58F0&affID=119357&tsp=4958"
CHR Profile: C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (BetterTTV) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2014-10-30]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-16]
CHR Extension: (Avira Browser Safety) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-11]
CHR Extension: (Helium Backup) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpglbgbpeobllokpmeagpoagjbfknanl [2015-01-19]
CHR Extension: (Google Wallet) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-05]
CHR Profile: C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-26]
CHR Extension: (BetterTTV) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2015-01-26]
CHR Extension: (Google Docs) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-26]
CHR Extension: (Google Drive) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-26]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-26]
CHR Extension: (YouTube) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-26]
CHR Extension: (Google Search) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-26]
CHR Extension: (Google Sheets) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-26]
CHR Extension: (Avira Browser Safety) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-01-26]
CHR Extension: (Google Wallet) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-26]
CHR Extension: (Gmail) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-26]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
R2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [377768 2013-11-01] (Intel Corporation)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2011-06-17] ()
S3 McComponentHostServiceSony; C:\Program Files (x86)\Sony\MSS\3.8.130\McCHSvc.exe [235216 2013-10-16] (McAfee, Inc.)
R2 nvservice; C:\Windows\system32\nvservice.exe [192800 2013-02-04] (NVIDIA Corporation)
R2 QDLService2kSony; c:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe [332024 2010-06-03] (QUALCOMM, Inc.)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [186048 2014-12-09] ()
R2 RzOvlMon; C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe [32960 2014-04-18] (Razer, Inc.)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [266168 2013-11-01] (Intel Corporation)
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [741640 2014-06-16] (DEVGURU Co., LTD.)
S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [377768 2013-11-01] (Intel Corporation)
R2 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [9216 2010-05-18] (Vodafone) [File not signed]
R2 VSNService; C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [845312 2010-08-11] (Sony Corporation) [File not signed]
R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1642544 2014-02-28] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 0067591363772028mcinstcleanup; C:\Windows\TEMP\006759~1.EXE -cleanup -nolog [X]
S2 mcbootdelaystartsvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 PDFProFiltSrv; C:\Program Files (x86)\Nuance\PDF Professional 8\PDFProFiltSrv.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31920 2014-04-09] (Wondershare)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-29] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [238080 2012-04-23] (Huawei Technologies Co., Ltd.)
S3 qcfiltersny2k; C:\Windows\System32\DRIVERS\qcfiltersny2k.sys [6400 2010-06-03] (QUALCOMM Incorporated)
S3 qcombussny; C:\Windows\System32\DRIVERS\qcombussny.sys [137800 2010-06-03] (MCCI)
S3 qcusbnetsny2k; C:\Windows\System32\DRIVERS\qcusbnetsny2k.sys [442368 2010-06-03] (QUALCOMM Incorporated)
S3 qcusbsersny2k; C:\Windows\System32\DRIVERS\qcusbserSny2k.sys [230784 2010-06-03] (QUALCOMM Incorporated)
S3 RRNetCap; C:\Windows\System32\DRIVERS\rrnetcap.sys [37480 2013-03-22] (RapidSolution Software AG)
R3 RRNetCapMP; C:\Windows\System32\DRIVERS\rrnetcap.sys [37480 2013-03-22] (RapidSolution Software AG)
R3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-04-18] (Razer, Inc.)
S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39592 2014-09-05] (Razer Inc)
R1 RzFilter; C:\Windows\system32\drivers\RzFilter.sys [74432 2014-04-18] (Razer, Inc.)
S3 rzmpos; C:\Windows\System32\DRIVERS\rzmpos.sys [35496 2014-09-05] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2014-12-09] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2014-12-10] (Razer, Inc.)
R3 semav6thermal64ro; C:\Windows\system32\drivers\semav6thermal64ro.sys [13792 2014-12-30] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-19 16:12 - 2015-02-19 16:12 - 02086912 _____ (Farbar) C:\Users\XXX YYY\Desktop\FRST64(1).exe
2015-02-19 11:50 - 2015-02-19 13:18 - 00053044 _____ () C:\vew.txt
2015-02-19 11:49 - 2015-02-19 11:49 - 00000000 _____ () C:\test.txt
2015-02-19 11:41 - 2015-02-19 11:41 - 00000000 _____ () C:\Users\XXX YYY\Documents\vew.txt
2015-02-19 10:48 - 2015-02-19 10:48 - 00061440 _____ ( ) C:\Users\XXX YYY\Desktop\VEW.exe
2015-02-19 10:14 - 2015-02-19 10:14 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\Steam
2015-02-18 09:31 - 2015-02-18 09:32 - 85509932 _____ () C:\Users\XXX YYY\Desktop\User Data.rar
2015-02-16 16:05 - 2015-02-16 16:05 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-XXXYYY-VAIO-Windows-7-Professional-(64-bit).dat
2015-02-16 16:05 - 2015-02-16 16:05 - 00000000 ____D () C:\RegBackup
2015-02-16 15:33 - 2015-02-16 16:08 - 00002107 _____ () C:\Users\XXX YYY\Documents\settings.ini
2015-02-16 15:33 - 2015-02-07 10:03 - 02172160 _____ (Tweaking.com) C:\Users\XXX YYY\Documents\Repair_Windows.exe
2015-02-16 15:33 - 2015-01-26 19:07 - 00014396 _____ () C:\Users\XXX YYY\Documents\file_list.txt
2015-02-16 15:33 - 2014-12-23 14:04 - 00000000 ____D () C:\Users\XXX YYY\Documents\color_presets
2015-02-16 15:33 - 2014-11-11 05:07 - 00000000 ____D () C:\Users\XXX YYY\Documents\repairs_info
2015-02-16 15:33 - 2014-10-20 23:13 - 00000000 ____D () C:\Users\XXX YYY\Documents\files
2015-02-16 15:33 - 2014-10-02 01:32 - 00005447 _____ () C:\Users\XXX YYY\Documents\Repair_Windows.exe.manifest
2015-02-16 15:33 - 2014-08-25 21:02 - 00852960 _____ (Tweaking.com) C:\Users\XXX YYY\Documents\TweakingImgCtl.ocx
2015-02-16 15:33 - 2014-04-03 22:54 - 00271328 _____ (Tweaking.com) C:\Users\XXX YYY\Documents\tweaking_com_treeview.ocx
2015-02-16 15:33 - 2014-04-03 22:54 - 00234464 _____ (Tweaking.com) C:\Users\XXX YYY\Documents\tweaking_tabs.ocx
2015-02-16 15:33 - 2013-09-04 10:16 - 00118841 _____ (Unicontsoft) C:\Users\XXX YYY\Documents\VszLib.dll
2015-02-16 15:33 - 2011-04-18 19:54 - 00277504 _____ (Igor Pavlov) C:\Users\XXX YYY\Documents\7za.dll
2015-02-16 15:33 - 2009-03-24 20:52 - 00136008 _____ (Microsoft Corporation) C:\Users\XXX YYY\Documents\msinet.ocx
2015-02-16 15:33 - 2003-01-26 22:41 - 00040960 _____ (vbAccelerator) C:\Users\XXX YYY\Documents\SSubTmr6.dll
2015-02-16 15:32 - 2015-02-16 15:32 - 10215062 _____ () C:\Users\XXX YYY\Downloads\tweaking.com_windows_repair_aio.zip
2015-02-12 17:25 - 2015-02-12 17:26 - 00000000 ____D () C:\Users\XXX YYY\Documents\Apowersoft Free Screen Recorder
2015-02-12 17:24 - 2015-02-12 17:24 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\Apowersoft
2015-02-12 17:24 - 2015-02-12 17:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apowersoft
2015-02-12 17:24 - 2015-02-12 17:24 - 00000000 ____D () C:\Program Files (x86)\Apowersoft
2015-02-12 17:24 - 2014-04-09 21:05 - 00031920 _____ (Wondershare) C:\Windows\system32\Drivers\Apowersoft_AudioDevice.sys
2015-02-12 17:24 - 2014-04-09 20:50 - 00443568 ____H (Bytescout) C:\Windows\SysWOW64\ApowersoftScreenCapturing.dll
2015-02-12 17:24 - 2014-04-09 20:50 - 00271536 ____H (Bytescout) C:\Windows\SysWOW64\ApowersoftScreenCapturingFilter.dll
2015-02-12 17:24 - 2014-04-09 20:50 - 00181424 ____H (Bytescout) C:\Windows\SysWOW64\ApowersoftVideoMixerFilter.dll
2015-02-12 17:23 - 2015-02-12 17:23 - 01203488 _____ () C:\Users\XXX YYY\Downloads\Screen Recorder - CHIP-Installer.exe
2015-02-12 13:41 - 2015-02-12 13:41 - 00000000 ____D () C:\Program Files (x86)\ESET
2015-02-12 13:39 - 2015-02-12 13:40 - 02347384 _____ (ESET) C:\Users\XXX YYY\Downloads\esetsmartinstaller_deu(1).exe
2015-02-12 13:37 - 2015-02-12 13:37 - 02347384 _____ (ESET) C:\Users\XXX YYY\Downloads\esetsmartinstaller_deu.exe
2015-02-12 11:35 - 2015-02-12 11:35 - 00139290 _____ () C:\Users\XXX YYY\Desktop\OTL Extras.Txt
2015-02-12 11:17 - 2015-02-12 11:36 - 00146944 _____ () C:\Users\XXX YYY\Desktop\OTL.Txt
2015-02-12 11:17 - 2015-02-12 11:17 - 00139534 _____ () C:\Users\XXX YYY\Desktop\Extras.Txt
2015-02-12 10:56 - 2015-02-12 10:57 - 00602112 _____ (OldTimer Tools) C:\Users\XXX YYY\Desktop\OTL.exe
2015-02-11 15:35 - 2015-02-11 15:35 - 00001008 _____ () C:\Users\XXX YYY\Desktop\checkup.txt
2015-02-11 15:25 - 2015-02-11 16:04 - 00000000 ____D () C:\Users\XXX YYY\Desktop\FRST-OlderVersion
2015-02-11 15:18 - 2015-02-11 15:18 - 00852594 _____ () C:\Users\XXX YYY\Desktop\SecurityCheck.exe
2015-02-10 16:21 - 2015-02-19 16:15 - 00032622 _____ () C:\Users\XXX YYY\Desktop\FRST.txt
2015-02-10 16:04 - 2015-02-10 16:04 - 00039026 _____ () C:\Users\XXX YYY\Desktop\HitmanPro_20150210_1603.log
2015-02-09 23:05 - 2015-02-09 23:05 - 11225840 _____ (SurfRight B.V.) C:\Users\XXX YYY\Downloads\HitmanPro_x64.exe
2015-02-09 21:15 - 2015-02-09 21:15 - 00039064 _____ () C:\ComboFix.txt
2015-02-09 20:56 - 2015-02-09 21:15 - 00000000 ____D () C:\Qoobox
2015-02-09 20:56 - 2015-02-09 21:13 - 00000000 ____D () C:\Windows\erdnt
2015-02-09 20:56 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-09 20:56 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-09 20:56 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-09 20:54 - 2015-02-09 20:55 - 05611930 ____R (Swearware) C:\Users\XXX YYY\Desktop\ComboFix.exe
2015-02-09 20:54 - 2015-02-09 20:54 - 05611930 _____ (Swearware) C:\Users\XXX YYY\Downloads\ComboFix.exe.part
2015-02-09 19:21 - 2015-02-09 19:21 - 02132992 _____ (Farbar) C:\Users\XXX YYY\Downloads\FRST64.exe
2015-02-09 18:04 - 2015-02-09 18:21 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-02-09 18:03 - 2015-02-09 18:21 - 00000000 ____D () C:\Users\XXX YYY\Desktop\mbar
2015-02-09 18:02 - 2015-02-09 18:02 - 16466552 _____ (Malwarebytes Corp.) C:\Users\XXX YYY\Downloads\mbar-1.08.3.1004.exe
2015-02-09 17:59 - 2015-02-09 17:59 - 00000000 ____D () C:\ProgramData\OnlineUpdate
2015-02-09 17:59 - 2015-02-09 17:59 - 00000000 ____D () C:\ProgramData\log
2015-02-09 17:23 - 2015-02-09 17:23 - 01124352 _____ (Farbar) C:\Users\XXX YYY\Downloads\FRST.exe
2015-02-09 15:05 - 2015-02-09 15:05 - 00442624 _____ () C:\Windows\Minidump\020915-9968-01.dmp
2015-02-09 12:53 - 2015-02-09 12:55 - 00042052 _____ () C:\Users\XXX YYY\Desktop\GMER.log
2015-02-09 12:40 - 2015-02-09 12:40 - 00268832 _____ () C:\Windows\Minidump\020915-10140-01.dmp
2015-02-09 12:29 - 2015-02-09 12:57 - 00149082 _____ () C:\Users\XXX YYY\Desktop\Trojanerboad Forumpost 090215.txt
2015-02-09 12:29 - 2015-02-09 12:29 - 00000869 _____ () C:\Users\XXX YYY\Desktop\Anleitung GMER.txt
2015-02-09 12:28 - 2015-02-09 12:28 - 00064922 _____ () C:\Users\XXX YYY\Downloads\Trojanerboad Forumpost 090215.txt
2015-02-09 12:23 - 2015-02-09 12:26 - 00001097 _____ () C:\Users\XXX YYY\Desktop\Malwarebytes Scan after Malwarebytes Removal.txt
2015-02-09 12:21 - 2015-02-09 12:30 - 00003827 _____ () C:\Users\XXX YYY\Desktop\Malwarebytes Scan.txt
2015-02-09 12:18 - 2015-02-09 12:18 - 00380416 _____ () C:\Users\XXX YYY\Downloads\Gmer-19357.exe
2015-02-09 12:01 - 2015-02-10 14:51 - 00024881 _____ () C:\Users\XXX YYY\Downloads\FRST.txt
2015-02-09 12:00 - 2015-02-19 16:13 - 00000000 ____D () C:\FRST
2015-02-09 11:58 - 2015-02-09 12:28 - 00000470 _____ () C:\Users\XXX YYY\Downloads\defogger_disable.log
2015-02-09 11:58 - 2015-02-09 11:58 - 00000000 _____ () C:\Users\XXX YYY\defogger_reenable
2015-02-09 11:57 - 2015-02-09 11:57 - 00050477 _____ () C:\Users\XXX YYY\Downloads\Defogger.exe
2015-02-09 09:49 - 2015-02-09 13:04 - 00003028 _____ () C:\Users\XXX YYY\Desktop\JRT.txt
2015-02-09 09:43 - 2015-02-09 09:43 - 01388274 _____ (Thisisu) C:\Users\XXX YYY\Downloads\JRT.exe
2015-02-09 09:37 - 2015-02-09 09:41 - 00000000 ____D () C:\AdwCleaner
2015-02-09 09:37 - 2015-02-09 09:37 - 02112512 _____ () C:\Users\XXX YYY\Downloads\AdwCleaner_4.110.exe
2015-02-07 08:01 - 2015-02-07 08:01 - 00262144 _____ () C:\Windows\Minidump\020715-11793-01.dmp
2015-02-05 17:20 - 2015-02-05 17:20 - 00000000 ____D () C:\Users\XXX YYY\Documents\Dungeon of the Endless
2015-02-05 16:56 - 2015-02-09 18:04 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-05 16:56 - 2015-02-09 18:03 - 00097496 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-05 16:56 - 2015-02-05 16:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-05 16:56 - 2015-02-05 16:56 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-05 16:56 - 2015-02-05 16:56 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-05 16:56 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-05 16:56 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-05 16:55 - 2015-02-05 16:55 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\XXX YYY\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-04 15:20 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-02-04 15:20 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-02-04 15:20 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-04 15:20 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-02-04 15:20 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-04 15:20 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-02-04 15:20 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-02-04 15:20 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-02-04 15:20 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-02-04 15:20 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-02-04 15:20 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-02-04 15:20 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-02-04 15:20 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-02-04 15:20 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-02-04 15:20 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-02-03 15:00 - 2015-02-03 15:01 - 07811072 _____ () C:\Users\XXX YYY\Downloads\LWAPlugin64BitInstaller32.msi
2015-01-29 14:05 - 2015-01-29 14:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-24 16:42 - 2015-01-24 19:43 - 00000000 ____D () C:\ProgramData\Steam
2015-01-23 16:45 - 2015-01-23 16:45 - 00001169 _____ () C:\Users\Public\Desktop\VTech Download Manager.lnk
2015-01-23 16:45 - 2015-01-23 16:45 - 00000000 ____D () C:\ProgramData\VTech
2015-01-23 16:45 - 2015-01-23 16:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech
2015-01-23 16:45 - 2015-01-23 16:45 - 00000000 ____D () C:\Program Files (x86)\VTech
2015-01-23 16:44 - 2015-01-23 16:45 - 20758664 _____ (VTech) C:\Users\XXX YYY\Downloads\Kidizoom1407_DE_ger_Setup.exe
2015-01-21 16:05 - 2015-01-21 16:05 - 00217384 _____ (Cisco WebEx LLC) C:\Users\XXX YYY\Downloads\eggits2_Awebex_Acom,eggits2-de,2077473508,-1093361774,MC,0-0,SDJTSwAAAAJeWSAuzW-CSBddk8nRdEnMuWSMwGr2g0C4q48zrQRhMg2_webex.exe
2015-01-21 15:56 - 2015-01-21 16:05 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\webex
2015-01-21 15:56 - 2015-01-21 15:56 - 00646648 _____ (Cisco WebEx LLC) C:\Users\XXX YYY\Downloads\Cisco_WebEx_Add-On.exe
2015-01-21 15:56 - 2015-01-21 15:56 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\WebEx
2015-01-21 15:56 - 2015-01-21 15:56 - 00000000 ____D () C:\ProgramData\WebEx
2015-01-20 14:11 - 2015-01-20 14:11 - 00359961 _____ () C:\Users\XXX YYY\Downloads\Dokument

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-19 16:13 - 2013-03-19 16:48 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-19 16:13 - 2013-03-19 16:48 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-19 16:11 - 2013-03-20 12:01 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\Skype
2015-02-19 16:08 - 2013-03-20 11:36 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-19 16:08 - 2013-03-19 16:42 - 01834783 _____ () C:\Windows\WindowsUpdate.log
2015-02-19 11:51 - 2013-03-19 17:01 - 00003966 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{74DD3A27-0DC4-4DEC-A150-6D12E280742E}
2015-02-19 11:49 - 2009-07-14 05:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-19 11:49 - 2009-07-14 05:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-19 11:48 - 2013-03-19 16:59 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\VirtualStore
2015-02-19 11:47 - 2013-03-19 16:35 - 00689352 _____ () C:\Windows\system32\perfh007.dat
2015-02-19 11:47 - 2013-03-19 16:35 - 00146652 _____ () C:\Windows\system32\perfc007.dat
2015-02-19 11:47 - 2009-07-14 06:13 - 01629436 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-19 11:44 - 2014-05-02 11:30 - 00005170 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for XXXYYY-VAIO-XXX YYY XXXYYY-VAIO
2015-02-19 11:43 - 2014-05-02 11:27 - 00000000 ___RD () C:\Users\XXX YYY\OneDrive
2015-02-19 11:43 - 2013-04-02 10:55 - 00000000 ___RD () C:\Users\XXX YYY\Dropbox
2015-02-19 11:43 - 2013-04-02 10:51 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\Dropbox
2015-02-19 11:43 - 2013-04-02 09:33 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-02-19 11:43 - 2010-07-19 21:44 - 00507252 _____ () C:\Windows\PFRO.log
2015-02-19 11:43 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-19 11:43 - 2009-07-14 05:51 - 00219326 _____ () C:\Windows\setupact.log
2015-02-16 17:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2015-02-16 16:34 - 2013-03-19 16:59 - 00117264 _____ () C:\Users\XXX YYY\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-16 16:34 - 2013-03-19 16:40 - 00000000 ____D () C:\Windows\CSC
2015-02-16 16:34 - 2009-07-14 08:45 - 00000000 ___RD () C:\Users\Public\Recorded TV
2015-02-16 16:34 - 2009-07-14 05:45 - 00446136 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-16 16:28 - 2009-07-14 03:34 - 00000546 _____ () C:\Windows\win.ini
2015-02-16 15:45 - 2013-04-02 10:51 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-12 16:15 - 2014-11-25 07:59 - 00000000 ____D () C:\Program Files\Recuva
2015-02-12 15:27 - 2013-03-20 12:11 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\Microsoft Help
2015-02-12 14:22 - 2013-04-02 10:14 - 00000000 ____D () C:\Users\XXX YYY\Documents\mobalo
2015-02-10 16:22 - 2013-12-06 11:02 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-10 16:22 - 2013-03-23 22:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-02-10 16:22 - 2013-03-23 22:04 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-02-09 21:15 - 2013-03-20 12:05 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\Apps\2.0
2015-02-09 21:15 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-02-09 21:12 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-02-09 21:10 - 2009-07-14 03:34 - 00000027 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_795
2015-02-09 15:05 - 2013-03-23 17:07 - 00000000 ____D () C:\Windows\Minidump
2015-02-09 11:58 - 2013-03-19 16:59 - 00000000 ____D () C:\Users\XXX YYY
2015-02-08 16:08 - 2013-03-19 16:48 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-08 16:08 - 2013-03-19 16:48 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-05 17:19 - 2013-03-20 11:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-05 17:19 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\addins
2015-02-05 16:28 - 2013-03-20 11:36 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-05 16:28 - 2013-03-20 11:36 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-05 16:28 - 2013-03-20 11:36 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-04 15:31 - 2013-08-19 18:06 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-04 15:20 - 2013-03-20 11:10 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-02 12:08 - 2010-07-19 21:45 - 00626734 _____ () C:\Windows\DPINST.LOG
2015-02-02 12:07 - 2013-03-25 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2015-01-24 19:43 - 2014-12-12 18:11 - 00000000 ____D () C:\ProgramData\PopCap Games
2015-01-21 18:27 - 2013-04-02 10:22 - 00000000 ____D () C:\Users\XXX YYY\.thinkbuzan
2015-01-21 18:26 - 2013-04-02 10:22 - 00000000 ____D () C:\ProgramData\ThinkBuzan
2015-01-21 18:26 - 2013-04-02 10:22 - 00000000 ____D () C:\ProgramData\JSoft

==================== Files in the root of some directories =======

2006-12-11 18:13 - 2006-12-11 18:13 - 0097336 _____ (Un4seen Developments) C:\Users\XXX YYY\AppData\Local\bass.dll
2006-12-11 18:13 - 2006-12-11 18:13 - 0013872 _____ (Un4seen Developments) C:\Users\XXX YYY\AppData\Local\basscd.dll
2007-08-13 16:46 - 2007-08-13 16:46 - 0102912 _____ (Albert L Faber) C:\Users\XXX YYY\AppData\Local\CDRip.dll
2007-01-18 20:09 - 2007-01-18 20:09 - 0623616 _____ (Ivan Bischof ©2003 - 2005) C:\Users\XXX YYY\AppData\Local\No23 Recorder.exe
2013-09-13 13:59 - 2013-11-05 17:27 - 0001509 _____ () C:\Users\XXX YYY\AppData\Local\RecConfig.xml
2014-04-05 12:13 - 2014-04-05 12:13 - 0000017 _____ () C:\Users\XXX YYY\AppData\Local\resmon.resmoncfg
2013-03-20 12:05 - 2013-03-19 02:13 - 0000000 _____ () C:\Users\XXX YYY\AppData\Local\{8163A258-9D27-40E7-8400-AAC988DB596D}
2013-03-20 12:05 - 2013-03-19 02:13 - 0000000 _____ () C:\Users\XXX YYY\AppData\Local\{E0B5EB61-5E6A-4483-A017-B5D5359A35B3}
2014-01-07 17:28 - 2014-01-07 17:28 - 0000057 _____ () C:\ProgramData\Ament.ini
2010-05-17 14:20 - 2010-05-17 14:20 - 0157382 ____R () C:\ProgramData\DeviceManager.xml.rc4

ZeroAccess:
C:\Users\XXX YYY\AppData\Local\{4fa287a5-a9e8-a902-8c66-f7e1d24caa8e}

Some content of TEMP:
====================
C:\Users\XXX YYY\AppData\Local\Temp\avgnt.exe
C:\Users\XXX YYY\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp6av0gr.dll


==================== Bamital & volsnap Check =================

(There is no auXXXatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-16 17:42

==================== End Of Log ============================

--- --- ---

Warlord711 19.02.2015 16:37

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Dein Java ist nicht mehr aktuell.
Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
  • Downloade dir bitte die neueste Java-Version von hier
  • Speichere die jxpiinstall.exe
  • Schließe alle laufenden Programme. Speziell deinen Browser.
  • Starte die jxpiinstall.exe. Diese wird den Installer für die neueste Java Version ( Java 8 Update 31 ) herunter laden.
  • Entferne den Haken bei "Installieren Sie die Ask-Toolbar ..." während der Installation.
  • Wenn die Installation beendet wurde
    Start --> Systemsteuerung --> Programme und deinstalliere alle älteren Java Versionen.
  • Starte deinen Rechner neu sobald alle älteren Versionen deinstalliert wurden.
Nach dem Neustart
  • Öffne erneut die Systemsteuerung --> Programme und klicke auf das Java Symbol.
  • Im Reiter Allgemein, klicke unter Temporäre Internetdateien auf Einstellungen.
  • Klicke auf Dateien löschen....
  • Gehe sicher das überall ein Haken gesetzt ist und klicke OK.
  • Klicke erneut OK.
schneller Plugin-Test: PluginCheck


Bleiben die Drucker-Meldung jetzt aus ?

LarryPerkins 20.02.2015 10:01

Liste der Anhänge anzeigen (Anzahl: 1)
Wie Du im Anhang siehst (wieder mit nem Screenrecorder aufgenommen) ist das Problem immernoch da.


Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-02-2015 01
Ran by XXX YYY at 2015-02-20 08:18:55 Run:2
Running from C:\Users\XXX YYY\Desktop
Loaded Profiles: XXX YYY (Available profiles: XXX YYY)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION

*****************

"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.

==== End of Fixlog 08:18:55 ====


Warlord711 20.02.2015 11:54

Zitat:

Task: {187BF442-5A85-44DE-9CC7-0241C7AC7642} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe
Wirklich ?

Win 7 und Office 2010 kosten doch zusammen keine 100 € bei ebay.



Lesestoff:
Cracks und Keygens
Den Kopierschutz von Software zu umgehen ist nach geltendem Recht illegal. Die Logfiles deuten stark darauf hin, dass du nicht legal erworbene Software einsetzt. Zudem sind Cracks und Patches aus dubioser Quelle sehr oft mit Schädlingen versehen, womit man sich also fast vorsätzlich infiziert.

Wir haben uns hier auf dem Board darauf geeinigt, dass wir an dieser Stelle nicht weiter bereinigen, da wir ein solches Vorgehen nicht unterstützen. Hinzu kommt, dass wir dich in unserer Anleitung und auch in diesem Wichtig-Thema unmissverständlich darauf hingewiesen haben, wie wir damit umgehen werden. Saubere, gute Software hat seinen Preis und die Softwarefirmen leben von diesen Einnahmen.


Da die Bereinigung eh schon durch ist, kannst das bitte löschen, schon allein um es als Fehlerquelle auszuschliessen.

Oder läuft dann Windows nicht mehr ?

LarryPerkins 20.02.2015 11:58

Ich weiß nicht genau was Du meinst..? Ich nutze Office 2013 mit monatl. Gebühr und Windows 7 war bei meinem Rechner dabei? Das installiert sich sogar bei nem Rechner Wipe von selbst neu. Was soll ich da löschen?

Warlord711 20.02.2015 12:10

What is AutoKMS.exe? - Microsoft Community

Also AutoKMS oder KMSpico ist zu 99% ein Hinweis auf gecracktes Office und/oder Windows. Da du Office 2010 lt. Addition.txt installiert hast, gehe ich erstmal davon aus das es zu 99% gecrackt ist.

Bitte lasse die Datei aus der Code-Box bei Virustotal überprüfen.
  • Klicke auf Wählen Sie eine
  • Kopiere nun folgendes in die Suchleiste
    Code:

    C:\Windows\AutoKMS.exe
  • und klicke auf Öffnen.
  • Klicke auf Scannen!.
  • Warte bitte bis die Datei vollständig hochgeladen wurde. Solltest Du folgende Meldung bekommen
    Zitat:

    Diese Datei wurde bereits von VirusTotal analysiert...
    klicke auf Neu analysieren.
  • Warte bis dir das Analysedatum angezeigt wird und der Scan abgeschlossen ist.
  • Kopiere den Link aus deiner Adresszeile und poste ihn hier.

LarryPerkins 20.02.2015 12:50

In C:\Windows gibt es keine AutoKMS.exe Datei.

Ja da ist tatsächlich noch Office 2010 drauf seh ich grad, aber das nutze ich schon lang nicht mehr. Ich hab das gerade deinstalliert, danke für den Hinweis. Woher ich das vor 5 Jahren hatte kann ich wirklich heute nicht mehr nachvollziehen, brauch es aber wie gesagt auch nicht.

Warlord711 20.02.2015 13:50

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

file: C:\Windows\AutoKMS.exe

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Und bitte neue FRST Logs. Haken setzen bei addition.txt dann auf Scan klicken

http://saved.im/mtg0mjy4yjlu/2014-04...ryscantool.png

LarryPerkins 20.02.2015 14:14

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-02-2015 01
Ran by Tom Rauhe at 2015-02-20 14:06:33 Run:3
Running from C:\Users\XXX\Desktop
Loaded Profiles: Tom Rauhe (Available profiles: Tom Rauhe)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
file: C:\Windows\AutoKMS.exe
*****************


========================= file: C:\Windows\AutoKMS.exe ========================

"C:\Windows\AutoKMS.exe" not found.
====== End Of File: ======


==== End of Fixlog 14:06:34 ====

Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-02-2015 01
Ran by XXX YYY at 2015-02-20 14:10:23
Running from C:\Users\XXX YYY\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7 Grand Steps, Step 1: What Ancients Begat (HKLM-x32\...\Steam App 238930) (Version:  - Mousechief)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.110 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Apowersoft kostenloser Bildschirmrekorder V1.4.0 (HKLM-x32\...\{4EFA42DB-E4EC-4537-9DF3-5158D08A9785}_is1) (Version: 1.4.0 - APOWERSOFT LIMITED)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft WebCam Companion 3 (HKLM-x32\...\{DE8AAC73-6D8D-483E-96EA-CAEDDADB9079}) (Version: 3.0.21.368 - ArcSoft)
Audials (HKLM-x32\...\{D928A4B7-126D-47B6-AD76-9848E51E1426}) (Version: 10.2.14807.700 - Audials AG)
Avira (HKLM-x32\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG)
Avira (x32 Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira)
Bad Hotel (HKLM-x32\...\Steam App 231720) (Version:  - Lucky Frame)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bejeweled 2 Deluxe (HKLM-x32\...\Steam App 3300) (Version:  - PopCap Games, Inc.)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.3868 - CDBurnerXP)
Chainsaw Warrior (HKLM-x32\...\Steam App 251710) (Version:  - Auroch Digital)
Choice of the Deathless (HKLM-x32\...\Steam App 318310) (Version:  - Choice of Games)
Chuzzle Deluxe (HKLM-x32\...\Steam App 3310) (Version:  - PopCap Games, Inc.)
Cinders (HKLM-x32\...\Steam App 293680) (Version:  - MoaCube)
Cisco WebEx Meetings (HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Citrix Online Launcher (HKLM-x32\...\{AC7E7905-8C59-4806-A96D-30936A2B1FC5}) (Version: 1.0.168 - Citrix)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Darkest Dungeon (HKLM-x32\...\Steam App 262060) (Version:  - Red Hook Studios)
Dead Man's Draw (HKLM-x32\...\Steam App 262450) (Version:  - Stardock Entertainment)
Death Skid Marks (HKLM-x32\...\Steam App 326150) (Version:  - Studio Whisky Tango Inc.)
Deinst. f. Druckertreiber UFR II (HKLM\...\Canon UFR II Printer Driver) (Version: 5, 4, 0, 0 - Canon Inc.)
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.3.80 - DivX, LLC)
Dropbox (HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Evernote (HKLM-x32\...\{F761359C-9CED-45AE-9A51-9D6605CD55C4}) (Version: 3.5.4.2224 - Evernote Corp.)
FastStone Capture 5.3 (HKLM-x32\...\FastStone Capture) (Version: 5.3 - FastStone Soft)
Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Frozen Synapse (HKLM-x32\...\Steam App 98200) (Version:  - Mode 7)
FTL: Faster Than Light (HKLM-x32\...\Steam App 212680) (Version:  - Subset Games)
Gods Will Be Watching (HKLM-x32\...\Steam App 274290) (Version:  - Deconstructeam)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.111 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
GoXXXeeting 6.0.0.1259 (HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\GoXXXeeting) (Version: 6.0.0.1259 - CitrixOnline)
Helium (HKLM-x32\...\{9A781940-AC41-4D5E-8E1E-76A04B916FB9}) (Version: 1.0.0 - ClockworkMod)
Hotline Miami (HKLM-x32\...\Steam App 219150) (Version:  - Dennaton Games)
HP Deskjet 3050 J610 series - Grundlegende Software für das Gerät (HKLM\...\{EF3293DE-FCAC-4742-91BF-AD0174143FC3}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050 J610 series Hilfe (HKLM-x32\...\{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}) (Version: 140.0.63.63 - Hewlett Packard)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
iMindMap 6 (HKLM-x32\...\{C5711BC2-2E1C-4556-9922-02BF2865A5EE}) (Version: 6.0.617 - ThinkBuzan)
Insaniquarium! Deluxe (HKLM-x32\...\Steam App 3320) (Version:  - PopCap Games, Inc.)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi-Software (HKLM\...\{D16A2127-B927-4379-B153-3DEC091E4EEB}) (Version: 13.02.1000 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.0.1014 - Intel Corporation)
Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.00.01.1002 - Intel Corporation)
Internet Manager (HKLM-x32\...\Internet Manager) (Version: 22.001.18.68.55 - Huawei Technologies Co.,Ltd)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
julitecCRM 7.5 (HKLM-x32\...\julitecCRM_is1) (Version:  - )
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Kentucky Route Zero (HKLM-x32\...\Steam App 231200) (Version:  - Cardboard Computer)
Long Live The Queen (Demo) 1.0 (HKLM-x32\...\Long Live The Queen_is1) (Version:  - Hanako Games)
LUFTRAUSERS (HKLM-x32\...\Steam App 233150) (Version:  - Vlambeer)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Lync Web App Plug-in (HKLM\...\{6619085B-A9D5-4DDD-800B-964903EAF546}) (Version: 15.8.8308.726 - Microsoft Corporation)
Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 15.0.4675.1003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Monster Loves You! (HKLM-x32\...\Steam App 226740) (Version:  - Radial Games Corp)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 31.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.4.0 (x86 de)) (Version: 31.4.0 - Mozilla)
No23 Recorder (HKLM-x32\...\{22B0E143-2B0B-435B-9F56-136A3D16065F}) (Version: 2.1.0.3 - No23)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.61.39 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC)
Papers, Please (HKLM-x32\...\Steam App 239030) (Version:  - 3909)
Pixel Piracy (HKLM-x32\...\Steam App 264140) (Version:  - Vitali Kirpu)
Plants vs. Zombies: Game of the Year (HKLM-x32\...\Steam App 3590) (Version:  - PopCap Games, Inc.)
Plush (HKLM-x32\...\Steam App 341820) (Version:  - Red Head Games)
Protector Suite 2009 (HKLM\...\{0F841121-4DB6-4B31-839F-7F5AB3BB3423}) (Version: 5.9.3.6321 - UPEK Inc.)
Psy High (HKLM-x32\...\Steam App 339510) (Version:  - Choice of Games)
Puzzle Quest (HKLM-x32\...\Steam App 12500) (Version:  - D3)
Qualcomm Gobi 2000 Package for Sony (HKLM-x32\...\{1F4E59C0-EE31-47EE-BCC3-1A73C3F023BF}) (Version: 1.1.160 - QUALCOMM)
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
RaidCall (HKLM-x32\...\RaidCall) (Version: 7.2.4-1.0.7299.14 - raidcall.com)
Razer Core (HKLM-x32\...\Razer Core) (Version: 1.0.1.66 - Razer Inc)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.19.23944 - Razer Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6028 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
SharpKeys (HKLM-x32\...\{636E94DA-99C0-448F-A931-3DAD83B4975F}) (Version: 3.5.0000 - RandyRants.com)
simfy (HKLM-x32\...\Simfy) (Version: 1.7.6 - simfy AG)
simfy (x32 Version: 1.7.6 - simfy AG) Hidden
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Sokobond (HKLM-x32\...\Steam App 290260) (Version:  - Alan Hazelden)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.16.0 - Synaptics Incorporated)
TBBackup 2 (Freiversion) (HKLM-x32\...\DED9B6BE-2B04-4799-A88F-8BBF4D114AAF_is1) (Version: 2 - Priotecs IT GmbH)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.28223 - TeamViewer)
The Bridge (HKLM-x32\...\Steam App 204240) (Version:  - Ty Taylor and Mario Castañeda)
Thieves' Gambit: Curse of the Black Cat (HKLM-x32\...\Steam App 328550) (Version:  - Choice of Games)
Thirty Flights of Loving (HKLM-x32\...\Steam App 214700) (Version:  - Blendo Games)
Tinypic 3.18 (HKLM-x32\...\{E3723A04-A894-4036-A78E-282E18F43C0A}_is1) (Version: Tinypic 3.18 - E. Fiedler)
TOP (HKLM\...\TOP) (Version: 2.1.1.0 - mediMACH GmbH & Co. KG)
TreeSize Free V2.7 (HKLM-x32\...\TreeSize Free_is1) (Version: 2.7 - JAM Software)
Uplink (HKLM-x32\...\Steam App 1510) (Version:  - Introversion Software)
VAIO Care (HKLM\...\{D9FFE40D-1A85-4541-992C-5EF505F391A4}) (Version: 8.4.2.12041 - Sony Corporation)
VAIO Care Recovery (HKLM\...\{6ED1750E-F44F-4635-8F0D-B76B9262B7FB}) (Version: 1.1.1.13230 - Sony Corporation)
VAIO Control Center (HKLM-x32\...\{72042FA6-5609-489F-A8EA-3C2DD650F667}) (Version: 4.3.0.05310 - Sony Corporation)
VAIO Data Restore Tool (HKLM-x32\...\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}) (Version: 1.4.0.05240 - Sony Corporation)
VAIO Data Restore Tool (x32 Version: 1.4.0.05240 - Sony Corporation) Hidden
VAIO Gate (HKLM-x32\...\{A7C30414-2382-4086-B0D6-01A88ABA21C3}) (Version: 2.2.0.06080 - Sony Corporation)
VAIO Gate Default (HKLM-x32\...\{B7546697-2A80-4256-A24B-1C33163F535B}) (Version: 2.2.0.07020 - Sony Corporation)
VAIO Hardware Diagnostics (x32 Version: 4.0.0.06230 - Sony Corporation) Hidden
VAIO Marketing Tools (HKLM-x32\...\MarketingTools) (Version:  - Sony Corporation)
VAIO screensaver (HKLM-x32\...\VAIO screensaver) (Version: 1.0.0.0 - Sony Europe)
VAIO Smart Network (HKLM-x32\...\{0899D75A-C2FC-42EA-A702-5B9A5F24EAD5}) (Version: 3.3.1.08110 - Sony Corporation)
VAIO Update (HKLM-x32\...\{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}) (Version: 7.0.1.02280 - Sony Corporation)
VAIO-Handbuch (HKLM-x32\...\{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}) (Version: 1.1.0.05280 - Sony Corporation)
VAIO-Support für Übertragungen (HKLM-x32\...\{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}) (Version: 1.2.0.06230 - Sony Corporation)
Valiant Hearts: The Great War™ / Soldats Inconnus : Mémoires de la Grande Guerre™ (HKLM-x32\...\Steam App 260230) (Version:  - Ubisoft Montpellier)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Vodafone Mobile Broadband (HKLM-x32\...\{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}) (Version: 10.0.300.23587 - Vodafone)
VTech Download Agent Library (x32 Version: 1.00.0000 - VTech) Hidden
VTech Download Manager (HKLM-x32\...\VTechDownloadManager) (Version:  - VTech)
VU5x64 (Version: 1.1.0 - Sony Corporation ) Hidden
VU5x86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden
VU5x86 (x32 Version: 1.1.0 - Sony Corporation ) Hidden
WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.5600 - Broadcom Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation)
WinRAR 5.01 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.1 - win.rar GmbH)
Wondershare Dr.Fone for Android(Build 4.8.1.136) (HKLM-x32\...\{1DB91A95-C548-4BA5-9D4C-18C7DEAAC39F}_is1) (Version: 4.8.1.136 - Wondershare Software Co.,Ltd.)
World of Goo (HKLM-x32\...\Steam App 22000) (Version:  - 2D BOY)
XnView 2.22 (HKLM-x32\...\XnView_is1) (Version: 2.22 - Gougelet Pierre-e)

==================== CusXXX CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\XXX YYY\AppData\Local\Citrix\GoXXXeeting\1259\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CusXXXCLSID: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)

==================== Restore Points  =========================

20-02-2015 12:15:20 Removed Microsoft Office Professional Plus 2010

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2015-02-16 16:28 - 00000855 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {07003042-FCBF-4E03-9084-D7217B6EC518} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated)
Task: {0F0A4936-B027-44CB-B669-5B9F92B3F192} - System32\Tasks\SONY\VAIO Power Management\VPM Logon Start => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {187BF442-5A85-44DE-9CC7-0241C7AC7642} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe
Task: {1A5ED98B-E26E-4F78-8E49-5AAF4F656B37} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-28] (Google Inc.)
Task: {1FA704D2-62BF-43D6-840A-2D4F9786E076} - System32\Tasks\SONY\SUS-BCF\Level4Month => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {2CE11264-F006-4465-8975-FA2EA0245B3D} - System32\Tasks\SONY\SUS-BCF\Level4Daily => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {2D0606BE-BE7B-4C6F-942C-07B45CBB4D01} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {367F27E4-A729-4EB5-80C6-6B08FE47DB1F} - System32\Tasks\Sony Corporation\VAIO Care\GetPOTInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {402882DC-CDFE-49E2-A954-3F809F37851D} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {413513C7-60B9-4045-8171-6A8D9EBDD495} - System32\Tasks\Sony Corporation\VAIO Care\VCCheckIolo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {568B3CF3-0B50-4A11-9478-284D3A055670} - System32\Tasks\SONY\VAIO Power Management\VPM Unlock => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {576BD409-939A-4F67-B3ED-0E82591D6BF3} - System32\Tasks\Sony Corporation\VAIO Care\ActiveStatusCollect => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {61B8DD12-39BF-4BBF-B084-8F92D5F3A324} - System32\Tasks\Sony Corporation\VAIO Care\VCMetrics => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {69CE1657-328E-4DA1-8663-A6BF1CCD6B53} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2014-02-28] (Sony Corporation)
Task: {8064F21C-7DCF-4763-9DBF-7722C2057EC9} - System32\Tasks\Microsoft\Office\Office AuXXXatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-11-04] (Microsoft Corporation)
Task: {80EF32D9-20FD-4C21-9265-C33EBCE1A4FD} - System32\Tasks\Sony Corporation\VAIO Care\VCRLog => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {81A39738-5497-488C-8C74-6567DD8AAD4B} - System32\Tasks\Sony Corporation\VAIO Care\VCSelfHeal => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {85FB3BD6-50D8-4849-9EBA-D1986B341972} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-11-12] (Microsoft Corporation)
Task: {888841F4-9762-4C71-B89D-B7EDB973865A} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2014-03-01] (Sony Corporation)
Task: {89E6205E-831F-4B74-BF7B-3026B6E6B365} - System32\Tasks\Sony Corporation\VAIO Care\CheckSystemInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {941F4092-FB9C-45CD-A9C2-B169B06301AE} - System32\Tasks\Sony Corporation\VAIO Care\UpdateSolution => C:\Program Files\Sony\VAIO Care\Solution.Updater.exe [2014-12-03] (Sony Corporation)
Task: {9F25FF11-44D1-4805-9E91-03529AA0C68C} - System32\Tasks\USER_ESRV_SVC => Wscript.exe //B //NoLogo "C:\Program Files\Sony\VAIO Care\ESRV\task.vbs"
Task: {B770129E-F306-434C-B31D-A16B84710116} - System32\Tasks\SONY\VAIO Power Management\VPM Session Change => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {BDDACF5E-FAE8-4757-B563-36FD9129FE8B} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {C8E76728-2150-4BA0-B8A4-312038C6D67C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-28] (Google Inc.)
Task: {C9569DB7-51E7-4271-825E-5D767A82801B} - System32\Tasks\SONY\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2010-06-08] (Sony Corporation)
Task: {CDEE1781-E40E-48A6-AF87-12F74E527282} - System32\Tasks\Sony Corporation\VAIO Care\UploadPOT => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2014-12-03] (Sony Corporation)
Task: {D82BD1C7-8232-4603-BFFC-6C038A5B5C53} - System32\Tasks\Sony Corporation\VAIO Care\DeployCRMflag => C:\Program Files\Sony\VAIO Care\DeployCRMflag.exe [2014-01-16] (Sony Corporation)
Task: {DBB38736-AA50-4AD2-9F1F-C2365E1C0309} - System32\Tasks\Microsoft Office 15 Sync Maintenance for XXXYYY-VAIO-XXX YYY XXXYYY-VAIO => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2014-11-04] (Microsoft Corporation)
Task: {E0069895-C592-4682-9B56-15AF40694CCF} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {E21FD473-244F-4C5F-A416-6E806AADD30D} - System32\Tasks\{AA8032E1-7990-40E7-9D86-A05BAD4EA3DB} => pcalua.exe -a "C:\Program Files (x86)\QT Lite\QTSystem\quicktime.cpl"
Task: {EA1DFED2-7347-45D2-9332-8F46642B0487} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2010-06-08] (Sony Corporation)
Task: {EAB4BD7C-A20A-4956-B70F-B8FB3C9F2A3C} - System32\Tasks\SONY\VAIO Wallpaper Setting Tool\VAIO Wallpaper Setting Tool => C:\Program Files (x86)\Sony\VAIO Wallpaper Setting Tool\VWSet.exe
Task: {F8544C8C-401A-4588-9992-5F23AC4E6FD4} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2010-03-05 09:21 - 2010-03-05 09:21 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2014-05-02 11:19 - 2014-05-20 08:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2011-03-14 16:27 - 2011-03-14 16:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe
2013-09-17 18:11 - 2011-06-17 12:04 - 00224096 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
2014-12-09 23:22 - 2014-12-09 23:22 - 00186048 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
2007-02-12 20:51 - 2007-02-12 20:51 - 01111552 _____ () C:\Program Files (x86)\FastStone Capture\FSCapture.exe
2014-01-10 06:26 - 2014-01-10 06:26 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2014-10-13 02:49 - 2014-06-20 07:42 - 00401280 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
2013-11-01 14:59 - 2013-11-01 14:59 - 00062464 _____ () C:\Program Files\Sony\VAIO Care\listener.exe
2013-10-02 09:38 - 2011-06-17 12:04 - 01434464 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe
2013-09-17 18:11 - 2009-01-10 11:32 - 00011362 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll
2013-09-17 18:11 - 2009-06-22 19:42 - 00043008 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll
2013-09-17 18:11 - 2010-05-05 09:47 - 02415104 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll
2013-09-17 18:11 - 2010-02-10 15:10 - 01148416 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll
2013-03-19 16:48 - 2010-05-31 19:18 - 00013824 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll
2013-03-19 16:48 - 2010-05-31 19:18 - 00013312 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSubPS.dll
2013-03-25 13:23 - 2014-11-11 19:47 - 00774656 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-01-24 19:33 - 2014-12-02 01:29 - 05002752 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-01-24 19:33 - 2014-12-02 01:29 - 01612800 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-01-24 19:33 - 2014-12-02 01:29 - 01210368 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2014-05-22 22:02 - 2015-02-19 00:51 - 02360000 _____ () C:\Program Files (x86)\Steam\video.dll
2014-08-29 09:13 - 2014-12-01 22:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2014-08-29 09:13 - 2014-12-01 22:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2014-08-29 09:13 - 2014-12-01 22:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2014-08-29 09:13 - 2014-12-01 22:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2014-08-29 09:13 - 2014-12-01 22:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2013-03-29 10:53 - 2015-02-19 00:51 - 00702656 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2014-09-25 11:37 - 2014-09-25 11:37 - 00081056 _____ () C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\LoggingPlatform.dll
2014-09-25 11:37 - 2014-09-25 11:37 - 00081056 _____ () C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\LoggingPlatform.DLL
2015-02-10 22:00 - 2015-02-10 22:00 - 00750080 _____ () C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-02-20 12:49 - 2015-02-20 12:49 - 00043008 _____ () c:\Users\XXX YYY\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmps2ulp7.dll
2015-02-10 22:00 - 2015-02-10 22:00 - 00047616 _____ () C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-02-10 22:00 - 2015-02-10 22:00 - 00865280 _____ () C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-02-10 22:00 - 2015-02-10 22:00 - 00200704 _____ () C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2009-07-13 22:03 - 2009-07-14 02:15 - 00364544 _____ () C:\Windows\SysWOW64\msjetoledb40.dll
2013-03-19 16:51 - 2013-03-19 16:51 - 00054784 _____ () C:\Program Files (x86)\Sony\Marketing Tools\Win32Interop.dll
2014-01-10 06:28 - 2014-01-10 06:28 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2014-10-13 02:49 - 2014-03-04 12:20 - 00117760 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll
2014-10-13 02:49 - 2014-04-22 03:14 - 00065536 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpServer.dll
2014-10-13 02:49 - 2014-05-06 06:39 - 00861184 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\platforms\qwindows.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00021504 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qgif.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00020992 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qico.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00204800 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qjpeg.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00218112 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qmng.dll
2014-10-13 02:49 - 2014-05-06 06:58 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qsvg.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00015360 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtga.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00307712 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtiff.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00014848 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qwbmp.dll
2014-10-13 02:49 - 2014-05-06 07:31 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\sensors\qtsensors_dummy.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00036352 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qgenericbearer.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00038912 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qnativewifibearer.dll
2013-03-26 15:16 - 2015-01-28 02:30 - 34641288 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2014-09-26 15:48 - 2014-11-18 14:08 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll
2014-12-08 18:04 - 2014-12-08 18:04 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\3d576cbc4ffc5ad06fd61510c5d8f326\IsdiInterop.ni.dll
2010-07-19 21:49 - 2010-03-04 04:08 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2015-01-17 18:47 - 2015-01-17 18:47 - 03347056 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2015-01-17 18:47 - 2015-01-17 18:47 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2015-01-17 18:47 - 2015-01-17 18:47 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2013-09-17 18:11 - 2010-02-10 15:43 - 09515520 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtGui4.dll
2013-10-02 09:38 - 2012-10-08 02:41 - 00082944 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\plugins\imageformats\qgif4.dll
2013-10-02 09:38 - 2012-10-08 02:41 - 00081920 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\plugins\imageformats\qico4.dll
2014-09-26 15:47 - 2014-11-18 14:07 - 00316576 _____ () C:\Program Files\Microsoft Office 15\root\office15\AppVIsvStream32.dll
2015-01-29 14:05 - 2015-01-29 14:05 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:7C784982

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no auXXXatic fix for this section.)

HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.178.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no auXXXatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-3557091032-3563988234-1886976076-500 - Administrator - Disabled)
Gast (S-1-5-21-3557091032-3563988234-1886976076-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3557091032-3563988234-1886976076-1002 - Limited - Enabled)
XXX YYY (S-1-5-21-3557091032-3563988234-1886976076-1000 - Administrator - Enabled) => C:\Users\XXX YYY

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/20/2015 02:06:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 35.0.1.5500, Zeitstempel: 0x54c1f9f3
Name des fehlerhaften Moduls: mozalloc.dll, Version: 35.0.1.5500, Zeitstempel: 0x54c1f224
Ausnahmecode: 0x80000003
Fehleroffset: 0x00001425
ID des fehlerhaften Prozesses: 0x2204
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3

Error: (02/20/2015 00:48:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: VCAgent.exe, Version: 8.4.2.12030, Zeitstempel: 0x5476d099
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000007fe923ea321
ID des fehlerhaften Prozesses: 0x18f4
Startzeit der fehlerhaften Anwendung: 0xVCAgent.exe0
Pfad der fehlerhaften Anwendung: VCAgent.exe1
Pfad des fehlerhaften Moduls: VCAgent.exe2
Berichtskennung: VCAgent.exe3

Error: (02/20/2015 00:48:21 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: VCAgent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
  bei VCAgent.View.MainWindow.WindowProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei System.Windows.Interop.HwndSource.PublicHooksFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
  bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
  bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
  bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.DefWndProcWrapper(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.GetMessage(System.Windows.Interop.MSG ByRef, IntPtr, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
  bei System.Windows.Application.RunInternal(System.Windows.Window)
  bei System.Windows.Application.Run()
  bei VCAgent.App.Main()

Error: (02/20/2015 11:58:09 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/20/2015 11:58:09 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/20/2015 08:28:56 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/20/2015 08:28:56 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/20/2015 08:24:49 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: VCAgent.exe, Version: 8.4.2.12030, Zeitstempel: 0x5476d099
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000007fe92b4b1f1
ID des fehlerhaften Prozesses: 0x1f40
Startzeit der fehlerhaften Anwendung: 0xVCAgent.exe0
Pfad der fehlerhaften Anwendung: VCAgent.exe1
Pfad des fehlerhaften Moduls: VCAgent.exe2
Berichtskennung: VCAgent.exe3

Error: (02/20/2015 08:24:48 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: VCAgent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
  bei VCAgent.View.MainWindow.WindowProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei System.Windows.Interop.HwndSource.PublicHooksFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
  bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
  bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
  bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.DefWndProcWrapper(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.GetMessage(System.Windows.Interop.MSG ByRef, IntPtr, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
  bei System.Windows.Application.RunInternal(System.Windows.Window)
  bei System.Windows.Application.Run()
  bei VCAgent.App.Main()

Error: (02/20/2015 08:18:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 35.0.1.5500, Zeitstempel: 0x54c1f9f3
Name des fehlerhaften Moduls: mozalloc.dll, Version: 35.0.1.5500, Zeitstempel: 0x54c1f224
Ausnahmecode: 0x80000003
Fehleroffset: 0x00001425
ID des fehlerhaften Prozesses: 0x77c
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3


System errors:
=============
Error: (02/20/2015 00:49:34 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: Dienst "WMPNetworkSvc" konnte nicht ordnungsgemäß gestartet werden, da ein Fehler "0x80004005" in "CoCreateInstance(CLSID_UPnPDeviceFinder)" aufgetreten ist. Überprüfen Sie, ob der Dienst "UPnPHost" ausgeführt wird und ob die Windows-Komponente "UPnPHost" richtig installiert ist.

Error: (02/20/2015 00:49:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "PDFProFiltSrv" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (02/20/2015 00:49:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (02/20/2015 00:49:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (02/20/2015 00:49:07 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht.

Error: (02/20/2015 00:47:28 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst lmhosts erreicht.

Error: (02/20/2015 08:25:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "PDFProFiltSrv" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (02/20/2015 08:25:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (02/20/2015 08:25:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (02/20/2015 08:25:31 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht.


Microsoft Office Sessions:
=========================
Error: (02/20/2015 02:06:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe35.0.1.550054c1f9f3mozalloc.dll35.0.1.550054c1f2248000000300001425220401d04d035b2d446eC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll4c56c079-b901-11e4-92b3-0024bed7ff33

Error: (02/20/2015 00:48:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: VCAgent.exe8.4.2.120305476d099unknown0.0.0.000000000c0000005000007fe923ea32118f401d04cdf269a5435C:\Program Files\Sony\VAIO Care\VCAgent.exeunknown5e915548-b8f6-11e4-aaa2-0024bed7ff33

Error: (02/20/2015 00:48:21 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: VCAgent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
  bei VCAgent.View.MainWindow.WindowProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei System.Windows.Interop.HwndSource.PublicHooksFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
  bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
  bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
  bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.DefWndProcWrapper(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.GetMessage(System.Windows.Interop.MSG ByRef, IntPtr, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
  bei System.Windows.Application.RunInternal(System.Windows.Window)
  bei System.Windows.Application.Run()
  bei VCAgent.App.Main()

Error: (02/20/2015 11:58:09 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\XXX YYY\AppData\Local\join.me\join.me.exe

Error: (02/20/2015 11:58:09 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\XXX YYY\AppData\Local\join.me\join.me.exe

Error: (02/20/2015 08:28:56 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\XXX YYY\AppData\Local\join.me\join.me.exe

Error: (02/20/2015 08:28:56 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\XXX YYY\AppData\Local\join.me\join.me.exe

Error: (02/20/2015 08:24:49 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: VCAgent.exe8.4.2.120305476d099unknown0.0.0.000000000c0000005000007fe92b4b1f11f4001d04c319f036b2eC:\Program Files\Sony\VAIO Care\VCAgent.exeunknown8d497b03-b8d1-11e4-aadb-0024bed7ff33

Error: (02/20/2015 08:24:48 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: VCAgent.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
  bei VCAgent.View.MainWindow.WindowProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei System.Windows.Interop.HwndSource.PublicHooksFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
  bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
  bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
  bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
  bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.DefWndProcWrapper(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei MS.Win32.UnsafeNativeMethods.IntGetMessageW(System.Windows.Interop.MSG ByRef, System.Runtime.InteropServices.HandleRef, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.GetMessage(System.Windows.Interop.MSG ByRef, IntPtr, Int32, Int32)
  bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
  bei System.Windows.Application.RunInternal(System.Windows.Window)
  bei System.Windows.Application.Run()
  bei VCAgent.App.Main()

Error: (02/20/2015 08:18:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe35.0.1.550054c1f9f3mozalloc.dll35.0.1.550054c1f224800000030000142577c01d04cdc9d74c15bC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dllba6ecc8e-b8d0-11e4-aadb-0024bed7ff33


CodeIntegrity Errors:
===================================
  Date: 2015-02-09 21:07:05.858
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-02-09 21:07:05.655
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5 CPU M 460 @ 2.53GHz
Percentage of memory in use: 66%
Total physical RAM: 3765.82 MB
Available physical RAM: 1265.65 MB
Total Pagefile: 7529.83 MB
Available Pagefile: 3786.67 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.17 GB) (Free:16.64 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: 720CB564)
Partition 1: (Not Active) - (Size=8 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=111.2 GB) - (Type=07 NTFS)

==================== End Of Log ============================


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2015 01
Ran by XXX YYY (administrator) on XXXYYY-VAIO on 20-02-2015 14:07:54
Running from C:\Users\XXX YYY\Desktop
Loaded Profiles: XXX YYY (Available profiles: XXX YYY)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvservice.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(UPEK Inc.) C:\Program Files\Protector Suite\upeksvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(QUALCOMM, Inc.) C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(UPEK Inc.) C:\Program Files\Protector Suite\psqltray.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
() C:\Program Files (x86)\FastStone Capture\FSCapture.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
(Sony Corporation) C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\csisyncclient.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
() C:\Program Files\Sony\VAIO Care\listener.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\winword.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Farbar) C:\Users\XXX YYY\Desktop\FRST64(1).exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9962016 2010-06-18] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1886504 2010-03-01] (Synaptics Incorporated)
HKLM\...\Run: [PSQLLauncher] => C:\Program Files\Protector Suite\launcher.exe [84744 2010-04-27] (UPEK Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [673136 2010-05-31] (Sony Corporation)
HKLM-x32\...\Run: [MobileBroadband] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [253440 2010-05-18] (Vodafone)
HKLM-x32\...\Run: [MarketingTools] => C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [26624 2013-03-19] (Sony Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-11] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585536 2015-01-06] (Razer Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-08-19] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (UPEK Inc.)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2874048 2015-02-19] (Valve Corporation)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [SkyDrive] => C:\Users\XXX YYY\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [277672 2014-09-25] (Microsoft Corporation)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30879328 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\...\Run: [GoogleChromeAutoLaunch_550EDA027B4B11347618D98EDCBB3ADF] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592 2015-02-04] (Google Inc.)
Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk
ShortcutTarget: FastStone Capture.lnk -> C:\Program Files (x86)\FastStone Capture\FSCapture.exe ()
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [UEAFOverlay] -> {F2F31467-B1AC-4df0-AE79-FD5FA085E22B} => C:\Program Files\Protector Suite\farchns.dll (UPEK Inc.)
ShellIconOverlayIdentifiers: [UEAFOverlayOpen] -> {A3E208F7-0E3A-4182-A7A6-B169D5D691AA} => C:\Program Files\Protector Suite\farchns.dll (UPEK Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\XXX YYY\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3557091032-3563988234-1886976076-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {3617BCD7-E991-4BB5-8542-09A0B20EE913} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {794C16B2-C354-42CB-8212-172F5BD771B6} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-9/4?satitle={searchTerms}
SearchScopes: HKU\S-1-5-21-3557091032-3563988234-1886976076-1000 -> {A70EC677-F517-45E6-831A-E87104D7AC0B} URL = hxxp://de.shopping.com/?linkin_id=8056363
BHO: No Name -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} ->  No File
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} ->  No File
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{876E33B5-EE1E-4322-8F79-79EB6087A1E2}: [NameServer] 
Tcpip\..\Interfaces\{AA2DF348-6AB3-482F-A8BC-41E89158A468}: [NameServer] 10.74.210.210 10.74.210.211

FireFox:
========
FF ProfilePath: C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default
FF DefaultSearchEngine: Google
FF SelectedSearchEngine: Google
FF Homepage: www.google.de
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*'))%20%7B%20return%20'PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\Sony\MSS\3.8.130\npMcAfeeMss.dll No File
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\XXX YYY\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3557091032-3563988234-1886976076-1000: @citrixonline.com/appdetectorplugin -> C:\Users\XXX YYY\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin HKU\S-1-5-21-3557091032-3563988234-1886976076-1000: LWAPlugin15.8 -> C:\Users\XXX YYY\AppData\Roaming\Mozilla\Plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\XXX YYY\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\XXX YYY\AppData\Roaming\mozilla\plugins\npLWAPlugin15.8.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\XXX YYY\AppData\Roaming\mozilla\plugins\npoctoshape.dll (Octoshape ApS)
FF SearchPlugin: C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\searchplugins\translate-korean-to-english.xml
FF Extension: ProxMate - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-08-09]
FF Extension: TinEye Reverse Image Search - C:\Users\XXX YYY\AppData\Roaming\Mozilla\Firefox\Profiles\gwlew6n9.default\Extensions\tineye@ideeinc.com.xpi [2013-03-20]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor

Chrome:
=======
CHR HomePage: Default -> hxxp://google.de/
CHR StartupUrls: Default -> "hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=5ABA002710DD58F0&affID=119357&tsp=4958"
CHR Profile: C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (BetterTTV) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2014-10-30]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-16]
CHR Extension: (Avira Browser Safety) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-11]
CHR Extension: (Helium Backup) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpglbgbpeobllokpmeagpoagjbfknanl [2015-01-19]
CHR Extension: (Google Wallet) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-05]
CHR Profile: C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-26]
CHR Extension: (BetterTTV) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2015-01-26]
CHR Extension: (Google Docs) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-26]
CHR Extension: (Google Drive) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-26]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-26]
CHR Extension: (YouTube) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-26]
CHR Extension: (Google Search) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-26]
CHR Extension: (Google Sheets) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-26]
CHR Extension: (Avira Browser Safety) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-01-26]
CHR Extension: (Google Wallet) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-26]
CHR Extension: (Gmail) - C:\Users\XXX YYY\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-26]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
R2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [377768 2013-11-01] (Intel Corporation)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2011-06-17] ()
S3 McComponentHostServiceSony; C:\Program Files (x86)\Sony\MSS\3.8.130\McCHSvc.exe [235216 2013-10-16] (McAfee, Inc.)
R2 nvservice; C:\Windows\system32\nvservice.exe [192800 2013-02-04] (NVIDIA Corporation)
R2 QDLService2kSony; c:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe [332024 2010-06-03] (QUALCOMM, Inc.)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [186048 2014-12-09] ()
R2 RzOvlMon; C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe [32960 2014-04-18] (Razer, Inc.)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [266168 2013-11-01] (Intel Corporation)
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [741640 2014-06-16] (DEVGURU Co., LTD.)
S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [377768 2013-11-01] (Intel Corporation)
R2 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [9216 2010-05-18] (Vodafone) [File not signed]
R2 VSNService; C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [845312 2010-08-11] (Sony Corporation) [File not signed]
R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1642544 2014-02-28] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 0067591363772028mcinstcleanup; C:\Windows\TEMP\006759~1.EXE -cleanup -nolog [X]
S2 mcbootdelaystartsvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 PDFProFiltSrv; C:\Program Files (x86)\Nuance\PDF Professional 8\PDFProFiltSrv.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31920 2014-04-09] (Wondershare)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-29] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [238080 2012-04-23] (Huawei Technologies Co., Ltd.)
S3 qcfiltersny2k; C:\Windows\System32\DRIVERS\qcfiltersny2k.sys [6400 2010-06-03] (QUALCOMM Incorporated)
S3 qcombussny; C:\Windows\System32\DRIVERS\qcombussny.sys [137800 2010-06-03] (MCCI)
S3 qcusbnetsny2k; C:\Windows\System32\DRIVERS\qcusbnetsny2k.sys [442368 2010-06-03] (QUALCOMM Incorporated)
S3 qcusbsersny2k; C:\Windows\System32\DRIVERS\qcusbserSny2k.sys [230784 2010-06-03] (QUALCOMM Incorporated)
S3 RRNetCap; C:\Windows\System32\DRIVERS\rrnetcap.sys [37480 2013-03-22] (RapidSolution Software AG)
R3 RRNetCapMP; C:\Windows\System32\DRIVERS\rrnetcap.sys [37480 2013-03-22] (RapidSolution Software AG)
R3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-04-18] (Razer, Inc.)
S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39592 2014-09-05] (Razer Inc)
R1 RzFilter; C:\Windows\system32\drivers\RzFilter.sys [74432 2014-04-18] (Razer, Inc.)
S3 rzmpos; C:\Windows\System32\DRIVERS\rzmpos.sys [35496 2014-09-05] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2014-12-09] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2014-12-10] (Razer, Inc.)
R3 semav6thermal64ro; C:\Windows\system32\drivers\semav6thermal64ro.sys [13792 2014-12-30] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-20 08:22 - 2015-02-20 08:21 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-02-20 08:20 - 2015-02-20 08:20 - 00639912 _____ (Oracle Corporation) C:\Users\XXX YYY\Downloads\jxpiinstall(1).exe
2015-02-19 16:15 - 2015-02-19 16:18 - 00056773 _____ () C:\Users\XXX YYY\Desktop\Addition.txt
2015-02-19 16:12 - 2015-02-19 16:12 - 02086912 _____ (Farbar) C:\Users\XXX YYY\Desktop\FRST64(1).exe
2015-02-19 11:50 - 2015-02-19 13:18 - 00053044 _____ () C:\vew.txt
2015-02-19 11:49 - 2015-02-19 11:49 - 00000000 _____ () C:\test.txt
2015-02-19 11:41 - 2015-02-19 11:41 - 00000000 _____ () C:\Users\XXX YYY\Documents\vew.txt
2015-02-19 10:48 - 2015-02-19 10:48 - 00061440 _____ ( ) C:\Users\XXX YYY\Desktop\VEW.exe
2015-02-19 10:14 - 2015-02-19 10:14 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\Steam
2015-02-18 09:31 - 2015-02-18 09:32 - 85509932 _____ () C:\Users\XXX YYY\Desktop\User Data.rar
2015-02-16 16:05 - 2015-02-16 16:05 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-XXXYYY-VAIO-Windows-7-Professional-(64-bit).dat
2015-02-16 16:05 - 2015-02-16 16:05 - 00000000 ____D () C:\RegBackup
2015-02-16 15:33 - 2015-02-16 16:08 - 00002107 _____ () C:\Users\XXX YYY\Documents\settings.ini
2015-02-16 15:33 - 2015-02-07 10:03 - 02172160 _____ (Tweaking.com) C:\Users\XXX YYY\Documents\Repair_Windows.exe
2015-02-16 15:33 - 2015-01-26 19:07 - 00014396 _____ () C:\Users\XXX YYY\Documents\file_list.txt
2015-02-16 15:33 - 2014-12-23 14:04 - 00000000 ____D () C:\Users\XXX YYY\Documents\color_presets
2015-02-16 15:33 - 2014-11-11 05:07 - 00000000 ____D () C:\Users\XXX YYY\Documents\repairs_info
2015-02-16 15:33 - 2014-10-20 23:13 - 00000000 ____D () C:\Users\XXX YYY\Documents\files
2015-02-16 15:33 - 2014-10-02 01:32 - 00005447 _____ () C:\Users\XXX YYY\Documents\Repair_Windows.exe.manifest
2015-02-16 15:33 - 2014-08-25 21:02 - 00852960 _____ (Tweaking.com) C:\Users\XXX YYY\Documents\TweakingImgCtl.ocx
2015-02-16 15:33 - 2014-04-03 22:54 - 00271328 _____ (Tweaking.com) C:\Users\XXX YYY\Documents\tweaking_com_treeview.ocx
2015-02-16 15:33 - 2014-04-03 22:54 - 00234464 _____ (Tweaking.com) C:\Users\XXX YYY\Documents\tweaking_tabs.ocx
2015-02-16 15:33 - 2013-09-04 10:16 - 00118841 _____ (Unicontsoft) C:\Users\XXX YYY\Documents\VszLib.dll
2015-02-16 15:33 - 2011-04-18 19:54 - 00277504 _____ (Igor Pavlov) C:\Users\XXX YYY\Documents\7za.dll
2015-02-16 15:33 - 2009-03-24 20:52 - 00136008 _____ (Microsoft Corporation) C:\Users\XXX YYY\Documents\msinet.ocx
2015-02-16 15:33 - 2003-01-26 22:41 - 00040960 _____ (vbAccelerator) C:\Users\XXX YYY\Documents\SSubTmr6.dll
2015-02-16 15:32 - 2015-02-16 15:32 - 10215062 _____ () C:\Users\XXX YYY\Downloads\tweaking.com_windows_repair_aio.zip
2015-02-12 17:25 - 2015-02-12 17:26 - 00000000 ____D () C:\Users\XXX YYY\Documents\Apowersoft Free Screen Recorder
2015-02-12 17:24 - 2015-02-12 17:24 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\Apowersoft
2015-02-12 17:24 - 2015-02-12 17:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apowersoft
2015-02-12 17:24 - 2015-02-12 17:24 - 00000000 ____D () C:\Program Files (x86)\Apowersoft
2015-02-12 17:24 - 2014-04-09 21:05 - 00031920 _____ (Wondershare) C:\Windows\system32\Drivers\Apowersoft_AudioDevice.sys
2015-02-12 17:24 - 2014-04-09 20:50 - 00443568 ____H (Bytescout) C:\Windows\SysWOW64\ApowersoftScreenCapturing.dll
2015-02-12 17:24 - 2014-04-09 20:50 - 00271536 ____H (Bytescout) C:\Windows\SysWOW64\ApowersoftScreenCapturingFilter.dll
2015-02-12 17:24 - 2014-04-09 20:50 - 00181424 ____H (Bytescout) C:\Windows\SysWOW64\ApowersoftVideoMixerFilter.dll
2015-02-12 17:23 - 2015-02-12 17:23 - 01203488 _____ () C:\Users\XXX YYY\Downloads\Screen Recorder - CHIP-Installer.exe
2015-02-12 13:41 - 2015-02-12 13:41 - 00000000 ____D () C:\Program Files (x86)\ESET
2015-02-12 13:39 - 2015-02-12 13:40 - 02347384 _____ (ESET) C:\Users\XXX YYY\Downloads\esetsmartinstaller_deu(1).exe
2015-02-12 13:37 - 2015-02-12 13:37 - 02347384 _____ (ESET) C:\Users\XXX YYY\Downloads\esetsmartinstaller_deu.exe
2015-02-12 11:35 - 2015-02-12 11:35 - 00139290 _____ () C:\Users\XXX YYY\Desktop\OTL Extras.Txt
2015-02-12 11:17 - 2015-02-12 11:36 - 00146944 _____ () C:\Users\XXX YYY\Desktop\OTL.Txt
2015-02-12 11:17 - 2015-02-12 11:17 - 00139534 _____ () C:\Users\XXX YYY\Desktop\Extras.Txt
2015-02-12 10:56 - 2015-02-12 10:57 - 00602112 _____ (OldTimer Tools) C:\Users\XXX YYY\Desktop\OTL.exe
2015-02-11 15:35 - 2015-02-11 15:35 - 00001008 _____ () C:\Users\XXX YYY\Desktop\checkup.txt
2015-02-11 15:25 - 2015-02-11 16:04 - 00000000 ____D () C:\Users\XXX YYY\Desktop\FRST-OlderVersion
2015-02-11 15:18 - 2015-02-11 15:18 - 00852594 _____ () C:\Users\XXX YYY\Desktop\SecurityCheck.exe
2015-02-10 16:21 - 2015-02-20 14:09 - 00030628 _____ () C:\Users\XXX YYY\Desktop\FRST.txt
2015-02-10 16:04 - 2015-02-10 16:04 - 00039026 _____ () C:\Users\XXX YYY\Desktop\HitmanPro_20150210_1603.log
2015-02-09 23:05 - 2015-02-09 23:05 - 11225840 _____ (SurfRight B.V.) C:\Users\XXX YYY\Downloads\HitmanPro_x64.exe
2015-02-09 21:15 - 2015-02-09 21:15 - 00039064 _____ () C:\ComboFix.txt
2015-02-09 20:56 - 2015-02-09 21:15 - 00000000 ____D () C:\Qoobox
2015-02-09 20:56 - 2015-02-09 21:13 - 00000000 ____D () C:\Windows\erdnt
2015-02-09 20:56 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-09 20:56 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-09 20:56 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-09 20:56 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-09 20:54 - 2015-02-09 20:55 - 05611930 ____R (Swearware) C:\Users\XXX YYY\Desktop\ComboFix.exe
2015-02-09 20:54 - 2015-02-09 20:54 - 05611930 _____ (Swearware) C:\Users\XXX YYY\Downloads\ComboFix.exe.part
2015-02-09 19:21 - 2015-02-09 19:21 - 02132992 _____ (Farbar) C:\Users\XXX YYY\Downloads\FRST64.exe
2015-02-09 18:04 - 2015-02-09 18:21 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-02-09 18:03 - 2015-02-09 18:21 - 00000000 ____D () C:\Users\XXX YYY\Desktop\mbar
2015-02-09 18:02 - 2015-02-09 18:02 - 16466552 _____ (Malwarebytes Corp.) C:\Users\XXX YYY\Downloads\mbar-1.08.3.1004.exe
2015-02-09 17:59 - 2015-02-09 17:59 - 00000000 ____D () C:\ProgramData\OnlineUpdate
2015-02-09 17:59 - 2015-02-09 17:59 - 00000000 ____D () C:\ProgramData\log
2015-02-09 17:23 - 2015-02-09 17:23 - 01124352 _____ (Farbar) C:\Users\XXX YYY\Downloads\FRST.exe
2015-02-09 15:05 - 2015-02-09 15:05 - 00442624 _____ () C:\Windows\Minidump\020915-9968-01.dmp
2015-02-09 12:53 - 2015-02-09 12:55 - 00042052 _____ () C:\Users\XXX YYY\Desktop\GMER.log
2015-02-09 12:40 - 2015-02-09 12:40 - 00268832 _____ () C:\Windows\Minidump\020915-10140-01.dmp
2015-02-09 12:29 - 2015-02-09 12:57 - 00149082 _____ () C:\Users\XXX YYY\Desktop\Trojanerboad Forumpost 090215.txt
2015-02-09 12:29 - 2015-02-09 12:29 - 00000869 _____ () C:\Users\XXX YYY\Desktop\Anleitung GMER.txt
2015-02-09 12:28 - 2015-02-09 12:28 - 00064922 _____ () C:\Users\XXX YYY\Downloads\Trojanerboad Forumpost 090215.txt
2015-02-09 12:23 - 2015-02-09 12:26 - 00001097 _____ () C:\Users\XXX YYY\Desktop\Malwarebytes Scan after Malwarebytes Removal.txt
2015-02-09 12:21 - 2015-02-09 12:30 - 00003827 _____ () C:\Users\XXX YYY\Desktop\Malwarebytes Scan.txt
2015-02-09 12:18 - 2015-02-09 12:18 - 00380416 _____ () C:\Users\XXX YYY\Downloads\Gmer-19357.exe
2015-02-09 12:01 - 2015-02-10 14:51 - 00024881 _____ () C:\Users\XXX YYY\Downloads\FRST.txt
2015-02-09 12:00 - 2015-02-20 14:08 - 00000000 ____D () C:\FRST
2015-02-09 11:58 - 2015-02-09 12:28 - 00000470 _____ () C:\Users\XXX YYY\Downloads\defogger_disable.log
2015-02-09 11:58 - 2015-02-09 11:58 - 00000000 _____ () C:\Users\XXX YYY\defogger_reenable
2015-02-09 11:57 - 2015-02-09 11:57 - 00050477 _____ () C:\Users\XXX YYY\Downloads\Defogger.exe
2015-02-09 09:49 - 2015-02-09 13:04 - 00003028 _____ () C:\Users\XXX YYY\Desktop\JRT.txt
2015-02-09 09:43 - 2015-02-09 09:43 - 01388274 _____ (Thisisu) C:\Users\XXX YYY\Downloads\JRT.exe
2015-02-09 09:37 - 2015-02-09 09:41 - 00000000 ____D () C:\AdwCleaner
2015-02-09 09:37 - 2015-02-09 09:37 - 02112512 _____ () C:\Users\XXX YYY\Downloads\AdwCleaner_4.110.exe
2015-02-07 08:01 - 2015-02-07 08:01 - 00262144 _____ () C:\Windows\Minidump\020715-11793-01.dmp
2015-02-05 17:20 - 2015-02-05 17:20 - 00000000 ____D () C:\Users\XXX YYY\Documents\Dungeon of the Endless
2015-02-05 16:56 - 2015-02-09 18:04 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-05 16:56 - 2015-02-09 18:03 - 00097496 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-05 16:56 - 2015-02-05 16:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-05 16:56 - 2015-02-05 16:56 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-05 16:56 - 2015-02-05 16:56 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-05 16:56 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-05 16:56 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-05 16:55 - 2015-02-05 16:55 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\XXX YYY\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-04 15:20 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-02-04 15:20 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-02-04 15:20 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-04 15:20 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-02-04 15:20 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-04 15:20 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-02-04 15:20 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-02-04 15:20 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-02-04 15:20 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-02-04 15:20 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-02-04 15:20 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-02-04 15:20 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-02-04 15:20 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-02-04 15:20 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-02-04 15:20 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-02-03 15:00 - 2015-02-03 15:01 - 07811072 _____ () C:\Users\XXX YYY\Downloads\LWAPlugin64BitInstaller32.msi
2015-01-29 14:05 - 2015-01-29 14:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-24 16:42 - 2015-01-24 19:43 - 00000000 ____D () C:\ProgramData\Steam
2015-01-23 16:45 - 2015-01-23 16:45 - 00001169 _____ () C:\Users\Public\Desktop\VTech Download Manager.lnk
2015-01-23 16:45 - 2015-01-23 16:45 - 00000000 ____D () C:\ProgramData\VTech
2015-01-23 16:45 - 2015-01-23 16:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech
2015-01-23 16:45 - 2015-01-23 16:45 - 00000000 ____D () C:\Program Files (x86)\VTech
2015-01-23 16:44 - 2015-01-23 16:45 - 20758664 _____ (VTech) C:\Users\XXX YYY\Downloads\Kidizoom1407_DE_ger_Setup.exe
2015-01-21 16:05 - 2015-01-21 16:05 - 00217384 _____ (Cisco WebEx LLC) C:\Users\XXX YYY\Downloads\eggits2_Awebex_Acom,eggits2-de,2077473508,-1093361774,MC,0-0,SDJTSwAAAAJeWSAuzW-CSBddk8nRdEnMuWSMwGr2g0C4q48zrQRhMg2_webex.exe
2015-01-21 15:56 - 2015-01-21 16:05 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\webex
2015-01-21 15:56 - 2015-01-21 15:56 - 00646648 _____ (Cisco WebEx LLC) C:\Users\XXX YYY\Downloads\Cisco_WebEx_Add-On.exe
2015-01-21 15:56 - 2015-01-21 15:56 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\WebEx
2015-01-21 15:56 - 2015-01-21 15:56 - 00000000 ____D () C:\ProgramData\WebEx

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-20 14:08 - 2013-03-20 12:01 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\Skype
2015-02-20 13:28 - 2013-03-20 11:36 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-20 13:13 - 2013-03-19 16:48 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-20 13:09 - 2014-05-02 11:30 - 00005170 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for XXXYYY-VAIO-XXX YYY XXXYYY-VAIO
2015-02-20 12:55 - 2013-03-19 17:01 - 00003966 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{74DD3A27-0DC4-4DEC-A150-6D12E280742E}
2015-02-20 12:55 - 2009-07-14 05:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-20 12:55 - 2009-07-14 05:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-20 12:54 - 2013-03-19 16:42 - 01873827 _____ () C:\Windows\WindowsUpdate.log
2015-02-20 12:53 - 2013-03-19 16:35 - 00689352 _____ () C:\Windows\system32\perfh007.dat
2015-02-20 12:53 - 2013-03-19 16:35 - 00146652 _____ () C:\Windows\system32\perfc007.dat
2015-02-20 12:53 - 2009-07-14 06:13 - 01629436 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-20 12:49 - 2014-05-02 11:27 - 00000000 ___RD () C:\Users\XXX YYY\OneDrive
2015-02-20 12:49 - 2013-04-02 10:55 - 00000000 ___RD () C:\Users\XXX YYY\Dropbox
2015-02-20 12:49 - 2013-04-02 10:51 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\Dropbox
2015-02-20 12:49 - 2013-04-02 09:33 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-02-20 12:49 - 2013-03-19 16:59 - 00115232 _____ () C:\Users\XXX YYY\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-20 12:49 - 2013-03-19 16:48 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-20 12:49 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-20 12:49 - 2009-07-14 05:51 - 00219494 _____ () C:\Windows\setupact.log
2015-02-20 12:49 - 2009-07-14 05:45 - 00443024 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-20 12:48 - 2010-07-19 21:44 - 00507616 _____ () C:\Windows\PFRO.log
2015-02-20 12:18 - 2013-03-25 12:10 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-20 12:18 - 2013-03-19 16:53 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-02-20 12:18 - 2013-03-19 16:49 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2015-02-20 12:18 - 2009-07-14 08:46 - 00000000 ____D () C:\Windows\ShellNew
2015-02-20 12:18 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2015-02-20 12:16 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-02-20 08:32 - 2014-08-15 21:13 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\Adobe
2015-02-20 08:23 - 2013-10-29 16:18 - 00000000 ____D () C:\ProgramData\Oracle
2015-02-20 08:21 - 2013-10-29 16:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-02-20 08:21 - 2013-06-25 08:53 - 00000000 ____D () C:\Program Files (x86)\Java
2015-02-19 11:48 - 2013-03-19 16:59 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\VirtualStore
2015-02-16 17:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2015-02-16 16:34 - 2013-03-19 16:40 - 00000000 ____D () C:\Windows\CSC
2015-02-16 16:34 - 2009-07-14 08:45 - 00000000 ___RD () C:\Users\Public\Recorded TV
2015-02-16 16:28 - 2009-07-14 03:34 - 00000546 _____ () C:\Windows\win.ini
2015-02-16 15:45 - 2013-04-02 10:51 - 00000000 ____D () C:\Users\XXX YYY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-12 16:15 - 2014-11-25 07:59 - 00000000 ____D () C:\Program Files\Recuva
2015-02-12 15:27 - 2013-03-20 12:11 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\Microsoft Help
2015-02-12 14:22 - 2013-04-02 10:14 - 00000000 ____D () C:\Users\XXX YYY\Documents\mobalo
2015-02-10 16:22 - 2013-12-06 11:02 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-10 16:22 - 2013-03-23 22:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-02-10 16:22 - 2013-03-23 22:04 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-02-09 21:15 - 2013-03-20 12:05 - 00000000 ____D () C:\Users\XXX YYY\AppData\Local\Apps\2.0
2015-02-09 21:15 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-02-09 21:12 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-02-09 21:10 - 2009-07-14 03:34 - 00000027 _____ () C:\Windows\system32\Drivers\etc\hosts_bak_795
2015-02-09 15:05 - 2013-03-23 17:07 - 00000000 ____D () C:\Windows\Minidump
2015-02-09 11:58 - 2013-03-19 16:59 - 00000000 ____D () C:\Users\XXX YYY
2015-02-08 16:08 - 2013-03-19 16:48 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-08 16:08 - 2013-03-19 16:48 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-05 17:19 - 2013-03-20 11:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-05 17:19 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\addins
2015-02-05 16:28 - 2013-03-20 11:36 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-05 16:28 - 2013-03-20 11:36 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-05 16:28 - 2013-03-20 11:36 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-04 15:31 - 2013-08-19 18:06 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-04 15:20 - 2013-03-20 11:10 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-02 12:08 - 2010-07-19 21:45 - 00626734 _____ () C:\Windows\DPINST.LOG
2015-02-02 12:07 - 2013-03-25 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2015-01-24 19:43 - 2014-12-12 18:11 - 00000000 ____D () C:\ProgramData\PopCap Games
2015-01-21 18:27 - 2013-04-02 10:22 - 00000000 ____D () C:\Users\XXX YYY\.thinkbuzan
2015-01-21 18:26 - 2013-04-02 10:22 - 00000000 ____D () C:\ProgramData\ThinkBuzan
2015-01-21 18:26 - 2013-04-02 10:22 - 00000000 ____D () C:\ProgramData\JSoft

==================== Files in the root of some directories =======

2006-12-11 18:13 - 2006-12-11 18:13 - 0097336 _____ (Un4seen Developments) C:\Users\XXX YYY\AppData\Local\bass.dll
2006-12-11 18:13 - 2006-12-11 18:13 - 0013872 _____ (Un4seen Developments) C:\Users\XXX YYY\AppData\Local\basscd.dll
2007-08-13 16:46 - 2007-08-13 16:46 - 0102912 _____ (Albert L Faber) C:\Users\XXX YYY\AppData\Local\CDRip.dll
2007-01-18 20:09 - 2007-01-18 20:09 - 0623616 _____ (Ivan Bischof ©2003 - 2005) C:\Users\XXX YYY\AppData\Local\No23 Recorder.exe
2013-09-13 13:59 - 2013-11-05 17:27 - 0001509 _____ () C:\Users\XXX YYY\AppData\Local\RecConfig.xml
2014-04-05 12:13 - 2014-04-05 12:13 - 0000017 _____ () C:\Users\XXX YYY\AppData\Local\resmon.resmoncfg
2013-03-20 12:05 - 2013-03-19 02:13 - 0000000 _____ () C:\Users\XXX YYY\AppData\Local\{8163A258-9D27-40E7-8400-AAC988DB596D}
2013-03-20 12:05 - 2013-03-19 02:13 - 0000000 _____ () C:\Users\XXX YYY\AppData\Local\{E0B5EB61-5E6A-4483-A017-B5D5359A35B3}
2014-01-07 17:28 - 2014-01-07 17:28 - 0000057 _____ () C:\ProgramData\Ament.ini
2010-05-17 14:20 - 2010-05-17 14:20 - 0157382 ____R () C:\ProgramData\DeviceManager.xml.rc4

ZeroAccess:
C:\Users\XXX YYY\AppData\Local\{4fa287a5-a9e8-a902-8c66-f7e1d24caa8e}

Some content of TEMP:
====================
C:\Users\XXX YYY\AppData\Local\Temp\avgnt.exe
C:\Users\XXX YYY\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmps2ulp7.dll


==================== Bamital & volsnap Check =================

(There is no auXXXatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-16 17:42

==================== End Of Log ============================

--- --- ---

Warlord711 20.02.2015 14:25

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

Task: {187BF442-5A85-44DE-9CC7-0241C7AC7642} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Kannst du schauen ob du VAIO Care über die Systemsteuerung reparieren kannst ? Da häufen sich die Fehlermeldungen im Log, könnte sein das dort Dateien korrupt sind.

LarryPerkins 20.02.2015 23:47

Ich hab in der Systemsteuerung nur die Option der Deinstallation, nicht des Reparierens, oder ich find's nicht.

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-02-2015 01
Ran by Tom Rauhe at 2015-02-20 23:40:44 Run:4
Running from C:\Users\XXX\Desktop
Loaded Profiles: XXX (Available profiles: XXX)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Task: {187BF442-5A85-44DE-9CC7-0241C7AC7642} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe
*****************

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{187BF442-5A85-44DE-9CC7-0241C7AC7642}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{187BF442-5A85-44DE-9CC7-0241C7AC7642}" => Key deleted successfully.
C:\Windows\System32\Tasks\AutoKMS => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS" => Key deleted successfully.

==== End of Fixlog 23:40:44 ====


Warlord711 21.02.2015 16:53

Ja, dann über Deinstallieren und neu installieren.

LarryPerkins 23.02.2015 17:06

Ich muss das noch testen, ich denke nicht dass es nochmal aufgetreten ist, aber das ist ja immer so knapp und kurz gewesen.
VAIO Dings trau ich mich nicht zu deinstallieren noch, weil das absolut null Support hat weil VAIO verkauft (und damit verdammit) wurde und nicht mehr weiter betreut wird.
Von Vaio Care exisitieren da draussen eine Million Versionen und Gedöns von denen keiner weiss was da gerade aktuell ist oder funktioniert oder sonstwas....

Ich meld mich wieder wenn ich doch noch was finde oder auch wenn ich nichts mehr finde... danke jedenfalls derweil schonmal :)

Warlord711 23.02.2015 17:14

OK, dann noch die obligatorische Verabschiedung ;-)

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems.

Ändere regelmäßig alle deine Passwörter, jetzt, nach der Bereinigung ist ein idealer Zeitpunkt dafür
  • verwende für jede Anwendung und jeden Account ein anderes Passwort
  • ändere regelmäßig dein Passwort, vor allem bei Onlinebanking oder deinem Emailpostfach ist dieses sehr wichtig
  • speichere keine Passwörter auf deinem PC, gib diese nicht an dritte weiter
  • ein sicheres Passwort besteht aus mindestens 8 Zeichen und beinhaltet Groß- und Kleinbuchstaben, Zahlen und Sonderzeichen
  • benutze keine Zahlen- oder Buchstabenkombinationen, ( zB 12345678, qwertzui) auch keine Zahlen oder Buchstabenmuster
  • verwende keine Passwörter die einen Bezug zu dir, deinem Wohnort, Familienmitglied oder Haustier (Geburtsdatum, Postleitzahl, Adresse, Name) haben

Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7 / 8 : Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti-Viren-Programm und zusätzlicher Schutz
  • Gehe sicher, dass du immer nur eine Anti-Viren Software installiert hast und dass diese auch up to date ist!
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion bietet zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • AdwCleaner
    Dieses Tool erkennt eine Vielzahl von Werbeprogrammen (Adware) und unerwümschten Programmen (PUPs).
    Starte das Tool einmal die Woche und lass es laufen. Sollte eine neue Version verfügbar sein, so wird dies angezeigt und du kannst dir die neueste Version direkt auf den Desktop downloaden.
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • WOT (Web of trust)
    Dieses AddOn warnt dich, bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser
Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Mozilla Firefox
  • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
  • NoScript
    Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt, wenn Du es bestätigst.
  • AdblockPlus
    Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
    Es spart außerdem Downloadkapazität.


Performance
  • Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
  • Halte dich fern von Registry Cleanern.
    Diese Schaden deinem System mehr als dass sie helfen. Hier ein englischer Link:
    Miekemoes Blogspot ( MVP )


Was du vermeiden solltest:
  • Klicke nicht auf alles, nur weil es dich dazu auffordert und schön bunt ist.
  • Verwende keine P2P oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie z.B. deinFoto.jpg.exe.
  • Lade keine Software von Softonic oder Chip herunter, da diese Installer oft mit Adware oder unerünschter Software versehen sind!



Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen oder Lob, Kritik und Wünsche loswerden?

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann.

LarryPerkins 24.02.2015 15:28

Also entweder ist es viel seltener oder nicht mehr da, das letzte hat scheinbar was gebracht, wieso auch immer. Sollte es nochmal auftauchen meld ich mich nochmal... :glaskugel2:
Hab euch 10€ gespendet :) danke nochmal! :dankeschoen:

Was empfiehlst Du denn dann statt chip? dachte das wäre halbwegs safe (im Gegensatz zu Softonic)

Warlord711 25.02.2015 09:38

Zitat:

Zitat von LarryPerkins (Beitrag 1432157)
Also entweder ist es viel seltener oder nicht mehr da, das letzte hat scheinbar was gebracht, wieso auch immer. Sollte es nochmal auftauchen meld ich mich nochmal... :glaskugel2:
Hab euch 10€ gespendet :) danke nochmal! :dankeschoen:

Was empfiehlst Du denn dann statt chip? dachte das wäre halbwegs safe (im Gegensatz zu Softonic)

Bei Chip+Softonic gibts in der Regel immer ZWEI Downloadmöglichkeiten:

Chip/Softonic Downloader:

Bei Chip.de und Softonic gibt es beim Download zwei Möglichkeiten:
einmal den Chip Downloader mit DownloadSponsor, der Werbung mitbringt und gern versucht, den User dazu zu überreden, noch diese und jene Toolbar zu installieren.

Und es gibt immer den alternativen Download, das ist die eigentliche Anwendung als Setup, so wie sie vom Hersteller kommt. Der Alternativlink ist genau unter der Chip Download-Schaltfläche.

http://www.trojaner-board.de/picture...&pictureid=516
http://www.trojaner-board.de/picture...&pictureid=519


Alle Zeitangaben in WEZ +1. Es ist jetzt 21:25 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131