Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-08-2014 04
Ran by **** at 2014-08-17 12:36:13
Running from C:\Users\****\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.4.0.2710 - Adobe Systems Incorporated) Hidden
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 20.2.1245.53580 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 20.2.1245.53580 - Alcor Micro Corp.) Hidden
Audials (HKLM-x32\...\{DA6EBFC9-8869-4B61-8D38-2668A395C5B0}) (Version: 11.0.54400.0 - Audials AG)
Benutzerhandbücher (x32 Version: 3.0.0.3 - Lenovo) Hidden
BitTorrent (HKCU\...\BitTorrent) (Version: 7.9.2.32355 - BitTorrent Inc.)
BlockAndSurf (HKLM-x32\...\14B128CB-7512-6580-5764-7AEBD4390FC0) (Version: - BlockAndSurf-software) <==== ATTENTION
CyberLink MediaStory (HKLM-x32\...\InstallShield_{55762F9A-FCE3-45d5-817B-051218658423}) (Version: 1.0.1314 - CyberLink Corp.)
CyberLink MediaStory (x32 Version: 1.0.1314 - CyberLink Corp.) Hidden
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.)
CyberLink PhotoDirector 3 (x32 Version: 3.0.1.4107 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.3.2.2 - Dolby Laboratories Inc)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.0.0.31 - Lenovo)
Energy Manager (x32 Version: 1.0.0.31 - Lenovo) Hidden
FlightGear v3.0.0 (HKLM\...\FlightGear_is1) (Version: - The FlightGear Team)
FreeSoftToday 014.110 (HKLM-x32\...\fst_de_110_is1) (Version: - FREESOFTTODAY) <==== ATTENTION
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.143 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6490.0 - IDT)
Intel Collaborative Processor Performance Control (HKLM-x32\...\0E7DAF70-FB54-4B91-B192-7E771C25AEEB) (Version: 1.0.0.1013 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3345 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.5.1000 - Intel Corporation)
Intel(R) Rapid Storage Technology (Version: 12.8.5.1000 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden
Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.7850 - Broadcom Corporation)
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 3.13.926.1 - Vimicro)
Lenovo Experience Improvement (HKLM\...\LenovoExperienceImprovement) (Version: 1.0.4.0 - Lenovo)
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.0.0.2105 - CyberLink Corp.) Hidden
Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.7 - CEWE COLOR AG u Co. OHG)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo Solution Center (HKLM\...\{2F45A217-E9C7-4984-B0AC-5BE31FF4712B}) (Version: 2.4.003.00 - Lenovo Group Limited)
Lenovo VeriFace (HKLM\...\Lenovo VeriFace) (Version: 5.0.13.5261 - Lenovo)
Lenovo Web Start (HKCU\...\Pokki_04bb6df446330549a2cb8d67fbd1a745025b7bd1) (Version: 1.0.2.53457 - Pokki)
Lenovo_Wireless_Driver (HKLM-x32\...\{5D642A72-8194-4A22-80DA-11FE610CCA8E}) (Version: 6.30.223.143 - Lenovo)
LibreOffice 4.2 Help Pack (German) (HKLM-x32\...\{56232F31-556D-4ABB-A039-58193778A627}) (Version: 4.2.0.4 - The Document Foundation)
LibreOffice 4.2.0.4 (HKLM-x32\...\{E043231F-34F2-4AF5-9400-0961CC15AAAE}) (Version: 4.2.0.4 - The Document Foundation)
LPT System Updater Service (x32 Version: 1.0.0.0 - LPT) Hidden <==== ATTENTION
Maxthon Cloud Browser (HKLM-x32\...\Maxthon3) (Version: 4.1.3.5000 - Maxthon International Limited)
McAfee LiveSafe – Internet Security (HKLM-x32\...\MSC) (Version: 12.8.958 - McAfee, Inc.)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden
Need For Speed™ World (HKLM-x32\...\{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1) (Version: 1.0.0.659 - Electronic Arts)
Nitro Pro 9 (HKLM\...\{4C32F7E8-A65F-4D3C-9153-9F3B57CB6872}) (Version: 9.0.5.9 - Nitro)
NVIDIA GeForce Experience 1.7 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.7 - NVIDIA Corporation)
NVIDIA Grafiktreiber 327.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.62 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.141.953 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA Systemsteuerung 327.62 (Version: 327.62 - NVIDIA Corporation) Hidden
NVIDIA Update 9.3.14 (Version: 9.3.14 - NVIDIA Corporation) Hidden
NVIDIA Update Components (Version: 9.3.14 - NVIDIA Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
PC Speed Up (HKLM\...\PCSU-SL_is1) (Version: 3.6.1.0 - Speedchecker Limited)
Plus-HD-9.1 (HKLM-x32\...\Plus-HD-9.1) (Version: 1.34.7.1 - Plus HD) <==== ATTENTION
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.)
PowerISO (HKLM-x32\...\PowerISO) (Version: 6.0 - Power Software Ltd)
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.21 - Qualcomm Atheros Inc.)
Remote Desktop Access (VuuPC) (HKLM-x32\...\VOPackage) (Version: 1.0.0.0 - CMI Limited) <==== ATTENTION
Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.16.10.61 - Client Connect LTD) <==== ATTENTION
Shopping Helper Smartbar (HKLM-x32\...\{16F8A832-DD84-4271-8B76-ACADE6DB3968}) (Version: 11.82.63.17791 - ReSoft Ltd.) <==== ATTENTION
Shopping Helper Smartbar Engine (HKCU\...\{0cc5cc23-4ebb-462a-85ae-f3bb91e618b7}) (Version: 11.82.63.17791 - ReSoft Ltd.) <==== ATTENTION
Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
Software Updater version 1.9.4 (HKLM-x32\...\Software Updater_is1) (Version: 1.9.4 - )
Spotify (HKCU\...\Spotify) (Version: 0.9.11.27.g2b1a638c - Spotify AB)
Start Menu (HKCU\...\Pokki) (Version: 0.269.2.430 - Pokki)
Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.9.1 - Synaptics Incorporated)
TmNationsForever (HKLM-x32\...\TmNationsForever_is1) (Version: - Nadeo)
UpperFind (HKLM\...\UpperFind) (Version: 2014.07.25.142836 - UpperFind)
User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
WindowsMangerProtect20.0.0.502 (HKLM-x32\...\WindowsMangerProtect) (Version: 20.0.0.502 - WindowsProtect LIMITED) <==== ATTENTION
Windows-Treiberpaket - Lenovo (ACPIVPC) System (02/17/2013 9.52.0.776) (HKLM\...\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
20-07-2014 11:08:24 Geplanter Prüfpunkt
21-07-2014 17:57:33 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
25-07-2014 18:05:20 Installed Lenovo Solution Center.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {0F6F9A1A-A3B7-4F98-90E5-3C1717FEF5A2} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {12037548-288F-494B-835D-6FA95217C97D} - System32\Tasks\Lenovo\Experience Improvement => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2013-06-03] (Lenovo)
Task: {148A3004-26E1-4CD4-ACE7-9904E076F2D0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-18] (Google Inc.)
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {243546A3-7990-4EF0-9FCC-E78EBD5F22CB} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation)
Task: {292B3B79-ACBC-40E7-A59E-4362DB42ED4B} - System32\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-5 => C:\Program Files (x86)\Plus-HD-9.1\590bb23f-9df4-4da4-8066-fab06d5a0bbf-5.exe [2014-07-21] (Plus HD)
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {2E709391-2BCC-49A5-90A7-A9F90A42126A} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {3B85BF54-36A1-49F2-980A-E831B86A877A} - System32\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-7 => C:\Program Files (x86)\Plus-HD-9.1\Plus-HD-9.1-nova.exe [2014-07-21] (Plus HD)
Task: {3B9EAE9A-6241-4035-9688-68203971319A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-18] (Google Inc.)
Task: {443537E9-F9E9-4910-9AF0-50DD9FDC7DD6} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {46E97D05-2BCB-468E-B91F-E6A75CFE428F} - System32\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-5_user => C:\Program Files (x86)\Plus-HD-9.1\590bb23f-9df4-4da4-8066-fab06d5a0bbf-5.exe [2014-07-21] (Plus HD)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {4C510E3F-5CC8-4198-8777-89926EF8FEF6} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2014-05-06] (Lenovo)
Task: {5A3313D8-D9E5-4D8B-99FD-7D63B44F6A99} - System32\Tasks\Lenovo\LSC\Time72Task => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe [2014-05-06] (Lenovo)
Task: {5AA1EA50-E62D-4D47-9046-5CA016B403FD} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\mxup.exe [2013-10-14] (Maxthon International ltd.)
Task: {63A1F9F8-670C-4CB8-AC5C-9AD5D24DE6C8} - System32\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-3 => C:\Program Files (x86)\Plus-HD-9.1\590bb23f-9df4-4da4-8066-fab06d5a0bbf-3.exe [2014-07-21] (Plus HD)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {75C383DA-F607-498B-9864-EFCA1C031B18} - System32\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-2 => C:\Program Files (x86)\Plus-HD-9.1\590bb23f-9df4-4da4-8066-fab06d5a0bbf-2.exe [2014-07-21] (Plus HD)
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {7A4E427F-9EB0-4897-9D5E-C8FC1026F8A1} - System32\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-1 => C:\Program Files (x86)\Plus-HD-9.1\Plus-HD-9.1-codedownloader.exe [2014-07-21] (Plus HD)
Task: {7B65C20E-CDFE-486F-B861-861D0D075FE9} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {8ED5F765-468E-41D5-905B-13B2765ED24C} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {92312BF6-DD9D-4CB0-8DB2-779DAEA49921} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {9FF17F1E-6DAB-448A-B407-B0F5EE621E41} - System32\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-6 => C:\Program Files (x86)\Plus-HD-9.1\Plus-HD-9.1-novainstaller.exe [2014-07-21] (Plus HD)
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A58153E6-D8D7-49F4-81D7-D3D8DD2CDBED} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {A5D165BA-5DAD-47F1-AD4A-1814DA5C05FD} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-07-21] (globalUpdate)
Task: {CED832EB-75B3-4A0E-BFB9-8EBE7222DA61} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Office2013\OFFICEICON.vbs [2013-06-03] ()
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {DF1744AD-EBD8-4902-B806-E3EE8F8DA407} - System32\Tasks\Lenovo\LSC\RebootCountTask => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe [2014-05-06] (Lenovo)
Task: {E60DAE37-5134-49BD-BFB2-ABF843D38BB7} - System32\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-11 => C:\Program Files (x86)\Plus-HD-9.1\590bb23f-9df4-4da4-8066-fab06d5a0bbf-11.exe [2014-07-21] (Plus HD)
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {EC56123E-E776-43AB-9A2E-EACB793D153B} - System32\Tasks\Microsoft\Windows\PLA\LSC Memory => Rundll32.exe C:\WINDOWS\system32\pla.dll,PlaHost "LSC Memory" "$(Arg0)"
Task: {F2F5204C-167E-454B-8D47-260B87682082} - System32\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-4 => C:\Program Files (x86)\Plus-HD-9.1\590bb23f-9df4-4da4-8066-fab06d5a0bbf-4.exe [2014-07-21] (Plus HD)
Task: {F329F74F-DAD0-49F4-A4C6-45DA848A84AC} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-05-06] (Lenovo)
Task: {F647D0C9-D28D-4C7A-86F5-6037228E1B17} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-07-11] (Microsoft Corporation)
Task: C:\WINDOWS\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-1.job => C:\Program Files (x86)\Plus-HD-9.1\Plus-HD-9.1-codedownloader.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-11.job => C:\Program Files (x86)\Plus-HD-9.1\590bb23f-9df4-4da4-8066-fab06d5a0bbf-11.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-2.job => C:\Program Files (x86)\Plus-HD-9.1\590bb23f-9df4-4da4-8066-fab06d5a0bbf-2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-3.job => C:\Program Files (x86)\Plus-HD-9.1\590bb23f-9df4-4da4-8066-fab06d5a0bbf-3.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-4.job => C:\Program Files (x86)\Plus-HD-9.1\590bb23f-9df4-4da4-8066-fab06d5a0bbf-4.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-5.job => C:\Program Files (x86)\Plus-HD-9.1\590bb23f-9df4-4da4-8066-fab06d5a0bbf-5.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-5_user.job => C:\Program Files (x86)\Plus-HD-9.1\590bb23f-9df4-4da4-8066-fab06d5a0bbf-5.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-6.job => C:\Program Files (x86)\Plus-HD-9.1\Plus-HD-9.1-novainstaller.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\590bb23f-9df4-4da4-8066-fab06d5a0bbf-7.job => C:\Program Files (x86)\Plus-HD-9.1\Plus-HD-9.1-nova.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-07-21 20:01 - 2014-07-03 07:35 - 00430888 _____ () C:\Program Files (x86)\PC Speed Up\PCSUService.exe
2013-09-04 20:13 - 2013-09-04 20:13 - 00049368 _____ () C:\Program Files\Lenovo\Bluetooth Software\btwleapi.dll
2014-06-16 14:21 - 2014-06-16 14:21 - 00034336 _____ () C:\Program Files (x86)\LPT\srpts.exe
2014-05-20 16:07 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2014-07-21 19:56 - 2014-07-21 19:56 - 00071680 _____ () C:\Users\****\AppData\Roaming\VOPackage\VOsrv.exe
2014-06-16 14:21 - 2014-06-16 14:21 - 00036384 _____ () C:\Program Files (x86)\LPT\srptsl.exe
2014-05-20 16:13 - 2014-05-20 16:13 - 00068368 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
2014-05-20 16:13 - 2014-05-20 16:13 - 00669288 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfDataStorageInterface.dll
2014-06-16 14:21 - 2014-06-16 14:21 - 00024608 _____ () C:\Program Files (x86)\LPT\srptm.exe
2014-07-23 16:32 - 2014-07-25 20:26 - 00106376 _____ () C:\Program Files (x86)\SupTab\WindowsSupportDll64.dll
2014-07-23 16:32 - 2014-07-25 20:26 - 00732040 _____ () C:\Program Files (x86)\SupTab\HpUI.exe
2014-07-16 11:16 - 2014-07-16 11:16 - 00064000 _____ () C:\Program Files (x86)\SupTab\Loader32.exe
2014-07-16 10:55 - 2014-07-16 10:55 - 00073216 _____ () C:\Program Files (x86)\SupTab\Loader64.exe
2014-07-21 20:07 - 2014-07-21 14:51 - 03320800 _____ () C:\Users\****\AppData\Local\fst_de_110\upfst_de_110.exe
2014-06-11 17:31 - 2014-06-11 17:31 - 02208520 _____ () C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe
2014-07-21 20:07 - 2014-07-21 14:51 - 03975136 _____ () C:\Program Files (x86)\fst_de_110\fst_de_110.exe
2014-07-21 20:07 - 2014-07-21 20:07 - 00130560 _____ () C:\Program Files (x86)\di9BlockAndSurf\BlockAndSurf.exe
2014-07-04 16:20 - 2014-07-07 19:15 - 00601144 _____ () C:\Users\****\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
2014-06-16 14:18 - 2014-06-16 14:18 - 00025120 _____ () C:\Users\****\AppData\Local\Smartbar\Application\Lrcnta.exe
2014-07-25 16:28 - 2014-08-17 12:31 - 00323312 _____ () C:\Program Files (x86)\UpperFind\updateUpperFind.exe
2014-07-25 21:30 - 2014-08-17 12:34 - 00323312 _____ () C:\Program Files (x86)\UpperFind\bin\utilUpperFind.exe
2014-07-25 21:31 - 2014-07-29 15:39 - 00286960 _____ () C:\Program Files (x86)\UpperFind\bin\UpperFind.PurBrowse64.exe
2014-07-21 20:01 - 2014-07-03 07:35 - 00585600 _____ () C:\Program Files (x86)\PC Speed Up\sqlite3.dll
2014-06-16 14:21 - 2014-06-16 14:21 - 00044064 _____ () C:\Program Files (x86)\LPT\srptc.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00018976 _____ () C:\Program Files (x86)\LPT\Smartbar.Common.dll
2014-06-16 14:21 - 2014-06-16 14:21 - 00060960 _____ () C:\Program Files (x86)\LPT\srut.dll
2014-05-20 15:25 - 2013-09-04 01:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-06-16 14:21 - 2014-06-16 14:21 - 00078368 _____ () C:\Program Files (x86)\LPT\srpt.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00067616 _____ () C:\Program Files (x86)\LPT\sppsm.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00157216 _____ () C:\Program Files (x86)\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00028704 _____ () C:\Program Files (x86)\LPT\Smartbar.Personalization.Common.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00167456 _____ () C:\Program Files (x86)\LPT\Smartbar.Infrastructure.Utilities.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00047648 _____ () C:\Program Files (x86)\LPT\srbu.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00026656 _____ () C:\Program Files (x86)\LPT\srpdm.dll
2014-06-16 14:18 - 2014-06-16 14:18 - 00028192 _____ () C:\Program Files (x86)\LPT\ProxySettings.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00047136 _____ () C:\Program Files (x86)\LPT\Smartbar.Monetization.Proxy.ProxyService.dll
2014-06-16 14:18 - 2014-06-16 14:18 - 00054304 _____ () C:\Program Files (x86)\LPT\Proxy.Lib.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00029216 _____ () C:\Program Files (x86)\LPT\sreu.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00055840 _____ () C:\Program Files (x86)\LPT\srprl.dll
2014-06-16 14:18 - 2014-06-16 14:18 - 00050208 _____ () C:\Program Files (x86)\LPT\lrrot.dll
2014-07-23 16:32 - 2014-07-25 20:26 - 00093576 _____ () C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll
2014-07-04 16:20 - 2014-07-07 19:15 - 36966968 _____ () C:\Users\****\AppData\Roaming\Spotify\Data\libcef.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00046080 _____ () C:\Program Files (x86)\Audials\Audials 11\boost_thread-vc90-mt-1_39.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00045056 _____ () C:\Program Files (x86)\Audials\Audials 11\boost_date_time-vc90-mt-1_39.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00068360 _____ () C:\Program Files (x86)\Audials\Audials 11\CrashRpt.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00409352 _____ () C:\Program Files (x86)\Audials\Audials 11\SQLite3.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00545032 _____ () C:\Program Files (x86)\Audials\Audials 11\StreamingClient.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00614912 _____ () C:\Program Files (x86)\Audials\Audials 11\boost_regex-vc90-mt-1_39.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00012800 _____ () C:\Program Files (x86)\Audials\Audials 11\boost_system-vc90-mt-1_39.dll
2014-07-21 19:59 - 2014-07-21 19:59 - 00283136 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Utils\b1b0ada49bd510acb11cff9dcefc34cc\Utils.ni.dll
2014-07-21 19:59 - 2014-07-21 19:59 - 00582656 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\ManagedInterfaces\6bb51b5339df42f85481cf4a2dae1812\ManagedInterfaces.ni.dll
2014-07-21 19:59 - 2014-07-21 19:59 - 00174592 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\fastJSON\1c10c85d1fe7c70d10f088694a0a6a9a\fastJSON.ni.dll
2014-07-21 19:59 - 2014-07-21 19:59 - 00507392 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\RSControls\2e588088757572d871eead30658adb0a\RSControls.ni.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00046624 _____ () C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00071712 _____ () C:\Users\****\AppData\Local\Smartbar\Application\srau.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00167456 _____ () C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 02337824 _____ () C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00068640 _____ () C:\Users\****\AppData\Local\Smartbar\Application\spbl.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00157216 _____ () C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00015904 _____ () C:\Users\****\AppData\Local\Smartbar\Application\siem.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00067616 _____ () C:\Users\****\AppData\Local\Smartbar\Application\sppsm.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00698400 _____ () C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00016416 _____ () C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00080416 _____ () C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00028704 _____ () C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll
2014-06-16 14:21 - 2014-06-16 14:21 - 00060960 _____ () C:\Users\****\AppData\Local\Smartbar\Application\srut.dll
2014-06-16 14:21 - 2014-06-16 14:21 - 00031264 _____ () C:\Users\****\AppData\Local\Smartbar\Application\srsbs.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00067104 _____ () C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00151072 _____ () C:\Users\****\AppData\Local\Smartbar\Application\smti.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00032800 _____ () C:\Users\****\AppData\Local\Smartbar\Application\srom.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00032288 _____ () C:\Users\****\AppData\Local\Smartbar\Application\smtu.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00040992 _____ () C:\Users\****\AppData\Local\Smartbar\Application\smta.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00047648 _____ () C:\Users\****\AppData\Local\Smartbar\Application\srbu.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00026144 _____ () C:\Users\****\AppData\Local\Smartbar\Application\sgml.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00063520 _____ () C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00026656 _____ () C:\Users\****\AppData\Local\Smartbar\Application\srpdm.dll
2014-06-16 14:18 - 2014-06-16 14:18 - 00045088 _____ () C:\Users\****\AppData\Local\Smartbar\Application\MACTrackBarLib.dll
2014-06-16 14:10 - 2014-06-16 14:10 - 00026656 _____ () C:\Users\****\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00036896 _____ () C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00194592 _____ () C:\Users\****\AppData\Local\Smartbar\Application\sgmu.dll
2014-05-12 11:21 - 2014-05-12 11:21 - 00061440 _____ () C:\Users\****\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00257056 _____ () C:\Users\****\AppData\Local\Smartbar\Application\srns.dll
2014-07-07 19:15 - 2014-07-07 19:15 - 00867896 _____ () C:\Users\****\AppData\Roaming\Spotify\Data\ffmpegsumo.dll
2014-07-04 16:20 - 2014-07-07 19:15 - 00886840 _____ () C:\Users\****\AppData\Roaming\Spotify\Data\libglesv2.dll
2014-07-04 16:20 - 2014-07-07 19:15 - 00108600 _____ () C:\Users\****\AppData\Roaming\Spotify\Data\libegl.dll
2014-01-17 18:32 - 2014-01-17 18:32 - 00569856 _____ () C:\Users\****\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll
2014-01-17 18:32 - 2014-01-17 18:32 - 01400846 _____ () C:\Users\****\AppData\Local\Pokki\Engine\avcodec-54.dll
2014-01-17 18:32 - 2014-01-17 18:32 - 00151054 _____ () C:\Users\****\AppData\Local\Pokki\Engine\avutil-51.dll
2014-01-17 18:32 - 2014-01-17 18:32 - 00222734 _____ () C:\Users\****\AppData\Local\Pokki\Engine\avformat-54.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00101408 _____ () C:\Users\****\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll
2014-07-21 20:07 - 2014-07-21 20:07 - 00195072 _____ () C:\Program Files (x86)\di9BlockAndSurf\176.dll
2014-06-16 14:20 - 2014-06-16 14:20 - 00142368 _____ () C:\Users\****\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll
2014-08-17 12:35 - 2014-08-15 12:12 - 00240128 _____ () C:\Program Files (x86)\UpperFind\bin\UpperFindDsp.dll
2014-07-25 21:31 - 2014-08-17 11:41 - 00096496 _____ () C:\Program Files (x86)\UpperFind\bin\UpperFind.BrowserAdapter.exe
2014-06-16 14:18 - 2014-06-16 14:18 - 00317984 _____ () C:\Program Files (x86)\LPT\Resources\ntdis_32.dll
2014-07-25 21:31 - 2014-08-17 11:41 - 00195312 _____ () C:\Program Files (x86)\UpperFind\bin\UpperFindBAApp.dll
2014-08-17 12:09 - 2014-08-07 05:20 - 00718152 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\libglesv2.dll
2014-08-17 12:09 - 2014-08-07 05:20 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\libegl.dll
2014-08-17 12:09 - 2014-08-07 05:20 - 01732936 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\ffmpegsumo.dll
2014-08-17 12:09 - 2014-08-07 05:20 - 14669128 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\PepperFlash\pepflashplayer.dll
2014-06-16 14:18 - 2014-06-16 14:18 - 00034848 _____ () C:\Users\****\AppData\Local\Smartbar\Application\lrcnt.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Windows:nlsPreferences
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/17/2014 00:33:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.17126, Zeitstempel: 0x53882e30
Name des fehlerhaften Moduls: jscript9.dll, Version: 11.0.9600.17207, Zeitstempel: 0x53a217f1
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00008737
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Vollständiger Name des fehlerhaften Pakets: IEXPLORE.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: IEXPLORE.EXE5
Error: (08/17/2014 00:30:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.17126, Zeitstempel: 0x53882e30
Name des fehlerhaften Moduls: jscript9.dll, Version: 11.0.9600.17207, Zeitstempel: 0x53a217f1
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00008737
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Vollständiger Name des fehlerhaften Pakets: IEXPLORE.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: IEXPLORE.EXE5
Error: (08/17/2014 00:22:12 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm IEXPLORE.EXE, Version 11.0.9600.17126 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: ac4
Startzeit: 01cfba03d624ab39
Endzeit: 4294967295
Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Berichts-ID: 57efd37c-25f8-11e4-825a-2025648809c8
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (08/17/2014 00:13:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.17126, Zeitstempel: 0x53882e30
Name des fehlerhaften Moduls: jscript9.dll, Version: 11.0.9600.17207, Zeitstempel: 0x53a217f1
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00008737
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Vollständiger Name des fehlerhaften Pakets: IEXPLORE.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: IEXPLORE.EXE5
Error: (08/17/2014 00:06:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.17126, Zeitstempel: 0x53882e30
Name des fehlerhaften Moduls: jscript9.dll, Version: 11.0.9600.17207, Zeitstempel: 0x53a217f1
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00008737
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Vollständiger Name des fehlerhaften Pakets: IEXPLORE.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: IEXPLORE.EXE5
Error: (07/26/2014 10:55:20 AM) (Source: Perflib) (EventID: 1023) (User: )
Description: rdyboost4
Error: (07/21/2014 08:11:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: hl.exe, Version: 1.1.1.1, Zeitstempel: 0x48feaf5a
Name des fehlerhaften Moduls: steamclient.dll, Version: 0.0.0.0, Zeitstempel: 0x4aa7bb95
Ausnahmecode: 0xc0000417
Fehleroffset: 0x000268d3
ID des fehlerhaften Prozesses: 0x215c
Startzeit der fehlerhaften Anwendung: 0xhl.exe0
Pfad der fehlerhaften Anwendung: hl.exe1
Pfad des fehlerhaften Moduls: hl.exe2
Berichtskennung: hl.exe3
Vollständiger Name des fehlerhaften Pakets: hl.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: hl.exe5
Error: (07/21/2014 08:11:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: hl.exe, Version: 1.1.1.1, Zeitstempel: 0x48feaf5a
Name des fehlerhaften Moduls: steamclient.dll, Version: 0.0.0.0, Zeitstempel: 0x4aa7bb95
Ausnahmecode: 0xc0000417
Fehleroffset: 0x000268d3
ID des fehlerhaften Prozesses: 0x21e8
Startzeit der fehlerhaften Anwendung: 0xhl.exe0
Pfad der fehlerhaften Anwendung: hl.exe1
Pfad des fehlerhaften Moduls: hl.exe2
Berichtskennung: hl.exe3
Vollständiger Name des fehlerhaften Pakets: hl.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: hl.exe5
Error: (07/21/2014 08:11:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: hl.exe, Version: 1.1.1.1, Zeitstempel: 0x48feaf5a
Name des fehlerhaften Moduls: steamclient.dll, Version: 0.0.0.0, Zeitstempel: 0x4aa7bb95
Ausnahmecode: 0xc0000417
Fehleroffset: 0x000268d3
ID des fehlerhaften Prozesses: 0xd04
Startzeit der fehlerhaften Anwendung: 0xhl.exe0
Pfad der fehlerhaften Anwendung: hl.exe1
Pfad des fehlerhaften Moduls: hl.exe2
Berichtskennung: hl.exe3
Vollständiger Name des fehlerhaften Pakets: hl.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: hl.exe5
Error: (07/21/2014 08:10:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: hl.exe, Version: 1.1.1.1, Zeitstempel: 0x48feaf5a
Name des fehlerhaften Moduls: steamclient.dll, Version: 0.0.0.0, Zeitstempel: 0x4aa7bb95
Ausnahmecode: 0xc0000417
Fehleroffset: 0x000268d3
ID des fehlerhaften Prozesses: 0x16f0
Startzeit der fehlerhaften Anwendung: 0xhl.exe0
Pfad der fehlerhaften Anwendung: hl.exe1
Pfad des fehlerhaften Moduls: hl.exe2
Berichtskennung: hl.exe3
Vollständiger Name des fehlerhaften Pakets: hl.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: hl.exe5
System errors:
=============
Error: (08/17/2014 00:19:20 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252.
Error: (08/17/2014 00:19:20 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252.
Error: (08/17/2014 00:10:37 PM) (Source: DCOM) (EventID: 10010) (User: ****PC)
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (07/29/2014 07:37:48 PM) (Source: DCOM) (EventID: 10010) (User: ****PC)
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (07/29/2014 07:21:38 PM) (Source: DCOM) (EventID: 10010) (User: ****PC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (07/29/2014 07:10:17 PM) (Source: DCOM) (EventID: 10010) (User: ****PC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (07/29/2014 06:52:51 PM) (Source: DCOM) (EventID: 10010) (User: ****PC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (07/29/2014 06:52:21 PM) (Source: DCOM) (EventID: 10010) (User: ****PC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (07/27/2014 03:02:52 AM) (Source: DCOM) (EventID: 10010) (User: ****PC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (07/27/2014 03:02:22 AM) (Source: DCOM) (EventID: 10010) (User: ****PC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Microsoft Office Sessions:
=========================
Error: (08/17/2014 00:33:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: IEXPLORE.EXE11.0.9600.1712653882e30jscript9.dll11.0.9600.1720753a217f1c000000500008737
Error: (08/17/2014 00:30:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: IEXPLORE.EXE11.0.9600.1712653882e30jscript9.dll11.0.9600.1720753a217f1c000000500008737
Error: (08/17/2014 00:22:12 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17126ac401cfba03d624ab394294967295C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE57efd37c-25f8-11e4-825a-2025648809c8
Error: (08/17/2014 00:13:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: IEXPLORE.EXE11.0.9600.1712653882e30jscript9.dll11.0.9600.1720753a217f1c000000500008737
Error: (08/17/2014 00:06:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: IEXPLORE.EXE11.0.9600.1712653882e30jscript9.dll11.0.9600.1720753a217f1c000000500008737
Error: (07/26/2014 10:55:20 AM) (Source: Perflib) (EventID: 1023) (User: )
Description: rdyboost4
Error: (07/21/2014 08:11:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: hl.exe1.1.1.148feaf5asteamclient.dll0.0.0.04aa7bb95c0000417000268d3215c01cfa50f3749c90fC:\Games\Counter-Strike\hl.exec:\games\counter-strike\steamclient.dll750d76c8-1102-11e4-8259-342387f9c098
Error: (07/21/2014 08:11:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: hl.exe1.1.1.148feaf5asteamclient.dll0.0.0.04aa7bb95c0000417000268d321e801cfa50f314a2cc5C:\Games\Counter-Strike\hl.exec:\games\counter-strike\steamclient.dll6f0c009a-1102-11e4-8259-342387f9c098
Error: (07/21/2014 08:11:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: hl.exe1.1.1.148feaf5asteamclient.dll0.0.0.04aa7bb95c0000417000268d3d0401cfa50f2eed66bcC:\Games\Counter-Strike\hl.exec:\games\counter-strike\steamclient.dll6caf7355-1102-11e4-8259-342387f9c098
Error: (07/21/2014 08:10:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: hl.exe1.1.1.148feaf5asteamclient.dll0.0.0.04aa7bb95c0000417000268d316f001cfa50f13abfbd0C:\Games\Counter-Strike\hl.exec:\games\counter-strike\steamclient.dll517166e9-1102-11e4-8259-342387f9c098
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4702MQ CPU @ 2.20GHz
Percentage of memory in use: 55%
Total physical RAM: 8116.27 MB
Available physical RAM: 3643.56 MB
Total Pagefile: 16820.27 MB
Available Pagefile: 12329.95 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:424.26 GB) (Free:356.09 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.9 GB) NTFS
Drive e: (PUBLIC_ENEMIES) (CDROM) (Total:6.96 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 9440B80C)
Partition: GPT Partition Type.
==================== End Of Log ============================ GMER: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-08-17 12:53:18
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000036 ST500LT012-1DG142 rev.0002LVM1 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\****\AppData\Local\Temp\kwtdqpod.sys
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\system32\nvvsvc.exe[9192] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff897bf169a 4 bytes [BF, 97, F8, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[9192] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff897bf16a2 4 bytes [BF, 97, F8, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[9192] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff897bf181a 4 bytes [BF, 97, F8, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[9192] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff897bf1832 4 bytes [BF, 97, F8, 7F]
.text C:\WINDOWS\Explorer.EXE[6748] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff897bf169a 4 bytes [BF, 97, F8, 7F]
.text C:\WINDOWS\Explorer.EXE[6748] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff897bf16a2 4 bytes [BF, 97, F8, 7F]
.text C:\WINDOWS\Explorer.EXE[6748] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff897bf181a 4 bytes [BF, 97, F8, 7F]
.text C:\WINDOWS\Explorer.EXE[6748] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff897bf1832 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4124] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff897bf169a 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4124] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff897bf16a2 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4124] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff897bf181a 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4124] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff897bf1832 4 bytes [BF, 97, F8, 7F]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[7132] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff897bf169a 4 bytes [BF, 97, F8, 7F]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[7132] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff897bf16a2 4 bytes [BF, 97, F8, 7F]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[7132] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff897bf181a 4 bytes [BF, 97, F8, 7F]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[7132] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff897bf1832 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[3892] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff897bf169a 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[3892] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff897bf16a2 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[3892] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff897bf181a 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[3892] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff897bf1832 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[3892] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ff8914c1f6a 4 bytes [4C, 91, F8, 7F]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[3892] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ff8914c1f82 4 bytes [4C, 91, F8, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe[5224] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ff897bf169a 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe[5224] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ff897bf16a2 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe[5224] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ff897bf181a 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe[5224] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ff897bf1832 4 bytes [BF, 97, F8, 7F]
.text c:\PROGRA~1\mcafee\vul\mcvulctr.exe[7928] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ff897bf169a 4 bytes [BF, 97, F8, 7F]
.text c:\PROGRA~1\mcafee\vul\mcvulctr.exe[7928] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ff897bf16a2 4 bytes [BF, 97, F8, 7F]
.text c:\PROGRA~1\mcafee\vul\mcvulctr.exe[7928] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ff897bf181a 4 bytes [BF, 97, F8, 7F]
.text c:\PROGRA~1\mcafee\vul\mcvulctr.exe[7928] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ff897bf1832 4 bytes [BF, 97, F8, 7F]
.text c:\PROGRA~1\mcafee\vul\MCVULA~2.EXE[616] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ff897bf169a 4 bytes [BF, 97, F8, 7F]
.text c:\PROGRA~1\mcafee\vul\MCVULA~2.EXE[616] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ff897bf16a2 4 bytes [BF, 97, F8, 7F]
.text c:\PROGRA~1\mcafee\vul\MCVULA~2.EXE[616] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ff897bf181a 4 bytes [BF, 97, F8, 7F]
.text c:\PROGRA~1\mcafee\vul\MCVULA~2.EXE[616] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ff897bf1832 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files (x86)\UpperFind\bin\UpperFind.PurBrowse64.exe[7552] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff897bf169a 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files (x86)\UpperFind\bin\UpperFind.PurBrowse64.exe[7552] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff897bf16a2 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files (x86)\UpperFind\bin\UpperFind.PurBrowse64.exe[7552] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff897bf181a 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files (x86)\UpperFind\bin\UpperFind.PurBrowse64.exe[7552] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff897bf1832 4 bytes [BF, 97, F8, 7F]
.text C:\WINDOWS\SysWOW64\rundll32.exe[10140] C:\Program Files (x86)\UpperFind\bin\UpperFindDsp.dll!Enum + 1 0000000070c61001 4 bytes [DB, FF, D3, 91]
.text C:\WINDOWS\SysWOW64\rundll32.exe[10140] C:\Program Files (x86)\UpperFind\bin\UpperFindDsp.dll!Enum + 6 0000000070c61006 4 bytes {JMP 0xffffffff91d3586b}
.text C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe[3496] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ff897bf169a 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe[3496] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ff897bf16a2 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe[3496] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ff897bf181a 4 bytes [BF, 97, F8, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe[3496] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ff897bf1832 4 bytes [BF, 97, F8, 7F]
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [5740:7116] fffff960009a5b90
Thread C:\WINDOWS\SysWOW64\rundll32.exe [10140:8956] 00000000029a4c20
---- Processes - GMER 2.1 ----
Process C:\Users\****\AppData\Roaming\VOPackage\VOsrv.exe (*** suspicious ***) @ C:\Users\****\AppData\Roaming\VOPackage\VOsrv.exe [2492](2014-07-21 17:56:44) 0000000000ea0000
Library C:\Users\****\AppData\Local\Pokki\Engine\libPokki.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Pokki\Engine\HostAppService.exe [3944] (Chromium/The Chromium Authors)(2014-03-20 22:40:48) 000000005c940000
Library C:\Users\****\AppData\Local\Pokki\Engine\icudt.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Pokki\Engine\HostAppService.exe [3944] (ICU Data DLL/The ICU Project)(2014-01-17 16:32:58) 000000005ba50000
Library C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000004e80000
Library C:\Users\****\AppData\Local\Smartbar\Application\srau.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000005120000
Library C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000005140000
Library C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000005900000
Library C:\Users\****\AppData\Local\Smartbar\Application\spbl.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000005490000
Library C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 00000000054d0000
Library C:\Users\****\AppData\Local\Smartbar\Application\siem.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000005550000
Library C:\Users\****\AppData\Local\Smartbar\Application\sppsm.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 00000000055b0000
Library C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000005600000
Library C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000005cb0000
Library C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000005d20000
Library C:\Users\****\AppData\Local\Smartbar\Application\srsbs.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000006400000
Library C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000008270000
Library C:\Users\****\AppData\Local\Smartbar\Application\smti.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 00000000083d0000
Library C:\Users\****\AppData\Local\Smartbar\Application\srom.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000008350000
Library C:\Users\****\AppData\Local\Smartbar\Application\smtu.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000008430000
Library C:\Users\****\AppData\Local\Smartbar\Application\smta.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 0000000008450000
Library C:\Users\****\AppData\Local\Smartbar\Application\srbu.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 000000000a180000
Library C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 000000000a1e0000
Library C:\Users\****\AppData\Local\Smartbar\Application\srpdm.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 000000000a1d0000
Library C:\Users\****\AppData\Local\Smartbar\Application\MACTrackBarLib.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 000000000b7a0000
Library C:\Users\****\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 000000000b7d0000
Library C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 000000000b970000
Library C:\Users\****\AppData\Local\Smartbar\Application\sgmu.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 000000000a260000
Library C:\Users\****\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 000000000a2e0000
Library C:\Users\****\AppData\Local\Smartbar\Application\Interop.WMPLib.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Smartbar.exe [4584] (FILE NOT FOUND) 000000000a570000
Library C:\Users\****\AppData\Local\Pokki\Engine\libPokki.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Pokki\Engine\HostAppService.exe [6392] (Chromium/The Chromium Authors)(2014-03-20 22:40:48) 000000005c940000
Library C:\Users\****\AppData\Local\Pokki\Engine\icudt.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Pokki\Engine\HostAppService.exe [6392] (ICU Data DLL/The ICU Project)(2014-01-17 16:32:58) 000000005ba50000
Library C:\Users\****\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Pokki\Engine\HostAppService.exe [6392](2014-01-17 16:32:58) 000000005b030000
Library C:\Users\****\AppData\Local\Pokki\Engine\avcodec-54.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Pokki\Engine\HostAppService.exe [6392](2014-01-17 16:32:58) 000000005ae30000
Library C:\Users\****\AppData\Local\Pokki\Engine\avutil-51.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Pokki\Engine\HostAppService.exe [6392](2014-01-17 16:32:56) 000000005c590000
Library C:\Users\****\AppData\Local\Pokki\Engine\avformat-54.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Pokki\Engine\HostAppService.exe [6392](2014-01-17 16:32:56) 000000005c470000
Library C:\ProgramData\Windows Genuine Advantage\{661450B0-4E20-44FB-8E7C-BF52EB469422}\api-ms-win-system-d3d11ref-l1-1-0.dll (*** suspicious ***) @ C:\WINDOWS\SysWOW64\regsvr32.exe [12948] ( /Microsoft Corporation)(2014-08-17 10:18:23) 0000000050900000
Library C:\Users\****\AppData\Local\Smartbar\Application\lrcnt.dll (*** suspicious ***) @ C:\Users\****\AppData\Local\Smartbar\Application\Lrcnta.exe [10324] (FILE NOT FOUND) 0000000004950000
Library C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_3.0.176.1_x64__bq6yxensn79aw\McCloudShim.dll (*** suspicious ***) @ C:\WINDOWS\system32\wwahost.exe [5960](2014-07-05 08:44:42) 00007ff8902d0000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- Anmerkung: Bei dem GMER-Scan erschien zweimal der Hinweis, dass auf irgendwelche Prozesse nicht zugegriffen werden könne, weil sie schon verwendet würden (oder so ähnlich). Ich hoffe, ich habe nicht vergessen, irgendwelche laufenden Programme zu schließen während des Scans (wie in der Anleitung stand), soweit ich weiß, hatte ich alle mir bekannten laufenden Prozesse beendet. Ich hoffe, das Logfile nützt euch auch so.
Vielen Dank schonmal im Voraus! |