Hi,
danke für Deine Hilfe! Kommend die beiden Logfiles :
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by Zeus1 (administrator) on Prometheus on 04-02-2015 09:41:05
Running from C:\Users\Zeus1\Downloads
Loaded Profiles: Zeus1 (Available profiles: Zeus1 & Test-gu & Administrator)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvwmi64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Novell, Inc.) C:\Program Files\Novell\Client\XTier\Services\xtsvcmgr.exe
(COC AG) C:\Program Files\COC AG\Docunize 2013\DocunizeSyncService.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Anti-Virus\FSGK32ST.exe
() C:\Program Files\Novell\Filr\FilrCacheLib.Hosting.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Anti-Virus\fsgk32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Common\FSMA32.EXE
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Common\FSHDLL32.EXE
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Common\FSHDLL64.EXE
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\ORSP Client\fsorsp.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Greenshot) C:\Program Files\Greenshot\Greenshot.exe
(Microsoft Corporation) C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(C4B Com For Business AG) C:\Program Files (x86)\XPhone40\XPhone.exe
(Novell, Inc.) C:\Program Files (x86)\Novell\Messenger\NMCL32.exe
(Dropbox, Inc.) C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\Dropbox.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Common\FSM32.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Anti-Virus\fssm32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\FWES\program\fsdfwd.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Common\FNRB32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Common\FIH32.exe
(C4B Com For Business AG) C:\Program Files (x86)\Common Files\C4B\Server\XPLogonUM.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Anti-Virus\fsav32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\mapisp32.exe
() C:\Program Files (x86)\mRemoteNG\mRemoteNG.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(NVIDIA Corporation) C:\Windows\System32\nvwmi64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(AbstractSpoon Software) C:\Users\Zeus1\Documents\ToDoListPortable\App\ToDoList\ToDoList.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\Infrastructure\Virtual Infrastructure Client\Launcher\VpxClient.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Spotify Ltd) C:\Users\Zeus1\AppData\Roaming\Spotify\spotify.exe
() C:\Users\Zeus1\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Zeus1\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Zeus1\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Zeus1\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Zeus1\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.5\Internet Explorer\vmware-vmrc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(johnsadventures.com) C:\Program Files (x86)\John's Background Switcher\BackgroundSwitcher.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11855976 2011-05-31] (Realtek Semiconductor)
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2722080 2013-08-09] ()
HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [495616 2014-05-12] (Greenshot)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-05-25] (shbox.de)
HKLM-x32\...\Run: [MMReminderService] => C:\Program Files (x86)\Mindjet\MindManager 10\MMReminderService.exe [38248 2012-02-27] (Mindjet)
HKLM-x32\...\Run: [F-Secure Manager] => C:\Program Files (x86)\F-Secure\Common\FSM32.EXE [347688 2014-07-01] (F-Secure Corporation)
HKLM-x32\...\Run: [F-Secure TNB] => C:\Program Files (x86)\F-Secure\FSGUI\TNBUtil.exe [1969192 2014-07-01] (F-Secure Corporation)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe\KeePass.exe [2065408 2013-11-03] (Dominik Reichl)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\Run: [BackgroundSwitcher] => C:\Program Files (x86)\John's Background Switcher\BackgroundSwitcher.exe [117400 2014-06-25] (johnsadventures.com)
HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\Run: [SkyDrive] => C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [277672 2014-09-25] (Microsoft Corporation)
HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\Run: [XPhone] => C:\Program Files (x86)\XPhone40\XPhone.exe [13540424 2013-05-01] (C4B Com For Business AG)
HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\Run: [Spotify] => C:\Users\Zeus1\AppData\Roaming\Spotify\Spotify.exe [6737976 2015-01-19] (Spotify Ltd)
HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\RunOnce: [Uninstall C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64"
HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\RunOnce: [Uninstall C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328"
HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\RunOnce: [Uninstall C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64"
HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\RunOnce: [Uninstall C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714"
HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\MountPoints2: {88f09027-db06-11e3-991b-2c27d735c49f} - D:\JetFlash220.exe
Lsa: [Authentication Packages] msv1_0 ncv1_0
Lsa: [Notification Packages] scecli iPrntWinCredMan
Startup: C:\Users\Test-gu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Test-gu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Zeus1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Zeus1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [1FilrInSyncOverlayExt] -> {B8FA9E43-38E6-4654-8A13-FF905AD22CE5} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [2FilrOutOfSyncOverlayExt] -> {60650AA8-0BCC-4253-BA44-DE96CA281F02} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [3FilrConflictOverlayExt] -> {052AFD79-F0D7-4B26-99C2-14D2AAA37503} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [HardLinkMenu] -> {0A479751-02BC-11d3-A855-0004AC2568AA} => C:\Program Files\LinkShellExtension\HardlinkShellExt.dll (Hermann Schinagl)
ShellIconOverlayIdentifiers: [IconOverlayHardLink] -> {0A479751-02BC-11d3-A855-0004AC2568DD} => C:\Program Files\LinkShellExtension\HardlinkShellExt.dll (Hermann Schinagl)
ShellIconOverlayIdentifiers: [IconOverlaySymbolicLink] -> {0A479751-02BC-11d3-A855-0004AC2568EE} => C:\Program Files\LinkShellExtension\HardlinkShellExt.dll (Hermann Schinagl)
ShellIconOverlayIdentifiers-x32: [HardLinkMenu] -> {0A479751-02BC-11d3-A855-0004AC2568AA} => C:\Program Files\LinkShellExtension\32\HardlinkShellExt.dll (Hermann Schinagl)
ShellIconOverlayIdentifiers-x32: [IconOverlayHardLink] -> {0A479751-02BC-11d3-A855-0004AC2568DD} => C:\Program Files\LinkShellExtension\32\HardlinkShellExt.dll (Hermann Schinagl)
ShellIconOverlayIdentifiers-x32: [IconOverlaySymbolicLink] -> {0A479751-02BC-11d3-A855-0004AC2568EE} => C:\Program Files\LinkShellExtension\32\HardlinkShellExt.dll (Hermann Schinagl)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3033516151-3775350169-36420636-1106\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.heise.de/newsticker
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{3917915B-878D-42E1-8708-932D9FDEC887}: [NameServer] 10.1.14.1
FireFox:
========
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @novell.com/iPrint -> C:\Windows\SysWOW64 ()
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @vmware.com/vmrc,version=5.1.0.00000 -> C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.1\Firefox\np-vmware-vmrc.dll No File
FF Plugin-x32: @vmware.com/vmrc,version=5.5.0.00000 -> C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.5\Firefox\np-vmware-vmrc.dll (VMware, Inc.)
FF Plugin-x32: vmware.com/client-support-plugin -> C:\Program Files (x86)\VMware\Client Integration Plug-in 5.5\npVMwareClientSupportPlugin-5-5-0.dll (VMware, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Zeus1\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.heise.de
CHR StartupUrls: Default -> "hxxp://www.google.de/", "hxxp://www.heise.de/", "hxxp://www.facebook.de/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-23]
CHR Extension: (Google Docs) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-23]
CHR Extension: (Google Drive) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-23]
CHR Extension: (YouTube) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-23]
CHR Extension: (Adblock Plus) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-09-23]
CHR Extension: (Silverlight for Chrome) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgnklfhofbcfndknbonklnijndoeknal [2015-02-02]
CHR Extension: (Google-Suche) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-23]
CHR Extension: (Hola Better Internet Engine) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\epbfmioobedknooiakdehepogalbgkng [2014-09-23]
CHR Extension: (Google Tabellen) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-23]
CHR Extension: (Office Editor) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbkeegbaiigmenfmjfclcdgdpimamgkj [2015-02-03]
CHR Extension: (AdBlock) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-09-23]
CHR Extension: (Hola Besseres Internet) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2014-09-23]
CHR Extension: (IE Tab) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2014-09-23]
CHR Extension: (Cisco WebEx Extension) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2014-10-27]
CHR Extension: (BB10 / PlayBook App Manager) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmbaalodpmjjhpobkgljnelbpblnikkp [2014-10-22]
CHR Extension: (Stop Autoplay for YouTube.) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgdfnbpkmkkdhgidgcpdkgpdlfjcgnnh [2014-09-23]
CHR Extension: (Ashish Mishra) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnkdbjbjpnpjeciipoaflmpcddinpjjp [2014-09-23]
CHR Extension: (Google Wallet) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-23]
CHR Extension: (Proxy SwitchyOmega) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\padekgcemlokbadohgkifijomclgjgif [2015-01-07]
CHR Extension: (Google Mail) - C:\Users\Zeus1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-23]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 dnsyncservice; C:\Program Files\COC AG\Docunize 2013\DocunizeSyncService.exe [60176 2014-03-17] (COC AG)
R2 F-Secure Gatekeeper Handler Starter; C:\Program Files (x86)\F-Secure\Anti-Virus\fsgk32st.exe [224296 2014-07-01] (F-Secure Corporation)
R3 F-Secure Network Request Broker; C:\Program Files (x86)\F-Secure\Common\FNRB32.EXE [217128 2014-07-01] (F-Secure Corporation)
R2 Filr Caching Service; C:\Program Files\Novell\Filr\FilrCacheLib.Hosting.exe [7168 2014-03-16] () [File not signed]
R3 FSDFWD; C:\Program Files (x86)\F-Secure\FWES\Program\fsdfwd.exe [855592 2014-07-01] (F-Secure Corporation)
R2 FSMA; C:\Program Files (x86)\F-Secure\Common\FSMA32.EXE [208424 2014-07-01] (F-Secure Corporation)
R3 FSORSPClient; C:\Program Files (x86)\F-Secure\ORSP Client\fsorsp.exe [60352 2013-10-29] (F-Secure Corporation)
R2 NVWMI; C:\Windows\system32\nvwmi64.exe [1248544 2013-08-09] (NVIDIA Corporation)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 XTSvcMgr; C:\Program Files\Novell\Client\XTier\Services\XTSvcMgr.exe [21176 2013-12-17] (Novell, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 F-Secure Filter; C:\Program Files (x86)\F-Secure\Anti-Virus\Win2K\FSfilter.sys [40256 2013-06-25] ()
R3 F-Secure Gatekeeper; C:\Program Files (x86)\F-Secure\Anti-Virus\minifilter\fsgk.sys [207400 2014-12-15] (F-Secure Corporation)
S4 F-Secure Recognizer; C:\Program Files (x86)\F-Secure\Anti-Virus\Win2K\FSrec.sys [25536 2013-06-25] ()
R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [56016 2014-12-15] ()
R1 FSFW; C:\Windows\System32\drivers\fsdfw.sys [94728 2014-07-01] (F-Secure Corporation)
R3 fsni; C:\Program Files (x86)\F-Secure\NIF\bin\fsni64.sys [89640 2014-07-09] (F-Secure Corporation)
R1 fsvista; C:\Program Files (x86)\F-Secure\Anti-Virus\minifilter\fsvista.sys [13352 2014-07-01] ()
R3 iANSMiniport; C:\Windows\System32\DRIVERS\iansw60e.sys [152808 2010-03-11] (Intel Corporation)
S3 IANSPROTOCOL; C:\Windows\System32\DRIVERS\iansw60e.sys [152808 2010-03-11] (Intel Corporation)
R0 NCFilter; C:\Windows\System32\DRIVERS\NCFilter.sys [112312 2013-12-17] ()
R0 NCRecognizer; C:\Windows\System32\DRIVERS\NCRecognizer.sys [121016 2013-12-17] ()
R0 NCUncFilter; C:\Windows\System32\DRIVERS\NCUncFilter.sys [27320 2013-12-17] ()
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R1 pefndis; C:\Windows\System32\DRIVERS\pefndis.sys [63152 2014-09-04] (Microsoft Corporation)
S3 wfpcapture; C:\Windows\System32\Drivers\wfpcapture.sys [55472 2014-09-04] (Microsoft Corporation)
S3 WIMMount; C:\Program Files (x86)\Windows Kits\8.0\Assessment and Deployment Kit\Deployment Tools\amd64\DISM\wimmount.sys [40392 2012-07-25] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-04 09:41 - 2015-02-04 09:41 - 00029316 _____ () C:\Users\Zeus1\Downloads\FRST.txt
2015-02-04 09:40 - 2015-02-04 09:41 - 00000000 ____D () C:\FRST
2015-02-04 09:40 - 2015-02-04 09:40 - 02131456 _____ (Farbar) C:\Users\Zeus1\Downloads\FRST64.exe
2015-01-29 08:42 - 2015-01-29 08:42 - 00000000 ____D () C:\Users\Zeus1\AppData\Roaming\Abstractspoon
2015-01-28 13:47 - 2015-01-28 13:47 - 00495616 _____ (Simon Tatham) C:\Users\Zeus1\Downloads\putty.exe
2015-01-28 08:45 - 2015-01-28 08:45 - 00002898 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Mindjet MindManager 2012.lnk
2015-01-28 08:45 - 2015-01-28 08:45 - 00002892 _____ () C:\Users\Public\Desktop\Mindjet MindManager 2012.lnk
2015-01-28 08:45 - 2015-01-28 08:45 - 00000000 ____D () C:\Users\Zeus1\Documents\Eigene Maps
2015-01-28 08:45 - 2015-01-28 08:45 - 00000000 ____D () C:\Users\Zeus1\AppData\Local\Mindjet
2015-01-27 12:55 - 2015-01-27 12:55 - 00742056 _____ ( ) C:\Users\Zeus1\Downloads\FileZilla_3.10.0.2_win32-setup.exe
2015-01-23 15:30 - 2015-01-23 15:30 - 00000000 ____D () C:\Users\Zeus1\AppData\Roaming\F-Secure
2015-01-23 15:13 - 2015-01-23 15:22 - 00000000 ____D () C:\Users\Zeus1\AppData\Roaming\Winamp
2015-01-23 10:49 - 2015-01-23 10:49 - 00000000 ____D () C:\Users\Zeus1\Downloads\miniwebserver
2015-01-23 10:41 - 2015-01-23 10:41 - 07663842 _____ () C:\Users\Zeus1\Downloads\AV3.5.2.2_150513.direct
2015-01-22 10:24 - 2015-01-22 10:24 - 00001567 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wireshark.lnk
2015-01-19 18:17 - 2015-02-02 16:22 - 00000000 ____D () C:\Users\Zeus1\AppData\Local\Spotify
2015-01-19 18:17 - 2015-01-19 18:17 - 00001827 _____ () C:\Users\Zeus1\Desktop\Spotify.lnk
2015-01-19 18:17 - 2015-01-19 18:17 - 00001813 _____ () C:\Users\Zeus1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-01-19 18:16 - 2015-02-04 08:37 - 00000000 ____D () C:\Users\Zeus1\AppData\Roaming\Spotify
2015-01-19 14:10 - 2015-02-02 13:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2015-01-14 12:25 - 2015-01-14 12:25 - 00000000 ____D () C:\ProgramData\Lexmark Universal v2 PS3
2015-01-14 12:01 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 12:01 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 12:01 - 2014-12-11 18:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 12:01 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 12:01 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 12:01 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 12:00 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 12:00 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 12:00 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 12:00 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 12:00 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 12:00 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 12:00 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-12 11:42 - 2015-01-12 11:42 - 00046811 _____ () C:\Users\Zeus1\Documents\ToDoLOC_Deu_57.zip
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-04 09:38 - 2013-09-25 12:33 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-04 09:35 - 2014-09-23 14:30 - 00000600 _____ () C:\Users\Zeus1\AppData\Local\PUTTY.RND
2015-02-04 09:19 - 2014-09-23 07:46 - 00000120 _____ () C:\Windows\system32\config\netlogon.ftl
2015-02-04 09:03 - 2009-07-14 05:45 - 00026448 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-04 09:03 - 2009-07-14 05:45 - 00026448 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-04 09:02 - 2013-06-26 14:20 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-04 08:17 - 2013-06-26 08:53 - 01258095 _____ () C:\Windows\WindowsUpdate.log
2015-02-04 07:34 - 2013-10-29 11:09 - 00406323 _____ () C:\Windows\FSISU.log
2015-02-04 06:34 - 2013-10-29 11:10 - 00229460 _____ () C:\action.log
2015-02-03 22:02 - 2013-06-26 14:20 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-03 15:01 - 2014-09-30 15:08 - 00000000 ____D () C:\Users\Zeus1\AppData\Roaming\KeePass
2015-02-03 14:16 - 2014-09-23 16:49 - 00000000 ____D () C:\Users\Zeus1\SapWorkDir
2015-02-02 17:53 - 2014-10-10 20:28 - 00002310 ____H () C:\Users\Zeus1\Documents\Default.rdp
2015-02-02 17:53 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2015-02-02 17:45 - 2014-09-23 13:13 - 00000000 ____D () C:\Users\Zeus1\AppData\Roaming\VMware
2015-02-02 13:03 - 2013-12-12 13:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-02 09:07 - 2009-07-14 05:51 - 00033274 _____ () C:\Windows\setupact.log
2015-01-30 10:21 - 2014-10-23 11:23 - 00000000 ____D () C:\Users\Zeus1\AppData\Local\Paint.NET
2015-01-28 13:17 - 2014-09-25 15:56 - 00000000 ____D () C:\Users\Zeus1\AppData\Roaming\.oit
2015-01-28 10:11 - 2014-10-21 16:09 - 00000000 ____D () C:\Users\Zeus1\Downloads\ADE
2015-01-28 08:45 - 2013-08-23 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mindjet MindManager 2012
2015-01-24 23:38 - 2013-09-25 12:33 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-24 23:38 - 2013-08-12 15:17 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-24 23:38 - 2013-08-12 15:17 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-22 10:24 - 2013-06-26 16:04 - 00000000 ____D () C:\Program Files\Wireshark
2015-01-19 23:48 - 2014-10-01 13:07 - 00000000 ____D () C:\Program Files (x86)\Pathfinder
2015-01-19 17:32 - 2013-07-01 08:58 - 00000000 ____D () C:\Temp
2015-01-19 09:37 - 2009-07-14 11:57 - 00704986 _____ () C:\Windows\system32\perfh007.dat
2015-01-19 09:37 - 2009-07-14 11:57 - 00152002 _____ () C:\Windows\system32\perfc007.dat
2015-01-19 09:37 - 2009-07-14 06:13 - 01637442 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-19 09:35 - 2014-09-23 13:16 - 00000000 ___RD () C:\Users\Zeus1\Dropbox
2015-01-19 09:35 - 2014-09-23 13:11 - 00000000 ____D () C:\Users\Zeus1\AppData\Roaming\Dropbox
2015-01-19 09:34 - 2014-09-23 08:14 - 00000000 ___RD () C:\Users\Zeus1\OneDrive
2015-01-19 09:33 - 2014-09-24 14:01 - 00000000 ____D () C:\Users\Zeus1\AppData\Local\FreePDF_XP
2015-01-19 09:33 - 2013-06-27 11:01 - 00000000 ____D () C:\NDPS
2015-01-19 09:32 - 2013-07-01 08:29 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-01-19 09:32 - 2013-06-26 13:40 - 00355100 _____ () C:\Windows\PFRO.log
2015-01-19 09:32 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-16 12:02 - 2013-08-23 10:51 - 01610786 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-01-15 12:10 - 2013-08-07 02:02 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-15 12:00 - 2013-06-26 13:00 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-14 11:21 - 2014-10-01 14:51 - 00000000 ____D () C:\Users\Zeus1\AppData\Local\Thunderbird
2015-01-06 04:36 - 2013-06-26 11:31 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
==================== Files in the root of some directories =======
2014-09-29 08:17 - 2014-09-29 08:26 - 0000600 _____ () C:\Users\Zeus1\AppData\Roaming\winscp.rnd
2014-09-23 14:30 - 2015-02-04 09:35 - 0000600 _____ () C:\Users\Zeus1\AppData\Local\PUTTY.RND
2013-06-27 11:19 - 2013-06-27 11:19 - 0000124 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2013-06-26 10:33 - 2013-06-26 10:33 - 0000315 _____ () C:\ProgramData\NCIDebug.log
2013-06-27 10:06 - 2013-06-27 10:06 - 0000000 _____ () C:\ProgramData\RVTools.log
Files to move or delete:
====================
C:\Users\Test-gu\.csp_ovftool_settings.js
Some content of TEMP:
====================
C:\Users\Test-gu\AppData\Local\Temp\003e61c9-2a3f-4d8f-b319-37c27d1beb93.dll
C:\Users\Test-gu\AppData\Local\Temp\0162d77b-8e5b-4ae5-880d-f468591f95a3.dll
C:\Users\Test-gu\AppData\Local\Temp\016964e6-f485-4b7a-a59d-19ae41eed0f9.dll
C:\Users\Test-gu\AppData\Local\Temp\02de534d-33dd-4f35-8fb9-2d8f283aba76.dll
C:\Users\Test-gu\AppData\Local\Temp\036f2caf-dac6-4911-be15-37911656658c.dll
C:\Users\Test-gu\AppData\Local\Temp\087705da-5cee-4f82-8eef-620c17ff6f13.dll
C:\Users\Test-gu\AppData\Local\Temp\1324e333-4ba8-4166-aaa9-44ab971f2367.dll
C:\Users\Test-gu\AppData\Local\Temp\18af9669-2e75-4f5c-a909-1ebfd0615da4.dll
C:\Users\Test-gu\AppData\Local\Temp\1c1b1708-156b-48bd-86d3-7b43c1e582ee.dll
C:\Users\Test-gu\AppData\Local\Temp\28784e8b-c1bd-4a36-a512-fcd4508f660c.dll
C:\Users\Test-gu\AppData\Local\Temp\2b7a9396-0b62-4d06-b8b9-82e5a4e1ffa1.dll
C:\Users\Test-gu\AppData\Local\Temp\2ebaad8e-2b2f-44a2-bc71-09fcf0150a17.dll
C:\Users\Test-gu\AppData\Local\Temp\31cec57e-09b1-4a1c-809c-1115a69c5b99.dll
C:\Users\Test-gu\AppData\Local\Temp\34d76b61-f847-4362-90a5-af280291ef18.dll
C:\Users\Test-gu\AppData\Local\Temp\3aae12f2-7e55-4580-b2a7-191b15382fa4.dll
C:\Users\Test-gu\AppData\Local\Temp\3c4333d4-4051-4a24-858a-af76c041c743.dll
C:\Users\Test-gu\AppData\Local\Temp\3ecc7cc2-ba49-4383-ab27-8e68f84749b4.dll
C:\Users\Test-gu\AppData\Local\Temp\41d316b7-1342-49f0-a3f2-8a73c464163b.dll
C:\Users\Test-gu\AppData\Local\Temp\43454683-ad39-47d2-b0db-3488b3c002ac.dll
C:\Users\Test-gu\AppData\Local\Temp\44046193-303f-4adb-92d9-403cfbb9e12f.dll
C:\Users\Test-gu\AppData\Local\Temp\4ebb3cf8-dd27-4a23-bc09-6f36f8a98636.dll
C:\Users\Test-gu\AppData\Local\Temp\4f752119-fe7b-44eb-a62c-247099986b72.dll
C:\Users\Test-gu\AppData\Local\Temp\4f7d3a9e-0a50-4132-b76f-6b9b5e138e32.dll
C:\Users\Test-gu\AppData\Local\Temp\532e9bfb-32ed-44ad-a8f8-c8a0aa7b2ccc.dll
C:\Users\Test-gu\AppData\Local\Temp\57340801-05b1-48ac-8006-2aadf7061321.dll
C:\Users\Test-gu\AppData\Local\Temp\59a8f6a6-f5a0-46c2-b7a8-431b3a6f9758.dll
C:\Users\Test-gu\AppData\Local\Temp\611d4b9e-814b-4a79-8944-fe8ff24cd8c2.dll
C:\Users\Test-gu\AppData\Local\Temp\6542c100-e070-4765-8fcd-8f71abe716be.dll
C:\Users\Test-gu\AppData\Local\Temp\68c83956-5723-44c2-8a1a-7528bbbbf745.dll
C:\Users\Test-gu\AppData\Local\Temp\712cfd9f-5858-4825-af02-647aa2c58273.dll
C:\Users\Test-gu\AppData\Local\Temp\77df2562-399f-4e89-88eb-1b4fbf56c9ba.dll
C:\Users\Test-gu\AppData\Local\Temp\780c53b4-4f35-49af-bebd-24e48f79b92b.dll
C:\Users\Test-gu\AppData\Local\Temp\7ba6a609-a73c-486d-96bd-76fcdc0f71d7.dll
C:\Users\Test-gu\AppData\Local\Temp\89836788-3c22-4b4b-9dc2-10ae39580b86.dll
C:\Users\Test-gu\AppData\Local\Temp\8b969464-b281-4ba1-b480-467fec23ae73.dll
C:\Users\Test-gu\AppData\Local\Temp\9d4ddc17-de18-4ee9-a730-251e852b84b0.dll
C:\Users\Test-gu\AppData\Local\Temp\9ef0601b-b0ef-4ec7-aeb6-c5e5288f3ce8.dll
C:\Users\Test-gu\AppData\Local\Temp\a92151c3-3978-480e-90c8-dc8179d1ae4c.dll
C:\Users\Test-gu\AppData\Local\Temp\aba61409-abca-44f1-85ae-9cf4b134c6ef.dll
C:\Users\Test-gu\AppData\Local\Temp\AcDeltree.exe
C:\Users\Test-gu\AppData\Local\Temp\AEV191C.exe
C:\Users\Test-gu\AppData\Local\Temp\AEV4DE1.exe
C:\Users\Test-gu\AppData\Local\Temp\AskSLib.dll
C:\Users\Test-gu\AppData\Local\Temp\BRSVC_437302_hlp.exe
C:\Users\Test-gu\AppData\Local\Temp\c12dbad8-7f6e-4e99-a849-cd87cb314dea.dll
C:\Users\Test-gu\AppData\Local\Temp\cd6afe27-db86-4b9e-8ded-b6c6d31c274f.dll
C:\Users\Test-gu\AppData\Local\Temp\cpqma-1d30479.dll
C:\Users\Test-gu\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpu1wwrz.dll
C:\Users\Test-gu\AppData\Local\Temp\e651579a-6103-48f5-84aa-0381e7759786.dll
C:\Users\Test-gu\AppData\Local\Temp\e72e7306-89f7-43cc-a857-1680ddf6ef41.dll
C:\Users\Test-gu\AppData\Local\Temp\f2a24af3-8041-48f2-a27e-7d09c64216e9.dll
C:\Users\Test-gu\AppData\Local\Temp\f338b505-866e-42ab-975d-676063b73fe5.dll
C:\Users\Test-gu\AppData\Local\Temp\fc4bfb39-ee8a-426a-874a-08c14f039b8e.dll
C:\Users\Test-gu\AppData\Local\Temp\HpqKbHook-1d30479.dll
C:\Users\Test-gu\AppData\Local\Temp\ICReinstall_Ping_Assist_Pro_1_2_0.exe
C:\Users\Test-gu\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Test-gu\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Test-gu\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Test-gu\AppData\Local\Temp\mRemote_Update.exe
C:\Users\Test-gu\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Test-gu\AppData\Local\Temp\nvStInst.exe
C:\Users\Test-gu\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Test-gu\AppData\Local\Temp\VMware-viclient-all-5.5.0-1281650.exe
C:\Users\Test-gu\AppData\Local\Temp\xmlUpdater.exe
C:\Users\Zeus1\AppData\Local\Temp\00f1b94e-bf54-4144-b371-91a4f88339ed.dll
C:\Users\Zeus1\AppData\Local\Temp\0be9b49e-effc-472d-a94a-008fbc16e768.dll
C:\Users\Zeus1\AppData\Local\Temp\1bda6d44-4086-433e-b840-022b34b9be4d.dll
C:\Users\Zeus1\AppData\Local\Temp\30894ba0-a461-4246-bf77-424af30cf956.dll
C:\Users\Zeus1\AppData\Local\Temp\30ae5a4b-7c83-4f62-8b18-b3dc9a5d4d9a.dll
C:\Users\Zeus1\AppData\Local\Temp\36cffa3b-bca1-42ea-8993-cb0a4e1c885f.dll
C:\Users\Zeus1\AppData\Local\Temp\396226d8-15ca-4699-8f35-e631cc12eaa7.dll
C:\Users\Zeus1\AppData\Local\Temp\54678cb0-0a75-4554-89a2-19428dfdda8d.dll
C:\Users\Zeus1\AppData\Local\Temp\55c02b74-60eb-4fcb-8fc1-7e6cba71dd2f.dll
C:\Users\Zeus1\AppData\Local\Temp\57f64f54-3410-4f41-9f91-1fe115c89554.dll
C:\Users\Zeus1\AppData\Local\Temp\5a4ea3c2-7dc3-441f-88df-ae6e1f643b31.dll
C:\Users\Zeus1\AppData\Local\Temp\65763b91-6e07-4b42-ba04-4e364e616770.dll
C:\Users\Zeus1\AppData\Local\Temp\66b281c8-c707-464b-a1ae-fe0f6196e6f7.dll
C:\Users\Zeus1\AppData\Local\Temp\694bb2fe-6b64-4532-abab-7ee6bd77cbaf.dll
C:\Users\Zeus1\AppData\Local\Temp\6b62f339-3ae0-4a3d-be66-be1aafd78f0d.dll
C:\Users\Zeus1\AppData\Local\Temp\6ed57888-d163-4492-b323-0590209620d1.dll
C:\Users\Zeus1\AppData\Local\Temp\704df6c4-1195-4be0-9dec-344630b759f2.dll
C:\Users\Zeus1\AppData\Local\Temp\70dd1b75-250b-4fd0-83a0-bca45b5fe31a.dll
C:\Users\Zeus1\AppData\Local\Temp\71d3a469-8f22-4aac-ba06-324e8d5e0585.dll
C:\Users\Zeus1\AppData\Local\Temp\81bd97a9-2b10-4351-a957-c37c15c11471.dll
C:\Users\Zeus1\AppData\Local\Temp\82d1fc4c-c4d6-48e7-92f7-feca02453c9d.dll
C:\Users\Zeus1\AppData\Local\Temp\84a50d2e-3bf1-4a7c-a6e9-6ac03e1ecb81.dll
C:\Users\Zeus1\AppData\Local\Temp\870deb73-aaf1-47d6-825a-47054e6174d4.dll
C:\Users\Zeus1\AppData\Local\Temp\896a213f-7981-438f-9e98-d671c0f33dd9.dll
C:\Users\Zeus1\AppData\Local\Temp\8b4ec85f-5086-4505-b046-ab18a79f6df2.dll
C:\Users\Zeus1\AppData\Local\Temp\8c03c87f-cb8a-439a-bcd0-89d1f91c39a3.dll
C:\Users\Zeus1\AppData\Local\Temp\a18535de-c12b-4eb8-be45-631e3a29cdfa.dll
C:\Users\Zeus1\AppData\Local\Temp\a2b10f5d-d2b1-451c-949b-13e2111c661b.dll
C:\Users\Zeus1\AppData\Local\Temp\b078bf05-eb37-4690-9bb6-4a194596b4c7.dll
C:\Users\Zeus1\AppData\Local\Temp\b23fb94e-3fae-4cd1-98cc-19c6b786bfb7.dll
C:\Users\Zeus1\AppData\Local\Temp\b8cd984f-c12e-4030-be12-7882fa0c84cc.dll
C:\Users\Zeus1\AppData\Local\Temp\c3729517-a413-4875-aa03-d7250bd03f05.dll
C:\Users\Zeus1\AppData\Local\Temp\cd986c9f-7cae-4e98-bbc1-3247a85ad315.dll
C:\Users\Zeus1\AppData\Local\Temp\cfa294a9-8d4c-49d4-a4fd-6544ae010e2c.dll
C:\Users\Zeus1\AppData\Local\Temp\d118a8d5-d694-449d-b2ad-554b28041a9e.dll
C:\Users\Zeus1\AppData\Local\Temp\d98118f8-2c45-46f9-8da5-9b2fe8797f7b.dll
C:\Users\Zeus1\AppData\Local\Temp\da5176e9-4c4d-4ade-9b91-f123d60b160c.dll
C:\Users\Zeus1\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpedio8r.dll
C:\Users\Zeus1\AppData\Local\Temp\eaeb3b0d-5705-4488-a8cf-6cf36334cbfa.dll
C:\Users\Zeus1\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\Zeus1\AppData\Local\Temp\TDLUpdate.exe
C:\Users\Zeus1\AppData\Local\Temp\TransText.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-03 00:37
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2015
Ran by Zeus1 at 2015-02-04 09:41:57
Running from C:\Users\Zeus1\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: F-Secure Client Security Premium 11.60 (Enabled - Up to date) {15414183-282E-D62C-CA37-EF24860A2F17}
AS: F-Secure Client Security Premium 11.60 (Enabled - Up to date) {AE20A067-0E14-D9A2-F087-D456FD8D65AA}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: F-Secure Client Security Premium 11.60 (Disabled) {2D7AC0A6-6241-D774-E168-461178D9686C}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
3CDaemon (HKLM-x32\...\3CDaemon) (Version: - )
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
AD Account Reset Tool (HKLM\...\{7EB0266F-3C24-465A-8B3F-72AFCF6CCA14}) (Version: 1.3.1 - Cjwdev)
Adaptive Server Enterprise PC Client (HKLM\...\Adaptive Server Enterprise PC Client) (Version: 15.5.0.1 - Sybase, Inc.)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
AdRem Free Remote Console for NetWare (HKLM-x32\...\AdRem Free Remote Console for NetWare) (Version: 3.72 - AdRem Software)
Assessment and Deployment Kit (HKLM-x32\...\{fc46d1b2-9557-4c1f-baac-04af4d2db7e4}) (Version: 8.59.25584 - Microsoft Corporation)
Autodesk DWG TrueView 2014 (HKLM\...\DWG TrueView 2014) (Version: 19.1.18.0 - Autodesk)
Cisco WebEx Meetings (HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\ActiveTouchMeetingClient) (Version: - Cisco WebEx LLC)
CVE-2013-3893 (HKLM\...\{55aab41f-5d5c-abdf-4568-baef76587bd7}.sdb) (Version: - )
DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation)
DocSetMinder deinstallieren (HKLM-x32\...\DSM_2.0.1.28910_is1) (Version: 2.0.1.28910 - GRC Partner GmbH)
Docunize 2013 (HKLM\...\{3DB97C5D-A2D8-4361-8ED9-C45D97CB063C}) (Version: 3.1.1 - COC AG)
Dropbox (HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
DWG TrueView 2014 (Version: 19.1.18.0 - Autodesk) Hidden
Enterprise Mode Site List Manager (HKLM-x32\...\{9AD66669-2F48-44DA-AEBE-DA44CCEC4193}) (Version: 1.0.0.0 - Microsoft Corporation)
ExamDiff 1.9 (Build 1.9.0.2) (HKLM-x32\...\ExamDiff_is1) (Version: 1.9.0.2 - PrestoSoft LLC)
FreePDF (Remove only) (HKLM-x32\...\FreePDF_XP) (Version: - )
F-Secure Client Security Premium - AntiVirus & AntiSpy-Schutz (HKLM-x32\...\F-Secure Anti-Virus) (Version: 9.51.131 - F-Secure Corporation)
F-Secure Client Security Premium - Browsing-Schutz (HKLM-x32\...\F-Secure Browsing Protection) (Version: 2.00.1013 - F-Secure Corporation)
F-Secure Client Security Premium - Internet-Schutzschild (HKLM-x32\...\F-Secure Internet Shield) (Version: 6.40 - F-Secure Corporation)
F-Secure Client Security Premium - Software-Updater (HKLM-x32\...\F-Secure Software Updater) (Version: 2.00.1384 - F-Secure Corporation)
F-Secure Client Security Premium - Web-Datenverkehr-Scanning (HKLM-x32\...\F-Secure Protocol Scanner) (Version: 3.00.422 - F-Secure Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.94 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
GPL Ghostscript (HKLM\...\GPL Ghostscript 9.07) (Version: 9.07 - Artifex Software Inc.)
Greenshot 1.1.9.13 (HKLM\...\Greenshot_is1) (Version: 1.1.9.13 - Greenshot)
HP StoreVirtual Centralized Management Console (HKLM-x32\...\HP StoreVirtual Centralized Management Console) (Version: 11.0.0.1278 - HP)
Intel(R) Network Connections 15.2.89.2 (HKLM\...\PROSetDX) (Version: 15.2.89.2 - Intel)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
John's Background Switcher 4.9 (HKLM-x32\...\{DD3DAD13-289E-440E-A5D3-3EFB25305018}_is1) (Version: 4.9 - johnsadventures.com)
KeePass Password Safe 2.24 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.24 - Dominik Reichl)
Kits Configuration Installer (x32 Version: 8.59.25584 - Microsoft) Hidden
Link Shell Extension (HKLM\...\HardlinkShellExt) (Version: 3.7.5.9 - Hermann Schinagl)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Message Analyzer (HKLM\...\{815DE591-9398-40BA-AEC7-6F113A2EAD06}) (Version: 4.0.7056.0 - Microsoft Corporation)
Microsoft Office Standard 2010 (HKLM-x32\...\Office14.STANDARD) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)
Microsoft redistributable runtime DLLs VS2005 SP1(x86) (HKLM-x32\...\{8E770F99-CF23-4BF9-BF4E-E3A2924FEB27}) (Version: 8.0.50727.762 - SAP)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 DEU (HKLM-x32\...\{0125D081-30D0-4A97-82A8-C28D444B6256}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 DEU (HKLM\...\{C3EAE456-7E7A-451F-80EF-F34C7A13C558}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visio Premium 2010 (HKLM-x32\...\Office14.VISIO) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mindjet MindManager 2012 (HKLM-x32\...\{B1FD6060-8DF9-4C67-AF5E-7D25A54D1854}) (Version: 10.1.459 - Mindjet)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.5.0 - Mozilla)
Mozilla Thunderbird 31.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.4.0 (x86 de)) (Version: 31.4.0 - Mozilla)
mRemoteNG (HKLM-x32\...\mRemoteNG) (Version: 1.72.5065.32737 - Next Generation Software)
MSXML 4.0 SP2 (KB941833) (HKLM-x32\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MySQL Connector/ODBC 5.3 (HKLM\...\{A1991404-2634-47E1-BC45-8F3B5014B1D1}) (Version: 5.3.4 - Oracle Corporation)
MySQL Connector/ODBC 5.3 (HKLM-x32\...\{4C6A664C-DCA0-4CC6-8752-ED0850E3135A}) (Version: 5.3.4 - Oracle Corporation)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.3.3 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 320.49 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 320.49 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 320.78 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 320.78 - NVIDIA Corporation)
NVIDIA Grafiktreiber 320.78 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 320.78 - NVIDIA Corporation)
NVIDIA nView 140.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 140.62 - NVIDIA Corporation)
NVIDIA WMI 2.12.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVWMI) (Version: 2.12.0 - NVIDIA Corporation)
Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.210.0 - Tracker Software Products Ltd)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6383 - Realtek Semiconductor Corp.)
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: - )
RVTools (HKLM-x32\...\{2A80312D-8BFF-4C2F-868C-0B2A1ACF3021}) (Version: 3.5.3 - RobWare)
SAP GUI 7.10 (HKLM-x32\...\SAPGUI710) (Version: 7.10 Compilation 2 - SAP AG)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0057-0000-0000-0000000FF1CE}_Office14.VISIO_{359ADBEC-068A-4CC9-9174-77AB8EDB867A}) (Version: - Microsoft)
Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-3033516151-3775350169-36420636-1106\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB)
Toolkit Documentation (x32 Version: 8.59.25584 - Microsoft) Hidden
VMware Client Integration Plug-in 5.5.0 (HKLM-x32\...\{837E9923-05EA-4091-A4EE-6FB10CEEE099}) (Version: 5.5.0.1280541 - VMware, Inc.)
VMware vSphere Client 5.5 (HKLM-x32\...\{4CFB0494-2E96-4631-8364-538E2AA91324}) (Version: 5.5.0.3580 - VMware, Inc.)
Winamp (HKLM-x32\...\Winamp) (Version: 5.64 - Nullsoft, Inc)
Windows NT Messaging (HKLM-x32\...\WMS) (Version: - )
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinSCP 5.1.5 (HKLM-x32\...\winscp3_is1) (Version: 5.1.5 - Martin Prikryl)
Wireshark 1.12.3 (64-bit) (HKLM-x32\...\Wireshark) (Version: 1.12.3 - The Wireshark developer community, hxxp://www.wireshark.org)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2014\en-US\dwgviewrficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{6A221957-2D85-42A7-8E19-BE33950D1DEB}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2014\dwgviewr.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3033516151-3775350169-36420636-1106_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
==================== Restore Points =========================
21-01-2015 07:04:49 Windows Update
24-01-2015 07:48:18 Windows Update
28-01-2015 06:35:49 Windows Update
04-02-2015 08:14:50 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2014-09-23 08:44 - 00000894 ____A C:\Windows\system32\Drivers\etc\hosts
192.168.252.53 sharepoint-test
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {59FF8102-6054-4C95-AF89-FE53ED3374CC} - System32\Tasks\{E0EC70C2-B91C-415B-B2A7-95502BF9EF9E} => pcalua.exe -a C:\Users\Zeus1\Downloads\sp42536.exe -d C:\Users\Zeus1\Downloads
Task: {83BC002B-EDCC-4DCD-8448-91B01C330731} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-26] (Google Inc.)
Task: {8A1602EC-BBE6-40F6-8678-6C27AEDE6A7A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-24] (Adobe Systems Incorporated)
Task: {8F0F6E5D-35B0-413D-B414-D58A0E60DA17} - System32\Tasks\{9736D510-D1AE-42EC-87CF-4A26AD55A2D2} => pcalua.exe -a E:\elite8100\Chipsatz.exe -d E:\elite8100
Task: {A0A3A140-4361-4160-AED3-15C1EA863545} - System32\Tasks\{25E5A63B-9AB9-433D-B78D-F052A4586AFE} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=6.5.0.158&LastError=407
Task: {A2CEA943-3231-416F-8339-182F652C4F08} - System32\Tasks\{734F51CC-7AD9-4589-9CD1-4622D8CC4B64} => pcalua.exe -a C:\Users\DV14\Downloads\igowin.exe -d C:\Users\DV14\Downloads
Task: {B380A27D-A002-4134-9600-5A4A295E2393} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-26] (Google Inc.)
Task: {BB40DEC8-CDA1-4816-AC9D-AD1538F1B65E} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {F2F7AD37-4B57-4427-974E-42FAF229E660} - System32\Tasks\{56BEBD7A-9ED7-4A72-9313-7F3EB2D978A9} => pcalua.exe -a "C:\Program Files (x86)\MySQL\Connector ODBC 5.2\myodbc-installer.exe" -d "C:\Program Files (x86)\MySQL\Connector ODBC 5.2"
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-01-09 13:26 - 2013-12-17 22:43 - 00049336 _____ () C:\Windows\system32\ncv1_0.DLL
2013-05-29 04:38 - 2013-12-17 22:43 - 01024696 _____ () C:\Windows\system32\ncnetprovider.dll
2014-01-09 13:26 - 2013-12-17 22:43 - 00109752 _____ () C:\Windows\system32\NCLangID.dll
2014-01-09 13:26 - 2013-12-17 22:43 - 00175288 _____ () C:\Windows\system32\MAPBASE.dll
2013-05-29 04:38 - 2013-12-17 22:43 - 00266936 _____ () C:\Windows\system32\NWSHLXNT.dll
2013-03-04 10:14 - 2013-03-04 10:14 - 00016384 _____ () C:\Windows\system32\nls\DEUTSCH\NCLangIDR.DLL
2013-03-04 10:14 - 2013-03-04 10:14 - 00086528 _____ () C:\Windows\system32\nls\DEUTSCH\MAPBASER.DLL
2013-03-04 10:14 - 2013-03-04 10:14 - 00102400 _____ () C:\Windows\system32\nls\DEUTSCH\NWSHLXNTR.DLL
2013-03-04 10:14 - 2013-03-04 10:14 - 00496640 _____ () C:\Windows\system32\nls\DEUTSCH\ncnetproviderR.DLL
2013-07-01 08:28 - 2013-08-09 21:07 - 00087328 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-06-27 11:15 - 2010-06-17 19:56 - 00087040 _____ () C:\Windows\System32\redmonnt.dll
2004-09-30 19:15 - 2004-09-30 19:15 - 00192000 _____ () C:\Program Files\LinkShellExtension\RockallDLL.dll
2013-07-01 08:30 - 2013-08-09 23:21 - 00496928 _____ () C:\Program Files\NVIDIA Corporation\nview\nvshell.dll
2012-06-18 16:24 - 2012-06-18 16:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll
2013-05-29 04:38 - 2013-12-17 22:43 - 01024696 _____ () C:\Windows\system32\NCNetProvider.DLL
2013-03-04 10:14 - 2013-03-04 10:14 - 00496640 _____ () C:\Windows\system32\nls\DEUTSCH\NCNetProviderR.DLL
2014-03-16 01:07 - 2014-03-16 01:07 - 00327168 _____ () C:\Program Files\Novell\Filr\filr.exe
2013-10-29 11:10 - 2014-07-01 12:58 - 00271912 _____ () c:\program files (x86)\f-secure\daas2\daas2_x64.dll
2013-11-14 01:11 - 2013-11-14 01:11 - 01274296 _____ () C:\Program Files (x86)\mRemoteNG\mRemoteNG.exe
2014-03-16 01:08 - 2014-03-16 01:08 - 00047616 _____ () C:\Program Files\Novell\Filr\FilrPropertySheet.dll
2014-03-16 01:08 - 2014-03-16 01:08 - 00093184 _____ () C:\Program Files\Novell\Filr\ShellExtensionLib.dll
2015-01-19 15:56 - 2015-01-19 15:56 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\a18535de-c12b-4eb8-be45-631e3a29cdfa.dll
2014-03-16 01:08 - 2014-03-16 01:08 - 00004096 _____ () C:\Program Files\Novell\Filr\de\FilrPropertySheet.resources.dll
2014-01-09 13:26 - 2013-03-04 06:44 - 00053248 _____ () C:\Windows\system32\nls\DEUTSCH\nccredproviderR.DLL
2015-01-27 08:27 - 2015-01-27 08:27 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\65763b91-6e07-4b42-ba04-4e364e616770.dll
2014-03-16 01:08 - 2014-03-16 01:08 - 00006144 _____ () C:\Program Files\Novell\Filr\FilrIpcClientLib.dll
2015-01-28 13:10 - 2015-01-28 13:10 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\1bda6d44-4086-433e-b840-022b34b9be4d.dll
2015-01-28 13:11 - 2015-01-28 13:11 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\54678cb0-0a75-4554-89a2-19428dfdda8d.dll
2015-01-28 13:11 - 2015-01-28 13:11 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\30894ba0-a461-4246-bf77-424af30cf956.dll
2015-01-28 13:12 - 2015-01-28 13:12 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\8c03c87f-cb8a-439a-bcd0-89d1f91c39a3.dll
2015-01-28 13:12 - 2015-01-28 13:12 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\55c02b74-60eb-4fcb-8fc1-7e6cba71dd2f.dll
2015-01-28 13:13 - 2015-01-28 13:13 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\b23fb94e-3fae-4cd1-98cc-19c6b786bfb7.dll
2015-01-28 13:59 - 2015-01-28 13:59 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\84a50d2e-3bf1-4a7c-a6e9-6ac03e1ecb81.dll
2015-01-28 13:59 - 2015-01-28 13:59 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\694bb2fe-6b64-4532-abab-7ee6bd77cbaf.dll
2015-01-28 14:00 - 2015-01-28 14:00 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\5a4ea3c2-7dc3-441f-88df-ae6e1f643b31.dll
2015-01-28 14:00 - 2015-01-28 14:00 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\d98118f8-2c45-46f9-8da5-9b2fe8797f7b.dll
2015-02-03 15:42 - 2015-02-03 15:42 - 00008192 _____ () C:\Users\Zeus1\AppData\Local\Temp\57f64f54-3410-4f41-9f91-1fe115c89554.dll
2015-01-19 18:17 - 2015-01-19 18:17 - 00374840 _____ () C:\Users\Zeus1\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
2014-12-01 14:05 - 2014-07-01 12:59 - 00551976 _____ () c:\program files (x86)\f-secure\fsoftupd\sqlite3s.dll
2013-10-29 11:10 - 2014-07-01 12:58 - 00220200 _____ () c:\program files (x86)\f-secure\daas2\daas2.dll
2014-09-25 13:21 - 2014-09-25 13:21 - 00081056 _____ () C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\LoggingPlatform.dll
2014-10-22 01:22 - 2014-10-22 01:22 - 00750080 _____ () C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-01-19 09:34 - 2015-01-19 09:34 - 00043008 _____ () c:\users\ramonb~1.ad\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpedio8r.dll
2014-10-22 01:22 - 2014-10-22 01:22 - 00047616 _____ () C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\libEGL.dll
2014-10-22 01:22 - 2014-10-22 01:22 - 00863744 _____ () C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2014-10-22 01:22 - 2014-10-22 01:22 - 00200704 _____ () C:\Users\Zeus1\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2013-10-29 11:09 - 2014-07-01 12:59 - 00642088 _____ () C:\Program Files (x86)\F-Secure\FSGUI\about.dll
2013-10-29 11:16 - 2013-10-29 11:16 - 00030888 _____ () C:\Program Files (x86)\F-Secure\Anti-Virus\minifilter\hashlib_x86.dll
2013-10-29 11:09 - 2014-11-18 12:49 - 00949288 _____ () C:\Program Files (x86)\F-Secure\Anti-Virus\fm4av.dll
2013-11-14 01:11 - 2013-11-14 01:11 - 00088504 _____ () C:\Program Files (x86)\mRemoteNG\de\mRemoteNG.resources.dll
2013-11-14 01:11 - 2013-11-14 01:11 - 00276920 _____ () C:\Program Files (x86)\mRemoteNG\AxInterop.MSTSCLib.dll
2013-11-06 09:12 - 2013-11-06 09:12 - 00153016 _____ () C:\Program Files (x86)\mRemoteNG\VncSharpNG.dll
2014-09-25 13:21 - 2014-09-25 13:21 - 00081056 _____ () C:\Users\Zeus1\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\LoggingPlatform.DLL
2004-09-30 18:09 - 2004-09-30 18:09 - 00155648 _____ () C:\Program Files\LinkShellExtension\32\RockallDLL.dll
2015-01-19 14:27 - 2015-01-27 20:01 - 00110592 _____ () C:\Users\Zeus1\Documents\ToDoListPortable\App\ToDoList\TransText.dll
2015-01-19 14:27 - 2015-01-27 20:01 - 00262144 _____ () C:\Users\Zeus1\Documents\ToDoListPortable\App\ToDoList\RTFContentCtrl.dll
2015-01-19 14:27 - 2015-01-27 20:01 - 00180224 _____ () C:\Users\Zeus1\Documents\ToDoListPortable\App\ToDoList\GanttChartExt.dll
2015-01-19 14:27 - 2015-01-27 20:01 - 00069632 _____ () C:\Users\Zeus1\Documents\ToDoListPortable\App\ToDoList\StatisticsExt.dll
2013-12-11 00:20 - 2013-12-11 00:20 - 00032472 _____ () C:\Program Files (x86)\VMware\Infrastructure\Virtual Infrastructure Client\5.5\VpxClient.SSPI.dll
2013-12-11 00:21 - 2013-12-11 00:21 - 08797912 _____ () C:\Program Files (x86)\VMware\Infrastructure\Virtual Infrastructure Client\5.5\de\VpxClientHtmlResources.dll
2013-12-11 00:20 - 2013-12-11 00:20 - 00043224 _____ () C:\Program Files (x86)\VMware\Infrastructure\Virtual Infrastructure Client\5.5\CryptoSupport.dll
2013-12-11 00:20 - 2013-12-11 00:20 - 00023256 _____ () C:\Program Files (x86)\VMware\Infrastructure\Virtual Infrastructure Client\5.5\AxInterop.VMwareRemoteConsoleTypeLib.dll
2015-01-31 01:03 - 2015-01-27 04:44 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.94\libglesv2.dll
2015-01-31 01:03 - 2015-01-27 04:44 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.94\libegl.dll
2015-01-31 01:03 - 2015-01-27 04:44 - 09171272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.94\pdf.dll
2015-01-19 14:10 - 2015-01-19 14:10 - 03347056 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2015-01-19 14:10 - 2015-01-19 14:10 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2015-01-19 14:10 - 2015-01-19 14:10 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2015-01-19 18:17 - 2015-01-19 18:17 - 36966968 _____ () C:\Users\Zeus1\AppData\Roaming\Spotify\Data\libcef.dll
2015-01-19 18:17 - 2015-01-19 18:17 - 00867896 _____ () C:\Users\Zeus1\AppData\Roaming\Spotify\Data\ffmpegsumo.dll
2015-01-19 18:17 - 2015-01-19 18:17 - 00886840 _____ () C:\Users\Zeus1\AppData\Roaming\Spotify\Data\libglesv2.dll
2015-01-19 18:17 - 2015-01-19 18:17 - 00108600 _____ () C:\Users\Zeus1\AppData\Roaming\Spotify\Data\libegl.dll
2013-08-17 10:01 - 2013-08-17 10:01 - 01253376 ____R () C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.5\Internet Explorer\libxml2.dll
2013-08-17 10:01 - 2013-08-17 10:01 - 00322560 ____R () C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.5\Internet Explorer\libcurl.dll
2013-08-17 10:01 - 2013-08-17 10:01 - 00311808 ____R () C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.5\Internet Explorer\libldap_r.dll
2013-08-17 10:01 - 2013-08-17 10:01 - 00138752 ____R () C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.5\Internet Explorer\liblber.dll
2015-01-31 01:03 - 2015-01-27 04:44 - 14913864 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.94\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
admin (S-1-5-21-87956333-892211714-1763142975-1001 - Limited - Enabled)
Administrator (S-1-5-21-87956333-892211714-1763142975-500 - Administrator - Disabled) => C:\Users\Administrator
Zeus1 (S-1-5-21-87956333-892211714-1763142975-1000 - Administrator - Enabled) => C:\Users\Zeus1
Gast (S-1-5-21-87956333-892211714-1763142975-501 - Limited - Disabled)
==================== Faulty Device Manager Devices =============
Name: Standardtastatur (PS/2)
Description: Standardtastatur (PS/2)
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardtastaturen)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/04/2015 01:11:29 AM) (Source: SideBySide) (EventID: 9) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Das Stammelement der Manifestdatei muss assembliert sein.
Error: (02/03/2015 07:43:20 PM) (Source: DNSyncService) (EventID: 10010) (User: )
Description: Signature Synchronization failed: Ein Teil des Pfades "C:\Users\Zeus1\AppData\Roaming\Microsoft\Signatures" konnte nicht gefunden werden.
Error: (02/03/2015 07:08:58 PM) (Source: DNSyncService) (EventID: 10010) (User: )
Description: Signature Synchronization failed: Ein Teil des Pfades "C:\Users\Zeus1\AppData\Roaming\Microsoft\Signatures" konnte nicht gefunden werden.
Error: (02/03/2015 05:45:38 PM) (Source: DNSyncService) (EventID: 10010) (User: )
Description: Signature Synchronization failed: Ein Teil des Pfades "C:\Users\Zeus1\AppData\Roaming\Microsoft\Signatures" konnte nicht gefunden werden.
Error: (02/03/2015 03:05:56 PM) (Source: DNSyncService) (EventID: 10010) (User: )
Description: Signature Synchronization failed: Ein Teil des Pfades "C:\Users\Zeus1\AppData\Roaming\Microsoft\Signatures" konnte nicht gefunden werden.
Error: (02/03/2015 00:48:22 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm dwgviewr.exe, Version 25.1.18.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1ff4
Startzeit: 01d03fa69dd3d7e7
Endzeit: 58
Anwendungspfad: C:\Program Files\Autodesk\DWG TrueView 2014\dwgviewr.exe
Berichts-ID: 8a447c63-ab9a-11e4-8a75-2c27d735c49f
Error: (02/03/2015 00:56:04 AM) (Source: SideBySide) (EventID: 9) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Das Stammelement der Manifestdatei muss assembliert sein.
Error: (02/02/2015 05:54:42 PM) (Source: DNSyncService) (EventID: 10010) (User: )
Description: Signature Synchronization failed: Ein Teil des Pfades "C:\Users\Zeus1\AppData\Roaming\Microsoft\Signatures" konnte nicht gefunden werden.
Error: (02/02/2015 10:02:21 AM) (Source: DNSyncService) (EventID: 10010) (User: )
Description: Signature Synchronization failed: Ein Teil des Pfades "C:\Users\Zeus1\AppData\Roaming\Microsoft\Signatures" konnte nicht gefunden werden.
Error: (02/02/2015 09:00:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: notify.exe, Version: 12.0.2.18211, Zeitstempel: 0x5151c176
Name des fehlerhaften Moduls: MSVCR90.dll, Version: 9.0.30729.6161, Zeitstempel: 0x4dace5b9
Ausnahmecode: 0xc0000417
Fehleroffset: 0x00026a14
ID des fehlerhaften Prozesses: 0xe7c
Startzeit der fehlerhaften Anwendung: 0xnotify.exe0
Pfad der fehlerhaften Anwendung: notify.exe1
Pfad des fehlerhaften Moduls: notify.exe2
Berichtskennung: notify.exe3
System errors:
=============
Error: (02/02/2015 04:05:58 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (02/02/2015 04:05:56 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (02/02/2015 04:05:54 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (02/02/2015 04:05:52 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (02/02/2015 04:05:50 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (02/02/2015 04:05:48 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (02/02/2015 04:05:46 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (02/02/2015 04:05:45 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (02/02/2015 04:05:43 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Error: (02/02/2015 04:05:41 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.
Microsoft Office Sessions:
=========================
Error: (02/04/2015 01:11:29 AM) (Source: SideBySide) (EventID: 9) (User: )
Description: C:\Program Files (x86)\Common Files\C4B\UMS\Word\adxloader.dll.ManifestC:\Program Files (x86)\Common Files\C4B\UMS\Word\adxloader.dll.Manifest2
Error: (02/03/2015 07:43:20 PM) (Source: DNSyncService) (EventID: 10010) (User: )
Description: Signature Synchronization failed: Ein Teil des Pfades "C:\Users\Zeus1\AppData\Roaming\Microsoft\Signatures" konnte nicht gefunden werden.
Error: (02/03/2015 07:08:58 PM) (Source: DNSyncService) (EventID: 10010) (User: )
Description: Signature Synchronization failed: Ein Teil des Pfades "C:\Users\Zeus1\AppData\Roaming\Microsoft\Signatures" konnte nicht gefunden werden.
Error: (02/03/2015 05:45:38 PM) (Source: DNSyncService) (EventID: 10010) (User: )
Description: Signature Synchronization failed: Ein Teil des Pfades "C:\Users\Zeus1\AppData\Roaming\Microsoft\Signatures" konnte nicht gefunden werden.
Error: (02/03/2015 03:05:56 PM) (Source: DNSyncService) (EventID: 10010) (User: )
Description: Signature Synchronization failed: Ein Teil des Pfades "C:\Users\Zeus1\AppData\Roaming\Microsoft\Signatures" konnte nicht gefunden werden.
Error: (02/03/2015 00:48:22 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: dwgviewr.exe25.1.18.01ff401d03fa69dd3d7e758C:\Program Files\Autodesk\DWG TrueView 2014\dwgviewr.exe8a447c63-ab9a-11e4-8a75-2c27d735c49f
Error: (02/03/2015 00:56:04 AM) (Source: SideBySide) (EventID: 9) (User: )
Description: C:\Program Files (x86)\Common Files\C4B\UMS\Word\adxloader.dll.ManifestC:\Program Files (x86)\Common Files\C4B\UMS\Word\adxloader.dll.Manifest2
Error: (02/02/2015 05:54:42 PM) (Source: DNSyncService) (EventID: 10010) (User: )
Description: Signature Synchronization failed: Ein Teil des Pfades "C:\Users\Zeus1\AppData\Roaming\Microsoft\Signatures" konnte nicht gefunden werden.
Error: (02/02/2015 10:02:21 AM) (Source: DNSyncService) (EventID: 10010) (User: )
Description: Signature Synchronization failed: Ein Teil des Pfades "C:\Users\Zeus1\AppData\Roaming\Microsoft\Signatures" konnte nicht gefunden werden.
CodeIntegrity Errors:
===================================
Date: 2015-01-23 15:08:00.090
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-23 14:29:47.830
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-23 14:15:28.424
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-23 14:04:05.965
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-23 13:54:44.903
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-23 13:18:26.946
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-23 13:09:21.224
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-23 12:59:53.820
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-23 12:53:47.452
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-01-23 12:44:40.065
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5 CPU 660 @ 3.33GHz
Percentage of memory in use: 71%
Total physical RAM: 8055.29 MB
Available physical RAM: 2282.94 MB
Total Pagefile: 16108.76 MB
Available Pagefile: 7417.88 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:232.79 GB) (Free:137.82 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: ACA7ACA7)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |