Nun die Additional.txt
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-05-2015
Ran by Henna at 2015-05-06 17:09:41
Running from \\Diskstation\igp\Gesamtdaten\Programme\Virentools\FRST-64Bit
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2797374447-40008444-4185456415-500 - Administrator - Disabled)
Gast (S-1-5-21-2797374447-40008444-4185456415-501 - Limited - Disabled)
Henna (S-1-5-21-2797374447-40008444-4185456415-1001 - Administrator - Enabled) => C:\Users\Henna
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Bitdefender Antivirus (Enabled - Up to date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Spyware-Schutz (Enabled - Up to date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Disabled) {A23392FD-84B9-F933-2C71-81E751F6EF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Acronis True Image 2015 (HKLM-x32\...\{08DC7D7A-1CA0-4E96-B12F-9B9577FCF0F8}Visible) (Version: 18.0.6525 - Acronis)
Acronis True Image 2015 (x32 Version: 18.0.6525 - Acronis) Hidden
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader Driver (HKLM-x32\...\AmUStor) (Version: 20.26.3317.04170 - Alcor Micro Corp.)
Alcor Micro USB Card Reader Driver (x32 Version: 20.26.3317.04170 - Alcor Micro Corp.) Hidden
AVG PC TuneUp 2015 (de-DE) (x32 Version: 15.0.1001.403 - AVG Technologies) Hidden
AVG PC TuneUp 2015 (HKLM-x32\...\AVG PC TuneUp) (Version: 15.0.1001.403 - AVG Technologies)
AVG PC TuneUp 2015 (x32 Version: 15.0.1001.403 - AVG Technologies) Hidden
Bitdefender Total Security 2015 (HKLM\...\Bitdefender) (Version: 18.22.0.1521 - Bitdefender)
Bullzip PDF Printer 10.8.0.2282 (HKLM\...\Bullzip PDF Printer_is1) (Version: 10.8.0.2282 - Bullzip)
CCleaner (HKLM\...\CCleaner) (Version: 5.05 - Piriform)
Classic Shell (HKLM\...\{7C129CF8-199F-4269-AAEE-60B5D8D716E2}) (Version: 4.2.1 - IvoSoft)
CLIQZ (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 1.0.0 - CLIQZ.com)
Corel Graphics - Windows Shell Extension (HKLM-x32\...\_{8616305F-122C-4341-9C37-47A9CD322AB2}) (Version: 17.1.0.572 - Corel Corporation)
Corel Graphics - Windows Shell Extension (x32 Version: 17.1.572 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 64 Bit (Version: 17.1.572 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - Capture (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - Common (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - Connect (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - Custom Data (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - DE (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - DrawHome (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - Filters (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - FontNav (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - IPM (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - IPM Content (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - PPHome (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - Redist (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - Setup Files (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - VideoBrowser (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 - Writing Tools (x32 Version: 17.1 - Corel Corporation) Hidden
CorelDRAW Home & Student Suite X7 (HKLM-x32\...\_{39212C63-B2E9-4ECB-8F91-6E41990093E1}) (Version: 17.1.0.572 - Corel Corporation)
CorelDRAW Home & Student Suite X7 (x32 Version: 17.1 - Corel Corporation) Hidden
DisplayLink Core Software (HKLM\...\{C2FE0D6B-1304-4E02-ACEE-C96E9F4AEECA}) (Version: 7.6.56275.0 - DisplayLink Corp.)
Duden-Bibliothek (HKLM-x32\...\{5C81B189-5456-40C4-9313-7FE6FA6DD64C}) (Version: 5.1.0 - Bibliographisches Institut AG)
ELOoffice (HKLM-x32\...\{C08EF2EB-27C6-4E99-B5C3-15AE8210B614}) (Version: - )
FreeCommander XE (HKLM-x32\...\FreeCommander XE_is1) (Version: - Marek Jasinski)
FreePDF (Remove only) (HKLM-x32\...\FreePDF_XP) (Version: - )
GPL Ghostscript (HKLM-x32\...\GPL Ghostscript 9.16) (Version: 9.16 - Artifex Software Inc.)
Hardcopy (HKLM-x32\...\Hardcopy) (Version: 2015.04.10 - www.hardcopy.de)
Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\{3FD0C489-0F02-481a-A3E1-9754CD396761}) (Version: - Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
KeePass Password Safe 2.29 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.29 - Dominik Reichl)
Lexware Elster (x32 Version: 15.00.00.0056 - Haufe-Lexware GmbH & Co.KG) Hidden
Lexware financial office 2015 (x32 Version: 19.06.00.0103 - Haufe-Lexware GmbH & Co.KG) Hidden
Lexware financial office plus 2015 (HKLM-x32\...\{4afb8420-9dcb-4001-b189-beb131647b6b}) (Version: 19.6.0.40 - Haufe-Lexware GmbH & Co.KG)
Lexware Info Service (x32 Version: 5.00.00.0044 - Haufe-Lexware GmbH & Co.KG) Hidden
Lexware Installations Dienst (x32 Version: 4.00.00.0005 - Haufe-Lexware GmbH & Co.KG) Hidden
Lexware online banking (x32 Version: 22.00.00.0035 - Haufe-Lexware GmbH & Co.KG) Hidden
Lexware PDF-Export 5 (x32 Version: 5.00.00.0005 - Haufe-Lexware GmbH & Co.KG) Hidden
LockHunter 3.1, 32/64 bit (HKLM\...\LockHunter_is1) (Version: - Crystal Rich Ltd)
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 37.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 de)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 37.0.2 - Mozilla)
Nero 12 (HKLM-x32\...\{80836C86-1305-40C9-B7C9-F3A75266070D}) (Version: 12.5.01900 - Nero AG)
Nuance Cloud Connector (HKLM-x32\...\{4C99EAAA-A846-4029-B500-312C5937D714}) (Version: 3.2.1026 - Nuance Communications, Inc.)
Nuance OmniPage Ultimate (HKLM-x32\...\{419512F9-D5E7-4ED2-BF99-E7F2C0176B6A}) (Version: 19.00.0000 - Nuance Communications, Inc.)
Nuance PaperPort 14 (HKLM-x32\...\{B2E8EFDC-E4FF-42A8-B305-FE06D29BB33C}) (Version: 14.5.0000 - Nuance Communications, Inc.)
Nuance PDF Create 8 (HKLM\...\{D8AD8411-A273-4560-B756-A418ED4910AD}) (Version: 8.10.6293 - Nuance Communications, Inc.)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
PDF Architect 3 (HKLM-x32\...\PDF Architect 3) (Version: 3.0.45.22485 - pdfforge GmbH)
PDF Architect 3 Create Module (x32 Version: 3.0.12.22873 - pdfforge GmbH) Hidden
PDF Architect 3 Edit Module (x32 Version: 3.0.12.22873 - pdfforge GmbH) Hidden
PDF Architect 3 View Module (x32 Version: 3.0.12.22873 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.1.1 - pdfforge)
PDF-XChange 2012 Pro (HKLM\...\{F92F0AAB-2EF6-412C-8BF4-0B11EB535280}_is1) (Version: 5.5.309.0 - Tracker Software Products Ltd)
PDF-XChange Editor (HKLM\...\{F108F0FC-D04F-412B-AA2D-0920E3E83A6D}) (Version: 5.5.312.1 - Tracker Software Products (Canada) Ltd.)
PDF-XChange Editor (HKLM-x32\...\{5400ac3b-582e-43db-8ce0-dabc2b5f4e69}) (Version: 5.5.309.0 - Tracker Software Products (Canada) Ltd.)
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
Profi cash (HKLM-x32\...\Profi cash) (Version: - )
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: 1.90 - Ghostgum Software Pty Ltd)
Scansoft PDF Create (x32 Version: - ) Hidden
Skype™ 7.3 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
Steganos Privacy Suite 15 (HKLM-x32\...\{704C8372-B1C3-4A76-AA5C-B91021B1DCFA}) (Version: 15.2.4 - Steganos Software GmbH)
SynchPst for Outlook 6.0.0.16 (HKLM-x32\...\68A5517D-0247-4EDA-9EC8-98258D5E3FD9_is1) (Version: 6.0.0.16 - Wisco)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB2889853) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUSR_{0C5B0539-7EDE-4297-947E-48890971B557}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
Wartung Samsung SCX-4623 Series (HKLM-x32\...\Samsung SCX-4623 Series) (Version: - Samsung Electronics CO.,LTD)
Welcome App (Start-up experience) (x32 Version: 12.0.15000 - Nero AG) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
06-05-2015 03:07:58 Geplanter Prüfpunkt
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {19DB299D-C0E4-465E-9A33-CE08322A99DA} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {2C262533-3D36-48C3-8A5F-8FF56F0969E3} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-04-01] (Microsoft Corporation)
Task: {41664AFF-6B41-4A89-84E7-EA5FB01EA4F3} - System32\Tasks\Microsoft Office 15 Sync Maintenance for PC2-Henna PC2 => C:\Program Files (x86)\Microsoft Office\Office15\MsoSync.exe [2015-02-10] (Microsoft Corporation)
Task: {5B95042F-9CAD-4A91-A32E-83CA71823682} - System32\Tasks\Lexware Info Service Assistent => C:\Program Files (x86)\Lexware\Update Manager\LxUpdateManager.exe [2014-09-26] (Haufe-Lexware GmbH & Co. KG)
Task: {65E6D4F0-F95A-4296-9914-2166E396AB26} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {6A7F8FE6-166C-496A-ABE8-B414D34829FF} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {6C0C9CE1-9C1A-43C0-A8B7-D3FF665C4D69} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {877B467A-FE2E-49AF-8C44-199389F082C5} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {A50646FC-91E3-4B3B-BCA9-772887F05DFA} - System32\Tasks\hcdll2_ex_x64 => C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe [2012-11-08] ()
Task: {A7E6101B-FD0A-447B-9E6D-F4DFC49B445C} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation)
Task: {C9C047DE-E946-42D6-A39D-851853C62D12} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-04-23] (Piriform Ltd)
Task: {CC666903-7C0A-4066-B967-2D5CAA01E0B5} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe [2015-02-25] (AVG Technologies)
Task: {EC2A74C2-8B0C-4DC7-B7D8-509CCA74A704} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-03-07] (Adobe Systems Incorporated)
Task: {F13C918B-0335-4431-A8B9-2FD79AAEB2DF} - \AdvancedDriverUpdaterRunAtStartup No Task File <==== ATTENTION
Task: {F894D82D-B58D-47BC-B1F5-0EF8274A636A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {FAF3E56A-ED3B-447A-B396-CAB5610601B6} - System32\Tasks\hcdll2_ex_Win32 => C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe [2013-07-17] ()
==================== Loaded Modules (whitelisted) ==============
2015-04-22 08:21 - 2014-08-27 16:31 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\txmlutil.dll
2015-04-22 08:21 - 2013-09-03 14:29 - 00101328 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdmetrics.dll
2015-04-22 08:21 - 2015-04-01 18:05 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\UI\accessl.ui
2015-04-22 08:21 - 2012-10-29 14:22 - 00152816 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdfwcore.dll
2015-05-06 12:04 - 2015-05-06 12:04 - 00790368 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_00350_003\ashttpbr.mdl
2015-05-06 12:04 - 2015-05-06 12:04 - 00711064 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_00350_003\ashttpdsp.mdl
2015-05-06 12:04 - 2015-05-06 12:04 - 02683520 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_00350_003\ashttpph.mdl
2015-05-06 12:04 - 2015-05-06 12:04 - 01326504 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_00350_003\ashttprbl.mdl
2015-02-25 09:25 - 2015-02-25 09:25 - 00712504 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\avgrepliba.dll
2015-04-22 08:21 - 2015-03-09 17:47 - 00471056 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdidntconp.dll
2015-04-22 08:21 - 2015-04-01 18:05 - 00188416 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\ui\bdidntconp.ui
2015-02-25 09:25 - 2015-02-25 09:25 - 00855864 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\tulnga.dll
2015-04-22 10:51 - 2006-02-23 11:35 - 00020480 _____ () C:\Windows\System32\FritzColorPort64.dll
2015-04-22 10:51 - 2006-02-22 10:39 - 00020480 _____ () C:\Windows\System32\FritzPort64.dll
2015-04-21 17:45 - 2012-06-21 07:25 - 00113152 _____ () C:\Windows\System32\redmon64.dll
2014-07-29 16:25 - 2014-07-29 16:25 - 00220672 _____ () C:\Program Files (x86)\Steganos Privacy Suite 15\ShellExtension.dll
2015-04-22 08:21 - 2014-08-27 16:30 - 00204280 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\txmlutil.dll
2015-04-22 08:21 - 2013-09-03 14:29 - 00095088 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdmetrics.dll
2013-03-12 02:32 - 2013-03-12 02:32 - 00624456 _____ () C:\Program Files (x86)\Common Files\ScanSoft Shared\PDF8\OutlookAddin.dll
2013-03-12 02:32 - 2013-03-12 02:32 - 00341832 _____ () C:\Program Files (x86)\Common Files\ScanSoft Shared\PDF8\MailProcessor7.dll
2015-02-10 14:13 - 2015-02-10 14:13 - 01754296 _____ () C:\Program Files (x86)\Microsoft Office\Office15\tmpod.dll
2014-01-23 07:55 - 2014-01-23 07:55 - 01030312 _____ () C:\Program Files (x86)\Microsoft Office\Office15\ADDINS\UmOutlookAddin.dll
2014-11-27 10:42 - 2014-11-27 10:42 - 00034624 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\thread_pool.dll
2014-11-27 10:47 - 2014-11-27 10:47 - 00420160 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll
2014-11-27 10:44 - 2014-11-27 10:44 - 00129344 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\EXPAT.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:A303874F
AlternateDataStreams: C:\Users\Henna\Desktop\AdwCleaner_4.203.exe:BDU
AlternateDataStreams: C:\Users\Henna\Desktop\JRT.exe:BDU
AlternateDataStreams: C:\Users\Henna\Downloads\ccsetup505.exe:BDU
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2797374447-40008444-4185456415-1001\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.178.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\StartupFolder: => "Nuance Cloud Connector.lnk"
HKLM\...\StartupApproved\Run: => "Acronis Scheduler2 Service"
HKLM\...\StartupApproved\Run32: => "StartCCC"
HKLM\...\StartupApproved\Run32: => "FreePDF Assistant"
HKLM\...\StartupApproved\Run32: => "TrueImageMonitor.exe"
HKLM\...\StartupApproved\Run32: => "AcronisTibMounterMonitor"
HKLM\...\StartupApproved\Run32: => "KeePass 2 PreLoad"
HKLM\...\StartupApproved\Run32: => "Steganos HotKeys"
HKLM\...\StartupApproved\Run32: => "SSS15 Chrome Autofill Relay"
HKLM\...\StartupApproved\Run32: => "SSS15 File Redirection Starter"
HKLM\...\StartupApproved\Run32: => "OmniPage Preload"
HKLM\...\StartupApproved\Run32: => "Nuance OmniPage Ultimate-reminder"
HKLM\...\StartupApproved\Run32: => "PDFCreHook"
HKLM\...\StartupApproved\Run32: => "PDF8 Registry Controller"
HKLM\...\StartupApproved\Run32: => "PaperPort PTD"
HKLM\...\StartupApproved\Run32: => "IndexSearch"
HKLM\...\StartupApproved\Run32: => "SCX4623_Scan2Pc"
HKLM\...\StartupApproved\Run32: => "4623 Scan2PC"
HKLM\...\StartupApproved\Run32: => "LexwareInfoService"
HKLM\...\StartupApproved\Run32: => "GrooveMonitor"
HKU\S-1-5-21-2797374447-40008444-4185456415-1001\...\StartupApproved\Run: => "SSS15 Browser Monitor"
HKU\S-1-5-21-2797374447-40008444-4185456415-1001\...\StartupApproved\Run: => "OpAgent"
HKU\S-1-5-21-2797374447-40008444-4185456415-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-2797374447-40008444-4185456415-1001\...\StartupApproved\Run: => "Skype"
==================== FirewallRules (whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [{2DF40960-F6DD-4C50-81A1-6F0FE3F8BEE1}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{85A00234-7B4F-4422-8136-A9CC57EA81C2}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{F2B36981-1C6D-4C62-96F7-D68AEA145925}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{5DFEDB64-4DEF-4AB1-A9E1-0425D49D0107}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{34B625D3-65B1-4A25-B0A0-D86B87D2C157}] => (Allow) C:\Program Files (x86)\Nuance\OmniPage19\OmniPage19.exe
FirewallRules: [{FC6E512E-0059-4E9C-8AA6-C3FA719BC829}] => (Allow) C:\Program Files (x86)\Nuance\OmniPage19\OmniPage19.exe
FirewallRules: [{F42896BE-067B-43D9-8DA6-055FAB27ADDB}] => (Allow) C:\Program Files (x86)\Nuance\OmniPage19\PPMV.exe
FirewallRules: [{459778EC-9356-49C0-9B5D-D9FEE078C132}] => (Allow) C:\Program Files (x86)\Nuance\OmniPage19\PPMV.exe
FirewallRules: [{F13723A9-3FDC-4773-8585-CFCDCD61E689}] => (Allow) C:\Program Files (x86)\Nuance\OmniPage19\Ereg\Ereg.exe
FirewallRules: [{47AB1CEB-36BB-424B-B760-7C57C837150E}] => (Allow) C:\Program Files (x86)\Nuance\OmniPage19\Ereg\Ereg.exe
FirewallRules: [{A69C87E0-A4C6-4A0F-9F72-8311C5557F00}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladinetClient.exe
FirewallRules: [{B1895FC7-0E35-4B68-8007-24860A5CFCC5}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladinetClient.exe
FirewallRules: [{8B37515D-1B13-4F3F-A0C0-0475B9C17CE3}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr.exe
FirewallRules: [{AF72E614-E769-4A28-ABB6-A1624573DFF5}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr.exe
FirewallRules: [{05BBBBAE-3EA0-4C74-A3E1-947DD93351E8}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr2003.exe
FirewallRules: [{2478B439-14C2-4598-9ECC-A758C3FC2231}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr2003.exe
FirewallRules: [{49063675-559B-4E7D-B9C8-823EFE0BCC2B}] => (Block) c:\Program Files (x86)\Corel\CorelDRAW Home & Student Suite X7\Programs\DrawHome.exe
FirewallRules: [{D9F0F792-B348-437D-85CA-CE2347AED0E3}] => (Block) c:\Program Files (x86)\Corel\CorelDRAW Home & Student Suite X7\Programs\PPHome.exe
FirewallRules: [{A51519AA-9782-4A7D-943B-E1C68A5BA2DD}] => (Allow) C:\Program Files (x86)\Advanced Driver Updater\adu.exe
FirewallRules: [{5F7032AA-296B-4F9F-8E0B-817D5FB0F670}] => (Allow) C:\Windows\twain_32\Samsung\ScanMgr.exe
FirewallRules: [{20B096E7-69E6-4C54-AB2D-EC1E14B2D252}] => (Allow) C:\Windows\twain_32\Samsung\ScanMgr.exe
FirewallRules: [{F548DD66-2B8D-4AB0-BBBD-CA7C9A951C0B}] => (Allow) C:\Windows\twain_32\Samsung\SCX4623\Scan2Pc.exe
FirewallRules: [{78C9D3F5-0CE0-4C1C-BC25-C7DD993AA066}] => (Allow) C:\Windows\twain_32\Samsung\SCX4623\Scan2Pc.exe
FirewallRules: [{EFEA19E3-349A-40F4-9DAC-837D8E5A7F12}] => (Allow) C:\Windows\twain_32\Samsung\SCX4623\Sscan2io.exe
FirewallRules: [{A9EA199B-A396-44A8-9A9C-EAF36E9C95A9}] => (Allow) C:\Windows\twain_32\Samsung\SCX4623\Sscan2io.exe
FirewallRules: [{EDA1AF35-20C6-4610-A9CB-EC1334D4BEC9}] => (Allow) C:\Program Files (x86)\Lexware\Update Service\Hmg.InstallationService.Service.exe
FirewallRules: [{DD80A232-9551-4874-ACAB-C1FCF119E6CC}] => (Allow) C:\Program Files (x86)\Lexware\Update Service\Hmg.InstallationService.Service.exe
FirewallRules: [{C8CE8120-8EA0-41E8-94BB-51F2F54F54EF}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{F55BD63D-3D59-4E43-82EA-B66BA45955CB}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{F5ECF774-FED0-409F-9986-637508C72E6F}] => (Allow) C:\Program Files (x86)\MicrosoftOffice\Office12\GROOVE.EXE
FirewallRules: [{D950C8A0-ADC6-4A1A-8069-2D5D2F50DACA}] => (Allow) C:\Program Files (x86)\MicrosoftOffice\Office12\GROOVE.EXE
FirewallRules: [{0F764D5F-DD70-438B-A4AF-CF2BF29A7D83}] => (Allow) C:\Program Files (x86)\MicrosoftOffice\Office12\ONENOTE.EXE
FirewallRules: [{7CF40BB5-D613-4AF0-B1F5-3FB1176D5406}] => (Allow) C:\Program Files (x86)\MicrosoftOffice\Office12\ONENOTE.EXE
FirewallRules: [{2EEA3A6C-4B90-4A86-89B0-F48199E25307}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{273BFFC3-DB9A-4B07-A09B-5DAC635CA6B5}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{1286B042-6E9D-438E-8A95-458238DC9428}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{D960A455-7FD0-4D8F-A145-E004C7EF6F91}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{D07A1678-7B33-4AE0-BB3E-E067887EA64E}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\outlook.exe
FirewallRules: [{D7A58484-3309-452E-92A3-30F5A0E4C090}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe
FirewallRules: [{93D55862-7348-4001-8DCB-94DE966B091B}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe
FirewallRules: [{1C6445E8-95A6-4A8D-89D9-040E6F5F7BBC}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{74151A35-5425-446C-8096-0FF6EA1046DC}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{0638652B-C507-422B-913C-C242F4980947}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe
FirewallRules: [{4BEE417C-5704-49F5-B89B-78E095C2260B}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe
FirewallRules: [{511A1855-DDDA-4726-B095-64A9958CA105}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6FEA46B0-9BC3-466C-9284-72C78F2105AB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{AA98DB16-6FDC-4E80-83FF-DD4D91ABEA95}] => (Allow) C:\Program Files (x86)\MicrosoftOffice\Office12\GROOVE.EXE
FirewallRules: [{6FA7F52A-5696-4176-ABA8-F8DC2A6B776A}] => (Allow) C:\Program Files (x86)\MicrosoftOffice\Office12\GROOVE.EXE
FirewallRules: [{8F67F174-D962-4E5E-9B27-9D3BCB60B62F}] => (Allow) C:\Program Files (x86)\MicrosoftOffice\Office12\ONENOTE.EXE
FirewallRules: [{70E945A5-8D35-4014-ACD8-341032E9DE3A}] => (Allow) C:\Program Files (x86)\MicrosoftOffice\Office12\ONENOTE.EXE
==================== Faulty Device Manager Devices =============
Name: USB camera
Description: USB camera
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (05/06/2015 04:38:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.3.9600.17667, Zeitstempel: 0x54c6f7c2
Name des fehlerhaften Moduls: PlayToDevice.dll, Version: 12.0.9600.17415, Zeitstempel: 0x5450365e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000001ae41
ID des fehlerhaften Prozesses: 0xe74
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
Vollständiger Name des fehlerhaften Pakets: Explorer.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Explorer.EXE5
Error: (05/06/2015 04:20:20 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Fehler beim Planen des Softwareschutzdiensts für den erneuten Start bei 2115-04-12T14:20:20Z. Fehlercode: 0x80040154.
Error: (05/06/2015 04:19:50 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Fehler beim Planen des Softwareschutzdiensts für den erneuten Start bei 2115-04-12T14:19:50Z. Fehlercode: 0x80040154.
Error: (05/06/2015 04:19:20 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Fehler beim Planen des Softwareschutzdiensts für den erneuten Start bei 2115-04-12T14:19:20Z. Fehlercode: 0x80040154.
Error: (05/06/2015 04:18:50 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Fehler beim Planen des Softwareschutzdiensts für den erneuten Start bei 2115-04-12T14:18:50Z. Fehlercode: 0x80040154.
Error: (05/06/2015 04:18:20 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Fehler beim Planen des Softwareschutzdiensts für den erneuten Start bei 2115-04-12T14:18:20Z. Fehlercode: 0x80040154.
Error: (05/06/2015 02:53:56 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Fehler beim Planen des Softwareschutzdiensts für den erneuten Start bei 2115-04-12T12:53:52Z. Fehlercode: 0x80040154.
Error: (05/06/2015 02:53:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: syncagentsrv.exe, Version: 17.0.0.2106, Zeitstempel: 0x5413beaf
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.8428, Zeitstempel: 0x520b1060
Ausnahmecode: 0x40000015
Fehleroffset: 0x000046b4
ID des fehlerhaften Prozesses: 0xcf0
Startzeit der fehlerhaften Anwendung: 0xsyncagentsrv.exe0
Pfad der fehlerhaften Anwendung: syncagentsrv.exe1
Pfad des fehlerhaften Moduls: syncagentsrv.exe2
Berichtskennung: syncagentsrv.exe3
Vollständiger Name des fehlerhaften Pakets: syncagentsrv.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: syncagentsrv.exe5
Error: (05/06/2015 02:51:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: loggingserver.exe, Version: 17.2.0.0, Zeitstempel: 0x51d41c91
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17736, Zeitstempel: 0x550f42c2
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00042089
ID des fehlerhaften Prozesses: 0xba8
Startzeit der fehlerhaften Anwendung: 0xloggingserver.exe0
Pfad der fehlerhaften Anwendung: loggingserver.exe1
Pfad des fehlerhaften Moduls: loggingserver.exe2
Berichtskennung: loggingserver.exe3
Vollständiger Name des fehlerhaften Pakets: loggingserver.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: loggingserver.exe5
Error: (05/06/2015 01:59:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: PPLINKS.EXE, Version: 14.5.13205.1029, Zeitstempel: 0x515e8d8c
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17736, Zeitstempel: 0x550f42c2
Ausnahmecode: 0xc000000d
Fehleroffset: 0x000f4da4
ID des fehlerhaften Prozesses: 0x1ea8
Startzeit der fehlerhaften Anwendung: 0xPPLINKS.EXE0
Pfad der fehlerhaften Anwendung: PPLINKS.EXE1
Pfad des fehlerhaften Moduls: PPLINKS.EXE2
Berichtskennung: PPLINKS.EXE3
Vollständiger Name des fehlerhaften Pakets: PPLINKS.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: PPLINKS.EXE5
System errors:
=============
Error: (05/06/2015 04:27:53 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Acronis Sync Agent Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (05/06/2015 04:27:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Nero Update" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/06/2015 04:27:51 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Corel License Validation Service V2, Powered by arvato" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/06/2015 04:27:51 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PDFProFiltSrvPP" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/06/2015 04:27:51 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PDF Architect 3 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/06/2015 04:27:51 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "GladFileMonSvc" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/06/2015 04:27:51 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Acronis Nonstop Backup Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (05/06/2015 04:27:51 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Adobe Acrobat Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/06/2015 04:27:51 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Acronis Scheduler2 Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (05/06/2015 04:27:51 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz
Percentage of memory in use: 24%
Total physical RAM: 8128.15 MB
Available physical RAM: 6175.66 MB
Total Pagefile: 9408.15 MB
Available Pagefile: 7272.61 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
==================== Drives ================================
Drive c: (System-II) (Fixed) (Total:117.52 GB) (Free:66.6 GB) NTFS
Drive d: (System-I) (Fixed) (Total:105.7 GB) (Free:24.66 GB) NTFS
Drive h: (GP-64GB-Steuer) (Removable) (Total:29.73 GB) (Free:14.49 GB) NTFS
Drive s: () (Network) (Total:916.15 GB) (Free:112.54 GB)
Drive v: () (Network) (Total:492.15 GB) (Free:139.4 GB)
Drive w: () (Network) (Total:916.15 GB) (Free:112.54 GB)
Drive x: () (Fixed) (Total:931.5 GB) (Free:202.92 GB) NTFS
Drive y: (Sicherungen) (Fixed) (Total:931.39 GB) (Free:219.62 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: FA98BE9C)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=117.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=105.7 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: E0CFA70A)
Partition: GPT Partition Type.
========================================================
Disk: 2 (Size: 931.5 GB) (Disk ID: 55D9C1D9)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
========================================================
Disk: 3 (MBR Code: Windows 7 or 8) (Size: 29.7 GB) (Disk ID: A6858073)
Partition 1: (Active) - (Size=29.7 GB) - (Type=07 NTFS)
==================== End Of Log ============================ --- --- ---
Nun die mbamlog.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 06.05.2015
Suchlauf-Zeit: 13:58:33
Logdatei: mbamlog.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.05.06.02
Rootkit Datenbank: v2015.04.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Henna
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 359345
Verstrichene Zeit: 7 Min, 19 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 78
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataContainer, In Quarantäne, [1654a2ee5238e4529bf3f0de966d9b65],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataContainer.1, In Quarantäne, [aebc3b55b4d6e2548905d2fc996abe42],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataController, In Quarantäne, [f377d9b7d0ba2f073a54587601029b65],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataController.1, In Quarantäne, [6406870953373afc6727ede161a224dc],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataTable, In Quarantäne, [2842c6cacac0340296f8d7f7748fba46],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataTable.1, In Quarantäne, [28421c74523896a0137bdfef659ece32],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataTableFields, In Quarantäne, [de8cbfd16129bc7a16789f2f7291768a],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataTableFields.1, In Quarantäne, [c3a75a3677136dc9bad48c42798ac13f],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataTableHolder, In Quarantäne, [b8b29df31b6f82b4236b28a6649f24dc],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataTableHolder.1, In Quarantäne, [5a105e320a807db9f797517da95a04fc],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.LSPLogic, In Quarantäne, [6307b8d841498fa7e2acdbf37b88659b],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.LSPLogic.1, In Quarantäne, [df8befa17911b87eb9d539953cc74eb2],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.ReadOnlyManager, In Quarantäne, [dd8d2b6578120f27494520aee3203ec2],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.ReadOnlyManager.1, In Quarantäne, [cb9fe7a924666dc9dab45876db2817e9],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.WFPController, In Quarantäne, [3a30d0c0fe8c7fb74e40349a2dd660a0],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.WFPController.1, In Quarantäne, [71f95e324a400d29fe900dc1b94a36ca],
PUP.Optional.Gambali.A, HKLM\SOFTWARE\CLASSES\APPID\Gambali.EXE, In Quarantäne, [313920708901b6800d5467687e85ad53],
PUP.Optional.Gambali.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\Gambali.EXE, In Quarantäne, [07630b85d0badf57134e99364fb4e61a],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataContainer, In Quarantäne, [87e34749addd6ec8cbc3ca04e51e3fc1],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataContainer.1, In Quarantäne, [7ded58385c2e7bbbcac4c30b1ee548b8],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataController, In Quarantäne, [a7c3f69abdcd88aed3bb21ad22e1dc24],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataController.1, In Quarantäne, [bab0cdc315757bbb6727349afc07e31d],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataTable, In Quarantäne, [e08ae2aeaedc96a05d312ea0a45fad53],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataTable.1, In Quarantäne, [0862622ebcce0d29fd910cc2c43f738d],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataTableFields, In Quarantäne, [f971860ad9b1e25426684f7fdb28da26],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataTableFields.1, In Quarantäne, [01699af652383006eda1d2fc33d024dc],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataTableHolder, In Quarantäne, [2b3f6b25cfbbfb3bf19df1ddbf4416ea],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataTableHolder.1, In Quarantäne, [0862f0a04545db5b0f7f428c91724eb2],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.LSPLogic, In Quarantäne, [c0aa2b652e5cd066484685490bf803fd],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.LSPLogic.1, In Quarantäne, [3a3048484b3f1026e0aebf0ff01337c9],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.ReadOnlyManager, In Quarantäne, [006af29ed2b857dfd9b5a02e9073ab55],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.ReadOnlyManager.1, In Quarantäne, [670309873a509c9a8905ffcfd82b3dc3],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.WFPController, In Quarantäne, [16544947ef9bd165a0ee577730d3946c],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.WFPController.1, In Quarantäne, [e486731db5d521151f6f11bdfa09857b],
PUP.Optional.Gambali.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\Gambali.EXE, In Quarantäne, [2a40652b701a6cca431e24ab010234cc],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{CD6F4F21-2287-4B46-82E5-530F4739C2B7}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{17B22A43-07EE-45AC-852C-BE612516B3FF}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{376B5603-A82C-41C6-8295-FE987FAAFFC0}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4351B7B4-6877-4868-8086-5810EEF0E6BF}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{45815B84-A33A-4144-A0F5-1F8FA0FBDD5A}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5A4ADDA0-6AF3-4FD1-B449-CA4156C4005C}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5ACB2FB1-ADB6-4B3A-ACA6-B47D213453C6}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{70A68E56-76A5-4870-8445-BC19846CF6AD}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{79B39846-AAF0-448E-A69C-BD8DD17C9354}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{87CA5D07-F5A7-4A3C-B18C-52028A56A378}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8E0A9D44-E2B9-40DC-8734-8DE53E362806}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B009BABC-3F0C-4255-9C4D-00E2836CA4C6}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F3DA2DA3-22C3-46E4-A3BE-B4A13185E6B0}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F7515862-DFE9-4673-BC9E-4A091B43F2F1}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{17B22A43-07EE-45AC-852C-BE612516B3FF}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{376B5603-A82C-41C6-8295-FE987FAAFFC0}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4351B7B4-6877-4868-8086-5810EEF0E6BF}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{45815B84-A33A-4144-A0F5-1F8FA0FBDD5A}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5A4ADDA0-6AF3-4FD1-B449-CA4156C4005C}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5ACB2FB1-ADB6-4B3A-ACA6-B47D213453C6}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{70A68E56-76A5-4870-8445-BC19846CF6AD}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{79B39846-AAF0-448E-A69C-BD8DD17C9354}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{87CA5D07-F5A7-4A3C-B18C-52028A56A378}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8E0A9D44-E2B9-40DC-8734-8DE53E362806}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B009BABC-3F0C-4255-9C4D-00E2836CA4C6}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F3DA2DA3-22C3-46E4-A3BE-B4A13185E6B0}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F7515862-DFE9-4673-BC9E-4A091B43F2F1}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{17B22A43-07EE-45AC-852C-BE612516B3FF}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{376B5603-A82C-41C6-8295-FE987FAAFFC0}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4351B7B4-6877-4868-8086-5810EEF0E6BF}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{45815B84-A33A-4144-A0F5-1F8FA0FBDD5A}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{5A4ADDA0-6AF3-4FD1-B449-CA4156C4005C}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{5ACB2FB1-ADB6-4B3A-ACA6-B47D213453C6}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{70A68E56-76A5-4870-8445-BC19846CF6AD}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{79B39846-AAF0-448E-A69C-BD8DD17C9354}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{87CA5D07-F5A7-4A3C-B18C-52028A56A378}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8E0A9D44-E2B9-40DC-8734-8DE53E362806}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B009BABC-3F0C-4255-9C4D-00E2836CA4C6}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F3DA2DA3-22C3-46E4-A3BE-B4A13185E6B0}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F7515862-DFE9-4673-BC9E-4A091B43F2F1}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{CD6F4F21-2287-4B46-82E5-530F4739C2B7}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{CD6F4F21-2287-4B46-82E5-530F4739C2B7}, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SecurityUtility Service, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 1
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
Dateien: 26
PUP.Optional.Winsock.HijackBoot, C:\Windows\System32\GambaliOff.ini, In Quarantäne, [c5a5eea268223ff77861fed65aa99c64],
PUP.Optional.Winsock.HijackBoot, C:\Windows\SysWOW64\GambaliOff.ini, In Quarantäne, [86e4256bf39711254e8ba52f33d07c84],
PUP.Optional.Gambali.A, C:\Windows\Temp\Gambali.log, In Quarantäne, [d8926a268dfd9b9b22b84b8911f255ab],
PUP.Optional.Gambali.A, C:\Windows\Temp\Gambalir.log, In Quarantäne, [a4c6038dd7b35fd7e0fb7f5544bf09f7],
PUP.Optional.Winsock.HijackBoot, C:\Windows\SysWOW64\Gambali.dll, Löschen bei Neustart, [96d4bdd306845dd94a5b431a768fff01],
PUP.Optional.Winsock.HijackBoot, C:\Windows\System32\Gambali64.dll, Löschen bei Neustart, [3b2fc9c709819c9a66404d10e322e61a],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\freebl3.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali.tlb, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali64.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\GambaliCrt.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libnspr4.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplc4.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplds4.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nss3.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssckbi.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssdbm3.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssutil3.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RfndNSIS.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia.ini, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia64.exe, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\smime3.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\SoftConfigTest.exe, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\softokn3.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\sqlite3.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ssl3.dll, In Quarantäne, [7af0741cd8b2b68099787c4b8c77b848],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Nun die AdwCleaner.txt
AdwCleaner Logfile: Code:
# AdwCleaner v4.203 - Bericht erstellt 06/05/2015 um 16:20:24
# Aktualisiert 30/04/2015 von Xplode
# Datenbank : 2015-05-05.1 [Server]
# Betriebssystem : Windows 8.1 Pro (x64)
# Benutzername : Henna - PC2
# Gestarted von : C:\Users\Henna\Desktop\AdwCleaner_4.203.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\AVG Secure Search
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Driver Updater
Ordner Gelöscht : C:\Program Files (x86)\AVG Secure Search
Ordner Gelöscht : C:\Program Files (x86)\Advanced Driver Updater
Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Users\Henna\AppData\Local\AVG Secure Search
Ordner Gelöscht : C:\Users\Henna\AppData\LocalLow\AVG Secure Search
Ordner Gelöscht : C:\Users\Henna\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Henna\AppData\Roaming\Systweak
Datei Gelöscht : C:\Users\Henna\Desktop\Goodgame Empire.lnk
***** [ Geplante Tasks ] *****
Task Gelöscht : AdvancedDriverUpdater_UPDATES
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKCU\Software\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\AVG Secure Search
Schlüssel Gelöscht : HKLM\SOFTWARE\AVG Security Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Driver Updater_is1
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v37.0.2 (x86 de)
*************************
AdwCleaner[R0].txt - [4332 Bytes] - [06/05/2015 16:14:59]
AdwCleaner[R1].txt - [4391 Bytes] - [06/05/2015 16:17:21]
AdwCleaner[R2].txt - [4450 Bytes] - [06/05/2015 16:19:11]
AdwCleaner[S0].txt - [4197 Bytes] - [06/05/2015 16:20:24]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4256 Bytes] ########## --- --- ---
[/CODE]
Und hier die letzte JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.8 (05.06.2015:1)
OS: Windows 8.1 Pro x64
Ran by Henna on 06.05.2015 at 16:27:36,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
Successfully deleted: [Task] C:\Windows\system32\tasks\AdvancedDriverUpdaterRunAtStartup
Successfully deleted: [Task] C:\Windows\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-2797374447-40008444-4185456415-1001
Successfully deleted: [Task] C:\Windows\tasks\AdvancedDriverUpdater_UPDATES.job
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{2DFF3579-5AA7-45B9-9328-1D38EA230861}
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{06E08260-0695-4EC1-A74B-1310D8899D93}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{2DFF3579-5AA7-45B9-9328-1D38EA230861}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06E08260-0695-4EC1-A74B-1310D8899D93}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{06E08260-0695-4EC1-A74B-1310D8899D93}
~~~ Files
~~~ Folders
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.05.2015 at 16:29:00,89
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Gruß
Henna |