FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-07-2015
Ran by Doreen (administrator) on DOREEN-PC on 22-07-2015 09:53:13
Running from C:\Users\Doreen\Desktop
Loaded Profiles: Doreen (Available Profiles: Doreen)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
(Logitech, Inc.) C:\Program Files\Logitech\SolarApp\L4301_Solar.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(DATA BECKER GmbH & Co KG) C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Gemalto N.V.) C:\Users\Doreen\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
() C:\Windows\jmesoft\Service.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
(Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(Lavasoft) C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
(Lenovo) C:\Windows\jmesoft\hotkey.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Brightness System\Lenovo Dynamic Brightness System.exe
() C:\Windows\jmesoft\JME_LOAD.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe
(ZTE) C:\Program Files (x86)\congstar\Internetmanager\Bin\mcserver.exe
(Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\AutoDetector\Monitor.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicatorCom.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
() C:\Program Files (x86)\congstar\Internetmanager\Bin\dbus-daemon.exe
() C:\Program Files (x86)\congstar\Internetmanager\Bin\gconfd-2.exe
() C:\Program Files (x86)\congstar\Internetmanager\Bin\db_daemon.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avpui.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Farbar) C:\Users\Doreen\Desktop\FRST64(1).exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11543656 2010-10-26] (Realtek Semiconductor)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-11-12] (Lenovo)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [itype] => c:\Program Files\Microsoft IntelliType Pro\itype.exe [1873256 2011-08-10] (Microsoft Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [2419512 2012-11-04] (Logitech, Inc.)
HKLM-x32\...\Run: [jmekey] => C:\windows\jmesoft\hotkey.exe [118784 2011-03-22] (Lenovo)
HKLM-x32\...\Run: [jmesoft] => C:\Windows\jmesoft\ServiceLoader.exe [28672 2011-03-16] ()
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Lenovo Eye Distance System] => C:\Program Files\Lenovo\Lenovo Eye Distance System\Lenovo Eye Distance System.exe [265216 2010-09-09] (Lenovo)
HKLM-x32\...\Run: [Lenovo Dynamic Brightness System] => C:\Program Files\Lenovo\Lenovo Brightness System\Lenovo Dynamic Brightness System.exe [285696 2010-10-08] (Lenovo)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [103720 2009-12-05] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe [222504 2009-05-14] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Ulead AutoDetector v2] => C:\Program Files (x86)\Common Files\Ulead Systems\AutoDetector\monitor.exe [90112 2004-11-26] (Ulead Systems, Inc.)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-11-11] (Logitech Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2015-02-24] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [44128 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [642664 2013-05-08] (Adobe Systems Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [193568 2014-11-28] (Geek Software GmbH)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Run: [CAHeadless] => C:\Program Files (x86)\Adobe\Elements 10 Organizer\CAHeadless\ElementsAutoAnalyzer.exe [835224 2011-09-01] (Adobe Systems Incorporated)
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-11-12] (Google Inc.)
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Run: [SanDiskSecureAccess_Manager.exe] => C:\Users\Doreen\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [30705792 2012-10-09] (Gemalto N.V.)
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Run: [KiesAirMessage] => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Run: [] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2015-02-24] (Samsung)
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Run: [Google Update] => C:\Users\Doreen\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-07-12] (Google Inc.)
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248176 2014-06-05] (TomTom)
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Run: [Personal ID] => C:\Program Files (x86)\coolspot AG\Personal ID\pid.exe [1132984 2014-11-07] (coolspot AG, Düsseldorf)
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Run: [HP Officejet Pro 8600 (NET)] => C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1381648 2015-06-30] (Lavasoft)
HKU\S-1-5-18\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30878816 2014-12-11] (Skype Technologies S.A.)
AppInit_DLLs: acaptuser64.dll => C:\windows\system32\acaptuser64.dll [119160 2008-06-12] (Adobe Systems, Inc.)
AppInit_DLLs-x32: acaptuser32.dll => "acaptuser32.dll" File not found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ControlCenter.lnk [2014-01-16]
ShortcutTarget: ControlCenter.lnk -> C:\Program Files (x86)\T-Home\Eumex 800 V1.30\ControlCenter.exe (T-Com)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MCtlSvc.lnk [2013-05-23]
ShortcutTarget: MCtlSvc.lnk -> C:\Program Files (x86)\congstar\Internetmanager\Bin\mcserver.exe (ZTE)
Startup: C:\Users\Doreen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk [2015-01-21]
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LEND&bmod=LEND
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COSP&ptag=D063015-A166D148A50&form=CONMHP&conlogo=CT3334470
URLSearchHook: HKU\S-1-5-21-2478697962-178253433-2156096982-1001 - (No Name) - {7e111a5c-3d11-4f56-9463-5310c3c69025} - No File
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2478697962-178253433-2156096982-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D063015-A166D148A50&form=CONBDF&conlogo=CT3334470&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2478697962-178253433-2156096982-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D063015-A166D148A50&form=CONBDF&conlogo=CT3334470&q={searchTerms}
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-10-09] (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-21] (Google Inc.)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-10-09] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-03-13] (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-21] (Google Inc.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2012-11-04] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-13] (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20] (Kaspersky Lab ZAO)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-21] (Google Inc.)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-21] (Google Inc.)
Toolbar: HKU\S-1-5-21-2478697962-178253433-2156096982-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-21] (Google Inc.)
Toolbar: HKU\S-1-5-21-2478697962-178253433-2156096982-1001 -> No Name - {7E111A5C-3D11-4F56-9463-5310C3C69025} - No File
Winsock: Catalog9 01 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-06-30] (Lavasoft Limited)
Winsock: Catalog9 02 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-06-30] (Lavasoft Limited)
Winsock: Catalog9 03 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-06-30] (Lavasoft Limited)
Winsock: Catalog9 04 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-06-30] (Lavasoft Limited)
Winsock: Catalog9 15 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-06-30] (Lavasoft Limited)
Winsock: Catalog9-x64 01 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-06-30] (Lavasoft Limited)
Winsock: Catalog9-x64 02 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-06-30] (Lavasoft Limited)
Winsock: Catalog9-x64 03 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-06-30] (Lavasoft Limited)
Winsock: Catalog9-x64 04 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-06-30] (Lavasoft Limited)
Winsock: Catalog9-x64 15 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-06-30] (Lavasoft Limited)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.250
Tcpip\..\Interfaces\{5E7FCEB4-5DF5-495C-8B42-D08ABD689ADC}: [NameServer] 10.74.210.210 10.74.210.211
Tcpip\..\Interfaces\{7409B70C-82A5-4DE9-94CD-8E56E20AFEEB}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{9A0EBC9D-7E8B-42BB-B987-4478BFDDB8C0}: [DhcpNameServer] 192.168.1.250
Tcpip\..\Interfaces\{B01200D9-E9F6-4043-8FB0-745A4D4286E8}: [NameServer] 10.74.210.210 10.74.210.211
Tcpip\..\Interfaces\{C8A9EE94-5E59-4B2E-B581-09067691F23D}: [DhcpNameServer] 192.168.8.1 192.168.8.1
FireFox:
========
FF ProfilePath: C:\Users\Doreen\AppData\Roaming\Mozilla\Firefox\Profiles\tquqylpi.default
FF DefaultSearchEngine: Google Default
FF SelectedSearchEngine: Bing
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-21] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-21] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-13] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-13] (Oracle Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com [2014-10-09] ()
FF Plugin-x32: @kaspersky.com/online_banking -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com [2014-10-09] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-10-09] ()
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-02-22] (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @protectdisc.com/NPPDLicenseHelper -> C:\Program Files (x86)\ProtectDisc\License Helper\NPPDLicenseHelper.dll [2008-02-22] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-21] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-10-15] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2478697962-178253433-2156096982-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Doreen\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-2478697962-178253433-2156096982-1001: @talk.google.com/O1DPlugin -> C:\Users\Doreen\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-2478697962-178253433-2156096982-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Doreen\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-21] (Google Inc.)
FF Plugin HKU\S-1-5-21-2478697962-178253433-2156096982-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Doreen\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-21] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Doreen\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Doreen\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF SearchPlugin: C:\Users\Doreen\AppData\Roaming\Mozilla\Firefox\Profiles\tquqylpi.default\searchplugins\google-default.xml [2015-07-01]
FF Extension: German Dictionary - C:\Users\Doreen\AppData\Roaming\Mozilla\Firefox\Profiles\tquqylpi.default\Extensions\de-DE@dictionaries.addons.mozilla.org [2014-06-12]
FF Extension: WOT - C:\Users\Doreen\AppData\Roaming\Mozilla\Firefox\Profiles\tquqylpi.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-07-10]
FF Extension: Cliqz Beta - C:\Users\Doreen\AppData\Roaming\Mozilla\Firefox\Profiles\tquqylpi.default\Extensions\cliqz@cliqz.com.xpi [2014-12-15]
FF Extension: Webutation - C:\Users\Doreen\AppData\Roaming\Mozilla\Firefox\Profiles\tquqylpi.default\Extensions\{15fe27f3-e5ab-2d59-4c5c-dadc7945bdbd}.xpi [2013-10-31]
FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_H\OCx32\addon
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013-02-20]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com [2014-09-12]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-09-12]
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\url_advisor@kaspersky.com [2014-09-12]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\anti_banner@kaspersky.com [2014-09-12]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com [2014-09-12]
FF HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Doreen\AppData\Roaming\Mozilla\Firefox\Profiles\tquqylpi.default\extensions\cliqz@cliqz.com
Chrome:
=======
CHR Profile: C:\Users\Doreen\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (WOT) - C:\Users\Doreen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2013-10-31]
CHR Extension: (Kaspersky Protection) - C:\Users\Doreen\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2014-09-13]
CHR Extension: (Logitech SetPoint) - C:\Users\Doreen\AppData\Local\Google\Chrome\User Data\Default\Extensions\edaibbiobngpbmeonadpbfafbkimjbdd [2013-02-27]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Doreen\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14]
CHR Extension: (Webutation) - C:\Users\Doreen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfclfmabiojpommfcalfdgjjeaahnjbj [2013-10-31]
CHR Extension: (Google Wallet) - C:\Users\Doreen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx [2013-02-20]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeActiveFileMonitor10.0; C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-09-01] (Adobe Systems Incorporated)
R2 AVP15.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe [233552 2014-04-20] (Kaspersky Lab ZAO)
R2 DBService; C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe [187456 2009-01-08] (DATA BECKER GmbH & Co KG) [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2014-03-04] (Macrovision Europe Ltd.) [File not signed]
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [351824 2014-01-15] ()
S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [682064 2014-04-26] ()
R2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-03-16] () [File not signed]
R2 L4301_Solar; C:\Program Files\Logitech\SolarApp\L4301_Solar.exe [405744 2013-01-30] (Logitech, Inc.)
R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe [2751792 2015-06-30] (Lavasoft Limited)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239184 2014-02-15] ()
S2 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [13312 2015-06-30] () [File not signed]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) [File not signed]
S3 BrSerIf; C:\Windows\System32\DRIVERS\BrSerIf.sys [97280 2006-09-03] (Brother Industries Ltd.)
S3 HSPADataCardusbmdm; C:\Windows\System32\DRIVERS\HSPADataCardusbmdm.sys [122752 2010-02-11] (HSPADataCard Incorporated)
S3 HSPADataCardusbnmea; C:\Windows\System32\DRIVERS\HSPADataCardusbnmea.sys [122752 2010-02-11] (HSPADataCard Incorporated)
S3 HSPADataCardusbser; C:\Windows\System32\DRIVERS\HSPADataCardusbser.sys [122752 2010-02-11] (HSPADataCard Incorporated)
S3 hwusb_cdcacm; C:\Windows\System32\DRIVERS\ew_cdcacm.sys [124800 2014-05-16] (Huawei Technologies Co., Ltd.)
S3 hwusb_wwanecm; C:\Windows\System32\DRIVERS\ew_wwanecm.sys [379392 2014-05-04] (Huawei Technologies Co., Ltd.)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [457824 2014-02-20] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [141320 2014-10-09] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [243808 2014-04-10] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [793800 2014-10-09] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [30304 2014-02-25] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [28768 2014-03-28] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-08-08] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2014-03-25] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [179296 2014-03-26] (Kaspersky Lab ZAO)
R1 tcpipBM; C:\Windows\System32\Drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.)
R0 WinI2C-DDC; C:\Windows\System32\drivers\DDCDrv.sys [20832 2008-04-08] (Nicomsoft Ltd.)
R0 WinI2C-DDC; C:\Windows\SysWOW64\drivers\DDCDrv.sys [15712 2010-03-23] (Nicomsoft Ltd.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-22 09:53 - 2015-07-22 09:53 - 00033078 _____ C:\Users\Doreen\Desktop\FRST.txt
2015-07-22 09:52 - 2015-07-22 09:51 - 02135552 _____ (Farbar) C:\Users\Doreen\Desktop\FRST64(1).exe
2015-07-22 09:12 - 2015-07-22 09:13 - 00000000 ____D C:\Users\Doreen\AppData\Local\{4E82FA95-4F58-4ADA-84FF-AD44BDE86FB9}
2015-07-21 23:09 - 2015-07-21 23:09 - 00000000 ____D C:\Users\Doreen\AppData\Local\{378DBF44-CBED-43C4-9ED4-410243D3125F}
2015-07-21 11:03 - 2015-07-21 11:04 - 00000000 ____D C:\Users\Doreen\AppData\Local\{2CAD7418-5B9A-48E3-B6C2-650F43BDE9A4}
2015-07-20 23:02 - 2015-07-20 23:02 - 00000000 ____D C:\Users\Doreen\AppData\Local\{33496C1A-D665-420A-AB17-486AB00A4CB2}
2015-07-20 11:01 - 2015-07-20 11:01 - 00000000 ____D C:\Users\Doreen\AppData\Local\{A5BC0510-748C-4E59-9504-AB2CE3048AE0}
2015-07-19 22:59 - 2015-07-19 23:00 - 00000000 ____D C:\Users\Doreen\AppData\Local\{A1E87707-78F7-4251-939E-A126C255C0CD}
2015-07-19 10:57 - 2015-07-19 10:58 - 00000000 ____D C:\Users\Doreen\AppData\Local\{3F551B8E-B416-4CDC-B22C-B786A9BEA570}
2015-07-18 22:56 - 2015-07-18 22:56 - 00000000 ____D C:\Users\Doreen\AppData\Local\{8804FF2E-0F2B-4774-B973-C28AE9004748}
2015-07-18 10:54 - 2015-07-18 10:55 - 00000000 ____D C:\Users\Doreen\AppData\Local\{95BD4133-6F2B-477A-9CE5-E1E677D70CA1}
2015-07-17 22:53 - 2015-07-17 22:54 - 00000000 ____D C:\Users\Doreen\AppData\Local\{D7BB09EC-B851-45CC-AC11-7ED995D6CE0E}
2015-07-17 10:52 - 2015-07-17 10:52 - 00000000 ____D C:\Users\Doreen\AppData\Local\{0CE7F40E-5D2B-4F6E-ABE0-2C7BA4069805}
2015-07-16 22:50 - 2015-07-16 22:51 - 00000000 ____D C:\Users\Doreen\AppData\Local\{32EE40AD-B0A0-4FC4-8F9C-A39B5C6C0DFC}
2015-07-16 10:48 - 2015-07-16 10:49 - 00000000 ____D C:\Users\Doreen\AppData\Local\{952384AE-CA56-4F72-8604-F439A50DEE85}
2015-07-15 22:47 - 2015-07-15 22:48 - 00000000 ____D C:\Users\Doreen\AppData\Local\{5FE5516A-6B98-4576-8EB8-8B48C55467ED}
2015-07-15 10:45 - 2015-07-15 10:46 - 00000000 ____D C:\Users\Doreen\AppData\Local\{4297042B-8EA0-4411-967C-5243C69F20E2}
2015-07-14 22:44 - 2015-07-14 22:45 - 00000000 ____D C:\Users\Doreen\AppData\Local\{3247C7E4-317E-4098-ADBE-6CEC3A9BC39C}
2015-07-14 10:42 - 2015-07-14 10:43 - 00000000 ____D C:\Users\Doreen\AppData\Local\{28208421-6141-4867-A265-FA469157CF5C}
2015-07-13 22:41 - 2015-07-13 22:42 - 00000000 ____D C:\Users\Doreen\AppData\Local\{BB95EE9B-1CA9-4510-84ED-EDEA5454C18C}
2015-07-13 10:40 - 2015-07-13 10:40 - 00000000 ____D C:\Users\Doreen\AppData\Local\{00E5E8EF-B5A9-403D-A36F-4C369862D4A7}
2015-07-12 22:39 - 2015-07-12 22:39 - 00000000 ____D C:\Users\Doreen\AppData\Local\{0A527F56-6DCD-4462-9773-33363C8FCF1C}
2015-07-12 10:37 - 2015-07-12 10:38 - 00000000 ____D C:\Users\Doreen\AppData\Local\{4A442A10-4FE7-4AA4-88D4-796AFF0F4E62}
2015-07-11 22:36 - 2015-07-11 22:37 - 00000000 ____D C:\Users\Doreen\AppData\Local\{BCFEBBA1-D536-4391-8617-0C35775CB57C}
2015-07-11 10:34 - 2015-07-11 10:35 - 00000000 ____D C:\Users\Doreen\AppData\Local\{429AFFC1-C89E-4452-A8B1-46BB5F62AA72}
2015-07-10 22:33 - 2015-07-10 22:34 - 00000000 ____D C:\Users\Doreen\AppData\Local\{390B3B3F-D8C2-4E8F-87B2-4595E8C337E5}
2015-07-10 10:32 - 2015-07-10 10:32 - 00000000 ____D C:\Users\Doreen\AppData\Local\{BD617B8F-7C37-4876-B476-C4B750EC43C9}
2015-07-09 19:38 - 2015-07-09 19:39 - 00000000 ____D C:\Users\Doreen\AppData\Local\{4A439040-7203-4741-A936-BEF9A67F8F97}
2015-07-09 15:56 - 2015-07-21 16:56 - 18524336 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe
2015-07-09 07:37 - 2015-07-09 07:37 - 00000000 ____D C:\Users\Doreen\AppData\Local\{251F0CF5-F5B7-47A1-91A8-9CA6CECFD74C}
2015-07-08 19:35 - 2015-07-08 19:36 - 00000000 ____D C:\Users\Doreen\AppData\Local\{1E3AA9F2-C391-4170-89F9-5D9E67B47068}
2015-07-08 07:33 - 2015-07-08 07:34 - 00000000 ____D C:\Users\Doreen\AppData\Local\{914BB9A3-413A-4B9B-99EB-C358A2667174}
2015-07-07 19:32 - 2015-07-07 19:33 - 00000000 ____D C:\Users\Doreen\AppData\Local\{F2B213CB-830E-4722-BE60-E0F9B17B40E4}
2015-07-07 07:30 - 2015-07-07 07:31 - 00000000 ____D C:\Users\Doreen\AppData\Local\{AD151779-A8E5-471F-87B2-F0E93A266516}
2015-07-06 19:29 - 2015-07-06 19:29 - 00000000 ____D C:\Users\Doreen\AppData\Local\{6FE3B495-7C61-4C79-B0CE-7A008D845875}
2015-07-06 07:27 - 2015-07-06 07:28 - 00000000 ____D C:\Users\Doreen\AppData\Local\{8F7399E1-D547-4358-83C6-BBB56F90A7C5}
2015-07-05 19:25 - 2015-07-05 19:26 - 00000000 ____D C:\Users\Doreen\AppData\Local\{A5B799F8-A5D8-4BBB-9680-E306D4F31F77}
2015-07-05 07:24 - 2015-07-05 07:24 - 00000000 ____D C:\Users\Doreen\AppData\Local\{2DF3C7D5-99DB-4042-B754-7612F44E9F02}
2015-07-04 19:22 - 2015-07-04 19:23 - 00000000 ____D C:\Users\Doreen\AppData\Local\{62107C26-86DB-4DF5-BBC1-5384F8D24A12}
2015-07-04 07:20 - 2015-07-04 07:21 - 00000000 ____D C:\Users\Doreen\AppData\Local\{54C37214-B87E-46CE-A420-3B87F164B3B8}
2015-07-03 20:09 - 2015-07-10 09:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-03 19:19 - 2015-07-03 19:19 - 00000000 ____D C:\Users\Doreen\AppData\Local\{5DFA9D4B-427C-4783-961D-B55E2F0CBDCF}
2015-07-03 07:17 - 2015-07-03 07:18 - 00000000 ____D C:\Users\Doreen\AppData\Local\{571211B6-4FC1-4921-8ACF-574DA8129A66}
2015-07-02 19:15 - 2015-07-02 19:16 - 00000000 ____D C:\Users\Doreen\AppData\Local\{FB480F01-C50F-4549-89EB-2C65B3BF7C14}
2015-07-02 07:14 - 2015-07-02 07:14 - 00000000 ____D C:\Users\Doreen\AppData\Local\{698C6748-D14F-4F28-BFF9-E3272B3D9A6C}
2015-07-01 19:12 - 2015-07-01 19:13 - 00000000 ____D C:\Users\Doreen\AppData\Local\{1677F023-9775-442A-8F63-F1DCF752C0AF}
2015-07-01 07:10 - 2015-07-01 07:11 - 00000000 ____D C:\Users\Doreen\AppData\Local\{8EEF50AC-075F-4B3B-B4D3-A0738C82DB81}
2015-07-01 07:09 - 2015-07-01 07:09 - 01125056 _____ (Adobe Systems Incorporated) C:\Users\Doreen\Downloads\flashplayer18au_ha_install.exe
2015-06-30 15:25 - 2015-06-30 15:25 - 00000000 __SHD C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2015-06-30 15:24 - 2015-07-21 14:51 - 00000000 ____D C:\Users\Doreen\AppData\Local\Lavasoft
2015-06-30 15:24 - 2015-07-21 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2015-06-30 15:24 - 2015-07-01 07:06 - 00002896 _____ C:\windows\SysWOW64\LavasoftTcpServiceOff.ini
2015-06-30 15:24 - 2015-07-01 07:06 - 00002896 _____ C:\windows\system32\LavasoftTcpServiceOff.ini
2015-06-30 15:24 - 2015-06-30 15:23 - 00422400 _____ (Lavasoft Limited) C:\windows\system32\LavasoftTcpService64.dll
2015-06-30 15:23 - 2015-07-21 14:51 - 00000000 ____D C:\ProgramData\Lavasoft
2015-06-30 15:23 - 2015-07-21 14:51 - 00000000 ____D C:\Program Files (x86)\Lavasoft
2015-06-30 15:23 - 2015-06-30 15:23 - 00342016 _____ (Lavasoft Limited) C:\windows\SysWOW64\LavasoftTcpService.dll
2015-06-30 15:23 - 2015-06-30 15:23 - 00001492 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2015-06-30 15:23 - 2015-06-30 15:23 - 00001201 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2015-06-30 15:23 - 2015-06-30 15:23 - 00001038 _____ C:\Users\Public\Desktop\Best Safe Browser.lnk
2015-06-30 15:23 - 2015-06-30 15:23 - 00000000 ____D C:\Users\Doreen\AppData\Roaming\RPEng
2015-06-30 15:23 - 2015-06-30 15:23 - 00000000 ____D C:\Program Files (x86)\FreeCodecPack
2015-06-30 15:23 - 2015-06-30 15:23 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2015-06-30 15:21 - 2015-06-30 15:21 - 36468360 _____ (DVDVideoSoft Ltd. ) C:\Users\Doreen\Downloads\FreeYouTubeToMP3Converter(3).exe
2015-06-30 13:36 - 2015-06-30 13:37 - 00000000 ____D C:\Users\Doreen\AppData\Local\{01C46CE3-1579-47EA-BD91-BECB5291C203}
2015-06-30 01:34 - 2015-06-30 01:35 - 00000000 ____D C:\Users\Doreen\AppData\Local\{6D41230B-C25A-4183-B5A5-77BBF1B4B0B3}
2015-06-29 13:33 - 2015-06-29 13:33 - 00000000 ____D C:\Users\Doreen\AppData\Local\{46A37C1C-2633-49E4-ABAE-C76C35F331B4}
2015-06-29 01:31 - 2015-06-29 01:32 - 00000000 ____D C:\Users\Doreen\AppData\Local\{5D00DFEB-44F8-40A1-8522-0DD2A36017BC}
2015-06-28 13:29 - 2015-06-28 13:30 - 00000000 ____D C:\Users\Doreen\AppData\Local\{9063EE03-99B8-440F-BC4D-8D32388F4F0A}
2015-06-28 01:28 - 2015-06-28 01:29 - 00000000 ____D C:\Users\Doreen\AppData\Local\{01F9B304-4024-470C-8F9F-BF0F34E84ED5}
2015-06-27 13:26 - 2015-06-27 13:27 - 00000000 ____D C:\Users\Doreen\AppData\Local\{69BCA4E4-F45F-4756-A399-851395D17EB7}
2015-06-27 01:25 - 2015-06-27 01:25 - 00000000 ____D C:\Users\Doreen\AppData\Local\{CD267171-BE9B-47BE-A955-6FD8D1136956}
2015-06-26 13:24 - 2015-06-26 13:24 - 00000000 ____D C:\Users\Doreen\AppData\Local\{D67ACA00-F72F-4DEC-AF6B-94070A463AB4}
2015-06-26 01:22 - 2015-06-26 01:23 - 00000000 ____D C:\Users\Doreen\AppData\Local\{B57177E0-DA27-4822-9787-2E5FA1F9382F}
2015-06-25 13:20 - 2015-06-25 13:21 - 00000000 ____D C:\Users\Doreen\AppData\Local\{5A5586A2-3BBC-4BAE-A266-22A363A3C6BE}
2015-06-25 01:18 - 2015-06-25 01:20 - 00000000 ____D C:\Users\Doreen\AppData\Local\{04AF065A-CFE5-428F-A445-41562A76B1D5}
2015-06-24 13:17 - 2015-06-24 13:17 - 00000000 ____D C:\Users\Doreen\AppData\Local\{83B96B94-6045-4BAF-A660-349853AC9812}
2015-06-24 01:16 - 2015-06-24 01:16 - 00000000 ____D C:\Users\Doreen\AppData\Local\{32174EFD-69B9-4643-886E-243838B31D11}
2015-06-23 13:14 - 2015-06-23 13:14 - 00000000 ____D C:\Users\Doreen\AppData\Local\{466592AD-5EAF-438A-867E-1D8F44F6A624}
2015-06-23 01:12 - 2015-06-23 01:13 - 00000000 ____D C:\Users\Doreen\AppData\Local\{6BD099B2-6528-43CD-81EF-4D14245A5997}
2015-06-22 13:11 - 2015-06-22 13:12 - 00000000 ____D C:\Users\Doreen\AppData\Local\{D70FBCD8-E3E7-4C2B-AABA-747A90D367FF}
2015-06-22 01:09 - 2015-06-22 01:10 - 00000000 ____D C:\Users\Doreen\AppData\Local\{75883031-CB0A-4125-8969-0D78BE342380}
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-22 09:53 - 2013-08-09 18:28 - 00000000 ____D C:\FRST
2015-07-22 09:39 - 2012-09-13 13:59 - 00000000 ____D C:\Users\Doreen\D Privat
2015-07-22 09:37 - 2013-03-16 21:28 - 00000000 ____D C:\Users\Doreen\lesezeichen
2015-07-22 09:37 - 2012-03-30 16:35 - 00000000 ____D C:\Users\Doreen
2015-07-22 09:36 - 2011-11-12 03:59 - 00699432 _____ C:\windows\system32\perfh007.dat
2015-07-22 09:36 - 2011-11-12 03:59 - 00149572 _____ C:\windows\system32\perfc007.dat
2015-07-22 09:36 - 2009-07-14 07:13 - 01620684 _____ C:\windows\system32\PerfStringBackup.INI
2015-07-22 09:33 - 2009-07-14 06:45 - 00020688 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-22 09:33 - 2009-07-14 06:45 - 00020688 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-22 09:32 - 2011-11-12 04:15 - 01058337 _____ C:\windows\WindowsUpdate.log
2015-07-22 09:30 - 2013-02-28 13:25 - 00000000 ____D C:\Users\Doreen\vomdyck
2015-07-22 09:29 - 2011-11-12 04:41 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-22 09:24 - 2012-10-01 17:36 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-07-22 09:23 - 2011-11-12 04:42 - 00165632 _____ C:\windows\system32\fastboot.set
2015-07-22 09:23 - 2011-11-12 04:41 - 00001106 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-22 09:22 - 2012-03-30 17:36 - 00000000 _____ C:\windows\system32\Drivers\lvuvc.hs
2015-07-22 09:22 - 2010-11-21 05:47 - 00178626 _____ C:\windows\PFRO.log
2015-07-22 09:22 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-07-22 09:22 - 2009-07-14 06:51 - 00213808 _____ C:\windows\setupact.log
2015-07-22 09:16 - 2013-08-20 12:07 - 00001124 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2478697962-178253433-2156096982-1001UA.job
2015-07-22 08:56 - 2012-03-30 20:13 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-07-21 16:56 - 2012-03-30 20:13 - 00778416 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-07-21 16:56 - 2012-03-30 20:13 - 00142512 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-21 16:56 - 2012-03-30 20:13 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-07-21 15:24 - 2011-11-12 04:41 - 00004106 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-21 15:24 - 2011-11-12 04:41 - 00003854 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-21 15:19 - 2013-08-24 14:58 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-07-21 15:18 - 2014-12-27 11:07 - 00003886 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2015-07-21 15:16 - 2013-08-20 12:07 - 00001072 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2478697962-178253433-2156096982-1001Core.job
2015-07-21 15:11 - 2013-08-20 12:07 - 00004096 _____ C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2478697962-178253433-2156096982-1001UA
2015-07-21 15:11 - 2013-08-20 12:07 - 00003700 _____ C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2478697962-178253433-2156096982-1001Core
2015-07-21 14:51 - 2015-04-16 03:30 - 00000000 ____D C:\windows\system32\appraiser
2015-07-21 14:51 - 2015-04-05 03:00 - 00000000 ___SD C:\windows\SysWOW64\GWX
2015-07-21 14:51 - 2015-04-05 03:00 - 00000000 ___SD C:\windows\system32\GWX
2015-07-21 14:51 - 2014-05-08 16:52 - 00000000 ___SD C:\windows\system32\CompatTel
2015-07-21 14:51 - 2014-03-04 16:31 - 00000000 ____D C:\ProgramData\FLEXnet
2015-07-21 14:51 - 2012-04-16 10:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-07-21 14:51 - 2012-04-16 10:20 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2015-07-21 14:51 - 2012-03-30 20:13 - 00000000 ____D C:\windows\system32\Macromed
2015-07-21 14:51 - 2011-11-12 04:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-07-21 14:51 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\NDF
2015-07-21 14:51 - 2009-07-14 05:20 - 00000000 ____D C:\windows\rescache
2015-07-21 14:51 - 2009-07-14 05:20 - 00000000 ____D C:\windows\PolicyDefinitions
2015-07-21 14:51 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-07-21 14:50 - 2009-07-14 05:20 - 00000000 ____D C:\windows\registration
2015-07-21 14:48 - 2014-11-23 14:15 - 00000000 ____D C:\ProgramData\Internet Manager
2015-07-21 14:48 - 2014-11-23 14:14 - 00000000 ____D C:\Program Files (x86)\T-Mobile
2015-07-21 14:39 - 2013-10-21 12:38 - 00000000 ____D C:\Users\Doreen\AppData\Local\CrashDumps
2015-07-20 18:57 - 2012-04-16 10:20 - 00000000 ____D C:\Users\Doreen\AppData\Roaming\FileZilla
2015-07-16 08:54 - 2014-01-11 13:41 - 00000000 ____D C:\ProgramData\firebird
2015-07-16 03:09 - 2013-08-08 15:41 - 00000000 ____D C:\windows\system32\MRT
2015-07-13 10:28 - 2013-08-05 23:02 - 00147456 ___SH C:\Users\Doreen\Thumbs.db
2015-07-10 09:48 - 2012-09-20 10:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-06 08:46 - 2014-01-07 01:22 - 00000000 ____D C:\Users\Doreen\Documents\Haus
2015-07-01 07:06 - 2009-07-14 07:09 - 00000000 ____D C:\windows\System32\Tasks\WPD
2015-06-30 15:26 - 2013-08-09 00:04 - 00000000 ____D C:\ProgramData\TuneUp Software
2015-06-30 15:23 - 2012-03-30 22:35 - 00000000 ____D C:\Users\Doreen\AppData\Roaming\DVDVideoSoft
2015-06-30 15:23 - 2012-03-30 22:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2015-06-29 11:00 - 2012-04-16 10:20 - 00001960 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2015-06-23 13:30 - 2010-11-21 05:27 - 00300704 _____ (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
==================== Files in the root of some directories =======
2012-10-09 17:43 - 2012-10-09 17:43 - 0000288 _____ () C:\Users\Doreen\AppData\Roaming\.backup.dm
2014-03-29 16:23 - 2014-04-01 00:23 - 0000084 _____ () C:\Users\Doreen\AppData\Roaming\WB.CFG
2014-03-13 19:18 - 2014-03-13 19:18 - 0000017 _____ () C:\Users\Doreen\AppData\Local\resmon.resmoncfg
2012-03-30 17:09 - 2012-03-30 17:09 - 0017408 _____ () C:\Users\Doreen\AppData\Local\WebpageIcons.db
2013-02-06 14:40 - 2013-02-06 14:40 - 0000057 _____ () C:\ProgramData\Ament.ini
2011-11-12 04:41 - 2011-11-12 04:41 - 1914000 _____ (Adobe Systems Incorporated) C:\ProgramData\flashax10.exe
Files to move or delete:
====================
C:\ProgramData\flashax10.exe
Some files in TEMP:
====================
C:\Users\Doreen\AppData\Local\Temp\4ip2huge.dll
C:\Users\Doreen\AppData\Local\Temp\autorun.dll
C:\Users\Doreen\AppData\Local\Temp\b1sbmkdf.dll
C:\Users\Doreen\AppData\Local\Temp\eTypeSetup.exe
C:\Users\Doreen\AppData\Local\Temp\FP_PL_PFS_INSTALLER_32bit-1.exe
C:\Users\Doreen\AppData\Local\Temp\FP_PL_PFS_INSTALLER_32bit.exe
C:\Users\Doreen\AppData\Local\Temp\fz306.exe
C:\Users\Doreen\AppData\Local\Temp\incredibar_installer.exe
C:\Users\Doreen\AppData\Local\Temp\installhelper.dll
C:\Users\Doreen\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Doreen\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\Doreen\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Doreen\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\Doreen\AppData\Local\Temp\jre-8u40-windows-au.exe
C:\Users\Doreen\AppData\Local\Temp\jre_setup.exe
C:\Users\Doreen\AppData\Local\Temp\LMkRstPt.exe
C:\Users\Doreen\AppData\Local\Temp\minibar-master-v1.exe
C:\Users\Doreen\AppData\Local\Temp\o9mn76qu.dll
C:\Users\Doreen\AppData\Local\Temp\Package_de_ww.exe
C:\Users\Doreen\AppData\Local\Temp\pdf24-creator-update.exe
C:\Users\Doreen\AppData\Local\Temp\qc_e3f0f3ef_27e6_4ca8_8a7c_a3d761aa54bb_64.exe
C:\Users\Doreen\AppData\Local\Temp\Quarantine.exe
C:\Users\Doreen\AppData\Local\Temp\readSTILog.dll
C:\Users\Doreen\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Doreen\AppData\Local\Temp\sfextra.dll
C:\Users\Doreen\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Doreen\AppData\Local\Temp\sqlite3.dll
C:\Users\Doreen\AppData\Local\Temp\SRAssetsHelper.dll
C:\Users\Doreen\AppData\Local\Temp\tbFree.dll
C:\Users\Doreen\AppData\Local\Temp\uninst1.exe
C:\Users\Doreen\AppData\Local\Temp\UpdateCheckerSetup.exe
C:\Users\Doreen\AppData\Local\Temp\wusetup.exE
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-07-13 00:16
==================== End of log ============================ --- --- ---
Additional
FRST Logfile: Code:
scan result of Farbar Recovery Scan Tool (x64) Version:20-07-2015
Ran by Doreen at 2015-07-22 09:54:25
Running from C:\Users\Doreen\Desktop
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2478697962-178253433-2156096982-500 - Administrator - Disabled)
Doreen (S-1-5-21-2478697962-178253433-2156096982-1001 - Administrator - Enabled) => C:\Users\Doreen
Gast (S-1-5-21-2478697962-178253433-2156096982-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2478697962-178253433-2156096982-1003 - Limited - Enabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - )
Adobe Acrobat 9 Pro Extended - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}) (Version: 9.5.5 - Adobe Systems)
Adobe Acrobat 9 Pro Extended 64-bit Add-On (HKLM\...\{AC76BA86-1033-0000-0064-0003D0000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Adobe Acrobat 9.5.5 - CPSID_83708 (HKLM-x32\...\{AC76BA86-1033-F400-7761-000000000004}_955) (Version: - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.6.0.19140 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.)
Adobe Flash Player 18 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Photoshop Elements 10 (HKLM-x32\...\Adobe Photoshop Elements 10) (Version: 10.0 - Adobe Systems Incorporated)
Adobe Premiere Elements 10 (HKLM\...\PremElem100) (Version: 10.0 - Adobe Systems Incorporated)
Adobe Premiere Elements 10 (Version: 10.0 - Adobe Systems Incorporated) Hidden
Adobe Reader XI (11.0.12) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
Any Video Converter 5 5.0.3 (HKLM-x32\...\Any Video Converter 5_is1) (Version: - Any-Video-Converter.com)
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Artisteer 4 (HKLM-x32\...\Artisteer 4) (Version: 4.0 - Extensoft)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CameraHelperMsi (x32 Version: 13.50.854.0 - Logitech) Hidden
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.1.3184 - CDBurnerXP)
Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.31 - Cliqz.com)
ColorPic (HKLM-x32\...\ColorPic) (Version: 4.1 - Iconico)
ColorPicker Gadget (HKLM-x32\...\{25742C0C-7655-4CF2-9D89-B0A3E5D08505}) (Version: 1.1.2 - Andreas Zimmermann)
congstar Internet-Manager (HKLM-x32\...\{27D28586-BEF1-4E06-8787-3B1FC3A41489}) (Version: 1.0.0.4 - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DATA BECKER Visitenkarten-Druckerei 12 (HKLM-x32\...\Visitenkarten-Druckerei 12_is1) (Version: 12.10.3.17 - DATA BECKER GmbH & Co. KG)
Dreamland-Photos Color Picker (HKLM-x32\...\{35583569-8128-4C90-9C2F-810314A6868A}) (Version: 2.0.3 - Dreamland-Photos)
Elements 10 Organizer (x32 Version: 10.0 - Ihr Firmenname) Hidden
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Eumex 800 V1.30 (HKLM-x32\...\InstallShield_{FACE9D51-E374-4DDB-857C-816FCB1D6B40}) (Version: 1.30.0000 - T-Home)
Eumex 800 V1.30 (x32 Version: 1.30.0000 - T-Home) Hidden
Eumex RNDIS64 Treiber V1.02 (HKLM\...\{293C4FDD-FB80-48F8-8B40-F085392FDAA1}) (Version: 1.02.0000 - Deutsche Telekom)
FileZilla Client 3.11.0.2 (HKLM-x32\...\FileZilla Client) (Version: 3.11.0.2 - Tim Kosse)
Free YouTube to MP3 Converter version 3.12.59.616 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.59.616 - DVDVideoSoft Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.89 - Google Inc.)
Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Talk Plugin (HKLM-x32\...\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6710.2136 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Officejet Pro 8600 - Grundlegende Software für das Gerät (HKLM\...\{D2D05FDB-4EDA-462D-8DB6-E0B9AD4FA25F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Officejet Pro 8600 Hilfe (HKLM-x32\...\{FDE820DD-CC88-4395-AD5C-801365B8F316}) (Version: 28.0.0 - Hewlett Packard)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
HPDiagnosticCoreDll (HKLM-x32\...\{9262B08F-E183-4FED-A2BD-23FF1A84EB79}) (Version: 1.0.15.0 - Hewlett Packard)
Hundescout (HKLM-x32\...\Breeder Software) (Version: 2.7.1 - Scoutsystems Software)
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 15.4 - Intel)
Internet Manager (HKLM-x32\...\Internet Manager) (Version: 22.001.19.04.55 - Huawei Technologies Co.,Ltd)
IP Camera (HKLM-x32\...\IP Camera) (Version: - )
IPCamClient (HKLM-x32\...\{B1534528-3E4B-4630-A06D-8115917A2B92}) (Version: 1.0.0.10 - )
IPCamera Finder (HKLM-x32\...\{75D2DA2F-790F-40E9-A4FB-AC151D3FF50F}) (Version: 1.0.0.1 - )
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 8 Update 40 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{653C1B5A-3287-47B1-8613-0745D4E771C4}) (Version: 15.0.0.463 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 15.0.0.463 - Kaspersky Lab) Hidden
Lenovo Dynamic Brightness System (HKLM-x32\...\{D9ED6D06-6002-495E-A7BC-46E6AE386996}) (Version: 4.0.00.22080 - Lenovo)
Lenovo EE Boot Optimizer (HKLM\...\Lenovo EE Boot Optimizer) (Version: 0.0.1.6 - Lenovo)
Lenovo Eye Distance System (HKLM-x32\...\{5183D7AB-D09B-411F-A74E-BBAEA61C6505}) (Version: 4.0.00.21090 - Lenovo)
Lenovo Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.4827a - CyberLink Corp.)
Lenovo Power2Go (x32 Version: 6.0.4827a - CyberLink Corp.) Hidden
Lenovo Rescue System (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 3.0.1409 - CyberLink Corp.)
Lenovo Rescue System (Version: 3.0.1409 - CyberLink Corp.) Hidden
Lenovo Tinian Fn PS/2 Keyboard Driver (HKLM-x32\...\{B266E062-D6C5-485B-B426-51B152B041A6}) (Version: V1.0.11.0321 - Lenovo)
Lenovo Treiber- und Anwendungsinstallation (HKLM-x32\...\{45970CD1-D599-47D4-938F-3E9800D54ED1}) (Version: 5.10.1809 - Lenovo)
Logitech SetPoint 6.51 (HKLM\...\sp6) (Version: 6.51.8 - Logitech)
Logitech Solar App 1.10 (HKLM\...\SolarApp) (Version: 1.10.3 - Logitech)
Logitech Unifying-Software 2.10 (HKLM\...\Logitech Unifying) (Version: 2.10.37 - Logitech)
Logitech Vid HD (HKLM-x32\...\Logitech Vid) (Version: 7.2 (7259) - Logitech Inc..)
Logitech Webcam-Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.40 - Logitech Inc.)
LVT (HKLM-x32\...\{D3063097-EC84-4D21-84A4-9D852E974355}) (Version: 4.1.2.0919 - Lenovo)
LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden
Macromedia Dreamweaver 8 (HKLM-x32\...\{44025BD7-AD10-4769-99AE-6378FD0303D6}) (Version: 8.0.0.2751 - Macromedia)
Macromedia Extension Manager (HKLM-x32\...\{0F022A2E-7022-497D-90A5-0F46746D8275}) (Version: 1.7.270 - Ihr Firmenname)
Mein Verein (HKLM-x32\...\{9ACE3A18-EE13-4012-989C-2BCDC95BA6B9}_is1) (Version: 12.0 - Buhl Data Service GmbH)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft IntelliType Pro 8.2 (HKLM\...\Microsoft IntelliType Pro 8.2) (Version: 8.20.469.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.25.00.03 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.1.1 - Mozilla)
Mozilla Thunderbird 31.1.1 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.1.1 (x86 de)) (Version: 31.1.1 - Mozilla)
Muziic Player & Encoder (HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\Muziic Player & Encoder) (Version: - )
MyFreeCodec (HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\MyFreeCodec) (Version: - )
Opera 12.16 (HKLM-x32\...\Opera 12.16.1860) (Version: 12.16.1860 - Opera Software ASA)
PDF24 Creator 6.9.2 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
Personal ID (HKLM-x32\...\{F722209B-739E-40E4-ADB1-062BD032A0DB}) (Version: 1.8.5.202 - coolspot AG)
PokerStars (HKLM-x32\...\PokerStars) (Version: - PokerStars)
PokerStars.net (HKLM-x32\...\PokerStars.net) (Version: - PokerStars.net)
PRE10STI64Installer (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
Protect Disc License Helper 1.0.118 (HKLM-x32\...\Protect Disc License Helper) (Version: 1.0.118 - Protect Disc)
ProtectDisc Driver, Version 11 (HKLM-x32\...\ProtectDisc Driver 11) (Version: 11.0.0.13 - ProtectDisc Software GmbH)
PSE10 STI Installer (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6230 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30123 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.26.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.26.0 - Renesas Electronics Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
SAMSUNG Android USB Modem Software (HKLM\...\SAMSUNG Android USB Modem) (Version: V5.28.2.1 - )
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15024.8 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.15024.8 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.)
SanDiskSecureAccess_Manager.exe (HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19269 - Gemalto N.V.)
Secret City (HKLM-x32\...\Secret City) (Version: 1.9.4662 - Utherverse Digital Inc)
Sinus 154 data II (x32 Version: 1.0.2.11 - T-Com) Hidden
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)
SmartSound Common Data (x32 Version: 1.1.0 - SmartSound Software Inc.) Hidden
SmartSound Premiere Elements 10 x64 Plugin (HKLM\...\{3DAE9A67-DD8D-4EDB-91F7-7B5132B1864D}) (Version: 5.70.0001 - SmartSound Software Inc.)
SmartSound Sonicfire Pro 5 (HKLM-x32\...\InstallShield_{1D273D91-D7D5-4036-8B84-EB4615FF5F81}) (Version: 5.7.1 - SmartSound Software Inc.)
SmartSound Sonicfire Pro 5 (x32 Version: 5.7.1 - SmartSound Software Inc.) Hidden
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Studie zur Verbesserung von HP Officejet Pro 8600 Produkten (HKLM\...\{B9824225-2055-4700-BCD4-64B25EC88264}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.12979 - TeamViewer)
TomTom HOME (HKLM-x32\...\{7A2BB1C8-903D-4585-9F3B-CADD67D07D37}) (Version: 2.9.8 - Ihr Firmenname)
TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
Ulead Photo Explorer 8.6 (HKLM-x32\...\{025C3792-E9C6-432A-92C1-661F99D021CA}) (Version: 8.6 - Ulead Systems, Inc.)
Ulead PhotoImpact 12 (HKLM-x32\...\{11AFE21E-B193-430D-B57A-DFF7815BB962}) (Version: 12.0 - Ulead System)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
VLC media player 2.0.4 (HKLM-x32\...\VLC media player) (Version: 2.0.4 - VideoLAN)
Web Companion (HKLM-x32\...\{f3a57455-0e92-41d4-beb0-b49037c8aed5}) (Version: 2.0.1025.2130 - Lavasoft)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows-Treiberpaket - T-Home Net (06/30/2010 6.0.6000.16384) (HKLM\...\7B73EBFEF26F2C40D3AA9D389F5CF2C77121106C) (Version: 06/30/2010 6.0.6000.16384 - T-Home)
WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2478697962-178253433-2156096982-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Doreen\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2478697962-178253433-2156096982-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Doreen\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2478697962-178253433-2156096982-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Doreen\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2478697962-178253433-2156096982-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Doreen\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2478697962-178253433-2156096982-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Doreen\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2478697962-178253433-2156096982-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Doreen\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2478697962-178253433-2156096982-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Doreen\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2478697962-178253433-2156096982-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Doreen\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2478697962-178253433-2156096982-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Doreen\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
==================== Restore Points =========================
21-07-2015 11:01:21 Windows Update
21-07-2015 12:20:53 Windows Update
21-07-2015 14:43:16 Wiederherstellungsvorgang
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2014-03-04 16:20 - 00001961 ____A C:\windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 adobeereg.com
127.0.0.1 hxxp://www.adobeereg.com
127.0.0.1 activate.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 192.150.18.108
127.0.0.1 activate.adobe.com:443
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobeereg.com
127.0.0.1 www.adobeereg.com
127.0.0.1 activate.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 192.150.18.108
127.0.0.1 adobeereg.com
127.0.0.1 www.adobeereg.com
127.0.0.1 activate.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 192.150.18.108
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
There are 7 more lines.
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {028FF670-B11B-41A4-94A7-410DD9B054EA} - System32\Tasks\{F4DC2EAB-3BE2-4D06-BF4A-65C39D1B9536} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {02D59E6F-4E43-4A5D-ACFB-AB71D74CFCB2} - System32\Tasks\{6D84DE02-094D-4EAE-B364-34DF0CC59C2E} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {05D10494-A0BA-4F49-A0A6-22D34107028A} - System32\Tasks\{BC76544C-702D-4759-9449-29D6EA7EDC10} => pcalua.exe -a D:\Windows_XP_64\client\instwcli.exe -d D:\Windows_XP_64\client
Task: {0B532F4E-A448-4E55-9A4B-B9E53FEF4F07} - System32\Tasks\{909C89BD-9D49-450F-9D91-B52D2CDEFAC5} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0F4C56A4-0995-4FD1-84B0-E91985261548} - System32\Tasks\{56087472-954C-4A11-94A1-E7957F401EF0} => Firefox.exe hxxp://ui.skype.com/ui/0/5.9.0.123/de/go/help.faq.installer?LastError=1603
Task: {11F545FF-1D0A-4922-B688-993439D3E66C} - System32\Tasks\{7F038BD4-6525-4E66-86B0-271AC82D4EFB} => Firefox.exe hxxp://ui.skype.com/ui/0/7.0.0.100/de/abandoninstall?source=lightinstaller&page=tsInstall
Task: {148B8802-0547-4F18-AD7B-2CAF944E2CDC} - System32\Tasks\{6E5B5806-1741-404B-84E0-7BD933B97DC6} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=5.10.0.116&LastError=404
Task: {18E3D70A-CC70-4DF2-86AC-A8FC13E8ECAA} - System32\Tasks\{449EBF9E-AFB8-4975-ADFF-989C1CBF061A} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1A413953-D93E-45D5-9314-E1A0C8E9D42F} - System32\Tasks\{E8C06396-9B23-4E7B-91A6-4E45FAE3522D} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {26670ED3-DA48-4D02-8256-F0A6A2E2A217} - System32\Tasks\{15D821F2-85B6-425D-9E25-1BFA28DD0563} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2B623DAE-727C-47B9-B409-95D5BDDC0824} - System32\Tasks\{FE823C39-4697-43A8-8C03-646E0B14613A} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2CAB9B2C-4B81-491B-A3DF-FED23DD106BF} - System32\Tasks\{65146164-9EB4-43A8-A37A-6600A91A5C50} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3171DCC1-E08A-4E35-9997-4BDBAFDAB945} - System32\Tasks\{504A4323-1321-489F-AD4C-00FC0AA7B311} => pcalua.exe -a "C:\Program Files (x86)\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe" -c /M{C53FB914-C1F6-4F9D-93E2-A3A84935EC15}
Task: {34423F63-B993-46E0-A592-FCF289592E58} - System32\Tasks\{2F2D5BBE-2221-47CB-9CF2-4C090D05B5BE} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {35028407-F273-4C41-9BA7-10FB1A19BCD5} - System32\Tasks\{917C8CA9-054E-4FD7-8C60-649E02851028} => Firefox.exe hxxp://ui.skype.com/ui/0/5.9.0.123/de/go/help.faq.installer?LastError=1603
Task: {467FD9E0-F22A-4F82-A63F-67258F4FB113} - System32\Tasks\{F27A4F3E-BD91-421E-9AA8-CB896ADFF2CB} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4C9E2EFA-C7C1-4480-92B3-133F779474A8} - System32\Tasks\{9DBE2208-24D0-4582-8C32-9EFEF8D1CD3E} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {506508F3-BAD8-4830-9724-B7CA1147C76A} - System32\Tasks\{2CCDBB75-E23B-43F5-BC38-E4886AB94845} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {55C4806F-8D12-4C35-AFDE-2BF41F406863} - System32\Tasks\{14DD6E76-BA98-4762-A6C5-62BDE089B541} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {571FCB47-4EBB-43A3-BA2D-67EF7BFC6465} - System32\Tasks\{50187403-BE47-4EEB-8CDC-083DEF2B3105} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {58AEDE92-F562-4439-AB98-20A1B3EA0F68} - System32\Tasks\{F4B2FAC0-A2D8-473B-B5B0-70C09BCF966D} => pcalua.exe -a D:\setup.exe -d D:\
Task: {5C7BD441-C219-4283-9DC4-9189BFD89C46} - System32\Tasks\{CECA4E16-87EC-4578-AAA6-866A8B670746} => pcalua.exe -a D:\Setup.exe -d D:\
Task: {5D191BCE-6930-4F55-B998-E6DA8EE11C7B} - System32\Tasks\{CADE48E2-9DAA-4C5A-9BFB-1C88AC54D140} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {78E2F79A-2468-4787-8E78-9C148E24A96F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2478697962-178253433-2156096982-1001UA => C:\Users\Doreen\AppData\Local\Google\Update\GoogleUpdate.exe [2013-07-12] (Google Inc.)
Task: {7CC1A72B-A6D8-4A22-BC48-D083358E9556} - System32\Tasks\{39CFB4F4-0F22-46C6-846A-EB64A54D9759} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {7D951310-B967-4567-95B2-707F84CBDD94} - System32\Tasks\AdobeAAMUpdater-1.0-Doreen-PC-Doreen => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-06-16] (Adobe Systems Incorporated)
Task: {8991AD69-BE4E-4B07-88DA-7429984DFCCD} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-21] (Adobe Systems Incorporated)
Task: {8CB318B0-A929-4A6C-A791-4DD56951757E} - System32\Tasks\{73A28CDE-BB5B-46C4-BFF0-6FDF95BEAF95} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8EB102CB-A4AA-4812-9B58-D917FC3CB7A0} - System32\Tasks\{FC9E664D-E362-49B3-9906-703DF4F12337} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {962C2452-7A93-47B4-BEB3-6324CA03CAB5} - System32\Tasks\{D8ED3E9E-76E4-447B-8B9F-AE45BA984DBE} => pcalua.exe -a D:\setup.exe -d D:\
Task: {96C960A4-CD33-4DEF-B8DA-E4C79DAB6BBD} - System32\Tasks\{2409C613-6CBB-45A3-848B-BD3C6598B6FF} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9DBDF1D5-E942-4F5D-BF51-070C87EDA1C3} - System32\Tasks\{4D738968-6A6C-4CFD-ADBF-385F22242B59} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A6D1FB88-8371-4802-9D16-FF7503FE8F71} - System32\Tasks\{D2E6FC15-D662-428F-B08B-DC1B3A7D8EDE} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {ABB2E8FD-49A1-445E-A737-BA42252B804E} - System32\Tasks\HPCustParticipation HP Officejet Pro 8600 => C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {B0A6780B-88B0-4A3B-BC3A-D4B906CB2B4C} - System32\Tasks\{4AF27388-3E7A-4BED-968D-CC8DF519E83E} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B125D9E6-1334-4E81-9F84-7A1AD5F857A4} - System32\Tasks\{803EE106-4C1D-4820-A331-7243579715D2} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B4A03C12-37A4-49C2-8AAE-99B2B4279579} - System32\Tasks\{C460F08B-5AFA-4FE7-B73A-8C5F0C2EA15F} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B7606D40-3A3E-4F8B-AF1A-196CC3524334} - System32\Tasks\{7B30F331-F01F-496A-BACD-644F9D069C17} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {BD55E8DE-42AA-4BC8-9007-EDB8A3D7A629} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {BE91F981-3A99-4FF5-97FC-B731E05F7DD5} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2478697962-178253433-2156096982-1001Core => C:\Users\Doreen\AppData\Local\Google\Update\GoogleUpdate.exe [2013-07-12] (Google Inc.)
Task: {BF55D808-45A4-462D-81A2-B02F8AA278EC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-15] (Google Inc.)
Task: {C994B2D1-21CF-4B13-889B-F0E720E61555} - System32\Tasks\{1CFA3876-4DAC-46B4-A699-874C8D4479B7} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CF88A20C-5D4A-449E-A40E-DC0F13EEB507} - System32\Tasks\ScanToPCActivationApp.exe_{E3F23E14-9270-495B-8D32-31129F2B2891} => C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {DE505D47-CF63-4A16-B8E1-1BAEBA933D66} - System32\Tasks\{C3E299D2-D7EF-400F-A9D7-DCD42F8B16EF} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=6.22.81.104&LastError=404
Task: {EE4E5C35-27C7-4E30-961C-26EE7C97830F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-15] (Google Inc.)
Task: {F04BE5A6-F043-49B9-B30F-28078103A378} - System32\Tasks\{862823A5-2617-46EC-ACCA-32E9784EF504} => pcalua.exe -a C:\Users\Doreen\Downloads\Muziic201Setup.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {FBBF3856-6665-4284-9E44-34B010B31BAE} - System32\Tasks\{0AD287F4-DAE0-4DFB-9789-7ADEADB38A13} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?source=lightinstaller&LastError=1603
Task: {FCC2C57F-3050-4B0A-9C96-948917E2CB8F} - System32\Tasks\{8975C8FA-7969-44BC-9071-3752C1569CB1} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2478697962-178253433-2156096982-1001Core.job => C:\Users\Doreen\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2478697962-178253433-2156096982-1001UA.job => C:\Users\Doreen\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2015-07-09 19:32 - 2015-06-02 17:18 - 00043480 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2014-01-15 05:42 - 2014-01-15 05:42 - 00351824 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe
2014-11-23 14:15 - 2014-04-26 08:15 - 00682064 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
2011-11-12 04:19 - 2011-03-16 06:47 - 00032768 _____ () C:\Windows\jmesoft\Service.exe
2014-10-03 20:15 - 2014-02-15 08:59 - 00239184 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2011-11-12 04:19 - 2011-03-22 00:12 - 00020480 _____ () C:\Windows\jmesoft\JME_LOAD.exe
2013-05-23 12:51 - 2010-05-13 10:42 - 00215552 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\dbus-daemon.exe
2013-05-23 12:51 - 2010-05-13 10:42 - 00043008 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\gconfd-2.exe
2013-05-23 12:51 - 2010-05-13 10:42 - 00031232 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\db_daemon.exe
2014-11-23 14:17 - 2014-04-23 04:43 - 01551440 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\LiveUpd.exe
2014-10-11 14:06 - 2014-10-11 14:06 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 14:05 - 2014-10-11 14:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-03-06 15:00 - 2014-03-06 15:00 - 01269952 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\kpcengine.2.3.dll
2012-02-15 01:05 - 2012-02-15 01:37 - 11796096 _____ () C:\Users\Doreen\AppData\Roaming\SanDisk\My Vaults\dmBackup.dll
2014-11-23 14:15 - 2013-08-16 08:53 - 00011362 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll
2014-11-23 14:15 - 2013-08-16 08:53 - 00043008 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll
2014-11-23 14:15 - 2014-02-15 09:31 - 02416640 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll
2014-11-23 14:15 - 2014-02-15 09:33 - 01148416 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll
2015-06-30 15:23 - 2015-06-30 15:23 - 00072192 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Utils.dll
2015-06-30 15:23 - 2015-06-30 15:23 - 00178176 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Business.dll
2015-06-30 15:23 - 2015-06-30 15:23 - 00040448 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.adblocker.dll
2015-06-30 15:23 - 2015-06-30 15:23 - 00067072 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SysInfo.dll
2015-06-30 15:23 - 2015-06-30 15:23 - 00026624 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Repositories.dll
2015-06-30 15:23 - 2015-06-30 15:23 - 00009216 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Utils.SqlLite.dll
2015-06-30 15:23 - 2015-06-30 15:23 - 00117248 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.PUP.Management.dll
2015-06-30 15:23 - 2015-06-30 15:23 - 00032768 _____ () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.CSharp.Utilities.dll
2011-11-12 04:19 - 2007-12-31 20:27 - 00007168 _____ () C:\Windows\jmesoft\VistaVolume.dll
2011-11-12 04:41 - 2010-09-20 20:08 - 00210432 _____ () C:\Program Files\Lenovo\Lenovo Brightness System\KeyStoneAdapter.dll
2011-11-12 04:41 - 2010-09-21 04:55 - 00182272 _____ () C:\Program Files\Lenovo\Lenovo Brightness System\DDCHelperWraper.dll
2011-11-12 04:19 - 2009-07-16 19:20 - 00032768 _____ () C:\Windows\jmesoft\Keyhook.dll
2009-12-05 02:59 - 2009-12-05 02:59 - 00619816 _____ () C:\Program Files (x86)\Lenovo\Power2Go\CLMediaLibrary.dll
2009-12-05 03:04 - 2009-12-05 03:04 - 00013096 _____ () C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvcPS.dll
2013-05-23 12:51 - 2010-05-13 10:41 - 00594432 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\dbus-1.dll
2013-05-23 12:51 - 2010-05-13 10:41 - 00157696 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\libgconf-2.dll
2013-05-23 12:51 - 2010-06-17 09:53 - 00089600 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\itapi.dll
2013-05-23 12:51 - 2008-05-06 13:50 - 00971776 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\libxml2.dll
2013-05-23 12:51 - 2009-03-28 09:19 - 00080688 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\zlib1.dll
2013-05-23 12:51 - 2010-06-17 09:53 - 00054272 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\coder.dll
2013-05-23 12:51 - 2010-06-17 09:53 - 00025088 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\log.dll
2013-05-23 12:51 - 2010-06-17 09:53 - 00043008 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\audio.dll
2013-05-23 12:51 - 2010-06-12 08:10 - 00034304 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\libctlsvr.dll
2012-04-05 15:14 - 2004-07-26 17:11 - 00028672 ____N () C:\Program Files (x86)\Common Files\Ulead Systems\AutoDetector\DetMethod.dll
2011-11-11 14:08 - 2011-11-11 14:08 - 02145304 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll
2011-11-11 14:08 - 2011-11-11 14:08 - 07956504 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll
2011-11-11 14:08 - 2011-11-11 14:08 - 00342552 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll
2011-11-11 14:08 - 2011-11-11 14:08 - 00029208 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll
2011-11-11 14:08 - 2011-11-11 14:08 - 00128536 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll
2014-03-19 20:37 - 2009-02-27 17:39 - 00019968 _____ () C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.deu
2013-05-23 12:51 - 2007-09-09 17:07 - 00151552 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\libexpat.dll
2013-05-23 12:51 - 2010-05-13 10:41 - 00055808 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\libgconfbackend-xml.dll
2013-05-23 12:51 - 2010-05-13 10:39 - 00341504 _____ () C:\Program Files (x86)\congstar\Internetmanager\Bin\sqlite3.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-2478697962-178253433-2156096982-1001\...\webcompanion.com -> hxxp://webcompanion.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2478697962-178253433-2156096982-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Doreen\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.250 - 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{7514660B-CAF8-48CF-8DFF-EEC3F0A2ACE7}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{E3B44397-CC34-43BB-8ACF-EB7026372198}] => (Allow) LPort=2869
FirewallRules: [{C743A41C-CE23-4E5A-9E9B-73DEE357862A}] => (Allow) LPort=1900
FirewallRules: [{CB36730A-A925-45DD-9DED-E8F044B8AC79}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{A91483C2-666A-4EF1-A040-0A9BBC1980EA}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{43BDC947-F2D4-4B3B-BB76-5CD8E2E508F4}] => (Allow) C:\Program Files (x86)\Opera\opera.exe
FirewallRules: [{44C05498-1AD2-4965-B8C6-033E414A939C}] => (Allow) C:\Program Files (x86)\Opera\opera.exe
FirewallRules: [{E2F743F7-8184-4BEB-B130-864DE8896029}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{C9CDCB1D-AA7B-48BC-B12E-9D37EBFDA4BE}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{73E96A80-4C47-4316-9F7A-18C841914C99}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{FEB162DA-7094-4FA0-903D-C3FFB040DF7B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{694B907C-D2FB-4244-B8A8-21354B5A0D9C}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{6973E533-C1E0-4205-BD41-731B270E5696}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{90E68B94-2D3D-4A88-900D-3634740BAC58}] => (Allow) C:\Program Files (x86)\Opera\pluginwrapper\opera_plugin_wrapper.exe
FirewallRules: [{AB24170F-C342-4281-B0AB-F1F13F861EC0}] => (Allow) C:\Program Files (x86)\Opera\pluginwrapper\opera_plugin_wrapper.exe
FirewallRules: [{FD272297-2A9A-4833-BDDC-371AD2B2FF86}] => (Allow) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe
FirewallRules: [{5889981B-0F07-4593-A888-1D0204CFA6B6}] => (Allow) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe
FirewallRules: [{72C76E64-9780-48EC-B109-CAD569692505}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{6B8EBC5B-970A-4F7C-86A3-E0D1CEF4DCB7}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{3ED25ADD-8A52-4209-8D9E-F7DFA0E9DE78}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{5D010693-1B1F-4F6F-8663-9B3D0EA6FE62}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{401051CC-CA2E-4EDC-93D9-C967D3D0C695}] => (Block) %SystemRoot%\System32\artisteer.exe
FirewallRules: [{77D60E68-3A87-4987-8F4B-671832644BA5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0328E9C4-9756-4EC0-BEC0-91527F9FA1F2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3E6F152E-E12D-4D83-B6D5-1484EEC5C584}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C22C916B-0A08-479E-B5E7-A70DB423931E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{16586BE4-CB12-4806-9A31-107C640E7D64}C:\windows\syswow64\ipcamera.exe] => (Allow) C:\windows\syswow64\ipcamera.exe
FirewallRules: [UDP Query User{040301D5-A003-410F-A5A7-F933876EF8A5}C:\windows\syswow64\ipcamera.exe] => (Allow) C:\windows\syswow64\ipcamera.exe
FirewallRules: [{D99581F6-9E0C-4967-BCF4-07DDD589E23F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{E52730B3-A106-4C10-B759-BA4C1C4CF3B2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0534CED4-AF3E-410C-A693-827FE6DF1EAD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{763F8A95-6242-4F5E-9BCF-CF8A7B20F3C3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{FE7CEF83-17E3-48E7-A122-F75E6BEC9771}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E0007185-692D-4B83-A00B-E8974D3772E3}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{D32745DF-D46A-493E-BD4F-6785C9DD326A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{969CFE04-2CBA-4AAB-8E91-E799A739B021}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{EFCCDA9D-AB14-4BAA-9B84-81E94D1E8D3A}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8600\bin\FaxApplications.exe
FirewallRules: [{2820DE00-4926-4A74-83D7-6984A90FA1E1}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8600\bin\DigitalWizards.exe
FirewallRules: [{113C6CA6-6BFE-479A-BBB3-D1AC51215DB9}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8600\bin\SendAFax.exe
FirewallRules: [{3E541302-B6D2-45F0-ABEF-5704600AE004}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8600\Bin\DeviceSetup.exe
FirewallRules: [{8AD6D16E-3D83-4B9A-BF90-812DBF46C3C9}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe
FirewallRules: [{C7091E01-0363-42A4-908A-A5C473544A5C}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{9EB6023A-7727-4729-8B38-888D2025A64E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/22/2015 09:24:10 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/21/2015 03:08:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/21/2015 03:02:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/21/2015 02:54:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/21/2015 02:38:47 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/21/2015 02:38:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mcserver.exe, Version: 1.0.0.0, Zeitstempel: 0x4c1324dc
Name des fehlerhaften Moduls: dbus-1.dll, Version: 0.0.0.0, Zeitstempel: 0x4bebbb2c
Ausnahmecode: 0x40000015
Fehleroffset: 0x00055d8f
ID des fehlerhaften Prozesses: 0xbb8
Startzeit der fehlerhaften Anwendung: 0xmcserver.exe0
Pfad der fehlerhaften Anwendung: mcserver.exe1
Pfad des fehlerhaften Moduls: mcserver.exe2
Berichtskennung: mcserver.exe3
Error: (07/21/2015 02:16:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 39.0.0.5659, Zeitstempel: 0x55934d06
Name des fehlerhaften Moduls: mozalloc.dll, Version: 39.0.0.5659, Zeitstempel: 0x55933a83
Ausnahmecode: 0x80000003
Fehleroffset: 0x00001aa1
ID des fehlerhaften Prozesses: 0x1a04
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Error: (07/21/2015 02:15:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 39.0.0.5659, Zeitstempel: 0x55934d06
Name des fehlerhaften Moduls: mozalloc.dll, Version: 39.0.0.5659, Zeitstempel: 0x55933a83
Ausnahmecode: 0x80000003
Fehleroffset: 0x00001aa1
ID des fehlerhaften Prozesses: 0x1ab0
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Error: (07/21/2015 02:15:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 39.0.0.5659, Zeitstempel: 0x55934d06
Name des fehlerhaften Moduls: mozalloc.dll, Version: 39.0.0.5659, Zeitstempel: 0x55933a83
Ausnahmecode: 0x80000003
Fehleroffset: 0x00001aa1
ID des fehlerhaften Prozesses: 0xd30
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Error: (07/21/2015 02:15:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 39.0.0.5659 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: f44
Startzeit: 01d0c3adc6805602
Endzeit: 32
Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Berichts-ID: 39f5d6bb-2fa2-11e5-8bdf-00094f000001
System errors:
=============
Error: (07/22/2015 09:23:39 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "IE Search Set" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (07/22/2015 09:23:39 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst IE Search Set erreicht.
Error: (07/22/2015 09:23:03 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (07/22/2015 09:23:03 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht.
Error: (07/21/2015 03:05:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (07/21/2015 03:05:57 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Internet Manager. OUC erreicht.
Error: (07/21/2015 03:05:29 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 21.07.2015 um 15:04:30 unerwartet heruntergefahren.
Error: (07/21/2015 03:03:39 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WerSvc erreicht.
Error: (07/21/2015 03:03:09 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WerSvc erreicht.
Error: (07/21/2015 03:00:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Internet Manager. OUC" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Microsoft Office:
=========================
CodeIntegrity Errors:
===================================
Date: 2014-09-12 17:09:12.977
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-09-12 17:09:12.977
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-09-12 17:08:05.008
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-09-12 17:08:05.008
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-09-12 17:08:03.183
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-09-12 17:08:03.183
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-09-12 17:08:03.105
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-09-12 17:08:03.105
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-09-12 17:06:00.847
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-09-12 17:06:00.847
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-2320 CPU @ 3.00GHz
Percentage of memory in use: 38%
Total physical RAM: 6126.39 MB
Available physical RAM: 3795.31 MB
Total Virtual: 12250.98 MB
Available Virtual: 9461.11 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:906.34 GB) (Free:676.58 GB) NTFS
Drive f: () (Removable) (Total:3.72 GB) (Free:1.21 GB) FAT
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: EE6DBC19)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=906.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=25.1 GB) - (Type=12)
========================================================
Disk: 1 (Size: 3.7 GB) (Disk ID: 0005F2E3)
Partition 1: (Active) - (Size=3.7 GB) - (Type=06)
==================== End of log ============================ --- --- --- |