Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 10.05.2015
Suchlauf-Zeit: 20:50:59
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.05.10.05
Rootkit Datenbank: v2015.04.21.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Steve
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 482468
Verstrichene Zeit: 53 Min, 19 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)
Registrierungswerte: 1
PUP.Optional.SecurityProtection.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|detgdp@gmail.com, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com, In Quarantäne, [7984c6cb99f1c86eb24f7a56ff0435cb]
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 10
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\lib, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\pack, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\locale, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\locale\en-US, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\locale\zh-CN, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\skin, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
Dateien: 15
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome.manifest, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\install.rdf, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\restartOverlay.xul, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\epurls.js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\inject.js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\restart.js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\lib\jquery-2.1.1.min.js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\pack\common.js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\pack\xagainit.js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\locale\en-US\restart.dtd, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\locale\zh-CN\restart.dtd, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\skin\icon.png, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\skin\iconsmall.png, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\skin\iconverysmall.png, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\skin\restartfirefox.css, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 10.05.2015
Suchlauf-Zeit: 20:50:59
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.05.10.05
Rootkit Datenbank: v2015.04.21.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Steve
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 482468
Verstrichene Zeit: 53 Min, 19 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)
Registrierungswerte: 1
PUP.Optional.SecurityProtection.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|detgdp@gmail.com, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com, In Quarantäne, [7984c6cb99f1c86eb24f7a56ff0435cb]
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 10
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\lib, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\pack, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\locale, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\locale\en-US, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\locale\zh-CN, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\skin, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
Dateien: 15
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome.manifest, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\install.rdf, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\restartOverlay.xul, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\epurls.js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\inject.js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\restart.js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\lib\jquery-2.1.1.min.js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\pack\common.js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\content\js\pack\xagainit.js, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\locale\en-US\restart.dtd, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\locale\zh-CN\restart.dtd, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\skin\icon.png, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\skin\iconsmall.png, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\skin\iconverysmall.png, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
PUP.Optional.SecurityProtection.A, C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\extensions\detgdp@gmail.com\chrome\skin\restartfirefox.css, In Quarantäne, [5e9fc2cfc7c339fd06745676bd463ac6],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.7.0 (05.09.2015:1)
OS: Windows 8.1 x64
Ran by Steve on 10.05.2015 at 22:06:26,43
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-2504205578-3664761490-1019857873-1001
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-2504205578-3664761490-1019857873-1002
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\G500\AppData\Roaming\mozilla\firefox\profiles\gt8dt6kh.default\minidumps [13 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10.05.2015 at 22:09:46,16
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-05-2015
Ran by Steve (administrator) on HOME on 10-05-2015 22:11:52
Running from C:\Users\G500\Downloads
Loaded Profiles: Steve (Available profiles: Steve & Banking-Konto & Administrator)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-08] (Intel Corporation)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [903384 2013-07-25] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [6340312 2013-07-19] (Realtek semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2894664 2013-08-08] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17111056 2013-12-19] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [193008 2013-12-19] (Lenovo(beijing) Limited)
HKLM-x32\...\Run: [Lenovo App Shop] => C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\ismagent.exe [156000 2013-07-19] (Intel Corporation)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-07] (CyberLink Corp.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [191016 2014-05-14] (Geek Software GmbH)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1279120 2012-09-27] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452272 2012-08-31] (CANON INC.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\...\Run: [Wunderlist] => "C:\Program Files (x86)\Wunderlist2\Wunderlist.exe" /silent
HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\...\Run: [Rainlendar2] => C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe [2611808 2014-03-16] ()
HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\...\Run: [Downloads\Perfect-Table-Plan-Clock_eventcountdownclock] => "C:\Users\G500\Downloads\eventcountdownclock.exe"
Startup: C:\Users\G500\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk [2014-05-12]
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\G500\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar75.lnk [2015-04-06]
ShortcutTarget: Sidebar75.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (No File)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\G500\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\G500\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\G500\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\G500\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\G500\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\G500\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\G500\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\x64\IEExt\ie_plugin.dll [2014-12-28] (Kaspersky Lab ZAO)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexbho.dll [2014-01-24] (CANON INC.)
BHO: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\x64\IEExt\ie_plugin.dll [2014-12-28] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\x64\IEExt\ie_plugin.dll [2014-12-28] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll [2014-12-28] (Kaspersky Lab ZAO)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-01-24] (CANON INC.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll [2014-12-28] (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll [2014-12-28] (Kaspersky Lab ZAO)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll [2014-01-24] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-01-24] (CANON INC.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-28] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker_6418E0D362104DADA084DC312DFA8ABC -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com [2014-12-28] ()
FF Plugin-x32: @kaspersky.com/online_banking_69A4E213815F42BD863D889007201D82 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com [2014-12-28] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com [2014-12-28] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll [2014-04-17] (pdfforge GmbH)
FF Plugin HKU\S-1-5-21-2504205578-3664761490-1019857873-1001: intel.com/AppUp -> C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\npAppUp.dll [2013-07-19] (Intel)
FF Plugin HKU\S-1-5-21-2504205578-3664761490-1019857873-1001: intel.com/AppUpx64 -> C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\npAppUp_x64.dll [2013-07-19] (Intel)
FF user.js: detected! => C:\ProgramData\Kaspersky Lab\SafeBrowser\S-1-5-21-2504205578-3664761490-1019857873-1001\FireFox\user.js [2014-12-28]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-12-28]
FF Extension: Translate This! - C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\Extensions\jid0-k75TfRGfOXPHfEZmJ9cKu5eCgLc@jetpack.xpi [2014-09-21]
FF Extension: Google Translator for Firefox - C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\Extensions\translator@zoli.bod.xpi [2014-09-21]
FF Extension: Adblock Plus - C:\Users\G500\AppData\Roaming\Mozilla\Firefox\Profiles\gt8dt6kh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-12]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900}.xpi [2015-04-24]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker_6418E0D362104DADA084DC312DFA8ABC@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com [2014-12-28]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com [2014-12-28]
FF HKLM-x32\...\Firefox\Extensions: [online_banking_69A4E213815F42BD863D889007201D82@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com [2014-12-28]
FF HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-12-28]
Chrome:
=======
CHR Profile: C:\Users\G500\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVP15.0.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe [234520 2014-08-30] (Kaspersky Lab ZAO)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
S2 ETDService; C:\Program Files\Elantech\ETDService.exe [92160 2013-07-29] (ELAN Microelectronics Corp.)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-08] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation)
S2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-08-02] (Intel Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1663880 2014-05-06] ()
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1716264 2014-04-17] (pdfforge GmbH)
S2 PDF Architect 2 Creator; C:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738344 2014-04-17] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-04-17] (pdfforge GmbH)
S2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
S2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2013-12-19] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [132920 2013-04-24] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1385784 2013-06-27] (Motorola Solutions, Inc.)
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [238288 2013-01-14] (Kaspersky Lab UK Ltd)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [468576 2014-03-31] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [46144 2014-07-02] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [150536 2014-12-28] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [247480 2014-08-12] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [800440 2015-03-12] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2014-02-25] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [28768 2014-03-28] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-08-08] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [68616 2014-12-28] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [77512 2014-12-28] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [179776 2014-07-09] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-10] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-08] (Intel Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation)
S3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [1975000 2013-07-31] (Realtek Semiconductor Corporation )
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8247640 2013-07-19] (Realtek Semiconductor Corp.)
R3 SensorsAlsDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation)
R3 SensorsHIDClassDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
U4 klkbdflt2; \SystemRoot\system32\DRIVERS\klkbdflt2.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-10 22:09 - 2015-05-10 22:09 - 00000992 _____ () C:\Users\G500\Desktop\JRT.txt
2015-05-10 22:06 - 2015-05-10 22:06 - 00000207 _____ () C:\WINDOWS\tweaking.com-regbackup-HOME-Windows-8.1-(64-bit).dat
2015-05-10 22:06 - 2015-05-10 22:06 - 00000000 ____D () C:\RegBackup
2015-05-10 22:04 - 2015-05-10 22:04 - 02720307 _____ (Thisisu) C:\Users\G500\Desktop\JRT.exe
2015-05-10 22:03 - 2015-05-10 22:03 - 00012465 _____ () C:\Users\G500\Desktop\AdwCleaner[S1].ods
2015-05-10 21:51 - 2015-05-10 22:02 - 00000000 ____D () C:\AdwCleaner
2015-05-10 21:51 - 2015-05-10 21:51 - 02204160 _____ () C:\Users\G500\Downloads\AdwCleaner_4.203.exe
2015-05-10 21:46 - 2015-05-10 21:46 - 00006647 _____ () C:\Users\G500\Desktop\mbam.txt
2015-05-10 20:50 - 2015-05-10 22:00 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-05-10 20:49 - 2015-05-10 20:49 - 00001129 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-10 20:49 - 2015-05-10 20:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-10 20:49 - 2015-05-10 20:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-10 20:49 - 2015-05-10 20:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-10 20:49 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-05-10 20:49 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-05-10 20:49 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-05-10 20:47 - 2015-05-10 20:48 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\G500\Downloads\mbam-setup-2.1.6.1022.exe
2015-05-10 08:53 - 2015-05-10 08:56 - 00028730 _____ () C:\Users\G500\Downloads\Addition.txt
2015-05-10 08:51 - 2015-05-10 22:12 - 00000000 ____D () C:\FRST
2015-05-10 08:51 - 2015-05-10 22:11 - 00020798 _____ () C:\Users\G500\Downloads\FRST.txt
2015-05-10 08:50 - 2015-05-10 08:50 - 02102784 _____ (Farbar) C:\Users\G500\Downloads\FRST64.exe
2015-05-03 11:20 - 2015-05-03 11:20 - 00000000 ____D () C:\Users\Public\Documents\sun
2015-05-03 11:18 - 2015-05-03 11:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.4
2015-05-03 11:17 - 2015-05-03 11:18 - 00000000 ____D () C:\Program Files (x86)\LibreOffice 4
2015-05-03 10:59 - 2015-05-10 21:17 - 00000000 ____D () C:\Users\G500\AppData\Roaming\vlc
2015-05-03 10:57 - 2015-05-03 10:57 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2015-05-03 10:52 - 2015-05-03 10:54 - 28849904 _____ () C:\Users\G500\Downloads\vlc-2.2.1-win32.exe
2015-05-03 10:51 - 2015-05-03 11:04 - 224325632 _____ () C:\Users\G500\Downloads\LibreOffice_4.4.2_Win_x86.msi
2015-04-24 18:25 - 2015-04-24 18:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-04-17 18:25 - 2015-04-17 18:25 - 00000000 ____D () C:\Users\Banking-Konto\Downloads\Wallpaper
2015-04-17 18:25 - 2015-04-17 18:25 - 00000000 ____D () C:\Users\Banking-Konto\Desktop\Wallpaper
2015-04-17 18:22 - 2015-04-17 18:23 - 03219628 _____ () C:\Users\Banking-Konto\Downloads\HD_Wallpaper_Travel.zip
2015-04-17 16:40 - 2015-04-17 16:40 - 00000000 ____D () C:\Users\Banking-Konto\AppData\Roaming\InstallShield
2015-04-17 16:40 - 2015-04-17 16:40 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver
2015-04-17 16:30 - 2015-04-17 16:30 - 00000000 ____D () C:\Users\G500\AppData\Roaming\EasySettingBox
2015-04-15 12:11 - 2015-04-15 12:11 - 00000000 ____D () C:\Users\Banking-Konto\AppData\Roaming\Apple Computer
2015-04-15 11:41 - 2015-03-23 00:45 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-04-15 11:41 - 2015-03-23 00:09 - 01111552 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-04-15 11:41 - 2015-03-23 00:09 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-04-15 11:41 - 2015-03-23 00:09 - 00769024 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-04-15 11:41 - 2015-03-23 00:09 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-04-15 11:41 - 2015-03-23 00:09 - 00419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-04-15 11:41 - 2015-03-23 00:09 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-04-15 11:41 - 2015-03-14 10:20 - 01385256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2015-04-15 11:41 - 2015-03-14 10:13 - 01124352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2015-04-15 11:00 - 2015-04-15 11:00 - 18178736 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2015-04-15 10:24 - 2015-03-23 23:59 - 07476032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-04-15 10:24 - 2015-03-23 23:59 - 01733952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-04-15 10:24 - 2015-03-20 04:40 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2015-04-15 10:23 - 2015-03-23 23:59 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2015-04-15 10:23 - 2015-03-23 23:58 - 01498872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-04-15 10:23 - 2015-03-23 23:45 - 00257216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2015-04-15 10:23 - 2015-03-20 06:12 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2015-04-15 10:23 - 2015-03-20 06:10 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-04-15 10:23 - 2015-03-20 06:10 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-04-15 10:23 - 2015-03-20 05:17 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\tracerpt.exe
2015-04-15 10:23 - 2015-03-20 04:41 - 00369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tracerpt.exe
2015-04-15 10:23 - 2015-03-20 04:16 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2015-04-15 10:23 - 2015-03-13 06:32 - 24980480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-04-15 10:23 - 2015-03-13 06:08 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-04-15 10:23 - 2015-03-13 06:07 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-04-15 10:23 - 2015-03-13 05:53 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-04-15 10:23 - 2015-03-13 05:50 - 06025216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-04-15 10:23 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-04-15 10:23 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-04-15 10:23 - 2015-03-13 05:26 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-04-15 10:23 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-04-15 10:23 - 2015-03-13 05:17 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-04-15 10:23 - 2015-03-13 05:16 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-04-15 10:23 - 2015-03-13 05:08 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-04-15 10:23 - 2015-03-13 05:07 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-04-15 10:23 - 2015-03-13 05:00 - 14397440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-04-15 10:23 - 2015-03-13 04:50 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-04-15 10:23 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-04-15 10:23 - 2015-03-13 04:45 - 02358784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-04-15 10:23 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-04-15 10:23 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-04-15 10:23 - 2015-03-13 04:33 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-04-15 10:23 - 2015-03-13 04:22 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-04-15 10:23 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-04-15 10:23 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-04-15 10:23 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-04-15 10:23 - 2015-02-21 01:49 - 00780800 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2015-04-15 10:22 - 2015-03-14 10:54 - 00133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-04-15 10:22 - 2015-03-14 03:56 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-04-15 10:22 - 2015-03-14 03:56 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-04-15 10:22 - 2015-03-14 03:51 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll
2015-04-15 10:22 - 2015-03-14 03:37 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-04-15 10:22 - 2015-03-14 03:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-04-15 10:22 - 2015-03-14 02:22 - 03678720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-04-15 10:22 - 2015-03-14 02:12 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-04-15 10:22 - 2015-03-14 02:12 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-04-15 10:22 - 2015-03-14 02:09 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-04-15 10:22 - 2015-03-14 02:08 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-04-15 10:22 - 2015-03-14 02:08 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-04-15 10:22 - 2015-03-14 02:06 - 02373632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-04-15 10:22 - 2015-03-14 02:06 - 00891392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-04-15 10:22 - 2015-03-14 02:02 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-04-15 10:22 - 2015-03-14 02:02 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-04-15 10:22 - 2015-03-14 01:59 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-04-15 10:22 - 2015-03-14 01:59 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-04-15 10:22 - 2015-03-13 04:58 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2015-04-15 10:22 - 2015-03-13 04:37 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2015-04-15 10:22 - 2015-03-04 12:25 - 00377152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2015-04-15 10:22 - 2015-03-04 05:04 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clfsw32.dll
2015-04-15 10:22 - 2015-03-04 04:19 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clfsw32.dll
2015-04-15 10:22 - 2015-02-24 10:32 - 00991552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2015-04-14 08:48 - 2015-04-14 08:48 - 00000000 ____D () C:\Users\G500\AppData\Roaming\GeoGebra 5.0
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-10 22:10 - 2013-12-19 20:19 - 00208008 _____ () C:\WINDOWS\setupact.log
2015-05-10 22:07 - 2014-05-03 14:29 - 29889190 _____ () C:\Users\Public\CAFADEBUG.log
2015-05-10 22:07 - 2013-12-19 21:05 - 00023040 _____ () C:\WINDOWS\system32\VfService.trf
2015-05-10 22:07 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-05-10 22:00 - 2014-09-15 22:20 - 00000000 ____D () C:\Users\G500\.rainlendar2
2015-05-10 22:00 - 2014-05-10 22:08 - 00000433 _____ () C:\WINDOWS\system32\Drivers\etc\hosts.ics
2015-05-10 22:00 - 2014-05-05 21:08 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-05-10 22:00 - 2014-05-03 20:58 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-05-10 21:59 - 2013-08-28 10:34 - 00041074 _____ () C:\WINDOWS\PFRO.log
2015-05-10 21:59 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-10 21:58 - 2013-08-22 15:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-05-10 21:41 - 2013-12-19 21:07 - 01743264 _____ () C:\WINDOWS\WindowsUpdate.log
2015-05-10 21:30 - 2013-12-19 21:13 - 00877622 _____ () C:\WINDOWS\system32\perfh007.dat
2015-05-10 21:30 - 2013-12-19 21:13 - 00195432 _____ () C:\WINDOWS\system32\perfc007.dat
2015-05-10 21:30 - 2013-08-28 10:36 - 02050414 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-05-10 21:02 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-05-08 18:45 - 2013-08-22 16:44 - 00534864 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-05-08 18:44 - 2014-05-03 21:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-07 23:52 - 2014-04-26 17:21 - 00000000 ____D () C:\Users\G500\Documents\Finance
2015-05-04 20:21 - 2014-04-26 15:57 - 00000000 ____D () C:\Users\G500\Documents\Applications
2015-05-03 18:01 - 2014-05-03 13:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-05-03 18:01 - 2014-05-03 13:54 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-05-03 11:25 - 2014-05-03 14:04 - 00007597 _____ () C:\Users\G500\AppData\Local\resmon.resmoncfg
2015-05-01 21:15 - 2014-08-13 17:31 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2015-04-27 21:20 - 2015-01-01 18:42 - 00000000 ____D () C:\Users\G500\Documents\Interessante Statistiken
2015-04-26 15:45 - 2014-04-26 17:21 - 00000000 ____D () C:\Users\G500\Documents\Skool
2015-04-22 17:41 - 2015-02-15 22:53 - 00000000 ____D () C:\Users\G500\Documents\Studium
2015-04-20 16:54 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppCompat
2015-04-17 16:56 - 2014-04-26 17:01 - 00000000 ____D () C:\Users\G500\Documents\programms
2015-04-17 16:55 - 2013-12-19 20:37 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-04-17 16:54 - 2014-06-11 23:06 - 00000000 ____D () C:\ProgramData\Apple
2015-04-17 16:48 - 2015-04-02 15:11 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-04-17 16:45 - 2013-08-22 17:36 - 00000000 __SHD () C:\Program Files\Windows Sidebar
2015-04-17 16:45 - 2013-08-22 17:36 - 00000000 __SHD () C:\Program Files (x86)\Windows Sidebar
2015-04-16 19:15 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-04-16 19:08 - 2013-08-22 17:20 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-04-15 14:07 - 2014-05-03 21:51 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-04-15 14:01 - 2014-05-03 21:51 - 128913832 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-04-15 13:53 - 2014-12-11 19:41 - 00000000 ____D () C:\WINDOWS\system32\appraiser
2015-04-15 13:53 - 2014-07-10 22:44 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2015-04-15 11:00 - 2014-05-05 21:08 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-04-15 10:17 - 2014-11-12 17:07 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaext.dll
2015-04-14 01:24 - 2015-03-11 22:55 - 00792056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-04-14 01:24 - 2015-03-11 22:55 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2014-11-29 22:07 - 2014-11-29 22:07 - 0004096 ____H () C:\Users\G500\AppData\Local\keyfile3.drm
2014-09-15 22:51 - 2014-09-25 22:52 - 0000173 _____ () C:\Users\G500\AppData\Local\msmathematics.qat.Steve
2014-05-03 14:04 - 2015-05-03 11:25 - 0007597 _____ () C:\Users\G500\AppData\Local\resmon.resmoncfg
2013-12-19 20:39 - 2013-12-19 20:39 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some content of TEMP:
====================
C:\Users\Banking-Konto\AppData\Local\Temp\octC2E.tmp.exe
C:\Users\G500\AppData\Local\Temp\javagiac0.10857691700995198.dll
C:\Users\G500\AppData\Local\Temp\javagiac0.5454160740087163.dll
C:\Users\G500\AppData\Local\Temp\Quarantine.exe
C:\Users\G500\AppData\Local\Temp\sqlite3.dll
C:\Users\G500\AppData\Local\Temp\tmd_34011777.exe
C:\Users\G500\AppData\Local\Temp\tmd_34012307.exe
C:\Users\G500\AppData\Local\Temp\tmd_34013031.exe
C:\Users\G500\AppData\Local\Temp\tmd_34016595.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-30 19:58
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
FRST Additions Logfile:
Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-05-2015
Ran by Steve at 2015-05-10 22:29:05
Running from C:\Users\G500\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2504205578-3664761490-1019857873-500 - Administrator - Disabled) => C:\Users\Administrator
Banking-Konto (S-1-5-21-2504205578-3664761490-1019857873-1002 - Limited - Enabled) => C:\Users\Banking-Konto
Gast (S-1-5-21-2504205578-3664761490-1019857873-501 - Limited - Disabled)
Steve (S-1-5-21-2504205578-3664761490-1019857873-1001 - Administrator - Enabled) => C:\Users\G500
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
¡Adelante! Nivel elemental (HKLM-x32\...\¡Adelante! Nivel elemental) (Version: 1.0.0.0 - Ernst Klett Verlag GmbH)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 15.0.0.356 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
AudibleManager (HKLM-x32\...\AudibleManager) (Version: 1476395353.4759644.48.2147344384 - Audible, Inc.)
Benutzerhandbuch (x32 Version: 1.0.0.17 - Lenovo) Hidden
Cambridge School Dictionary (HKLM-x32\...\NSIS_csd) (Version: - )
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.4.1.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - Canon Inc.)
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.2.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - Canon Inc.)
Canon Kurzwahlprogramm (HKLM-x32\...\Speed Dial Utility) (Version: 1.3.0 - Canon Inc.)
Canon MX920 series Benutzerregistrierung (HKLM-x32\...\Canon MX920 series Benutzerregistrierung) (Version: - *Canon Inc.)
Canon MX920 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX920_series) (Version: 1.00 - Canon Inc.)
Canon MX920 series On-screen Manual (HKLM-x32\...\Canon MX920 series On-screen Manual) (Version: 7.6.0 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 1.1.0 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 1.0.1 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.1.0 - Canon Inc.)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.3.53 - Conexant)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.3.2.2 - Dolby Laboratories Inc)
Dropbox (HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\...\Dropbox) (Version: 2.6.31 - Dropbox, Inc.)
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 8.0.2.14 - Lenovo)
Energy Management (x32 Version: 8.0.2.14 - Lenovo) Hidden
Free YouTube Download version 3.2.51.1215 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.51.1215 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.52.1215 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.52.1215 - DVDVideoSoft Ltd.)
GeoGebra 5 (HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\...\GeoGebra 5) (Version: 5.0.75.0 - International GeoGebra Institute)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3308 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 3.0.1327.1) (HKLM\...\{302600C1-6BDF-4FD1-1307-148929CC1385}) (Version: 3.1.1307.0362 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{8ED07EBD-22AD-415A-B71E-C1AD86862C2E}) (Version: 15.0.1.415 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 15.0.1.415 - Kaspersky Lab) Hidden
Lenovo App Shop (HKLM-x32\...\Lenovo App Shop 45246) (Version: 3.10.0.45246.24 - Lenovo)
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10240 - Realtek Semiconductor Corp.)
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.0.0.2105 - CyberLink Corp.) Hidden
Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.7 - CEWE COLOR AG u Co. OHG)
Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.25.1 - ELAN Microelectronic Corp.)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5108.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5108.52 - CyberLink Corp.) Hidden
Lenovo Solution Center (HKLM\...\{2F45A217-E9C7-4984-B0AC-5BE31FF4712B}) (Version: 2.4.003.00 - Lenovo Group Limited)
Lenovo VeriFace (HKLM\...\Lenovo VeriFace) (Version: 5.0.13.5261 - Lenovo)
LibreOffice 4.4.2.2 (HKLM-x32\...\{99A395EF-A310-40BB-B7A3-E3FF07CC38FC}) (Version: 4.4.2.2 - The Document Foundation)
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft Mathematics (64-bit) (HKLM\...\{E57B7E0A-8BE5-42E2-BE60-C07ED680A063}) (Version: 4.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 37.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 de)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.5.0 - Mozilla)
Mozilla Thunderbird 31.6.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.6.0 (x86 de)) (Version: 31.6.0 - Mozilla)
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.24.16092 - pdfforge GmbH)
PDF Architect 2 Create Module (HKLM-x32\...\{1D8D2505-D5B4-42F5-8398-672DC4B49576}) (Version: 2.0.5.16319 - pdfforge GmbH)
PDF Architect 2 View Module (HKLM-x32\...\{3DA20A12-AD9F-4A75-8A6F-5204EEB94359}) (Version: 2.0.5.16319 - pdfforge GmbH)
PDF24 Creator 6.4.1 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.)
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.21 - Qualcomm Atheros Inc.)
Rainlendar2 (remove only) (HKLM-x32\...\Rainlendar2) (Version: - )
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.39048 - Realtek Semiconductor Corp.)
Samsung_MonSetup (HKLM-x32\...\{8EA79DBF-D637-448A-89D6-410A087A4493}) (Version: 1.00.0000 - Samsung)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
UserGuide (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.17 - Lenovo)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
VLC media player 2.1.4 (HKLM\...\VLC media player) (Version: 2.1.4 - VideoLAN)
Windows-Treiberpaket - Lenovo (ACPIVPC) System (02/17/2013 9.52.0.776) (HKLM\...\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2504205578-3664761490-1019857873-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\G500\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2504205578-3664761490-1019857873-1001_Classes\CLSID\{9E506282-69D3-5ABA-9C1D-15994B37F4AC}\InprocServer32 -> C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\npAppUp_x64.dll (Intel)
CustomCLSID: HKU\S-1-5-21-2504205578-3664761490-1019857873-1001_Classes\CLSID\{9E506282-69D3-5ABA-9C1D-15994B37F4AD}\InprocServer32 -> C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\npAppUp_x64.dll (Intel)
CustomCLSID: HKU\S-1-5-21-2504205578-3664761490-1019857873-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\G500\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2504205578-3664761490-1019857873-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\G500\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2504205578-3664761490-1019857873-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\G500\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2504205578-3664761490-1019857873-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\G500\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
==================== Restore Points =========================
26-04-2015 02:31:22 Geplanter Prüfpunkt
03-05-2015 11:07:38 Installed LibreOffice 4.4.2.2
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {00246168-B3FA-47A7-B5DB-309B11DC122A} - \Optimize Start Menu Cache Files-S-1-5-21-2504205578-3664761490-1019857873-1002 No Task File <==== ATTENTION
Task: {1E78B272-87C9-475E-8790-6115A337AF4A} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {2B73296A-941B-458A-B78D-9253A29FE0DD} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
Task: {493933DC-E082-4AF8-BE8B-E5601A0A676B} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {49E6BF23-5004-4DF4-9A25-8563BFE2204E} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-04-15] (Microsoft Corporation)
Task: {75FF1B5F-CC23-4AE4-9009-CEC1029C81A2} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {812169A3-7AB9-42A3-8859-15667514DA26} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {860078CB-95B2-4076-9931-054080AF75E4} - \Optimize Start Menu Cache Files-S-1-5-21-2504205578-3664761490-1019857873-1001 No Task File <==== ATTENTION
Task: {9B19978A-0AD8-4516-88ED-8AFE1103E80B} - System32\Tasks\Lenovo\LSC\Time72Task => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe [2014-05-06] (Lenovo)
Task: {A9384EE6-688A-4E9B-9D3A-B64637D704AB} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2014-05-06] ()
Task: {B1181ED0-E2C7-4C95-863F-91C132A4CDAE} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-09] (CyberLink Corp.)
Task: {B144A510-16F2-48E6-A188-662811EBA794} - System32\Tasks\Lenovo\LSC\RebootCountTask => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe [2014-05-06] (Lenovo)
Task: {BF724B23-5956-4410-8961-0B30F06B6618} - System32\Tasks\Lenovo\LSC\LSCTaskService => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCTaskService.exe [2014-05-06] ()
Task: {E06823A5-95E8-4997-A7D3-51A1A6D02DDF} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-05-06] (Lenovo)
Task: {E14D7F80-AC6B-44EE-8100-5439CA743A8A} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation)
Task: {E2D0B93A-78B6-4BA3-9417-AF199E712EA7} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2014-05-06] (Lenovo)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) ==============
2014-08-30 18:12 - 2014-08-30 18:12 - 01269952 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\kpcengine.2.3.dll
2013-12-19 20:38 - 2013-08-08 23:23 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-08-30 18:12 - 2014-12-28 22:29 - 00332584 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\online_banking@kaspersky.com\nponlinebanking.dll
2014-08-30 18:12 - 2014-12-28 22:29 - 00459048 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\content_blocker@kaspersky.com\npcontentblocker.dll
2014-08-30 18:12 - 2014-12-28 22:29 - 00587048 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\FFExt\virtual_keyboard@kaspersky.com\npvkplugin.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\Users\G500\OneDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\G500\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.2.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\Run: => "BTMTrayAgent"
HKLM\...\StartupApproved\Run: => "IAStorIcon"
HKLM\...\StartupApproved\Run: => "Energy Management"
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run32: => "Lenovo App Shop"
HKLM\...\StartupApproved\Run32: => "UpdateP2GShortCut"
HKLM\...\StartupApproved\Run32: => "IJNetworkScannerSelectorEX"
HKLM\...\StartupApproved\Run32: => "CanonQuickMenu"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "PDFPrint"
HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\...\StartupApproved\StartupFolder: => "OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk"
HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\...\StartupApproved\StartupFolder: => "Sidebar554.lnk"
HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\...\StartupApproved\StartupFolder: => "Sidebar75.lnk"
HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\...\StartupApproved\Run: => "Pokki"
HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\...\StartupApproved\Run: => "Wunderlist"
HKU\S-1-5-21-2504205578-3664761490-1019857873-1001\...\StartupApproved\Run: => "Downloads\Perfect-Table-Plan-Clock_eventcountdownclock"
==================== FirewallRules (whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{AC65CE89-8FF6-4469-9B2F-C99D119EA9DD}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{34EFEDE5-3CDF-4443-BC74-BC69D354C971}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{DCC2D15C-2FB9-4D02-964E-96196898BF7C}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{06358B28-2F29-4520-80B6-6A72F6074800}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{21D4BE95-F46F-4852-8F3A-C6E69FB43B30}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{678F35DF-FBF7-48D4-BF22-A9E4BFFF9D95}] => (Allow) C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\ismagent.exe
FirewallRules: [{2F9405D5-2E08-4CA3-89CC-522857FEBD5C}] => (Allow) C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\ismloader.exe
FirewallRules: [{ED545708-EA00-44DB-87F0-3642FD10C732}] => (Allow) C:\Users\G500\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{349AFE77-AA14-4002-B02A-2173E383F8D3}] => (Allow) C:\Users\G500\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{5AE6FB6D-1C5B-4318-B37D-AAA9FEC20877}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [TCP Query User{D0AD203B-9CCA-4DFB-904D-6657771C991E}G:\xampp\mysql\bin\mysqld.exe] => (Block) G:\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{FAF95716-7477-4B22-8B06-966E1AC53628}G:\xampp\mysql\bin\mysqld.exe] => (Block) G:\xampp\mysql\bin\mysqld.exe
FirewallRules: [{9DDCFB1D-E682-413A-8559-48DC5D583E33}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6A914848-F0C5-46F0-B8B7-2BC2BEF3B419}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{2C964F41-1591-4951-882A-2D59E1906FF4}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{D145B786-B7BC-474F-96E9-DBBD0EA9D982}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (05/10/2015 09:59:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe_stisvc, Version: 6.3.9600.17415, Zeitstempel: 0x54504177
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000000000
ID des fehlerhaften Prozesses: 0x410
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe_stisvc0
Pfad der fehlerhaften Anwendung: svchost.exe_stisvc1
Pfad des fehlerhaften Moduls: svchost.exe_stisvc2
Berichtskennung: svchost.exe_stisvc3
Vollständiger Name des fehlerhaften Pakets: svchost.exe_stisvc4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe_stisvc5
Error: (05/10/2015 09:01:23 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (05/09/2015 11:59:28 PM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
Description: Der Desktopfenster-Manager hat einen schwerwiegenden Fehler (0x8898008d) festgestellt.
Error: (05/09/2015 11:59:18 PM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
Description: Der Desktopfenster-Manager hat einen schwerwiegenden Fehler (0x8898008d) festgestellt.
Error: (05/08/2015 06:46:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe_stisvc, Version: 6.3.9600.17415, Zeitstempel: 0x54504177
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000000000
ID des fehlerhaften Prozesses: 0x774
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe_stisvc0
Pfad der fehlerhaften Anwendung: svchost.exe_stisvc1
Pfad des fehlerhaften Moduls: svchost.exe_stisvc2
Berichtskennung: svchost.exe_stisvc3
Vollständiger Name des fehlerhaften Pakets: svchost.exe_stisvc4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe_stisvc5
Error: (05/07/2015 11:51:45 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: WmiApRplC:\WINDOWS\system32\wbem\wmiaprpl.dll4
Error: (05/07/2015 11:51:44 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: rdyboost4
Error: (05/07/2015 11:51:44 PM) (Source: PerfNet) (EventID: 2004) (User: )
Description:
Error: (05/07/2015 11:51:43 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: MSDTCC:\WINDOWS\system32\msdtcuiu.DLL4
Error: (05/07/2015 11:51:42 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: LsaC:\Windows\System32\Secur32.dll4
System errors:
=============
Error: (05/10/2015 10:12:07 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description:
Error: (05/10/2015 10:07:26 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Dynamic Application Loader Host Interface Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/10/2015 10:07:26 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Rapid Storage Technology" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/10/2015 10:07:26 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Bluetooth OBEX Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/10/2015 10:07:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Modules Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (05/10/2015 10:07:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Integrated Clock Controller Service - Intel(R) ICCS" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/10/2015 10:07:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "VeriFaceSrv" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/10/2015 10:07:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Conexant SmartAudio service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/10/2015 10:07:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Cyberlink RichVideo64 Service(CRVS)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (05/10/2015 10:07:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Microsoft Office Sessions:
=========================
Error: (01/24/2015 08:09:50 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6713.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 36 seconds with 0 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-3110M CPU @ 2.40GHz
Percentage of memory in use: 45%
Total physical RAM: 3993.77 MB
Available physical RAM: 2163.13 MB
Total Pagefile: 5017.77 MB
Available Pagefile: 2905.74 MB
Total Virtual: 131072 MB
Available Virtual: 131071.83 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:426.54 GB) (Free:127.38 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.62 GB) NTFS
Drive f: (Transcend) (Removable) (Total:7.53 GB) (Free:6.89 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 15BDBD43)
Partition: GPT Partition Type.
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 7.5 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7.5 GB) - (Type=0C)
==================== End Of Log ============================
--- --- ---