![]() |
|
Log-Analyse und Auswertung: Telekom Abuse Mail Port 25 gesperrtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Telekom Abuse Mail Port 25 gesperrt Guten Tag, ich habe vom Telekom Abuse Team die bekannte Mail, dass über meinen Internetzugang Schadsoftware verschickt wird, erhalten und mir wurde im Zuge dessen der Port 25 gesperrt. Eine Avira Boot-CD fand keine Viren. defogger_disable: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 00:33 on 04/01/2014 (Nutzername) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. HKCU:AlcoholAutomount -> Removed Checking for services/drivers... SPTD -> Disabled (Service running -> reboot required) -=E.O.F=- FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-01-2014 Ran by Nutzername (administrator) on ULTRABOOK on 04-01-2014 00:41:47 Running from C:\Users\Nutzername\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe () C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe () C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe () C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe () C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe () C:\Program Files\ShrewSoft\VPN Client\iked.exe () C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (Intel Corporation) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe () C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe (CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (LENOVO) C:\Program Files (x86)\Lenovo\Lenovo CAPOSD\CAPOSD.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Dropbox, Inc.) C:\Users\Nutzername\AppData\Roaming\Dropbox\bin\Dropbox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe () C:\Users\Nutzername\Downloads\gmer_2.1.19163.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [792224 2011-12-13] (Atheros Communications) HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [657568 2011-12-13] (Atheros Commnucations) HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [378968 2012-01-05] (Alcor Micro Corp.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2847016 2011-11-10] (Synaptics Incorporated) HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe [883840 2012-03-29] (Conexant Systems, Inc.) HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SACpl.exe [1654400 2012-02-21] (Conexant Systems, Inc.) HKLM\...\Run: [SynLenovoGestureMgr] - C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [408872 2011-11-10] (Synaptics) HKLM\...\Run: [UpdatePRCShortCut] - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8079408 2012-08-15] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [6202416 2012-08-15] (Lenovo(beijing) Limited) HKLM\...\Run: [PAC7302_Monitor] - C:\Windows\PixArt\PAC7302\Monitor.exe HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [152896 2012-06-25] (Intel Corporation) HKLM-x32\...\Run: [Lenovo Registration] - C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2012-01-26] (Lenovo, Inc.) HKLM-x32\...\Run: [Intelligent Touchpad] - C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe [291272 2011-12-08] () HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-28] (CyberLink) HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-28] (CyberLink Corp.) HKLM-x32\...\Run: [VeriFaceManager] - C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-08-15] (Lenovo) HKLM-x32\...\Run: [UpdatePRCShortCut] - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM-x32\...\Run: [CAPOSD] - C:\Program Files (x86)\Lenovo\Lenovo CAPOSD\CAPOSD.exe [1876992 2012-02-17] (LENOVO) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] - C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe HKLM-x32\...\Run: [BrowserPlugInHelper] - C:\Program Files (x86)\Wondershare\AllMyTube\BrowserPlugInHelper.exe HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) MountPoints2: {a0f81a47-68bc-11e3-8d2e-005056c00008} - G:\wubi.exe MountPoints2: {d935929d-d8a2-11e2-92e5-b6816737ce57} - G:\HTC_Sync_Manager_PC.exe MountPoints2: {d93592a1-d8a2-11e2-92e5-b6816737ce57} - G:\HTC_Sync_Manager_PC.exe AppInit_DLLs: C:\ProgramData\WebTect\WebTect_x64.dll [4269056 2013-12-29] () AppInit_DLLs-x32: c:\progra~3\webtect\webtect.dll [4112384 2013-12-29] () Startup: C:\Users\Nutzername\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Nutzername\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=KMOH&bmod=KMOH HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://websearch.searchboxes.info/?pid=377&r=2013/07/26&hid=1860432997&lg=EN&cc=DE&unqvl=28 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.google.com/ig/redirectdomain?brand=KMOH&bmod=KMOH HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://websearch.searchboxes.info/?pid=377&r=2013/07/26&hid=1860432997&lg=EN&cc=DE&unqvl=28 SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.searchboxes.info/?l=1&q={searchTerms}&pid=377&r=2013/07/26&hid=1860432997&lg=EN&cc=DE&unqvl=28 SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7KMOH_deDE508 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7KMOH_deDE508 BHO: SaveLiotss - {82D8FF96-8EF2-5C85-14F5-EBC914A32AFD} - C:\ProgramData\SaveLiotss\S.x64.dll () BHO: CheapMe - {A9A22C18-6EE0-CB7C-2A73-2179973D9EC4} - C:\ProgramData\CheapMe\5hHY.x64.dll () BHO-x32: SaveLiotss - {82D8FF96-8EF2-5C85-14F5-EBC914A32AFD} - C:\ProgramData\SaveLiotss\S.dll () BHO-x32: CheapMe - {A9A22C18-6EE0-CB7C-2A73-2179973D9EC4} - C:\ProgramData\CheapMe\5hHY.dll () Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\..\Interfaces\{8B2448EA-317B-4A2E-8899-A3DA40FC2AB3}: [NameServer]192.168.178.1 Tcpip\..\Interfaces\{C29C6EBE-8506-460E-80DC-BB371ACD6305}: [NameServer]130.83.22.60,130.83.56.60 FireFox: ======== FF ProfilePath: C:\Users\Nutzername\AppData\Roaming\Mozilla\Firefox\Profiles\y7ui8hs2.default FF SearchEngineOrder.1: WebSearch FF SearchEngineOrder.user_pref("browser.search.order.1,S", "WebSearch");: user_pref("browser.search.order.1,S", "WebSearch"); FF SelectedSearchEngine: Google FF Homepage: about:blank FF Keyword.URL: hxxp://websearch.searchboxes.info/?pid=377&r=2013/07/26&hid=1860432997&lg=EN&cc=DE&unqvl=28&l=1&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Nutzername\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: electronicarts.com/GameFacePlugin - C:\Users\Nutzername\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts) FF SearchPlugin: C:\Users\Nutzername\AppData\Roaming\Mozilla\Firefox\Profiles\y7ui8hs2.default\searchplugins\WebSearch.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Send to XBMC - C:\Users\Nutzername\AppData\Roaming\Mozilla\Firefox\Profiles\y7ui8hs2.default\Extensions\jid0-YCM0p5WlCGjvBJcZhAusQ5h26wM@jetpack.xpi FF Extension: Adblock Plus - C:\Users\Nutzername\AppData\Roaming\Mozilla\Firefox\Profiles\y7ui8hs2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= CHR HomePage: hxxp://websearch.searchboxes.info/?pid=377&r=2013/07/26&hid=1860432997&lg=EN&cc=DE&unqvl=28 CHR RestoreOnStartup: "hxxp://websearch.searchboxes.info/?pid=377&r=2013/07/26&hid=1860432997&lg=EN&cc=DE&unqvl=28" CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll No File CHR Plugin: (Intel\u00C2\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel\u00C2\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (Windows Live\u00C2\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll No File CHR Plugin: (Default Plug-in) - default_plugin No File CHR Extension: (Google Wallet) - C:\Users\Nutzername\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR Extension: (SaveLiotss) - C:\Users\Nutzername\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofieklnppgomeoemahkhepeanfghllfd\6.3 CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 25e4f9bf; C:\Windows\system32\rundll32.exe [45568 2009-07-14] (Microsoft Corporation) R2 25e4f9bf; C:\Windows\SysWow64\rundll32.exe [44544 2009-07-14] (Microsoft Corporation) S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) S2 BootShieldSvc; C:\Windows\System32\BootShieldSvc.exe [123952 2012-02-06] (Lenovo) R2 DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [14848 2013-08-13] () S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) R2 iked; C:\Program Files\ShrewSoft\VPN Client\iked.exe [1127736 2013-07-01] () R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-04-16] () R2 ipsecd; C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe [810808 2013-07-01] () R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-02-05] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [164184 2012-04-16] (Intel Corporation) S4 LenovoSmartConnectService; C:\Program Files (x86)\Lenovo\Lenovo Smart Update\LenovoSmartConnectService.exe [66608 2012-02-20] (Lenovo) S2 libusbd; C:\Windows\SysWow64\libusbd-nt.exe [18944 2005-03-09] (hxxp://libusb-win32.sourceforge.net) R2 MySQL; C:\Program Files\MySQL\MySQL Server 5.5\my.ini [8919 2012-11-09] () R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.) S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) R2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [15680000 2012-08-15] () R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2011-12-13] (Atheros) S3 {08CECC71-A9B1-417d-AB3A-C57C4F854F53}629803837; C:\mo'stream\mo\RunAsSvc.exe [176128 2006-06-05] (Pirmasoft - Dieter Schmeer) ==================== Drivers (Whitelisted) ==================== R0 BootShield; C:\Windows\System32\drivers\BootShield.sys [31536 2012-04-16] (Lenovo Corporation") R1 BootShieldfltr; C:\Windows\System32\drivers\BootShieldfltr.sys [61744 2012-02-16] (Lenovo Corporation) R2 Dokan; C:\Windows\system32\drivers\dokan.sys [120408 2013-08-13] (Windows (R) Win 7 DDK provider) R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769816 2011-07-09] (www.ext2fsd.com) R3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2012-02-06] (Intel Corporation) R3 LAD; C:\Windows\System32\DRIVERS\LAD.sys [8192 2012-01-12] (TODO: <Company name>) S3 libusb0; C:\Windows\SysWow64\drivers\libusb0.sys [33792 2005-03-09] () R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) S3 PAC7302; C:\Windows\System32\DRIVERS\PAC7302.SYS [527872 2007-11-08] (PixArt Imaging Inc.) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2012-08-20] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [12384 2012-08-20] () S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [748648 2010-08-12] (Realtek Semiconductor Corporation ) R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8217704 2012-02-06] (Realtek Semiconductor Corp.) R0 vsock; C:\Windows\System32\drivers\vsock.sys [70256 2012-07-06] (VMware, Inc.) S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation) U3 BcmSqlStartupSvc; U2 CLKMSVC10_3A60B698; U2 CLKMSVC10_C3B3B687; S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] U2 DriverService; U2 iATAgentService; U2 idealife Update Service; U3 IGRS; U2 IviRegMgr; U2 Oasis2Service; U2 PCCarerService; U2 ReadyComm.DirectRouter; U2 RichVideo; U2 RtLedService; U2 SeaPort; U2 SoftwareService; S4 sptd; \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [x] U3 kwrdrpoc; \??\C:\Users\Nutzername\AppData\Local\Temp\kwrdrpoc.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-04 00:39 - 2014-01-04 00:39 - 00377856 _____ C:\Users\Nutzername\Downloads\gmer_2.1.19163.exe 2014-01-04 00:37 - 2014-01-04 00:37 - 00050249 _____ C:\Users\Nutzername\Downloads\Addition.txt 2014-01-04 00:36 - 2014-01-04 00:41 - 00021938 _____ C:\Users\Nutzername\Downloads\FRST.txt 2014-01-04 00:36 - 2014-01-04 00:36 - 01931750 _____ (Farbar) C:\Users\Nutzername\Downloads\FRST64.exe 2014-01-04 00:36 - 2014-01-04 00:36 - 00000000 ____D C:\FRST 2014-01-04 00:33 - 2014-01-04 00:33 - 00050477 _____ C:\Users\Nutzername\Downloads\Defogger.exe 2014-01-04 00:33 - 2014-01-04 00:33 - 00000652 _____ C:\Users\Nutzername\Downloads\defogger_disable.log 2014-01-04 00:33 - 2014-01-04 00:33 - 00000216 _____ C:\Users\Nutzername\defogger_reenable 2014-01-04 00:19 - 2014-01-04 00:19 - 13079688 _____ (Microsoft Corporation) C:\Users\Nutzername\Downloads\Silverlight_x64(1).exe 2014-01-03 23:35 - 2014-01-03 23:35 - 00002685 _____ C:\Users\Nutzername\Downloads\fujirou_lyrics_in_th-1.0.aum 2014-01-03 23:35 - 2014-01-03 23:35 - 00002545 _____ C:\Users\Nutzername\Downloads\fujirou_lyric_wiki-1.1.aum 2014-01-03 23:32 - 2014-01-03 23:32 - 00005120 _____ C:\Users\Nutzername\Downloads\lololyr.aum 2014-01-03 23:31 - 2014-01-03 23:31 - 00001160 _____ C:\Users\Nutzername\Downloads\mymodule.aum 2014-01-03 14:56 - 2014-01-03 14:56 - 622399488 _____ C:\Users\Nutzername\Documents\rescuedisk.iso 2014-01-03 14:19 - 2014-01-03 14:43 - 624175864 _____ (Avira GmbH) C:\Users\Nutzername\Downloads\rescue12-system.exe 2014-01-01 21:03 - 2014-01-01 21:03 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\AVM 2014-01-01 21:02 - 2014-01-01 21:03 - 00000000 ____D C:\Program Files (x86)\FRITZ!Fernzugang einrichten 2014-01-01 21:01 - 2014-01-01 21:01 - 05946232 _____ C:\Users\Nutzername\Downloads\FRITZ!Box-Fernzugang einrichten.exe 2013-12-31 17:00 - 2013-12-31 17:00 - 00002561 _____ C:\Windows\diagwrn.xml 2013-12-31 17:00 - 2013-12-31 17:00 - 00001908 _____ C:\Windows\diagerr.xml 2013-12-31 13:36 - 2013-12-31 13:36 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\Nero 2013-12-31 10:34 - 2013-12-31 10:36 - 00000000 ____D C:\Program Files (x86)\Nero 2013-12-31 10:33 - 2013-12-31 10:40 - 00000000 ____D C:\ProgramData\Nero 2013-12-31 10:32 - 2013-12-31 10:33 - 00000219 _____ C:\Users\Nutzername\Documents\nero.txt 2013-12-31 10:28 - 2013-12-31 10:28 - 00000000 ____D C:\ProgramData\Energy Management 2013-12-31 10:24 - 2013-12-31 10:24 - 00000000 ____D C:\ProgramData\SaveLiotss 2013-12-31 10:24 - 2013-12-31 10:24 - 00000000 ____D C:\ProgramData\CheapMe 2013-12-31 10:24 - 2013-12-31 10:24 - 00000000 ____D C:\ProgramData\cdcmgolnhhooaokpikoniljebdnnijik 2013-12-31 10:24 - 2013-12-31 10:24 - 00000000 ____D C:\ProgramData\485f8ee9961a1c7e 2013-12-30 21:30 - 2013-12-30 21:30 - 00001654 _____ C:\Users\Nutzername\Documents\htc amazon.txt 2013-12-30 12:54 - 2013-12-30 15:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-12-30 01:40 - 2013-12-30 01:40 - 00000469 _____ C:\Users\Nutzername\Documents\htc.txt 2013-12-30 00:54 - 2013-12-30 00:54 - 04142110 _____ C:\Users\Nutzername\Downloads\Camera.apk 2013-12-29 15:50 - 2013-12-29 15:50 - 00000000 ____D C:\Users\Nutzername\Downloads\asus treiber 2013-12-29 15:20 - 2013-12-29 15:20 - 00000000 ____D C:\Users\Nutzername\Downloads\winfromusb 2013-12-29 15:18 - 2013-12-29 15:19 - 22619852 _____ (Igor Pavlov) C:\Users\Nutzername\Downloads\WinSetupFromUSB-1-1.exe 2013-12-29 13:07 - 2013-12-29 13:07 - 00104061 _____ C:\Users\Nutzername\Downloads\enigma_2_astra-hb_matze.zip 2013-12-29 12:52 - 2013-12-29 12:52 - 00000000 ____D C:\ProgramData\WebTect 2013-12-25 22:05 - 2013-12-25 22:06 - 15165440 _____ C:\Users\Nutzername\Downloads\pyLoad-0.4.9-4-armv5.spk 2013-12-24 20:40 - 2013-01-06 16:56 - 00000000 ____D C:\Users\Nutzername\Downloads\JdAdapter 0.4.2 2013-12-24 20:39 - 2013-12-24 20:40 - 06338259 _____ C:\Users\Nutzername\Downloads\jdadapter-0.4.2-Release-Package.zip 2013-12-24 19:42 - 2013-12-24 19:46 - 00000000 ____D C:\Users\Nutzername\Downloads\owncloud 2013-12-24 13:48 - 2013-12-24 13:48 - 00000000 ____D C:\ProgramData\Oracle 2013-12-24 13:48 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-12-24 13:47 - 2013-12-24 13:47 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log 2013-12-24 13:47 - 2013-10-08 07:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-12-24 13:47 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-12-24 13:47 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-12-24 13:43 - 2013-12-24 13:43 - 00915368 _____ (Oracle Corporation) C:\Users\Nutzername\Downloads\jxpiinstall(1).exe 2013-12-22 00:56 - 2013-12-22 00:56 - 00010293 _____ C:\Users\Nutzername\Downloads\print.html 2013-12-22 00:56 - 2013-12-22 00:56 - 00000000 ____D C:\Users\Nutzername\Downloads\print-Dateien 2013-12-20 11:18 - 2013-12-20 11:38 - 00003283 _____ C:\Users\Nutzername\Documents\newfile.php 2013-12-20 10:39 - 2013-12-20 11:32 - 00003072 _____ C:\Users\Nutzername\Documents\open.php 2013-12-20 10:38 - 2013-12-20 12:02 - 00004887 _____ C:\Users\Nutzername\Documents\viewer.js 2013-12-20 10:34 - 2013-12-20 10:35 - 00053568 _____ C:\Users\Nutzername\Documents\curl.so 2013-12-20 10:34 - 2013-12-20 10:34 - 00053568 _____ C:\Users\Nutzername\Documents\curl53.so 2013-12-20 10:29 - 2013-12-20 10:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-20 10:18 - 2013-12-20 10:18 - 09918692 _____ C:\Users\Nutzername\Documents\libphp5opt.so 2013-12-20 10:17 - 2013-12-20 10:17 - 13598428 _____ C:\Users\Nutzername\Documents\libphp5apache.so 2013-12-20 10:04 - 2013-12-20 10:05 - 00000061 _____ C:\Users\Nutzername\Documents\gd.ini 2013-12-20 09:48 - 2013-12-20 10:28 - 00038793 _____ C:\Users\Nutzername\Documents\php.ini 2013-12-20 09:48 - 2013-12-20 10:12 - 00038793 _____ C:\Users\Nutzername\Documents\php53.ini 2013-12-20 09:48 - 2013-12-20 09:48 - 00069726 _____ C:\Users\Nutzername\Documents\phpbackup.ini 2013-12-20 09:44 - 2013-12-20 09:45 - 00001111 _____ C:\Users\Nutzername\Documents\ipkg.conf 2013-12-20 09:41 - 2013-12-20 09:42 - 16818359 _____ C:\Users\Nutzername\Downloads\php-5.5.7.tar.gz 2013-12-20 09:37 - 2013-12-20 09:37 - 00027931 _____ C:\Users\Nutzername\Downloads\curl-5.3.14-1(1).ipk 2013-12-19 17:41 - 2013-12-19 17:50 - 00000000 ____D C:\Users\Nutzername\Downloads\raspbmc-win32(1) 2013-12-19 17:41 - 2013-12-19 17:41 - 00180081 _____ C:\Users\Nutzername\Downloads\raspbmc-win32(1).zip 2013-12-19 16:49 - 2013-12-19 16:49 - 00000000 ____D C:\Users\Nutzername\Downloads\raspbmc-plugin 2013-12-19 16:48 - 2013-12-19 16:48 - 00149690 _____ C:\Users\Nutzername\Downloads\raspbmc-plugin.tar.gz 2013-12-19 16:10 - 2013-12-19 16:10 - 00003630 _____ C:\Windows\System32\Tasks\Paragon ExtFS for Windows 2013-12-19 16:10 - 2013-12-19 16:10 - 00000000 ____D C:\Program Files (x86)\Paragon Software 2013-12-19 16:10 - 2013-12-19 16:10 - 00000000 ____D C:\Program Files (x86)\Dokan 2013-12-19 16:00 - 2013-12-19 16:00 - 04509379 _____ (DiskInternals Research) C:\Users\Nutzername\Downloads\Linux_Reader(1).exe 2013-12-19 15:58 - 2013-12-19 15:58 - 01054440 _____ C:\Users\Nutzername\Downloads\Paragon_ExtFS_for_Windows_2.73.exe 2013-12-19 15:44 - 2013-12-19 15:44 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\TightVNC 2013-12-19 15:44 - 2013-12-19 15:44 - 00000000 ____D C:\ProgramData\TightVNC 2013-12-19 15:44 - 2013-12-19 15:44 - 00000000 ____D C:\Program Files\TightVNC 2013-12-19 15:43 - 2013-12-19 15:43 - 02367488 _____ C:\Users\Nutzername\Downloads\tightvnc-2.7.10-setup-64bit.msi 2013-12-18 15:54 - 2013-12-18 15:54 - 00027931 _____ C:\Users\Nutzername\Downloads\curl-5.3.14-1.ipk 2013-12-18 15:21 - 2013-12-18 15:21 - 04689382 _____ C:\Users\Nutzername\Downloads\curl-7.34.0.zip 2013-12-17 08:29 - 2013-12-17 08:29 - 02910848 _____ C:\Users\Nutzername\Downloads\GraphVisualizer.zip 2013-12-14 20:59 - 2013-12-14 20:59 - 00000000 ____D C:\Users\Nutzername\AppData\Local\{CA00F620-FE9C-45E3-BC58-9F7AE9C20D45} 2013-12-10 10:27 - 2013-12-10 10:29 - 106478430 _____ C:\Users\Nutzername\Downloads\oc_export_instance_13-12-10_09-24-07.zip 2013-12-10 10:24 - 2013-12-10 10:25 - 15436770 _____ C:\Users\Nutzername\Downloads\owncloud-latest.tar.bz2 2013-12-10 09:48 - 2013-12-10 09:49 - 15436770 _____ C:\Users\Nutzername\Downloads\owncloud-5.0.13.tar.bz2 2013-12-09 14:07 - 2013-12-09 14:07 - 02433536 _____ C:\Users\Nutzername\Documents\aufgabe1-3.ppt 2013-12-06 18:28 - 2013-12-06 18:28 - 09091423 _____ (Electronic Arts) C:\Users\Nutzername\Downloads\GameFaceBrowserPluginInstaller.1.8.0.0.exe 2013-12-06 18:28 - 2013-12-06 18:28 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\Electronic Arts 2013-12-05 13:57 - 2013-12-05 13:57 - 11703558 _____ C:\Users\Nutzername\Downloads\Framework OpenGL Terrain Texture Culling.zip ==================== One Month Modified Files and Folders ======= 2014-01-04 00:41 - 2014-01-04 00:36 - 00021938 _____ C:\Users\Nutzername\Downloads\FRST.txt 2014-01-04 00:41 - 2009-07-14 05:45 - 00031840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-04 00:41 - 2009-07-14 05:45 - 00031840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-04 00:39 - 2014-01-04 00:39 - 00377856 _____ C:\Users\Nutzername\Downloads\gmer_2.1.19163.exe 2014-01-04 00:37 - 2014-01-04 00:37 - 00050249 _____ C:\Users\Nutzername\Downloads\Addition.txt 2014-01-04 00:37 - 2012-08-15 16:04 - 01530872 _____ C:\Windows\WindowsUpdate.log 2014-01-04 00:36 - 2014-01-04 00:36 - 01931750 _____ (Farbar) C:\Users\Nutzername\Downloads\FRST64.exe 2014-01-04 00:36 - 2014-01-04 00:36 - 00000000 ____D C:\FRST 2014-01-04 00:35 - 2012-11-03 19:35 - 00000000 ___RD C:\Dropbox 2014-01-04 00:35 - 2012-11-03 19:33 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\Dropbox 2014-01-04 00:35 - 2012-11-03 18:08 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\Skype 2014-01-04 00:34 - 2013-07-26 15:21 - 00000418 ____H C:\Windows\Tasks\schedule!3036567561.job 2014-01-04 00:34 - 2013-05-07 14:28 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2014-01-04 00:34 - 2012-11-06 10:42 - 00000000 ____D C:\ProgramData\VMware 2014-01-04 00:34 - 2012-11-03 20:18 - 00038254 _____ C:\Users\Public\CAFADEBUG.log 2014-01-04 00:34 - 2012-11-03 20:08 - 00000000 ___RD C:\Users\Nutzername\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-04 00:34 - 2012-11-03 20:06 - 02751496 _____ C:\FaceProv.log 2014-01-04 00:34 - 2012-08-15 16:41 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-04 00:34 - 2012-08-15 16:40 - 00000000 ____D C:\ProgramData\VeriFace 2014-01-04 00:34 - 2012-08-15 16:28 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2014-01-04 00:34 - 2010-11-21 04:47 - 00399580 _____ C:\Windows\PFRO.log 2014-01-04 00:34 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-04 00:34 - 2009-07-14 05:51 - 00001938 _____ C:\Windows\setupact.log 2014-01-04 00:33 - 2014-01-04 00:33 - 00050477 _____ C:\Users\Nutzername\Downloads\Defogger.exe 2014-01-04 00:33 - 2014-01-04 00:33 - 00000652 _____ C:\Users\Nutzername\Downloads\defogger_disable.log 2014-01-04 00:33 - 2014-01-04 00:33 - 00000216 _____ C:\Users\Nutzername\defogger_reenable 2014-01-04 00:33 - 2012-11-03 20:06 - 00000000 ____D C:\Users\Nutzername 2014-01-04 00:29 - 2012-11-03 14:57 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-04 00:19 - 2014-01-04 00:19 - 13079688 _____ (Microsoft Corporation) C:\Users\Nutzername\Downloads\Silverlight_x64(1).exe 2014-01-04 00:13 - 2012-08-15 16:41 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-03 23:35 - 2014-01-03 23:35 - 00002685 _____ C:\Users\Nutzername\Downloads\fujirou_lyrics_in_th-1.0.aum 2014-01-03 23:35 - 2014-01-03 23:35 - 00002545 _____ C:\Users\Nutzername\Downloads\fujirou_lyric_wiki-1.1.aum 2014-01-03 23:32 - 2014-01-03 23:32 - 00005120 _____ C:\Users\Nutzername\Downloads\lololyr.aum 2014-01-03 23:31 - 2014-01-03 23:31 - 00001160 _____ C:\Users\Nutzername\Downloads\mymodule.aum 2014-01-03 23:13 - 2012-11-03 19:38 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\vlc 2014-01-03 17:50 - 2012-12-15 19:41 - 00000132 _____ C:\Users\Nutzername\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen 2014-01-03 17:22 - 2012-08-16 01:50 - 00700884 _____ C:\Windows\system32\perfh007.dat 2014-01-03 17:22 - 2012-08-16 01:50 - 00150074 _____ C:\Windows\system32\perfc007.dat 2014-01-03 17:22 - 2009-07-14 06:13 - 01624440 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-03 16:07 - 2012-11-03 20:08 - 00000000 ____D C:\Users\Nutzername\Documents\Bluetooth Folder 2014-01-03 14:56 - 2014-01-03 14:56 - 622399488 _____ C:\Users\Nutzername\Documents\rescuedisk.iso 2014-01-03 14:43 - 2014-01-03 14:19 - 624175864 _____ (Avira GmbH) C:\Users\Nutzername\Downloads\rescue12-system.exe 2014-01-02 16:54 - 2013-06-13 10:18 - 00000600 _____ C:\Users\Nutzername\AppData\Local\PUTTY.RND 2014-01-01 21:03 - 2014-01-01 21:03 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\AVM 2014-01-01 21:03 - 2014-01-01 21:02 - 00000000 ____D C:\Program Files (x86)\FRITZ!Fernzugang einrichten 2014-01-01 21:01 - 2014-01-01 21:01 - 05946232 _____ C:\Users\Nutzername\Downloads\FRITZ!Box-Fernzugang einrichten.exe 2013-12-31 17:08 - 2013-02-23 12:49 - 00001648 _____ C:\Users\Nutzername\Documents\ax_files.xml 2013-12-31 17:00 - 2013-12-31 17:00 - 00002561 _____ C:\Windows\diagwrn.xml 2013-12-31 17:00 - 2013-12-31 17:00 - 00001908 _____ C:\Windows\diagerr.xml 2013-12-31 17:00 - 2009-07-14 05:51 - 00000000 _____ C:\Windows\setuperr.log 2013-12-31 15:35 - 2013-03-20 20:19 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\dvdcss 2013-12-31 13:36 - 2013-12-31 13:36 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\Nero 2013-12-31 10:40 - 2013-12-31 10:33 - 00000000 ____D C:\ProgramData\Nero 2013-12-31 10:36 - 2013-12-31 10:34 - 00000000 ____D C:\Program Files (x86)\Nero 2013-12-31 10:36 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Cursors 2013-12-31 10:33 - 2013-12-31 10:32 - 00000219 _____ C:\Users\Nutzername\Documents\nero.txt 2013-12-31 10:28 - 2013-12-31 10:28 - 00000000 ____D C:\ProgramData\Energy Management 2013-12-31 10:28 - 2012-11-03 15:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-31 10:24 - 2013-12-31 10:24 - 00000000 ____D C:\ProgramData\SaveLiotss 2013-12-31 10:24 - 2013-12-31 10:24 - 00000000 ____D C:\ProgramData\CheapMe 2013-12-31 10:24 - 2013-12-31 10:24 - 00000000 ____D C:\ProgramData\cdcmgolnhhooaokpikoniljebdnnijik 2013-12-31 10:24 - 2013-12-31 10:24 - 00000000 ____D C:\ProgramData\485f8ee9961a1c7e 2013-12-30 21:30 - 2013-12-30 21:30 - 00001654 _____ C:\Users\Nutzername\Documents\htc amazon.txt 2013-12-30 15:06 - 2013-12-30 12:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-12-30 01:40 - 2013-12-30 01:40 - 00000469 _____ C:\Users\Nutzername\Documents\htc.txt 2013-12-30 00:54 - 2013-12-30 00:54 - 04142110 _____ C:\Users\Nutzername\Downloads\Camera.apk 2013-12-29 20:48 - 2012-12-29 13:09 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\FileZilla 2013-12-29 15:50 - 2013-12-29 15:50 - 00000000 ____D C:\Users\Nutzername\Downloads\asus treiber 2013-12-29 15:20 - 2013-12-29 15:20 - 00000000 ____D C:\Users\Nutzername\Downloads\winfromusb 2013-12-29 15:19 - 2013-12-29 15:18 - 22619852 _____ (Igor Pavlov) C:\Users\Nutzername\Downloads\WinSetupFromUSB-1-1.exe 2013-12-29 13:49 - 2012-12-30 22:52 - 00000000 ____D C:\Steam 2013-12-29 13:07 - 2013-12-29 13:07 - 00104061 _____ C:\Users\Nutzername\Downloads\enigma_2_astra-hb_matze.zip 2013-12-29 12:52 - 2013-12-29 12:52 - 00000000 ____D C:\ProgramData\WebTect 2013-12-29 12:52 - 2013-07-26 15:22 - 00000000 ____D C:\Program Files (x86)\WebSearch 2013-12-29 12:52 - 2013-07-26 15:21 - 00000000 ____D C:\Program Files (x86)\SafeSaver 2013-12-28 16:05 - 2012-11-06 10:45 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\VMware 2013-12-28 16:05 - 2012-11-06 10:45 - 00000000 ____D C:\Users\Nutzername\AppData\Local\VMware 2013-12-25 22:13 - 2013-12-25 22:13 - 00040057 _____ C:\Users\Nutzername\Downloads\Downloader.rar 2013-12-25 22:06 - 2013-12-25 22:05 - 15165440 _____ C:\Users\Nutzername\Downloads\pyLoad-0.4.9-4-armv5.spk 2013-12-24 20:40 - 2013-12-24 20:39 - 06338259 _____ C:\Users\Nutzername\Downloads\jdadapter-0.4.2-Release-Package.zip 2013-12-24 19:46 - 2013-12-24 19:42 - 00000000 ____D C:\Users\Nutzername\Downloads\owncloud 2013-12-24 13:48 - 2013-12-24 13:48 - 00000000 ____D C:\ProgramData\Oracle 2013-12-24 13:47 - 2013-12-24 13:47 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log 2013-12-24 13:47 - 2013-03-05 06:45 - 00000000 ____D C:\Program Files (x86)\Java 2013-12-24 13:43 - 2013-12-24 13:43 - 00915368 _____ (Oracle Corporation) C:\Users\Nutzername\Downloads\jxpiinstall(1).exe 2013-12-22 00:56 - 2013-12-22 00:56 - 00010293 _____ C:\Users\Nutzername\Downloads\print.html 2013-12-22 00:56 - 2013-12-22 00:56 - 00000000 ____D C:\Users\Nutzername\Downloads\print-Dateien 2013-12-20 12:02 - 2013-12-20 10:38 - 00004887 _____ C:\Users\Nutzername\Documents\viewer.js 2013-12-20 11:38 - 2013-12-20 11:18 - 00003283 _____ C:\Users\Nutzername\Documents\newfile.php 2013-12-20 11:32 - 2013-12-20 10:39 - 00003072 _____ C:\Users\Nutzername\Documents\open.php 2013-12-20 10:35 - 2013-12-20 10:34 - 00053568 _____ C:\Users\Nutzername\Documents\curl.so 2013-12-20 10:34 - 2013-12-20 10:34 - 00053568 _____ C:\Users\Nutzername\Documents\curl53.so 2013-12-20 10:30 - 2013-12-20 10:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-20 10:28 - 2013-12-20 09:48 - 00038793 _____ C:\Users\Nutzername\Documents\php.ini 2013-12-20 10:18 - 2013-12-20 10:18 - 09918692 _____ C:\Users\Nutzername\Documents\libphp5opt.so 2013-12-20 10:17 - 2013-12-20 10:17 - 13598428 _____ C:\Users\Nutzername\Documents\libphp5apache.so 2013-12-20 10:12 - 2013-12-20 09:48 - 00038793 _____ C:\Users\Nutzername\Documents\php53.ini 2013-12-20 10:05 - 2013-12-20 10:04 - 00000061 _____ C:\Users\Nutzername\Documents\gd.ini 2013-12-20 09:48 - 2013-12-20 09:48 - 00069726 _____ C:\Users\Nutzername\Documents\phpbackup.ini 2013-12-20 09:45 - 2013-12-20 09:44 - 00001111 _____ C:\Users\Nutzername\Documents\ipkg.conf 2013-12-20 09:42 - 2013-12-20 09:41 - 16818359 _____ C:\Users\Nutzername\Downloads\php-5.5.7.tar.gz 2013-12-20 09:37 - 2013-12-20 09:37 - 00027931 _____ C:\Users\Nutzername\Downloads\curl-5.3.14-1(1).ipk 2013-12-19 17:50 - 2013-12-19 17:41 - 00000000 ____D C:\Users\Nutzername\Downloads\raspbmc-win32(1) 2013-12-19 17:41 - 2013-12-19 17:41 - 00180081 _____ C:\Users\Nutzername\Downloads\raspbmc-win32(1).zip 2013-12-19 16:49 - 2013-12-19 16:49 - 00000000 ____D C:\Users\Nutzername\Downloads\raspbmc-plugin 2013-12-19 16:48 - 2013-12-19 16:48 - 00149690 _____ C:\Users\Nutzername\Downloads\raspbmc-plugin.tar.gz 2013-12-19 16:10 - 2013-12-19 16:10 - 00003630 _____ C:\Windows\System32\Tasks\Paragon ExtFS for Windows 2013-12-19 16:10 - 2013-12-19 16:10 - 00000000 ____D C:\Program Files (x86)\Paragon Software 2013-12-19 16:10 - 2013-12-19 16:10 - 00000000 ____D C:\Program Files (x86)\Dokan 2013-12-19 16:00 - 2013-12-19 16:00 - 04509379 _____ (DiskInternals Research) C:\Users\Nutzername\Downloads\Linux_Reader(1).exe 2013-12-19 15:58 - 2013-12-19 15:58 - 01054440 _____ C:\Users\Nutzername\Downloads\Paragon_ExtFS_for_Windows_2.73.exe 2013-12-19 15:44 - 2013-12-19 15:44 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\TightVNC 2013-12-19 15:44 - 2013-12-19 15:44 - 00000000 ____D C:\ProgramData\TightVNC 2013-12-19 15:44 - 2013-12-19 15:44 - 00000000 ____D C:\Program Files\TightVNC 2013-12-19 15:43 - 2013-12-19 15:43 - 02367488 _____ C:\Users\Nutzername\Downloads\tightvnc-2.7.10-setup-64bit.msi 2013-12-19 15:15 - 2012-11-03 19:33 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-12-18 15:54 - 2013-12-18 15:54 - 00027931 _____ C:\Users\Nutzername\Downloads\curl-5.3.14-1.ipk 2013-12-18 15:21 - 2013-12-18 15:21 - 04689382 _____ C:\Users\Nutzername\Downloads\curl-7.34.0.zip 2013-12-17 08:29 - 2013-12-17 08:29 - 02910848 _____ C:\Users\Nutzername\Downloads\GraphVisualizer.zip 2013-12-14 20:59 - 2013-12-14 20:59 - 00000000 ____D C:\Users\Nutzername\AppData\Local\{CA00F620-FE9C-45E3-BC58-9F7AE9C20D45} 2013-12-14 17:25 - 2012-11-05 17:33 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-12-12 16:02 - 2013-02-07 13:24 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-12-12 16:02 - 2012-11-03 18:08 - 00000000 ____D C:\ProgramData\Skype 2013-12-10 20:31 - 2012-11-03 14:57 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-10 20:31 - 2012-11-03 14:57 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-10 20:31 - 2012-11-03 14:57 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-10 10:29 - 2013-12-10 10:27 - 106478430 _____ C:\Users\Nutzername\Downloads\oc_export_instance_13-12-10_09-24-07.zip 2013-12-10 10:25 - 2013-12-10 10:24 - 15436770 _____ C:\Users\Nutzername\Downloads\owncloud-latest.tar.bz2 2013-12-10 09:49 - 2013-12-10 09:48 - 15436770 _____ C:\Users\Nutzername\Downloads\owncloud-5.0.13.tar.bz2 2013-12-09 14:07 - 2013-12-09 14:07 - 02433536 _____ C:\Users\Nutzername\Documents\aufgabe1-3.ppt 2013-12-09 12:58 - 2013-11-12 14:09 - 00001719 _____ C:\Users\Nutzername\weka.log 2013-12-06 18:28 - 2013-12-06 18:28 - 09091423 _____ (Electronic Arts) C:\Users\Nutzername\Downloads\GameFaceBrowserPluginInstaller.1.8.0.0.exe 2013-12-06 18:28 - 2013-12-06 18:28 - 00000000 ____D C:\Users\Nutzername\AppData\Roaming\Electronic Arts 2013-12-05 13:57 - 2013-12-05 13:57 - 11703558 _____ C:\Users\Nutzername\Downloads\Framework OpenGL Terrain Texture Culling.zip Files to move or delete: ==================== C:\ProgramData\Shrew Soft VPN.dat Some content of TEMP: ==================== C:\Users\Nutzername\AppData\Local\Temp\AutoRun.exe C:\Users\Nutzername\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Nutzername\AppData\Local\Temp\eauninstall.exe C:\Users\Nutzername\AppData\Local\Temp\firefoxjre_exe.exe C:\Users\Nutzername\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Nutzername\AppData\Local\Temp\jna675992043944514527.dll C:\Users\Nutzername\AppData\Local\Temp\jre-7u13-windows-i586-iftw.exe C:\Users\Nutzername\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\Nutzername\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Nutzername\AppData\Local\Temp\mscomctlocxupdater.exe C:\Users\Nutzername\AppData\Local\Temp\pylBCA0.tmp.exe C:\Users\Nutzername\AppData\Local\Temp\SC4_UNINST.EXE C:\Users\Nutzername\AppData\Local\Temp\SimCity 4_uninst.exe C:\Users\Nutzername\AppData\Local\Temp\SkypeSetup.exe C:\Users\Nutzername\AppData\Local\Temp\vlc-2.0.4-win32.exe C:\Users\Nutzername\AppData\Local\Temp\vlc-2.0.5-win32.exe C:\Users\Nutzername\AppData\Local\Temp\vlc-2.0.6-win32.exe C:\Users\Nutzername\AppData\Local\Temp\vlc-2.0.7-win32.exe C:\Users\Nutzername\AppData\Local\Temp\vlc-2.0.8-win32.exe C:\Users\Nutzername\AppData\Local\Temp\vlc-2.1.2-win32.exe C:\Users\Nutzername\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-31 11:04 ==================== End Of Log ============================ Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-01-2014 Ran by Nutzername at 2014-01-04 00:42:18 Running from C:\Users\Nutzername\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Tools for .Net 3.5 - DEU Lang Pack (x32 Version: 3.11.50727 - Microsoft Corporation) Hidden Tools for .Net 3.5 (x32 Version: 3.11.50727 - Microsoft Corporation) Hidden µTorrent (HKCU Version: 3.3.2.30303 - BitTorrent Inc.) Absolute Reminder (x32 Version: 2.0.0.17 - Absolute Software) Acronis*True*Image*Home 2012 (x32 Version: 15.0.7133 - Acronis) Hidden Adobe AIR (x32 Version: 3.5.0.880 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.5.0.880 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Photoshop CS6 (x32 Version: 13.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05 - Adobe Systems Incorporated) Alcor Micro USB Card Reader (x32 Version: 3.1.3042.60281 - Alcor Micro Corp.) Alcor Micro USB Card Reader (x32 Version: 3.1.3042.60281 - Alcor Micro Corp.) Hidden Atheros WLAN Client Installation Program (x32 Version: 9.0 - Atheros) Benutzerhandbuch (x32 Version: 1.0.0.6 - Lenovo) Hidden Blend for Visual Studio 2012 (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden Blend for Visual Studio 2012 DEU resources (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden Bluetooth Win7 Suite (64) (Version: 7.3.0.145 - Atheros Communications) BootShield (x32 Version: 1.0.1.9 - Lenovo) calibre (x32 Version: 0.9.43 - Kovid Goyal) Catan 1.0 (x32 Version: 1.0 - USM) CheapMe (x32 Version: - CheapMeu) Cities XL 2012 (x32 Version: 1.0.0 - Focus Home Interactive) Clonk Rage (x32 Version: - RedWolf Design GmbH) Conexant HD Audio (Version: 8.54.28.50 - Conexant) Counter-Strike (x32 Version: - Valve) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32 Version: - Microsoft) Devenv-Ressourcen für Microsoft Visual Studio 2012 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Dia (nur entfernen) (x32 Version: - ) Dolby Home Theater v4 (x32 Version: 7.2.7000.7 - Dolby Laboratories Inc) Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4521.29298 - PreEmptive Solutions) Hidden Dotfuscator and Analytics Community Edition Language Pack (x32 Version: 5.5.4521.29298 - PreEmptive Solutions) Hidden Dropbox (HKCU Version: 2.4.10 - Dropbox, Inc.) EA SPORTS Game Face Browser Plugin 1.8.0.0 (HKCU Version: 1.8.0.0 - Electronic Arts) Energy Management (x32 Version: 7.0.4.1 - Lenovo) Energy Management (x32 Version: 7.0.4.1 - Lenovo) Hidden Entity Framework Designer für Visual Studio 2012 - DEU (x32 Version: 11.1.20702.00 - Microsoft Corporation) Erforderliche Komponenten für SSDT (x32 Version: 11.0.2100.60 - Microsoft Corporation) Ext2Fsd 0.51 (Version: 0.51 - Matt Wu) FileZilla Client 3.7.3 (x32 Version: 3.7.3 - Tim Kosse) FLV Player 2.0 (build 25) (x32 Version: 2.0 (build 25) - Martijn de Visser) FRITZ!Box-Fernzugang einrichten (x32 Version: 1.0.3 - AVM Berlin) Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.) Google Earth (x32 Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden GTA2 (x32 Version: 1.00.001 - ) Gtk# for .Net 2.12.10 (x32 Version: 2.12.10 - Novell, Inc.) Gtk# for .Net 2.12.10 (x32 Version: 2.12.10 - Xamarin, Inc.) HTC BMP USB Driver (x32 Version: 1.0.5375 - HTC) HTC Driver Installer (x32 Version: 3.0.0.007 - HTC Corporation) HTC Driver Installer (x32 Version: 4.0.1.001 - HTC Corporation) IIS 8.0 Express (Version: 8.0.1557 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (Version: - ) IIS Express Application Compatibility Database for x86 (Version: - ) Intel AppUp(SM) center (x32 Version: 03.05.11 - Intel) Intel(R) Management Engine Components (x32 Version: 8.0.10.1464 - Intel Corporation) Intel(R) OpenCL CPU Runtime (x32 Version: - Intel Corporation) Intel(R) Processor Graphics (x32 Version: 8.15.10.2656 - Intel Corporation) Intel(R) Rapid Start Technology (x32 Version: 1.0.0.1021 - Intel Corporation) Intel(R) Rapid Storage Technology (x32 Version: 11.1.0.1006 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.4.220 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.23.943.1 - Intel Corporation) Hidden Intelligent Touchpad (x32 Version: 1.00.0108 - Lenovo) IPTInstaller (x32 Version: 4.0.8 - HTC) IsoBuster 3.1 (x32 Version: 3.1 - Smart Projects) Java 7 Update 21 (64-bit) (Version: 7.0.210 - Oracle) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java SE Development Kit 7 Update 21 (64-bit) (Version: 1.7.0.210 - Oracle) Java SE Development Kit 7 Update 21 (x32 Version: 1.7.0.210 - Oracle) Java SE Development Kit 7 Update 9 (64-bit) (Version: 1.7.0.90 - Oracle) JDownloader 0.9 (x32 Version: 0.9 - AppWork GmbH) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Lenovo CAPOSD (x32 Version: 1.0.0.7 - Lenovo) Lenovo CAPOSD (x32 Version: 1.0.0.7 - Lenovo) Hidden Lenovo EasyCamera (x32 Version: 6.1.7600.142 - Realtek Semiconductor Corp.) Lenovo OneKey Recovery (Version: 7.0.0.3807 - CyberLink Corp.) Hidden Lenovo OneKey Recovery (x32 Version: 7.0.0.3807 - CyberLink Corp.) Lenovo Registration (x32 Version: 1.0.4 - Lenovo Inc.) Lenovo Smart Update (x32 Version: 1.0.29 - Lenovo Corporation) Lenovo YouCam (x32 Version: 3.1.3728 - CyberLink Corp.) Lenovo YouCam (x32 Version: 3.1.3728 - CyberLink Corp.) Hidden LenovoDrv_x64 (Version: 1.0.00 - Lenovo) LibUSB-Win32-0.1.10.1 (x32 Version: 0.1.10.1 - LibUSB-Win32) LinuxLive USB Creator (x32 Version: 2.8 - Thibaut Lauziere) Little Fighter (x32 Version: - ) LocalESPC (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden LocalESPCui for de-de (x32 Version: 8.59.25584 - Microsoft) Hidden MATLAB R2012a (Version: 7.14 - The MathWorks, Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden MeshLab_64b 1.3.2 (Version: 1.3.2 - Paolo Cignoni - Guido Ranzuglia VCG - ISTI - CNR) Microsoft .NET Framework 4 Multi-Targeting Pack (x32 Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5 (Version: 4.5.50709 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5 Multi-Targeting Pack (x32 Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK - DEU Lang Pack (x32 Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (x32 Version: 4.5.50709 - Microsoft Corporation) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 3 - DEU (x32 Version: 3.0.20105.0 - Microsoft Corporation) Microsoft ASP.NET MVC 3 - Visual Studio 2012 Tools Update - DEU (x32 Version: 3.0.30710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 3 - Visual Studio 2012 Tools Update (x32 Version: 3.0.30710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 3 (x32 Version: 3.0.20105.0 - Microsoft Corporation) Microsoft ASP.NET MVC 4 - Visual Studio 2012 Tools - DEU (x32 Version: 4.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 4 - Visual Studio 2012 Tools (x32 Version: 4.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 4 Runtime - DEU (x32 Version: 4.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 4 Runtime (x32 Version: 4.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET Web Pages - DEU (x32 Version: 1.0.20105.0 - Microsoft Corporation) Microsoft ASP.NET Web Pages - Visual Studio 2012 Tools - DEU (x32 Version: 1.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET Web Pages - Visual Studio 2012 Tools (x32 Version: 1.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET Web Pages (x32 Version: 1.0.20105.0 - Microsoft Corporation) Microsoft ASP.NET Web Pages 2 - Visual Studio 2012 Tools - DEU (x32 Version: 2.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET Web Pages 2 - Visual Studio 2012 Tools (x32 Version: 2.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET Web Pages 2 Runtime - DEU (x32 Version: 2.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET Web Pages 2 Runtime (x32 Version: 2.0.20710.0 - Microsoft Corporation) Hidden Microsoft Help Viewer 2.0 (x32 Version: 2.0.50727 - Microsoft Corporation) Microsoft Help Viewer 2.0 (x32 Version: 2.0.50727 - Microsoft Corporation) Hidden Microsoft Help Viewer 2.0 Language Pack - DEU (x32 Version: 2.0.50727 - Microsoft Corporation) Microsoft Help Viewer 2.0 Language Pack - DEU (x32 Version: 2.0.50727 - Microsoft Corporation) Hidden Microsoft LightSwitch for Visual Studio 2012 Core (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft LightSwitch für Visual Studio 2012 CoreRes - DEU (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft NuGet - Visual Studio 2012 (x32 Version: 2.0.30625.9003 - Microsoft Corporation) Hidden Microsoft Office (x32 Version: 14.0.6120.5004 - Microsoft Corporation) Microsoft Office 2010 Service Pack 1 (SP1) (x32 Version: - Microsoft) Microsoft Office 2010 Service Pack 1 (SP1) (x32 Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden Microsoft Portable Library Multi-Targeting Pack (x32 Version: 11.0.50709.17929 - Microsoft Corporation) Hidden Microsoft Portable Library Multi-Targeting Pack Language Pack - deu (x32 Version: 11.0.50709.17929 - Microsoft Corporation) Hidden Microsoft Report Viewer Add-On for Visual Studio 2012 (x32 Version: 11.1.2802.16 - Microsoft Corporation) Hidden Microsoft Report Viewer Add-On für Visual Studio 2012 (x32 Version: 11.1.2802.16 - Microsoft Corporation) Hidden Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Silverlight 4 SDK - Deutsch (x32 Version: 4.0.60310.0 - Microsoft Corporation) Microsoft Silverlight 5 SDK - DEU (x32 Version: 5.0.61118.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2012 Command Line Utilities (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (Version: 11.0.2316.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x32 Version: 11.0.2316.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x32 Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL Compiler Service (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL Language Service (x32 Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 DEU (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (11.1.20627.00) (x32 Version: 11.1.20627.00 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - DEU (11.1.20627.00) (x32 Version: 11.1.20627.00 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x32 Version: 10.50.1600.1 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x64) (Version: 10.50.1600.1 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Designtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Compilers - DEU Resources (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Compilers (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Core Libraries (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Extended Libraries (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Microsoft Foundation Class Libraries (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Debug Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Debug Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Office Developer Tools (x64) (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Office Developer Tools (x64) Language Pack - DEU (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40303 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40308 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU (Version: 10.0.40303 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (Version: 10.0.40303 - Microsoft Corporation) Microsoft Visual Studio 2012 Devenv (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 IntelliTrace Core amd64 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 IntelliTrace Core x86 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 IntelliTraceLoc (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 IntelliTraceLoc (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 SharePoint Developer Tools (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 SharePoint Developer Tools DEU Language Pack (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Shell (Minimum) (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Shell (Minimum) Interop Assemblies (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Shell-(Mindest)-Ressourcen (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Tools für SQL Server Compact 4.0 SP1 DEU (x32 Version: 4.0.8876.1 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012-Leistungserfassungstools - DEU (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012-Leistungserfassungstools (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012-Vorbereitung (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Premium 2012 - DEU (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Premium 2012 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Premium 2012 (x32 Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual Studio Professional 2012 - DEU (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Professional 2012 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Object Model (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - DEU (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Storyboarding (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Storyboarding Language Pack - DEU (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Team Explorer (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Team Explorer Language Pack - DEU (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Ultimate 2012 XAML UI Designer Core (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Ultimate 2012 XAML UI Designer deu Resources (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Web Deploy 3.0 (Version: 3.1236.1631 - Microsoft Corporation) Microsoft Web Deploy dbSqlPackage Provider - DEU (x32 Version: 10.3.20225.0 - Microsoft Corporation) Microsoft Web Developer Tools - Visual Studio 2012 - DEU (x32 Version: 1.0.30710.0 - Microsoft Corporation) Hidden Microsoft Web Developer Tools - Visual Studio 2012 (x32 Version: 1.0.30710.0 - Microsoft Corporation) Hidden Microsoft Web Platform Installer 4.0 (Version: 4.0.1622 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (x32 Version: 4.0.20823.0 - Microsoft Corporation) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft-System-CLR-Typen für SQL Server 2012 (x32 Version: 11.0.2100.60 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (x64) (Version: 11.0.2100.60 - Microsoft Corporation) MiniTool Partition Wizard Home Edition 7.6 (x32 Version: - MiniTool Solution Ltd.) Minutor (x32 Version: 1.6.3 - Sean Kasun) mo'stream (x32 Version: 0.5 - mokim) MozBackup 1.5.1 (x32 Version: - Pavel Cvrcek) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 24.2.0 - Mozilla) Mozilla Thunderbird 24.2.0 (x86 de) (x32 Version: 24.2.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0 - Microsoft Corporation) MySQL Server 5.5 (Version: 5.5.28 - Oracle Corporation) Nero BackItUp (x32 Version: 12.0.3002 - Nero AG) Hidden Nero BackItUp Help (CHM) (x32 Version: 12.0.3000 - Nero AG) Hidden Nero Blu-ray Player (x32 Version: 12.0.14300 - Nero AG) Hidden Nero BurnRights (x32 Version: 12.0.5000 - Nero AG) Hidden Nero BurnRights Help (CHM) (x32 Version: 12.0.5000 - Nero AG) Hidden Nero ControlCenter (x32 Version: 11.0.15300 - Nero AG) Hidden Nero ControlCenter Help (CHM) (x32 Version: 12.0.5000 - Nero AG) Hidden Nero Core Components (x32 Version: 11.0.18100 - Nero AG) Hidden Nero CoverDesigner (x32 Version: 12.0.9000 - Nero AG) Hidden Nero CoverDesigner Help (CHM) (x32 Version: 12.0.2000 - Nero AG) Hidden Nero DiscSpeed 11 (x32 Version: 7.0.10400.2.100 - Nero AG) Hidden Nero DiscSpeed Help (CHM) (x32 Version: 12.0.1000 - Nero AG) Hidden Nero Express (x32 Version: 12.0.20000 - Nero AG) Hidden Nero Express Help (CHM) (x32 Version: 12.0.5000 - Nero AG) Hidden Nero InfoTool (x32 Version: 12.0.3000 - Nero AG) Hidden Nero InfoTool Help (CHM) (x32 Version: 12.0.0002 - Nero AG) Hidden Nero Kwik Media (x32 Version: 1.18.18800 - Nero AG) Hidden Nero Kwik Media Help (CHM) (x32 Version: 12.0.4000 - Nero AG) Hidden Nero Kwik Themes Basic (x32 Version: 12.0.11500 - Nero AG) Hidden Nero SharedVideoCodecs (x32 Version: 1.0.12100.2.0 - Nero AG) Hidden Nero Update (x32 Version: 11.0.11800.31.0 - Nero AG) Hidden Nero12EssTSST (x32 Version: 12.0.01100 - Nero AG) Notepad++ (x32 Version: 6.3.3 - Notepad++ Team) NVIDIA PhysX (x32 Version: 9.10.0223 - NVIDIA Corporation) OpenOffice.org 3.4.1 (x32 Version: 3.41.9593 - Apache Software Foundation) OptimizerPro (Version: 1.0 - BetterSoft) <==== ATTENTION Paragon ExtFS for Windows (x32 Version: - ) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden Pirmasoft RunAsSvc - mo'stream (x32 Version: 1.6.159.59 - Pirmasoft - Dieter Schmeer) Pizza Connection 2 (x32 Version: - ) PreEmptive Analytics Client German Language Pack (x32 Version: 1.0.2180.1 - PreEmptive Solutions) Hidden PreEmptive Analytics Visual Studio Components (x32 Version: 1.0.2180.1 - PreEmptive Solutions) Hidden Prerequisite installer (x32 Version: 12.0.0002 - Nero AG) Hidden PS3 Media Server (x32 Version: 1.72.0 - PS3 Media Server) Realtek Ethernet Controller All-In-One Windows Driver (x32 Version: 7.48.823.2011 - Realtek) SaveLiotss (x32 Version: - SaveoLuoots) SCE PlayStation(R)Mobile SDK 1.20.00 (x32 Version: 1.20.00 - Sony Computer Entertainment Inc.) SD Formatter (x32 Version: 2.9.5 - SDA) Secure Download Manager (x32 Version: 3.1.0 - Kivuto Solutions Inc.) Serious Sam 2 (x32 Version: - ) Shrew Soft VPN Client (Version: - ) Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) Slik Subversion 1.8.4 (x64) (Version: 1.8.4.0 - SlikSvn & The SharpSvn Project) StarUML 5.0.2.1570 (x32 Version: - Plastic Software, Inc.) Steam (x32 Version: 1.0.0.0 - Valve Corporation) SugarSync Manager (x32 Version: 1.9.49.86082 - SugarSync, Inc.) Synaptics Pointing Device Driver (Version: 15.3.33.0 - Synaptics Incorporated) System Requirements Lab CYRI (x32 Version: 5.0.6.0 - Husdawg, LLC) Tableau 8.0 (x32 Version: 8.0.998 - Tableau Software) Terraria (x32 Version: - Re-Logic) TeX Live 2012 (HKCU Version: 2012 - ) TightVNC (Version: 2.7.10.0 - GlavSoft LLC.) tools-freebsd (x32 Version: 9.2.0.812388 - VMware, Inc.) Hidden tools-linux (x32 Version: 9.2.0.812388 - VMware, Inc.) Hidden tools-netware (x32 Version: 9.2.0.812388 - VMware, Inc.) Hidden tools-solaris (x32 Version: 9.2.0.812388 - VMware, Inc.) Hidden tools-windows (x32 Version: 9.2.0.812388 - VMware, Inc.) Hidden tools-winPre2k (x32 Version: 9.2.0.812388 - VMware, Inc.) Hidden Ubisoft Game Launcher (x32 Version: 1.0.0.0 - UBISOFT) Unity (x32 Version: - Unity Technologies ApS) Unity Web Player (HKCU Version: - Unity Technologies ApS) Update for (KB2504637) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft Office 2010 (KB2553065) (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2553092) (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2566458) (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Visual Studio 2012 (KB2781514) (x32 Version: 11.0.51219 - Microsoft Corporation) UserGuide (x32 Version: 1.0.0.6 - Lenovo) Vegas Pro 12.0 (64-bit) (Version: 12.0.367 - Sony) VeriFace (x32 Version: 4.0.1.1230 - Lenovo) Visual Studio 2012 Prerequisites - DEU Language Pack (Version: 11.0.50727 - Microsoft Corporation) Hidden Visual Studio 2012 Prerequisites (Version: 11.0.50727 - Microsoft Corporation) Hidden Visual Studio Extensions for Windows Library for JavaScript (x32 Version: 1.0.8514.0 - Microsoft Corporation) Hidden VLC media player 2.0.2 (Version: 2.0.2 - VideoLAN) VLC media player 2.1.2 (x32 Version: 2.1.2 - VideoLAN) VMware Workstation (Version: 9.0.0 - VMware, Inc.) Hidden VMware Workstation (x32 Version: 9.0.0 - VMware, Inc) WBFS Manager 3.0 (x32 Version: 3.0 - AlexDP) WCF Data Services 5.0 (for OData v3) DEU Language Pack (x32 Version: 5.0.50628.0 - Microsoft Corporation) Hidden WCF Data Services 5.0 (for OData v3) Primary Components (x32 Version: 5.0.50628.0 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2012 (x32 Version: 5.0.50710.0 - Microsoft Corporation) Hidden WCF Data Services Tools for Visual Studio 11 DEU Language Pack (x32 Version: 5.0.50710.0 - Microsoft Corporation) Hidden WCF RIA Services V1.0 SP2 (x32 Version: 4.1.61829.0 - Microsoft Corporation) WebTect (x32 Version: - WorldLoad) Weka 3.6.10 (x32 Version: 3.6.10 - Machine Learning Group, University of Waikato, Hamilton, NZ) WinDirStat 1.1.2 (HKCU Version: - ) Windows App Certification Kit Native Components (Version: 8.59.25584 - Microsoft Corporation) Hidden Windows App Certification Kit x64 (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Driver Package - Lenovo Corporation (LAD) System (01/13/2012 1.0.0.2) (Version: 01/13/2012 1.0.0.2 - Lenovo Corporation) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Family Safety (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Runtime Intellisense Content - de-de (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit DirectX x64 Remote (Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit DirectX x86 Remote (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit for Windows Store Apps (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit for Windows Store Apps DirectX x64 Remote (Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit for Windows Store Apps DirectX x86 Remote (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows-Treiberpaket - Lenovo (ACPIVPC) System (12/15/2011 7.1.0.1) (Version: 12/15/2011 7.1.0.1 - Lenovo) WinMerge 2.12.4 (x32 Version: 2.12.4 - Thingamahoochie Software) WinPcap 4.1.3 (x32 Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinRAR 4.20 (64-Bit) (Version: 4.20.0 - win.rar GmbH) Wireshark 1.8.5 (64-bit) (x32 Version: 1.8.5 - The Wireshark developer community, hxxp://www.wireshark.org) Zoo Tycoon 2 (x32 Version: 1.0 - Microsoft) ==================== Restore Points ========================= 01-01-2014 20:02:19 FRITZ!Box-Fernzugang einrichten wird installiert ==================== Hosts content: ========================== 2009-07-14 03:34 - 2012-11-27 22:22 - 00001289 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0EA8C207-9318-4AF5-A6CB-2D4E618E1596} - System32\Tasks\schedule!3036567561 => C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe [2013-01-23] () <==== ATTENTION Task: {0FDD9477-608A-4660-85F6-E3509ACB2067} - System32\Tasks\Intel® Rapid Start Technology Manager => C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe [2012-02-05] (Intel) Task: {1D8B175A-D447-42DB-98B7-40FDC87F0AF2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated) Task: {23C66DD3-69D2-4089-898B-A5A623760C1E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-08-15] (Google Inc.) Task: {89BDAF7D-80CA-4FAA-BB55-28ACBE2D501F} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe Task: {A2DFAECA-3320-467C-AF68-FD96969F7547} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2011-01-28] (CyberLink) Task: {B3625402-A3D7-4AF4-9187-8229FBEFDC3C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-08-15] (Google Inc.) Task: {B7781493-6262-4325-ADB1-0FEBB7A3378A} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe Task: {D2367FA3-5DF3-4B6E-A999-1596A7829618} - System32\Tasks\OFFICE2010ACT => C:\Windows\System32\OFFICEICON.vbs [2012-02-23] () Task: {F675A69A-90F9-4EFC-831A-A59D52BC5F81} - System32\Tasks\Paragon ExtFS for Windows => C:\Program Files (x86)\Paragon Software\Paragon ExtFS for Windows\Paragon ExtFS for Windows.exe [2013-11-29] () Task: {F7C45D10-56D9-4290-AAEE-B500051A316E} - System32\Tasks\Absolute Reminder => C:\Program Files (x86)\Absolute Software\Absolute Reminder\AbsoluteReminder.exe [2011-07-12] (Absolute Software) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\schedule!3036567561.job => C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2011-03-17 00:07 - 2011-03-17 00:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2008-12-20 02:20 - 2012-08-15 16:47 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll 2012-04-19 15:22 - 2012-08-15 16:47 - 01516592 _____ () C:\Program Files (x86)\Lenovo\Energy Management\EMWpfUI.dll 2012-03-10 15:31 - 2012-08-15 16:47 - 00012336 _____ () C:\Program Files (x86)\Lenovo\Energy Management\de-DE\EMWpfUI.resources.dll 2008-12-20 02:20 - 2012-08-15 16:47 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll 2012-03-12 03:00 - 2012-02-17 17:21 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll 2012-08-15 14:11 - 2012-08-15 14:11 - 01222656 _____ () C:\Program Files (x86)\VMware\VMware Workstation\libxml2.dll 2013-12-29 12:52 - 2013-12-29 12:52 - 04112384 _____ () C:\ProgramData\WebTect\WebTect.dll 2013-12-29 12:52 - 2013-12-29 12:52 - 00180048 _____ () C:\ProgramData\WebTect\WebTectSvc.dll 2012-08-15 16:33 - 2012-06-25 14:45 - 00891392 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\QtNetwork4.dll 2012-08-15 16:33 - 2012-06-25 14:45 - 02281984 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\QtCore4.dll 2012-08-15 16:33 - 2012-06-25 14:45 - 00322048 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\log4cplus.dll 2012-08-15 16:33 - 2012-06-25 14:45 - 00339456 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\QtXml4.dll 2012-08-15 16:33 - 2012-06-25 14:45 - 00400384 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\sqlite3.dll 2012-08-15 16:33 - 2012-06-25 14:45 - 00015872 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\featureController.dll 2012-08-15 16:33 - 2012-06-25 14:45 - 00062976 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\osEvents.dll 2012-08-15 16:33 - 2012-06-25 14:45 - 00195584 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\libgsoap.dll 2012-08-15 16:33 - 2012-06-25 14:45 - 00062464 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\zlib1.dll 2012-08-15 16:33 - 2012-06-25 14:45 - 00443904 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\deviceProfile.dll 2012-08-15 16:33 - 2012-06-25 14:45 - 00019456 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\eventsSender.dll 2012-08-15 16:33 - 2012-06-25 14:45 - 00060928 _____ () C:\Program Files (x86)\Intel\IntelAppStore\bin\serviceManagerStarter.dll 2012-08-15 16:40 - 2012-08-15 16:40 - 00013664 _____ () C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll 2011-06-28 07:28 - 2011-06-28 07:28 - 00042496 _____ () C:\Program Files (x86)\Lenovo\Lenovo CAPOSD\QTKB.dll 2013-12-20 10:29 - 2013-12-20 10:30 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2011-03-17 00:11 - 2011-03-17 00:11 - 04297568 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\Nutzername\AppData\Roaming\Dropbox\bin\libcef.dll 2013-01-10 16:18 - 2013-01-10 16:18 - 00172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\2134117ca053ce1825bac39b909a2946\IsdiInterop.ni.dll 2012-08-15 16:09 - 2012-02-01 15:25 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2012-08-15 16:22 - 2012-03-28 15:18 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Nutzername\Documents\[go_student].bat:com.dropbox.attributes ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Shrew Soft Virtual Adapter Description: Shrew Soft Virtual Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Shrew Soft Service: vnet Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (01/04/2014 00:36:02 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc) (User: ) Description: An error has occurred (---query FLAG_AUTO_SVC_CHANGED key success failed with 1, The Code is:0x424.). Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc) (User: ) Description: An error has occurred (---Get FLAG_AUTO_SVC_CHANGED Open key suc failed with 0, The Code is:0x422.). Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc) (User: ) Description: An error has occurred (---query FLAG_AUTO_SVC_CHANGED key success failed with 1, The Code is:0x424.). Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc) (User: ) Description: An error has occurred (---Get FLAG_AUTO_SVC_CHANGED Open key suc failed with 0, The Code is:0x422.). Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc) (User: ) Description: An error has occurred (---query POLICYVT key success failed with 0, The Code is:0x424.). Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc) (User: ) Description: An error has occurred (---Get Poicy Open key suc failed with 0, The Code is:0x422.). Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc) (User: ) Description: An error has occurred (---query FLAG_AUTO_SVC_CHANGED key success failed with 1, The Code is:0x424.). Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc) (User: ) Description: An error has occurred (---Get FLAG_AUTO_SVC_CHANGED Open key suc failed with 0, The Code is:0x422.). Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc) (User: ) Description: An error has occurred (---query POLICYVT key success failed with 0, The Code is:0x424.). System errors: ============= Error: (01/04/2014 00:34:18 AM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (01/04/2014 00:34:14 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "LibUsb-Win32 - Daemon, Version 0.1.10.1" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/04/2014 00:34:13 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/04/2014 00:34:10 AM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\libusb0.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (01/04/2014 00:34:09 AM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\libusb0.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (01/04/2014 00:34:09 AM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\libusb0.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (01/04/2014 00:34:07 AM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\libusb0.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (01/04/2014 00:34:07 AM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\libusb0.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (01/03/2014 04:07:11 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "LibUsb-Win32 - Daemon, Version 0.1.10.1" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/03/2014 04:07:11 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (01/04/2014 00:36:02 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc)(User: ) Description: BootShieldSvc---query FLAG_AUTO_SVC_CHANGED key success failed with 1, The Code is:0x424. Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc)(User: ) Description: BootShieldSvc---Get FLAG_AUTO_SVC_CHANGED Open key suc failed with 0, The Code is:0x422. Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc)(User: ) Description: BootShieldSvc---query FLAG_AUTO_SVC_CHANGED key success failed with 1, The Code is:0x424. Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc)(User: ) Description: BootShieldSvc---Get FLAG_AUTO_SVC_CHANGED Open key suc failed with 0, The Code is:0x422. Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc)(User: ) Description: BootShieldSvc---query POLICYVT key success failed with 0, The Code is:0x424. Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc)(User: ) Description: BootShieldSvc---Get Poicy Open key suc failed with 0, The Code is:0x422. Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc)(User: ) Description: BootShieldSvc---query FLAG_AUTO_SVC_CHANGED key success failed with 1, The Code is:0x424. Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc)(User: ) Description: BootShieldSvc---Get FLAG_AUTO_SVC_CHANGED Open key suc failed with 0, The Code is:0x422. Error: (01/04/2014 00:34:30 AM) (Source: BootShieldSvc)(User: ) Description: BootShieldSvc---query POLICYVT key success failed with 0, The Code is:0x424. ==================== Memory info =========================== Percentage of memory in use: 60% Total physical RAM: 3957.08 MB Available physical RAM: 1571 MB Total Pagefile: 7912.34 MB Available Pagefile: 4936.64 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (Windows7_OS) (Fixed) (Total:213.26 GB) (Free:13.22 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (LENOVO) (Fixed) (Total:25.47 GB) (Free:21.46 GB) NTFS Drive e: (Data) (Fixed) (Total:207.3 GB) (Free:142.8 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 8 GB) (Disk ID: 1E79D320) Partition 1: (Not Active) - (Size=8 GB) - (Type=84) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 1E79D324) Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=213 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=233 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=19 GB) - (Type=02) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2014-01-04 00:58:21 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-1 Intel___ rev.1.0. 465,76GB Running: gmer_2.1.19163.exe; Driver: C:\Users\Nutzername\AppData\Local\Temp\kwrdrpoc.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560 fffff800031f7000 45 bytes [00, 00, 4D, 00, 40, 47, 4D, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 607 fffff800031f702f 16 bytes [00, 00, 00, 00, 00, 00, 10, ...] ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe[2264] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762d1465 2 bytes [2D, 76] .text C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe[2264] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762d14bb 2 bytes [2D, 76] .text ... * 2 .text C:\Users\Nutzername\AppData\Roaming\Dropbox\bin\Dropbox.exe[6464] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 00000000762d1465 2 bytes [2D, 76] .text C:\Users\Nutzername\AppData\Roaming\Dropbox\bin\Dropbox.exe[6464] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 00000000762d14bb 2 bytes [2D, 76] .text ... * 2 ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\AUDIODG.EXE [1312:2912] 0000000074b375a0 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74e543c2aa60 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74e543c2aa60@980d2e92e4d7 0x21 0xC8 0x98 0x8E ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xED 0xC1 0xE6 0x41 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xFE 0xE3 0xDF 0x1B ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x9E 0x34 0x41 0x98 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74e543c2aa60 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74e543c2aa60@980d2e92e4d7 0x21 0xC8 0x98 0x8E ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xED 0xC1 0xE6 0x41 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xFE 0xE3 0xDF 0x1B ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x9E 0x34 0x41 0x98 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{60868564-A801-D4A3-0145-5089FAC14F32} ---- EOF - GMER 2.1 ---- Vielen Dank und viele Grüße Geändert von radix89 (04.01.2014 um 01:30 Uhr) |
Themen zu Telekom Abuse Mail Port 25 gesperrt |
4d36e972-e325-11ce-bfc1-08002be10318, adblock, autokms, avira, cheapme, computer, cpu, device driver, entfernen, error, excel, failed, firefox, flash player, focus, google, home, homepage, installation, mozilla, optimizerpro, performance, plug-in, popup, port, realtek, registry, required, rundll, scan, security, svchost.exe, usb, wlan |